Skip to content

Fork-internal verification: prove Orca worktree ownership before destructive teardown (upstream PR 4838) - #4

Open
MLA82 wants to merge 3 commits into
mainfrom
fm/werft-pr3723-ersatz
Open

MLA82 wants to merge 3 commits into
mainfrom
fm/werft-pr3723-ersatz

Conversation

@MLA82

@MLA82 MLA82 commented Sep 18, 2026

Copy link
Copy Markdown
Owner

Internal verification run only. This pull request exists solely so the inherited CI runs against this branch inside our own fork, where no workflow approval is required.

It is not intended to be merged. The corresponding upstream proposal is kunchenguid#4838, which replaces the earlier kunchenguid#3723.

The mandatory no-mistakes gate is expected to be red here: the attestation is bound to the upstream head, not to this internal pull request. That gate is a separate step and is not what this run is testing.

An Orca scout teardown, or any Orca teardown run with --force, skipped the
early Orca path-match check and only re-verified it after
reap_task_worktree_processes had already run against the recorded worktree
path, so a stale or reassigned Orca worktree id could have its processes
signalled before ownership was ever proven.

Fold the Orca proof into require_owned_task_worktree_slot, the same
early, single-owner ownership determination the treehouse pool-slot claim
already uses, so it runs once, well before Fix 1/Fix 2, for every kind and
--force alike, instead of being re-checked ad hoc at each later call site.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant