fix: prevent silent backlog body loss in tasks wrapper - #208
Merged
Merged
Conversation
`fm-tasks-axi.sh update|edit --body|--body-file` replaced the whole body, so a caller meaning to add evidence could silently drop the prior text. Add a wrapper-owned `append-note` that keeps the prior body and verifies the stored result, and refuse a replace that would drop a non-empty body unless `--archive-body` keeps the old text recoverable.
…nd replacement guidance
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Prevent silent loss of a backlog item's body. On 2026-10-05, adding evidence to two items with
bin/fm-tasks-axi.sh edit <id> --body-file <file>replaced both bodies with only the new text, because the preceding read (show --json) printed nothing; the originals had to be recovered from session logs.Requirements:
tasks-axialready supports (tasks-axi --help,edit --help,update --help; AGENTS.md section 10 mentionsupdate --body-fileand--archive-body) and make the safe path the easy one inbin/fm-tasks-axi.sh, the wrapper this repo owns.fm-tasks-axi.sh append-note <id> --body-file <f>, also--body <text>).update/editwith--body/--body-file) refuse when the new body would drop a non-empty prior body, unless an explicit flag is passed; the chosen flag is--archive-bodyso the old text stays recoverable in tasks-axi's note archive. A replace whose new text still contains the prior body, or a replace of an empty body, proceeds unflagged (deliberate: those cannot lose text).show/listreject--json, so the wrapper reads the prior body fromshow --fulland fails closed when that read cannot be parsed. node is used to decode the JSON-quoted body line because jq is optional.Acceptance criteria:
bin/fm-test-run.sh --changed,FM_LINT_JOBS=1 bin/fm-lint.shclean, and the PR's full GitHub CI suite green.Firstmate-Validation-Generation: 2716322c0d01807c3f7439b538717213
What Changed
append-note <id> --body <text>or--body-file <path>to preserve the existing body, append text, and verify the stored result. The wrapper usesshow --fullbecause upstream has no append verb or JSON body-read support, and refuses writes when it cannot parse the body.updateandeditbody replacements, includingtaskaliases: dropping existing text requires--archive-body; preserving replacements and empty bodies proceed unflagged.Risk Assessment
High-impact surface (every backlog note write goes through this wrapper). The round-1 review bypass (flags before the ID, and
task update/task edit) was fixed in the review step and is covered by regression tests.Known limitation: append-note and the replace guard read the body and then write it as separate steps, so two concurrent writers to the same item could still lose a note; this is accepted because backlog mutations are already serialized by the backlog lease, and closing it fully would need an append or conditional-update primitive that upstream tasks-axi does not provide.
Testing
Focused real-CLI regressions and independent manual commands passed against isolated backlogs, with body and archive transcripts captured. One archive-format assertion was corrected and re-run successfully. Lint, broad regression, and CI remain with their assigned phases.
Evidence: Live CLI commands, persisted bodies, and recoverable archive
Evidence: Focused real-CLI regression results
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
bin/fm-tasks-axi.sh:315- With a non-empty prior body,update --json <id> --body replacementreturns here without checking preservation. Upstream removes flags before resolving the ID, so it successfully replaces the body without archiving. The same bypass affectsedit, both body input forms, andtask update/task edit, which bypass dispatch at bin/fm-tasks-axi.sh:340–346. Normalize the supported command forms and resolve the positional ID before applying the shared guard; otherwise refuse unsupported forms before forwarding.bin/fm-tasks-axi.sh:258- Simplification: append-note introduces a new--jsonoutput mode that no stated requirement needs. Remove its parser branch, forwarding at bin/fm-tasks-axi.sh:295, and usage declarations at lines 5, 97, and 233; retain the requested append operation.bin/fm-tasks-axi.sh:245- Simplification: append-note additionally accepts--body=...and--body-file=...at bin/fm-tasks-axi.sh:245 and :254. The requested separate-value forms satisfy the intent without these additional matching paths. Remove these branches unless the broader syntax is desired; upstream replacement-command compatibility can remain unchanged.🔧 Fix applied.
4 issues (2 errors, 2 warnings) still open:
bin/fm-tasks-axi.sh:315- With a non-empty prior body,update --json <id> --body replacementreturns here without checking preservation. Upstream removes flags before resolving the ID, so it successfully replaces the body without archiving. The same bypass affectsedit, both body input forms, andtask update/task edit, which bypass dispatch at bin/fm-tasks-axi.sh:340–346. Normalize the supported command forms and resolve the positional ID before applying the shared guard; otherwise refuse unsupported forms before forwarding.bin/fm-tasks-axi.sh:258- Simplification: append-note introduces a new--jsonoutput mode that no stated requirement needs. Remove its parser branch, forwarding at bin/fm-tasks-axi.sh:295, and usage declarations at lines 5, 97, and 233; retain the requested append operation.bin/fm-tasks-axi.sh:245- Simplification: append-note additionally accepts--body=...and--body-file=...at bin/fm-tasks-axi.sh:245 and :254. The requested separate-value forms satisfy the intent without these additional matching paths. Remove these branches unless the broader syntax is desired; upstream replacement-command compatibility can remain unchanged.bin/fm-tasks-axi.sh:284- Round 1 left a read/write race unresolved. Two append-note calls can read body X; B writes X+B and verifies successfully; A then writes X+A and verifies successfully, silently losing B without an archive. The same invariant must hold at bin/fm-tasks-axi.sh:272 (append read), :287 (verification), :330 (replacement-guard read), and :352 (forwarded replacement): a preserving replacement approved against X can overwrite intervening notes. Enforce preservation against the current body inside the shared mutation critical section. Coordinated locking or a conditional-update primitive extends the current machinery, so the remedy needs authorization; the existing upstream update lock covers only the write, not this preceding read.✅ **Test** - passed
✅ No issues found.
tasks-axi --help,tasks-axi edit --help, andtasks-axi update --helpTMPDIR="$PWD/.test-append-validation/tmp" bin/fm-test-run.sh tests/fm-tasks-axi.test.shpython3 .test-append-validation/drive.py: real wrapper commands with body, archive, and unchanged-backlog assertionsRemoved disposable testing directories and verifiedgit status --shortwas clean.✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.