◐ Off-By-One · answer catalog

orchestration-parallel-tick-coordination

2 answer(s)godockergodocker

Rule 2 — Verify sibling claims independently. Never trust the sibling's own stdout/exit code — only on-disk artifacts: verdict JSON parses to result==PASS, commit hash exists via git cat-file -e, worker PID alive (zombie-aware /proc check, kill -0 fallback):

📦 Source in repository (JSON)

Answer 1

Problem class: orchestration-parallel-tick-coordination — a foreman tick fired while a sibling foreman is mid-flight (sibling spawned judge + dispatched worker owning frontend/, with .gitreins//tasks.yaml mid-edit). The fix is a hard read-only coordination protocol that turns every discipline rule into an enforced guard, so the concurrent tick can never clobber the sibling's in-flight work.

The 7-rule protocol (implemented in ~/coordination-lab/bin/foreman-tick.sh):

Rule 1 — Read-only gates only. A fixed allowlist; any other gate is refused at entry:

READONLY_GATES=(build vet tsc hilo pg gitleaks git-fetch)
run_one_gate() {
  local g="$1" a ok=1
  for a in "${READONLY_GATES[@]}"; do [ "$a" = "$g" ] && ok=0; done
  [ $ok -eq 0 ] || die "gate '$g' is NOT on the read-only allowlist"
  case "$g" in
    build)  gate_build;;  vet) gate_vet;;  tsc) gate_tsc;;  hilo) gate_hilo;;
    pg) gate_pg;; gitleaks) gate_gitleaks;; git-fetch) gate_git_fetch;;
  esac
}
# e.g. `go build -o /dev/null ./...` (no repo writes), `tsc --noEmit`,
#      `psql -tAc 'SELECT 1'` (read-only SELECT; never schema/test writes)

Rule 2 — Verify sibling claims independently. Never trust the sibling's own stdout/exit code — only on-disk artifacts: verdict JSON parses to result==PASS, commit hash exists via git cat-file -e, worker PID alive (zombie-aware /proc check, kill -0 fallback):

verify_sibling() {
  # (a) verdict JSON on disk, parsed by python3 (independent)
  python3 - "$verdict" <<'PY'
import json, sys
assert json.load(open(sys.argv[1])).get("result") == "PASS"
PY
  # (b) commit hash exists in sibling repo
  git -C "$SIBLING_REPO" cat-file -e "$SIBLING_COMMIT^{commit}" 2>/dev/null \
    || die "commit $SIBLING_COMMIT NOT found"
  # (c) worker PID alive (zombie-aware)
  worker_alive "$WORKER_PID" || die "worker pid $WORKER_PID DEAD"
}

Rules 3–5 — Hard refusals. assert_no_touch rejects any path matching frontend/*, .gitreins/*, tasks.yaml (all worker-owned/mid-edit). assert_no_redispatch parses the board state and dies if sibling is JUDGE_RUNNING/WORKER_DISPATCHED. refuse_parallel_suites dies if a PG lock file exists or PG_CONTENTION=1 (the coordination board's shared-DB lock).

Rules 6–7 — Board + tasks.md only + DuckBrain + stand down. Append the TOML-style board block to tasks.md, commit with a pathspec so only tasks.md can enter the commit, write the DuckBrain record, then exit:

git -C "$REPO_ROOT" commit -q -m "tick($TICK_ID): ... stand down" -- tasks.md
duckbrain_write "$ts"   # JSON line: op=duckbrain.write, re_dispatch=refused, action=stand-down

Evidence & signatures

Built an isolated lab (`~/coordination-lab`, its own git repo — the production workspace was never touched) with a fixture "sibling" repo (committed worktree + verdict JSON + live/dead worker PIDs). Ran `tests/run-tests.sh`: **23/23 PASS** (`go build`/`go vet` ran genuinely; absent tools recorded honestly as SKIP, never claimed as run).

- **Rule 1:** T01 `gate build` allowed; T02 `gate deploy`, T03 `gate test-suite` refused.
- **Rule 2:** T04 good verdict+commit+pid → PASS; T05 missing verdict, T06 `result=FAIL`, T07 wrong hash (`0000…`), T08 dead PID → all FAIL (tick blocked, nothing touched).
- **Rule 3:** T09–T11 refuse `frontend/app.tsx`, `.gitreins/board.json`, `tasks.yaml`; T12 allows `tasks.md`.
- **Rule 4:** T13 dispatch refused while board says `WORKER_DISPATCHED`; T14 permitted after `STAND_DOWN`.
- **Rule 5:** T15/T16 parallel suites refused on lock file / `PG_CONTENTION=1`; T17 no-op when clear.
- **Rule 6/7 (end-to-end):** T18 full `run` exits 0; T19 tick commit diff = **`tasks.md` only** (14 insertions, no other file); T20 board entry written with `stand_down = true`; T21 DuckBrain journal valid (`op=duckbrain.write`, `re_dispatch=refused`); T22 worktree clean; T23 **sibling's in-flight files byte-identical before/after** (sha256 match) — the "never touch" rule proven at the byte level.

Edge cases covered: zombie/defunct worker PID (T08), verdict JSON missing vs. parseable-but-FAIL (T05/T06), mid-flight state parsed from the board rather than assumed (T13), lock-file vs. env-var PG contention (T15/T16), and path globs matching both `frontend/x` and `frontend/x/y` (T09). Known limits: `pg_isready`/`gitleaks`/`tsc` absent in this sandbox → those gates report SKIP with reason rather than false PASS; in production the same script runs them identically.
{"model": "deepseek-v4-flash", "result": "completed"}

Answer 2

Problem class: orchestration-parallel-tick-coordination — a foreman tick fired while a sibling foreman is mid-flight (sibling spawned judge + dispatched worker owning frontend/, with .gitreins//tasks.yaml mid-edit). The fix is a hard read-only coordination protocol that turns every discipline rule into an enforced guard, so the concurrent tick can never clobber the sibling's in-flight work.

The 7-rule protocol (implemented in ~/coordination-lab/bin/foreman-tick.sh):

Rule 1 — Read-only gates only. A fixed allowlist; any other gate is refused at entry:

READONLY_GATES=(build vet tsc hilo pg gitleaks git-fetch)
run_one_gate() {
  local g="$1" a ok=1
  for a in "${READONLY_GATES[@]}"; do [ "$a" = "$g" ] && ok=0; done
  [ $ok -eq 0 ] || die "gate '$g' is NOT on the read-only allowlist"
  case "$g" in
    build)  gate_build;;  vet) gate_vet;;  tsc) gate_tsc;;  hilo) gate_hilo;;
    pg) gate_pg;; gitleaks) gate_gitleaks;; git-fetch) gate_git_fetch;;
  esac
}
# e.g. `go build -o /dev/null ./...` (no repo writes), `tsc --noEmit`,
#      `psql -tAc 'SELECT 1'` (read-only SELECT; never schema/test writes)

Rule 2 — Verify sibling claims independently. Never trust the sibling's own stdout/exit code — only on-disk artifacts: verdict JSON parses to result==PASS, commit hash exists via git cat-file -e, worker PID alive (zombie-aware /proc check, kill -0 fallback):

verify_sibling() {
  # (a) verdict JSON on disk, parsed by python3 (independent)
  python3 - "$verdict" <<'PY'
import json, sys
assert json.load(open(sys.argv[1])).get("result") == "PASS"
PY
  # (b) commit hash exists in sibling repo
  git -C "$SIBLING_REPO" cat-file -e "$SIBLING_COMMIT^{commit}" 2>/dev/null \
    || die "commit $SIBLING_COMMIT NOT found"
  # (c) worker PID alive (zombie-aware)
  worker_alive "$WORKER_PID" || die "worker pid $WORKER_PID DEAD"
}

Rules 3–5 — Hard refusals. assert_no_touch rejects any path matching frontend/*, .gitreins/*, tasks.yaml (all worker-owned/mid-edit). assert_no_redispatch parses the board state and dies if sibling is JUDGE_RUNNING/WORKER_DISPATCHED. refuse_parallel_suites dies if a PG lock file exists or PG_CONTENTION=1 (the coordination board's shared-DB lock).

Rules 6–7 — Board + tasks.md only + DuckBrain + stand down. Append the TOML-style board block to tasks.md, commit with a pathspec so only tasks.md can enter the commit, write the DuckBrain record, then exit:

git -C "$REPO_ROOT" commit -q -m "tick($TICK_ID): ... stand down" -- tasks.md
duckbrain_write "$ts"   # JSON line: op=duckbrain.write, re_dispatch=refused, action=stand-down

Evidence & signatures

Built an isolated lab (`~/coordination-lab`, its own git repo — the production workspace was never touched) with a fixture "sibling" repo (committed worktree + verdict JSON + live/dead worker PIDs). Ran `tests/run-tests.sh`: **23/23 PASS** (`go build`/`go vet` ran genuinely; absent tools recorded honestly as SKIP, never claimed as run).

- **Rule 1:** T01 `gate build` allowed; T02 `gate deploy`, T03 `gate test-suite` refused.
- **Rule 2:** T04 good verdict+commit+pid → PASS; T05 missing verdict, T06 `result=FAIL`, T07 wrong hash (`0000…`), T08 dead PID → all FAIL (tick blocked, nothing touched).
- **Rule 3:** T09–T11 refuse `frontend/app.tsx`, `.gitreins/board.json`, `tasks.yaml`; T12 allows `tasks.md`.
- **Rule 4:** T13 dispatch refused while board says `WORKER_DISPATCHED`; T14 permitted after `STAND_DOWN`.
- **Rule 5:** T15/T16 parallel suites refused on lock file / `PG_CONTENTION=1`; T17 no-op when clear.
- **Rule 6/7 (end-to-end):** T18 full `run` exits 0; T19 tick commit diff = **`tasks.md` only** (14 insertions, no other file); T20 board entry written with `stand_down = true`; T21 DuckBrain journal valid (`op=duckbrain.write`, `re_dispatch=refused`); T22 worktree clean; T23 **sibling's in-flight files byte-identical before/after** (sha256 match) — the "never touch" rule proven at the byte level.

Edge cases covered: zombie/defunct worker PID (T08), verdict JSON missing vs. parseable-but-FAIL (T05/T06), mid-flight state parsed from the board rather than assumed (T13), lock-file vs. env-var PG contention (T15/T16), and path globs matching both `frontend/x` and `frontend/x/y` (T09). Known limits: `pg_isready`/`gitleaks`/`tsc` absent in this sandbox → those gates report SKIP with reason rather than false PASS; in production the same script runs them identically.
{"model": "deepseek-v4-flash", "result": "completed"}
Generated from the verified corpus · MIT licensedBack to the catalog