Repository navigation
fix(land): close the tap on every non-merged exit, not only on red (CLOUD-458) - #362
Conversation
CLOUD-420 The landing lease is enforced only by the code path that honours it, so an agent that skips `land` still spends a full matrix
Why CLOUD-393 serialises landing behind a lease and cuts the discarded-CI-run rate. It is enforced entirely inside That is the failure this repository names on its front page: "A new rule without a runnable gate is half a change. Prose is feedforward only." The lease is a convention honoured by the cooperating path, and the threat model is the honest agent that does the wrong thing — CLOUD-200 records a session that satisfied The dominant case is residue, not defiance. Measured 05:17–05:19Z on 2026-08-12: four concurrent The enabling gap. The lease identifies a clone ( Refinement — Ready
Nothing in the table asks why a push happened, which is what makes it cover the residue case: the precondition is per job rather than per landing, so a push to a PR left ready by an interrupted The last row is the design and not a fallback: failing open costs one matrix, while failing closed on an unreadable ref stops every PR in the fleet, and a body minted before this change ages out within one TTL (120s).
Cost (§1), in the unit the invoice uses. This repository is private and every
Local execution is the unmetered tier and nothing here moves work onto the metered one. The CI-side check exists because the local one is the half an interrupted session never reaches. Test obligation
Commit / bump (§6): Blockers (§8): blockedBy CLOUD-363 — the stop conclusion is safe only once a cancelled required check reads as no verdict rather than as red, which is in flight on #302. CLOUD-393 landed in #340, so the lease exists, and adding Acceptance
CLOUD-458 `land` re-drafts only on red, so every other interrupted landing leaves a ready PR that buys a full matrix on any later push
Why
Measured 2026-08-12, 05:17–05:19Z: four concurrent The draft economy is the whole reason drafts exist here: CI does not run on drafts, so iteration is free until a landing is actually being attempted. Readying is how Refinement — Ready
Test obligation
Commit / bump (§6): Blockers (§8): none. Acceptance
|
`land` readies a PR and re-drafted it on exactly one exit: red CI. Every other way a landing ends — a lost lease, a rebase conflict, a stopped task, a container reclaim — left the PR ready for good, and every later push to it bought a full matrix with no landing attempt in progress at all. Measured 2026-08-12: four concurrent `pull_request` matrices, three of the four PRs `draft=false` behind an interrupted land. The re-draft is conditional on the head's verdict, which is the design and not a caveat. The pre-push ready fires only on a head with NO graded run, so re-drafting a head that already graded green strands it: unmergeable while draft, and unreadyable because `graded_runs` is no longer zero. Readying it anyway is the worse repair — `ready_for_review` is a CI trigger, so recovering a green head would buy a whole matrix where that resume is a free fast-forward today. So red and no-answer re-draft, green stays ready, and "could not look" leaves it alone rather than stranding a head on a reading we failed to take. `checks-green` is the authority for "is this head green", not `graded_runs`: the two answer different questions, and the one that counts a failed or cancelled run as an answer would leave a green head ready only by accident. A SIGKILLed land runs no trap, so this closes the graceful subset only. Refs: CLOUD-458
…never fires `fails rebase` alone is inert: `land` rebases only when the branch is not already linear, and the stub's default is linear, so four of the new exit-trap cases sailed past the intended conflict into the fast-forward wait and blocked on `main-watch`, which never answers by design. A wedged suite emits no `not ok`, so it read as 463 passing tests for 31 minutes. The suite's existing conflict case already pairs the two levers; this copies that pairing rather than inventing a second way to reach the same stop. Refs: CLOUD-458
758e9cb to
2414d5c
Compare
|
|
/fast-forward |



Only the red path re-drafted, so a landing interrupted any other way — a lost
lease, a rebase conflict, a stopped task — left the PR ready for good, and every
later push to it bought a full matrix with no landing attempt in progress at all.
Measured 2026-08-12, 05:17–05:19Z: four concurrent
pull_requestmatrices whilethe lease changed hands three times, three of the four PRs
draft=falsebehindan interrupted land.
The re-draft is conditional, and that is the design
The pre-push ready fires only on a head with no graded run, so re-drafting a
head that already graded green strands it: unmergeable while draft, unreadyable
because
graded_runsis no longer zero. Readying it anyway is the worse repair —ready_for_reviewis a CI trigger, so recovering a green head buys a wholematrix where that resume is a free fast-forward today.
checks-greenis the authority for "is this head green", notgraded_runs: thetwo answer different questions, and the one that counts a failed or cancelled run
as an answer would leave a green head ready only by accident.
What a reviewer should look at
close_the_tapruns first in the EXIT trap and is guarded onsingleton_held,so a refused second land — which owns neither the lease nor the PR — touches
nothing. Same discipline the lease release already uses.
isDraft. Whether the PR is still open is already answered bylandedand by thedieabove, andpr view --json stateis sequenced by thepoll it belongs to.
server-side precondition (CLOUD-420) is what catches the rest.
Tests
tests/land.batsgains six cases, mutation-checked in both directions: remove thetrap call and the ungraded case goes back to leaving the PR ready; remove the
green guard and the green case starts re-drafting. Plus the unreadable verdict,
the merged path (with the verdict lever set to the value that would re-draft, so
it asserts the flag rather than the absence of an opportunity), the refused
singleton, and a failed re-draft not changing the exit code.
Refs: CLOUD-458