Repository navigation
feat(land-lock): carry the authorised branch, and answer whether it may run (CLOUD-420) - #363
Conversation
…ay run The lease identifies a CLONE — hostname-pid-random — which a GitHub runner has nothing to compare itself against, so the lease is checkable only by the code path that cooperates. That is CLOUD-420's enabling gap: an agent that pushes to an already-ready PR spends a full matrix without ever touching the lock, and measured 2026-08-12 that was four concurrent matrices while the lease changed hands three times, every holder honouring it. A branch name is the one identifier both ends can see. The lease body gains a `branch:` line and land-lock gains `authorises <branch>`, a read-only verb that is a pure function of (lease state, branch): 0 run, 3 stop, 2 could not look. Three is a third answer the usual pair cannot carry, since 1 already means "held by someone else" — a reason to stop rather than the instruction. It is the one predicate here that fails OPEN, and the asymmetry is the whole design: a lease this cannot read would stop every job in the fleet, where waving one matrix through costs one matrix. An unreachable remote, an unparseable body and a lease carrying no branch all run. That last row is not an edge case during rollout — it is every lease minted before this commit, which is why the field ships ahead of the CI step that reads it. The name `branch` was already taken here for the lease's own ref, so the new value is `land_branch`; writing the wrong one would stamp batten-land-lock into every lease and look correct in review. A test pins that. Ten rows cover the table and both mutants discriminate: inverting the comparison kills the run/stop pair, turning fail-open into fail-closed kills the rollout row. Refs: CLOUD-420 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X4tzyT3Q3hXo5QFEESENYP
CLOUD-420 The landing lease is enforced only by the code path that honours it, so an agent that skips `land` still spends a full matrix
Why CLOUD-393 serialises landing behind a lease and cuts the discarded-CI-run rate. It is enforced entirely inside That is the failure this repository names on its front page: "A new rule without a runnable gate is half a change. Prose is feedforward only." The lease is a convention honoured by the cooperating path, and the threat model is the honest agent that does the wrong thing — CLOUD-200 records a session that satisfied The dominant case is residue, not defiance. Measured 05:17–05:19Z on 2026-08-12: four concurrent The enabling gap. The lease identifies a clone ( Refinement — Ready
Nothing in the table asks why a push happened, which is what makes it cover the residue case: the precondition is per job rather than per landing, so a push to a PR left ready by an interrupted The last row is the design and not a fallback: failing open costs one matrix, while failing closed on an unreadable ref stops every PR in the fleet, and a body minted before this change ages out within one TTL (120s).
Cost (§1), in the unit the invoice uses. This repository is private and every
Local execution is the unmetered tier and nothing here moves work onto the metered one. The CI-side check exists because the local one is the half an interrupted session never reaches. Test obligation
Commit / bump (§6): Blockers (§8): blockedBy CLOUD-363 — the stop conclusion is safe only once a cancelled required check reads as no verdict rather than as red, which is in flight on #302. CLOUD-393 landed in #340, so the lease exists, and adding Acceptance
|
|
|
/fast-forward |



First of two for CLOUD-420. This is the enabling gap the issue names: the lease identifies a clone (
hostname-pid-random), which a GitHub runner has nothing to compare itself against — so the lease is checkable only by the code path that already cooperates.branch:line, andland-lockgainsauthorises <branch>: read-only, side-effect free, a pure function of (lease state, branch). Exits 0 run / 3 stop / 2 could not look. Three is a third answer the usual pair cannot carry —1already means "held by someone else", which is a reason to stop rather than the instruction.branch:all run.branch:, so that fail-open row is not an edge case during rollout — it is every lease. Landing the field first means live leases already carry it when the workflow check arrives.branchwas already a global here meaning the lease's own ref, so the new value island_branch. Writing the wrong one stampsbatten-land-lockinto every lease and looks correct in review; a test pins it.45/45 in
tests/land-lock.bats, ten of them new. Both mutants discriminate: inverting the comparison kills the run/stop pair, turning fail-open into fail-closed kills the rollout row.Next PR: the workflow precondition,
ci-local-parity's property, andready-guard's receipt — plus a correction to the issue's design that measurement turned up, noted below.Correction for the issue: the refinement rests on "branch protection requires only
final, which concludes cancelled too". That is false —ci.yml:242usesalways(), which GitHub runs even when the run is cancelled. Proven on run31566043914:cicancelled,finalexecuted and failed. The next PR changes it to!cancelled(); without that, every lease-stopped run would redfinalandlandre-drafts on red — re-drafting healthy PRs fleet-wide, the outcome the hazard section calls disqualifying.Refs: CLOUD-420
Generated by Claude Code