Conversation
ThreatCrush Security Scan4586 finding(s) HIGH/CRITICAL: 43 | MEDIUM: 4032 | LOW: 511
…and 4536 more. Full results in the Security tab. Snippets are redacted; ThreatCrush never prints matched credential material. |
ce712e5 to
c0dbd01
Compare
464c5f4 to
b84f2ef
Compare
| FNXC:TriagePlanningRecovery 2026-09-19-04:04: | ||
| The sweep announced "Recovering specified triage task <id>" on every poll for cards it never | ||
| recovered, and recorded no outcome when the recovery declined or when its own gates skipped the | ||
| candidate. The recorded engine log held 180 announcements and zero reasons, so an operator could |
| paused: false, | ||
| steps: [{ title: "Implement", status: "pending" }], | ||
| workflowStepResults: [ | ||
| { workflowStepId: "plan-review", workflowStepName: "Plan Review", phase: "pre-merge", status: "passed", verdict: "APPROVE" }, |
82d59cc to
4af29b0
Compare
…ing-spin + graph identity + session watchdog) FNXC:BoardReliability 2026-09-24-00:46: Consolidates the board-reliability fixes (the engine theme, kept separate from verify-perf in #11): 1. SOURCE-OF-TRUTH stranded count (stranded-commits.ts): fork-point + "0 task-unique = 0 stranded"; a failed fork-point falls back to ZERO, never the raw base. listStrandedCommits() uses the single source (the 2nd call site). 2. Planning-spin: an unchanged-but-valid authoritative PROMPT.md is SUCCESS (was re-planning forever). 3. Graph-failure identity: a parse/compile failure names the failing stage, not node 'unknown'. 4. Session-idle watchdog: aborts a runaway session (budget 250 tools / idle 30min) with RUNAWAY_SESSION (call fn_task_done). 5. Manual retry clears ANY non-user pause. Plus the typecheck step stays READ-ONLY (tsc --build --noEmit). Symptom Verification: - Original symptom: "N stranded commits since <base>" treadmill + planning-spin + node 'unknown' + 4h runaway sessions. - Exact reproduction: a task branch at the main tip vs merge-base; a valid unchanged PROMPT.md; a session that never calls fn_task_done. - Assertion it is gone: countStrandedCommits()==0 for shared lineage; planning accepts a valid unchanged spec; the watchdog aborts runaway sessions; the typecheck emits nothing (read-only).
…ead-only) FNXC:VerifyPerf 2026-09-24-01:00: MOVED from #17 (board-reliability) to #11 (verify-perf theme, per review). The typecheck step keeps the incremental tsbuildinfo cache (warm runs recheck only changed files) while staying READ-ONLY (--noEmit: no dist emit, no partial dist on a killed typecheck). Symptom Verification: warm verify typecheck rechecks only changed files; the step emits nothing (read-only).
2150a29 to
0dfb730
Compare
|
Review notes for the audited SHA The TypeScript build-cache change is worth keeping: a focused compiler check confirmed that One description needs correction: Git's built-in |
Problem
Two root causes parked task runs for hours on the 2026-09-23 nightly fleet (12GB desktop):
.changeset/pre.jsoncorruption on merge/rebase — when a branch rebased across achore(release)commit (e.g.v0.78.0-beta.6) and the conflict was resolved from the older side, the beta anchor broke andcheck-pre-json-anchorfailed deterministically on that branch. Two review tasks sat terminal-failed 8–9h with verification blocked. Same regression class as fix(RUFU-075): safest scheduler queue/mission-store writes for minimal stores Runfusion/Fusion#3472.pnpm -rdefaults to 4 concurrent projects, and pnpm 10.33 silently ignores the~/.npmrc workspace-concurrencykey (it echoes the value; behavior stays at 4). Each task typecheck fanned out 4tsc --noEmitworkers (500MB–1.4GB each) and thrashed the machine: memory PSIfull94%, engine HTTP timeouts, runs stuck in swap for 70+ minutes.Fix
.gitattributes:.changeset/pre.json merge=binary— built-in git merge driver that keeps the copy from the branch being merged INTO (the exact rulescripts/check-pre-json-anchor.mjsprescribes manually). No per-clone configuration needed — the commonmerge=oursrecipe requiresgit config merge.ours.driver truein every clone and otherwise leaves full conflict markers. The check stays as detection; this prevents the corruption at conflict-resolution time.pnpm-workspace.yaml:workspaceConcurrency: 2— caps recursive package commands at 2 projects at a time (the live pnpm 10.x config channel). Scope is onepnpm -rinvocation only. The manifest comment now states why the value stays a constant — pnpm 10 has no live env channel for it, and this is the only backstop for an ad-hocpnpm -rno script wraps — and that it is a blunt guardrail overridable per command with--workspace-concurrency, not a project requirement. Callers this repo owns already pass that flag explicitly (scripts/test-changed.mjsderives it fromFUSION_TEST_WORKSPACE_CONCURRENCY).scripts/verify-fast.mjs:TYPECHECK_PARALLEL_LIMITnow derives from RAM instead of core count — this is the guard that actually covers the typecheck fan-out of root cause 2.verify:fastspawns onepnpm --filter <pkg> typecheckprocess per changed package, and those bypassworkspaceConcurrencyentirely, so the key above cannot bound them. The oldmin(4, cpuCount / 2)gave 4 here;tscis memory-bound (1–1.4GB RSS each), so the ceiling is now 1 worker per 5GB of total RAM, capped at 4 — 2 on this 12GB box, and a 64GB machine is no longer slowed down by it.FUSION_VERIFY_FAST_TYPECHECK_CONCURRENCYoverrides the derived default, alongside the existingFUSION_VERIFY_FAST_SERIAL. Measured 2026-09-23: the 4-wide batch sat in D state at 3–7% CPU per worker for 10+ min with zero progress, drove memory PSIfullto 80%, and froze the desktop twice.STATIC_CHECK_PARALLEL_LIMITis untouched (those steps are node-startup dominated, not memory bound).scripts/dev-with-memory.mjs: the dev heap ceiling wasFUSION_DEV_MEMORY_MB || "8192"— a constant sized after one workstation, handing every node child an 8GB heap ceiling on a 12GB box. It now derives fromos.totalmem()(half of RAM, clamped 1–8GB → 6381MB here) with the env override kept. The wrapper also stopped prepending a second--max-old-space-sizewhenNODE_OPTIONSalready pins one (callers like the local Fusion launcher pin 2048, and precedence between repeated V8 flags is not worth relying on).Tests
pre.jsonrebase conflict leaves<<<<<<<markers with the older side able to win (bug reproduced); withmerge=binarythe file resolves to the INTO side automatically.node --check scripts/verify-fast.mjsclean; importing the module asserts the derived ceiling lands in 1–4 (2 on this 12GB box) and thatbuildTypecheckStep("@fusion/core", { hasTypecheck: true }).parallelLimitequals that constant rather than a literal, so a future edit cannot silently leave the step at 4. Override path checked too:FUSION_VERIFY_FAST_TYPECHECK_CONCURRENCY=3yields 3, while a garbage or0value falls back to the derived default. Exits non-zero if any assertion breaks.node --check scripts/dev-with-memory.mjsclean; formula check asserts the derived value lands in the 1–8GB clamp (6381MB on this 12GB box, no clamping in play here), and the NODE_OPTIONS dedup asserts three cases — an inherited--max-old-space-sizeis left untouched, an empty inheritance injects one, and other inherited flags (--trace-warnings) are preserved. Exits non-zero if any assertion breaks.node scripts/check-fnxc-future-dates.mjs— 0 future-dated stamps (both FNXC notes use adate -ustamp).TYPECHECK_PARALLEL_LIMITacross the tree: no test asserts the old value of 4.pnpm install --frozen-lockfile --ignore-scripts --offline,pnpm check:workspace-package-graph,pnpm check:pre-json— all exit 0.Changeset
None — repository build/merge configuration only; no published package behavior changes.
Implements FUSI-021 / FUSI-022.