Fix customer boundaries and record continuity (5.1.19) - #160
Conversation
| if (fs.existsSync(destPath)) { | ||
| const existing = fs.readFileSync(destPath, 'utf8') | ||
| if (/FDEOS|fdeops/i.test(existing)) { | ||
| if (existing.includes(content.trim())) { |
There was a problem hiding this comment.
🟡 Older adapters gain duplicate instructions
An adapter from an older release fails existing.includes(content.trim()) and receives another full instruction block. Agents then load duplicate, potentially conflicting guidance.
Learn more
Previously shipped adapters contain the skill pointer but can differ from the current template after any wording update. Exact full-template matching therefore treats a valid older adapter as absent and appends the complete template beneath it. The next identical install becomes stable because the new template is now present, but the old block remains permanently duplicated.
Example: A workspace has an AGENTS.md adapter from version 5.1.9 containing ~/.claude/skills/fde/SKILL.md. Version 5.1.19 has revised setup wording, so the exact substring check fails and appends a second complete AGENTS.md adapter.
Recommended fix: Recognize an installed adapter by a durable combination such as the FDEOps marker plus the canonical skill-pointer path. Distinguish that from the tested orphan marker and incidental brand mentions. If adapters must be upgraded, replace only the previously managed block using explicit start and end markers instead of appending another block.
Was this helpful? React with 👍 or 👎 to provide feedback.
Customer record operations now fail safely when a selector or file is invalid, and preserve state across retirement and concurrent setup.
Regression coverage includes private and malformed metadata, all four MCP tools, adapter idempotency, concurrent setup, risk retirement, write refusal/retry, and debrief rollback after a failed atomic write. Independent review covered the changed boundaries and adjacent locking paths. No live customer or AI-host validation is claimed.
Validation:
npm run checkpassed all 479 tests with no skips. Package dry-run contains no private audit or handoff artifacts.