Skip to content

Fix customer boundaries and record continuity (5.1.19) - #160

Merged
suboss87 merged 3 commits into
Mainfrom
fix/customer-boundaries-5.1.19
Sep 22, 2026
Merged

suboss87 merged 3 commits into
Mainfrom
fix/customer-boundaries-5.1.19

Conversation

@suboss87

@suboss87 suboss87 commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Customer record operations now fail safely when a selector or file is invalid, and preserve state across retirement and concurrent setup.

  • Redact ingest metadata before it becomes a filename; reject invalid explicit MCP customer selections.
  • Keep new risks active after earlier risks are retired, preserve concurrent workspace bindings, and release owned locks on write failures.
  • Append missing agent pointers despite incidental FDEOps mentions. Verify the exact npm version with fresh, bounded registry retries.

Regression coverage includes private and malformed metadata, all four MCP tools, adapter idempotency, concurrent setup, risk retirement, write refusal/retry, and debrief rollback after a failed atomic write. Independent review covered the changed boundaries and adjacent locking paths. No live customer or AI-host validation is claimed.

Validation: npm run check passed all 479 tests with no skips. Package dry-run contains no private audit or handoff artifacts.


Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread bin/install.js Outdated
if (fs.existsSync(destPath)) {
const existing = fs.readFileSync(destPath, 'utf8')
if (/FDEOS|fdeops/i.test(existing)) {
if (existing.includes(content.trim())) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Older adapters gain duplicate instructions

An adapter from an older release fails existing.includes(content.trim()) and receives another full instruction block. Agents then load duplicate, potentially conflicting guidance.

Learn more

Previously shipped adapters contain the skill pointer but can differ from the current template after any wording update. Exact full-template matching therefore treats a valid older adapter as absent and appends the complete template beneath it. The next identical install becomes stable because the new template is now present, but the old block remains permanently duplicated.

Example: A workspace has an AGENTS.md adapter from version 5.1.9 containing ~/.claude/skills/fde/SKILL.md. Version 5.1.19 has revised setup wording, so the exact substring check fails and appends a second complete AGENTS.md adapter.

Recommended fix: Recognize an installed adapter by a durable combination such as the FDEOps marker plus the canonical skill-pointer path. Distinguish that from the tested orphan marker and incidental brand mentions. If adapters must be upgraded, replace only the previously managed block using explicit start and end markers instead of appending another block.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

@suboss87
suboss87 merged commit 072baac into Main Sep 22, 2026
1 check passed
@suboss87
suboss87 deleted the fix/customer-boundaries-5.1.19 branch October 2, 2026 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant