fleetd #770: lead identity keys on the space, not the tab label #774

Closed
agent wants to merge 0 commits from worker/770-lead-tab-is-a-fixed-contract-464625-1 into main
Member

Merged locally as a fast-forward to main at 7942378, verified by ref (git ls-remote origin refs/heads/main → 79423787d0cd1226b5d256030fbc782c8cf7512d). Closing because the commit is already on main, not because the work was rejected.

Verified by the lead before merging, independently of the worker's report:

  • Fast-forwardable: git merge-base --is-ancestor origin/main <branch> → yes, one commit.
  • Whole production diff read: FleetConfig, LeadTabScanner, LeadLauncher, FleetdAssembly.
  • Test delta counted directly: +5 @Test, −0, which reconciles 2168 → 2173 against the count measured at 364b229. The worker reported "7 new tests"; five are new and five are renames of tests this change inverts (aLeadWithNoTabRefusesToStart → aLeadWithNoTabIsAcceptedAndFoundByTheFixedLabel, twoLeadsSharingTheSameExactTabRefusesToStart → twoLeadersSharingTheSameWorkspaceRefuseToStart, and three more). No test was deleted.
  • Built in a throwaway worktree at the exact commit: MVN_EXIT=0, BUILD SUCCESS, and the totals cross-checked two independent ways — Maven's aggregate line and a sum over all 179 surefire XML files both give 2173 tests, 0 failures, 0 errors, 0 skipped.
  • Tree parity: the merged tree equals the tree built and tested, dd6bf99e06cbfc8779124f6d44b234f775cf99db on both sides.
  • Rule 4: no new test reads main source as text. Rule 5: PackageCyclesTest green in that run.
  • templateCanRenderAs(template, null) returns false, so a lead with no tab: — the recommended config now — cannot crash validation. This was worth checking, because validateLeadTabPrefixes still passes leader.tab() into it and that value is now routinely null.

The four assembly-fixture changes are honest corrections, not masking. FakeHerdr's workspace is labelled ltms while Leader.workspace defaults to fleet, so under space-scoped matching the fixture described an impossible world. Adding workspace: "ltms" makes each fixture self-consistent.

Safe to deploy on this host, re-measured at merge time:

fleetd.yaml  fleet.leaders.opus.workspace: fleet
             fleet.leaders.opus.tab: "lead: opus"
herdr        w2 label 'fleet'
             w2:tY  label 'lead: opus'     ← in acceptedLabels(), so still matches
             w2:t31 label 'dev: sonnet #1' ← matches nothing, as intended

So countLeads finds one live lead and ensureLeads() launches nothing — the second-lead hazard this unit was written around does not fire here.

One nit not worth a change: the reflowed comment in LeadLauncher.countLeads keeps the phrase "can no longer be excluded wholesale". "No longer" is history language under code-quality rule 1, but the phrase is carried over rather than introduced, and the sentence is accurate.

Merged locally as a fast-forward to `main` at `7942378`, verified by ref (`git ls-remote origin refs/heads/main` → `79423787d0cd1226b5d256030fbc782c8cf7512d`). Closing because the commit is already on `main`, not because the work was rejected. Verified by the lead before merging, independently of the worker's report: - Fast-forwardable: `git merge-base --is-ancestor origin/main <branch>` → yes, one commit. - Whole production diff read: `FleetConfig`, `LeadTabScanner`, `LeadLauncher`, `FleetdAssembly`. - Test delta counted directly: **+5 `@Test`, −0**, which reconciles 2168 → 2173 against the count measured at `364b229`. The worker reported "7 new tests"; five are new and five are renames of tests this change inverts (`aLeadWithNoTabRefusesToStart` → `aLeadWithNoTabIsAcceptedAndFoundByTheFixedLabel`, `twoLeadsSharingTheSameExactTabRefusesToStart` → `twoLeadersSharingTheSameWorkspaceRefuseToStart`, and three more). No test was deleted. - Built in a throwaway worktree at the exact commit: `MVN_EXIT=0`, `BUILD SUCCESS`, and the totals cross-checked two independent ways — Maven's aggregate line and a sum over all 179 surefire XML files both give **2173 tests, 0 failures, 0 errors, 0 skipped**. - Tree parity: the merged tree equals the tree built and tested, `dd6bf99e06cbfc8779124f6d44b234f775cf99db` on both sides. - Rule 4: no new test reads main source as text. Rule 5: `PackageCyclesTest` green in that run. - `templateCanRenderAs(template, null)` returns `false`, so a lead with no `tab:` — the recommended config now — cannot crash validation. This was worth checking, because `validateLeadTabPrefixes` still passes `leader.tab()` into it and that value is now routinely null. The four assembly-fixture changes are honest corrections, not masking. `FakeHerdr`'s workspace is labelled `ltms` while `Leader.workspace` defaults to `fleet`, so under space-scoped matching the fixture described an impossible world. Adding `workspace: "ltms"` makes each fixture self-consistent. Safe to deploy on this host, re-measured at merge time: ``` fleetd.yaml fleet.leaders.opus.workspace: fleet fleet.leaders.opus.tab: "lead: opus" herdr w2 label 'fleet' w2:tY label 'lead: opus' ← in acceptedLabels(), so still matches w2:t31 label 'dev: sonnet #1' ← matches nothing, as intended ``` So `countLeads` finds one live lead and `ensureLeads()` launches nothing — the second-lead hazard this unit was written around does not fire here. One nit not worth a change: the reflowed comment in `LeadLauncher.countLeads` keeps the phrase "can no longer be excluded wholesale". "No longer" is history language under code-quality rule 1, but the phrase is carried over rather than introduced, and the sentence is accurate.
agent added 1 commit 2026-10-05 13:49:42 +02:00
fleetd #770: lead identity keys on the space, not the tab label
CI / shell-tests (pull_request) Failing after 9s
CI / contract (pull_request) Successful in 54s
CI / build (pull_request) Failing after 1m57s
CI / shell-tests (push) Failing after 9s
CI / contract (push) Successful in 53s
CI / build (push) Failing after 1m52s
79423787d0
The lead tab label becomes a fixed constant (Leader.LEAD_TAB_LABEL = "lead");
fleet.leaders.<name>.tab is now optional legacy, matched case-insensitively
alongside the constant via Leader.acceptedLabels(). The uniqueness boundary
between leads moves from the exact tab text to the workspace: FleetConfig
refuses two leaders that share a workspace, LeadTabScanner indexes lead
labels per space (collaborators stay space-agnostic), and
LeadLauncher.leadNameOf/countLeads require both the accepted label and the
lead's own space to match, so a legacy-labelled tab in the wrong space never
counts and a daemon restart never double-spawns a second lead next to a live
one. Config validation also refuses a fleet.tabLabel template or a
collaborator tab that can render as the fixed lead label.
ltms closed this pull request 2026-10-05 13:55:17 +02:00
ltms deleted branch worker/770-lead-tab-is-a-fixed-contract-464625-1 2026-10-05 13:55:17 +02:00
Some checks are pending
CI / shell-tests (pull_request) Failing after 9s
CI / contract (pull_request) Successful in 54s
CI / build (pull_request) Failing after 1m57s
CI / shell-tests (push) Failing after 9s
CI / contract (push) Successful in 53s
CI / build (push) Failing after 1m52s

Pull request closed

Sign in to join this conversation.