diff --git a/11-Features.md b/11-Features.md index 7764b5e..d0d05a3 100644 --- a/11-Features.md +++ b/11-Features.md @@ -2851,6 +2851,33 @@ carry no provider prefix at all. So the id is always compared, the provider only have one, and absent, incomplete or unparseable evidence is UNKNOWN — never a mismatch, never a quarantine. +**The bigger gotcha: for a long time this check did not run at all for most spawns, and said +nothing (#267).** `checkModelMatch` has exactly one call site, and it sits *after* the #249 gate that +returns early when the spawn was given no fleetd-provisioned worktree — which the code itself calls +"the ordinary, expected shape of the large majority of spawns". So the detector built after the `xf` +incident was switched off for most of the spawns it existed to protect, silently. + +Since #267 that case is no longer silent. Once per profile, when a model is configured: + +``` +opencode model-mismatch check (fleetd #175) cannot run for profile 'X': it was spawned +without a fleetd-provisioned worktree (fleetd #249), so its cwd may be shared with other +sessions and the actual model it is running cannot be safely told apart from a sibling's — +spawn with worktree:true to enable the check for this profile. +``` + +**The check itself still does not run there, and that is deliberate.** The model can only be read via +`actualModelForSessionId`, keyed on the *resolved* session id. The only other lookup is +`sessionIdForDirectory`, the "newest row for this directory" heuristic #249 exists to distrust: on a +shared cwd it can return a sibling's row, so a sibling running a different, correctly-configured +model would look like this profile's mismatch and quarantine an innocent credential. A false +quarantine takes real capacity away on bad evidence, which is worse than failing to detect. **Spawn +with `worktree:true` if you want the check.** + +Worth naming as a shape, because it is not the same one as the entry above: **a safety check rode on +the same return value as an identity lookup.** #249 tightened the identity question for good reasons +and narrowed the safety check as a side effect. Neither change was wrong alone — the coupling was. + ## Every file a member must read follows the member's own user **What.** Two more places where fleetd used to write a file into its own process's filesystem and