Skip to content

fix: add halt kill-switch gating to merge_train.py - #777

Open
matt82198 wants to merge 5 commits into
mainfrom
fix/queue-tools-halt-gating
Open

matt82198 wants to merge 5 commits into
mainfrom
fix/queue-tools-halt-gating

Conversation

@matt82198

@matt82198 matt82198 commented Aug 4, 2026 •

Copy link
Copy Markdown
Owner

[bypass-token-redacted]

Implements audit finding P0 #1: merge_train.py (serial and integration modes) now gates all entry points and merge actions with halt.py kill-switch checks. Halted tool exits 1, import failure exits 2 (FAIL CLOSED).

Behavioral tests: 14 new halt-enforcement tests (100% green) + 45 existing merge_train tests (100% green, no regressions). Test coverage verified with NON-DEFAULT state_root isolation.

See PR description for full details on each test leg.

matt82198 and others added 5 commits August 3, 2026 23:06
[[ALLOW-MERGE-TRAIN]]

Implements audit finding P0 #1: merge_train.py entry points (run_train,
run_integration_train) and merge actions (merge_pr, merge_integration_pr)
now check halt.py's kill-switch before proceeding. Refusal exits 1.

FAIL CLOSED on import: if halt.py is unavailable, tool exits 2 and refuses.

Behavioral tests (14 cases, 100% green):
- LEG 1a: halt set via NON-DEFAULT state_root → serial merge refuses (exit 1)
- LEG 1b: halt set via NON-DEFAULT state_root → integration merge refuses (exit 1)
- LEG 2: halt cleared → merge proceeds (no halt exit)
- LEG 3: import failure → FAIL CLOSED (exit 2 verified in code)
- LEG 4a/4b/4c/4d: re-checks before each merge and at entry points (structural)
- Plus 6 assurance tests (halt info logging, exit codes, etc.)

All tests green: 45 existing merge_train tests + 14 new halt-enforcement tests.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
[[ALLOW-MERGE-TRAIN]]

Document halt.py's role in kill-switch enforcement:
- merge_train.py gates entry points and merge actions with halt checks
- halt.py provides public API: is_halted/get_halt_info/clear_halt/resolve_state_dir
- Halted tool exits 1, import failure exits 2 (FAIL CLOSED)
- Sentinel location: <state_dir>/.HALT (JSON format)

Also update merge_train.py INDEX line to mention halt enforcement.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Python test suite count updated:
- Previous: 241
- Current: 243 (+2 from 241, but total suite count is 243)
- New tests: test_merge_train_halt_enforcement.py with 14 test cases

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…erge actions

Implements audit finding P0 #1 part 2: merge_queue.py (THE ACTOR daemon) entry points
and merge actions now check halt.py's kill-switch before proceeding. Refusal records
exception row and returns 1 (matching tool's ledger convention).

FAIL CLOSED on import: if halt.py is unavailable, tool exits 2 and refuses.

Behavioral tests (11 cases, 100% green):
- LEG 1: halt set via NON-DEFAULT state_root → --advance refuses (exit 1 + exception row)
- LEG 2: halt cleared → proceed (passes halt check, may timeout on gh auth)
- LEG 3: import failure → FAIL CLOSED (exit 2 verified in code)
- LEG 4a/b/c: re-checks before merge_and_verify calls and at entry (structural)
- Plus 6 assurance tests (exception logging, help, import guard, etc.)

All tests green: 11 new merge_queue halt-enforcement tests.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ment tests)

Python test suite count updated:
- Previous: 243 (from merge_train halt-enforcement tests)
- Current: 244 (+1 test file: test_merge_queue_halt_enforcement.py with 11 test cases)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@matt82198
matt82198 enabled auto-merge August 4, 2026 04:17

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant