Skip to content

fix(beads): publish attach outputs before bd creates graph (FUZZ-050) - #722

Merged
randlee merged 1 commit into
fix/t-7-fuzz-017-r3-large-exponentfrom
fix/t-7-fuzz-050-attach-write-order
Oct 8, 2026
Merged

randlee merged 1 commit into
fix/t-7-fuzz-017-r3-large-exponentfrom
fix/t-7-fuzz-050-attach-write-order

Conversation

@randlee

@randlee randlee commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Fixes comp-t-7.22 (campaign run 3 FUZZ-050, high): attach and preview-attach write and check every local output (including the <rendered_formula>.graph.json plan file) before bd create --graph runs, so a local write failure refuses with BEADS_OUTPUT_PATH_INVALID naming the path and bd has written nothing. Regression tests cover a directory at the plan-file path for both operations.

Rebased 3648e11 -> d2c5704 onto #721. Gates at d2c5704: clippy -D warnings clean, fmt clean, cargo test --workspace 1072 passed / 0 failed / 0 ignored.

🤖 Generated with Claude Code

@randlee

randlee commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

QA fix verification: comp-t-7.22-qa (FUZZ-050) at d2c5704

Verdict: PASS. 1 carried finding verified fixed.

Finding Disposition
FUZZ-050 fixed

The fuzz coordinator, locked to FUZZ-050, verified at the pinned commit through the real CLI against a fake-bd stub that logs every call:

  • With a directory at <rendered_formula>.graph.json, attach and preview-attach now exit 2 with outcome refused, code BEADS_OUTPUT_PATH_INVALID, and a message naming the exact .graph.json path. The stub log shows only cook and show: no create --graph and no other bd call. Baseline: BEADS_RENDER_FAILED, and create --graph was called.
  • Other variants: read-only output directory refuses with zero bd calls (baseline: BEADS_RENDER_FAILED); a dangling-symlink plan path is unchanged (BEADS_OUTPUT_PATH_SYMLINK); a plan path whose parent is a regular file now returns BEADS_OUTPUT_PATH_INVALID exit 3 with zero bd calls (baseline gave BEADS_TEMPLATE_PATH_INVALID, the wrong code); an existing regular file at the plan path is overwritten as before. Disk-full not tested; a missing-directory rendered_formula is FUZZ-042 territory and was not examined.
  • Happy path unchanged: normalized stub logs (cook, show, create --graph, with --dry-run for preview), the plan file content passed to create --graph, and the receipt are identical to baseline. The intended change is that the public plan file and rendered formula are published before create --graph (bd reads its private snapshot input).
  • Per-request snapshots hold (fuzz_014 tests, including concurrent attaches, pass). No stray temp files remain after a refusal; after a failed create (stub exit 1) the plan file stays in place, as on baseline.
  • Both fuzz_050 tests are un-ignored, pass, and fail on the base origin/fix/t-7-fuzz-017-r3-large-exponent; cargo test -p sc-composer-beads passes in full. Local fmt, clippy -D warnings and cargo test -p sc-composer-beads -p sc-compose are clean at this head.

Notes, not findings:

  • Docs gap: BEADS_OUTPUT_PATH_INVALID is documented only in ADR-0021 and the bead manual as "parent directory missing or cannot be resolved". It is not in ADR-0023, and it is now also used for non-regular-file destinations and a failed local write, so the wording is narrower than the behaviour. The finding's deliverable 2 asks for the correct code; the doc wording may want widening.
  • Outcome is refused when .graph.json is a directory but failed for a read-only output directory (both before any bd mutation).
  • The rendered formula is written locally even on a refusal (harmless; bd untouched). After a failed create, a plan file for beads that were not created stays in place (as on baseline).

Disclosures: fake-bd stub, not real bd. CI not checked (rate-limit rule). An earlier verifier attempt died on an API rate limit and was re-run from scratch; this report rests only on the re-run.

@randlee
randlee force-pushed the fix/t-7-fuzz-050-attach-write-order branch from d2c5704 to 8a804d6 Compare October 8, 2026 00:25
@randlee
randlee removed this pull request from stack #625 October 8, 2026 00:45
@randlee
randlee added this pull request to stack #739 October 8, 2026 01:15
@randlee
randlee force-pushed the fix/t-7-fuzz-050-attach-write-order branch from 8a804d6 to f260164 Compare October 8, 2026 01:16
@randlee
randlee merged commit df9b0e1 into integrate/phase-t Oct 8, 2026
11 of 13 checks passed
@randlee
randlee deleted the fix/t-7-fuzz-050-attach-write-order branch October 8, 2026 14:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant