You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit b85699c
Browse filesBrowse the repository at this point in the historyBrowse files
fix(coding): the single-flight claim covered 1 of 3 paths that start a Pilot (#208)
#208 said "one driver per engine". It put the claim on
`POST /sessions/:id/run` and nowhere else. There are THREE paths that start a
Pilot against a live session, and the other two were wide open:
routes/coding.ts:1332 /sessions/:id/run ✅ claimed
routes/coding.ts:1008 the `drive_claude` tool ❌
lib/loop-drivers.ts owner Loop + delegate_goal ❌
So a Lead delegating a goal, or the owner pressing Loop, could put a SECOND
Pilot on a session a first was already driving — the two interleaving
`tmux send-keys` into one pane, each reasoning over a terminal the other is
writing to. That is exactly the failure the claim exists to prevent, and it was
reachable by the two most ordinary actions in the product. The route-only fix was
a sixth of a guarantee.
(The other three `CODING_SESSION.create` sites are `mode: "watch"` finish-watchers
— passive, they send no instructions, so they correctly take no claim.)
Both paths now claim BEFORE anything observable is written. Order matters: a claim
checked after the run row exists strands an `agent_loop_runs` row no workflow will
close (the #207C failure), and a refusal after the board write announces work that
never started. Each threads its `driverId` into the workflow so the existing
release path (`endSession`, #206) frees it.
Also removed `delegateToPilot` — 94 lines made unreachable by #210's driver table
and still carrying its own unclaimed `CODING_SESSION.create`. Dead code that
starts workflows is worse than dead code.
And raised the remaining browser-runner timeouts from 60s to 120s. `beforeEach`
launches a fresh real Chrome per test — eight per file — so a launch alone can eat
most of a 60s budget under load; two different tests there timed out in one
full-suite run and the file passed 8/8 in 27s in isolation right after. The
heaviest test was already bumped for precisely this; the rest were left to flake.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
0 commit comments