Observed behavior: Reconciliation journal publication does not retain its parent directory identity. writeJournal passes no parent handle to atomicWritePrivateFile; normal and blocked-error paths therefore create/tighten and publish by pathname. A replaced reconciliations/ directory can receive journal or failure metadata.
Expected behavior: Authenticate and retain the reconciliation journal parent through publication, including blocked-error handling. Refuse to publish into a rebound directory and preserve the primary failure when failure-record publication is also refused.
Root cause: At candidate baseline f1d44d2fcc439ea1802571e048a724a22465857c, src/worktree-reconciliation.ts:308-310 calls the atomic writer without its optional retained-parent argument. The blocked paths at lines 2265-2270 and 2311-2312 use the same pathname-only publication. The no-parent writer calls ensurePrivateDirectory, which uses recursive mkdir and chmod rather than retained-entry authentication.
How to reproduce safely: Static source inspection establishes the missing retained-parent argument. For a future regression test, use a private synthetic HOME and a deterministic lifecycle seam to rename the fixture reconciliation directory and place a private replacement at its pathname; assert neither journal transitions nor blocked failure metadata are published into the replacement. No live HOME, credentials, daemon, or operational exploitation is needed or was used for this report.
Environment:
- Agent: GLM-5.3 Max planning review; Astra Bug owner adjudication
- Connector: repository static inspection
- OS: Fedora Linux
Independent P2 follow-up discovered during #974 planning under Epic #968. It is outside frozen S3 and is not part of #974's target-parent lifecycle scope. Review context: GLM plan P1-2, owner severity/scope adjudication P2. Originating PR: #1071. This issue is not resolved by that PR.
Observed behavior: Reconciliation journal publication does not retain its parent directory identity.
writeJournalpasses no parent handle toatomicWritePrivateFile; normal and blocked-error paths therefore create/tighten and publish by pathname. A replacedreconciliations/directory can receive journal or failure metadata.Expected behavior: Authenticate and retain the reconciliation journal parent through publication, including blocked-error handling. Refuse to publish into a rebound directory and preserve the primary failure when failure-record publication is also refused.
Root cause: At candidate baseline
f1d44d2fcc439ea1802571e048a724a22465857c,src/worktree-reconciliation.ts:308-310calls the atomic writer without its optional retained-parent argument. The blocked paths at lines 2265-2270 and 2311-2312 use the same pathname-only publication. The no-parent writer callsensurePrivateDirectory, which uses recursive mkdir and chmod rather than retained-entry authentication.How to reproduce safely: Static source inspection establishes the missing retained-parent argument. For a future regression test, use a private synthetic HOME and a deterministic lifecycle seam to rename the fixture reconciliation directory and place a private replacement at its pathname; assert neither journal transitions nor blocked failure metadata are published into the replacement. No live HOME, credentials, daemon, or operational exploitation is needed or was used for this report.
Environment:
Independent P2 follow-up discovered during #974 planning under Epic #968. It is outside frozen S3 and is not part of #974's target-parent lifecycle scope. Review context: GLM plan P1-2, owner severity/scope adjudication P2. Originating PR: #1071. This issue is not resolved by that PR.