Files
BFM-decomp/tools
Drew T 25b72baa8a fix(recover): single-instance lock — the driver is not parallel-safe and now refuses instead of corrupting
Three properties compose into tree corruption under concurrency:
  (a) assert_write_set measures a GLOBAL git status, so a concurrent run's writes read as THIS
      run's blast-radius violation and abort it;
  (b) an abort does NOT restore the stage edits already on disk;
  (c) gate_stage's commit is a deliberately broad 'git add -u src/' — and it must be, since
      propagation touches many overlays and a narrower filename glob once DROPPED four R22-verified
      banks — so a concurrent --commit sweeps the aborted run's half-applied edits into its commit.

Measured today: xargs -P 4 over 33 binaries put 696 broken lines of ov_MAIN_012 into md_MAIN_026's
+1 bank commit; check-all went 212/213 and the wave bank was blocked behind it (R59).

Narrowing the gate's git add was the WRONG fix (it would restore defect (c)'s predecessor). Instead
the driver enforces its own contract: flock on .run/recover/.driver.lock, refuse loudly (R43).
Control: with the lock held -> rc 1 REFUSED; lock free -> rc 0 and the probe runs normally.
2026-08-29 15:51:25 -06:00
..