feat(FN-4044): harden task ID collision guards and allocation safety

Hardens task ID collision guards across distributed instances by adding `isAllocated` checks in `store.ts` and rewriting `distributed-task-id.ts` with deterministic collision-safe allocation logic, backed by a new `store-create-collision.test.ts` suite reproducing the race path. Updates architecture

Fusion-Task-Id: FN-4044
This commit is contained in:
Fusion
2026-05-12 06:26:37 -07:00
committed by gsxdsm
parent e0fcc7e2fa
commit 72e94dddbe
11 changed files with 632 additions and 194 deletions

View File

@@ -369,6 +369,26 @@ Archive entries preserve key metadata needed for restoration, including:
- Moves task to `done`
- Logs “Task restored from archive” when recovering from compact archive entry
### Task-ID collision safety and operator recovery
- Ordinary task creation, duplicate, and refine flows now fail safely if the chosen task ID already exists in active storage or archive storage. Existing task rows/files always win; the new create attempt must retry with a fresh reservation instead of overwriting data.
- A failed create may burn a distributed reservation. Gaps in `FN-*` numbering are expected and are safer than reissuing a possibly-colliding ID.
- `config.nextId` is legacy/read-only. The live allocator state is `distributed_task_id_state.nextSequence`, reconciled on store open against live tasks, archived task snapshots, and reservation history.
If you suspect **historical overwrites from pre-FN-4044 builds**, inspect surviving evidence in this order:
1. `archive.db` / archived task snapshots for the missing ID
2. `.fusion/tasks/<id>/task.json.bak`, `PROMPT.md`, attachments, and any surviving worktree branch named for the task
3. agent run logs / task documents / activity log entries that still mention the original ID
4. git commits whose subject/body references the original task ID but no longer matches the current task metadata
Recovery/backfill guidance:
- If the original task row still exists in archive storage, unarchive or manually recreate the task from that snapshot.
- If only prompt/worktree/git evidence survives, create a replacement task with a new ID and copy over the recovered description, prompt, documents, and attachments manually.
- If both the active row and archive snapshot were overwritten, Fusion cannot reconstruct lost attachments/comments automatically; recreate them from git history, branch/worktree contents, screenshots, or external issue trackers.
- Record the incident in the replacement task so future audits understand why the task ID and commit history diverge.
## GitHub Issue Import and PR Creation
Import issues: