Summary
A review of tracked workspace changes on a WSL Windows-mounted DrvFS repository returned ready / review.start from gentle_review inspect, but following that transition failed before native START with candidate-view-invalid. No lineage, mutation, or consent envelope was created.
Read-only source and filesystem diagnosis strongly points to candidate-view permission attestation on DrvFS without POSIX metadata. This is a high-confidence diagnosis, not a newly reproduced isolated test: the failed temporary view was already cleaned up, so its exact first failing assertion could not be inspected.
Environment
- Pi:
0.85.0
- gentle-pi package:
2.4.0, commit 525812fb8f2ba5f5e26c867d4a18321b6eda46ba
- gentle-ai CLI:
2.4.0-rc.8
- Repository under
/mnt/<drive>/<repo> on WSL
findmnt -T <repo> reports 9p, aname=drvfs, without metadata
stat reports 0777 for repository files and the candidate-views parent directory
git config core.filemode: false
- Negotiated STATUS:
gentle-ai.review-integration.status/v7, contract gentle-ai.review-integration/v2, workspace projection
Observed flow
- Open a repository with a normal tracked workspace diff on the mount described above.
- Call
gentle_review with {"operation":"inspect"}. Result offers review.start with the correct target and changed paths.
- Follow the offered route using
gentle_review START with ordinary mode and a fresh idempotency key.
- The facade returns:
{
"operation": "start",
"status": "blocked",
"outcome": "native-operation-failed",
"lineage_created": false,
"mutation_performed": false,
"mutation_outcome": "none",
"reset_eligible": false,
"diagnostics": {
"code": "candidate-view-invalid",
"message": "candidate view rejected before native START"
},
"next_action": "resolve-native-operation-failure"
}
This occurred twice for the same unchanged candidate. No reset, recovery, or security-check bypass was attempted. This report does not claim a clean-main synthetic reproduction or a tested fix.
Technical evidence and likely cause
At the pinned gentle-pi commit:
extensions/gentle-ai.ts:5094-5112: inspect obtains/maps target STATUS; it does not materialize/verify the candidate view.
extensions/gentle-ai.ts:5499-5537: START materializes the candidate view and verifies it before setting nativeStartAttempted and invoking native START.
lib/review-candidate-view.ts:583-610,799-855: the view is placed under the Git common directory and protected using chmod with 0444/0555.
lib/review-candidate-view.ts:884-906: directory, .git, and file checks reject writable mode bits; file executable modes are also verified.
lib/review-candidate-view.ts:231-238: candidate-view validation errors default to candidate-view-invalid.
extensions/gentle-ai.ts:3941-3944: the detailed pre-native error is replaced by the generic message above.
The likely failure is that this mount cannot represent the requested POSIX permission modes. The first directory-mode check is a likely rejection point, but the exact failing entry was not retained. The installed decoder accepts status/v7; version skew alone is not evidence of a schema failure here.
Expected behavior
Either support this filesystem while preserving candidate immutability, or reject the unsupported permission capability early with an actionable, sanitized diagnostic. Recommend a repository whose Git common directory resides on a native Linux filesystem; a linked worktree under Linux with its common directory still on DrvFS would not address this placement constraint.
Do not relax the immutability guard or recommend recovery when no lineage exists. Enabling DrvFS metadata or upgrading has not been tested as a fix in this report.
Suggested acceptance criteria
- Detect or characterize ineffective POSIX permission changes before presenting an opaque START failure.
- Preserve fail-closed immutable candidate validation.
- Provide a specific, sanitized filesystem/permission-capability diagnostic and a safe next step.
- Retain behavior on native Linux filesystems and add regression coverage for ineffective chmod semantics.
- Document the Git common-directory filesystem requirement.
Related issues and secondary observation
Searched open and closed issues for candidate-view-invalid, DrvFS, and WSL candidate permissions. No exact DrvFS report was found. #222 and #252 address related candidate-view safety/diagnostics; #284 concerns cwd equivalence rather than permission semantics.
After the user explicitly chose to leave the candidate unreviewed in chat, the once-per-candidate reminder still requested START. The agent_end handler (extensions/gentle-ai.ts:6039-6102) checks STATUS and a nudged-target set, not that chat decision. Because START never returned a consent envelope, no provider-owned decline could be recorded. This is a secondary UX observation, not proof of a second cause or a request to parse chat as review authority.
Summary
A review of tracked workspace changes on a WSL Windows-mounted DrvFS repository returned
ready/review.startfromgentle_review inspect, but following that transition failed before native START withcandidate-view-invalid. No lineage, mutation, or consent envelope was created.Read-only source and filesystem diagnosis strongly points to candidate-view permission attestation on DrvFS without POSIX metadata. This is a high-confidence diagnosis, not a newly reproduced isolated test: the failed temporary view was already cleaned up, so its exact first failing assertion could not be inspected.
Environment
0.85.02.4.0, commit525812fb8f2ba5f5e26c867d4a18321b6eda46ba2.4.0-rc.8/mnt/<drive>/<repo>on WSLfindmnt -T <repo>reports9p,aname=drvfs, withoutmetadatastatreports0777for repository files and the candidate-views parent directorygit config core.filemode:falsegentle-ai.review-integration.status/v7, contractgentle-ai.review-integration/v2, workspace projectionObserved flow
gentle_reviewwith{"operation":"inspect"}. Result offersreview.startwith the correct target and changed paths.gentle_reviewSTART with ordinary mode and a fresh idempotency key.{ "operation": "start", "status": "blocked", "outcome": "native-operation-failed", "lineage_created": false, "mutation_performed": false, "mutation_outcome": "none", "reset_eligible": false, "diagnostics": { "code": "candidate-view-invalid", "message": "candidate view rejected before native START" }, "next_action": "resolve-native-operation-failure" }This occurred twice for the same unchanged candidate. No reset, recovery, or security-check bypass was attempted. This report does not claim a clean-main synthetic reproduction or a tested fix.
Technical evidence and likely cause
At the pinned gentle-pi commit:
extensions/gentle-ai.ts:5094-5112: inspect obtains/maps target STATUS; it does not materialize/verify the candidate view.extensions/gentle-ai.ts:5499-5537: START materializes the candidate view and verifies it before settingnativeStartAttemptedand invoking native START.lib/review-candidate-view.ts:583-610,799-855: the view is placed under the Git common directory and protected usingchmodwith0444/0555.lib/review-candidate-view.ts:884-906: directory,.git, and file checks reject writable mode bits; file executable modes are also verified.lib/review-candidate-view.ts:231-238: candidate-view validation errors default tocandidate-view-invalid.extensions/gentle-ai.ts:3941-3944: the detailed pre-native error is replaced by the generic message above.The likely failure is that this mount cannot represent the requested POSIX permission modes. The first directory-mode check is a likely rejection point, but the exact failing entry was not retained. The installed decoder accepts status/v7; version skew alone is not evidence of a schema failure here.
Expected behavior
Either support this filesystem while preserving candidate immutability, or reject the unsupported permission capability early with an actionable, sanitized diagnostic. Recommend a repository whose Git common directory resides on a native Linux filesystem; a linked worktree under Linux with its common directory still on DrvFS would not address this placement constraint.
Do not relax the immutability guard or recommend recovery when no lineage exists. Enabling DrvFS metadata or upgrading has not been tested as a fix in this report.
Suggested acceptance criteria
Related issues and secondary observation
Searched open and closed issues for
candidate-view-invalid, DrvFS, and WSL candidate permissions. No exact DrvFS report was found. #222 and #252 address related candidate-view safety/diagnostics; #284 concerns cwd equivalence rather than permission semantics.After the user explicitly chose to leave the candidate unreviewed in chat, the once-per-candidate reminder still requested START. The
agent_endhandler (extensions/gentle-ai.ts:6039-6102) checks STATUS and a nudged-target set, not that chat decision. Because START never returned a consent envelope, no provider-owned decline could be recorded. This is a secondary UX observation, not proof of a second cause or a request to parse chat as review authority.