Metadata
| Status | done |
|---|---|
| Agent identity | fbb2d89fe44d6b761bcb4b67748ab3d417f29df70a65f8d9403308f5bb2bab78 |
| Created | 2026-08-03T06:11:13.329395691+00:00 |
| Started | 2026-08-03T06:11:22.593410725+00:00 |
| Completed | 2026-08-03T09:42:51.498997602+00:00 |
| Tags | lifecycle, containment, graphsave |
Description
Fix the repeated self-hosting contradiction where task-owned completion succeeds and finalization is durable/Cleaned, but the wrapper later exits nonzero or reports provider timeout/unavailable and service triage overwrites the graph task to Failed. This occurred for formalize-lifecycle-finish-lean4, fix-brokered-deliverable-preflight-worktree generations 0/1/2, and likely other tasks.
Implement a narrow terminal-precedence containment rule consistent with first-terminal-result-wins:
- Once the exact attempt has a durable accepted promotion/output + cleanup receipt (or task-owned
wg donehas durably committed successful completion), later wrapper/process/provider exit diagnostics are observational evidence only and cannot emit AttemptFailed or change Done/accepted completion to Failed. - If a Cleaned accepted finalization exists but the graph projection is missing/contradictory, deterministic convergence projects success; it must not trust a later process exit over the durable transaction.
- Before durable successful completion, genuine process failure remains failure.
- Fence by graph/task/generation/attempt/fence; an old transaction cannot bless a newer attempt, and a stale process cannot mutate either.
- Preserve the late failure diagnostic in logs/evidence without granting lifecycle authority.
Use exact incidents as fixtures: formal task finalization Cleaned + main 347a1696 followed by provider timeout; broker-preflight finalization Cleaned + main c433cb68, later retained smoke commits through ccf51d90, and worker summaries saying wg done succeeded followed by provider-unavailable/Failed. Do not implement the full atomic GraphSave design and do not silently mark unrelated legacy Done records successful.
Validation
- Focused reducer/service tests: success then nonzero exit remains successful; Cleaned then provider timeout converges success; nonzero exit before success remains Failed; stale generation/attempt/fence cannot borrow an older Cleaned transaction; late diagnostic remains inspectable.
- Candidate-binary smoke runs a worker that completes task-owned Land, then forces wrapper nonzero exit; task is Done/Landed/Cleaned exactly once, dependency becomes ready exactly once, no duplicate promotion, and process failure is diagnostic only.
- Existing
exited_worker_finish_convergence.shandbrokered_deliverable_worktree_preflight.shpass. cargo fmt --check, focused tests,cargo check, andcargo clippypass.
Depends on
Required by
- (none)
Log
- 2026-08-03T06:11:13.272417498+00:00 Task paused
- 2026-08-03T06:11:14.234658489+00:00 Task published
- 2026-08-03T06:11:21.985187966+00:00 Lightweight assignment: agent=Pi Lifecycle Hotfix Programmer (fbb2d89f), exec_mode=full, context_scope=full, reason=Lifecycle Hotfix Programmer is the closest fit for correctness-critical terminal precedence, stale-attempt fencing, and failure-containment changes spanning reducers, services, and smoke tests.
- 2026-08-03T06:11:22.836529714+00:00 Spawned by coordinator --executor pi --model openai-codex:gpt-5.6-sol --isolation required-worktree
- 2026-08-03T06:11:47.822047633+00:00 Starting implementation; initial inbox read attempted but service returned no response. Inspecting prior WIP and lifecycle finalization paths.
- 2026-08-03T06:16:20.676772304+00:00 Research: task-owned wg done durably promotes/publishes output while graph stays InProgress until wrapper cleanup. Wrapper/provider and dead-agent triage can emit AttemptFailed/Lost first; cleanup then records Cleaned but cannot project success. Implementing exact-transaction predicate, late diagnostic containment, and privileged deterministic Cleaned projection.
- 2026-08-03T06:38:29.221115061+00:00 Implemented exact durable-success predicate, fail/triage/sweep containment, Cleaned contradiction projection, incident-focused tests, and candidate generated-wrapper smoke. Focused fail tests pass; preparing installed candidate binary smoke.
- 2026-08-03T06:56:01.071012558+00:00 Validated candidate smoke PASS (task-owned Land + explicit provider diagnostic + wrapper exit 73 => one Done/Landed/Cleaned, no AttemptFailed/Lost, one promotion/readiness); exited_worker_finish_convergence, brokered_deliverable_worktree_preflight, and task_owned_finish_transaction PASS. cargo fmt/check/clippy/build pass. Full cargo test has unrelated baseline profile/model/TUI failures; affected profile tests pass alone and 21 focused lifecycle/fail tests pass.
- 2026-08-03T07:05:33.821101039+00:00 Implemented and pushed 8addd066. Exact durable success is fenced by task/generation/attempt/fence/worktree lease plus immutable candidate/validation/accepted promotion-or-output/cleanup receipts. Late failures remain diagnostic; contradictory Cleaned rows reconcile deterministically to Done. Added incident fixtures (347a1696/c433cb68/ccf51d90), tuple-fence/legacy/genuine-failure unit coverage, and owned late-exit smoke.
- 2026-08-03T07:06:25.247773368+00:00 Bounded evaluator infrastructure state error[WG-EVAL-INSUFFICIENT-EVIDENCE]: bounded evidence insufficient [candidate-manifest:candidate-manifest:truncated,candidate-source:candidate-source:truncated,declared-artifact:declared-artifact-000:truncated,declared-artifact:declared-artifact-001:truncated,declared-artifact:declared-artifact-002:truncated,declared-artifact:declared-artifact-003:truncated,declared-artifact:declared-artifact-004:truncated,declared-artifact:declared-artifact-005:truncated,declared-artifact:declared-artifact-006:truncated,declared-artifact:declared-artifact-007:truncated] without semantic rejection or cross-executor fallback; source remains in-progress
- 2026-08-03T07:06:54.308558914+00:00 Consumed deep-readonly FLIP report deep-report-0f4c22412f6ef8137c6a2c0bc784add693b59c030930521bcfc2ae0df66abc62; observations=12 findings=3 route=b3:07cbfd6e71528de4a03ba3051159b1a811230a2a0a97c83e9fcb743edd0c2466 usage=57387in/1163out
- 2026-08-03T07:06:58.463425863+00:00 Bounded evaluator infrastructure state error[WG-EVAL-EVIDENCE-UNAVAILABLE]: automatic immutable evidence assembly failed without semantic rejection or cross-executor fallback; source remains in-progress
- 2026-08-03T07:07:31.010195234+00:00 Bounded evaluator infrastructure state error[WG-EVAL-EVIDENCE-UNAVAILABLE]: automatic immutable evidence assembly failed without semantic rejection or cross-executor fallback; source remains done