Repository navigation
Conversation
A decomposed child with workspace_kind=worktree and no explicit path got workspace_path=NULL. Dispatch then tried to anchor it on the board's default_workdir and, when the board had none, failed the spawn with 'no default_workdir set' — twice, tripping the failure-limit circuit breaker (live: t_ab2a7ce8, t_2dd0f5b7, 2026-09-02). The root of a decomposed callback graph is usually itself a dispatcher-materialized worktree <repo>/.worktrees/<root-id>, so the repo is recoverable from the root row: when the root path is a linked worktree checkout, stamp each pathless worktree child with the root's git common-dir parent (the main repo) as its explicit anchor. Children still get per-task worktrees (never the root's literal checkout), so sibling isolation is unchanged; a repo that can't be recovered keeps the anchorless row and the board-default dispatch path; scratch roots are untouched. Regression tests cover anchor inheritance + end-to-end child spawn resolution with no board default_workdir, the unrecoverable-root fallback, and scratch-root non-leakage.
A task whose title/body carries the durable PRODUCT_SIGNOFF marker defines its job as reporting back for human sign-off rather than driving to a terminal lifecycle transition. Repeated clean exits without one are a property of that workflow, so _account_protocol_violation now classifies such tasks at accounting time (read from the task row, so the exemption survives retries, reclaims, and dispatcher restarts) and never auto-blocks them — the violation is still recorded and the task retried, but the gave_up breaker never fires across any number of limit-reaching runs. Review round 1 correction for t_4067fdf1: the one-run PRODUCT_SIGNOFF test could not reach the breaker; it is replaced by a regression that drives the task through the full violation limit and proves it stays ready with no gave_up event, while ordinary coder/QA omissions keep their bounded retry/block behavior (covered by the existing limit test).
…wnership loss (c-027) heartbeat_fire_claim() collapsed fire-fence acquisition failure into False. During slow fenced delivery the worker's own heartbeat thread cannot acquire the same process-local RLock, so a successfully delivering run was misclassified as ownership loss and terminalled as 'Interrupted by shutdown before terminal completion.' (TrustMRR exec 4219b48d while RSI recovery exec f502e929 was settling). Tri-state contract: - True = renewed/confirmed owner - False = authoritatively inspected: owner mismatch / absent claim - None = fence unavailable/unconfirmed (contention or store error) - initial validation stays fail-closed: run starts only on exactly True - heartbeat loop: None rides the existing grace window (180s prod vs 30s fence wait); immediate cancel only on explicit False - post-run probes (_fire_claim_ownership_lost, both interrupted blocks, terminal owner-CAS read): None can never adjudicate a confirmed loss; uncertain outcomes get distinct ledger errors - mark_job_run also tri-state: None = fence unavailable (CAS never ran), False stays reserved for confirmed owner mismatch - _side_effect_fence unchanged: still the exactly-once save/delivery barrier Tests (all written red-first, verified failing on unfixed code): slow_owned_delivery (parent handoff), sustained fence-contention grace, pre/post-delivery None probes, grace-exhausted None probe, terminal write None, mark_job_run fence-unavailable None, RSI recovery dispatch fails closed during original's fenced delivery, TrustMRR slow-owned delivery terminal success. Managed-gateway restart E2E (systemd scope) passes on host: one gateway, single side effect, single delivery.
# Conflicts: # cron/jobs.py
This appears to be an integration/handoff artifact that bundles the reviewed heads of #102073, #101629, #102620 and #102627 and states that no upstream merge is requested. Upstream review happens on those four PRs individually; if this PR is meant only as an operational checkpoint, consider keeping it on the fork. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Integration scope
This is a single cumulative operational candidate; it does not replace or duplicate the four feature PRs. It merge-preserves the exact reviewed heads of:
f40e3977a327b8c5c3f3edad7b957d75a0cf6a19) — spend-neutral provider reset backoff6a49d075ddc98c9c002b8007642728e6591e283d) — decomposed worktree repo-anchor inheritancede20c1676fee3fec629c781db4416eb34869af6c) — fail-closed worker finalization plus durable PRODUCT_SIGNOFF handlingd74a8d157a5a4e3fabac716df2d9c14420ec34ae) — tri-state cron fire-claim ownershipThe only integration conflict was
cron/jobs.py::mark_job_run: the resolution retains #102073’sprovider_backoffargument and forwarding while adopting #102627’sOptional[bool]tri-state return contract.Verification
scripts/run_tests.shover every changed Python test file: 17 files, 473 passed, 0 failed. This one matrix covers provider backoff, Chronos/provider/manual-run paths, worktree decomposition and real child spawn resolution, worker lifecycle finalization/PRODUCT_SIGNOFF, fire-fence contention/heartbeat/shutdown races, and the associated agent/provider compatibility paths.git merge-base --is-ancestorpasses for all four exact reviewed heads;git diff --check 7b72fd124..HEADis clean.No deployment is included in this PR, and no upstream merge is requested as part of the operational handoff.