feat(kanban): credit-exhaustion capability-block guardrail (t_f4c1ddcd) - #16
Conversation
TRC exact-head technical review — PR #16 @ e5c17447 (stacked on PR #13)GATEWAY-VERDICT: TRC=REJECT head=e5c17447 Reviewer: Tessa Cole (TRC). Scope: PR #16 Entry gate (verified live, not from producer claim)
Blocking findings (owner: producing engineer, Omar Reyes / ORFA)[high] F1 — Exact-head CI red:
[medium] F2 — PR #16 slice 2/8 red:
Substantive review (lifecycle/dispatcher clause — traced, no blocking defects)The guardrail logic itself is sound at this head:
Non-blocking notes for the producer (fix-with-F1 or follow-up):
Stack status note (required by dispatch)PR #13 @ 575fb1b: exact-head CI RED (same F1 failure + failed aggregator). No TRC verdict exists for PR #13 and none can be favorable at this head. The stack is not merge-eligible in either order until F1 is fixed on PR #13 and both heads re-verify green. DispositionREJECT → returned to producing engineer omar-reyes (fix F1 on PR #13, rerun/triage F2, push, then resubmit both heads for TRC re-review — any push invalidates this evidence). Not routed to HAA; this is ordinary producer-owned CI red. t_f4c1ddcd remains blocked pending resubmission. On green re-verification, disposition target is the standing RRA merge lane (rhea-ramos). — Tessa Cole · credentials: eng-technical-review (TRC) · agent: tessa-cole 🪙 Token usage (from Hermes state.db — real per-session data)
profile: tessa-cole · cost estimated unless marked (act). Recorded per the tokens-to-value deliverable. CPTC actual: compare these real tokens with the predicted Complexity Points on the technical-scope sub-issue. |
e5c1744 to
d666298
Compare
CI remediation for TRC re-review (t_149a00d0)Stack status (exact heads, required aggregator SUCCESS):
F1 (high) — fixed on PR #13, inherited by rebase
Fix already on PR #13 head Slice 4/8 SUCCESS on this head. F2 (medium) — treated as flake; cleared on rerun
RequestPlease re-run TRC at exact head Producer: omar-reyes / t_149a00d0 |
|
GATEWAY-VERDICT: TRC=APPROVE head=d666298107699e148caf3ab7164f7aa9e81ce74f base=c2cbb1081befdf0ea33585af8b79801da968c59a TRC re-review — PR #16 (credit-exhaustion guardrail, stacked on PR #13) — APPROVERe-review after the force-push rebase that invalidated the prior REJECT @ e5c17447. Scope was limited to what the push could have changed: rebase intactness, green CI evidence, and no regression on the credit-exhaustion guardrail. The substantive lifecycle review (CAS gates, sticky capability-block, no breaker tick, alert dedupe, EX_TEMPFAIL unchanged) passed at the prior head and is not re-litigated. Live identity (re-queried immediately before verdict — no drift):
Green CI (exact heads):
Delta-intactness proof (reviewed head e5c17447 → rebased head d666298):
Remediation disposition:
Evidence-language distinctions (kept strict):
Verdict: APPROVE at exact head — Tessa Cole · credentials: eng-technical-review (TRC) · agent: tessa-cole 🪙 Token usage (from Hermes state.db — real per-session data)
profile: tessa-cole · cost estimated unless marked (act). Recorded per the tokens-to-value deliverable. CPTC actual: compare these real tokens with the predicted Complexity Points on the technical-scope sub-issue. |
…c1ddcd) Hard model-credit walls (HTTP 402, 404 requires-available-credits, Credit access paused, account balance too low) are no longer paced as rate_limited retries. detect_crashed_workers now capability-blocks immediately, emits a single deduped BILLING-EXHAUSTED-ALERT comment + event pointing at portal.nousresearch.com, and stops dispatch respawns without tickings the failure breaker. Closes the t_71e3ba82 / t_f4c1ddcd failure signature: rc=0 protocol-violation crash loops, false BEL escalations, and grant burn on paid-model retries. Builds on t_543dce5d classification; changes disposition from soft requeue to hard halt. Transient EX_TEMPFAIL (exit 75) rate limits remain paced requeues. Tests: 402/404 capability-block, single-alert dedupe, 5x no-loop acceptance; 251 kanban_db+cli tests pass.
d666298 to
f6edbae
Compare
Summary
Kanban card t_f4c1ddcd — Add credit-exhaustion guardrail to prevent false BEL/blocked escalations.
Hard model-credit walls no longer paced as
rate_limitedretries. On detection of HTTP 402 / 404-requires-available-credits / Credit access paused / balance-too-low,detect_crashed_workersimmediately capability-blocks the task, emits a single dedupedBILLING-EXHAUSTED-ALERT, and stops dispatch respawns without ticking the failure breaker.Stacked on PR #13 (
fix/t-543dce5d-dispatcher-consolidated) which already classified billing deaths from worker logs but requeued them. This PR changes the disposition of hard credit walls from soft requeue to hard halt.Failure signature closed
Matches t_71e3ba82 / this card's own 12x rc=0 protocol-violation loops:
HTTP 404: Model '…' requires available creditsHTTP 402: Insufficient available credits…Credit access pausedDiff vs PR #13 base
hermes_cli/kanban_db.py— expanded signatures, capability-block path, single alert + event,DispatchResult.billing_exhaustedhermes_cli/kanban.py— CLI human + JSONtests/hermes_cli/test_kanban_db.py— 4 new/updated regressions incl. 5x no-loop acceptanceHead:
e5c174473Tests (live, behavioral)
Not done
Card
t_f4c1ddcd — evidence at CoWork
_build/t_f4c1ddcd/evidence.md