Conversation
A worker parked on a provider quota wall kept a live, painting harness while its turn could not advance, so every one of them read as working from its semantic busy record. The measured fleet incident had all of one provider's workers stalled at the same weekly limit while supervision saw a healthy fleet. Recognize the wall from the pane text the busy reader already inspects. The signal is built from two independent rendered families - a wall-shaped limit phrase and a scheduled retry/reset phrase - within the last few non-empty lines, so no single vendor string is load-bearing and ordinary worker prose does not match. A busy verdict over that wall reports `quota` instead of busy. fm-crew-state.sh surfaces it as its own `state: quota` rather than collapsing it into working or a declared pause, because a quota-killed worker cannot be relaunched in place; the recovery skill now states that preserve-and-replace under a new id is the path. The portable regression pins the logic and its divergence cases over synthetic transcripts. The live guard drives the real installed OpenCode TUI against a local 429 stub so its own retry modal renders with no model tokens spent, and proves the same task reads working before the wall and quota after it.
|
Speaking as Kun's firstmate: First look on HEAD Contract-class: new-default (own verdict; do not trust PR "fix" framing). Main crew-state vocabulary is CI/NM: tip was action_required. Fork workflows approved this pass after diff review (no workflow file edits; pane-text regex only; no secrets): CI 35482640403, Require no-mistakes 35482640479 — queued. MERGEABLE/UNSTABLE. Missing attestation will keep NM red. VISION.md (each rule)
Decision: waiting-author — add matching attestation for this HEAD. Not an auto-merge candidate (new-default). When otherwise green+MATCH, Firstmate flag for captain decision — not waiting on author for the class call. No Firstmate flag yet (not otherwise-ready). Security: clean. No Closes/Fixes claims verified. |
What
A worker parked on a provider quota wall must not report itself as working.
The measured incident had every worker on one provider stalled at the same weekly limit while
bin/fm-crew-state.shreported each onestate: working - source: pane - harness busy.bin/fm-busy-lib.shgains a rendered quota-wall check as the one cross-harness override that DOWNGRADES a busy semantic verdict toquota; a missing or misread signal leaves the semantic verdict intact.quota,retry) does not match.bin/fm-crew-state.shsurfaces it as its ownstate: quota(sourcepane) with a preserve-and-replace detail, rather than collapsing it intoworking,paused, orstale..agents/skills/stuck-crewmate-recovery/SKILL.mdstates that a quota-parked worker is neither a wedge nor a declared external wait and cannot be relaunched in place.Why its own state
The recovery differs.
A 429/quota modal leaves the composer unreadable and the control plane correctly refuses to type into it, so an in-place relaunch cannot fix it and a fresh worker on the same provider would hit the same wall; the work is preserved and brought back under a new task id chosen for a provider with headroom.
Tests
Portable regression in
tests/fm-crew-state.test.sh, over synthetic pane transcripts with no real harness:quota;adding a usage-limit retry path, still readsworking;crew_is_provably_workingsurfaces a quota-parked worker rather than absorbing it.Live guard
tests/fm-quota-wall-live-e2e.test.shin thelive-harness-optinfamily (token-free, default-on):it drives the real installed OpenCode TUI against a local 429 stub provider so OpenCode paints its own retry modal, then proves the same task reads
workingbefore the wall andquotaafter it.Dated result recorded in
docs/verification/runtime-backends.md.Verification
tests/fm-crew-state.test.sh- all pass.tests/fm-quota-wall-live-e2e.test.sh- OpenCode 1.18.31 real 429 quota retry modal classifies as quota, not working.tests/fm-busy-state.test.sh,tests/fm-busy-adapter-wiring.test.sh,tests/fm-watch-triage.test.sh,tests/fm-inactive-reconcile.test.sh,tests/fm-fleet-snapshot-view.test.sh,tests/fm-control.test.sh- all pass.bin/fm-lint.shclean;bin/fm-doc-audience-check.shclean.