Skip to content

fix: validate only changed attempt index blobs after migration - #3797

Merged
stranske merged 3 commits into
mainfrom
codex/followup-3793-delta-presence
Oct 7, 2026
Merged

stranske merged 3 commits into
mainfrom
codex/followup-3793-delta-presence

Conversation

@stranske

@stranske stranske commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Problem and change

Closes #3793.

Merged #3792 avoided repeated scans only while the attempt subtree stayed unchanged. One legacy-writer addition still caused1,002 historical index-blob reads after the initial1,001 migration. Store a version2 per-entry filename/blob-SHA/PR manifest and a conditional checkpoint so changed trees fetch only new or replaced blobs. Complete pinned tree correspondence, independent ledger reconciliation, positive/negative freshness fences and fail-closed write handling remain enforced. Version1 inventories remain untouched; v2 requires one migration. Metadata enumeration and manifest bytes remain O(N).

Tasks

  • Reuse validated unchanged entries across older-writer additions and recompute membership after replacement/removal.
  • Publish complete manifests create-only and advance checkpoints with conditional file SHA; reconcile only identical complete mappings.
  • Preserve current-tree fences and fail closed on corrupt/missing expected checkpoints, incomplete trees, conflicts and lost responses.
  • Mirror source/template and update the sync contract and operator documentation.

Acceptance Criteria

  • Separate Node processes invoking production reporter defaults:1,001 bootstrap blob reads, then exactly1per successive addition and2for a two-entry batch; no historical blob rereads.
  • Source/template replacement/removal, same-positive-set conflicting-map, positive/negative concurrency, stale CAS loser, missing expected checkpoint and partial/lost write regressions pass.
  • Actual source mutant disabling immutable-entry reuse causes both separate-process regressions to fail at1002!=1; byte-identical restoration gives121focused testsPASS.
  • Template sync, strict completeness, syntax and diff whitespace checks pass.

Complete commands, restored source hashes and full RED/GREEN console evidence: docs/evidence/issue-3793-delta/README.md.

The121focused tests are not the whole repository suite. No live authority writes, fleet rollout or original provider-verdict relabeling occurred. Current-head hosted checks, full expected topology, zero active non-outdated threads and seven-minute floor remain mandatory before guarded squash. Source3793 stays open through actual verify:compare and report disposition. Prior #3792 CONCERNS remain recorded.

Independent Sol6.1Medium assessment e0d91f72711685d9e3e312c7ee24218d6911d23be70f86b97d23a94455b9fdad found a bootstrap publication-loss-plus-churn restart gap in975fb508. Adopted in02ebc6ec9: a fixed complete create-only bootstrap manifest supplies a known validated recovery base before keyed publication. The new manifest-loss/churn regression fails on the actual975fb508production source and passes after restoration; four interrupted bootstrap phases recover with only one new blob read. Earlier advisory is not represented as approval of this new head.

Source: Issue #3793

Closes #3793

Automated Status Summary

Scope

Scope section missing from source issue.

Context for Agent

Related Issues/PRs

Tasks

  • Implement durable tree-bound presence/backfill in .github/scripts/keepalive_authority_state.js and its templates/consumer-repo/.github/scripts/keepalive_authority_state.js counterpart; preserve immutable attempt and receipt validation.
  • Add separate-helper warm-path, stale/older-writer and negative-to-positive regressions in .github/scripts/__tests__/keepalive-authority-state.test.js; exercise keepalive_post_work_reporter.js with its default helper.
  • Run focused authority/reporter tests, template sync/completeness/parity/drift checks, and update the operator contract for migration and uncertain writes.
  • Repair changed-tree incremental presence in .github/scripts/keepalive_authority_state.js through the existing codex/keepalive-replay-missing-ledger: retain authority attempt guard #3792 source chain; retain final-head Major-thread disposition and run issue-bound verification on the necessary bounded follow-up.

Acceptance criteria

  • Deliberately reproduce existing P×N call growth, then demonstrate bounded warm-path blob reads across separate helper/reporter instances for positive and negative PRs with a large legacy population.
  • Prove negative-to-positive transitions and concurrent/partial-write safety; uncertain migration/cache state fails closed. Legacy backfill and repeat reads must not rescan full history every hourly sweep.
  • Exercise the actual consumer reporter's default helper; retain source/consumer regressions, template sync/completeness/parity/drift checks, and focused authority/reporter tests.
  • The original Major thread is resolved from final-head implementation evidence; preserve that disposition. This issue remains OPEN for the actual changed-tree performance gap. Before any follow-up merge: unchanged exact head, seven-minute floor, zero active non-outdated unresolved threads, complete suites/runs, authoritative expected/required topology. After merge: actual verify:compare against this issue and explicit non-PASS disposition.

Summary by CodeRabbit

  • Bug Fixes
    • Improved the accuracy of pull request attempt-presence checks when attempt records are added, changed, or removed.
    • Checks now recover from interrupted updates and reject inconsistent or incomplete records rather than returning an uncertain result.
    • Reduced repeat reads for unchanged records while ensuring updates are validated before results are used.

@stranske stranske added agent:codex Agent-created issues from Codex agents:keepalive Use to initiate keepalive functionality with agents autofix Opt-in automated formatting & lint remediation codex codex-automation agent:auto Delegates agent routing to the auto-delegation policy labels Oct 7, 2026
@stranske
stranske deployed to agent-standard October 7, 2026 01:30 — with GitHub Actions Active
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: stranske/Workflows/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Essentials
  • Run ID: 4537219a-1e76-4c52-ad19-5a3e756d8793
📥 Commits

Reviewing files that changed from the base of the PR and between 89be005 and 8eb9667.

📒 Files selected for processing (14)
  • .github/scripts/__tests__/helpers/keepalive-presence-server.js
  • .github/scripts/__tests__/helpers/presence-process.js
  • .github/scripts/__tests__/keepalive-attempt-presence.test.js
  • .github/scripts/__tests__/keepalive-authority-state.test.js
  • .github/scripts/__tests__/keepalive-presence-delta.test.js
  • .github/scripts/keepalive_authority_state.js
  • .github/sync-manifest.yml
  • docs/evidence/issue-3793-delta/README.md
  • docs/evidence/issue-3793-delta/bootstrap-before-red.txt
  • docs/evidence/issue-3793-delta/mutant-red.txt
  • docs/evidence/issue-3793-delta/mutation.json
  • docs/evidence/issue-3793-delta/restored-green.txt
  • docs/keepalive/GoalsAndPlumbing.md
  • templates/consumer-repo/.github/scripts/keepalive_authority_state.js

Included review availability: This review used your included allowance. 1 included review remains after this review. Your included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.


📝 Walkthrough

Walkthrough

The reporter now tracks attempt-index presence with version 2 manifests keyed to immutable tree snapshots. It reuses unchanged index entries, validates changed entries, and uses bootstrap manifests and conditional checkpoints for publication and recovery. Tests cover both script surfaces and concurrent or interrupted writes.

Changes

Attempt-Presence Inventory

Layer / File(s) Summary
Version 2 manifests and delta scans
.github/scripts/keepalive_authority_state.js, templates/consumer-repo/.github/scripts/keepalive_authority_state.js
Both scripts now store sorted attempt-index path, blob-SHA, and PR entries. They reuse unchanged entries, validate changed indexes, and derive PR membership from the full mapping.
Bootstrap and checkpoint recovery
.github/scripts/keepalive_authority_state.js, templates/consumer-repo/.github/scripts/keepalive_authority_state.js
Both scripts read bootstrap or checkpoint state, verify manifest coverage against the attempt-index tree, and conditionally advance or repair checkpoints. An existing version 2 directory without either recovery record is rejected.
Mock API and concurrency regressions
.github/scripts/__tests__/helpers/*, .github/scripts/__tests__/keepalive-*.test.js
The mock server supports version 2 inventory records and checkpoint compare-and-swap. Tests cover changed and removed indexes, conflicting mappings, stale writers, lost responses, and interrupted recovery on both script surfaces.
Inventory contract and validation records
.github/sync-manifest.yml, docs/keepalive/GoalsAndPlumbing.md, docs/evidence/issue-3793-delta/*
The manifest description and operator documentation describe the version 2 inventory and recovery behavior. Evidence files record test and mutation results, plus limits on acceptance claims.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Bug fix · Severity of issue fixed: Medium

Sequence Diagram(s)

sequenceDiagram
  participant Reporter as Keepalive reporter
  participant GitData as GitHub Git Data API
  participant Contents as GitHub Contents API
  Reporter->>GitData: Read attempt-index tree and blob SHAs
  Reporter->>Contents: Read checkpoint or bootstrap manifest
  Reporter->>GitData: Read added or changed index blobs
  Reporter->>Contents: Publish keyed manifest
  Reporter->>Contents: Conditionally advance checkpoint
  Reporter->>GitData: Confirm current attempt-index tree
Loading

Merge Risk: ⚪ Minimal · up to 8eb96

No actionable defect remains identified. Complete the stated pre-merge checks before merging.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 2.56% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 39 functions across 7 files. (7 skipped: 7… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: reusing validated blobs and validating only changed attempt-index blobs after migration.
Linked Issues check ✅ Passed For active issue #3793, v2 manifests bind each index path and blob SHA to its PR number. Changed-tree scans reuse unchanged validated entries and fetch changed blobs; membership is recomputed for remo…
Out of Scope Changes check ✅ Passed The changed source and consumer template implement the #3793 presence inventory. Test helpers and regressions validate its production-reporter behavior and failure cases. The operator documentation, s…
Full details: Docstring Coverage

Explanation

Docstring coverage is 2.56% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 39 functions across 7 files. (7 skipped: 7 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T01:32:34.034783Z 975fb50 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@stranske
stranske deployed to agent-standard October 7, 2026 01:31 — with GitHub Actions Active
@stranske-keepalive

stranske-keepalive Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Keepalive Loop Status

PR #3797 | Agent: Claude | Iteration 2/12

Current State

Metric Value
Iteration progress [##--------] 2/12
Action fix (agent-run-failed)
Agent status ✅ ALL TASKS COMPLETE
Gate unknown
Tasks 16/16 complete
Timeout 45 min (default)
Timeout usage 1m elapsed (3%, 44m remaining)
Keepalive ✅ enabled
Autofix ❌ disabled

Agent Delegation (auto mode)

Field Value
Selected agent Claude
Reason cooldown (3 rounds remaining)
Delegation source static

🔍 Failure Classification

| Error type | infrastructure |
| Error category | resource |
| Suggested recovery | Confirm the referenced resource exists (repo, PR, branch, workflow, or file). |

⚠️ Failure Tracking

| Consecutive failures | 2/3 |
| Reason | agent-run-failed |

@stranske-keepalive

stranske-keepalive Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor
Keepalive Work Log (click to expand)
# Time (UTC) Agent Action Result Files Tasks Progress Commit Gate
0 2026-10-07 01:32:14 Codex wait (gate-not-success) skipped — 0 8/16 — —
0 2026-10-07 01:39:36 Codex run (agent-run-failed) failure 40 file(s) 0 8/16 193abd3 cancelled
1 2026-10-07 01:47:03 Codex run (ready) success 34 file(s) +8 16/16 8eb9667 success
1 2026-10-07 01:51:08 Claude run (agent-run-failed) failure — 0 16/16 — success
2 2026-10-07 01:55:57 Codex run (fix-verification-gaps) retry success 32 file(s) 0 16/16 — success
2 2026-10-07 02:11:27 Codex wait (gate-not-success) skipped — 0 16/16 — —
2 2026-10-07 02:24:25 Claude run (agent-run-failed) failure — 0 16/16 — success
2 2026-10-07 02:25:51 Claude fix (agent-run-failed) retry failure — 0 16/16 — —

@stranske
stranske deployed to agent-standard October 7, 2026 01:32 — with GitHub Actions Active
@stranske-automation-bot

Copy link
Copy Markdown
Collaborator

Runner dispatch state for codex on PR #3797. Do not edit.

@stranske
stranske deployed to agent-standard October 7, 2026 01:37 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Runner dispatch state for codex on PR #3797. Do not edit.

@stranske-automation-bot

Copy link
Copy Markdown
Collaborator

Runner dispatch state for codex on PR #3797. Do not edit.

@agents-workflows-bot
agents-workflows-bot Bot deployed to agent-standard October 7, 2026 01:46 Active
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Runner dispatch state for codex on PR #3797. Do not edit.

@stranske

stranske commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

Closer exact-head checkpoint: concurrent keepalive commit 8eb96679dbff9f93c836699678f4163ac32e5ed4 adds stale-CAS and invalid-delta production-default regression tests plus contract documentation; no production helper change. Fetched and fast-forwarded the clean linked worktree, inspected the complete two-file delta, and reran the four focused Node suites: 125 tests passed, zero failures. Previous 02ebc6ec9c541e6c33b519ae9a0725cd100992ef full expected-check topology PASS is historical only. Guard correctly refused merge on the changed head. Current CI is running; next closer action is full expected-check topology and unchanged-head/zero-active-thread guard after the new seven-minute review floor, then squash and actual source #3793 verification. No merge or provider PASS claimed.

@stranske-automation-bot

Copy link
Copy Markdown
Collaborator

Runner dispatch state for claude on PR #3797. Do not edit.

@stranske-automation-bot

Copy link
Copy Markdown
Collaborator

Runner dispatch state for codex on PR #3797. Do not edit.

@stranske
stranske merged commit b4c5c6b into main Oct 7, 2026
54 checks passed
@stranske
stranske deleted the codex/followup-3793-delta-presence branch October 7, 2026 02:10
@stranske stranske added the verify:compare Compare multiple LLM evaluations label Oct 7, 2026
@stranske
stranske deployed to agent-standard October 7, 2026 02:10 — with GitHub Actions Active
@agents-workflows-bot agents-workflows-bot Bot mentioned this pull request Oct 7, 2026
5 tasks done
@stranske
stranske deployed to agent-high-privilege October 7, 2026 02:10 — with GitHub Actions Active
@stranske
stranske deployed to agent-standard October 7, 2026 02:11 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Provider Comparison Report

Provider Summary

Provider Model Verdict Confidence Summary
openai gpt-5.6-terra CONCERNS 80% The visible implementation substantively addresses the changed-tree performance gap. It replaces the v1 positive-only inventory with a v2, tree-bound per-entry {path, blob_sha, pr_number} manifes...
anthropic claude-sonnet-5-5 CONCERNS 60% The visible diff implements the intended v2 per-entry manifest design. Entries are keyed by filename and blob SHA, and the scan reuses only exact immutable matches, so a changed tree fetches only n...
📋 Full Provider Details (click to expand)

openai

  • Model: gpt-5.6-terra
  • Verdict: CONCERNS
  • Confidence: 80%
  • Scores:
    • Correctness: 7.0/10
    • Completeness: 5.0/10
    • Quality: 7.0/10
    • Testing: 8.0/10
    • Risks: 6.0/10
  • Summary: The visible implementation substantively addresses the changed-tree performance gap. It replaces the v1 positive-only inventory with a v2, tree-bound per-entry {path, blob_sha, pr_number} manifest; unchanged filename/SHA entries are reused while new or replaced blobs are revalidated, and PR membership is recomputed for removals. It adds a create-only bootstrap manifest plus a SHA-conditional checkpoint, with current-tree fences intended to fail closed on concurrent change, malformed mappings, missing recovery state, partial writes, and stale checkpoint writers. Source and consumer-template implementations appear mirrored, and the added tests cover separate processes using production reporter defaults, 1,001 bootstrap reads followed by one-read deltas, batched additions, replacement/removal, mapping conflicts, CAS races, negative-to-positive behavior, and lost/interrupted writes. Documentation and mutation RED/GREEN evidence are also present in the visible diff. However, required acceptance evidence/artifacts are unavailable and key changed-code/test portions are truncated, so full correctness, deliverable completeness, and the mandated post-merge issue disposition cannot be verified.
  • Concerns:
    • A PASS is not possible because the supplied acceptance evidence is explicitly incomplete: referenced workflow artifacts were unavailable, and required acceptance evidence cannot be fully verified.
    • The changed-code material was truncated downstream, including the central authority-state implementation and the new delta regression file. The visible code strongly suggests the intended v2 manifest/checkpoint protocol, but the omitted helper implementations (manifest decoding, complete-tree validation, checkpoint advancement, and recovery behavior) cannot be independently verified end-to-end.
    • The acceptance criterion requires a post-merge actual verify:compare against Issue Bound missing-ledger replay API calls with durable PR-keyed attempt presence #3793 and an explicit non-PASS disposition. The supplied material says this is required and that the issue remains open, but the required post-merge evidence is unavailable here; this is unverifiable rather than demonstrably absent.
    • The new persistence protocol is materially more complex than v1: correctness depends on exact Contents API SHA/CAS semantics, immutable commit-pinned reads, and recovery from lost responses. The visible tests cover these cases extensively, but the incomplete code view prevents confirming every fail-closed path and all reconciliation details.

anthropic

  • Model: claude-sonnet-5-5
  • Verdict: CONCERNS
  • Confidence: 60%
  • Scores:
    • Correctness: 8.0/10
    • Completeness: 7.0/10
    • Quality: 7.0/10
    • Testing: 8.0/10
    • Risks: 7.0/10
  • Summary: The visible diff implements the intended v2 per-entry manifest design. Entries are keyed by filename and blob SHA, and the scan reuses only exact immutable matches, so a changed tree fetches only new or replaced blobs. Membership is recomputed from the current entries, which handles replacements and removals. The checkpoint is advanced with a conditional file SHA. A bootstrap manifest is published before keyed publication so recovery works after a lost response. Tree fences surround the delta, manifest and checkpoint phases, and uncertain states fail closed. Tests run separate Node processes against the production reporter defaults and assert the bootstrap read count of 1001 and then exactly 1 blob read per added index, 2 for a two-entry batch. They also cover replacement and removal, corrupt mappings, concurrency, stale checkpoint compare-and-swap, a missing checkpoint, and partial or lost writes, on both the source and template copies. The evidence directory includes a mutant RED run (1002 !== 1) and a restored GREEN run, along with hashes. Documentation and the sync manifest were updated. The implementation looks sound where visible, but I withhold PASS because the code and acceptance evidence were truncated and the artifact lookup was unavailable.
  • Concerns:
    • Coverage is incomplete. Four changed files were truncated and the workflow artifact lookup was unavailable, so a PASS is not permitted. I could not see the remaining bodies of keepalive_authority_state.js (readPresenceCheckpoint, readBootstrapPresence, createBootstrapPresence, createAttemptPresence, advancePresenceCheckpoint, validatePresenceTree), the template's corresponding functions, the tail of the delta test file, or the tail of restored-green.txt.
    • The criterion 'byte-identical restoration gives 121 focused tests PASS' rests on retained console output. Only the first part of restored-green.txt was visible, so I could not confirm the 121-test count or the final pass summary. The mutation.json hashes show identical source and template hashes, which is consistent with the claim.
    • The 'actual verify:compare' and explicit non-PASS disposition criteria apply after merge. They are process steps that cannot be evaluated from the code diff.
    • Visible design risks: (1) Every warm read now calls validatePresenceTree, which reads the tree and the manifest again. Warm calls rose from a bound of 15 to 18, and the manifest bytes remain O(N). The documentation states this honestly. (2) The bootstrap manifest is create-only with a fixed name. A stale or corrupt bootstrap could pin an old base. The code does validate it against the current tree through scanAttemptIndexes, which reuses an entry only on an exact path and blob-SHA match. (3) If the checkpoint is missing and the v2 directory exists with no bootstrap, reads fail closed. That is intentional and tested.
    • The warm-path call bound in the first test (writes of 3 and calls of 18 or fewer) is an empirical fixture bound, not a structural guarantee.

Agreement

  • Verdict: CONCERNS (all providers)
  • Correctness: scores within 1 point (avg 7.5/10, range 7.0-8.0)
  • Quality: scores within 1 point (avg 7.0/10, range 7.0-7.0)
  • Testing: scores within 1 point (avg 8.0/10, range 8.0-8.0)
  • Risks: scores within 1 point (avg 6.5/10, range 6.0-7.0)

Disagreement

Dimension openai anthropic
Completeness 5.0/10 7.0/10

Unique Insights

  • openai: A PASS is not possible because the supplied acceptance evidence is explicitly incomplete: referenced workflow artifacts were unavailable, and required acceptance evidence cannot be fully verified.; The changed-code material was truncated downstream, including the central authority-state implementation and the new delta regression file. The visible code strongly suggests the intended v2 manifest/checkpoint protocol, but the omitted helper implementations (manifest decoding, complete-tree validation, checkpoint advancement, and recovery behavior) cannot be independently verified end-to-end.; The acceptance criterion requires a post-merge actual verify:compare against Issue Bound missing-ledger replay API calls with durable PR-keyed attempt presence #3793 and an explicit non-PASS disposition. The supplied material says this is required and that the issue remains open, but the required post-merge evidence is unavailable here; this is unverifiable rather than demonstrably absent.; The new persistence protocol is materially more complex than v1: correctness depends on exact Contents API SHA/CAS semantics, immutable commit-pinned reads, and recovery from lost responses. The visible tests cover these cases extensively, but the incomplete code view prevents confirming every fail-closed path and all reconciliation details.
  • anthropic: Coverage is incomplete. Four changed files were truncated and the workflow artifact lookup was unavailable, so a PASS is not permitted. I could not see the remaining bodies of keepalive_authority_state.js (readPresenceCheckpoint, readBootstrapPresence, createBootstrapPresence, createAttemptPresence, advancePresenceCheckpoint, validatePresenceTree), the template's corresponding functions, the tail of the delta test file, or the tail of restored-green.txt.; The criterion 'byte-identical restoration gives 121 focused tests PASS' rests on retained console output. Only the first part of restored-green.txt was visible, so I could not confirm the 121-test count or the final pass summary. The mutation.json hashes show identical source and template hashes, which is consistent with the claim.; The 'actual verify:compare' and explicit non-PASS disposition criteria apply after merge. They are process steps that cannot be evaluated from the code diff.; Visible design risks: (1) Every warm read now calls validatePresenceTree, which reads the tree and the manifest again. Warm calls rose from a bound of 15 to 18, and the manifest bytes remain O(N). The documentation states this honestly. (2) The bootstrap manifest is create-only with a fixed name. A stale or corrupt bootstrap could pin an old base. The code does validate it against the current tree through scanAttemptIndexes, which reuses an entry only on an exact path and blob-SHA match. (3) If the checkpoint is missing and the v2 directory exists with no bootstrap, reads fail closed. That is intentional and tested.; The warm-path call bound in the first test (writes of 3 and calls of 18 or fewer) is an empirical fixture bound, not a structural guarantee.

🔍 LangSmith Traces

@stranske-automation-bot

Copy link
Copy Markdown
Collaborator

Runner dispatch state for claude on PR #3797. Do not edit.

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Claude keepalive run failed

Field Value
Exit Code 1
Error Category unknown
Error Type unknown
Run View logs

Suggested Recovery

retry

What to do

  1. Check the workflow logs for detailed error output
  2. If this is a configuration issue, update the relevant settings
  3. If the error persists, consider adding the needs-human label for manual review
  4. Re-run the workflow once the issue is resolved
Output summary
Prompt preparation failed (missing prompt file).

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Runner dispatch state for claude on PR #3797. Do not edit.

@stranske-automation-bot

Copy link
Copy Markdown
Collaborator

Runner dispatch state for claude on PR #3797. Do not edit.

@stranske

stranske commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

Independent post-merge acceptance disposition for source #3793, exact squash b4c5c6bb92c5571e2c5e5c9f65fa45484446fa4d from #3797 head 8eb96679dbff9f93c836699678f4163ac32e5ed4.

Actual issue-bound compare run 37560723543 reports CONCERNS/CONCERNS, corpus NON_PASS, ci_failed=false. Both full provider reports were read. Their blocking claims concern truncated helper/test/console inputs, unavailable artifact lookup and post-merge process steps; neither identifies a demonstrated implementation defect. Those provider verdicts remain CONCERNS; this is an independent evidence-backed disposition, not a provider PASS.

At the exact merged source in a clean detached linked checkout:

  • Read the complete hasAttemptIndexesForPr, scanAttemptIndexes, decodePresence, validatePresenceTree, bootstrap create/read, checkpoint read/CAS and immutable manifest create/read implementations, including every body omitted from provider inputs. Verified complete pinned-tree/path/blob correspondence, exact unchanged-entry reuse, recomputed membership, create-only full mappings, conditional checkpoint SHA and explicit freshness/error paths. Source/template SHA256 both df70d060db6e0bd4f2dbb2fe141fc06c9b3c4b3c2c6194fb3d23252478921034.
  • Ran node --test .github/scripts/__tests__/keepalive-authority-state.test.js .github/scripts/__tests__/keepalive-attempt-presence.test.js .github/scripts/__tests__/keepalive-presence-delta.test.js .github/scripts/__tests__/keepalive-reporter-applicability.test.js: 125 passed, 0 failed. Independent processes using production reporter defaults assert 1,001 bootstrap blob reads, then exactly one for each successive legacy-writer addition and two for the batch. Replacement/removal, missing ledger, positive/negative freshness, corrupt/conflicting mapping, stale checkpoint CAS and interrupted bootstrap/publication/churn controls pass on both source and template.
  • Deliberately disabled actual immutable-entry reuse on BOTH production surfaces and ran the entire delta suite: 14 failed, 10 passed, including both independent-process cases at 1002 != 1. Restored byte-identical source/template, reran the complete four-suite command: 125 passed, 0 failed. The earlier 121-test transcript is fully present and its final summary confirms 121/121; the later four tests explain the current 125 count.
  • python3 scripts/validate_template_sync.py, python3 scripts/validate_template_completeness.py --strict, both node --check commands and git diff --check passed; clean checkout after restoration. Complete operator contract and retained original bootstrap-regression RED evidence inspected.
  • Live fix: validate only changed attempt index blobs after migration #3797 remains MERGED at the stated squash/head with no review-thread pagination and zero unresolved threads. The pre-merge exact-head full topology/floor/unchanged-head receipt is retained in the prior closer round; no new merge is asserted. Original codex/keepalive-replay-missing-ledger: retain authority attempt guard #3792 Major-thread disposition remains preserved.

This resolves the independently confirmed changed-tree historical-blob-rescan debt and the current report-coverage objections. Metadata/tree/manifest bytes remain O(N); the measured blob-read bounds are fixture acceptance, not an O(1) total-cost or deployed fleet-protection claim. No live authority writes or rollout occurred. Source #3793 can now close with this explicit NON_PASS disposition; no duplicate follow-up is needed.

Full lossless fresh commands, RED/GREEN output, hashes, report and live receipts: closer round 20261007T0221Z, 3797-control.json, 3797-mutant-red.txt, 3797-restored-green.txt, 3797-template-sync.txt, 3797-completeness.txt. Retained source evidence: exact merged evidence.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Runner dispatch state for claude on PR #3797. Do not edit.

This branch was successfully deployed

2 active deployments
agent-standard — 8eb96679 Deployed Oct 7, 2026 by stranske via Update keepalive summary #22551
agent-high-privilege — 8eb96679 Deployed Oct 7, 2026 by stranske via privilege environment gate #15364
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent:auto Delegates agent routing to the auto-delegation policy agent:codex Agent-created issues from Codex agents:keepalive Use to initiate keepalive functionality with agents autofix Opt-in automated formatting & lint remediation codex codex-automation verify:compare Compare multiple LLM evaluations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bound missing-ledger replay API calls with durable PR-keyed attempt presence

2 participants