Skip to content

fix(supervision): preserve messages until delivery and reconcile Manager identity - #339

Merged
boadij merged 2 commits into
mainfrom
fix/supervision-delivery-identity
Oct 10, 2026
Merged

boadij merged 2 commits into
mainfrom
fix/supervision-delivery-identity

Conversation

@boadij

@boadij boadij commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

Fixes #311
Fixes #338

Summary

Prevent queued supervision messages from disappearing before Pi records their delivery, and keep Herdr pane identity aligned with the verified Manager role. Both fixes reuse existing coordination, session-history, and metadata contracts; no new persistent state or transport.

Changes

  • Receipt-gated delivery: Keep inbox records until the exact message is present in the recipient's complete Pi session history. Recheck after asynchronous authorization and before submission to avoid duplicate delivery; retain existing quarantine, lease, and generation safeguards.
  • Safe retries: Suppress resubmission while Pi is busy or has pending messages. Retry an unreceipted message only when idle, after 1 second following settlement or a conservative 30-second fallback if Pi never emits agent_settled. Clear per-message tracking after acceptance or rejection.
  • Authorization: Retain records when Manager/scope verification is inconclusive; continue rejecting definitively invalid assignments, identities, or lease generations.
  • Herdr identity: Reassert Manager metadata after verified session restoration, clear obsolete Lead tokens, ignore stale queued reports, and record publication failures without affecting role authority. Reset error deduplication after a successful report.
  • Regression coverage: Add receipt/authorization-race, retry-and-pending-message, stale-authority, Manager restoration, and metadata failure → success → failure checks to existing tests.

Validation

Reported for follow-up HEAD 95566425aff24a6e067ef9a94d7b13b72ff4f8d9:

  • npm test -- extension/supervision.test.ts — passed
  • npm test -- extension/controller-api.test.ts — passed
  • npm test -- extension/commands.test.ts — passed
  • npm test -- extension/extension-contract.test.ts — passed
  • npm run smoke -- manager-recovery — passed
  • npm run check — 926 passed, 0 failed, 1 skipped
  • git diff --check — passed

GitHub Actions Validate workflow at this HEAD also passed, including Ubuntu, macOS, Windows, package, and container jobs. External Review #2 found no merge-blocking issues; that review did not independently rerun the local test or smoke commands.

Guarantees and limits

message_staff success acknowledges durable enqueue, not receipt. Inbox consumption now requires the recipient's persisted Pi message. Delivery remains recoverable rather than distributed exactly-once: the 30-second fallback (and crash recovery) can replay a message if Pi persists it unusually late. Herdr metadata remains best-effort presentation and never determines Manager authority.

The fixes address confirmed code defects, but do not conclusively establish the cause of the October 8, 2026 live incident.

Retain coordination records until their exact persisted Pi session receipt is visible, suppress repeated submissions while work is in flight, and keep transient Manager verification failures recoverable. Reconcile restored Manager pane identity and report metadata failures without rolling back authority.

The process-local retry guard bounds duplicate submissions but permits replay after a crash before Pi persists its receipt; it does not provide distributed exactly-once delivery.
@boadij

boadij commented Oct 10, 2026

Copy link
Copy Markdown
Owner Author

Follow-up for External Review #1 (commit 9556642): addressed all four findings without changing the delivery architecture. The drain now rechecks exact receipts after async authorization and before submission; the inbox retries an unreceipted submission only when Pi is idle with no pending messages (1s after settlement, or after a conservative 30s fallback when Pi can fail before agent_settled); accepted/rejected callbacks clear settled-ID bookkeeping; successful Herdr metadata publications reset failure deduplication. Added regressions for the authorization race, pending-message retry suppression and pre-settlement fallback, and metadata failure → success → failure recovery.\n\nValidation passed: npm test -- extension/supervision.test.ts, npm test -- extension/controller-api.test.ts, npm test -- extension/commands.test.ts, npm test -- extension/extension-contract.test.ts, npm run smoke -- manager-recovery, npm run check (926 passed, 0 failed, 1 skipped), and git diff --check. PR remains open and unmerged.

@boadij
boadij merged commit f9b955a into main Oct 10, 2026
7 checks passed
@boadij
boadij deleted the fix/supervision-delivery-identity branch October 10, 2026 08:45
boadij pushed a commit that referenced this pull request Oct 10, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.24.0](v0.23.0...v0.24.0)
(2026-10-10)


### Features

* **ui:** enable verified click-to-focus in status widgets
([#342](#342))
([b7ca8fd](b7ca8fd))


### Fixes

* **supervision:** preserve messages until delivery and reconcile
Manager identity
([#339](#339))
([f9b955a](f9b955a))
* **ui:** repair managed Lead to Manager navigation
([#344](#344))
([d0777bc](d0777bc))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant