Repository navigation
Conversation
Use Pi execution outcomes instead of assistant text to classify managed Agent results and Lead handoffs. Preserve pending work and route interruption reports through existing Manager and Chief authority paths with stable report identities and replay-safe publication. Document current recovery behavior and cover terminal errors, retry outcomes, Lead failures, and report replay.
Preserve project-assignment refreshes, route unassigned Lead failures through the verified Chief path, bound failure details, and serialize retryable herd finalization. Recover pending reports without falsely marking required publication complete. Add regression coverage for report recovery, Manager backlog wake, assignment refresh, and concurrent finalization. Add an isolated real-Pi terminal-failure smoke scenario and document its acceptance evidence.
Allow successful unassigned Lead herds to finish without a project recipient, while preserving required assigned handoffs and reporting factual completion when no integration summary is available. Keep restoration pending when a newer report is unsent, and guard cancellation-report failures so Agent results still reconcile.
Use the existing project-assignment authority for herd finalization so managed Leads cannot finish when worktree scope is unverifiable. Persist assigned direct handoffs for replay, keep Agent-result settlement running when publication fails, and serialize idle replay with completion.
Persist successful report intents for managed Lead direct handoffs and herd completion before fallible assignment verification, while continuing to require the current assignment for publication. Keep unassigned Leads free of project-message intents and require currentProjectAssignment in the runtime host instead of the weaker scope lookup fallback. Add restart regressions for preserving and replaying the original direct and herd summaries once. Remove manually incremented model-execution counters that did not test execution behavior.
Persist each durable Lead report destination before fallible authority lookup and honor it during replay. Project-directed reports still require the current assignment to be verified; a released assignment cannot redirect an old report to Chief. New unassigned failures retain the authorized Chief route, while legacy reports without a destination fail closed.\n\nAdd takeover and targetless-legacy regressions, and clean up the test assertion to verify the durable report state directly.
Route replay from the saved project or Chief destination, and require current role and assignment authority without substituting another recipient. Bind Chief publication to the verified session and lease; fail closed for targetless legacy reports across roles. Add lifecycle regressions for assignment and role changes, preserving the original report ID and payload until its authorized destination is restored.
Keep a successful managed herd unfinished while its required project assignment is unavailable, preserving the durable report intent for an authorized retry. Restore the blocked-publication idle-recovery regression alongside the Chief-routing test.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Context: #302
External Review #1 corrections
project_assignmentIDs may be refreshed while pending; immutable-payload conflict checks remain for other Chief message kinds.External Review #2 corrections
Controlled terminal-failure smoke
npm run smoke -- terminal-failurepassed withreportCount: 1and cleanup passing. It used an isolated custom provider to emit partial assistant text followed by a retryable error, exhausted Pi's bounded native retries, and observed final error settlement and one actionable project failure report. The exact Lead session, assignment, and worktree remained intact; there was no success handoff, extra Lead writer, or automatic tool replay.Validation
npm test -- extension/controller-lifecycle.test.ts— PASS (81 tests).terminal-failure,continuation,manager-recovery, andchief-tree.npm run format— run once as the final pre-commit mutation; formatter changed only the two intended files.npm run format:check— PASS.git diff --check— PASS.npm run validate— PASS (970 passed, 1 skipped, 0 failed); build succeeded and package audit passed (70 files).Limitations
This update does not claim full completion of #302, so it intentionally does not add
Closes #302. The controlled live injection covers an assigned Lead failure; the full issue's hierarchy-wide role/outcome and supervisor-absence/replacement acceptance matrix is broader than this PR's demonstrated live scenario.When no Chief can be verified, failure evidence remains in the originating Pi session; there is no durable future-Chief inbox. Stable report identity and replay-safe writes do not provide transactional exactly-once delivery across independent stores. No automatic model retry, tool replay, process restart, or worktree recreation is introduced.
External Review #3 corrections
currentProjectAssignment()authority. A managed Lead whose worktree scope cannot be verified now fails closed with a durable diagnostic, does not recordfinished, and retains its pending handoff; genuinely unassigned Leads still finish normally.report_pendingintents, publish using the existing project-message transport, and can replay without another Lead model execution. Publication errors are durably diagnosed; unassigned direct responses create no project intent.finishIfIdle()restoration and completion so concurrent idle recovery cannot replay the same report or write duplicate completion transitions.External Review #3 validation
npm test -- extension/controller-lifecycle.test.ts— PASS (86 tests).terminal-failure,manager-recovery, andcontinuation.npm run formatcompleted;npm run format:checkandgit diff --check— PASS.npm run validate— PASS (975 passed, 1 skipped, 0 failed); build succeeded and package audit passed (70 files).This revision still does not claim the full hierarchy-wide acceptance criteria for #302 and intentionally does not add
Closes #302.External Review #4 corrections
currentProjectAssignment()on the Lead runtime host and remove the weaker worktree-scope fallback callbacks.modelExecutionscounters; they did not instrument or verify model execution during restore.External Review #4 validation
npm test -- extension/controller-lifecycle.test.ts— PASS (88 passed, 0 failed).terminal-failureandmanager-recovery.npm run format:check— PASS.git diff --check— PASS.npm run validate— PASS (977 passed, 1 skipped, 0 failed); package audit passed (70 files).This revision still does not claim the full hierarchy-wide acceptance criteria for #302 and intentionally does not add
Closes #302.External Review #5 correction
projectorchiefdestination with each durable Lead report before authority lookup, and preserve that destination during replay.currentProjectAssignment()path verifies the current assignment; the existing project-message publication authority is retained. If/takeoverreleased the assignment, the old Manager-directed report remains pending and is not rerouted to Chief.External Review #5 validation
npm test -- extension/controller-lifecycle.test.ts— PASS (89 passed, 0 failed).npm run format:check— PASS.git diff --check— PASS.npm run validate— PASS (978 passed, 1 skipped, 0 failed); build succeeded and package audit passed (70 files).This revision still does not claim the full hierarchy-wide acceptance criteria for #302 and intentionally does not add
Closes #302.External Review #6 correction
External Review #6 validation
npm test -- extension/controller-lifecycle.test.ts— PASS (89 passed, 0 failed).npm run format:check— PASS.git diff --check— PASS.npm run validate— PASS (978 passed, 1 skipped, 0 failed); build succeeded and package audit passed (70 files).This revision still does not claim the full hierarchy-wide acceptance criteria for #302 and intentionally does not add
Closes #302.External Review #7 corrections
finishedmarker. Persisted report targets continue to govern replay.report_sent, and onefinishedmarker under competing recovery calls.External Review #7 validation
npm test -- extension/controller-lifecycle.test.ts— PASS (91 passed, 0 failed, 0 skipped).npm run format:check— PASS.git diff --check— PASS.npm run validate— PASS (980 passed, 1 skipped, 0 failed); build completed and package audit passed (70 files).This revision still does not claim the full hierarchy-wide acceptance criteria for #302 and intentionally does not add
Closes #302.