Repository navigation
fix(compadre): bound delivery retries and keep request images out of Postgres - #55
Conversation
# Conflicts: # apps/server/src/compadre/NativeThreadEvents.test.ts # apps/server/src/orchestration/Layers/ProviderRuntimeIngestion.ts # apps/server/src/orchestration/decider.ts # docs/internals/compadre-fork.md
|
Release validation: controller CI passed on 508ce64 (full controller tests, Postgres persistence and migration checks). Local integrated central tests passed (74), focused controller regression tests passed, Temporal policy tests passed, server/controller typechecks passed, and scoped lint passed. Root Check repeats the same 18 lint errors already present on merged PR #54, in untouched Sidebar, backup/MCP tests, hosted CLI PATH, and install-hosted-gh files. Not suppressing rules or folding unrelated cleanup into this reliability change. Remaining root test results are being reviewed before merge. Production preflight found zero inline-image request rows. The two confirmed orphaned runs from today had neither a workflow nor persisted request; normal finalization now records aborted state and closes their streams without deleting history. Live fault canaries follow deployment. |
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: unavailable · PR result: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
|
Final CI comparison: all controller/client checks and server shards 1–2 passed. Server shard 3 has exactly the same 15 ProviderCommandReactor test failures as merged PR #54 (compared normalized failing test names). Root Check has the same 18 pre-existing lint errors. No newly failing tests or lint errors were found. Proceeding with the authorized rollout, without changing or disabling those unrelated baseline checks. |
|
Live verification completed on web eebb368 / API bd59531 (replacement instance r29v6), using the API only:
Live checks caught and fixed the helper UUID issue (#56) and a missing narrowly scoped native-input S3 grant (documented in #57). The first API deployment failed on a transient Temporal connection outage affecting both old/new instances; retry succeeded after dependency recovery. Canaries are being stopped; final readback follows the docs-only deployment. No browser rendering or shared-database crash was simulated. |
|
Final post-deployment readback passed (2026-09-11). API is live at aa57ba9 on srv-da73bogae00c738hgl3g-b6cf59d94-64gf5; web remains on eebb368. API /health and web /healthz return 200. Both successful Codex/Claude canaries retain completed runs, ready sessions with no active turn, cancelled delivery workflows and zero pending activities; persistence-failure canary is stopped with no run/workflow. All injected faults are cleared. Message counts remain 5/6/1 after deployment. Read-only Postgres inspection confirms zero inline-image request records; the 20,980,470-byte image test retains ten references in 5,610 bytes of JSON. Three ordinary delivery consumers are STARTED and heartbeating on the new instance (attempt 4 reflects deployment handoffs, not an active retry loop). Follow-ups #56 and #57 are merged and deployed. Earlier evidence and known baseline CI failures remain documented above. No browser verification was performed; live verification used the authenticated API, durable workflow state, S3 integrity checks, and central read models. Database capacity/alerting changes were not part of this rollout. |
Request persistence failures could strand a running turn, large inline images amplified Postgres writes, and failed native delivery could retry indefinitely while central state stayed working.
Persist private S3 references before creating a run; bound delivery retries and expose a durable blocked state; retry transient central SQL errors with stable command IDs. Add API-key-protected, canary-only fault injection and inspection through the canonical central command/read path, with runbook and skill updates.
Verification: targeted controller, central ingestion, native event, Temporal policy, and real Postgres persistence tests passed. Controller and server typechecks passed. Production preflight found 535 stored requests and zero inline-image records, so no backfill is currently needed; legacy inline reads/trimming were removed. Existing Temporal histories retain the required replay-safe versioning.
After merge, verify both Render deployments and exercise live API canaries; no browser verification is claimed. Recheck inline records after old-instance drain.
Model/harness: GPT-5 / Codex.