Skip to content

fix(routing): preserve retryable failure on exhausted pool - #1222

Merged
seonghobae merged 9 commits into
mainfrom
fix/exhausted-pool-retryable-final-error
Sep 27, 2026
Merged

seonghobae merged 9 commits into
mainfrom
fix/exhausted-pool-retryable-final-error

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Structure → Gap

Baseline on the real review path: 89 Noema runs, 72 with sanitized sidecar logs, 2026-09-16..21.

  • Runner admission dominates. p50 is ≈6.2 h before the review job starts, against ≈43 min of job wall. That queue lives outside this repository.
  • After admission, CO requests take 60 % of the job wall (p50). The remaining gateway causes are:

Gap: when every orchestrator/free candidate fails, _invoke raises whichever classified upstream error came last. The same provider outcomes can give different caller retryability depending on their order.

candidate outcomes (in order) before after
504, 504, 400 400 invalid_request_error (non-retryable) 504 provider_timeout
400, 504, 504 504 504
504, 400, 504 504 504
400, 400, 400 400 400

A caller treats 400 as a permanent request fault and skips its bounded capacity re-dispatch.

Before/after on real data

10 real review requests ended in 400. In 5 of them, earlier candidates had failed transiently (for example 8 transient failures out of 9 attempts). With this change those 5 surface a retryable 5xx/429. The other 5 had no transient failure and still surface 400.

The sample is failure-biased because evidence was uploaded only on failure. Re-measure after .github#2326.

Change

Track the last retryable upstream failure and surface it when the last failure is non-retryable. This stabilizes retryability, while the exact status among retryable failures can still vary by order. For virtual model requests, wait within the configured request budget for a cooled 429 candidate after other eligible candidates fail, then retry it once. Structured synthesis applies the same bounded recovery. Explicitly selected models keep their immediate error behavior.

Tests

  • New file tests/test_exhausted_pool_final_error_order.py goes through the real HTTP server, with a fake transport at ModelClient._open_provider and no network.
    • RED on origin/main 5665b0a: [504,504,400] returns 400.
    • GREEN on the updated head: 8 passed (-W error), including 429 and 413 boundaries with one transport call per candidate.
  • Related suites (provider_error_taxonomy, passthrough_provider_failover, provider_reliability, tool_execution_fallback, rate_limit_aware_admission): 316 passed.
    • The 4 test_provider_reliability.py failures are pre-existing locally on base.
    • test_invoke_preserves_final_classified_failure_across_candidates (all-429) still passes.
  • Full local suite vs main: failure sets are identical (200 F / 31 E pre-existing), and this branch has 4 more passes.

Latest verification

OpenCode change-request RCA, 2026-09-27 05:55 UTC

  • The OpenCode review for 128e9bc9 cites central .github run 36188050429. Its coverage-evidence job 108295187524 failed at Dockerfile line 89: requirements-noema-document-ci-hashes.txt was absent from the build context. The log ends Trusted coverage tool image build failed before PR execution. This is a trusted-tool materialization defect, not measured product coverage failure; the model review was skipped by this gate.
  • Existing owner .github#2385 now has head 372f5b8bb1ae1bb32ab29e9afbe363d81aed81e3; it includes the lock materialization repair and its exact-head checks remain queued/pending. Protected integration of that owner repair precedes a fresh exact-head review here. This does not authorize dismissing reviews or bypassing checks.

Draft/review admission RCA, 2026-09-27 05:52 UTC

  • The 04:57 Ready-admission receipt returned this PR to Draft citing active OpenCode changes requested. Authenticated review data and public REST /pulls/1222/reviews show those reviews belong to fc5685dc and 128e9bc9, not current 048d90b3. They remain historical review evidence, not current-head product findings. The current-head P1 was repaired in 048d90b3 and its thread resolved.
  • Draft conversion cancelled Security and Quality run 36289442917; the subsequent run 36295796324 skipped. Restored Ready on unchanged head at 05:51 UTC to reopen substantive review/CI admission. No approval was dismissed or fabricated; protected merge still requires actual exact-head approvals and checks. The actor's local Ready-admission implementation is not yet located, so its source repair is not claimed.

Verified external wait, 2026-09-27 02:50 UTC

Current HEAD 048d90b3, 2026-09-27

  • Current-head review comment identified that structured orchestrator/free could stop at a first 400 before checking a later 429 candidate. The reverse-order HTTP case failed with 400 before this fix. Commit 048d90b3 defers provider 400 until the eligible candidates are checked; 401/403 remain terminal. The review thread was answered and resolved.
  • Local warning-strict routing verification: 107 passed, exit 0 (tests/test_actions_model_fallback.py, tests/test_structured_output_distinct_fallback.py, tests/test_rate_limit_aware_admission.py, tests/test_exhausted_pool_final_error_order.py; sibling project interpreter, -c /dev/null -p no:cacheprovider -W error). Both 429→400 and 400→429 succeed through the HTTP boundary with one bounded 429 retry. No current-head hosted approval or gate verdict is claimed yet.

Hosted gate attribution, 2026-09-27 (previous HEAD 240a9ed8)

  • Security and Quality run 36238088222 failed before product tests: an import names a nonexistent embedding lease constant, pip --require-hashes rejects a VCS fast-mlsirm entry, and cargo fmt lacks rustfmt. The five implicated files are byte-identical to origin/main@5665b0ad; this PR changes none of them. Draft #1209 carries those exact repairs and its Security and Quality run 36138545926 passed all four jobs, but it is not merged.
  • CodeQL PR run 36238088228 has a successful dispatch coordinator and failing compatibility shards whose logs say they await an authenticated exact-head terminal verdict. A dispatched scan is not a passing CodeQL result. Central review-control repair .github#2385 remains open; its CodeQL gate also fails.
  • At 240a9ed8, SAST Semgrep and Security Scan passed. Formal OpenCode reviews still cite older heads (fc5685dc, 128e9bc9); no current-head Noema or OpenCode approval is established.
  • At 240a9ed8, the first Noema run 36238087384 and OpenCode run 36238087376 were green because the PR was Draft at execution: Noema skipped verdict preparation and OpenCode skipped the review request. Ready for review was restored on 2026-09-27 without changing the head; auto-merge was requested. CodeQL dispatch run 36287525429 was queued for that head.

At 240a9ed8, the new HTTP front-door regression is RED against archived predecessor 128e9bc9 (HTTP 400 invalid_request_error, 1 failed) and GREEN on that head with -W error (1 passed); its adjacent HTTP controls passed too (5 passed). It runs the conduct stages and structured orchestrator/free request through the server with a fake synthesis client, verifying 429 → 400 → bounded retry success, route receipt, and one failure observation per rejected candidate. This is local boundary evidence, not a deployed Noema run.

At 03d4962d, the three focused routing suites pass with warnings treated as errors: 68 tests, process exit 0 (../.venv/bin/python -m pytest -q -c /dev/null -p no:cacheprovider -W error tests/test_structured_output_distinct_fallback.py tests/test_rate_limit_aware_admission.py tests/test_exhausted_pool_final_error_order.py). The local pytest installation lacks the configured asyncio option; -c /dev/null avoids that unrelated config warning, and disabling pytest's cache avoids writing under /dev. The new structured orchestrator/free regression is RED before the fix for 429→400 and GREEN after it; 401/403 still fail closed, and a repeated 429 is retried only once. The observed Noema workflow installed an older, pinned gateway SHA (767e67fb), so its 429 result is not execution evidence for this patch. Current-head OpenCode coverage preparation and repository security jobs are blocked by separate CI defects tracked in ContextualWisdomLab/.github#2385 and this repository's #1209; Noema continuation permissions are tracked in ContextualWisdomLab/.github#2372.

Scope

Separate from #1209 (shared CI repair) and #1221 (breaker/quarantine). Same boundary rule as AGENTS.md's exhausted-pool classification guidance.

🤖 Generated with Claude Code

https://claude.ai/code/session_012ABB9sb4szFEteww67UYZy

Summary by CodeRabbit

  • 버그 수정
    • 여러 후보 요청이 모두 실패할 때 오류 결과가 실패 순서에 따라 달라지던 문제를 수정했습니다.
    • 재시도 가능한 오류가 포함된 경우 해당 오류를 반환하며, 재시도 가능한 오류끼리는 마지막 오류를 기준으로 결과를 결정합니다.
    • 모든 후보가 요청을 거부하면 400 오류를 반환합니다.
    • 자동으로 모델을 선택하는 요청은 쿨다운 중인 후보가 있으면 제한된 시간 동안 기다린 뒤 재시도합니다. 대기 예산을 소진하면 쿨다운 정보가 포함된 재시도 가능한 429 오류를 반환합니다. 명시적으로 모델을 선택한 요청은 분류된 오류를 즉시 반환합니다.
    • 구조화된 응답 요청은 다른 후보의 실패 후에도 429를 반환한 후보를 한 번 재시도할 수 있습니다. 결과가 불확실한 요청은 다시 실행하지 않습니다.

2026-09-27 capacity RCA and native-policy recovery

  • Live census across 84 nonarchived org repositories found 56 assigned running jobs: 32 Strix, 23 Noema, 1 autofix. A subsequent step snapshot found 26 Strix and 23 Noema jobs provisioning the shared sidecar; five jobs had already completed. Every remaining running job belonged to a live Draft PR. Same-head identity alone did not establish Ready admission.
  • Current central Strix and Noema workflows already cancel matching runs when a PR converts to Draft. Those cleanup jobs themselves require Actions capacity. Applied that existing policy through native Actions cancellation, with immediate live open/Draft/head and exact PR-title/run-status validation before each request, only for Noema and Strix. All 47 requested cancellations are verified completed/cancelled; three changed/terminal targets were skipped. Autofix was left alone. No Ready PR, review verdict, security gate, or source HEAD was modified.
  • The cancelled Argos Strix run 36242234525 now exposes its log: vendoring at 00:48:54Z, pinned dependency installation at 00:48:56Z, live ZDR feed and sidecar launch at 00:54:16Z, with no health confirmation before cancellation. This localizes that long-running instance after installation and sidecar launch; it does not establish the internal provider failure or authorize an inference timeout.
  • Current PR HEAD remains 048d90b3715f792bd6a779d0b013c665fdb01385, Ready. Security run 36298416892 and central-owner #2385 checks still required runner admission at the last direct check. Queue cleanup is verified; successful review, CI, and protected merge are not yet established.

When every orchestrator/free candidate failed, _invoke raised whichever
classified upstream error came last. Two provider timeouts followed by
one model's 400 therefore answered 400 invalid_request_error, telling
the caller the request was permanently invalid. The same outcomes in
another order answered 504. Noema evidence shows 5 of 10 final-400
review requests had earlier transient failures, so a bounded capacity
re-dispatch was skipped.

Track the last retryable upstream failure and surface it when the last
failure is non-retryable. An all-400 pool still reports 400. Retry and
replay authorization, the breaker, and 413/429 handling are unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ABB9sb4szFEteww67UYZy
@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 25 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 92b2403c-6f34-4780-88d0-1f6e1b6d276e

📥 Commits

Reviewing files that changed from the base of the PR and between 03d4962 and 222757e.

📒 Files selected for processing (6)
  • CHANGELOG.d/exhausted-pool-retryable-final-error.md
  • contextual_orchestrator/orchestrator.py
  • tests/test_actions_model_fallback.py
  • tests/test_exhausted_pool_final_error_order.py
  • tests/test_rate_limit_aware_admission.py
  • tests/test_structured_output_distinct_fallback.py
ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 7d9e60c4-1826-4102-98c1-196c92a0dcc4

📥 Commits

Reviewing files that changed from the base of the PR and between b961986 and 03d4962.

📒 Files selected for processing (3)
  • CHANGELOG.d/exhausted-pool-retryable-final-error.md
  • contextual_orchestrator/orchestrator.py
  • tests/test_structured_output_distinct_fallback.py
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.d/exhausted-pool-retryable-final-error.md
Files not reviewed due to moderation or processing errors (1)
  • contextual_orchestrator/orchestrator.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

후보 풀이 소진되면 마지막 오류가 비재시도 가능해도 앞서 발생한 재시도 가능한 오류를 반환합니다. 가상 선택자와 구조화된 합성 요청에서는 쿨다운 후보를 요청 예산에 따라 재시도합니다. 관련 회귀 테스트와 변경 로그를 추가했습니다.

Changes

후보 풀 오류 및 쿨다운 복구

Layer / File(s) Summary
재시도 가능한 오류 보존
contextual_orchestrator/orchestrator.py, tests/test_exhausted_pool_final_error_order.py, CHANGELOG.d/exhausted-pool-retryable-final-error.md
후보 풀이 소진되면 마지막 오류가 비재시도 가능해도 앞서 저장한 재시도 가능한 ProviderUpstreamError를 반환합니다. 테스트는 혼합 실패와 400 또는 413만 발생하는 경우의 최종 상태 및 오류 코드를 확인합니다.
구조화된 합성 재시도
contextual_orchestrator/orchestrator.py, tests/test_structured_output_distinct_fallback.py, CHANGELOG.d/exhausted-pool-retryable-final-error.md
구조화된 합성 요청은 후보별 429 쿨다운과 재시도 상태를 기록하고, 요청 예산 내에서 쿨다운 후보를 한 번 재시도합니다. 테스트는 재시도 성공, 401 또는 403에 따른 종료, 반복 429 이후 후보 풀 소진을 확인합니다.
쿨다운 후보 복구 대기
contextual_orchestrator/orchestrator.py, tests/test_rate_limit_aware_admission.py, CHANGELOG.d/exhausted-pool-retryable-final-error.md
가상 선택자 요청은 적격 후보 중 쿨다운이 남은 후보가 있으면 요청 예산 내에서 회복을 기다린 뒤 선택을 재시도합니다. 테스트는 다른 후보에서 400 또는 504가 발생해도 429 후보를 다시 호출하는지 확인합니다.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Suggested reviewers: claude

Merge Risk: ⚪ Minimal · up to 03d49

The changed failure and cooldown paths show no identified blocker to merging after normal checks.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 03d49

A transient failure can now take precedence over a later provider authentication or permission rejection, potentially prompting callers to retry a request they previously would have stopped. No gateway authorization bypass is established.

Retained concerns

  • Medium · security · inferred: On pool exhaustion, an earlier retryable provider failure can replace the final provider authentication or permission denial, changing the response that a caller uses to decide whether to retry.
Security review details

Security Blast Radius

  • inferred — The demonstrated exposure is an authenticated, multi-candidate free-model request and its caller-visible error; broader tenant exposure or downstream retry volume is not established.

Security Findings and Attack Paths

  • inferred — If a transient failure precedes a final provider 401 or 403, exhausted-pool precedence can return the transient error instead. This obscures a provider denial and may induce caller redispatch; it does not demonstrate bypass of gateway authentication.

Trust Boundaries and Controls

  • observed — The structured-synthesis denial test keeps provider authentication and permission errors fail-closed after a 429; the exhausted-pool HTTP tests do not exercise those statuses.

Resilience and Maintainability Implications

  • inferred — The new structured-synthesis cooldown deadline bounds waiting, but the inspected path does not establish one end-to-end deadline or cancellation context spanning its preceding workflow and subsequent provider attempts.

Hardening Proposals

  • proposed — Define explicit precedence for provider authentication and permission denials when a pool has also seen transient failures, and validate that decision at the HTTP boundary.
  • proposed — Verify a caller-owned deadline and cancellation policy across workflow execution, cooldown waiting, and provider attempts before treating the wait budget as an end-to-end request bound.
🚥 Pre-merge checks | ✅ 4 | ❓ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ❓ Inconclusive Docstring coverage is 53.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 15 functions across 3 files. (2 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 후보 풀이 소진될 때 재시도 가능한 오류를 보존하는 핵심 변경을 정확하고 간결하게 설명합니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 53.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 15 functions across 3 files. (2 skipped: 1 unsupported, 1 too large.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Warning

Review coverage is incomplete: 1 file could not be fully reviewed. Findings from completed review steps are included; see review info for details.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Verification of exact head fc5685dc (.github lead). This is an evidence comment only, not an approval: this account authored the PR.

  • RED→GREEN: tests/test_exhausted_pool_final_error_order.py → 4 passed. With orchestrator.py reverted to origin/main, the (504, 504, 400) case fails as expected (1 failed, 3 passed).
  • No regression: 28 test files that exercise ProviderUpstreamError/_invoke give an identical failure set on this head and on origin/main (61 failed, 979 passed on both). Those 61 are the existing main drift that fix(ci): repair protected-main security and runtime regressions #1209 addresses. tests/test_provider_embedding_batch_backend.py is excluded because it has the known main import error that fix(ci): repair protected-main security and runtime regressions #1209 fixes.
  • Merge: clean against origin/main (0 behind), and git merge-tree against fix(ci): repair protected-main security and runtime regressions #1209 0b369007 has 0 conflicts.
  • Review note (non-blocking): the surface is order-independent in retryability class, not in exact status. (504, 429, 400) raises 429 and (429, 504, 400) raises 504; both are retryable, which matches the stated intent.
  • Hosted wait vs runner queue: every runner-bound job on this head has been QUEUED since the runs were created at 22:28:29Z (the only COMPLETED jobs are no-runner skips). No check has failed. The wait is org Actions runner admission, not a defect in this PR.
  • Merge dependencies: the required opencode-review needs a current-head OpenCode verdict, which depends on .github#2333 (/v1 base URL). A non-author App approval is also needed (last-push approval rule).

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • CHANGELOG.d/exhausted-pool-retryable-final-error.md — repository behavior
  • contextual_orchestrator/orchestrator.py — Python module behavior
  • tests/test_exhausted_pool_final_error_order.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: exhausted-pool-retryable-final-error.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: exhausted-pool-retryable-final-error.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Python: orchestrator.py"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: orchestrator.py"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Test: test_exhausted_pool_final_error_order.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_exhausted_pool_final_error_order.py"]
  R3 --> V3["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: fc5685dcb61f0814e4e838700751ca812a1b0bda
  • Workflow run: 35690707096
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: exhausted-pool-retryable-final-error.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: exhausted-pool-retryable-final-error.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Python: orchestrator.py"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: orchestrator.py"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Test: test_exhausted_pool_final_error_order.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_exhausted_pool_final_error_order.py"]
  R3 --> V3["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

@seonghobae seonghobae changed the title fix(routing): make an exhausted pool's final error order-independent fix(routing): preserve retryable failure on exhausted pool Sep 24, 2026
@opencode-agent
opencode-agent Bot disabled auto-merge September 25, 2026 17:57

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • CHANGELOG.d/exhausted-pool-retryable-final-error.md — repository behavior
  • contextual_orchestrator/orchestrator.py — Python module behavior
  • tests/test_exhausted_pool_final_error_order.py — regression suite
  • tests/test_rate_limit_aware_admission.py — regression suite
  • tests/test_structured_output_distinct_fallback.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: exhausted-pool-retryable-final-error.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: exhausted-pool-retryable-final-error.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Python: orchestrator.py"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: orchestrator.py"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Test: test_exhausted_pool_final_error_order.py (3 files)"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_exhausted_pool_final_error_order.py (3 files)"]
  R3 --> V3["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 128e9bc9513ec37232589111d87cd98c656b13d0
  • Workflow run: 36188050429
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: exhausted-pool-retryable-final-error.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: exhausted-pool-retryable-final-error.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Python: orchestrator.py"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: orchestrator.py"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Test: test_exhausted_pool_final_error_order.py (3 files)"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_exhausted_pool_final_error_order.py (3 files)"]
  R3 --> V3["targeted test run"]
Loading

@seonghobae
seonghobae enabled auto-merge (squash) September 26, 2026 10:32
@opencode-agent
opencode-agent Bot disabled auto-merge September 26, 2026 13:58

Copy link
Copy Markdown
Contributor Author

Admission correction — exact current head 240a9ed8fae049468d4aa86f7ec052ff4c718205 was re-fetched immediately before this transition. The PR remains Open and its branch, commits, reviews, and valid delta are preserved, but it is not merge-admissible: 활성 CHANGES_REQUESTED 2개; terminal workflow failure: Security and Quality:failure. Moving it to Draft/Proposed records the live blocker without retiring or closing the work. Return it to Ready only after the same exact head (or a non-destructive reconciled successor) is mergeable, has no substantive unresolved review state, and has terminal required Checks.

@seonghobae
seonghobae marked this pull request as draft September 26, 2026 15:25
@seonghobae
seonghobae marked this pull request as ready for review September 27, 2026 02:31
@seonghobae
seonghobae enabled auto-merge (squash) September 27, 2026 02:32
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T02:36:20.313811Z 240a9ed Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 240a9ed8fa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread contextual_orchestrator/orchestrator.py Outdated

Copy link
Copy Markdown
Contributor Author

Exact-head Ready-admission repair

Audited head 048d90b3715f792bd6a779d0b013c665fdb01385 against base 5665b0ad1e07ffb5e9f8c59e44b6b2a785298013 (7 ahead / 0 behind).

Current substantive blocker evidence:

  • active CHANGES_REQUESTED: opencode-agent

Queued/pending/in-progress Checks are not blockers and were not treated as failures. This PR is being returned to Draft/Proposed so review admission does not imply readiness while the recorded blocker remains. Preserve the branch and complete the causal source/review/topology repair on a new non-force commit; then re-fetch this exact head's Checks and reviews before restoring Ready.

No merge, close, bypass, review dismissal, synthetic status/approval, manual rerun, force push, or destructive rebase is authorized by this receipt.

@seonghobae
seonghobae marked this pull request as draft September 27, 2026 04:57
auto-merge was automatically disabled September 27, 2026 04:57

Pull request was converted to draft

@seonghobae
seonghobae marked this pull request as ready for review September 27, 2026 05:51
@seonghobae
seonghobae marked this pull request as draft September 27, 2026 10:51
@seonghobae
seonghobae marked this pull request as ready for review September 27, 2026 10:51
@seonghobae seonghobae closed this Sep 27, 2026
@seonghobae seonghobae reopened this Sep 27, 2026
@seonghobae
seonghobae merged commit 51a5951 into main Sep 27, 2026
17 of 21 checks passed
@seonghobae
seonghobae deleted the fix/exhausted-pool-retryable-final-error branch September 27, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant