Skip to content

fix: end every open run, visibility, and wider round ceilings - #108

Merged
abedegno merged 13 commits into
mainfrom
fix/open-run-endings
Sep 26, 2026
Merged

abedegno merged 13 commits into
mainfrom
fix/open-run-endings

Conversation

@abedegno

Copy link
Copy Markdown
Owner

What and why

The remaining fixes from the #768 run, plus the two gaps the codex review of #107 found.

Runs that never ended

  • cancel ends a run that has no PR. It recorded cancel_run but never the terminal fact, and waves skipped front-half cancelled runs, so four legacy runs have been open since September. cancel now records escalated itself when the run has no implementation output. It finishes a run an earlier cancel left at cancelled instead of refusing it, checks that the kernel accepted the record, and reads the state back.
  • The sweep takes every cancelled run, with or without output. If retiring the sessions or the record fails, the resume path's cancelled case records the fact on the next wave (second codex review).
  • The sweep takes back-half runs whatever their output. A pass that died between start_implementation and its output left a run at implementing that no wave found. Resumed, _step_loop adopts the PR the implementer pushed or, finding none, the pass ends the run.
  • Every terminal fact is read back. Five record_run_outcome sites retired the queue file on the assumption the fact had been accepted. They now share _finish_pass's read-back (_run_ended), keep the queue file when the kernel refused, and say so in the row.

Seating and cost

  • When both vendors are conflicted, the vendor that started the repair implements again (new coordinator.cli implementer). Before, every wave paid for a review that the kernel refused.

Visibility

  • no_verdict parks keep their cause. The derivation's note travels as the park's cause, JSON-encoded rather than interpolated, and the issue notice leads with Why:.
  • Resumed passes report the run's repair rounds from the journal (spec §2), not just the rounds from their own pass.
  • coordinator.cli status / batch/status.sh print each open run's state, park reason, PR, rounds, front-half seats and last activity.

Bounds

  • Policy ceilings raised to 1..20 rounds and 4..120 seats; defaults unchanged. #768's plan needed nine rounds, each with distinct findings. A front-half no_progress like the back half's was considered and not built: front-half findings are free text hashed whole, so "the same findings three times" would essentially never fire, and identical_resubmission already stops a looping author.

Tidy-up

  • Removed the unused back.repair_for_head. ARCHITECTURE §8 no longer says the repair protocol is missing.

Effect on the merge gate

None. Nothing here changes review, CI observation or merge authorization. Seating changes only which vendor implements when both are conflicted; the kernel's independence check is unchanged and still refuses a conflicted reviewer.

Testing

  • bash batch/run-queue.sh --self-test passes (macOS; Linux via CI)
  • New behaviour has test cases: queue generation (implementing without output; cancelled without output), cancel ×4 (ends, finishes a legacy run, leaves a PR run to the wave, retire failure), refused-terminal-fact ×2, no-PR resume ends the run, implementer seating, implementer/rounds/status CLI, no_verdict cause (client encoding including multi-byte, runner pass-through, notice), resumed rounds, policy ceilings
  • Guards shown red first; the refused-failed test was mutated at its one site (restoring the unconditional retire) and failed

Whole suite: 2021 passed, 3 skipped. Codex review: its one Important finding (cancelled runs stranded if cancel fails partway) is fixed here; nothing else was found.

Anything a reviewer should look at twice

cancel recorded cancel_run and retired the sessions but never the terminal
fact, and waves never sweep a front-half cancelled run, so it stayed open
forever (four legacy runs). With no implementation output there is nothing
left for a pass to do, so cancel now records escalated itself; a run an
earlier cancel left at cancelled is finished rather than refused. A run
with output keeps its resume path.
The back-half clause asked for implementation output, so a pass that died
between start_implementation and its output left a run at implementing
that no wave found (the issue wears bircher:running). Past the seam the
sweep no longer asks for output; resumed, _step_loop adopts the PR the
implementer pushed or, finding none, the pass ends the run.
Five sites recorded record_run_outcome and retired the queue file on the
assumption it was taken; the adapter is advisory, so a refusal (a
superseded generation, as on #768) retired the item over a run still open.
They now share _finish_pass's read-back through _run_ended, keep the queue
file on a refusal and say so in the row.
…pair

A pass that died between a repair's start_implementation and its output
left both vendors in the conflicted set, and the runner kept this wave's
pick, so every wave paid for a review the kernel refused. The vendor that
started the implementation (new coordinator.cli implementer mode) now
implements again; its output makes it the only conflicted actor and the
other vendor reviews.
…journal

closed-loop spec §2 counts rounds from the journal for the scorecard and
the log; a resumed pass reported only its own, so a run repaired over five
waves showed one round or none. New coordinator.cli rounds mode.
The back-half no_verdict park was recorded with no cause, so the notice on
the issue could only say there was no verdict. The derivation's note now
travels as the cause (sanitised in the client, whose hand-built JSON broke
on a quote or newline) and the notice leads with it.
coordinator.cli status (and batch/status.sh) prints each open run's state,
current park reason, PR, repair rounds, front-half seats used/bound and
last activity from the journal alone; --all includes ended runs.
1..5 rounds cut off a front half that was making progress: #768's plan
took nine rounds of distinct findings and reached them only through a
person's grants. The ceilings are now 1..20 rounds and 4..120 seats;
defaults are unchanged, and identical_resubmission still stops a looping
author.
tr/cut sanitising dropped the note's quotes and backslashes and cut bytes,
so a multi-byte character could be split into invalid UTF-8. The cause is
now JSON-encoded by the interpreter and bounded in characters.
Codex review: cancel records the terminal fact only when retiring the
sessions and the record both succeed, and the sweep skipped cancelled runs
without output, so either failure left the run open forever. The sweep now
takes every cancelled run (the resume path's cancelled case ends it), and
cancel checks acceptance and reads the state back.
@abedegno
abedegno merged commit 396ffac into main Sep 26, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant