Fix the PR-divergence respawn loop: loop gate, CEO god-mode, PR conflict resolver, sequence-ordered merge (#164)

* fix(orchestrator,panel): bound the respawn loop gate and give the CEO a status override

The PM respawn loop gate could never fire on a recurring tracing_gap: every
same-status respawn that emitted a tracing_gap reset the strike counter, so a
task whose unblock can never satisfy its decision gate respawned forever. Cap
the number of tracing_gap resets (pm_respawn_max_tracing_resets) so strikes
accrue once a gap is clearly recurring rather than progressing, and route the
pm-review and blocker dispatch respawn paths through the gate so it actually
applies to those loops.

Panel: the task status dropdown was driven solely by the lifecycle graph, so a
task wedged in a terminal/blocked state offered no actionable transitions. Add
an audited admin status override (PATCH status -> admin_set_status) for every
non-in-band target, letting the human operator force any state.

* feat(git): add rebase_onto_base and close_pull_request PR-divergence primitives

Agents had no way to resolve a PR that could not merge because a sibling merged
overlapping work first: their only moves were complete (which 405s) or block
(which loops). Add the two missing operations:

- rebase_onto_base rebases a head branch onto the latest base and classifies
  the outcome: superseded (no unique commits -> safe to close), rebased (unique
  work -> force-pushed, ready to merge), or conflicts (aborted, needs a human).
- close_pull_request retires a superseded PR with an explanatory comment.

These back both the sequence-ordered merge and the conflict resolver.

* feat(gateway): auto-resolve a leaf PR that can't merge instead of looping

When a sibling lands overlapping work first, the cell PM's complete() merge
hits a GitHub 405 and the task re-blocks, respawning the PM forever (the
production wedge: one task burned 6000+ tool calls over 3 hours). The merge
now raises MergeConflictError, and cell_pm_complete resolves it:

- rebase the branch onto the current base;
- superseded (no unique commits) -> close the dead PR + complete the task
  without a redundant merge (the manual action operators kept requesting);
- rebased (unique work) -> retry the merge, then complete;
- genuine conflicts -> admin-override the task to awaiting_ceo_approval and
  alert the CEO, so it leaves agent dispatch instead of looping.

MergeConflictError subclasses GitError, so existing handlers are unaffected.

* test(git): silence unused-arg lint in close_pull_request stub

* feat(orchestrator): sequence-ordered merge for leaf siblings

Leaf siblings share one cell branch, but within-cell siblings were all left at
the default sequence 0, so two leaf PRs raced into the same branch and the
second wedged. Now:

- decomposition assigns each new sibling the next ordinal within its parent, so
  the merge order is well-defined;
- the pm-review dispatcher holds a higher-sequence leaf until its earlier
  same-team siblings are terminal, so they merge into the shared branch in order
  instead of racing.

Loop-free by construction: a gated task is simply not dispatched this tick (no
reject, no respawn). Terminal siblings never block, so a cancelled sibling can't
deadlock the rest; any sibling lookup failure degrades to dispatch.

* test: use monkeypatch.setattr instead of type:ignore in new tests

CI type-checks tests/ (the type-gated suite) which my local 'mypy roboco/' skipped.
The method-mock assignments tripped mypy method-assign/assignment; replace the
silencing comments with monkeypatch.setattr and local mock refs for assertions,
matching the project's no-type:ignore rule.

* fix(git): stop get_status misreporting an unstaged deletion as staged

git_status used stdout.strip().split() before parsing porcelain. strip() eats
the leading space on the first line, so an unstaged deletion (' D file') became
'D file' and parsed as a STAGED deletion — the false 'staged' that caused 6
wasted QA cycles when a dev deleted a file without staging it. Use splitlines(),
which preserves the index/worktree status columns.

* feat(panel): mobile sidebar hamburger + Sheet drawer (AC1)

The umbrella's AC1 was never built: on mobile the sidebar had no entry point.
Extract the nav/footer into shared SidebarNav/SidebarFooter, hide the static
sidebar below md, and add a hamburger in the header that opens the same nav in a
left Sheet drawer (closing on navigation). Desktop is unchanged.

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
Renzo F
2026-06-14 23:18:58 +02:00
committed by GitHub
co-authored by Renn F
parent bb9d4ff12a
commit 2817ca1ceb
14 changed files with 1297 additions and 64 deletions
@@ -105,6 +105,15 @@ export function TaskHeader({ task, onAction }: TaskHeaderProps) {
const nextStatuses: TaskStatus[] = (validTransitionsData ?? []).filter(
(s) => s !== task.status
);
// God-mode: the panel always acts as the CEO/operator, so the dropdown also
// offers every OTHER status as a forced admin override — letting the CEO
// recover a task wedged in a state with no valid in-band move (e.g. a task
// stuck in `blocked` whose PR can never merge, or reopening a `cancelled`
// task). These route through the audited admin-override path, not lifecycle
// verbs. See handleStatusChange.
const overrideStatuses: TaskStatus[] = Object.values(TaskStatus).filter(
(s) => s !== task.status && !nextStatuses.includes(s)
);
const [deleteOpen, setDeleteOpen] = useState(false);
// Inline editing states
@@ -177,8 +186,7 @@ export function TaskHeader({ task, onAction }: TaskHeaderProps) {
// Skip if same status
if (newStatus === task.status) return;
// Backend requires lifecycle actions for ALL status changes
// Map target status to the action that achieves it
// Map a target status to the lifecycle action that achieves it in-band.
const statusToAction: Partial<Record<TaskStatus, string>> = {
[TaskStatus.PENDING]: "reopen", // From cancelled
[TaskStatus.CLAIMED]: "claim",
@@ -193,10 +201,26 @@ export function TaskHeader({ task, onAction }: TaskHeaderProps) {
};
const action = statusToAction[newStatus];
if (action && onAction) {
// Prefer the real lifecycle action when this is a valid in-band transition —
// it runs the proper side effects (e.g. `complete` merges the PR).
if (action && nextStatuses.includes(newStatus) && onAction) {
onAction(action);
} else {
toast.error(`Cannot transition to ${statusLabels[newStatus]} from current status`);
return;
}
// God-mode override: force ANY status, even from a state with no valid
// in-band move (a task wedged in `blocked` whose PR can never merge, or
// reopening a `cancelled` task). Audited via PATCH /tasks/{id} {status} ->
// admin_set_status. No PR merge / lifecycle side effects fire — this is a
// pure, operator-driven state correction the CEO is entitled to make.
try {
await updateTask.mutateAsync({
taskId: task.id,
updates: { status: newStatus },
});
toast.success(`Status forced to ${statusLabels[newStatus]}`);
} catch {
toast.error(`Failed to set status to ${statusLabels[newStatus]}`);
}
};
@@ -347,6 +371,19 @@ export function TaskHeader({ task, onAction }: TaskHeaderProps) {
</span>
</SelectItem>
))}
{/* God-mode: every remaining status as an audited admin
override (no valid in-band transition). Marked "force" so
the operator knows it bypasses the normal lifecycle. */}
{overrideStatuses.map((status) => (
<SelectItem key={status} value={status}>
<span className={`px-2 py-0.5 rounded ${statusColors[status]}`}>
{statusLabels[status]}
</span>
<span className="ml-1 text-[10px] uppercase tracking-wide text-muted-foreground">
force
</span>
</SelectItem>
))}
</SelectContent>
</Select>