fix(run-hardening): break PM decision-gate, stale-agent, and empty-diff loops (#255)

Forensic triage of a 24h run reconstructed the dominant gateway.rejected
loops from the audit_log. After earlier deploys fixed the i_will_plan crash
and the open_pr push-gap, three real, recurring-capable burn loops remained.
This fixes them at the architecture level, not by prompt-nagging.

journal:decision write-then-gate (the dominant completion-path blocker):
PM decision-point verbs required a separate note(scope='decision') call
before the verb, which loaded/weak models forget to chain — so complete and
unblock hit a tracing_gap (journal:decision missing) and respawn-looped,
stranding finished tasks forever. Each verb now auto-records its OWN
rationale as the journal:decision before the gate runs (the proven
i_am_blocked -> write_struggle pattern), so the gate passes off real,
persisted reasoning. unblock gains a required `reason` (threaded MCP tool ->
request schema -> routes -> choreographer); delegate derives the decision
from its title + description; complete/submit_up/submit_root/escalate_up/
escalate_to_ceo reuse their existing notes/reason. The gate still runs as
defense-in-depth; the auto-record is idempotent within the decision window
and best-effort. Adds JournalService.write_decision and
Choreographer._ensure_pm_decision.

open_pr empty-diff 422: an overlapping-decomposition leaf with zero commits
vs its base makes GitHub 422 "No commits between ...". The generic
invalid_state "retry" looped the dev 15x on one task. open_pr now steers to a
terminal i_am_blocked hand-off so the PM completes or cancels the redundant
leaf.

owns_task stale-agent loop (41x): a superseded agent (task reassigned away)
calling i_am_done/open_pr got a PRECONDITION_OWNERSHIP tracing_gap it read as
a fixable precondition and retried forever. Both verbs now short-circuit with
the clear not_authorized "no longer yours -> give_me_work" steer that
resume/unclaim already use.

RAG docs updated for the new unblock(reason) signature; CHANGELOG entries
added under 0.11.0 (unreleased). open_pr refactored into
_open_pr_preflight_rejection + _open_pr_failure_env to stay within the
return-count and complexity budgets.

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
Renzo F
2026-06-25 01:07:05 +02:00
committed by GitHub
co-authored by Renn F
parent 4a18dbe4c8
commit 60c64c70e8
21 changed files with 507 additions and 73 deletions
+10 -6
View File
@@ -154,7 +154,9 @@ async def test_unblock_restores_pre_block_state() -> None:
deps = _make_deps(task=task_svc, journal=journal_svc)
c = Choreographer(deps)
env = await c.unblock(pm_id, task_id, restore=True)
env = await c.unblock(
pm_id, task_id, "block resolved upstream; restoring", restore=True
)
assert env.error is None
assert env.status == "awaiting_documentation"
task_svc.unblock_with_restore.assert_awaited_once_with(pm_id, task_id, restore=True)
@@ -182,7 +184,7 @@ async def test_unblock_default_restores() -> None:
c = Choreographer(deps)
# restore omitted -> defaults to True
env = await c.unblock(pm_id, task_id)
env = await c.unblock(pm_id, task_id, "block resolved upstream; restoring")
assert env.status == "awaiting_qa"
@@ -199,7 +201,7 @@ async def test_unblock_blocks_without_journal_decision() -> None:
deps = _make_deps(task=task_svc, journal=journal_svc)
c = Choreographer(deps)
env = await c.unblock(pm_id, task_id)
env = await c.unblock(pm_id, task_id, "block resolved upstream; restoring")
body = env.as_dict()
assert body["error"] == "tracing_gap"
assert "journal:decision" in body["missing"]
@@ -215,7 +217,7 @@ async def test_unblock_wrong_state_returns_invalid_state() -> None:
deps = _make_deps(task=task_svc)
c = Choreographer(deps)
env = await c.unblock(pm_id, task_id)
env = await c.unblock(pm_id, task_id, "block resolved upstream; restoring")
body = env.as_dict()
assert body["error"] == "invalid_state"
@@ -241,7 +243,9 @@ async def test_unblock_restore_false_returns_legacy_message() -> None:
deps = _make_deps(task=task_svc, journal=journal_svc)
c = Choreographer(deps)
env = await c.unblock(pm_id, task_id, restore=False)
env = await c.unblock(
pm_id, task_id, "block resolved upstream; restoring", restore=False
)
body = env.as_dict()
assert body["status"] == "in_progress"
assert "re-engage" in body["next"].lower()
@@ -267,7 +271,7 @@ async def test_unblock_refused_while_a_dependency_is_unfinished() -> None:
deps = _make_deps(task=task_svc, journal=journal_svc)
c = Choreographer(deps)
env = await c.unblock(pm_id, task_id)
env = await c.unblock(pm_id, task_id, "block resolved upstream; restoring")
body = env.as_dict()
assert body["error"] == "invalid_state"