mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
fix(run-hardening): break PM decision-gate, stale-agent, and empty-diff loops (#255)
Forensic triage of a 24h run reconstructed the dominant gateway.rejected loops from the audit_log. After earlier deploys fixed the i_will_plan crash and the open_pr push-gap, three real, recurring-capable burn loops remained. This fixes them at the architecture level, not by prompt-nagging. journal:decision write-then-gate (the dominant completion-path blocker): PM decision-point verbs required a separate note(scope='decision') call before the verb, which loaded/weak models forget to chain — so complete and unblock hit a tracing_gap (journal:decision missing) and respawn-looped, stranding finished tasks forever. Each verb now auto-records its OWN rationale as the journal:decision before the gate runs (the proven i_am_blocked -> write_struggle pattern), so the gate passes off real, persisted reasoning. unblock gains a required `reason` (threaded MCP tool -> request schema -> routes -> choreographer); delegate derives the decision from its title + description; complete/submit_up/submit_root/escalate_up/ escalate_to_ceo reuse their existing notes/reason. The gate still runs as defense-in-depth; the auto-record is idempotent within the decision window and best-effort. Adds JournalService.write_decision and Choreographer._ensure_pm_decision. open_pr empty-diff 422: an overlapping-decomposition leaf with zero commits vs its base makes GitHub 422 "No commits between ...". The generic invalid_state "retry" looped the dev 15x on one task. open_pr now steers to a terminal i_am_blocked hand-off so the PM completes or cancels the redundant leaf. owns_task stale-agent loop (41x): a superseded agent (task reassigned away) calling i_am_done/open_pr got a PRECONDITION_OWNERSHIP tracing_gap it read as a fixable precondition and retried forever. Both verbs now short-circuit with the clear not_authorized "no longer yours -> give_me_work" steer that resume/unclaim already use. RAG docs updated for the new unblock(reason) signature; CHANGELOG entries added under 0.11.0 (unreleased). open_pr refactored into _open_pr_preflight_rejection + _open_pr_failure_env to stay within the return-count and complexity budgets. Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
@@ -359,13 +359,13 @@ async def test_i_am_done_proceeds_when_all_gates_pass() -> None:
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_i_am_done_blocks_unauthorized() -> None:
|
||||
"""Spec's PRECONDITION_OWNERSHIP rejects with tracing_gap when the
|
||||
caller does not own the task.
|
||||
"""A caller that does not own the task gets a clear not_authorized that
|
||||
steers to give_me_work — not the owns_task tracing_gap it would retry.
|
||||
|
||||
Pre-spec migration the verb returned a separate not_authorized
|
||||
envelope from an inline ownership check; the spec now drives this
|
||||
decision via PRECONDITION_OWNERSHIP, which surfaces as tracing_gap
|
||||
with the `owns_task` missing token.
|
||||
A reassignment short-circuit runs before the spec gate, so a stale /
|
||||
superseded agent is told plainly the task is no longer its own (instead
|
||||
of reading PRECONDITION_OWNERSHIP's tracing_gap as a fixable precondition
|
||||
and looping i_am_done — the observed owns_task burn-loop).
|
||||
"""
|
||||
agent_id = uuid4()
|
||||
other_id = uuid4()
|
||||
@@ -381,5 +381,6 @@ async def test_i_am_done_blocks_unauthorized() -> None:
|
||||
|
||||
env = await c.i_am_done(agent_id, task_id, "done")
|
||||
body = env.as_dict()
|
||||
assert body["error"] == "tracing_gap"
|
||||
assert "owns_task" in body["missing"]
|
||||
assert body["error"] == "not_authorized"
|
||||
assert "no longer assigned" in (body.get("message") or "").lower()
|
||||
assert "give_me_work" in (body.get("remediate") or "")
|
||||
|
||||
Reference in New Issue
Block a user