Files
roboco/tests/unit/runtime/test_respawn_gate_oscillation.py
T
0f1ed3cc6a Hotfixes (#293)
* fix(mcp): delegate tool carries the collision surface the B1a gate demands

TASK_AT_DELEGATE (5fc85419) requires intends_to_touch on code delegations,
but the MCP delegate tool never gained the parameter — PMs were rejected
with incomplete_input and could never comply (live fleet-wide delegation
wall, 2026-07-02). Adds intends_to_touch / adds_migration / touches_shared /
depends_on to the tool and forwards them; parity test locks the invariant.

* fix(git): assembly-integrity guard accepts squash-merged children

git cherry patch-matches each child commit individually, so a squash merge
(N patches -> one commit, new patch-id) read as 'work missing' and the #11
guard refused every legitimate submit_up (live 2026-07-02: S6 cell, three
squash-merged children at the branch tip). A parent commit carrying the
child's [taskid8] prefix now proves the child landed; children with no
marker stay flagged — the original incident the guard exists for.

* fix(git): diff head prefers origin when the local ref is behind it

Assembled branches advance on ORIGIN as child PRs squash-merge on GitHub,
but _resolve_head_ref preferred the inspecting clone's parked local ref —
the PR-gate reviewer's evidence diff was built from a pre-merge snapshot
and re-flagged work that had already landed (two false pr_fail verdicts
on the S6 cell PR, live 2026-07-02). When both refs exist and the local
ref is strictly behind origin, resolve to origin/<branch>; local-ahead
(unpushed) and diverged refs keep priority, single-ref cases unchanged.

* test(mcp): plan-gate fields must be tool parameters (parity class lock)

Extends the delegate parity test to every choreographer plan-depth gate:
a gate that can reject with missing=[field] must name only fields the
corresponding MCP tool can send, else the agent can never comply.

* perf(api): wire TaskSummaryResponse into a bounded /tasks/summary route

The panel fetched /api/tasks unbounded and full-fat — 2MB per refresh
measured live (2026-07-02), ~21KB/task, and the trimmed
TaskSummaryResponse was dead code. /tasks/summary returns exactly the
fields list views render (~50x lighter); the status-only branch of
/tasks now honors its limit, and the eleven unbounded task list routes
are capped.

* perf(panel): kill the per-page request flood and fat payloads

Every page load funneled ~85 default-prefetch RSC requests + 665KB of
images + the 2MB task list through the browser's six HTTP/1.1
connections — real data calls queued ~2s before being sent (measured
via Playwright resource timing, 2026-07-02).

- prefetch={false} on all 59 Links (sidebar, task rows, kanban cards,
  list rows) — ~85 requests/refresh down to a handful
- icon/apple-icon/logo resized to render size: 665KB -> 54KB; unused
  219KB PNG removed
- task list fetches the trimmed /tasks/summary (2MB -> ~100KB),
  normalized into the Task shape so list consumers keep their types
- ReactQueryDevtools rendered only in development

* fix(api): Annotated limit defaults so direct-call tests get real ints

Query(...) positional defaults arrive as Query objects when a route
function is invoked outside the HTTP layer (integration tests call
handlers directly) and broke the new [:limit] slices.

* fix(api,panel): summary carries completed_at + board_review_complete

The metrics page computes velocity client-side from completed_at and the
CEO approval queue gates on board_review_complete — both were nulled by
the summary normalizer, so Completed Today/Week read 0 against 63 real
completions and approved-board tasks could vanish from the queue. The
queue also renders quick_context, so it fetches the full list (small,
status-scoped) via tasksApi.listFull instead of the summary.

* fix(runtime): spawn manifest workspace_path follows the task's project

_build_manifest_for_agent hardcoded the roboco project workspace for
every agent; a guard-core task's manifest claimed /data/workspaces/roboco
while the container cwd sat in the task worktree. The manifest now takes
the same _resolve_workspace_cwd the container -w uses — one resolver,
both surfaces agree by construction.

* fix(runtime): respawn breaker catches status ping-pong loops

Any status CHANGE fully reset the strike counter, so a blocked <->
in_progress oscillation — which changes status on every spawn while
advancing nothing — never tripped the gate (live 2026-07-02: 8 spawns
over two hours). A status never seen on the (agent, task) still fully
resets; a REVISITED status gets a bounded reset budget mirroring
tracing_resets, after which strikes accrue and the gate fires.

* fix(runtime): unassigned-QA dispatch spawns without pre-claiming

The transitioning pre-claim moved awaiting_qa -> claimed before the QA
agent existed; the spawned agent's claim_review/pass_review both demand
awaiting_qa, so it bounced twice and unclaimed (live 2026-07-02,
ba7b751c). Matches _spawn_assigned_qa and the external-PR reviewer
dispatch: no pre-claim, the agent claims itself via claim_review.

* fix(tests): narrow await_args before kwargs access (mypy union-attr)

* Minor upgrades

* fix(policy): team-match gate gains org-wide exemption; resume/unblock/activate now team-matched

needs_team_match sat in its permissive fallback since shipping (no
caller supplied Context.agent_team) and three PM verbs opted out
entirely — a misrouted frontend cell PM blocked, escalated, and held a
backend task through exactly that gap (live 2026-07-02). Org-wide roles
(main_pm, board, CEO, PR reviewer) are exempt so escalation handling
and root-PR gating keep working; cell-scoped roles are now enforced
wherever the caller supplies the team.

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
2026-07-02 15:36:49 +02:00

95 lines
3.3 KiB
Python

"""The respawn breaker must not be fooled by status ping-pong.
Live 2026-07-02: a dev looped blocked -> in_progress -> blocked for two hours
(8 spawns, 30 gateway rejections) and the breaker never tripped — every
status CHANGE fully reset the strike counter, and an A<->B oscillation
changes status on every spawn. A revisited status now gets a bounded reset
budget (mirroring tracing_resets); genuinely new statuses keep the full
reset so forward progress is never punished.
"""
from __future__ import annotations
from typing import Any, cast
from unittest.mock import AsyncMock, patch
from uuid import uuid4
import pytest
from roboco.runtime.orchestrator import AgentOrchestrator
def _new_orchestrator() -> AgentOrchestrator:
orch = AgentOrchestrator.__new__(AgentOrchestrator)
orch._pm_respawn_tracker = {}
orch._bg_tasks = set()
cast("Any", orch)._schedule_respawn_persist = lambda *_a, **_k: None
return orch
def _quiet_audit() -> AsyncMock:
audit = AsyncMock()
audit.has_recent_tracing_gap = AsyncMock(return_value=False)
return audit
@pytest.mark.asyncio
async def test_status_ping_pong_eventually_trips_the_gate() -> None:
"""blocked <-> in_progress oscillation accrues strikes past the budget."""
orch = _new_orchestrator()
task_id = str(uuid4())
statuses = ["blocked", "in_progress"] * 6
results = []
with (
patch("roboco.services.audit.get_audit_service", return_value=_quiet_audit()),
patch(
"roboco.services.notification.NotificationService",
return_value=AsyncMock(),
),
):
for status in statuses:
results.append(
await orch._pm_respawn_should_gate(
"be-dev-1", {"id": task_id, "status": status}
)
)
assert any(results), (
"an A<->B status oscillation never accumulated strikes — the exact "
"2026-07-02 two-hour loop the breaker exists to stop"
)
@pytest.mark.asyncio
async def test_forward_progress_through_new_statuses_never_gates() -> None:
orch = _new_orchestrator()
task_id = str(uuid4())
lifecycle = ["pending", "claimed", "in_progress", "verifying", "awaiting_qa"]
with (
patch("roboco.services.audit.get_audit_service", return_value=_quiet_audit()),
patch(
"roboco.services.notification.NotificationService",
return_value=AsyncMock(),
),
):
for status in lifecycle:
assert not await orch._pm_respawn_should_gate(
"be-dev-1", {"id": task_id, "status": status}
), f"forward progress into {status} must not gate"
@pytest.mark.asyncio
async def test_single_revisit_within_budget_does_not_gate() -> None:
"""A legitimate revision cycle (one revisit) stays under the budget."""
orch = _new_orchestrator()
task_id = str(uuid4())
with (
patch("roboco.services.audit.get_audit_service", return_value=_quiet_audit()),
patch(
"roboco.services.notification.NotificationService",
return_value=AsyncMock(),
),
):
for status in ["in_progress", "awaiting_qa", "in_progress", "awaiting_qa"]:
assert not await orch._pm_respawn_should_gate(
"be-dev-1", {"id": task_id, "status": status}
), "one revision round-trip must not trip the breaker"