diff --git a/tasks/active/2026-09-03-projectdata-production-capacity-emergency.md b/tasks/active/2026-09-03-projectdata-production-capacity-emergency.md index d1680d6acd..87146f1636 100644 --- a/tasks/active/2026-09-03-projectdata-production-capacity-emergency.md +++ b/tasks/active/2026-09-03-projectdata-production-capacity-emergency.md @@ -670,3 +670,40 @@ Relief shipped: superadmin `POST /api/admin/project-data/storage/:projectId/grou (branch `claude/friendly-planck-qziggg`), which prunes grouped/FTS search rows delete-first. Staging verification was skipped on Raphaël's explicit instruction for this emergency; the at-cap behaviour is proven by the first bounded production call. + +## Reconciliation — 2026-10-05 (weekly queue audit) + +**Verdict: stays active, now recovering on its own.** The headline criterion (at or below +9,000,000,000 bytes) is still unmet, but the size is falling for the first time since the breaker +opened on 2026-09-27, and none of the 2026-09-30 next actions is still waiting on a human. + +Measured 2026-10-05 (read-only production D1 `sam-prod`): + +- `project_data_storage_telemetry`: **9,719,410,688 bytes** at 05:15Z (usage ratio 0.9719, status + `degraded`). That is 90.5% of the hard 10 GiB cap. +- Daily 16:40Z samples from `project_data_storage_telemetry_history`: 10.627 GB (10-01), + 10.267 GB (10-02), 10.213 GB (10-03), 9.842 GB (10-04). Overnight 10-05 the hourly samples fall + by 12 to 15 MB an hour. At 250 to 370 MB a day, the 9.0 GB target is about two to three days out. +- `project_data_archive_circuit_breakers`: SAM's breaker is **`closed`** ("Closed from admin UI", + updated 2026-10-02 16:29Z). +- SAM archive migrations: 452 `published`, 47 `frozen`, and **0** `failed`, `poisoned` or in + flight. Publishes per day: 14 (10-02), 40 (10-03), 59 (10-04), 17 by 05:52Z on 10-05. The global + sweep (`archive_sharding_global_sweep`) last finished `succeeded`, with 0 budget stalls. + +What changed since 2026-09-30: + +- The root object hit the hard cap on 10-02 (see the incident section above). #2215 shipped the + superadmin grouped-FTS wall recovery and freed about 464 MB. +- The failed and poisoned migrations were abandoned from Admin → Storage and the breaker was + closed (10-02 16:28Z to 16:29Z). SAM archives resumed at 16:33Z. +- #2216 slowed the archive sweep to one hour on 10-03 02:50Z. #2220 restored the 18-minute + cadence the same day at 13:27Z, so the #2161 rollback question is settled: keep 18 minutes. + +Still open: + +1. The headline criterion. Re-measure around 2026-10-08. If the drain flattens before 9.0 GB, the + next lever is Slice C below, not another manual relief call. +2. Slice C (bounded root history indexing) is still unmerged: commit `7868bc894` on + `sam/implement-reliable-projectdata-archiving-tc49jm`, now 217 commits behind `main`. +3. Rebuild grouped FTS rows after the wall recovery: + `tasks/backlog/2026-10-02-rebuild-grouped-fts-after-wall-recovery.md`. diff --git a/tasks/archive/2026-06-15-codex-acp-midprompt-disconnect.md b/tasks/archive/2026-06-15-codex-acp-midprompt-disconnect.md index 5ad3007e38..413b29c137 100644 --- a/tasks/archive/2026-06-15-codex-acp-midprompt-disconnect.md +++ b/tasks/archive/2026-06-15-codex-acp-midprompt-disconnect.md @@ -75,7 +75,7 @@ The ACP peer closes JSON-RPC first: SAM receives `peer disconnected before respo - [x] Keep unrecoverable failure explicit and terminal. - [x] Add exact JSON-RPC recoverable race and terminal diagnostic/redaction coverage. - [x] Phase 5 review round (go, security, constitution, test, docs-sync, task-completion): no CRITICAL/HIGH live bugs. Applied converged go+security fallback tightening (`crashRecovery.sessionID` only on `inProgress`), clarifying comments, and AC-aligned test additions (per-prerequisite terminal diagnostics for acpSessionId/agentType/all-three; captured-session LoadSession identity assertion; agentType partial-clear fallback; `crashRecoveryInProgress==false` on terminal path). Race + full vm-agent suites green. -- [x] Validate mid-prompt disconnect → `LoadSession` recovery on staging (real VM, new binary). Done 2026-07-11 with `claude-code` (agent-agnostic recovery path) because staging `openai-codex` OAuth is revoked (filed `tasks/backlog/2026-07-11-codex-staging-oauth-refresh-token-revoked.md`). Killed the agent process mid-generation; vm-agent logs show the exact `-32603 "peer disconnected before response"` routed to `deferring to crash recovery` → `attempting LoadSession with previous session` → `LoadSession succeeded`; task stayed `in_progress` with `errorMessage=null`, same `agentSessionId`, message count kept climbing (291→350). No terminal failure, no silent stall. Note: this run's goroutine ordering was Prompt-returns-first (live fields present); the specific cleanup-wins race is covered deterministically by unit tests. +- [x] Validate mid-prompt disconnect → `LoadSession` recovery on staging (real VM, new binary). Done 2026-07-11 with `claude-code` (agent-agnostic recovery path) because staging `openai-codex` OAuth is revoked (filed `tasks/archive/2026-07-11-codex-staging-oauth-refresh-token-revoked.md`). Killed the agent process mid-generation; vm-agent logs show the exact `-32603 "peer disconnected before response"` routed to `deferring to crash recovery` → `attempting LoadSession with previous session` → `LoadSession succeeded`; task stayed `in_progress` with `errorMessage=null`, same `agentSessionId`, message count kept climbing (291→350). No terminal failure, no silent stall. Note: this run's goroutine ordering was Prompt-returns-first (live fields present); the specific cleanup-wins race is covered deterministically by unit tests. - [ ] Complete required reviews (done), CI (green), staging coordination (TURN 2 done), merge, and production monitoring. ### Updated acceptance criteria diff --git a/tasks/backlog/2026-07-11-codex-staging-oauth-refresh-token-revoked.md b/tasks/archive/2026-07-11-codex-staging-oauth-refresh-token-revoked.md similarity index 73% rename from tasks/backlog/2026-07-11-codex-staging-oauth-refresh-token-revoked.md rename to tasks/archive/2026-07-11-codex-staging-oauth-refresh-token-revoked.md index 5d2826c178..48ce151c11 100644 --- a/tasks/backlog/2026-07-11-codex-staging-oauth-refresh-token-revoked.md +++ b/tasks/archive/2026-07-11-codex-staging-oauth-refresh-token-revoked.md @@ -1,5 +1,7 @@ # Codex (openai-codex) unusable on staging — OAuth refresh token revoked +> **Reconciliation 2026-10-05: archived as obsolete, not fixed by a dedicated change.** The symptom is gone: on 2026-10-03, fresh `openai-codex` VM and Instant turns completed on staging for the same smoke user (`provider_mode` `sam`) with no auth error, during the #2207/#2217 runtime-distribution staging runs (`scripts/diagnostics/acp-runtime-distribution.md:145-157,268-289`). Read-only staging D1 shows that user's `openai-codex` agent settings at `provider_mode='sam'` (updated 2026-10-03 15:01Z) and an active `oauth-token` credential created 2026-08-21. Moved from `tasks/backlog/` because `tasks/archive/2026-06-15-codex-acp-midprompt-disconnect.md` links to it. + ## Problem On staging (`sammy.party`), an `openai-codex` agent session for the smoke user diff --git a/tasks/active/2026-09-30-acp-c1-structured-forms.md b/tasks/archive/2026-09-30-acp-c1-structured-forms.md similarity index 92% rename from tasks/active/2026-09-30-acp-c1-structured-forms.md rename to tasks/archive/2026-09-30-acp-c1-structured-forms.md index 273d0fa257..b62d49f178 100644 --- a/tasks/active/2026-09-30-acp-c1-structured-forms.md +++ b/tasks/archive/2026-09-30-acp-c1-structured-forms.md @@ -61,3 +61,7 @@ selection and fresh-stock GPT-5.5 rollback now have distinct live evidence. Timeout/interruption and unsupported-model attempts remain explicitly excluded from successful continuation claims. No new provider login or token custody was added. Final rollback and release disposition remain parent-owned. + +--- + +_Reconciled 2026-10-05 (weekly queue reconciliation): shipped via PR #2206 (`989bf7bb6`, merged 2026-09-30T21:43Z), first successful production deploy run 36783707657 (2026-09-30T22:07Z). PR #2217 (`b79136805`) later added the schema-name field labels and the release. Production enablement came with deploy run 37137757826 (2026-10-03T16:41Z), and the `sam-api-prod` readback on 2026-10-05 shows `ACP_INTERACTION_FORMS_ENABLED=true`. Live form continuation is recorded for Codex only, on VM and Instant (`scripts/diagnostics/acp-runtime-distribution.md`). #2217 lists Claude forms as deterministic builder coverage only, yet forms are offered to any agent in conversation mode (`apps/api/src/services/acp-interaction-runtime-config.ts:15`). No boxes left unticked._ diff --git a/tasks/active/2026-09-30-acp-permission-chat-ui.md b/tasks/archive/2026-09-30-acp-permission-chat-ui.md similarity index 88% rename from tasks/active/2026-09-30-acp-permission-chat-ui.md rename to tasks/archive/2026-09-30-acp-permission-chat-ui.md index 4d36a4ccf1..07d4c20947 100644 --- a/tasks/active/2026-09-30-acp-permission-chat-ui.md +++ b/tasks/archive/2026-09-30-acp-permission-chat-ui.md @@ -81,3 +81,7 @@ Worker, shared schema, VM, or documentation contract changes are required. - Draft PR and handoff only; coordinator owns integrated staging and activation. - No VM, Worker route, shared schema, auth/token custody, form, or URL elicitation changes. - Do not advertise forms or URL requests. + +--- + +_Reconciled 2026-10-05 (weekly queue reconciliation): draft PR #2200 was closed unmerged (2026-09-30T22:32Z). Its reviewed head `e13a166b5` shipped inside integration PR #2202 (`86e6c5b75`, merged 2026-09-30T16:16Z). That commit added `AcpPermissionCard.tsx`, `useAcpPermissionInteractions.ts` and `apps/web/src/lib/api/acp-interactions.ts`, and deleted `packages/acp-client/src/components/PermissionDialog.tsx`. First successful production deploy run 36744720219 (2026-09-30T16:30Z). Permission creation was enabled in production by deploy run 37137757826 (2026-10-03T16:41Z, #2217 release), and the `sam-api-prod` readback on 2026-10-05 shows `ACP_INTERACTIONS_ENABLED=true`. #2200's only later commit, `fca210a90`, is test-only, and main's audit spec has the retry-control clearance assertions (`apps/web/tests/playwright/acp-permission-chat-audit.spec.ts:524-548`). No boxes left unticked._ diff --git a/tasks/active/2026-09-30-acp-runtime-permission-bridge.md b/tasks/archive/2026-09-30-acp-runtime-permission-bridge.md similarity index 93% rename from tasks/active/2026-09-30-acp-runtime-permission-bridge.md rename to tasks/archive/2026-09-30-acp-runtime-permission-bridge.md index 74145bb2a3..19bb34db72 100644 --- a/tasks/active/2026-09-30-acp-runtime-permission-bridge.md +++ b/tasks/archive/2026-09-30-acp-runtime-permission-bridge.md @@ -101,3 +101,7 @@ Slice B connects ACP `RequestPermission` to the shipped Cloudflare create/answer - Ambiguous create acknowledgement does not override an answer already consumed by the runtime; the matching receipt remains duplicate-safe. - Permission cancellation is owned by the exact prompt attempt. An old attempt's cancellation cannot cancel a newer attempt's permission. - The real `acp-go-sdk@v0.13.5` connection remains usable after prompt deadline/cancel closes the matching permission. + +--- + +_Reconciled 2026-10-05 (weekly queue reconciliation): draft PR #2201 was closed unmerged (2026-09-30T16:49Z). Its head `96df904f7` shipped inside integration PR #2202 (`86e6c5b75`, merged 2026-09-30T16:16Z), which added `packages/vm-agent/internal/acp/session_host_interactions.go`. No non-test `internal/acp` Go file still selects `Options[0]`. First successful production deploy run 36744720219 (2026-09-30T16:30Z). The parent's release lifted the keep-disabled and unmerged constraints. Production activation came with deploy run 37137757826 (2026-10-03T16:41Z), and the `sam-api-prod` readback on 2026-10-05 shows `ACP_INTERACTIONS_ENABLED=true`. No boxes left unticked._ diff --git a/tasks/active/2026-09-30-activate-acp-permissions.md b/tasks/archive/2026-09-30-activate-acp-permissions.md similarity index 92% rename from tasks/active/2026-09-30-activate-acp-permissions.md rename to tasks/archive/2026-09-30-activate-acp-permissions.md index bb5021653d..fd7823fe8d 100644 --- a/tasks/active/2026-09-30-activate-acp-permissions.md +++ b/tasks/archive/2026-09-30-activate-acp-permissions.md @@ -207,3 +207,7 @@ selection and fresh-stock GPT-5.5 rollback now have distinct live evidence. Timeout/interruption and unsupported-model attempts remain explicitly excluded from successful continuation claims. No new provider login or token custody was added. Final rollback and release disposition remain parent-owned. + +--- + +_Reconciled 2026-10-05 (weekly queue reconciliation): draft PR #2204 landed through PR #2217 (`b79136805`, merged 2026-10-03T15:59Z). Its head `8a5a1d1ad` is reachable from main, so GitHub marks #2204 merged at the same second, recording `61c796f4b`. First successful production deploy run 37136649002 (2026-10-03T16:23Z); the earlier run 37135306422 failed target validation. Activation: the production Environment overrides `ACP_INTERACTIONS_ENABLED`, `ACP_INTERACTION_FORMS_ENABLED` and `ACP_INTERACTION_URLS_ENABLED` were set to `true` at 16:41:02–05Z, followed by deploy run 37137757826 (workflow_dispatch, 16:41Z). A Cloudflare readback of `sam-api-prod` on 2026-10-05 shows all three `true`. Checked-in defaults remain `false` (`apps/api/wrangler.toml:392-394`, `packages/shared/src/acp-interactions.ts:39-41`). Acceptance evidence: `apps/api/tests/acp-interaction-runtime-config.test.ts:7-32` covers explicit opt-in, and `apps/api/tests/workers/acp-interaction-vertical-slice.test.ts:61` covers reading and answering a pending request after the flag is turned off. The criterion "URL elicitation remains unavailable" was superseded when the parent also enabled URLs in the #2217 release. The old workspace `01M3RBZ3RX4JN084KMNM21A5MT` snapshot is still `degraded/home-skipped` in production D1 and expires 2026-10-07T09:47:49Z; no owner review of it is recorded. No boxes left unticked._ diff --git a/tasks/active/2026-09-30-add-gpt-6-1-sol.md b/tasks/archive/2026-09-30-add-gpt-6-1-sol.md similarity index 76% rename from tasks/active/2026-09-30-add-gpt-6-1-sol.md rename to tasks/archive/2026-09-30-add-gpt-6-1-sol.md index 419e68a153..a518c18f64 100644 --- a/tasks/active/2026-09-30-add-gpt-6-1-sol.md +++ b/tasks/archive/2026-09-30-add-gpt-6-1-sol.md @@ -27,8 +27,9 @@ OpenAI released GPT-6.1 Sol on 2026-09-29. SAM's static OpenAI Codex picker, Ope - [x] Confirm the provider deprecations check requires no catalog removals. - [x] Keep the checked OpenCode static fallback synchronized with the live `models.dev` snapshot. - [x] Run focused and full repository validation. Focused shared tests pass (84/84), the GPT-6.1 proxy vertical-slice test passes, and lint, typecheck, build, and file-size checks pass. The full test run reached 11,059/11,062 before three unrelated API failures under suite load; both affected files pass together in isolation (76/76). -- [ ] Complete specialist review, staging verification, CI, and best-effort CodeRabbit review. -- [ ] Merge and monitor the production deployment, then verify the live production catalog. +- [x] Complete specialist review, staging verification, CI, and best-effort CodeRabbit review. + - _Reconciled 2026-10-05:_ PR #2199 records task-completion-validator, constitution-validator and test-engineer PASS. Deploy Staging run 36688240865 succeeded at `fb9b447a6`. Every non-skipped PR check is SUCCESS. CodeRabbit raised one transport finding at 07:37 UTC; it was fixed in `fb9b447a6` and the thread resolved. +- [ ] Merge and monitor the production deployment, then verify the live production catalog. — not ticked: the merge (#2199 `762a97cf5`) and production deploy run 36697264202 are evidenced, but no production catalog readback is recorded. `/api/model-catalog/*` requires auth (an unauthenticated GET returns 401). The `openai-codex` catalog is served statically (`apps/api/src/services/model-catalog.ts:60-61`) from `packages/shared/src/model-catalog.ts:119`. The OpenCode catalog is dynamic (models.dev), so its live content is unverified. ## Acceptance criteria @@ -45,3 +46,7 @@ OpenAI released GPT-6.1 Sol on 2026-09-29. SAM's static OpenAI Codex picker, Ope - https://models.dev/api.json - https://developers.cloudflare.com/ai-gateway/integrations/coding-agents/openai-codex/ - `.claude/rules/52-model-catalog-lifecycle.md` + +--- + +_Reconciled 2026-10-05 (weekly queue reconciliation): shipped via PR #2199 (`762a97cf5`, merged 2026-09-30T09:10Z), first successful production deploy run 36697264202 (2026-09-30T09:37Z). One box stays unticked because no authenticated production catalog readback is recorded. Selecting the model in a Codex session failed at ACP startup until PR #2205 (`4e18af6b8`, deploy run 37188274268, 2026-10-04T08:14Z). `tasks/archive/2026-09-30-fix-gpt-6-1-sol-acp-startup.md` records a staging provider HTTP 400 for Codex with a ChatGPT account, and leaves a successful production completion to Raphaël's manual test._ diff --git a/tasks/active/2026-09-30-integrate-acp-permissions.md b/tasks/archive/2026-09-30-integrate-acp-permissions.md similarity index 94% rename from tasks/active/2026-09-30-integrate-acp-permissions.md rename to tasks/archive/2026-09-30-integrate-acp-permissions.md index 6eb4d24ec5..827ddf7912 100644 --- a/tasks/active/2026-09-30-integrate-acp-permissions.md +++ b/tasks/archive/2026-09-30-integrate-acp-permissions.md @@ -41,7 +41,7 @@ The reviewed ACP runtime bridge in PR #2201 and project-chat permission UI in PR - [x] Confirm normal chat remains functional and review mobile/desktop staging screenshots. - [x] Delete only integration-owned staging workspaces/nodes immediately and prove zero owned VMs remain at rest. - [x] Create and maintain a draft integration PR with exact deployed commit, resource IDs, fixtures, requests/results, bounded observability, cleanup, integration fixes, and remaining gaps. -- [ ] Send the final branch/head/PR/CI/staging evidence to parent task `01M3RT1PBZNM57EMC00B7ZXAEK`; do not merge or mark ready. +- [ ] Send the final branch/head/PR/CI/staging evidence to parent task `01M3RT1PBZNM57EMC00B7ZXAEK`; do not merge or mark ready. — not ticked: superseded. No record of a message to `01M3RT1PBZNM57EMC00B7ZXAEK` was found. The coordinating parent became `01M3SG06CFJYF7F6HVJXHTFTN1`. That parent reviewed final head `aecaf205f` (#2202 comment 5914878688, 2026-09-30T15:56Z) and released #2202 under Raphaël's authorization (merged 16:16Z). ## Acceptance criteria @@ -103,3 +103,7 @@ Pinned deploy run `36718788997` then failed closed before publishing at the Work - The two live runtimes prove successful delivery receipts; the deliberately lost/unconfirmed receipt, cancellation/deadline/Stop/process-loss, recreated-generation fencing, feature-off/version-skew, and stopped/stale-running no-wake cases remain deterministic evidence from the named suites rather than staged fault injection. This avoids mislabeling local coverage as deployed proof. - The preload fixture exercised the pinned Codex ACP process path under SAM `bypassPermissions`/never-full-access configuration and emitted permission requests by design; it is not evidence that actual Codex emits them. No actual Codex account permission emission or actual Claude account emission was proven, so both remain explicit rollout gaps. Claude support here is limited to the reviewed adapter implementation and deterministic SDK fixture coverage. - After deleting the VM and retained Instant workspace/node/profile through the public API, the authoritative D1 query returned zero nodes outside `deleted`/`failed`. All five temporary staging GitHub Environment overrides were then removed. Restoration deploy `36736535610` republishes the same exact candidate SHA with checked-in `ACP_INTERACTIONS_ENABLED=false`; production was never mutated. + +--- + +_Reconciled 2026-10-05 (weekly queue reconciliation): shipped via PR #2202 (`86e6c5b75`, squash-merged 2026-09-30T16:16Z), first successful production deploy run 36744720219 (2026-09-30T16:30Z). The acceptance criterion that the PR "remains draft and unmerged" was superseded by the parent's release. Checked-in defaults remain `false`. Production permission creation was later enabled by an explicit Environment override (deploy run 37137757826, 2026-10-03T16:41Z). One box is left unticked as superseded because the parent handoff target changed (see that line)._ diff --git a/tasks/active/2026-10-01-acp-auth-diagnosis.md b/tasks/archive/2026-10-01-acp-auth-diagnosis.md similarity index 93% rename from tasks/active/2026-10-01-acp-auth-diagnosis.md rename to tasks/archive/2026-10-01-acp-auth-diagnosis.md index a84eac4dea..641f64801b 100644 --- a/tasks/active/2026-10-01-acp-auth-diagnosis.md +++ b/tasks/archive/2026-10-01-acp-auth-diagnosis.md @@ -73,3 +73,7 @@ selection and fresh-stock GPT-5.5 rollback now have distinct live evidence. Timeout/interruption and unsupported-model attempts remain explicitly excluded from successful continuation claims. No new provider login or token custody was added. Final rollback and release disposition remain parent-owned. + +--- + +_Reconciled 2026-10-05 (weekly queue reconciliation): draft PRs #2209 and #2210 were closed unmerged (2026-10-03T16:00Z). #2209's head `df1ef598a` is not on main. #2210 (head `b7334b6f8`) carried #2209's reviewed changes into PR #2217, merged as `b79136805` on 2026-10-03T15:59Z. That commit added `packages/vm-agent/internal/acp/auth_failure.go`, `session_host_loopback_diagnosis.go`, and the reason codes in `packages/shared/src/failure-classification.ts:115-160`. The creator-gated banners are at `apps/web/src/components/project-message-view/SessionStatusBanners.tsx:43-60`. First successful production deploy run 37136649002 (2026-10-03T16:23Z). Limit: the "parent-owned final runtime matrix" above was not run live. #2217's Limits section says the reason-code tests "include real SDK/HTTP/Worker/UI boundaries, not an assertion that every external account failure was reproduced live." No boxes left unticked._ diff --git a/tasks/active/2026-10-01-acp-c2-url-elicitation.md b/tasks/archive/2026-10-01-acp-c2-url-elicitation.md similarity index 93% rename from tasks/active/2026-10-01-acp-c2-url-elicitation.md rename to tasks/archive/2026-10-01-acp-c2-url-elicitation.md index f7fc623398..3b297de3e7 100644 --- a/tasks/active/2026-10-01-acp-c2-url-elicitation.md +++ b/tasks/archive/2026-10-01-acp-c2-url-elicitation.md @@ -162,3 +162,7 @@ selection and fresh-stock GPT-5.5 rollback now have distinct live evidence. Timeout/interruption and unsupported-model attempts remain explicitly excluded from successful continuation claims. No new provider login or token custody was added. Final rollback and release disposition remain parent-owned. + +--- + +_Reconciled 2026-10-05 (weekly queue reconciliation): draft PR #2207 landed through PR #2217 (`b79136805`, merged 2026-10-03T15:59Z). Its head `bbfc13999` is reachable from main, so GitHub marks #2207 merged at the same second. First successful production deploy run 37136649002 (2026-10-03T16:23Z). The acceptance criterion "draft, dormant, unmerged, undeployed" was superseded by the parent's release. URLs were enabled in production by deploy run 37137757826 (2026-10-03T16:41Z), and the `sam-api-prod` readback on 2026-10-05 shows `ACP_INTERACTION_URLS_ENABLED=true`. The checked-in default remains `false` (`apps/api/wrangler.toml:394`). The live wrapper→Go→Worker→browser gap was closed for Codex on a VM (both completion orders) and on Instant (URL `62842f67-…`), per `scripts/diagnostics/acp-runtime-distribution.md`. Claude URL continuation was not run live. Post-timeout tool availability is open in Idea `01M414TM187NXNWF8AFNJZ6181`. No boxes left unticked._ diff --git a/tasks/archive/2026-10-05-weekly-queue-reconciliation.md b/tasks/archive/2026-10-05-weekly-queue-reconciliation.md new file mode 100644 index 0000000000..c57f483adf --- /dev/null +++ b/tasks/archive/2026-10-05-weekly-queue-reconciliation.md @@ -0,0 +1,549 @@ +# Weekly queue reconciliation — 2026-10-05 + +**SAM task:** `01M45AG431MM1A1ERVN3PJ2HZK` +**Branch:** `sam/weekly-queue-memory-reconciliation-pj2hzk` +**Previous run:** `tasks/archive/2026-09-30-weekly-queue-reconciliation.md` (PR #2198) + +## Problem + +The repo's work-tracking surfaces drift from shipped reality. Merged work sits in +`tasks/active/`, and `tasks/backlog/` collects entries that shipped, were superseded, or duplicate +each other. This run reconciles both against `main` and production so the queue shows only work +that is genuinely open, and posts a status or park decision on every open PR older than 7 days. + +## Research findings + +- The brief estimated about 75 active and 260 backlog files. The tree at `ee80b0ee0` held + **9 active and 214 backlog** files: last week's run (#2198) had already cut the queue to 1 and 208. +- Backlog delta since #2198 (`fb6c928c4`): six new files (2026-10-02 and 2026-10-04, filed by + #2215, #2224 and #2226), one modified (`2026-09-26-trustworthy-task-status`), none removed. + 208 + 6 = 214. +- 26 PRs merged between 2026-09-30 07:46Z and 2026-10-05. Production deployed `main` HEAD + `ee80b0ee0` successfully (Deploy Production run 37245799681, 2026-10-05 00:00Z), so all 26 are + live. +- Open PRs older than 7 days: #1788, #1817, #2020, #2062 and #2160. Nothing changed for any of + them since 2026-09-30 except drift from `main`. + +## Method + +1. Built the evidence base: the 26 merged PRs with merge commits, touched paths and summaries; the + Deploy Production run history; last week's per-file verdicts for 206 of the 214 backlog files. +2. Audited the 8 ACP and GPT-6.1 active files with one reviewer. It established the landing PR, + the merge commit and the first successful production deploy for each, and read the deployed + values of the three ACP flags from the production Worker settings. The ProjectData emergency + file was audited by hand against read-only production D1. +3. Delta-audited all 214 backlog files with seven parallel read-only reviewers (line-balanced + batches of 11 to 42 files). Each file was checked against the code in `main`, not against PR + titles. The 8 files with no 2026-09-30 verdict got a full audit. Verdicts: UNCHANGED, PROGRESS, + SHIPPED, SUPERSEDED, DUPLICATE, OBSOLETE, UNSURE. The rule was "when unsure, keep". +4. Removed a file only on a verified delete-class verdict, and archived it instead of deleting it + when anything that remains links to its path. +5. Verified every new production bug a reviewer reported, in code and in read-only production D1, + before recording it. + +## Outcome + +| Directory | Before | After | +| ---------------- | -----: | --------: | +| `tasks/active/` | 9 | **1** | +| `tasks/backlog/` | 214 | **213** | +| `tasks/archive/` | 1,167 | **1,177** | + +Before: 9 + 214 + 1,167 = 1,390. After: 1 + 213 + 1,177 = 1,391. The difference of +1 is this +ledger (+1) and one new backlog entry (+1), minus one deleted backlog file (−1). + +## Active: 9 → 1 + +### Archived (8) + +Every one is merged and live. The reviewer ticked one box with cited evidence, left two unticked +with a reason on the line, and added a provenance footer to each file. In production, +`ACP_INTERACTIONS_ENABLED`, `ACP_INTERACTION_FORMS_ENABLED` and `ACP_INTERACTION_URLS_ENABLED` +read `true` (production Environment overrides set 2026-10-03 16:41Z, applied by run 37137757826). +The checked-in defaults are still `false`. + +| File | Shipped by | First production deploy | Boxes left unticked | +| ------------------------------------------ | ---------------------------------------------------------------- | ------------------------------------ | ----------------------------------------------------------- | +| `2026-09-30-acp-c1-structured-forms` | #2206 `989bf7bb6`; labels and release via #2217 `b79136805` | run 36783707657 | none | +| `2026-09-30-acp-permission-chat-ui` | #2200 closed unmerged; its head shipped inside #2202 `86e6c5b75` | run 36744720219 | none | +| `2026-09-30-acp-runtime-permission-bridge` | #2201 closed unmerged; its head shipped inside #2202 `86e6c5b75` | run 36744720219 | none | +| `2026-09-30-activate-acp-permissions` | draft #2204 landed via #2217 `b79136805` | run 37136649002 (flags: 37137757826) | none | +| `2026-09-30-add-gpt-6-1-sol` | #2199 `762a97cf5` | run 36697264202 | live production catalog readback (route needs auth) | +| `2026-09-30-integrate-acp-permissions` | #2202 `86e6c5b75` | run 36744720219 | evidence handoff to a parent that was replaced (superseded) | +| `2026-10-01-acp-auth-diagnosis` | #2209 closed unmerged; via #2210 into #2217 `b79136805` | run 37136649002 | none | +| `2026-10-01-acp-c2-url-elicitation` | draft #2207 landed via #2217 `b79136805` | run 37136649002 | none | + +### Kept active (1) + +`2026-09-03-projectdata-production-capacity-emergency`, with a dated 2026-10-05 block. It is +recovering on its own, but its headline criterion (at or below 9,000,000,000 bytes) is unmet: + +- 9,719,410,688 bytes at 05:15Z (status `degraded`), down from 10.627 GB on 10-01 and falling 250 + to 370 MB a day. +- The breaker has been `closed` since 2026-10-02 16:29Z. Migrations: 452 published, 47 frozen, 0 + failed or poisoned. +- Slice C (`7868bc894`) is still unmerged, 217 commits behind `main`. + +## Open PRs older than seven days + +Each comment states only what changed since 2026-09-30 and the one decision that ends the park. + +| PR | Age | Behind `main` | Comment | Decision needed | +| -------------------------------------- | ---: | ------------: | ------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------- | +| #1788 scheduled OSV scan | 56 d | 811 | [5989368788](https://github.com/raphaeltm/simple-agent-manager/pull/1788#issuecomment-5989368788) | Build the private intake, or drop scheduled OSV scanning | +| #1817 architecture workspace prototype | 53 d | 799 | [5989369431](https://github.com/raphaeltm/simple-agent-manager/pull/1817#issuecomment-5989369431) | Close (keep as an Idea) or commit to re-cutting as slices | +| #2020 SonarQube Cloud coverage | 31 d | 341 | [5989370007](https://github.com/raphaeltm/simple-agent-manager/pull/2020#issuecomment-5989370007) | `SONAR_TOKEN`, disable Automatic Analysis, set `SONAR_CI_ENABLED` | +| #2062 sleep-progress moon asset | 24 d | 295 | [5989370558](https://github.com/raphaeltm/simple-agent-manager/pull/2062#issuecomment-5989370558) | Show an animated moon for sleep progress, and where | +| #2160 shared Codex app-server spike | 8 d | 182 | [5989371142](https://github.com/raphaeltm/simple-agent-manager/pull/2160#issuecomment-5989371142) | Keep parked until a native test account exists, or close as an Idea | + +The first four have now had a weekly reconciliation comment since 2026-09-23 plus near-daily "PR +Shepherd" park comments, with no human reply. The decisions are repeated in the SAM digest. + +## Found during the audit + +- **A production bug from #2222, firing every five minutes.** `hasDurableRecord` + (`apps/api/src/scheduled/stuck-task-live-runtime.ts:230-236`) binds a LIKE pattern of 51 to 69 + bytes, over D1's 50-byte limit. The dedupe read fails, is logged as a warning, and a duplicate + `platform_errors` row is written each sweep: 59 rows for task `01M44DA3EDRCGNATD4R3FT0Y7A` + (01:36Z to 06:27Z on 10-05) and 9 for `01M42YQA8QPJQBW48KTDQFAHDE` in production observability + D1. Recorded on `2026-08-07-fix-stuck-task-sweep-pattern-complexity`, whose open regression guard + would have caught it. +- **#2230's new `sleeping` task status is missing from the "active" status sets.** Verified in + code: slept VM conversations drop out of the dashboard's Active Tasks, MCP `list_project_agents` + and the account map, and `send_message_to_subtask` / `stop_subtask` refuse a slept child. + Likely from code reading: opening a slept VM conversation renders the provisioning indicator and + polls every 2 s. Filed as `tasks/backlog/2026-10-05-sleeping-task-status-follow-ups.md`. A + `sleeping` task also has no terminal exit after the 7-day snapshot purge (item 3 of + `2026-09-26-trustworthy-task-status`). +- **GPT-6.1 Sol still fails inside SAM.** Session `ba34fe12` (2026-10-04 21:20Z) got HTTP 400 + "The 'gpt-6.1-sol' model is not supported when using Codex with a ChatGPT account". SAM pins + `@openai/codex@0.156.1` with the SAM C2 patch + (`packages/vm-agent/internal/acp/gateway.go:32`, `codex_runtime_installer.sh`, both + `apps/api` Dockerfiles), and public reports show the same error on 0.156.1. Raphaël confirmed + Sol 6.1 works in his standalone Codex. The diagnosing task `01M42XKK2P41J0091Q8HQ93YJS` ended + `failed` only because its workspace was deleted while it awaited a follow-up. +- **An agent auto-commit reverted a deliberate config change on `main`.** "chore: save agent work" + `c9316fb3f`, carried in by #2217, set `.codex/config.toml` `model_reasoning_effort` back to + `"low"`, undoing `2f78efcff` (`"medium"`). The vm-agent rewrites a SAM-managed block in that + tracked file (`packages/vm-agent/internal/acp/codex_config.go:240-244`). Recorded on + `2026-07-19-repo-history-bloat-cleanup`. +- **ACP permission prompts are effectively dormant in production.** Since #2225 every agent + defaults to Bypass Permissions, so permission cards appear only for sessions set to Manual. Forms + and URL requests are unaffected. +- **Untracked ACP release gaps.** Form and URL continuation were proven live only with Codex, + although production offers both to every agent in conversation mode + (`acp-interaction-runtime-config.ts:15-16`), and the auth-diagnosis live test matrix was never + run (#2217 "Limits"). The 11 ACP chat-guidance Playwright tests #2217 added sit in a quarantined + spec, so CI never runs them. + +## Backlog: 214 → 213 + +### Verdict tally (214 files audited) + +| Verdict | Files | Action | +| ---------- | ----: | ---------------------------------------------------------------------- | +| UNCHANGED | 204 | Kept; 19 of them got a dated note with a corrected fact or new finding | +| PROGRESS | 8 | Kept, with a `Reconciliation 2026-10-05` block | +| SUPERSEDED | 1 | Deleted | +| OBSOLETE | 1 | Archived (an archived task links to it); link repointed | +| DUPLICATE | 0 | — | + +Three files that were UNSURE on 2026-09-30 are still kept (counted as UNCHANGED). + +### Removed (2), one line each + +- `2026-03-29-vm-agent-read-header-timeout` (superseded, **deleted**): fixed differently in #2217 + (`6a042d599`). The upload handler now sets its own read deadline from `FILE_UPLOAD_TIMEOUT` + (`packages/vm-agent/internal/server/file_transfer.go:83-91`, real-socket test + `file_upload_deadline_test.go`), and the short server `ReadTimeout` is kept on purpose for every + other route. Only last week's ledger names it. +- `2026-07-11-codex-staging-oauth-refresh-token-revoked` (obsolete, **archived**): the symptom is + gone. Fresh `openai-codex` VM and Instant turns completed on staging on 2026-10-03 for the same + smoke user, during the #2207/#2217 runtime-distribution runs. Archived because + `tasks/archive/2026-06-15-codex-acp-midprompt-disconnect.md` links to it (repointed). + +### New entry (1) + +- `2026-10-05-sleeping-task-status-follow-ups`: the #2230 `sleeping` gaps listed above. + +### Progress since 2026-09-30, block added (8) + +- `2026-02-20-acp-session-error-observability`: #2217 added bounded prompt-failure reason codes + and creator-gated chat guidance. +- `2026-03-03-simplify-shared-packages`: #2225 deleted the unused permission-mode descriptions. +- `2026-03-07-research-chat-truncation-causes`: #2224 made a 401 non-terminal for the message + reporter (B2's 401 case). +- `2026-04-01-replace-source-contract-tests`: #2225 replaced one route source-contract block with + a real-SQL behavioral test. +- `2026-07-17-stale-playwright-audit-specs`: #2217 repaired part of the recoverable-error spec, but + it stays quarantined (99 of 120 specs). +- `2026-08-04-sleeping-status-renders-as-unknown`: #2230 shipped the Sleeping badge and its test. +- `2026-08-11-vm-agent-snapshot-degradation-union-mismatch`: #2208 made the lifecycle-repair + allowlist moot. +- `2026-09-26-trustworthy-task-status`: #2230's `sleeping` status takes VM conversations out of + the false day-7 failure; Instant tasks, pre-#2230 rows and the post-purge end state remain. + +### Corrected or extended, note added (19) + +- `2026-08-07-fix-stuck-task-sweep-pattern-complexity`: the #2222 production recurrence above. +- `2026-07-20-instant-ping-container-died-midsession`: #2230 widened it (`sleeping` refused by MCP + orchestration). +- `2026-07-19-repo-history-bloat-cleanup`: the `.codex/config.toml` auto-commit revert. +- `2026-03-30-enforce-per-project-task-execution-timeout`: premise corrected; + `TASK_RUN_MAX_EXECUTION_MS` has not killed a live task since #1567. +- `2026-02-20-agent-session-startup-optimization`: scope grew (on-demand Codex runtime install at + session start, #2217); stale code references flagged. +- `2026-03-14-unified-session-task-workspace-state-machine`: wrong file pointer corrected (#2223 + moved the code). +- `2026-07-12-cf-container-wake-restore-hardening`: all five cited locations moved by #2218. +- `2026-03-17-mcp-token-do-storage-security`: pre-split paths updated; #2230's wake reset adds no + exposure. +- `2026-03-28-file-raw-security-hardening`: criterion 1 is owned by + `2026-03-28-migrate-file-proxy-token-to-auth-header`. +- `2026-05-01-ai-proxy-credential-hardening`: #2224 renewal noted; links idea + `01M432G3276YZWCP3HEJ5B25J5`. +- `2026-04-24-session-header-a11y-token-fixes`: item #10 must also cover `sleeping`. +- `2026-07-04-fix-flaky-tests-at-root`: two more load-sensitive tests. +- `2026-06-07-theme-switcher-playwright-coverage-gaps`: both specs it extends are quarantined. +- `2026-07-16-project-data-row-fault-isolation-audit`: a second tolerant `mapRows` already exists. +- `2026-09-23-resource-sparkline-gap-marker-has-no-colour`: now 27 files, plus two more undefined + classes. +- `2026-09-25-split-permanent-session-recovery-refusals`: pointers corrected; #2230 rewrote + `session-recovery.ts` (370 lines), so the cited `:456` no longer existed. +- `2026-09-25-stopping-sleep-with-failed-projectdata-session`: pointers corrected after #2223 and + #2230 moved the code; cross-referenced to the #2230 failed-wake change. +- `2026-07-19-instant-launch-stuck-queued-on-disconnect`: the July-tasks sub-item is closable. +- `2026-07-25-admin-ai-proxy-orphaned-default-model`: #2199 added a second trigger. + +### Unchanged, no edit needed: 185 + +No merge this week touched their open scope; each was checked against this week's 26 merges. Three of them were UNSURE on 2026-09-30 and stay kept: `2026-02-23-suppress-background-subagents-in-acp`, `2026-07-14-stabilize-codex-crash-recovery-reporting-tests`, `2026-09-08-staging-capacity-query-and-deploy-reset-noise`. + +- `2026-02-15-vm-agent-in-place-binary-update` +- `2026-02-16-additional-cloud-providers` +- `2026-02-16-sidebar-redesign-tier2` +- `2026-02-17-persistent-terminal-sessions` +- `2026-02-17-vm-log-browser` +- `2026-02-20-acp-reconnect-replay-integration-test` +- `2026-02-20-orphaned-session-detection-and-recovery` +- `2026-02-23-suppress-background-subagents-in-acp` +- `2026-02-23-worktree-redesign` +- `2026-02-24-vm-agent-process-lifecycle-and-stability` +- `2026-02-27-tdf-1-task-state-machine` +- `2026-02-28-mobile-nav-dropdown-menus` +- `2026-03-03-improve-test-infrastructure` +- `2026-03-03-simplify-deploy-scripts-and-infra` +- `2026-03-03-simplify-durable-objects-and-schema` +- `2026-03-03-simplify-vm-agent-architecture` +- `2026-03-03-simplify-web-app-components` +- `2026-03-03-task-completion-lifecycle` +- `2026-03-04-system-reliability-and-maintainability-hardening` +- `2026-03-09-fix-task-status-display` +- `2026-03-09-llm-task-prioritization` +- `2026-03-10-log-viewer-test-coverage-gaps` +- `2026-03-12-bootstrap-token-dual-auth-dead-code` +- `2026-03-13-binary-install-security-hardening` +- `2026-03-13-scaleway-provider-improvements` +- `2026-03-13-wire-provider-env-var-overrides` +- `2026-03-14-fork-dialog-ui-polish` +- `2026-03-14-summarize-endpoint-hardening` +- `2026-03-15-agent-profiles-4-system-prompt-injection` +- `2026-03-16-compute-lifecycle-test-gaps` +- `2026-03-16-mcp-page-size-limits-not-configurable` +- `2026-03-16-notification-phase2-perf-followups` +- `2026-03-16-notification-security-followups` +- `2026-03-16-notification-test-coverage-gaps` +- `2026-03-16-notification-ui-accessibility-followups` +- `2026-03-16-port-exposure-security-hardening` +- `2026-03-17-acp-subagent-idle-detection` +- `2026-03-17-dispatch-push-parent-branch` +- `2026-03-18-code-context-for-task-submission` +- `2026-03-18-fix-git-identity-conversation-mode` +- `2026-03-18-gcp-self-hosting-docs` +- `2026-03-18-workspace-mcp-server-p2` +- `2026-03-19-chat-view-transitions` +- `2026-03-19-graph-execution-model` +- `2026-03-19-mcp-notification-waituntil` +- `2026-03-19-virtual-scrolling-test-coverage-gaps` +- `2026-03-24-deployment-settings-ui-fixes` +- `2026-03-28-migrate-file-proxy-token-to-auth-header` +- `2026-03-30-account-map-db-indexes` +- `2026-04-03-split-oversized-files` +- `2026-04-08-credential-helper-per-workspace-directory` +- `2026-04-09-document-heartbeat-acp-sweep` +- `2026-04-09-trigger-api-optimizations` +- `2026-04-10-git-show-colon-refspec-injection` +- `2026-04-10-route-level-error-message-leakage` +- `2026-04-10-web-lazy-loading-error-boundaries-a11y` +- `2026-04-12-credential-validity-quota-bypass` +- `2026-04-12-devcontainer-config-secondary-paths` +- `2026-04-13-knowledge-graph-hardening` +- `2026-04-13-knowledge-graph-test-coverage` +- `2026-04-18-agent-key-card-accessibility` +- `2026-04-18-credentials-miniflare-integration-tests` +- `2026-04-18-multi-level-override-framework` +- `2026-04-18-project-credentials-followups` +- `2026-04-18-project-credentials-missing-tests` +- `2026-04-18-project-credentials-playwright-audit` +- `2026-04-19-trial-late-audit-hardening` +- `2026-04-19-trial-orchestrator-boot-test-coverage-gaps` +- `2026-04-19-trial-orchestrator-step-handler-coverage` +- `2026-04-19-trial-sse-abort-propagation` +- `2026-04-19-trial-sse-cursor-persistence` +- `2026-04-20-platform-trial-enabled-env-var` +- `2026-04-22-infrastructure-nav-and-platform-infra-admin` +- `2026-04-23-deploy-script-security-hardening` +- `2026-04-23-remove-docker-requires-from-vm-agent-systemd` +- `2026-04-24-library-like-escape-clause` +- `2026-04-26-durable-interrupts-test-gaps` +- `2026-04-27-sam-tools-post-review-improvements` +- `2026-04-30-unified-user-usage-stats` +- `2026-05-01-fix-playwright-desktop-test-infrastructure` +- `2026-05-01-wp6-openai-routing-integration-test` +- `2026-05-01-wp6-playwright-visual-audit` +- `2026-05-03-harness-phase1-capable-coding-agent` +- `2026-05-03-harness-phase2-sam-platform-integration` +- `2026-05-06-compact-mode-test-coverage-gaps` +- `2026-05-10-lifecycle-state-accuracy` +- `2026-05-11-duplicate-task-session-finalization` +- `2026-05-19-error-banner-role-alert` +- `2026-05-20-amp-project-chat-mcp-wiring` +- `2026-05-26-encrypted-swap-cloud-init` +- `2026-06-03-tts-phase-benchmark` +- `2026-06-04-error-node-cleanup` +- `2026-06-06-library-ui-a11y-preexisting` +- `2026-06-06-projectlibrary-rule18-split` +- `2026-06-07-leak-sweep-test-coverage-gaps` +- `2026-06-08-same-org-submodule-repo-access` +- `2026-06-09-git-credential-loopback-container-binding` +- `2026-06-09-git-credential-node-token-fallback-hardening` +- `2026-06-11-compose-parser-test-coverage` +- `2026-06-12-deployment-provisioning-route-tests` +- `2026-06-12-timeline-drawer-post-merge-fixes` +- `2026-06-15-alternative-inference-providers-backend` +- `2026-06-17-deploy-engine-security-hardening-followups` +- `2026-06-18-api-composition-root-extraction` +- `2026-06-18-deploy-day2-ops-followups` +- `2026-06-18-vm-agent-bootstrap-pipeline` +- `2026-06-18-vm-agent-lifecycle-idempotent-shutdown` +- `2026-06-20-agent-crash-loop-kitty-keyboard-escape` +- `2026-06-24-compose-publish-x-sam-routes` +- `2026-06-26-admin-user-resource-overview` +- `2026-07-12-gitlab-token-lock-rate-limit` +- `2026-07-12-multi-installation-cloudflare-namespaces` +- `2026-07-14-stabilize-codex-crash-recovery-reporting-tests` +- `2026-07-16-observability-mcp-outcome-parsing-gap` +- `2026-07-19-instant-session-capacity-controls` +- `2026-07-19-split-env-interface` +- `2026-07-21-extend-stale-instant-callback-guard-coverage` +- `2026-07-21-instant-container-request-timeout-cancellation` +- `2026-07-21-project-invite-role-and-link-gaps` +- `2026-07-21-remove-sandbox-env-fallbacks-from-container-runtime` +- `2026-07-23-byo-phase0-review-followups` +- `2026-07-23-credential-routes-preexisting-hardening` +- `2026-07-23-vultr-onboarding-wizard-parity` +- `2026-07-25-translate-proxy-sampling-params-4-7-plus` +- `2026-07-29-observability-info-events-persisted-as-errors` +- `2026-08-03-durable-follow-up-prompt-delivery` +- `2026-08-04-auto-commit-push-guard-false-positive-manual-workspaces` +- `2026-08-04-flaky-vultr-ip-poll-error-test` +- `2026-08-04-instant-persistence-step-renders-as-provisioning-vm` +- `2026-08-04-report-issue-length-env-vars-cannot-raise-limits` +- `2026-08-04-shared-staging-do-migration-pinning` +- `2026-08-06-digitalocean-vultr-pagination-silent-truncation` +- `2026-08-06-harden-vm-incident-callback-lifecycle-binding` +- `2026-08-06-investigate-orphaned-projectdata-alarm-wall-time` +- `2026-08-06-isolate-standalone-agent-process-environment` +- `2026-08-06-project-orchestrator-cancel-status-events` +- `2026-08-06-reconciliation-dead-target-task-status-events` +- `2026-08-06-run-gate-ignores-platform-cloud-credential` +- `2026-08-06-wrangler-sync-env-parity-test-coverage-gap` +- `2026-08-07-durable-background-vm-provisioning` +- `2026-08-07-expand-frontend-query-cache-and-persistence` +- `2026-08-07-pre-destroy-safe-evidence-capture` +- `2026-08-08-debugging-overhaul-review-followups` +- `2026-08-09-staging-session-task-reconciliation-repair-failures` +- `2026-08-11-clipped-overflow-debt-sweep` +- `2026-08-11-migrate-remaining-source-contract-ui-tests` +- `2026-08-11-project-agent-short-conversation-duplicate-message` +- `2026-08-11-trigger-paused-reason-signal` +- `2026-08-17-migrate-cancel-stalled-prompt-to-record-turn-end` +- `2026-08-18-cf-container-single-gate-harness-race` +- `2026-08-18-chat-agent-state-single-do-rpc` +- `2026-08-18-consolidate-hand-rolled-visibility-polls` +- `2026-08-18-project-data-id-name-identity-source` +- `2026-08-23-get-instructions-missing-observation-ids` +- `2026-08-23-knowledge-injection-followups` +- `2026-08-23-policy-row-retention-bound` +- `2026-09-08-agent-version-metadata-not-published` +- `2026-09-08-ended-chat-requests-deleted-workspace` +- `2026-09-08-staging-capacity-query-and-deploy-reset-noise` +- `2026-09-08-staging-repeated-noop-storage-alarms` +- `2026-09-09-chat-requests-reaped-task-404` +- `2026-09-09-docs-site-table-cells-overflow-on-mobile` +- `2026-09-09-node-idle-timeout-project-setting-has-no-consumer` +- `2026-09-09-scheduler-explorer-slot-count-model` +- `2026-09-11-bookmark-anchored-d1-reads` +- `2026-09-12-split-project-data-archive-sharding-module` +- `2026-09-14-www-scrollable-table-wrappers-not-keyboard-focusable` +- `2026-09-19-volume-status-badge-and-create-time-status` +- `2026-09-23-playwright-audit-shell-mocks-crash` +- `2026-09-23-schedules-panel-hardcoded-poll-interval` +- `2026-09-25-composable-capacity-source-anchor-guard` +- `2026-09-25-reporter-session-switch-unsent-rows` +- `2026-09-25-staging-allocation-plan-no-longer-current` +- `2026-09-25-structured-log-error-text-redaction` +- `2026-09-27-chat-switch-list-first-paint` +- `2026-09-27-workspace-chat-view-transcript-cache` +- `2026-09-28-workspace-page-chat-stop-sends-chat-session-id` +- `2026-09-29-flaky-harness-activity-coalesce-test` +- `2026-09-30-update-idea-append-silently-truncated-at-cap` +- `2026-10-02-rebuild-grouped-fts-after-wall-recovery` +- `2026-10-04-acp-client-tailwind-classes-not-generated` +- `2026-10-04-instant-generation-aware-callback-token-renewal` +- `2026-10-04-legacy-chat-user-links-invisible-light-mode` +- `2026-10-04-snapshot-relay-node-proof-in-body` +- `2026-10-04-update-after-bootstrap-workspace-token-writer` + +## SAM memory (Part 2, done through SAM MCP, not in this diff) + +Recorded here so the next weekly run can see what changed. + +- **Session review.** About 75 sessions from 2026-09-21 to 2026-10-05 were read for human + corrections and frustration. Every quote used for a policy was re-verified with + `search_messages`. Coverage gap: each project-wide message search reached only 4 of 128 archive + owners, so daytime 09-22 and 09-24 may be under-covered. Repeated patterns: + - **Short, plain answers**, asked for in six sessions. + - **"Did it actually ship?"**: work reported done that had not landed or did not fix the + symptom, in nine sessions. + - **Coordinators going dormant or missing their wake**, in six sessions. + - **Agents handing decisions back** ("needs your OK", "want me to merge?"), in eight sessions. + - **Direct links he can act on from his phone**, asked for in four sessions. +- **Knowledge, 18 observations updated** to current facts: + - Sol 6.1 still fails inside SAM. + - The sleep-loop facts fixed by #2218, #2223 and #2224. + - #2230's stable task identity, with a pointer to the regression entry. + - ProjectData at 9.72 GB and falling; the R2 orphan cost after #2220. + - The project-tracking heuristics. + - Three observations that attributed the ACP delivery coordinator's relayed review messages to + Raphaël now say they came from the coordinator. + - The per-node workspace cap observation is marked superseded (Raphaël, 09-25: "I want that + shit out the fucking door"). + - The Jev "do not ship a generic passthrough" recommendation is marked contested by his 09-29 + "go broad" pushback. + - The dormant-coordinator and response-style observations now carry the recurrence evidence. +- **Knowledge, 14 retired:** + - One spent wave authorization (the 10-04 health wave shipped as #2222, #2223 and #2224). + - Six PR #2210 review gates (the PR closed when #2217 shipped). + - Three ACP-delivery coordination notes. + - Five superseded PR-specific CodeRabbit waivers. +- **Knowledge, 8 added, 6 confirmed.** Added: + - Ranked options in a SAM Idea for planning answers. + - Chat-list ordering by conversation activity (#2228). + - Agent-messaging provenance, with the misattribution as a live example. + - Direct links. + - Handing decisions back. + - The new `ShippingVerification` entity. + - Usage-limit wakes for coordinators. + - Raphaël's 10-05 stalled-tool classifier direction. +- **Ideas:** + - Completed: MCP lineage checks `01M0SD6W5SR7FWFVWTK7DWV318` (#1900, #2230), Commenting MVP + `01M0JQB842XSJ3W172DYPB37HN`, exact Git-state restore `01M30PPM0B96G2RM1HC4Q7EHG6` (#2115). + - Cancelled as duplicates: `01M3WYXYPX8F8H0QN0X8MBJNXK` → `01M3WACF99XYACR3TKHC19Z6JZ`, and + `01KW4D1HKGCV2N8VDNB3Y7BTDX` → `01M43B7Q8HC87N3AEW187Q6BMT`. The survivors absorbed their + evidence. + - Narrowed or retitled: stable task identity follow-ups `01M43NCRFC9VF93RPM355FZAKJ`, legacy + recovery rows `01M3WACF99XYACR3TKHC19Z6JZ`, file commenting Phase 2 + `01M0N1250YESBW2R497KXDZVSC`. Title-only for the two plans already full at 64 KiB: ACP + `01M3P2E0JJNQRXX020P65ZRKEJ` and ProjectData `01M0YZNBKSKQZ47NC0K7M8N5AX`. + - Status notes on 10 more ideas. + - Created: GPT-6.1 Sol fails inside SAM, `01M45CXE5ZG10WTT30V5HCSY9V`. +- **Policies:** + - **Deactivated 7** task-scoped policies whose work verifiably shipped: `38df5a88` (#2030), + `805199d8` (#2059), `390ef351` (eventing, #2075), `fb2f6edf` (#1898), `1e946849` (commenting + MVP), `f8bed08d` (#1824), `528fc2af` (ACP delivery). The cap counts only policies that apply + now, and it had blocked three explicit saves this week. + - **Added 2**, for explicitly and repeatedly stated preferences: `be92174d` (keep chat replies + short and plain, one question at a time) and `d465ac2d` (give direct links for anything + Raphaël may act on). + - **Clarified 1:** `d60830e2` now says a direct change request authorizes merging once every + gate passes. This follows his 10-04 "Not sure I follow. Why did you not merge?" and his 10-03 + "create a PR, get it green, get it shi[p]ped as soon as possible". + - Live policies: 99 before, 94 after (cap 100). + - Not changed: `d73204ef` (keep the Sol profile on gpt-6.1-sol) stays, because the + compatibility work is not finished. Policy `66060db4`, which held the ProjectData destructive + gates, expired on 2026-09-22 and was not renewed (nobody restated it). +- **Not recorded, deliberately:** "Go one step deeper…" (a one-off correction that rule 39 + covers), and "each batch can overlap by a bit" (specific to one coordinator). The + `.workflow-state.md` request ("Ok. Make that happen.") is draft PR #2227. + +## Genuinely open for the week of 2026-10-06 (ranked) + +1. **#2230's `sleeping` status is missing from the "active" status sets.** It affects every VM + sleep since 2026-10-05 00:00Z. Slept conversations vanish from Active Tasks, + `list_project_agents` and the account map. Agents cannot message (`send_message_to_subtask`, + `send_durable_message`) or stop a slept VM agent, which breaks "sleep and be durably woken" for + coordinator → child messages. A slept chat likely renders as provisioning. + (`tasks/backlog/2026-10-05-sleeping-task-status-follow-ups.md`, SAM idea + `01M43NCRFC9VF93RPM355FZAKJ`) +2. **#2222's stuck-task dedupe writes a duplicate `platform_errors` row every five minutes.** Its + LIKE pattern is over D1's 50-byte limit (59 rows for one task in five hours). A small fix, plus + the ≤ 50-byte regression guard that would have caught it. + (`tasks/backlog/2026-08-07-fix-stuck-task-sweep-pattern-complexity.md`) +3. **A failed VM wake still fails the conversation.** Since #2230 it fails the conversation's own + task and fires the parent's task-wait hooks. (SAM idea `01M3MFDMZ5AS0BXPHZWS3CRFED`, + `tasks/backlog/2026-09-25-stopping-sleep-with-failed-projectdata-session.md`) +4. **GPT-6.1 Sol is unusable inside SAM.** The pinned Codex CLI `0.156.1` rejects it for ChatGPT + accounts. Rebase the SAM C2 patch onto a current Codex CLI and keep its design constraints. + Raphaël tried it several times on 10-04. (SAM idea `01M45CXE5ZG10WTT30V5HCSY9V`) +5. **"Expired, not failed."** 11 of the 34 tasks that failed since 2026-09-30 were lifecycle + outcomes: 4 expired human-input requests, 6 day-7 runtime verdicts, and 1 deleted workspace + while awaiting a follow-up. A `sleeping` task also has no terminal exit after the 7-day purge. + (`tasks/backlog/2026-09-26-trustworthy-task-status.md`, SAM idea `01KZNGJG1DCH8DBC835Y0272P4`) +6. **ProjectData root object to ≤ 9.0 GB.** It is recovering on its own (9.72 GB, falling 250 to + 370 MB a day). Re-measure around 10-08; land Slice C (`7868bc894`) if the drain flattens; then + rebuild grouped FTS. (`tasks/active/2026-09-03-projectdata-production-capacity-emergency.md`) +7. **`update_idea` silently drops appends at 64 KiB.** The ACP and ProjectData plans are full; this + run had to retitle them instead of appending. + (`tasks/backlog/2026-09-30-update-idea-append-silently-truncated-at-cap.md`) +8. **ACP live-proof gaps.** Forms and URL requests were proven live only with Codex, but production + offers them to every agent; the auth-diagnosis live matrix was never run; #2217's 11 ACP + Playwright tests sit in a quarantined spec. (SAM idea `01M3P2E0JJNQRXX020P65ZRKEJ`, + `tasks/backlog/2026-07-17-stale-playwright-audit-specs.md`) +9. **Agent auto-commits rewrite the tracked `.codex/config.toml`.** One silently reverted + `model_reasoning_effort` to `"low"` on `main` (via #2217). Decide the intended value and stop + the vm-agent writing SAM-managed config into a tracked file. + (`tasks/backlog/2026-07-19-repo-history-bloat-cleanup.md`) +10. **Five parked PRs need Raphaël's call.** #1817 close or commit (799 behind), #1788 OSV intake, + #2020 Sonar account actions, #2062 moon asset, #2160 Codex app-server spike. + +Also open, unchanged this week: prompt-cancel section B (SAM idea `01M31M9G3T4SEWT9ZW1BM4QKZ3`); +the per-profile agent admin switch §8 (`01M388Y1Q1068DNT69KTBFXSMB`, two premises now stale after +#2202/#2225); the staging-contention check (`01M3M0AK930MJXX12TFT9VJ3PH`); check-ins that kill +working agents (flight-queue item 11, no recurrence in production since 09-28); the Playwright +quarantine (99 of 120 specs); the R2 orphaned-snapshot backfill (`01M40H4ZBTVC9WPNMRA5VMGPS9`); +and the AI-proxy token of agent processes alive past 24 h (`01M432G3276YZWCP3HEJ5B25J5`). + +## Implementation checklist + +- [x] Verify each of the 9 active files against its landing PR, the first successful production + deploy, and (for flags) the deployed value; archive shipped files with a provenance footer +- [x] Add a dated status block to every active file that stays active +- [x] Delta-audit all 214 backlog files against this week's 26 merges (7 parallel read-only + reviewers, line-balanced batches); fully audit the 8 files with no 2026-09-30 verdict +- [x] Remove backlog files only on a verified delete-class verdict; archive and repoint instead + when anything that remains references the path +- [x] Add a `Reconciliation 2026-10-05` block to every file with new progress or a corrected fact +- [x] File a backlog entry for any bug the audit finds +- [x] Post a status nudge or park decision on #1788, #1817, #2020, #2062 and #2160 +- [x] Record the full ledger here, then move this file to `tasks/archive/` + +## Acceptance criteria + +- [x] Every file left in `tasks/active/` has a measurably unmet acceptance criterion and live work: + only the ProjectData emergency (9.72 GB against a 9.0 GB target). +- [x] Every archived file states how it shipped, and no box is ticked without evidence. +- [x] Every backlog removal has a one-line rationale in the PR description and in this ledger. +- [x] No citation in the repo points at a task path this PR moved or deleted. +- [x] Each open PR older than 7 days has a new 2026-10-05 comment. +- [x] The before/after file arithmetic closes exactly (see Outcome). diff --git a/tasks/backlog/2026-02-20-acp-session-error-observability.md b/tasks/backlog/2026-02-20-acp-session-error-observability.md index 9389168dbb..1655ef5b22 100644 --- a/tasks/backlog/2026-02-20-acp-session-error-observability.md +++ b/tasks/backlog/2026-02-20-acp-session-error-observability.md @@ -1,5 +1,14 @@ # ACP Session Error Observability & Reconnection Reliability +> **Reconciliation 2026-10-05:** PR #2217 (b79136805, merged 2026-10-03) brought in the ACP Slice D auth-diagnosis commits ee6fd576f and 7640dea85. `ClassifyPromptError` / `ClassifyPromptFailure` (`packages/vm-agent/internal/acp/auth_failure.go:14,53`) now replace the free-form `Prompt failed: %v`. The replacement is a bounded reason code (`model_provider_credential_missing|_rejected`, `model_unavailable`, `provider_overloaded`, `agent_crash`, `network_error`, else `agent_prompt_failed`). It appears in the `ACP Prompt failed` lifecycle/error-reporter payload and the JSON-RPC error (`session_host_prompt.go:657-673`), and in task callbacks (`packages/vm-agent/internal/server/server.go:1542-1553`). A missing agent credential now reports `model_provider_credential_missing` (`session_host_selection.go:51-60`). Project chat shows creator-gated guidance for it (`apps/web/src/components/project-message-view/SessionStatusBanners.tsx:25-48`, `apps/web/src/components/debug/FailureCard.tsx:101-107`). Still open: +> - Codes for every other lifecycle and error-reporter event. `reportAgentError` still takes a free-form `step` (`session_host_reporting.go:19-37`). +> - The per-session event timeline, the `GET /workspaces/:id/agent-sessions/:sessionId/events` API (does not exist), and the "Session Log" view. +> - Banners for silent failures: LoadSession fallback, buffer overflow, replay timeout. +> - Reconnection-progress UI. +> - A longer timeout for close code 1001. +> - Server-side connection migration. +> - Phase 5 error metrics, dashboards and connection-quality tracking. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** diff --git a/tasks/backlog/2026-02-20-agent-session-startup-optimization.md b/tasks/backlog/2026-02-20-agent-session-startup-optimization.md index 57eee4c179..026670e936 100644 --- a/tasks/backlog/2026-02-20-agent-session-startup-optimization.md +++ b/tasks/backlog/2026-02-20-agent-session-startup-optimization.md @@ -1,5 +1,7 @@ # Agent Session Startup Optimization +> **Reconciliation 2026-10-05:** Scope grew this week instead of shipping. Since #2217, VM Codex sessions verify, download (about 132.6 MB) and install the pinned Codex runtime when a session starts (`packages/vm-agent/internal/acp/session_host.go:625-637` → `codex_runtime_distribution.go:56`, 5-minute default timeout in `config.go:35`). That belongs in this file's Phase 2 pre-install scope. Key and settings fetches are still sequential (`session_host_selection.go:51,229`). The references to `@zed-industries/claude-code-acp` and `session_host.go:295-330` below are stale. + **Created**: 2026-02-20 **Status**: Backlog **Priority**: High diff --git a/tasks/backlog/2026-03-03-simplify-shared-packages.md b/tasks/backlog/2026-03-03-simplify-shared-packages.md index 2473f1624a..5971095d9d 100644 --- a/tasks/backlog/2026-03-03-simplify-shared-packages.md +++ b/tasks/backlog/2026-03-03-simplify-shared-packages.md @@ -1,5 +1,12 @@ # Simplify Shared Packages +> **Reconciliation 2026-10-05:** #2225 (9ef726c20) deleted the unused `AGENT_PERMISSION_MODE_DESCRIPTIONS`. Only `AGENT_PERMISSION_MODE_LABELS` remains (`packages/shared/src/constants/agent-settings.ts:24-30`), so the labels/descriptions merge is done. Still open: +> +> - Move the computed `isIdle`, `isTerminated` and `workspaceUrl` out of the API response type (`packages/shared/src/types/session.ts:23-27`). +> - Decide `toolMetadata`: `z.string()` at `vm-agent-contract.ts:202` vs a Record at `types/session.ts:62`. +> - Remove the `HETZNER_IMAGE` alias (`constants/hetzner.ts:20-21`). +> - Remove the positional-args overload (`packages/acp-client/src/transport/websocket.ts:91-128`). + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** diff --git a/tasks/backlog/2026-03-07-research-chat-truncation-causes.md b/tasks/backlog/2026-03-07-research-chat-truncation-causes.md index 3b00e4052b..fac536008d 100644 --- a/tasks/backlog/2026-03-07-research-chat-truncation-causes.md +++ b/tasks/backlog/2026-03-07-research-chat-truncation-causes.md @@ -1,5 +1,13 @@ # Research: Chat Messages Appear Truncated While Agent Still Working +> **Reconciliation 2026-10-05:** #2224 (4f223d6fa) fixed B2's 401 case. A rejected token no longer deletes the outbox: the reporter holds rows until a renewed or re-delivered token arrives, and reports a pause longer than `MSG_AUTH_RENEWAL_WAIT` (default 15 min) (`packages/vm-agent/internal/messagereport/credential.go`, `sender.go:143-145,214-221`). VM workspace callback tokens are now renewed before they expire. Still open: +> - **B2, 403 case:** a node-scoped or other-workspace token gets 403 "Insufficient token scope" (`apps/api/src/routes/workspaces/_helpers.ts:338-376`). That is still terminal and clears the session outbox (`sender.go:217-221`, `messagereport/reporter.go:411-417`). See `2026-10-04-update-after-bootstrap-workspace-token-writer.md`. +> - **B2, Instant case:** Instant tokens are not renewed (`2026-10-04-instant-generation-aware-callback-token-renewal.md`). Held rows are lost if the runtime is torn down. +> - **B5:** `acp/ordered_reader.go:103-168` still never checks `scanner.Err()`. +> - **B1:** tracked in `2026-09-25-reporter-session-switch-unsent-rows.md`. +> - **B3, B4, C3:** re-verify. +> - **C1 (optional):** no outbox flush before the `awaiting_followup` callback (`server/server.go:1449-1536`). + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** the research itself (every failure mode below is cited), plus two fixes: diff --git a/tasks/backlog/2026-03-14-unified-session-task-workspace-state-machine.md b/tasks/backlog/2026-03-14-unified-session-task-workspace-state-machine.md index 49264ecc90..e5da4ee3f5 100644 --- a/tasks/backlog/2026-03-14-unified-session-task-workspace-state-machine.md +++ b/tasks/backlog/2026-03-14-unified-session-task-workspace-state-machine.md @@ -1,5 +1,7 @@ # Unified Session/Task/Workspace State Machine +> **Reconciliation 2026-10-05:** Pointer correction only. The 2026-09-30 block cites `session-sleep-execution.ts:367` for the sleep-time ACP `interrupted` call; #2223 moved it to `apps/api/src/services/session-sleep-teardown.ts:316-333`. Gap 5 is still open: the stop paths update `chat_sessions` only (`apps/api/src/durable-objects/project-data/sessions.ts:290-312`). + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** every cascade except gap 5 (paths under `apps/api/src/` unless noted). diff --git a/tasks/backlog/2026-03-17-mcp-token-do-storage-security.md b/tasks/backlog/2026-03-17-mcp-token-do-storage-security.md index 481cf10ec9..2659211c9a 100644 --- a/tasks/backlog/2026-03-17-mcp-token-do-storage-security.md +++ b/tasks/backlog/2026-03-17-mcp-token-do-storage-security.md @@ -1,5 +1,7 @@ # MCP Token Plaintext Storage in Durable Object State +> **Reconciliation 2026-10-05:** The cited `durable-objects/task-runner.ts:89,860-861` predates the TaskRunner split. The token is now set at `apps/api/src/durable-objects/task-runner/agent-session-step.ts:105-132` and persisted unredacted through `task-runner/attempt-storage.ts:5-18`. It is redacted only in `task-runner/status.ts:4-5` and revoked only on failure (`task-runner/state-machine.ts:456-467`). #2230's wake reset nulls it without revoking it, which matches the existing TTL-only expiry for runs that did not fail: no new exposure, scope unchanged. + **Created**: 2026-03-17 **Source**: Security audit of fix/mcp-token-ttl-alignment branch diff --git a/tasks/backlog/2026-03-28-file-raw-security-hardening.md b/tasks/backlog/2026-03-28-file-raw-security-hardening.md index 24bfe4f4d7..51840a1bbf 100644 --- a/tasks/backlog/2026-03-28-file-raw-security-hardening.md +++ b/tasks/backlog/2026-03-28-file-raw-security-hardening.md @@ -1,5 +1,7 @@ # File Raw Endpoint Security Hardening +> **Reconciliation 2026-10-05:** Criterion 1 (the JWT in the `FileViewerPanel` ``) is also claimed by `2026-03-28-migrate-file-proxy-token-to-auth-header.md`, whose 2026-09-30 block owns it; treat that file as the owner. Nothing else changed: the raw paths are untouched and the vm-agent Content-Length check still defaults to `'0'`. + **Created**: 2026-03-28 **Source**: Security auditor review of image rendering feature PR diff --git a/tasks/backlog/2026-03-29-vm-agent-read-header-timeout.md b/tasks/backlog/2026-03-29-vm-agent-read-header-timeout.md deleted file mode 100644 index 1839b4b9d6..0000000000 --- a/tasks/backlog/2026-03-29-vm-agent-read-header-timeout.md +++ /dev/null @@ -1,18 +0,0 @@ -# Switch VM Agent HTTP Server from ReadTimeout to ReadHeaderTimeout - -## Problem - -The VM agent HTTP server uses `ReadTimeout` (default: 15s) which applies to the entire request body read, not just headers. With the increased file upload limit (50MB per file), uploads over moderate connections (e.g., 5 Mbps ≈ 80s for 50MB) will be silently killed by the server before the handler finishes reading the body. - -## Context - -Discovered during Go specialist review of PR increasing file upload limits to 50MB. Pre-existing issue that becomes more impactful at larger file sizes. - -**Location**: `packages/vm-agent/internal/server/server.go:421` - -## Acceptance Criteria - -- [ ] Replace `ReadTimeout` with `ReadHeaderTimeout` in the HTTP server configuration -- [ ] `ReadHeaderTimeout` protects against slowloris attacks on headers -- [ ] Body-read timing governed by handler context timeouts (`FileUploadTimeout`, etc.) -- [ ] Test that large file uploads don't time out at the server level diff --git a/tasks/backlog/2026-03-30-enforce-per-project-task-execution-timeout.md b/tasks/backlog/2026-03-30-enforce-per-project-task-execution-timeout.md index 23406bbe2b..16d2dd87d1 100644 --- a/tasks/backlog/2026-03-30-enforce-per-project-task-execution-timeout.md +++ b/tasks/backlog/2026-03-30-enforce-per-project-task-execution-timeout.md @@ -1,5 +1,7 @@ # Enforce Per-Project Task Execution Timeout +> **Reconciliation 2026-10-05:** The premise needs correcting. `TASK_RUN_MAX_EXECUTION_MS` has not killed a live task since #1567; #2222 documents this at `apps/api/src/scheduled/stuck-task-live-runtime.ts:17-18`. The only hard stop is `TASK_RUN_ABSOLUTE_CEILING_MS` (24h, `packages/shared/src/constants/task-execution.ts:26`). Option A would therefore only move the recovery check: the "terminated after 30 minutes" criterion needs its own kill path (Option B, or a per-project absolute ceiling). The per-project value is still not read by the stuck-task sweep or TaskRunner (`apps/api/src/scheduled/stuck-tasks.ts:1113` reads env only). + ## Problem Statement The `taskExecutionTimeoutMs` per-project scaling parameter is stored in the projects table, collected via the Settings UI, and passed through `TaskRunConfig.projectScaling` — but it is never enforced at runtime. The stuck-tasks cron (`apps/api/src/scheduled/stuck-tasks.ts`) only reads the platform-wide `TASK_RUN_MAX_EXECUTION_MS` env var. diff --git a/tasks/backlog/2026-04-01-replace-source-contract-tests.md b/tasks/backlog/2026-04-01-replace-source-contract-tests.md index 4e780b3b8d..58f7cafddf 100644 --- a/tasks/backlog/2026-04-01-replace-source-contract-tests.md +++ b/tasks/backlog/2026-04-01-replace-source-contract-tests.md @@ -1,5 +1,7 @@ # Replace Source-Contract Tests with Behavioral Integration Tests +> **Reconciliation 2026-10-05:** PR #2225 (9ef726c20) deleted the agent-settings-callback source-contract block from `apps/api/tests/unit/project-agent-defaults.test.ts`. That block read `routes/workspaces/runtime.ts`. It was replaced by a behavioral route test on a real SQL engine, `apps/api/tests/unit/routes/workspace-agent-settings-callback.test.ts:47-194` (`app.request`, no `readFileSync`). Still open: every item in the 2026-09-30 block. `project-agent-defaults.test.ts` still reads `routes/tasks/submit.ts` and `routes/mcp/dispatch-tool.ts` (`:391-415`), so all 28 listed files remain. The detector regex in `scripts/quality/check-source-contract-tests.ts:52-55` is still unfixed. No new route source-contract tests were added this week. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** all 9 named files in `apps/api/tests/unit/routes/` were deleted by PR #598 diff --git a/tasks/backlog/2026-04-24-session-header-a11y-token-fixes.md b/tasks/backlog/2026-04-24-session-header-a11y-token-fixes.md index 10f941f2d5..d05ee472bc 100644 --- a/tasks/backlog/2026-04-24-session-header-a11y-token-fixes.md +++ b/tasks/backlog/2026-04-24-session-header-a11y-token-fixes.md @@ -1,5 +1,7 @@ # Session Header Accessibility and Design Token Fixes +> **Reconciliation 2026-10-05:** #2230 added a `sleeping` task status. SessionHeader's badge (`apps/web/src/components/project-message-view/SessionHeader.tsx:455-479`) gives it the same fallback style as `cancelled` (item #10), which uses an undefined token. Whoever fixes item #10 should cover `sleeping` too. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** files are under `apps/web/src/components/project-message-view/`. diff --git a/tasks/backlog/2026-05-01-ai-proxy-credential-hardening.md b/tasks/backlog/2026-05-01-ai-proxy-credential-hardening.md index 28f04cc3b3..57f96aece2 100644 --- a/tasks/backlog/2026-05-01-ai-proxy-credential-hardening.md +++ b/tasks/backlog/2026-05-01-ai-proxy-credential-hardening.md @@ -1,5 +1,7 @@ # AI Proxy Credential Hardening +> **Reconciliation 2026-10-05:** #2224 (`4f223d6fa`) now injects the renewed callback token (`packages/vm-agent/internal/acp/session_host_startup.go:365,402`), but it is still the full callback token: no proxy-scoped token, BaseURL origin check, or sentinel guard on credential sync. A related gap is tracked only as SAM idea `01M432G3276YZWCP3HEJ5B25J5`: an agent process that is already running keeps the token it started with as its AI-proxy key (`session_host_callback_token.go:20-23`). + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** Go tests for the main proxy injection branches diff --git a/tasks/backlog/2026-06-07-theme-switcher-playwright-coverage-gaps.md b/tasks/backlog/2026-06-07-theme-switcher-playwright-coverage-gaps.md index 36b1626c77..1d9da97f75 100644 --- a/tasks/backlog/2026-06-07-theme-switcher-playwright-coverage-gaps.md +++ b/tasks/backlog/2026-06-07-theme-switcher-playwright-coverage-gaps.md @@ -1,5 +1,7 @@ # Theme switcher — close Playwright audit coverage gaps +> **Reconciliation 2026-10-05:** Both specs this file extends are quarantined (`apps/web/tests/playwright/visual-audit-quarantine.txt:105-106`, since 2026-08-25), so new coverage there will not run in CI until `2026-07-17-stale-playwright-audit-specs.md` repairs them. + **Date:** 2026-06-07 **Origin:** Late-arriving task-completion-validator (WARN, 2 MEDIUM) on the merged three-way theme switcher (PR #1246, task diff --git a/tasks/backlog/2026-07-04-fix-flaky-tests-at-root.md b/tasks/backlog/2026-07-04-fix-flaky-tests-at-root.md index 2dfd80487a..138e0e7393 100644 --- a/tasks/backlog/2026-07-04-fix-flaky-tests-at-root.md +++ b/tasks/backlog/2026-07-04-fix-flaky-tests-at-root.md @@ -1,5 +1,7 @@ # Fix All Known Flaky Tests at the Root (No Retries) +> **Reconciliation 2026-10-05:** Two more load-sensitive tests surfaced in this week's PRs and are tracked nowhere else: `apps/api/tests/unit/routes/nodes-max-nodes-quota.test.ts` hits its 5 s timeout under a full parallel `pnpm test`, also on `main` (#2205), and `apps/web/tests/unit/components/admin/error-trends.test.tsx` failed once under CI load (#2199). None of this file's fixes shipped; none of its named tests failed in the 15 failed CI runs since 2026-09-30. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** item 1. The ToolCallCard test now awaits the final UI state diff --git a/tasks/backlog/2026-07-12-cf-container-wake-restore-hardening.md b/tasks/backlog/2026-07-12-cf-container-wake-restore-hardening.md index 230f8593f3..ce954425cd 100644 --- a/tasks/backlog/2026-07-12-cf-container-wake-restore-hardening.md +++ b/tasks/backlog/2026-07-12-cf-container-wake-restore-hardening.md @@ -1,5 +1,7 @@ # cf-container wake/restore hardening follow-ups +> **Reconciliation 2026-10-05:** All five open items are still open, but #2218 moved the cited code. Current locations: `skipOversizedUntracked` is at `packages/vm-agent/internal/server/session_snapshot_wip.go:128` and still uses `context.Background()` at `:150`; `absoluteControlPlaneURL` is at `session_snapshot.go:412`; the restore fetch is at `apps/api/src/durable-objects/vm-agent-container.ts:901`; the node-management TTL is at `apps/api/src/services/jwt.ts:189`; the circular import is at `apps/api/src/services/node-agent.ts:758-762`. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** diff --git a/tasks/backlog/2026-07-16-project-data-row-fault-isolation-audit.md b/tasks/backlog/2026-07-16-project-data-row-fault-isolation-audit.md index ae94bd6cfa..94402f2c33 100644 --- a/tasks/backlog/2026-07-16-project-data-row-fault-isolation-audit.md +++ b/tasks/backlog/2026-07-16-project-data-row-fault-isolation-audit.md @@ -1,5 +1,7 @@ # Audit project-data DO list reads for single-bad-row fault isolation +> **Reconciliation 2026-10-05:** A second tolerant row mapper already exists: `mapRows` in `apps/api/src/durable-objects/project-data/project-events-storage-helpers.ts:594`, used by five project-events modules since #1962, duplicates `apps/api/src/durable-objects/row-validation.ts:50`. The fault-isolation fix should consolidate onto one helper rather than add a third. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** diff --git a/tasks/backlog/2026-07-17-stale-playwright-audit-specs.md b/tasks/backlog/2026-07-17-stale-playwright-audit-specs.md index e598cad6af..c2708f6169 100644 --- a/tasks/backlog/2026-07-17-stale-playwright-audit-specs.md +++ b/tasks/backlog/2026-07-17-stale-playwright-audit-specs.md @@ -1,5 +1,13 @@ # Repair or retire stale Playwright audit specs (164 failures on main) +> **Reconciliation 2026-10-05:** No spec left quarantine this week. #2217 (b79136805) added the onboarding-wizard dismissal seed (`project-chat-recoverable-error-audit.spec.ts:108`) and 11 ACP auth/loopback-guidance tests to that spec. The ACP task reports them passing locally (`tasks/archive/2026-10-01-acp-auth-diagnosis.md:59`), but the spec is still quarantined (`visual-audit-quarantine.txt:80`), so none of its 13 tests run in CI. The 5 audit specs added this week are not quarantined, so the count is now 99 of 120. Still open: +> - Run the recoverable-error spec in CI mode and un-quarantine it. It still does not assert the "Send another message to retry" guidance (now `FailureCard.tsx:330`). +> - Repair or retire every other quarantined spec and delete its entry. This includes `knowledge-ui-audit` against the still-quarantined `agent-context-audit`, and the still-unverified nav-toggle and chat-file-viewer fixes. +> - `slice-e-theme-audit` ideas mocks. +> - A full corpus run with 0 failures. +> - Do `2026-09-23-playwright-audit-shell-mocks-crash.md` first. +> - The "Carried over 2026-09-30" items. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** a drift guard. PR #1908 (ddd991fc4) added diff --git a/tasks/backlog/2026-07-19-instant-launch-stuck-queued-on-disconnect.md b/tasks/backlog/2026-07-19-instant-launch-stuck-queued-on-disconnect.md index 2995f2c205..4267e603b3 100644 --- a/tasks/backlog/2026-07-19-instant-launch-stuck-queued-on-disconnect.md +++ b/tasks/backlog/2026-07-19-instant-launch-stuck-queued-on-disconnect.md @@ -1,5 +1,7 @@ # Instant-Session Launch Leaves Task Stuck `queued` When the Client Disconnects +> **Reconciliation 2026-10-05:** The "confirm cleanup of the two July tasks" sub-item can be dropped: production D1 shows both tasks `failed` by the stuck-queued sweep at 2026-07-19T01:20Z, with their workspaces and nodes `deleted`. Everything else is unchanged; still no test drives the `instant_persistence` branch (`apps/api/src/scheduled/stuck-tasks.ts:906,1277`). + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** diff --git a/tasks/backlog/2026-07-19-repo-history-bloat-cleanup.md b/tasks/backlog/2026-07-19-repo-history-bloat-cleanup.md index c545fde816..e59a9c044b 100644 --- a/tasks/backlog/2026-07-19-repo-history-bloat-cleanup.md +++ b/tasks/backlog/2026-07-19-repo-history-bloat-cleanup.md @@ -1,5 +1,7 @@ # Repo History Bloat: Purge Accidentally-Committed Agent State + Add Size Guard +> **Reconciliation 2026-10-05:** A new instance of the auto-commit problem, this time a behavior change rather than bloat. The vm-agent rewrites a SAM-managed block inside the tracked `.codex/config.toml` (`packages/vm-agent/internal/acp/codex_config.go:240-244`), and "chore: save agent work" auto-commits carried that rewrite to `main` inside #2217: `c9316fb3f` set `model_reasoning_effort` back to `"low"`, undoing the deliberate `2f78efcff` ("preserve shared Codex reasoning setting", `"medium"`). Four auto-commits on 2026-10-01 touched only that file, and `main` still says `"low"`. The blob guard and the rewrite decision are still open. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** diff --git a/tasks/backlog/2026-07-20-instant-ping-container-died-midsession.md b/tasks/backlog/2026-07-20-instant-ping-container-died-midsession.md index f4721ed0ba..946d7995ba 100644 --- a/tasks/backlog/2026-07-20-instant-ping-container-died-midsession.md +++ b/tasks/backlog/2026-07-20-instant-ping-container-died-midsession.md @@ -1,5 +1,7 @@ # Instant container died mid-session during production verification ping; no parent-side terminal path for dead-node children +> **Reconciliation 2026-10-05:** #2230 widened this. VM teardown now sets tasks to `sleeping` (`apps/api/src/services/session-sleep-teardown.ts:214-230`), and MCP `ACTIVE_STATUSES` (`apps/api/src/routes/mcp/_helpers.ts:322`) does not include it, so `stop_subtask` and `send_message_to_subtask` refuse a slept child (`routes/mcp/orchestration-comms.ts:146`), even though `sleeping → cancelled` is an allowed transition (`services/task-status.ts:37`). That part is tracked with the other `sleeping` gaps in `2026-10-05-sleeping-task-status-follow-ups.md`. The node-not-running refusal this file describes is unchanged (`orchestration-comms.ts:190-204`). + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** diff --git a/tasks/backlog/2026-07-25-admin-ai-proxy-orphaned-default-model.md b/tasks/backlog/2026-07-25-admin-ai-proxy-orphaned-default-model.md index 71ceda0341..4fca886aac 100644 --- a/tasks/backlog/2026-07-25-admin-ai-proxy-orphaned-default-model.md +++ b/tasks/backlog/2026-07-25-admin-ai-proxy-orphaned-default-model.md @@ -1,5 +1,7 @@ # Admin AI Proxy UI: Handle KV Default Model No Longer in Catalog +> **Reconciliation 2026-10-05:** A second trigger now exists. #2199 hides Responses-only models from `models[]` (`apps/api/src/routes/admin-ai-proxy.ts:106-108`), so an environment default of `gpt-6.1-sol` would show up orphaned in the picker. Still no orphan flag. + ## Problem `GET /api/admin/ai-proxy/config` returns `defaultModel` from the KV override diff --git a/tasks/backlog/2026-08-04-sleeping-status-renders-as-unknown.md b/tasks/backlog/2026-08-04-sleeping-status-renders-as-unknown.md index 0f57d139ec..520b158dbf 100644 --- a/tasks/backlog/2026-08-04-sleeping-status-renders-as-unknown.md +++ b/tasks/backlog/2026-08-04-sleeping-status-renders-as-unknown.md @@ -1,5 +1,12 @@ # A sleeping Instant session renders as "Unknown" (and often "Unhealthy") +> **Reconciliation 2026-10-05:** #2230 (ee80b0ee0) added `sleeping` → **Sleeping** with the muted palette to `statusConfig` (`packages/ui/src/components/StatusBadge.tsx:72-76`), plus a rendered-label test (`packages/ui/tests/StatusBadge.test.tsx:17`). Call sites pass the raw status, so sleeping workspaces and nodes now read "Sleeping" (`WorkspaceCard.tsx:98`, `NodeCard.tsx:142`, `NodeOverviewSection.tsx:52`). The docs caution paragraph was already removed by #1785 (00169b016). Still open: +> +> - A sleeping Instant node still shows **Unhealthy** next to it. It is written at `vm-agent-container-runtime.ts:178,213` and `services/session-sleep-teardown.ts:236`, and rendered at `NodeCard.tsx:143` and `NodeOverviewSection.tsx:53`. +> - The 375px and 1280px Playwright audit of sleeping workspace and node cards. +> - The audit of other statuses missing from `statusConfig` (shared with `2026-09-19-volume-status-badge-and-create-time-status.md`). +> - Optional: the shared `STATUS_LABELS` (`packages/shared/src/constants/status.ts:10`) is still unused and now duplicates `statusConfig`. + > **Reconciliation 2026-09-30:** still open. Re-observed on 2026-09-28 > (`tasks/archive/2026-09-28-instant-idle-sleep-wake.md:367`). The "audit the other missing > statuses" item overlaps the `StatusBadge` coverage work in diff --git a/tasks/backlog/2026-08-07-fix-stuck-task-sweep-pattern-complexity.md b/tasks/backlog/2026-08-07-fix-stuck-task-sweep-pattern-complexity.md index 75f5956aae..d0c331ea9d 100644 --- a/tasks/backlog/2026-08-07-fix-stuck-task-sweep-pattern-complexity.md +++ b/tasks/backlog/2026-08-07-fix-stuck-task-sweep-pattern-complexity.md @@ -1,5 +1,7 @@ # Fix stuck-task sweep pattern complexity failures +> **Reconciliation 2026-10-05: the same bug class is live in production again, from #2222.** `hasDurableRecord` (`apps/api/src/scheduled/stuck-task-live-runtime.ts:230-236`) binds `%"preservationKey":""%`, which is 51 to 69 bytes for real keys, over D1's 50-byte LIKE limit. The first record is written; from the next sweep on, the dedupe read throws, is caught with only a warning (`stuck_task.live_runtime_record_lookup_failed`), and a duplicate `platform_errors` row is inserted every five minutes. Production observability D1, 2026-10-05: task `01M44DA3EDRCGNATD4R3FT0Y7A` has 59 rows with the same key (01:36Z to 06:27Z) and task `01M42YQA8QPJQBW48KTDQFAHDE` has 9. The bound statement returns `LIKE or GLOB pattern too complex` (7500) in production, while a 48-byte pattern on the same rows succeeds. The better-sqlite3 unit test cannot see D1's limit. Suggested fix: match on an exact column or `json_extract(context, '$.preservationKey') = ?` instead of LIKE. This makes the open regression guard below (bound LIKE patterns stay at or under 50 bytes) urgent. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** the fix, in 8eed3b740 (PR #1765). The failing statement was the TaskRunner-mismatch diff --git a/tasks/backlog/2026-08-11-vm-agent-snapshot-degradation-union-mismatch.md b/tasks/backlog/2026-08-11-vm-agent-snapshot-degradation-union-mismatch.md index 95d94ab964..2922328404 100644 --- a/tasks/backlog/2026-08-11-vm-agent-snapshot-degradation-union-mismatch.md +++ b/tasks/backlog/2026-08-11-vm-agent-snapshot-degradation-union-mismatch.md @@ -1,5 +1,10 @@ # VM Agent Session-Snapshot Degradation Value Missing From API Union/Allowlist +> **Reconciliation 2026-10-05:** #2208 (7a9782c90) removed the usable-degraded allowlist from `scheduled/session-sleep-lifecycle-repair.ts`. Repair now selects and re-checks only `status='available'` with `degradation='none'` (`:114-115,140-141`), so leaving out `agent-context-skipped` and `wip-only` there no longer matters. The route allowlist (`routes/workspaces/session-snapshots.ts:49-57`) still covers every degradation value the vm-agent sends. Still open: +> +> - Decide `FILE_LOSS_DEGRADATIONS` (`services/failed-task-preservation.ts:449`) and record the decision in a comment. It omits `agent-context-skipped`, which keeps its file artifacts, so that is probably intended. +> - The cross-boundary search for other vm-agent-emitted enum/string literals whose allowlists have drifted. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** the four checked items, in 00169b016 (PR #1785). diff --git a/tasks/backlog/2026-09-23-resource-sparkline-gap-marker-has-no-colour.md b/tasks/backlog/2026-09-23-resource-sparkline-gap-marker-has-no-colour.md index 9858121def..44d3e7f199 100644 --- a/tasks/backlog/2026-09-23-resource-sparkline-gap-marker-has-no-colour.md +++ b/tasks/backlog/2026-09-23-resource-sparkline-gap-marker-has-no-colour.md @@ -1,5 +1,13 @@ # Undefined --sam-color-* tokens in apps/web (was: ResourceSparkline gap marker has no colour) +> **Reconciliation 2026-10-05:** Scope grew. The three new ACP cards use the Tailwind class +> `text-fg-secondary` (`apps/web/src/components/project-message-view/Acp{Permission,Form,Url}Card.tsx`), +> so it is now in 27 `apps/web` files (24 in the 2026-09-30 block, plus those 3). The separate +> `--sam-color-fg-secondary` custom property in `apps/web/src/components/debug/FailureCard.tsx` +> moved from `:173,214` to `:188,245`. The undefined `hover:bg-bg-hover` and `text-fg-accent` +> classes in four files (items M1/M2 of `2026-06-12-timeline-drawer-post-merge-fixes.md`) belong in +> the same sweep. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** PR #2185 (`2075aa074`) replaced the sparkline with the uPlot timeline in @@ -69,6 +77,6 @@ sample 28): the grey dot is present, the vertical line is not. `DOCS_SHOTS=1 npx playwright test docs-screenshots-sessions` and commit the refreshed docs image. Three places in `apps/www/src/content/docs/docs/guides/session-resources.md` describe the marker - as it renders *today* and must be updated together, or the guide half-reverts: + as it renders _today_ and must be updated together, or the guide half-reverts: the chart-legend bullet under "The detail timeline", the "Gaps and resets" section, and the Troubleshooting row about a long flat stretch. diff --git a/tasks/backlog/2026-09-25-split-permanent-session-recovery-refusals.md b/tasks/backlog/2026-09-25-split-permanent-session-recovery-refusals.md index 4d5a3b474f..e0a4878297 100644 --- a/tasks/backlog/2026-09-25-split-permanent-session-recovery-refusals.md +++ b/tasks/backlog/2026-09-25-split-permanent-session-recovery-refusals.md @@ -1,5 +1,12 @@ # Give permanent session-recovery refusals their own names +> **Reconciliation 2026-10-05:** Pointer correction only. #2230 (`ee80b0ee0`) rewrote +> `apps/api/src/services/session-recovery.ts` (`createRecoveryTask` became +> `reactivateSleepingTask`; the file is now 370 lines), so the 2026-09-30 block's +> `session-recovery.ts:~372-392` and `:456` now read `:188` (`placement_unsatisfiable`), `:207-208` +> (`placement_credentials_missing`) and `:275` (`session_recovery_placement_lookup_failed`). The +> reason codes and logic are unchanged; still open as described. + > **Reconciliation 2026-09-30 (weekly queue audit): partially shipped; still open.** > > - **Shipped:** diff --git a/tasks/backlog/2026-09-25-stopping-sleep-with-failed-projectdata-session.md b/tasks/backlog/2026-09-25-stopping-sleep-with-failed-projectdata-session.md index 725658324d..30fa913296 100644 --- a/tasks/backlog/2026-09-25-stopping-sleep-with-failed-projectdata-session.md +++ b/tasks/backlog/2026-09-25-stopping-sleep-with-failed-projectdata-session.md @@ -1,5 +1,14 @@ # A `stopping` sleep whose ProjectData session is already `failed` retries forever +> **Reconciliation 2026-10-05:** Still open; pointer correction. The failed-session predicate +> is now `apps/api/src/scheduled/session-sleep-lifecycle-repair.ts:51-55` (the `failed` arm at +> `:54`), and the retry when the session is not already closed is at `:167`. The recovery-workspace +> finalize with `agentSessionStatus: 'failed'` moved to +> `apps/api/src/durable-objects/task-runner/state-machine.ts:641-648`. #2223's bounded sleep +> episode does not cover a sleep stuck in `stopping`. Since #2230 a failed VM wake also fails the +> conversation's own task (`state-machine.ts:305`); see SAM idea `01M3MFDMZ5AS0BXPHZWS3CRFED` and +> `2026-10-05-sleeping-task-status-follow-ups.md`. + > **Reconciliation 2026-09-30:** still open (`session-sleep-lifecycle-repair.ts:48,171` unchanged). > Same class as SAM idea `01M3MFDMZ5AS0BXPHZWS3CRFED`, also unfixed: > `apps/api/src/durable-objects/task-runner/state-machine.ts:582-589` finalizes recovery workspaces diff --git a/tasks/backlog/2026-09-26-trustworthy-task-status.md b/tasks/backlog/2026-09-26-trustworthy-task-status.md index 3b074871e3..1c5f8271bf 100644 --- a/tasks/backlog/2026-09-26-trustworthy-task-status.md +++ b/tasks/backlog/2026-09-26-trustworthy-task-status.md @@ -1,5 +1,29 @@ # Make SAM Task Status Trustworthy +> **Reconciliation 2026-10-05:** PR #2230 (`ee80b0ee0`) added the task status `sleeping`. VM +> sleep teardown now writes it (`apps/api/src/services/session-sleep-teardown.ts:212-229`). The +> stuck-task sweep selects only `queued`/`delegated`/`in_progress` +> (`apps/api/src/scheduled/stuck-tasks.ts:326,343,360`), so a VM conversation task slept after +> #2230 can no longer get the day-7 `failed` verdict. This is from reading the code; production D1 +> has not confirmed it. Still open: +> +> 1. Instant (`cf-container`) tasks stay `in_progress` while asleep +> (`session-sleep-teardown.ts:212-213`). They still depend on +> `isHumanResumableConversationTask` (`apps/api/src/services/task-sleep-preservation.ts:206-236`), +> which still joins the `session_snapshots` row that the 7-day purge deletes. +> 2. VM tasks slept before #2230 were not backfilled. They stay `in_progress` on the old path until +> their snapshots age out. +> 3. Decide the end state of a `sleeping` task whose snapshot the purge retires. Today it stays +> `sleeping` with no bound: +> - the purge stops only the ProjectData session +> (`apps/api/src/scheduled/session-snapshot-purge.ts:141`); +> - `sleeping` can only move to queued/delegated/in_progress/cancelled +> (`apps/api/src/services/task-status.ts:37`); +> - a wake is refused as `sleeping_snapshot_missing` +> (`apps/api/src/services/session-recovery.ts:230`). +> 4. The production-shape regression test (a conversation task with no snapshot row). +> 5. Staging verification of #2153. + > **Status (2026-09-30 weekly reconciliation): partially shipped, moved back to backlog.** > > - **Shipped** in PR #2153 (`1cd4194db`, merged 2026-09-26, production deploy run 36280892213): diff --git a/tasks/backlog/2026-10-05-sleeping-task-status-follow-ups.md b/tasks/backlog/2026-10-05-sleeping-task-status-follow-ups.md new file mode 100644 index 0000000000..6e55bfd642 --- /dev/null +++ b/tasks/backlog/2026-10-05-sleeping-task-status-follow-ups.md @@ -0,0 +1,77 @@ +# Task status `sleeping` (#2230) is missing from the "active" status sets + +## Problem + +PR #2230 (merged 2026-10-04 23:37Z as `ee80b0ee0`, deployed by run 37245799681 at 2026-10-05 +00:00Z) added the task status `sleeping`. VM sleep teardown now writes it +(`apps/api/src/services/session-sleep-teardown.ts:214-230`; the task update is new in #2230). +Before #2230, teardown left the task status alone, so a slept VM conversation kept its earlier +status. Several consumers enumerate "active" statuses and were not updated, so slept VM tasks +now fall through them. Found by the 2026-10-05 weekly queue reconciliation +(`tasks/archive/2026-10-05-weekly-queue-reconciliation.md`). + +1. **Hidden from the active lists (verified in code).** `listAgentActivityTasks({ activeOnly: true })` + filters on `AGENT_ACTIVITY_ACTIVE_TASK_STATUSES`, which is `queued`, `delegated` and + `in_progress` (`apps/api/src/services/agent-activity.ts:16-20`, condition at `:178-182`). Its + callers are the dashboard's Active Tasks (`apps/api/src/routes/dashboard.ts:74`), the MCP tool + `list_project_agents` (`apps/api/src/routes/mcp/workspace-tools-direct.ts:47`) and the account + map's active view (`apps/api/src/routes/account-map.ts:155`). Slept VM conversations disappear + from all three. The dashboard card's "Sleeping" indicator + (`apps/web/src/components/ActiveTaskCard.tsx:46`) can now only show for Instant rows. At + 2026-10-05 05:15Z, production D1 held 2 tasks in `sleeping`. +2. **No agent can message a slept VM agent, and parents cannot stop a slept child (verified in + code).** MCP `resolveAgentTarget` refuses any target whose status is not in `ACTIVE_STATUSES`, which is + `queued`, `in_progress`, `delegated` and `awaiting_followup` + (`apps/api/src/routes/mcp/_helpers.ts:322`, check at + `apps/api/src/routes/mcp/orchestration-comms.ts:146`). It is used by `send_message_to_subtask` + and `stop_subtask` (`orchestration-comms.ts:253,449`), and `send_durable_message` applies the + same check (`apps/api/src/routes/mcp/mailbox-tools.ts:378`), so no agent in the project can + message a slept VM agent. `sleeping → cancelled` is an allowed transition + (`apps/api/src/services/task-status.ts:37`), so the stop refusal is not intended. +3. **A slept VM chat likely renders as provisioning (code reading, not reproduced).** The project + chat restore effect calls `setProvisioning` for every non-terminal status other than + `in_progress` (`apps/web/src/pages/project-chat/useProjectChatState.ts:536`), and `isTerminal` + does not list `sleeping` (`apps/web/src/pages/project-chat/types.ts:71-73`). Teardown also nulls + `executionStep`. Opening a slept VM conversation therefore probably shows the provisioning + indicator, sets `isProvisioning` (which suppresses auto-resume, + `apps/web/src/components/project-message-view/useConnectionRecovery.ts:269`), and polls the task + every 2 s while the chat is open (`useProjectChatState.ts:463-470`). The same effect is behind + `2026-08-04-instant-persistence-step-renders-as-provisioning-vm.md` and + `2026-09-09-chat-requests-reaped-task-404.md`. +4. **No status event for the transition (verified in code).** The write to `sleeping` records no + `task_status_events` row, while the wake back to `queued` does + (`apps/api/src/services/session-recovery.ts:151`). This widens the open gap in + `2026-02-27-tdf-1-task-state-machine.md`. + +Related, tracked elsewhere: + +- A failed VM wake now writes `failed` on the conversation's own task + (`apps/api/src/durable-objects/task-runner/state-machine.ts:305`) and fires the parent's + task-wait hooks (`:351-365`); before #2230 only a recovery row failed. From code reading. SAM + idea `01M3MFDMZ5AS0BXPHZWS3CRFED` and `2026-09-25-stopping-sleep-with-failed-projectdata-session.md`. +- A `sleeping` task has no terminal exit after the 7-day snapshot purge: item (3) of + `2026-09-26-trustworthy-task-status.md`. +- SessionHeader gives `sleeping` the undefined fallback style of `cancelled`: item #10 of + `2026-04-24-session-header-a11y-token-fixes.md`. + +## Implementation checklist + +- [ ] List every consumer that enumerates task statuses as "active", "live" or "non-terminal" + (API, MCP, web, scheduled sweeps) and decide per consumer whether `sleeping` belongs. Prefer + one shared constant over patching each list. +- [ ] Dashboard Active Tasks, `list_project_agents` and the account map include slept VM + conversations, with the Sleeping indicator. +- [ ] `send_message_to_subtask` and `send_durable_message` to a slept VM agent are accepted and + delivered through the durable wake path (or refused with an explicit, documented reason); + `stop_subtask` cancels a slept child. +- [ ] Opening a slept VM conversation renders the sleeping state, not provisioning, and does not + start the 2 s task poll. +- [ ] The transition to `sleeping` writes a `task_status_events` row. + +## Acceptance criteria + +- [ ] Each fix has a test that reaches it the way production does: put a VM task to sleep through + the real teardown path, then call the real route or tool (`.claude/rules/62`). Do not + hand-write `status='sleeping'` as the only setup. +- [ ] Each test has a control proving the same consumer still excludes terminal tasks. +- [ ] A behavioral web test covers the chat restore effect with a `sleeping` task.