Skip to content

🐛 [fix] github: pause runs when required reads fail - #24

Merged
EricTechPro merged 5 commits into
mainfrom
codex/github-read-failures
Oct 4, 2026
Merged

EricTechPro merged 5 commits into
mainfrom
codex/github-read-failures

Conversation

@EricTechPro

@EricTechPro EricTechPro commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Note

⏳ In review · round 1 · ✅ 6/6 AC · head 3668990

Depends on #23. This draft targets codex/approval-freshness so the diff contains only the GitHub failure handling change. Retarget to main after #23 lands.

Problem

A failed gh pr diff request became an empty diff, so the merge gate could miss a risky change and continue to migrations or merge. Other required reads could turn failures into an empty board, an open issue, or full API quota.

A run also had no shared local pause state. A worker could keep dispatching or writing after another worker lost the GitHub evidence it needed.

Solution

  • Route required reads in the merge, approval, planning, preflight, legacy runner, and issue-filing paths through a read-only helper. Each logical read gets three total attempts. Known query, authentication, or permission errors stop immediately.
  • Check response fields and completeness before using them. Reject partial GraphQL pages, incomplete diffs, malformed board data, and capped duplicate searches.
  • Save the first failure locally in a halt file shared across linked worktrees. Preserve work, claims, locks, and approval evidence. Future dispatch and guarded writes stop with exit 79.
  • Resume only after an explicit recovery check succeeds. A corrected query or fresh diff metadata can replace the failed read during recovery; the original failure stays in the archived record.
  • Attempt writes once. A lost merge response gets a readback of the merge state. Other uncertain write outcomes pause for inspection before restarting.
  • Teach workflow agents to report halted, stop queued work, and check the shared halt before writes. Install the helper with the existing script pack and include it in setup checks and repair.
  • Merge current main while preserving head-bound approval, upgrade recovery, and status-restoration protections.
  • Route duplicate/adopt writes through the shared repository pause check before each comment, label, or project mutation; preserve existing issue IDs and exit 79 for mid-run pauses.
  • Regression exercises existing pauses, pauses during discovery, labeling, and placement:12 failures on the unfixed router,66 assertions green after the fix.

Acceptance criteria

  • Three failed attempts pause the run; temporary failures can recover and later reads start with a fresh attempt count.
    ↳ tests/test_github_reads.py
  • Missing or incomplete evidence cannot permit dispatch, migration, or merge.
    ↳ tests/test_github_reads.py, tests/test-merge-gate.sh, tests/test-preflight.sh
  • Worktrees share the pause, keep local work and claims, and require checked recovery.
    ↳ tests/test_github_reads.py, including failed recovery and corrected-query recovery
  • The workflow stops queued work after a lane reports the pause.
    ↳ tests/test-workflow-halt.sh, 5 scenarios
  • Failed duplicate checks cannot create issues; uncertain writes are not replayed or reported as success.
    ↳ merge-gate, bug filer, refactor filer, collector, and legacy runner regressions
  • Existing safety checks pass and an independent review has no remaining findings.
    ↳ bash tests/run-safety.sh: 36 suites passed; all 8 GitHub checks passed on final head 3668990; setup 10 and install 17 scenarios passed after the helper-check follow-up; git diff --check passed

Iteration history

Lane Done Time Details
🔨 builder ✅ Oct 3, 11:24 PDT 39ce91b; 36 safety suites passed
🧐 reviewer ✅ Oct 3, 11:24 PDT Independent review cleared; read, approval, workflow, merge, and filer suites rerun
🔨 builder ✅ Oct 3, 11:29 PDT 3668990; helper check/repair coverage passed; independent delta review cleared

Risk

🟡 Medium · shared failure handling changes several CLI paths. Tests use offline GitHub stubs; live board, database, and release actions were not run.

Workflow cancellation takes effect at checkpoints. Already-running agent commands cannot be recalled. The legacy runner signals only workers it launched. Unknown write outcomes require checking GitHub before clearing the halt. Duplicate searches that reach the existing 200-item limit pause instead of assuming no match. Automatic database or other tool outage detection is outside this change.

- Verify trusted request and human reply for the current PR head and steps.
- Refresh stale blocked requests without treating them as approved.
- Pass 34 offline safety suites and independent review.
- Retry required reads up to three times and reject incomplete evidence.
- Preserve a shared local halt until explicit checked recovery.
- Stop dispatch and unsafe writes; reconcile uncertain merge outcomes once.
- Pass 36 safety suites and independent review.
- Include the required reader in setup checks and repair.
- Cover removal and repair of both safety helpers.
- Pass setup and install checks plus independent delta review.
@EricTechPro
EricTechPro changed the base branch from codex/approval-freshness to main October 4, 2026 06:18
EricTechPro and others added 2 commits October 3, 2026 23:22
Keep bounded evidence reads and exit79 while integrating head-bound approvals, upgrade recovery, task-status restoration, and PR author-note policy.

Co-Authored-By: Codex <noreply@openai.com>
Resolve the shared halt helper before router-owned paths and recheck before each comment, label, and project mutation. Preserve known issue numbers and exit79 on mid-run pauses, including placement.

Offline regression: unfixed router fails12pause assertions; fixed router passes66assertions covering preexisting pauses, read-time pauses, labeling, placement, and issue identity.

Co-Authored-By: Codex <noreply@openai.com>
@EricTechPro
EricTechPro marked this pull request as ready for review October 4, 2026 06:25
@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@EricTechPro
EricTechPro merged commit d6868fc into main Oct 4, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant