Repository navigation
Pause Security after failed fixes and offer fixing - #582
Draft
JacobStephens2 wants to merge 7 commits into
Draft
JacobStephens2 wants to merge 7 commits into
JacobStephens2 wants to merge 7 commits into
Conversation
…. Please try a different model.) 2026-10-08T20:34:30Z, host thirdshift. Uncommitted work at the time of failure is included in this commit.
JacobStephens2
marked this pull request as draft
October 8, 2026 20:34
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Record the pending dispatch before starting its Run so a rejected ending write cannot reopen Fencing. Preserve private edits when recording the ending. Share existing advice rendering for stderr and the Run notification, and document Fencing's cron line and pauses in the README and help.
Closes #544
Evidence
a_failed_fix_keeps_its_claim_and_pauses_security_and_pickup_until_closedfailed because the issue becamesecurity-fix,ready-for-agent. The offer test failed because stderr omitted both choices.After: Both pass, including public/private storage, failures before/after a PR, resuming after closure, and explicit suppression of the offer.
After: All three named reviewer regressions pass and remain in the suite. A separate regression verifies preservation of private notes written during the fix. Successful fixes awaiting review continue to allow Security work.
cargo fmt --checkandcargo clippy --all-targets -- -D warningspassed.cargo test --no-fail-fastpassed: 1598 passed, 1 ignored across 40 test targets.Test seams
Review coverage
Fixed point: the fetched
issue-427tip,1bff3a03089b81435fc456eb2a2f8089e394bde6. Independent Standards and Spec reviews each had one coverage follow-up. Both axes read 11 of the 12 changed files.tests/command_surface.rswas left unread by both independent reviewers: after their one coverage follow-up, full validation found its old Ready-issue help assertion needed thesecurity-fixexclusion. The updated existing assertion passes its exact targeted test.Standards: four findings addressed. Spec: two findings addressed. Every behavioral finding was run as written before deciding it; its regression remains.
Unaddressed findings
Standards
None.
Spec
None.
Merge Danger
Door: two-way
The change adds status lines to existing private records; it requires no data migration.
Blast Radius: Scheduling
Security-fix Claim retention, Security/Pickup scheduling, and the Security run's fixing offer. An unfinished dispatch stays paused if its ending cannot be recorded, until the Day shift closes its fix issue.
Built with codex · gpt-6.1-sol · xhigh