Skip to content

Pause Security after failed fixes and offer fixing - #582

Draft
JacobStephens2 wants to merge 7 commits into
issue-427from
issue-544
Draft

JacobStephens2 wants to merge 7 commits into
issue-427from
issue-544

Conversation

@JacobStephens2

@JacobStephens2 JacobStephens2 commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

Security run
  Ready issue → yield
  open failed/unfinished fix → skip, record Activity log reason
  audit → reproduce
    fixing allowed → dispatch one fix
    undecided → offer the command and [security].fix

Failed fix → keep Claim, exclude from Pickup
Closed fix issue → allow Security runs again

Record the pending dispatch before starting its Run so a rejected ending write cannot reopen Fencing. Preserve private edits when recording the ending. Share existing advice rendering for stderr and the Run notification, and document Fencing's cron line and pauses in the README and help.

Closes #544

Evidence

  • Before: a_failed_fix_keeps_its_claim_and_pauses_security_and_pickup_until_closed failed because the issue became security-fix,ready-for-agent. The offer test failed because stderr omitted both choices.
    After: Both pass, including public/private storage, failures before/after a PR, resuming after closure, and explicit suppression of the offer.
  • Before: Each reviewer's behavioral reproducer failed as written: Pickup took a fix after Claim creation failed; Security audited again after its failed-ending PATCH was rejected.
    After: All three named reviewer regressions pass and remain in the suite. A separate regression verifies preservation of private notes written during the fix. Successful fixes awaiting review continue to allow Security work.
  • Validation: cargo fmt --check and cargo clippy --all-targets -- -D warnings passed. cargo test --no-fail-fast passed: 1598 passed, 1 ignored across 40 test targets.

Test seams

  • End-to-end scenario harness: real binary and Git, fake GitHub and Harness; stderr, Activity log and Run notification.
  • Pass seam: Security gate order and choice of work through its in-memory adapter.

Review coverage

Fixed point: the fetched issue-427 tip, 1bff3a03089b81435fc456eb2a2f8089e394bde6. Independent Standards and Spec reviews each had one coverage follow-up. Both axes read 11 of the 12 changed files. tests/command_surface.rs was left unread by both independent reviewers: after their one coverage follow-up, full validation found its old Ready-issue help assertion needed the security-fix exclusion. The updated existing assertion passes its exact targeted test.

Standards: four findings addressed. Spec: two findings addressed. Every behavioral finding was run as written before deciding it; its regression remains.

Unaddressed findings

Standards

None.

Spec

None.

Merge Danger

Door: two-way

The change adds status lines to existing private records; it requires no data migration.

Blast Radius: Scheduling

Security-fix Claim retention, Security/Pickup scheduling, and the Security run's fixing offer. An unfinished dispatch stays paused if its ending cannot be recorded, until the Day shift closes its fix issue.

Built with codex · gpt-6.1-sol · xhigh

@JacobStephens2
JacobStephens2 marked this pull request as draft October 8, 2026 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant