You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reconcile an amended plan suffix at the runner-audited checkpoint and require explicit revision- and snapshot-bound continuation approval.
Preserve approval ancestry across committed continuation items; include reconciled completion in runner polling and publishing; refuse to skip completed work if an item changes without changing its ID.
Settle owed scope and safety findings before continuation reconciliation, keep review available on reconciliation refusal while marking approvals stale, and support approval/publication after a final-item scope finding.
Restrict checkpoint-owner amendments to declaring observed out-of-scope paths; completed work definitions remain immutable.
Bind continuation planning context to the audited checkpoint and preserve the original prompt byte-for-byte for ordinary plans.
Trigger ready publishing when a newly approved empty continuation completes an already-running task, without triggering on action replays or refusals.
Validate the complete continuation candidate schema before suffix-only semantic validation, and reject duplicate dependencies plus invalid, duplicate, or overlapping checkpoint-owner path declarations under the configured filesystem identity.
Keep continuation approval retryable during shutdown, including stale partial-body requests and configurations without an active runner.
A fresh high-effort independent full-diff review of origin/main...1321cb1 returned no actionable findings.
Exact-head GitHub CI is green: both standard test runs and the real-Docker isolation run passed.
A full local suite attempt reached Docker supervisor coverage but hit the repository's existing Docker cleanup timeout/hang; it is not counted as passing. The exact-head GitHub real-Docker job completed successfully instead.
Review status
Copilot: full candidate schema was not validated before completed items were sliced away. Fixed in ed9bc84; a 30-item-plan regression proves a 31st item cannot be persisted. Replied and resolved; nothing declined.
Copilot: checkpoint-owner declarations could duplicate or overlap paths. Fixed in ed9bc84; regressions cover add/delete collisions, parent/child overlap, duplicate rename sources, and case-folded aliases. Replied and resolved; nothing declined.
Copilot summary concern: completed items could carry renamed_from on a non-rename declaration. Reproduced and fixed in the same owner-declaration guard with regression coverage; nothing declined.
Independent review: duplicate dependencies on the completed prefix were filtered before suffix validation. Fixed in fa832c6; regression rejects a repeated completed dependency.
Copilot: a stale continuation approval finishing its body during shutdown could save a retry-blocking 409. Reproduced and fixed across a4eb7a3 and 8758c6e; regressions cover server shutdown, no-runner shutdown, and direct runner admission closure. Replied and resolved; nothing declined.
Independent review: completed checkpoint declarations could bypass canonical repository-path validation. Reproduced and fixed in 1321cb1; regression rejects the unsafe declaration before approval.
Final independent review: no actionable findings on exact head 1321cb1.
Final Copilot review: Findings: None on exact head 1321cb1; it confirms the shutdown finding is resolved.
Deferred follow-up issues: none identified.
Review-lesson audit
Full-candidate schema, path identity, and completed-prefix ownership findings are covered by the existing fail-closed validation and untrusted-path rules in AGENTS.md.
Shutdown/replay findings are covered by the existing outer-admission, partial-request shutdown, and retryable-503/idempotency rules in AGENTS.md.
The duplicate-dependency invariant was a one-off semantic gap and is now recorded as a targeted regression.
No new AGENTS.md rule is needed; no finding was declined.
Defer reconciliation when scope debt remains unresolved
web/server.ts:123
Owed scope evidence must also settle before reconciliation. If resumed P2 commits out-of-scope changes but its checkpoint save fails, importing an amendment to P2 makes this call reject its changed definition against the older P1 checkpoint. Resume then cannot reach the scope-debt branch or ItemExecutor.begin(), which would record P2's missing pause first. Defer reconciliation for scope debt as well as safety debt.
Addressed the summary-only scope-debt finding on 296deeb. The resume path now skips continuation reconciliation while any finding is owed, allowing the missing scope pause to settle first. The regression simulates a later out-of-scope result plus an edited completed item and verifies the resume API records the scope checkpoint before prefix reconciliation can refuse.
Validate renamed_from invariant on completed items
core/plan.ts:147
The completed prefix skips the v1 renamed_from check, but its checkpoint owner can still gain file declarations. An appended add for extra-a with renamed_from: 'extra-b' passes reconciliation when both paths were observed, and approval incorrectly counts both as declared. Validate this invariant on completed items before slicing or returning for an empty suffix, and add a regression rejecting this amendment.
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
Durable migrations, continuation authorization, and automatic publishing across recovery and shutdown require final human review and confirmation of passing exact-head CI.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validation
284d92ed5b1b0101c61723db1c693e680fb75d85(currentorigin/main, including Docs: refresh architecture progress #133).1321cb19233a8f723422cfc556e36b0b490fa984.git diff --checkpassed.origin/main...1321cb1returned no actionable findings.Review status
ed9bc84; a 30-item-plan regression proves a 31st item cannot be persisted. Replied and resolved; nothing declined.ed9bc84; regressions cover add/delete collisions, parent/child overlap, duplicate rename sources, and case-folded aliases. Replied and resolved; nothing declined.renamed_fromon a non-rename declaration. Reproduced and fixed in the same owner-declaration guard with regression coverage; nothing declined.fa832c6; regression rejects a repeated completed dependency.a4eb7a3and8758c6e; regressions cover server shutdown, no-runner shutdown, and direct runner admission closure. Replied and resolved; nothing declined.1321cb1; regression rejects the unsafe declaration before approval.1321cb1.Findings: Noneon exact head1321cb1; it confirms the shutdown finding is resolved.Review-lesson audit
AGENTS.md.AGENTS.md.AGENTS.mdrule is needed; no finding was declined.