FN-9028: guard automatic mission rollup status writers

Protect automatic mission and milestone status rollups with a durable writer-coverage ratchet.

- Add source-level coverage for every computed mission and milestone status writer.
- Verify core persistence and engine reconciliation preserve blocked and archived intent.
- Document shared rollup-ownership guard requirements.

Files changed:
 docs/missions.md                                   |   2 +-
 .../mission-rollup-status-writer-ratchet.test.ts   | 170 +++++++++++++++++++++
 .../mission-status-recompute-guard.test.ts         |  11 ++
 .../__tests__/postgres/mission-store.pg.test.ts    |  43 ++++--
 packages/core/src/missions/mission-types.ts        |   4 +-
 .../mission-autopilot-rollup-guard.test.ts         | 115 ++++++++++++++
 6 files changed, 331 insertions(+), 14 deletions(-)

Fusion-Task-Id: FN-9028

Fusion-Task-Lineage: 89b72b57-fc73-4268-a639-5edac05ff8f8

Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>
This commit is contained in:
gsxdsm
2026-08-13 16:01:57 -07:00
parent d39c0ae9eb
commit cb4ab3b6da
6 changed files with 331 additions and 14 deletions

View File

@@ -386,7 +386,7 @@ If validation cannot run (unexpected loop state, duplicate trigger, blocked vali
Mission `status` and `autopilotEnabled` transitions are atomically written with a mission activity event. The event records stable actor type/id, optional display name, source, and before/after values; unchanged values create no transition event. Dashboard controls identify an operator, tools identify an agent when they expose a sensitive mutation, and autonomous engine paths identify the system/autopilot.
Automatic hierarchy rollup, including terminal-task delivery reconciliation, owns only `planning`, `active`, and `complete` for missions and milestones. It never rewrites intentional `blocked` or `archived` status during hierarchy churn; a blocked mission stays blocked even after all milestones complete. Those statuses change only through resume, an explicit status write, or the mission clear-blocked path.
Automatic hierarchy rollup, including terminal-task delivery reconciliation, owns only `planning`, `active`, and `complete` for missions and milestones. It never rewrites intentional `blocked` or `archived` status during hierarchy churn; a blocked mission stays blocked even after all milestones complete. Those statuses change only through resume, an explicit status write, or the mission clear-blocked path. `packages/core/src/__tests__/mission-rollup-status-writer-ratchet.test.ts` inventories first-party computed status writers and requires each automatic writer to use the shared ownership guard.
## `autopilotEnabled` vs `autoAdvance`