Commit Graph

4214 Commits

Author SHA1 Message Date
Fusion Agent
bf147d6ade test(FN-WF): prove Code Review remediation produces named steps that run and merge
You asked why I could not prove it. Because I kept trying to prove it THROUGH S05,
which asserts a different property — no merge without a current approval — and
reaches it by racing the background auto-merge. That race is the source of its
intermittency, and it has nothing to do with remediation.

The behaviour itself does not need that race. `pipeline-remediation.pipeline.test.ts`
drives it explicitly, turn by turn, and asserts three things in order:

  1. a Code Review REVISE appends a step carrying `remediation` metadata — named
     work derived from the reviewer's findings, not a bare bounce;
  2. no step is left pending — the appended work is actually executed, which is the
     failure mode that previously left it `pending` forever;
  3. `mergeDetails.mergeConfirmed` — the loop terminates instead of merely looking
     alive.

Five consecutive runs, five passes.

REVERTED in the same change: the `workflow-graph-foreach` relaxation that let a
sequential region grow past its pinned step count. I justified it with a measured
failure, but that measurement came from a configuration since fixed elsewhere and no
longer reproduces — with the growth removed the full lane passes 89/89, including
this new drive. An engine change to a core execution primitive that no failing test
requires is dead weight on a hot path, so it goes rather than staying "just in case".
A future case that genuinely needs growth must arrive with a test that fails without it.

pnpm lint 0 errors, test:gate, verify:fast, and three consecutive full runs:
133.1s, 136.0s, 134.2s of the 150s budget.
2026-08-25 19:46:49 +00:00
Fusion Agent
4750b689ea refactor(FN-WF): classify workflow gates structurally, not by display name
Three defects of the same family, all of which let a LABEL decide BEHAVIOUR.

1. `workflowNodeRequiresWorktree` matched `/(?:^|\b)(?:review|verification)(?:\b|$)/i`
   against `config.name`. A deterministic verification gate — exit codes only, no
   mutation path — was therefore classified write-capable purely because it is
   called "Verification", and the review seal refused it on every post-approval
   replay. It now keys on `reviewKind`, `workflowAction` and the optional-group id.

2. The review seal's `isCodeReview` also matched `/code review/i`, so its central
   question — "is this THE review that seals the tree?" — depended on a name an
   operator may change. Renaming the gate to "Final Review" would have silently
   stopped it being recognised while every other gate kept being sealed against it.
   That is why the rename was blocked; it no longer is.

3. `getRunningOptionalGateBadge` gated on a closed list of three step ids, so gates
   a workflow adds showed no badge at all: the operator watched an apparently idle
   card until "Merging" appeared at the end. It now asks whether the running step
   is a lane-owned gate.

Also: task cards arrive in the review lane with their step list EXPANDED, as they
already were in in-progress. The initial state is computed once per mount and a
column move remounts the card, so a card the operator had open collapsed itself
exactly when its review gates started running.

Lifecycle-column ratchet ceilings lowered to the measured counts (todo 64→12,
in-progress 197→72, in-review 213→28). They had drifted so far above reality that
the ratchet was inert for the thing it exists to stop — the TaskCard guard that hid
review-lane progress was one of those tolerated sites, and it had no way to notice.

Tests updated to the new truth rather than around it: the seal ratchet now asserts
a deterministic gate must NOT be write-capable, and the badge tests assert the
expanded list.

pnpm lint 0 errors, test:gate, verify:fast, dashboard 695, core 38, engine 8, and
three consecutive smoke runs: 122.4s, 126.3s, 124.8s of the 150s budget.
2026-08-25 12:31:43 +00:00
Fusion Agent
f22ebca62a test(FN-WF): treat a revoked merge gate as the deferral it is, and stop the engine before clearing globals
Two harness correctness fixes, both found chasing the S05 flake.

REVOKED GATE. `MergeGateRevokedError` escaped the graph dispatch and failed the
scenario. It is a DEFERRAL, not a failure — FN-180's own contract, and the reason
it carries a dedicated error type so callers cannot convert a gate lost mid-merge
into a retry or a failed park. It fires when a merge admitted on an earlier turn
reaches its ref-advance fence after a REVISE has already returned the card to
in-progress: the engine refusing correctly while the driver races it. The dispatch
now swallows ONLY that type, by NAME rather than by import, because importing
merger-errors.js would break the pre-FN-180 differential run the harness self-test
enforces.

TEARDOWN ORDER. `dispose` reset the shared mock registry and cleared
`activeSessionRegistry` BEFORE stopping the engine, stranding in-flight sessions on
default scripts mid-teardown and hiding them from the liveness checks the stop path
consults. Both are process-global, so the damage landed on whichever file ran next.

Together these took S05 on builtin:coding-ideas-v2 from failing 3 runs out of 3 to
2 out of 6 — a real reduction, and not zero, so it is still not shipped. S05 stays
on its original workflows, where the lane is green four consecutive full runs:
122.4s, 126.6s, 124.0s, 116.9s of the 150s budget.

builtin:coding-ideas-v2 remains at 18 of 19 scenarios plus the multi-repository
workspace drive.
2026-08-25 05:38:46 +00:00
Fusion Agent
19c3981a50 feat(FN-WF): cover S07 on V2 by releasing its operator park in recovery
Named remediation parks an unactionable review rejection as `awaiting-approval`
with `paused: true` — deliberately, because there is no actionable finding to
derive work from, so a human must decide. S07's recovery driver only re-drove the
graph, and a drive cannot move a paused card, so the declared recovery could never
reach a merge and the scenario read as a wedge.

The recovery now performs the operator's half of its own contract ("operator
retry, or the cause disappears") before driving: it releases an EXPLICIT
awaiting-approval park and then approves through the restored graph session. The
merge that follows is still fully asserted, so this widens no assertion.

builtin:coding-ideas-v2 covers 18 of 19 scenarios plus the multi-repository
workspace drive. Three consecutive full runs: 123.6s, 125.7s, 126.1s of 150s.

S05 stays on its original workflows. It passes 22/22 when its file runs alone but
fails intermittently under full-lane load, and settling in-flight merges at every
graph dispatch — before and after, with a 10x larger drain bound — did not remove
it. That points at cross-file interference rather than the merge race it first
resembled, and an unexplained flake is not something to ship.
2026-08-25 04:22:49 +00:00
Fusion Agent
eba8c1052d feat(FN-WF): let a foreach cover steps appended after expansion
A sequential foreach region pinned its step count at expansion and never revisited
it, so work appended afterwards never received an instance. That is what made
named remediation unusable: `review-remediation-steps` derives fix-it steps from a
reviewer's findings and appends them to `task.steps`, and every one of them stayed
`pending` forever — the merge boundary's foreach coverage never completed and the
card terminalized with `merge-boundary-unproven`.

The region now re-reads the live step list per iteration, exactly as the existing
status probe already did, and extends its bound when the list has grown. Growth is
the ONLY relaxation: the pin still governs every step it already covers, a
shrinking list is ignored, and `pinnedStepCount + 64` stops a pathological appender
spinning the region. The worktree-isolated path keeps the strict pin, because its
instances are allocated up front.

Other workflows are unaffected by construction — with no appended steps the bound
never moves and the loop is byte-identical.

builtin:coding-ideas-v2 accordingly enables named remediation on BOTH review gates:
a rejected review now returns the card to in-progress carrying steps that name what
must be fixed, with the PROMPT.md File Scope widened to the files they touch,
instead of an unchanged checklist.

Three consecutive full runs: 122.1s, 124.5s, 122.9s of the 150s budget.

S05 and S07 stay on their original workflows: with named remediation live, S05 is
intermittent on V2 under full-lane load and S07's park oscillates instead of
settling. Both are visible, neither is shipped green.
2026-08-25 03:46:32 +00:00
Fusion Agent
f193c196e3 fix(FN-WF): seal on gate presence, and settle in-flight merges between turns
REVIEW SEAL. The already-satisfied carve-out tested the result's STATUS, which is
unanswerable at that point: the optional group writes a fresh `pending` row when it
STARTS, overwriting the terminal record before the check runs. Measured on S13, the
replayed documentation gate showed `pending` with `priorAttempts=failed/failed/...`
and its earlier `passed` was simply gone, so the carve-out never fired and a
conflicting merge left the card cycling instead of retrying.

Presence of a result row is the correct signal, and it is exact rather than lax:
these gates run UPSTREAM of Code Review, so a current approval proves the gate
already ran in this episode, while a gate that has genuinely never run has no row
at all and is still refused. S13 ("scripted merger resolves a conflict") now passes
on builtin:coding-ideas-v2.

HARNESS RACE. `runProductionTurn` now drains any in-flight merge before dispatching.
A REVISE returns the card to in-progress, and a merge admitted on an earlier turn
then hits its ref-advance fence and is correctly revoked with "task is in
'in-progress', must be in 'in-review'" — the engine behaving properly while the
driver raced it. The drain is a bounded event-loop yield, not a wall-clock wait, so
it costs nothing when no merge is in flight and cannot mask a hang.

builtin:coding-ideas-v2 now covers 18 of 19 scenarios plus the multi-repository
workspace drive. Three consecutive full runs: 129.0s, 122.5s, 125.1s of 150s.

S05 ("code review revisions require a current approval") stays on its original
workflows: it remains intermittent on V2 under full-lane load, and a flake is not
something to ship.
2026-08-25 03:11:56 +00:00
Fusion Agent
d976ed4118 fix(FN-WF): remove duplicate V2 edges and match the review seal on group ids
Two defects, and the first explains most of what looked intractable.

DUPLICATE EDGES. The V2 IR re-pushed `completion-summary -> code-review`,
`code-review -> merge-gate` and the code-review rework, all of which it already
inherits, so the graph carried each of them twice. A duplicated success edge out
of a review gate is a second competing traversal of the same lane. Pushing only
the genuinely new edges fixed S05 ("Code Review REVISE twice, then approve") and
S17 ("restart recovery resumes each recorded stage exactly once") on
builtin:coding-ideas-v2 together — both had been chased through remediation
policy, rework targets and mock routing, and neither was ever about those.

REVIEW SEAL ID MATCH. The already-satisfied carve-out compared the failing node's
own id against recorded results, but a gate runs as its optional group's inner
template node (`documentation-delivery-step`) while its result is recorded under
the group (`documentation-delivery`). The comparison therefore never matched, and
the carve-out was dead code for every optional group — precisely the shape it
exists to protect.

builtin:coding-ideas-v2 now covers 18 of the 19 declared scenarios plus the
multi-repository workspace drive. Three consecutive full runs: 124.7s, 131.5s and
127.3s against the 150s budget.

S13 ("scripted merger resolves a conflict") remains on its original workflows: it
still replays the documentation gate after a conflicting merge, and the base S05
showed one cross-file failure at full-lane scale that does not reproduce when the
file runs alone. Neither is shipped green.
2026-08-25 02:28:20 +00:00
Fusion Agent
324c67d16c fix(FN-WF): make V2 rework converge, and cover S07
Root cause of the stalled rework: named remediation (`review-remediation-steps`)
is UNAVAILABLE to a foreach-executed workflow. The parse node preserves an
appended step and then answers `already-expanded`, because the foreach is PINNED
to the step list it first expanded — so a step appended afterwards never receives
an instance and stays `pending` forever. The merge boundary's foreach coverage
then never completes and the card terminalizes with `merge-boundary-unproven`
("no pre-merge node result recorded"), measured on S05 as
`steps=["Implement deterministic pipeline output:pending"]` in the review lane.

`implementationOnlySteps` + `preserveRemediationSteps` on the parse node is the
pair that selects that mechanism, so V2 no longer sets it and keeps the inherited
"reopen-trailing" policy, which re-runs instances the foreach already owns. The
planner constraint is unaffected: it lives in the seam PROMPT, while
`implementationOnlySteps` only audits leakage by its own design.

Code Review rework accordingly returns to `code-review` as the inherited graph
does. Stated cost: a Code Review REVISE no longer regenerates the documentation.
Verification rework still re-enters `verification` and replays the doc node with
it, because a failing test needs re-running rather than new implementation steps.

Also fixes the smoke mock: gate routing intercepted the writable Code Review
Remediation session and returned a bare approval, skipping the branch that
completes the steps a REVISE reopened.

S07 ("unactionable Code Review rejection") now passes on builtin:coding-ideas-v2,
bringing it to 15 of 19 scenarios plus the multi-repository workspace drive.
S05 still does not converge and stays on its proven workflows.

Lane green twice: 6 files, 82 tests, 19/19 scenarios, 115.1s and 118.4s of 150s.
2026-08-25 01:58:00 +00:00
Fusion Agent
d866617f40 test(FN-WF): complete every pending step in the smoke executor mock
The mock marked only step 0 done. A review gate that appends named remediation
work (`review-remediation-steps`) adds steps beyond the first, and a workflow whose
parse node disables trailing-step reopening depends on exactly that mechanism to
give a bounced card something to execute — so those steps stayed pending forever.
The mock now completes every pending step, as a real executor does.

This is necessary but not sufficient for S05 on builtin:coding-ideas-v2: the
remediation step IS appended and still ends pending
(`["Implement deterministic pipeline output:done",
   "Fix: The disposable fixture needs the scripted remediation commit.:pending"]`),
so the bounced card is not re-dispatched through an executor session that can
complete it. S05 and S07 therefore stay on their proven workflows rather than
shipping red.

Lane green: 6 files, 81 tests, 19/19 scenarios.
2026-08-25 01:30:20 +00:00
Fusion Agent
cfe65527ca fix(FN-WF): make the smoke mock honest, and match V2 remediation to its reopen policy
The pipeline-smoke executor mock routed a gate turn by its TOOL SURFACE. Code
Review is a writable inline-fix review, so on a review-column workflow it arrives
with the task-update tool, fell through to the implementation branch, and ended by
emitting a blanket APPROVE — silently discarding the scenario's scripted verdict.
Measured: S07 scripts `codeReviewModes: ["empty-revise"]` and the persisted result
was `code-review:passed:APPROVE:code`, which then sealed the tree and blocked the
replay of Documentation & Delivery. Two failures downstream of one mislabel.

Gate turns are now routed by the step they name (`Execute the workflow step "X"`),
which is present on every gate turn and absent from the implementation session.
Non-review gates approve without consuming review verdicts.

This matters beyond the two scenarios it fixes: the mock was manufacturing false
greens. S05 on builtin:coding-ideas-v2 passed only because its scripted
"revise twice, then approve" was being auto-approved, so the workflow's rework path
was never exercised at all. Making the mock honest reveals that path as genuinely
broken, and S05/S07 accordingly move back to the workflows where they are proven.
A green that came from a mislabel is worse than a red.

Also aligns V2's code-review remediation with `review-remediation-steps`. That is
not cosmetic symmetry: the workflow sets the parse node's `implementationOnlySteps`
+ `preserveRemediationSteps`, which `resolveStepReopenPolicy` reads as reopen
policy "none". The two are a matched pair — with trailing-step reopening disabled,
the inherited `pre-merge-remediation` returns the card to in-progress with every
step already done and nothing to execute. The earlier revert of this change blamed
the wrong cause: the empty `git merge --squash` ref came from the merger mock
resolving `task.branch`, since fixed at the harness.

Lane green: 6 files, 81 tests, 19/19 scenarios, 107.7s and 107.1s against 150s.
Remaining V2 gap, stated rather than hidden: the Code Review REVISE -> rework path
does not converge ("did not persist completed implementation-step projection"), so
S05, S07, S13 and S17 stay on their original workflows.
2026-08-25 01:21:22 +00:00
Fusion Agent
975d8a0ed2 test(FN-WF): stop non-review gates consuming a scenario's scripted review verdicts
Two places in the pipeline-smoke mock treated any readonly, non-Plan-Review turn
as a Code Review, so on a review-column workflow the Documentation & Delivery gate
ate the verdict scripted for Code Review. S07 scripts
`codeReviewModes: ["empty-revise"]` to exercise an unactionable Code Review
rejection; the card instead died with `documentation-delivery: failed: REVISE`
before Code Review ever ran.

- `emitReview` classified everything that was not Plan Review as "code".
- The executor script forces `emitReview(context, "code")` whenever a readonly
  session coincides with scripted `codeReviewModes` — and a documentation gate is
  readonly too, so it took that branch as well.

Both now identify the executing step from the workflow-step system prompt
("You are a workflow step agent executing: <name>") and exclude the known
non-review gates. Detection is by EXCLUSION rather than an allow-list on purpose:
the real reviewer prompt does not carry the literal "Code Review", so allow-listing
silently approves every genuine review instead — measured, it turned S07 green on
`builtin:coding-ideas` for the wrong reason.

S07 on builtin:coding-ideas-v2 now gets past that misattribution and reaches the
review seal instead, which is a different and still-open problem, so the scenario
stays on its original workflows. Lane is green and faster than the previous
matrix: 6 files, 82 tests, 19/19 scenarios, 97.2s and 100.3s against the 150s
budget.
2026-08-24 21:20:23 +00:00
Fusion Agent
94f660e672 fix(FN-WF): stop a failed merge stranding review-column tasks, and widen V2 coverage
Two review-seal defects, both found by running builtin:coding-ideas-v2 through the
whole scenario matrix rather than the nominal path alone.

1. A DETERMINISTIC verification gate was sealed as write-capable. It needs a
   worktree because it runs the project's test/build commands there, but it only
   reads the tree — `verification-gate.ts` has no mutation path.
   `workflowNodeRequiresWorktree` conflates "needs a worktree" with "writes", and
   its inline-fix branch matches on the node NAME (`/review|verification/i`), so a
   gate named "Verification" was refused after any approval.

2. A gate that already `passed` or was `skipped` was refused on replay. A
   post-approval requeue — a merge conflict, a transient merge failure — walks the
   graph back through gates whose output is already inside the approved tree.
   Refusing them converts a retryable merge into a terminal wedge; re-running them
   would rewrite the tree the review approved. "Already produced, already
   reviewed" now resolves as satisfied. A gate with no result still hits the
   refusal, which is the case the seal exists for.

Measured by pipeline-smoke S13, where a conflicting merge left the card cycling on
documentation-delivery with `workspace-review-seal-required` instead of retrying.

Coverage: builtin:coding-ideas-v2 now runs 16 of the 19 declared scenarios plus
the multi-repository workspace drive, up from 1. The duration budget is
re-baselined 90s -> 150s, and the workload growth is itemised in docs/testing.md:
17 added scenario executions and a second project shape, 124.95s measured against
76.9s for the smaller matrix. Three consecutive full runs: 116.9s, 115.6s, 119.8s.

NOT covered, deliberately and stated rather than hidden: S07 (unactionable review
rejection), S13 (scripted merge-conflict resolution) and S17 (restart resilience)
still run on the original workflows only. S07 and S13 do not converge on V2, and
S17 produced one intermittent post-merge failure in four full-lane runs — a flake
is not something to ship or to paper over, so those three stay uncovered until
they are understood.
2026-08-24 16:21:30 +00:00
Fusion Agent
f4487b4b31 test(FN-WF): prove the pipeline end to end on multi-repository workspaces
The smoke lane now drives a workspace task on builtin:coding-ideas-v2 from the
Ideas intake to `merged-done`, alongside the existing single-repository coverage.
6 files, 65 tests, 19/19 scenarios, 77.1s of the 90s budget.

Two fixture defects stood between the harness and that proof, both of the same
shape: a workspace task legitimately has NO task-level `branch` — each repository
owns one under `workspaceWorktrees[repo].branch`.

- The scripted merger was handed `task.branch ?? ""`, so it ran
  `git merge --squash` on an empty ref ("merge:  - not something we can merge"),
  surfacing only as the generic "Workspace repository repo1 could not land".
- Resolving the branch at INSTALL time was still wrong: the merge is attempted in
  the same turn as the first install, before acquisition has created any
  per-repository worktree. The scripts now receive an async getter that reads the
  live task when the merger actually runs, so ordering cannot make it stale.

This also corrects an earlier misattribution recorded in the previous commit: the
land failure was NOT a missing `repositoryScope`. A probe showed the scope
confirmed, the review evidence recorded, and `workspaceWorktrees.repo1.branch`
populated — the harness simply never passed that branch to the merger.

The workspace path is now measured, not inferred: plan, plan-review, parse,
verification, documentation-delivery, completion-summary, code review
("All 1 modified in-scope sub-repo(s) approved") and the per-repository land all
run, with `mergeDetails.mergeConfirmed` asserted on the persisted row.
2026-08-24 15:29:07 +00:00
Fusion Agent
c8b2b10732 test(FN-WF): add multi-repository workspace support to the pipeline smoke harness
The smoke lane was single-repository only, so the workspace path — the one that
actually broke in production — was never driven end to end. Adds:

- `createPipelineWorkspaceFixture`: a real workspace project whose ROOT is a plain
  container (no Git metadata) holding per-repository checkouts with their own
  origins and a `.fusion/workspace.json`. The single-repo fixture cannot express
  this shape, because there the root and the repository are the same directory —
  which is why a node resolving the root as a worktree still worked by accident.
- `PipelineGitFixture.integrationRepoDir`: integration git (`rev-parse main`,
  ancestry, status, worktree prune) now targets a repository rather than the
  project root. Single-repo fixtures answer `repoDir`, so nothing changes there.
- `PipelineSmokeHarness.create(pg, { workspace: true })` and an optional confirmed
  `repositoryScope` on `createPipelineTask`, which workspace acquisition requires
  before any write-capable node runs.
- The executor mock now resolves the repository it can commit in. Its
  `existsSync(cwd/.git)` guard skipped the whole implementation block on a
  workspace session (cwd is the task directory), so no commit existed and Code
  Review reported "No changes — not reviewed" on an untouched scoped repository.

Measured with these in place, a workspace task on builtin:coding-ideas-v2 now
clears plan, plan-review, parse, verification, documentation-delivery and code
review ("All 1 modified in-scope sub-repo(s) approved"). That is the direct
end-to-end confirmation that the FN-158-shaped session-boundary fix works: the
write-capable documentation gate runs in a workspace instead of dying with
"Refusing to start coding agent in incomplete worktree".

It then fails at the workspace LAND step with "Workspace repository repo1 could
not land". The underlying cause is written to the task log rather than stdout and
is not yet identified, so the end-to-end workspace drive test is deliberately NOT
committed: shipping it red would put a permanently failing test in the lane, and
weakening it to assert only the progress reached would be appeasement. Mono-repo
coverage is unchanged and green (63 tests, 19/19 scenarios).
2026-08-24 14:18:50 +00:00
Fusion Agent
9e76393cfa fix(FN-WF): make review-column workflows actually merge
A required pre-merge step is not necessarily a content review. Review-column
workflows also require a deterministic verification gate (exit codes) and a
documentation/delivery gate; neither records a `reviewInputFingerprint` because
neither binds a diff. `evaluatePreMergeApprovals` compared them against the merge
content anyway, classified both as `unprovable-content`, and `canMergeTask`
answered "task has no provable approval for the content being merged" — an
unsatisfiable gate, so NOTHING could ever merge on such a workflow. Cards reached
the merge, were refused, and looped through verification-remediation.

The carve-out is narrow: a step that is neither `code-review` nor a
`reviewKind: "code"` result AND recorded no fingerprint of its own is not
diff-bound and passes on its status. A content review that DID record a
fingerprint is still compared, and a code review missing one is still refused, so
FN-180's guarantee is untouched. Reverting the carve-out fails the new tests.

builtin:review-gated-coding carried the identical latent defect and never reached
its merge to expose it.

Proven end to end: pipeline-smoke now drives S01 on builtin:coding-ideas-v2 from
the Ideas intake through promotion, planning, plan review, implementation,
verification, documentation, summary and code review to `merged-done` —
63 tests, 19/19 scenarios, 74.7s against the 90s budget. S01 keeps that workflow
permanently, because all five defects fixed in this effort passed structural
review and only a real card reaching `merged-done` exposed them.
2026-08-24 10:07:22 +00:00
Fusion Agent
3efdc42ad4 fix(FN-WF): repair the review-gated planning seam, prompt, and workspace gate boundary
Four defects found by pointing the FN-182 pipeline-smoke harness at a review-gated
workflow. Three of them also affected builtin:review-gated-coding, where they had
been latent because that graph dies earlier on the review seal.

1. `planning-implementation-only` is a PROMPT key, never an executable seam.
   `resolveSeamName` accepts exactly seven seam names and throws
   `Unsupported workflow seam` otherwise, so the `plan` node threw on every task:
   the graph failed at `plan`, the card bounced to todo, and the board reported
   "Execution dispatch refused — task is still unplanned" — pressing Start
   appeared to do nothing. The seam is now `planning`; only the prompt differs.

2. The seam prompt contradicted itself. It was the full triage prompt — whose
   template MANDATES `### Step {N-1}: Testing & Verification` and
   `### Step {N}: Documentation & Delivery` — plus one appended line asking for
   neither. The template won, so tasks emitted both steps and ran them in
   in-progress, duplicating the review gates. The template region is now removed
   and replaced by an explicit prohibition. The parse node's
   `implementationOnlySteps` is not a backstop: it only audits, by design.

3. `requireImplementationOnlySteps` was inert when set on an already-built
   plan-review node: the prompt is assembled by `planReviewOptionalGroupNode`
   and no engine code reads the flag, so the reviewer never received its
   criterion. Both derived workflows now call `applyImplementationOnlyStepReview`.

4. Write-capable graph nodes declared no session boundary on workspace tasks, so
   the single-repo assertion resolved the task DIRECTORY (a container of per-repo
   worktrees, no `.git`) as a worktree and refused: "Refusing to start coding
   agent in incomplete worktree", failing the gate before a verdict and requeuing
   the task. FN-158 gave Code Review the `workspace-task-dir` boundary but not the
   generic prompt path. Extracted as a pure `resolveGraphNodeSessionBoundary`.

Also reorders coding-ideas-v2 to `verification -> documentation-delivery ->
completion-summary -> code-review -> merge`. The summary escapes the review seal
(readonly) but still acquires a worktree, and any node between the review and the
merge invalidates FN-180's review-diff fingerprint.

Known incomplete: builtin:coding-ideas-v2 still does not converge end to end —
pipeline-smoke S01 reaches merge and is refused with "task has no provable
approval for the content being merged". Not yet root-caused; the workflow must be
treated as unusable until it is.
2026-08-24 06:39:28 +00:00
Fusion Agent
b818eb20ad feat(FN-WF): add the Coding (Ideas) V2 workflow with review-column gates
Selectable built-in `builtin:coding-ideas-v2`. It clones the Coding (Ideas) IR
without mutating it, so the manual `ideas` intake (`autoTriage: false`) and the
whole board shape are unchanged, and moves testing and documentation out of the
planner's implementation checklist into visible review-column gates:

  in-progress : steps            = implementation only
  in-review   : verification -> documentation-delivery -> code-review
                -> completion-summary -> merge-gate -> merge

Ordering is load-bearing, not cosmetic. `execute-workflow-graph.ts` refuses any
write-capable node once a Code Review APPROVE exists, so that a passed review
seals the tree and nothing unreviewed reaches main. `verification-step` and
`documentation-delivery-step` are both write-capable and therefore run BEFORE
the review; `completion-summary` is `toolMode: "readonly"` and runs after it, so
the card blurb describes the state that was actually approved.

Both remediation loops re-enter at `verification`, never at `code-review`: a
REVISE replays verification AND documentation-delivery, so the docs and
changeset are regenerated to include what the review demanded before it re-reads
them. Documentation stays both current and reviewed.

The planner is switched to the `planning-implementation-only` seam so it stops
emitting "Testing & Verification" and "Documentation & Delivery" steps, which
would otherwise duplicate the gates under identical names.

Adds a ratchet running the production `workflowNodeRequiresWorktree` classifier
over the success chain: it reports zero offenders here and correctly flags
`documentation-delivery` on builtin:review-gated-coding, whose post-review
ordering deadlocks every task once its review approves.
2026-08-24 05:59:49 +00:00
Fusion Agent
5990ebb752 fix(FN-184): stop an in-flight merge aborting on its own merging status
FN-180's in-flight revoke watcher read `runAiMerge`'s own `status:"merging"`
stamp as a blocking pre-merge verdict: `merging`/`merging-pr` are members of
HARD_BLOCKING_TASK_STATUSES and daemon/dashboard/serve all wire the unoptioned
`getTaskMergeBlocker`. The merge aborted itself within the same second, the
drain catch cleared the stamp, and the sweep re-admitted the task every
`pollIntervalMs` forever. The abort branch spends no `mergeRetries`, so nothing
bounded the loop: no task merged, on any project, and no card was ever parked.

Fixed at both seams, because the watcher alone leaves the merge dying later:
- `ProjectEngine.wireTaskPauseMergeInterruption` evaluates the blocker against a
  verdict view that neutralizes `isMergeActiveStatus` for the owned task.
- `assertMergeGateStillOpen` (merger-ai) re-reads the task from the store at the
  ref-advance fence, so it observes the same stamp and revoked the very merge it
  guards. Same neutralization applied.

Genuine verdicts still abort: failed/pending pre-merge step results, `paused`,
`needs-replan`, and the scheduler's `queued` (deliberately not neutralized —
MERGE_CONFIRMED_TRANSIENT_STATUSES would have swallowed it). A merge-active
stamp on a different task never enters the branch.

Replaces the FN-180 source-grep coverage with behavioral tests driving the real
production blocker through the handler. Proven differential: reverting the
neutralization fails exactly the `merging` and `merging-pr` cases (2 of 11).

Fusion-Task-Id: FN-184
2026-08-24 04:45:58 +00:00
Fusion Agent
bde81ad4ff feat(FN-182): add deterministic AI-free pipeline smoke lane
Opt-in `pnpm smoke:pipeline` lane replaying 19 declared scenarios across
builtin:coding-ideas and the builtin:coding non-regression floor, driving the
real engine: disposable local Git repositories, throwaway PostgreSQL store,
production graph dispatch, ProjectEngine merge admission, real worktree
acquisition, and deterministic mock-provider scripts under testMode.

Each scenario declares one closed terminal state (merged-done, inert-intake,
parked, manual-hold, no-op-merge); an undeclared terminal fails the run, and
five wedge detectors (W1-W5) reject contradictory parks, finalization loops,
severed sessions, unreachable waits, and quiescence without progress.

Differential proof: on the pre-FN-180 tree (95ea06b48) exactly S05, S06, S09,
S10 and S16 fail across both workflows with behavioral assertions, and pass
after FN-180 — the FN-175/FN-177 incident classes are reproduced mechanically.

The declared duration budget is re-baselined 70s -> 90s at landing. The harness
did not degrade: the identical branch measured 61.8-64.1s against the
pre-integration main and 73.2-80.2s against the same main after 65 upstream
commits, with growth in transform, import and test phases the lane does not own.
docs/testing.md records the measurements, the cause, and the file-consolidation
lever to reach for before the budget is touched again.

Excluded from engine-default and engine-core; the merge gate is unchanged and
CI runs the lane non-blocking after merge.

Fusion-Task-Id: FN-182
2026-08-24 04:19:21 +00:00
Fusion Agent
8e8e3233c6 Merge remote-tracking branch 'origin/main'
# Conflicts:
#	docs/dashboard-guide.md
#	packages/core/src/__tests__/postgres/schema-applier.test.ts
#	packages/core/src/__tests__/task-merge.test.ts
#	packages/core/src/merge/task-merge.ts
#	packages/core/src/postgres/schema-applier.ts
#	packages/core/src/task-store/merge-queue-ops.ts
#	packages/dashboard/app/__tests__/App.keyboard-shortcuts.test.tsx
#	packages/dashboard/app/components/ChatView.css
#	packages/dashboard/app/components/ChatView.tsx
#	packages/dashboard/app/components/__tests__/ChatView.core-contracts.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.core-interactions.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.core.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.draft.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.message-edit.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.mobile-render.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.mobile.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.new-chat-default.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.rooms.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.scroll-to-top.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.sessions-rooms.test.tsx
#	packages/dashboard/app/components/__tests__/ChatView.thinking-level.test.tsx
#	packages/engine/src/__tests__/executor-step-session.test.ts
#	packages/engine/src/__tests__/merge-abort-clears-transient-status.test.ts
#	packages/engine/src/__tests__/merger-ai-cleanup.test.ts
#	packages/engine/src/__tests__/merger-merge-lifecycle.test.ts
#	packages/engine/src/__tests__/workspace-merger.test.ts
#	packages/engine/src/merge/auto-merge-finalization.ts
#	packages/engine/src/merge/merger-ai.ts
#	packages/engine/src/project-engine.ts
#	packages/engine/src/run-audit/run-audit-catalogue.ts
#	packages/engine/src/self-healing.ts
#	packages/engine/src/worktree/review-diff-fingerprint.ts
#	packages/i18n/locales/es/app.json
#	packages/i18n/locales/fr/app.json
#	packages/i18n/locales/ko/app.json
#	packages/i18n/locales/pt-BR/app.json
#	packages/i18n/locales/zh-CN/app.json
#	packages/i18n/locales/zh-TW/app.json
2026-08-24 03:55:34 +00:00
Timoteo
23b152f494 fix: normalize subscribe for callback-only runtime sessions (#3504)
## Summary

- normalize callback-only plugin sessions at the shared runtime boundary
- preserve runtime-native subscriptions and isolate subscriber failures
- strengthen ACP multi-delta, unsubscribe, and callback-delivery
coverage
- correct the task environment and unsubscribe contracts

## Why

PR #3501 fixed the generic ACP adapter, but workflow steps still call
`session.subscribe()` unconditionally. Bundled callback-only runtimes
such as Hermes and the vendored Grok/Claude/OMP ACP clients can still
return sessions without that method. Handling the compatibility once in
`createResolvedAgentSession` closes every current runtime surface
without copying the bridge into each adapter.

## Testing

- `packages/engine`: `agent-session-helpers.test.ts` — 61 passed
- `fusion-plugin-acp-runtime`: `runtime-adapter.test.ts` — 14 passed
- `fusion-plugin-acp-runtime`: `process-manager.test.ts` — 15 passed
- engine typecheck passed
- ACP runtime typecheck passed
- changeset format, FNXC date check, ESLint, and `git diff --check`
passed


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
  - Improved compatibility with callback-based runtime sessions.
- Added reliable subscriptions for text, thinking, and tool activity
updates.
  - Preserved native subscription behavior where available.
  - Prevented subscriber errors from interrupting event delivery.
  - Improved unsubscribe behavior for removed handlers.
  - Improved event delivery during deferred runtime fallback.
  - Corrected task environment values passed to runtime subprocesses.

- **Tests**
- Expanded coverage for streaming updates, fallback handling, cleanup,
and subscriber isolation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-23 19:00:06 -07:00
Fusion Agent
cb16f418c7 FN-183: ensure local integration branch readiness
Guarantee projects have a usable local integration branch ref across creation, import, and merge workflows.

- Add shared integration-branch readiness and repository initialization helpers.
- Wire project registration, CLI commands, central storage, and merge execution to establish the ref.
- Document the behavior and cover CLI, dashboard, core, and engine integration paths.

Files changed:
 .changeset/fn-183-integration-branch-readiness.md  |   7 +
 docs/architecture.md                               |   2 +-
 docs/cli-reference.md                              |   4 +-
 docs/getting-started.md                            |   2 +-
 docs/settings-reference.md                         |   2 +-
 .../auto-git-init-project-registration.md          |  21 +++
 docs/workspaces.md                                 |   2 +-
 packages/cli/src/commands/__tests__/init.test.ts   |  70 +++++--
 .../cli/src/commands/__tests__/project.test.ts     |  22 +++
 packages/cli/src/commands/init.ts                  |  26 ++-
 packages/cli/src/commands/project.ts               |  20 ++
 packages/core/src/__tests__/git-repository.test.ts | 190 +++++++++++++++++++
 .../__tests__/integration-branch-readiness.test.ts |  94 ++++++++++
 packages/core/src/central/central-core.ts          |  65 +++++--
 packages/core/src/git/git-repository.ts            | 112 ++++++++++--
 .../core/src/git/integration-branch-readiness.ts   | 201 +++++++++++++++++++++
 packages/core/src/index.gate.ts                    |  14 ++
 packages/core/src/index.ts                         |  14 ++
 packages/core/src/merge/task-merge.ts              |   2 +-
 .../register-project-git-readiness.test.ts         | 132 +++++++++++++-
 .../src/routes/register-project-routes.ts          |  31 +++-
 .../src/__tests__/integration-branch.test.ts       | 135 ++++++++++++++
 packages/engine/src/__tests__/merger-ai.test.ts    |  21 +++
 packages/engine/src/merge/integration-branch.ts    | 127 ++++++++++++-
 packages/engine/src/merge/merger-ai.ts             |  25 ++-
 25 files changed, 1273 insertions(+), 68 deletions(-)

Fusion-Task-Id: FN-183
Fusion-Task-Lineage: ee63d45a-3406-4064-b16f-a2fe6dc0ad86
Co-authored-by: Fusion <noreply@runfusion.ai>
2026-08-24 01:20:23 +00:00
gsxdsm
64cb17c100 FN-9204: advertise a valid memory MCP server version
Make the built-in memory MCP server complete the SDK-validated initialize handshake.

- Include a non-empty version in fusion-memory serverInfo responses.
- Cover the real SDK handshake, malformed-response skip path, and JSON-RPC envelopes.
- Document the protocol requirement and add a patch changeset.

Files changed:
 .changeset/fn-9204-memory-mcp-handshake.md         |   7 ++
 docs/mcp.md                                        |   2 +
 .../__tests__/mcp-memory-server-spawn.test.ts      |   5 +-
 .../mcp/__tests__/memory-mcp-handler.test.ts       |   7 +-
 packages/core/src/memory/mcp/memory-mcp-handler.ts |   8 +-
 .../src/__tests__/mcp-memory-handshake.test.ts     | 120 +++++++++++++++++++++
 6 files changed, 146 insertions(+), 3 deletions(-)

Fusion-Task-Id: FN-9204

Fusion-Task-Lineage: 0f68bdd5-56fe-4fdb-867f-2a5e0ea4de65

Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>
2026-08-23 17:17:08 -07:00
gsxdsm
d6c1e27709 test: delete comment-pinning assertions in engine and desktop
Part of the repo-wide census for the new "tests assert behavior, never source
text or comments" rule.

- merger-integration-worktree: deleted "keeps direct-reuse shortcut…", whose
  sole assertion pinned a `// …Skip acquireTaskWorktree's` comment in merger.ts.
- auto-heal-review-lane-callsite-audit: deleted "the DELIBERATE-LITERAL note
  still claims…", whose sole assertion pinned a comment sentence in
  project-engine.ts. That file's two real AST/call-site cases are untouched.
- electron-builder-config: deleted a pin on "intentionally deferred", which
  exists only inside YAML comments of desktop-windows.yml.

Each of these had a comment as its entire subject, so there was no behavior to
preserve — deleting the assertion is the complete fix.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 16:56:54 -07:00
Phil Larson
00b7078f79 fix: preserve reclaimed worktree branch provenance (#3507)
## Summary

- persist engine branch-write provenance when reclaiming an existing
task worktree
- cover branch-conflict reclaim with a regression assertion for the
branch, worktree, and provenance tuple

## Test plan

- `pnpm --filter @fusion/engine exec vitest run
src/__tests__/executor-worktree.test.ts --silent=passed-only
--reporter=dot`
- `pnpm --filter @fusion/engine typecheck`
- `pnpm check:changesets -- --strict`
- `pnpm check:fnxc-future-dates`
- `pnpm build`


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
  * Improved recovery when reclaiming existing task worktrees.
* Preserved task branch details and worktree paths during
branch-conflict recovery.
* Recorded whether branch updates originated from the system or an
operator for more reliable task state tracking.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com>
2026-08-23 16:53:38 -07:00
Phil Larson
c9f3f11a72 fix: allow worktree agents to read user skills (#3506)
## Summary

- allow worktree sessions to read the standard user skill root at
`~/.agents/skills`
- keep sibling `~/.agents` files and all write/edit/Bash access outside
the exception
- canonicalize existing path components so symlinks cannot escape an
allowed skill root
- document the boundary and add a patch changeset

This extends the same host-skill consistency fixed in #2384: Fusion
should not tell an agent to load a skill and then block the skill body.

## Test plan

- [x] 15 worktree-boundary tests
- [x] `pnpm --filter @fusion/engine typecheck`
- [x] scoped ESLint
- [x] changeset and FNXC date checks
- [x] `pnpm verify:fast` (20 steps, including build and boot smoke)
- [x] CLI CI-shape test (72 tests)

## Local gate notes

`pnpm test:gate` passed all static checks, 432 engine-core tests, and
184 core unit tests. Its PostgreSQL lane could not authenticate locally
(`empty password returned by client`). The full
`pi-create-fn-agent.test.ts` run also reaches an unrelated
dashboard-chat principal assertion failure already present at the exact
`origin/main` SHA; the 15 boundary tests pass.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Worktree agents can read and search skills installed in the standard
`~/.agents/skills` directory.

- **Bug Fixes**
- Preserved worktree protections for writing, editing, and Bash
operations.
- Blocked access to unrelated files and prevented symlink-based boundary
escapes across supported path operations.
  - Improved access validation for paths that do not yet exist.

- **Documentation**
- Updated worktree boundary documentation to describe skill access and
its restrictions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-23 16:53:10 -07:00
ischindl
8fcf4bdbaa feat: Stash memory backend — session capture, per-chat backfill, opt-in vector search (#3494)
## Summary

Adds the **Stash memory backend** (`memory.backendType=stash`) that
connects Fusion's agent memory to the
[Stash](https://github.com/Fergana-Labs/stash) product — *knowledge
bases for the agent era* ([product site:
joinstash.ai](https://joinstash.ai)). Fusion becomes a first-class Stash
client: complete chat sessions and finished tasks are captured into
Stash, memory is recalled during chat, and Stash sessions are kept in
sync with the dashboard (including deletes and archival).

**Product:** <https://github.com/Fergana-Labs/stash> ·
[joinstash.ai](https://joinstash.ai)

## What's included

### 1. Stash memory backend (RUFU-068 / RUFU-121)
- New `StashMemoryBackend` (`memory.backendType=stash`) with `stashUrl`
/ `stashApiKey` settings (global secrets-store `stash-api-key` +
per-project override).
- **Complete-chat-session capture** keyed by ChatSession id.
- Sessions are classified into **per-project folders** (get-or-create,
`external_key fusion-<projectId>`, 1h per-process cache) and
**soft-deleted with their chat** via `DELETE /api/chat/sessions/:id`.
- Per-conversation **memory-focus** read-time scoping (new
`0066_chat_session_memory_focus.sql` migration — sequence renumbered
0059→0060→0061→0065→0066 as origin/main claimed the lower numbers);
event metadata enriched with `project` / `project_name` / `chat_title`.
- Recall queries normalized to single-keyword / explicit-OR ASCII (≤100
chars); shared normalizer export reused by per-turn recall.

### 2. Per-task executor transcript capture (RUFU-122)
Finished or failed tasks upload their executor transcript
(`agent-log.jsonl`) to Stash as a task session.

### 3. Bulk archive Stash sync (RUFU-125)
Archived task-planner chats soft-delete their Stash sessions on bulk
archival (paged). The snapshot of doomed session ids is taken *before*
the local bulk delete, and the Stash sync runs fire-and-forget so a
Stash stall can never delay local archival.

### 4. Per-chat "Preserve to Stash" backfill (RUFU-136)
A per-chat action that backfills a chat's full history into Stash, with
client-side idempotency and a pre-check that skips already-uploaded
content (fail-closed, no duplicate upload on transport failure).
- **Session-folder naming fix:** the first project folder is now named
"Fusion — &lt;project name&gt;" instead of the bare "Fusion" fallback
(the backfill now resolves the central-registry project name,
best-effort, never blocking the upload).

### 5. Opt-in semantic (vector) recall (RUFU-126)
`stashVectorSearch` setting (default `false` — **zero behavior change
until enabled**). For multi-word queries the backend tries Stash's
semantic-search endpoint first, then falls back byte-identically to the
keyword path. Definitive 404/405/501/503 responses are negatively cached
per process. Requires a patched Stash server (new endpoint +
`sentence-transformers` + embedding backfill); unpatched servers are
transparently bypassed after the first 404.

## Safety
- **Opt-in / inert by default:** the default backend remains `qmd`; the
Stash backend is inert until `memoryBackendType=stash` + `stashUrl` are
set.
- All Stash I/O is **best-effort, fail-closed, and non-blocking** — a
Stash outage never blocks chat, task completion, or archival. No
run-audit content is emitted.

## Testing
- Backfill + delete-sync suites (20/20), Stash backend suite (68/68),
executor memory / session capture suites, `memory-focus-recalling`,
description-guard — all green.
- `tsc` clean across core / engine / dashboard.
- Live verification: bulk backfill of 21/24 chats completed; the
"Preserve to Stash" action is idempotent on re-run.

## Changesets
- `@runfusion/fusion` **minor** — Stash memory backend + capture
(RUFU-068/121), per-task transcript (RUFU-122), bulk archive sync
(RUFU-125), per-chat backfill (RUFU-136), opt-in vector search
(RUFU-126)
- `@runfusion/fusion` **patch** — backfill session-folder naming fix


## Rebase Note (2026-08-23)

Rebased onto `origin/main` `3f448f7292` (v0.77.0-beta.7). Conflicts
resolved additively:
- `packages/core/src/postgres/schema-applier.ts` + test — upstream's
0062-0065 migrations (task/subtask splitting removal, AI merge review
reconciliation, task repository scope, FN-149 review convergence)
unioned with this PR's `chat_sessions.memory_focus` migration, which is
**renumbered 0065 → 0066** (upstream's FN-149 shipped 0065 canonically
on origin/main); `SCHEMA_BASELINE_VERSION` advances to `0066`.
- `packages/dashboard/app/components/ChatView.tsx` — upstream's docked
chat sidebar resize handlers unioned with the RUFU-136 "Preserve to
Stash" backfill handler.
- New commit: `settings.memory.*` stash-backend i18n keys added to all 6
secondary locales (RUFU-121/122 parity fix; `pnpm i18n:status` no longer
reports any violation introduced by this PR).

**Deploy note (operator environments that already ran a pre-rebase build
of this PR):** the memory-focus SQL may already be in the schema under
ledger row `0065`. Remap that row to `0066` (`UPDATE
fusion_schema_migrations SET version = '0066' WHERE version = '0065';`)
*before* first boot of a 0066-ceiling binary — otherwise the fresh
upstream `0065_fn_149_review_convergence_stage.sql` would be skipped as
"already applied". Clean databases (no prior memory-focus row) need no
action.

**CI note — Lint (lifecycle-column census) is red on the merge base:**
`pnpm check:lifecycle-columns --strict` fails identically on pure
`origin/main` `3f448f7292` with
`packages/core/src/db/legacy-adoption.ts: 0 -> 3` (3 column guards in
the U9b legacy-adoption table without a baseline entry or
`DELIBERATE-LITERAL` marker). Verified by running the census on a clean
origin/main checkout — inherited from the base, not introduced by this
PR. Fix belongs upstream; tracked separately.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added Stash memory integration with project configuration and optional
semantic search.
  * Added per-chat memory focus controls and a `/focus` command.
  * Added “Preserve to Stash” for uploading complete chat history.
  * Added automatic chat, task transcript, and completion-event capture.
* Added project-specific Stash session folders and archive/delete
synchronization.
* **Bug Fixes**
* Improved Stash folder naming and handling of missing branches during
no-commit tasks.
* **Documentation**
* Added setup, configuration, integration, vector-search, and
performance guidance.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Fusion <noreply@runfusion.ai>
Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com>
2026-08-23 16:46:14 -07:00
Phil Larson
38edc2366b fix(core): restore executor workflow creation guidance (#3513)
## Summary
- restore explicit executor guidance for assigning workflows to tasks
the agent creates
- keep the existing prohibition on rerouting the task currently being
executed
- restore parity between both built-in executor prompt variants and
their regression test

## Test plan
- `pnpm --filter @fusion/core exec vitest run --silent=passed-only
--reporter=dot src/__tests__/agent-prompts.test.ts`
- `pnpm --filter @fusion/core typecheck`
- `pnpm check:changesets`
- `pnpm exec eslint packages/core/src/agents/agent-prompts.ts`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Executor workflow guidance now appears only when task creation or
delegation capabilities are available.
* Built-in executor prompts provide clearer task-assignment instructions
based on available capabilities.
  * Custom executor prompts remain unchanged.
* Removed outdated workflow-setting guidance when task-management
capabilities are unavailable.

* **Tests**
* Added coverage for task creation, delegation, and capability-specific
workflow guidance scenarios.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-23 16:45:03 -07:00
gsxdsm
08f8c26ec1 fix: honor the workflow-principal hold cooldown on the dispatch path
The U4 executor peel (#3317) rewrote executor.ts from a pre-change base and
dropped `isPrincipalHoldCoolingDown`, re-inlining the read inside
executeWorkflowGraph behind `!opts?.alreadyClaimed` — a flag its only caller,
executeCore, always sets. The ladder kept recording and clearing correctly, so
it read as working while never once deferring a dispatch.

Without it, an unroutable role pool re-enters the graph on every dispatch only
to re-fence and re-park: one graph run, two work-item writes and two audit rows
per pass, for a condition that clears only when an operator enables or adds an
agent. The `!repeated` log suppression keeps that flood invisible after the
first line.

Restore the guard in executeCore, ahead of the graphRouting claim. Position is
load-bearing in both directions: returning after the claim would strand it
(graphRunnerOwnsClaim stops the finally from cleaning up), which is also why
the inner check must keep its alreadyClaimed gate.

Make the ladder a primitive with one exported writer and one exported reader so
a lost reader is a lost reference the compiler can see, rather than a .get()
that quietly moved somewhere its guard could never be true. Its test-mode zero
is now read at record time; bound at module load it collapsed the cooldown to
until === now under VITEST, so no test could have caught this.

Regression test asserts the invariant on both entry surfaces plus the negatives
that keep the guard from becoming a permanent block. Mutation-checked: with the
guard disabled the two dispatch-deferral cases fail.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 15:45:20 -07:00
gsxdsm
39812f4898 test: quarantine one suite-only flake, record another, fix the lockstep guard
Full engine suite at a97aa84a20: 3 failures out of 12,414. All three diagnosed:

- self-healing-pending-wedge-notification's marker-selection case fails ONLY in
  a full-suite run (expects 1 elapsed marker, sees 2) and passes deterministically
  alone. This is its SECOND sighting, so per AGENTS.md it is an on-sight
  quarantine with no further discretion: ledger entry + matching vitest exclude,
  same commit, 2026-09-06 deletion deadline.
- spec-drift-reconciler's exponential-backoff case shows the same shape on a
  FIRST sighting, so it is recorded in the observed register instead of evicting
  that file's other passing coverage. Both are timer-driven reconciler tests that
  only fail alongside other suites, pointing at cross-file fake-timer state.
- merge-orphan-durable-write-inventory drift was pure lineHint movement (19
  changed, zero newly unclassified entries) after product edits shifted lines.
  Regenerated.

Also fixes check-quarantine-ledger.mjs, which could not see the exclude I added:
its comment stripper treated the `/**` inside glob literals like "node_modules/**"
and "src/**/*.slow.test.ts" as a block-comment opener and deleted through to the
next "*/", swallowing whole array literals and every entry after them. It now
scans string-aware, so the lockstep check actually holds. Nothing was appeased:
no timeout widened, no retry added, no assertion relaxed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 15:43:00 -07:00
Phil Larson
bc82d8e0e1 fix(core): thread review lanes through merge readiness (#3514)
## Summary
- thread resolved review lanes through `isTaskReadyForMerge`
- preserve required pre-merge step filtering
- add coverage for a renamed review lane

## Test plan
- `pnpm --filter @fusion/core exec vitest run --silent=passed-only
--reporter=dot src/__tests__/task-merge.test.ts`
- `pnpm --filter @fusion/core typecheck`
- `pnpm check:lane-wiring`
- `pnpm check:changesets`
- `pnpm exec eslint packages/core/src/merge/task-merge.ts
packages/core/src/__tests__/task-merge.test.ts`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Custom review lanes are now honored during merge-readiness checks and
auto-merge processing.
  * Renamed workflow lanes correctly determine whether tasks can merge.
* Tasks resumed from a paused state are routed and evaluated using the
appropriate review lane.
* The default `in-review` lane remains supported when no custom review
lanes are configured.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com>
2026-08-23 15:31:17 -07:00
gsxdsm
a97aa84a20 fix: remove debug probes swept into ab9789f0a8 by mistake
ab9789f0a8 was committed with `git add -A` while an agent was mid-investigation
in this same checkout, so it captured that agent's temporary instrumentation:
eight `process.stderr.write('[F] …')` probe lines inside product code
(executor/mark-stuck-aborted.ts) and a 359-line scratch copy of a test file.
Both were pushed. Reverting both; no product behavior was ever intended to
change in those files.

Also lands the executor-stuck-requeue fix that investigation produced: the
grace-timeout assertion ran before the product finished, because the callback
continues past its timer into resetStepsIfWorkLost -> loadWorkspaceConfig, real
async fs I/O that `vi.advanceTimersByTimeAsync` does not await. The test now
awaits a completion barrier resolved by the requeue's own final moveTask rather
than a timeout or retry. The product was correct.

Lesson for this checkout: stage by explicit path while agents are running.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 15:05:27 -07:00
gsxdsm
ab9789f0a8 fix: correct workspace review fingerprint range and land-intent resolve gating
Two product defects surfaced by workspace-e2e's remaining failures.

1. A merge-boundary fence silently did not apply. captureWorkspaceReviewEvidence
   computes a repository's file list over baseCommitSha..<resolved task branch>,
   but computeReviewDiffFingerprint hardcoded baseRef..HEAD. For a workspace
   entry whose checkout sits on the integration branch those are different
   ranges, so the fingerprint did not describe the files captured beside it: a
   diverged checkout hard-failed an approved repository as content-changed,
   and a checkout at the base produced an empty diff -> undefined fingerprint ->
   the repo dropped out of mergeBoundaryFingerprints, so BOTH the
   approval-missing and content-changed fences stopped applying to it at all.
   computeReviewDiffFingerprint now takes an optional headRef; workspace
   evidence passes the resolved task branch. The singular-review caller, whose
   worktree IS the branch, keeps the ambient HEAD default.

2. Land intents were recorded and resolved under different conditions.
   landOneRepo records an intent only when ctx.workspaceLand is set, which
   landWorkspaceTask passes only for remote targets, but the resolve side was
   gated on durableLandLease alone. A local-only land therefore resolved an
   intent that was never recorded, got "missing", and failed a fully-landed
   repo as a partial land AFTER its integration ref had advanced. Resolve now
   uses the same condition as record.

The approveWorkspaceReview helper's "reviewStep called exactly once" constant
only held because defect 1 suppressed a repository; it now derives the expected
count from the same production capture the review loop uses.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 15:01:39 -07:00
gsxdsm
e37ebd5af9 chore(release): v0.77.0-beta.8
Version bump via changesets.
2026-08-23 14:49:26 -07:00
gsxdsm
455bdbc007 fix: repair the engine suite and the product regressions it was pointing at
Six parallel agents worked the 150 remaining failures. Engine suite: 297 failing
tests at baseline 3f448f7292 -> 8. 12,391 passing.

The failures were mostly pointing at live regressions, not stale tests. Eleven
product defects found and fixed:

- Operator approval mail dropped from BOTH executor gate closures: a gate paused
  a task for approval and no mailbox row was ever written.
- FN-8840 title-duplicate handling reverted in triage.ts, self-healing.ts, and
  scheduler.ts: a title-only "DUPLICATE: <id>" card consumed a full planner
  session, an operator-authored PROMPT.md could be erased, and a title-only
  redirect became dispatchable again.
- A failed plan-admission audit write set its dedupe marker anyway, silencing
  the stall permanently (FN-8600 regression); engine now has an outcome-reporting
  bounded-audit seam mirroring core's FN-9182.
- A best-effort plan mirror could abort a whole planning attempt after the
  authoritative PROMPT.md had already been written.
- AI-merge cleanup lost its alreadyAbsent/idempotent signal on the real-git path.
- Workspace merge-boundary file comparison ran without its review-evidence fence,
  hard-failing every file for callers with no review episode.
- After a file-scope violation the retry re-selected the rejected squash and
  never re-merged.
- Parallel step branches leaked: a name-based classifier read executor-created
  fusion/step-* branches as operator-owned and skipped cleanup.
- workspace_coordination_leases / workspace_land_intents were missing from
  projectTableNames, so the PG harness never truncated them and leases leaked
  across tests.

Four of those are silent reversions from ONE commit, 1cf86baa1c, labeled a
behavior-preserving "executor pure peels" refactor. It passed its own targeted
verification; only a full-suite audit found them.

Test-side repairs are root-cause fixes at shared factories: required pre-merge
gate declarations, branch-write provenance, fake stores missing production write
seams, dead vi.mock specifiers that silently mocked nothing (allowlist ratcheted
11 -> 8), and stale expectations after deliberate IR/tool/error-class changes.
Tests for deleted features were deleted with their removing commit cited.

Left red deliberately (4): executor-worktree-liveness's unrouted-graph-run
assertion and three workspace-e2e landing-stack layers, each needing a design
ruling rather than a test edit. Two durable-write call sites remain flagged
unresolved rather than given invented fencing verdicts.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 12:31:25 -07:00
gsxdsm
29f9edf153 test: declare branch-write provenance in reliability fixtures
Three more fixtures wrote a task branch without an origin, so the
`updateTaskUnlockedImpl` provenance boundary threw before any scenario ran —
the same guard, and the same missed-fixture class, as the shared reliability
helper fixed earlier. Each fixture binds a task to its worktree branch on the
engine's behalf, so each now says so.

worktree-lifecycle-certification 0/4 -> 4/4, audit-and-recovery 1/3 -> 3/3,
self-healing-interactions 6/7 -> 7/7.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 11:11:18 -07:00
gsxdsm
4f40c91b38 test: drop reviewer-prompt tests for the deliberately removed splitting feature
Four tests asserted DEFAULT_REVIEWER_PROMPT still carried the task-SPLITTING
contract: "Subtask breakdown", "12+ implementation steps", "The bar for
splitting is high", and a REVISE directing the planner to fn_task_create 2-5
child tasks. FN-074 removed task splitting across core, dashboard, and engine,
and FN-125 removed the reviewer's ability to create tasks at all. FN-074's
message says it updated affected tests; these were missed and sat red asserting
a contract the product deliberately dropped.

Removed rather than repaired: restoring that prompt text to make them pass would
re-add removed behaviour. The two tests in this block covering the prompt
contract that still exists are untouched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 10:28:33 -07:00
gsxdsm
324145c1e1 test: repair engine fixtures that predate shipped product guards
The engine suite's failures are not independent bugs; they are a handful of
systemic drifts where a guard shipped and its fixtures were never updated.

- Required pre-merge gates (FN-158): the door refuses a card whose enabled
  optional groups produced no result, and the built-in workflow enables Plan and
  Code Review by default. Merge-mechanics fixtures now declare an explicit empty
  list, stating the intent they always had. group-merge-coordinator's
  "post-Code-Review member" instead gets real PASSING workflowStepResults,
  because recording the pass is what that fixture actually means.
- Branch-write provenance: the shared reliability fixture creates a task with a
  branch, which now requires an explicit origin. It stands in for an
  engine-created branch, so it says so.
- updateTaskAtomic: a production write seam missing from several fake stores,
  copied from the faithful fake in merger-ai.test.ts.
- Durable-write inventory: eight unclassified TaskStore surfaces classified,
  including the two batched reads this branch added.
- workflow-graph-merge-region-collapse asserted completion-summary AFTER
  code-review; the IR wires it before, and production logs agree.

merger-ai.test.ts alone goes 37 -> 0. Engine failures 288 -> ~200.

Also records a first-sighting suite-only flake in the observed register per the
standing rule, rather than quarantining a file with substantial coverage.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 10:18:50 -07:00
gsxdsm
ea48af7ab5 fix: require a durable merge record for the step-finalization exemption
Full-suite set-diff against 3f448f7292 caught three regressions the raw counts
hid (that suite is chronically red: 297 failures at baseline, 294 with the
change).

The step exemption was too broad. It also applied to
recoverAlreadyMergedReviewTasks, the content-scan recovery where mergeDetails is
ABSENT and landing is inferred by finding matching content on the base branch.
That heuristic can match a cherry-pick, so exempting incomplete steps there
would launder a genuinely unfinished task to done on a guess — which is exactly
what landed-content-soft-blocker.real-git.test.ts exists to prevent. The
exemption now requires mergeConfirmed AND a commitSha: FN-9193's actual state,
and nothing weaker. Content-scan recovery and no-op merges keep the blocker.

Also seeds mergeSweepHoldReasons in the shared merge-lane fixture, which the
fixture-drift guard requires of every auto-merge state field.

Verified by set-diff: zero test files now fail that did not fail at baseline.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 09:45:10 -07:00
gsxdsm
a879ead0fc fix: let a proven merge finalize even with unfinished steps
FN-9193's branch landed on main as eaa1d47c, but a Code Review revision request
had reset its steps while the approved merge was in flight. The card was left
mergeConfirmed WITH incomplete steps, and every finalization site refused with
"task has incomplete steps" — so it sat failed, re-reading its own contradiction.
Restarting it made things worse: replanning issued seven fresh pending steps, so
the retry re-created the exact condition blocking it. A loop with no exit.

Holding a landed card out of done un-merges nothing; the code is on the target
branch either way. All four finalization sites now use
getMergeConfirmedFinalizationBlocker, which exempts incomplete steps once
landing is proven and records the unfinished ones on the task instead of
dropping them. A no-op merge that landed no content still blocks — that is the
protective half of the guard being replaced, and the executor's no-op branch
depends on it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 09:26:16 -07:00
gsxdsm
038f802ba4 fix: make the workflow graph the only merge authority
ProjectEngine's in-review auto-merge sweep was a second merge authority. It
judged eligibility from column, status, steps and retry budget alone, with no
idea where the card sat in its workflow graph, so it merged work the graph had
never authorized: FN-9191 merged ~2s after fn_task_done, before Code Review had
ever started, and FN-9193 merged while Code Review was re-running — the gate
then requested revision and reset the steps, but the in-flight merge landed the
pre-remediation branch anyway and left the card mergeConfirmed WITH incomplete
steps, unfinalizable for five hours.

- classifyMergeSweepAdmission (core) admits only merge-confirmed finalization,
  a card parked at a merge-region node, an interrupted attempt, or a fenced
  quiescent stall. Every initiation is fenced on satisfied pre-merge gates.
- All four doors prove authority: the sweep, the 300ms column-entry handoff
  (which matches FN-9191's timing better than any sweep tick), the unpause
  re-enqueue, and a position-only pre-dispatch re-check for cards the graph
  moved out of the merge lane while they were queued.
- workflow-merge-region.ts holds the canonical merge-region predicate;
  INTERPRETER_ENTRY_NODE_KINDS now aliases it so the two cannot drift.
- Multi-repo: branch-group integration/promotion are merge-region nodes, an
  in-flight sub-repo land reads as foreign liveness, and a cross-node
  merge-dispatch lease defers.
- Sweep reads are batched, so admission costs O(1) queries per poll.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 03:29:32 -07:00
Fusion Agent
db254241f1 FN-180: enforce merge execution and current review gates
Prevent merge progression while execution is active and require current, content-matched review approval before finalization.

- Add shared pre-merge approval and content descriptor gates.
- Exclude actively executing tasks from merge and reconcile confirmed merges safely.
- Centralize step reopening and strengthen merge lifecycle, audit, and regression coverage.

Files changed:
 ...80-merge-execution-exclusion-and-review-gate.md |   7 +
 docs/architecture.md                               |   1 +
 docs/run-audit.md                                  |   2 +
 docs/testing.md                                    |   5 +
 docs/workflow-steps.md                             |   2 +
 .../confirmed-merge-reconciliation.test.ts         |  17 ++
 .../src/__tests__/pre-merge-approval-gate.test.ts  |  33 ++++
 .../__tests__/pre-merge-approval-workspace.test.ts |  30 +++
 .../src/__tests__/required-pre-merge-steps.test.ts |  47 ++++-
 packages/core/src/__tests__/task-merge.test.ts     |   9 +-
 packages/core/src/db/legacy-adoption.ts            |   7 +
 packages/core/src/index.gate.ts                    |  11 +-
 packages/core/src/index.ts                         |  11 +-
 .../src/merge/confirmed-merge-reconciliation.ts    |  34 ++++
 .../core/src/merge/merge-content-descriptor.ts     |  10 +
 packages/core/src/merge/pre-merge-approval.ts      |  71 +++++++
 .../core/src/merge/required-pre-merge-steps.ts     |  69 +++++++
 packages/core/src/merge/task-merge.ts              |  35 ++--
 packages/core/src/task-store/merge-queue-ops.ts    |  50 ++---
 .../src/workflows/workflow-step-reopen-policy.ts   |  18 ++
 .../__tests__/ChatView.core-contracts.test.tsx     |   5 +-
 .../__tests__/ChatView.core-interactions.test.tsx  |   5 +-
 .../components/__tests__/ChatView.core.test.tsx    |   5 +-
 .../components/__tests__/ChatView.draft.test.tsx   |   5 +-
 .../__tests__/ChatView.message-edit.test.tsx       |   5 +-
 .../__tests__/ChatView.mobile-render.test.tsx      |   5 +-
 .../components/__tests__/ChatView.mobile.test.tsx  |   5 +-
 .../__tests__/ChatView.scroll-to-top.test.tsx      |   5 +-
 .../__tests__/ChatView.sessions-rooms.test.tsx     |   5 +-
 .../__tests__/ChatView.thinking-level.test.tsx     |   5 +-
 .../confirmed-merge-must-finalize.test.ts          |  32 ++++
 .../src/__tests__/executor-step-session.test.ts    |  29 ++-
 .../src/__tests__/manual-merge-bypass.test.ts      |   1 +
 .../merge-abort-clears-transient-status.test.ts    |  66 ++++---
 .../merge-content-descriptor-doors.test.ts         |  28 +++
 .../__tests__/merge-execution-exclusion.test.ts    |  65 +++++++
 .../__tests__/merge-gate-single-authority.test.ts  |  28 +++
 .../src/__tests__/merge-inflight-revoke.test.ts    |  26 +++
 .../merge-worktree-removal-live-session.test.ts    |  29 +++
 .../engine/src/__tests__/merger-ai-cleanup.test.ts |   8 +-
 .../src/__tests__/merger-merge-lifecycle.test.ts   |  11 +-
 .../__tests__/step-reopen-single-authority.test.ts | 116 ++++++++++++
 .../workflow-graph-optional-step-fix.test.ts       |  10 +
 .../engine/src/__tests__/workspace-merger.test.ts  |  13 +-
 .../engine/src/executor/cleanup-merge-state.ts     |  45 +----
 .../src/executor/finalize-already-reviewed-task.ts |  20 +-
 .../src/executor/recover-failed-pre-merge-step.ts  |   7 +-
 .../src/executor/reopen-last-step-for-revision.ts  |  41 +----
 .../request-pre-merge-optional-step-fix.ts         |  13 +-
 packages/engine/src/executor/reset-merge-state.ts  |   7 +-
 .../src/executor/review-convergence-ladder.ts      |   6 +
 packages/engine/src/executor/run-implementation.ts |  33 +++-
 .../engine/src/merge/auto-merge-finalization.ts    |  49 +++--
 packages/engine/src/merge/merge-content-capture.ts |  49 +++++
 .../engine/src/merge/merge-execution-exclusion.ts  |  47 +++++
 packages/engine/src/merge/merger-ai.ts             | 204 ++++++++++++++++-----
 packages/engine/src/merge/merger-errors.ts         |  13 ++
 packages/engine/src/merger.ts                      |  29 ++-
 packages/engine/src/project-engine.ts              | 153 ++++++++++++----
 .../engine/src/run-audit/run-audit-catalogue.ts    |  12 ++
 packages/engine/src/self-healing.ts                |  36 ++--
 packages/engine/src/util/run-audit.ts              |   4 +
 .../engine/src/worktree/review-diff-fingerprint.ts |  36 +++-
 .../src/worktree/workspace-review-evidence.ts      |   2 +-
 64 files changed, 1420 insertions(+), 367 deletions(-)

Fusion-Task-Id: FN-180

Fusion-Task-Lineage: 4c2cdae0-be25-49c9-a918-60768ddc7686

Co-authored-by: Fusion <noreply@runfusion.ai>
2026-08-23 09:22:26 +00:00
Fusion Agent
95ea06b48a FN-179: add workspace contention wait-state recovery
Persist workspace acquisition contention as an operator-visible wait state and make recovery, lease authority, and localized dashboard status handling consistent.

- Add the contention wait-state schema, persistence, reset, serialization, and audit plumbing.
- Coordinate workspace acquisition claims, leases, retries, and self-healing recovery across engine and core.
- Surface contention status in task cards and detail views with translated labels and regression coverage.
- Document the workspace behavior and add the required changeset.

Files changed:
 .changeset/fn-179-workspace-acquire-contention.md  |   7 +
 AGENTS.md                                          |   1 +
 docs/architecture.md                               |   4 +-
 docs/dashboard-guide.md                            |   1 +
 docs/workspaces.md                                 |   4 +-
 .../src/__tests__/postgres/schema-applier.test.ts  |  34 ++++-
 ...workspace-worktrees-concurrent-merge.pg.test.ts |  35 +++++
 .../0066_fn_179_session_contention_wait_state.sql  |   3 +
 packages/core/src/postgres/schema-applier.ts       |  12 +-
 packages/core/src/postgres/schema/project.ts       |   2 +
 packages/core/src/store.ts                         |   2 +-
 .../core/src/task-store/branch-and-pr-entities.ts  |   2 +-
 packages/core/src/task-store/persistence.ts        |   4 +
 packages/core/src/task-store/reset-lifecycle.ts    |   2 +
 packages/core/src/task-store/serialization.ts      |   2 +
 packages/core/src/task-store/task-artifacts-ops.ts |   4 +
 packages/core/src/task-store/task-mutation-ops.ts  |  41 +++---
 packages/core/src/task-store/task-row-mappers.ts   |   2 +-
 packages/core/src/task-store/task-update.ts        |  10 ++
 packages/core/src/tasks/manual-retry-reset.ts      |   2 +
 packages/core/src/types/task/task-core.ts          |   4 +
 packages/dashboard/app/components/ListView.tsx     |   4 +-
 packages/dashboard/app/components/TaskCard.tsx     |   2 +-
 .../dashboard/app/components/TaskDetailModal.tsx   |   1 +
 .../taskStatusBadgeLabel.host-inventory.test.ts    |  19 +++
 .../utils/__tests__/taskStatusBadgeLabel.test.ts   |   7 +
 .../dashboard/app/utils/taskStatusBadgeLabel.ts    |   8 ++
 .../executor-planning-lock-transport-retry.test.ts | 132 ++++++++++++++++++
 ...roject-engine-spec-drift-startup-replay.test.ts |  84 ++++++++++++
 .../src/__tests__/self-healing-workspace.test.ts   |  58 ++++++++
 .../workspace-acquire-claim-release.test.ts        |  69 ++++++++++
 .../workspace-acquire-contention-hold.test.ts      |  75 +++++++++++
 .../workspace-acquire-lease-authority.test.ts      | 122 +++++++++++++++++
 .../worktree-acquisition-workspace.test.ts         |  32 +++++
 packages/engine/src/agent-tools.ts                 |  26 +++-
 .../engine/src/agents/active-session-registry.ts   |   9 ++
 .../create-authoritative-workflow-seams.ts         |  14 +-
 packages/engine/src/executor/deps-bags.ts          |   3 -
 .../engine/src/executor/execute-workflow-graph.ts  |   4 +-
 packages/engine/src/executor/run-implementation.ts |  34 ++++-
 .../engine/src/executor/session-contention-hold.ts |  47 +++----
 .../engine/src/executor/wire-executor-lifecycle.ts |  32 ++++-
 packages/engine/src/planning-handoff-recovery.ts   |  11 ++
 packages/engine/src/project-engine.ts              |   8 +-
 packages/engine/src/self-healing.ts                |  63 ++++++++-
 packages/engine/src/util/run-audit.ts              |   4 +
 .../engine/src/worktree/worktree-acquisition.ts    | 147 ++++++++++++++++-----
 packages/i18n/locales/en/app.json                  |   2 +
 packages/i18n/locales/es/app.json                  |   4 +-
 packages/i18n/locales/fr/app.json                  |   4 +-
 packages/i18n/locales/ko/app.json                  |   4 +-
 packages/i18n/locales/pt-BR/app.json               |   4 +-
 packages/i18n/locales/zh-CN/app.json               |   4 +-
 packages/i18n/locales/zh-TW/app.json               |   4 +-
 packages/i18n/src/resources.d.ts                   |   2 +
 55 files changed, 1103 insertions(+), 118 deletions(-)

Fusion-Task-Id: FN-179

Fusion-Task-Lineage: 30f1b365-2847-4ec1-85b3-23a98c92de40

Co-authored-by: Fusion <noreply@runfusion.ai>
2026-08-23 08:26:56 +00:00
Fusion Agent
e25f8907d9 FN-175: add review-gated verification workflow
Add review-owned verification, remediation, and documentation gates across workflow execution and task progress.

- Add built-in review-gated coding workflow and verification/documentation nodes.
- Preserve remediation steps and enforce finalize/merge guards after review findings.
- Surface review-gate progress in the dashboard and document the workflow and audit behavior.
- Add focused core, engine, and dashboard regression coverage.

Files changed:
 .changeset/fn-175-review-gated-workflow.md         |  7 ++
 docs/architecture.md                               |  4 +
 docs/dashboard-guide.md                            |  4 +
 docs/run-audit.md                                  |  5 ++
 docs/workflow-steps.md                             |  6 ++
 .../builtin-review-gated-coding-workflow.test.ts   | 48 +++++++++++
 .../__tests__/no-commits-finalize-guard.test.ts    | 15 ++++
 .../core/src/__tests__/remediation-steps.test.ts   | 64 ++++++++++++++
 packages/core/src/index.gate.ts                    |  9 ++
 packages/core/src/index.ts                         | 10 +++
 .../core/src/merge/no-commits-finalize-guard.ts    | 12 ++-
 packages/core/src/store.ts                         |  6 +-
 .../core/src/task-store/remediation-step-ops.ts    | 45 ++++++++++
 packages/core/src/tasks/remediation-steps.ts       | 48 +++++++++++
 packages/core/src/types/task/task-log.ts           | 15 ++++
 .../builtin-documentation-delivery-group.ts        | 32 +++++++
 .../src/workflows/builtin-plan-review-group.ts     | 11 ++-
 .../builtin-review-gated-coding-workflow-ir.ts     | 60 +++++++++++++
 .../workflows/builtin-verification-gate-group.ts   | 26 ++++++
 .../core/src/workflows/builtin-workflow-prompts.ts |  2 +
 .../builtin-workflow-remediation-nodes.ts          | 20 +++++
 packages/core/src/workflows/builtin-workflows.ts   | 14 ++++
 packages/core/src/workflows/index.ts               |  3 +
 packages/dashboard/app/components/TaskCard.css     |  5 ++
 packages/dashboard/app/components/TaskCard.tsx     | 12 ++-
 .../__tests__/taskProgress.review-gates.test.ts    | 19 +++++
 packages/dashboard/app/utils/taskProgress.ts       |  2 +
 .../review-gated-remediation-steps.test.ts         | 43 ++++++++++
 .../review-gated-step-preservation.test.ts         | 32 +++++++
 .../review-gated-verification-gate.test.ts         | 50 +++++++++++
 .../executor/append-review-remediation-steps.ts    | 97 ++++++++++++++++++++++
 .../engine/src/executor/build-parse-steps-deps.ts  |  1 +
 .../engine/src/executor/cleanup-merge-state.ts     |  9 +-
 packages/engine/src/executor/deps-bags.ts          |  9 +-
 .../src/executor/derive-remediation-steps.ts       | 76 +++++++++++++++++
 packages/engine/src/executor/free-reexports.ts     |  1 +
 packages/engine/src/executor/impl-bindings.ts      |  1 +
 .../request-pre-merge-optional-step-fix.ts         | 17 ++++
 packages/engine/src/executor/reset-merge-state.ts  |  5 +-
 .../engine/src/executor/run-graph-custom-node.ts   |  7 +-
 packages/engine/src/executor/run-implementation.ts |  3 +
 .../engine/src/executor/send-task-back-for-fix.ts  |  5 +-
 .../src/executor/task-executor-session-facades.ts  |  1 +
 packages/engine/src/merge/merger-ai.ts             | 19 ++++-
 packages/engine/src/merger.ts                      | 27 +++++-
 packages/engine/src/self-healing.ts                | 24 +++++-
 .../workflow-node-runners/parse-steps-runner.ts    | 26 +++++-
 .../src/workflow-node-runners/verification-gate.ts | 77 +++++++++++++++++
 .../src/workflows/workflow-graph-executor.ts       |  4 +-
 49 files changed, 1014 insertions(+), 24 deletions(-)

Fusion-Task-Id: FN-175

Fusion-Task-Lineage: 3c555a09-4cea-4b03-a315-b6a354a2eac3

Co-authored-by: Fusion <noreply@runfusion.ai>
2026-08-23 05:37:27 +00:00
Fusion Agent
37124bb7f9 FN-173: replace duplicate Keep action with dismissible tag
Replace the duplicate-task Keep button with a dismissible duplicate tag and update the related operator guidance.

- Add dismissible duplicate tags across task cards, detail views, docks, and overflow surfaces.
- Update localized copy, documentation, notifications, styling, and regression coverage.
- Record the published CLI/dashboard change in a changeset.

Files changed:
 .changeset/fn-173-removal.md                       |   7 +
 docs/settings-reference.md                         |   4 +-
 docs/task-management.md                            |   8 +-
 packages/dashboard/app/App.tsx                     |   2 +-
 packages/dashboard/app/components/DockTaskList.tsx |   9 +-
 packages/dashboard/app/components/TaskCard.css     |  47 ++++---
 packages/dashboard/app/components/TaskCard.tsx     |  31 +++--
 .../dashboard/app/components/TaskDetailModal.css   |  23 ++++
 .../dashboard/app/components/TaskDetailModal.tsx   |  51 ++++---
 .../__tests__/TaskCard.duplicate-tag.test.tsx      | 150 +++++++++++++++++++++
 .../app/components/__tests__/TaskCard.test.tsx     |  10 +-
 .../__tests__/TaskDetailModal.rendering.test.tsx   |  30 ++++-
 .../app/components/dashboard/MainContent.tsx       |   2 +
 .../app/components/overflowViewRegistry.tsx        |   2 +
 .../app/components/useRightDockController.tsx      |   3 +
 .../__tests__/notification-service.test.ts         |  31 +++++
 .../src/notification/notification-service.ts       |   3 +-
 packages/i18n/locales/en/app.json                  |  20 +--
 packages/i18n/locales/es/app.json                  |  20 +--
 packages/i18n/locales/fr/app.json                  |  20 +--
 packages/i18n/locales/ko/app.json                  |  20 +--
 packages/i18n/locales/pt-BR/app.json               |  20 +--
 packages/i18n/locales/zh-CN/app.json               |  20 +--
 packages/i18n/locales/zh-TW/app.json               |  20 +--
 packages/i18n/src/resources.d.ts                   |  18 +--
 25 files changed, 431 insertions(+), 140 deletions(-)

Fusion-Task-Id: FN-173
Fusion-Task-Lineage: efc810f4-d2b9-4ee9-874e-56ea2c00fa32
Co-authored-by: Fusion <noreply@runfusion.ai>
2026-08-23 05:19:57 +00:00
gsxdsm
012d42008f chore(release): v0.77.0-beta.7
Version bump via changesets.
2026-08-22 19:27:22 -07:00
gsxdsm
b47fb70b81 fix: defer merge on unrun pre-merge gates instead of failing the task
An enabled pre-merge gate that has not reported yet is a not-yet condition,
not a failure. FN-9191 proved the difference is load-bearing: the in-review
auto-merge sweep enqueued the card ~2s after fn_task_done and ~18s before the
graph started its own Code Review node, the merge door correctly refused, and
the auto-merge error path parked it status="failed". Code Review APPROVED two
minutes later, but every subsequent merge — including the graph's own merge
node — then died on "task is marked 'failed'".

- Merge doors throw the typed PreMergeStepsNotRunError for that blocker.
- The auto-merge error path treats it as a deferral: no status write, no
  mergeRetries burn, no operator handoff.
- enqueueEligibleInReviewTasks holds a card out of the merge queue until every
  enabled pre-merge group has a result, so the race stops at admission.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-22 19:23:15 -07:00
gsxdsm
3edb843f9b fix: start tailscaled in Docker image and preflight tailscale daemon readiness
Tailscale remote access failed in the container with a bare "process exited 1":
the image ships the `tailscale` CLI but nothing ever ran `tailscaled`, so the
`tailscale funnel <port>` spawn died instantly on "failed to connect to local
tailscaled".

- Add scripts/docker-entrypoint.sh, which best-effort starts tailscaled in
  userspace-networking mode (needs neither NET_ADMIN nor /dev/net/tun, so the
  documented `docker run` is unchanged) and then execs the CLI with CMD verbatim.
  Opt out with FUSION_DISABLE_TAILSCALED=1.
- Symlink /var/lib/tailscale into /home/node/.tailscale so the documented
  `-v <vol>:/home/node` mount persists the node login across container recreates,
  and pre-create the daemon's socket/log paths node-owned before the USER switch.
- Preflight daemon reachability and backend state with `tailscale status --json`
  in evaluateRemoteLifecycle instead of only `which tailscale`, so unreachable,
  logged-out, and stopped backends all report an actionable
  runtime_prerequisite_missing reason rather than an unexplained exit 1.

Regression coverage asserts the invariant across all three unusable-backend
surfaces, not just the reported container repro.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-22 19:09:41 -07:00
Fusion Agent
bd7a41315c fix(FN-158): remove residual conflict marker
Fusion-Task-Id: FN-158
2026-08-23 01:38:45 +00:00
Fusion Agent
bfaa0f42da FN-158: enforce workspace multi-repo merge boundaries
Support workspace tasks across a shared root with scope-driven repositories and verifiable merge gates.

- Route task work through one workspace directory with per-repository acquisition and isolation.
- Add sandbox session policies and per-repository verification command handling.
- Enforce required pre-merge checks and honest merge blocking for workspace changes.
- Update workspace, workflow, and sandbox documentation and release metadata.

Files changed:
 .changeset/fn-158-workspace-single-root.md         |   7 +
 docs/sandbox.md                                    |   6 +-
 docs/workflow-steps.md                             |   6 +-
 docs/workspaces.md                                 |  12 +-
 .../core/src/__tests__/legacy-adoption.test.ts     |  15 +-
 .../src/__tests__/required-pre-merge-steps.test.ts |  25 ++++
 .../core/src/__tests__/store-bypass-review.test.ts |  24 ++-
 packages/core/src/__tests__/task-merge.test.ts     |  24 +++
 .../core/src/__tests__/worktree-layout.test.ts     |  29 ++++
 packages/core/src/db/legacy-adoption.ts            |  20 ++-
 packages/core/src/index.gate.ts                    |   4 +
 packages/core/src/index.ts                         |   4 +
 .../core/src/merge/required-pre-merge-steps.ts     |  26 ++++
 packages/core/src/merge/task-merge.ts              |  35 ++++-
 packages/core/src/store.ts                         |  59 ++++++--
 packages/core/src/task-store/lifecycle-ops.ts      |   1 +
 packages/core/src/task-store/merge-queue-ops.ts    |   5 +-
 packages/core/src/task-store/moves.ts              |  13 +-
 packages/core/src/task-store/task-artifacts-ops.ts |  11 +-
 packages/core/src/tasks/worktree-layout.ts         |  43 +++++-
 packages/core/src/types/workflow/workflow-steps.ts |   3 +-
 .../executor-workspace-session-cwd.test.ts         |  42 ++++--
 .../src/__tests__/node-worktree-isolation.test.ts  |  13 +-
 .../src/__tests__/pi-create-fn-agent.test.ts       |  16 ++
 .../engine/src/__tests__/project-engine.test.ts    |  20 ++-
 .../src/__tests__/reviewer-workspace.test.ts       |  30 +++-
 .../src/__tests__/run-verification-command.test.ts |  90 +++++++++++-
 .../__tests__/sandbox/sandbox-exec-policy.test.ts  |  16 +-
 .../src/__tests__/sandbox/session-policy.test.ts   |  45 ++++++
 .../__tests__/workspace-add-repo-midflight.test.ts |   9 ++
 .../engine/src/__tests__/workspace-e2e.test.ts     |  13 +-
 .../workspace-root-worktree-routing.test.ts        |  18 +--
 packages/engine/src/agent-tools.ts                 |  15 +-
 packages/engine/src/agents/agent-runtime.ts        |  19 +++
 .../engine/src/agents/agent-session-helpers.ts     |  15 ++
 packages/engine/src/execution/hold-release.ts      |  29 ++++
 .../engine/src/execution/run-verification-tool.ts  | 114 ++++++++++++++-
 .../create-authoritative-workflow-seams.ts         |  20 +--
 packages/engine/src/executor/deps-bags.ts          |   5 +-
 .../executor/ensure-graph-custom-node-worktree.ts  |  24 ++-
 .../executor/ensure-task-worktree-for-planning.ts  |  36 ++---
 .../engine/src/executor/execute-workflow-step.ts   |   4 +-
 .../src/executor/finalize-already-reviewed-task.ts |   6 +-
 .../src/executor/prepare-graph-node-execution.ts   |  14 +-
 .../engine/src/executor/run-graph-custom-node.ts   | 161 +++++++++++++--------
 packages/engine/src/executor/run-implementation.ts | 117 ++++++++++++---
 packages/engine/src/merge/merger-ai.ts             |  16 +-
 packages/engine/src/merger.ts                      |  20 ++-
 packages/engine/src/pi.ts                          | 150 ++++++++++++++++---
 packages/engine/src/project-engine.ts              |  10 +-
 packages/engine/src/runtimes/in-process-runtime.ts |   4 +-
 packages/engine/src/sandbox/bubblewrap-backend.ts  |  55 ++++++-
 packages/engine/src/sandbox/bubblewrap-policy.ts   |  10 +-
 packages/engine/src/sandbox/index.ts               |   1 +
 .../engine/src/sandbox/sandbox-exec-backend.ts     |  45 +++++-
 packages/engine/src/sandbox/sandbox-exec-policy.ts |  18 ++-
 packages/engine/src/sandbox/session-policy.ts      |  41 ++++++
 packages/engine/src/sandbox/types.ts               |  11 ++
 packages/engine/src/self-healing.ts                |   1 +
 packages/engine/src/triage.ts                      |  10 ++
 .../engine/src/worktree/worktree-acquisition.ts    |  53 ++++---
 61 files changed, 1393 insertions(+), 315 deletions(-)

Fusion-Task-Id: FN-158

Fusion-Task-Lineage: ba57f5a2-fa69-4210-8ea7-3d124be3deb2

Co-authored-by: Fusion <noreply@runfusion.ai>
2026-08-23 01:37:58 +00:00