FN-5351 adds structured telemetry for merge audit events and integration worktree state, including typed ref-advance tracking, terminal handoff fallback audit, and integration state probes with corresponding reliability backstop tests and documentation updates.
Fusion-Task-Id: FN-5351
Implements ref-only integration branch advancement via `git update-ref` instead of checkout+commit, including a new `merger-ref-update-advance.ts` helper, a reduced and clarified `merger.ts`, comprehensive unit and real-git regression coverage, and audit event wiring.
Fusion-Task-Id: FN-5350
Removes the `cwd-main` integration fallback mode (FN-5348), eliminating the legacy shortcut path where the merger would operate directly on the project root instead of a dedicated worktree. Steps normalize the `reuse-task-worktree` integration mode as the sole path, wire stricter mode invariants in
Fusion-Task-Id: FN-5348
Fixes a stale queued-status recovery branch in self-healing and updates the corresponding test assertions to match the corrected behavior.
Fusion-Task-Id: FN-5434
A task that picked up status='queued' or overlapBlockedBy while waiting in
todo (file-scope overlap with a higher-priority peer) was carrying those
todo-dispatch markers into in-review, where the merge gate then permanently
refused with "task is marked 'queued'". Ghost-review → todo → scheduler
re-queue → stranded-completed-todo recovery → in-review formed a steady-
state loop that never let the task merge.
moveTaskInternal now treats queued/blockedBy/overlapBlockedBy as todo-only
dispatch state and clears them on every transition into in-review. failed
and awaiting-* statuses are left untouched (already covered by an existing
test, plus a new regression test for the queued case).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Added executor logic to skip retries when a review is pending for a task, introducing a `pendingReviewBlockHelper` in the task-done path and updating the retry-gate to consult it; two new reliability-interaction test suites cover the feature behavior and composition with existing retry/backstop laye
Fusion-Task-Id: FN-5436
Close the last fire-and-forget gap from the previous fixes: the task:moved
(away from in-progress) and task:deleted listeners no longer call the
synchronous fire-and-forget `abortInFlightTaskWork`. Instead they track an
awaited disposal promise per task in `pendingTaskDisposals`. The task:moved
(to in-progress) dispatch path awaits any in-flight disposal for the same
task before calling `execute()`, so a fast bounce (in-progress → todo →
in-progress) no longer races the conflict-cleanup path against a still-live
shell.
`awaitAbortInFlightTaskWork` now claims each session surface (activeSessions,
activeStepExecutors, activeWorkflowStepSessions, activeSubagentSessions)
synchronously before awaiting any async abort. This lets concurrent disposal
calls for the same task dedupe naturally — the second call finds the maps
empty and no-ops, preserving the existing single-abort/single-dispose
contract that the soft-delete and user-cancel tests assert.
Adds a regression test in executor-user-cancel covering the re-dispatch
ordering: an immediate task:moved-to-in-progress that follows a still-running
task:moved-away must wait for abort to complete before execute() runs.
The legacy `abortInFlightTaskWork` is removed (no callers).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Code-review follow-up to cf0101be7. The merger integration worktree path
was still calling bare `activeSessionRegistry.reconcileStaleSelfOwned` for
same-task entries, bypassing the minIdleMs window introduced by the main
fix. A merger-handoff that races a warming-down session could clear a
registry entry < 5s old. Route through `reconcileSelfOwnedActiveSessionForRemoval`
with the `executingTaskLock` process probe so all reconcile sites enforce
the same liveness contract. Test updated to backdate `registeredAt`,
matching the pattern used for the other reliability-interactions tests.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Three independent reliability fixes that all surfaced as the same bug:
live tasks losing their worktrees mid-execution and emitting
`wrong_toplevel` errors.
Fix A — executor stale-self-owned classifier:
`reconcileSelfOwnedActiveSessionForRemoval` now takes a process-active
probe (`executingTaskLock.has`) and a minimum-idle window (default 5s)
in addition to the existing in-memory `activeWorktrees` binding probe.
Recently-registered or still-running entries are refused with
`process-active-refuses` / `too-recent-refuses`, with audit-grade
log lines. Both the pre-remove path
(`reconcileSelfOwnedBeforeRemove`), the post-throw retry in
`removeOwnWorktreeWithReconcile`, and the defensive reconcile in
`removeWorktree` route through the same hardened gates.
Fix B — pause synchronously reaps the agent session:
New `awaitAbortInFlightTaskWork` mirrors the existing fire-and-forget
abort but awaits each `session.abort()` /
`stepExecutor.terminateAllSessions()` /
`workflowSession.abort()`. `parkTaskAfterWorkflowStepPause` calls it
before `moveTask("todo")`, and the `task:updated` user-pause handler
routes through it, so a fast re-dispatch can no longer race a still-
live shell.
Fix C — self-healing realpath + active-task skip:
`reconcileTaskWorktreeMetadata` now realpath-normalizes both sides of
the registry comparison (handling macOS `/private/var/...`) and
refuses to clear `worktree`/`branch` on in-progress or in-review
tasks. The skip emits a new
`task:auto-recover-worktree-metadata-skipped-active` audit event;
executor-level recovery paths remain in charge of active tasks.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- Added optional dependencies parameter to taskUpdateParams schema
- Implemented validation for self-dependency and non-existent task IDs
- Updates task dependencies via store.updateTask() when parameter is provided
- Preserves existing dependencies when parameter is omitted
- Updated tool description to document the new parameter
Adds a fallback retry counter to the reviewer that resets on successful step completion, preventing premature escalation when earlier steps exhaust retries while later ones succeed; also aligns dashboard trace buffer types and adds comprehensive coverage for the reset semantics.
Fusion-Task-Id: FN-5435
Fixed self-healing to suppress unnecessary blocked-by refreshes when there are no changes (no-op), preventing spurious requeues. Added a regression test covering this scenario in the self-healing test suite.
Fusion-Task-Id: FN-5433
Raised room transcript defaults (`messagesBefore` and `daysBefore`) in the core settings schema and updated project-level setting defaults, with corresponding documentation refresh in the settings reference. Added full test coverage for room compaction defaults, pinned room default settings in Setti
Fusion-Task-Id: FN-5374
The unconditional listTasks() in assertNoDependencyCycle was wasted work
for the common no-dependency write and broke the same-agent duplicate
intake fail-open path: tests that stub listTasks to throw had the cycle
check consume the rejection before _maybeAutoArchiveSameAgentDuplicate's
try/catch could swallow it, propagating the error out of createTask.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Adds a `room-coordination.ts` helper module for multi-agent coordination messaging, wires coordination notices into the agent heartbeat path, and ships tests plus documentation for the feature. A changeset prepares the `@runfusion/fusion` package for release.
Fusion-Task-Id: FN-5425
Scheduler now gates task update invalidation, preventing spurious invalidations when engine lifecycle changes (soft-delete, lease recovery) touch task metadata, with coverage via new scheduler invalidation tests and a small dashboard server test adjustment.
Fusion-Task-Id: FN-5430
The dashboard's corruption banner refresh action was a no-op for clearing
stale corruption flags after the user repaired the DB. Database.
scheduleBackgroundIntegrityCheck runs the integrity check exactly once at
engine boot and then early-returns forever after, so corruptionDetected
was sticky for the life of the process. POST /api/health/refresh just
read the cached flag back.
Add Database.refreshIntegrityCheck() and TaskStore.refreshDatabaseHealth()
which synchronously re-run the integrity check and update the cached
state, and have the route use them. After REINDEX / fn db --vacuum / any
in-place repair, users can now clear the banner without restarting the
engine.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Exposes the `opencode-go` provider via `startup-model-sync`, wires it into the daemon and serve commands, and adds a refresh-status indicator in the SettingsModal that triggers model reloading whenever the provider key is saved. Includes a changeset, settings documentation, and corresponding tests a
Fusion-Task-Id: FN-5424
One-off helper to re-import specific FN-* tasks from .fusion/tasks/<id>/task.json
back into the live SQLite DB after a restore. Mirrors the column list used by
db-migrate.ts:migrateTasks but uses INSERT OR IGNORE so existing rows are
never overwritten. Used to rebuild FN-5415..FN-5425 after the FN-5407 backup
corruption recovery.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The tasks table description column is NOT NULL, so a task arriving with
description == null/undefined would fail the insert with a constraint
error. Default to "" in getTaskPersistValues, matching the ?? null / ?? 0
treatment of other optional fields.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Backups opened a second node:sqlite connection against the live fusion.db
and ran PRAGMA wal_checkpoint(TRUNCATE) before copying. A node:sqlite
SIGSEGV mid-checkpoint (the recurring pager_write crash noted in db.ts)
could leave the main DB file extended-but-zeroed, which is exactly the
failure mode that wiped a 1GB fusion.db tonight.
Replace the in-process checkpoint with a plain cp of the main DB plus any
sibling -wal/-shm files. SQLite replays the WAL on first open, so
uncheckpointed pages survive without us ever opening a second connection
against the live database.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The merge adds a post-completion defensive backstop that probes and removes stale same-task `activeSessionRegistry` entries on `done`/`archived` transitions, completing FN-5346 with a shared reconcile helper, a defensive ownership probe wired into paused cleanup, audit event alignment, and regressio
Fusion-Task-Id: FN-5346
Add room open performance diagnostics and warm cache hydration for room switches (FN-5388). The implementation adds a timing instrumentation utility, SWR cache constants, warm-room handoff logic in `useChatRooms`, and a documentation file covering the performance model, accompanied by regression tes
Fusion-Task-Id: FN-5388
FN-5407 adds paired central backup support to the Fusion task management system, with both the core backup engine and CLI commands updated to handle central database backup pairs. Documentation was updated to reflect the new capability, and two stabilization fixes were included to handle central bac
Fusion-Task-Id: FN-5407
FN-5389 adds dashboard resume event instrumentation: a `resumeInstrumentation` utility captures SSE resume signals, wired through `useChat`, `useChatRooms`, and `useTasks` hooks, with remount markers in `Board` and `ChatView`; diagnostics routes expose resume events for observability, documented in
Fusion-Task-Id: FN-5389
Preserve chat scroll state across view transitions in ChatView, with comprehensive test coverage. The feature adds scroll position persistence logic gated behind a debug trace flag, and a full test suite covering the scroll state behavior.
Fusion-Task-Id: FN-5380
Removes a title-length guard from mission routes (4-line deletion in `mission-routes.ts`) and adds end-to-end coverage for long interview mission titles (`mission-e2e.test.ts`).
Fusion-Task-Id: FN-5406
Removes the speculative orphan requeue mutation path from self-healing, replacing it with an observation-only sweep that no longer attempts to re-enqueue orphaned tasks — a conservative regression that eliminates noisy false-positive recovery attempts. The change includes rewritten unit coverage, a
Fusion-Task-Id: FN-5337
Added manifest-gated checksum verification for cloudflared remote access tunnels: a pinned manifest validator (Step 1) and enforcement logic (Step 2) wired into the settings memory routes, with aligned tests and documentation covering fail-closed install behavior and pending-manifest guidance.
Fusion-Task-Id: FN-5375
Follow-up to c64884c24 addressing three review findings, including one
real interaction bug caught by a new test.
MEDIUM
- Re-indented and rewrote 'if (directReuseEligible) try { ... } catch'
as 'if (directReuseEligible) { try { ... } catch { ... } }' with the
whole body at one consistent indent level. No behavior change \u2014 fixes
the mismatched indentation from c64884c24 where the body sat one level
deeper than its containing block.
LOW
- Two new backstop tests in merge-reuse-task-worktree.test.ts:
* 'preserves worktrees with uncommitted tracked changes' \u2014 asserts the
fast-path leaves a tracked-dirty worktree alone (result.worktreeRemoved
is false, dir still exists). Without this, a future refactor could
silently re-enable destructive cleanup.
* 'cleans up worktrees with only untracked noise' \u2014 asserts untracked
junk (.DS_Store, editor swap files) does NOT block cleanup. Also caught
a real interaction bug: 'git worktree remove' without --force refuses
on untracked files, so the LOW finding's intent (drop noise, preserve
tracked dirt) needs --force on the removal call. Restored --force with
a comment explaining why it's safe (the tracked-only dirty check above
already refused if there was real work to preserve).
- Switched 'git status' check from '--untracked-files=normal' to
'--untracked-files=no'. Tracked modifications and staged changes still
block cleanup; untracked junk is correctly ignored. Dirty-skip warn log
now includes the first 5 dirty paths for operator diagnosability.
Tests
- Full @fusion/engine suite: 448 files / 5883 tests / 9 skipped, all green
- pnpm lint green, pnpm build green
Follow-up to 8e6740468 addressing six review findings, including one real
regression (combined short flags bypass amend detection).
HIGH
- Combined short flags ('-am', '-vm', '-sm', '-aF', ...) now count as
message-supplying tokens in the prepare-commit-msg empty-commit guard.
Previously, an agent could bypass the guard with
git commit --allow-empty -am 'fix --amend handling'
because '-am' did not match the literal '-m' case, so the token loop
continued past the message text and matched the '--amend' substring inside
it. The new pattern -[!-]*[mF]* matches any short combined flag containing
'm' or 'F' while leaving '--amend' (starts with '--') untouched.
Verified locally with two regression tests for '-am' and '-vm' plus one
positive test confirming legitimate '-am' with a real tracked modification
still succeeds.
MEDIUM
- Early empty-own-diff fast-path cleanup no longer uses 'git worktree remove
--force'. We now run 'git status --porcelain --untracked-files=normal'
first; dirty worktrees (or status-check failures) are left alone for the
self-healing sweep to reconcile later. Prevents silent loss of uncommitted
scratch in the no-op finalize path.
- MergeResult.task is now kept in sync with the DB after early-fast-path
cleanup. After 'store.updateTask(taskId, { worktree: null, branch: null })'
succeeds, the in-memory task.worktree/.branch are also cleared to undefined
so the returned result.task does not advertise a removed path or deleted
branch.
LOW
- Branch deletion in the fast-path cleanup only fires when 'task.branch' was
non-null on entry. If the task did not explicitly own a branch on entry,
we never invoke 'git branch -D'; orphan refs are left for
cleanupOrphanedBranches to handle. Prevents deleting a stray ref that
happened to share the canonical name.
- Inverted the empty 'if (poolBypassRequired) {} else { ... }' block in
reacquireReuseIntegrationWorktree to 'if (directReuseEligible) try { ... }'
with the pool-bypass note above it. No behavior change \u2014 just removes the
awkward empty branch and the one-level-deeper indent on the direct-reuse
logic.
Tests
- Full @fusion/engine suite: 448 files / 5881 tests / 9 skipped, all green
- pnpm lint green, pnpm build green