Post-fix verification review (correctness + adversarial + reliability, unanimous
P0) found that the earlier retry-burn fix introduced an infinite loop: parking a
WorkspaceTaskMergeError task with status:null + mergeRetries:0 passes every
auto-merge eligibility gate (canMergeTask short-circuits only on status==='failed'),
so the cooldown sweep re-enqueues it every tick → guard re-throws → re-park, forever.
- Park with status:'failed' (keep mergeRetries:0). canMergeTask now blocks the
auto-sweep; a human's manual merge still works because it flows through the
manual-resolver branch (rejectMergeResolvers), which bypasses canMergeTask — so
'failed' does not block manual retry (the original comment's worry was wrong).
- Detect the error via `err instanceof Error && err.name === "WorkspaceTaskMergeError"`,
matching the VerificationError/MergeAbortedError convention and bundle-safe across
the @fusion/core→@fusion/engine boundary (drops the now-unused class import).
- Document that the dispatch door guard is a fast-fail only; the unconditional
chokepoint guard inside runAiMerge is the authoritative enforcement.
- Add a regression test asserting the auto-merge park sets status:'failed' (not null).
Gate green: lint, typecheck, build, test:gate (649+58), project-engine (81).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>