FN-8923 sat silent in Todo for 7+ hours with zero run-audit rows. Its plan node
held on principal routing, triage correctly recorded `needs-replan`, and then
dependency auto-unblock nulled that status when its blocker completed. From that
moment the card was invisible to both lanes: triage saw a fully-written spec with
no replan flag and skipped it, while the executor's `isUnplannedForExecution`
refused to dispatch because no capacity-boundary continuation existed. Not stuck
in a retry loop -- unowned.
- Dependency auto-unblock clears only the `queued` marker it owns, at all four
sites (scheduler.ts plus three in self-healing.ts). `status` is a shared
lifecycle channel and `needs-replan` is the only signal that re-admits a
hold-column card whose PROMPT.md is already a real spec.
- New self-healing sweep `reconcilePrincipalHeldPlanningContinuations` re-queues
planning for a card whose sole active continuation is a principal-routing hold.
A planning hold otherwise has no retry owner at all. Gated on the planning
lane, effective auto-merge, an owned (null) status, and the shared planning
lifecycle lock, so it cannot clobber a triage claim or launder a `failed` /
`stuck-killed` / `queued` card into a replan.
- Workflow node-instance-id materialization is idempotent across foreach, loop,
and optional-group containers. It re-wrapped its own output on every dispatch,
so FN-8869 grew a ~1.8 KB `run_id` of ~30 repeated segments on a hot indexed
column and every retry read as a distinct run.
- An unresolvable node instance or absent IR now fails closed instead of being
treated as an edited-away override -- the previous shape would have discarded a
real reviewer fence and handed a named review to the pool.
- Mirror the routing exports into the gate-safe core barrel; the reduced barrel
resolved them to `undefined`, a latent trap for any suite reaching the router.
Findings from a multi-reviewer pass; 9 of 11 confirmed by an independent
validator. Each fix carries a regression asserting the invariant across its
surfaces, not the single reported case -- the optional-group accretion test was
verified to fail without the fix.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>