Skip to content

fix(engine): report the failing workflow-graph stage instead of node unknown - #16

Open
timoteo7 wants to merge 1 commit into
mainfrom
fix/graph-failure-node-identity-beta6
Open

timoteo7 wants to merge 1 commit into
mainfrom
fix/graph-failure-node-identity-beta6

Conversation

@timoteo7

Copy link
Copy Markdown
Owner

See commit for Root Cause + Symptom Verification (FUSI-020/021/022).

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

ThreatCrush Security Scan

4586 finding(s)

HIGH/CRITICAL: 43 | MEDIUM: 4032 | LOW: 511

Severity Rule Location
HIGH secret-database-url .github/workflows/full-suite.yml:55
HIGH secret-generic-credential .github/workflows/full-suite.yml:56
HIGH secret-database-url .github/workflows/full-suite.yml:284
HIGH secret-generic-credential .github/workflows/full-suite.yml:285
HIGH secret-database-url .github/workflows/full-suite.yml:324
HIGH secret-generic-credential .github/workflows/full-suite.yml:325
HIGH secret-database-url .github/workflows/pr-checks.yml:221
HIGH secret-generic-credential .github/workflows/pr-checks.yml:222
HIGH secret-generic-credential .github/workflows/release.yml:522
HIGH secret-generic-credential .github/workflows/release.yml:524
HIGH secret-generic-credential .github/workflows/test-release.yml:445
HIGH secret-generic-credential .github/workflows/test-release.yml:447
HIGH secret-generic-credential docs/cli-reference.md:80
HIGH secret-generic-credential docs/signals-connectors.md:34
HIGH secret-generic-credential docs/signals-connectors.md:77
HIGH secret-generic-credential docs/signals-connectors.md:94
HIGH secret-generic-credential docs/signals-connectors.md:117
HIGH secret-generic-credential docs/signals-connectors.md:159
HIGH secret-generic-credential packages/cli/STANDALONE.md:71
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:12
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:30
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:31
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:102
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:103
HIGH secret-generic-credential packages/core/src/postgres/embedded-lifecycle.ts:843
HIGH secret-database-url packages/core/src/postgres/embedded-lifecycle.ts:1574
HIGH secret-database-url packages/core/src/postgres/pg-backup.ts:756
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:651
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:727
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:81
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:115
HIGH js-ssrf-outbound-request packages/dashboard/src/routes.ts:1858
HIGH js-host-header-trust packages/dashboard/src/server.ts:2689
HIGH js-host-header-trust packages/dashboard/src/server.ts:2714
HIGH js-host-header-trust packages/dashboard/src/server.ts:3025
HIGH js-host-header-trust packages/dashboard/src/server.ts:3193
HIGH secret-slack-webhook plugins/examples/fusion-plugin-notification/README.md:46
HIGH secret-database-url scripts/pg-test-server.mjs:200
HIGH secret-database-url scripts/pg-test-server.mjs:231
HIGH secret-database-url scripts/pg-test-server.mjs:241
HIGH secret-generic-credential scripts/sync-fusion-skill-tools.mjs:550
HIGH secret-generic-credential scripts/verify-windows-elevated-restricted.mjs:81
HIGH secret-generic-credential scripts/verify-windows-encoding-recovery.mjs:41
MEDIUM redos-nested-quantifier docs/agents.md:1710
MEDIUM insecure-temp-file packages/cli/src/__tests__/bin.test.ts:136
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:33
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:34
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:35
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:43
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:48

…and 4536 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

FNXC:TriagePlanningRecovery 2026-09-19-04:04:
The sweep announced "Recovering specified triage task <id>" on every poll for cards it never
recovered, and recorded no outcome when the recovery declined or when its own gates skipped the
candidate. The recorded engine log held 180 announcements and zero reasons, so an operator could
paused: false,
steps: [{ title: "Implement", status: "pending" }],
workflowStepResults: [
{ workflowStepId: "plan-review", workflowStepName: "Plan Review", phase: "pre-merge", status: "passed", verdict: "APPROVE" },
@timoteo7

Copy link
Copy Markdown
Owner Author

Consolidated into #14 (board-reliability).

@timoteo7 timoteo7 closed this Sep 23, 2026
timoteo7 pushed a commit that referenced this pull request Sep 23, 2026
…lanning-spin + graph identity)

FNXC:BoardReliability 2026-09-23-22:04:
Consolidates the board-reliability fixes into ONE PR (supersedes #15 and #16):
1. SOURCE-OF-TRUTH stranded count (execution/stranded-commits.ts): fork-point + "0 task-unique = 0 stranded";
   a failed fork-point falls back to ZERO, never the raw baseRef (shared fork/main lineage is never unsaved work).
2. Planning-spin: an unchanged-but-valid authoritative PROMPT.md is SUCCESS (was re-planning forever).
3. Graph-failure identity: a parse/compile failure names the failing stage, not node 'unknown'.
4. Manual retry clears ANY non-user pause (was only the deadlock reason).

Symptom Verification:
- Original symptom: "not safely reclaimable (N stranded commits since <base>)" treadmill + planning-spin + node 'unknown'.
- Exact reproduction: a task branch at the main tip (0 unique commits) vs merge-base; a valid unchanged PROMPT.md.
- Assertion it is gone: countStrandedCommits()==0 for shared lineage at the single source; planning accepts a valid unchanged spec.
@timoteo7 timoteo7 reopened this Sep 24, 2026
@timoteo7

Copy link
Copy Markdown
Owner Author

Review notes for the audited SHA 16c2e407c71add68e8f08f6755f58355ac6b11ab:

The pause/deletion guard on the delayed Plan Review retry is useful; please keep it with a behavioral test proving a paused, user-paused, or deleted task is not dispatched. The title's graph-stage identity fix is not present in the diff—the added note says that identity is still deferred—so the title/scope should be corrected or the actual diagnostic change added separately.

The PR also carries shellout allowlist entries for integration-branch.ts, which is changed in #5, not here. At this audited SHA, the scanner finds four synchronous call sites in that file, while the PR test expects eight and adds allowlist signatures that do not match those sites. Please move the matching allowlist updates with the integration-branch implementation and assert both unmatched and stale allowlist entries, rather than keeping mismatched policy data here. The TypeScript build changes belong with the performance work in #11.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants