Skip to content

fix(engine): board-reliability consolidation (stranded source + planning-spin + graph identity + session watchdog) - #17

Open
timoteo7 wants to merge 1 commit into
mainfrom
fix/task-dispatch-pause-review-loop
Open

timoteo7 wants to merge 1 commit into
mainfrom
fix/task-dispatch-pause-review-loop

Conversation

@timoteo7

Copy link
Copy Markdown
Owner

Supersedes the closed #10 (cannot reopen). See the commit for Root Cause + Symptom Verification.

@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

ThreatCrush Security Scan

4586 finding(s)

HIGH/CRITICAL: 43 | MEDIUM: 4032 | LOW: 511

Severity Rule Location
HIGH secret-database-url .github/workflows/full-suite.yml:55
HIGH secret-generic-credential .github/workflows/full-suite.yml:56
HIGH secret-database-url .github/workflows/full-suite.yml:284
HIGH secret-generic-credential .github/workflows/full-suite.yml:285
HIGH secret-database-url .github/workflows/full-suite.yml:324
HIGH secret-generic-credential .github/workflows/full-suite.yml:325
HIGH secret-database-url .github/workflows/pr-checks.yml:221
HIGH secret-generic-credential .github/workflows/pr-checks.yml:222
HIGH secret-generic-credential .github/workflows/release.yml:522
HIGH secret-generic-credential .github/workflows/release.yml:524
HIGH secret-generic-credential .github/workflows/test-release.yml:445
HIGH secret-generic-credential .github/workflows/test-release.yml:447
HIGH secret-generic-credential docs/cli-reference.md:80
HIGH secret-generic-credential docs/signals-connectors.md:34
HIGH secret-generic-credential docs/signals-connectors.md:77
HIGH secret-generic-credential docs/signals-connectors.md:94
HIGH secret-generic-credential docs/signals-connectors.md:117
HIGH secret-generic-credential docs/signals-connectors.md:159
HIGH secret-generic-credential packages/cli/STANDALONE.md:71
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:12
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:30
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:31
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:102
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:103
HIGH secret-generic-credential packages/core/src/postgres/embedded-lifecycle.ts:843
HIGH secret-database-url packages/core/src/postgres/embedded-lifecycle.ts:1574
HIGH secret-database-url packages/core/src/postgres/pg-backup.ts:756
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:651
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:727
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:81
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:115
HIGH js-ssrf-outbound-request packages/dashboard/src/routes.ts:1858
HIGH js-host-header-trust packages/dashboard/src/server.ts:2689
HIGH js-host-header-trust packages/dashboard/src/server.ts:2714
HIGH js-host-header-trust packages/dashboard/src/server.ts:3025
HIGH js-host-header-trust packages/dashboard/src/server.ts:3193
HIGH secret-slack-webhook plugins/examples/fusion-plugin-notification/README.md:46
HIGH secret-database-url scripts/pg-test-server.mjs:200
HIGH secret-database-url scripts/pg-test-server.mjs:231
HIGH secret-database-url scripts/pg-test-server.mjs:241
HIGH secret-generic-credential scripts/sync-fusion-skill-tools.mjs:550
HIGH secret-generic-credential scripts/verify-windows-elevated-restricted.mjs:81
HIGH secret-generic-credential scripts/verify-windows-encoding-recovery.mjs:41
MEDIUM redos-nested-quantifier docs/agents.md:1710
MEDIUM insecure-temp-file packages/cli/src/__tests__/bin.test.ts:136
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:33
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:34
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:35
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:43
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:48

…and 4536 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

FNXC:TriagePlanningRecovery 2026-09-19-04:04:
The sweep announced "Recovering specified triage task <id>" on every poll for cards it never
recovered, and recorded no outcome when the recovery declined or when its own gates skipped the
candidate. The recorded engine log held 180 announcements and zero reasons, so an operator could
paused: false,
steps: [{ title: "Implement", status: "pending" }],
workflowStepResults: [
{ workflowStepId: "plan-review", workflowStepName: "Plan Review", phase: "pre-merge", status: "passed", verdict: "APPROVE" },
timoteo7 pushed a commit that referenced this pull request Sep 24, 2026
…ead-only)

FNXC:VerifyPerf 2026-09-24-01:00:
MOVED from #17 (board-reliability) to #11 (verify-perf theme, per review). The typecheck step keeps the incremental
tsbuildinfo cache (warm runs recheck only changed files) while staying READ-ONLY (--noEmit: no dist emit, no partial dist
on a killed typecheck).

Symptom Verification: warm verify typecheck rechecks only changed files; the step emits nothing (read-only).
@timoteo7
timoteo7 force-pushed the fix/task-dispatch-pause-review-loop branch from e6c0b48 to 6f75d66 Compare September 24, 2026 01:00
Comment thread packages/engine/src/__tests__/self-healing.test.ts Fixed
Comment thread packages/engine/src/__tests__/self-healing.test.ts Fixed
@timoteo7
timoteo7 force-pushed the fix/task-dispatch-pause-review-loop branch 3 times, most recently from 9f58a8b to a14c77b Compare September 24, 2026 06:07
@timoteo7
timoteo7 force-pushed the fix/task-dispatch-pause-review-loop branch from 78daa29 to 321491d Compare September 25, 2026 04:15
@timoteo7

Copy link
Copy Markdown
Owner Author

Review notes for the audited SHA 321491dccfbcb753619e9da29dfd35de0a72ec10:

The current diff changes ten TypeScript configs to disable source/declaration maps; it does not contain the stranded-source, planning-spin, graph-identity, or watchdog fixes promised by the title. Please retitle and scope this as a build-output change, or close/supersede it with the actual behavior fixes in their respective PRs. Six of the config edits appear redundant because those packages inherit the changed plugin base config.

Before landing the map change, please show a measured build/package benefit and verify that published diagnostics/artifacts do not depend on those maps. The package-files test and upstream config expect map globs, but that alone does not prove this change breaks packaging; the issue is that the PR currently provides neither the advertised reliability work nor evidence for removing the maps.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants