refactor(runtime): delete dead controller-generation, sealed-refresh, re-finalization and recovery-authority code - #1193
Merged
Conversation
…n path refinalizeControllerFailures re-ran host finalization of a task whose verifier had finished but which the controller had recorded as an artifact-contract failure, authorized by a newly committed controller generation. Its only caller was the `resume --refinalize-controller-failures` branch that #961 (native Smithers continuation) removed, so no package, template, script or test has called it since. Delete the function (cyclomatic complexity 74) and its three helpers. The node-controller-refinalization-intent and -result event variants stay in the event schema, so journals that recorded them still parse. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…eneration writers #961 moved `resume --refresh-controller` to renderCurrentSmithersController and removed every production caller of refreshedSmithersControllerSnapshot, prepareControllerGeneration and commitControllerGeneration, so nothing has written smithers/controller-generation-journal.json since. Linked-evidence reads (status, sync, pause, cancel, replay, fork and the inspection commands) still called effectiveControllerGeneration. For every run without a journal it replayed the whole events.jsonl and read run.json and state.json again, only to return the sealed control snapshot unchanged. - readLinkedWorkflowEvidence uses the verified control snapshot directly. LinkedWorkflowEvidence drops its controllerGeneration and controllerSnapshot fields, which for such runs equalled controlGeneration and verifiedControl. - materializeWorkflowExecutionSnapshot drops the refresh-only authorizedGenerations parameter; every caller publishes exactly the control generation. - Deleted: refreshedSmithersControllerSnapshot and its helpers (smithers.ts's only use of the TypeScript compiler), the journal writers, selection and projection code, and the refresh-only workflow-integrity helpers. - Kept: verifyCommittedControllerGenerationAuthority, the read-only verifier the Modal cloud handoff (packages/modal/src/node-provider.ts) still calls. The controller-generation fields of state.json and run.json and the workflow-controller-generation-recorded event stay in their schemas so old documents parse. Only a run refreshed before #961 has a journal, and such a run was sealed before resolved-config v4, which #1120 put out of scope. Its journal is no longer read; the refreshed snapshot generation it left beside the sealed one now fails linked-evidence reads with "workflow execution snapshots contain an unexpected generation". Tests: delete the tests of the deleted code, drop assertions that files nothing writes any more do not exist, and add a test that linked evidence does not read a leftover journal (on the base branch it fails with "controller generation journal is invalid"). Co-Authored-By: Claude Opus 5.5 <[email protected]>
Only the pre-#961 `resume --retry-failed` wrote state.provenance.recovery; #961 removed its last writer. Synchronization and terminal reporting still read it: - Every sync ran reconcilePreparedRecoveryProvenance and recoveryAuthorizesTerminalAggregate. finalRunStatus reported a run failed whenever a retained disposition said prior_status "failed" and recovered false but could not be authenticated. A run whose disposition was left "prepared" was therefore reported failed after every task succeeded, with no diagnostic. - Terminal reporting accepted a succeeded run whose engine run ended failed when workflow-recovery-authority.ts authenticated the recovery. Delete workflow-recovery-authority.ts, both workflow-sync helpers, the run-recovered emission, the recovery options of finalRunStatus and unattributedTerminalWorkflowFailure, and the observedTaskEvidence map that only the authorization read. Run status now follows the runner's terminal state. The optional recovery and recovery_history state fields and the run-recovered event variant stay in their schemas so old documents parse. Tests: delete the source-slicing workflow-completion-policy test and the recovery-authorization report tests. Rewrite the report-recovery sync test to the native same-ID resume shape (it also passes on the base branch). Add a test for a retained prepared disposition (on the base branch the run ends "failed") and one that a succeeded state cannot publish a terminal report for a failed engine run. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…lumbing - WorkflowSynchronizationControl.allowMissingWorkflowRun: #961 removed the retry preparation that passed it, and nothing else does. smithersSnapshotReportsMissingRun becomes module-private. - verifyWorkflowControlFiles and workflowControlGeneration: exported wrappers with no caller in any package, template, script or test. - The retry-failure preamble: the generated workflow embedded it and then discarded it (`void retryFailureTemplate`). The renderer stops loading it, the template drops its placeholder, and the lint globals drop the name. The prompts package still ships retry-failure.mdx. Co-Authored-By: Claude Opus 5.5 <[email protected]>
synchronizeLinkedWorkflowRun, the function that set the ceiling at 90, drops to 76 without the recovery and missing-run branches, and refinalizeControllerFailures (74) is gone. The highest remaining value is 83 (verifyCoverageProductionInventory in artifact-gates.ts), so the ceiling and the contributing guide move there. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…rifier re-checks - Delete `.ultrafuzz/prompts/_templates/agent-preamble/retry-failure.mdx`, its loader entry and its prompt-catalog row. The retry-template plumbing commit on this branch removed its only production load. Its "inserted values are data" and missing-variable assertions move to `topology-runtime-context`, the one preamble production renders with variables. - `materializeWorkflowExecutionSnapshot`: drop the generation-format check. The generation is always the SHA-256 of the seal (`verifyWorkflowControlSnapshot`), and `reconcileStaleSnapshotPublications` still checks it before any write. - `verifyCommittedControllerGenerationAuthority`: drop the re-checks of the journal head (manifest root, manifest identity, event authentication) and the default event replays that only the deleted writers used. `verifyControllerGenerationJournalEvents` already performs these checks for every entry, and every entry must be committed. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This was referenced Sep 29, 2026
aviggiano
added a commit
that referenced
this pull request
Sep 29, 2026
The earlier commits deleted the Modal node provider, the only production caller of two exports: - runtime: verifyCommittedControllerGenerationAuthority and its CommittedControllerGenerationAuthority result. #1193 deleted every other export of workflow-controller-generation.ts and kept this one only for the node provider, so the whole module goes: the journal and manifest readers it keeps are private to that verifier. The runtime index stops re-exporting it. - artifacts: referenceArtifactManifestAuthorityForArtifactDir. No generated-workflow template in v0.1.0, v0.1.1, main or integration/wave1 references either name, so resuming an older run is unaffected. The artifacts test that called its export now asserts the same fact through a live path: the parsed manifest keeps its reference authority. The runtime verifier's only test was the dynamic controller-refresh test, which #1193 deleted with the refresh code. In the generated workflow, dynamicExecutionPath(task, value, label) read `task` only for the removed cloud branch and had become a copy of currentProjectPath(value, label). It is deleted, its 12 call sites call currentProjectPath, and the seven path.resolve(process.cwd(), ...) wrappers around its already absolute result are gone. The verifier test's one-element local/cloud loop is inlined. Stale cloud wording goes from six code comments, the artifact-contract migration reference (the node schemas are deleted, not retained) and the harness research page. Refs #134 Co-Authored-By: Claude Opus 5.5 <[email protected]>
aviggiano
added a commit
that referenced
this pull request
Sep 30, 2026
…ng change New entries now go straight into CHANGELOG.md under Unreleased, so the entry this branch had moved to consolidated release notes comes back. It sits under Breaking changes rather than Other changes: a run whose report producer succeeded under an earlier release's workflow and that is resumed with --refresh-controller before its verifier runs now fails that verifier until `resume --refresh-controller --retry-failed` reruns the producer, and the reference docs retire #585's claim that the run filesystem cannot be used to forge the producer. Main already files changes without a `!` whose only break is to older runs there (#1176, #1193). The entry also says that plain `resume` keeps the workflow persisted at launch, and that the recovered producer's failed_attempts omits the attempts from before the refresh. Co-Authored-By: Claude Opus 5.5 <[email protected]>
aviggiano
added a commit
that referenced
this pull request
Sep 30, 2026
The earlier commits deleted the Modal node provider, the only production caller of two exports: - runtime: verifyCommittedControllerGenerationAuthority and its CommittedControllerGenerationAuthority result. #1193 deleted every other export of workflow-controller-generation.ts and kept this one only for the node provider, so the whole module goes: the journal and manifest readers it keeps are private to that verifier. The runtime index stops re-exporting it. - artifacts: referenceArtifactManifestAuthorityForArtifactDir. No generated-workflow template in v0.1.0, v0.1.1, v0.1.2, main or integration/wave1 references either name, so resuming an older run is unaffected. The artifacts test that called its export now asserts the same fact through a live path: the parsed manifest keeps its reference authority. The runtime verifier's only test was the dynamic controller-refresh test, which #1193 deleted with the refresh code. In the generated workflow, dynamicExecutionPath(task, value, label) read `task` only for the removed cloud branch and had become a copy of currentProjectPath(value, label). It is deleted, its 12 call sites call currentProjectPath, and the seven path.resolve(process.cwd(), ...) wrappers around its already absolute result are gone. The verifier test's one-element local/cloud loop is inlined. Stale cloud wording goes from six code comments, the artifact-contract migration reference (the node schemas are deleted, not retained) and the harness research page. Refs #134 Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #921, #462
Problem
Native Smithers continuation (#961) removed every caller of three mechanisms:
refreshedSmithersControllerSnapshot,prepareControllerGenerationandcommitControllerGeneration;refinalizeControllerFailures, reached only through the removed--refinalize-controller-failuresflag;state.provenance.recovery, written only by the pre-fix(runtime): restore native Smithers continuation #961resume --retry-failed.Their code stayed behind, about 2,350 lines of runtime source, and parts of it still ran on hot paths:
effectiveControllerGeneration. That coversstatus, sync,pause,cancel,replay,forkand the inspection commands. No run since fix(runtime): restore native Smithers continuation #961 has a controller-generation journal, so for every current run the call replayed the wholeevents.jsonland readrun.jsonandstate.jsonagain. It then returned the sealed control snapshot unchanged.reconcilePreparedRecoveryProvenanceandrecoveryAuthorizesTerminalAggregateoverstate.provenance.recovery. For every run in scope this was dead work. fix(runtime): restore native Smithers continuation #961 removed the last writer of a disposition, and resolved-config v4 (feat(runtime): default to best-effort runs with agent-written PARTIAL reports #1120), which every run in scope uses, came after fix(runtime): restore native Smithers continuation #961. The status flip this code can cause is therefore latent, and only a pre-fix(runtime): restore native Smithers continuation #961 state can trigger it. Given a retainedprepareddisposition (prior_status: "failed",recovered: false, no authenticated submission),finalRunStatusreported the runfailedafter every task had succeeded, with no diagnostic. Reproduced onorigin/integration/wave1(a48ad9c) with a hand-written fixture: the run endsfailed. On this branch it endssucceeded.synchronizeLinkedWorkflowRun(cyclomatic complexity 90) set the repository-wide ceiling.refinalizeControllerFailures(74) had no caller at all.Root cause
#961 deleted the entry points but not the machinery behind them, or the read-side hooks that still consult its state. The removed entry points were:
start-run.ts;allowMissingWorkflowRun: truesync call.Change
Six commits:
refinalizeControllerFailuresand three helpers fromworkflow-sync.ts(−568 lines). Thenode-controller-refinalization-*event variants stay in the event schema, so old journals parse.readLinkedWorkflowEvidencematerializes the verified control snapshot directly.LinkedWorkflowEvidencedropscontrollerGenerationandcontrollerSnapshot. For every run without a journal they equalledcontrolGenerationandverifiedControl.materializeWorkflowExecutionSnapshotdrops the refresh-onlyauthorizedGenerationsparameter.smithers.ts:refreshedSmithersControllerSnapshotand its helpers, about 450 lines. They included the module's only use of the TypeScript compiler.workflow-controller-generation.ts: the journal writers and the selection and projection code. The file goes from 1,203 to 532 lines.workflow-integrity.ts: the refresh-only helpers.resume --refresh-controllerpath (renderCurrentSmithersController) is untouched.workflow-recovery-authority.ts,reconcilePreparedRecoveryProvenance,recoveryAuthorizesTerminalAggregateand therun-recoveredemission.finalRunStatusandunattributedTerminalWorkflowFailure, and theobservedTaskEvidencemap that only the authorization read.failedcannot publish a terminal report.recoveryandrecovery_historystate fields and therun-recoveredevent variant stay in their schemas.docs/reference/artifacts-reports.mdis updated.WorkflowSynchronizationControl.allowMissingWorkflowRunand its branch.smithersSnapshotReportsMissingRunbecomes module-private.verifyWorkflowControlFilesandworkflowControlGeneration.void retryFailureTemplate). The renderer, the template placeholder and the lint globals all drop it.synchronizeLinkedWorkflowRundrops to 76. The new repository maximum isverifyCoverageProductionInventory(83) inartifact-gates.ts.docs/contributing.mdis updated to match..ultrafuzz/prompts/_templates/agent-preamble/retry-failure.mdx, its loader entry inpackages/prompts/src/render.ts, and its prompt-catalog row. The prompt catalog is regenerated and now lists 9 composition templates. After commit 4 nothing in production loaded the file. Its test's "inserted values are data" and missing-variable assertions move totopology-runtime-context, the one preamble that production renders with variables.materializeWorkflowExecutionSnapshot. It stood in forsortedUniqueGenerations, which had to validate generations read from the journal. The selected generation is now always the SHA-256 of the seal (verifyWorkflowControlSnapshot), andreconcileStaleSnapshotPublicationsstill checks it before any write. A read-only call with a malformed generation would still fail, on the snapshot-root or not-published check, before it reads a snapshot file.verifyCommittedControllerGenerationAuthority: the re-checks of the journal head (manifest root, manifest identity, event authentication) and the default event replays that only the deleted writers used.verifyControllerGenerationJournalEventsalready makes these checks for every entry, and every entry must be committed. The file goes from 532 to 497 lines.Size: +142 / −3,962 lines (net −3,820).
Removed from the
@ultrafuzz/runtimeindex (17 names):refinalizeControllerFailures,ControllerFailureRefinalizationInput,ControllerFailureRefinalizationResult,refreshedSmithersControllerSnapshot,RefreshedSmithersControllerSnapshot,prepareControllerGeneration,commitControllerGeneration,commitPublishedPreparedControllerGeneration,effectiveControllerGeneration,PreparedControllerGeneration,EffectiveControllerGeneration,replaceBunStartupControlsForControllerRefresh,reconcileStaleWorkflowExecutionSnapshotPublications,isBunStartupControlPath,smithersSnapshotReportsMissingRun,verifyWorkflowControlFilesandworkflowControlGeneration.@ultrafuzz/promptsloses the"retry-failure"member ofAgentPreambleTemplateName.Deliberately not built
No dedicated refusal for runs that carry a controller-generation journal, although the spec allowed one.
schemaVersionisconst: "ultrafuzz.resolved-config.v4"(by reading the code; not run).workflow execution snapshots contain an unexpected generation(see Verification).Kept
verifyCommittedControllerGenerationAuthorityand the journal and manifest readers it needs: the 497 remaining lines ofworkflow-controller-generation.ts. Its only caller is the Modal per-node cloud handoff (packages/modal/src/node-provider.ts). Draft v04 deletes that caller but not this file. Once v04 lands, the whole file and itsverifyCommittedControllerGenerationAuthorityexport have no caller. They should be deleted then, in v04 or right after it.Kept the old schema entries, so old
state.json,run.jsonandevents.jsonlstill parse:state.jsonandrun.json;workflow-controller-generation-recorded,node-controller-refinalization-*andrun-recoveredevent variants.artifact-gates.tsstill preferscontrollerExecutionSnapshotwhen a pre-fix(runtime): restore native Smithers continuation #961 state has one.Left two smithers.ts candidates from the compiler map: the predecessor-patch upgrade paths and the
ensureSmithersDependenciesrepair branches. They sit in the Smithers patch registry and controller-install code that v01 and v10 are changing.Verification
Base for comparisons:
origin/integration/wave1at a48ad9c, in a separate worktree.syncRun follows the runner past a retry-failed recovery a pre-#961 build left prepared. The base ends the runfailedwith an empty diagnostics list. This branch ends itsucceeded.linked workflow evidence does not read a leftover controller-generation journal. The base fails all reads withWORKFLOW_CONTROL_EVIDENCE_INVALID: controller generation journal is invalid. This branch succeeds in the default,observeOnlyandtolerateControlDivergencemodes. The base was run with the same assertions, under the test's earlier name and with a non-null assertion that was later replaced for strict lint.agent preamble MDX > treats inserted values as data(moved in commit 6). The rendered value names another bound variable. Against a renderer changed to expand a second time, the test fails. The change was a temporary experiment and was reverted.syncRun publishes a report after a resumed report agent succeeds. It is rewritten from the hand-built recovery-disposition fixture to the native same-ID resume shape. It also passes on the base, so it is not evidence of the change.terminal reporting refuses a succeeded run whose workflow ended failed. It keeps the refusal that the ten deleted invalid-recovery variants asserted.runtime.test.ts;dynamic-lifecycle.test.ts;verified-output.test.ts;workflow-completion-policy.test.ts, whose four tests transpiled slices ofworkflow-sync.tssource;agent-preamble.test.ts.readLinkedWorkflowEvidencein all three modes, andgetRunHealth, then returnedWORKFLOW_CONTROL_EVIDENCE_INVALID: workflow execution snapshots contain an unexpected generation.event_id, and the event's removal. All three are still rejected withcontroller generation event does not authenticate its journal entry.runtime.test.ts, targeted: 23/23 pass. The pattern covered:controller refreshtest;snapshot …materialization, recovery and anchoring test, andpublishing an execution snapshot flushes each file once.Two of the 23 first failed at launch with the known host race
workflow execution file dependencies/packages/…/<file> changed while reading(see below), and both passed when rerun alone.verified-output,pinned-submodulesandtask-workflow-identity: 59/59 pass.dynamic-lifecycle.test.ts, targeted: 8/8 pass. The pattern covered everyrefreshed controllerand controller-refresh test,current-controller rendering, and the two published-controls readability tests.@ultrafuzz/promptsagent-preambleandscaffold-catalog: 7/7 pass.Modal
node-provider.test.ts -t "controller-generation|controller generations"(the kept verifier): 4/4 pass.Earlier, before commit 6: all of
dynamic-lifecycle.test.tspassed exceptdynamic state materialization checks the synchronization deadline before publication. That test failed once under host load, then passed four reruns here and one on the base. Its 500 ms deadline also bounds the fake runner's inspection subprocess, becauseinspectionExecutionControlpassesdeadlineMs − nowas the timeout. That is the likely cause (inferred, not proven).pnpm -w build,pnpm -w typecheck,pnpm -w knipandpnpm -w docs:check;npx prettier --checkandnpx eslinton the changed files;CI=1 ESLINT_PLUGIN_DIFF_COMMIT=origin/integration/wave1 pnpm -w lint:strict:ci;pnpm -w lint. A repo-wide complexity scan puts the maximum at 83, down from 90 on the base.workflow.tsxonorigin/integration/wave1: 98 blobs, fromgit rev-list origin/integration/wave1 -- <path>. None of the 19 deleted exports appears anywhere in any of them (whole-file word match). The 19 are the 17 index names plus the two recovery-authority functions.runtime.test.ts. It was interrupted after about 11 minutes and is not evidence either way. Its three failures were:workflow execution file dependencies/packages/…/LICENSE changed while reading, which trips when other processes run pnpm on the host;Risk / compatibility
Runs sealed since fix(runtime): restore native Smithers continuation #961. They never carry a journal or a recovery disposition, so their behaviour is unchanged. The only difference is one fewer full
events.jsonlreplay per linked-evidence read (by reading the code; not timed).Runs from before fix(runtime): restore native Smithers continuation #961. These are pre-v4 and out of scope (feat(runtime): default to best-effort runs with agent-written PARTIAL reports #1120).
status,pause,cancel,replay,forkand the inspection commands with the snapshot-generation error above. Plainresumedoes not read linked evidence and is unaffected (by reading).report, dashboard). Its state issucceeded, its lastworkflow-syncedisfailed, and it hasrecovered: true.loadCurrentFinalReportSnapshotrepeats the stopped-state check on every read and now throwsterminal reporting lacks consistent stopped workflow evidence(by reading; not run). Such reports are very likely unreadable on the base already. The saved receipt must match today's projection byte for byte, and the report projection has changed since fix(runtime): restore native Smithers continuation #961 (6fffcf4, 131ff3e, b964ae2).Generated workflows and prompts. Old generated workflows keep working: none references a deleted runtime name, and each already embeds its rendered preamble, so deleting
retry-failure.mdxchanges nothing for a sealed run. No digest covers the built-in prompt tree.API.
LinkedWorkflowEvidenceloses two fields.materializeWorkflowExecutionSnapshotloses one optional parameter.renderAgentPreambleTemplateandloadAgentPreambleTemplateno longer accept"retry-failure".No workspace package used any of these;
pnpm -w buildpasses.Merge overlap. A
git merge-treeof this branch against every pushed wave-2 branch shows one conflict:smithers.tswith v04. v04 editsrefreshedSmithersControllerSnapshotandreplaceInternalModuleFiles, which this branch deletes, and both branches trim the same import lines. To resolve it:isSensitiveSecretValue, whose last use it deletes. This branch dropsassertExpandedGraphSchemaand thetypescripttype import.No other pushed wave-2 branch adds a use of a deleted name. These overlaps merge cleanly:
workflow-sync.tssynchronizeTasks(v02's node-status transitions);smithers.tsoutside the deleted code (v01's Smithers patch registry);packages/prompts/src/render.ts(v07);workflow-completion-policy.test.ts, which v09a may also target.v10 is not pushed, so it was not checked. It also changes the
smithers.tsimport block.Pre-existing failure, not fixed here.
status keeps reporting runner health when run-state synchronization failsfails identically on the base. Its tornusage.jsonlno longer makes synchronization throw, because w02 (fix(runtime): attempt and usage ledgers never block run synchronization #1186) turned accounting failures intoWORKFLOW_ACCOUNTING_FAILEDwarnings. The test still expectsWORKFLOW_STATE_SYNC_FAILED.Changelog entry
Removed three pieces of code that native continuation (#961) left without callers: the sealed controller-refresh (controller-generation journal) code, controller re-finalization, and retry-failed recovery.
resume --refresh-controlleris unchanged.status, sync,pause,cancel,replayandforkno longer replay the event journal to select a controller generation. Run status now follows the workflow runner instead of a retained recovery disposition. Two kinds of pre-#961 run are affected, and both were planned before resolved-config v4, so they are already out of scope. A run refreshed before #961 now fails these commands. A run recovered before #961 can no longer re-read its terminal report.🤖 Generated with Claude Code
The PR appears safe to merge within the current resolved-config v4 run contract.
Summary
Removes orphaned controller-generation, re-finalization, and retry-failed recovery machinery. Linked-evidence reads now use the verified seal directly, and synchronization follows the runner’s terminal state. The PR also removes the unused retry-failure preamble and lowers the complexity ceiling.
Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR A[Verified workflow-control seal] --> B[Linked workflow evidence] B --> C[Single execution snapshot] C --> D[Lifecycle and inspection] D --> E[Runner and task evidence] E --> F[Run status] F --> G[Terminal report consistency check]Reviews (1) · Last reviewed commit: "refactor: delete the orphaned retry-fail..."