Skip to content

Report actionable merge refusals and preserve recovery certainty - #2519

Merged
cbusillo merged 4 commits into
mainfrom
work/issue2494-train-refusal-evidence
Sep 27, 2026
Merged

cbusillo merged 4 commits into
mainfrom
work/issue2494-train-refusal-evidence

Conversation

@shiny-code-app

@shiny-code-app shiny-code-app Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

GitHub's conclusive 405 merge refusal was reported as an upstream outage with a retry instruction. The adapter now preserves that rejection, reads the same PR once for bounded diagnosis, and returns HTTP 409 github_merge_rejected with the attempt trace, PR number, provider status, and either an observed behind head or an explicitly unconfirmed cause. Raw provider bodies are excluded.

On a resumed partial batch, LP first reconciles an unresolved earlier attempt from the unchanged open-head/base evidence, then blocks an observed behind head before new admission or another merge. The first landed entry remains recorded. This is the refusal/recovery slice of #2494; the separately approved protected batch PR implementation follows under #2518.

Validation:

  • 218 focused adapter, HTTP/controller, and persisted-admission tests passed; the final adapter run has 90 tests including the two reproduced review regressions.
  • All 3,616 local unittest targets passed after the review fixes; Ruff, formatting, and mypy passed.
  • JetBrains explicit inspection of all seven PR files: RED, 115 findings. Triage identified 112 findings on unchanged lines, an intentional diagnostic exception boundary, and two intentional test-double casts. No suppression or profile change. The earlier clean-worktree changed-files report did not establish PR coverage; see the inspection correction comment.
  • Anthropic claude-opus-5-5 review found two issues: blocking before unresolved-attempt reconciliation, and an IncompleteRead diagnostic failure masking the 405. Both reproduced and were fixed. The full local suite passed afterward.

No live merge or provider mutation was used to test refusal handling. Real batch landing and service-posted feedback remain required by #2494. The qualification pair #2516/#2517 stays unqueued until the batch landing repair is deployed.

Refs #2494. Design decision: #2518.

Commit 8fda3439 also returns fixed public error text to address CodeQL alert 45; 100 HTTP merge-train tests pass. The attempted train landing was rejected before effect, as recorded in the controller diagnostic and linked workflow comment.

Comment thread control_plane/http_app.py Fixed
@shiny-code-app shiny-code-app Bot added the ready-to-merge Every Code PR is ready for repository owner merge review label Sep 26, 2026
cbusillo added a commit that referenced this pull request Sep 26, 2026
@cbusillo

cbusillo commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Launchplane completed the merge-train step for this pull request.

Launchplane finished the merge-train step for this pull request.

Launchplane manages this comment and will update it as the train moves.

@shiny-code-app

Copy link
Copy Markdown
Contributor Author

The attempted train landing was refused: Merge Train Runner 36280044430, trace launchplane_req_13158ea3c0194af78dda1f6067de2649. The stored controller diagnostic classifies the #2519 outcome as outcome_rejected; GitHub confirms the PR is still open and unmerged. No repeat landing was requested.

GitHub's merge panel identifies CodeQL alert 45 as a blocking rule despite passing workflow checks. Commit 8fda3439 replaces the response's exception string with fixed public text, retaining the bounded status/PR/diagnosis fields. All 100 HTTP merge-train tests and Ruff checks pass; fresh CI and CodeQL are pending.

Inspection correction: the prior clean-worktree changed_files report did not establish full PR-file coverage. A fresh inspection of the two locally changed files returned RED with 39 findings, including warnings on unchanged lines. An explicit inspection of all seven PR files is now running; the original blanket GREEN claim is withdrawn pending full triage. No suppression or profile change was made.

@shiny-code-app

Copy link
Copy Markdown
Contributor Author

Inspection triage for 8fda3439: explicit coverage of all seven PR files returned native RED, run 45, with 115 findings. Of these, 112 are on unchanged lines relative to origin/main; this patch does not undertake their cleanup. The three findings on changed lines were reviewed:

  • The diagnostic-only broad exception at merge_train_github.py:1433 is deliberate. A failed follow-up GET, including a truncated HTTP body, must never replace the already observed conclusive 405. The IncompleteRead regression test covers this boundary. The provider-effect exception path remains separate.
  • Two casts in test_merge_train_github.py inject the existing permissive structural test double into GuardedMergeAdmission call sites. The tests deliberately exercise the real provider adapter with that double; the fixture implements the invoked methods. Mypy accepts these casts, and no production cast was introduced.

No inspection suppression, profile change, or baseline change was made. The detailed cached findings read later reported project snapshot churn, so that follow-up read is diagnostic evidence rather than a new current verdict; the completed native inspection's RED result is retained. The previous blanket GREEN statement is superseded by this bounded report. All 100 HTTP merge-train tests passed on the CodeQL fix, and hosted checks remain pending.

cbusillo added a commit that referenced this pull request Sep 27, 2026
@cbusillo
cbusillo merged commit 51701ba into main Sep 27, 2026
33 checks passed
@cbusillo
cbusillo deleted the work/issue2494-train-refusal-evidence branch September 27, 2026 00:28
@shiny-code-app

Copy link
Copy Markdown
Contributor Author

Delivered through the normal LP train, with the CodeQL fix included:

  • Landing: 51701bac73b3c38cbf4f3724acade37643c38599 via protected runner 36282512782.
  • Controller trace: launchplane_req_84097889817b4f199bb9bde23330cd16; candidate d8e90d8d0e065d139332637db57058f7938f79b3; final merged record merge-train-batch-landing-plan-20260927T002816Z-6990913e0b514d1b. The controller is idle with clean reconciliation.
  • Service-managed completion feedback was delivered by that runner.
  • Exact landing CI, Security, and CodeQL passed. Deploy Launchplane 36282604246 passed and built image digest sha256:e06fcad94c57c75c291c1ca1fd07e7c854eb5491f52a29b21fa3cef852c24d28 with revision label 51701bac73b3c38cbf4f3724acade37643c38599.
  • The deployed service reports that same digest, runtime read trace launchplane_req_19f73066f44a49b0b3fe6b1202de6f54. The clean local default checkout was safely fast-forwarded to the exact landing.

This prerequisite's delivery does not close #2494. The protected batch implementation is #2524; #2516/#2517 remain unqueued for its genuine two-entry proof.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-to-merge Every Code PR is ready for repository owner merge review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants