Skip to content

bug(ship): recover original unit after post-approval changes #2412

Description

@justinhelmer

What happened

Original Switchboard #2406 Ship unit plan-fix-issue-2406-a-salvage-25fd9f:U1 opened PR #2411 at exact 6c4228c08466a79fd839d01660de5b27812526ef. Its first automated review approved and ended the unit merge_ready. An independent review then found a P0 production-shaped failure: child.startedAt < codingStart.at rejects the actual nominal #3808 U4 by 2,686 ms. GitHub now has a CHANGES_REQUESTED review at that exact head; #2411 must not merge.

The existing #2406 Slack thread received one explicit agent:ship finding follow-up. It created a new Ship instance plan-on-the-existing-2406-uni-8d01ad (parent 73a65d62-7275-4a86-931e-4897e98b0541, coding child 77d88183-d6fb-4740-ac56-f34857e45e59) instead of a fix round on the original unit. Both were stopped before the child attached its workspace: zero model turns/tool calls/code writes, no PR. Its accidental branch points to then-current main e95df261ef9be23f075cc80f37d1baec933e6d9d and is retained for audit. The original #2411 head remains unchanged and blocked.

Current supported-path gap

Live v1.264.0 recoverOriginalUnit accepts a terminal request_changes/no_verdict review boundary, not this original unit's approve + merge_ready ending. It would return recovery_ending_unsupported. The unit also reports a channel $50 cost cap; current recovery refuses unknown prior spend with cost_cap_spend_unknown, which must not be bypassed. Merged #2409 improves explicit PR targeting for fresh Ship work, but its spec treats a completed publication-bound unit as released and starts a new unit. It does not preserve this original unit identity.

Expected

Provide a supported, exact-head continuation for a completed original Ship unit when a later legitimate review requests changes before person merge. Verify the same requester/owner, repository, unit, ref, PR, and head; preserve cumulative rounds/time/cost and durable spend evidence; reject stale, foreign, missing or competing writes. Admit at most one fix round on the original unit, require a production-shaped regression with the child starting 2,686 ms before its coding-start event, then re-review and current-head CI before merge readiness. Do not infer spend, reset a cap, or replace the original unit/ref/writer. If the contract cannot safely support this case, expose the exact refusal and a reviewed operator disposition path.

Related but distinct: #2362 concerns a body-only follow-up routed to Ship; #2265 is a checkpoint command misroute; #2350 loses publication binding after a head rewrite; #2406 is the underlying salvage-pushed findings repair. This issue is post-approval correction of a merge_ready original unit.

Activity

  1. coreplane-switchboard commented on Sep 26, 2026

    @coreplane-switchboard
    Contributor

    Independent exact-head review requested for the #2412 repair at 387d0326cbd29157ae06c5b39b13cc5ed81b8556, branch plan/fix-p0-issue-2412-from-c-85c007/u1. The focused PR description is submitted; PR creation and CI await the coding post-step. This is not a request to resume #2406, #2411 or Nominal U4.

    Review focus: exact later review/reviewer/head authorization, complete persisted priced child evidence including failed attempts, one CAS claim/receipt, unchanged absolute lease and $50 cap, full read-only review before typed findings, maxRounds and exact-head CI/re-review. The six focused files pass 704 tests; bot tsconfig, changed-file lint/format, hygiene/specs, test-guard and decisions checks pass. No live recovery, merge, release or deployment was attempted.

    Receipts: original source unit plan-fix-p0-issue-2412-from-c-85c007:U1; coding child 63425468-74c0-41cf-8738-4b6176cac8e8; rebased onto main 345ed441 before the final leased push. Parent-run UUID is not exposed to this child. No PR or CI result was visible at the last API read.

    Read-only overlap audit: held #2411 remains at 6c4228c08466a79fd839d01660de5b27812526ef with review 5324414426 requesting changes. Its production recovery insertion and adjacent spec edit are separable; the shared adminCoordinator test insertion conflicts and must preserve both test groups when that writer later rebases. Draft #1625 remains unchanged at b0a3c0b6e0c2952875c08c5098691fbf3294841b: channel/clarification/read-record hunks are semantically separate, but its stale base already conflicts in shared coordinator files; the test append also needs reconciliation. Neither protected branch was modified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions