Parent: #13
Depends on: #29, #30, and #49 (merged through PR #63; durable foundation under #3)
Suite roadmap: #11
Ordered implementation checkpoints
The 2026-09-26 live re-query confirms #49 is merged at 711fbe3c19c0e080ab6c67b74d7945cd29675a74, with main CI green. This parent remains open while its three native sub-issues land in order:
One bounded review PR at a time; stop for maintainer merge. Per the maintainer's 2026-09-26 instruction, hand back work after focused local checks without waiting for hosted/default-branch CI, and record unverified gates honestly. No automatic merges. Changed-plan migration and automatic scheduling remain outside this sequence.
Outcome
Prove Flow's lifecycle and authority state machine with deterministic transition traces, content-aware invalidation, and no duplicated consequential effects.
Required scenarios
- cancellation before start, during a provider, and between completed steps;
- timeout, nonzero exit, signal termination, output-limit failure, host interruption, and restart;
- resume after completed, partially completed, and interrupted work;
- invalid or corrupt checkpoint;
- changed input, plan, configuration, provider lock, implementation, accepted artifact, or validation evidence;
- retryable versus terminal failure;
- idempotent retry and reuse of accepted completed work;
- refusal when mutation, upload, publication, signing, network, paid service, or another consequential effect lacks authority;
- cancellation or failure during cleanup, with honest residual-state evidence.
Scope
- Add expected state-transition traces and terminal classifications to the scenario corpus.
- Assert which work is reused, invalidated, retried, skipped, blocked, or awaiting authority.
- Prove downstream-only invalidation where the accepted run model permits it.
- Use harmless sentinels and counters to prove completed work and consequential effects are not duplicated.
- Keep explanations typed, deterministic, actionable, and redacted.
Acceptance criteria
Non-goals
Acceptance reconciliation — #66 / PR #69
All original criteria have local executable evidence. PR #69 closes this parent only on maintainer merge. See the immutable lifecycle guide, 49-recipe catalog, and local validation record.
| Original criterion |
Evidence |
| Compatible resume preserves accepted completed work |
Completed/partial restart recipes plus effect-completed-reuse; all accepted counters remain one. |
| Changed or corrupt evidence invalidates affected/dependent work |
Existing changed/corrupt recipes, #64 transitive/fan-in/context tests, and effect-stale-authority. |
| Retry never silently duplicates accepted or consequential work |
Completed execution/retry refused; failed/interrupted retries require matching authority and acknowledgement; repeated recovery decision IDs are rejected. Explicitly acknowledged uncertain retries can repeat effects. |
| Authority denial occurs before prohibited effects |
Seven deny-* recipes; zero denied/descendant counters and a working independent positive control. |
| Interrupted runs retain bounded inspection/recovery evidence |
Fresh-process host-exit recipes, retained first candidates, cleanup-cancelled, cleanup-failed, and enforced history/artifact budgets. |
| Traces and explanations match durable schemas |
Public RunStore/RunAssessment boundaries, validated RunState snapshots, typed refusals, correlated authority/attempts, allowlisted receipts, and privacy canaries. |
| Suite is deterministic, hermetic, budgeted, drift-checked |
49 recipes twice in fresh roots on both toolchains; strict receipt completeness, exact source identity, kernel limits, and negative report tests. |
Rust 1.85 passed all targets, including all 81 acceptance recipes and 49 lifecycle recipes twice each. Stable Rust passed the 49 lifecycle recipes twice. Focused Clippy, formatting, documentation tests, contract/repository validators, and negative report checks passed. Hosted CI and macOS/Windows results were not checked or awaited, per the maintainer's 2026-09-26 instruction.
#13/#11 remain open for provider integrations and later release/audit gates. No runtime schema, scheduler, automatic cleanup, real external-effect, or exactly-once guarantee was added.
Parent: #13
Depends on: #29, #30, and #49 (merged through PR #63; durable foundation under #3)
Suite roadmap: #11
Ordered implementation checkpoints
The 2026-09-26 live re-query confirms #49 is merged at
711fbe3c19c0e080ab6c67b74d7945cd29675a74, with main CI green. This parent remains open while its three native sub-issues land in order:83f1ea161aa5aba03da5de6b287005252000cd4b, and main CI passed.6db839facc822707e9e3a9d74dda044faac77fe7.One bounded review PR at a time; stop for maintainer merge. Per the maintainer's 2026-09-26 instruction, hand back work after focused local checks without waiting for hosted/default-branch CI, and record unverified gates honestly. No automatic merges. Changed-plan migration and automatic scheduling remain outside this sequence.
Outcome
Prove Flow's lifecycle and authority state machine with deterministic transition traces, content-aware invalidation, and no duplicated consequential effects.
Required scenarios
Scope
Acceptance criteria
Non-goals
Acceptance reconciliation — #66 / PR #69
All original criteria have local executable evidence. PR #69 closes this parent only on maintainer merge. See the immutable lifecycle guide, 49-recipe catalog, and local validation record.
effect-completed-reuse; all accepted counters remain one.effect-stale-authority.deny-*recipes; zero denied/descendant counters and a working independent positive control.cleanup-cancelled,cleanup-failed, and enforced history/artifact budgets.Rust 1.85 passed all targets, including all 81 acceptance recipes and 49 lifecycle recipes twice each. Stable Rust passed the 49 lifecycle recipes twice. Focused Clippy, formatting, documentation tests, contract/repository validators, and negative report checks passed. Hosted CI and macOS/Windows results were not checked or awaited, per the maintainer's 2026-09-26 instruction.
#13/#11 remain open for provider integrations and later release/audit gates. No runtime schema, scheduler, automatic cleanup, real external-effect, or exactly-once guarantee was added.