Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix: lock terminal task threads (#177)

3 months ago

0b54726
Authored
Max Weinbach6/21/2026, 3:45:52 PM
* fix: enforce terminal task thread locks

Reject terminal task-owned turn/start and turn/steer through structured JSON-RPC task_locked errors, stop late aborted turn output before projection, document protocol v7.39, and cover restart, race, isolation, and reopen/retry flows with production JSON-RPC tests.

* fix: render terminal task chats read-only

Hide the normal composer for completed, cancelled, and failed task conversations, expose server-status-driven Reopen or Retry actions, preserve transcript and add-thread accessibility state, and cover completed and failed terminal task UI behavior.

* test: support isolated Electron user data dirs

Add a dev/test-only COWORK_ELECTRON_USER_DATA_DIR override before userData-backed desktop services and the single-instance lock, fail closed in packaged builds, document the live-verification knob, and harden desktop startup/onboarding tests.

* fix: close terminal task review gaps

Guard terminal Reopen and Retry actions against same-tick duplicate clicks, preserve cancelled outcomes for terminal-quiesced turns, and extend deterministic UI/JSON-RPC regressions for the reviewed paths.

* fix: preserve usage for cancelled task turns

Merge provider usage before suppressing post-cancellation task-turn output and extend the production JSON-RPC terminal race regression to assert exact-turn usage notification without false completion telemetry.

* docs: include task locked error code

Add task_locked to the shared ServerErrorCode protocol union so the structured terminal task lock contract is documented consistently.

* fix: suppress late cancelled turn streams

* fix: block terminal task tool races

* fix: gate download side effects

* fix: close remaining task mutation gates

* fix: gate remaining task side effects

* fix: settle task terminal lock races

Close remaining terminal task lifecycle races reported on PR #177. Add effect-settlement barriers for terminal transitions, final mutation checks for queued steer drains, native Codex approval and yolo coverage, non-cooperative MCP settlement behavior, projected task_locked data, and keyed desktop lifecycle action state.\n\nRegenerate JSON-RPC protocol artifacts and add deterministic production-path plus desktop regressions for the reviewed edge cases.

* test: cover task terminal quiesce timeouts

* fix: close terminal quiescence races

* fix: quiesce source and artifact terminal races

* fix: defer terminal directive checkpoints

Record self-origin terminal directive receipts and checkpoints only after the matching deferred terminal commit finalizes. Failed quiescence now leaves no receipt or success checkpoint, while retry and replay paths remain idempotent.

* fix: guard terminal task admission races

* fix: wait for child agents before terminal tasks

* fix: close task lock race escapes

Harden terminal task locking across late user-content materialization, steer delivery, partial abort handling, retry serialization, child-agent settlement, and JSON-RPC agent controls.

Add deterministic production-path regressions for attachment rollback, branded task-lock aborts, abort partial suppression, live and queued steer races, task retry serialization, child spawn settlement, inherited child task locks, and direct agent route task_locked errors.

* fix: harden terminal task admission races

* fix: harden task locks across steers and controls

* fix: close terminal task race gaps

* fix: close terminal task review races

* fix: serialize desktop task lifecycle actions

* fix: defer task cancel terminal locks

* fix: remove terminal route prelock bypass

* fix: harden terminal task quiescence edges

Remove the dead prepared route-lock escape hatch and keep terminal lock publication inside coordinator-owned mutation ownership/revalidation paths.

Preserve completed artifact revisions when terminal quiescence fails by marking durable pending settlement and retrying safely, while keeping no-review retry state intact.

Tighten live steer admission, Codex pre-ack usage identity, AgentControl fixed-point races, committed-reader coverage, task notification subscription buffering, and task cancel lock regressions.

* fix: stabilize artifact settlement retries

Retry only terminal quiescence and structured task-lock failures with bounded backoff, while keeping blocked and atomic settlement failures fail-closed. Add deterministic coverage for delayed locks, terminal races, non-retryable failures, rollback integrity, and scheduler overrides.

* fix: align terminal lifecycle pending state

Match terminal reopen and retry controls to the current task action and revision so stale requests cannot disable the wrong UI. Allow a newer lifecycle revision to supersede an older request while preventing stale responses from clearing or overwriting the current latch. Add store and dual-sidebar regressions for the status-change race.

* test: isolate session provider logout

Inject provider logout through the session auth manager so the unit test never launches a live Codex app-server logout. Preserve the production default while verifying the injected path directly, eliminating the exact five-second CI timeout.

* fix: replace stale lifecycle actions

Deduplicate terminal lifecycle requests only when both action and revision match. Let an opposite reopen or retry action supersede a stale latch, while request ownership keeps the prior result from clearing or overwriting the active request.

* fix: preserve lifecycle latches across revisions

Keep same-action reopen and retry requests pending across task revision drift while allowing opposite actions to supersede stale latches. Cover both store deduplication and dual-sidebar pending state after a revision-only task update.

* test: await terminal lock publication

Replace the fixed child-settlement delay with an explicit wait for the coordinator pending terminal lock. This keeps the interrupt-replacement regression deterministic while still proving the task remains working until quiescence completes.

Parent868f5c5

109 files changed
  • AGENTS.md+1−0
  • apps/desktop/README.md+1−0
  • apps/desktop/electron/main.ts+5−0
  • apps/desktop/electron/services/userDataOverride.ts+30−0
  • apps/desktop/src/app/store.actions/tasks.ts+51−1
  • apps/desktop/src/app/store.helpers.ts+7−0
  • apps/desktop/src/app/store.ts+1−0
  • apps/desktop/src/ui/ChatView.tsx+28
−2
  • apps/desktop/src/ui/tasks/TaskContextSidebar.tsx+27−14
  • apps/desktop/src/ui/tasks/TaskConversationSidebar.tsx+45−2
  • apps/desktop/test/desktop-onboarding.test.tsx+4−1
  • apps/desktop/test/main-process-startup.test.ts+17−0
  • apps/desktop/test/task-actions.test.ts+53−0
  • apps/desktop/test/task-mode-ui.test.tsx+609−3
  • apps/desktop/test/user-data-override.test.ts+71−0
  • apps/mobile/src/features/cowork/protocolTypes.ts+39−0
  • apps/mobile/src/features/cowork/snapshotReducer.ts+2−0
  • docs/generated/websocket-jsonrpc.d.ts+7−7
  • docs/generated/websocket-jsonrpc.schema.json+1−1
  • docs/websocket-protocol.md+37−3
  • src/agent.ts+52−1
  • src/experimental/a2ui/routes.ts+17−4
  • src/runtime/antigravityRuntime.ts+4−1
  • src/runtime/codexAppServer/config.ts+10−1
  • src/runtime/codexAppServer/notifications.ts+18−16
  • src/runtime/codexAppServer/runTurn.ts+59−27
  • src/runtime/codexAppServer/serverRequests.ts+25−1
  • src/runtime/pi/tools.ts+2−1
  • src/runtime/toolOutputOverflow.ts+39−7
  • src/runtime/types.ts+6−1
  • src/server/agents/AgentControl.ts+175−13
  • src/server/agents/types.ts+2−0
  • src/server/jsonrpc/routes/agents.ts+86−22
  • src/server/jsonrpc/routes/outcomes.ts+12−0
  • src/server/jsonrpc/routes/tasks.ts+225−185
  • src/server/jsonrpc/routes/turn.ts+10−7
  • src/server/jsonrpc/routes/types.ts+9−0
  • src/server/jsonrpc/schema.misc.ts+1−0
  • src/server/jsonrpc/schema.session.ts+1−0
  • src/server/projection/conversationProjectionFeedItems.ts+1−0
  • src/server/protocol.ts+5−1
  • src/server/runtime/ServerRuntime.ts+65−20
  • src/server/runtime/SessionRegistry.ts+25−2
  • src/server/runtime/WorkspaceJsonRpcSubscribers.ts+89−3
  • src/server/session/AgentSession.ts+26−3
  • src/server/session/AgentSessionManagerRegistry.ts+8−2
  • src/server/session/ProviderAuthManager.ts+2−1
  • src/server/session/SessionAdminManager.ts+14−0
  • src/server/session/SessionContext.ts+14−2
  • src/server/session/SessionRuntime.ts+9−0
  • src/server/session/SessionRuntimeSupport.ts+8−2
  • src/server/session/TurnExecutionManager.ts+191−46
  • src/server/session/taskLocks.ts+198−0
  • src/server/session/turnExecution/runTurnInvocation.ts+30−1
  • src/server/session/turnExecution/runUserMessageTurn.ts+268−97
  • src/server/session/turnExecution/steerCoordinator.ts+291−51
  • src/server/session/turnExecution/userMessageAttachments.ts+192−24
  • src/server/session/turnExecution/userMessageTurnHelpers.ts+44−10
  • src/server/sessionDb.ts+187−33
  • src/server/sessionDb/tasks.ts+65−17
  • src/server/sessionDb/writeCoordinator.ts+4−0
  • src/server/tasks/TaskCoordinator.ts+922−146
  • src/shared/projectedItems.ts+3−1
  • src/shared/sessionSnapshot.ts+35−0
  • src/tools/bash.ts+19−10
  • src/tools/context.ts+6−0
  • src/tools/edit.ts+1−0
  • src/tools/manageMemory.ts+10−4
  • src/tools/memory.ts+8−2
  • src/tools/mutationGuard.ts+57−0
  • src/tools/persistentAgents.ts+2−0
  • src/tools/spawnAgent.ts+1−0
  • src/tools/taskReview.ts+1−0
  • src/tools/webFetch.ts+38−9
  • src/tools/write.ts+12−5
  • src/types.ts+27−0
  • test/a2ui/conversationProjection.test.ts+36−0
  • test/a2ui/feedItem.test.ts+40−0
  • test/a2ui/jsonRpcActionRoute.test.ts+265−24
  • test/a2ui/upsertFeedItem.test.ts+39−0
  • test/agentControl.test.ts+249−2
  • test/fixtures/codexAppServerMock.ts+57−2
  • test/jsonrpc.task-workspace-subscription.test.ts+157−0
  • test/jsonrpc.tasks-route.test.ts+37−1
  • test/jsonrpc.thread-read-projector.test.ts+60−0
  • test/jsonrpc/flow.task-terminal-locks.test.ts+3239−0
  • test/jsonrpc/flow.turnSteer.test.ts+158−0
  • test/mobile.task-lock-errors.test.ts+130−0
  • test/persistentAgents.tool.test.ts+50−0
  • test/runtime.codex-app-server.test.ts+468−2
  • test/runtime.pi-runtime.test.ts+41−0
  • test/runtime/codex-app-server/turn.test.ts+520−0
  • test/server/runtime/sessionRegistry.taskContinuation.test.ts+13−0
  • test/server/runtime/workspaceJsonRpcSubscribers.test.ts+198−0
  • test/session-db.test.ts+61−0
  • test/session/agentSession.harness.ts+2−0
  • test/session/agentSession.messaging.test.ts+532−1
  • test/session/agentSession.provider.test.ts+8−0
  • test/session/steerCoordinator.test.ts+664−0
  • test/session/taskLocks.test.ts+42−0
  • test/spawnAgent.tool.test.ts+42−0
  • test/task-artifact-versions.test.ts+1055−32
  • test/task-mode.persistence.test.ts+1131−20
  • test/tools/taskReview.test.ts+77−0
  • test/tools/tools.bash.test.ts+67−0
  • test/tools/tools.manageMemory.test.ts+33−0
  • test/tools/tools.memory.test.ts+40−0
  • test/tools/tools.webFetch.test.ts+39−1
  • test/tools/tools.write.test.ts+21−0