Repository navigation
feat(cli): claim and start contributor tasks with explicit retry keys - #480
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (17)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe CLI adds contributor task claim and start commands through public REST operations. The commands require caller-supplied idempotency keys, validate responses, and report uncertain outcomes without automatically retrying. ChangesContributor task writes
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant TaskCommand
participant APIClient
participant PublicRESTAPI
TaskCommand->>APIClient: ClaimTask or StartTask with task ID, key, and reason
APIClient->>PublicRESTAPI: POST mutation with Idempotency-Key
PublicRESTAPI-->>APIClient: Mutation response or API error
APIClient-->>TaskCommand: Validated result or failure
Merge Risk: ⚪ Minimal · up to No actionable claim/start risk remains identified; the PR is mergeable after normal checks. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 8.82% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 34 functions across 11 files. (6 skipped: 6 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Change
WS-CLI-001-06 — Public contributor task claim/start.
Goal and intent
Extend contributor discovery with purposeful claim/start commands, not a second
authorization or task lifecycle implementation.
Bounded record.
What changed and design
task claim TASK_ID --idempotency-key UUID [--reason TEXT]andtask start.automatic key/retry, operator override or local authority.
identity, complete escaped text and preserved successful API JSON.
uncertain. Observation is not rollback proof; manual replay preserves the
unchanged action/task/reason/key and can be denied after authority/state changes.
sent task POST or existing profile PATCH bodies after HTTP/2 GOAWAY. Profile
payload and error classification remain unchanged; its existing no-retry
contract is restored by the same shared guard.
Scope control and product behavior
CLI source/tests and affected README, roadmap and Commitrail only. Current main
is incorporated; both CLI06 and main's ARCH-04E1B-B2 initiative updates are retained.
Backend, MCP, workflows and dependency files are unchanged. Workstream still
owns authority, transactions, audit and replay. No submission/review activation,
binary publication or deployed-provider claim.
Evidence
Candidate:
597bde00544107ee93b1c43e1a5c46bf8cb45887.all 32 tests passed in 41.70s on PostgreSQL16 through migration0020, with cleanup.
Checkout
3535561eand head597bde00share exact tree28d145d26052f4e3c5c24a1702dc271df6f0b786.passed all nine lanes and the required aggregate: 8,652 unique case completions,
zero skips/deselections, plus the real public-API end-to-end drill. Every lane
exited0 without interruption; no retry was needed on this head. Agent Gates
and both MCP checks also passed.
6c885424local PostgreSQL16 attempt reached the unchanged 240-second deadline(exit124); exact-head/migration0020 and complete database cleanup are recorded.
This timeout is not a pass.
passed all 31 tests on previous head
6c885424in 48.64s with real PostgreSQL16/migration0020, zero skipsor deselections and complete isolation cleanup/container teardown. Checkout
9c32f096and that prior head share exact tree6c0f591ba08b3274e4cc1d424cabd2471b776cd0.This is historical proof, not a current-head pass.
not passing evidence for this repaired push. Required hosted checks must rerun.
Test delta and external findings
Existing tests remain selected; no tests removed, skipped or weakened.
The public API journey proves persisted claim/start, fresh authority, assignment
lineage, exact replay, conflicts and absent/foreign/Reviewer/revoked/suspended
denials. HTTP cases protect wire/input/output, composite identity and uncertainty.
EXT-CLI06-HTTP2-REPLAY(P2): repaired by disabling task POSTGetBody.A real TLS/ALPN HTTP2 peer receives the complete body before graceful GOAWAY.
The new process regression fails on the previous binary (two connections),
passes on the repair (one request and unknown outcome), and covers claim/start.
EXT-CLI06-NULL-DETAILS(P3): added an otherwise complete HTTP403 envelopewith null
details. Removing only the existing non-null guard makes the testfail at its intended unknown-outcome assertion; the baseline passes.
EXT-CLI06-PATCH-REPLAY: tracing the same owner reproduced two completeprofile PATCH bodies after GOAWAY on
6c885424. The shared one-shot mutationguard and dedicated profile process regression restore its existing contract.
Impact-routed reviews and external checks
Affected security, architecture/documentation and QA/test-delta reviews pass on
the clean final candidate. No open internal findings remain.
CodeRabbit reported no actionable comments on
6c885424; its check on this finalpush is rate-limited, not a fresh substantive review. No GitHub review threads exist.
The prior Backend run hit its unchanged 1,200-second task-lane execution deadline:
528 case completions were recorded, but no pytest final summary. It is not a pass
or current-head evidence. The fresh current-head run passed in full.
CI integrity, remaining risks and human focus
No workflow/dependency/gate changes, percentage quotas, test weakening or timeout
increase. Assignment invalidation is asynchronous. Local Flow/inference/storage
fixtures do not certify deployed providers. Review explicit retry-key handling,
composite contributor projection and uncertain outcomes. Further public journeys
and binary distribution remain later work.
Human approval/merge remains required; this PR does not authorize either.