-
Notifications
You must be signed in to change notification settings - Fork 2
plat 001
github-actions[bot] edited this page Sep 20, 2026
·
1 revision
PUL-7B849CC6: keyed-input parser, unknown-ID, sibling/map isolation, explicit-input precedence and opening-prompt tests pass on current source.
Resolved in SQLite for internal tracking with previous concern/detail records preserved in resolution events. Source/tests verified; deployed replay and historical business/module-result repair are not claimed. Full mapping: remaining-report audit.
| Coordination | Value |
|---|---|
| Assigned agent | Claude Code |
| Ticket state | runtime_reverify |
| Last synchronized | 2026-08-04 |
Claim this ticket in this file before implementation. During active work, update this fragment rather than the shared index; synchronize the index once at handoff, review, or completion.
- Priority: P0
- Owner: workflow orchestration/handoff
-
Source finding:
HARNESS-RUN-FULL-WORKFLOW-HUMAN-INPUT-LOSS -
Source database:
Workflow/upwork/db/db.sqlite -
Recorded state:
external_action_required, severityhigh -
Problem: a human-input override supplied to
run_full_workflowdid not appear in the target child step's opening prompt. - Impact: run-specific safety or scope constraints can be silently ignored while the workflow continues and reports success.
-
Evidence: the saved scheduler conversation contains the two-feed
override; the child
search-find-and-shortlistsession does not; its raw artifact shows thatmost_recentwas scraped anyway. -
Implementation (2026-08-03):
run_full_workflownow parseshuman_inputsstrictly, rejects malformed and unknown step IDs before launch, copies the map into immutable execution/batch contexts, and derives one isolated context per dispatched step. The keyed value reaches regular, message-sequence, todo, and human-input steps without leaking to siblings; an explicitexecute_step(human_input=...)remains higher priority. - Verification: focused tests cover both MCP-decoded map shapes, fail-closed parsing, unknown IDs, two distinct child values, sibling isolation, map-copy isolation, and explicit single-step precedence. A real scheduled full-run replay remains required before closing the Upwork finding.
- Current workaround: compare each producing child's prompt and raw provenance with the requested override.
- Acceptance: an E2E passes distinct keyed values to at least two child steps and proves each child sees only its intended value; missing or unknown keys fail before execution.
Auto-synced from docs/ on main. Edit there, not here.