-
Notifications
You must be signed in to change notification settings - Fork 2
plat 047
| Coordination | Value |
|---|---|
| Assigned agent | Codex |
| Ticket state |
implementation_in_progress — forward identity/revision binding implemented; immutable partial-run history still pending |
| Last synchronized | 2026-08-28 |
- Priority: P1
- Owner: run-folder retention and execution identity
- Source workflow: Upwork
-
Also reproduced in: Social Media (
PUL-DB292C50, where Pulse treated normaliteration-0use as contamination while inspecting retainediteration-293evidence).
Grouped work can reuse a logical folder such as iteration-0 across producing
runs. SQLite lifecycle rows and cost records can retain durable execution IDs,
but physical review evidence under the reused folder may be overwritten or
become ambiguous. This is distinct from PLAT-031: that ticket fixed cost-ledger
identity across archive rotation; it did not make every run artifact immutable.
The ambiguity also crosses plan versions. Current run metadata has no
plan_revision or plan_hash, so a retained iteration-N cannot be bound to
the executable plan, step configuration, and validation contracts that
produced it. Pulse can only infer from timestamps and current plan text. That
is how an old routing contract and the current routing contract became one
misleading critical finding in PUL-DB292C50.
Choose one immutable physical artifact identity per producing execution, keep a small latest pointer for compatibility, and link findings/reviews to that identity. Migration and retention limits must be defined before changing folder layout. No implementation is claimed by the 2026-08-07 reviewer fixes.
The design must also provide two platform-owned records:
-
Workflow/<workflow>/runs/run_index.json, atomically maintained byrotatePairedIterationZero, identifying the active slot, retained folders, last completed rotation, and full-run versus partial-group reuse semantics. - A content-addressed executable plan revision under
planning/revisions/plan-<digest>.json. Every newrun_metadata.jsonbinds to that revision before execution. The canonical bundle includes the plan, step configuration, validation contracts, and every other configuration surface that can change step behavior.
Retaining or rotating a run must preserve both its immutable execution identity
and plan-revision reference. Historical runs without proof are
unknown_legacy; timestamps must never be used to guess a revision.
Pulse deterministic intake must expose the normalized identity/revision facts.
Reviewers trust those facts and do not infer current/retained status or plan
identity from iteration-N names, timestamps, or current plan text.
- A full run rotates the previous active slot and publishes a consistent run index; a partial-group run is explicitly represented as reuse of the active slot.
- Pulse can resolve any new retained run to its immutable execution identity and exact plan revision.
- Repeated runs of an unchanged plan share one revision; a behaviorally relevant plan/config/validation mutation creates a different revision.
- Legacy retained runs remain visibly unknown rather than receiving inferred revision assignments.
- Re-reviewing
PUL-DB292C50cannot classify ordinary use ofiteration-0as contamination. It must isolate the actual missing-selection fail-closed verification boundary or close the stale claim.
PLAT-197) starts after this ticket's identity boundary. It owns who initiated a plan mutation, why, which dependent surfaces were reconciled, and which later impact evidence is linked. PLAT-047 owns which plan/run actually produced the evidence PLAT-197 evaluates.
Implemented for new executions:
- full-run rotation and partial-group reuse atomically publish
runs/run_index.jsonwith explicit active/retained lifecycle and policy; - every producing group receives a new
run-<nanoseconds>execution identity; - execution now fails before the group starts if its
run_metadata.jsoncannot be bound to a content-addressed executable plan revision; - revisions cover
workflow.json, the plan, planning step config, evaluation plan, and evaluation step config, and are reused when canonical content is unchanged; and - deterministic Pulse runtime intake exposes the run index, lifecycle role,
execution identity, and plan revision. Legacy evidence is explicitly
unknown_legacyinstead of receiving a timestamp-based guess.
Still open before this ticket can close:
- a rerun of the same group during partial-group reuse still replaces that group's mutable artifact directory. The new identity prevents provenance ambiguity for the current contents, but it does not retain every historical partial execution under its own physical path;
- every lower-level artifact/receipt is not yet independently stamped and
rejected when it contradicts the owning
run_metadata.json; and -
PUL-DB292C50needs a live re-review after deployment to verify that the reviewer consumes the deterministic identity facts instead of the stale iteration-name inference.
Fresh local evidence still exposes overwritten/mixed partial-run provenance:
partial groups reuse iteration-0, while newer output files can coexist with
older failed metadata. Execution IDs and plan revision references already help
identify evidence, but do not make physical partial-attempt artifacts immutable.
This remaining acceptance criterion stays open. Link PLAT-089
for stale attempt-log contamination; do not infer recovery from an outer status
or promote a later artifact into proof for an earlier execution.
Social Media additionally lost retained evidence with retention set to 3. PLAT-304) fixes the authorized retention setting's write denial; it does not fix partial-run overwrites or reconstruct already-pruned evidence.
PLAT-305) implements the first review/scheduling/research/lifecycle release. This ticket's remaining foundation acceptance is still required and is not closed by adding Architecture or outcome tracking. Historical evidence and legacy workflow behavior remain unchanged by that release.
PLAT-320 owns the compatible storage migration that reserves
iteration-0 for Builder/manual execution and gives each saved-schedule
occurrence an immutable iteration-N-sched folder before any workflow tool
call. It also owns propagation into direct execute_step, evaluation, logs,
retention, APIs/UI, AgentWorks guidance and Pulse intake.
PLAT-047 remains the parent immutable-physical-identity requirement and retains the unresolved Builder/partial-run evidence criteria. PLAT-320 must not close PLAT-047 merely by isolating scheduled folders: lower-level evidence identity and the mutable Builder compatibility path must also remain truthful.
Auto-synced from docs/ on main. Edit there, not here.