Skip to content

openplanr 1.22.0 — durable per-role operate orchestration

Choose a tag to compare

@AsemDevs AsemDevs released this 03 Aug 12:25
· 281 commits to main since this release
ae1b1cb

Fixes the failure where a stalled advisory lens destroyed an entire operating
cycle.

What went wrong before

A real credentialed run produced strong analysis from four of five lenses and
lost all of it. The orchestrator waited for every lens before recording any, one
lens hung, the shared lease expired, and the completed work went with it. The
cycle directory was never written, status called the board quiet while it was
mid-advising, and report rendered every lens not_evaluated while real
analyses sat in temporary files.

What changes

Durability. Each result is recorded the instant its role returns. The
lease-bound session write is serialized so concurrent records cannot lose an
already-recorded role, and the lease renews by heartbeat independently of any
result.

Honesty. Validated lenses persist immediately, so the cycle directory
materialises before the Chair runs and a mid-cycle report shows real analysis. An
advising cycle is never described as quiet, and a lens is never rendered
not_evaluated without a governed event and a reason. Completion is verified
from on-disk artifacts rather than from a command exiting zero.

Liveness. The advisor fan-out runs through an explicit lifecycle state
machine with bounded retry, per-attempt timeout, cancellation and resume. A lens
that never returns gets a governed terminal path, plus an operator escape once
the session lease has lapsed — so recovery does not depend on a well-behaved
runtime. The previous fan-out deadlocked outright on a hung lens.

Chair over partial boards. Recorded, quiet, not-evaluated, failed,
still-running and citation-rejected stay six distinct states, and an absent lens
is surfaced as a gap the Chair must not synthesize around.

Citations. Classified by kind, so a gitignored planning tree is fully citable
— it previously could not resolve at all. One invalid citation drops only its own
proposal; the narrative and valid siblings survive.

Housekeeping. Scratch lives under a project-and-cycle-keyed path with an
ownership manifest, and cleanup touches only what is provably ours. Legacy
operating profiles migrate instead of being suggested and then rejected.

Pins planr-pipeline@0.39.0.