Stop deleting live folded-run rows on post-deploy grants/clone failure - #476
Conversation
deployAdoptedWorkflowFromSource resolving means a live child now exists on the sidecar; a plain Error out of markRunDeployClone or sendRunGrants afterward currently reads as "nothing was deployed" and deletes the run's rows, orphaning a live, unauthorized agent with no DB trace (CL-7213).
deployAdoptedWorkflowFromSource resolving means a live child now exists on the sidecar. A plain Error out of markRunDeployClone or sendRunGrants afterward used to read as "nothing was deployed," so launchFoldedRun's failure-path rollback deleted the run's rows, leaving a live agent running, unauthorized, and untracked (CL-7213). Both failure sites now throw SessionLaunchError(..., leakedAgent: true), matching the existing signal the rollback already branches on.
… phases Both post-deploy failure sites threw SessionLaunchError with the same "grants" phase; SessionLaunchError.phase is surfaced in upstream cleanup diagnostics, so a markRunDeployClone failure was misreported as a grants failure. Each step now throws with its own phase label.
|
Read the diff directly, traced the acceptance criteria against it, and ran the code-review skill against this branch (note: a parallel review lane was saturating the shared subagent pool during part of this pass, so some of the deeper read was done directly rather than via a sub-agent — recorded here for the record). Verified the try/catch boundary in One nit found and fixed: both post-deploy failure sites ( Verified: |
Summary
deployAtHeadinpackages/folded-runs/src/launch.tswritesmarkRunDeployCloneand sends the run's grants frame afterdeployAdoptedWorkflowFromSourceresolves — meaning a live child already exists on the sidecar by that point. A plainErrorthrown out of either step used to be indistinguishable from "the deploy never happened," solaunchFoldedRun's failure-path rollback deleted the run'sworkflow_runandfolded_runrows, leaving a live, unauthorized, and now completely untracked agent running.Both post-deploy failure sites now throw
SessionLaunchError(phase, cause, leakedAgent: true)— the same signaldeployAdoptedWorkflowFromSourceitself already uses elsewhere in the vendored session service — solaunchFoldedRun's existingleakedbranch marks the runfailedbut leaves it routable instead of deleting its rows.Verification
launchFoldedRun(packages/folded-run-one-shot,packages/chat/src/platform-adapter.ts,apps/hub/src/routine-launcher.ts,scripts/db-setup.ts, others): none do type-based inspection on the thrown error beyond a genericinstanceof Errorfor message extraction, whichSessionLaunchErrorstill satisfies. No caller behavior changes.bun run typecheck— cleanbun run lint— 0 errors (pre-existing unrelated warnings only)packages/folded-runstest suite — 63 pass, 0 fail, including the two new leak-rollback regression testsScope
Limited to the rollback path in
packages/folded-runs/src/launch.ts. Does not touch thecredentialCipherwiring or the crypto cache work living in the same package under other tickets.Linear: CL-7213