Skip to content

Record exclusive-allocation deploys in run-key history - #536

Merged
TheGreatAxios merged 2 commits into
mainfrom
cl-7274-run-key-history-never-records-exclusive-allocation-deploys
Aug 31, 2026
Merged

TheGreatAxios merged 2 commits into
mainfrom
cl-7274-run-key-history-never-records-exclusive-allocation-deploys

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Exclusive-allocation deploys rotate workflow_run.public_key through updateAnchorPublicKeyUnderAllocationLock, then emit agent.deploy.ack with allocated set. @corbits/run-key-history skipped those acks, matching the orchestrator listener's guard — but that guard is not how the service path writes the key. Result: zero history rows for that entire deployment class, so signature re-verification failed for it.

This drops the allocated skip in our listener so every observed deploy ack is recorded, including exclusive-allocation deploys and post-failure allocation replacements. No dual path, no vendor edits.

Shared-capacity writes (deployCodeSourcedWorkflow, deployAdoptedCodeSourcedWorkflow) already emit ordinary acks and were already recorded.

Test plan

  • Converted the PR CL-7274: document run-key-history's exclusive-allocation gap #523 test.failing to a passing test; inverted the skip-contract test
  • HUB_DATA_DIR=$(mktemp -d) bun test packages/run-key-history — 26 pass, 0 fail
  • bunx tsc --noEmit -p packages/run-key-history/tsconfig.json
  • prettier --check / eslint on the changed files
  • check:report-error is already red on main and unrelated

Closes the live gap tracked in CL-7274.

@TheGreatAxios
TheGreatAxios merged commit 5e3c014 into main Aug 31, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant