You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Non-blocking findings from the Fable re-review of #447 (attempt lifecycle on the MCP surface). None of them weakens a gate; each one is either a disclosure gap or a loop that can't make progress.
request_acceptance asks again after a replayed receipt.
An agent with write access to approvals/ copies a genuine approval under a new id. Both copies then read receipt-replayed, and traverse stops for an operator (correct).
request_acceptance instead discloses the pair and asks the person again. An accept mints a second genuine approval for the same candidate.
Fix: when a non-genuine approval's receipt names a request that exists in storage (replayed or expired), stop the way traverse does rather than asking again.
Gate limitations don't reach the person.buildAcceptanceRequest builds the presentation from standardLimitations, the re-read, and ignored approvals. It never includes gate.limitations. For example, 'the change has no stored brief.md' reaches gate callers but never the human deciding. Fix: merge gate.limitations into the presentation.
A planned change with no slices is stuck.
A crash between plan's change CAS and its slice writes leaves a change planned with zero slices.
Traverse then advises plan-slices, which plan refuses ('slices are planned once, from draft'). No action recovers it.
Fix: allow plan on a planned change that has zero slices, or have traverse emit blocked-needs-operator.
Non-blocking findings from the Fable re-review of #447 (attempt lifecycle on the MCP surface). None of them weakens a gate; each one is either a disclosure gap or a loop that can't make progress.
request_acceptanceasks again after a replayed receipt.approvals/copies a genuine approval under a new id. Both copies then readreceipt-replayed, and traverse stops for an operator (correct).request_acceptanceinstead discloses the pair and asks the person again. An accept mints a second genuine approval for the same candidate.attempt-lifecycle.md, feat: attempt lifecycle on the MCP surface (start_attempt, capture_candidate, record_review) #447).buildAcceptanceRequestbuilds the presentation fromstandardLimitations, the re-read, and ignored approvals. It never includesgate.limitations. For example, 'the change has no stored brief.md' reachesgatecallers but never the human deciding. Fix: mergegate.limitationsinto the presentation.plan's change CAS and its slice writes leaves a changeplannedwith zero slices.plan-slices, whichplanrefuses ('slices are planned once, from draft'). No action recovers it.planon aplannedchange that has zero slices, or have traverse emitblocked-needs-operator.Refs #409, #447.