#86 FTX-86: RunFlow reconcile — terminal-state widening + unobservable-binding backstop
Description
EditEARS SPEC:
Context: RunFlow shipped their commit f13e238 (Option 2) — DELETE now terminalizes
non-terminal nodes to `cancelled` before soft-deleting, and the node-state endpoint
reads through the delete predicate. Re-verified independently by us on 2026-07-26
(audit/evaluations/probe_deleted_workflow_gate_readable.py, PASS). FTX-81's detection
keys on the literal string "cancelled" only, which is now narrower than the set of
terminal states that orphan a human task.
- UN-RF-5: When a bound RunFlow approval node reports a terminal state that records no
approval (`cancelled` or `failed`) while the linked decision is still active, the
Futex reconcile worker shall withdraw the decision as an audited `cancelled` outcome,
recording the observed node state verbatim as withdrawal evidence.
- UN-RF-6: If a bound RunFlow approval node reports `succeeded` while the linked
decision is still active, then the Futex reconcile worker shall leave the decision
untouched, because `succeeded` is positive evidence of an out-of-band approval and
must never be recorded as a cancellation.
- UN-RF-7: While a bound node is in a non-terminal state (`pending`, `queued`,
`running`, `waiting_approval`), the Futex reconcile worker shall leave the decision
untouched.
- UN-RF-8: If RunFlow is unreachable or returns any non-2xx response, then the Futex
reconcile worker shall leave the decision untouched. A 404 shall never be read as
cancellation: it is indistinguishable from a revoked credential, a wrong-tenant
lookup, or a deleted tenant.
- UN-RF-9: While a decision is active and its RunFlow binding is older than the
configured maximum binding age and the current node-state read fails, the Futex
reconcile worker shall escalate the decision to a human exactly once (audit event
plus assignee notification) and shall not terminalize it.
- UN-RF-10: The Futex RunFlow sync worker shall continue to treat a 404 on
approve/reject as a permanent failure that dead-letters the job with a
`runflow_sync_error` audit, so a revoked or misprovisioned credential cannot be
silently absorbed as success.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...