#86 FTX-86: RunFlow reconcile — terminal-state widening + unobservable-binding backstop

closed high bug Created 2026-07-26 18:59 · Updated 2026-07-31 19:30

Description

Edit
EARS SPEC: Context: RunFlow shipped their commit f13e238 (Option 2) — DELETE now terminalizes non-terminal nodes to `cancelled` before soft-deleting, and the node-state endpoint reads through the delete predicate. Re-verified independently by us on 2026-07-26 (audit/evaluations/probe_deleted_workflow_gate_readable.py, PASS). FTX-81's detection keys on the literal string "cancelled" only, which is now narrower than the set of terminal states that orphan a human task. - UN-RF-5: When a bound RunFlow approval node reports a terminal state that records no approval (`cancelled` or `failed`) while the linked decision is still active, the Futex reconcile worker shall withdraw the decision as an audited `cancelled` outcome, recording the observed node state verbatim as withdrawal evidence. - UN-RF-6: If a bound RunFlow approval node reports `succeeded` while the linked decision is still active, then the Futex reconcile worker shall leave the decision untouched, because `succeeded` is positive evidence of an out-of-band approval and must never be recorded as a cancellation. - UN-RF-7: While a bound node is in a non-terminal state (`pending`, `queued`, `running`, `waiting_approval`), the Futex reconcile worker shall leave the decision untouched. - UN-RF-8: If RunFlow is unreachable or returns any non-2xx response, then the Futex reconcile worker shall leave the decision untouched. A 404 shall never be read as cancellation: it is indistinguishable from a revoked credential, a wrong-tenant lookup, or a deleted tenant. - UN-RF-9: While a decision is active and its RunFlow binding is older than the configured maximum binding age and the current node-state read fails, the Futex reconcile worker shall escalate the decision to a human exactly once (audit event plus assignee notification) and shall not terminalize it. - UN-RF-10: The Futex RunFlow sync worker shall continue to treat a 404 on approve/reject as a permanent failure that dead-letters the job with a `runflow_sync_error` audit, so a revoked or misprovisioned credential cannot be silently absorbed as success.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...