>_
.issue.db
/issues
Dashboard
Issues
Memory
Lessons
Audit Log
New Issue
Edit Issue #86
Update issue details
Title *
Description
EARS SPEC: Context: RunFlow shipped their commit f13e238 (Option 2) — DELETE now terminalizes non-terminal nodes to `cancelled` before soft-deleting, and the node-state endpoint reads through the delete predicate. Re-verified independently by us on 2026-07-26 (audit/evaluations/probe_deleted_workflow_gate_readable.py, PASS). FTX-81's detection keys on the literal string "cancelled" only, which is now narrower than the set of terminal states that orphan a human task. - UN-RF-5: When a bound RunFlow approval node reports a terminal state that records no approval (`cancelled` or `failed`) while the linked decision is still active, the Futex reconcile worker shall withdraw the decision as an audited `cancelled` outcome, recording the observed node state verbatim as withdrawal evidence. - UN-RF-6: If a bound RunFlow approval node reports `succeeded` while the linked decision is still active, then the Futex reconcile worker shall leave the decision untouched, because `succeeded` is positive evidence of an out-of-band approval and must never be recorded as a cancellation. - UN-RF-7: While a bound node is in a non-terminal state (`pending`, `queued`, `running`, `waiting_approval`), the Futex reconcile worker shall leave the decision untouched. - UN-RF-8: If RunFlow is unreachable or returns any non-2xx response, then the Futex reconcile worker shall leave the decision untouched. A 404 shall never be read as cancellation: it is indistinguishable from a revoked credential, a wrong-tenant lookup, or a deleted tenant. - UN-RF-9: While a decision is active and its RunFlow binding is older than the configured maximum binding age and the current node-state read fails, the Futex reconcile worker shall escalate the decision to a human exactly once (audit event plus assignee notification) and shall not terminalize it. - UN-RF-10: The Futex RunFlow sync worker shall continue to treat a 404 on approve/reject as a permanent failure that dead-letters the job with a `runflow_sync_error` audit, so a revoked or misprovisioned credential cannot be silently absorbed as success.
Priority
Low
Medium
High
Critical
Status
Open
In Progress
Closed
Won't Do
Due Date (YYYY-MM-DD)
Tags (comma separated)
Related Issues (IDs)
Enter IDs of issues related to this one. They will be linked as 'related'.
Update Issue
Cancel