#98 FTX-98: RunFlow 409 is two different answers; treating both as idempotent success absorbs a misrouted approval

closed high bug Created 2026-07-31 18:06 · Updated 2026-07-31 18:09

Description

Edit
EARS SPEC: - When RunFlow answers a node approve/reject call with HTTP 409 and detail not_awaiting_approval, the Futex RunFlow client shall treat the call as an idempotent success. - If RunFlow answers with HTTP 409 and any other detail, then the Futex RunFlow client shall treat the call as a permanent failure and shall not report the decision as delivered. - If a RunFlow sync job fails because the bound node is not an approval node, then the worker shall record an audit reason identifying the misrouted binding. - The Futex reconcile worker shall continue to treat a non-2xx read as evidence about Futex rather than about the gate (UN-RF-8), and that decision shall be recorded explicitly in the spec. CAUSE: app/integrations/runflow_client.py treats ANY 409 as success. RunFlow reports (thr-71c468b00f0e4e7c815a) that 409 carries two distinct details: not_awaiting_approval (node no longer waiting - safe) and not_an_approval_node (the bound node is not a gate at all - NOT success). Swallowing the second reports a human decision as delivered against a node that could never have accepted it.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...