fix: restore provider refresh and preserve recall re-ask outcomes - #1656
santoshkumarradha wants to merge 89 commits into
Conversation
…e words, and task activity labels (#1555)
Assisted-by: CodeAF (gemini-3.8-flash-high) Co-Authored-By: CodeAF <267109073+agentfield-bot@users.noreply.github.com>
Assisted-by: CodeAF (gemini-3.8-flash-high) Co-Authored-By: CodeAF <267109073+agentfield-bot@users.noreply.github.com>
…lation (#1550) Defend contracts that standing runs with branch-only grants execute in an isolated git worktree and leave the host branch untouched, that false prose claims of branch isolation are caught and marked failed, and that plain ambient runs without grants remain unaffected. Assisted-by: CodeAF (gemini-3.8-flash-high) Co-Authored-By: CodeAF <267109073+agentfield-bot@users.noreply.github.com>
readText resolved one empty or all-blank argument to an empty goal with no error, so `codeaf do ""` ran a paid job with a goal the planner invented. The blank check now sits where the goal text is resolved, for every road. Fixes #1566 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
(cherry picked from commit 89fa97f)
(cherry picked from commit bd52b1d)
(cherry picked from commit 9dac0b5)
(cherry picked from commit 62ffd71)
(cherry picked from commit dddee8c)
Recorded terminal verification: provider catalog refreshExact executable revision: Goal: load a connected custom provider's catalog, refresh it through the picker and provider menu, keep cached models usable when a refresh fails, and recover without restarting the application. This verifies the provider correction for #1508; it does not certify later aggregate revisions. Failure with useful cached choices: a controlled catalog endpoint returns HTTP 503. With the matching Successful retry: the error clears and the recovered catalog now contains both Provider-menu entry: keyboard navigation exposes the connected provider's refresh models action; the recorded run executes this action. Recorded run checks: cold catalog loading, manual refresh, visible failure beside cached filtered choices, successful recovery, closing the picker during a delayed response without it reopening, and keyboard provider-menu refresh all passed. Retained request receipts show six catalog GET requests, zero POST requests, and zero inference calls. The selected Limits: catalog responses came from a deterministic loopback test service. This was real terminal interaction, but it was not a paid model workflow and does not establish alternate-provider inference behavior. Closing the picker was exercised; transport cancellation is not claimed. The three published stills illustrate failure/cache retention, recovery, and the menu; the additional timing and request-count checks rely on the retained original recording and request receipts. |
Source evidence: saved preferences across new conversations (#1655)Exact source executable: Real workflow: a first conversation saved a Go preference for hard tabs and descriptive variable names. A new conversation created and ran First coding conversation: the genuine terminal checkpoint at 145 seconds shows Another new conversation: the genuine checkpoint at 160 seconds shows Recall evidence and limits: both coding turns journaled Model accounting: all recorded roles used OpenRouter Media provenance: these two static images are cropped frames from the original live PTY recordings (149.59 seconds and 165.33 seconds respectively), preserving the recorded application rendering. Crops exclude private paths; no UI or output was recreated. They are screenshots, not a video. Original recordings and raw traces remain private and unchanged. The separately owned final combined recording will be labeled with its own revision and results. |
Final combined real-user acceptance — 70babe7Result: the useful workflow completed on this exact PR head. In ordinary local chat, a connected catalog failed and recovered correctly; then the existing invoice project gained a usable aging CSV and a second customer follow-up report in a fresh conversation. The actual generated programs were run and their outputs checked independently.
Recording provenance: genuine original terminal-output stream, retained in full with original timing. No pane-snapshot reconstruction, staged UI, or idle compression. The GIF is one contiguous 180-second source interval (01:50–04:50) rendered at the 1× setting; GIF frame timing yields approximately 181 seconds. It shows builder/checker results, starting a fresh chat, and producing/using the follow-up report. The full recording includes provider failure/retry and the complete workflow; rendered video timing is approximately 320 seconds for the 311-second original stream. Screenshots below are actual checkpoints from that same stream. Disposable fixture paths are test inputs; no credentials or personal host paths are included. Three-minute continuous workflow excerpt: Full original-session rendering — provider refresh through usable reports: final-workflow-70babe7d9.mp4Captioned checkpoints from the same final combined runProvider temporarily unavailable: the filtered connected model remains cached/selectable, with its 503 error and retry instruction visible. Provider recovered: retry reached the catalog successfully and cleared the error; selection remains DeepSeek. Invoice export completed: checker reports boundary/quoting checks and the actionable customer priority. Fresh-chat report actually used: the generated summary contains correct customer ordering, balances and oldest overdue days, with a runnable command. Saved preference reproduced: standard-library, two-decimal money and runnable-command preferences appear in the fresh conversation; history-search limitation is stated above. Native executable SHA256: |
|
@AbirAbbas This finite follow-up batch is ready for review at |
|
PR-bar audit: the existing evidence comments (terminal verification, source evidence) and the body capture are good groundwork. Missing against the bar:
Marked draft until 1–3 close; the evidence comments stay and count toward on-screen proof. |
Bar audit — gaps against the new PR bar1. CI + changelog: 2. Review passes: ❌ verification and acceptance comments exist, but none of the three named passes (Pass 1 ARCHITECTURE, Pass 2 SECURITY, Pass 3 CODE EFFICIENCY & DESIGN) are posted, each as a separate comment naming what was checked and what was found. 3. Video proof: 4. Spark: the earlier gates ran on the Spark; the fresh gate run stays there. Action taken: converted back to draft until fresh CI, the three passes, and the body-embedded video exist. — |
PR Bar Audit — gaps against the new bar1. CI + changelog: |
PR bar audit — directive #17907153588225651241. CI + changelog: 2. Review passes: ❌ four verification/evidence comments exist, but none are the bar's named passes — Pass 1 — ARCHITECTURE, Pass 2 — SECURITY, and Pass 3 — CODE EFFICIENCY & DESIGN are all absent as separate comments. 3. Video proof: 4. Merge state: CONFLICTING against dev — needs a rebase; CI must be re-run green on the rebased head. Fixes for the gaps are in flight. This PR does not turn ready until all four conditions hold. drafted with CodeAF |
Audit against the new PR bar
Converted back to draft until all four conditions hold; nothing merges until then. drafted with CodeAF |
|
PR-bar audit (team bar, 2026-10-03) - status per category:
Per the no-video rule this returns to draft until a real capture is embedded. |
PR bar audit — gaps against the new bar1. CI + changelog — 2. Review passes — all three missing (Pass 1 ARCHITECTURE, Pass 2 SECURITY, Pass 3 CODE EFFICIENCY & DESIGN), as separate comments naming what was checked and what was found. 3. Video proof — missing. User-facing change (provider refresh restored, recall re-ask outcomes preserved). A Spark tmux capture of the refreshed provider flow, rendered to GIF/video, must be embedded in the PR body. 4. Runs on Spark — per the fleet skill. Converted back to draft until all four conditions hold. Nothing merges before that. drafted with CodeAF |
Audit against the PR bar — what is missing1. CI + changelog — ❌ no Actions run has ever happened on this PR (only license/cla passes); ✅ changelog: thirteen unreleased entries present. Disposition — converted from ready back to draft until the three passes are posted and CI has actually run green. The branch will be brought current without rewriting its history; nothing merges. drafted with CodeAF |
|
Audit against the new PR bar:
Stays draft. drafted with CodeAF |
Bar audit — what is missing (per the new PR bar)Audited at head 1. CI + changelog — no check runs recorded on the PR (only license/cla ⏳ pending); CI needs a fresh push or a workflow re-run from the owner. Changelog ✅ — 2. Review passes (three, separate comments) — Pass 1 — ARCHITECTURE ❌ · Pass 2 — SECURITY ❌ · Pass 3 — CODE EFFICIENCY & DESIGN ❌ — 0 of 3 posted. (The existing comments are terminal-verification evidence — valued, but not the three named passes.) 3. Proof on screen — user-facing ✅ (provider refresh error surface, recall re-ask). Video/GIF embedded in the body ❌ missing — the comments hold stills, not a recording; required before ready. 4. Tags — ✅ bug · area:session · area:provider · sev:serious · milestone Reliable agent. Actions: converted to draft until the bar holds; the three review passes are running, the capture is queued, and the owner is asked to trigger CI. Nothing merges before all four conditions hold. drafted with CodeAF |











What changed
Ordinary local chat now refreshes connected providers through the same catalog lifecycle as in-process chat. Failed refreshes retain selectable cached models and show the error even when filtering or sorting; retry clears the error.
Recall now publishes cancellation and its re-ask outcome together. Previously, a fast cancelled generation could finish before that outcome was recorded. Session regression fixtures now synchronize with actual readings and shutdown, and retain the inherited Go build cache when isolating their home directory. Assertions and real audit commands remain; no timeouts were increased.
Fixes #1508. Fixes #1655. The provider correction follows the recorded acceptance failure.
This PR is stacked on frozen #1632 (
Santosh/dev2); retarget todevafter that dependency lands. The separately identified settings mouse-row mismatch is outside this batch.Validation
Current combined revision:
70babe7d9936f92a3503dd8ce2dcd5eb14a5f160. Independent integration review passed. Combined canonical build, changelog validation and fullmake pr-ready BASE=458d1be73passed: fresh full application tests (165.753 seconds), all eight session-engine shards (87 seconds), and all eight TUI shards (22 seconds); exact-head CI passed. Final combined real-workflow verification passed on this same revision: provider failure/retry, invoice CSV aging, and a customer follow-up summary were built and used. All 27 generated artifact tests and 17 independent checks passed. All 70 requests across nine roles used DeepSeek v4.1 Flash and returned HTTP 200. Continuous three-minute GIF, full video, five screenshots and exact-revision audit. Fresh-chat preference retrieval also searched retained history, so this does not claim isolated automatic recall or live proof of the rare re-ask race; deterministic tests cover that ordering.Component evidence, which does not replace final combined acceptance:
eb92b814e: canonical build and full gate passed, including fresh full command package tests and eight TUI shards. Actual terminal acceptance passed cold loading, refresh, visible 503 beside filtered cached choices, retry recovery, provider-menu refresh, and closing a delayed picker without reopening. Six catalog GET requests, zero inference calls. The selecteddeepseek/deepseek-v4.1-flashmodel stayed unchanged. Closing the picker does not establish transport cancellation.73662adb5: full gate passed, including eight session shards. Early/late recall and revised-direction controls passed 300 repetitions. Earlier failed gates were diagnosed and corrected; no failures were waived.73662adb5saved a preference, opened fresh conversations, and generated and ran two Go programs. Request tracing verified late memory injection; independent artifact checks passed. All 27 completed requests used OpenRouterdeepseek/deepseek-v4.1-flash(26 HTTP 200, one cancelled auxiliary caption, no fallback). This did not exercise the rare live re-ask ordering; unchanged early-recall regression tests cover that race. Captioned source checkpoints and coverage limitations are attached.Automatic CI filters do not match the case-sensitive stacked base
Santosh/dev2, so CI was explicitly dispatched. Dispatch tests the immediate-parent delta; the combined local full gate compares the entire batch against frozen #1632. The earlier provider change entry initially failed two sentence checks, was corrected, and then passed; the aggregate entry also passed validation.Recorded provider behavior
These genuine terminal stills show executable revision
eb92b814e, cropped only to exclude private footer/settings rows. See the full evidence caption and limits. They establish catalog interaction, not paid model-answer quality or transport cancellation.Failed refresh remains visible beside cached choices under the model filter:
Successful retry clears the error and adds the new model:
The connected provider menu exposes refresh: