Files
PaperClipAI/server
DottaandPaperclip 9ae3d8db3d fix: keep pre-dispatch review waits out of execution recovery (#15024)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The queued-run gate can cancel a continuation that must wait for
review.
> - This cancellation happens before execution authority or a provider
starts.
> - Recovery currently treats the gate receipt as unknown provider
execution.
> - That mistake blocks a conversation after a successful reply and
hides Retry.
> - This pull request recognizes only the recorded, unclaimed
review-wait state.
> - Review waits keep their normal disposition path, and new user input
can recover older false holds.

## Linked Issues or Issue Description

Refs #15015, #15020, and #15022. Related #11614 narrows the review
posture that causes cancellation; this change corrects recovery after a
valid cancellation.

**What happened?**

After a successful agent reply, the queued-run gate cancelled an
automatic continuation with `issue_continuation_waiting_on_review`. The
gate retained `timeoutSource: stale_queued_run_gate` and a matching stop
reason. No execution authority or provider started. Recovery still
created an unknown-action hold, moved the task to Blocked, and hid
Retry.

**Expected behavior**

Use normal review-wait disposition repair for this recorded state. Allow
Retry, a new user message, or saved undelivered input to recover an
older false hold after ordinary admission checks pass. Preserve the
cancelled run and do not replay its input.

**Steps to reproduce**

1. Finish an agent turn on an open task that has a real review target.
2. Let the automatic continuation reach the queued-run review gate.
3. Refresh after the cancelled run is checked by recovery.
4. Confirm a review wait is handled as a wait rather than unknown
provider work.
5. Reproduce an older false hold for the same receipt, then request
Retry or send a new message.
6. Confirm only one fresh turn starts, and contradictory execution or
cleanup evidence retains the hold.

**Paperclip version or commit**

Reproduced on `215586d127`.

**Deployment mode**

Authenticated private self-hosted server, built from source.

## What Changed

- Recognize the exact review-wait dispatch receipt only while all
execution claims remain unset.
- Exempt recovery only after checking retained launch and provider
events, coordinators, and environment cleanup. Keep the synchronous
classifier conservative without that database proof.
- Apply the verified classification to automatic recovery, heartbeat
retries, and stranded-queue release, so saved user input starts once.
- Reuse guarded startup admission for Retry, new input, and saved input
on older false holds.
- Show a precise review-wait notice and keep continuation guidance
consistent with Retry availability.
- Verify provider events, launch events, coordinators, and cleanup
before admission.
- Add five initial red regressions, three additional red recovery
evidence regressions, concurrent saved-input coverage, and negative
evidence checks.
- Document the review-wait contract.

## Verification

- Red: five regressions fail on unchanged master. Existing review-wait
and contradictory-evidence cases still pass.
- Workspace `pnpm -r typecheck` passes.
- All 752 affected recovery, continuation, queue, classification, and
retry-scheduling tests pass.
- Three additional review regressions failed before the database proof
was added; all 12 focused review-wait cases then pass.
- Workspace `pnpm build` passes.
- Saved-input promotion and recovery notice regressions fail before
their fixes and pass afterward.
- Current-head CI has 54 passing checks and 2 skipped optional Storybook
checks. Greptile reviewed `0bf1437110e1617ae4544afa41f4319eac763dba` at
5/5 with zero open findings. The complete suite runs in sharded CI. No
complete local monolithic pass is claimed; an earlier long run was
stopped, and its unrelated failing case passed in isolation.

## Risks

The error code alone cannot establish that no provider started. This
exception also requires the server gate receipt, matching stop reason,
and null execution authority fields. User admission separately checks
coordinator, launch and provider events, environment cleanup, pending
decisions, ownership, task holds, budget, and active execution. No
migration or dependency change.

## Model Used

OpenAI Codex, an agent based on GPT-6. The exact runtime model ID and
context window are not exposed in this session. Used reasoning,
repository tools, code execution, and browser inspection.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-03 01:00:42 -05:00
..