Commit 95d1969
authored
fix(provenance): let a run that never started report why it failed (#7281)
* fix(provenance): let a run that never started report why it failed
A copilot-run workflow that fails before reaching the engine crossed
back with no provenance, which latched the tool's registry and reduced
the result to "result unavailable". The caller was told its run failed
but not that the workflow was undeployed, or the input invalid, or the
slot unavailable — the reasons this layer produces before any block
runs, naming no secret because none had been resolved yet.
The executor attaches its execution result to every throw, so the
absence of one is proof that no block ran: output, logs and error are
all undefined and the only content is a message this layer wrote. That
is an absence, not an inability to vouch, so the crossing now carries
an exact-empty envelope. The message still passes the tool boundary's
egress projection against the same registry, so anything that registry
knows is still redacted. A run that did execute and could not vouch
hands back its incomplete envelope exactly as before, and that still
latches.
Make the attach total rather than conditional to keep that inference
sound. A block failure is already normalized on the way in, so the old
`instanceof Error` guard held in practice; what it did not give was a
guarantee covering a non-Error raised by the engine's own synchronous
work. toError is identity-preserving, so ordinary failures keep their
type.
The empty envelope moves to the registry module, which owns the
vocabulary, replacing a private copy in the logging session so one
definition states what "vouched for, naming nothing" is.
* fix(provenance): keep the post-run crossing window out of the never-started claim
Review round 1, both findings accepted.
The post-run crossing runs inside the same try as the executor call, so
when that import is what throws, the catch sees an error carrying no
execution result — the same evidence a run that never started leaves.
The previous condition read that as "nothing crossed" and vouched for
it, when in fact an execution exists and its provenance was never
imported, which is exactly the content that cannot be vouched for.
Record whether the executor returned and require both facts before
claiming the absence: not past the executor, and no result attached.
Everything else hands back whatever envelope it has, and an incomplete
one still latches.
The executor test also could not fail against the old gated attach: a
block failure is normalized on the way in, so its rejection already
arrived as an Error. Drive it through the cancellation subscribe run()
awaits before the queue instead, which is its own synchronous work and
reaches the catch untouched — the case the total attach exists for.
* fix(provenance): carry the run's result through post-execution failures
Round 2, cubic's finding accepted — and it was a distinct window, not a
restatement of round 1. The executor's post-execution work runs after
the run has produced a result but before `executeWorkflow` returns, so
a failure there reached callers with no result attached: the run threw
nothing itself, and the flag added last round could not be set yet.
Every consumer that reads a missing result as "no block ran" was wrong
in that window, this crossing included.
Fix it where the result lives rather than at each reader. The executor
attaches its own on the throws it raises; `executeWorkflow` now does the
same for failures raised after it holds one, skipping the case the
executor already recorded. Logging and trace spans get the same benefit
for free — they read the identical signal.
That makes an absent result total again, so the boolean flag goes and
the crossing reads one thing: the result from the error, or the one
already returned when the failure came later still, from the crossing
itself. Only a failure with neither can claim nothing ran. The
post-return case now describes content with the run's real envelope
rather than latching blind, which is strictly more accurate than either
prior behaviour.
* fix(provenance): normalize a post-execution failure so it can carry the result
Round 3, cubic's finding accepted. The guard added last round required
the caught value to already be an `Error`, so a non-Error raised by
post-execution work skipped the attach and was rethrown bare — the same
hole this branch closed in the executor, left open one layer up by my
own change. A Copilot run would have reported an executed workflow as
never started and vouched for content it cannot describe.
Normalize once at the top of the catch and use that value throughout,
including the rethrow, matching what the executor does. `toError`
returns an `Error` unchanged, so a custom error class keeps its
identity and every ordinary failure is untouched — the existing
identity assertion on the rejection path still holds.
Two tests: the result reaches an ordinary post-execution failure, and a
non-Error one is normalized so it can carry the result too. The second
fails against the previous guard.1 parent d7c9f51 commit 95d1969
8 files changed
Lines changed: 280 additions & 22 deletions
File tree
- apps/sim
- executor
- execution
- utils
- lib
- logs/execution
- workflows
- application
- executor
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | | - | |
| 31 | + | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| |||
275 | 275 | | |
276 | 276 | | |
277 | 277 | | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
278 | 311 | | |
279 | 312 | | |
280 | 313 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
185 | 185 | | |
186 | 186 | | |
187 | 187 | | |
188 | | - | |
189 | | - | |
190 | | - | |
191 | | - | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
192 | 199 | | |
193 | 200 | | |
194 | 201 | | |
| |||
Lines changed: 12 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
226 | 226 | | |
227 | 227 | | |
228 | 228 | | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
229 | 241 | | |
230 | 242 | | |
231 | 243 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
46 | 46 | | |
47 | 47 | | |
48 | 48 | | |
| 49 | + | |
49 | 50 | | |
50 | 51 | | |
51 | 52 | | |
| |||
124 | 125 | | |
125 | 126 | | |
126 | 127 | | |
127 | | - | |
128 | | - | |
129 | | - | |
130 | | - | |
131 | 128 | | |
132 | 129 | | |
133 | 130 | | |
| |||
Lines changed: 129 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
391 | 391 | | |
392 | 392 | | |
393 | 393 | | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
| 511 | + | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
394 | 523 | | |
Lines changed: 28 additions & 10 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
36 | | - | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
37 | 40 | | |
38 | 41 | | |
39 | 42 | | |
| |||
250 | 253 | | |
251 | 254 | | |
252 | 255 | | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
253 | 263 | | |
254 | 264 | | |
255 | 265 | | |
| |||
302 | 312 | | |
303 | 313 | | |
304 | 314 | | |
| 315 | + | |
305 | 316 | | |
306 | 317 | | |
307 | 318 | | |
| |||
325 | 336 | | |
326 | 337 | | |
327 | 338 | | |
328 | | - | |
329 | | - | |
330 | | - | |
331 | | - | |
332 | | - | |
333 | | - | |
334 | | - | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
335 | 345 | | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
336 | 352 | | |
337 | | - | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
338 | 356 | | |
339 | 357 | | |
340 | 358 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
| 59 | + | |
59 | 60 | | |
60 | 61 | | |
61 | 62 | | |
| |||
296 | 297 | | |
297 | 298 | | |
298 | 299 | | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
299 | 338 | | |
300 | 339 | | |
301 | 340 | | |
| |||
0 commit comments