Repository navigation
Add best-effort oldest-first work queue selection - #65246
Conversation
Prefer the oldest available Work using immutable enqueue metadata while retaining safety-only publication and allowing reordering. Add ordering properties, negative controls, and guarded witnesses, and document the weak queue contract. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Add matching enqueue-time selection in JavaScript and Go, preserve first-submission age and legacy records, expose snapshot recommendations, and default operator claims to the oldest available Work without reselecting on publication retry. Update schemas and exercise both implementations against shared fixtures. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
✅ Test Quality Sentinel completed test quality analysis. Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff
|
|
🧠 Matt Pocock Skills Reviewer failed during the skills-based review.
|
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.
|
|
✅ PR Code Quality Reviewer completed the code quality review.
|
|
✅ Ponytail Reviewer completed successfully! Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details.
|
✅ Design Decision Gate — ADR VerifiedADR reviewed: ADR-64955: Git-Backed Work Queue Coordination — implementation aligns with the stated decision. Great work! 🏗️ 📋 Verification SummaryVerified against
No divergences found between the ADR and this PR's implementation.
|
Comment MemoryNote This comment is managed by comment memory.It stores persistent context for this thread in the code block at the top of this comment.
|
There was a problem hiding this comment.
Verdict
I did not find a blocking bug in the changed lines. The oldest-first claim path keeps the initially selected work across branch-update retries, and the mirrored JS/Go replay changes stay consistent with the new fixtures and tests.
Highlights
- Checked the new default claim flow against pkg/workqueue/branch.go; the selected work_id is captured once and reused on publication conflicts instead of being reselected.
- Spot-checked the JS and Go replay logic for enqueue ordering, duplicate submission handling, and legacy enqueued fallback semantics.
- Existing review comments were empty, so there were no duplicate findings to suppress.
🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 60.1 AIC · ⌖ 6.99 AIC · ⊞ 20.2K
Comment /review to run again
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new enqueue field changes the strict version-1 wire format without advancing its protocol version or codemod path.
Review effort: Balanced
Findings: 1
What changed in this PR
Adds best-effort oldest-first selection to the git-backed work queue while preserving concurrent, non-FIFO processing.
Changes:
- Adds enqueue metadata and deterministic selection in Go and JavaScript.
- Defaults CLI claims and MCP recommendations to oldest available Work.
- Extends schemas, tests, documentation, and the TLA+ model.
| File | Description |
|---|---|
specs/work-queue/WorkQueue.tla |
Models oldest-first staging. |
specs/work-queue/WorkQueue.cfg |
Checks queue selection. |
specs/work-queue/WeakOrderingWitness.cfg |
Demonstrates permitted reordering. |
specs/work-queue/transactions.tsp |
Adds enqueue-time schema fields. |
specs/work-queue/traces.sh |
Runs ordering witness traces. |
specs/work-queue/selection-fixtures.json |
Provides shared ordering fixtures. |
specs/work-queue/RecoveryWitness.cfg |
Checks selection during recovery. |
specs/work-queue/Recovery.cfg |
Adds recovery selection verification. |
specs/work-queue/README.md |
Documents queue-ordering semantics. |
specs/work-queue/QueueOrdering.cfg |
Configures two-item ordering checks. |
specs/work-queue/ExternalEffectWitness.cfg |
Adds selection verification. |
specs/work-queue/CompetingClaimsWitness.cfg |
Covers concurrent dispatchers. |
specs/work-queue/check.sh |
Runs new positive and negative checks. |
specs/work-queue/BrokenQueueSelection.cfg |
Tests the selection negative control. |
schemas/logs.schema.json |
Exposes enqueue metadata. |
schemas/logs-jsonl.schema.json |
Exposes enqueue metadata in JSONL logs. |
schemas/audit.schema.json |
Exposes enqueue metadata in audits. |
pkg/workqueue/selection.go |
Implements Go queue selection. |
pkg/workqueue/selection_test.go |
Tests Go selection behavior. |
pkg/workqueue/schema/WorkTransaction.json |
Extends operator Work schema. |
pkg/workqueue/schema/WorkQueueWorkTransaction.json |
Extends runtime Work schema. |
pkg/workqueue/schema_test.go |
Tests enqueue schema validation. |
pkg/workqueue/replay.go |
Projects ordered available Work. |
pkg/cli/work_command.go |
Defaults claims to oldest available Work. |
pkg/cli/work_command_test.go |
Tests selection and retry behavior. |
pkg/cli/logs_work_queue.go |
Parses enqueue metadata from snapshots. |
pkg/cli/logs_work_queue_test.go |
Tests snapshot metadata validation. |
docs/adr/64955-git-backed-work-queue-coordination.md |
Records ordering design decisions. |
actions/setup/js/work_queue_store.test.cjs |
Tests retry identity preservation. |
actions/setup/js/work_queue_store.cjs |
Extends transaction typing. |
actions/setup/js/work_queue_replay.test.cjs |
Tests JavaScript ordering and metadata. |
actions/setup/js/work_queue_replay.cjs |
Implements JavaScript selection and replay. |
actions/setup/js/work_queue_mcp_server.test.cjs |
Tests MCP ordering recommendations. |
actions/setup/js/work_queue_mcp_server.cjs |
Returns ordered Work and next_work. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 240.5 AIC · ⌖ 14.3 AIC · ⊞ 10K
Comment /matt to run again
Add a deterministic 1-to-2 codemod, preserve strict historical message shapes and age-zero Work, and align runtime schemas, audit parsing, documentation, and regression tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep duplicate submissions as age-preserving no-ops while exposing an idempotent count and accurate per-attempt new/rejected/idempotent publication diagnostics. Cover mixed outcomes, physical duplicates, skipped writes, and retry accounting. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
@copilot run pr-finisher / fix ci failures |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Fixed in 925aebf: the Codex workflow test now resolves omitted models through the Codex engine default and accepts the supported |
|
@copilot update TLA+ specification with new semantics |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Updated in 1a4d956: the TLA+ model now covers same-identity Work resubmissions with different enqueue metadata as idempotent no-ops, and checks that they preserve replayed facts and the original enqueue age. A reduced TLC configuration passed (84 states); the full work-queue search did not finish in this run. |
|
@copilot resolve the merge conflicts on this branch. |
…rdering # Conflicts: # pkg/workflow/prompts_test.go Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Merged |
|
🎉 This pull request is included in a new release. Release: |

Why
The work queue should behave like a queue without the coordination cost of strict FIFO. Prefer older available Work while allowing concurrent processing and occasional reordering from delayed visibility or publication.
Approach
gh aw work-queue claim --run-id RUNto oldest-first selection, retaining--work-idas an explicit operator override. The MCP snapshot reader exposes ordered available Work and anext_workrecommendation, not durable authority.Compatibility and trade-offs
Historical records without enqueue metadata use age zero and sort before timestamped Work. Duplicate submissions retain the first durable Work fact's age; conflicting metadata already in the log is rejected. Transaction schemas, audit schemas, historical log readers, and protocol documentation are updated together. Broader dispatcher mutation integration remains separate, and the model does not quantify reordering frequency.
Validation
bash specs/work-queue/check.sh: all three bounded positive configurations exhausted successfully; all negative controls and the weak-ordering witness produced the expected results.bash specs/work-queue/traces.sh: competing Claims, recovery, external effects, and weak-ordering witnesses passed.go test ./pkg/workqueue -count=1andgo test ./pkg/cli -run '^TestWork(Command|Queue)' -count=1passed.npm run typecheckand six focused JavaScript queue suites passed, covering 76 tests.make fmt,make lint-cjs, andmake agent-report-progress-no-testpassed. Impacted Go tests also passed during the final validation run; lint findings were corrected and rechecked separately to avoid repeating the unit-test gate. All 302 workflow lock files remain in sync.