Skip to content

Add best-effort oldest-first work queue selection - #65246

Merged
pelikhan merged 7 commits into
mainfrom
pelikhan-work-queue-ordering
Oct 3, 2026
Merged

pelikhan merged 7 commits into
mainfrom
pelikhan-work-queue-ordering

Conversation

@pelikhan

@pelikhan pelikhan commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Why

The work queue should behave like a queue without the coordination cost of strict FIFO. Prefer older available Work while allowing concurrent processing and occasional reordering from delayed visibility or publication.

Approach

  • Add immutable Unix-millisecond enqueue metadata and matching oldest-available selection in JavaScript and Go. Work identity breaks timestamp ties; claimed and terminal Work is skipped.
  • Default gh aw work-queue claim --run-id RUN to oldest-first selection, retaining --work-id as an explicit operator override. The MCP snapshot reader exposes ordered available Work and a next_work recommendation, not durable authority.
  • Preserve the selected Work identity across publication retries. Publication still checks safety rather than global FIFO; no global sequence allocator, queue lock, or completion barrier is introduced.
  • Extend the TLA+ model with a selection action property, a negative control, and a guarded witness demonstrating permitted reordering. Shared fixtures exercise the JavaScript and Go implementations, including compaction, cancellation, and replay order independence.

Compatibility and trade-offs

Historical records without enqueue metadata use age zero and sort before timestamped Work. Duplicate submissions retain the first durable Work fact's age; conflicting metadata already in the log is rejected. Transaction schemas, audit schemas, historical log readers, and protocol documentation are updated together. Broader dispatcher mutation integration remains separate, and the model does not quantify reordering frequency.

Validation

  • bash specs/work-queue/check.sh: all three bounded positive configurations exhausted successfully; all negative controls and the weak-ordering witness produced the expected results.
  • bash specs/work-queue/traces.sh: competing Claims, recovery, external effects, and weak-ordering witnesses passed.
  • go test ./pkg/workqueue -count=1 and go test ./pkg/cli -run '^TestWork(Command|Queue)' -count=1 passed.
  • npm run typecheck and six focused JavaScript queue suites passed, covering 76 tests.
  • make fmt, make lint-cjs, and make agent-report-progress-no-test passed. Impacted Go tests also passed during the final validation run; lint findings were corrected and rechecked separately to avoid repeating the unit-test gate. All 302 workflow lock files remain in sync.

pelikhan and others added 2 commits October 2, 2026 22:04
Prefer the oldest available Work using immutable enqueue metadata while retaining safety-only publication and allowing reordering. Add ordering properties, negative controls, and guarded witnesses, and document the weak queue contract.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Add matching enqueue-time selection in JavaScript and Go, preserve first-submission age and legacy records, expose snapshot recommendations, and default operator claims to the oldest available Work without reselecting on publication retry. Update schemas and exercise both implementations against shared fixtures.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@pelikhan
pelikhan marked this pull request as ready for review October 3, 2026 05:25
Copilot AI balanced review requested due to automatic review settings October 3, 2026 05:25
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer failed during the skills-based review.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

Generated by Ponytail Reviewer for #65246

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate — ADR Verified

ADR reviewed: ADR-64955: Git-Backed Work Queue Coordination — implementation aligns with the stated decision. Great work! 🏗️

📋 Verification Summary

Verified against docs/adr/64955-git-backed-work-queue-coordination.md.

  • The ADR now commits to best-effort oldest-first selection using immutable enqueue-time metadata, with safety revalidated at publication rather than strict global FIFO.
  • pkg/workqueue/selection.go, pkg/cli/work_command.go, and actions/setup/js/work_queue_replay.cjs implement oldest-available selection and preserve the originally selected Work across retries.
  • actions/setup/js/work_queue_mcp_server.cjs exposes ordered available Work plus next_work as a recommendation, matching the ADR's read-only snapshot boundary.
  • Supporting schema, parsing, and tests in Go and JavaScript were updated together (pkg/workqueue/schema/*.json, pkg/cli/logs_work_queue.go, actions/setup/js/work_queue_*test.cjs, pkg/workqueue/selection_test.go), and no contradictory architectural change appears in the diff.

No divergences found between the ADR and this PR's implementation.

🏗️ ADR gate enforced by Design Decision Gate 🏗️ · pi · gpt54 · 18.1 AIC · ⌖ 9.19 AIC · ⊞ 10.9K · ◷
Comment /review to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Comment Memory

reviewed_at: 2026-10-03T05:28:26Z
review_event: COMMENT
top_themes:
  - No merge-blocking correctness or queue-ordering regressions found in changed lines
files_reviewed:
  - actions/setup/js/work_queue_mcp_server.cjs
  - actions/setup/js/work_queue_replay.cjs
  - actions/setup/js/work_queue_store.cjs
  - pkg/cli/logs_work_queue.go
  - pkg/cli/work_command.go
  - pkg/workqueue/replay.go
  - pkg/workqueue/selection.go
  - specs/work-queue/WorkQueue.tla
comment_count: 0

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 60.1 AIC · ⌖ 6.99 AIC · ⊞ 20.2K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

I did not find a blocking bug in the changed lines. The oldest-first claim path keeps the initially selected work across branch-update retries, and the mirrored JS/Go replay changes stay consistent with the new fixtures and tests.

Highlights
  • Checked the new default claim flow against pkg/workqueue/branch.go; the selected work_id is captured once and reused on publication conflicts instead of being reselected.
  • Spot-checked the JS and Go replay logic for enqueue ordering, duplicate submission handling, and legacy enqueued fallback semantics.
  • Existing review comments were empty, so there were no duplicate findings to suppress.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 60.1 AIC · ⌖ 6.99 AIC · ⊞ 20.2K
Comment /review to run again

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new enqueue field changes the strict version-1 wire format without advancing its protocol version or codemod path.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Adds best-effort oldest-first selection to the git-backed work queue while preserving concurrent, non-FIFO processing.

Changes:

  • Adds enqueue metadata and deterministic selection in Go and JavaScript.
  • Defaults CLI claims and MCP recommendations to oldest available Work.
  • Extends schemas, tests, documentation, and the TLA+ model.
File Description
specs/​work-queue/​WorkQueue.tla Models oldest-first staging.
specs/​work-queue/​WorkQueue.cfg Checks queue selection.
specs/​work-queue/​WeakOrderingWitness.cfg Demonstrates permitted reordering.
specs/​work-queue/​transactions.tsp Adds enqueue-time schema fields.
specs/​work-queue/​traces.sh Runs ordering witness traces.
specs/​work-queue/​selection-fixtures.json Provides shared ordering fixtures.
specs/​work-queue/​RecoveryWitness.cfg Checks selection during recovery.
specs/​work-queue/​Recovery.cfg Adds recovery selection verification.
specs/​work-queue/​README.md Documents queue-ordering semantics.
specs/​work-queue/​QueueOrdering.cfg Configures two-item ordering checks.
specs/​work-queue/​ExternalEffectWitness.cfg Adds selection verification.
specs/​work-queue/​CompetingClaimsWitness.cfg Covers concurrent dispatchers.
specs/​work-queue/​check.sh Runs new positive and negative checks.
specs/​work-queue/​BrokenQueueSelection.cfg Tests the selection negative control.
schemas/​logs.schema.json Exposes enqueue metadata.
schemas/​logs-jsonl.schema.json Exposes enqueue metadata in JSONL logs.
schemas/​audit.schema.json Exposes enqueue metadata in audits.
pkg/​workqueue/​selection.go Implements Go queue selection.
pkg/​workqueue/​selection_test.go Tests Go selection behavior.
pkg/​workqueue/​schema/​WorkTransaction.json Extends operator Work schema.
pkg/​workqueue/​schema/​WorkQueueWorkTransaction.json Extends runtime Work schema.
pkg/​workqueue/​schema_test.go Tests enqueue schema validation.
pkg/​workqueue/​replay.go Projects ordered available Work.
pkg/​cli/​work_command.go Defaults claims to oldest available Work.
pkg/​cli/​work_command_test.go Tests selection and retry behavior.
pkg/​cli/​logs_work_queue.go Parses enqueue metadata from snapshots.
pkg/​cli/​logs_work_queue_test.go Tests snapshot metadata validation.
docs/​adr/​64955-git-backed-work-queue-coordination.md Records ordering design decisions.
actions/​setup/​js/​work_queue_store.test.cjs Tests retry identity preservation.
actions/​setup/​js/​work_queue_store.cjs Extends transaction typing.
actions/​setup/​js/​work_queue_replay.test.cjs Tests JavaScript ordering and metadata.
actions/​setup/​js/​work_queue_replay.cjs Implements JavaScript selection and replay.
actions/​setup/​js/​work_queue_mcp_server.test.cjs Tests MCP ordering recommendations.
actions/​setup/​js/​work_queue_mcp_server.cjs Returns ordered Work and next_work.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread specs/work-queue/transactions.tsp

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 240.5 AIC · ⌖ 14.3 AIC · ⊞ 10K
Comment /matt to run again

Comment thread actions/setup/js/work_queue_replay.cjs
pelikhan and others added 2 commits October 2, 2026 22:52
Add a deterministic 1-to-2 codemod, preserve strict historical message shapes and age-zero Work, and align runtime schemas, audit parsing, documentation, and regression tests.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep duplicate submissions as age-preserving no-ops while exposing an idempotent count and accurate per-attempt new/rejected/idempotent publication diagnostics. Cover mixed outcomes, physical duplicates, skipped writes, and retry accounting.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@pelikhan

pelikhan commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

@copilot run pr-finisher / fix ci failures

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@copilot run pr-finisher / fix ci failures

Fixed in 925aebf: the Codex workflow test now resolves omitted models through the Codex engine default and accepts the supported copilot/auto canary route. Local validation passed; CI must be re-triggered by a maintainer because agent pushes do not start new runs.

@pelikhan

pelikhan commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

@copilot update TLA+ specification with new semantics

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@copilot update TLA+ specification with new semantics

Updated in 1a4d956: the TLA+ model now covers same-identity Work resubmissions with different enqueue metadata as idempotent no-ops, and checks that they preserve replayed facts and the original enqueue age. A reduced TLC configuration passed (84 states); the full work-queue search did not finish in this run.

@pelikhan

pelikhan commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

@copilot resolve the merge conflicts on this branch.

…rdering

# Conflicts:
#	pkg/workflow/prompts_test.go

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts on this branch.

Merged main and resolved the conflict in pkg/workflow/prompts_test.go in merge commit 6407e97. The resolution retains main's shared Codex model compatibility helper and tests. Focused tests and change-scoped validation passed.

@pelikhan
pelikhan merged commit 25cd1c2 into main Oct 3, 2026
29 checks passed
@pelikhan
pelikhan deleted the pelikhan-work-queue-ordering branch October 3, 2026 13:57
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants