Authoritative cross-role generic queue allocation for controller #840
Closed
opened 2026-07-22 22:58:33 -05:00 by jcwalker3
·
0 comments
No Branch/Tag Specified
master
fix/issue-790-slice-a-heartbeat-policy
feat/issue-628-autonomous-handoffs-orchestration
feat/issue-634-readonly-system-health-api
feat/issue-638-webui-app-shell-phase1
fix/issue-840-cross-role-queue-allocation
feat/issue-822-atomic-install-authority-kernel
feat/issue-633-console-authz-audit-model
feat/issue-636-inventory-api
fix/issue-815-preflight-worktree-forwarding
feat/issue-812-publish-unpublished-commit
feat/issue-635-project-registry-api
feat/issue-798-worker-registry-schema
feat/issue-610-live-remote-parity
docs/issue-632-web-console-architecture
fix/issue-760-exact-owner-renewal
fix/issue-787-kill-segment-separators
chore/issue-681-preserve-review-session-wip
v1.1.0
Labels
Clear labels
allocator
anti-stomp
architecture
bug
chore
codex
concurrency
contamination
control-plane
dashboard
database
design
documentation
enhancement
gitea
glitchtip
important
incident
incident-bridge
integration
jenkins
labels
leases
mcp
mcp-health
mcp-menu
multi-project
mutating
nice-to-have
observability
portability
preflight
protected-branch
queue
read-only
reconnect
recovery
refactor
release
reliability
resumable-review
reviewer
roadmap
safety
security
self-hosted
sentry
stale-runtime
status:blocked
status:in-progress
status:pr-open
status:ready
terminal-lock
testing
tracker
type:bug
type:feature
type:feature
type:guardrail
visibility
workflow
workflow-hardening
workflow-hardening
Controller-owned work allocator
Prevent concurrent LLM session stomping
Architecture / structural design
OpenAI Codex client / workflow session surface
Concurrent session safety
Workflow or session contamination incident
MCP control-plane coordination and allocation authority
MCP operational dashboard/queue view
Internal coordination storage (SQLite/Postgres)
Design / investigation, no implementation
Docs / runbooks
New feature or improvement
Gitea MCP workflow
GlitchTip integration
Operational or process incident requiring durable audit trail
Sentry-to-Gitea incident bridging
Integration testing
Jenkins integration
Label taxonomy management
Lease adopt/release/expire lifecycle
MCP server / tooling
MCP namespace and runtime health
MCP menu surface
Work spanning multiple monitoring projects or Gitea repos
Mutating action; requires gating
Observability, metrics, traces, error reporting
Cross-platform / portability
Shared preflight gates before mutation
Protected branch / stable-branch policy concern
Work queue visibility and allocation
Read-only, no mutation
MCP client reconnect/reload recovery path
Recovery paths for stale/foreign leases
Code refactor / restructure
Release / versioning
Reliability / failure handling
Persist and resume prepared review verdicts across sessions
Reviewer workflow tooling
Roadmap / umbrella issue
Safety rails and fail-closed mutation guards
Security / trust boundary
Self-hosted infrastructure integration
Sentry error monitoring integration
Stale backend daemon / runtime-vs-master parity failures
Issue is blocked
Issue is being worked on
Issue has an open pull request
Issue is ready for work
Terminal review lock (#332) path
Tests / test coverage
Issue tracker hygiene / meta
Bug or defect
Feature or enhancement
Feature or enhancement
Safety gate or guardrail
Workflow state visibility for LLMs/operators
Cross-tool workflow
LLM workflow coordination hardening
LLM workflow coordination hardening
No labels
type:bug
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Scaled-Tech-Consulting/Gitea-Tools#840
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
Controller-owned queue allocation is not authoritative across roles. Observed defects:
gitea_allocate_next_workinvoked through gitea-controller binds allocation torole=controllerand returnsselected=nulleven when the authoritative dashboard contains eligible author, reviewer, merger, or reconciler work.gitea_route_task_sessiondoes not recognize the generic task typeprocess_work_queueand returnsambiguous_task_stop.Controller role metadata is inconsistent:
gitea_whoami:role=controllerrole_kind=reconcileractive_role=reconcilerrole=controllerRoot cause (current code)
allocator_service.classify_skipforROLE_CONTROLLERonly accepts reconciler-needed / blocked diagnosis targets, so normal author/reviewer/merger candidates are skipped as "does not require controller".role_session_router.TASK_REQUIRED_ROLEhas noprocess_work_queueentry → fail-closed ambiguous route._role_kind) instead of the declared profile role, so a controller profile can be mislabeled reconciler.Required behavior
Canonical controller-owned cross-role allocation mode
allocation_mode=cross_role).Generic queue task type
process_work_queue(and hyphen alias) ingitea_route_task_sessionwithrequired_role=controller.allowed_current_session.Normalize controller role metadata to
controllergitea_whoamiprofile.role, control-plane guiderole_kind, task routeractive_role, and allocatorrolemust agree oncontrollerwhen the active profile declares controller (or profile name contains controller).Dashboard remains explanatory
gitea_workflow_dashboardstays read-only and must never replace allocator selection. Update controller prompt text only if needed to point at cross-role allocate / process_work_queue.Acceptance criteria
selected=null.limittruncates skip lists only; selection ranks complete inventory (pagination unaffected).gitea_route_task_session(task_type="process_work_queue")under controller returnsallowed_current_session(notambiguous_task_stop).controlleracross whoami, control-plane guide, router active_role, and allocator role.Affected areas
allocator_service.pyrole_session_router.pytask_capability_map.pygitea_mcp_server.py(gitea_allocate_next_work, control-plane guide, role helpers)namespace_workspace_binding.py(controller role kind normalization)workflow_dashboard.py(prompt only if needed)tests/Non-goals
Safety
Fail closed on incomplete inventory, unknown roles, and ownership ambiguity. Never assign raw monitoring incidents.