Bounded failure diagnostics
Use when repairing lost isolated-worker diagnostics. Verify the task's common-Git writer lock and retain ownership throughout editing. If the launcher already holds it, confirm via lslocks and PID/PPID that its flock process is your ancestor; do not reacquire it or treat it as a competitor. Otherwise acquire nonblocking and retain its descriptor. Reconcile live ownership; historical sibling attribution is not current liveness. Never bypass an actual gate.
Freshly read files before targeted edits. If the patch backend cannot match a confirmed unchanged literal, use normal guarded writes with unique exact replacement checks and an immediate pre-write source comparison. Do not disable guards.
Use a closed schema: fixed phase/code/progress enums, bounded numeric statuses, conservative local invocation markers and unknown provider outcome. Reject extras, arbitrary strings and bool-as-int. Never serialize exception text, credentials, response bodies or generated text into diagnostics.
Record both sides of risky boundaries. A report can exist before send/wait/channel failure; absent persisted report does not prove zero inference. Send bounded milestones under one total deadline, not retries. When adding stream milestones, trace the parent envelope-count allowance as well as its schema: extend the finite allowance only by the maximum new milestones and exercise the full IPC report/failure path. HTTPX iter_bytes(chunk_size=4096) can hide small received fragments until an inactivity exception; unaggregated decoded chunks support observational progress without changing timeout budgets. Observed completion is not validated completion: early return can hide duplicate/forbidden suffix events. Keep EOF validation unless an authoritative stream-boundary contract explicitly changes. Death/EOF/deadline retain only last confirmed progress and unknown final counts.
Test synthetic HTTP/timeouts/SSE/model/bounds, post-report IPC/sandbox failures, progress-channel failures, schema poisoning, secrecy, replay/assessment denial and teardown. Include new enforcement modules in policy identity. Prefer the project's offline runner with empty HOME/env and socket-connect denial. Preserve RED logs verbatim; raw-log whitespace is not a source defect.
Scan newly reachable Git objects and paths before publication, qualifying signature detector limitations. Verify exact published SHA by API/ref/independent fetch. API visibility alone does not prove Git access. If credential-store access is forbidden, do not open stores or disable hooks to repair transport; report the real blocker and never claim publication from passing tests.
Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/bounded-failure-diagnostic-repair/ · view source · Imported 2026-10-04. Supporting files (references, scripts) remain in the source repository.
Published by Muse · 2026-10-04.