Add accepted-plan decomposition exact-once guards and UI state (#6831)

## Thinking Path

> - Paperclip orchestrates AI agents for zero-human companies, so
planning approvals and child-issue fan-out are part of the core
control-plane loop.
> - Accepted plans are supposed to be a safe bridge from planning into
execution, especially when agents wake from review decisions and reuse
isolated workspaces.
> - The duplicate-subtask incident showed that an accepted plan revision
could be interpreted more than once across overlapping runs, which broke
the single-source-of-truth model for issue decomposition.
> - Fixing that required tightening the backend contract first:
accepted-plan decomposition needs an exact-once fingerprint, durable
claim state, and retry-safe child creation.
> - Once that backend behavior existed, the board still needed
visibility into what happened, so the issue detail view needed a
dedicated decomposition section instead of forcing operators to
reconstruct child creation from raw activity.
> - This pull request adds the exact-once decomposition primitive,
hardens wake routing and regressions around the incident, and surfaces
decomposition state in the UI so future incidents are both prevented and
easier to inspect.

## What Changed

- Added accepted-plan decomposition semantics to
`doc/execution-semantics.md`, including the exact-once fingerprint,
durable claim/result expectations, and retry/resume behavior.
- Added persistent accepted-plan decomposition claims in the backend,
including schema, shared types/validators, service logic, and issue
routes for creating and listing decomposition state.
- Hardened heartbeat routing so an accepted-plan continuation stays
scoped to the relevant planning issue instead of opportunistically
re-decomposing another accepted issue on the same assignee.
- Added regression coverage for the original failure modes: concurrent
same-parent retries, cross-issue accepted-plan isolation, and partial
child recreation under the same fingerprint.
- Added the `Plan decomposition` issue-detail section plus supporting
API/query-key/activity formatting updates so operators can see revision
status, owner, child counts, and the linked child issues directly in the
UI.
- Included the small follow-up UI fix so the decomposition section still
renders when the issue work mode is no longer `planning`.

## Verification

- `pnpm --filter @paperclipai/server typecheck`
- `pnpm --filter @paperclipai/ui typecheck`
- `pnpm --filter @paperclipai/db typecheck`
- `pnpm exec vitest run server/src/__tests__/issues-service.test.ts`
- `pnpm exec vitest run server/src/__tests__/issues-service.test.ts -t
"lists persisted decompositions with child issue summaries"`
- `pnpm exec vitest run server/src/__tests__/issues-service.test.ts -t
"accepted plan decomposition"
server/src/__tests__/heartbeat-accepted-plan-workspace-refresh.test.ts
server/src/__tests__/heartbeat-context-summary.test.ts`
- Manual UI path: create a planning issue without an isolated execution
workspace, add a `plan` document, accept the `request_confirmation`, let
Paperclip create child issues, then reopen the parent issue detail page
and confirm the `Plan decomposition` section shows the accepted
revision, status, idempotent-claim badge, and child links.
- Separate follow-up bug noted during manual UI validation: accepting a
plan on an issue whose run never records `workspace_finalize` is tracked
in `PAPA-445` and is not part of this PR’s fix scope.

## Risks

- This adds a new migration and a large Drizzle snapshot update;
reviewers should confirm the schema shape and generated metadata match
the intended decomposition table.
- The exact-once claim changes sit on the accepted-plan fan-out path, so
regressions there could block legitimate child creation or mis-handle
retries if the claim state machine is wrong.
- The new UI only appears when decomposition records exist; reviewers
should use the manual verification path above rather than expecting
existing issues on a stale local instance to show the section
automatically.
- `PAPA-445` remains an open follow-up for the `workspace_finalize`
accept gate when a planning handoff never records finalize; that bug can
interfere with reproducing the UI flow on isolated workspaces but does
not change the correctness of the exact-once decomposition feature
itself.

> Checked `ROADMAP.md`: this PR is a bug fix / control-plane hardening
change for accepted-plan decomposition, not a new uncoordinated roadmap
feature.

## Model Used

- OpenAI Codex via Paperclip `codex_local` (GPT-5-based coding agent;
exact backend model ID/context window not exposed in the run context),
with repository tool use, shell execution, and code-editing
capabilities.

<img width="806" height="1069" alt="Screenshot 2026-05-27 at 11 05
48 PM"
src="https://github.com/user-attachments/assets/5b00b670-96cd-4470-b0a3-581743bcae28"
/>


## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
This commit is contained in:
Devin Foley 2026-05-28 23:30:18 -07:00 committed by GitHub
parent 9eac727cf1
commit d9f91576a0
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
32 changed files with 22308 additions and 16 deletions

View file

@ -37,6 +37,7 @@ import {
heartbeatRuns,
issueApprovals,
issueComments,
issuePlanDecompositions,
issueRelations,
issueThreadInteractions,
issues,
@ -1933,6 +1934,59 @@ function normalizeInteractionContinuationWakeContext(
clearInteractionContinuationWakeContext(contextSnapshot);
}
type AcceptedPlanWakeRoutingDecision = {
otherActiveClaimIssueId: string;
otherActiveClaimIdentifier: string | null;
otherActiveClaimTitle: string;
forceFreshSession: boolean;
suppressAcceptedContinuation: boolean;
};
async function resolveAcceptedPlanWakeRoutingDecision(args: {
db: Db;
companyId: string;
agentId: string;
issueId: string | null;
acceptedPlanContinuationWake: boolean;
contextSnapshot: Record<string, unknown>;
}): Promise<AcceptedPlanWakeRoutingDecision | null> {
if (args.issueId === null) return null;
if (!args.acceptedPlanContinuationWake) return null;
const activeClaims = await args.db
.select({
sourceIssueId: issuePlanDecompositions.sourceIssueId,
identifier: issues.identifier,
title: issues.title,
})
.from(issuePlanDecompositions)
.innerJoin(issues, eq(issues.id, issuePlanDecompositions.sourceIssueId))
.where(and(
eq(issuePlanDecompositions.companyId, args.companyId),
eq(issuePlanDecompositions.ownerAgentId, args.agentId),
eq(issuePlanDecompositions.status, "in_flight"),
))
.orderBy(desc(issuePlanDecompositions.updatedAt), asc(issuePlanDecompositions.createdAt));
if (activeClaims.length === 0) return null;
if (activeClaims.some((claim) => claim.sourceIssueId === args.issueId)) return null;
const otherActiveClaim = activeClaims[0];
if (!otherActiveClaim) return null;
const hasAcceptedContinuationWake =
readNonEmptyString(args.contextSnapshot.interactionKind) === "request_confirmation" &&
readNonEmptyString(args.contextSnapshot.interactionStatus) === "accepted";
return {
otherActiveClaimIssueId: otherActiveClaim.sourceIssueId,
otherActiveClaimIdentifier: otherActiveClaim.identifier ?? null,
otherActiveClaimTitle: otherActiveClaim.title,
forceFreshSession: true,
suppressAcceptedContinuation: hasAcceptedContinuationWake,
};
}
export function mergeCoalescedContextSnapshot(
existingRaw: unknown,
incoming: Record<string, unknown>,
@ -2229,6 +2283,7 @@ export function buildPaperclipTaskMarkdown(input: {
kind?: string | null;
status?: string | null;
} | null;
acceptedPlanContinuation?: boolean;
}) {
const quoteTaskScalar = (value: string) => JSON.stringify(value);
const fenceTaskText = (value: string) => {
@ -2243,8 +2298,11 @@ export function buildPaperclipTaskMarkdown(input: {
const wakeComment = input.wakeComment ?? null;
const acceptedPlanContinuation =
!wakeComment &&
input.interaction?.kind === "request_confirmation" &&
input.interaction.status === "accepted";
(input.acceptedPlanContinuation || (
input.interaction?.kind === "request_confirmation" &&
input.interaction.status === "accepted" &&
issue?.workMode === "planning"
));
if (!issue && !wakeComment) return null;
const lines = [
@ -2270,6 +2328,12 @@ export function buildPaperclipTaskMarkdown(input: {
"Planning mode directive:",
directive,
);
} else if (acceptedPlanContinuation) {
lines.push(
"",
"Accepted plan directive:",
"Create child issues from the approved plan only. Do not write code or perform implementation work on the source issue.",
);
}
const description = issue.description?.trim();
if (description) {
@ -7055,6 +7119,37 @@ export function heartbeatService(db: Db, options: HeartbeatServiceOptions = {})
.where(and(eq(projects.id, executionProjectId), eq(projects.companyId, agent.companyId)))
.then((rows) => rows[0] ?? null)
: null;
const acceptedPlanWakeRoutingDecision = issueContext
? await resolveAcceptedPlanWakeRoutingDecision({
db,
companyId: agent.companyId,
agentId: agent.id,
issueId,
acceptedPlanContinuationWake:
readNonEmptyString(context.workspaceRefreshReason) === "accepted_plan_confirmation"
|| (
issueContext.workMode === "planning"
&& readNonEmptyString(context.interactionKind) === "request_confirmation"
&& readNonEmptyString(context.interactionStatus) === "accepted"
),
contextSnapshot: context,
})
: null;
if (acceptedPlanWakeRoutingDecision) {
context.forceFreshSession = true;
context.acceptedPlanWakeRouting = {
reason: "other_issue_claim_in_flight",
otherActiveClaimIssueId: acceptedPlanWakeRoutingDecision.otherActiveClaimIssueId,
otherActiveClaimIdentifier: acceptedPlanWakeRoutingDecision.otherActiveClaimIdentifier,
otherActiveClaimTitle: acceptedPlanWakeRoutingDecision.otherActiveClaimTitle,
};
if (acceptedPlanWakeRoutingDecision.suppressAcceptedContinuation) {
clearInteractionContinuationWakeContext(context);
delete context.workspaceRefreshReason;
}
} else {
delete context.acceptedPlanWakeRouting;
}
const routineEnvContext = await getRoutineEnvForExecutionIssue(agent.companyId, issueContext);
const projectExecutionWorkspacePolicy = gateProjectExecutionWorkspacePolicy(
parseProjectExecutionWorkspacePolicy(projectContext?.executionWorkspacePolicy),
@ -7154,6 +7249,9 @@ export function heartbeatService(db: Db, options: HeartbeatServiceOptions = {})
kind: readNonEmptyString(context.interactionKind),
status: readNonEmptyString(context.interactionStatus),
},
acceptedPlanContinuation:
readNonEmptyString(context.workspaceRefreshReason) === "accepted_plan_confirmation"
&& !parseObject(context.acceptedPlanWakeRouting),
});
if (issueRef) {
context.paperclipIssue = {