The request
Reliability plan for top three unresolved issues
Read the full request
Inspect the current default branch of the imported mgtf/atoma repository. Produce a text-only reliability project plan, with no file edits. Reassess the confirmed findings in docs/archive/reviews/code-review-2026-10-02.md against current code and tests; do not assume an old finding remains open. Select the three highest-value unresolved workstreams. For each, provide the exact current evidence, affected files, a bounded implementation sequence, dependencies, a verification method, and a clear done condition. Rank the workstreams, explain the ranking, and distinguish verified facts from uncertainties. Respect repository AGENTS.md and subsystem contracts. Do not launch a live Atoma run, deploy, push, or change repository files as part of the analysis.
The result
# Reliability project plan
## Verified baseline and constraints
- `AGENTS.md` requires subsystem guidance before source work (`AGENTS.md:12`, SHA-256 `80234867afeb78ce7715c4a8679d27be00dd117b4d2f470f4c4f65d79f38cb30`). It also says tests should cross the production boundary (`AGENTS.md:386-391`) and forbids starting a run merely for connectivity (`AGENTS.md:376-379`).
- MCP guidance requires one HTTP surface and loose output schemas: “Never add an `outputSchema` a payload can miss” (`src/mcp/AGENTS.md:136-139`, SHA-256 `462898e7817925821cd00305549916e5378cae1e9f75ea49d299aa50b0338e7f`).
- The archived review is SHA-256 `59c5f314876501fa9b5e758de3ac46cb740cc8f3addc5c837b4a4071299f0af2`. Its correction table is historical evidence only; current status below is based on current source/tests.
- The authorized documentation search returned no passages for the requested MCP/Jev/run-contract query (snapshot SHA-256 `a0293b7cd38573ee41d45a81a5206bf6427c0fd528473c433d196fcfb1317731`); this is not evidence that contracts are absent.
## Reassessment of all 12 confirmed findings
1. **1.1 MCP closed output schemas — Partially resolved.** Current `atoma_costs` and `atoma_sentinel_health` use `z.looseObject` and include the previously missing fields (`src/mcp/tools.ts:945-972,1010-1030`, SHA-256 `d3954ce7f4f1e5d3f50d244977a1c3b7812069e05ff93caeaec7235e2e6bb4e6`). `tests/mcp-http.test.ts:746-758` exercises declared schemas through the SDK, and `tests/mcp-modern.test.ts:112-125` checks schemas are open. A full live 41-tool/client matrix was not executed.
2. **1.2 resumed-client accounting — Uncertain/partially resolved.** `initialiseResumed` now calls `countClient` (`src/mcp/http.ts:604-627`, SHA-256 `20025ac175fc4604d7e37de44842cd2e7bf3ba652f0c3ff95dd5b27ad98c1662`), and `tests/mcp-http-lifetimes.test.ts:342-358` checks restart, resumed count, and caller binding. A real deployment-to-deployment continuity check was not performed.
3. **1.3 Codex-home preemption — Resolved by current correction record.** The archived correction states preemption is classified independently of cancellation-error shape; no contrary current source/test evidence was found in the bounded search.
4. **1.4 lost Jev audits on failure — Partially resolved.** Current runner code settles audits before trace closure on cancellation, watchdog, success, and error (`src/run/runner.ts:1194-1203,1271-1275,1295-1303,1416-1423`, SHA-256 `92ac57b6e526bc26c4d09daa06ac784f3b3b79f34bdb40e91221dfa05ac17031`). `tests/runner-tissue-routing.test.ts:121-163` verifies failure and shutdown ordering. A dedicated watchdog execution was not run.
5. **1.5 criterion auto-contradiction — Resolved.** The archived correction specifies normalized IDs, required judgements, and conservative duplicate handling; current acceptance/inherited-check regression tests cover stopped and missing replay evidence (`tests/inherited-checks.test.ts:795-838`).
6. **1.6 retired ChatGPT pins — Resolved.** The correction records rejection before client construction; no contrary current source evidence was found in the bounded search.
7. **1.7 lost zero cache-write prices — Resolved.** `src/cli/modelCatalogUpdate.ts:260-267` preserves `current.cacheWrite`; `tests/model-catalog-update.test.ts:167-174` asserts every known zero remains zero.
8. **1.8 zero-as-unlimited mismatch — Resolved by the correction record.** Current settings code has a shared `zeroMeansUnlimited` path (`src/cli/settings.ts:47,109`); no contrary current evidence was found.
9. **1.9 oversized starting file presented as removed — Resolved by the correction record.** Current bounded search found the related replay/starting-workspace tests but no remaining matching “removed when too large” implementation claim.
10. **1.10 empty stopped replay treated as approval — Resolved.** Current tests explicitly verify stopped replay visibility with zero established baseline (`tests/inherited-checks.test.ts:833-838`).
11. **1.11 root remediation ignored inherited contradictions — Resolved by the correction record.** Current inherited-check regression coverage includes refusal when prior checks were not replayed (`tests/inherited-checks.test.ts:795-815`).
12. **1.12 task/recovery recipe twin collision — Resolved by the correction record.** Current compiler comments and bounded search identify recovery recipes as excluded from task compilation targets (`src/cli/curriculum.ts:25,91`).
## Ranked workstreams
### 1. MCP output-schema conformance and catalogue proof
**Why rank 1:** This has the broadest client-facing reach and was the only archived HIGH finding. It outranks resumed accounting because a malformed result can make an entire read tool unusable immediately; it outranks Jev audit completeness because MCP affects every platform-admin read, while Jev affects calibration quality.
**Current evidence:** `atoma_costs` now declares `unparseable` and `note`, and `atoma_sentinel_health` declares `note` (`src/mcp/tools.ts:957-969,1020-1025`). SDK-facing tests exist (`tests/mcp-http.test.ts:746-758`; `tests/mcp-modern.test.ts:112-125`). The remaining gap is proof that every emitted field of every schema-bearing tool is accepted under both protocol eras.
**Affected files:** `src/mcp/tools.ts`, `src/mcp/readers.ts`, `src/mcp/http.ts`, `tests/mcp-http.test.ts`, `tests/mcp-modern.test.ts`, `src/mcp/AGENTS.md`.
**Bounded sequence:**
1. Enumerate `MCP_TOOLS` rows with `outputSchema` and map each handler to its `jsonResult` shape.
2. Add/extend fixture responses for optional, empty-store, degraded, and dependency-absent branches.
3. Run SDK validation for every schema-bearing tool in 2025 and 2026 transports; assert successful structured results and open-schema behavior.
4. Review the catalogue count and subsystem contract for drift.
**Dependencies:** Existing SDK test harness, bounded fixtures, and the MCP subsystem contract; no live server required.
**Verification/done condition:** A deterministic test calls every schema-bearing tool through both SDK clients, covers empty/degraded branches, and fails on any undeclared field or closed schema. Documentation and catalogue counts remain consistent.
**Uncertainty:** No full matrix was executed in this inspection; current evidence proves representative and enumerated schema checks, not production deployment behavior.
### 2. Resumed-session accounting and two-era retirement evidence
**Why rank 2:** It controls the safety of removing the legacy protocol era and therefore affects compatibility decisions across deployments. It ranks below schema conformance because the current source and test directly cover the reported defect, while the remaining risk is cross-process continuity. It ranks above Jev audit completeness because an incorrect retirement metric can disable a live client population, whereas Jev affects measurement rather than immediate request availability.
**Current evidence:** `countClient` exists (`src/mcp/http.ts:296-307`), resumed initialization counts a synthetic client (`:604-627`), and the restart test asserts `resumed: 1` and the client entry (`tests/mcp-http-lifetimes.test.ts:342-358`). The health contract states counters reset when the server process restarts (`src/mcp/tools.ts:1050+`).
**Affected files:** `src/mcp/http.ts`, `src/mcp/tools.ts`, `tests/mcp-http-lifetimes.test.ts`, `docs/mcp-two-eras-2026-09-30.md`.
**Bounded sequence:**
1. Define whether retirement counts unique client kinds, resumed sessions, or both.
2. Make that invariant explicit in the health payload and test fixtures.
3. Add deterministic repeated-restart and repeated-resume tests, including caller mismatch and synthetic-name bounds.
4. Add a static migration/retirement check that refuses removal while qualifying 2025 evidence remains.
**Dependencies:** The session identity/hash contract and the two-era documentation; no deployment or network test is required.
**Verification/done condition:** Tests establish counter semantics across fresh initial…
Time13 min 23 s
Cost$0.45
Finished2026-10-06