Follow-up to merged PR #12955, review suggestion R3-5. This records a later unresolved Suggestion for post-merge follow-up.
Problem
After submission may have happened, the coordinator intentionally retains recovery retries. A later permanent Workspace refusal can keep that path retrying without a retry horizon or a specific externally visible stuck reason. The linked review identifies a bound-Turn scenario after grant revocation or draining. The generic post-submission retry behavior predates the new exception arm; the issue is how to represent and reconcile this now-reachable state safely.
Requested change
Define the supported recovery/blocked-state policy and its observable signal for permanent authority loss after submission may have been admitted. Establish what authoritative evidence can distinguish not-admitted work from an unknown admitted outcome. Choose a safe reconciliation or visible blocked state before implementing any terminal behavior; document the decision in both design languages.
Acceptance criteria
- Tests cover a permanent refusal during recovery after possible submission, with stable prompt/execution identity and no duplicate effects.
- A genuinely unknown or admitted submission is not failed or replayed merely because authority is currently unavailable, a retry count is high, or a local event watermark is absent.
- Any terminal transition requires affirmative authoritative evidence that it is safe; otherwise expose/document the selected recovery-blocked policy and expected retry/operator behavior.
- The existing lost-submit-response regression remains valid. This issue does not prescribe the review comment's example missing-watermark shortcut.
Context
Source at merged main a63157304a: relevant code/documentation. Measurements and mutation results in the linked review are the reviewer's prior evidence, not experiments rerun while filing this issue.
中文摘要:明确“可能已提交后又永久失权”的可观察恢复状态及处理策略;保留不确定提交的安全性,不能仅凭重试次数或缺失本地水位就终止或重放。
Follow-up to merged PR #12955, review suggestion R3-5. This records a later unresolved Suggestion for post-merge follow-up.
Problem
After submission may have happened, the coordinator intentionally retains recovery retries. A later permanent Workspace refusal can keep that path retrying without a retry horizon or a specific externally visible stuck reason. The linked review identifies a bound-Turn scenario after grant revocation or draining. The generic post-submission retry behavior predates the new exception arm; the issue is how to represent and reconcile this now-reachable state safely.
Requested change
Define the supported recovery/blocked-state policy and its observable signal for permanent authority loss after submission may have been admitted. Establish what authoritative evidence can distinguish not-admitted work from an unknown admitted outcome. Choose a safe reconciliation or visible blocked state before implementing any terminal behavior; document the decision in both design languages.
Acceptance criteria
Context
Source at merged main
a63157304a: relevant code/documentation. Measurements and mutation results in the linked review are the reviewer's prior evidence, not experiments rerun while filing this issue.中文摘要:明确“可能已提交后又永久失权”的可观察恢复状态及处理策略;保留不确定提交的安全性,不能仅凭重试次数或缺失本地水位就终止或重放。