MessageService's TIMED_OUT_QUEUED javadoc says the message is still queued; the code 12 lines of behaviour later cancels it #513
Closed
opened 2026-09-12 05:56:51 +02:00 by ltms
·
3 comments
No Branch/Tag Specified
main
worker/fleetd-612-unita-87807e-1
worker/612-b3-mcpwirings-da2b58-3
worker/612-b2-cb185-176d3a-2
worker/612-b1-completion-457459-1
worker/612-agaps-73a926-2
worker/608-sleeps-3a64ff-3
worker/621-b4520b-1
worker/618-b83894-2
worker/fleetd-615-e05481-5
worker/lead-autocompact-5f1ab2-3
worker/fleetd-613-f85deb-3
worker/fleetd-608-flaky-nudge-test-d0c2d1-3
worker/lead-context-gauge-ad404f-1
worker/gauge-wiring-9158c1-4
worker/redeploy-slowstart-ead0e5-5
worker/charter-bytes-13668c-6
worker/rollover-outcome-291483-2
worker/589-f64303-2
worker/593-1a8025-5
worker/589-fcd2aa-1
worker/568-9fdaa2-3
worker/571-attempted-outcome-5739f7-2
worker/581-completionresolver-cas-sites-0542b7-6
worker/562-loop-health-wiring-test-99611c-5
worker/562-surface-loop-health-7df5cc-4
worker/575-waiter-cleanup-sites-62ad80-1
worker/572-answer-lock-release-46a9ae-5
worker/567-probe-channel-leak-a38fc5-6
worker/551-record-before-send-7cbf56-1
worker/561-listener-fanout-survives-a-throw-61d538-2
worker/555-redeploy-main-flow-seam-65c2f5-2
worker/556-injector-owns-registration-e027a5-1
worker/552-post-restart-mktemp-abort-bc2672-4
worker/553-onstatus-completion-leak-0da881-2
worker/550-shasum-linux-196132-1
worker/538-loop-dies-on-error-4a5eeb-6
worker/426-health-coverage-ef1fd4-4
worker/504-failed-reported-clean-3cfd66-3
worker/537-capturedlog-close-e4c437-2
worker/459-broken-link-targets-cadc17-5
worker/535-appender-leak-fe74c1-1
worker/512-part2-shutdown-detection-434701-9
worker/529-logger-level-sweep-2a5533-8
worker/528-drain-gate-call-site-5de83d-7
charter/forge-mcp-vs-token
worker/521-swap-guard-unpinned-28e931-5
worker/519-probe-test-harness-d25ab8-4
worker/525-logger-level-leak-1b4eb0-6
worker/518-fleetmcp-resolver-wiring-8ef96c-1
worker/512-drain-complete-line-7edd71-3
worker/517-abort-branch-and-jar-id-41b641-2
worker/500-9e52c9-3
worker/509-4912f4-2
worker/511-9a4b23-1
worker/493-479f45-2
worker/505-03f8b2-1
worker/492-followup-detect-unclear
worker/501-a31fa0-7
worker/498-451d1c-5
worker/494-1015ce-2
worker/492-209647-1
worker/489-001902-2
worker/480-relative-handover-path-906323-1
worker/480-b-handover-skill-45bf1f-5
worker/474-followup-source-pin-f54a55-17
worker/474-charter-check-on-reload-f54a55-17
worker/466-quarantine-repeatcount-report
worker/393-opencode-skill-seeding-71854b-13
worker/469-canonical-tool-names-2a472a-16
worker/466-quarantine-escalation-5ae9c1-15
worker/446-hot-exhausted-pattern-0af580-6
worker/464-charter-tool-name-guard-a85635-12
worker/463-listfleet-default-fails-open-f1c76c-11
worker/458-invariant-5-by-purpose-862f9a-10
worker/439-coordinator-row-gate-bc032a-8
worker/449-herdr-protocol-576015-4
worker/450-abstract-spawn-599e1c-5
worker/437-ack-refuses-177d91-1
worker/444-placement-window-feb56a-2
worker/440-helddurable-derived-d462d7-13
worker/425-rework-placement-resolve-c58ba1-9
worker/421-lead-peek-held-msgs-cdbad2-10
worker/435-fixed-policy-cap-fe11de-12
worker/422-gate-state-observability-9e79d6-11
worker/431-memberregistry-live-readers-cdbad2-10
worker/424-architect-slot-hot-038b41-7
worker/422-model-gate-spawn-c29f48-6
worker/425-default-profile-live-f55534-8
worker/415-coverage-wording-2cbf9c-5
worker/416-3ad1da-1
worker/418-588283-3
worker/deterministic-stamp-race-409-3cb7b6-10
worker/armed-reads-live-config-404-ed931f-9
worker/reply-peer-refusal-391-5a34bd-7
worker/models-allowlist-aa9e9b-3
worker/ttl-stamp-race-399-f1122f-8
worker/scrub-receipt-400-316b3e-5
worker/exhaustion-detection-395-105105-6
worker/scrub-abort-394-316b3e-5
fix/scrub-uid-abort
worker/task-scrub-517574-2
worker/t386-clock-bd5b78-4
worker/t384-scrub-813790-5
worker/t381-cc-748314-2
worker/t373-336973-2
worker/t365-3920c5-3
worker/t358-6e989b-1
worker/t355-8b321c-1
worker/fleetd-369-hermetic-git-tests-e8b19a-3
worker/fleetd-368-stale-lead-binding-f5682e-2
worker/fleetd-360-deploy-units-0d3793-1
worker/359-dead-lead-tabs-f1253b-4
worker/362-worktree-skills-c03e51-3
worker/361-coord-visibility-655144-1
362-plugin-visibility-and-drift
worker/errscan-bed2ca-2
worker/amqp-log-identity-bed2ca-2
worker/withdefaults-guard-561704
worker/sleepguard-82076d-1
worker/fd334-9ee1b6-5
worker/fd348-f1ab27-4
worker/fd335-a71c35-1
worker/fd342-174a17-2
worker/fd345-490d0f-3
worker/fleetd-337-5ec7d4-21
worker/fleetd-341-af5a6b-24
worker/fleetd-339-5ca0a2-23
worker/fleetd-338-83a4a1-22
worker/fleetd-333-281f46-18
worker/fleetd-329-11bdbb-16
worker/fleetd-330-2770fb-17
worker/fix-326-50506e-15
worker/fix-324-3e9bbf-14
worker/fix-323-b8287d-13
worker/fix-316b-bd0860-11
worker/fix-318-76ca36-9
worker/fix-317-486aec-8
worker/fix-315-ce47c5-6
worker/fix-307-275890-6
worker/fix-308-b4f664-7
worker/fix-309-ec3939-8
worker/fix-310-7a3974-9
worker/fix-302-52ad0e-9
worker/fix-298-ce1acb-8
worker/fix-297-66bd11-7
worker/fix-296-104622-6
worker/fix-293-bare-closetab-eb22b5-3
worker/fix-280-gone-ask-lapse-bca98e-2
worker/fix-290-reapidle-guard-coverage-9b0dd1-1
worker/fix-285-trust-seed-8f3565-10
worker/fix-284-backend-error-seat-85912c-11
worker/fix-282-chained-ask-e6d0bb-8
worker/fix-283-teardown-leaks-f40dfa-9
worker/fix-281-pin-handler-actions-4921ac-7
worker/audit-rendezvous-lifecycle-d072ae-2
worker/audit-health-placement-1a2476-6
worker/audit-teardown-exits-e207a5-3
worker/audit-launcher-asymmetry-27e370-4
worker/audit-rest-authz-6ca53c-5
worker/investigate-275-abandon-asking-fdef52-8
worker/fix-274-worktree-leak-b0095d-7
worker/fix-273-exhausted-pattern-9665b5-6
worker/fleetd-267-model-check-bd8068-1
worker/fleetd-131-archunit-18b834-7
worker/fleetd-266-sshagent-rename-a014ff-6
worker/fleetd-184-uid-claim-8e1f31-4
worker/fleetd-184-warn-b381ee-10
worker/fleetd-184-docs-be1d12-9
worker/fleetd-257-9bf010-7
worker/fleetd-103-23a113-6
worker/fleetd-247-342356-5
worker/fleetd-116-04dea8-4
worker/fleetd-252-a830e0-3
worker/fleetd-111-7e8673-9
worker/fleetd-155c-f8ef4b-8
worker/fleetd-176-b928ca-3
worker/fleetd-249-7a7878-2
worker/cb248-composition-root-b-9acdf7-15
worker/cb148-envrc-default-fa6c82-12
worker/cb201-unit5-wiring-6c12e6-8
worker/cb241-fallback-echo-1175e9-11
worker/cb149-trust-dialog-2392a5-9
worker/cb134-148-overlay-visible-c9b986-10
worker/cb234-session-id-keyed-04e1fc-1
worker/cb201-unit3-nudge-abdf5c-6
worker/cb201-unit2-policy-c1102c-5
worker/cb201-unit4-outcome-a13bfa-7
worker/cb201-unit1-classifier-91b9b1-4
worker/cb201-227-refine-831980-3
worker/cb175-model-readback-0f085f-1
worker/cb222-charter-tmpdir-17f013-1
worker/cb226-architect-slot-race-cd3aa8-3
worker/cb224-worktree-root-group-024523-2
worker/cb-123-role-demotion-c600f7-2
worker/cb-219-opencode-roots-1f677e-1
worker/cb214-claude-session-id-b9eab4-4
worker/cb213-zdotdir-wrong-process-dd6de4-3
worker/cb211-exhaustion-classification-9546e0-2
worker/cb137-ambiguous-task-4df3d8-4
worker/cb209-agentsessionid-4dfdb6-2
worker/cb185-hostenvnames-2692b5-3
worker/cb206-opencode-sqlite-128718-2
worker/cb185-worktree-group-fc0c99-1
worker/cb-137-ask-ticket-e7760c-2
worker/cb-172-broker-uri-d36ae4-4
worker/cb-175-model-readback-76ead6-3
worker/cb-161-pane-ancestry-293510-1
worker/cb-164-rebase-885863-8
worker/cb-164-empty-scrape-false-success-1a80af-3
fix/cb-197-ticket-ttl-from-completion
worker/cb-189-remote-url-coverage-4692f3-1
worker/cb-185-blockers-027756-4
worker/cb-192-gap-log-11b631-2
worker/cb-633-fix-5f4396-3
worker/cb185-router-d6436d-3
worker/cb185-router-routing-gaps-9e9d33-3
worker/cb185-paneids-992586-2
worker/cb-633-allow-list-union-ed374b-1
worker/cb-157-credential-in-remote-url-496e44-2
worker/cb-641-health-herdr-evidence-8f1f54-6
worker/cb-640-health-msg-evidence-99c9cd-1
worker/cb-642-fleets-status-skill-bbbc40-5
cb-634-ide-mcp
worker/lead-comms-wiring-c014b9-7
worker/lead-mailbox-c19577-6
worker/autocompact-window-82bc2f-5
worker/cb-634-probe-18056f-4
worker/cb635-broker-urienv
worker/cb-632-config-retry-8e0efa-7
lead/cb-622e-claude-md
lead/cb-622-followup
worker/cb-622a-165dff-1
lead/cb-622d-opencode-mount
worker/cb-622b-717c67-2
worker/cb-622c-ab7759-3
worker/cb-617b2-20ca4b-3
worker/cb-617a-5c2f4a-1
worker/cb596-4e49ef-3
worker/cb586-10500c-1
worker/cb-606-b9343a-25
worker/cb604-1445f8-24
worker/cb582-477374-21
worker/cb584-8c2281-22
worker/cb600-e6b9a9-20
worker/cb602-ce257f-19
worker/cb601-b42837-18
worker/cb598-6c7ba7-17
worker/cb599-740fe4-16
worker/cb597-282224-15
worker/cb590fix-185e9a-10
worker/cb528-recovery-race
worker/cb594-96bead-8
worker/cb590-916766-2
worker/cb527-997d99-3
worker/cb592-env-leak-3cbf9c-1
worker/cb588-async-ticket-nudge-3218f7-5
worker/cb578b-9dcb13-6
worker/cb581-d24826-5
worker/m2-u5-ef8c42-15
worker/cb578a-516499-2
worker/cb576-01a04b-17
worker/cb579-lead-tab-acba06-20
worker/cb580-terminal-health-ed6058-21
worker/cb577-f36fdc-18
worker/cb573b-3db06f-16
worker/cb568c-f36fdc-18
worker/cb568-drop-cause-c3ac1c
worker/cb575-cancelled-notification-c3ac1c
worker/m4-sol-a2cbec-3
worker/cb574-async-ask-c3ac1c
worker/cb573-health-model-8ca857-14
worker/cb572-unknown-target-7f2e35-13
worker/u4-700706-9
worker/u3-b9fcb6-6
worker/u2-ef5b68-4
worker/u1-469dce-1-clean
worker/u1-469dce-1
worker/cb-564-health-events-70cf7e-2
worker/cb-565-recycle-drops-role-98e58f-3
worker/cb-563-missing-reply-df2866-1
worker/cb-562-readiness-gate-silent-6c23c9-3
worker/cb-560-architect-presence-da8155-1
worker/cb-561-architect-silent-off-a71cab-2
worker/cb-548-bind-architect-slot-fe1b8c-1
worker/parity-overlay-settings-5fb711-1
secrets-central-store
cb-559-hot-key-correction
cb-557-fleet-role-pools
worker/cb-553-maxload-explicit-spawn-305ee3-6
worker/cb-551-idle-lead-heartbeat-f1633c-1
worker/cb-544-drain-preserves-worktree-925fad-3
worker/cb-552-docs-sync-1cb9cf-4
worker/cb-548-rendezvous-guard-rebased
worker/cb-548-rendezvous-guard-116b53-10
worker/cb-548-authz-v2-586df6-8
worker/cb-548-authz-264363-5
salvage/cb-528b-codex-home
salvage/cb-528a-codex-launcher
CB-518-primary-flow
feature/peer-launcher-spi
cb-103-injector
v1.1.0
v1.0.0
Labels
Clear labels
blocked
needs-live-proof
ready-to-delegate
silent-default
Cannot start until something else lands. The body says what.
Merged and green, but never shown working on the running daemon. Not the same as done.
Scope, files and acceptance criteria are written. A worker can be briefed from the body alone.
A feature that compiles, passes tests, and ships turned off. Nine recurrences and counting.
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: fleet/fleetd#513
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
A documentation defect, not a behaviour defect. I am filing it because it cost me a wrong conclusion today and would have cost a ticket, and because the wrong text is the one a reader reaches first.
Two statements in one file, and they disagree
fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java:302— javadoc on thequeuedDeliveriesfield:MessageService.java:395— javadoc onhasQueuedDelivery:MessageService.java:952-956— the code that actually runs on that timeout:The inline comment is the correct one.
Injector.cancelatinject/Injector.java:270-284does exactly what it says:t.queue.remove(p). The pending is gone. It is also tested —InjectorTest.java:181assertsCancellation.CANCELLED, and:196assertsDELIVEREDfor the race where delivery wins.So the two javadoc sentences describe behaviour that CB-640 removed. They are not vague, they are wrong in the specific direction that matters.
Why this is worth a ticket rather than a quiet edit
The behaviour they describe used to be real. I hit it on 2026-08-16: a ticket reported
failed/no reply — timed_out_queued, the member was alive and had committed 74 seconds earlier, and the queued brief was delivered later and restarted the same ticket on top of finished work.Today I was about to file that as a live defect — a timed-out ticket not cancelling its queued delivery, with a write-after-expiry consequence, on a peer lead's encouragement. I read the code first and found the opposite. What made me confident enough to nearly skip that step was this javadoc: it agrees with my memory of the old behaviour, so I had two sources saying the same thing and no reason to look further.
That is the shape: a stale doc is most dangerous when it agrees with a stale memory, because the reader gets a false confirmation instead of a contradiction. One of the two would have made me check. Two agreeing made me stop.
It is also the same family as #500 and #511 — a wrong stated fact stopping the next reader looking further — but at the doc layer, where nothing can fail and no test can catch it.
The fix
Rewrite both javadoc blocks to say what CB-640 actually left behind. The correct meaning of
TIMED_OUT_QUEUEDis now:Say plainly that
queuedDeliveriesrecords a fact about a message that is gone, not a pointer to something pending. The field name is now misleading too — "queued" is precisely what it is not — so consider renaming it in the same change. Judge that yourself; the rename is optional and the text is not.Keep and keep clear the distinction that is still true and still valuable:
TIMED_OUT_WORKING— delivered; the member has it and only the reply is outstanding.TIMED_OUT_QUEUED— never delivered, and now cancelled; the member has not seen a word of it.Related, and deliberately not in scope
The phase word
failedfor a message that was never delivered is a separate readability problem —failedthere does not mean the work failed. Not filing it here; this ticket is only the contradiction.Acceptance
:302and:395describe cancellation, not queueing.grep -n 'still sitting in the injector' fleetd/src/main/javareturns nothing.mvn -f fleetd/pom.xml clean installstill passes — report the Tests run / Failures / Errors / Skipped line verbatim, and do not pipe it, because a pipe hides a failure behind a zero exit.queuedDeliveries, the rename must be complete: no caller, test, or comment left using the old name.Re-scoping this: it is not a tidy-up, and I have the evidence of the harm
I filed this as a stale-comment cleanup. It then caused a concrete, measurable error — mine — within a day, so the severity line was wrong and I am correcting it.
The contradiction, measured on
mainata6415f3The same file makes two opposite claims about what
TIMED_OUT_QUEUEDmeans.MessageService.java:306(thequeuedDeliveriesfield javadoc) and:395-397(hasQueuedDelivery's javadoc):MessageService.java:954-957, the inline comment in thecatch (TimeoutException)branch that actually produces the outcome:The inline comment is the correct one.
Injector.cancel(Injector.java:270) removes the entry:So on the ordinary path a timed-out queued send is cancelled and cannot be delivered later. The two javadocs describe behaviour from before CB-640's cancel was added.
What the stale javadoc actually cost
I was about to file a ticket titled, roughly, "a timed-out ticket does not cancel its queued delivery — a dead brief is delivered late and its side effects land twice." I had a severity argument ready: a brief that edits files or opens a PR gets applied a second time against a tree it was not written for, after the caller has been told the ticket is terminal.
That defect does not exist. I derived it from this javadoc plus a memory of my own that was formed from the same older code. The fleet01 lead, reasoning from my description, agreed with it — and then correctly flagged their own agreement as derived rather than measured. I have since retracted the whole thing to them.
Two agreeing sources that are stale descendants of the same code cannot disagree with each other. They can only be stale together, and that feels exactly like corroboration. That is what makes this class of stale comment more expensive than it looks: it does not merely fail to inform, it manufactures false confirmation for a reader who already half-remembers the old behaviour.
So the fix is not just "correct the wording"
:302/:306and:395-397to say what the code does: the Pending is cancelled at timeout and cannot arrive later;TIMED_OUT_QUEUEDrecords that delivery never happened, as a fact for fleet health, not that a delivery is still pending.TIMED_OUT_QUEUEDreads as "it is queued". It means "it was still queued when we gave up, and we then cancelled it." Renaming the enum constant is a wider change (it reachesFleetApp.java:645, which maps it to the REST string"queued", andFleetMcp.java:806); do not do it in this ticket. Do add one line at the declaration,MessageService.java:96, so the name is read correctly at the point it is defined."queued"too (FleetApp.java:645). That is an operator-visible word for a message that has been cancelled. Flag it; do not change it here — it is an API string and needs its own decision.One thing I am explicitly NOT claiming
There is a narrow window in
cancel: ifp.state == QUEUEDbutt.queue.remove(p)returnsfalse, the method returnscancellationOf(p)→NOT_DELIVERED, so the caller reportsTIMED_OUT_QUEUEDwhile this call did not remove the Pending. Whether that state is reachable, and whether the delivery loop then completes the delivery, I have not measured. I am not filing it and nobody should treat it as a known defect. It is recorded here only so the next reader does not think the audit was exhaustive.Relatedly, my original observation — a stale brief restarting a member that had already finished — was real, but my explanation of it was wrong. The pane scrape showed my brief in the pane, which means it had been typed in, i.e. delivered. That is the
TIMED_OUT_WORKINGpath, not a queue entry firing late. The symptom stands; the mechanism I attributed it to does not.Acceptance
:954-957. Quote both before and after.TIMED_OUT_QUEUEDdeclaration (:96) explaining what the name does and does not mean.Rework needed on PR #564 — the new javadoc replaces a wrong claim with a narrower wrong claim
I verified the build on a tree merged with
origin/main. That part is clean:worker/513-timed-out-queued-javadoc-da3628-3intoorigin/main(4f9aba4) is a fast-forward, mergedHEAD=ed28b51mvn install→ exit 0{@link Injector#cancel}links resolve. Positive control:mvn javadoc:javadocreported 8 complaints insideMessageService.java(at:113,:144,:216,:277— all pre-existing "no @param"), so the tool really did analyse that file and would have reported an unresolved reference. None of its complaints falls on a changed line. There is nomaven-javadoc-plugininfleetd/pom.xml, so javadoc is not a build gate here.The problem is the content of the new comments.
TIMED_OUT_QUEUEDhas four routes, not oneThe outcome is returned at
MessageService.java:957-958whenwasDeliveredis false. That needsinjector.cancel(delivery)to return something other thanDELIVERED— so eitherCANCELLEDorNOT_DELIVERED.cancelreturnsPendinggot therecancelcancel anything?CANCELLED(Injector.java:284)QUEUED, removed fromt.queueNOT_DELIVERED(Injector.java:289)Injector.java:400—agentsFor(target).send(target, p.text())threwNOT_DELIVEREDInjector.java:419— readiness grace expired (READINESS_GRACE_POLLS), never attemptedNOT_DELIVEREDInjector.java:691—drop(target, cause), the target is gone, queue clearedOn routes 2, 3 and 4
cancel()cancels nothing. It reads a state another code path already set and reports it (cancellationOf,Injector.java:288-290).So two sentences are wrong, in three places
"
sendcancels the pending entry (Injector#cancel) before returning this outcome" — true on route 1 only. It names the mechanism of the case that motivated the ticket and states it as the invariant."the target never saw a word of it" — the code does not establish this on route 2.
AgentControl.sendcalls herdragent.prompt, which pastes the text into a live pane and submits it in one call. If that call throws after herdr has pasted, characters are already in the pane. I have not reproduced a partial paste, and I am not claiming it happens — I am saying the comment asserts something the code does not support, and it asserts it to an operator who would then not go and look at the pane.Affected blocks on
ed28b51: theTIMED_OUT_QUEUEDenum constant (:93-99),queuedDeliveries(:307-314),hasQueuedDelivery(:400-408), andhasOrphanedDelegation(:426-430, where "no record of a cancelled, undelivered send" carries the milder form of the same over-claim).What is actually true on all four routes
That is what the javadoc should say. The mechanism sentence should either be dropped or list the routes. Route 2 needs its own qualifier: delivery was attempted and the herdr call failed, so nothing here proves the pane stayed clean.
Also fix the inline comment that seeded this
MessageService.java:953-954:"it cannot arrive later" is correct. "The exact
Pendingwas cancelled" is the same route-1-only claim, and it is pre-existing — it is very likely where the wording in the new javadoc came from. Correct it in the same pass.Acceptance criteria for the rework
cancelcancelled the entry, unless it is qualified to the case wherecancelreturnsCANCELLED.MessageService.java:953-954too.mvn installand report the exit code next to the test count, with the count taken from the surefire reports rather than a pipe.Why this is worth a second pass rather than a merge
This ticket exists because a comment stated one path's behaviour as the invariant, and a reader acted on it. The fix does the same thing again, one path further along. The general form is worth keeping in mind beyond this diff: we write a rule down at the moment an instance bites, so the instance's incidental details get recorded at full confidence. The check that catches it is to ask what case makes this exact wording give the wrong answer.
Credit where due: the diff is still a real improvement. The old text told an operator a message was coming that was never coming — wrong in the dangerous direction. This is wrong in a narrower one.
Merged as
f4f5f31PR #564 merged, branch deleted. Verified on a tree merged with
origin/mainbefore the merge, not on the branch alone.The rework answers all five criteria
cancelcancelled the entry"Injector.Cancellation#CANCELLED, withNOT_DELIVEREDnamed as the other caseCANCELLEDAgentControl#send) threw" / "a failed delivery attempt can leave a partial paste behind"MessageService.java:953-954My own verification
origin/main(4f9aba4) is a fast-forward tocb64bc8mvn install→ exit 0,BUILD SUCCESSsurefire-reports/*.txtfilesTIMED_OUT_QUEUED→ 5 as the positive control.the target never saw a word of it→ 0 andThe exact Pending was cancelled→ 0Injector.Cancellation#CANCELLED,Injector.Cancellation#NOT_DELIVERED,dev.ltms.fleet.herdr.AgentControl#send): no unresolved reference. Positive control: javadoc analysedMessageService.javaand emitted its 8 pre-existingno @param/no main descriptioncomplaints, with line numbers shifted by exactly the +6 lines the diff adds above them. The 6unknown tagerrors in the log are all insession/Worktrees.java, a file this diff does not touch.Two notes worth keeping
The worker flagged the one check it could not complete rather than claiming it — it had not re-run the javadoc control on
cb64bc8and said so. That is the right call and it is why the gap got closed instead of assumed.On my own side, a grep of mine returned a false zero while confirming the rework: the string I searched for spans a javadoc line wrap, and
grepis line-based, so it could never match. Caught by a positive control. The general form is already in my notes — a multi-line string cannot be found by a line-oriented search — and it fired again here one turn after I wrote it down.Why this needed two passes
The first pass replaced a wrong claim with a narrower wrong claim, which is the same defect this ticket was filed to fix, one path further along. The cause is worth naming, and it came from the fleet01 lead:
The check that catches it is mechanical rather than creative: take the originating instance and invert one feature at a time. Here the originating instance was "the send timed out and we cancelled it in time". Inverting when the fate was decided — before the call instead of by it — produces the other three routes immediately.
Closing.