Destination
A release-ready codebase with no unexplained errors in the riskoff PC logs: every ERROR/WARN class diagnosed and fixed-or-accepted, verified by a clean production run. The cron→report pipeline (cron run → Telegram report) works end-to-end with zero silent drops.
Notes
- Scope: cron→delivery→report pipeline + prefilter + claude_health + the stderr-drain noise (both worker and cron copies). Provider composition and other subsystems are out of scope.
- Repo conventions: AGENTS.md (Rust standards, verification cadence, architecture split). Plan first; do not fix until tickets resolve and the approach is proven empirically.
- Skills per ticket: grilling + domain-modeling for decisions; research for the shared
wait_with_output hang; prototype for the live probe.
- Log source:
~/.right/logs/riskoff.log.2026-08-*, PC logs via ~/.right/run/state.json + PC API, aggregator log right-mcp-server.
Decisions so far
Not yet specified
All execution tickets have landed (#183–#187, #189, #190–#194; #189/#191 closed). The frontier is the release gate itself: run the 24h production soak and curate the error allowlist per #188.
Out of scope
- Provider composition/credential subsystem (
right_openshell::providers, dashboard) — separate ownership.
- Historical
ssrf_denied network-policy errors — pre-fix era, not reproducing.
- Telegram API
delete_my_commands channel rejection — accepted noise.
- Historical delivery exit-1 fast-fail (auth/ssrf, SSH era) — distinct root cause, gone since microsandbox cutover.
Destination
A release-ready codebase with no unexplained errors in the riskoff PC logs: every ERROR/WARN class diagnosed and fixed-or-accepted, verified by a clean production run. The cron→report pipeline (cron run → Telegram report) works end-to-end with zero silent drops.
Notes
wait_with_outputhang; prototype for the live probe.~/.right/logs/riskoff.log.2026-08-*, PC logs via~/.right/run/state.json+ PC API, aggregator logright-mcp-server.Decisions so far
wait_with_output; fix: break-on-result + kill.ExecEvent::Exitednever fires; break-on-result + kill at async_delivery.rs:1145 and learning_prefilter.rs:559. Ready to implement.ClaudeHealth→McpInitHealth, logsclaude_health:→right_mcp_init:; probe stderr piped + bounded 2 KiB tail excerpt in failure error alongside exit code; still non-billable.skip_reflection_decision; 529/429/5xx/turn-limit classified results skip the futile--resumeturn and report the classifier's user message; unclassifiable failures still reflect.mcp__right__send_message(correctly disallowed) and leaks a "Delivery note" into user-facing content. Blocked by Fix delivery and prefilter json-mode hang (break-on-result + kill) #189.Not yet specified
All execution tickets have landed (#183–#187, #189, #190–#194; #189/#191 closed). The frontier is the release gate itself: run the 24h production soak and curate the error allowlist per #188.
Out of scope
right_openshell::providers, dashboard) — separate ownership.ssrf_deniednetwork-policy errors — pre-fix era, not reproducing.delete_my_commandschannel rejection — accepted noise.