Private run terminal metadata
2026-09-15 — staging result and production stop gate
API586 promotes the
reviewed staging candidate, preserving Notes and ordinary run recovery. The
first corrected-source timeout case still reported cancelled/-3; that failed
receipt is retained. After the prior API process actually stopped, a new owned
60-second private run reported timed_out/-2 with input cleanup. Old-writer
attribution remains a hypothesis, not a proven cause of the earlier failure.
Acceptance now requires retired Main containers to have stopped before the next
run; sole COMPLETED service status is insufficient. Production task 122 passed workflow/schema checks and prior task 121 process
termination was verified before production metadata-tree acceptance. That tree
result does not extend the staged private-run timeout proof to production, where
private-run activation and its acceptance remain separate.
Staging chronology and source evidence.
2026-09-15 — original source fix (historical preparation)
Tracking: Vault #241, master #247.
Owned hosted staging acceptance exposed successful runs with missing startedAt, and an actually running 60-second timeout reported as owner cancellation. Historical receipts remain unchanged; these observations do not establish acceptance of this fix.
Reconciliation now copies the control plane's valid started_at once. This timestamp records worker claim/setup start, not user-process spawn. Missing or malformed values remain absent. completedAt remains the API reconciliation observation time.
An optional, internal privateCancelCause records the first committed owner or deadline cancellation intent. Competing intents cannot overwrite it. A confirmed cancelled control-plane result becomes timed_out with exit code -2 only when that first cause was the deadline. Success and genuine failure remain their actual outcomes. A lost cancellation response remains nonterminal until supported reconciliation confirms an outcome; legacy cancellation without a cause is not retrospectively labelled a deadline. The Prisma field is additive and requires no index DDL.
deliveryState continues to describe the authorization grant. permit_reserved is not a running-process status, and cleaned input mappings do not change it into a completed grant. Use run status and individual input states together.
Validation covers real Mongo owner/deadline interleaving, lost cancellation recovery, legacy records, malformed start metadata, and preservation of success/cleanup failure. At initial preparation this change was not deployed. The staged result and production gate above supersede that deployment status, without changing the historical failure receipts.