Pre-existing issues flagged by the QA panel on #3939 (not introduced there):
reconcile_interrupted leaves delegation ledger edges unsettled — background/store.py (~437) marks jobs interrupted on process restart without going through mark_complete, so the delegation ledger (STATE.ledger_store) keeps open edges for jobs that will never finish (org chart / delegation views show them as running forever). Settle the ledger edge when reconciling.
- Scheduler
add_job/update_job can raise non-ValueError for malformed cron — scheduler/interface.py (~94) documents ValueError for bad schedules; some malformed cron strings raise other exceptions from the cron parser, which callers (tools, REST) don't catch → 500 / tool crash. Normalise to ValueError with a clear message; test a few malformed inputs.
- Watch
clear() vs evaluate() race can resurrect a cleared watch — graph/watches/controller.py (~69): clear() pops the per-watch lock without acquiring it, so an evaluate() that already read the watch can write it back after it was cleared. Take the lock in clear() (or tombstone) and test the interleaving.
Pre-existing issues flagged by the QA panel on #3939 (not introduced there):
reconcile_interruptedleaves delegation ledger edges unsettled —background/store.py(~437) marks jobs interrupted on process restart without going throughmark_complete, so the delegation ledger (STATE.ledger_store) keeps open edges for jobs that will never finish (org chart / delegation views show them as running forever). Settle the ledger edge when reconciling.add_job/update_jobcan raise non-ValueErrorfor malformed cron —scheduler/interface.py(~94) documentsValueErrorfor bad schedules; some malformed cron strings raise other exceptions from the cron parser, which callers (tools, REST) don't catch → 500 / tool crash. Normalise toValueErrorwith a clear message; test a few malformed inputs.clear()vsevaluate()race can resurrect a cleared watch —graph/watches/controller.py(~69):clear()pops the per-watch lock without acquiring it, so anevaluate()that already read the watch can write it back after it was cleared. Take the lock inclear()(or tombstone) and test the interleaving.