Repository navigation
[Bug] UpdateConfig does not wake sandbox watchers after an atomic policy revision commit #2517
Description
Activity
- addedstate:triage-neededOpened without agent diagnostics and needs triageOpened without agent diagnostics and needs triage
on Jul 28, 2026 - addedarea:gatewayGateway server and control-plane workGateway server and control-plane workarea:policyPolicy engine and policy lifecycle workPolicy engine and policy lifecycle workand removedstate:triage-neededOpened without agent diagnostics and needs triageOpened without agent diagnostics and needs triage
on Jul 28, 2026 📋 triage-agent
Triage Assessment
Classification: bug-confirmed
Summary
The atomic sandbox-policy update path persists a new revision and annotations but does not wake local
WatchSandbox(follow_status=true)observers. This is a confirmed gateway policy-lifecycle defect, not user error.The report's supervisor impact is overstated: sandbox supervisors poll
GetSandboxConfigon a timer and do not consumeSandboxWatchBus. The direct impact is stale CLI/SDK/TUI status streams. #2518 is the separate same-hash policy-acknowledgement defect.Investigation
In current
main(b1c7ff68),put_policy_revision_atomiccommits successfully. No notification follows; the freshly written record then takes the same-hash early return, bypassing the later notification at line 2261.The existing
update_config_same_policy_hash_with_new_provenance_creates_revisiontest confirms the exact revision/provenance transition; the focused test passes on currentmainbut does not assert watcher delivery.SandboxWatchBusdocuments that producers notify whenever persisted sandbox records change, andWatchSandboxblocks on that bus.Searches found no duplicate or merged fix. Open PR #2257 adds eventual shared-store polling and would partially mask the symptom, but it does not restore this local post-commit notification invariant and is not a duplicate.
Recommendation
Notify once immediately after the atomic retry block commits successfully and before the fallible reload/same-hash return. Do not notify for same-policy/same-provenance no-ops, retry conflicts, or failed writes. Extend the regression test to subscribe before
UpdateConfig, assert one received event, then assertEmptyto enforce exactly-once behavior.Recommended labels:
area:gateway,area:policy. Removestate:triage-neededand assign issue typeBug. Do not applystate:agent-ready; that remains a human decision.
Agent Diagnostic
create-github-issuerepository workflowUpdateConfigpath is unchangedmainatf00ad23a; other policy mutation paths notify the sandbox watch bus, but this path does notDescription
Actual behavior:
UpdateConfigcan persist a new sandbox policy revision in its atomic merge branch and return that revision successfully, but it does not callsandbox_watch_bus.notify. A watcher already subscribed for that sandbox receives no event. This differs from the non-atomic policy update and other policy mutation paths, which notify after persistence.Expected behavior: every successfully committed sandbox configuration revision that can change the settings-poll result wakes connected watchers exactly once. Conflicting retries and failed writes must not notify.
Reproduction Steps
sandbox_watch_busfor that sandbox ID.UpdateConfigwith identical policy content and changed annotations/provenance, causing the atomic merge path to persist revision 2.watch_rx.try_recv()returnsEmpty.A focused server test can reproduce the failure by extending
update_config_same_policy_hash_with_new_provenance_creates_revisionwith a watcher subscription and notification assertion.Environment
Suspected Cause
handle_update_config_innerassigns the committed annotations immediately after the atomic retry loop, but does not notify the sandbox watch bus. The later standalone policy-persistence path does notify, so the atomic branch violates the same post-commit invariant.Proposed Fix
Call
state.sandbox_watch_bus.notify(&sandbox_id)immediately after the atomic commit succeeds and before subsequent response processing. Add a regression assertion that:UpdateConfig;Logs