Skip to content
Troubleshooting

Troubleshooting

Each entry quotes the message exactly as the code emits it (%s, %v and %d are filled in at run time), then gives the cause and the fix.

Building

replacement directory ../security does not exist

Cause: grpc/go.mod resolves inference, mesh, security and store from sibling checkouts next to your core checkout, and they are not there. Inside a git worktree, the relative path resolves from the worktree, not from the workspace.

Fix: check out the siblings next to core, or symlink them beside the worktree with relative targets. For the CLI alone, GOFLAGS=-mod=vendor go build ./cmd/core builds from the committed grpc/vendor/.

A missing symbol from a sibling (for example undefined: …)

Cause: usually a sibling checkout on another session’s branch, not your code.

Fix: do not switch the sibling. Add a detached worktree of its default branch and build with a GOWORK file kept outside the repo.

core dev

mistralrs-server binary or model not found under %s/grpc/agents — apps spawn their own if configured.

Cause: there is no shared inference binary or GGUF weights under the PULSE repo.

Fix: place the mistralrs-server binary and weights under ../pulse/grpc/agents, or accept that there is no local model.

[face] backend build failed — see .dev/face-build.log, or the log is empty

Cause: core dev reads the environment variables FACE_REPO and PULSE_REPO (default ../face, ../pulse), not the --face-repo flag. A wrong path fails before the compiler writes anything.

Fix: export FACE_REPO=/path/to/face (and PULSE_REPO), then core dev up face.

%s was not ready within %s (still running, pid %d — see %s) / %s exited before it was ready (%s)

Cause: a supervised child failed its readiness check (supervisor.go).

Fix: read the log file the message names under .dev/, then run core dev down before retrying.

CORE dev is NOT up: %d process(es) above died during bring-up. Fix those first; `core dev down` to clean up.

Fix: scroll up for the ❌ lines, fix those, and run core dev down.

STALE BINARY: the rebuild did not land (%v).

Cause: the devgateway was rebuilt but the new binary lacks the :443 capability, so the previous build keeps running.

Fix: core dev hosts rebuilds it and re-grants the capability. On failure it reports could not re-grant cap_net_bind_service to the new binary.

core session

no inference endpoint found — start one (or pass --inference-url / CORE_SESSION_INFERENCE_URL); probed …

Cause: nothing answered /v1/models on the local candidates.

Fix: start the dev stack or a model, or pass --inference-url.

inference endpoint %s not reachable: %v

Fix: check the URL you passed. The session expects an OpenAI-compatible endpoint.

--repo must be owner/name, got %q / one of --issue or --prompt is required

Fix: pass --repo org/name and a goal.

expected exactly one App installation, found %d — set CORE_GH_APP_INSTALLATION_ID

Cause: App-token mode (CORE_GH_APP_ID + key set) with an App installed in several places.

Fix: set CORE_GH_APP_INSTALLATION_ID, or unset the App variables to use your core auth login token.

declined: the human operator did not approve this command / declined: no confirmation channel available for this command

Cause: the approval gate. The second form means there is no terminal (for example under Actions), so every gated call is declined.

Fix: answer y at the prompt. For unattended runs, use --verify build or --verify test to admit build and test commands.

blocked: command matches a disallowed pattern (%s)

Cause: the run_shell denylist (for example sudo, curl … | sh, .git/config).

Fix: none; this is intended. The model sees the refusal and adapts.

path %q escapes the workspace / path %q is inside .git, which tools may not touch

Cause: workspace confinement in tools.go. This is intended.

verification tier %q needs the sandbox, and CORE_SESSION_SANDBOX=off turns it off — model-written tests are never run unsandboxed; use --verify build, or drop the opt-out

Fix: use --verify build, or unset CORE_SESSION_SANDBOX on a machine where bwrap works.

unknown verification policy %q — use off, build, or test

Fix: correct --verify or CORE_SESSION_VERIFY.

turn %d: %d consecutive malformed replies, giving up

Cause: the model returned three unparseable replies in a row. That is usually the wrong tier or an overloaded plane.

Fix: check --model (default coder), then core session resume <id>.

refusing to navigate to non-local host %q …

Fix: pass --browser-allow-remote if you really mean it.

session %s: no console configured — report kept locally (set console_url in ~/.core.yaml, then `core session sync`)

Cause: --console-url has no default. Fix: set it and run core session sync.

session %s: report not delivered (kept pending for `core session sync`): %v

When %v is console 403: … with the body token does not carry the App's rights for org "…":

Cause: the console accepts reports only from tokens carrying the GitHub App’s rights for its org.

Fix: sign in with core auth login through the same App, then run core session sync.

core session serve

MessageFix
no repositories allowed — pass --repo for each repo a queued instruction may touchpass --repo at least once; there is no wildcard
no console URL — set --console-url, CORE_CONSOLE_URL, or console_url in ~/.core.yamlset the console URL
session commands require a personal GitHub App token (`core auth login`) for org %q — installation tokens are not acceptedrun core auth login; CI tokens cannot queue or claim
could not resolve the GitHub login for this token; refusing to queue or claim a command without a verified identityre-run core auth login --force
this console does not know its GitHub org: …the console has no readable App installation and CORE_GITHUB_ORG is unset; fix it on the console side
queue is full — drain it before adding more (HTTP 429)let serve claim or finish the queued items first

Agents

The review, triage or self-heal comment says the model was unreachable

For example: the sovereign coder model was unreachable at …, or the coder model answered, but not in the review shape, so nothing from its answer is shown here.

Cause: a runtime model failure. It is posted as a degraded notice so a broken plane cannot look like “nothing found”.

Fix: check the inference plane and the model router. Then re-comment @core_check or wait for the next sweep.

reviewer: INFERENCE_URL not set — … (same shape for every agent)

Cause: the workflow did not set the endpoint. This is a configuration failure, and it is loud by design.

The curator runs green every day but publishes nothing

Cause: CURATOR_CRON_DRY_RUN is unset, which means dry.

Fix: set the Actions variable to the literal false.

### 🔒 Forger is DISARMED in the run summary

Fix: set CORE_FORGE_ENABLED=true, or arm forger in the console’s agent controls.

A PR keeps its review:findings-open label

The label clears only on a clean review. Check for a pending draft from fixer/* or core-resolve/*, since the resolver does not re-attempt a PR with one. Otherwise wait for the 17 */3 * * * resolver sweep. See Review Pipeline.

A dispatched review never finishes; core/review stays pending

A pending status older than 90 minutes is re-dispatched by core-review-sweep.yml. Nobody needs to comment.

Console

PUT /api/agent-schedules/{name} returns nothing to change: send at least one of enabled, dryRun, schedule

Fix: include at least one of those fields. A 404 reading no scheduled agent named … means the name is not a scheduled agent.

GET /api/audit/verify answers 503

There is no persisted chain to check. The audit log could not be attached, and the chain is stderr-only for this process.

The session-admins list cannot be changed

PUT /api/session-admins refuses an empty list and one that removes the caller with nobody left. If it fails with not changed: the audit record could not be made durable first: …, the audit log is not writable.