Troubleshooting
Each entry quotes the message exactly as the code emits it (%s, %v and %d are filled in at run time), then gives the cause and the fix.
Building
replacement directory ../security does not exist
Cause: grpc/go.mod resolves inference, mesh, security and store from sibling checkouts next to your core checkout, and they are not there. Inside a git worktree, the relative path resolves from the worktree, not from the workspace.
Fix: check out the siblings next to core, or symlink them beside the worktree with relative targets. For the CLI alone, GOFLAGS=-mod=vendor go build ./cmd/core builds from the committed grpc/vendor/.
A missing symbol from a sibling (for example undefined: …)
Cause: usually a sibling checkout on another session’s branch, not your code.
Fix: do not switch the sibling. Add a detached worktree of its default branch and build with a GOWORK file kept outside the repo.
core dev
mistralrs-server binary or model not found under %s/grpc/agents — apps spawn their own if configured.
Cause: there is no shared inference binary or GGUF weights under the PULSE repo.
Fix: place the mistralrs-server binary and weights under ../pulse/grpc/agents, or accept that there is no local model.
[face] backend build failed — see .dev/face-build.log, or the log is empty
Cause: core dev reads the environment variables FACE_REPO and PULSE_REPO (default ../face, ../pulse), not the --face-repo flag. A wrong path fails before the compiler writes anything.
Fix: export FACE_REPO=/path/to/face (and PULSE_REPO), then core dev up face.
%s was not ready within %s (still running, pid %d — see %s) / %s exited before it was ready (%s)
Cause: a supervised child failed its readiness check (supervisor.go).
Fix: read the log file the message names under .dev/, then run core dev down before retrying.
CORE dev is NOT up: %d process(es) above died during bring-up. Fix those first; `core dev down` to clean up.
Fix: scroll up for the ❌ lines, fix those, and run core dev down.
STALE BINARY: the rebuild did not land (%v).
Cause: the devgateway was rebuilt but the new binary lacks the :443 capability, so the previous build keeps running.
Fix: core dev hosts rebuilds it and re-grants the capability. On failure it reports could not re-grant cap_net_bind_service to the new binary.
core session
no inference endpoint found — start one (or pass --inference-url / CORE_SESSION_INFERENCE_URL); probed …
Cause: nothing answered /v1/models on the local candidates.
Fix: start the dev stack or a model, or pass --inference-url.
inference endpoint %s not reachable: %v
Fix: check the URL you passed. The session expects an OpenAI-compatible endpoint.
--repo must be owner/name, got %q / one of --issue or --prompt is required
Fix: pass --repo org/name and a goal.
expected exactly one App installation, found %d — set CORE_GH_APP_INSTALLATION_ID
Cause: App-token mode (CORE_GH_APP_ID + key set) with an App installed in several places.
Fix: set CORE_GH_APP_INSTALLATION_ID, or unset the App variables to use your core auth login token.
declined: the human operator did not approve this command / declined: no confirmation channel available for this command
Cause: the approval gate. The second form means there is no terminal (for example under Actions), so every gated call is declined.
Fix: answer y at the prompt. For unattended runs, use --verify build or --verify test to admit build and test commands.
blocked: command matches a disallowed pattern (%s)
Cause: the run_shell denylist (for example sudo, curl … | sh, .git/config).
Fix: none; this is intended. The model sees the refusal and adapts.
path %q escapes the workspace / path %q is inside .git, which tools may not touch
Cause: workspace confinement in tools.go. This is intended.
verification tier %q needs the sandbox, and CORE_SESSION_SANDBOX=off turns it off — model-written tests are never run unsandboxed; use --verify build, or drop the opt-out
Fix: use --verify build, or unset CORE_SESSION_SANDBOX on a machine where bwrap works.
unknown verification policy %q — use off, build, or test
Fix: correct --verify or CORE_SESSION_VERIFY.
turn %d: %d consecutive malformed replies, giving up
Cause: the model returned three unparseable replies in a row. That is usually the wrong tier or an overloaded plane.
Fix: check --model (default coder), then core session resume <id>.
refusing to navigate to non-local host %q …
Fix: pass --browser-allow-remote if you really mean it.
session %s: no console configured — report kept locally (set console_url in ~/.core.yaml, then `core session sync`)
Cause: --console-url has no default. Fix: set it and run core session sync.
session %s: report not delivered (kept pending for `core session sync`): %v
When %v is console 403: … with the body token does not carry the App's rights for org "…":
Cause: the console accepts reports only from tokens carrying the GitHub App’s rights for its org.
Fix: sign in with core auth login through the same App, then run core session sync.
core session serve
| Message | Fix |
|---|---|
no repositories allowed — pass --repo for each repo a queued instruction may touch | pass --repo at least once; there is no wildcard |
no console URL — set --console-url, CORE_CONSOLE_URL, or console_url in ~/.core.yaml | set the console URL |
session commands require a personal GitHub App token (`core auth login`) for org %q — installation tokens are not accepted | run core auth login; CI tokens cannot queue or claim |
could not resolve the GitHub login for this token; refusing to queue or claim a command without a verified identity | re-run core auth login --force |
this console does not know its GitHub org: … | the console has no readable App installation and CORE_GITHUB_ORG is unset; fix it on the console side |
queue is full — drain it before adding more (HTTP 429) | let serve claim or finish the queued items first |
Agents
The review, triage or self-heal comment says the model was unreachable
For example: the sovereign coder model was unreachable at …, or the coder model answered, but not in the review shape, so nothing from its answer is shown here.
Cause: a runtime model failure. It is posted as a degraded notice so a broken plane cannot look like “nothing found”.
Fix: check the inference plane and the model router. Then re-comment @core_check or wait for the next sweep.
reviewer: INFERENCE_URL not set — … (same shape for every agent)
Cause: the workflow did not set the endpoint. This is a configuration failure, and it is loud by design.
The curator runs green every day but publishes nothing
Cause: CURATOR_CRON_DRY_RUN is unset, which means dry.
Fix: set the Actions variable to the literal false.
### 🔒 Forger is DISARMED in the run summary
Fix: set CORE_FORGE_ENABLED=true, or arm forger in the console’s agent controls.
A PR keeps its review:findings-open label
The label clears only on a clean review. Check for a pending draft from fixer/* or core-resolve/*, since the resolver does not re-attempt a PR with one. Otherwise wait for the 17 */3 * * * resolver sweep. See Review Pipeline.
A dispatched review never finishes; core/review stays pending
A pending status older than 90 minutes is re-dispatched by core-review-sweep.yml. Nobody needs to comment.
Console
PUT /api/agent-schedules/{name} returns nothing to change: send at least one of enabled, dryRun, schedule
Fix: include at least one of those fields. A 404 reading no scheduled agent named … means the name is not a scheduled agent.
GET /api/audit/verify answers 503
There is no persisted chain to check. The audit log could not be attached, and the chain is stderr-only for this process.
The session-admins list cannot be changed
PUT /api/session-admins refuses an empty list and one that removes the caller with nobody left. If it fails with not changed: the audit record could not be made durable first: …, the audit log is not writable.