Commit Graph
3368 Commits
Author SHA1 Message Date
Yichen Jiang c748f30055 fix(workspace-context): skip blocked touches and disable in Code Mode
Address the two remaining review warnings on PR #106.

- tools/post-execute: when a downstream listener/policy returns `block`,
  return early without loading or attaching workspace instructions. The
  registry turns a block into a final isError result, so reconciling off
  the original successful result leaked instructions from a rejected call
  and advanced nested/baseline tracking off a touch that never happened.
- Disable workspaceContext in the Code Mode examples: fs tools run as
  run_code sub-dispatches and code-mode.ts drops sub-call additionalContext,
  so dynamic AGENTS.md updates are silently discarded there.

Update the block regression test to assert no context is attached, and add
a waterfall case proving accept still surfaces the discovered instructions.
2026-07-13 03:40:10 +00:00
Dudu-0223 7ea1bf119f feat(agent-loop): run safe tool calls in parallel 2026-07-13 11:13:21 +08:00
Dudu-0223 5ac03dde3f fix(review): generalize spill storage locators 2026-07-13 11:07:27 +08:00
Dudu-0223 43535aab42 Merge remote-tracking branch 'origin/master' into codex/truncated-design
# Conflicts:
#	docs/capability-seams.md
#	docs/config-catalog.md
#	docs/cordis-catalog/services.md
#	docs/core-data-structures/core.md
#	docs/event-producer-consumer.md
#	docs/module-graph.md
#	docs/rfc/INDEX.md
#	docs/tool-catalog.md
#	examples/acp-agent/README.md
#	packages/README.md
#	packages/bash/bash/README.md
#	packages/core/tools/tests/gen-tool-catalog.spec.ts
#	packages/support/acp-snapshot/src/harness.ts
#	pnpm-lock.yaml
#	scripts/gen-doc-graphs.ts
#	scripts/gen-tool-catalog.ts
#	scripts/type-equiv.manifest.json
2026-07-13 09:49:46 +08:00
Tianyi Cui 23850b4ad9 docs: align model experience with scoped runtime 2026-07-12 23:59:05 +08:00
Tianyi Cui f0ea495b97 Merge remote-tracking branch 'origin/worktree-agent-scope-design' into codex/pr224-simplification-audit
# Conflicts:
#	docs/config-catalog.md
#	docs/cordis-catalog/services.md
2026-07-12 23:57:01 +08:00
Tianyi Cui 37c01d36ff Merge remote-tracking branch 'origin/codex/package-readme-limitations-audit-20260712' into codex/model-experience-readmes-20260712 2026-07-12 23:55:57 +08:00
Tianyi Cui 6ebc7313a0 docs(agent-core): correct invariants limitation 2026-07-12 23:55:01 +08:00
Tianyi Cui 5158cc3e0b Merge remote-tracking branch 'origin/codex/package-readme-limitations-audit-20260712' into codex/model-experience-readmes-20260712
# Conflicts:
#	packages/AGENTS.md
2026-07-12 23:54:00 +08:00
Tianyi Cui 8d5dce1824 docs: condense package guidance after scope merge 2026-07-12 23:49:42 +08:00
Tianyi Cui d2ed172aca Merge remote-tracking branch 'origin/worktree-agent-scope-design' into codex/package-readme-limitations-audit-20260712
# Conflicts:
#	packages/core/agent-loop/README.md
#	packages/core/system-prompt/README.md
2026-07-12 23:44:15 +08:00
Tianyi Cui b33e79cbdd Merge finalized PR #224 into prose cleanup 2026-07-12 23:43:41 +08:00
Tianyi Cui f7b9cea733 docs: clarify scoped persona shadowing 2026-07-12 23:40:27 +08:00
Tianyi Cui 74ada5777c Merge PR #224 updates into prose cleanup 2026-07-12 23:36:49 +08:00
Tianyi Cui 6967c584d1 Merge remote-tracking branch 'origin/worktree-agent-scope-design' into codex/package-readme-limitations-audit-20260712
# Conflicts:
#	packages/core/scope/README.md
#	packages/session-persistence/session-persistence-jsonl/README.md
#	packages/session-persistence/session-persistence-sqlite/README.md
#	packages/subagent/subagent-acp/README.md
#	packages/subagent/subagent-fork/README.md
#	packages/subagent/subagent-inprocess/README.md
#	packages/subagent/subagent/README.md
#	packages/subagent/tool-subagent/README.md
#	packages/support/invariants/README.md
#	packages/support/subagent-mock/README.md
#	packages/workflow/workflow-workerthread/README.md
#	packages/workflow/workflow/README.md
2026-07-12 23:35:47 +08:00
kingwl 1fe2f99580 refactor(mode): drop the per-mode tool allowlist — enforce where an enforcer exists
A ModeDefinition is now exactly { section, access? }; unknown keys (a
tools list included) fail loud at load. What plan mode still does: the
guidance section, the exit_plan_mode visibility rule (plan only, both
soft surfaces), the access cap's bash/resolve-mode clamp, and the two
cap-derived pre-execute guards (the bash trio is withheld when no
confining executor can honor the cap; sandbox escalation is denied
while it holds). The general deny-by-default gate and the assemble
allowlist filter are gone: which tools a mode admits is an effects
question, and a hand-maintained name list mislabels it — it must track
every composed tool and rots silently as tools arrive. The dimension
returns as a consumer of effects self-declaration on tool definitions
(MCP ToolAnnotations as the template) — rationale and restart trigger
archived in the RFC's Alternatives/Deferred; the interim guidance-only
non-shell restraint is priced in Consequences.

Exiting plan is now a pure removal (the exit tool + section), which the
delta encoding CAN express: the re-recorded plan-mode fixture pins one
plan-shaped initial header snapshot plus one header-delta instead of
two snapshots.
2026-07-12 23:20:36 +08:00
Tianyi Cui 738054562d fix: complete scoped lifecycle simplification 2026-07-12 23:15:07 +08:00
kingwl 99650a201b feat(mode): the access cap — plan mode composes with the sandbox instead of banning bash
A ModeDefinition may declare access: the widest sandbox access shell
commands run under while the mode holds, on the SANDBOX_MODES ladder.
The bash seam gains the resolution point to hang it on: BashExecutor.
resolveMode(session) folds override ?? default and dispatches the new
bash/resolve-mode waterfall; dsh-tool-bash consults it at both the
stamping site and the escalation baseline; dsh-mode's clamp listener
takes the ladder minimum per call. Two independent log folds compose at
read time — the mode never writes the sandbox knob, so the two switch
in any order and the knob re-emerges intact on exit.

The built-in plan definition ships access: read-only with the bash trio
allowlisted CONDITIONALLY: both policy layers admit bash/bash_output/
bash_kill only while a confining executor is mounted (an unconfinable
shell cannot honor the cap), and a bash call carrying sandbox_permissions
under a cap is denied at the gate — no widening mid-mode; the widened
step belongs in the plan.

examples/plan-acp-agent swaps bash-local for sandbox-local +
bash-sandbox (workspace-write default, clamped read-only inside plan)
plus the approval seam; the re-recorded plan-mode arc runs a real cat
inside plan under the clamped sandbox, and modes-advertise now pins the
sandbox-mode and approval config options. RFC amended to the landed
shape (access cap section, orthogonality FAQ, deferred item resolved
into effects self-declaration).
2026-07-12 22:51:09 +08:00
Tianyi Cui ed5304fb6d docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
Tianyi Cui bb3f6bd736 refactor(subagent): unify async readiness and cancellation 2026-07-12 22:41:59 +08:00
Tianyi Cui 02ca71db57 refactor(core): simplify tools prompts and trusted services 2026-07-12 22:39:01 +08:00
Tianyi Cui 28e04ff4fb refactor(core): simplify scoped agent lifecycles 2026-07-12 22:36:04 +08:00
kingwl 88db403d9f Merge branch 'worktree-session-modes-rfc' (master: sandbox stack #169, skills #109, prompt snapshots #254)
The stack rebases onto a moved master through its base branch. Beyond
mechanical unions (both branches' demo scripts, example rows, service
roles, tool lists, acp deps, doc budgets — each side fit alone, the
union needs the higher ceilings), three semantic reconciliations:

- The ACP bridge now carries BOTH per-session surfaces: the sandbox
  stack's config options + approval answerer and this branch's session
  modes; session/new and session/load advertise modes AND configOptions
  side by side.
- The feature matrix supersedes the sandbox stance per the RFC's
  second-lander rule: session/set_mode and current_mode_update flip to
  shipped-by-dsh-mode, config-option rows stay as #169 wrote them, and
  §6 records both landed features under the picker-to-modes /
  knobs-to-config-options division.
- The snapshot pin grammar (#254: one header snapshot + declared deltas
  + a Markdown prompt golden) gains a symmetric declaration for what a
  delta cannot express: expectedHeaderSnapshots — a plan-mode flip
  resorts the canonical tool list, so its widening lands as a second
  full snapshot, now its own Markdown section. The pin-less-class and
  model-turn-only-pin amendments carry over; new fixtures cover the
  extended writer paths, and the plan-acp-agent scenarios re-recorded
  under the merged composition (the app now bundles the skill tool)
  with the suite's refresh mode wired through.
2026-07-12 20:08:09 +08:00
Tianyi Cui e8fed4fb66 fix(session): contain post-commit observers 2026-07-12 18:57:42 +08:00
Yichen Jiang 8f5ea04c3f fix(tasks): validate owner identity and brand session ids 2026-07-12 17:10:02 +08:00
Yichen Jiang d4b5227071 fix(bash): validate managed env namespace 2026-07-12 17:03:11 +08:00
Tianyi Cui a34801df4b fix(agent-loop): own queued message input 2026-07-12 16:54:37 +08:00
Yichen Jiang 1aadce9fe7 refactor(core): centralize DSH home resolution 2026-07-12 16:30:01 +08:00
Yichen Jiang 48e7bde361 refactor(bash): centralize managed env prefix 2026-07-12 16:14:13 +08:00
Yichen Jiang 2688df99cd Merge remote-tracking branch 'origin/master' into codex/rfc-subagent-background-tasks
# Conflicts:
#	examples/acp-agent/tests/snapshots/both-mode-turn/session.jsonl
#	examples/acp-agent/tests/snapshots/code-mode-turn/session.jsonl
#	examples/acp-agent/tests/snapshots/skill-load/session.jsonl
#	examples/acp-agent/tests/snapshots/text-turn/session.jsonl
#	examples/sandbox-acp-agent/tests/snapshots/escalation-approved/session.jsonl
#	examples/sandbox-acp-agent/tests/snapshots/escalation-rejected/session.jsonl
#	examples/sandbox-acp-agent/tests/snapshots/mode-switching/session.jsonl
2026-07-12 16:09:22 +08:00
Yichen Jiang bd9abba638 fix(tasks): harden lifecycle and bundle config 2026-07-12 16:00:56 +08:00
Yichen Jiang df9617aaff feat(bash): generalize managed shell environment 2026-07-12 15:41:42 +08:00
Tianyi Cui 7e3d46a3ce docs(scope): split contract from runtime design 2026-07-12 13:25:04 +08:00
Yichen Jiang acdbe7b828 Merge remote-tracking branch 'origin/master' into codex/agent-session-jsonl-location
# Conflicts:
#	examples/acp-agent/tests/snapshots/both-mode-turn/session.jsonl
#	examples/acp-agent/tests/snapshots/code-mode-turn/session.jsonl
#	examples/acp-agent/tests/snapshots/skill-load/session.jsonl
#	examples/acp-agent/tests/snapshots/text-turn/session.jsonl
#	examples/sandbox-acp-agent/tests/snapshots/mode-switching/session.jsonl
2026-07-12 13:01:26 +08:00
Tianyi Cui 1795dc6e19 test(apps): configure workspace context in loader fixtures 2026-07-12 12:15:05 +08:00
Tianyi Cui e9a54f0e71 fix(workspace-context): require explicit byte budgets 2026-07-12 12:09:35 +08:00
Tianyi Cui 855abe9d60 Merge remote-tracking branch 'origin/master' into codex/pr106-comment-fixes 2026-07-12 11:49:21 +08:00
Tianyi Cui cb03c8c284 fix(scope): align trust and input boundaries
Rewrite the agent-scope RFC with executable examples and an explicit security non-goal. Harden subagent scalar and depth validation, and pin live tool-filter semantics across code, tests, and generated docs.
2026-07-12 11:17:57 +08:00
Tianyi Cui d427478c44 fix(subagent): validate direct depth boundaries 2026-07-12 10:48:20 +08:00
Tianyi Cui 875c3d62d8 fix(workflow): reap children after settled dispose 2026-07-12 10:39:55 +08:00
Tianyi Cui 48067c3a7a fix(subagent): validate depth config at load 2026-07-12 10:33:29 +08:00
Tianyi Cui 9fc2260bb6 fix(workflow): harden terminal cleanup races
Queue worker results before settlement cleanup, claim terminal and death boundaries before provider callbacks, and close late-message admission.

Make child cancellation and disposal reentrancy-safe across the workflow bridge and generic subagent wrapper, with adversarial regression coverage and RFC documentation.
2026-07-12 10:17:31 +08:00
Hypatia May bea27efc4b fix(session-query): reject markerless surface events 2026-07-12 10:09:47 +08:00
Hypatia May 03ce8bfea3 Merge remote-tracking branch 'origin/master' into session-query
# Conflicts:
#	docs/capability-seams.md
#	docs/config-catalog.md
#	packages/README.md
#	packages/cordis/tool-cordis/src/api-catalog.ts
#	pnpm-lock.yaml
2026-07-12 10:09:16 +08:00
Tianyi Cui c5b1a7941f fix(scope): harden lifecycle ownership foundation
Make Cordis construction and teardown ownership reentrancy-safe, then carry caller and provider ownership through reservation, setup, publication, quiescence, and sentinel retirement.

Stabilize registry carriers and factory/workflow boundaries, add adversarial lifecycle regressions, and align the rewritten RFC plus generated contracts with the enforced behavior.
2026-07-12 08:57:05 +08:00
Tianyi Cui 197f7237d2 fix(workflow): bootstrap source worker transforms 2026-07-12 06:19:53 +08:00
Tianyi Cui a9cb70d896 fix(scope): harden final ownership boundaries 2026-07-12 05:13:17 +08:00
Tianyi Cui 36b8370027 fix(scope): close remaining ownership boundaries 2026-07-12 03:51:55 +08:00
Tianyi Cui 75838e10b5 docs: trim generated prose 2026-07-12 03:36:43 +08:00
Tianyi Cui 84a9b7374c docs: propose further simplifications 2026-07-12 03:11:21 +08:00