Skip to content

Let workers check and repair their assigned changes - #104

Merged
arjitj2 merged 2 commits into
mainfrom
arjit/worker-local-checks
Sep 30, 2026
Merged

arjitj2 merged 2 commits into
mainfrom
arjit/worker-local-checks

Conversation

@arjitj2

@arjitj2 arjitj2 commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Closes #103

What changed

Writers run suitable local checks, repair failures caused by their edits, and rerun affected checks. External adapters pair tool guidance with invocation flags; every prompt transport receives the same rendered ownership contract. File-only writers request a validated run-checks handoff. The parent retains Git mutations and independent acceptance.

External Claude writers use session-scoped sandboxed Bash, with no unsandboxed escape or allowed network domains. Project and user settings cannot add command exclusions. A version preflight requires Claude Code 2.1.285 or newer before writer dispatch. Read-only behavior, authentication handling, saved model choices and fallback policy are preserved. Plugin version is 1.10.2.

Verification

  • Bun tests, strict typecheck, static invariants, and plugin validation pass.
  • The exact candidate is installed in both affected harnesses.
  • The changed behavior passes from each affected user surface.
  • Evidence below names the version, action, and observed result.

Candidate head b5a5ff7504af9e7d26dcea4645e27e910defe2c8. Both supported local-marketplace installations load plugin 1.10.2. Checkout, loaded marketplace trees and installed caches match SHA-256 fd41f4fecdf3a01545bc337ba1c1d5b5643ad4e16f490bea94fc6cc03fd13e30 of the sorted relative-path/file-hash map (213 files, generated dependencies excluded).

Installed parent and user action Worker execution evidence Independent parent acceptance
Claude Code 2.1.285 invoked pstack:poteto-mode, dispatched native pstack:pstack-opus-high Native provider tool call/result pairs show 2 failing baseline tests, a scoped edit, and 2 passing tests 2 passing tests; implementation only changed; tracked tests, worker HEAD and seed unchanged
Codex CLI 0.159.0 discovered the installed skill in native host metadata, invoked $pstack:poteto-mode, dispatched native codex:gpt-6.1-sol@high Host subagent metadata confirms model/high effort. Bound native tool calls show exit 1 baseline and exit 0 recheck 2 passing tests; implementation only changed; tracked tests, worker HEAD and seed unchanged
Installed Codex parent invoked the installed launcher for claude:opus@high, apiSpend: deny Transparent CLI recorder captured sandboxed Bash baseline failure and passing rerun. Receipt reports claude-opus-5-5 and complete 2 passing tests; implementation only changed; tracked tests, worker HEAD and seed unchanged
Installed Codex parent invoked the installed launcher for devin:swe-2@high, apiSpend: deny Recorder selected ATIF sandboxed exec call/result pairs before export cleanup: baseline exit 1, recheck exit 0. Receipt is complete; exact swe-2-high argv is pinned, backend model identity is not reported 2 passing tests; implementation only changed; tracked tests, worker HEAD and seed unchanged

Every fixture used python3 -B -m unittest -v. Recorders preserve the observed argv, stdin, stdout and exit status and inject no provider settings. Native observations came from the host transcript, not worker-written logs. Claude also ran permitted read-only git status --short; no Git mutation was assigned or observed. Worker prose was treated as advisory.

Negative candidate checks:

  • Hostile project sandbox settings did not permit an outside-checkout canary write. One actual Bash attempt failed with Operation not permitted; canary unchanged, no retry.
  • An outside-directory cache write failed once; parent-owned cache contents remained unchanged.
  • Sandboxed https://example.com access failed with proxy HTTP 403. The same parent control request succeeded with HTTP 200. No retry or widened network allowance.
  • An outer disposable OS policy denied execution of /usr/bin/sandbox-exec. The writer's one Bash attempt failed with exit 126; the in-checkout execution marker was absent, with no unsandboxed retry. This measures sandbox process startup failure, not every unsupported platform.
  • Old/malformed/missing-version cases prove no model launch through synthetic CLI boundary tests. Strict native preparation remains unsupported; strict external preparation exits 79 with processStarted: false. A synthetic file-only handoff passes fixed task/checkpoint/file/check/HEAD validation and parent acceptance. Unconfigured file-only providers are not claimed as live-verified, and strict Git confinement remains unsupported.

All 765 Bun tests pass. Strict typecheck, maintenance/session-start/documentation tests, documentation checker, static invariants, Claude plugin validator, manifest parsing, upstream ledger and verification Doctor pass. CI verify is green on the exact head. Copilot review was requested and confirmed; its account quota was exhausted, so no line findings or approval were produced.

Failed and incomplete probes remain retained separately outside the checkout. An initial external capture missed recorders because of login-shell PATH setup; fresh fixtures with explicit process instrumentation supplied the successful evidence above. No provider fallback or continuation was used. The independently tracked incomplete Devin export in #60 remains outside this change. No lab reports or private transcripts are packaged.

Documentation impact

Updated the behavior owner plugins/pstack/skills/poteto-mode/references/provider-dispatch.md, the worker verification recipe, package manifests, changelog, and the version mirror in UPSTREAM.md.

@arjitj2
arjitj2 requested a balanced review from Copilot September 30, 2026 07:12

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@arjitj2
arjitj2 marked this pull request as ready for review September 30, 2026 15:44
@arjitj2
arjitj2 merged commit 7ca71eb into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support worker local checks with accurate provider execution guidance

2 participants