fix(standing): approve worktree isolation explicitly and retain unfinished work - #1560
Draft
santoshkumarradha wants to merge 7 commits into
Draft
santoshkumarradha wants to merge 7 commits into
santoshkumarradha wants to merge 7 commits into
Conversation
Assisted-by: CodeAF (gemini-3.8-flash-high) Co-Authored-By: CodeAF <267109073+agentfield-bot@users.noreply.github.com>
Assisted-by: CodeAF (gemini-3.8-flash-high) Co-Authored-By: CodeAF <267109073+agentfield-bot@users.noreply.github.com>
…lation (#1550) Defend contracts that standing runs with branch-only grants execute in an isolated git worktree and leave the host branch untouched, that false prose claims of branch isolation are caught and marked failed, and that plain ambient runs without grants remain unaffected. Assisted-by: CodeAF (gemini-3.8-flash-high) Co-Authored-By: CodeAF <267109073+agentfield-bot@users.noreply.github.com>
Member
Author
Two-Pass Code ReviewPass 1: Defects & Contracts
Pass 2: Architecture & Software Craft
|
Member
Author
Two-Pass Code ReviewPass 1: Defects & Contracts
Pass 2: Architecture & Software Craft
|
santoshkumarradha
marked this pull request as ready for review
September 27, 2026 03:20
Member
Author
Pass 3 Review: Production Readiness, Concurrency & CI Status
drafted with CodeAF |
Member
Author
|
@AbirAbbas this is review ready |
santoshkumarradha
marked this pull request as draft
September 27, 2026 14:35
santoshkumarradha
marked this pull request as ready for review
September 27, 2026 15:08
This was referenced Sep 27, 2026
santoshkumarradha
marked this pull request as draft
September 27, 2026 16:43
This was referenced Sep 27, 2026
Draft
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Isolated work approval and scheduled execution — recorded on Spark
Goal: Use the pantry project to preview a higher shopping threshold in a retained Git worktree, keeping the original project clean and avoiding an unsafe ordinary one-time execution path.
Observed outcome: The isolated weekly approval card offered schedule or decline, with no Only now option. A later corrected one-time schedule ran through the normal five-minute ticker in a scheduler-created retained worktree. Its uncommitted shopping-list.md added tea at threshold six; the original main remained clean at 343452d8a82209ca0207c13fa363e2e0666b9367. Four independent artifact tests passed and both one-time orders retired.
Watch the workflow (MP4) · Animated GIF · Original terminal recording (.cast)
Evidence: tested revision
7f7f05a6199fef1855f1a805e76ffee189acc9d5; Spark sessioncritical-extended-1560guard-v2. Execution/binary identity, model receipts, checksums and playback details. All 85 recorded calls used OpenRouterdeepseek/deepseek-v4.1-flash, including auxiliary calls. Artifact verification, artifact test output, final standing state, coverage and limitations. Spark make pr-ready and GitHub run 36334512416 passed for this revision.Playback and limits: Original
.castis preserved; GIF/MP4 play at 3× speed with idle intervals capped at 3 seconds. The first operator-supplied CLI command used an incorrect positional output path and failed. The recording preserves that failure, the model’s manual recovery and the corrected scheduled run. Helpers initially over-investigated; the operator interrupted and redirected them. Only the audited main terminal recording is published; private helper transcripts are excluded. Model Pool was off, and background installation was explicitly off for this profile to protect the shared timer. This branch still uses reminder wording for scheduled tasks; separately tested PR #1612 corrects that label. Isolated Once is intentionally unavailable; combining #1560 and #1612 must retain this guard. Explicit paths are not sandboxed, and watch/probe Once is not claimed verified.Technical acceptance does not resolve the separate shared-timer ownership/cleanup blocker from earlier testing; readiness remains held by the coordinating task.
Supplemental correction verified in separate PR #1612
Separate PR #1612 corrects the old one-off task card wording noted below. Its live task card says Run it then / Runs the work then. The isolated-run evidence below remains the original #1560 revision.
Tested revision
f855f2e6510c155b282cba388db2f92d2121dda3on Spark: a practical shopping-note workflow, 19 generated-project tests, unchanged inventory and zero saved recurring definitions. All 30 receipts used OpenRouterdeepseek/deepseek-v4.1-flash; Model Pool was disabled as disclosed in coverage/limitations.Fix PR #1612 · Video · GIF · Original terminal recording · Actual corrected card · Post-approval execution evidence
This evidence tests the separate corrective revision; it does not claim this PR’s original head already contains that fix. Earlier recordings and their limitations remain below. Tomorrow’s task was declined, not executed; ordinary model-action and permission limits still apply. Integration boundary: this #1612 base does not contain #1560 does.isolate, so ordinary Once tools do not prove isolated execution. Consolidation must suppress Once for isolated tasks or use a shared isolated executor. Isolated Once and watch/probe Once were not live-verified.
Real product workflow — recorded on Spark
Goal: Build a useful pantry shopping report, then schedule an isolated larger-buffer preview that can be reviewed without changing the main project.
Observed outcome: CodeAF built the report and tests, accepted two isolated drafts, and ran them through the normal scheduler. The final threshold-6 preview added tea to shopping-list.md. That change remained uncommitted and recoverable in the retained worktree while the host project stayed clean at its original commit. Both one-off orders retired after running; independent retained-project checks passed all 4 tests.
Watch the workflow (MP4) · Animated GIF · Original terminal recording (.cast)
Evidence: tested revision
75b0f9a7265723b33b41208b38a8eb2831b37813; Spark sessioncritical-extended-1560-v2. Execution/binary identity, model receipts, checksums and playback details. All 78 recorded calls used OpenRouterdeepseek/deepseek-v4.1-flash, including auxiliary calls. Independent artifact verification, retained-project tests, saved standing states.Playback and limits: Original
.castis preserved; GIF/MP4 play at 3× speed with idle intervals capped at 3 seconds. The roughly 15-minute original includes the normal five-minute scheduler polling wait and two trial drafts. Run used --one-model with Model Pool disabled for #1608. The old one-off task card used reminder wording; task-aware wording is tracked separately in #1612 and is not part of this tested revision. Isolation is a separate Git worktree, not a filesystem sandbox; explicit host paths remain accessible.Scheduled coding work can run in the active checkout and lose unfinished files when a temporary worktree is removed. A task now stores
does.isolate, shows the separate-worktree choice on its approval card, and retains its worktree and recovery metadata after the firing. Grant and reply text no longer select an execution mode or decide whether work succeeded.Related to #1550. Existing orders keep their current behavior; replace and approve an order with isolation enabled to change it. Isolation starts from committed HEAD and is not a filesystem sandbox. Explicit commands can still address other folders. Copies are retained for review rather than automatically merged or deleted.
Validation:
does.isolate=true, approved it with1, and ran the product'scodeaf tickafter it became due. The worker wroteUNCOMMITTED_REVIEW_1560toretained.txtwithout committing it. After the ticker exited,git status --shortin the saved worktree still showed?? retained.txt; the original checkout was clean and its main commit unchanged. The run metadata retained the branch and worktree path.deepseek/deepseek-v4.1-flash, including worker, talk, low and reflex roles.