Skip to content

fix: make one-time standing approvals truthful and actionable - #1612

Draft
santoshkumarradha wants to merge 8 commits into
devfrom
codex/1611-standing-once-handoff
Draft

santoshkumarradha wants to merge 8 commits into
devfrom
codex/1611-standing-once-handoff

Conversation

@santoshkumarradha

@santoshkumarradha santoshkumarradha commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Isolated work approval and scheduled execution — recorded

Goal: Use the pantry project to preview a higher shopping threshold in a retained Git worktree, keeping the original project clean and avoiding an unsafe ordinary one-time execution path.

Observed outcome: The isolated weekly approval card offered schedule or decline, with no Only now option. A later corrected one-time schedule ran through the normal five-minute ticker in a scheduler-created retained worktree. Its uncommitted shopping-list.md added tea at threshold six; the original main remained clean at 343452d8a82209ca0207c13fa363e2e0666b9367. Four independent artifact tests passed and both one-time orders retired.

Real CodeAF workflow result

Watch the workflow (MP4) · Animated GIF · Original terminal recording (.cast)

Real CodeAF workflow — speed-adjusted preview

Isolated weekly work offers schedule or decline, with no ordinary Only now option

Evidence: tested revision 7f7f05a6199fef1855f1a805e76ffee189acc9d5. Execution/binary identity, model receipts, checksums and playback details. All 85 recorded calls used OpenRouter deepseek/deepseek-v4.1-flash, including auxiliary calls. Artifact verification, artifact test output, final standing state, coverage and limitations. make pr-ready and GitHub run 36334512416 passed for this revision.

Playback and limits: Playback is accelerated 3× with idle periods shortened. The first operator-supplied CLI command used an incorrect positional output path and failed. The recording preserves that failure, the model’s manual recovery and the corrected scheduled run. Helpers initially over-investigated; the operator interrupted and redirected them. Only the audited main terminal recording is published; private helper transcripts are excluded. Model Pool was off, and background installation was explicitly off for this profile to protect the shared timer. This branch still uses reminder wording for scheduled tasks; separately tested PR #1612 corrects that label. Isolated Once is intentionally unavailable; combining #1560 and #1612 must retain this guard. Explicit paths are not sandboxed, and watch/probe Once is not claimed verified.
Technical acceptance does not resolve the separate shared-timer ownership/cleanup blocker from earlier testing; readiness remains held by the coordinating task.

User workflow

Goal: Use the existing pantry CLI to prepare a practical SHOPPING.md note, choose a one-time run instead of weekly automation, correct its date convention and review a possible later refresh.

Observed outcome: Choosing Only now immediately led to actual CLI execution and writing SHOPPING.md with beans buy 3 / rice buy 1, without a corrective user message. The inventory stayed unchanged and no recurring schedule was saved. A follow-up changed the document to use inventory-file modification date. A later one-off card correctly said Run it then / Runs the work then; it was declined. The finished workflow ran 19 tests and independently verified zero saved standing definitions.

Real CodeAF workflow result

Watch the workflow (MP4) · Animated GIF · Original terminal recording (.cast)

Real CodeAF workflow — speed-adjusted preview

Actual one-time work approval card with corrected action wording

Evidence: tested revision f855f2e6510c155b282cba388db2f92d2121dda3. Execution/binary identity, model receipts, checksums and playback details. All 30 recorded calls used OpenRouter deepseek/deepseek-v4.1-flash, including auxiliary calls. Independent execution, post-approval tool transcript, resulting shopping note, full coverage and limitations.

Playback and limits: Playback is accelerated 3× with idle periods shortened. This is separate corrective PR #1612; the fix is not implied to exist in the original #1596/#1520/#1560 heads. Model Pool was disabled as the documented #1608 workaround. Pending actions still rely on ordinary model tools, permissions and limits; this proves actual execution for this request, not guaranteed behavior for every request. Tomorrow’s task was declined rather than executed. The model briefly described the declined card as awaiting approval; its actual state settled to not set up and the final saved-item list was empty. Integration boundary: this tested base has no does.isolate field. Ordinary Once tool execution does not enforce #1560 separate-worktree isolation. Isolated tasks must suppress Once or use a shared isolated executor in consolidation; isolated Once and watch/probe Once are not live-verified.

Revision note: recorded runtime f855f2e6510c155b282cba388db2f92d2121dda3; later head 9417fd756 changes only test synchronization and fixture setup: program fixtures now join cleanup after the store closes, and the young-bash steering test uses an explicit release barrier and age seam (fixes #1623). Production runtime is unchanged; the recording is not a binary built from this newer head. Cleanup regression passed 25 repetitions and young-bash regression passed 50; two additional handover/decision fixtures use their existing watched/held-session helpers. Final full local session checks passed both shards in 274 seconds; all current CI checks passed (run 36336590188).

Selecting “Only now, don't repeat” previously reported “done now” before any execution and returned a generic continuation that could be misread as a decline. The tool now hands back the complete approved action with an explicit run-once decision and pending execution state; the card reports approval rather than completion. Unsupported once answers are refused.

One-time scheduled work also names the real action: “Run it then”, rather than promising a reminder. Say-only reminders retain their existing labels. The ordinary conversation retains its existing workspace, permissions and spending controls; this does not launch a second unattended execution path.

Fixes #1611.

Validation at f855f2e65 : focused session/TUI regressions and make build passed. In the recorded real pantry workflow, choosing Only now caused bash/read/write execution and produced SHOPPING.md without a corrective user message. A later inventory-date correction and one-time scheduling decision used the same working report. Nineteen pantry subprocess tests passed; stock data was unchanged; no standing job was saved. All 30 usage receipts used OpenRouter deepseek/deepseek-v4.1-flash, including auxiliary calls. Fleet session: critical-extended-1611-v2.

Limitations: the structured handoff still relies on the model performing ordinary tools; the approval receipt does not claim completed work. The future one-time task was declined after inspecting its correct work labels. Live profile used model_pool=off for separately tracked #1608/#1610. Final head 9417fd756 passed its full session suite with two shards and pinned Go caches (274 seconds); all CI checks passed (run 36336590188). Earlier local light checks and the full TUI suite passed; subsequent changes are test-only. Technical verification is complete. Draft remains held for the coordinating task’s separate shared-timer cleanup checkpoint.

Final verification: exact-head check record and full session result.

@santoshkumarradha santoshkumarradha added bug Something the code does that it should not area:session The engine — turns, tasks, the toolbelt, checkpoints labels Sep 27, 2026
@santoshkumarradha santoshkumarradha added this to the Reliable agent milestone Sep 27, 2026
@santoshkumarradha santoshkumarradha added area:chat The v3 surface a person sits in front of (internal/tui3) sev:serious Wrong or missing behaviour a person meets in ordinary use labels Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:chat The v3 surface a person sits in front of (internal/tui3) area:session The engine — turns, tasks, the toolbelt, checkpoints bug Something the code does that it should not sev:serious Wrong or missing behaviour a person meets in ordinary use

Projects

None yet

Development

Successfully merging this pull request may close these issues.

test: young bash steering regression can miss its short-lived foreground state standing: Only now can do nothing while the card claims done

1 participant