Skip to content

F2b: per-item execution and the runner's commit step - #68

Draft
mchwang wants to merge 2 commits into
feat/f1e-planning-feedbackfrom
feat/f2b-item-execution
Draft

mchwang wants to merge 2 commits into
feat/f1e-planning-feedbackfrom
feat/f2b-item-execution

Conversation

@mchwang

@mchwang mchwang commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Lane F, step F2, slice F2b: per-item execution and the runner's commit step. Stacked on #60 (F1e, the top of the F1 stack). Related: #22, #66, #51.

About the diff: this branch also contains F2a's commit (c1e2277, cherry-picked from #67), because F2b uses its prompt builder and audit. That commit drops out when #67 merges and the stack is rebased. The F2b-only change is the last commit.

What this does

Implements "codeboost makes every commit" (design, "How codeboost runs a plan") against a fake D workspace. The four workspace operations are the ones proposed in #66 (materialize, snapshotDeclaredLinks, inspectChanges, commit, plus release).

  • runner/execution.ts: executionDeps is the RunnerDeps for execute attempts:
    • prepare: a fresh workspace from the recorded head of the attempt's snapshot; a no-follow snapshot of declared symlinks; the prompt and approvedArgv from prepareExecution (F2a).
    • finish: inspectChanges, then auditRun (F2a).
      • A safety violation throws FinishFailure("Safety violation: …"): no commit, and the attempt fails with that diagnostic.
      • No changes: "planned but unchanged".
      • Otherwise the runner's own commit, with Plan-Item: P<n> and Plan-Revision: r<k> trailers, of exactly the audited paths, matched to the audit's digest. It returns the owned ledger entry.
    • release: removes the workspace.
  • ItemExecutor.runTask runs the plan items in order, one attempt each:
    • out-of-scope files are committed with the item, then a checkpoint is recorded and the task moves to needs amendment;
    • a safety violation moves the task to needs human;
    • any other non-completed attempt stops the run and reports why.
  • Coordinator (F1b):
    • an optional asynchronous finish step replaces validate for writable attempts; FinishFailure keeps its own diagnostic;
    • an optional release step runs after the terminal write, on every path, including endings before launch;
    • a failed release keeps the slot under a marker.
  • Store (F1a): settleAttempt takes a history record and calls recordHistory inside the same transaction as completed, after its guards. This is the publication order in the F1 contract. A commit made in task storage but not published (a refused CAS, or a stop during finish) is discarded with the storage.

Validation (head f0957ad)

  • npm run typecheck: passes.
  • CI's unit set: 552 passed, 0 failed. 8 of those are new, in test/runner-execution.test.ts, using the real Store, coordinator and executor with a fake workspace and launcher:
    • two items in order, with trailers, ledger owners, and each item starting from the previous commit;
    • an unchanged item;
    • out-of-scope files, giving a checkpoint and needs amendment;
    • a violation, giving needs human with no commit;
    • an agent failure;
    • a refused commit, with no ledger entry;
    • a stop during the commit, which is discarded;
    • a release failure, giving a marker;
    • the release always after the terminal write.
  • Mutation check: six guards were broken one at a time, and each was caught:
    • history not recorded with completed;
    • release before the terminal write;
    • a violation leaving the task running;
    • a commit despite a violation;
    • no Plan-Revision trailer;
    • out-of-scope files not pausing.

Not in this slice

🤖 Generated with Claude Code

mchwang and others added 2 commits September 27, 2026 01:17
prepareExecution builds the trusted execute/fix request: untrusted issue,
plan fields, lessons and problem text only in escaped JSON data blocks,
filled in one pass; approvedArgv only from the item's structured cmd checks
that exactly match an approved argv. auditRun is a pure audit over D's change
manifest (#66): safety violations first (metadata, .git, link targets,
gitlinks, new or converted symlinks, unsafe targets, odd entries, oversized
reports), then in-scope versus out-of-scope files for the commit step.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ItemExecutor runs a task's plan items in order as execute attempts.
executionDeps materializes a fresh workspace and snapshots declared links,
builds the prompt with prepareExecution, and in finish() inspects changes,
audits them with auditRun, and makes the runner's own commit with
Plan-Item/Plan-Revision trailers. The coordinator gains an async finish step
and a release step after the terminal write; settleAttempt records the
owned ledger entry with completed in the same transaction. A safety violation
moves the task to needs human; out-of-scope files are committed and pause it
in needs amendment with a checkpoint. The workspace is D's (#66), faked here.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant