Skip to content

Resolve the launch's immutable base SHA vector and pin every participant - #1093

Merged
ppXD merged 2 commits into
mainfrom
feat/s1-launch-sha-vector
Jul 11, 2026
Merged

ppXD merged 2 commits into
mainfrom
feat/s1-launch-sha-vector

Conversation

@ppXD

@ppXD ppXD commented Jul 11, 2026

Copy link
Copy Markdown
Owner

Summary

  • S1 (PR② of 3): at launch, each cloneable repo's tip commit is resolved ONCE over the same git transport the clones use (git ls-remote with the same URL/credential — RemoteTipResolver), frozen into the definition snapshot as the agent node's pinnedSha (primary + per related entry), and honored by the existing PinnedSha substrate (Add the immutable-base pin substrate to workspace provisioning #1086) at clone time — the planner, the grounded plan reviewer, and every agent the run dispatches materialize the SAME base even when the remote advances mid-run
  • Pin eligibility (LaunchBasePinResolver): the primary pins at the operator's BaseBranch (else the default branch), related repos at their authored refs; session-soft refs stay unpinned (their branch-or-default disjunction cannot be one commit), URL-less repos stay unpinned; a missing AUTHORED ref or unreachable remote fails the launch loud (422 workspace_unresolvable), while a missing IMPLICIT default (empty/new repo, stale record) launches unpinned
  • The grounded plan reviewer clones at the same pin (PlannerConfig → PlanAuthorNode → WorkflowPlanRequest → CriticPlannerDecorator → PlanReviewRequest → AgentReviewSpec), closing the review-tree-vs-execution-tree drift
  • Pinned clones stay SHALLOW when the pin equals the fetched tip (the common launch), deepening only when the tip advanced — fetch-by-sha, then unshallow, then loud failure (a force-pushed-away pin still surfaces)
  • git is added to the API image as the ONE sanctioned synchronous use (read-only ls-remote, no clone); the Dockerfile note is updated accordingly
  • Adversarial scan ran (1 FATAL + 5 major + 5 minor): FATAL (git absent from API image) and all majors fixed in the second commit; supervisor-lane threading (and its half-read guard) is PR③ scope

Test plan

  • Unit 5648/5648 — resolver (real git: branch/HEAD/tag-peeled/lightweight-tag/branch-over-tag/soft-fallback/implicit-null/empty/unreachable/sanitize), eligibility policy, mapping stamps, spec factories, reviewer task pin, node contract pins
  • Integration 2341/2341 — new LaunchBasePinFlowTests (7): freeze-at-launch vs advanced tip, operator-BaseBranch pin, missing-BaseBranch loud, URL-less unpinned, session-continue unpinned, empty-remote unpinned, deep-lane gate; zero regressions
  • Shallow-retained: pin==tip keeps --is-shallow-repository true

Follow-ups (named, non-blocking)

  • PR③: supervisor lane consumes the vector (spawned agents + supervisor grounding same commit; lifts the projection gate)
  • Grounding reference param on IRepoGroundingProvider lands with S2 (its first real consumer)

ppXD added 2 commits July 11, 2026 08:48
At launch each cloneable repo's tip commit is resolved ONCE over the same
git transport the clones use (git ls-remote with the same URL/credential),
frozen into the definition snapshot as the agent node's pinnedSha (primary
+ per related entry), and honored by the existing PinnedSha substrate at
clone time — so the planner, the grounded plan reviewer, and every agent
the run dispatches materialize the SAME base even when the remote advances
mid-run. Session-soft refs stay unpinned (their branch-or-default
disjunction cannot be one commit); URL-less repos stay unpinned; a missing
hard ref or unreachable remote fails the launch loud.
- git ships in the API image (the one sanctioned synchronous use: read-only
  ls-remote at launch); a missing binary now names the topology bug
- WorkspaceException maps to 422 with the operator-actionable message
- an IMPLICIT default branch the remote lacks (empty/new repo, stale
  record) launches unpinned; only authored refs fail loud
- ls-remote lines matched by EXACT full ref name (patterns are tail-glob);
  15s timeout on the synchronous path; sha256 OIDs accepted; stored-URL
  userinfo stripped from error messages
- pinned clones stay SHALLOW when the pin is the fetched tip, deepening
  only when the tip advanced (fetch-by-sha, then unshallow) — the common
  launch pays nothing over the pre-S1 clone
- the vector resolves only for projections that consume it (single-agent +
  plan-map); the supervisor lane is threaded in the follow-up
@ppXD
ppXD merged commit 69e6a74 into main Jul 11, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant