Skip to content

Keep model-authored acceptance from carrying a setup command - #2079

Merged
ppXD merged 1 commit into
mainfrom
fix/keep-model-authored-acceptance-from-carrying-setup
Oct 7, 2026
Merged

ppXD merged 1 commit into
mainfrom
fix/keep-model-authored-acceptance-from-carrying-setup

Conversation

@ppXD

@ppXD ppXD commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Summary

  • A supervisor reply could author acceptance.setupCommand and acceptance.timeoutSeconds.
    • The schema never offers them, but its additionalProperties:false is advisory (JsonSchemaValidator does not read it), and a schema-less fallback carries no schema at all.
    • The projector froze both into the ledger, and every supervisor grading lane ran them.
    • ModelAuthoredAcceptanceConverter now sits on the four decision slots: plan subtask, plan phase, stop, and amend replacement. It drops both knobs on read and on write, which also covers ledger rows stored before this change.
    • Operator specs (node config, AgentTask.Acceptance) keep both.
  • The grader bounds every step's window (setup, check, oracle-restore git): 0 or less grades at 300 s, and anything above 3600 s is capped at SupervisorLane.MaxAcceptanceGradeTimeoutSeconds. The supervisor lanes never validate the contract, which is why the bound lives in the grader.
  • An operator contract is validated, so it is no longer rewritten silently.
    • AgentAcceptanceContract.ValidateAuthored refuses a timeoutSeconds outside 1..3600 and names the ceiling.
    • agent.code fails at staging.
    • The executor's and local verifier's contract check fails closed as SpecIncomplete before anything runs.
  • SupervisorTurnService.ReadStopAcceptance is internal and pinned directly. The stop-gate stored-row test now exercises the production reader, not a copy.
  • The GradeDirectoryAsync doc no longer claims that grading the live workspace is equivalent to grading a clone. OraclePaths pin only literal files.
  • Owner-visible changes:
    • A stored workflow whose acceptance timeoutSeconds is 0 or less, or above 3600, now fails at staging with a named message instead of grading under a rewritten window.
    • In-flight supervisor decisions that already carried either knob grade without it from the next fold.
    • EvaluatorVersion moves to supervisor-acceptance/v8.

Test plan

  • Unit: an 8-case route × stored-row Theory (plan fold, spawn, stop gate, amend overlay); a write-side strip; operator round-trip; member-classification pin; bounded-window Theory; the ValidateAuthored window Theory; agent.code staging Theory (7200 / 0 refused, 900 kept)
  • Integration: SupervisorModelAcceptanceSetupFlowTests; LocalAcceptanceVerifierFlowTests (an out-of-range window is SpecIncomplete and runs nothing)
  • Regression: full unit suite (11875 passed, 1 skipped); integration Acceptance|TaskLaunchFlow|PlanMap|AgentNodeFlow|SupervisorStop (287 passed)
  • Mutation: disabling the window rule fails 6 rows; reading the stop acceptance around the converter fails the stop-gate row

A supervisor reply could author acceptance.setupCommand and
acceptance.timeoutSeconds even though the decision schema never offers
them. The server's schema check does not read additionalProperties, a
schema-less fallback request carries no schema at all, and the bind
maps any member SupervisorAcceptanceSpec declares. The projector froze
both into the ledger, and every supervisor grading lane handed them to
the grader, which ran the setup argv in the grading workspace (with
host network under bubblewrap) and read a timeout of 0 as no wall
clock at all.

ModelAuthoredAcceptanceConverter now sits on the four acceptance slots
a supervisor decision carries (plan subtask, plan phase, stop, amend
replacement) and drops both knobs on read and on write. Because it is
on the slot, it also covers ledger rows written before this change,
which the rehydrate re-reads on every turn. Operator specs (node
config, AgentTask.Acceptance) keep both.

The grader now bounds every step's window itself (setup, check and the
oracle restore's git commands), because the supervisor lanes never
validate the contract first: a non-positive value grades at the 300 s
default and anything longer is capped at 3600 s. EvaluatorVersion
moves to v8 for that change.

An operator contract is validated, so it is no longer rewritten
silently: ValidateAuthored refuses a timeoutSeconds outside 1..3600
with a message naming the ceiling. agent.code fails at staging, and
the executor's and local verifier's contract check fails closed as
SpecIncomplete before anything runs. Only lanes that never validate
still rely on the grader's bound.

The stop gate's reader is now internal and pinned directly, so the
stored-row test exercises the production reader instead of a copy.

GradeDirectoryAsync's doc no longer claims that grading the agent's
live directory is equivalent to grading a clone.
@ppXD
ppXD merged commit 0c9b383 into main Oct 7, 2026
6 checks passed
@ppXD
ppXD deleted the fix/keep-model-authored-acceptance-from-carrying-setup branch October 7, 2026 04:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant