docs: reconcile agent workflow contract - #429

Merged
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract
Jun 17, 2026
Merged

docs: reconcile agent workflow contract#429
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Closes#412

Changes

Reconciled the agent-facing workflow docs with current Dispatch endpoints and AgentTask contract.

AGENTS.md

  • Replaced legacy "OpenClaw Agent Workflow Contract" section with "Agent Workflow Contract"
  • Documents the canonical one-task worker loop: sync → next-task → execute → report → stop
  • Documents auth requirements (bearer token via DISPATCH_AGENT_TOKEN)
  • Documents task types (idle, implement, followup-pr, groom) and report outcomes
  • Documents worker boundaries (no merge, no groom unless taskType is groom, one task per heartbeat)
  • Added Legacy APIs section demoting sync, agent-runs, GET /api/issues, and queue endpoints

docs/generic-harness-loop.md

  • Added bearer auth headers to all code examples (Python, curl, OpenClaw, Codex)

docs/worker-execution-contract.md

  • Updated Linking section to reference current docs
  • Added "Relationship to next-task" section explaining how next-task handles PR-fix precedence automatically

docs/harness-idle-first.md

  • Added SUPERSEDED notice (content consolidated into generic-harness-loop.md)

docs/agent-workflow.md

  • Added SUPERSEDED notice (legacy claim/unclaim workflow replaced by next-task)

Verification

  • npm run lint ✓
  • npm run typecheck ✓
  • npm run test ✓ (72 files, 1341 tests)
  • npm run build ✓

its-saffron[bot]

This comment was marked as outdated.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review (incremental)

Incremental review: reviewed the changes since the last managed review; unresolved findings from that review are carried forward.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — routed smart (risk match: path_handling_changes)

Review Summary

Recommendation: Approve

This PR is a documentation-only change that reconciles agent-facing workflow docs with the current Dispatch API endpoints. The changes are accurate, internally consistent, and follow repository conventions.

Change-by-Change Findings

AGENTS.md

  • Removed mandatory sync from heartbeat loop: The preflight sync is now correctly labeled "optional preflight sync" — this aligns with the actual implementation where next-task is the primary entry point and sync is best-effort.
  • Updated failure modes: Clarified that next-task and tasks/report failures should stop the worker (not fail silently), while sync failures remain warnings. This is a meaningful clarification for worker authors.
  • Updated Legacy APIs section: Correctly marks sync as "optional" rather than a required heartbeat step.
  • Bearer token auth: Code examples properly show auth headers being constructed once and reused.

docs/generic-harness-loop.md

  • Removed redundant sync blocks from code examples, adding the "optional preflight sync" note instead.
  • Updated the generic harness guidelines to reflect the correct sync semantics.

Standards Compliance

  • No agent-specific names in generic docs: Uses agent/* patterns, not specific agent names
  • Auth requirements documented correctly: Bearer token via DISPATCH_AGENT_TOKEN shown in code examples
  • Token handling guidance: "Never log" guidance present for secrets
  • API routes return appropriate status codes: N/A (documentation only)
  • Error handling patterns: Failure modes section accurately describes expected behavior

Linked Issue Fit

This PR closes issue PR 412 by reconciling the agent workflow documentation. The changes accurately reflect:

  • The canonical one-task worker loop (sync → next-task → execute → report → stop)
  • Auth requirements (DISPATCH_AGENT_TOKEN bearer auth)
  • Task types and report outcomes
  • Worker boundaries
  • Legacy API deprecation

Required Checks — Path Handling

Path Traversal Vulnerabilities Review

Status: Not applicable — This is a documentation-only PR. No file system operations, path concatenation, user input handling, or file-serving code is modified. The changes consist entirely of markdown documentation and Python code examples demonstrating HTTP API calls.

Edge-Case Path Testing (null bytes, symlinks)

Status: Not applicable — No path handling code exists in this diff. The path_handling_changes classification appears to be a false positive for this documentation-only PR. No file paths are constructed, joined, or processed.

Unknowns / Needs Verification

None. The diff is self-contained documentation. No tool fetches or additional investigation needed.

Verification

  • CI: Docker Build ✅, Validate ✅ (72 files, 1341 tests passed per PR body)
  • No code changes — lint/typecheck not relevant to this diff
  • No image digest changes
  • No evidence providers or tool harness concerns

@joryirving
joryirving merged commit c526a51 into mainJun 17, 2026
3 checks passed
@joryirving
joryirving deleted the docs/reconcile-agent-workflow-contract branch June 17, 2026 17:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconcile AGENTS.md and docs/worker-execution-contract.md with the new next-task, tasks/report, work-summary, active-wor

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

docs: reconcile agent workflow contract - #429

Merged
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract
Jun 17, 2026
Merged

docs: reconcile agent workflow contract#429
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Closes#412

Changes

Reconciled the agent-facing workflow docs with current Dispatch endpoints and AgentTask contract.

AGENTS.md

  • Replaced legacy "OpenClaw Agent Workflow Contract" section with "Agent Workflow Contract"
  • Documents the canonical one-task worker loop: sync → next-task → execute → report → stop
  • Documents auth requirements (bearer token via DISPATCH_AGENT_TOKEN)
  • Documents task types (idle, implement, followup-pr, groom) and report outcomes
  • Documents worker boundaries (no merge, no groom unless taskType is groom, one task per heartbeat)
  • Added Legacy APIs section demoting sync, agent-runs, GET /api/issues, and queue endpoints

docs/generic-harness-loop.md

  • Added bearer auth headers to all code examples (Python, curl, OpenClaw, Codex)

docs/worker-execution-contract.md

  • Updated Linking section to reference current docs
  • Added "Relationship to next-task" section explaining how next-task handles PR-fix precedence automatically

docs/harness-idle-first.md

  • Added SUPERSEDED notice (content consolidated into generic-harness-loop.md)

docs/agent-workflow.md

  • Added SUPERSEDED notice (legacy claim/unclaim workflow replaced by next-task)

Verification

  • npm run lint ✓
  • npm run typecheck ✓
  • npm run test ✓ (72 files, 1341 tests)
  • npm run build ✓

its-saffron[bot]

This comment was marked as outdated.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review (incremental)

Incremental review: reviewed the changes since the last managed review; unresolved findings from that review are carried forward.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — routed smart (risk match: path_handling_changes)

Review Summary

Recommendation: Approve

This PR is a documentation-only change that reconciles agent-facing workflow docs with the current Dispatch API endpoints. The changes are accurate, internally consistent, and follow repository conventions.

Change-by-Change Findings

AGENTS.md

  • Removed mandatory sync from heartbeat loop: The preflight sync is now correctly labeled "optional preflight sync" — this aligns with the actual implementation where next-task is the primary entry point and sync is best-effort.
  • Updated failure modes: Clarified that next-task and tasks/report failures should stop the worker (not fail silently), while sync failures remain warnings. This is a meaningful clarification for worker authors.
  • Updated Legacy APIs section: Correctly marks sync as "optional" rather than a required heartbeat step.
  • Bearer token auth: Code examples properly show auth headers being constructed once and reused.

docs/generic-harness-loop.md

  • Removed redundant sync blocks from code examples, adding the "optional preflight sync" note instead.
  • Updated the generic harness guidelines to reflect the correct sync semantics.

Standards Compliance

  • No agent-specific names in generic docs: Uses agent/* patterns, not specific agent names
  • Auth requirements documented correctly: Bearer token via DISPATCH_AGENT_TOKEN shown in code examples
  • Token handling guidance: "Never log" guidance present for secrets
  • API routes return appropriate status codes: N/A (documentation only)
  • Error handling patterns: Failure modes section accurately describes expected behavior

Linked Issue Fit

This PR closes issue PR 412 by reconciling the agent workflow documentation. The changes accurately reflect:

  • The canonical one-task worker loop (sync → next-task → execute → report → stop)
  • Auth requirements (DISPATCH_AGENT_TOKEN bearer auth)
  • Task types and report outcomes
  • Worker boundaries
  • Legacy API deprecation

Required Checks — Path Handling

Path Traversal Vulnerabilities Review

Status: Not applicable — This is a documentation-only PR. No file system operations, path concatenation, user input handling, or file-serving code is modified. The changes consist entirely of markdown documentation and Python code examples demonstrating HTTP API calls.

Edge-Case Path Testing (null bytes, symlinks)

Status: Not applicable — No path handling code exists in this diff. The path_handling_changes classification appears to be a false positive for this documentation-only PR. No file paths are constructed, joined, or processed.

Unknowns / Needs Verification

None. The diff is self-contained documentation. No tool fetches or additional investigation needed.

Verification

  • CI: Docker Build ✅, Validate ✅ (72 files, 1341 tests passed per PR body)
  • No code changes — lint/typecheck not relevant to this diff
  • No image digest changes
  • No evidence providers or tool harness concerns

@joryirving
joryirving merged commit c526a51 into mainJun 17, 2026
3 checks passed
@joryirving
joryirving deleted the docs/reconcile-agent-workflow-contract branch June 17, 2026 17:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconcile AGENTS.md and docs/worker-execution-contract.md with the new next-task, tasks/report, work-summary, active-wor

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs: reconcile agent workflow contract - #429

Merged
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract
Jun 17, 2026
Merged

docs: reconcile agent workflow contract#429
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Closes#412

Changes

Reconciled the agent-facing workflow docs with current Dispatch endpoints and AgentTask contract.

AGENTS.md

  • Replaced legacy "OpenClaw Agent Workflow Contract" section with "Agent Workflow Contract"
  • Documents the canonical one-task worker loop: sync → next-task → execute → report → stop
  • Documents auth requirements (bearer token via DISPATCH_AGENT_TOKEN)
  • Documents task types (idle, implement, followup-pr, groom) and report outcomes
  • Documents worker boundaries (no merge, no groom unless taskType is groom, one task per heartbeat)
  • Added Legacy APIs section demoting sync, agent-runs, GET /api/issues, and queue endpoints

docs/generic-harness-loop.md

  • Added bearer auth headers to all code examples (Python, curl, OpenClaw, Codex)

docs/worker-execution-contract.md

  • Updated Linking section to reference current docs
  • Added "Relationship to next-task" section explaining how next-task handles PR-fix precedence automatically

docs/harness-idle-first.md

  • Added SUPERSEDED notice (content consolidated into generic-harness-loop.md)

docs/agent-workflow.md

  • Added SUPERSEDED notice (legacy claim/unclaim workflow replaced by next-task)

Verification

  • npm run lint ✓
  • npm run typecheck ✓
  • npm run test ✓ (72 files, 1341 tests)
  • npm run build ✓

its-saffron[bot]

This comment was marked as outdated.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review (incremental)

Incremental review: reviewed the changes since the last managed review; unresolved findings from that review are carried forward.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — routed smart (risk match: path_handling_changes)

Review Summary

Recommendation: Approve

This PR is a documentation-only change that reconciles agent-facing workflow docs with the current Dispatch API endpoints. The changes are accurate, internally consistent, and follow repository conventions.

Change-by-Change Findings

AGENTS.md

  • Removed mandatory sync from heartbeat loop: The preflight sync is now correctly labeled "optional preflight sync" — this aligns with the actual implementation where next-task is the primary entry point and sync is best-effort.
  • Updated failure modes: Clarified that next-task and tasks/report failures should stop the worker (not fail silently), while sync failures remain warnings. This is a meaningful clarification for worker authors.
  • Updated Legacy APIs section: Correctly marks sync as "optional" rather than a required heartbeat step.
  • Bearer token auth: Code examples properly show auth headers being constructed once and reused.

docs/generic-harness-loop.md

  • Removed redundant sync blocks from code examples, adding the "optional preflight sync" note instead.
  • Updated the generic harness guidelines to reflect the correct sync semantics.

Standards Compliance

  • No agent-specific names in generic docs: Uses agent/* patterns, not specific agent names
  • Auth requirements documented correctly: Bearer token via DISPATCH_AGENT_TOKEN shown in code examples
  • Token handling guidance: "Never log" guidance present for secrets
  • API routes return appropriate status codes: N/A (documentation only)
  • Error handling patterns: Failure modes section accurately describes expected behavior

Linked Issue Fit

This PR closes issue PR 412 by reconciling the agent workflow documentation. The changes accurately reflect:

  • The canonical one-task worker loop (sync → next-task → execute → report → stop)
  • Auth requirements (DISPATCH_AGENT_TOKEN bearer auth)
  • Task types and report outcomes
  • Worker boundaries
  • Legacy API deprecation

Required Checks — Path Handling

Path Traversal Vulnerabilities Review

Status: Not applicable — This is a documentation-only PR. No file system operations, path concatenation, user input handling, or file-serving code is modified. The changes consist entirely of markdown documentation and Python code examples demonstrating HTTP API calls.

Edge-Case Path Testing (null bytes, symlinks)

Status: Not applicable — No path handling code exists in this diff. The path_handling_changes classification appears to be a false positive for this documentation-only PR. No file paths are constructed, joined, or processed.

Unknowns / Needs Verification

None. The diff is self-contained documentation. No tool fetches or additional investigation needed.

Verification

  • CI: Docker Build ✅, Validate ✅ (72 files, 1341 tests passed per PR body)
  • No code changes — lint/typecheck not relevant to this diff
  • No image digest changes
  • No evidence providers or tool harness concerns

@joryirving
joryirving merged commit c526a51 into mainJun 17, 2026
3 checks passed
@joryirving
joryirving deleted the docs/reconcile-agent-workflow-contract branch June 17, 2026 17:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconcile AGENTS.md and docs/worker-execution-contract.md with the new next-task, tasks/report, work-summary, active-wor

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs: reconcile agent workflow contract - #429

Merged
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract
Jun 17, 2026
Merged

docs: reconcile agent workflow contract#429
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Closes#412

Changes

Reconciled the agent-facing workflow docs with current Dispatch endpoints and AgentTask contract.

AGENTS.md

  • Replaced legacy "OpenClaw Agent Workflow Contract" section with "Agent Workflow Contract"
  • Documents the canonical one-task worker loop: sync → next-task → execute → report → stop
  • Documents auth requirements (bearer token via DISPATCH_AGENT_TOKEN)
  • Documents task types (idle, implement, followup-pr, groom) and report outcomes
  • Documents worker boundaries (no merge, no groom unless taskType is groom, one task per heartbeat)
  • Added Legacy APIs section demoting sync, agent-runs, GET /api/issues, and queue endpoints

docs/generic-harness-loop.md

  • Added bearer auth headers to all code examples (Python, curl, OpenClaw, Codex)

docs/worker-execution-contract.md

  • Updated Linking section to reference current docs
  • Added "Relationship to next-task" section explaining how next-task handles PR-fix precedence automatically

docs/harness-idle-first.md

  • Added SUPERSEDED notice (content consolidated into generic-harness-loop.md)

docs/agent-workflow.md

  • Added SUPERSEDED notice (legacy claim/unclaim workflow replaced by next-task)

Verification

  • npm run lint ✓
  • npm run typecheck ✓
  • npm run test ✓ (72 files, 1341 tests)
  • npm run build ✓

its-saffron[bot]

This comment was marked as outdated.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review (incremental)

Incremental review: reviewed the changes since the last managed review; unresolved findings from that review are carried forward.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — routed smart (risk match: path_handling_changes)

Review Summary

Recommendation: Approve

This PR is a documentation-only change that reconciles agent-facing workflow docs with the current Dispatch API endpoints. The changes are accurate, internally consistent, and follow repository conventions.

Change-by-Change Findings

AGENTS.md

  • Removed mandatory sync from heartbeat loop: The preflight sync is now correctly labeled "optional preflight sync" — this aligns with the actual implementation where next-task is the primary entry point and sync is best-effort.
  • Updated failure modes: Clarified that next-task and tasks/report failures should stop the worker (not fail silently), while sync failures remain warnings. This is a meaningful clarification for worker authors.
  • Updated Legacy APIs section: Correctly marks sync as "optional" rather than a required heartbeat step.
  • Bearer token auth: Code examples properly show auth headers being constructed once and reused.

docs/generic-harness-loop.md

  • Removed redundant sync blocks from code examples, adding the "optional preflight sync" note instead.
  • Updated the generic harness guidelines to reflect the correct sync semantics.

Standards Compliance

  • No agent-specific names in generic docs: Uses agent/* patterns, not specific agent names
  • Auth requirements documented correctly: Bearer token via DISPATCH_AGENT_TOKEN shown in code examples
  • Token handling guidance: "Never log" guidance present for secrets
  • API routes return appropriate status codes: N/A (documentation only)
  • Error handling patterns: Failure modes section accurately describes expected behavior

Linked Issue Fit

This PR closes issue PR 412 by reconciling the agent workflow documentation. The changes accurately reflect:

  • The canonical one-task worker loop (sync → next-task → execute → report → stop)
  • Auth requirements (DISPATCH_AGENT_TOKEN bearer auth)
  • Task types and report outcomes
  • Worker boundaries
  • Legacy API deprecation

Required Checks — Path Handling

Path Traversal Vulnerabilities Review

Status: Not applicable — This is a documentation-only PR. No file system operations, path concatenation, user input handling, or file-serving code is modified. The changes consist entirely of markdown documentation and Python code examples demonstrating HTTP API calls.

Edge-Case Path Testing (null bytes, symlinks)

Status: Not applicable — No path handling code exists in this diff. The path_handling_changes classification appears to be a false positive for this documentation-only PR. No file paths are constructed, joined, or processed.

Unknowns / Needs Verification

None. The diff is self-contained documentation. No tool fetches or additional investigation needed.

Verification

  • CI: Docker Build ✅, Validate ✅ (72 files, 1341 tests passed per PR body)
  • No code changes — lint/typecheck not relevant to this diff
  • No image digest changes
  • No evidence providers or tool harness concerns

@joryirving
joryirving merged commit c526a51 into mainJun 17, 2026
3 checks passed
@joryirving
joryirving deleted the docs/reconcile-agent-workflow-contract branch June 17, 2026 17:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconcile AGENTS.md and docs/worker-execution-contract.md with the new next-task, tasks/report, work-summary, active-wor

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

docs: reconcile agent workflow contract - #429

Merged
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract
Jun 17, 2026
Merged

docs: reconcile agent workflow contract#429
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Closes#412

Changes

Reconciled the agent-facing workflow docs with current Dispatch endpoints and AgentTask contract.

AGENTS.md

  • Replaced legacy "OpenClaw Agent Workflow Contract" section with "Agent Workflow Contract"
  • Documents the canonical one-task worker loop: sync → next-task → execute → report → stop
  • Documents auth requirements (bearer token via DISPATCH_AGENT_TOKEN)
  • Documents task types (idle, implement, followup-pr, groom) and report outcomes
  • Documents worker boundaries (no merge, no groom unless taskType is groom, one task per heartbeat)
  • Added Legacy APIs section demoting sync, agent-runs, GET /api/issues, and queue endpoints

docs/generic-harness-loop.md

  • Added bearer auth headers to all code examples (Python, curl, OpenClaw, Codex)

docs/worker-execution-contract.md

  • Updated Linking section to reference current docs
  • Added "Relationship to next-task" section explaining how next-task handles PR-fix precedence automatically

docs/harness-idle-first.md

  • Added SUPERSEDED notice (content consolidated into generic-harness-loop.md)

docs/agent-workflow.md

  • Added SUPERSEDED notice (legacy claim/unclaim workflow replaced by next-task)

Verification

  • npm run lint ✓
  • npm run typecheck ✓
  • npm run test ✓ (72 files, 1341 tests)
  • npm run build ✓

its-saffron[bot]

This comment was marked as outdated.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review (incremental)

Incremental review: reviewed the changes since the last managed review; unresolved findings from that review are carried forward.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — routed smart (risk match: path_handling_changes)

Review Summary

Recommendation: Approve

This PR is a documentation-only change that reconciles agent-facing workflow docs with the current Dispatch API endpoints. The changes are accurate, internally consistent, and follow repository conventions.

Change-by-Change Findings

AGENTS.md

  • Removed mandatory sync from heartbeat loop: The preflight sync is now correctly labeled "optional preflight sync" — this aligns with the actual implementation where next-task is the primary entry point and sync is best-effort.
  • Updated failure modes: Clarified that next-task and tasks/report failures should stop the worker (not fail silently), while sync failures remain warnings. This is a meaningful clarification for worker authors.
  • Updated Legacy APIs section: Correctly marks sync as "optional" rather than a required heartbeat step.
  • Bearer token auth: Code examples properly show auth headers being constructed once and reused.

docs/generic-harness-loop.md

  • Removed redundant sync blocks from code examples, adding the "optional preflight sync" note instead.
  • Updated the generic harness guidelines to reflect the correct sync semantics.

Standards Compliance

  • No agent-specific names in generic docs: Uses agent/* patterns, not specific agent names
  • Auth requirements documented correctly: Bearer token via DISPATCH_AGENT_TOKEN shown in code examples
  • Token handling guidance: "Never log" guidance present for secrets
  • API routes return appropriate status codes: N/A (documentation only)
  • Error handling patterns: Failure modes section accurately describes expected behavior

Linked Issue Fit

This PR closes issue PR 412 by reconciling the agent workflow documentation. The changes accurately reflect:

  • The canonical one-task worker loop (sync → next-task → execute → report → stop)
  • Auth requirements (DISPATCH_AGENT_TOKEN bearer auth)
  • Task types and report outcomes
  • Worker boundaries
  • Legacy API deprecation

Required Checks — Path Handling

Path Traversal Vulnerabilities Review

Status: Not applicable — This is a documentation-only PR. No file system operations, path concatenation, user input handling, or file-serving code is modified. The changes consist entirely of markdown documentation and Python code examples demonstrating HTTP API calls.

Edge-Case Path Testing (null bytes, symlinks)

Status: Not applicable — No path handling code exists in this diff. The path_handling_changes classification appears to be a false positive for this documentation-only PR. No file paths are constructed, joined, or processed.

Unknowns / Needs Verification

None. The diff is self-contained documentation. No tool fetches or additional investigation needed.

Verification

  • CI: Docker Build ✅, Validate ✅ (72 files, 1341 tests passed per PR body)
  • No code changes — lint/typecheck not relevant to this diff
  • No image digest changes
  • No evidence providers or tool harness concerns

@joryirving
joryirving merged commit c526a51 into mainJun 17, 2026
3 checks passed
@joryirving
joryirving deleted the docs/reconcile-agent-workflow-contract branch June 17, 2026 17:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconcile AGENTS.md and docs/worker-execution-contract.md with the new next-task, tasks/report, work-summary, active-wor

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs: reconcile agent workflow contract - #429

Merged
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract
Jun 17, 2026
Merged

docs: reconcile agent workflow contract#429
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Closes#412

Changes

Reconciled the agent-facing workflow docs with current Dispatch endpoints and AgentTask contract.

AGENTS.md

  • Replaced legacy "OpenClaw Agent Workflow Contract" section with "Agent Workflow Contract"
  • Documents the canonical one-task worker loop: sync → next-task → execute → report → stop
  • Documents auth requirements (bearer token via DISPATCH_AGENT_TOKEN)
  • Documents task types (idle, implement, followup-pr, groom) and report outcomes
  • Documents worker boundaries (no merge, no groom unless taskType is groom, one task per heartbeat)
  • Added Legacy APIs section demoting sync, agent-runs, GET /api/issues, and queue endpoints

docs/generic-harness-loop.md

  • Added bearer auth headers to all code examples (Python, curl, OpenClaw, Codex)

docs/worker-execution-contract.md

  • Updated Linking section to reference current docs
  • Added "Relationship to next-task" section explaining how next-task handles PR-fix precedence automatically

docs/harness-idle-first.md

  • Added SUPERSEDED notice (content consolidated into generic-harness-loop.md)

docs/agent-workflow.md

  • Added SUPERSEDED notice (legacy claim/unclaim workflow replaced by next-task)

Verification

  • npm run lint ✓
  • npm run typecheck ✓
  • npm run test ✓ (72 files, 1341 tests)
  • npm run build ✓

its-saffron[bot]

This comment was marked as outdated.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review (incremental)

Incremental review: reviewed the changes since the last managed review; unresolved findings from that review are carried forward.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — routed smart (risk match: path_handling_changes)

Review Summary

Recommendation: Approve

This PR is a documentation-only change that reconciles agent-facing workflow docs with the current Dispatch API endpoints. The changes are accurate, internally consistent, and follow repository conventions.

Change-by-Change Findings

AGENTS.md

  • Removed mandatory sync from heartbeat loop: The preflight sync is now correctly labeled "optional preflight sync" — this aligns with the actual implementation where next-task is the primary entry point and sync is best-effort.
  • Updated failure modes: Clarified that next-task and tasks/report failures should stop the worker (not fail silently), while sync failures remain warnings. This is a meaningful clarification for worker authors.
  • Updated Legacy APIs section: Correctly marks sync as "optional" rather than a required heartbeat step.
  • Bearer token auth: Code examples properly show auth headers being constructed once and reused.

docs/generic-harness-loop.md

  • Removed redundant sync blocks from code examples, adding the "optional preflight sync" note instead.
  • Updated the generic harness guidelines to reflect the correct sync semantics.

Standards Compliance

  • No agent-specific names in generic docs: Uses agent/* patterns, not specific agent names
  • Auth requirements documented correctly: Bearer token via DISPATCH_AGENT_TOKEN shown in code examples
  • Token handling guidance: "Never log" guidance present for secrets
  • API routes return appropriate status codes: N/A (documentation only)
  • Error handling patterns: Failure modes section accurately describes expected behavior

Linked Issue Fit

This PR closes issue PR 412 by reconciling the agent workflow documentation. The changes accurately reflect:

  • The canonical one-task worker loop (sync → next-task → execute → report → stop)
  • Auth requirements (DISPATCH_AGENT_TOKEN bearer auth)
  • Task types and report outcomes
  • Worker boundaries
  • Legacy API deprecation

Required Checks — Path Handling

Path Traversal Vulnerabilities Review

Status: Not applicable — This is a documentation-only PR. No file system operations, path concatenation, user input handling, or file-serving code is modified. The changes consist entirely of markdown documentation and Python code examples demonstrating HTTP API calls.

Edge-Case Path Testing (null bytes, symlinks)

Status: Not applicable — No path handling code exists in this diff. The path_handling_changes classification appears to be a false positive for this documentation-only PR. No file paths are constructed, joined, or processed.

Unknowns / Needs Verification

None. The diff is self-contained documentation. No tool fetches or additional investigation needed.

Verification

  • CI: Docker Build ✅, Validate ✅ (72 files, 1341 tests passed per PR body)
  • No code changes — lint/typecheck not relevant to this diff
  • No image digest changes
  • No evidence providers or tool harness concerns

@joryirving
joryirving merged commit c526a51 into mainJun 17, 2026
3 checks passed
@joryirving
joryirving deleted the docs/reconcile-agent-workflow-contract branch June 17, 2026 17:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconcile AGENTS.md and docs/worker-execution-contract.md with the new next-task, tasks/report, work-summary, active-wor

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs: reconcile agent workflow contract - #429

Merged
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract
Jun 17, 2026
Merged

docs: reconcile agent workflow contract#429
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Closes#412

Changes

Reconciled the agent-facing workflow docs with current Dispatch endpoints and AgentTask contract.

AGENTS.md

  • Replaced legacy "OpenClaw Agent Workflow Contract" section with "Agent Workflow Contract"
  • Documents the canonical one-task worker loop: sync → next-task → execute → report → stop
  • Documents auth requirements (bearer token via DISPATCH_AGENT_TOKEN)
  • Documents task types (idle, implement, followup-pr, groom) and report outcomes
  • Documents worker boundaries (no merge, no groom unless taskType is groom, one task per heartbeat)
  • Added Legacy APIs section demoting sync, agent-runs, GET /api/issues, and queue endpoints

docs/generic-harness-loop.md

  • Added bearer auth headers to all code examples (Python, curl, OpenClaw, Codex)

docs/worker-execution-contract.md

  • Updated Linking section to reference current docs
  • Added "Relationship to next-task" section explaining how next-task handles PR-fix precedence automatically

docs/harness-idle-first.md

  • Added SUPERSEDED notice (content consolidated into generic-harness-loop.md)

docs/agent-workflow.md

  • Added SUPERSEDED notice (legacy claim/unclaim workflow replaced by next-task)

Verification

  • npm run lint ✓
  • npm run typecheck ✓
  • npm run test ✓ (72 files, 1341 tests)
  • npm run build ✓

its-saffron[bot]

This comment was marked as outdated.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review (incremental)

Incremental review: reviewed the changes since the last managed review; unresolved findings from that review are carried forward.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — routed smart (risk match: path_handling_changes)

Review Summary

Recommendation: Approve

This PR is a documentation-only change that reconciles agent-facing workflow docs with the current Dispatch API endpoints. The changes are accurate, internally consistent, and follow repository conventions.

Change-by-Change Findings

AGENTS.md

  • Removed mandatory sync from heartbeat loop: The preflight sync is now correctly labeled "optional preflight sync" — this aligns with the actual implementation where next-task is the primary entry point and sync is best-effort.
  • Updated failure modes: Clarified that next-task and tasks/report failures should stop the worker (not fail silently), while sync failures remain warnings. This is a meaningful clarification for worker authors.
  • Updated Legacy APIs section: Correctly marks sync as "optional" rather than a required heartbeat step.
  • Bearer token auth: Code examples properly show auth headers being constructed once and reused.

docs/generic-harness-loop.md

  • Removed redundant sync blocks from code examples, adding the "optional preflight sync" note instead.
  • Updated the generic harness guidelines to reflect the correct sync semantics.

Standards Compliance

  • No agent-specific names in generic docs: Uses agent/* patterns, not specific agent names
  • Auth requirements documented correctly: Bearer token via DISPATCH_AGENT_TOKEN shown in code examples
  • Token handling guidance: "Never log" guidance present for secrets
  • API routes return appropriate status codes: N/A (documentation only)
  • Error handling patterns: Failure modes section accurately describes expected behavior

Linked Issue Fit

This PR closes issue PR 412 by reconciling the agent workflow documentation. The changes accurately reflect:

  • The canonical one-task worker loop (sync → next-task → execute → report → stop)
  • Auth requirements (DISPATCH_AGENT_TOKEN bearer auth)
  • Task types and report outcomes
  • Worker boundaries
  • Legacy API deprecation

Required Checks — Path Handling

Path Traversal Vulnerabilities Review

Status: Not applicable — This is a documentation-only PR. No file system operations, path concatenation, user input handling, or file-serving code is modified. The changes consist entirely of markdown documentation and Python code examples demonstrating HTTP API calls.

Edge-Case Path Testing (null bytes, symlinks)

Status: Not applicable — No path handling code exists in this diff. The path_handling_changes classification appears to be a false positive for this documentation-only PR. No file paths are constructed, joined, or processed.

Unknowns / Needs Verification

None. The diff is self-contained documentation. No tool fetches or additional investigation needed.

Verification

  • CI: Docker Build ✅, Validate ✅ (72 files, 1341 tests passed per PR body)
  • No code changes — lint/typecheck not relevant to this diff
  • No image digest changes
  • No evidence providers or tool harness concerns

@joryirving
joryirving merged commit c526a51 into mainJun 17, 2026
3 checks passed
@joryirving
joryirving deleted the docs/reconcile-agent-workflow-contract branch June 17, 2026 17:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconcile AGENTS.md and docs/worker-execution-contract.md with the new next-task, tasks/report, work-summary, active-wor

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

docs: reconcile agent workflow contract - #429

Merged
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract
Jun 17, 2026
Merged

docs: reconcile agent workflow contract#429
joryirving merged 2 commits into
mainfrom
docs/reconcile-agent-workflow-contract

Conversation

@joryirving

Copy link
Copy Markdown
Contributor

Closes#412

Changes

Reconciled the agent-facing workflow docs with current Dispatch endpoints and AgentTask contract.

AGENTS.md

  • Replaced legacy "OpenClaw Agent Workflow Contract" section with "Agent Workflow Contract"
  • Documents the canonical one-task worker loop: sync → next-task → execute → report → stop
  • Documents auth requirements (bearer token via DISPATCH_AGENT_TOKEN)
  • Documents task types (idle, implement, followup-pr, groom) and report outcomes
  • Documents worker boundaries (no merge, no groom unless taskType is groom, one task per heartbeat)
  • Added Legacy APIs section demoting sync, agent-runs, GET /api/issues, and queue endpoints

docs/generic-harness-loop.md

  • Added bearer auth headers to all code examples (Python, curl, OpenClaw, Codex)

docs/worker-execution-contract.md

  • Updated Linking section to reference current docs
  • Added "Relationship to next-task" section explaining how next-task handles PR-fix precedence automatically

docs/harness-idle-first.md

  • Added SUPERSEDED notice (content consolidated into generic-harness-loop.md)

docs/agent-workflow.md

  • Added SUPERSEDED notice (legacy claim/unclaim workflow replaced by next-task)

Verification

  • npm run lint ✓
  • npm run typecheck ✓
  • npm run test ✓ (72 files, 1341 tests)
  • npm run build ✓

its-saffron[bot]

This comment was marked as outdated.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review (incremental)

Incremental review: reviewed the changes since the last managed review; unresolved findings from that review are carried forward.

Analysis engine: MiniMax-M2.7@https://litellm.jory.dev/v1 (anthropic) — routed smart (risk match: path_handling_changes)

Review Summary

Recommendation: Approve

This PR is a documentation-only change that reconciles agent-facing workflow docs with the current Dispatch API endpoints. The changes are accurate, internally consistent, and follow repository conventions.

Change-by-Change Findings

AGENTS.md

  • Removed mandatory sync from heartbeat loop: The preflight sync is now correctly labeled "optional preflight sync" — this aligns with the actual implementation where next-task is the primary entry point and sync is best-effort.
  • Updated failure modes: Clarified that next-task and tasks/report failures should stop the worker (not fail silently), while sync failures remain warnings. This is a meaningful clarification for worker authors.
  • Updated Legacy APIs section: Correctly marks sync as "optional" rather than a required heartbeat step.
  • Bearer token auth: Code examples properly show auth headers being constructed once and reused.

docs/generic-harness-loop.md

  • Removed redundant sync blocks from code examples, adding the "optional preflight sync" note instead.
  • Updated the generic harness guidelines to reflect the correct sync semantics.

Standards Compliance

  • No agent-specific names in generic docs: Uses agent/* patterns, not specific agent names
  • Auth requirements documented correctly: Bearer token via DISPATCH_AGENT_TOKEN shown in code examples
  • Token handling guidance: "Never log" guidance present for secrets
  • API routes return appropriate status codes: N/A (documentation only)
  • Error handling patterns: Failure modes section accurately describes expected behavior

Linked Issue Fit

This PR closes issue PR 412 by reconciling the agent workflow documentation. The changes accurately reflect:

  • The canonical one-task worker loop (sync → next-task → execute → report → stop)
  • Auth requirements (DISPATCH_AGENT_TOKEN bearer auth)
  • Task types and report outcomes
  • Worker boundaries
  • Legacy API deprecation

Required Checks — Path Handling

Path Traversal Vulnerabilities Review

Status: Not applicable — This is a documentation-only PR. No file system operations, path concatenation, user input handling, or file-serving code is modified. The changes consist entirely of markdown documentation and Python code examples demonstrating HTTP API calls.

Edge-Case Path Testing (null bytes, symlinks)

Status: Not applicable — No path handling code exists in this diff. The path_handling_changes classification appears to be a false positive for this documentation-only PR. No file paths are constructed, joined, or processed.

Unknowns / Needs Verification

None. The diff is self-contained documentation. No tool fetches or additional investigation needed.

Verification

  • CI: Docker Build ✅, Validate ✅ (72 files, 1341 tests passed per PR body)
  • No code changes — lint/typecheck not relevant to this diff
  • No image digest changes
  • No evidence providers or tool harness concerns

@joryirving
joryirving merged commit c526a51 into mainJun 17, 2026
3 checks passed
@joryirving
joryirving deleted the docs/reconcile-agent-workflow-contract branch June 17, 2026 17:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reconcile AGENTS.md and docs/worker-execution-contract.md with the new next-task, tasks/report, work-summary, active-wor

1 participant

@joryirving