Quest: Resume workflows with their Workspace, repositories, and Agent state #218

Description

@taras

Story

As a workflow author, I want xmd workflow to retain one provider-backed
Workspace with the run's journal, repositories, and Agent state, so supervised
procedures resume after interruption without reconstructing hidden filesystem or
transcript state.

Settled contract

PR #358 records the normative architecture in architecture.md and
specs/workflow-workspace-spec.md:

  • xmd run uses the caller's current environment and makes no restoration
    guarantee; xmd workflow owns one retained WorkflowRun and implicit root
    Workspace.
  • One SQLite database holds logically separate filtered journal, versioned DOFS,
    Repository/Worktree metadata, and Agent-session stores.
  • One expansion produces one effect and one Workspace transaction. Completed
    durable effects restore their results, ephemeral attachments rebuild the live
    Effection tree, and partial replay continues from the retained frontier.
  • Missing or corrupt authoritative Workspace state is unrecoverable rather than
    silently replaced.
  • Workflow Agents receive no Workspace materialization or additional
    directories. They request observations and propose mutations as constrained
    generated XMD executed by the host.
  • Prompt, Git-host, Issue, and other external effects reconcile stable identity
    at their owning provider boundary; they do not claim cross-system atomicity.
  • Public lifecycle operations remain host-neutral and preserve one executor
    authority.

This issue is the implementation umbrella. Child issues own executable
acceptance detail; this body owns the shared invariants and current closure map.

Current delivery state

The retained lifecycle, history, named Repository/Worktree composition, local
Git and Git-host effects, provider-neutral Issue and Fetch effects, ambient
authentication, authorized workflow component bundle, generated-XMD observation
and mutation admission, retained Agent sessions, durable answer delivery,
explicit ordinary-resume scheduling, adversarial composition, and end-to-end
certification are all implemented.

PR #181 contains the remaining integrated delivery. At exact head
e85479c33ce4c91d821e0eaf195150db374ae4a6 over base and merge base
6717e867c9467114e6b060620d5b18c87beb2c48, #299 recorded certification PASS.
All frozen commands passed, including both source and compiled entrypoints,
CF1-CF6, the 31-file owner matrix, Node and Bun WFH rows, typing,
publishability, and the frozen verification task.

The only remaining PR-local work is #292's truthful synchronization of the
living workflow and delivery records. #290's document proof, #301's complete
composition, and #300's explicit scheduling slice are implemented on PR #181;
those issues close with the PR rather than receiving another product pass.

Remaining order

  1. Implement Make the adversarial implementation workflow accurately describe its behavior #292 against the exact certified PR head and obtain Planner PASS
    on one focused feedback commit.
  2. Integrate that commit, refresh PR ✨ Compose and certify the supervised adversarial implementation workflow #181's title/body, and run the applicable
    delivery gate and required CI.
  3. Mark the PR ready, obtain required review, and merge.
  4. Close Test the adversarial planning workflow with shipped components #290, Deliver answers to suspended workflows for later resumption #300, Compose the supervised adversarial implementation workflow #301, Make the adversarial implementation workflow accurately describe its behavior #292, and this umbrella through the delivered merge.

No later hardening issue is inserted into this gate:

Cross-cutting invariants

  • WorkflowRun establishment and base pinning precede Workspace attachment.
  • Shared production modules use contextual APIs and contain no runtime or
    provider detection.
  • One authoritative host-owned DOFS connection serves a workflow database and
    serializes Workspace-local effects.
  • Security filtering occurs before journal insertion; co-located Workspace
    content is not automatically journal or training data.
  • Completed replay attaches no Workspace, Agent, process, Git-host, Issue, or
    Fetch provider.
  • Status, list, and history are read-only and cannot advance a run.
  • No required state exists only in a transcript, host path, provider handle,
    branch name, or Git sidecar ref.
  • External effects reconcile stable identity and never claim atomicity across
    SQLite and a provider.
  • Answer delivery records without executing. Manual and explicit trusted-host
    scheduling invoke the same ordinary resume path and executor lock. No watcher,
    delivery-to-resume wiring, unattended arbitration, or second executor ships.
  • An Agent reaches the Workspace only as data: it names source and XMD admits
    and executes it. Generated Git, Git-host, Issue, process, credential, and
    other external effects remain outside the admitted classes.

Completion

This umbrella closes when PR #181 merges after #292 synchronization and the
normal delivery gate. Transactional Worker Shell, portable adapter-level
no-tool enforcement, the ordinary host-filesystem race, and the unrelated
error-printing correction remain independent follow-ups.

Intentionally excluded

  • A public remote-host selector or deployed XMD service.
  • Worker Shell or Worker JavaScript in the initial topology.
  • Native subprocess execution, writable FUSE, bundled workerd, or Containers.
  • Watchers, automatic answer-to-resume wiring, and unattended iteration
    arbitration.
  • Human actor attestation.
  • Automatic ingestion or arbitrary scanning of Workspace files.
  • Recovery from deleted or corrupt authoritative Workspace state.
  • Rewinding external systems during a history fork.

Authoritative evidence

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    questCoordinating story with dependency-ordered sub-issues

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
      Skip to content

      Quest: Resume workflows with their Workspace, repositories, and Agent state #218

      Description

      @taras

      Story

      As a workflow author, I want xmd workflow to retain one provider-backed
      Workspace with the run's journal, repositories, and Agent state, so supervised
      procedures resume after interruption without reconstructing hidden filesystem or
      transcript state.

      Settled contract

      PR #358 records the normative architecture in architecture.md and
      specs/workflow-workspace-spec.md:

      • xmd run uses the caller's current environment and makes no restoration
        guarantee; xmd workflow owns one retained WorkflowRun and implicit root
        Workspace.
      • One SQLite database holds logically separate filtered journal, versioned DOFS,
        Repository/Worktree metadata, and Agent-session stores.
      • One expansion produces one effect and one Workspace transaction. Completed
        durable effects restore their results, ephemeral attachments rebuild the live
        Effection tree, and partial replay continues from the retained frontier.
      • Missing or corrupt authoritative Workspace state is unrecoverable rather than
        silently replaced.
      • Workflow Agents receive no Workspace materialization or additional
        directories. They request observations and propose mutations as constrained
        generated XMD executed by the host.
      • Prompt, Git-host, Issue, and other external effects reconcile stable identity
        at their owning provider boundary; they do not claim cross-system atomicity.
      • Public lifecycle operations remain host-neutral and preserve one executor
        authority.

      This issue is the implementation umbrella. Child issues own executable
      acceptance detail; this body owns the shared invariants and current closure map.

      Current delivery state

      The retained lifecycle, history, named Repository/Worktree composition, local
      Git and Git-host effects, provider-neutral Issue and Fetch effects, ambient
      authentication, authorized workflow component bundle, generated-XMD observation
      and mutation admission, retained Agent sessions, durable answer delivery,
      explicit ordinary-resume scheduling, adversarial composition, and end-to-end
      certification are all implemented.

      PR #181 contains the remaining integrated delivery. At exact head
      e85479c33ce4c91d821e0eaf195150db374ae4a6 over base and merge base
      6717e867c9467114e6b060620d5b18c87beb2c48, #299 recorded certification PASS.
      All frozen commands passed, including both source and compiled entrypoints,
      CF1-CF6, the 31-file owner matrix, Node and Bun WFH rows, typing,
      publishability, and the frozen verification task.

      The only remaining PR-local work is #292's truthful synchronization of the
      living workflow and delivery records. #290's document proof, #301's complete
      composition, and #300's explicit scheduling slice are implemented on PR #181;
      those issues close with the PR rather than receiving another product pass.

      Remaining order

      1. Implement Make the adversarial implementation workflow accurately describe its behavior #292 against the exact certified PR head and obtain Planner PASS
        on one focused feedback commit.
      2. Integrate that commit, refresh PR ✨ Compose and certify the supervised adversarial implementation workflow #181's title/body, and run the applicable
        delivery gate and required CI.
      3. Mark the PR ready, obtain required review, and merge.
      4. Close Test the adversarial planning workflow with shipped components #290, Deliver answers to suspended workflows for later resumption #300, Compose the supervised adversarial implementation workflow #301, Make the adversarial implementation workflow accurately describe its behavior #292, and this umbrella through the delivered merge.

      No later hardening issue is inserted into this gate:

      Cross-cutting invariants

      • WorkflowRun establishment and base pinning precede Workspace attachment.
      • Shared production modules use contextual APIs and contain no runtime or
        provider detection.
      • One authoritative host-owned DOFS connection serves a workflow database and
        serializes Workspace-local effects.
      • Security filtering occurs before journal insertion; co-located Workspace
        content is not automatically journal or training data.
      • Completed replay attaches no Workspace, Agent, process, Git-host, Issue, or
        Fetch provider.
      • Status, list, and history are read-only and cannot advance a run.
      • No required state exists only in a transcript, host path, provider handle,
        branch name, or Git sidecar ref.
      • External effects reconcile stable identity and never claim atomicity across
        SQLite and a provider.
      • Answer delivery records without executing. Manual and explicit trusted-host
        scheduling invoke the same ordinary resume path and executor lock. No watcher,
        delivery-to-resume wiring, unattended arbitration, or second executor ships.
      • An Agent reaches the Workspace only as data: it names source and XMD admits
        and executes it. Generated Git, Git-host, Issue, process, credential, and
        other external effects remain outside the admitted classes.

      Completion

      This umbrella closes when PR #181 merges after #292 synchronization and the
      normal delivery gate. Transactional Worker Shell, portable adapter-level
      no-tool enforcement, the ordinary host-filesystem race, and the unrelated
      error-printing correction remain independent follow-ups.

      Intentionally excluded

      • A public remote-host selector or deployed XMD service.
      • Worker Shell or Worker JavaScript in the initial topology.
      • Native subprocess execution, writable FUSE, bundled workerd, or Containers.
      • Watchers, automatic answer-to-resume wiring, and unattended iteration
        arbitration.
      • Human actor attestation.
      • Automatic ingestion or arbitrary scanning of Workspace files.
      • Recovery from deleted or corrupt authoritative Workspace state.
      • Rewinding external systems during a history fork.

      Authoritative evidence

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        questCoordinating story with dependency-ordered sub-issues

        Projects

        No projects

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          Quest: Resume workflows with their Workspace, repositories, and Agent state #218

          Description

          @taras

          Story

          As a workflow author, I want xmd workflow to retain one provider-backed
          Workspace with the run's journal, repositories, and Agent state, so supervised
          procedures resume after interruption without reconstructing hidden filesystem or
          transcript state.

          Settled contract

          PR #358 records the normative architecture in architecture.md and
          specs/workflow-workspace-spec.md:

          • xmd run uses the caller's current environment and makes no restoration
            guarantee; xmd workflow owns one retained WorkflowRun and implicit root
            Workspace.
          • One SQLite database holds logically separate filtered journal, versioned DOFS,
            Repository/Worktree metadata, and Agent-session stores.
          • One expansion produces one effect and one Workspace transaction. Completed
            durable effects restore their results, ephemeral attachments rebuild the live
            Effection tree, and partial replay continues from the retained frontier.
          • Missing or corrupt authoritative Workspace state is unrecoverable rather than
            silently replaced.
          • Workflow Agents receive no Workspace materialization or additional
            directories. They request observations and propose mutations as constrained
            generated XMD executed by the host.
          • Prompt, Git-host, Issue, and other external effects reconcile stable identity
            at their owning provider boundary; they do not claim cross-system atomicity.
          • Public lifecycle operations remain host-neutral and preserve one executor
            authority.

          This issue is the implementation umbrella. Child issues own executable
          acceptance detail; this body owns the shared invariants and current closure map.

          Current delivery state

          The retained lifecycle, history, named Repository/Worktree composition, local
          Git and Git-host effects, provider-neutral Issue and Fetch effects, ambient
          authentication, authorized workflow component bundle, generated-XMD observation
          and mutation admission, retained Agent sessions, durable answer delivery,
          explicit ordinary-resume scheduling, adversarial composition, and end-to-end
          certification are all implemented.

          PR #181 contains the remaining integrated delivery. At exact head
          e85479c33ce4c91d821e0eaf195150db374ae4a6 over base and merge base
          6717e867c9467114e6b060620d5b18c87beb2c48, #299 recorded certification PASS.
          All frozen commands passed, including both source and compiled entrypoints,
          CF1-CF6, the 31-file owner matrix, Node and Bun WFH rows, typing,
          publishability, and the frozen verification task.

          The only remaining PR-local work is #292's truthful synchronization of the
          living workflow and delivery records. #290's document proof, #301's complete
          composition, and #300's explicit scheduling slice are implemented on PR #181;
          those issues close with the PR rather than receiving another product pass.

          Remaining order

          1. Implement Make the adversarial implementation workflow accurately describe its behavior #292 against the exact certified PR head and obtain Planner PASS
            on one focused feedback commit.
          2. Integrate that commit, refresh PR ✨ Compose and certify the supervised adversarial implementation workflow #181's title/body, and run the applicable
            delivery gate and required CI.
          3. Mark the PR ready, obtain required review, and merge.
          4. Close Test the adversarial planning workflow with shipped components #290, Deliver answers to suspended workflows for later resumption #300, Compose the supervised adversarial implementation workflow #301, Make the adversarial implementation workflow accurately describe its behavior #292, and this umbrella through the delivered merge.

          No later hardening issue is inserted into this gate:

          Cross-cutting invariants

          • WorkflowRun establishment and base pinning precede Workspace attachment.
          • Shared production modules use contextual APIs and contain no runtime or
            provider detection.
          • One authoritative host-owned DOFS connection serves a workflow database and
            serializes Workspace-local effects.
          • Security filtering occurs before journal insertion; co-located Workspace
            content is not automatically journal or training data.
          • Completed replay attaches no Workspace, Agent, process, Git-host, Issue, or
            Fetch provider.
          • Status, list, and history are read-only and cannot advance a run.
          • No required state exists only in a transcript, host path, provider handle,
            branch name, or Git sidecar ref.
          • External effects reconcile stable identity and never claim atomicity across
            SQLite and a provider.
          • Answer delivery records without executing. Manual and explicit trusted-host
            scheduling invoke the same ordinary resume path and executor lock. No watcher,
            delivery-to-resume wiring, unattended arbitration, or second executor ships.
          • An Agent reaches the Workspace only as data: it names source and XMD admits
            and executes it. Generated Git, Git-host, Issue, process, credential, and
            other external effects remain outside the admitted classes.

          Completion

          This umbrella closes when PR #181 merges after #292 synchronization and the
          normal delivery gate. Transactional Worker Shell, portable adapter-level
          no-tool enforcement, the ordinary host-filesystem race, and the unrelated
          error-printing correction remain independent follow-ups.

          Intentionally excluded

          • A public remote-host selector or deployed XMD service.
          • Worker Shell or Worker JavaScript in the initial topology.
          • Native subprocess execution, writable FUSE, bundled workerd, or Containers.
          • Watchers, automatic answer-to-resume wiring, and unattended iteration
            arbitration.
          • Human actor attestation.
          • Automatic ingestion or arbitrary scanning of Workspace files.
          • Recovery from deleted or corrupt authoritative Workspace state.
          • Rewinding external systems during a history fork.

          Authoritative evidence

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            questCoordinating story with dependency-ordered sub-issues

            Projects

            No projects

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Quest: Resume workflows with their Workspace, repositories, and Agent state #218

              Description

              @taras

              Story

              As a workflow author, I want xmd workflow to retain one provider-backed
              Workspace with the run's journal, repositories, and Agent state, so supervised
              procedures resume after interruption without reconstructing hidden filesystem or
              transcript state.

              Settled contract

              PR #358 records the normative architecture in architecture.md and
              specs/workflow-workspace-spec.md:

              • xmd run uses the caller's current environment and makes no restoration
                guarantee; xmd workflow owns one retained WorkflowRun and implicit root
                Workspace.
              • One SQLite database holds logically separate filtered journal, versioned DOFS,
                Repository/Worktree metadata, and Agent-session stores.
              • One expansion produces one effect and one Workspace transaction. Completed
                durable effects restore their results, ephemeral attachments rebuild the live
                Effection tree, and partial replay continues from the retained frontier.
              • Missing or corrupt authoritative Workspace state is unrecoverable rather than
                silently replaced.
              • Workflow Agents receive no Workspace materialization or additional
                directories. They request observations and propose mutations as constrained
                generated XMD executed by the host.
              • Prompt, Git-host, Issue, and other external effects reconcile stable identity
                at their owning provider boundary; they do not claim cross-system atomicity.
              • Public lifecycle operations remain host-neutral and preserve one executor
                authority.

              This issue is the implementation umbrella. Child issues own executable
              acceptance detail; this body owns the shared invariants and current closure map.

              Current delivery state

              The retained lifecycle, history, named Repository/Worktree composition, local
              Git and Git-host effects, provider-neutral Issue and Fetch effects, ambient
              authentication, authorized workflow component bundle, generated-XMD observation
              and mutation admission, retained Agent sessions, durable answer delivery,
              explicit ordinary-resume scheduling, adversarial composition, and end-to-end
              certification are all implemented.

              PR #181 contains the remaining integrated delivery. At exact head
              e85479c33ce4c91d821e0eaf195150db374ae4a6 over base and merge base
              6717e867c9467114e6b060620d5b18c87beb2c48, #299 recorded certification PASS.
              All frozen commands passed, including both source and compiled entrypoints,
              CF1-CF6, the 31-file owner matrix, Node and Bun WFH rows, typing,
              publishability, and the frozen verification task.

              The only remaining PR-local work is #292's truthful synchronization of the
              living workflow and delivery records. #290's document proof, #301's complete
              composition, and #300's explicit scheduling slice are implemented on PR #181;
              those issues close with the PR rather than receiving another product pass.

              Remaining order

              1. Implement Make the adversarial implementation workflow accurately describe its behavior #292 against the exact certified PR head and obtain Planner PASS
                on one focused feedback commit.
              2. Integrate that commit, refresh PR ✨ Compose and certify the supervised adversarial implementation workflow #181's title/body, and run the applicable
                delivery gate and required CI.
              3. Mark the PR ready, obtain required review, and merge.
              4. Close Test the adversarial planning workflow with shipped components #290, Deliver answers to suspended workflows for later resumption #300, Compose the supervised adversarial implementation workflow #301, Make the adversarial implementation workflow accurately describe its behavior #292, and this umbrella through the delivered merge.

              No later hardening issue is inserted into this gate:

              Cross-cutting invariants

              • WorkflowRun establishment and base pinning precede Workspace attachment.
              • Shared production modules use contextual APIs and contain no runtime or
                provider detection.
              • One authoritative host-owned DOFS connection serves a workflow database and
                serializes Workspace-local effects.
              • Security filtering occurs before journal insertion; co-located Workspace
                content is not automatically journal or training data.
              • Completed replay attaches no Workspace, Agent, process, Git-host, Issue, or
                Fetch provider.
              • Status, list, and history are read-only and cannot advance a run.
              • No required state exists only in a transcript, host path, provider handle,
                branch name, or Git sidecar ref.
              • External effects reconcile stable identity and never claim atomicity across
                SQLite and a provider.
              • Answer delivery records without executing. Manual and explicit trusted-host
                scheduling invoke the same ordinary resume path and executor lock. No watcher,
                delivery-to-resume wiring, unattended arbitration, or second executor ships.
              • An Agent reaches the Workspace only as data: it names source and XMD admits
                and executes it. Generated Git, Git-host, Issue, process, credential, and
                other external effects remain outside the admitted classes.

              Completion

              This umbrella closes when PR #181 merges after #292 synchronization and the
              normal delivery gate. Transactional Worker Shell, portable adapter-level
              no-tool enforcement, the ordinary host-filesystem race, and the unrelated
              error-printing correction remain independent follow-ups.

              Intentionally excluded

              • A public remote-host selector or deployed XMD service.
              • Worker Shell or Worker JavaScript in the initial topology.
              • Native subprocess execution, writable FUSE, bundled workerd, or Containers.
              • Watchers, automatic answer-to-resume wiring, and unattended iteration
                arbitration.
              • Human actor attestation.
              • Automatic ingestion or arbitrary scanning of Workspace files.
              • Recovery from deleted or corrupt authoritative Workspace state.
              • Rewinding external systems during a history fork.

              Authoritative evidence

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                questCoordinating story with dependency-ordered sub-issues

                Projects

                No projects

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  Quest: Resume workflows with their Workspace, repositories, and Agent state #218

                  Description

                  @taras

                  Story

                  As a workflow author, I want xmd workflow to retain one provider-backed
                  Workspace with the run's journal, repositories, and Agent state, so supervised
                  procedures resume after interruption without reconstructing hidden filesystem or
                  transcript state.

                  Settled contract

                  PR #358 records the normative architecture in architecture.md and
                  specs/workflow-workspace-spec.md:

                  • xmd run uses the caller's current environment and makes no restoration
                    guarantee; xmd workflow owns one retained WorkflowRun and implicit root
                    Workspace.
                  • One SQLite database holds logically separate filtered journal, versioned DOFS,
                    Repository/Worktree metadata, and Agent-session stores.
                  • One expansion produces one effect and one Workspace transaction. Completed
                    durable effects restore their results, ephemeral attachments rebuild the live
                    Effection tree, and partial replay continues from the retained frontier.
                  • Missing or corrupt authoritative Workspace state is unrecoverable rather than
                    silently replaced.
                  • Workflow Agents receive no Workspace materialization or additional
                    directories. They request observations and propose mutations as constrained
                    generated XMD executed by the host.
                  • Prompt, Git-host, Issue, and other external effects reconcile stable identity
                    at their owning provider boundary; they do not claim cross-system atomicity.
                  • Public lifecycle operations remain host-neutral and preserve one executor
                    authority.

                  This issue is the implementation umbrella. Child issues own executable
                  acceptance detail; this body owns the shared invariants and current closure map.

                  Current delivery state

                  The retained lifecycle, history, named Repository/Worktree composition, local
                  Git and Git-host effects, provider-neutral Issue and Fetch effects, ambient
                  authentication, authorized workflow component bundle, generated-XMD observation
                  and mutation admission, retained Agent sessions, durable answer delivery,
                  explicit ordinary-resume scheduling, adversarial composition, and end-to-end
                  certification are all implemented.

                  PR #181 contains the remaining integrated delivery. At exact head
                  e85479c33ce4c91d821e0eaf195150db374ae4a6 over base and merge base
                  6717e867c9467114e6b060620d5b18c87beb2c48, #299 recorded certification PASS.
                  All frozen commands passed, including both source and compiled entrypoints,
                  CF1-CF6, the 31-file owner matrix, Node and Bun WFH rows, typing,
                  publishability, and the frozen verification task.

                  The only remaining PR-local work is #292's truthful synchronization of the
                  living workflow and delivery records. #290's document proof, #301's complete
                  composition, and #300's explicit scheduling slice are implemented on PR #181;
                  those issues close with the PR rather than receiving another product pass.

                  Remaining order

                  1. Implement Make the adversarial implementation workflow accurately describe its behavior #292 against the exact certified PR head and obtain Planner PASS
                    on one focused feedback commit.
                  2. Integrate that commit, refresh PR ✨ Compose and certify the supervised adversarial implementation workflow #181's title/body, and run the applicable
                    delivery gate and required CI.
                  3. Mark the PR ready, obtain required review, and merge.
                  4. Close Test the adversarial planning workflow with shipped components #290, Deliver answers to suspended workflows for later resumption #300, Compose the supervised adversarial implementation workflow #301, Make the adversarial implementation workflow accurately describe its behavior #292, and this umbrella through the delivered merge.

                  No later hardening issue is inserted into this gate:

                  Cross-cutting invariants

                  • WorkflowRun establishment and base pinning precede Workspace attachment.
                  • Shared production modules use contextual APIs and contain no runtime or
                    provider detection.
                  • One authoritative host-owned DOFS connection serves a workflow database and
                    serializes Workspace-local effects.
                  • Security filtering occurs before journal insertion; co-located Workspace
                    content is not automatically journal or training data.
                  • Completed replay attaches no Workspace, Agent, process, Git-host, Issue, or
                    Fetch provider.
                  • Status, list, and history are read-only and cannot advance a run.
                  • No required state exists only in a transcript, host path, provider handle,
                    branch name, or Git sidecar ref.
                  • External effects reconcile stable identity and never claim atomicity across
                    SQLite and a provider.
                  • Answer delivery records without executing. Manual and explicit trusted-host
                    scheduling invoke the same ordinary resume path and executor lock. No watcher,
                    delivery-to-resume wiring, unattended arbitration, or second executor ships.
                  • An Agent reaches the Workspace only as data: it names source and XMD admits
                    and executes it. Generated Git, Git-host, Issue, process, credential, and
                    other external effects remain outside the admitted classes.

                  Completion

                  This umbrella closes when PR #181 merges after #292 synchronization and the
                  normal delivery gate. Transactional Worker Shell, portable adapter-level
                  no-tool enforcement, the ordinary host-filesystem race, and the unrelated
                  error-printing correction remain independent follow-ups.

                  Intentionally excluded

                  • A public remote-host selector or deployed XMD service.
                  • Worker Shell or Worker JavaScript in the initial topology.
                  • Native subprocess execution, writable FUSE, bundled workerd, or Containers.
                  • Watchers, automatic answer-to-resume wiring, and unattended iteration
                    arbitration.
                  • Human actor attestation.
                  • Automatic ingestion or arbitrary scanning of Workspace files.
                  • Recovery from deleted or corrupt authoritative Workspace state.
                  • Rewinding external systems during a history fork.

                  Authoritative evidence

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    questCoordinating story with dependency-ordered sub-issues

                    Projects

                    No projects

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      Quest: Resume workflows with their Workspace, repositories, and Agent state #218

                      Description

                      @taras

                      Story

                      As a workflow author, I want xmd workflow to retain one provider-backed
                      Workspace with the run's journal, repositories, and Agent state, so supervised
                      procedures resume after interruption without reconstructing hidden filesystem or
                      transcript state.

                      Settled contract

                      PR #358 records the normative architecture in architecture.md and
                      specs/workflow-workspace-spec.md:

                      • xmd run uses the caller's current environment and makes no restoration
                        guarantee; xmd workflow owns one retained WorkflowRun and implicit root
                        Workspace.
                      • One SQLite database holds logically separate filtered journal, versioned DOFS,
                        Repository/Worktree metadata, and Agent-session stores.
                      • One expansion produces one effect and one Workspace transaction. Completed
                        durable effects restore their results, ephemeral attachments rebuild the live
                        Effection tree, and partial replay continues from the retained frontier.
                      • Missing or corrupt authoritative Workspace state is unrecoverable rather than
                        silently replaced.
                      • Workflow Agents receive no Workspace materialization or additional
                        directories. They request observations and propose mutations as constrained
                        generated XMD executed by the host.
                      • Prompt, Git-host, Issue, and other external effects reconcile stable identity
                        at their owning provider boundary; they do not claim cross-system atomicity.
                      • Public lifecycle operations remain host-neutral and preserve one executor
                        authority.

                      This issue is the implementation umbrella. Child issues own executable
                      acceptance detail; this body owns the shared invariants and current closure map.

                      Current delivery state

                      The retained lifecycle, history, named Repository/Worktree composition, local
                      Git and Git-host effects, provider-neutral Issue and Fetch effects, ambient
                      authentication, authorized workflow component bundle, generated-XMD observation
                      and mutation admission, retained Agent sessions, durable answer delivery,
                      explicit ordinary-resume scheduling, adversarial composition, and end-to-end
                      certification are all implemented.

                      PR #181 contains the remaining integrated delivery. At exact head
                      e85479c33ce4c91d821e0eaf195150db374ae4a6 over base and merge base
                      6717e867c9467114e6b060620d5b18c87beb2c48, #299 recorded certification PASS.
                      All frozen commands passed, including both source and compiled entrypoints,
                      CF1-CF6, the 31-file owner matrix, Node and Bun WFH rows, typing,
                      publishability, and the frozen verification task.

                      The only remaining PR-local work is #292's truthful synchronization of the
                      living workflow and delivery records. #290's document proof, #301's complete
                      composition, and #300's explicit scheduling slice are implemented on PR #181;
                      those issues close with the PR rather than receiving another product pass.

                      Remaining order

                      1. Implement Make the adversarial implementation workflow accurately describe its behavior #292 against the exact certified PR head and obtain Planner PASS
                        on one focused feedback commit.
                      2. Integrate that commit, refresh PR ✨ Compose and certify the supervised adversarial implementation workflow #181's title/body, and run the applicable
                        delivery gate and required CI.
                      3. Mark the PR ready, obtain required review, and merge.
                      4. Close Test the adversarial planning workflow with shipped components #290, Deliver answers to suspended workflows for later resumption #300, Compose the supervised adversarial implementation workflow #301, Make the adversarial implementation workflow accurately describe its behavior #292, and this umbrella through the delivered merge.

                      No later hardening issue is inserted into this gate:

                      Cross-cutting invariants

                      • WorkflowRun establishment and base pinning precede Workspace attachment.
                      • Shared production modules use contextual APIs and contain no runtime or
                        provider detection.
                      • One authoritative host-owned DOFS connection serves a workflow database and
                        serializes Workspace-local effects.
                      • Security filtering occurs before journal insertion; co-located Workspace
                        content is not automatically journal or training data.
                      • Completed replay attaches no Workspace, Agent, process, Git-host, Issue, or
                        Fetch provider.
                      • Status, list, and history are read-only and cannot advance a run.
                      • No required state exists only in a transcript, host path, provider handle,
                        branch name, or Git sidecar ref.
                      • External effects reconcile stable identity and never claim atomicity across
                        SQLite and a provider.
                      • Answer delivery records without executing. Manual and explicit trusted-host
                        scheduling invoke the same ordinary resume path and executor lock. No watcher,
                        delivery-to-resume wiring, unattended arbitration, or second executor ships.
                      • An Agent reaches the Workspace only as data: it names source and XMD admits
                        and executes it. Generated Git, Git-host, Issue, process, credential, and
                        other external effects remain outside the admitted classes.

                      Completion

                      This umbrella closes when PR #181 merges after #292 synchronization and the
                      normal delivery gate. Transactional Worker Shell, portable adapter-level
                      no-tool enforcement, the ordinary host-filesystem race, and the unrelated
                      error-printing correction remain independent follow-ups.

                      Intentionally excluded

                      • A public remote-host selector or deployed XMD service.
                      • Worker Shell or Worker JavaScript in the initial topology.
                      • Native subprocess execution, writable FUSE, bundled workerd, or Containers.
                      • Watchers, automatic answer-to-resume wiring, and unattended iteration
                        arbitration.
                      • Human actor attestation.
                      • Automatic ingestion or arbitrary scanning of Workspace files.
                      • Recovery from deleted or corrupt authoritative Workspace state.
                      • Rewinding external systems during a history fork.

                      Authoritative evidence

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        questCoordinating story with dependency-ordered sub-issues

                        Projects

                        No projects

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          Quest: Resume workflows with their Workspace, repositories, and Agent state #218

                          Description

                          @taras

                          Story

                          As a workflow author, I want xmd workflow to retain one provider-backed
                          Workspace with the run's journal, repositories, and Agent state, so supervised
                          procedures resume after interruption without reconstructing hidden filesystem or
                          transcript state.

                          Settled contract

                          PR #358 records the normative architecture in architecture.md and
                          specs/workflow-workspace-spec.md:

                          • xmd run uses the caller's current environment and makes no restoration
                            guarantee; xmd workflow owns one retained WorkflowRun and implicit root
                            Workspace.
                          • One SQLite database holds logically separate filtered journal, versioned DOFS,
                            Repository/Worktree metadata, and Agent-session stores.
                          • One expansion produces one effect and one Workspace transaction. Completed
                            durable effects restore their results, ephemeral attachments rebuild the live
                            Effection tree, and partial replay continues from the retained frontier.
                          • Missing or corrupt authoritative Workspace state is unrecoverable rather than
                            silently replaced.
                          • Workflow Agents receive no Workspace materialization or additional
                            directories. They request observations and propose mutations as constrained
                            generated XMD executed by the host.
                          • Prompt, Git-host, Issue, and other external effects reconcile stable identity
                            at their owning provider boundary; they do not claim cross-system atomicity.
                          • Public lifecycle operations remain host-neutral and preserve one executor
                            authority.

                          This issue is the implementation umbrella. Child issues own executable
                          acceptance detail; this body owns the shared invariants and current closure map.

                          Current delivery state

                          The retained lifecycle, history, named Repository/Worktree composition, local
                          Git and Git-host effects, provider-neutral Issue and Fetch effects, ambient
                          authentication, authorized workflow component bundle, generated-XMD observation
                          and mutation admission, retained Agent sessions, durable answer delivery,
                          explicit ordinary-resume scheduling, adversarial composition, and end-to-end
                          certification are all implemented.

                          PR #181 contains the remaining integrated delivery. At exact head
                          e85479c33ce4c91d821e0eaf195150db374ae4a6 over base and merge base
                          6717e867c9467114e6b060620d5b18c87beb2c48, #299 recorded certification PASS.
                          All frozen commands passed, including both source and compiled entrypoints,
                          CF1-CF6, the 31-file owner matrix, Node and Bun WFH rows, typing,
                          publishability, and the frozen verification task.

                          The only remaining PR-local work is #292's truthful synchronization of the
                          living workflow and delivery records. #290's document proof, #301's complete
                          composition, and #300's explicit scheduling slice are implemented on PR #181;
                          those issues close with the PR rather than receiving another product pass.

                          Remaining order

                          1. Implement Make the adversarial implementation workflow accurately describe its behavior #292 against the exact certified PR head and obtain Planner PASS
                            on one focused feedback commit.
                          2. Integrate that commit, refresh PR ✨ Compose and certify the supervised adversarial implementation workflow #181's title/body, and run the applicable
                            delivery gate and required CI.
                          3. Mark the PR ready, obtain required review, and merge.
                          4. Close Test the adversarial planning workflow with shipped components #290, Deliver answers to suspended workflows for later resumption #300, Compose the supervised adversarial implementation workflow #301, Make the adversarial implementation workflow accurately describe its behavior #292, and this umbrella through the delivered merge.

                          No later hardening issue is inserted into this gate:

                          Cross-cutting invariants

                          • WorkflowRun establishment and base pinning precede Workspace attachment.
                          • Shared production modules use contextual APIs and contain no runtime or
                            provider detection.
                          • One authoritative host-owned DOFS connection serves a workflow database and
                            serializes Workspace-local effects.
                          • Security filtering occurs before journal insertion; co-located Workspace
                            content is not automatically journal or training data.
                          • Completed replay attaches no Workspace, Agent, process, Git-host, Issue, or
                            Fetch provider.
                          • Status, list, and history are read-only and cannot advance a run.
                          • No required state exists only in a transcript, host path, provider handle,
                            branch name, or Git sidecar ref.
                          • External effects reconcile stable identity and never claim atomicity across
                            SQLite and a provider.
                          • Answer delivery records without executing. Manual and explicit trusted-host
                            scheduling invoke the same ordinary resume path and executor lock. No watcher,
                            delivery-to-resume wiring, unattended arbitration, or second executor ships.
                          • An Agent reaches the Workspace only as data: it names source and XMD admits
                            and executes it. Generated Git, Git-host, Issue, process, credential, and
                            other external effects remain outside the admitted classes.

                          Completion

                          This umbrella closes when PR #181 merges after #292 synchronization and the
                          normal delivery gate. Transactional Worker Shell, portable adapter-level
                          no-tool enforcement, the ordinary host-filesystem race, and the unrelated
                          error-printing correction remain independent follow-ups.

                          Intentionally excluded

                          • A public remote-host selector or deployed XMD service.
                          • Worker Shell or Worker JavaScript in the initial topology.
                          • Native subprocess execution, writable FUSE, bundled workerd, or Containers.
                          • Watchers, automatic answer-to-resume wiring, and unattended iteration
                            arbitration.
                          • Human actor attestation.
                          • Automatic ingestion or arbitrary scanning of Workspace files.
                          • Recovery from deleted or corrupt authoritative Workspace state.
                          • Rewinding external systems during a history fork.

                          Authoritative evidence

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            questCoordinating story with dependency-ordered sub-issues

                            Projects

                            No projects

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              Quest: Resume workflows with their Workspace, repositories, and Agent state #218

                              Description

                              @taras

                              Story

                              As a workflow author, I want xmd workflow to retain one provider-backed
                              Workspace with the run's journal, repositories, and Agent state, so supervised
                              procedures resume after interruption without reconstructing hidden filesystem or
                              transcript state.

                              Settled contract

                              PR #358 records the normative architecture in architecture.md and
                              specs/workflow-workspace-spec.md:

                              • xmd run uses the caller's current environment and makes no restoration
                                guarantee; xmd workflow owns one retained WorkflowRun and implicit root
                                Workspace.
                              • One SQLite database holds logically separate filtered journal, versioned DOFS,
                                Repository/Worktree metadata, and Agent-session stores.
                              • One expansion produces one effect and one Workspace transaction. Completed
                                durable effects restore their results, ephemeral attachments rebuild the live
                                Effection tree, and partial replay continues from the retained frontier.
                              • Missing or corrupt authoritative Workspace state is unrecoverable rather than
                                silently replaced.
                              • Workflow Agents receive no Workspace materialization or additional
                                directories. They request observations and propose mutations as constrained
                                generated XMD executed by the host.
                              • Prompt, Git-host, Issue, and other external effects reconcile stable identity
                                at their owning provider boundary; they do not claim cross-system atomicity.
                              • Public lifecycle operations remain host-neutral and preserve one executor
                                authority.

                              This issue is the implementation umbrella. Child issues own executable
                              acceptance detail; this body owns the shared invariants and current closure map.

                              Current delivery state

                              The retained lifecycle, history, named Repository/Worktree composition, local
                              Git and Git-host effects, provider-neutral Issue and Fetch effects, ambient
                              authentication, authorized workflow component bundle, generated-XMD observation
                              and mutation admission, retained Agent sessions, durable answer delivery,
                              explicit ordinary-resume scheduling, adversarial composition, and end-to-end
                              certification are all implemented.

                              PR #181 contains the remaining integrated delivery. At exact head
                              e85479c33ce4c91d821e0eaf195150db374ae4a6 over base and merge base
                              6717e867c9467114e6b060620d5b18c87beb2c48, #299 recorded certification PASS.
                              All frozen commands passed, including both source and compiled entrypoints,
                              CF1-CF6, the 31-file owner matrix, Node and Bun WFH rows, typing,
                              publishability, and the frozen verification task.

                              The only remaining PR-local work is #292's truthful synchronization of the
                              living workflow and delivery records. #290's document proof, #301's complete
                              composition, and #300's explicit scheduling slice are implemented on PR #181;
                              those issues close with the PR rather than receiving another product pass.

                              Remaining order

                              1. Implement Make the adversarial implementation workflow accurately describe its behavior #292 against the exact certified PR head and obtain Planner PASS
                                on one focused feedback commit.
                              2. Integrate that commit, refresh PR ✨ Compose and certify the supervised adversarial implementation workflow #181's title/body, and run the applicable
                                delivery gate and required CI.
                              3. Mark the PR ready, obtain required review, and merge.
                              4. Close Test the adversarial planning workflow with shipped components #290, Deliver answers to suspended workflows for later resumption #300, Compose the supervised adversarial implementation workflow #301, Make the adversarial implementation workflow accurately describe its behavior #292, and this umbrella through the delivered merge.

                              No later hardening issue is inserted into this gate:

                              Cross-cutting invariants

                              • WorkflowRun establishment and base pinning precede Workspace attachment.
                              • Shared production modules use contextual APIs and contain no runtime or
                                provider detection.
                              • One authoritative host-owned DOFS connection serves a workflow database and
                                serializes Workspace-local effects.
                              • Security filtering occurs before journal insertion; co-located Workspace
                                content is not automatically journal or training data.
                              • Completed replay attaches no Workspace, Agent, process, Git-host, Issue, or
                                Fetch provider.
                              • Status, list, and history are read-only and cannot advance a run.
                              • No required state exists only in a transcript, host path, provider handle,
                                branch name, or Git sidecar ref.
                              • External effects reconcile stable identity and never claim atomicity across
                                SQLite and a provider.
                              • Answer delivery records without executing. Manual and explicit trusted-host
                                scheduling invoke the same ordinary resume path and executor lock. No watcher,
                                delivery-to-resume wiring, unattended arbitration, or second executor ships.
                              • An Agent reaches the Workspace only as data: it names source and XMD admits
                                and executes it. Generated Git, Git-host, Issue, process, credential, and
                                other external effects remain outside the admitted classes.

                              Completion

                              This umbrella closes when PR #181 merges after #292 synchronization and the
                              normal delivery gate. Transactional Worker Shell, portable adapter-level
                              no-tool enforcement, the ordinary host-filesystem race, and the unrelated
                              error-printing correction remain independent follow-ups.

                              Intentionally excluded

                              • A public remote-host selector or deployed XMD service.
                              • Worker Shell or Worker JavaScript in the initial topology.
                              • Native subprocess execution, writable FUSE, bundled workerd, or Containers.
                              • Watchers, automatic answer-to-resume wiring, and unattended iteration
                                arbitration.
                              • Human actor attestation.
                              • Automatic ingestion or arbitrary scanning of Workspace files.
                              • Recovery from deleted or corrupt authoritative Workspace state.
                              • Rewinding external systems during a history fork.

                              Authoritative evidence

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                questCoordinating story with dependency-ordered sub-issues

                                Projects

                                No projects

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions