Compose the supervised adversarial implementation workflow #301

Description

@taras

Story

As a user, I want the complete adversarial implementation loop to run under explicit supervision, so I retain product authority while deterministic XMD components own operational effects.

Current delivery state

Slice 2 is now the only open unit, and it is the composition itself. Its old three-PR sequence is collapsed: #577 shipped the durable workflow checkpoint at 1d528219, and #580 shipped the URL-addressed pull-request reads at f230e8fd. What remains is PR #181, which owns the complete composition and its evidence.

Implementation at exact PR #181 head 9ef6edcf205f57ba08cc84ba7a009919ed403957 exposed two defects in shipped prerequisites. Both are complete: #588 shipped ordinary proven non-force fast-forward advancement for <Git.Push /> through PR #594, and #589 restored continuation through durable effects inside generated XMD through PR #597. Slice 2 is active again on PR #181; after rebasing, AC3 and AC4 become positive acceptance cases rather than blocker diagnostics.

The shipped substrate now includes:

Every complete-loop effect the composition consumes is now shipped: Git.Push (#370, PR #495), PullRequest (#295, PRs #500/#504), the URL-addressed pull-request reads (#576, PR #580), deferred Issue (#296, PR #516), XMD-mediated workflow Agent turns and the authored observation loop (#302, PRs #549/#550), generated-XMD observation and mutation admission (#369, PRs #497/#572/#574), expression-prop undefined omission (#537, PR #541), and the durable checkpoint (#577). The Agent still receives no Workspace materialization, additionalDirectories, MCP server, native tool, credential or direct mutation channel. Portable adapter-level no-tool enforcement remains the non-blocking #496 follow-up.

PR #493 implemented slice 1: the boundary between retained workflow-definition identity and the authored stage components the root invokes.

Delivery slices

Slice 1: authorized workflow component bundle

Implement a closed workflow component bundle that lets a retained workflow definition invoke trusted Markdown component code without reintroducing a mutable repository component search path.

The first consumer is the adversarial workflow's stage components:

  • InstructionFiles
  • Discovery
  • UserCheckpoint
  • Planning
  • Implementation

Those names become reachable under xmd workflow start and xmd workflow resume only when the trusted workflow host authorizes their exact component source as part of the workflow definition. Ordinary xmd run component resolution remains unchanged.

Slice 2: complete supervised adversarial composition

Compose the root workflow through discovery, handoff validation, planning convergence, authorization, XMD-mediated Agent observations and proposals, constrained generated XMD, local Git effects, explicit Push, PullRequest create/update, its URL-addressed evidence reads, review, deferred Issue creation, revision, and final acceptance — as one supervised run under xmd workflow start, typed answer delivery and explicit xmd workflow resume.

The composition remains owned by PR #181 and is active. Rebase it onto current main, convert AC3 and AC4 into successful end-to-end regressions, and complete the frozen matrix.

Scheduling, watchers and unattended resume are outside it. A resume stays an explicit act; the scheduling slice is #300's. This slice defines no additional persistence model, Agent authority model, Git-host reconciliation policy, or executor.

Slice 1 contract

xmd workflow start continues to establish an immutable workflow definition from Git. It executes bytes from the pinned commit, not from the caller's mutable working tree. The generic workflow component search path remains empty.

A workflow root may declare a closed component bundle in frontmatter:

workflow:
components:
InstructionFiles: ./InstructionFiles.mdDiscovery: ./Discovery.mdUserCheckpoint: ./UserCheckpoint.mdPlanning: ./Planning.mdImplementation: ./Implementation.md

The initial bundle admits only Markdown component files named explicitly in that map. Values are POSIX paths relative to the root document's directory in the same pinned Git tree. Absolute paths, parent traversal, globs, directories, URLs, TypeScript components, package imports, generated paths and duplicate names are refused. Names that are structural constructs, reserved host registrations, or core defaults are refused in this slice; the bundle exists for workflow-owned stage components, not for replacing language or security primitives.

On start, the trusted workflow host reads the root and every declared component from the same pinned commit, validates every component declaration, and constructs a normalized bundle:

  • component name;
  • canonical repository-relative component path;
  • component source hash; and
  • the retained component source needed for durable selection and replay.

That normalized bundle is part of workflow-definition identity. Compatible reuse compares it with the run ID, descriptor, definition base and normalized props. A caller-selected run ID with a different bundle is an incompatible definition reuse, even when the root path and props are unchanged.

On resume, the host reconstructs the same bundle from retained definition metadata and the pinned Git object, verifies the retained hashes, and installs only that bundle for the live execution. A current checkout file with the same name or path is ignored. Missing, unreadable, changed, incompatible or unauthorized component code is refused before that code executes or advances the workflow.

Bundle installation is a trusted-host operation, not public middleware. It gives the document no capability to authorize more code. Public middleware, props, eval bindings, generated source, and a same-name file in the mutable checkout may refuse or narrow behavior, but cannot add bundle entries, replace retained component source, or widen what code is authorized to execute.

Retained component-selection history must agree with the authorized bundle. A replay that tries to restore a component selection outside the retained bundle, with a mismatched source hash, or with a mutable-checkout path in place of retained source is refused before component code executes or any later durable effect appends.

The bundle is not generated-XMD admission. A generated fragment still cannot name these components, Fetch, or any other component until #369 admits pinned identities and exact bounded requests.

Material choices still use #367 suspension and #300 typed answer delivery. Delivering an answer records it without executing the workflow. Continuation occurs only through the ordinary explicit resume path, which acquires the executor lock and claims the retained answer durably. Automatic scheduling remains #300's later slice.

Do not add file watchers, unattended arbitration, a second executor authority, or a generic workflow component search path here.

Acceptance: slice 1

  • xmd workflow start accepts a root-declared closed component bundle and records the normalized bundle in workflow-definition identity.
  • xmd workflow resume reconstructs and validates the same retained bundle before any bundled component executes.
  • A workflow root can invoke InstructionFiles, Discovery, UserCheckpoint, Planning, and Implementation from trusted bundle source under start and resume.
  • The bundle reads component source from the pinned definition commit, never from mutable checkout content beside the retained root.
  • Compatible reuse of a caller-selected run ID requires the same normalized component bundle; a changed component path, source hash, name set, or root-relative declaration is refused as incompatible definition reuse.
  • Retained-history admission refuses component selections outside the retained bundle or with mismatched retained source before executing component code or appending later durable effects.
  • Missing, unreadable, malformed, schema-invalid, incompatible, duplicate, escaping, non-Markdown, structural-name, reserved-name, and core-default-name bundle entries are refused before component code executes.
  • Ordinary xmd run component resolution is unchanged.
  • Workflow execution gains no generic repository component search path.
  • Public middleware, props, eval bindings, generated source, or same-name checkout files cannot add, replace, or widen authorized component code.
  • Generated-XMD admission remains unchanged and still belongs to Evaluate Agent-generated XMD through a constrained allowlist #369.
  • Delivering an answer alone starts no execution; continuation still occurs only after explicit resume acquires the executor lock.
  • Focused tests use fixtures that exercise start, resume, compatible reuse, retained-history admission, mutable-checkout substitution, and refusal-before-execution. The ✨ Compose and certify the supervised adversarial implementation workflow #181 workflow documents consume the bundle when they are present on the implementation branch, but slice 1 does not require the complete adversarial loop to run.
  • Architecture and workflow/executable-MDX specifications describe the bundle identity, authority, replay, failure and compatibility boundaries in present tense.

Acceptance: later complete composition

  • One supervised WorkflowRun reaches final acceptance across process interruption using retained suspension, typed answer delivery and explicit resume. Scheduled resume is Deliver answers to suspended workflows for later resumption #300's later slice and is not part of this acceptance.
  • Failed plan and pull-request verdicts return prescriptive prompts to the responsible retained Agent context.
  • Material choices suspend for user authority and never default to approval; only the exact validated retained answer may continue that request.
  • Agents receive no Workspace materialization or additional directories; XMD performs every admitted observation and mutation. The initial adapter-level tool suppression guarantee is limited as recorded by Run workflow Agents through XMD-mediated observations #302 and Require ACP adapters to enforce tool-free workflow Agent sessions #496.
  • Two repositories can participate through explicit named Repository/Worktree composition.
  • Commit, Push, PullRequest, and deferred Issue remain distinct durable or reconciled effects.
  • Every declared artifact and effect result is available to a later execution without manual copy/paste or hidden transcript state.
  • Failure and cancellation halt live resources while retaining explicit recoverable or terminal state.
  • No automatic watcher, unattended arbitration, or alternative executor authority is introduced by this composition story.

Dependencies

Slice 1: authorized workflow component bundle

Later complete composition

All of these are shipped:

Remaining and deliberately outside this slice:

End goal: #181.

Out of scope

  • A generic workflow component search path.
  • Loading component code from the mutable checkout on resume.
  • TypeScript component bundles, package component bundles, imports, globs or directory bundles.
  • Replacing structural constructs, reserved host registrations or core defaults through the workflow bundle.
  • Generated-XMD admission of bundled components or Fetch; Evaluate Agent-generated XMD through a constrained allowlist #369 owns that later proof.
  • Automatically resuming as part of answer delivery.
  • File watchers, branch watchers, unattended iteration arbitration or a public remote-host selector.
  • Replacing the executor lock, lifecycle state machine, journal secret policy, suspension identity, Git-host reconciliation contract, or Agent authority model.
  • Portable ACP adapter-level no-tool enforcement; Require ACP adapters to enforce tool-free workflow Agent sessions #496 owns that non-blocking hardening.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
      Skip to content

      Compose the supervised adversarial implementation workflow #301

      Description

      @taras

      Story

      As a user, I want the complete adversarial implementation loop to run under explicit supervision, so I retain product authority while deterministic XMD components own operational effects.

      Current delivery state

      Slice 2 is now the only open unit, and it is the composition itself. Its old three-PR sequence is collapsed: #577 shipped the durable workflow checkpoint at 1d528219, and #580 shipped the URL-addressed pull-request reads at f230e8fd. What remains is PR #181, which owns the complete composition and its evidence.

      Implementation at exact PR #181 head 9ef6edcf205f57ba08cc84ba7a009919ed403957 exposed two defects in shipped prerequisites. Both are complete: #588 shipped ordinary proven non-force fast-forward advancement for <Git.Push /> through PR #594, and #589 restored continuation through durable effects inside generated XMD through PR #597. Slice 2 is active again on PR #181; after rebasing, AC3 and AC4 become positive acceptance cases rather than blocker diagnostics.

      The shipped substrate now includes:

      Every complete-loop effect the composition consumes is now shipped: Git.Push (#370, PR #495), PullRequest (#295, PRs #500/#504), the URL-addressed pull-request reads (#576, PR #580), deferred Issue (#296, PR #516), XMD-mediated workflow Agent turns and the authored observation loop (#302, PRs #549/#550), generated-XMD observation and mutation admission (#369, PRs #497/#572/#574), expression-prop undefined omission (#537, PR #541), and the durable checkpoint (#577). The Agent still receives no Workspace materialization, additionalDirectories, MCP server, native tool, credential or direct mutation channel. Portable adapter-level no-tool enforcement remains the non-blocking #496 follow-up.

      PR #493 implemented slice 1: the boundary between retained workflow-definition identity and the authored stage components the root invokes.

      Delivery slices

      Slice 1: authorized workflow component bundle

      Implement a closed workflow component bundle that lets a retained workflow definition invoke trusted Markdown component code without reintroducing a mutable repository component search path.

      The first consumer is the adversarial workflow's stage components:

      • InstructionFiles
      • Discovery
      • UserCheckpoint
      • Planning
      • Implementation

      Those names become reachable under xmd workflow start and xmd workflow resume only when the trusted workflow host authorizes their exact component source as part of the workflow definition. Ordinary xmd run component resolution remains unchanged.

      Slice 2: complete supervised adversarial composition

      Compose the root workflow through discovery, handoff validation, planning convergence, authorization, XMD-mediated Agent observations and proposals, constrained generated XMD, local Git effects, explicit Push, PullRequest create/update, its URL-addressed evidence reads, review, deferred Issue creation, revision, and final acceptance — as one supervised run under xmd workflow start, typed answer delivery and explicit xmd workflow resume.

      The composition remains owned by PR #181 and is active. Rebase it onto current main, convert AC3 and AC4 into successful end-to-end regressions, and complete the frozen matrix.

      Scheduling, watchers and unattended resume are outside it. A resume stays an explicit act; the scheduling slice is #300's. This slice defines no additional persistence model, Agent authority model, Git-host reconciliation policy, or executor.

      Slice 1 contract

      xmd workflow start continues to establish an immutable workflow definition from Git. It executes bytes from the pinned commit, not from the caller's mutable working tree. The generic workflow component search path remains empty.

      A workflow root may declare a closed component bundle in frontmatter:

      workflow:
      components:
      InstructionFiles: ./InstructionFiles.mdDiscovery: ./Discovery.mdUserCheckpoint: ./UserCheckpoint.mdPlanning: ./Planning.mdImplementation: ./Implementation.md

      The initial bundle admits only Markdown component files named explicitly in that map. Values are POSIX paths relative to the root document's directory in the same pinned Git tree. Absolute paths, parent traversal, globs, directories, URLs, TypeScript components, package imports, generated paths and duplicate names are refused. Names that are structural constructs, reserved host registrations, or core defaults are refused in this slice; the bundle exists for workflow-owned stage components, not for replacing language or security primitives.

      On start, the trusted workflow host reads the root and every declared component from the same pinned commit, validates every component declaration, and constructs a normalized bundle:

      • component name;
      • canonical repository-relative component path;
      • component source hash; and
      • the retained component source needed for durable selection and replay.

      That normalized bundle is part of workflow-definition identity. Compatible reuse compares it with the run ID, descriptor, definition base and normalized props. A caller-selected run ID with a different bundle is an incompatible definition reuse, even when the root path and props are unchanged.

      On resume, the host reconstructs the same bundle from retained definition metadata and the pinned Git object, verifies the retained hashes, and installs only that bundle for the live execution. A current checkout file with the same name or path is ignored. Missing, unreadable, changed, incompatible or unauthorized component code is refused before that code executes or advances the workflow.

      Bundle installation is a trusted-host operation, not public middleware. It gives the document no capability to authorize more code. Public middleware, props, eval bindings, generated source, and a same-name file in the mutable checkout may refuse or narrow behavior, but cannot add bundle entries, replace retained component source, or widen what code is authorized to execute.

      Retained component-selection history must agree with the authorized bundle. A replay that tries to restore a component selection outside the retained bundle, with a mismatched source hash, or with a mutable-checkout path in place of retained source is refused before component code executes or any later durable effect appends.

      The bundle is not generated-XMD admission. A generated fragment still cannot name these components, Fetch, or any other component until #369 admits pinned identities and exact bounded requests.

      Material choices still use #367 suspension and #300 typed answer delivery. Delivering an answer records it without executing the workflow. Continuation occurs only through the ordinary explicit resume path, which acquires the executor lock and claims the retained answer durably. Automatic scheduling remains #300's later slice.

      Do not add file watchers, unattended arbitration, a second executor authority, or a generic workflow component search path here.

      Acceptance: slice 1

      • xmd workflow start accepts a root-declared closed component bundle and records the normalized bundle in workflow-definition identity.
      • xmd workflow resume reconstructs and validates the same retained bundle before any bundled component executes.
      • A workflow root can invoke InstructionFiles, Discovery, UserCheckpoint, Planning, and Implementation from trusted bundle source under start and resume.
      • The bundle reads component source from the pinned definition commit, never from mutable checkout content beside the retained root.
      • Compatible reuse of a caller-selected run ID requires the same normalized component bundle; a changed component path, source hash, name set, or root-relative declaration is refused as incompatible definition reuse.
      • Retained-history admission refuses component selections outside the retained bundle or with mismatched retained source before executing component code or appending later durable effects.
      • Missing, unreadable, malformed, schema-invalid, incompatible, duplicate, escaping, non-Markdown, structural-name, reserved-name, and core-default-name bundle entries are refused before component code executes.
      • Ordinary xmd run component resolution is unchanged.
      • Workflow execution gains no generic repository component search path.
      • Public middleware, props, eval bindings, generated source, or same-name checkout files cannot add, replace, or widen authorized component code.
      • Generated-XMD admission remains unchanged and still belongs to Evaluate Agent-generated XMD through a constrained allowlist #369.
      • Delivering an answer alone starts no execution; continuation still occurs only after explicit resume acquires the executor lock.
      • Focused tests use fixtures that exercise start, resume, compatible reuse, retained-history admission, mutable-checkout substitution, and refusal-before-execution. The ✨ Compose and certify the supervised adversarial implementation workflow #181 workflow documents consume the bundle when they are present on the implementation branch, but slice 1 does not require the complete adversarial loop to run.
      • Architecture and workflow/executable-MDX specifications describe the bundle identity, authority, replay, failure and compatibility boundaries in present tense.

      Acceptance: later complete composition

      • One supervised WorkflowRun reaches final acceptance across process interruption using retained suspension, typed answer delivery and explicit resume. Scheduled resume is Deliver answers to suspended workflows for later resumption #300's later slice and is not part of this acceptance.
      • Failed plan and pull-request verdicts return prescriptive prompts to the responsible retained Agent context.
      • Material choices suspend for user authority and never default to approval; only the exact validated retained answer may continue that request.
      • Agents receive no Workspace materialization or additional directories; XMD performs every admitted observation and mutation. The initial adapter-level tool suppression guarantee is limited as recorded by Run workflow Agents through XMD-mediated observations #302 and Require ACP adapters to enforce tool-free workflow Agent sessions #496.
      • Two repositories can participate through explicit named Repository/Worktree composition.
      • Commit, Push, PullRequest, and deferred Issue remain distinct durable or reconciled effects.
      • Every declared artifact and effect result is available to a later execution without manual copy/paste or hidden transcript state.
      • Failure and cancellation halt live resources while retaining explicit recoverable or terminal state.
      • No automatic watcher, unattended arbitration, or alternative executor authority is introduced by this composition story.

      Dependencies

      Slice 1: authorized workflow component bundle

      Later complete composition

      All of these are shipped:

      Remaining and deliberately outside this slice:

      End goal: #181.

      Out of scope

      • A generic workflow component search path.
      • Loading component code from the mutable checkout on resume.
      • TypeScript component bundles, package component bundles, imports, globs or directory bundles.
      • Replacing structural constructs, reserved host registrations or core defaults through the workflow bundle.
      • Generated-XMD admission of bundled components or Fetch; Evaluate Agent-generated XMD through a constrained allowlist #369 owns that later proof.
      • Automatically resuming as part of answer delivery.
      • File watchers, branch watchers, unattended iteration arbitration or a public remote-host selector.
      • Replacing the executor lock, lifecycle state machine, journal secret policy, suspension identity, Git-host reconciliation contract, or Agent authority model.
      • Portable ACP adapter-level no-tool enforcement; Require ACP adapters to enforce tool-free workflow Agent sessions #496 owns that non-blocking hardening.

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        No labels
        No labels

        Projects

        No projects

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          Compose the supervised adversarial implementation workflow #301

          Description

          @taras

          Story

          As a user, I want the complete adversarial implementation loop to run under explicit supervision, so I retain product authority while deterministic XMD components own operational effects.

          Current delivery state

          Slice 2 is now the only open unit, and it is the composition itself. Its old three-PR sequence is collapsed: #577 shipped the durable workflow checkpoint at 1d528219, and #580 shipped the URL-addressed pull-request reads at f230e8fd. What remains is PR #181, which owns the complete composition and its evidence.

          Implementation at exact PR #181 head 9ef6edcf205f57ba08cc84ba7a009919ed403957 exposed two defects in shipped prerequisites. Both are complete: #588 shipped ordinary proven non-force fast-forward advancement for <Git.Push /> through PR #594, and #589 restored continuation through durable effects inside generated XMD through PR #597. Slice 2 is active again on PR #181; after rebasing, AC3 and AC4 become positive acceptance cases rather than blocker diagnostics.

          The shipped substrate now includes:

          Every complete-loop effect the composition consumes is now shipped: Git.Push (#370, PR #495), PullRequest (#295, PRs #500/#504), the URL-addressed pull-request reads (#576, PR #580), deferred Issue (#296, PR #516), XMD-mediated workflow Agent turns and the authored observation loop (#302, PRs #549/#550), generated-XMD observation and mutation admission (#369, PRs #497/#572/#574), expression-prop undefined omission (#537, PR #541), and the durable checkpoint (#577). The Agent still receives no Workspace materialization, additionalDirectories, MCP server, native tool, credential or direct mutation channel. Portable adapter-level no-tool enforcement remains the non-blocking #496 follow-up.

          PR #493 implemented slice 1: the boundary between retained workflow-definition identity and the authored stage components the root invokes.

          Delivery slices

          Slice 1: authorized workflow component bundle

          Implement a closed workflow component bundle that lets a retained workflow definition invoke trusted Markdown component code without reintroducing a mutable repository component search path.

          The first consumer is the adversarial workflow's stage components:

          • InstructionFiles
          • Discovery
          • UserCheckpoint
          • Planning
          • Implementation

          Those names become reachable under xmd workflow start and xmd workflow resume only when the trusted workflow host authorizes their exact component source as part of the workflow definition. Ordinary xmd run component resolution remains unchanged.

          Slice 2: complete supervised adversarial composition

          Compose the root workflow through discovery, handoff validation, planning convergence, authorization, XMD-mediated Agent observations and proposals, constrained generated XMD, local Git effects, explicit Push, PullRequest create/update, its URL-addressed evidence reads, review, deferred Issue creation, revision, and final acceptance — as one supervised run under xmd workflow start, typed answer delivery and explicit xmd workflow resume.

          The composition remains owned by PR #181 and is active. Rebase it onto current main, convert AC3 and AC4 into successful end-to-end regressions, and complete the frozen matrix.

          Scheduling, watchers and unattended resume are outside it. A resume stays an explicit act; the scheduling slice is #300's. This slice defines no additional persistence model, Agent authority model, Git-host reconciliation policy, or executor.

          Slice 1 contract

          xmd workflow start continues to establish an immutable workflow definition from Git. It executes bytes from the pinned commit, not from the caller's mutable working tree. The generic workflow component search path remains empty.

          A workflow root may declare a closed component bundle in frontmatter:

          workflow:
          components:
          InstructionFiles: ./InstructionFiles.mdDiscovery: ./Discovery.mdUserCheckpoint: ./UserCheckpoint.mdPlanning: ./Planning.mdImplementation: ./Implementation.md

          The initial bundle admits only Markdown component files named explicitly in that map. Values are POSIX paths relative to the root document's directory in the same pinned Git tree. Absolute paths, parent traversal, globs, directories, URLs, TypeScript components, package imports, generated paths and duplicate names are refused. Names that are structural constructs, reserved host registrations, or core defaults are refused in this slice; the bundle exists for workflow-owned stage components, not for replacing language or security primitives.

          On start, the trusted workflow host reads the root and every declared component from the same pinned commit, validates every component declaration, and constructs a normalized bundle:

          • component name;
          • canonical repository-relative component path;
          • component source hash; and
          • the retained component source needed for durable selection and replay.

          That normalized bundle is part of workflow-definition identity. Compatible reuse compares it with the run ID, descriptor, definition base and normalized props. A caller-selected run ID with a different bundle is an incompatible definition reuse, even when the root path and props are unchanged.

          On resume, the host reconstructs the same bundle from retained definition metadata and the pinned Git object, verifies the retained hashes, and installs only that bundle for the live execution. A current checkout file with the same name or path is ignored. Missing, unreadable, changed, incompatible or unauthorized component code is refused before that code executes or advances the workflow.

          Bundle installation is a trusted-host operation, not public middleware. It gives the document no capability to authorize more code. Public middleware, props, eval bindings, generated source, and a same-name file in the mutable checkout may refuse or narrow behavior, but cannot add bundle entries, replace retained component source, or widen what code is authorized to execute.

          Retained component-selection history must agree with the authorized bundle. A replay that tries to restore a component selection outside the retained bundle, with a mismatched source hash, or with a mutable-checkout path in place of retained source is refused before component code executes or any later durable effect appends.

          The bundle is not generated-XMD admission. A generated fragment still cannot name these components, Fetch, or any other component until #369 admits pinned identities and exact bounded requests.

          Material choices still use #367 suspension and #300 typed answer delivery. Delivering an answer records it without executing the workflow. Continuation occurs only through the ordinary explicit resume path, which acquires the executor lock and claims the retained answer durably. Automatic scheduling remains #300's later slice.

          Do not add file watchers, unattended arbitration, a second executor authority, or a generic workflow component search path here.

          Acceptance: slice 1

          • xmd workflow start accepts a root-declared closed component bundle and records the normalized bundle in workflow-definition identity.
          • xmd workflow resume reconstructs and validates the same retained bundle before any bundled component executes.
          • A workflow root can invoke InstructionFiles, Discovery, UserCheckpoint, Planning, and Implementation from trusted bundle source under start and resume.
          • The bundle reads component source from the pinned definition commit, never from mutable checkout content beside the retained root.
          • Compatible reuse of a caller-selected run ID requires the same normalized component bundle; a changed component path, source hash, name set, or root-relative declaration is refused as incompatible definition reuse.
          • Retained-history admission refuses component selections outside the retained bundle or with mismatched retained source before executing component code or appending later durable effects.
          • Missing, unreadable, malformed, schema-invalid, incompatible, duplicate, escaping, non-Markdown, structural-name, reserved-name, and core-default-name bundle entries are refused before component code executes.
          • Ordinary xmd run component resolution is unchanged.
          • Workflow execution gains no generic repository component search path.
          • Public middleware, props, eval bindings, generated source, or same-name checkout files cannot add, replace, or widen authorized component code.
          • Generated-XMD admission remains unchanged and still belongs to Evaluate Agent-generated XMD through a constrained allowlist #369.
          • Delivering an answer alone starts no execution; continuation still occurs only after explicit resume acquires the executor lock.
          • Focused tests use fixtures that exercise start, resume, compatible reuse, retained-history admission, mutable-checkout substitution, and refusal-before-execution. The ✨ Compose and certify the supervised adversarial implementation workflow #181 workflow documents consume the bundle when they are present on the implementation branch, but slice 1 does not require the complete adversarial loop to run.
          • Architecture and workflow/executable-MDX specifications describe the bundle identity, authority, replay, failure and compatibility boundaries in present tense.

          Acceptance: later complete composition

          • One supervised WorkflowRun reaches final acceptance across process interruption using retained suspension, typed answer delivery and explicit resume. Scheduled resume is Deliver answers to suspended workflows for later resumption #300's later slice and is not part of this acceptance.
          • Failed plan and pull-request verdicts return prescriptive prompts to the responsible retained Agent context.
          • Material choices suspend for user authority and never default to approval; only the exact validated retained answer may continue that request.
          • Agents receive no Workspace materialization or additional directories; XMD performs every admitted observation and mutation. The initial adapter-level tool suppression guarantee is limited as recorded by Run workflow Agents through XMD-mediated observations #302 and Require ACP adapters to enforce tool-free workflow Agent sessions #496.
          • Two repositories can participate through explicit named Repository/Worktree composition.
          • Commit, Push, PullRequest, and deferred Issue remain distinct durable or reconciled effects.
          • Every declared artifact and effect result is available to a later execution without manual copy/paste or hidden transcript state.
          • Failure and cancellation halt live resources while retaining explicit recoverable or terminal state.
          • No automatic watcher, unattended arbitration, or alternative executor authority is introduced by this composition story.

          Dependencies

          Slice 1: authorized workflow component bundle

          Later complete composition

          All of these are shipped:

          Remaining and deliberately outside this slice:

          End goal: #181.

          Out of scope

          • A generic workflow component search path.
          • Loading component code from the mutable checkout on resume.
          • TypeScript component bundles, package component bundles, imports, globs or directory bundles.
          • Replacing structural constructs, reserved host registrations or core defaults through the workflow bundle.
          • Generated-XMD admission of bundled components or Fetch; Evaluate Agent-generated XMD through a constrained allowlist #369 owns that later proof.
          • Automatically resuming as part of answer delivery.
          • File watchers, branch watchers, unattended iteration arbitration or a public remote-host selector.
          • Replacing the executor lock, lifecycle state machine, journal secret policy, suspension identity, Git-host reconciliation contract, or Agent authority model.
          • Portable ACP adapter-level no-tool enforcement; Require ACP adapters to enforce tool-free workflow Agent sessions #496 owns that non-blocking hardening.

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            No labels
            No labels

            Projects

            No projects

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Compose the supervised adversarial implementation workflow #301

              Description

              @taras

              Story

              As a user, I want the complete adversarial implementation loop to run under explicit supervision, so I retain product authority while deterministic XMD components own operational effects.

              Current delivery state

              Slice 2 is now the only open unit, and it is the composition itself. Its old three-PR sequence is collapsed: #577 shipped the durable workflow checkpoint at 1d528219, and #580 shipped the URL-addressed pull-request reads at f230e8fd. What remains is PR #181, which owns the complete composition and its evidence.

              Implementation at exact PR #181 head 9ef6edcf205f57ba08cc84ba7a009919ed403957 exposed two defects in shipped prerequisites. Both are complete: #588 shipped ordinary proven non-force fast-forward advancement for <Git.Push /> through PR #594, and #589 restored continuation through durable effects inside generated XMD through PR #597. Slice 2 is active again on PR #181; after rebasing, AC3 and AC4 become positive acceptance cases rather than blocker diagnostics.

              The shipped substrate now includes:

              Every complete-loop effect the composition consumes is now shipped: Git.Push (#370, PR #495), PullRequest (#295, PRs #500/#504), the URL-addressed pull-request reads (#576, PR #580), deferred Issue (#296, PR #516), XMD-mediated workflow Agent turns and the authored observation loop (#302, PRs #549/#550), generated-XMD observation and mutation admission (#369, PRs #497/#572/#574), expression-prop undefined omission (#537, PR #541), and the durable checkpoint (#577). The Agent still receives no Workspace materialization, additionalDirectories, MCP server, native tool, credential or direct mutation channel. Portable adapter-level no-tool enforcement remains the non-blocking #496 follow-up.

              PR #493 implemented slice 1: the boundary between retained workflow-definition identity and the authored stage components the root invokes.

              Delivery slices

              Slice 1: authorized workflow component bundle

              Implement a closed workflow component bundle that lets a retained workflow definition invoke trusted Markdown component code without reintroducing a mutable repository component search path.

              The first consumer is the adversarial workflow's stage components:

              • InstructionFiles
              • Discovery
              • UserCheckpoint
              • Planning
              • Implementation

              Those names become reachable under xmd workflow start and xmd workflow resume only when the trusted workflow host authorizes their exact component source as part of the workflow definition. Ordinary xmd run component resolution remains unchanged.

              Slice 2: complete supervised adversarial composition

              Compose the root workflow through discovery, handoff validation, planning convergence, authorization, XMD-mediated Agent observations and proposals, constrained generated XMD, local Git effects, explicit Push, PullRequest create/update, its URL-addressed evidence reads, review, deferred Issue creation, revision, and final acceptance — as one supervised run under xmd workflow start, typed answer delivery and explicit xmd workflow resume.

              The composition remains owned by PR #181 and is active. Rebase it onto current main, convert AC3 and AC4 into successful end-to-end regressions, and complete the frozen matrix.

              Scheduling, watchers and unattended resume are outside it. A resume stays an explicit act; the scheduling slice is #300's. This slice defines no additional persistence model, Agent authority model, Git-host reconciliation policy, or executor.

              Slice 1 contract

              xmd workflow start continues to establish an immutable workflow definition from Git. It executes bytes from the pinned commit, not from the caller's mutable working tree. The generic workflow component search path remains empty.

              A workflow root may declare a closed component bundle in frontmatter:

              workflow:
              components:
              InstructionFiles: ./InstructionFiles.mdDiscovery: ./Discovery.mdUserCheckpoint: ./UserCheckpoint.mdPlanning: ./Planning.mdImplementation: ./Implementation.md

              The initial bundle admits only Markdown component files named explicitly in that map. Values are POSIX paths relative to the root document's directory in the same pinned Git tree. Absolute paths, parent traversal, globs, directories, URLs, TypeScript components, package imports, generated paths and duplicate names are refused. Names that are structural constructs, reserved host registrations, or core defaults are refused in this slice; the bundle exists for workflow-owned stage components, not for replacing language or security primitives.

              On start, the trusted workflow host reads the root and every declared component from the same pinned commit, validates every component declaration, and constructs a normalized bundle:

              • component name;
              • canonical repository-relative component path;
              • component source hash; and
              • the retained component source needed for durable selection and replay.

              That normalized bundle is part of workflow-definition identity. Compatible reuse compares it with the run ID, descriptor, definition base and normalized props. A caller-selected run ID with a different bundle is an incompatible definition reuse, even when the root path and props are unchanged.

              On resume, the host reconstructs the same bundle from retained definition metadata and the pinned Git object, verifies the retained hashes, and installs only that bundle for the live execution. A current checkout file with the same name or path is ignored. Missing, unreadable, changed, incompatible or unauthorized component code is refused before that code executes or advances the workflow.

              Bundle installation is a trusted-host operation, not public middleware. It gives the document no capability to authorize more code. Public middleware, props, eval bindings, generated source, and a same-name file in the mutable checkout may refuse or narrow behavior, but cannot add bundle entries, replace retained component source, or widen what code is authorized to execute.

              Retained component-selection history must agree with the authorized bundle. A replay that tries to restore a component selection outside the retained bundle, with a mismatched source hash, or with a mutable-checkout path in place of retained source is refused before component code executes or any later durable effect appends.

              The bundle is not generated-XMD admission. A generated fragment still cannot name these components, Fetch, or any other component until #369 admits pinned identities and exact bounded requests.

              Material choices still use #367 suspension and #300 typed answer delivery. Delivering an answer records it without executing the workflow. Continuation occurs only through the ordinary explicit resume path, which acquires the executor lock and claims the retained answer durably. Automatic scheduling remains #300's later slice.

              Do not add file watchers, unattended arbitration, a second executor authority, or a generic workflow component search path here.

              Acceptance: slice 1

              • xmd workflow start accepts a root-declared closed component bundle and records the normalized bundle in workflow-definition identity.
              • xmd workflow resume reconstructs and validates the same retained bundle before any bundled component executes.
              • A workflow root can invoke InstructionFiles, Discovery, UserCheckpoint, Planning, and Implementation from trusted bundle source under start and resume.
              • The bundle reads component source from the pinned definition commit, never from mutable checkout content beside the retained root.
              • Compatible reuse of a caller-selected run ID requires the same normalized component bundle; a changed component path, source hash, name set, or root-relative declaration is refused as incompatible definition reuse.
              • Retained-history admission refuses component selections outside the retained bundle or with mismatched retained source before executing component code or appending later durable effects.
              • Missing, unreadable, malformed, schema-invalid, incompatible, duplicate, escaping, non-Markdown, structural-name, reserved-name, and core-default-name bundle entries are refused before component code executes.
              • Ordinary xmd run component resolution is unchanged.
              • Workflow execution gains no generic repository component search path.
              • Public middleware, props, eval bindings, generated source, or same-name checkout files cannot add, replace, or widen authorized component code.
              • Generated-XMD admission remains unchanged and still belongs to Evaluate Agent-generated XMD through a constrained allowlist #369.
              • Delivering an answer alone starts no execution; continuation still occurs only after explicit resume acquires the executor lock.
              • Focused tests use fixtures that exercise start, resume, compatible reuse, retained-history admission, mutable-checkout substitution, and refusal-before-execution. The ✨ Compose and certify the supervised adversarial implementation workflow #181 workflow documents consume the bundle when they are present on the implementation branch, but slice 1 does not require the complete adversarial loop to run.
              • Architecture and workflow/executable-MDX specifications describe the bundle identity, authority, replay, failure and compatibility boundaries in present tense.

              Acceptance: later complete composition

              • One supervised WorkflowRun reaches final acceptance across process interruption using retained suspension, typed answer delivery and explicit resume. Scheduled resume is Deliver answers to suspended workflows for later resumption #300's later slice and is not part of this acceptance.
              • Failed plan and pull-request verdicts return prescriptive prompts to the responsible retained Agent context.
              • Material choices suspend for user authority and never default to approval; only the exact validated retained answer may continue that request.
              • Agents receive no Workspace materialization or additional directories; XMD performs every admitted observation and mutation. The initial adapter-level tool suppression guarantee is limited as recorded by Run workflow Agents through XMD-mediated observations #302 and Require ACP adapters to enforce tool-free workflow Agent sessions #496.
              • Two repositories can participate through explicit named Repository/Worktree composition.
              • Commit, Push, PullRequest, and deferred Issue remain distinct durable or reconciled effects.
              • Every declared artifact and effect result is available to a later execution without manual copy/paste or hidden transcript state.
              • Failure and cancellation halt live resources while retaining explicit recoverable or terminal state.
              • No automatic watcher, unattended arbitration, or alternative executor authority is introduced by this composition story.

              Dependencies

              Slice 1: authorized workflow component bundle

              Later complete composition

              All of these are shipped:

              Remaining and deliberately outside this slice:

              End goal: #181.

              Out of scope

              • A generic workflow component search path.
              • Loading component code from the mutable checkout on resume.
              • TypeScript component bundles, package component bundles, imports, globs or directory bundles.
              • Replacing structural constructs, reserved host registrations or core defaults through the workflow bundle.
              • Generated-XMD admission of bundled components or Fetch; Evaluate Agent-generated XMD through a constrained allowlist #369 owns that later proof.
              • Automatically resuming as part of answer delivery.
              • File watchers, branch watchers, unattended iteration arbitration or a public remote-host selector.
              • Replacing the executor lock, lifecycle state machine, journal secret policy, suspension identity, Git-host reconciliation contract, or Agent authority model.
              • Portable ACP adapter-level no-tool enforcement; Require ACP adapters to enforce tool-free workflow Agent sessions #496 owns that non-blocking hardening.

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                No labels
                No labels

                Projects

                No projects

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  Compose the supervised adversarial implementation workflow #301

                  Description

                  @taras

                  Story

                  As a user, I want the complete adversarial implementation loop to run under explicit supervision, so I retain product authority while deterministic XMD components own operational effects.

                  Current delivery state

                  Slice 2 is now the only open unit, and it is the composition itself. Its old three-PR sequence is collapsed: #577 shipped the durable workflow checkpoint at 1d528219, and #580 shipped the URL-addressed pull-request reads at f230e8fd. What remains is PR #181, which owns the complete composition and its evidence.

                  Implementation at exact PR #181 head 9ef6edcf205f57ba08cc84ba7a009919ed403957 exposed two defects in shipped prerequisites. Both are complete: #588 shipped ordinary proven non-force fast-forward advancement for <Git.Push /> through PR #594, and #589 restored continuation through durable effects inside generated XMD through PR #597. Slice 2 is active again on PR #181; after rebasing, AC3 and AC4 become positive acceptance cases rather than blocker diagnostics.

                  The shipped substrate now includes:

                  Every complete-loop effect the composition consumes is now shipped: Git.Push (#370, PR #495), PullRequest (#295, PRs #500/#504), the URL-addressed pull-request reads (#576, PR #580), deferred Issue (#296, PR #516), XMD-mediated workflow Agent turns and the authored observation loop (#302, PRs #549/#550), generated-XMD observation and mutation admission (#369, PRs #497/#572/#574), expression-prop undefined omission (#537, PR #541), and the durable checkpoint (#577). The Agent still receives no Workspace materialization, additionalDirectories, MCP server, native tool, credential or direct mutation channel. Portable adapter-level no-tool enforcement remains the non-blocking #496 follow-up.

                  PR #493 implemented slice 1: the boundary between retained workflow-definition identity and the authored stage components the root invokes.

                  Delivery slices

                  Slice 1: authorized workflow component bundle

                  Implement a closed workflow component bundle that lets a retained workflow definition invoke trusted Markdown component code without reintroducing a mutable repository component search path.

                  The first consumer is the adversarial workflow's stage components:

                  • InstructionFiles
                  • Discovery
                  • UserCheckpoint
                  • Planning
                  • Implementation

                  Those names become reachable under xmd workflow start and xmd workflow resume only when the trusted workflow host authorizes their exact component source as part of the workflow definition. Ordinary xmd run component resolution remains unchanged.

                  Slice 2: complete supervised adversarial composition

                  Compose the root workflow through discovery, handoff validation, planning convergence, authorization, XMD-mediated Agent observations and proposals, constrained generated XMD, local Git effects, explicit Push, PullRequest create/update, its URL-addressed evidence reads, review, deferred Issue creation, revision, and final acceptance — as one supervised run under xmd workflow start, typed answer delivery and explicit xmd workflow resume.

                  The composition remains owned by PR #181 and is active. Rebase it onto current main, convert AC3 and AC4 into successful end-to-end regressions, and complete the frozen matrix.

                  Scheduling, watchers and unattended resume are outside it. A resume stays an explicit act; the scheduling slice is #300's. This slice defines no additional persistence model, Agent authority model, Git-host reconciliation policy, or executor.

                  Slice 1 contract

                  xmd workflow start continues to establish an immutable workflow definition from Git. It executes bytes from the pinned commit, not from the caller's mutable working tree. The generic workflow component search path remains empty.

                  A workflow root may declare a closed component bundle in frontmatter:

                  workflow:
                  components:
                  InstructionFiles: ./InstructionFiles.mdDiscovery: ./Discovery.mdUserCheckpoint: ./UserCheckpoint.mdPlanning: ./Planning.mdImplementation: ./Implementation.md

                  The initial bundle admits only Markdown component files named explicitly in that map. Values are POSIX paths relative to the root document's directory in the same pinned Git tree. Absolute paths, parent traversal, globs, directories, URLs, TypeScript components, package imports, generated paths and duplicate names are refused. Names that are structural constructs, reserved host registrations, or core defaults are refused in this slice; the bundle exists for workflow-owned stage components, not for replacing language or security primitives.

                  On start, the trusted workflow host reads the root and every declared component from the same pinned commit, validates every component declaration, and constructs a normalized bundle:

                  • component name;
                  • canonical repository-relative component path;
                  • component source hash; and
                  • the retained component source needed for durable selection and replay.

                  That normalized bundle is part of workflow-definition identity. Compatible reuse compares it with the run ID, descriptor, definition base and normalized props. A caller-selected run ID with a different bundle is an incompatible definition reuse, even when the root path and props are unchanged.

                  On resume, the host reconstructs the same bundle from retained definition metadata and the pinned Git object, verifies the retained hashes, and installs only that bundle for the live execution. A current checkout file with the same name or path is ignored. Missing, unreadable, changed, incompatible or unauthorized component code is refused before that code executes or advances the workflow.

                  Bundle installation is a trusted-host operation, not public middleware. It gives the document no capability to authorize more code. Public middleware, props, eval bindings, generated source, and a same-name file in the mutable checkout may refuse or narrow behavior, but cannot add bundle entries, replace retained component source, or widen what code is authorized to execute.

                  Retained component-selection history must agree with the authorized bundle. A replay that tries to restore a component selection outside the retained bundle, with a mismatched source hash, or with a mutable-checkout path in place of retained source is refused before component code executes or any later durable effect appends.

                  The bundle is not generated-XMD admission. A generated fragment still cannot name these components, Fetch, or any other component until #369 admits pinned identities and exact bounded requests.

                  Material choices still use #367 suspension and #300 typed answer delivery. Delivering an answer records it without executing the workflow. Continuation occurs only through the ordinary explicit resume path, which acquires the executor lock and claims the retained answer durably. Automatic scheduling remains #300's later slice.

                  Do not add file watchers, unattended arbitration, a second executor authority, or a generic workflow component search path here.

                  Acceptance: slice 1

                  • xmd workflow start accepts a root-declared closed component bundle and records the normalized bundle in workflow-definition identity.
                  • xmd workflow resume reconstructs and validates the same retained bundle before any bundled component executes.
                  • A workflow root can invoke InstructionFiles, Discovery, UserCheckpoint, Planning, and Implementation from trusted bundle source under start and resume.
                  • The bundle reads component source from the pinned definition commit, never from mutable checkout content beside the retained root.
                  • Compatible reuse of a caller-selected run ID requires the same normalized component bundle; a changed component path, source hash, name set, or root-relative declaration is refused as incompatible definition reuse.
                  • Retained-history admission refuses component selections outside the retained bundle or with mismatched retained source before executing component code or appending later durable effects.
                  • Missing, unreadable, malformed, schema-invalid, incompatible, duplicate, escaping, non-Markdown, structural-name, reserved-name, and core-default-name bundle entries are refused before component code executes.
                  • Ordinary xmd run component resolution is unchanged.
                  • Workflow execution gains no generic repository component search path.
                  • Public middleware, props, eval bindings, generated source, or same-name checkout files cannot add, replace, or widen authorized component code.
                  • Generated-XMD admission remains unchanged and still belongs to Evaluate Agent-generated XMD through a constrained allowlist #369.
                  • Delivering an answer alone starts no execution; continuation still occurs only after explicit resume acquires the executor lock.
                  • Focused tests use fixtures that exercise start, resume, compatible reuse, retained-history admission, mutable-checkout substitution, and refusal-before-execution. The ✨ Compose and certify the supervised adversarial implementation workflow #181 workflow documents consume the bundle when they are present on the implementation branch, but slice 1 does not require the complete adversarial loop to run.
                  • Architecture and workflow/executable-MDX specifications describe the bundle identity, authority, replay, failure and compatibility boundaries in present tense.

                  Acceptance: later complete composition

                  • One supervised WorkflowRun reaches final acceptance across process interruption using retained suspension, typed answer delivery and explicit resume. Scheduled resume is Deliver answers to suspended workflows for later resumption #300's later slice and is not part of this acceptance.
                  • Failed plan and pull-request verdicts return prescriptive prompts to the responsible retained Agent context.
                  • Material choices suspend for user authority and never default to approval; only the exact validated retained answer may continue that request.
                  • Agents receive no Workspace materialization or additional directories; XMD performs every admitted observation and mutation. The initial adapter-level tool suppression guarantee is limited as recorded by Run workflow Agents through XMD-mediated observations #302 and Require ACP adapters to enforce tool-free workflow Agent sessions #496.
                  • Two repositories can participate through explicit named Repository/Worktree composition.
                  • Commit, Push, PullRequest, and deferred Issue remain distinct durable or reconciled effects.
                  • Every declared artifact and effect result is available to a later execution without manual copy/paste or hidden transcript state.
                  • Failure and cancellation halt live resources while retaining explicit recoverable or terminal state.
                  • No automatic watcher, unattended arbitration, or alternative executor authority is introduced by this composition story.

                  Dependencies

                  Slice 1: authorized workflow component bundle

                  Later complete composition

                  All of these are shipped:

                  Remaining and deliberately outside this slice:

                  End goal: #181.

                  Out of scope

                  • A generic workflow component search path.
                  • Loading component code from the mutable checkout on resume.
                  • TypeScript component bundles, package component bundles, imports, globs or directory bundles.
                  • Replacing structural constructs, reserved host registrations or core defaults through the workflow bundle.
                  • Generated-XMD admission of bundled components or Fetch; Evaluate Agent-generated XMD through a constrained allowlist #369 owns that later proof.
                  • Automatically resuming as part of answer delivery.
                  • File watchers, branch watchers, unattended iteration arbitration or a public remote-host selector.
                  • Replacing the executor lock, lifecycle state machine, journal secret policy, suspension identity, Git-host reconciliation contract, or Agent authority model.
                  • Portable ACP adapter-level no-tool enforcement; Require ACP adapters to enforce tool-free workflow Agent sessions #496 owns that non-blocking hardening.

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    No labels
                    No labels

                    Projects

                    No projects

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      Compose the supervised adversarial implementation workflow #301

                      Description

                      @taras

                      Story

                      As a user, I want the complete adversarial implementation loop to run under explicit supervision, so I retain product authority while deterministic XMD components own operational effects.

                      Current delivery state

                      Slice 2 is now the only open unit, and it is the composition itself. Its old three-PR sequence is collapsed: #577 shipped the durable workflow checkpoint at 1d528219, and #580 shipped the URL-addressed pull-request reads at f230e8fd. What remains is PR #181, which owns the complete composition and its evidence.

                      Implementation at exact PR #181 head 9ef6edcf205f57ba08cc84ba7a009919ed403957 exposed two defects in shipped prerequisites. Both are complete: #588 shipped ordinary proven non-force fast-forward advancement for <Git.Push /> through PR #594, and #589 restored continuation through durable effects inside generated XMD through PR #597. Slice 2 is active again on PR #181; after rebasing, AC3 and AC4 become positive acceptance cases rather than blocker diagnostics.

                      The shipped substrate now includes:

                      Every complete-loop effect the composition consumes is now shipped: Git.Push (#370, PR #495), PullRequest (#295, PRs #500/#504), the URL-addressed pull-request reads (#576, PR #580), deferred Issue (#296, PR #516), XMD-mediated workflow Agent turns and the authored observation loop (#302, PRs #549/#550), generated-XMD observation and mutation admission (#369, PRs #497/#572/#574), expression-prop undefined omission (#537, PR #541), and the durable checkpoint (#577). The Agent still receives no Workspace materialization, additionalDirectories, MCP server, native tool, credential or direct mutation channel. Portable adapter-level no-tool enforcement remains the non-blocking #496 follow-up.

                      PR #493 implemented slice 1: the boundary between retained workflow-definition identity and the authored stage components the root invokes.

                      Delivery slices

                      Slice 1: authorized workflow component bundle

                      Implement a closed workflow component bundle that lets a retained workflow definition invoke trusted Markdown component code without reintroducing a mutable repository component search path.

                      The first consumer is the adversarial workflow's stage components:

                      • InstructionFiles
                      • Discovery
                      • UserCheckpoint
                      • Planning
                      • Implementation

                      Those names become reachable under xmd workflow start and xmd workflow resume only when the trusted workflow host authorizes their exact component source as part of the workflow definition. Ordinary xmd run component resolution remains unchanged.

                      Slice 2: complete supervised adversarial composition

                      Compose the root workflow through discovery, handoff validation, planning convergence, authorization, XMD-mediated Agent observations and proposals, constrained generated XMD, local Git effects, explicit Push, PullRequest create/update, its URL-addressed evidence reads, review, deferred Issue creation, revision, and final acceptance — as one supervised run under xmd workflow start, typed answer delivery and explicit xmd workflow resume.

                      The composition remains owned by PR #181 and is active. Rebase it onto current main, convert AC3 and AC4 into successful end-to-end regressions, and complete the frozen matrix.

                      Scheduling, watchers and unattended resume are outside it. A resume stays an explicit act; the scheduling slice is #300's. This slice defines no additional persistence model, Agent authority model, Git-host reconciliation policy, or executor.

                      Slice 1 contract

                      xmd workflow start continues to establish an immutable workflow definition from Git. It executes bytes from the pinned commit, not from the caller's mutable working tree. The generic workflow component search path remains empty.

                      A workflow root may declare a closed component bundle in frontmatter:

                      workflow:
                      components:
                      InstructionFiles: ./InstructionFiles.mdDiscovery: ./Discovery.mdUserCheckpoint: ./UserCheckpoint.mdPlanning: ./Planning.mdImplementation: ./Implementation.md

                      The initial bundle admits only Markdown component files named explicitly in that map. Values are POSIX paths relative to the root document's directory in the same pinned Git tree. Absolute paths, parent traversal, globs, directories, URLs, TypeScript components, package imports, generated paths and duplicate names are refused. Names that are structural constructs, reserved host registrations, or core defaults are refused in this slice; the bundle exists for workflow-owned stage components, not for replacing language or security primitives.

                      On start, the trusted workflow host reads the root and every declared component from the same pinned commit, validates every component declaration, and constructs a normalized bundle:

                      • component name;
                      • canonical repository-relative component path;
                      • component source hash; and
                      • the retained component source needed for durable selection and replay.

                      That normalized bundle is part of workflow-definition identity. Compatible reuse compares it with the run ID, descriptor, definition base and normalized props. A caller-selected run ID with a different bundle is an incompatible definition reuse, even when the root path and props are unchanged.

                      On resume, the host reconstructs the same bundle from retained definition metadata and the pinned Git object, verifies the retained hashes, and installs only that bundle for the live execution. A current checkout file with the same name or path is ignored. Missing, unreadable, changed, incompatible or unauthorized component code is refused before that code executes or advances the workflow.

                      Bundle installation is a trusted-host operation, not public middleware. It gives the document no capability to authorize more code. Public middleware, props, eval bindings, generated source, and a same-name file in the mutable checkout may refuse or narrow behavior, but cannot add bundle entries, replace retained component source, or widen what code is authorized to execute.

                      Retained component-selection history must agree with the authorized bundle. A replay that tries to restore a component selection outside the retained bundle, with a mismatched source hash, or with a mutable-checkout path in place of retained source is refused before component code executes or any later durable effect appends.

                      The bundle is not generated-XMD admission. A generated fragment still cannot name these components, Fetch, or any other component until #369 admits pinned identities and exact bounded requests.

                      Material choices still use #367 suspension and #300 typed answer delivery. Delivering an answer records it without executing the workflow. Continuation occurs only through the ordinary explicit resume path, which acquires the executor lock and claims the retained answer durably. Automatic scheduling remains #300's later slice.

                      Do not add file watchers, unattended arbitration, a second executor authority, or a generic workflow component search path here.

                      Acceptance: slice 1

                      • xmd workflow start accepts a root-declared closed component bundle and records the normalized bundle in workflow-definition identity.
                      • xmd workflow resume reconstructs and validates the same retained bundle before any bundled component executes.
                      • A workflow root can invoke InstructionFiles, Discovery, UserCheckpoint, Planning, and Implementation from trusted bundle source under start and resume.
                      • The bundle reads component source from the pinned definition commit, never from mutable checkout content beside the retained root.
                      • Compatible reuse of a caller-selected run ID requires the same normalized component bundle; a changed component path, source hash, name set, or root-relative declaration is refused as incompatible definition reuse.
                      • Retained-history admission refuses component selections outside the retained bundle or with mismatched retained source before executing component code or appending later durable effects.
                      • Missing, unreadable, malformed, schema-invalid, incompatible, duplicate, escaping, non-Markdown, structural-name, reserved-name, and core-default-name bundle entries are refused before component code executes.
                      • Ordinary xmd run component resolution is unchanged.
                      • Workflow execution gains no generic repository component search path.
                      • Public middleware, props, eval bindings, generated source, or same-name checkout files cannot add, replace, or widen authorized component code.
                      • Generated-XMD admission remains unchanged and still belongs to Evaluate Agent-generated XMD through a constrained allowlist #369.
                      • Delivering an answer alone starts no execution; continuation still occurs only after explicit resume acquires the executor lock.
                      • Focused tests use fixtures that exercise start, resume, compatible reuse, retained-history admission, mutable-checkout substitution, and refusal-before-execution. The ✨ Compose and certify the supervised adversarial implementation workflow #181 workflow documents consume the bundle when they are present on the implementation branch, but slice 1 does not require the complete adversarial loop to run.
                      • Architecture and workflow/executable-MDX specifications describe the bundle identity, authority, replay, failure and compatibility boundaries in present tense.

                      Acceptance: later complete composition

                      • One supervised WorkflowRun reaches final acceptance across process interruption using retained suspension, typed answer delivery and explicit resume. Scheduled resume is Deliver answers to suspended workflows for later resumption #300's later slice and is not part of this acceptance.
                      • Failed plan and pull-request verdicts return prescriptive prompts to the responsible retained Agent context.
                      • Material choices suspend for user authority and never default to approval; only the exact validated retained answer may continue that request.
                      • Agents receive no Workspace materialization or additional directories; XMD performs every admitted observation and mutation. The initial adapter-level tool suppression guarantee is limited as recorded by Run workflow Agents through XMD-mediated observations #302 and Require ACP adapters to enforce tool-free workflow Agent sessions #496.
                      • Two repositories can participate through explicit named Repository/Worktree composition.
                      • Commit, Push, PullRequest, and deferred Issue remain distinct durable or reconciled effects.
                      • Every declared artifact and effect result is available to a later execution without manual copy/paste or hidden transcript state.
                      • Failure and cancellation halt live resources while retaining explicit recoverable or terminal state.
                      • No automatic watcher, unattended arbitration, or alternative executor authority is introduced by this composition story.

                      Dependencies

                      Slice 1: authorized workflow component bundle

                      Later complete composition

                      All of these are shipped:

                      Remaining and deliberately outside this slice:

                      End goal: #181.

                      Out of scope

                      • A generic workflow component search path.
                      • Loading component code from the mutable checkout on resume.
                      • TypeScript component bundles, package component bundles, imports, globs or directory bundles.
                      • Replacing structural constructs, reserved host registrations or core defaults through the workflow bundle.
                      • Generated-XMD admission of bundled components or Fetch; Evaluate Agent-generated XMD through a constrained allowlist #369 owns that later proof.
                      • Automatically resuming as part of answer delivery.
                      • File watchers, branch watchers, unattended iteration arbitration or a public remote-host selector.
                      • Replacing the executor lock, lifecycle state machine, journal secret policy, suspension identity, Git-host reconciliation contract, or Agent authority model.
                      • Portable ACP adapter-level no-tool enforcement; Require ACP adapters to enforce tool-free workflow Agent sessions #496 owns that non-blocking hardening.

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        No labels
                        No labels

                        Projects

                        No projects

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          Compose the supervised adversarial implementation workflow #301

                          Description

                          @taras

                          Story

                          As a user, I want the complete adversarial implementation loop to run under explicit supervision, so I retain product authority while deterministic XMD components own operational effects.

                          Current delivery state

                          Slice 2 is now the only open unit, and it is the composition itself. Its old three-PR sequence is collapsed: #577 shipped the durable workflow checkpoint at 1d528219, and #580 shipped the URL-addressed pull-request reads at f230e8fd. What remains is PR #181, which owns the complete composition and its evidence.

                          Implementation at exact PR #181 head 9ef6edcf205f57ba08cc84ba7a009919ed403957 exposed two defects in shipped prerequisites. Both are complete: #588 shipped ordinary proven non-force fast-forward advancement for <Git.Push /> through PR #594, and #589 restored continuation through durable effects inside generated XMD through PR #597. Slice 2 is active again on PR #181; after rebasing, AC3 and AC4 become positive acceptance cases rather than blocker diagnostics.

                          The shipped substrate now includes:

                          Every complete-loop effect the composition consumes is now shipped: Git.Push (#370, PR #495), PullRequest (#295, PRs #500/#504), the URL-addressed pull-request reads (#576, PR #580), deferred Issue (#296, PR #516), XMD-mediated workflow Agent turns and the authored observation loop (#302, PRs #549/#550), generated-XMD observation and mutation admission (#369, PRs #497/#572/#574), expression-prop undefined omission (#537, PR #541), and the durable checkpoint (#577). The Agent still receives no Workspace materialization, additionalDirectories, MCP server, native tool, credential or direct mutation channel. Portable adapter-level no-tool enforcement remains the non-blocking #496 follow-up.

                          PR #493 implemented slice 1: the boundary between retained workflow-definition identity and the authored stage components the root invokes.

                          Delivery slices

                          Slice 1: authorized workflow component bundle

                          Implement a closed workflow component bundle that lets a retained workflow definition invoke trusted Markdown component code without reintroducing a mutable repository component search path.

                          The first consumer is the adversarial workflow's stage components:

                          • InstructionFiles
                          • Discovery
                          • UserCheckpoint
                          • Planning
                          • Implementation

                          Those names become reachable under xmd workflow start and xmd workflow resume only when the trusted workflow host authorizes their exact component source as part of the workflow definition. Ordinary xmd run component resolution remains unchanged.

                          Slice 2: complete supervised adversarial composition

                          Compose the root workflow through discovery, handoff validation, planning convergence, authorization, XMD-mediated Agent observations and proposals, constrained generated XMD, local Git effects, explicit Push, PullRequest create/update, its URL-addressed evidence reads, review, deferred Issue creation, revision, and final acceptance — as one supervised run under xmd workflow start, typed answer delivery and explicit xmd workflow resume.

                          The composition remains owned by PR #181 and is active. Rebase it onto current main, convert AC3 and AC4 into successful end-to-end regressions, and complete the frozen matrix.

                          Scheduling, watchers and unattended resume are outside it. A resume stays an explicit act; the scheduling slice is #300's. This slice defines no additional persistence model, Agent authority model, Git-host reconciliation policy, or executor.

                          Slice 1 contract

                          xmd workflow start continues to establish an immutable workflow definition from Git. It executes bytes from the pinned commit, not from the caller's mutable working tree. The generic workflow component search path remains empty.

                          A workflow root may declare a closed component bundle in frontmatter:

                          workflow:
                          components:
                          InstructionFiles: ./InstructionFiles.mdDiscovery: ./Discovery.mdUserCheckpoint: ./UserCheckpoint.mdPlanning: ./Planning.mdImplementation: ./Implementation.md

                          The initial bundle admits only Markdown component files named explicitly in that map. Values are POSIX paths relative to the root document's directory in the same pinned Git tree. Absolute paths, parent traversal, globs, directories, URLs, TypeScript components, package imports, generated paths and duplicate names are refused. Names that are structural constructs, reserved host registrations, or core defaults are refused in this slice; the bundle exists for workflow-owned stage components, not for replacing language or security primitives.

                          On start, the trusted workflow host reads the root and every declared component from the same pinned commit, validates every component declaration, and constructs a normalized bundle:

                          • component name;
                          • canonical repository-relative component path;
                          • component source hash; and
                          • the retained component source needed for durable selection and replay.

                          That normalized bundle is part of workflow-definition identity. Compatible reuse compares it with the run ID, descriptor, definition base and normalized props. A caller-selected run ID with a different bundle is an incompatible definition reuse, even when the root path and props are unchanged.

                          On resume, the host reconstructs the same bundle from retained definition metadata and the pinned Git object, verifies the retained hashes, and installs only that bundle for the live execution. A current checkout file with the same name or path is ignored. Missing, unreadable, changed, incompatible or unauthorized component code is refused before that code executes or advances the workflow.

                          Bundle installation is a trusted-host operation, not public middleware. It gives the document no capability to authorize more code. Public middleware, props, eval bindings, generated source, and a same-name file in the mutable checkout may refuse or narrow behavior, but cannot add bundle entries, replace retained component source, or widen what code is authorized to execute.

                          Retained component-selection history must agree with the authorized bundle. A replay that tries to restore a component selection outside the retained bundle, with a mismatched source hash, or with a mutable-checkout path in place of retained source is refused before component code executes or any later durable effect appends.

                          The bundle is not generated-XMD admission. A generated fragment still cannot name these components, Fetch, or any other component until #369 admits pinned identities and exact bounded requests.

                          Material choices still use #367 suspension and #300 typed answer delivery. Delivering an answer records it without executing the workflow. Continuation occurs only through the ordinary explicit resume path, which acquires the executor lock and claims the retained answer durably. Automatic scheduling remains #300's later slice.

                          Do not add file watchers, unattended arbitration, a second executor authority, or a generic workflow component search path here.

                          Acceptance: slice 1

                          • xmd workflow start accepts a root-declared closed component bundle and records the normalized bundle in workflow-definition identity.
                          • xmd workflow resume reconstructs and validates the same retained bundle before any bundled component executes.
                          • A workflow root can invoke InstructionFiles, Discovery, UserCheckpoint, Planning, and Implementation from trusted bundle source under start and resume.
                          • The bundle reads component source from the pinned definition commit, never from mutable checkout content beside the retained root.
                          • Compatible reuse of a caller-selected run ID requires the same normalized component bundle; a changed component path, source hash, name set, or root-relative declaration is refused as incompatible definition reuse.
                          • Retained-history admission refuses component selections outside the retained bundle or with mismatched retained source before executing component code or appending later durable effects.
                          • Missing, unreadable, malformed, schema-invalid, incompatible, duplicate, escaping, non-Markdown, structural-name, reserved-name, and core-default-name bundle entries are refused before component code executes.
                          • Ordinary xmd run component resolution is unchanged.
                          • Workflow execution gains no generic repository component search path.
                          • Public middleware, props, eval bindings, generated source, or same-name checkout files cannot add, replace, or widen authorized component code.
                          • Generated-XMD admission remains unchanged and still belongs to Evaluate Agent-generated XMD through a constrained allowlist #369.
                          • Delivering an answer alone starts no execution; continuation still occurs only after explicit resume acquires the executor lock.
                          • Focused tests use fixtures that exercise start, resume, compatible reuse, retained-history admission, mutable-checkout substitution, and refusal-before-execution. The ✨ Compose and certify the supervised adversarial implementation workflow #181 workflow documents consume the bundle when they are present on the implementation branch, but slice 1 does not require the complete adversarial loop to run.
                          • Architecture and workflow/executable-MDX specifications describe the bundle identity, authority, replay, failure and compatibility boundaries in present tense.

                          Acceptance: later complete composition

                          • One supervised WorkflowRun reaches final acceptance across process interruption using retained suspension, typed answer delivery and explicit resume. Scheduled resume is Deliver answers to suspended workflows for later resumption #300's later slice and is not part of this acceptance.
                          • Failed plan and pull-request verdicts return prescriptive prompts to the responsible retained Agent context.
                          • Material choices suspend for user authority and never default to approval; only the exact validated retained answer may continue that request.
                          • Agents receive no Workspace materialization or additional directories; XMD performs every admitted observation and mutation. The initial adapter-level tool suppression guarantee is limited as recorded by Run workflow Agents through XMD-mediated observations #302 and Require ACP adapters to enforce tool-free workflow Agent sessions #496.
                          • Two repositories can participate through explicit named Repository/Worktree composition.
                          • Commit, Push, PullRequest, and deferred Issue remain distinct durable or reconciled effects.
                          • Every declared artifact and effect result is available to a later execution without manual copy/paste or hidden transcript state.
                          • Failure and cancellation halt live resources while retaining explicit recoverable or terminal state.
                          • No automatic watcher, unattended arbitration, or alternative executor authority is introduced by this composition story.

                          Dependencies

                          Slice 1: authorized workflow component bundle

                          Later complete composition

                          All of these are shipped:

                          Remaining and deliberately outside this slice:

                          End goal: #181.

                          Out of scope

                          • A generic workflow component search path.
                          • Loading component code from the mutable checkout on resume.
                          • TypeScript component bundles, package component bundles, imports, globs or directory bundles.
                          • Replacing structural constructs, reserved host registrations or core defaults through the workflow bundle.
                          • Generated-XMD admission of bundled components or Fetch; Evaluate Agent-generated XMD through a constrained allowlist #369 owns that later proof.
                          • Automatically resuming as part of answer delivery.
                          • File watchers, branch watchers, unattended iteration arbitration or a public remote-host selector.
                          • Replacing the executor lock, lifecycle state machine, journal secret policy, suspension identity, Git-host reconciliation contract, or Agent authority model.
                          • Portable ACP adapter-level no-tool enforcement; Require ACP adapters to enforce tool-free workflow Agent sessions #496 owns that non-blocking hardening.

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            No labels
                            No labels

                            Projects

                            No projects

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              Compose the supervised adversarial implementation workflow #301

                              Description

                              @taras

                              Story

                              As a user, I want the complete adversarial implementation loop to run under explicit supervision, so I retain product authority while deterministic XMD components own operational effects.

                              Current delivery state

                              Slice 2 is now the only open unit, and it is the composition itself. Its old three-PR sequence is collapsed: #577 shipped the durable workflow checkpoint at 1d528219, and #580 shipped the URL-addressed pull-request reads at f230e8fd. What remains is PR #181, which owns the complete composition and its evidence.

                              Implementation at exact PR #181 head 9ef6edcf205f57ba08cc84ba7a009919ed403957 exposed two defects in shipped prerequisites. Both are complete: #588 shipped ordinary proven non-force fast-forward advancement for <Git.Push /> through PR #594, and #589 restored continuation through durable effects inside generated XMD through PR #597. Slice 2 is active again on PR #181; after rebasing, AC3 and AC4 become positive acceptance cases rather than blocker diagnostics.

                              The shipped substrate now includes:

                              Every complete-loop effect the composition consumes is now shipped: Git.Push (#370, PR #495), PullRequest (#295, PRs #500/#504), the URL-addressed pull-request reads (#576, PR #580), deferred Issue (#296, PR #516), XMD-mediated workflow Agent turns and the authored observation loop (#302, PRs #549/#550), generated-XMD observation and mutation admission (#369, PRs #497/#572/#574), expression-prop undefined omission (#537, PR #541), and the durable checkpoint (#577). The Agent still receives no Workspace materialization, additionalDirectories, MCP server, native tool, credential or direct mutation channel. Portable adapter-level no-tool enforcement remains the non-blocking #496 follow-up.

                              PR #493 implemented slice 1: the boundary between retained workflow-definition identity and the authored stage components the root invokes.

                              Delivery slices

                              Slice 1: authorized workflow component bundle

                              Implement a closed workflow component bundle that lets a retained workflow definition invoke trusted Markdown component code without reintroducing a mutable repository component search path.

                              The first consumer is the adversarial workflow's stage components:

                              • InstructionFiles
                              • Discovery
                              • UserCheckpoint
                              • Planning
                              • Implementation

                              Those names become reachable under xmd workflow start and xmd workflow resume only when the trusted workflow host authorizes their exact component source as part of the workflow definition. Ordinary xmd run component resolution remains unchanged.

                              Slice 2: complete supervised adversarial composition

                              Compose the root workflow through discovery, handoff validation, planning convergence, authorization, XMD-mediated Agent observations and proposals, constrained generated XMD, local Git effects, explicit Push, PullRequest create/update, its URL-addressed evidence reads, review, deferred Issue creation, revision, and final acceptance — as one supervised run under xmd workflow start, typed answer delivery and explicit xmd workflow resume.

                              The composition remains owned by PR #181 and is active. Rebase it onto current main, convert AC3 and AC4 into successful end-to-end regressions, and complete the frozen matrix.

                              Scheduling, watchers and unattended resume are outside it. A resume stays an explicit act; the scheduling slice is #300's. This slice defines no additional persistence model, Agent authority model, Git-host reconciliation policy, or executor.

                              Slice 1 contract

                              xmd workflow start continues to establish an immutable workflow definition from Git. It executes bytes from the pinned commit, not from the caller's mutable working tree. The generic workflow component search path remains empty.

                              A workflow root may declare a closed component bundle in frontmatter:

                              workflow:
                              components:
                              InstructionFiles: ./InstructionFiles.mdDiscovery: ./Discovery.mdUserCheckpoint: ./UserCheckpoint.mdPlanning: ./Planning.mdImplementation: ./Implementation.md

                              The initial bundle admits only Markdown component files named explicitly in that map. Values are POSIX paths relative to the root document's directory in the same pinned Git tree. Absolute paths, parent traversal, globs, directories, URLs, TypeScript components, package imports, generated paths and duplicate names are refused. Names that are structural constructs, reserved host registrations, or core defaults are refused in this slice; the bundle exists for workflow-owned stage components, not for replacing language or security primitives.

                              On start, the trusted workflow host reads the root and every declared component from the same pinned commit, validates every component declaration, and constructs a normalized bundle:

                              • component name;
                              • canonical repository-relative component path;
                              • component source hash; and
                              • the retained component source needed for durable selection and replay.

                              That normalized bundle is part of workflow-definition identity. Compatible reuse compares it with the run ID, descriptor, definition base and normalized props. A caller-selected run ID with a different bundle is an incompatible definition reuse, even when the root path and props are unchanged.

                              On resume, the host reconstructs the same bundle from retained definition metadata and the pinned Git object, verifies the retained hashes, and installs only that bundle for the live execution. A current checkout file with the same name or path is ignored. Missing, unreadable, changed, incompatible or unauthorized component code is refused before that code executes or advances the workflow.

                              Bundle installation is a trusted-host operation, not public middleware. It gives the document no capability to authorize more code. Public middleware, props, eval bindings, generated source, and a same-name file in the mutable checkout may refuse or narrow behavior, but cannot add bundle entries, replace retained component source, or widen what code is authorized to execute.

                              Retained component-selection history must agree with the authorized bundle. A replay that tries to restore a component selection outside the retained bundle, with a mismatched source hash, or with a mutable-checkout path in place of retained source is refused before component code executes or any later durable effect appends.

                              The bundle is not generated-XMD admission. A generated fragment still cannot name these components, Fetch, or any other component until #369 admits pinned identities and exact bounded requests.

                              Material choices still use #367 suspension and #300 typed answer delivery. Delivering an answer records it without executing the workflow. Continuation occurs only through the ordinary explicit resume path, which acquires the executor lock and claims the retained answer durably. Automatic scheduling remains #300's later slice.

                              Do not add file watchers, unattended arbitration, a second executor authority, or a generic workflow component search path here.

                              Acceptance: slice 1

                              • xmd workflow start accepts a root-declared closed component bundle and records the normalized bundle in workflow-definition identity.
                              • xmd workflow resume reconstructs and validates the same retained bundle before any bundled component executes.
                              • A workflow root can invoke InstructionFiles, Discovery, UserCheckpoint, Planning, and Implementation from trusted bundle source under start and resume.
                              • The bundle reads component source from the pinned definition commit, never from mutable checkout content beside the retained root.
                              • Compatible reuse of a caller-selected run ID requires the same normalized component bundle; a changed component path, source hash, name set, or root-relative declaration is refused as incompatible definition reuse.
                              • Retained-history admission refuses component selections outside the retained bundle or with mismatched retained source before executing component code or appending later durable effects.
                              • Missing, unreadable, malformed, schema-invalid, incompatible, duplicate, escaping, non-Markdown, structural-name, reserved-name, and core-default-name bundle entries are refused before component code executes.
                              • Ordinary xmd run component resolution is unchanged.
                              • Workflow execution gains no generic repository component search path.
                              • Public middleware, props, eval bindings, generated source, or same-name checkout files cannot add, replace, or widen authorized component code.
                              • Generated-XMD admission remains unchanged and still belongs to Evaluate Agent-generated XMD through a constrained allowlist #369.
                              • Delivering an answer alone starts no execution; continuation still occurs only after explicit resume acquires the executor lock.
                              • Focused tests use fixtures that exercise start, resume, compatible reuse, retained-history admission, mutable-checkout substitution, and refusal-before-execution. The ✨ Compose and certify the supervised adversarial implementation workflow #181 workflow documents consume the bundle when they are present on the implementation branch, but slice 1 does not require the complete adversarial loop to run.
                              • Architecture and workflow/executable-MDX specifications describe the bundle identity, authority, replay, failure and compatibility boundaries in present tense.

                              Acceptance: later complete composition

                              • One supervised WorkflowRun reaches final acceptance across process interruption using retained suspension, typed answer delivery and explicit resume. Scheduled resume is Deliver answers to suspended workflows for later resumption #300's later slice and is not part of this acceptance.
                              • Failed plan and pull-request verdicts return prescriptive prompts to the responsible retained Agent context.
                              • Material choices suspend for user authority and never default to approval; only the exact validated retained answer may continue that request.
                              • Agents receive no Workspace materialization or additional directories; XMD performs every admitted observation and mutation. The initial adapter-level tool suppression guarantee is limited as recorded by Run workflow Agents through XMD-mediated observations #302 and Require ACP adapters to enforce tool-free workflow Agent sessions #496.
                              • Two repositories can participate through explicit named Repository/Worktree composition.
                              • Commit, Push, PullRequest, and deferred Issue remain distinct durable or reconciled effects.
                              • Every declared artifact and effect result is available to a later execution without manual copy/paste or hidden transcript state.
                              • Failure and cancellation halt live resources while retaining explicit recoverable or terminal state.
                              • No automatic watcher, unattended arbitration, or alternative executor authority is introduced by this composition story.

                              Dependencies

                              Slice 1: authorized workflow component bundle

                              Later complete composition

                              All of these are shipped:

                              Remaining and deliberately outside this slice:

                              End goal: #181.

                              Out of scope

                              • A generic workflow component search path.
                              • Loading component code from the mutable checkout on resume.
                              • TypeScript component bundles, package component bundles, imports, globs or directory bundles.
                              • Replacing structural constructs, reserved host registrations or core defaults through the workflow bundle.
                              • Generated-XMD admission of bundled components or Fetch; Evaluate Agent-generated XMD through a constrained allowlist #369 owns that later proof.
                              • Automatically resuming as part of answer delivery.
                              • File watchers, branch watchers, unattended iteration arbitration or a public remote-host selector.
                              • Replacing the executor lock, lifecycle state machine, journal secret policy, suspension identity, Git-host reconciliation contract, or Agent authority model.
                              • Portable ACP adapter-level no-tool enforcement; Require ACP adapters to enforce tool-free workflow Agent sessions #496 owns that non-blocking hardening.

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                No labels
                                No labels

                                Projects

                                No projects

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions