Quest: Export workflow runs as portable .xmd files #599

Description

@taras

Quest outcome

Export a workflow run as an immutable .xmd file that can leave CI, be
inspected on another machine, and become the source of a separate local run.

CI workflow run ──export──> build-failure.xmd
├──inspect──> same recorded evidence
└──fork─────> new independent local run

The file never becomes the original live run. It cannot resume, answer, cancel,
delete, or otherwise advance that run.

Example

A CI workflow fails after changing its Workspace and exchanging several turns
with an Agent.

The CI host exports build-failure.xmd. A developer downloads that one file and
can:

  1. inspect the workflow's status and history without executing it;
  2. inspect the committed Workspace and exact workflow definition associated
    with that history;
  3. see whether each recorded Agent conversation can be continued elsewhere; and
  4. create a new local run from a selected checkpoint.

Creating the local run copies the selected workflow history and Workspace. It
does not modify or depend on the CI run.

When the selected history includes a portable Agent conversation, the
destination provider creates a separate conversation containing exactly the
turns through that checkpoint. Importing it executes no Prompt and produces no
new model response. Live Agent work becomes possible only after the new
workflow run has been committed successfully.

What the artifact contains

The artifact contains the complete XMD-owned evidence needed to understand and
fork the selected committed state:

  • the run record and committed journal history;
  • the selected event and Workspace state, called the artifact's frontier;
  • every Workspace byte and the associated Repository and Worktree records;
  • the root Markdown and component sources the workflow used, preserved together
    as its authenticated definition; and
  • a portability result for every recorded Agent session, plus an opaque provider
    bundle when that conversation can be reproduced through the selected
    checkpoint.

The artifact does not contain destination credentials, host paths, live
provider stores, executor locks, SQLite sidecars, open transactions, or other
authority belonging to the machine that exported it.

Stable public boundary

.xmd and the artifact's semantic format are public. SQLite is only the private
encoding used by format V1.

The artifact's identity comes from the workflow evidence it represents, not its
filename, location, or incidental SQLite layout. Copying or renaming the file
does not change that identity.

Readers open the file read-only and validate the complete container, manifest,
contents, and derived identity before returning any information. A malformed,
unsupported, or modified artifact returns no partial status, history, Workspace,
or Agent-portability result.

Export

Export takes the source run's executor lock before selecting the committed
frontier. This prevents the run from advancing while the artifact is assembled.

The output path receives the complete artifact atomically or remains unchanged.
Export never replaces an existing file and never changes the source run,
journal, Workspace, or provider state.

The command reports both:

  • a semantic artifact identity for the evidence represented; and
  • a SHA-256 digest for the exact file bytes transferred or published by CI.

Inspection

Artifact status and history use the existing workflow inspection commands with
an explicit artifact path.

Inspection:

  • executes no document;
  • starts no Agent or external provider;
  • materializes no live Workspace;
  • reads no workflow definition from Git;
  • writes no journal, migration, or sidecar; and
  • gives the same semantic result after the file is copied, renamed, or mounted
    read-only.

An artifact path is not a local workflow-run ID, and a directory of downloaded
artifacts does not become the local run registry.

Continue by forking

Continuation always creates a separate workflow run that can resume
independently, with a new identity.

The fork copies the selected journal prefix, Workspace state, and workflow
definition. It shares no writable state, lock, or provider-owned directory with
the artifact or source run.

The new run records its lineage:

  • artifact identity;
  • source run identity;
  • selected event; and
  • selected Workspace root.

Two artifacts containing different evidence cannot reuse one destination run
merely because they claim the same source run or checkpoint.

Agent conversation portability

Every Agent Prompt records the provider checkpoint needed to identify the exact
conversation prefix it produced.

For a portable conversation:

  1. the artifact carries a confidential, opaque provider bundle;
  2. the destination supplies its own authentication;
  3. a qualified provider creates a separate conversation containing exactly the
    turns through the recorded checkpoint, with no Prompt during import;
  4. the provider publishes the new conversation state and asserts its identity;
  5. XMD commits the new workflow-run mapping; and
  6. only then may the new run execute another Prompt.

Provider storage and XMD's workflow database cannot be committed as one
transaction. Recovery therefore identifies which side completed and either
finishes the same mapping or refuses conflicting state. It never creates a
second conversation silently.

A provider that cannot reproduce the exact prefix remains unsupported and
fails closed.

Provider support

  • Codex qualifies through App Server conversation forking at an exact recorded
    turn, without executing another turn.
  • Claude checkpoint transport is useful, but the currently proven command form
    executes a Prompt. Claude remains unsupported for this capability unless Provide a supported no-turn Claude exact-prefix Agent bundle lifecycle #626
    proves a supported no-turn path.
  • ACP session forking copies only the conversation head and does not satisfy an
    arbitrary exact-checkpoint request.

Delivered foundations

These stories remain complete. Agent-aware portability continues through the
remaining dependent stories.

Remaining blocking stories

Delivery order

  1. Complete Finalize XMD artifact V1 with Agent portability evidence #621.
  2. Complete Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 after Finalize XMD artifact V1 with Agent portability evidence #621 and the delivered Retain provider checkpoint tokens for workflow Agent Prompts #622.
  3. Complete Amend workflow artifact export with Agent bundle capture #625 after Finalize XMD artifact V1 with Agent portability evidence #621, Retain provider checkpoint tokens for workflow Agent Prompts #622, and Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624.
  4. Complete Amend artifact inspection with intrinsic Agent forkability #623 after Finalize XMD artifact V1 with Agent portability evidence #621. It may proceed alongside Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 and Amend workflow artifact export with Agent bundle capture #625.
  5. Complete Fork an XMD artifact into independent workflow history #603 after all four prerequisite stories.

#626 may add supported no-turn Claude portability afterward. It does not block
this Quest.

Completion

The Quest is complete when:

  • one immutable artifact preserves the complete selected workflow evidence;
  • inspection works anywhere without execution authority;
  • every Agent session has a complete portability result;
  • portable Agent conversations can be recreated through an exact checkpoint
    without another model turn;
  • continuation creates an independent run and provider state;
  • conflicting identities refuse rather than reuse unrelated state;
  • interrupted provider/database publication recovers deterministically; and
  • all remaining blocking stories are delivered.

Authoritative contract

  • specs/xmd-artifact-spec.md
  • specs/workflow-workspace-spec.md
  • the workflow Agent sections of specs/executable-mdx-spec.md
  • architecture.md
  • plans/xmd-portable-artifact-quest.md

The specifications own the detailed structural and evidence matrices. Child
stories implement that contract rather than choosing different product
behavior.

Out of scope

  • Publishing or uploading artifacts from CI.
  • Signed provenance, retention policy, final-digest attestation, and redacted
    reports.
  • Treating the artifact as authority to control the source run.
  • Carrying destination credentials or provider launch configuration.
  • Carrying live provider stores, locks, indexes, or ACPX queue state.
  • Converting or migrating artifacts between semantic format versions.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestquestCoordinating story with dependency-ordered sub-issues

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
      Skip to content

      Quest: Export workflow runs as portable .xmd files #599

      Description

      @taras

      Quest outcome

      Export a workflow run as an immutable .xmd file that can leave CI, be
      inspected on another machine, and become the source of a separate local run.

      CI workflow run ──export──> build-failure.xmd
      ├──inspect──> same recorded evidence
      └──fork─────> new independent local run
      

      The file never becomes the original live run. It cannot resume, answer, cancel,
      delete, or otherwise advance that run.

      Example

      A CI workflow fails after changing its Workspace and exchanging several turns
      with an Agent.

      The CI host exports build-failure.xmd. A developer downloads that one file and
      can:

      1. inspect the workflow's status and history without executing it;
      2. inspect the committed Workspace and exact workflow definition associated
        with that history;
      3. see whether each recorded Agent conversation can be continued elsewhere; and
      4. create a new local run from a selected checkpoint.

      Creating the local run copies the selected workflow history and Workspace. It
      does not modify or depend on the CI run.

      When the selected history includes a portable Agent conversation, the
      destination provider creates a separate conversation containing exactly the
      turns through that checkpoint. Importing it executes no Prompt and produces no
      new model response. Live Agent work becomes possible only after the new
      workflow run has been committed successfully.

      What the artifact contains

      The artifact contains the complete XMD-owned evidence needed to understand and
      fork the selected committed state:

      • the run record and committed journal history;
      • the selected event and Workspace state, called the artifact's frontier;
      • every Workspace byte and the associated Repository and Worktree records;
      • the root Markdown and component sources the workflow used, preserved together
        as its authenticated definition; and
      • a portability result for every recorded Agent session, plus an opaque provider
        bundle when that conversation can be reproduced through the selected
        checkpoint.

      The artifact does not contain destination credentials, host paths, live
      provider stores, executor locks, SQLite sidecars, open transactions, or other
      authority belonging to the machine that exported it.

      Stable public boundary

      .xmd and the artifact's semantic format are public. SQLite is only the private
      encoding used by format V1.

      The artifact's identity comes from the workflow evidence it represents, not its
      filename, location, or incidental SQLite layout. Copying or renaming the file
      does not change that identity.

      Readers open the file read-only and validate the complete container, manifest,
      contents, and derived identity before returning any information. A malformed,
      unsupported, or modified artifact returns no partial status, history, Workspace,
      or Agent-portability result.

      Export

      Export takes the source run's executor lock before selecting the committed
      frontier. This prevents the run from advancing while the artifact is assembled.

      The output path receives the complete artifact atomically or remains unchanged.
      Export never replaces an existing file and never changes the source run,
      journal, Workspace, or provider state.

      The command reports both:

      • a semantic artifact identity for the evidence represented; and
      • a SHA-256 digest for the exact file bytes transferred or published by CI.

      Inspection

      Artifact status and history use the existing workflow inspection commands with
      an explicit artifact path.

      Inspection:

      • executes no document;
      • starts no Agent or external provider;
      • materializes no live Workspace;
      • reads no workflow definition from Git;
      • writes no journal, migration, or sidecar; and
      • gives the same semantic result after the file is copied, renamed, or mounted
        read-only.

      An artifact path is not a local workflow-run ID, and a directory of downloaded
      artifacts does not become the local run registry.

      Continue by forking

      Continuation always creates a separate workflow run that can resume
      independently, with a new identity.

      The fork copies the selected journal prefix, Workspace state, and workflow
      definition. It shares no writable state, lock, or provider-owned directory with
      the artifact or source run.

      The new run records its lineage:

      • artifact identity;
      • source run identity;
      • selected event; and
      • selected Workspace root.

      Two artifacts containing different evidence cannot reuse one destination run
      merely because they claim the same source run or checkpoint.

      Agent conversation portability

      Every Agent Prompt records the provider checkpoint needed to identify the exact
      conversation prefix it produced.

      For a portable conversation:

      1. the artifact carries a confidential, opaque provider bundle;
      2. the destination supplies its own authentication;
      3. a qualified provider creates a separate conversation containing exactly the
        turns through the recorded checkpoint, with no Prompt during import;
      4. the provider publishes the new conversation state and asserts its identity;
      5. XMD commits the new workflow-run mapping; and
      6. only then may the new run execute another Prompt.

      Provider storage and XMD's workflow database cannot be committed as one
      transaction. Recovery therefore identifies which side completed and either
      finishes the same mapping or refuses conflicting state. It never creates a
      second conversation silently.

      A provider that cannot reproduce the exact prefix remains unsupported and
      fails closed.

      Provider support

      • Codex qualifies through App Server conversation forking at an exact recorded
        turn, without executing another turn.
      • Claude checkpoint transport is useful, but the currently proven command form
        executes a Prompt. Claude remains unsupported for this capability unless Provide a supported no-turn Claude exact-prefix Agent bundle lifecycle #626
        proves a supported no-turn path.
      • ACP session forking copies only the conversation head and does not satisfy an
        arbitrary exact-checkpoint request.

      Delivered foundations

      These stories remain complete. Agent-aware portability continues through the
      remaining dependent stories.

      Remaining blocking stories

      Delivery order

      1. Complete Finalize XMD artifact V1 with Agent portability evidence #621.
      2. Complete Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 after Finalize XMD artifact V1 with Agent portability evidence #621 and the delivered Retain provider checkpoint tokens for workflow Agent Prompts #622.
      3. Complete Amend workflow artifact export with Agent bundle capture #625 after Finalize XMD artifact V1 with Agent portability evidence #621, Retain provider checkpoint tokens for workflow Agent Prompts #622, and Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624.
      4. Complete Amend artifact inspection with intrinsic Agent forkability #623 after Finalize XMD artifact V1 with Agent portability evidence #621. It may proceed alongside Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 and Amend workflow artifact export with Agent bundle capture #625.
      5. Complete Fork an XMD artifact into independent workflow history #603 after all four prerequisite stories.

      #626 may add supported no-turn Claude portability afterward. It does not block
      this Quest.

      Completion

      The Quest is complete when:

      • one immutable artifact preserves the complete selected workflow evidence;
      • inspection works anywhere without execution authority;
      • every Agent session has a complete portability result;
      • portable Agent conversations can be recreated through an exact checkpoint
        without another model turn;
      • continuation creates an independent run and provider state;
      • conflicting identities refuse rather than reuse unrelated state;
      • interrupted provider/database publication recovers deterministically; and
      • all remaining blocking stories are delivered.

      Authoritative contract

      • specs/xmd-artifact-spec.md
      • specs/workflow-workspace-spec.md
      • the workflow Agent sections of specs/executable-mdx-spec.md
      • architecture.md
      • plans/xmd-portable-artifact-quest.md

      The specifications own the detailed structural and evidence matrices. Child
      stories implement that contract rather than choosing different product
      behavior.

      Out of scope

      • Publishing or uploading artifacts from CI.
      • Signed provenance, retention policy, final-digest attestation, and redacted
        reports.
      • Treating the artifact as authority to control the source run.
      • Carrying destination credentials or provider launch configuration.
      • Carrying live provider stores, locks, indexes, or ACPX queue state.
      • Converting or migrating artifacts between semantic format versions.

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        enhancementNew feature or requestquestCoordinating story with dependency-ordered sub-issues

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          Quest: Export workflow runs as portable .xmd files #599

          Description

          @taras

          Quest outcome

          Export a workflow run as an immutable .xmd file that can leave CI, be
          inspected on another machine, and become the source of a separate local run.

          CI workflow run ──export──> build-failure.xmd
          ├──inspect──> same recorded evidence
          └──fork─────> new independent local run
          

          The file never becomes the original live run. It cannot resume, answer, cancel,
          delete, or otherwise advance that run.

          Example

          A CI workflow fails after changing its Workspace and exchanging several turns
          with an Agent.

          The CI host exports build-failure.xmd. A developer downloads that one file and
          can:

          1. inspect the workflow's status and history without executing it;
          2. inspect the committed Workspace and exact workflow definition associated
            with that history;
          3. see whether each recorded Agent conversation can be continued elsewhere; and
          4. create a new local run from a selected checkpoint.

          Creating the local run copies the selected workflow history and Workspace. It
          does not modify or depend on the CI run.

          When the selected history includes a portable Agent conversation, the
          destination provider creates a separate conversation containing exactly the
          turns through that checkpoint. Importing it executes no Prompt and produces no
          new model response. Live Agent work becomes possible only after the new
          workflow run has been committed successfully.

          What the artifact contains

          The artifact contains the complete XMD-owned evidence needed to understand and
          fork the selected committed state:

          • the run record and committed journal history;
          • the selected event and Workspace state, called the artifact's frontier;
          • every Workspace byte and the associated Repository and Worktree records;
          • the root Markdown and component sources the workflow used, preserved together
            as its authenticated definition; and
          • a portability result for every recorded Agent session, plus an opaque provider
            bundle when that conversation can be reproduced through the selected
            checkpoint.

          The artifact does not contain destination credentials, host paths, live
          provider stores, executor locks, SQLite sidecars, open transactions, or other
          authority belonging to the machine that exported it.

          Stable public boundary

          .xmd and the artifact's semantic format are public. SQLite is only the private
          encoding used by format V1.

          The artifact's identity comes from the workflow evidence it represents, not its
          filename, location, or incidental SQLite layout. Copying or renaming the file
          does not change that identity.

          Readers open the file read-only and validate the complete container, manifest,
          contents, and derived identity before returning any information. A malformed,
          unsupported, or modified artifact returns no partial status, history, Workspace,
          or Agent-portability result.

          Export

          Export takes the source run's executor lock before selecting the committed
          frontier. This prevents the run from advancing while the artifact is assembled.

          The output path receives the complete artifact atomically or remains unchanged.
          Export never replaces an existing file and never changes the source run,
          journal, Workspace, or provider state.

          The command reports both:

          • a semantic artifact identity for the evidence represented; and
          • a SHA-256 digest for the exact file bytes transferred or published by CI.

          Inspection

          Artifact status and history use the existing workflow inspection commands with
          an explicit artifact path.

          Inspection:

          • executes no document;
          • starts no Agent or external provider;
          • materializes no live Workspace;
          • reads no workflow definition from Git;
          • writes no journal, migration, or sidecar; and
          • gives the same semantic result after the file is copied, renamed, or mounted
            read-only.

          An artifact path is not a local workflow-run ID, and a directory of downloaded
          artifacts does not become the local run registry.

          Continue by forking

          Continuation always creates a separate workflow run that can resume
          independently, with a new identity.

          The fork copies the selected journal prefix, Workspace state, and workflow
          definition. It shares no writable state, lock, or provider-owned directory with
          the artifact or source run.

          The new run records its lineage:

          • artifact identity;
          • source run identity;
          • selected event; and
          • selected Workspace root.

          Two artifacts containing different evidence cannot reuse one destination run
          merely because they claim the same source run or checkpoint.

          Agent conversation portability

          Every Agent Prompt records the provider checkpoint needed to identify the exact
          conversation prefix it produced.

          For a portable conversation:

          1. the artifact carries a confidential, opaque provider bundle;
          2. the destination supplies its own authentication;
          3. a qualified provider creates a separate conversation containing exactly the
            turns through the recorded checkpoint, with no Prompt during import;
          4. the provider publishes the new conversation state and asserts its identity;
          5. XMD commits the new workflow-run mapping; and
          6. only then may the new run execute another Prompt.

          Provider storage and XMD's workflow database cannot be committed as one
          transaction. Recovery therefore identifies which side completed and either
          finishes the same mapping or refuses conflicting state. It never creates a
          second conversation silently.

          A provider that cannot reproduce the exact prefix remains unsupported and
          fails closed.

          Provider support

          • Codex qualifies through App Server conversation forking at an exact recorded
            turn, without executing another turn.
          • Claude checkpoint transport is useful, but the currently proven command form
            executes a Prompt. Claude remains unsupported for this capability unless Provide a supported no-turn Claude exact-prefix Agent bundle lifecycle #626
            proves a supported no-turn path.
          • ACP session forking copies only the conversation head and does not satisfy an
            arbitrary exact-checkpoint request.

          Delivered foundations

          These stories remain complete. Agent-aware portability continues through the
          remaining dependent stories.

          Remaining blocking stories

          Delivery order

          1. Complete Finalize XMD artifact V1 with Agent portability evidence #621.
          2. Complete Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 after Finalize XMD artifact V1 with Agent portability evidence #621 and the delivered Retain provider checkpoint tokens for workflow Agent Prompts #622.
          3. Complete Amend workflow artifact export with Agent bundle capture #625 after Finalize XMD artifact V1 with Agent portability evidence #621, Retain provider checkpoint tokens for workflow Agent Prompts #622, and Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624.
          4. Complete Amend artifact inspection with intrinsic Agent forkability #623 after Finalize XMD artifact V1 with Agent portability evidence #621. It may proceed alongside Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 and Amend workflow artifact export with Agent bundle capture #625.
          5. Complete Fork an XMD artifact into independent workflow history #603 after all four prerequisite stories.

          #626 may add supported no-turn Claude portability afterward. It does not block
          this Quest.

          Completion

          The Quest is complete when:

          • one immutable artifact preserves the complete selected workflow evidence;
          • inspection works anywhere without execution authority;
          • every Agent session has a complete portability result;
          • portable Agent conversations can be recreated through an exact checkpoint
            without another model turn;
          • continuation creates an independent run and provider state;
          • conflicting identities refuse rather than reuse unrelated state;
          • interrupted provider/database publication recovers deterministically; and
          • all remaining blocking stories are delivered.

          Authoritative contract

          • specs/xmd-artifact-spec.md
          • specs/workflow-workspace-spec.md
          • the workflow Agent sections of specs/executable-mdx-spec.md
          • architecture.md
          • plans/xmd-portable-artifact-quest.md

          The specifications own the detailed structural and evidence matrices. Child
          stories implement that contract rather than choosing different product
          behavior.

          Out of scope

          • Publishing or uploading artifacts from CI.
          • Signed provenance, retention policy, final-digest attestation, and redacted
            reports.
          • Treating the artifact as authority to control the source run.
          • Carrying destination credentials or provider launch configuration.
          • Carrying live provider stores, locks, indexes, or ACPX queue state.
          • Converting or migrating artifacts between semantic format versions.

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            enhancementNew feature or requestquestCoordinating story with dependency-ordered sub-issues

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Quest: Export workflow runs as portable .xmd files #599

              Description

              @taras

              Quest outcome

              Export a workflow run as an immutable .xmd file that can leave CI, be
              inspected on another machine, and become the source of a separate local run.

              CI workflow run ──export──> build-failure.xmd
              ├──inspect──> same recorded evidence
              └──fork─────> new independent local run
              

              The file never becomes the original live run. It cannot resume, answer, cancel,
              delete, or otherwise advance that run.

              Example

              A CI workflow fails after changing its Workspace and exchanging several turns
              with an Agent.

              The CI host exports build-failure.xmd. A developer downloads that one file and
              can:

              1. inspect the workflow's status and history without executing it;
              2. inspect the committed Workspace and exact workflow definition associated
                with that history;
              3. see whether each recorded Agent conversation can be continued elsewhere; and
              4. create a new local run from a selected checkpoint.

              Creating the local run copies the selected workflow history and Workspace. It
              does not modify or depend on the CI run.

              When the selected history includes a portable Agent conversation, the
              destination provider creates a separate conversation containing exactly the
              turns through that checkpoint. Importing it executes no Prompt and produces no
              new model response. Live Agent work becomes possible only after the new
              workflow run has been committed successfully.

              What the artifact contains

              The artifact contains the complete XMD-owned evidence needed to understand and
              fork the selected committed state:

              • the run record and committed journal history;
              • the selected event and Workspace state, called the artifact's frontier;
              • every Workspace byte and the associated Repository and Worktree records;
              • the root Markdown and component sources the workflow used, preserved together
                as its authenticated definition; and
              • a portability result for every recorded Agent session, plus an opaque provider
                bundle when that conversation can be reproduced through the selected
                checkpoint.

              The artifact does not contain destination credentials, host paths, live
              provider stores, executor locks, SQLite sidecars, open transactions, or other
              authority belonging to the machine that exported it.

              Stable public boundary

              .xmd and the artifact's semantic format are public. SQLite is only the private
              encoding used by format V1.

              The artifact's identity comes from the workflow evidence it represents, not its
              filename, location, or incidental SQLite layout. Copying or renaming the file
              does not change that identity.

              Readers open the file read-only and validate the complete container, manifest,
              contents, and derived identity before returning any information. A malformed,
              unsupported, or modified artifact returns no partial status, history, Workspace,
              or Agent-portability result.

              Export

              Export takes the source run's executor lock before selecting the committed
              frontier. This prevents the run from advancing while the artifact is assembled.

              The output path receives the complete artifact atomically or remains unchanged.
              Export never replaces an existing file and never changes the source run,
              journal, Workspace, or provider state.

              The command reports both:

              • a semantic artifact identity for the evidence represented; and
              • a SHA-256 digest for the exact file bytes transferred or published by CI.

              Inspection

              Artifact status and history use the existing workflow inspection commands with
              an explicit artifact path.

              Inspection:

              • executes no document;
              • starts no Agent or external provider;
              • materializes no live Workspace;
              • reads no workflow definition from Git;
              • writes no journal, migration, or sidecar; and
              • gives the same semantic result after the file is copied, renamed, or mounted
                read-only.

              An artifact path is not a local workflow-run ID, and a directory of downloaded
              artifacts does not become the local run registry.

              Continue by forking

              Continuation always creates a separate workflow run that can resume
              independently, with a new identity.

              The fork copies the selected journal prefix, Workspace state, and workflow
              definition. It shares no writable state, lock, or provider-owned directory with
              the artifact or source run.

              The new run records its lineage:

              • artifact identity;
              • source run identity;
              • selected event; and
              • selected Workspace root.

              Two artifacts containing different evidence cannot reuse one destination run
              merely because they claim the same source run or checkpoint.

              Agent conversation portability

              Every Agent Prompt records the provider checkpoint needed to identify the exact
              conversation prefix it produced.

              For a portable conversation:

              1. the artifact carries a confidential, opaque provider bundle;
              2. the destination supplies its own authentication;
              3. a qualified provider creates a separate conversation containing exactly the
                turns through the recorded checkpoint, with no Prompt during import;
              4. the provider publishes the new conversation state and asserts its identity;
              5. XMD commits the new workflow-run mapping; and
              6. only then may the new run execute another Prompt.

              Provider storage and XMD's workflow database cannot be committed as one
              transaction. Recovery therefore identifies which side completed and either
              finishes the same mapping or refuses conflicting state. It never creates a
              second conversation silently.

              A provider that cannot reproduce the exact prefix remains unsupported and
              fails closed.

              Provider support

              • Codex qualifies through App Server conversation forking at an exact recorded
                turn, without executing another turn.
              • Claude checkpoint transport is useful, but the currently proven command form
                executes a Prompt. Claude remains unsupported for this capability unless Provide a supported no-turn Claude exact-prefix Agent bundle lifecycle #626
                proves a supported no-turn path.
              • ACP session forking copies only the conversation head and does not satisfy an
                arbitrary exact-checkpoint request.

              Delivered foundations

              These stories remain complete. Agent-aware portability continues through the
              remaining dependent stories.

              Remaining blocking stories

              Delivery order

              1. Complete Finalize XMD artifact V1 with Agent portability evidence #621.
              2. Complete Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 after Finalize XMD artifact V1 with Agent portability evidence #621 and the delivered Retain provider checkpoint tokens for workflow Agent Prompts #622.
              3. Complete Amend workflow artifact export with Agent bundle capture #625 after Finalize XMD artifact V1 with Agent portability evidence #621, Retain provider checkpoint tokens for workflow Agent Prompts #622, and Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624.
              4. Complete Amend artifact inspection with intrinsic Agent forkability #623 after Finalize XMD artifact V1 with Agent portability evidence #621. It may proceed alongside Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 and Amend workflow artifact export with Agent bundle capture #625.
              5. Complete Fork an XMD artifact into independent workflow history #603 after all four prerequisite stories.

              #626 may add supported no-turn Claude portability afterward. It does not block
              this Quest.

              Completion

              The Quest is complete when:

              • one immutable artifact preserves the complete selected workflow evidence;
              • inspection works anywhere without execution authority;
              • every Agent session has a complete portability result;
              • portable Agent conversations can be recreated through an exact checkpoint
                without another model turn;
              • continuation creates an independent run and provider state;
              • conflicting identities refuse rather than reuse unrelated state;
              • interrupted provider/database publication recovers deterministically; and
              • all remaining blocking stories are delivered.

              Authoritative contract

              • specs/xmd-artifact-spec.md
              • specs/workflow-workspace-spec.md
              • the workflow Agent sections of specs/executable-mdx-spec.md
              • architecture.md
              • plans/xmd-portable-artifact-quest.md

              The specifications own the detailed structural and evidence matrices. Child
              stories implement that contract rather than choosing different product
              behavior.

              Out of scope

              • Publishing or uploading artifacts from CI.
              • Signed provenance, retention policy, final-digest attestation, and redacted
                reports.
              • Treating the artifact as authority to control the source run.
              • Carrying destination credentials or provider launch configuration.
              • Carrying live provider stores, locks, indexes, or ACPX queue state.
              • Converting or migrating artifacts between semantic format versions.

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                enhancementNew feature or requestquestCoordinating story with dependency-ordered sub-issues

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  Quest: Export workflow runs as portable .xmd files #599

                  Description

                  @taras

                  Quest outcome

                  Export a workflow run as an immutable .xmd file that can leave CI, be
                  inspected on another machine, and become the source of a separate local run.

                  CI workflow run ──export──> build-failure.xmd
                  ├──inspect──> same recorded evidence
                  └──fork─────> new independent local run
                  

                  The file never becomes the original live run. It cannot resume, answer, cancel,
                  delete, or otherwise advance that run.

                  Example

                  A CI workflow fails after changing its Workspace and exchanging several turns
                  with an Agent.

                  The CI host exports build-failure.xmd. A developer downloads that one file and
                  can:

                  1. inspect the workflow's status and history without executing it;
                  2. inspect the committed Workspace and exact workflow definition associated
                    with that history;
                  3. see whether each recorded Agent conversation can be continued elsewhere; and
                  4. create a new local run from a selected checkpoint.

                  Creating the local run copies the selected workflow history and Workspace. It
                  does not modify or depend on the CI run.

                  When the selected history includes a portable Agent conversation, the
                  destination provider creates a separate conversation containing exactly the
                  turns through that checkpoint. Importing it executes no Prompt and produces no
                  new model response. Live Agent work becomes possible only after the new
                  workflow run has been committed successfully.

                  What the artifact contains

                  The artifact contains the complete XMD-owned evidence needed to understand and
                  fork the selected committed state:

                  • the run record and committed journal history;
                  • the selected event and Workspace state, called the artifact's frontier;
                  • every Workspace byte and the associated Repository and Worktree records;
                  • the root Markdown and component sources the workflow used, preserved together
                    as its authenticated definition; and
                  • a portability result for every recorded Agent session, plus an opaque provider
                    bundle when that conversation can be reproduced through the selected
                    checkpoint.

                  The artifact does not contain destination credentials, host paths, live
                  provider stores, executor locks, SQLite sidecars, open transactions, or other
                  authority belonging to the machine that exported it.

                  Stable public boundary

                  .xmd and the artifact's semantic format are public. SQLite is only the private
                  encoding used by format V1.

                  The artifact's identity comes from the workflow evidence it represents, not its
                  filename, location, or incidental SQLite layout. Copying or renaming the file
                  does not change that identity.

                  Readers open the file read-only and validate the complete container, manifest,
                  contents, and derived identity before returning any information. A malformed,
                  unsupported, or modified artifact returns no partial status, history, Workspace,
                  or Agent-portability result.

                  Export

                  Export takes the source run's executor lock before selecting the committed
                  frontier. This prevents the run from advancing while the artifact is assembled.

                  The output path receives the complete artifact atomically or remains unchanged.
                  Export never replaces an existing file and never changes the source run,
                  journal, Workspace, or provider state.

                  The command reports both:

                  • a semantic artifact identity for the evidence represented; and
                  • a SHA-256 digest for the exact file bytes transferred or published by CI.

                  Inspection

                  Artifact status and history use the existing workflow inspection commands with
                  an explicit artifact path.

                  Inspection:

                  • executes no document;
                  • starts no Agent or external provider;
                  • materializes no live Workspace;
                  • reads no workflow definition from Git;
                  • writes no journal, migration, or sidecar; and
                  • gives the same semantic result after the file is copied, renamed, or mounted
                    read-only.

                  An artifact path is not a local workflow-run ID, and a directory of downloaded
                  artifacts does not become the local run registry.

                  Continue by forking

                  Continuation always creates a separate workflow run that can resume
                  independently, with a new identity.

                  The fork copies the selected journal prefix, Workspace state, and workflow
                  definition. It shares no writable state, lock, or provider-owned directory with
                  the artifact or source run.

                  The new run records its lineage:

                  • artifact identity;
                  • source run identity;
                  • selected event; and
                  • selected Workspace root.

                  Two artifacts containing different evidence cannot reuse one destination run
                  merely because they claim the same source run or checkpoint.

                  Agent conversation portability

                  Every Agent Prompt records the provider checkpoint needed to identify the exact
                  conversation prefix it produced.

                  For a portable conversation:

                  1. the artifact carries a confidential, opaque provider bundle;
                  2. the destination supplies its own authentication;
                  3. a qualified provider creates a separate conversation containing exactly the
                    turns through the recorded checkpoint, with no Prompt during import;
                  4. the provider publishes the new conversation state and asserts its identity;
                  5. XMD commits the new workflow-run mapping; and
                  6. only then may the new run execute another Prompt.

                  Provider storage and XMD's workflow database cannot be committed as one
                  transaction. Recovery therefore identifies which side completed and either
                  finishes the same mapping or refuses conflicting state. It never creates a
                  second conversation silently.

                  A provider that cannot reproduce the exact prefix remains unsupported and
                  fails closed.

                  Provider support

                  • Codex qualifies through App Server conversation forking at an exact recorded
                    turn, without executing another turn.
                  • Claude checkpoint transport is useful, but the currently proven command form
                    executes a Prompt. Claude remains unsupported for this capability unless Provide a supported no-turn Claude exact-prefix Agent bundle lifecycle #626
                    proves a supported no-turn path.
                  • ACP session forking copies only the conversation head and does not satisfy an
                    arbitrary exact-checkpoint request.

                  Delivered foundations

                  These stories remain complete. Agent-aware portability continues through the
                  remaining dependent stories.

                  Remaining blocking stories

                  Delivery order

                  1. Complete Finalize XMD artifact V1 with Agent portability evidence #621.
                  2. Complete Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 after Finalize XMD artifact V1 with Agent portability evidence #621 and the delivered Retain provider checkpoint tokens for workflow Agent Prompts #622.
                  3. Complete Amend workflow artifact export with Agent bundle capture #625 after Finalize XMD artifact V1 with Agent portability evidence #621, Retain provider checkpoint tokens for workflow Agent Prompts #622, and Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624.
                  4. Complete Amend artifact inspection with intrinsic Agent forkability #623 after Finalize XMD artifact V1 with Agent portability evidence #621. It may proceed alongside Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 and Amend workflow artifact export with Agent bundle capture #625.
                  5. Complete Fork an XMD artifact into independent workflow history #603 after all four prerequisite stories.

                  #626 may add supported no-turn Claude portability afterward. It does not block
                  this Quest.

                  Completion

                  The Quest is complete when:

                  • one immutable artifact preserves the complete selected workflow evidence;
                  • inspection works anywhere without execution authority;
                  • every Agent session has a complete portability result;
                  • portable Agent conversations can be recreated through an exact checkpoint
                    without another model turn;
                  • continuation creates an independent run and provider state;
                  • conflicting identities refuse rather than reuse unrelated state;
                  • interrupted provider/database publication recovers deterministically; and
                  • all remaining blocking stories are delivered.

                  Authoritative contract

                  • specs/xmd-artifact-spec.md
                  • specs/workflow-workspace-spec.md
                  • the workflow Agent sections of specs/executable-mdx-spec.md
                  • architecture.md
                  • plans/xmd-portable-artifact-quest.md

                  The specifications own the detailed structural and evidence matrices. Child
                  stories implement that contract rather than choosing different product
                  behavior.

                  Out of scope

                  • Publishing or uploading artifacts from CI.
                  • Signed provenance, retention policy, final-digest attestation, and redacted
                    reports.
                  • Treating the artifact as authority to control the source run.
                  • Carrying destination credentials or provider launch configuration.
                  • Carrying live provider stores, locks, indexes, or ACPX queue state.
                  • Converting or migrating artifacts between semantic format versions.

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    enhancementNew feature or requestquestCoordinating story with dependency-ordered sub-issues

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      Quest: Export workflow runs as portable .xmd files #599

                      Description

                      @taras

                      Quest outcome

                      Export a workflow run as an immutable .xmd file that can leave CI, be
                      inspected on another machine, and become the source of a separate local run.

                      CI workflow run ──export──> build-failure.xmd
                      ├──inspect──> same recorded evidence
                      └──fork─────> new independent local run
                      

                      The file never becomes the original live run. It cannot resume, answer, cancel,
                      delete, or otherwise advance that run.

                      Example

                      A CI workflow fails after changing its Workspace and exchanging several turns
                      with an Agent.

                      The CI host exports build-failure.xmd. A developer downloads that one file and
                      can:

                      1. inspect the workflow's status and history without executing it;
                      2. inspect the committed Workspace and exact workflow definition associated
                        with that history;
                      3. see whether each recorded Agent conversation can be continued elsewhere; and
                      4. create a new local run from a selected checkpoint.

                      Creating the local run copies the selected workflow history and Workspace. It
                      does not modify or depend on the CI run.

                      When the selected history includes a portable Agent conversation, the
                      destination provider creates a separate conversation containing exactly the
                      turns through that checkpoint. Importing it executes no Prompt and produces no
                      new model response. Live Agent work becomes possible only after the new
                      workflow run has been committed successfully.

                      What the artifact contains

                      The artifact contains the complete XMD-owned evidence needed to understand and
                      fork the selected committed state:

                      • the run record and committed journal history;
                      • the selected event and Workspace state, called the artifact's frontier;
                      • every Workspace byte and the associated Repository and Worktree records;
                      • the root Markdown and component sources the workflow used, preserved together
                        as its authenticated definition; and
                      • a portability result for every recorded Agent session, plus an opaque provider
                        bundle when that conversation can be reproduced through the selected
                        checkpoint.

                      The artifact does not contain destination credentials, host paths, live
                      provider stores, executor locks, SQLite sidecars, open transactions, or other
                      authority belonging to the machine that exported it.

                      Stable public boundary

                      .xmd and the artifact's semantic format are public. SQLite is only the private
                      encoding used by format V1.

                      The artifact's identity comes from the workflow evidence it represents, not its
                      filename, location, or incidental SQLite layout. Copying or renaming the file
                      does not change that identity.

                      Readers open the file read-only and validate the complete container, manifest,
                      contents, and derived identity before returning any information. A malformed,
                      unsupported, or modified artifact returns no partial status, history, Workspace,
                      or Agent-portability result.

                      Export

                      Export takes the source run's executor lock before selecting the committed
                      frontier. This prevents the run from advancing while the artifact is assembled.

                      The output path receives the complete artifact atomically or remains unchanged.
                      Export never replaces an existing file and never changes the source run,
                      journal, Workspace, or provider state.

                      The command reports both:

                      • a semantic artifact identity for the evidence represented; and
                      • a SHA-256 digest for the exact file bytes transferred or published by CI.

                      Inspection

                      Artifact status and history use the existing workflow inspection commands with
                      an explicit artifact path.

                      Inspection:

                      • executes no document;
                      • starts no Agent or external provider;
                      • materializes no live Workspace;
                      • reads no workflow definition from Git;
                      • writes no journal, migration, or sidecar; and
                      • gives the same semantic result after the file is copied, renamed, or mounted
                        read-only.

                      An artifact path is not a local workflow-run ID, and a directory of downloaded
                      artifacts does not become the local run registry.

                      Continue by forking

                      Continuation always creates a separate workflow run that can resume
                      independently, with a new identity.

                      The fork copies the selected journal prefix, Workspace state, and workflow
                      definition. It shares no writable state, lock, or provider-owned directory with
                      the artifact or source run.

                      The new run records its lineage:

                      • artifact identity;
                      • source run identity;
                      • selected event; and
                      • selected Workspace root.

                      Two artifacts containing different evidence cannot reuse one destination run
                      merely because they claim the same source run or checkpoint.

                      Agent conversation portability

                      Every Agent Prompt records the provider checkpoint needed to identify the exact
                      conversation prefix it produced.

                      For a portable conversation:

                      1. the artifact carries a confidential, opaque provider bundle;
                      2. the destination supplies its own authentication;
                      3. a qualified provider creates a separate conversation containing exactly the
                        turns through the recorded checkpoint, with no Prompt during import;
                      4. the provider publishes the new conversation state and asserts its identity;
                      5. XMD commits the new workflow-run mapping; and
                      6. only then may the new run execute another Prompt.

                      Provider storage and XMD's workflow database cannot be committed as one
                      transaction. Recovery therefore identifies which side completed and either
                      finishes the same mapping or refuses conflicting state. It never creates a
                      second conversation silently.

                      A provider that cannot reproduce the exact prefix remains unsupported and
                      fails closed.

                      Provider support

                      • Codex qualifies through App Server conversation forking at an exact recorded
                        turn, without executing another turn.
                      • Claude checkpoint transport is useful, but the currently proven command form
                        executes a Prompt. Claude remains unsupported for this capability unless Provide a supported no-turn Claude exact-prefix Agent bundle lifecycle #626
                        proves a supported no-turn path.
                      • ACP session forking copies only the conversation head and does not satisfy an
                        arbitrary exact-checkpoint request.

                      Delivered foundations

                      These stories remain complete. Agent-aware portability continues through the
                      remaining dependent stories.

                      Remaining blocking stories

                      Delivery order

                      1. Complete Finalize XMD artifact V1 with Agent portability evidence #621.
                      2. Complete Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 after Finalize XMD artifact V1 with Agent portability evidence #621 and the delivered Retain provider checkpoint tokens for workflow Agent Prompts #622.
                      3. Complete Amend workflow artifact export with Agent bundle capture #625 after Finalize XMD artifact V1 with Agent portability evidence #621, Retain provider checkpoint tokens for workflow Agent Prompts #622, and Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624.
                      4. Complete Amend artifact inspection with intrinsic Agent forkability #623 after Finalize XMD artifact V1 with Agent portability evidence #621. It may proceed alongside Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 and Amend workflow artifact export with Agent bundle capture #625.
                      5. Complete Fork an XMD artifact into independent workflow history #603 after all four prerequisite stories.

                      #626 may add supported no-turn Claude portability afterward. It does not block
                      this Quest.

                      Completion

                      The Quest is complete when:

                      • one immutable artifact preserves the complete selected workflow evidence;
                      • inspection works anywhere without execution authority;
                      • every Agent session has a complete portability result;
                      • portable Agent conversations can be recreated through an exact checkpoint
                        without another model turn;
                      • continuation creates an independent run and provider state;
                      • conflicting identities refuse rather than reuse unrelated state;
                      • interrupted provider/database publication recovers deterministically; and
                      • all remaining blocking stories are delivered.

                      Authoritative contract

                      • specs/xmd-artifact-spec.md
                      • specs/workflow-workspace-spec.md
                      • the workflow Agent sections of specs/executable-mdx-spec.md
                      • architecture.md
                      • plans/xmd-portable-artifact-quest.md

                      The specifications own the detailed structural and evidence matrices. Child
                      stories implement that contract rather than choosing different product
                      behavior.

                      Out of scope

                      • Publishing or uploading artifacts from CI.
                      • Signed provenance, retention policy, final-digest attestation, and redacted
                        reports.
                      • Treating the artifact as authority to control the source run.
                      • Carrying destination credentials or provider launch configuration.
                      • Carrying live provider stores, locks, indexes, or ACPX queue state.
                      • Converting or migrating artifacts between semantic format versions.

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        enhancementNew feature or requestquestCoordinating story with dependency-ordered sub-issues

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          Quest: Export workflow runs as portable .xmd files #599

                          Description

                          @taras

                          Quest outcome

                          Export a workflow run as an immutable .xmd file that can leave CI, be
                          inspected on another machine, and become the source of a separate local run.

                          CI workflow run ──export──> build-failure.xmd
                          ├──inspect──> same recorded evidence
                          └──fork─────> new independent local run
                          

                          The file never becomes the original live run. It cannot resume, answer, cancel,
                          delete, or otherwise advance that run.

                          Example

                          A CI workflow fails after changing its Workspace and exchanging several turns
                          with an Agent.

                          The CI host exports build-failure.xmd. A developer downloads that one file and
                          can:

                          1. inspect the workflow's status and history without executing it;
                          2. inspect the committed Workspace and exact workflow definition associated
                            with that history;
                          3. see whether each recorded Agent conversation can be continued elsewhere; and
                          4. create a new local run from a selected checkpoint.

                          Creating the local run copies the selected workflow history and Workspace. It
                          does not modify or depend on the CI run.

                          When the selected history includes a portable Agent conversation, the
                          destination provider creates a separate conversation containing exactly the
                          turns through that checkpoint. Importing it executes no Prompt and produces no
                          new model response. Live Agent work becomes possible only after the new
                          workflow run has been committed successfully.

                          What the artifact contains

                          The artifact contains the complete XMD-owned evidence needed to understand and
                          fork the selected committed state:

                          • the run record and committed journal history;
                          • the selected event and Workspace state, called the artifact's frontier;
                          • every Workspace byte and the associated Repository and Worktree records;
                          • the root Markdown and component sources the workflow used, preserved together
                            as its authenticated definition; and
                          • a portability result for every recorded Agent session, plus an opaque provider
                            bundle when that conversation can be reproduced through the selected
                            checkpoint.

                          The artifact does not contain destination credentials, host paths, live
                          provider stores, executor locks, SQLite sidecars, open transactions, or other
                          authority belonging to the machine that exported it.

                          Stable public boundary

                          .xmd and the artifact's semantic format are public. SQLite is only the private
                          encoding used by format V1.

                          The artifact's identity comes from the workflow evidence it represents, not its
                          filename, location, or incidental SQLite layout. Copying or renaming the file
                          does not change that identity.

                          Readers open the file read-only and validate the complete container, manifest,
                          contents, and derived identity before returning any information. A malformed,
                          unsupported, or modified artifact returns no partial status, history, Workspace,
                          or Agent-portability result.

                          Export

                          Export takes the source run's executor lock before selecting the committed
                          frontier. This prevents the run from advancing while the artifact is assembled.

                          The output path receives the complete artifact atomically or remains unchanged.
                          Export never replaces an existing file and never changes the source run,
                          journal, Workspace, or provider state.

                          The command reports both:

                          • a semantic artifact identity for the evidence represented; and
                          • a SHA-256 digest for the exact file bytes transferred or published by CI.

                          Inspection

                          Artifact status and history use the existing workflow inspection commands with
                          an explicit artifact path.

                          Inspection:

                          • executes no document;
                          • starts no Agent or external provider;
                          • materializes no live Workspace;
                          • reads no workflow definition from Git;
                          • writes no journal, migration, or sidecar; and
                          • gives the same semantic result after the file is copied, renamed, or mounted
                            read-only.

                          An artifact path is not a local workflow-run ID, and a directory of downloaded
                          artifacts does not become the local run registry.

                          Continue by forking

                          Continuation always creates a separate workflow run that can resume
                          independently, with a new identity.

                          The fork copies the selected journal prefix, Workspace state, and workflow
                          definition. It shares no writable state, lock, or provider-owned directory with
                          the artifact or source run.

                          The new run records its lineage:

                          • artifact identity;
                          • source run identity;
                          • selected event; and
                          • selected Workspace root.

                          Two artifacts containing different evidence cannot reuse one destination run
                          merely because they claim the same source run or checkpoint.

                          Agent conversation portability

                          Every Agent Prompt records the provider checkpoint needed to identify the exact
                          conversation prefix it produced.

                          For a portable conversation:

                          1. the artifact carries a confidential, opaque provider bundle;
                          2. the destination supplies its own authentication;
                          3. a qualified provider creates a separate conversation containing exactly the
                            turns through the recorded checkpoint, with no Prompt during import;
                          4. the provider publishes the new conversation state and asserts its identity;
                          5. XMD commits the new workflow-run mapping; and
                          6. only then may the new run execute another Prompt.

                          Provider storage and XMD's workflow database cannot be committed as one
                          transaction. Recovery therefore identifies which side completed and either
                          finishes the same mapping or refuses conflicting state. It never creates a
                          second conversation silently.

                          A provider that cannot reproduce the exact prefix remains unsupported and
                          fails closed.

                          Provider support

                          • Codex qualifies through App Server conversation forking at an exact recorded
                            turn, without executing another turn.
                          • Claude checkpoint transport is useful, but the currently proven command form
                            executes a Prompt. Claude remains unsupported for this capability unless Provide a supported no-turn Claude exact-prefix Agent bundle lifecycle #626
                            proves a supported no-turn path.
                          • ACP session forking copies only the conversation head and does not satisfy an
                            arbitrary exact-checkpoint request.

                          Delivered foundations

                          These stories remain complete. Agent-aware portability continues through the
                          remaining dependent stories.

                          Remaining blocking stories

                          Delivery order

                          1. Complete Finalize XMD artifact V1 with Agent portability evidence #621.
                          2. Complete Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 after Finalize XMD artifact V1 with Agent portability evidence #621 and the delivered Retain provider checkpoint tokens for workflow Agent Prompts #622.
                          3. Complete Amend workflow artifact export with Agent bundle capture #625 after Finalize XMD artifact V1 with Agent portability evidence #621, Retain provider checkpoint tokens for workflow Agent Prompts #622, and Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624.
                          4. Complete Amend artifact inspection with intrinsic Agent forkability #623 after Finalize XMD artifact V1 with Agent portability evidence #621. It may proceed alongside Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 and Amend workflow artifact export with Agent bundle capture #625.
                          5. Complete Fork an XMD artifact into independent workflow history #603 after all four prerequisite stories.

                          #626 may add supported no-turn Claude portability afterward. It does not block
                          this Quest.

                          Completion

                          The Quest is complete when:

                          • one immutable artifact preserves the complete selected workflow evidence;
                          • inspection works anywhere without execution authority;
                          • every Agent session has a complete portability result;
                          • portable Agent conversations can be recreated through an exact checkpoint
                            without another model turn;
                          • continuation creates an independent run and provider state;
                          • conflicting identities refuse rather than reuse unrelated state;
                          • interrupted provider/database publication recovers deterministically; and
                          • all remaining blocking stories are delivered.

                          Authoritative contract

                          • specs/xmd-artifact-spec.md
                          • specs/workflow-workspace-spec.md
                          • the workflow Agent sections of specs/executable-mdx-spec.md
                          • architecture.md
                          • plans/xmd-portable-artifact-quest.md

                          The specifications own the detailed structural and evidence matrices. Child
                          stories implement that contract rather than choosing different product
                          behavior.

                          Out of scope

                          • Publishing or uploading artifacts from CI.
                          • Signed provenance, retention policy, final-digest attestation, and redacted
                            reports.
                          • Treating the artifact as authority to control the source run.
                          • Carrying destination credentials or provider launch configuration.
                          • Carrying live provider stores, locks, indexes, or ACPX queue state.
                          • Converting or migrating artifacts between semantic format versions.

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            enhancementNew feature or requestquestCoordinating story with dependency-ordered sub-issues

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              Quest: Export workflow runs as portable .xmd files #599

                              Description

                              @taras

                              Quest outcome

                              Export a workflow run as an immutable .xmd file that can leave CI, be
                              inspected on another machine, and become the source of a separate local run.

                              CI workflow run ──export──> build-failure.xmd
                              ├──inspect──> same recorded evidence
                              └──fork─────> new independent local run
                              

                              The file never becomes the original live run. It cannot resume, answer, cancel,
                              delete, or otherwise advance that run.

                              Example

                              A CI workflow fails after changing its Workspace and exchanging several turns
                              with an Agent.

                              The CI host exports build-failure.xmd. A developer downloads that one file and
                              can:

                              1. inspect the workflow's status and history without executing it;
                              2. inspect the committed Workspace and exact workflow definition associated
                                with that history;
                              3. see whether each recorded Agent conversation can be continued elsewhere; and
                              4. create a new local run from a selected checkpoint.

                              Creating the local run copies the selected workflow history and Workspace. It
                              does not modify or depend on the CI run.

                              When the selected history includes a portable Agent conversation, the
                              destination provider creates a separate conversation containing exactly the
                              turns through that checkpoint. Importing it executes no Prompt and produces no
                              new model response. Live Agent work becomes possible only after the new
                              workflow run has been committed successfully.

                              What the artifact contains

                              The artifact contains the complete XMD-owned evidence needed to understand and
                              fork the selected committed state:

                              • the run record and committed journal history;
                              • the selected event and Workspace state, called the artifact's frontier;
                              • every Workspace byte and the associated Repository and Worktree records;
                              • the root Markdown and component sources the workflow used, preserved together
                                as its authenticated definition; and
                              • a portability result for every recorded Agent session, plus an opaque provider
                                bundle when that conversation can be reproduced through the selected
                                checkpoint.

                              The artifact does not contain destination credentials, host paths, live
                              provider stores, executor locks, SQLite sidecars, open transactions, or other
                              authority belonging to the machine that exported it.

                              Stable public boundary

                              .xmd and the artifact's semantic format are public. SQLite is only the private
                              encoding used by format V1.

                              The artifact's identity comes from the workflow evidence it represents, not its
                              filename, location, or incidental SQLite layout. Copying or renaming the file
                              does not change that identity.

                              Readers open the file read-only and validate the complete container, manifest,
                              contents, and derived identity before returning any information. A malformed,
                              unsupported, or modified artifact returns no partial status, history, Workspace,
                              or Agent-portability result.

                              Export

                              Export takes the source run's executor lock before selecting the committed
                              frontier. This prevents the run from advancing while the artifact is assembled.

                              The output path receives the complete artifact atomically or remains unchanged.
                              Export never replaces an existing file and never changes the source run,
                              journal, Workspace, or provider state.

                              The command reports both:

                              • a semantic artifact identity for the evidence represented; and
                              • a SHA-256 digest for the exact file bytes transferred or published by CI.

                              Inspection

                              Artifact status and history use the existing workflow inspection commands with
                              an explicit artifact path.

                              Inspection:

                              • executes no document;
                              • starts no Agent or external provider;
                              • materializes no live Workspace;
                              • reads no workflow definition from Git;
                              • writes no journal, migration, or sidecar; and
                              • gives the same semantic result after the file is copied, renamed, or mounted
                                read-only.

                              An artifact path is not a local workflow-run ID, and a directory of downloaded
                              artifacts does not become the local run registry.

                              Continue by forking

                              Continuation always creates a separate workflow run that can resume
                              independently, with a new identity.

                              The fork copies the selected journal prefix, Workspace state, and workflow
                              definition. It shares no writable state, lock, or provider-owned directory with
                              the artifact or source run.

                              The new run records its lineage:

                              • artifact identity;
                              • source run identity;
                              • selected event; and
                              • selected Workspace root.

                              Two artifacts containing different evidence cannot reuse one destination run
                              merely because they claim the same source run or checkpoint.

                              Agent conversation portability

                              Every Agent Prompt records the provider checkpoint needed to identify the exact
                              conversation prefix it produced.

                              For a portable conversation:

                              1. the artifact carries a confidential, opaque provider bundle;
                              2. the destination supplies its own authentication;
                              3. a qualified provider creates a separate conversation containing exactly the
                                turns through the recorded checkpoint, with no Prompt during import;
                              4. the provider publishes the new conversation state and asserts its identity;
                              5. XMD commits the new workflow-run mapping; and
                              6. only then may the new run execute another Prompt.

                              Provider storage and XMD's workflow database cannot be committed as one
                              transaction. Recovery therefore identifies which side completed and either
                              finishes the same mapping or refuses conflicting state. It never creates a
                              second conversation silently.

                              A provider that cannot reproduce the exact prefix remains unsupported and
                              fails closed.

                              Provider support

                              • Codex qualifies through App Server conversation forking at an exact recorded
                                turn, without executing another turn.
                              • Claude checkpoint transport is useful, but the currently proven command form
                                executes a Prompt. Claude remains unsupported for this capability unless Provide a supported no-turn Claude exact-prefix Agent bundle lifecycle #626
                                proves a supported no-turn path.
                              • ACP session forking copies only the conversation head and does not satisfy an
                                arbitrary exact-checkpoint request.

                              Delivered foundations

                              These stories remain complete. Agent-aware portability continues through the
                              remaining dependent stories.

                              Remaining blocking stories

                              Delivery order

                              1. Complete Finalize XMD artifact V1 with Agent portability evidence #621.
                              2. Complete Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 after Finalize XMD artifact V1 with Agent portability evidence #621 and the delivered Retain provider checkpoint tokens for workflow Agent Prompts #622.
                              3. Complete Amend workflow artifact export with Agent bundle capture #625 after Finalize XMD artifact V1 with Agent portability evidence #621, Retain provider checkpoint tokens for workflow Agent Prompts #622, and Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624.
                              4. Complete Amend artifact inspection with intrinsic Agent forkability #623 after Finalize XMD artifact V1 with Agent portability evidence #621. It may proceed alongside Add the trusted Agent bundle lifecycle with Codex exact-prefix support #624 and Amend workflow artifact export with Agent bundle capture #625.
                              5. Complete Fork an XMD artifact into independent workflow history #603 after all four prerequisite stories.

                              #626 may add supported no-turn Claude portability afterward. It does not block
                              this Quest.

                              Completion

                              The Quest is complete when:

                              • one immutable artifact preserves the complete selected workflow evidence;
                              • inspection works anywhere without execution authority;
                              • every Agent session has a complete portability result;
                              • portable Agent conversations can be recreated through an exact checkpoint
                                without another model turn;
                              • continuation creates an independent run and provider state;
                              • conflicting identities refuse rather than reuse unrelated state;
                              • interrupted provider/database publication recovers deterministically; and
                              • all remaining blocking stories are delivered.

                              Authoritative contract

                              • specs/xmd-artifact-spec.md
                              • specs/workflow-workspace-spec.md
                              • the workflow Agent sections of specs/executable-mdx-spec.md
                              • architecture.md
                              • plans/xmd-portable-artifact-quest.md

                              The specifications own the detailed structural and evidence matrices. Child
                              stories implement that contract rather than choosing different product
                              behavior.

                              Out of scope

                              • Publishing or uploading artifacts from CI.
                              • Signed provenance, retention policy, final-digest attestation, and redacted
                                reports.
                              • Treating the artifact as authority to control the source run.
                              • Carrying destination credentials or provider launch configuration.
                              • Carrying live provider stores, locks, indexes, or ACPX queue state.
                              • Converting or migrating artifacts between semantic format versions.

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                enhancementNew feature or requestquestCoordinating story with dependency-ordered sub-issues

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions