Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 8 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,14 +10,19 @@ Multi-platform workit: OpenCode, Cursor, Codex CLI/desktop, Pi, and the CLI shar
| Implementation | subagent-driven via native `task`, delegated status from session parentage (child `parentID` must equal the coordinator session handle) | native `subagentStart` assignment; file writes pass through to host policy, exact stop identity, AskQuestion answers, arbitrary shell writes, and Tab edits remain agent_guided/unavailable | project-trust `tool_call` boundary; file writes pass through to host policy, shell writes remain agent_guided and no OS sandbox is provided | n/a (`workit task` only) |
| Lifecycle | `workit_task` pause/resume/close (native decision receipts) | `workit_task` pause/resume/close (policy-only) | session start/compaction/shutdown continuity; supervised stock-Pi worker lifecycle | `workit task pause\|resume\|close` |
| Handoff | manual `workit state export` + destination `state import` via the handoff skill (no native session spawn) | seeds a handoff prompt for the next agent | fresh stock-Pi review/worker processes; no nested worker launch | `workit state export` + destination `state import` (or printed handoff prompt) |
| Tools | one dual artifact: V1 `server()` + V2 `setup()`, ten native tools (eight families + external action + init apply) with `codemode:false` on V2 | MCP server (`workit_*`) | eight native core-backed `workit_<family>` tools (+ adapter-owned `workit_external_action`) | `workit` commands |
| Tools | one dual artifact: V1 `server()` + V2 `setup()`, ten native tools (eight families + read-only context + init apply) with `codemode:false` on V2 | MCP server (`workit_*`) | eight native core-backed `workit_<family>` tools (+ adapter-owned `workit_external_action`) | `workit` commands |
| Shared MCP transport | n/a (native tools remain host-owned) | `@brainervirus/workit-mcp`; host wiring remains adapter-owned | n/a (native tools remain host-owned) | n/a |
| Skills | `skills.paths` + fourteen canonical policy-selected method skills (no vendored Superpowers dirs) | plugin `skills/` dirs | package `pi.skills` + fourteen canonical method skills | n/a |
| Branch policy init | `workit_init_apply action=branch_policy` (narrow registration) | pending — use the wizard screen (unattested MCP cannot mutate) | pending — use the wizard screen (no host surface is wired yet) | wizard screen |
| Distribution | npm plugin entry (`opencode.json`) | Cursor Marketplace (git-discovered `.cursor-plugin/plugin.json`) | npm package manifest (`pi.extensions`/`pi.skills`) | npm bin (`npx`) |

OpenCode's native adapter keeps the eight shared operation contracts authoritative while projecting advertised nested schemas to the provider's supported depth; runtime parsing remains core-owned.

OpenCode V1 and V2 expose no managed external mutation tool. Use native host
tools for effects and `workit_context` for read-only inspection; do not rebuild
proposal/approval orchestration or retain a disabled execution alias. Existing
uncertain history remains inspectable and must be reconciled before retry.

Concrete optional Git, hosting, YouTrack, and documentation mutations remain
adapter-owned on host surfaces that can attest the effect. They must run
through the shared one-time action reservation and host-observed settlement,
Expand All @@ -27,7 +32,8 @@ matching). Caller-unattested MCP keeps optional mutations unavailable. The CLI
(including `--confirm` without a TTY) return `needs_input` and never fabricate
an approval receipt.

Read-only `context.read` is available on OpenCode, Pi, and the CLI for the
Read-only `workit_context` is available on OpenCode; Pi and the CLI use
`context.read` for the
enumerated git/PR/YouTrack/changelog/release/affected contexts without
approval or writer ownership; release context includes a deterministic draft,
and affected context identifies files only. Documentation edits continue
Expand Down
22 changes: 12 additions & 10 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,19 +5,21 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

> **Version model.** The repository's package manifests pin a fixed source
> version (`0.4.0`); [semantic-release](https://semantic-release.gitbook.io)
> computes the next version from Conventional Commits and rewrites the package
> versions and internal `workspace:*` dependencies **in CI only**
> (`packages/workit-core/scripts/rewrite-workspace-deps.ts`), never committing
> the rewrite back to the repository. This file is maintained by hand and
> documents through `0.6.0`; releases published after that (for example
> `0.6.1`, `0.7.0`, `0.7.1`) were created by the release workflow and their
> notes live in GitHub Releases, not here. The published npm version can
> therefore run ahead of both the source manifests and this changelog.
> **Version model.** Semantic-release computes published versions from
> Conventional Commits. The release workflow rewrites internal dependencies
> for publishing, then synchronizes source manifests through its manifest PR.
> GitHub Releases contain the generated release notes; this file records
> manually maintained changes, including unreleased work.

## [Unreleased]

### Changed

- OpenCode V1/V2 remove managed external mutations and proposal/approval
orchestration. Native host tools execute effects; strict read-only
`workit_context` replaces the old combined action/context tool. Existing
history and remaining-host action machinery are preserved.

### Fixed

- OpenCode action approvals revalidate same-text proposals before rejecting
Expand Down
17 changes: 9 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ host documents.

| Package | Purpose |
| ----------- | ------------------------------------------------------------------------------- |
| OpenCode | Native plugin with fourteen method skills, ten tools (eight shared families plus external action and init apply), and provider-safe schemas |
| OpenCode | Native plugin with fourteen method skills, ten tools (eight shared families plus read-only context and init apply), and provider-safe schemas |
| Cursor | MCP transport, one native hook dispatcher, one contract rule, and fourteen skills |
| Codex | Native plugin manifest, shared MCP transport, documented lifecycle hooks, and fourteen skills |
| Pi | Native npm extension with nine tools (eight shared families plus external action), fourteen skills, and session continuity |
Expand Down Expand Up @@ -296,13 +296,13 @@ MCP provider keeps read-only inspection usable without an attested caller and
returns `capability_unavailable` for authority-sensitive mutations when the
host cannot prove the caller boundary.

Optional Git, hosting, YouTrack, and documentation effects use one-time
On Pi and the CLI, optional Git, hosting, YouTrack, and documentation effects use one-time
approved action reservations and host-observed settlement on the existing
host-owned effect surfaces. A concrete call must match the exact canonical
operation/target/payload approved by the native host; prose or substring
matches never authorize it. Missing credentials leave unrelated core work
usable, while an uncertain remote outcome blocks blind retry. OpenCode and Pi
use native approval receipts; the CLI `workit action` route shows the exact
usable, while an uncertain remote outcome blocks blind retry. Pi
uses native approval receipts; the CLI `workit action` route shows the exact
descriptor and requires an interactive TTY confirmation. A headless CLI call
(including `--confirm` without a TTY) returns `needs_input`, while the
caller-unattested MCP surface keeps optional mutations unavailable. Time
Expand All @@ -313,8 +313,9 @@ when managed coordination or outcome reconciliation is unnecessary. Inspect the
target checkout's conventions first; native permissions apply. There is no need
to start a Workit task just to commit, and a local commit does not require PR
readiness or task-closure paperwork. Never switch execution paths to evade a
denial or retry an uncertain managed effect. Managed actions remain optional for
their target locking and outcome reconciliation. See the
denial or retry an uncertain managed effect. OpenCode V1 and V2 use native
host tools for mutations; Workit exposes read-only `workit_context` and shared
coordination tools, with no managed external-action executor. See the
[action reliability specification](docs/adaptive-workit/reliability-spec.md).
Newly assessed bounded behavior changes keep behavioral checks and self-review.
Security, data, public-contract and operational consequences, the thorough
Expand Down Expand Up @@ -358,8 +359,8 @@ Examples:
- comment-only `youtrack.update` with `{ "issueId": "ABC-1", "markdown": "..." }`
- `changelog.apply` with `{ "entries": [{ "category": "Added", "text": "..." }] }`

All native adapters and the CLI also expose the read-only `context.read`
operation for `git`, `pr`, `youtrack`, `github_issue`, `gitlab_issue`,
OpenCode exposes the read-only `workit_context` tool with a flat payload.
Pi and the CLI expose the read-only `context.read` operation for `git`, `pr`, `youtrack`, `github_issue`, `gitlab_issue`,
`changelog`, `release`, and `affected` context. The tracker kinds return the
same title/body/state triple through authenticated `gh` and `glab` (GitLab
subgroups kept); they fail closed when the CLI is unavailable or not logged in.
Expand Down
43 changes: 43 additions & 0 deletions docs/adaptive-workit/plan.md
Original file line number Diff line number Diff line change
Expand Up @@ -449,3 +449,46 @@ focused question only when one of those choices blocks a concrete slice.
restart OpenCode once to activate the tested source; inspect new-session
routing before model-driven qualification. Do not rebuild or reload while
the current user session is running.

### OpenCode native-effects cutover — 2026-09-30

- Baseline: PR #134 squash-merged, all fourteen PR checks and main CI passed;
v1.3.1 published. Started from manifest-synced main `94adf7a` with a clean tree.
- User selected removal, not disabled managed executors, on both OpenCode V1
and V2. The cutover contract in `reliability-spec.md` supersedes OpenCode's
old external-mutation tool. Shared Pi/CLI effects remain in use.
- Slice 1: delete OpenCode mutation registration, proposal/autoapproval runner
and obsolete routing; expose strict read-only `workit_context`. Slice 2
depends on 1: adapt adapter/acceptance tests, retaining generic decisions,
receipts, workers, shell policy and read-only contexts. Slice 3 depends on
1–2: docs, full isolated checks, pack checks and installed V2 loader probe.
- Two Luna workers have disjoint source/test scopes; the coordinator owns
guidance, integration and acceptance. No active host build/reload, real-history
migration or pending-outcome settlement occurs during development.
- Acceptance includes absent executor on both versions, mutation-shaped context
input rejected without effects, unchanged state/history and remaining-host
behavior. Checkpoint and final counts follow after integration.
- Slice 1 complete: mutation registration, executor/proposal/autoapproval code
and retired repo/YouTrack aliases removed. Context uses the canonical payload
and existing read helper, without importing the generic effect executor.
Production typecheck and scoped adapter lint passed. Independent Luna review
found no definite defect; pinned V1 runtime preserves raw inputs for strict
handler validation. Shared guidance no longer points to deleted tool aliases.
Next: finalize tests and isolated build/pack/native loader checks.

- Slices 2–3 complete: obsolete executor tests removed; strict context, receipt
replay protection, worker provenance, native shell policy and shared Pi/CLI
effects retained. Updated one historical traceability reference to the current
no-action-authorization regression. Full isolated `bun run check` passed:
1,531 tests, lint, format, build and typecheck. Seven release-candidate tarballs
and marketplace validation passed.
- Installed V2.0.19 and official Docker V1.18.30 loaded the candidate in private
fixtures and registered the same ten tools, with context present and managed
executor absent. These are loader checks, not model-driven qualification.
The V1 fixture container was stopped; no user session was resumed. Candidate
source matches the workspace; active artifact/config hashes remain unchanged.
Evidence: `/tmp/workit-native-effects-{full-check,pack,v2-probe,v1-probe}.log`
and `/tmp/workit-native-effects-x7cspusr/` source/host hashes and probe results.
- Remaining: publish PR, babysit CI and squash-merge; then activate the local pin
only at a safe restart boundary. No live history migration is required or
authorized. Historical unknown outcomes require evidence before native retry.
52 changes: 47 additions & 5 deletions docs/adaptive-workit/reliability-spec.md
Original file line number Diff line number Diff line change
@@ -1,10 +1,12 @@
# Workit action reliability

Date: 2026-09-30. Status: implemented and isolated acceptance passed; active-host deployment pending.
Date: 2026-09-30. Status: native-effects cutover passed isolated acceptance; v1.3.1 baseline retained.

The v1.3.1 proposal-binding work below is historical for OpenCode mutation
execution. The native-effects cutover at the end supersedes that execution path.

This extends the adaptive spec; it does not authorize live migration or effects
in the user's running sessions. Existing workspace-resolution changes are a
separate dirty-tree slice and must remain intact.
in the user's running sessions. Previously reconciled workspace-resolution changes remain intact.

## Reproduced problem

Expand All @@ -18,7 +20,7 @@ rejected the approval before checking which descriptor remained current.
Changing the commit message escaped the collision and caused another question.
Task closure then induced an assessment and additional schema retries.

## Required behavior
## v1.3.1 required behavior (historical mutation adapter)

1. Resolve all proposals matching an observed approval before deciding whether
they are ambiguous. Evict only descriptors proven stale by successful fresh
Expand Down Expand Up @@ -80,7 +82,7 @@ defines native capabilities; questions are not permission grants. These referenc
guide the implementation but do not prove Workit's reliability. Scenario tests
and saved host evidence must do that.

## Proactive audit dispositions
## v1.3.1 proactive audit dispositions

- Approval identity: stale same-text proposals, ask-time ordering, duplicate
delivery and consumed-receipt replay have regression coverage. V2 must capture
Expand Down Expand Up @@ -112,3 +114,43 @@ and saved host evidence must do that.
loader probe do not establish one-shot reliability across models. A bounded
model-driven qualification should measure retries and duplicate questions
before making that claim. Do not run the budgeted 90-run suite implicitly.

## OpenCode native-effects cutover

User decision, 2026-09-30: remove managed external mutations from both OpenCode
versions rather than retain disabled executors or add a V1-only permission shim.
Native host tools own Git, hosting, YouTrack and documentation effects. Native
denials, sandbox rules and target-repository conventions remain authoritative.

Remove `workit_external_action`, its adapter-only proposal queues, standing
approval orchestration and effect runner. Do not add a compatibility alias that
can still execute mutations. Retain eight shared operation families, native
decision receipts for real policy choices, worker/lifecycle support and config
initialization. Expose the existing read-only contexts through `workit_context`
with a strict flat payload schema; context reads cannot select a mutation.

Shared core/Pi/CLI effect machinery remains in use and is outside this adapter
removal. Persisted action history, pending/unknown outcomes, decisions, tasks and
leases are preserved. Inspection remains available, but an uncertain historical
effect must be reconciled from actual evidence before any native retry. Do not
fake settlement or migrate live history during this cutover.

Acceptance slices:

1. Remove both native registrations and OpenCode-only execution/proposal code;
verify V1 and V2 expose context, families and init only. No effects alias.
2. Retain strict read-only context validation and session/worker provenance;
reject mutation-shaped input without Git or Workit state writes. Preserve
decision receipt replay protection and native shell-policy regression checks.
3. Replace obsolete execution tests and current guidance. Shared effects and
uncertainty tests for the remaining hosts continue to pass. Qualification
scripts must not attempt the removed tool or advertise stale capability.
4. Isolated build/full checks, package acceptance and installed V2 private loader
probe. Preserve the running host's artifact/config until a safe restart.

The installed V2.0.19 bundle uses `options.permission ?? toolName` for coarse
whole-action deny filtering; it does not expose a custom-tool permission assert
for each subprocess. V1 has an async `ToolContext.ask`, but Workit's existing
effects are synchronous and would need another command authorization layer.
Native execution avoids duplicating the host's command scanner and permission
workflow on either version.
2 changes: 1 addition & 1 deletion docs/workit-v1/capabilities.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Workit v1 host capability matrix

Generated from adapter fixtures. Fixture revision: `workit-v1-2026-09-09`.
Generated from adapter fixtures. Fixture revision: `workit-v1-2026-09-30`.

Unknown or untested cells fail the applicable baseline rather than reading as supported.

Expand Down
Loading
Loading