feat(prompts): progress updates, outcome-scoped research, single-source destructive-fix gate - #374
Merged
Merged
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4ffae52111
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Owner
Author
|
@codex review |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is PR 3 of 3 from the prompt-cruft audit. It makes the behavioural prompt changes for the current Opus and Sonnet generation, and it single-sources the destructive-fix gate.
Behaviour changes (intended)
## Continuous Executionsection inagents/overlord.mdno longer suppresses all user-facing text. The overlord still proceeds without pausing. It now surfaces stop conditions, every Tier-A surface, the final report, and a brief progress line on long stretches: multi-wave implement loops, PR watches, and brood dispatch. Per-state announcements, transition logs, and tool-by-tool narration stay out.agents/github-reviewer.mdandagents/local-reviewer.mdno longer say "produce zero text output". The Output Contract YAML remains the report returned to the caller.agents/cerebrate.mdnow reads until every step's file list is complete and it is confident in it. Unresolved paths go to Open questions. This replaces the fixed budget of 3N files.enable-brood-remotetrigger. The skill description gives one trigger example instead of four near-synonyms. The explicit-request-only gating is unchanged.Repetition removed (meaning-preserving)
Each of these sites now keeps one authoritative statement:
agents/overlord.mdagents/cerebrate.mdplan-interrogationimproving-architectureand itsINTERFACE-DESIGNreferencecreep-spread, whose term rules now point atCONTEXT-FORMAT.mddecision-report, whose constraints now live in## Do Notgovernance/workflow.mdnow sizes the PR summary to the change instead of capping it at five sentences. Local review confirmed that no rule was dropped and that no reference dangles.Destructive Fix Gate is single-sourced (safety)
The ten-category gate used to be hand-mirrored in
governance/safety-rails.mdandgovernance/security-policy.md, and the two copies had drifted apart. An earlier commit on this branch aligned one copy to the other and narrowed category 2 as a result: "Delete files marked as security-relevant". That is now fixed.One canonical list.
security-policy.md(Destructive Fix Confirmation Gate) holds the only list. Each category is aDESTRUCTIVE-CAT <n>:marker line, and each row is the union of both former wordings, so no row is narrower than either copy onmain.Broadest reading. An explicit rule says every category is read at its broadest, and that no marking or label is ever a precondition for a category to fire.
Pointer, not copy.
safety-rails.mdkeeps its## Destructive Fix Gateheader and trigger framing, and points to the canonical list. All existing references resolve, andagents/drone.mdnow cites the canonical section.Regression guards. Two fixtures guard the change:
tests/policy/safety-destructive-fix-gate-single-source.jsonasserts exactly ten markers at the canonical file.tests/policy/safety-destructive-fix-gate-no-second-copy.jsonasserts zero markers in the five citing documents.Both were bite-proofed. Each of these mutations turns the suite red: re-narrowing a row, deleting or adding a category, re-copying the rows, and deleting the never-restates sentence.
Checker fix found along the way
tools/policy_check.shset_checkused to abort the whole run on a fixture file with zeroextract_regexmatches: the grep fallback appended a second{}, whichjq --argjsonrejected. The fallback now runs only when perl is absent, and a failed pipeline yields an empty capture. A SAFETY-CANARY witnesses the fix, and it was bite-proofed against the reverted code.Validation
bash tools/validate.sh --changed, which runs the full suite becausetools/**changed: 23 suites pass and there are 0 new policy findings.main.Versioning
MINOR 4.0.2 -> 4.1.0. The overlord's user-visible output changes, and the destructive-fix gate is broadened. There is no API or format break.
CHANGELOG.mdhas a[4.1.0]entry with Added, Changed, and Fixed sections.Known limitations and follow-ups
set_checktreats extractor failures as zero matches. This behaviour is inherited frommainand unreachable with the current fixtures. The fix needs a decision on whether perl becomes a hard CI dependency.DESTRUCTIVE-CATmarkers. This limitation is stated in the fixture descriptions.