Skip to content

fix: refuse nested worker launches; workers are told they are the worker (sume#7839) - #20

Open
chasehuh wants to merge 1 commit into
mainfrom
astra-disconnect-fix-7839
Open

chasehuh wants to merge 1 commit into
mainfrom
astra-disconnect-fix-7839

Conversation

@chasehuh

Copy link
Copy Markdown
Owner

Fixes the "Astra Mini workers disconnect" pattern tracked in https://github.com/sumelabs/sume/issues/7839. Do not merge without Chase's confirm (the Mini currently runs this branch from ~/.cstack/src).

Root cause

  1. Worker prompts opened with the launch spec itself (--backend codex --model gpt-6-astra --effort mid, --host mini, "Fresh worker", "Job title: …"), and the desk AGENTS.md says "You are the main agent unless told otherwise". Nothing told the Codex worker otherwise, so it read the orchestration skill and launched itself as a nested worker.
  2. --host local from inside the worker: Codex's unified_exec_startup returned the tool call early (status: failed, child banner in stdout), the model reported "Started …", the outer job exited rc=0, and Codex killed the tracked child pid at turn end (nested log's last write 05:36:18, outer end 05:36:19). No remote-jobs/ dir → --status "unknown job".
  3. --host mini from the Mini (ssh to itself) → a duplicate detached job on the same clone while the outer job still exited rc=0.
  4. tokenmaxxing is not involved: the supervisor passes the environment through and the outer sessions ended with a clean turn.completed.

Changes

  • agent-human-stream.sh: SUME_WORKER_SESSION export, [sume worker session] prompt preamble, nested-launch refusal (exit 5).
  • sume-bg-launch.sh: same refusal for launches; --status/--jobs/--attach/--kill still work; SUME_BG_ALLOW_NESTED=1 override.
  • sume-bg-remote.sh: SUME_BG_REMOTE_JOB export (+ the live Mini keychain file-store line that was uncommitted on the Mini).
  • install.sh + sume-desk/worker-mode-snippet.md: "Sume worker mode (always on)" appended to ~/.codex/AGENTS.md and ~/.grok/AGENTS.md; check-wiring.sh asserts it.
  • AGENTS.md, SKILL.md, docs/MINI-WORKER-HOST.md: worker exception, prompt hygiene, the pattern.
  • Tests: sume-bg-launch.test.sh 10/11, agent-human-stream.test.py::test_worker_preamble_and_nested_guard.

Verification

  • sume-bg-launch.test.sh: all ok (11 cases). agent-human-stream --self-test: ok.
  • Probe on the Mini through the real path (sume-bg-launch --host mini, codex/gpt-6-astra, prompt with the same misleading header): job 20260917T055755Z-astra-nest-probe stayed attached, saw SUME_WORKER_SESSION / SUME_BG_REMOTE_JOB in its tool shell, both nested launch attempts returned exit 5, finished PROBE: done, exit_code=0, zero child logs / registry rows. Details on sume#7839.

🤖 Generated with Claude Code

…ker (sume#7839)

Astra (codex) Mini workers kept "disconnecting": the outer session read the
launcher flags quoted in its prompt plus the desk's "you are the main agent
unless told otherwise", launched a nested worker via sume-bg-launch, reported
"Started …" and exited rc=0. Codex's unified exec had returned the tool call
early (status: failed) and killed the tracked child at turn end, so the nested
session vanished with no remote-jobs trace; --host mini from the Mini (ssh to
itself) made duplicate jobs instead.

- agent-human-stream: export SUME_WORKER_SESSION, prepend a "[sume worker
  session]" preamble to every launched prompt (prompt_head stays original),
  refuse launches inside a worker session (exit 5; --sessions/--self-test
  are reads). AGENT_HUMAN_STREAM_WORKER_PREAMBLE=0 / SUME_BG_ALLOW_NESTED=1.
- sume-bg-launch: same guard for launches (control plane still allowed).
- sume-bg-remote run: export SUME_BG_REMOTE_JOB so the refusal names the
  Mini job; also commit the live Mini keychain file-store export.
- install.sh: append "Sume worker mode (always on)" to ~/.codex/AGENTS.md and
  ~/.grok/AGENTS.md (Claude Code inherits via the import); check-wiring
  asserts it. AGENTS.md / SKILL.md: worker exception + prompt hygiene
  (no launcher flags in the prompt body). docs/MINI-WORKER-HOST.md: the
  pattern and the guards.
- tests: host test 10/11 (guard, control plane, override, job marker) and
  a wrapper self-test for the preamble + guard; both scrub inherited markers
  so install.sh works from inside a worker.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant