feat(implementation): let the orchestrator keep commit authority over dispatched workers - #4511
Conversation
… dispatched workers Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…mmit authority Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 1m 14s —— View job Security review
No security issues found. This PR changes only Markdown-authored agent/skill instructions and metadata for the
There's no code here that parses untrusted input, handles secrets/tokens, exposes a network surface, or changes tool grants/permissions ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 36544fe1d0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Claude finished @kyle-sexton's task in 3m 4s —— View job Code review complete ✅
Scope: reviewed the full diff ( What I checked:
No blocking findings. The one thing I weighed and decided not to raise: the new "Concurrency" bullet in I did not independently re-run the author's shell-script verification suites or the paid Branch: |
…mit authority Plain status --porcelain collapses a new directory to one entry, so a return or a synthesized verifier diff could omit new files. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 2m 17s —— View job Code review complete ✅
Scope: this session's diff since the lane's prior review (posted at What I checked:
No blocking findings. The fix is narrowly scoped, correct, and applied consistently across both files that describe the |
|
Claude finished @kyle-sexton's task in 1m 4s —— View job Security review
No security issues found. Reviewed the full diff at head Every changed file is Markdown-authored agent/skill instructions or plain metadata for the
None of this parses untrusted input, handles secrets/credentials, exposes a network surface, or changes tool grants ( |
…on an unknown commit authority Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 43s —— View job Security review complete ✅
No security issues found. This session reviewed the full PR diff at head That incremental change is two small wording edits, both in Markdown-authored agent/skill instructions:
Neither edit touches parsing of untrusted input, secrets/credential handling, network surface, or tool grants ( |
|
Claude finished @kyle-sexton's task in 2m 42s —— View job Code review complete ✅
Scope: reviewed the full diff ( What changed since the last review and what I checked:
No blocking findings. The incremental commit is a narrow, correct closure of two gaps a prior fresh-context verifier and Codex flagged; both fixes are internally consistent with the rest of the contract and with each other. I did not independently re-run the author's shell-script verification suites or the paid |
…worker authority (#4262) (#4698) <!-- CURSOR_AGENT_PR_BODY_BEGIN --> Fixes #4262 ## Summary Defines a wave as one phase’s worker-row batch. One git writer per worktree binds under both commit authorities (`worker` → serialize shared worktree; concurrent shared worktree needs `orchestrator`). Keeps #4511 orchestrator concurrency. New/updated evals 7 and 9. Versions: `implementation` → 0.18.2; `work-items` wording bump (may collide with stacked #4688–#4690 — serialize on merge). ## Sources - git-worktree / lockfile.h; triage A+B outcome B ## Test plan - [x] evals; changelog parity (per implementer) ## Notes **Merge after** work-items stack #4688/#4689/#4690 if those land first, or renumber work-items here. <!-- CURSOR_AGENT_PR_BODY_END --> <div><a href="https://cursor.com/agents/bc-ab53da24-b89d-4314-a060-0da474e837e9?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a> <a href="https://cursor.com/background-agent?bcId=bc-ab53da24-b89d-4314-a060-0da474e837e9&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a> </div> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Closes #4508
Summary
A plan whose worker fence forbids staging, committing, and pushing (because the orchestrator owns a
commit-subject gate or a push-once rule) could not use the implementation lane:
implementation:implementerwas described as always committing and pushing early, and/implementation:implement-dispatchmade commit-and-push-early a clause of every brief whileforbidding a generic subagent for source edits. This adds an explicitly declared commit
authority brief field (
workerby default,orchestratoras the alternative) so the orchestratorcan keep commit authority while still dispatching the tier-bound implementer.
Fix
agents/implementer.md: description made conditional; new## Commit authoritysection. Underorchestratorthe worker edits only (no index or ref writes, no provisioning), works in theassigned worktree, and returns
git status --porcelain --untracked-files=allpaths instead ofa sha. A commit-forbidding fence with no declared mode, a commit-authority value other than
workerororchestrator, a missing worktree path, or a request for worker-side provisioningunder
orchestratoris a STOP.skills/implement-dispatch/SKILL.md: new### Commit authoritysubsection (when to declare it,worktree, brief, verification of the uncommitted tree including untracked files, the
orchestrator's combined phase-boundary commit, push per the plan's push rule, concurrency);
Prerequisites, cadence steps 1, 3, 4, Phase boundaries, and Gotchas made conditional where they
assumed a worker commit. The rule against generic subagents stands.
skills/implement-dispatch/evals/evals.json: case 8 covers a no-commit plan fence, with anegative expectation for a narrow fence.
README.mdimplementer row;plugin.json0.17.0 -> 0.18.0; CHANGELOG[0.18.0].Absent the field, behavior is unchanged, so
/work-items:workand/implementation:implementcallers keep worker commit authority.
Verification
Measured at head
36544fe1d, base47555b587. A later commit answers the Codex review thread(untracked files inside a new directory): a scratch-repo probe showed plain
status --porcelainprints
?? newdir/while--untracked-files=alllists each file; check-skill PASS and zeroU+2014 on the added lines were rerun on it.
bash scripts/check-changed-skills.sh 47555b587:1 skill(s) checked, 0 failed.bash scripts/check-changelog-parity.sh --check-bump 47555b587: every changed version has itsCHANGELOG entry.
3 files scanned, no em dashes; U+2014 on added diff lines: 0.CHECK_SKILL_SKILLS_ROOT=plugins/implementation/skills bash plugins/skill-quality/scripts/check-skill.sh implement-dispatch:PASS, 0 errors, 0 warning(s);evals.jsonparses.scripts/validate-plugin-contracts.test.shPASS=42 FAIL=0,scripts/check-changed-skills.test.shPASS=21 FAIL=0,plugins/skill-quality/scripts/check-evals-quality.test.sh0 failures. The remaining--explainselection is left to CI; every touched file is a recorded no-suite path.criteria and named three weak points (shebang gotcha still unconditional, verifier diff not
covering untracked files, push wording in the agent); all three are fixed in
36544fe1dand thegates above were rerun on it.
Related
back to a generic agent and lost the implementer's model-tier binding.
questions, each challenged by a fresh-context validator with the rationale withheld:
general-purposeagent. Answer: the mode.Validator: confirmed (a generic agent breaks the skill's tier-binding rule).
challenged (a narrow fence could be misread and silently drop push-early crash insurance).
Adopted the verdict: explicit declaration only; a commit-forbidding fence without it is a STOP.
claude plugin eval) is a paid model run and was notexecuted; the case is statically validated only.
🤖 Generated with Claude Code