From 568cee7482b5b4d84b698584c5d5afc57c5cb6e7 Mon Sep 17 00:00:00 2001 From: kjgbot Date: Sun, 30 Aug 2026 23:09:17 +0200 Subject: [PATCH 1/2] fix(workflows): build agent preps kernel + fixtures in its own sandbox (replaces #64, #65) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit PR #64 tried a separate pre-build STEP — cloud steps have per-step sandboxes (ops/BACKLOG.md:688-707), so the binary never reached build-1. PR #65 put the prep in build's prompt but got two real swarm findings: 1. Comment hardcoded kernel/target/debug/relayflowd — PR #38 fixed that pattern; ops/cargo.sh:42-52 redirects builds via CARGO_TARGET_DIR and exposes RELAYFLOWD_BIN. Prompt now references RELAYFLOWD_BIN. 2. `cd kernel && ...` followed by `cd .. && find` broke when the agent ran commands as separate tool calls — cd doesn't persist. Now uses `( cd kernel && sh ../ops/cargo.sh build )` subshell and `find testdata/preflight ...` (no cd needed). Also drops the `|| true` failure-hiders — a silent skip here reproduces the exact stall we're trying to fix. --- workflows/drive-cloud.yaml | 16 ++++++++++++---- workflows/drive.yaml | 28 ++++++++++++++++++++++------ 2 files changed, 34 insertions(+), 10 deletions(-) diff --git a/workflows/drive-cloud.yaml b/workflows/drive-cloud.yaml index 04670a1d..23b124a5 100644 --- a/workflows/drive-cloud.yaml +++ b/workflows/drive-cloud.yaml @@ -179,10 +179,18 @@ workflows: dependsOn: - assess-gate-1 maxIterations: 3 - task: "Read ops/NEXT.md, AGENTS.md, and the relevant parts of\ndocs/RFC-0001-everything-is-a-relayflow.md.\ - \ Implement exactly that\nwork package \u2014 nothing more. Run the definition-of-done commands\n\ - yourself and iterate until they pass. Keep files small and\nsingle-purpose. End with BUILD_DONE\ - \ only when the definition of done\npasses locally; paste the passing output.\n" + task: "Before touching your work package, prepare this sandbox: build the\nkernel binary that sdk/tests/live-kernel.test.ts\ + \ exec's via\nops/cargo.sh's RELAYFLOWD_BIN, and restore +x on preflight fixtures\nthat the sandbox\ + \ strips. Run these three commands (subshells so cd\nsurvives if you invoke them as separate tool\ + \ calls):\n\n chmod +x ops/cargo.sh\n ( cd kernel && sh ../ops/cargo.sh build )\n find\ + \ testdata/preflight -type f -name '*-cli' -exec chmod +x {} +\n\nEach must succeed. Do NOT swallow\ + \ errors with `|| true` \u2014 a silent\nskip here reproduces the exact \"19 SDK failures\" that\ + \ runs 60-63,\n65-67 stalled on. Paste the last 5 lines of the kernel build's\noutput in your summary;\ + \ if the build fails, fix the actual failure\nbefore proceeding to npm test.\n\nThen implement the\ + \ work package: read ops/NEXT.md, AGENTS.md, and\nthe relevant parts of docs/RFC-0001-everything-is-a-relayflow.md.\n\ + Implement exactly that work package \u2014 nothing more. Run the\ndefinition-of-done commands yourself\ + \ and iterate until they pass.\nKeep files small and single-purpose. End with BUILD_DONE only when\n\ + the definition of done passes locally; paste the passing output.\n" verification: type: output_contains value: BUILD_DONE diff --git a/workflows/drive.yaml b/workflows/drive.yaml index 9dd5523e..4cf18b9f 100644 --- a/workflows/drive.yaml +++ b/workflows/drive.yaml @@ -274,12 +274,28 @@ workflows: dependsOn: [assess-gate] maxIterations: 3 task: | - Read ops/NEXT.md, AGENTS.md, and the relevant parts of - docs/RFC-0001-everything-is-a-relayflow.md. Implement exactly that - work package — nothing more. Run the definition-of-done commands - yourself and iterate until they pass. Keep files small and - single-purpose. End with BUILD_DONE only when the definition of done - passes locally; paste the passing output. + Before touching your work package, prepare this sandbox: build the + kernel binary that sdk/tests/live-kernel.test.ts exec's via + ops/cargo.sh's RELAYFLOWD_BIN, and restore +x on preflight fixtures + that the sandbox strips. Run these three commands (subshells so cd + survives if you invoke them as separate tool calls): + + chmod +x ops/cargo.sh + ( cd kernel && sh ../ops/cargo.sh build ) + find testdata/preflight -type f -name '*-cli' -exec chmod +x {} + + + Each must succeed. Do NOT swallow errors with `|| true` — a silent + skip here reproduces the exact "19 SDK failures" that runs 60-63, + 65-67 stalled on. Paste the last 5 lines of the kernel build's + output in your summary; if the build fails, fix the actual failure + before proceeding to npm test. + + Then implement the work package: read ops/NEXT.md, AGENTS.md, and + the relevant parts of docs/RFC-0001-everything-is-a-relayflow.md. + Implement exactly that work package — nothing more. Run the + definition-of-done commands yourself and iterate until they pass. + Keep files small and single-purpose. End with BUILD_DONE only when + the definition of done passes locally; paste the passing output. verification: type: output_contains value: BUILD_DONE From f5b1f5f7853ad67d9e77fd0ade387d87161ba226 Mon Sep 17 00:00:00 2001 From: kjgbot Date: Sun, 30 Aug 2026 23:22:25 +0200 Subject: [PATCH 2/2] fix(workflows): narrow run history to #63 + tell build to STOP on kernel failure MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Codex history lens found: - The "runs 60-63, 65-67 stalled on the 19 failures" claim was too broad. Only #63 explicitly reported the 19 failures; #60-#62 had different blockers, #66 was auth, #67 landed changes. Narrowed to #63. - The "fix the actual failure" wording could authorize out-of-scope kernel repair when ops/NEXT.md excludes it. Changed to STOP without BUILD_DONE on build failure — kernel repair is explicitly out of scope. --- workflows/drive-cloud.yaml | 9 +++++---- workflows/drive.yaml | 9 +++++---- 2 files changed, 10 insertions(+), 8 deletions(-) diff --git a/workflows/drive-cloud.yaml b/workflows/drive-cloud.yaml index 23b124a5..a44fb0c5 100644 --- a/workflows/drive-cloud.yaml +++ b/workflows/drive-cloud.yaml @@ -184,10 +184,11 @@ workflows: \ strips. Run these three commands (subshells so cd\nsurvives if you invoke them as separate tool\ \ calls):\n\n chmod +x ops/cargo.sh\n ( cd kernel && sh ../ops/cargo.sh build )\n find\ \ testdata/preflight -type f -name '*-cli' -exec chmod +x {} +\n\nEach must succeed. Do NOT swallow\ - \ errors with `|| true` \u2014 a silent\nskip here reproduces the exact \"19 SDK failures\" that\ - \ runs 60-63,\n65-67 stalled on. Paste the last 5 lines of the kernel build's\noutput in your summary;\ - \ if the build fails, fix the actual failure\nbefore proceeding to npm test.\n\nThen implement the\ - \ work package: read ops/NEXT.md, AGENTS.md, and\nthe relevant parts of docs/RFC-0001-everything-is-a-relayflow.md.\n\ + \ errors with `|| true` \u2014 a silent\nskip here reproduces the \"19 SDK failures\" PR #63 explicitly\ + \ reported\nin its ops/NEEDS_HUMAN.md. Paste the last 5 lines of the kernel\nbuild's output in your\ + \ summary; if the build itself fails, report\nthe captured failure output and STOP without BUILD_DONE.\ + \ Kernel\nrepair is out of scope per ops/NEXT.md \u2014 do not attempt it here.\n\nThen implement\ + \ the work package: read ops/NEXT.md, AGENTS.md, and\nthe relevant parts of docs/RFC-0001-everything-is-a-relayflow.md.\n\ Implement exactly that work package \u2014 nothing more. Run the\ndefinition-of-done commands yourself\ \ and iterate until they pass.\nKeep files small and single-purpose. End with BUILD_DONE only when\n\ the definition of done passes locally; paste the passing output.\n" diff --git a/workflows/drive.yaml b/workflows/drive.yaml index 4cf18b9f..e2818be8 100644 --- a/workflows/drive.yaml +++ b/workflows/drive.yaml @@ -285,10 +285,11 @@ workflows: find testdata/preflight -type f -name '*-cli' -exec chmod +x {} + Each must succeed. Do NOT swallow errors with `|| true` — a silent - skip here reproduces the exact "19 SDK failures" that runs 60-63, - 65-67 stalled on. Paste the last 5 lines of the kernel build's - output in your summary; if the build fails, fix the actual failure - before proceeding to npm test. + skip here reproduces the "19 SDK failures" PR #63 explicitly reported + in its ops/NEEDS_HUMAN.md. Paste the last 5 lines of the kernel + build's output in your summary; if the build itself fails, report + the captured failure output and STOP without BUILD_DONE. Kernel + repair is out of scope per ops/NEXT.md — do not attempt it here. Then implement the work package: read ops/NEXT.md, AGENTS.md, and the relevant parts of docs/RFC-0001-everything-is-a-relayflow.md.