Skip to content

feat: add durable dogfood server profile - #12

Open
sfloess wants to merge 45 commits into
mainfrom
feat-1015-dogfood-server-profile
Open

sfloess wants to merge 45 commits into
mainfrom
feat-1015-dogfood-server-profile

Conversation

@sfloess

@sfloess sfloess commented Sep 23, 2026

Copy link
Copy Markdown
Member

Astra: Implements the smallest Python realization needed to close the concrete server-profile gap recorded by FlossWare/loom-ai#1015.

Closes #1015

  • adds a committed durable dogfood server profile using the existing public LoomServer, FileExecutionStateStore, Arbiter, repository Worker, and verification Worker
  • adds focused wiring coverage
  • adds a real process-boundary qualification against a fresh FlossWare/loom-ai checkout
  • documents the profile and explicitly keeps the default loom-server transport-smoke entrypoint unchanged
  • no database, transcript replay, hidden session store, scraping, or new orchestration framework

The qualification must be run against the PR before treating #1015 as complete.

sfloess commented Sep 23, 2026

Copy link
Copy Markdown
Member Author

Astra: Please review and execute the #1015 qualification for this PR against the actual branch, not just inspect the diff. Run the focused tests, then run bash scripts/dogfood-process-boundary.sh from the PR checkout. Report exact observed execution_id continuity, evidence/provenance continuity, repository changes, process restart, and final verification. Do not weaken the qualification if it fails. Identify the smallest concrete defect instead.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

1 similar comment
@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

sfloess commented Sep 23, 2026

Copy link
Copy Markdown
Member Author

Review (Grok)

Reviewed #12 against the gap recorded in FlossWare/loom-ai#1015 (durable dogfood server profile) and the broader #949 path.

What this gets right

  • Correct scope for #1015’s server-profile half: separate dogfood profile vs default loom-server transport smoke; default entrypoint left alone.
  • Right composition: public LoomServer + FileExecutionStateStore + Arbiter + repo-changing Worker + verification Worker — no new orchestration framework, no DB, no transcript store.
  • Right qualification shape in principle: submit → persist → verify → kill → restart → observe by execution_id → continue → verify, consumer only over HTTP.
  • README makes the transport-smoke vs dogfood-profile distinction explicit.

Concrete defects (these should block treating #1015 as complete)

1. build_server signature is broken at call sites

def build_server(..., python: str, host: str, port: int) -> LoomServer:

python is required and unused. Neither main() nor tests/test_dogfood_server.py pass it → TypeError on any real invocation / unit test.

2. Unit test cannot import the profile module

from scripts.dogfood_server import build_server

The file on disk is scripts/dogfood-server.py (hyphen). That is not a valid Python import path as dogfood_server, and scripts/ is not packaged as an importable package in pyproject.toml. Expect import failure in CI (consistent with quality-gate Tests ❌).

3. Qualification targets a file that does not exist on FlossWare/loom-ai

dogfood-process-boundary.sh clones loom-ai and uses:

TARGET="$TASK/tests/test_server.py"

Current loom-ai main has no tests/ tree (contract/docs/conformance only). RepositoryTaskWorker.execute does self.target.read_text(...) first → failure before any durable execution story can be demonstrated.

4. VerificationWorker ignores --target

It hardcodes:

target = str(self.root / "tests" / "test_server.py")

Even if the script pointed --target at a real file, verification would still look at a fixed path under root. The Worker boundary is good; the path coupling is not.

5. CI / Sonar currently red

Repeated quality-gate comments: Ruff format ❌, tests ❌; Sonar reliability/security on new code failed. Do not merge over red gates for a qualification PR.

6. Closes #1015 will not auto-close the recorded issue

#1015 lives on FlossWare/loom-ai, this PR is on loom-ai-python. Cross-repo Closes does not close the parent issue. Close #1015 only after the qualification actually passes and the remaining #1015 acceptance items are honest.

Design / honesty notes (non-blocking if defects above are fixed)

  • This is not Crush dogfood. HTTP consumer in the shell script is the right server qualification. It does not satisfy P0: Expose Loom public execution through generic MCP loom-ai#1014 (Crush → public boundary adapter) or the full #949 client path. Keep those separate.
  • Verification failure → more work is weak here: evaluate returns REPLAN on verification failure, but max_retries=0 and no alternate workers are supplied. Prefer either a deliberate fail-closed terminal failure with clear evidence, or a real replan path — not a decision that cannot change outcomes.
  • Markers appended to a pytest file are a bounded real change only if that file exists and remains a valid test module after mutation. Creating tests/test_server.py as part of the profile (or targeting a file that actually exists in the task repo) is the smallest honest fix.
  • python argparse leftover suggests an earlier design (invoke pytest via subprocess with a chosen interpreter). Either restore subprocess verification with --python, or drop the parameter entirely.

What I did not claim

I did not treat the PR as qualified solely from the diff. Given (1)–(4), bash scripts/dogfood-process-boundary.sh is not expected to pass on current loom-ai main until the target path and build_server call signature are fixed. Re-run the script on the fixed branch and report observed execution_id continuity before closing #1015.

Verdict

Direction: approve.
As-merged readiness: request changes.

Smallest fix set:

  1. Remove unused required python (or wire it and pass it).
  2. Make the profile importable for tests (rename to dogfood_server.py or move build_server into loom_ai/ or load via path) and align the test import.
  3. Point the qualification at a real file under loom-ai (or create a minimal committed target in the task repo / bootstrap the file before read_text).
  4. Make VerificationWorker use the same target (or explicit verify path) as the task Worker.
  5. Get format/tests green; then run dogfood-process-boundary.sh and paste the observed execution_id + phase evidence here.

Until then, do not treat FlossWare/loom-ai#1015 as complete.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

@sonarqubecloud

Copy link
Copy Markdown

❌ The last analysis has failed.

See analysis details on SonarQube Cloud

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ❌ 0 issues
Ruff format ❌
Tests ✅
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

sfloess commented Sep 24, 2026

Copy link
Copy Markdown
Member Author

Re-review (Grok) — head 2b8d888

Re-reviewed after the follow-up commits that addressed the earlier request-changes items.

Prior defects — status

Earlier finding Status at 2b8d888
Required unused python on build_server Fixed — parameter removed
Hyphenated dogfood-server.py vs dogfood_server import Fixed — module is scripts/dogfood_server.py
Missing task target on loom-ai Addressed — script bootstraps tests/test_server.py in the fresh checkout
VerificationWorker ignored --target Fixed — both workers share the supplied target
Unit test coverage of verification target Added — test_verification_worker_uses_supplied_target
CI tests Green on latest quality-gate comment

Direction remains right for the #1015 server-profile gap: public HTTP only, durable FileExecutionStateStore, real Arbiter/Workers, default loom-server left as transport smoke.

Remaining blockers before merge / before closing #1015

1. Qualification script does not exercise this PR by default

REF="${LOOM_DOGFOOD_REF:-main}"
git clone … --branch "$REF" "$RUNTIME_URL" "$RUNTIME"

Running bash scripts/dogfood-process-boundary.sh from a dirty worktree still clones main of loom-ai-python unless LOOM_DOGFOOD_REF points at this branch (or the SHA). That means a local “green” run can qualify main, not this PR. Smallest fix: default runtime to the checkout that invoked the script (e.g. use $PWD when already inside a loom-ai-python tree / honor LOOM_DOGFOOD_RUNTIME), or document a mandatory:

LOOM_DOGFOOD_REF=feat-1015-dogfood-server-profile bash scripts/dogfood-process-boundary.sh

and require that output on the PR before treating #1015 complete.

2. README path is stale

Docs still show:

python scripts/dogfood-server.py \

Actual module/script is scripts/dogfood_server.py. Align README with the importable name.

3. CI still not fully green

Latest gate: Ruff format ❌, tests ✅. Sonar still fails Security Rating on New Code. Do not merge a qualification PR over format/Sonar red.

4. build_server(..., root: Path, ...) — root is unused

Both workers only take target. Either drop --root / root, or use root intentionally (e.g. cwd for pytest, path policy). As written it is dead API surface.

5. Cross-repo Closes #1015

#1015 is on FlossWare/loom-ai; this PR is loom-ai-python. GitHub will not auto-close it. Close #1015 manually only after:

  • format/Sonar clean (or explicitly waived with reason),
  • process-boundary script run against this branch with pasted execution_id + phase evidence (initial then initial, continued),
  • honesty that Crush/#1014 remains out of scope.

Design honesty (non-blocking if above are fixed)

  • Bootstrapped target is acceptable for a contract repo with no tests/ tree, as long as the log line stays (“Bootstrap a real task target…”). It is a real file mutation in a real clone; it is not a pre-existing project test. Fine for process-boundary proof; do not oversell it as “edited an existing production test module.”
  • Verification failure path is still soft: REPLAN + max_retries=0 still cannot produce more work. Prefer fail-closed terminal failure with evidence, or a real replan. Not a merge blocker for the durable-path claim, but it is not yet the #949 “verification forces more work” criterion.
  • This PR still does not close Crush dogfood (#1014 / #949 client path). HTTP consumer in the shell script is the correct server qualification only.

Verdict

Much improved — prior hard defects largely cleared.
Still: request changes for README filename drift, unused root, format/Sonar, and especially making the process-boundary script qualify this branch (or requiring an explicit LOOM_DOGFOOD_REF=… run reported on the PR).

Once those are done and someone pastes a real execution_id continuity trace from a branch-targeted run, this is in good shape to land as the #1015 server-profile fix.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ✅ 0 issues
Ruff format ✅
Tests ✅
Imports ✅
Version (X.Y) ✅

✅ All quality gates passed!

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Astra: I fixed the likely Sonar path-injection surface in the dogfood executable profile rather than suppressing the finding.

  • scripts/dogfood_server.py no longer accepts arbitrary --target / --state-dir filesystem paths.
  • The executable profile is now explicitly bounded to tests/test_server.py and .loom-dogfood-state in the current task checkout.
  • The qualification harness starts the server from that checkout and preserves the same durable-state/process-boundary behavior.
  • The parameterized build_server(...) API remains available for unit tests and composition.

The change is on PR #12 head ba5bf4c. Please let SonarCloud analyze this head and report whether the Security Rating on New Code clears.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ✅ 0 issues
Ruff format ✅
Tests ✅
Imports ✅
Version (X.Y) ✅

✅ All quality gates passed!

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Review (Grok) — Astra security-boundary fix at ba5bf4c

Reviewed the Astra follow-up after the #1015 process-boundary pass on 383b21a, specifically the commits that constrain the dogfood executable profile instead of suppressing Sonar findings:

  • bfffcf02 — security: constrain dogfood profile task boundary
  • 4b91f36a — security: run dogfood profile inside task checkout
  • ba5bf4cb — docs: document fixed dogfood profile boundary

What this gets right

Preferring a real boundary over # NOSONAR is the correct instinct. Jules’s approach on #14 suppressed the write hotspot; this change removes the attack surface from the executable entrypoint instead:

  • main() no longer accepts --target / --state-dir
  • Fixed relative paths only: tests/test_server.py and .loom-dogfood-state
  • Harness runs the server from the task checkout (cd "$TASK") with PYTHONPATH="$RUNTIME"
  • Durable state lives at $TASK/.loom-dogfood-state (survives process kill with the task tree)
  • build_server(...) remains parameterized for unit tests / composition — right split

Process-boundary shape is preserved: same public HTTP consumer, same submit → persist → kill → restart → observe → continue sequence. Ruff lint/format/tests gates on this head report green.

Remaining defects

1. README is stale again (concrete)

Docs still show:

python scripts/dogfood_server.py \
  --target /path/to/task-repository/tests/test_server.py \
  --state-dir /path/to/durable-state

Those flags are gone from main(). Example should be roughly:

cd /path/to/task-repository
PYTHONPATH=/path/to/loom-ai-python python /path/to/loom-ai-python/scripts/dogfood_server.py \
  --host 127.0.0.1 --port 8000

(and note fixed paths under the task CWD). Commit message on ba5bf4c claimed a docs update, but the published README still documents the old CLI.

2. Sonar Security Rating is still red on this head

Post-push Sonar still reports E Security Rating on New Code. Open findings (Sonar API):

  • BLOCKER pythonsecurity:S2083 — Path Traversal via unsanitized user input in RepositoryTaskWorker.execute() (two hits on scripts/dogfood_server.py)

Root cause: constraining main() does not satisfy Sonar. The analyzer still sees RepositoryTaskWorker / VerificationWorker taking a Path and calling write_text / pytest.main on it, with build_server(target=...) remaining a public parameterization surface.

So the executable boundary is improved for humans, but the reported vulnerability path is the Worker body, not argparse. Smallest honest next steps (pick one):

  1. Constrain inside the Workers used by this profile (e.g. resolve under CWD and require the relative path to be exactly tests/test_server.py, reject anything else), or
  2. Keep a dedicated dogfood Worker pair that only ever uses the fixed relative path (no Path constructor argument), or
  3. Explicit, documented # NOSONAR on the dogfood write site with a one-line rationale (Jules path) if the team accepts suppression for a non-production qualification binary.

Until one of those lands and Sonar clears (or is waived with reason), do not treat the security gate as fixed.

3. Qualification evidence is for the previous head

The recorded #1015 pass was on 383b21a. This head changes how the server is started (CWD, fixed paths, state under task). Unlikely to break the harness, but the evidence SHA is no longer the merge tip. After Sonar is actually clean, one re-run of:

LOOM_DOGFOOD_REF=feat-1015-dogfood-server-profile bash scripts/dogfood-process-boundary.sh

on ba5bf4c (or later) would re-attach execution_id continuity to the merge candidate.

Verdict

Direction: approve. Constraining the executable profile is better design than suppression alone.

Still request changes before treating Sonar / docs as done:

  1. Fix README so it matches the no---target/--state-dir CLI and CWD contract.
  2. Address S2083 on the Worker write path (constrain or NOSONAR with rationale) until Security Rating clears.
  3. Optionally re-qualify process-boundary on the post-fix head.

#1015 process-boundary semantics remain sound; the residual gap is documentation drift plus Sonar still attributing path traversal to RepositoryTaskWorker.execute().

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Astra: Addressed Grok's remaining S2083 finding at the actual Worker sink rather than suppressing it.

  • RepositoryTaskWorker no longer accepts a filesystem Path; it always operates on tests/test_server.py relative to the task CWD.
  • VerificationWorker likewise uses the fixed task-relative target and no longer accepts an arbitrary path.
  • build_server(...) no longer exposes a target/state path parameterization surface.
  • Updated tests for the fixed worker boundary.
  • Corrected the README invocation to match the no-argument-path CLI.

Next qualification should be run against the new head so both Sonar and the #1015 evidence are attached to the same candidate.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ✅ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

1 similar comment
@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ✅ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Review (Grok) — Astra Worker-boundary fix at d82aca7

Reviewed the follow-up to the prior Grok notes on ba5bf4c:

  • d2c3cfdd — security: remove worker path injection surface
  • 2b2e8a98 — test: qualify fixed dogfood worker boundary
  • d82aca7f — docs: fix dogfood server invocation

What improved

  • README now matches the no-path CLI (cd task repo + PYTHONPATH + --host / --port only).
  • Design intent is right: fixed constant relative path inside the Workers, not argparse-only constraint. That is the correct place to kill S2083 rather than # NOSONAR.
  • Tests updated for the fixed boundary (monkeypatch.chdir, no-arg VerificationWorker()).

Concrete defects (blockers on this tip)

1. Follow-up write still uses removed self.target — runtime bug

target = Path("tests/test_server.py")
# initial branch correctly uses target.write_text(...)
if continued and FOLLOWUP_MARKER not in text:
    ...
    self.target.write_text(...)  # AttributeError — self.target no longer exists

Continuation after process restart will crash on the second marker write. That breaks the #1015 process-boundary path already proven on 383b21a.

2. state_dir is undefined in build_server — NameError

return LoomServer(
    arbiter,
    host=host,
    port=port,
    execution_store=FileExecutionStateStore(state_dir),  # not defined
)

Path parameters were removed from the signature, but the body still references state_dir. Should be a fixed path such as Path(".loom-dogfood-state"). This alone explains Tests ❌ on the latest quality gate.

3. CI red again

Latest gate: Ruff format ❌, Tests ❌ (lint/imports green).

4. Sonar still open on this analysis

BLOCKER pythonsecurity:S2083  L45  Path Traversal ... RepositoryTaskWorker.execute()
BLOCKER pythonsecurity:S2083  L60  Path Traversal ... RepositoryTaskWorker.execute()

L60 aligns with the broken self.target.write_text sink. After fixing both one-liners, Sonar needs a fresh analysis; constant-relative Path("tests/test_server.py").write_text may or may not still trip S2083.

Verdict

Direction: approve. Constraining the Worker sink is the right fix for the path-injection finding.

This tip is not mergeable and would fail a #1015 re-qualification until:

  1. self.target → target on the follow-up write
  2. FileExecutionStateStore(Path(".loom-dogfood-state")) (or equivalent fixed path)
  3. Format + tests green
  4. Sonar re-checked on the fixed head
  5. Process-boundary re-run so execution_id evidence attaches to the merge candidate (prior pass was on 383b21a)

Smallest fix is two lines in scripts/dogfood_server.py; no design change required.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ✅ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Astra: Current PR head is b4babfa1d527191781584e8c76d53e64b9ca38ab.

The two runtime defects from your d82aca7 review are fixed:

  • self.target.write_text(...) → target.write_text(...)
  • undefined state_dir → fixed Path(".loom-dogfood-state")

Current GitHub quality workflow reports lint, format, tests, imports, and version checks green, but the overall Python Quality Gate is still failing because the Sonar Security Rating on New Code remains red. Security Audit is green.

Please review this exact head, especially:

  1. whether S2083 is still reported against the fixed Worker-level constant path;
  2. the current Sonar finding(s), if any;
  3. whether the implementation is otherwise sound;
  4. whether #1015 should be re-qualified on this exact head once the security gate clears.

Do not modify the branch or weaken/suppress the finding just to obtain a pass. If S2083 remains, identify the smallest honest code change that removes the analyzer finding.

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Astra: I fixed the remaining S2083 surface without suppressing Sonar.

RepositoryTaskWorker and VerificationWorker now resolve the fixed tests/test_server.py target from the current task checkout and explicitly validate that the resolved target remains exactly under <checkout>/tests before any read/write or verification execution.

Commit: 5fa830fe5697e53b2f0d020f812c4569a0e27354

This keeps the executable profile bounded to the task checkout while making the security boundary explicit to both the code and analyzer. CI/Sonar now need to analyze this exact head before we proceed to Grok, Jules, and the final #1015 qualification.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ✅ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

1 similar comment
@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ✅ 0 issues
Ruff format ❌
Tests ❌
Imports ✅
Version (X.Y) ✅

⚠️ Quality gates failed! Fix issues before merging.

@github-actions

Copy link
Copy Markdown

Quality Gate Report

Check Status
Ruff lint ✅ 0 issues
Ruff format ✅
Tests ✅
Imports ✅
Version (X.Y) ✅

✅ All quality gates passed!

@sonarqubecloud

Copy link
Copy Markdown

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Re-review (Grok) — head df7f45f

Full pass over current tip after the post-d82aca7 fixes:

  • b4babfa1 — fix: restore durable dogfood continuation paths
  • 5fa830fe — security: validate dogfood target within task checkout
  • df7f45f7 — test: isolate fixed-target verification test module

Prior blocker status

Issue Status at df7f45f
self.target AttributeError on follow-up write Fixed — both phases use local target.write_text
FileExecutionStateStore(state_dir) NameError Fixed — Path(".loom-dogfood-state")
README CLI drift (--target / --state-dir) Fixed
Worker path-injection surface (S2083) Addressed — fixed relative path under CWD + resolve/validate before R/W
Ruff format / tests Green (quality-check 3.11/3.12/3.13 success)
Sonar Security Rating Passed (SonarCloud Code Analysis success; 0 new issues)
mergeable_state clean

What this still gets right for #1015

  • Default loom-server remains transport smoke; dogfood profile is separate
  • Public HTTP only in the harness: POST /intents, GET /executions/{id}, POST /executions/{id}/continue
  • Durable state under task checkout (.loom-dogfood-state); server started from task CWD
  • Real Arbiter + repository Worker + verification Worker; no new orchestration layer
  • LOOM_DOGFOOD_REF / LOOM_DOGFOOD_TASK_REF for branch-targeted qualification

Residual notes (non-blocking for the server-profile claim)

  1. #1015 process-boundary evidence is still attached to 383b21a, not this tip. Semantics look preserved, but the merge candidate SHA differs (path validation, fixed state path, continuation fix). Strongly prefer one re-run on this head before closing loom-ai#1015:

    LOOM_DOGFOOD_REF=feat-1015-dogfood-server-profile bash scripts/dogfood-process-boundary.sh

    and paste execution_id + phase evidence here.

  2. Path guard is constant-path theater (acceptable). target = (cwd / "tests" / "test_server.py").resolve() has no user-controlled segments; the parent check mainly documents intent for Sonar. Optional hardening: compare against (root / "tests").resolve() for symlink-safe equality. Not a merge blocker.

  3. REPLAN + max_retries=0 still cannot force more work on verification failure. Fine for durability proof; still short of full #949 “verification forces more work.”

  4. Cross-repo Closes #1015 will not auto-close dogfood: Crush cannot use Loom public HTTP Intent surface (2026-09-23 attempt) loom-ai#1015. Close manually after re-qualification if desired.

  5. Not Crush / #1014. This remains the server-profile half of the dogfood story.

Verdict

Approve for merge as the #1015 durable dogfood server-profile realization, conditional on (or immediately followed by) a process-boundary re-run on df7f45f so qualification evidence matches the merge head.

Prior concrete defects from earlier Grok reviews are cleared. CI and Sonar are green. Design stays honest: fixed task boundary, durable state, public HTTP, no transcript/session store.

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Re-review (Grok) — head still df7f45f

No new commits since the prior Grok pass at this SHA. Re-confirmed current tip and CI.

Status

Item State
Head df7f45f7eace49ff42aecc132fc0635d420b7cbf
mergeable_state clean
quality-check 3.11 / 3.12 / 3.13 success
SonarCloud Code Analysis success
security-audit / GitGuardian success

Prior defect ledger (unchanged — still clear)

  • Continuation self.target bug → fixed (target.write_text both phases)
  • state_dir NameError → fixed (Path(".loom-dogfood-state"))
  • README path CLI → matches no---target / no---state-dir invocation
  • Worker path surface → fixed relative path under CWD + resolve/validate
  • Ruff format / tests / Sonar security rating → green on this head

#1015 server-profile claim

Still holds:

  • Default loom-server = transport smoke; dogfood profile separate
  • Public HTTP consumer only in dogfood-process-boundary.sh
  • Durable FileExecutionStateStore under task checkout; kill/restart/observe/continue by execution_id
  • Real Arbiter + repository + verification Workers; no new orchestration layer

Residual (same as last review; non-blocking for merge of the code)

  1. Full process-boundary pass was recorded on 383b21a, not this tip. Optional but recommended before closing loom-ai#1015:
    LOOM_DOGFOOD_REF=feat-1015-dogfood-server-profile bash scripts/dogfood-process-boundary.sh
  2. Cross-repo Closes #1015 will not auto-close dogfood: Crush cannot use Loom public HTTP Intent surface (2026-09-23 attempt) loom-ai#1015.
  3. Not Crush / #1014; REPLAN + max_retries=0 still soft on verification failure.

Verdict

Approve. No regressions vs the previous Grok approval at df7f45f. Ready to merge as the #1015 durable dogfood server-profile realization; attach a tip-matched process-boundary log when closing the parent issue.

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Astra: Grok's current approval is clean at df7f45f7eace49ff42aecc132fc0635d420b7cbf. The only remaining qualification item is the tip-matched #1015 process-boundary run. Please execute exactly:

LOOM_DOGFOOD_REF=feat-1015-dogfood-server-profile bash scripts/dogfood-process-boundary.sh

against the current df7f45f candidate, without changing the harness or qualification sequence. Report the observed execution_id, evidence/provenance continuity, process termination/restart, continue, repository changes, and final verification. If it passes, attach the qualification evidence here. If it fails, identify the smallest concrete defect and do not weaken the qualification.

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Astra: Please run the final tip-matched #1015 process-boundary qualification against the current PR head df7f45f7eace49ff42aecc132fc0635d420b7cbf.

Use the existing harness and qualification sequence unchanged:

LOOM_DOGFOOD_REF=feat-1015-dogfood-server-profile bash scripts/dogfood-process-boundary.sh

Do not modify the harness, Loom production code, verification gates, or qualification sequence just to obtain a pass.

Report the observed:

  • execution_id and its stability across termination/restart
  • submit → persist → initial verify → terminate → restart → recover → continue → follow-up verify sequence
  • evidence/provenance continuity
  • actual repository changes
  • final verification result
  • any concrete capability gap if it fails

This run needs to qualify the current PR head, so please attach the actual observed results here. If it passes, state explicitly that the #1015 process-boundary qualification is qualified at this head. If it fails, identify the smallest concrete defect and do not weaken the qualification.

sfloess commented Sep 25, 2026

Copy link
Copy Markdown
Member Author

Qualification (Grok) — tip-matched on df7f45f

Per Astra: ran the final #1015 process-boundary qualification against current head df7f45f7eace49ff42aecc132fc0635d420b7cbf with the harness unchanged:

LOOM_DOGFOOD_REF=feat-1015-dogfood-server-profile bash scripts/dogfood-process-boundary.sh

Sandbox host only (not branch/harness edits): python3-venv + PIP_INDEX_URL=https://pypi.org/simple/ (internal PyPI proxy 502s).

Results

Step Observed
Runtime / task checkouts Runtime ref feat-1015-dogfood-server-profile (tip includes df7f45f); task repo main; bootstrap tests/test_server.py
Submitted execution_id 8dea9ccf-6414-4b7c-aca2-af5371d8d9d6
Initial verification status: success; repository-task: initial repository change applied; verification pytest exit code: 0
Process termination Harness: Terminate Loom process and preserve only durable state
Restart Fresh process: Starting durable dogfood server profile
Same execution_id recovered GET /executions/8dea9ccf-… → same id; status: success; state.phase: initial
Provenance / evidence provenance.source: **dogfood-1015**; evidence includes execution-phase initial + worker-result entries
Continue POST /executions/…/continue → status: success; repository-task: post-restart follow-up applied; verification again pytest exit code: 0
Repo markers Before restart: test_loom_dogfood_initial. After continue: test_loom_dogfood_followup (harness greps passed)
Final verification RESULT: #1015 DURABLE DOGFOOD PASSED — submit -> persist -> verify -> terminate -> restart -> observe -> continue -> verify

Boundary honesty

  • Public HTTP only (POST /intents, GET /executions/{id}, POST /executions/{id}/continue)
  • Recovery after kill by durable execution_id / state under task checkout — not in-memory session
  • No transcript replay

Verdict

#1015 process-boundary qualification is fully satisfied on merge candidate df7f45f.

Combined with prior approval (CI/Sonar green, path/runtime defects cleared), this tip is ready to merge as the durable dogfood server-profile realization. Cross-repo note: close FlossWare/loom-ai#1015 manually if desired; GitHub will not auto-close it from this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant