4e5e4e56ea
Scope creep — an implementer writing files it never declared — is the dominant local-model failure that compiler/tests don't catch. A stage can now declare a `writes` manifest (workspace-relative globs); a FILE_WRITE that resolves inside the workspace but outside the declared set is raised as PATH_OUTSIDE_MANIFEST → BLOCK, so the model gets the violation as tool feedback and retries within scope (the §2 bounded-retry signal). Implemented as a plane-2 rule beside PathContainmentRule (same effect-based dispatch on FILE_WRITE, same symlink-safe WorldProbe resolution, same recorded observations so replay reads them back — invariant #9). An empty manifest is unrestricted; out-of-workspace targets stay PathContainmentRule's concern, so the two rules don't double-flag. - StageConfig.writeManifest + TomlWorkflowLoader `writes` parsing - ToolCallAssessmentInput.writeManifest, threaded from the active stage via SessionOrchestrator.runPlane2Assessment - new ManifestContainmentRule, registered in the server assessor - shared candidatePathStrings extracted so both path rules judge the same target set - role_pipeline.toml documents the option on the implementer stage The dedicated ManifestViolationEvent the spec names is not added: the violation is already recorded replayably in ToolCallAssessedEvent (issue + observations + BLOCK) and surfaced in the TUI rationale band. A first-class event is worth adding only once reconciliation consumes it.
129 lines
4.0 KiB
TOML
129 lines
4.0 KiB
TOML
# Role pipeline: analyst → architect → planner → implementer ⇄ reviewer
|
|
#
|
|
# Each stage produces a typed artifact that the next stage `needs`, so work flows forward
|
|
# without a human relaying notes. The decision journal (pinned into every stage's context)
|
|
# carries steering/approvals/verdicts across the whole run, so the reviewer sees the same
|
|
# ground truth as the planner.
|
|
#
|
|
# The implementer⇄reviewer loop is gated by review_report.verdict:
|
|
# approved → done
|
|
# changes_requested → back to implementer (capped by implementer.max_retries, then escalates)
|
|
#
|
|
# Requires these artifact kinds in ~/.config/correx/config.toml (schemas under docs/schemas/):
|
|
# [[artifacts]]
|
|
# id = "analysis"; schema_path = "schemas/analysis.json"; llm_emitted = true
|
|
# [[artifacts]]
|
|
# id = "design"; schema_path = "schemas/design.json"; llm_emitted = true
|
|
# [[artifacts]]
|
|
# id = "impl_plan"; schema_path = "schemas/impl_plan.json"; llm_emitted = true
|
|
# [[artifacts]]
|
|
# id = "review_report"; schema_path = "schemas/review_report.json"; llm_emitted = true
|
|
#
|
|
# Prompt files (prompts/*.md, relative to this workflow) must exist for a real run.
|
|
|
|
id = "role_pipeline"
|
|
start = "analyst"
|
|
|
|
# 1. Understand the request and the relevant code. Read-only.
|
|
[[stages]]
|
|
id = "analyst"
|
|
prompt = "prompts/analyst.md"
|
|
produces = [{ name = "analysis", kind = "analysis" }]
|
|
allowed_tools = ["file_read", "ShellTool"]
|
|
token_budget = 16384
|
|
max_retries = 2
|
|
|
|
# 2. Decide the approach and component boundaries.
|
|
[[stages]]
|
|
id = "architect"
|
|
prompt = "prompts/architect.md"
|
|
needs = ["analysis"]
|
|
produces = [{ name = "design", kind = "design" }]
|
|
token_budget = 16384
|
|
max_retries = 2
|
|
|
|
# 3. Break the design into ordered, verifiable steps.
|
|
[[stages]]
|
|
id = "planner"
|
|
prompt = "prompts/planner.md"
|
|
needs = ["design"]
|
|
produces = [{ name = "impl_plan", kind = "impl_plan" }]
|
|
token_budget = 16384
|
|
max_retries = 2
|
|
|
|
# 4. Implement the plan. Writes files (jailed to the workspace). The loop target —
|
|
# max_retries here caps how many review→implement refinement rounds are allowed.
|
|
# Optional: a `writes` manifest (workspace-relative globs) hard-bounds where this
|
|
# stage may write — a FILE_WRITE outside it is blocked as scope creep. Left open
|
|
# here because the targets are task-specific; a task-scoped workflow would set e.g.
|
|
# writes = ["core/sessions/**", "testing/sessions/**"]
|
|
[[stages]]
|
|
id = "implementer"
|
|
prompt = "prompts/implementer.md"
|
|
needs = ["impl_plan"]
|
|
produces = [{ name = "patch", kind = "file_written" }]
|
|
allowed_tools = ["file_read", "file_write", "file_edit", "ShellTool"]
|
|
token_budget = 32768
|
|
max_retries = 3
|
|
|
|
# 5. Review the patch against the plan; emit a structured verdict.
|
|
[[stages]]
|
|
id = "reviewer"
|
|
prompt = "prompts/reviewer.md"
|
|
needs = ["patch", "impl_plan"]
|
|
produces = [{ name = "review_report", kind = "review_report" }]
|
|
token_budget = 32768
|
|
max_retries = 2
|
|
|
|
# --- forward edges ---
|
|
|
|
[[transitions]]
|
|
id = "analyst-to-architect"
|
|
from = "analyst"
|
|
to = "architect"
|
|
condition_type = "artifact_validated"
|
|
condition_artifact_id = "analysis"
|
|
|
|
[[transitions]]
|
|
id = "architect-to-planner"
|
|
from = "architect"
|
|
to = "planner"
|
|
condition_type = "artifact_validated"
|
|
condition_artifact_id = "design"
|
|
|
|
[[transitions]]
|
|
id = "planner-to-implementer"
|
|
from = "planner"
|
|
to = "implementer"
|
|
condition_type = "artifact_validated"
|
|
condition_artifact_id = "impl_plan"
|
|
|
|
[[transitions]]
|
|
id = "implementer-to-reviewer"
|
|
from = "implementer"
|
|
to = "reviewer"
|
|
condition_type = "artifact_validated"
|
|
condition_artifact_id = "patch"
|
|
|
|
# --- verdict-gated loop exit / re-entry ---
|
|
|
|
[[transitions]]
|
|
id = "review-approved"
|
|
from = "reviewer"
|
|
to = "done"
|
|
condition_type = "artifact_field_equals"
|
|
condition_artifact_id = "review_report"
|
|
condition_field = "verdict"
|
|
condition_value = "approved"
|
|
condition_operator = "eq"
|
|
|
|
[[transitions]]
|
|
id = "review-changes-requested"
|
|
from = "reviewer"
|
|
to = "implementer"
|
|
condition_type = "artifact_field_equals"
|
|
condition_artifact_id = "review_report"
|
|
condition_field = "verdict"
|
|
condition_value = "approved"
|
|
condition_operator = "neq"
|