v3 workflow: intent, phases, review, submission, enforcement, burn-in

The v3 stack, previously an uncommitted working tree, plus this session's two
units and the burn-in instrument. This commit is the burn-in build identity:
coordinator and worker must both report this revision before a task is created.

Workflow (earlier sessions, uncommitted until now): human decision events and
reduction, source cursors and reconcile-before-launch, turn-boundary
reconciliation, internal/agentctx as the single renderer, ace-fca phases with
sealed artifacts, the trajectory gate, bounded grilling, independent review,
task pr enforcement, and human review reflection.

Capability restrictions at the agent boundary: an authz.Agent surface at
GatedWrite may ask and may not act. It also fixes two bugs the unit exposed --
gated surfaces could not reach the two endpoints written for them, and
RequestHumanDecision would block an unowned task while rejecting a question
from the session that did own it.

Turn-boundary reconcile-failure escalation: a streak of consecutive failures
asks the session to hand off, fenced on the lease epoch, with reconcile_failure
as a real handoff reason. The worker was dropping the coordinator's verdict on
the floor; it now acts on it.

Burn-in: herdr.WriteLaunchContext dumps the exact agentctx.Build result to
<worktree>/.orchestra/launch.md at every launch, local and federated. BURNIN.md
is the runbook. deploy/build.sh stamps both binaries from one commit.

go build, go vet and go test ./... pass, 20 packages.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-26 18:31:20 +04:00
parent 97a9c65302
commit 7f12c7fc37
78 changed files with 16417 additions and 352 deletions
+20
View File
@@ -36,6 +36,7 @@ func TestFederatedReachabilityDefersRemoteHerdrToWorkerHeartbeat(t *testing.T) {
func TestCoordinatorOwnsOnlyLocalHerdrInFederationMode(t *testing.T) {
local := registry.Herdr{ID: "homesrv-opencode", MachineID: "homesrv"}
localTmux := registry.Herdr{ID: "homesrv-claude", MachineID: "homesrv", Backend: "tmux", Harness: "claude"}
remote := registry.Herdr{ID: "workpc-opencode", MachineID: "workpc"}
if !coordinatorOwnsHerdr(local, "homesrv") {
t.Fatal("coordinator does not own its local herdr")
@@ -43,6 +44,9 @@ func TestCoordinatorOwnsOnlyLocalHerdrInFederationMode(t *testing.T) {
if coordinatorOwnsHerdr(remote, "homesrv") {
t.Fatal("coordinator claimed a worker-owned remote herdr")
}
if coordinatorOwnsHerdr(localTmux, "homesrv") {
t.Fatal("coordinator claimed a local worker-owned tmux backend")
}
if !coordinatorOwnsHerdr(remote, "") {
t.Fatal("single-machine mode should retain legacy local ownership")
}
@@ -69,3 +73,19 @@ func TestMultiMachineRegistryRequiresKnownLocalMachine(t *testing.T) {
t.Fatalf("known local machine rejected: %v", err)
}
}
func TestTmuxRegistryRequiresMachineIdentityEvenOnOneMachine(t *testing.T) {
r, err := registry.New(registry.Config{
Machines: []registry.Machine{{ID: "homesrv", Address: "homesrv:9145"}},
Herdrs: []registry.Herdr{{ID: "homesrv-claude", MachineID: "homesrv", Backend: "tmux", Harness: "claude"}},
})
if err != nil {
t.Fatal(err)
}
if err := validateLocalMachine(r, ""); err == nil {
t.Fatal("worker-owned tmux backend accepted without machine identity")
}
if err := validateLocalMachine(r, "homesrv"); err != nil {
t.Fatal(err)
}
}