fix(fork): route the stopship scout through tool_search and grep_files - #61
Conversation
The read-only scout brief commanded a `File` call with `action` `search_content`, but `File` is a hidden replay-only alias (`model_visible=false`): it never reaches a model-visible catalog, and the child step loop fails any call outside the child's policy-filtered catalog outright. The release-acceptance explore gate's first step therefore could not succeed; dispatch-by-alias only worked below the catalog gate (replay tests calling `registry.resolve` directly). Route the scout through the live surface instead: response 1 activates the deferred `grep_files` with one `tool_search` call, response 2 runs the same alternation search through `grep_files` (path/include/pattern/max_results/context_lines), and response 3 returns the verdict. The step and token caps are unchanged; the evidence turn grows one small activation response. Guard both halves so neither side silently drifts again: one forkguard test pins the scout surface to an active `tool_search` plus a deferred, searchable `grep_files` with no `File`, and another pins the fixture definition to catalog-visible tool names only. Signed-off-by: asto <asto18089@126.com>
|
Thanks @asto18089 for taking the time to contribute. This repository is observing a maintainer-managed PR intake gate in dry-run mode, so this pull request is staying open. This note helps maintainers prepare the allowlist before any enforcement is considered. Please read |
The review of Hmbown#61 caught one real break and three guard-fidelity gaps: - js_authoring.rs still pinned the retired `File`/`search_content` scout wording, so the workspace suite and CI went red on this branch. Pin the new three-response contract instead. - The scout surface guard built its registry with no explicit scope, while the fixture scout really runs under the read-only lowering `["File"]`. Build it with that scope so the alias-family intersection that keeps grep_files discoverable is guarded too. - The brief guard only denied backticked `File` and bare `search_content`; deny the hidden replay aliases as whole words so an unbackticked citation cannot slip past. - Add the behavioral counterpart: one tool_search call must make grep_files dispatchable through execute_from_surface, and a File call must keep failing the catalog gate. Signed-off-by: asto <asto18089@126.com>
|
Full four-track review of the original head (4a669ce) + fix-up commit Root cause and fix: confirmed end to end. Fix-ups in
Also corrected the PR description: this PR shares Verification: |
JensenChen28
left a comment
There was a problem hiding this comment.
已审查当前 head 对目标分支的实际差异,未发现需要阻塞合入的问题;提交前重新确认 required checks 通过。核对了 stopship scout 的 tool_search → grep_files 激活路径及相关回归。本轮以静态审查和远端门禁为依据,未在本机运行完整 Rust workspace 或所有平台测试。
Resolve the tests.rs anchor collision: keep the stopship scout surface, brief, and activation-path guards from this branch and the skill-catalog and handle_read hint guards that landed with Hmbown#56. Signed-off-by: asto18089 <asto18089@126.com>
Problem
workflows/stopship.workflow.js(the version-neutral release-acceptance fixture) briefs its read-only explore scout with aFilecall usingaction: "search_content". The follow-up review of #56 found this is not merely stylistic:Fileis a hidden replay-only alias (model_visible=false), so it never reaches a model-visible catalog, and the live child step loop dispatches throughexecute_from_surface, which fails any name outside the child's policy-filtered catalog outright. The explore gate's first step cannot succeed today — dispatch-by-alias only worked below the catalog gate (replay tests callingregistry.resolvedirectly).Fix
Route the scout through the live read-only surface:
tool_searchcall (query: "grep_files") to activate the deferred content-search tool.grep_filescall with the same evidence contract as before (path., the exact five-fileincludelist, the same high-signal alternationpattern,max_results80,context_lines2).Step and token caps are unchanged (
max_steps6, 480s, 96k); the evidence turn grows one small activation response.grep_filesis the canonical name for the retiredsearch_contentaction (already mapped incanonical_action.rs), and the scout surface provably carries it: it passes the read-only evidence filter viais_read_only().Regression guards
forkguard_scout_surface_keeps_tool_search_grep_files_activation_pathpins the scout surface to a first-turn-activetool_searchplus a deferred, searchablegrep_fileswith noFile. It builds the registry with the scope the fixture scout really runs under (the read-only lowering["File"]), so the alias-family intersection that keepsgrep_filesdiscoverable under that legacy rule is guarded too — the exact reshape that silently broke the fixture is now a red test.forkguard_workflow_briefs_name_catalog_visible_toolspins the fixture definition (not the maintainer comment) to catalog-visible tool names, denying hidden replay aliases (File,Bash,TodoWrite,work_update,read_file,write_file,edit_file) and the retiredsearch_contentas whole words — an unbackticked citation can no longer slip past. Mutation-checked: reverting the brief wording turns the test red.forkguard_scout_activation_makes_grep_files_dispatchableis the behavioral counterpart: on the live scout surface, onetool_searchcall must makegrep_filesdispatchable throughexecute_from_surface, and aFilecall must keep failing the catalog gate. Composition can drift from behavior; this cannot.stopship_acceptance_fixture_is_read_only_and_gate_complete(workflow crate) now pins the three-response activation contract instead of the retired wording.Verification
cargo test -p codewhale-workflow --lib stopship_acceptance_fixture_is_read_only_and_gate_completeandcargo test -p codewhale-tui --lib(new guards, the envelope ceiling test, andstopship_acceptance_fixture_emits_role_gate_and_terminal_receipts, which compiles this fixture) all pass;cargo fmt --checkand clippy (CI flags) clean on the touched files.Base
One commit on top of the current r1 maintenance head
ae7e3fb36. Sharescrates/tui/src/tools/subagent/tests.rswith #56 (both PRs append at end of file), so whichever merges second needs a trivial keep-both rebase; no semantic coupling. Closes the leftover disclosed in #56 and Pinvou/pinvou-agent#490.No-Issue: fork-side fixture repair; the disclosure in #56/Hmbown#490 tracks it.