Skip to content

Implement base-only trial workspaces - #102

Merged
Jordak merged 8 commits into
mainfrom
codex/issue-90-base-only-workspaces
Jun 7, 2026
Merged

Jordak merged 8 commits into
mainfrom
codex/issue-90-base-only-workspaces

Conversation

@Jordak

@Jordak Jordak commented Jun 6, 2026 •

Copy link
Copy Markdown
Owner

Previously, trial workspaces were normal git clones checked out at the task commit, which could leave upstream history, tags, and future commits visible in .git. ADR 0010 and #90 chose base-only workspaces so agent trials and reference verification do not expose hidden fixes through local history.

Changes

  • Materialize agent workspaces from a no-checkout private prep clone by reading pinned Git object data, staging the synthetic index directly, and creating a deterministic detached synthetic base commit with Git plumbing.
  • Avoid git archive, checkout smudge filters, LFS hydration, local commit hooks, template leakage, branch/tag/ref leakage, and ambient repo-context Git env in agent-facing workspace preparation.
  • Reject source tree entries that would materialize Git control paths before the fresh synthetic repo is initialized.
  • Capture diffs against the synthetic base ref and record workspace policy/base refs in run-surface evidence.
  • Convert commit reference artifacts to patches in a no-checkout private prep clone before applying them to base-only reference workspaces.
  • Add task repo/commit provenance and update reports, digests, docs, and tests.

Deferred Follow-Up

Validation

  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m py_compile agentlab/execution/workspace.py agentlab/execution/phases.py tests/test_workspace.py tests/test_reference.py tests/test_task_execution.py
  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m unittest tests.test_workspace tests.test_reference tests.test_task_execution
  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m unittest tests.test_workspace tests.test_reference tests.test_run_surface tests.test_task_execution tests.test_runner tests.test_codex_cli tests.test_claude_code
  • git diff --check
  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m agentlab task validate tasks/starter
  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m unittest discover
  • Review-loop verification pass: 2/2 reviewers reported No new findings. on head 67bdca6.

Readiness evidence: #90, ADR 0010 (docs/adr/0010-use-base-only-agent-workspaces.md)
Readiness verdict: Ready to Implement

Closes #90

@Jordak

Jordak commented Jun 7, 2026 •

Copy link
Copy Markdown
Owner Author

Agent Review

Scope: PR #102, e156eed5f723936dfd4bed309a099a1b961a330b..67bdca6c0ecf44f13fea9d8fd20b8e518d802572
Pass: modified review-loop, verification-first plus final fresh and verification passes
Review packet: consolidated in this comment and local Codex report
Reviewers: 4 initial verification/fresh reviewers, 2 focused final verification reviewers

Issue families:

  1. [IF1] Severity: P1 - Prep clone and workspace Git environment could inherit host Git config/context
    Found by: review-loop verification reviewers across earlier passes
    Evidence: agentlab/execution/commands.py, agentlab/tasks/environment.py, tests/test_workspace.py, tests/test_reference.py, tests/test_task_execution.py
    Issue family: base-only workspace prep and task commands must not inherit host repo context, global Git config, or injected Git config variables that can change clone, ref, or command behavior.
    Related occurrences or sweep: swept prep clone, reference verification, task setup/baseline/action/test env, Codex/Claude command paths, and focused regression tests.
    Why it matters: ambient Git config/env can reintroduce hidden remotes, checkout behavior, or non-synthetic repo context.
    Decision: fixed
    Autopilot classification: auto-fix
    Autopilot rationale: evidenced, in scope for Use base-only git workspaces for all agent trials #90, and closed by reusing the shared Git env isolation path without adding a new mode.
    Complexity posture: neutral
    Smallest closing move or lazy-human decision: tighten existing env helpers and add narrow regression coverage.
    Suggested fix or fix commit: 77ab11d, 4a70e68, 8c63ba3

  2. [IF2] Severity: P1 - Synthetic workspace could expose Git control surfaces from source tree paths
    Found by: P5-R2-F1, P5-R4-F2
    Evidence: agentlab/execution/workspace.py, tests/test_workspace.py
    Issue family: source tree materialization must not write .git control paths before the fresh synthetic repo is initialized.
    Related occurrences or sweep: checked workspace materialization path and added a plumbing-created .GIT/config regression test.
    Why it matters: a malicious or unusual source tree could preseed repo config/hooks/remotes and violate the fresh-base boundary.
    Decision: fixed
    Autopilot classification: auto-fix
    Autopilot rationale: repeated, in-scope, and closed with a small path guard.
    Complexity posture: neutral
    Smallest closing move or lazy-human decision: reject any case-folded .git path component.
    Suggested fix or fix commit: 67bdca6

  3. [IF3] Severity: P2 - Synthetic base still had branch/ref/reflog affordances
    Found by: P5-R2-F2, P5-R3-F1, P5-R4-F1
    Evidence: agentlab/execution/workspace.py, tests/test_workspace.py, tests/test_reference.py
    Issue family: agent-facing workspaces should expose one synthetic base commit through detached HEAD, with no local branch, remote, tag refs, or reflogs.
    Related occurrences or sweep: checked trial workspaces and reference verification workspaces; tests assert one HEAD commit, empty head/remote/tag refs, and absent .git/logs.
    Why it matters: branch/ref affordances undercut ADR 0010's no-branches/no-history invariant.
    Decision: fixed
    Autopilot classification: auto-fix
    Autopilot rationale: repeated, directly tied to ADR 0010, and fixed with Git plumbing already in use.
    Complexity posture: neutral
    Smallest closing move or lazy-human decision: set core.logAllRefUpdates=false and update detached HEAD with update-ref --no-deref.
    Suggested fix or fix commit: 67bdca6

  4. [IF4] Severity: P3 - Stale diff-base override kept a non-synthetic escape hatch
    Found by: P5-R4-F3
    Evidence: agentlab/execution/phases.py
    Issue family: task execution should always capture diffs against prepared.workspace_base_ref.
    Related occurrences or sweep: searched for diff_base_ref and removed the unused parameter.
    Why it matters: leaving an unused override invites future drift from the base-only invariant.
    Decision: fixed
    Autopilot classification: auto-fix
    Autopilot rationale: small deletion that reduces complexity.
    Complexity posture: reduced
    Smallest closing move or lazy-human decision: delete the parameter and always pass the synthetic base ref.
    Suggested fix or fix commit: 67bdca6

Declined issue families:

Resolved ask-user decisions:

  • None.

Unresolved ask-user blockers:

  • None.

Validation notes:

  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m py_compile agentlab/execution/workspace.py agentlab/execution/phases.py tests/test_workspace.py tests/test_reference.py tests/test_task_execution.py
  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m unittest tests.test_workspace tests.test_reference tests.test_task_execution - 23 tests OK
  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m unittest tests.test_workspace tests.test_reference tests.test_run_surface tests.test_task_execution tests.test_runner tests.test_codex_cli tests.test_claude_code - 54 tests OK
  • git diff --check
  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m agentlab task validate tasks/starter - 12 task files OK
  • PYTHONPYCACHEPREFIX=/tmp/agentlab-pycache python3 -m unittest discover - 236 tests OK
  • Final verification pass: P6-R1 and P6-R2 both reported No new findings.

@Jordak
Jordak marked this pull request as ready for review June 7, 2026 15:49
@Jordak
Jordak merged commit d12ba50 into main Jun 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Use base-only git workspaces for all agent trials

1 participant