🤖 feat: opt new user-created workspaces in to unrelated messaging by default - #4440
Conversation
This comment has been minimized.
This comment has been minimized.
|
@codex review |
|
@codex security review |
There was a problem hiding this comment.
🛡️ Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: 92e8be31c6
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
|
@codex review |
|
@codex security review |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0ae0703f92
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
@codex security review |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6a103c800f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Pausing this PR for an owner decision. It is not ready, and it will not be merged in its current state. Why: the review loop is not converging. The review budget is used up (three Codex code+security pairs = six reviews). Each fix to when the default consent becomes visible has opened another window where a freshly created workspace is discoverable before its creator finishes setting it up:
Proposed scope reduction (needs owner acceptance, because it narrows "all new workspaces"):
The three round-3 threads stay open until that decision is made. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9836ac075e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: df1bf424e1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 60a984c0b0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7b88b06780
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Halting this PR without merging. The review budget is used up and the review loop is not converging. State at
Open defects introduced by this PR
Proposed next step |
|
Correction to the halt record: CI on |
…erred checkouts after sanitization; restore post-write re-read
|
Resuming with a reduced scope, approved by the owner ("take a safer/progressive path"). Scope now: default consent for workspaces a user creates (new, scratch, multi-project, fork). Delegated What changed in the design
Review budget: the original six rounds are used up. I am declaring a bounded extension of 2 rounds for this re-scoped diff: one fix round (blockers only) and one verification round. If the second round finds any new blocker, I stop without merging. |
|
@codex review |
|
@codex security review |
|
Codex Review: Didn't find any major issues. Another round soon, please! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
Hiding the Codex review summary: Codex approved head |
…-default UI test A second manual parent send raced the first child's report wake-up turn after #4440/#4449 and was intermittently never dispatched (7/10 local runs), which dequeued the PR. One parent step now reawakens both. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
Summary
Root workspaces that a user creates (new, scratch, multi-project, fork) are now opted in to unrelated (cross-task-tree) messaging by default, so agents in other task trees can reach them with
task_send_messagewithout a manual toggle. Existing workspaces are unchanged, sub-agents stay off, and the per-workspace toggle still turns it off permanently. Delegatedtask(kind: "workspace")targets follow in #4453.Background
Cross-tree messaging requires recipient consent (
unrelatedWorkspaceConsent). It was off by default, and the refusal is reported asnot_foundto hide the target's existence, so new workspaces looked missing to other agents.This PR is delivered progressively. Granting consent to delegated targets at creation opened a new timing window with every fix (see the halt comments below), so that part moved to its own designed follow-up (#4453).
Implementation
mintUnrelatedWorkspaceConsent()mints the generation and asserts that it passes the fail-closed reader. The existing toggle uses the same helper.task_list(scope:"instance")and admission:createScratch()/createMultiProject(): no setup steps; written atomically with the entry.create()with an immediate checkout: after registration-time plugin-override sanitization, before announcing.create()with a deferred checkout: aftermaterializeDeferredCheckouthas populated and sanitized the checkout, before the init hook. It does not rely onwaitForInit, which a second backend sharing the root does not observe. An explicit toggle made between the announcement and the grant cancels it. Removal, a failed checkout or a failed sanitization never grant.fork(): last, after sanitization, goal inheritance and the pending branch-summary marker. It gets its own generation, never the source's.WorkspaceTurnManagerpassesskipDefaultUnrelatedWorkspaceConsent(🤖 feat: opt delegated task(kind:workspace) targets in to unrelated messaging by default #4453).grantCreationUnrelatedWorkspaceConsentre-reads config after its write and reports only the persisted value.Config.saveConfigswallows write failures (🤖 fix: config writes swallow save failures while the in-process snapshot keeps the edit #4444), and editConfig's transform runs on an uncached read, so a re-read does detect them.task_send_messagedescription andtask_idparameter,task_listinstance-scope description, schema description. Generated docs are refreshed.Validation
New and updated tests. Each fails on the previous behavior or under a targeted mutation, and passes now:
create(): persists a valid generation, with none while registration sanitization runs; withskipDefaultUnrelatedWorkspaceConsent, nothing is persisted, announced or pending.materializeDeferredCheckouthas no consent during sanitization, grants before the init hook and publishes; failed sanitization and failed checkout never grant.createWorkspaceTurncreates delegated targets with the skip flag.Local gates ran with the repo-pinned Bun 1.3.5 (the PATH default here is 1.2.15, which produced unrelated local failures).
Risks
Review history
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high• Cost:$34.04