Skip to content

[Safety] Exact-base worktree creation so every subagent shares a verified identity #126

Description

@rmems

Note

Historical GitHub issue. This issue is closed and retained for provenance. Its original body may describe an older writ/worktrees-hives architecture; do not treat retired Python/lab, Research-Hive, Graph-MVP, hook-enforcement, managed-worktree, babysit, or blanket local-merge restrictions below as current requirements.
Current product direction: https://linear.app/rpd-34/issue/RM-116/epic-writ-parallel-subagent-collaboration-ownership-and-conflict
Linear is the required task tracker; GitHub keeps source/PR/review/check history.

Important

Product goal (2026-09-05): worktrees-hives exists so worktree subagents can coordinate on one Git repository. A manager assigns isolated worktrees; workers share a hard wh-core safety/identity boundary (exact base, no ambient HEAD, no auto-merge). Prefer work that strengthens that coordination loop over analyzer theater or frozen research-hive expansion.

Important

Active stabilization work. Finish through corrected PR #131 after #129 and #133. Keep this change inside the minimal Rust safety kernel.

Goal

A worker branch/worktree must be created from an explicit, verified commit rather than ambient controller HEAD, a stale checkout, or an existing branch with ambiguous identity.

Required contract

  • Resolve the requested start point to one canonical commit before mutation.
  • Create or validate the worker branch and worktree against that exact commit.
  • Return the canonical start commit, resulting worker HEAD, branch identity, path, and registration evidence.
  • Fail closed on an existing or mismatched branch; never silently adopt it.
  • Preserve structured postcondition/residual data across the Rust/Python bridge.
  • Treat postcondition identity failures as typed operational failures rather than generic policy prose.
  • Compare full symbolic refs, not ambiguous shortened branch names.
  • Normalize and validate full commit IDs consistently across Rust and Python.

Boundary compatibility — absorbed from #135

Adding a required --start-point changes the published machine request grammar. PR #131 must not label that change as compatible schema v1.

Use the smallest safe pre-1.0 migration:

  • explicitly version the request boundary, or
  • return a deterministic machine-readable upgrade/incompatibility error for the legacy request shape.

Do not restore ambient-HEAD behavior for compatibility. Once this acceptance is implemented, close #135 as absorbed.

Out of scope for this PR

Those paths must continue to fail closed.

Acceptance criteria

  • Dirty or stale controller checkout cannot change the created worker base.
  • Existing branch mismatch fails before worktree adoption.
  • Canonical start and worker HEAD identities are returned and verified.
  • Full symbolic-ref comparison handles tag/branch-name collisions.
  • Typed residual evidence survives the Python bridge.
  • Request grammar and errors have an honest machine-readable boundary version.
  • Current submitted commits satisfy attribution checks; synthetic review commits are ignored.
  • Rust and Python native gates pass.

Relationships

Planning synthesis: OpenAI Codex, 2026-08-31.

Activity

  1. self-assigned this
    on Aug 30, 2026
  2. linear-code commented on Aug 30, 2026

    @linear-code
    Contributor
  3. moved this from Backlog to In progress in Autonomous Software Engineeringon Aug 30, 2026
  4. moved this from In progress to In review in Autonomous Software Engineeringon Aug 30, 2026
  5. 2 remaining items

  6. changed the title [-][Safety] Require an explicit exact base for wh worktree creation[/-] [+][Safety] Exact-base worktree creation so every subagent shares a verified identity[/+] on Sep 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions