Skip to content

Let every Worker fix its own check failures in the same session - #21

Merged
christopherjnelson merged 1 commit into
mainfrom
feat/worker-check-gate
Sep 29, 2026
Merged

christopherjnelson merged 1 commit into
mainfrom
feat/worker-check-gate

Conversation

@christopherjnelson

Copy link
Copy Markdown
Member

Before: only Codex had a shell, and even Codex couldn't run the repository's checks, because its workspace has no installed dependencies and no network. Every Worker learned that lint, typecheck or tests failed only after its turn ended. Each failure then cost a new Worker attempt plus an Orchestrator turn, with a fresh context and a 2KB excerpt of the output.

After: when any Worker (Claude Code, Codex or Antigravity) finishes a turn, the bridge pauses it and Foreman runs the configured checks on its workspace. If a check the Worker could have caused fails, the same CLI session is resumed with the command and a head-and-tail output excerpt, so the Worker fixes it with full context, inside the same attempt. No Worker gets a shell, and Foreman's validation after the turn is still the authoritative result.

How: the bridge accepts metadata.foreman_worker_gate: {max_rounds} on Worker requests. After each completed turn it keeps the task in_progress and emits a worker_gate activity event. It serves a complete snapshot while paused, then waits for POST .../responses/{id}/worker-gate. On a failed verdict it resumes the native session: --resume for Claude (transcript dirs bound per workspace), exec resume without --ephemeral for Codex, and --conversation for Antigravity. Foreman sees the activity event during the stream and reuses its existing checks on the paused workspace: snapshot verification, the format step and sandboxed validation. It leaves out checks already red on the base, treats a scope violation as a failure, and posts the verdict. Any infrastructure problem answers skipped, which ends the turn as it is. FOREMAN_WORKER_CHECK_ROUNDS (default 2, max 3, 0 disables) bounds the rounds, and the gate is off when automatic validation correction is off for the run. Each round is logged as a worker.check_round event and in metadata.worker_gate. The Codex capability text no longer implies it can run the repo's tools.

Tests: 4 new unit tests, and 5 new bridge tests with fake CLIs in bubblewrap. The bridge tests cover Claude and Antigravity resuming their kept sessions with the feedback, the passed, timeout and cancel paths, and request validation. They also include an end-to-end run where Foreman fails a real check, Codex resumes its session, fixes the check and passes validation, all in one Worker attempt. Typecheck, 644 unit tests, 75 bridge tests and the build pass locally.

Not yet verified against the real CLIs: each harness's native resume through the bridge sandbox (fake CLIs stand in here).

🤖 Generated with Claude Code

https://claude.ai/code/session_01QNxsX5P27Z5iKd2TVtB8Ej


Generated by Claude Code

The bridge now pauses a completed Worker turn, Foreman runs the configured
checks on the paused workspace, and a failed verdict resumes the same CLI
session with the failures (claude --resume, codex exec resume, agy
--conversation). No Worker gets a shell, and Foreman's validation after the
turn stays the authoritative result. FOREMAN_WORKER_CHECK_ROUNDS (default 2,
0 disables) bounds the rounds; the gate is off when automatic validation
correction is off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QNxsX5P27Z5iKd2TVtB8Ej
@christopherjnelson
christopherjnelson marked this pull request as ready for review September 29, 2026 16:48
@christopherjnelson
christopherjnelson merged commit 3b5f8ff into main Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants