Repository navigation
Epic: surpass Claude Code on agentic coding (subagents, modes, checkpoints, background) #196
Description
Activity
- addedenhancementNew feature or requestNew feature or requestepicUmbrella trackerUmbrella trackerloop-systemAgent loop core: budget, gates, delegationAgent loop core: budget, gates, delegation
on Jun 16, 2026 Implementation Roadmap (v0.1 draft — open for feedback)
Each issue below maps to a single PR with a clear scope, mandate-compliance check, and acceptance criteria. The four sub-issues build on each other: #192 is the foundation, the rest compose it.
PR 1: #192 Subagents (foundation, 1-2 weeks)
Scope: spawn isolated child context, return summary, propagate stop-gate + lessons.
// internal/subagent/spawn.go type SpawnOpts struct { Prompt string Profile string // agent profile name MaxTurns int // child-side budget (defense in depth) VerifyCmd string // child runs verify-gate on its result } type SpawnResult struct { Summary string Verdict string // verified | unverified | failed Tokens int CostUSD float64 } func Spawn(ctx context.Context, opts SpawnOpts) (SpawnResult, error)
Key constraints:
- Each subagent gets a fresh
agentloop.Loop(no shared state with parent) - The parent's verification gate is RE-RUN on the child's summary (defense in depth)
- Lessons are READ-ONLY for the child (no writes — they're the parent's domain)
- The child's transcript is saved but never sent back to the parent (only the summary)
- Spawning is bounded: max 4 concurrent subagents per parent turn
Acceptance:
sin subagent 'review the auth module'returns a 200-word summary + a verdict- The summary passes the parent's verify-gate (so the parent can trust it)
- Lessons are filtered: the child sees parent's pre-existing lessons but its own attempts don't pollute them
- Test coverage ≥ 80%; race-clean
PR 2: #193 Permission modes (additive, 2-3 days)
Scope: three session-wide modes layered on the existing per-tool rule engine.
Mode Behavior plan(default)Read-only tools allowed; mutating tools require explicit approval acceptEditsEdit/Write allowed; Bash requires approval; deny list still hard-blocks bypassAll allow-list tools allowed; deny list still hard-blocks Key constraints:
- Layered:
bypassmode does NOT override the deny list (M4 mandate preserved) - The mode is set per session, not per turn (no flip-flopping)
- The mode is logged in the session transcript for audit
Acceptance:
sin-code chat --mode=planshows mutating tools as 'ask' in the rule enginesin-code chat --mode=acceptEditsallows Edit/Write without per-tool approvalsin-code chat --mode=bypassstill blocks 'Bash:rm -rf' via the deny list- All three modes pass existing tests (additive only)
PR 3: #194 Checkpoints (safety net, 3-5 days)
Scope: auto-snapshot before mutating tools;
sin checkpoint/sin rewind.Storage: content-addressed via modernc.org/sqlite. Each checkpoint = a Merkle root of the workspace files. The
Checkpointtable is keyed by session-id + turn-id.type Checkpoint struct { ID string // session-id:turn-id Merkle [32]byte CreatedAt time.Time Files int // count Size int // total bytes }
Key constraints:
- Snapshot ONLY on mutating tools (Edit, Write, Bash with non-readonly verbs)
- Snapshot is incremental (only changed files; baseline = last checkpoint)
- Rewind is per-turn (not per-session) — no global undo
- Rewind is logged; the operator must explicitly confirm
Acceptance:
- After 3 Edit operations,
sin checkpoint listshows 3 entries sin rewind <id>restores the workspace to that snapshotsin rewindon a non-mutating turn is a no-op- Rewinding doesn't delete the lesson log (the agent can learn from the rewind)
PR 4: #195 Background tasks (compose, 3-5 days)
Scope:
sin_backgroundCLI +sin bg list|logs|cancel. Each background task is asubagent.Spawnon a goroutine.type BackgroundTask struct { ID string Prompt string StartedAt time.Time Status string // running | verified | failed | cancelled Result *SpawnResult } func Background(ctx context.Context, opts SpawnOpts) (string, error) // returns task id func List(filter TaskFilter) []BackgroundTask func Logs(id string, lines int) string func Cancel(id string) error
Key constraints:
- Each background task is a fresh
agentloop.Loop(no shared state with parent) - The parent turn can return immediately after Spawn; the task runs concurrently
- The result is stored in SQLite; the parent reads it on demand via
sin bg logs - The
on_completehook fires the parent's lesson-recorder automatically (closed learning loop)
Acceptance:
sin_background 'refactor auth module'returns a task id immediatelysin bg listshows the task as 'running' then 'verified' when donesin bg logs <id>shows the child's transcript (truncated to last 100 lines by default)sin bg cancel <id>kills the goroutine cleanly (defer-based cleanup)- The parent's session does not block on the background task
Sequencing rationale
- Subagents: isolated-context delegation (sin_subagent) #192 first — every other feature builds on it. Without isolated contexts, the other three are unsafe to use.
- Session-wide permission modes (plan / acceptEdits / bypass) #193 second — small, immediately useful, no architectural risk. Unlocks the demo:
sin-code chat --mode=acceptEditsis a much better UX than today's per-tool approval. - Workspace checkpointing + rewind (sin checkpoint / sin rewind) #194 third — provides the safety net that makes
--mode=bypassactually safe. Without it,bypassis just 'turn off safety'. - Background tasks (sin_background / sin bg list|logs|cancel) #195 last — composes Subagents: isolated-context delegation (sin_subagent) #192 onto goroutines; the moment we have a working subagent.Spawn, background tasks are a 50-line wrapper.
Total estimate
- 3-4 weeks for the full sequence
- 1 dev (no parallel work needed because Subagents: isolated-context delegation (sin_subagent) #192 blocks the rest)
- The
internal/agentlooppackage is the load-bearing primitive: every PR touches it
What this epic does NOT do
- Network-driven subagent delegation (cross-process) — out of scope, see issue on Federation
- Multi-user permission modes (operator A vs operator B) — out of scope, M4 is single-user
- CRDT-based workspace sync — out of scope (Federation in [v3.20 rag] RAG over instinct store: semantic search for top-N selection #160 v2)
This is a draft. Open for review before PR 1 starts.
- Each subagent gets a fresh
All four Gaps closed (sequencing as suggested in body):
- Subagents: isolated-context delegation (sin_subagent) #192 (subagents) -> PR feat(subagent): sin-code subagent CLI (issue #192, wraps #153) #231 (sin-code subagent CLI) merged 2026-06-16
- Session-wide permission modes (plan / acceptEdits / bypass) #193 (perm modes) -> PR feat(permission): session-wide modes (issue #193, plan/acceptEdits/bypass) #234 (plan/acceptEdits/bypass) merged 2026-06-16
- Workspace checkpointing + rewind (sin checkpoint / sin rewind) #194 (rewind) -> PR feat(checkpoint): workspace checkpointing + rewind (issue #194) #235 (content-addressed snapshots) merged 2026-06-16
- Background tasks (sin_background / sin bg list|logs|cancel) #195 (background) -> PR feat(agentloop): background task registry (issue #195, v0 in-process) #233 (in-process TaskRegistry) merged 2026-06-16
Sub-issues are all closed. The non-negotiable constraints held:
- M2 preserved: no new runtime dependency. modernc.org/sqlite
(already in go.sum) for the index, stdlib for blob I/O. - Default behavior is byte-for-byte identical: --mode empty,
--no-auto-checkpoint, no --background. Every new feature
is opt-in via flag. - All five loop-engineering issues (Loop: Stagnations-Erkennung + adaptives Stop-Budget #150, Loop: Token-/Kosten-Budget mit Hard-Cap #151, Loop: Self-Reflection-Turn vor Completion #152, Loop: Sub-Agent / Tool-Delegation #153, Verify: Sprach-agnostische Predicates (Polyglot) #154)
that composed into the subagents surface are also merged +
closed.
Closing this epic. The roadmap item 'surpass Claude Code on
agentic coding' is satisfied for this cycle.
Goal: be better than Claude Code on agentic coding
This epic tracks the four architectural gaps where Claude Code is currently
ahead of SIN-Code on agent loops, tools, and autonomy — each scoped so it can be
closed without breaking Mandate M2 (one static binary,
CGO_ENABLED=0,SQLite via
modernc.org/sqlite, no new runtime dependency).Where SIN-Code is already AHEAD (do not rebuild)
internal/agentloop,internal/stopgate): completion authority is decoupled from the worker. ClaudeCode has no equivalent — it trusts its own "done".
internal/lessons): persistent, cross-sessionfailure memory injected before the first turn. Claude Code does not learn
across sessions.
swarm_cmd.go): N profiles race, first verified result wins.internal/orchestrator): critic / adversary / confidencecalibration (Brier score).
The strategy below is deliberately to layer Claude Code's strengths on top of
these, so each new capability also inherits our verification + learning — which
is what makes the result better, not just equal.
Gaps to close
Claude Code's biggest edge. Delegate a sub-task into a fresh context window via
a child
agentloop.Loop, return only a summary. Combined with our stop-gate +lessons, this is strictly stronger than Claude Code's subagents.
plan/acceptEdits/bypass). Layered on the existing per-tool rule engine + hooks veto.tools;
sin checkpoint/sin rewind. Content-addressed viamodernc.org/sqlite.sin_background+sin bg list|logs|cancel. Each background task is asubagent.Spawnon agoroutine, so it inherits verification.
Suggested sequencing
biggest competitive step.
bypass/acceptEditsmodes safe to use.Non-negotiable constraints (apply to all four)
CGO_ENABLED=0.identical to today so existing tests and runs are unaffected.
go build ./...green.