Skip to content

fix(intake): enforce scoped interactive boundaries - #47

Merged
ignorejjj merged 1 commit into
mainfrom
fix/intake-safety-boundaries
Jul 11, 2026
Merged

ignorejjj merged 1 commit into
mainfrom
fix/intake-safety-boundaries

Conversation

@ignorejjj

Copy link
Copy Markdown
Member

Summary / 概述

Closes #46.

  • Make every visible intake reply a hard user-turn boundary; mixed text + tool responses are suppressed instead of executing behind a displayed question.
  • Split scoped, read-only research discussion from benchmark launch planning, remove intake shell access, and enforce canonical user-approved paths across Read/Glob/Grep.
  • Stage immutable launch plans and require a later explicit confirmation handled by the CLI controller, so go cannot trigger a model rewrite.
  • Reset filesystem authority on resume/reset, redact persisted tool/compaction data, and reject unsafe conversation/experience paths.
  • Honor the documented nested llm: project configuration during intake preflight and update English/Chinese docs and READMEs.

Linked issue / 关联 issue

Closes #46

Type of change / 改动类型

  • 🐞 Bug fix / 缺陷修复 (fix)
  • ✨ Feature / 新功能 (feat)
  • 📝 Docs / 文档 (docs)
  • ♻️ Refactor / 重构 (refactor)
  • ✅ Tests / 测试 (test)
  • 🔧 Chore / build / CI (chore)

How was this tested? / 如何验证?

.venv/bin/python -m ruff check src tests
.venv/bin/python -m pytest -q
# 489 tests collected; full suite passed with 6 optional-environment skips

git diff --check
# clean

Real CLI E2E against a local scripted OpenAI-compatible endpoint:
- Chinese future-intent question: 1 model request, then returned to `you ›`
- Mixed visible text + sibling Read: tool suppressed; sibling content never read/persisted
- Authorized Read: 2 model requests (tool-only, then answer); persisted result redacted
- Pure sibling Read: BLOCKED by path policy; secret absent from model request/history
- Staged LaunchExperiment: `go` entered the outer Research Contract with request count still 1; final run was cancelled with `n`

Checklist / 检查清单

  • PR title follows Conventional Commits (e.g. fix(config): ...). / PR 标题遵循 Conventional Commits 规范。
  • The change is focused and reasonably small. / 改动聚焦且体量合理。
  • I ran the relevant tests locally (python tests/test_*.py) and they pass. / 我已在本地运行相关测试并通过。
  • Docs / examples updated if behavior or config changed. / 若行为或配置有变更,已同步更新文档/示例(含 README.zh-CN.md)。
  • No secrets, API keys, or tokens are included in the diff. / diff 中不包含任何密钥、API key 或 token。

Make visible replies hard user-turn boundaries, suppress mixed tool execution, and separate read-only discussion from launch planning. Stage immutable launch plans for explicit controller approval, enforce user-authorized filesystem scopes, and harden persisted conversation and experience data.

Also honor documented nested llm project settings during intake preflight and add real CLI-backed regression coverage for drift, scope denial, and staged launch confirmation.

Constraint: Preserve autonomous coordinator and executor ReAct behavior

Rejected: Prompt-only guardrails | cannot enforce turn or filesystem boundaries

Confidence: high

Scope-risk: moderate
@ignorejjj
ignorejjj merged commit 65ffcc8 into main Jul 11, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: intake can continue acting after yielding to the user

1 participant