Skip to content

v0.17.7

Choose a tag to compare

@hieuphung97 hieuphung97 released this 06 Sep 01:15
· 226 commits to main since this release
7c56f68

A controlled probe repeated an earlier harness round against the current protocol —
same configuration, same brief, same task, one variable changed. The reviewer
accepted a change whose counterexample had never been observed: the same failure
three earlier releases had each been written to close.

The reviewer was not at fault. Its coordinator's dispatch prompt told it that if
the instrument passes, return ACCEPT — an acceptance criterion the coordinator
invented, contradicting the protocol. The reviewer complied with what it was given.

Measured before changing anything

A Spike measured what actually reaches a dispatched worker.

The execution plane's injected preamble has exactly three sections, all authored by
the plane, with no slot this protocol or a project can extend. The only
project-controlled content is the prompt the coordinator writes.

Separately, four harnesses were each asked for a token planted in AGENTS.md,
under instructions not to read, open, search or grep any file. All four returned
it. AGENTS.md auto-loads into a dispatched worker's context; the skill does not.

Those are the only two routes to a worker, and this change takes neither.

What changed

Two sentences in the worker-launch section: the dispatch prompt carries the task,
its scope and the evidence required, and does not define the role dispositions or
the conditions for reaching one.

The review section is byte-identical to the previous release. Three releases have
edited it to fix this; this one does not.

The distinction is addressee, not readership. The review section was in the
coordinator's context on all three prior attempts, since the skill loads in full.
What changed is that those regulated the reviewer while the observed failure was
the coordinator — and a dispatched reviewer may not have the skill loaded at all,
so that section could not have reached it in any case.

The check binds placement

The first version of the contract check searched the whole file, so the sentences
could be moved verbatim into an unrelated section with everything still green —
though placement is the entire claim, since the rule exists to be met while a
prompt is being composed. The check now extracts the section and asserts the
sentences are inside it.

What this does not do

Nothing here observes a coordinator writing a prompt. This change is not verified
by its own delivery; only a further probe tests it, and the decision record says so
rather than implying otherwise.