Skip to content

v0.2.3

Choose a tag to compare

@janit janit released this 21 Sep 06:13
· 5 commits to main since this release

--scope is now enforced against the diff, rather than requested in the
prompt.

Until now the scope you gave a unit was prose interpolated into the worker's
instructions, and nothing ever compared it to what the worker actually did. A
unit told to touch src/** could write anywhere in its worktree and merge. The
reproduction has been in the test suite since a security review on 2026-09-20,
pinned as a description of what the tool did; it now describes what it
refuses to do.

UNIT "touches-readme" → out_of_scope  [0s, 1 commit(s), branch gator/touches-readme]
NOT merged: the unit changed files outside the scope it was given.
declared scope: src/**
outside it:
  README.md
--- worktree kept at .gator/worktrees/touches-readme ---

What is checked

The whole base-to-result diff: both endpoints of a rename, deletions, new
files, mode changes and symlinks. Each is a way to move work out of the
declared area, and a check that looked only at added files would miss every one
of them. Git's output is read NUL-delimited, so a path cannot hide inside a
newline.

A violation holds the merge, keeps the worktree for inspection, and names the
offending paths. The unit is atomic — the in-scope half is not merged either.

One matcher

Validation and enforcement share it. If the rules a planner must satisfy
differed from the rules a worker is held to, the scope a model may declare
would drift from the scope it is judged against.

The single deliberate difference: you may write --scope "**" to decline
scoping, because that is a choice a person can make and be asked about. The
planner cannot — a whole-repository scope proposed by the thing being judged is
not a scope.

Precedence

Following the specification: the worker's own failure outranks scope, and scope
outranks a failing verifier. A unit that wrote where it should not is not
redeemed by a green build, and "it wrote outside its scope" is the more
actionable thing to tell you.

Upgrading

deno task install. If you have been relying on broad scopes implicitly, units
that stray will now be held rather than merged — widen the scope deliberately,
or use "**".