-
Notifications
You must be signed in to change notification settings - Fork 2
plat 257
PLAT-257 — Step learnings/knowledge access contract diverged across prompts, filesystem guards, and Builder guidance
| Coordination | Value |
|---|---|
| Assigned agent | Codex |
| Ticket state | implemented; runtime reverify |
| Last synchronized | 2026-08-30 |
- Priority: runtime permission contract, severity high.
- Related: PLAT-061), PLAT-062), PLAT-124), PLAT-223.
- Origin: user-requested audit of whether every workflow step can read the shared learnings and knowledgebase stores.
Normal steps already defaulted to read access for both stores, but the contract was inconsistent in two important ways:
-
canReadLearningsintentionally excludes evaluation-mode and deterministic routing steps from prompt injection, while regular, scripted, todo, message-sequence, retry, and continuation filesystem guards independently calledresolveLearningsAccess. Evaluation agents could therefore receive shell/file read permission for learnings that their prompt deliberately omitted. The execution-agent factory could also re-broaden a guard after an outer caller narrowed it. - The runtime's unset
knowledgebase_accessdefault has beenreadsince PLAT-055/K, but the Builder tool schema, theAgentConfigssource contract, andUseKnowledgebasecomments still saidnone/opt-in. PLAT-061 claimed this documentation drift was fixed, but only the canonical reference was updated; the live Builder schema remained incorrect.
- Added
resolveExecutionLearningsAccessas the shared prompt/filesystem capability decision. - Routed ordinary execution, execution-agent creation (including retries and recovery), scripted execution, todo orchestration, and message sequences through that decision.
- Evaluation message sequences now suppress only learnings writes; configured DB/KB behavior is preserved.
- Corrected every stale Builder/source description to state that KB reads are
default-on and
noneis the explicit opt-out. Writes remain gated by a contribution contract.
Human-input and deterministic routing steps execute no agent and therefore receive no filesystem capability. Evaluation steps keep KB reads but no learnings access. All ordinary agentic step forms default to read access for both stores.
- Table-driven coverage for regular, message-sequence, todo, evaluation,
routing, and explicit-
nonelearning resolution. - Message-sequence evaluation coverage proves learnings writes are suppressed without broadening or removing DB/KB writes.
-
go test ./pkg/orchestrator/agents/workflow/step_based_workflowpasses.
Runtime reverify: after deployment, inspect one ordinary step, one todo or message-sequence step, and one evaluation run's effective Folder Guard.
Retain explicit builder acceptance cases for generated guidance coherence:
DB guidance must name accessible managed tools/read surfaces; reusable learnings
must not contradict plan execution environment or variable names. Sales Outreach
had a GOG_HOME fallback forbidden by its plan plus $GOG_HOME versus
$VAR_GOG_HOME confusion; its workflow repair was subsequently verified across
three normal runs (PUL-93DC16E9). That repair is not proof that the builder now
prevents every equivalent contradiction. Validate knowledgebase/learnings against
the executable contract at authoring/change time, not on every healthy Pulse tick.
LinkedIn PUL-D3AD004C is another acceptance case: a verifier deleted a successfully
posted comment's DB receipt after relying on an earlier failed snapshot. Require
same-execution side-effect evidence before destructive reconciliation. This is
not yet reduced to a shared deterministic platform-code reproduction; do not
mark that prevention complete from the workflow-level prompt repair alone.
PLAT-305) implements the first review/scheduling/research/lifecycle release. This ticket's remaining foundation acceptance is still required and is not closed by adding Architecture or outcome tracking. Historical evidence and legacy workflow behavior remain unchanged by that release.
Auto-synced from docs/ on main. Edit there, not here.