-
Notifications
You must be signed in to change notification settings - Fork 3
plat 436
| Coordination | Value |
|---|---|
| State | fixed on main; not deployed |
| Date | 2026-10-04 |
| Owner | step-execution |
| Related | PLAT-432 (named route tools; the run that exposed it), PLAT-428 |
Scripted steps should not self-heal at run time. If a script fails, the step (and the workflow) fails and Pulse reports it. Writing and repairing scripts is a deliberate Builder action.
At run time a scripted step could reach an LLM in four ways: no readable saved
script (an LLM wrote one from scratch, which also happened when a folder-guard
denial hid an existing script), a failed script (up to 3 LLM repair rounds), a
lock_code step (an LLM "recovery turn", then agentic fallback), and plain
retries. The repair LLM can write anywhere under code/, which most plausibly
emptied a route's saved folder in the PLAT-432 investigation (inferred).
-
scriptedRunIsStrict: every run is strict (run the savedmain.py, fail with its error); the existing saved-script-only path does the work. OnlyExecutionContext.AllowScriptRepairlifts it, set solely by the Builder's ownexecute_stepin Workshop mode, outside a scheduled session, withoutfast_path_only, and never when the controller's run kind is a schedule, Slack or webhook.script_onlysteps stay strict for the Builder too. - Routes called by an agent,
run_full_workflow(also from the Builder chat), schedules and Relay/webhook runs are runs. -
lock_codenow only stops the Builder's own repair; tool and guidance text updated; code-authoring says runs never repair scripts. - Unit test
TestScriptedRunIsStrictUnlessTheBuilderRepairs.
The Builder's guidance still described the old behaviour in several places.
Fixed: scripted.md now opens with "Scripts are built by you, not healed by the
run" (runs execute the saved script and fail on its error; Pulse reports it; the
Builder writes and repairs with execute_step); optimize-playbook.md no longer
says lock_code stops "the fix loop / execution agent" in runs (four places: it
now only stops the Builder's own execute_step repair, and advises locking late);
code-authoring.md drops "autofix sees it" and scopes the exit-code-2 rule to the
Builder's own runs; workflow-tools.md says only the Builder's execute_step
may repair. Test: scripted_no_self_heal_test.go fails if any of the old
promises reappears.
docs/workflow/learn_code_flow.md (the scripted execution description) now opens
with the run-time rule and scopes generation, repair, save-back, the lock_code
effect and the code_exec fallback to the Builder's own execute_step.
- Live:
cli-step-contract(saved scripted step + named route, strict by default) PASS on claude-code, 2026-10-04. Not yet live-checked: a failing script failing the step with no LLM turn, and Builderexecute_stepauthoring a new script. - Pulse reporting of the failure is the existing step-failure path; not re-verified here.
-
TestGetRelayCommandCatalogWithoutGenericRuntimeRegistrationfails on current main, unrelated to this change.
Auto-synced from docs/ on main. Edit there, not here.