v2.10.1
·
66 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Fixed
- The kernel already forbade asking the owner to choose engineering mechanics. It now restates that where a permitted ask is actually put.
Authorityallows an ask for a protected action, a material product choice, or a human-only step, which governs what an ask may concern and never how it is worded.Autonomygoverns the wording, and its explanation was scoped to the product choice, so nothing repeated the ban at the moment a run decides how to phrase a protected ask it is entitled to make. The two sentences compose without conflict — choose the mechanism yourself, then ask only for the grant — and the receipt below is a run that failed to compose them. The kernel now states the composition: a protected or human-only ask is put the same way as a product choice, as what it changes for the owner, their account, or their exposure, with the technical decision already taken. No choice between technical options is put to them, and where the ask exists only because a step is theirs to perform, what is asked for is that step rather than approval of the way around it.
Evidence
- An installed 2.10.0 session on a real project ended a two-hour run by asking its owner whether it might replace a named environment variable on staging with the currently authorized GitHub CLI token, offered against a properly scoped token the same sentence called better. The owner rejected it as a question that was never theirs, and named the boundary in their own words: they settle product questions and what no agent can reach, and nothing else.
- The run deviated from text that was plain and in context. "Do not ask them to choose libraries, branches, test commands, schemas, architecture, or other engineering mechanics" was in the kernel all session; the run's reasoning never reaches it, and reasons only from the credential clause it was obeying, which it quoted an hour earlier while making the staging configuration change beside it without asking, because the owner's request had named staging and had not named credentials. Told the decision was its own, it named the same defect the owner had — the phrasing, not the ask — and finished the delivery within the hour. The message's other item, a payment setting only the owner could reach, drew no objection.
- One session cannot show that agents in general need more than the sentence that was already there, and this release does not claim it does. The receipt meets the revisit condition recorded under "An unstated choice is an unfinished result" — an owner asked about engineering mechanics — and not the neighbouring condition of repeated such questions: a scan of every session on both hosts that loaded the package in a real project found this one instance, and the only other permission-shaped question was a legitimate product question about what a public ranking may reveal.
- So this is a clarification shipped against an unmet evidence bar, recorded as the owner's decision rather than as a demonstrated need, the same disposition 2.5.0, 2.8.0 and 2.10.0 took. Their ground is that the owner never handling engineering is the boundary the product exists to hold, so a single visible breach of it is worth restating the rule where the breach happened. What holds the cost down is that nothing here is a step or a gate: it constrains the wording of an ask the contract already permitted, in the section that already explains how an ask is put.
- Two narrower alternatives lost. Rescoping the existing sentence from "a product choice" to any input would have carried "recommend one option" with it, which is written for a menu and would license the very shape that failed. Narrowing the credential gate so that configuring a credential inside an already-granted destination needs no separate grant would have removed the question instead of fixing how it was put, and the receipt argues against it: what was moving was the owner's personal identity into a persistent deployed service, which is the case that clause protects, and the grant cost one turn rather than the work.
- The separation this states is the one
mattpocock/skillsissue #962 proposes and its maintainers have left open: ask about the situation and the outcome in plain language, and map the answer to the technical term afterward. It also carries to a protected ask a boundary this project had already drawn three times against a menu of engineering options put to the owner, into-spec,to-tickets, andfinishing-a-development-branch. - Whether the wording changes what a run writes is
UNVERIFIED. No paired receipt was made, and the rule the run broke was already there.