Bridged child owns the task: worker bridge path, license and caveats - #438
Conversation
…July codex caveats retired - worker.md Phase 1b: implementer tier resolved before Phase 1.5; a CLI-reached model hands the task to the bridged child via pointer prompt + usage brief, one foreground bridge call, dirty-remainder commit, base..HEAD range review, focused gates, then Phase 3; `stage: implement` line records model + delegated count - work phases.md 3c and the SECTION3C mirror heredoc: the worker bridges and the conductor never does; mirror 3c carries the implementer-tier paragraph again, with grep guards for both literals - usage.md long-task brief: "never spawn another bridge"; carries the judicious-subagent license and asks for the delegation count in the digest; no-plan-route.md names the owner as the holder wherever it runs - July "keep the child flat" caveats (usage.md self-bridge line, codex reach page shell-out row) are dated watch lines naming openai/codex#33267 with the 0.153.4 / gpt-6-astra measurements and the 0.144-0.145 reported range - fn-98 R2 folded in: codex reach page in-host row and platforms.md worker-pin note state the measured steering facts; fn-98 closed with a pointer, R4-R9 recorded as undone - STRATEGY.md "The owner holds the license"; .flow/criteria.md G3; bug memory entry for the #436 widening; CHANGELOG Unreleased entry - Codex mirror regenerated (sync-codex.sh twice, clean second run) Task: fn-245-bridge-child-owns-the-task-worker.1 Claude-Session: https://claude.ai/code/session_01JFYv5JtK8HAsshpWRAT5YL
…orwarded license and the stage-line model source - work 3c dispatch (canonical + SECTION3C mirror heredoc) gains the optional IMPLEMENTER line; worker Phase 1b consults it as the highest routing rung - no-plan-route.md license names the owner as the only committer and defers the commit convention to the owner's path, so the forwarded paragraph agrees with the long-task brief's checkpoint convention - Phase 1b records `model:` from the bridge command line (never the child's self-report) and `delegated:` from the digest - Codex mirror regenerated (sync-codex.sh twice, clean second run) Review round 1 (codex, three draws): three merged findings, all addressed. Task: fn-245-bridge-child-owns-the-task-worker.1 Claude-Session: https://claude.ai/code/session_01JFYv5JtK8HAsshpWRAT5YL
…eview-round memory entry - usage.md names the codex-cli versions, counts, date and issue; the model identifier stays on the codex reach page (fn-195 R2 guard) - bug memory entry for the fn-245 review round (forwarded license carried the wrong holder's commit contract) - Codex mirror regenerated (sync-codex.sh twice, clean second run) Task: fn-245-bridge-child-owns-the-task-worker.1 Claude-Session: https://claude.ai/code/session_01JFYv5JtK8HAsshpWRAT5YL
PR SummaryMedium Risk Overview The long-task brief narrows the #436 never-list from "never spawn another agent or bridge" to "never spawn another bridge" and embeds the fan-out license so the bridged child matches an in-host worker. Codex guidance is updated: Reviewed by Cursor Bugbot for commit 9d4a688. Configure here. |
- Phase 1b: inert and unreachable branches end the phase explicitly; Done-when scoped to the bridged branch - Investigate-first rule carries the Phase 1b bridged carve-out in sibling-rule shape - Conduct checklist gains the bridged-implementer contract with its failure clause Claude-Session: https://claude.ai/code/session_01JFYv5JtK8HAsshpWRAT5YL
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 9d4a688. Configure here.
Bridge child owns the task: worker bridge path, fan-out license restored, July codex caveats retired
The direct route rests on one owner seeing the whole task and deciding its own delegation. When a routing block pins the implementer to a model reached over a CLI bridge, the worker never consulted that tier, and the #436 long-task brief forbade the child from spawning any agent, a clause no requirement asked for.
Follow-up to #436 (closed #431). Adopts the diagnosis of #437 without its shape; see Decisions.
TL;DR
codex exec: multi_agent_v2 subagent results unusable — parent turn fails with "Encrypted function output content could not be decrypted or decoded" openai/codex#33267 still open upstream for 0.144 to 0.145, its minimal repro clean on 0.153.4, zero decode errors across the September spawning runs. fn-98's undone R2 (steering works on both paths since 0.146.0) is delivered here and fn-98 is closed.Not in this PR (by design)
The change, top to bottom
When the implementer tier is reached over a CLI bridge, the bridged child now owns the task and its own delegation: the worker gains a thin Phase 1b that hands the task over and reviews the child's commit range, the long-task brief bans only a nested bridge and carries the fan-out license, the July codex caveats become dated watches with the measured evidence (folding in fn-98's undone R2), and a strategy principle plus standing criterion G3 make the next accidental narrowing a review finding.
fn-245-aid-3934991a07cfcf662d978796aa4b7b46e8bccec27109effe3934991aae7b29256a06381ce9041cfb6c4173b9Legend:
WHYPRINCIPLESTEPKEPTVERIFY·NEWMODIFIEDDELETEDRENAMEDCOPIED·CANONICALGENERATEDMECHANICALWHY0. Two defects and a policy gap — The worker never consults the implementer tier, so a routing block pinning a CLI-reached model is silently ignored and the session model implements. The #436 long-task brief says never spawn another agent, a clause no requirement asked for; the worker generalized the July keep-the-child-flat caveats into a never-list and three checks missed it. Nothing stated whether fan-out on the bridged path belongs to the wrapper or the child, and the direct route's premise is one owner with the whole task and its own delegation.Evidence: source:s-spec
PRINCIPLE1. The owner holds the license — Whoever implements owns delegation: the in-host worker on the standard path, the bridged child over a CLI bridge. Wrappers, scouts, and conductors never fan out on the implementer's behalf. Safety rules bound push, history rewrite, scope, verdict, and nested bridges, never the owner's own delegation. Recorded as a strategy design principle and as standing criterion G3, which completion review judges on every spec.Evidence: source:s-t1, source:s-c1, source:s-r7, source:s-r8, R-ID:R7, R-ID:R8, task:fn-245-bridge-child-owns-the-task-worker.1
MODIFIEDCANONICALSTRATEGY.mdMODIFIEDCANONICAL.flow/criteria.mdSTEP2. Worker Phase 1b: hand the task to the bridged child — A new worker phase resolves the implementer tier (an optional IMPLEMENTER dispatch line, then the routing block, then defaults) and, when the model is reached only by CLI, skips Phase 1.5 and every worker-side scout, composes a pointer prompt of identities and rails plus the usage guide's brief and the license verbatim, runs one foreground bridge call at the commit-permitting sandbox, then on return commits any dirty remainder, records the implement stage line with the model from the command line and the child's delegation count, reviews base..HEAD against the acceptance criteria, runs the focused gates, and continues at Phase 3. Step 3c states the worker bridges and the conductor never does; the mirror generator carries the same text.Evidence: source:s-t1, source:s-c1, source:s-c2, source:s-r1, source:s-r2, source:s-r6, R-ID:R1, R-ID:R2, R-ID:R6, task:fn-245-bridge-child-owns-the-task-worker.1
MODIFIEDCANONICALplugins/flow-next/agents/worker.mdMODIFIEDCANONICALplugins/flow-next/skills/flow-next-work/phases.mdMODIFIEDCANONICALscripts/sync-codex.shSTEP3. Brief and license: the child keeps its fan-out — The long-task brief's never clause reads never spawn another bridge, and the brief carries the judicious-subagent license so a bridged child holds the same delegation license as the in-host worker; its digest reports the number of subagents dispatched. The no-plan route's license names the owner as its holder wherever the owner runs and defers the commit convention to the owner's path, which a review finding showed was contradicting the brief's checkpoint convention.Evidence: source:s-t1, source:s-c1, source:s-c2, source:s-r3, R-ID:R3, task:fn-245-bridge-child-owns-the-task-worker.1
MODIFIEDCANONICALplugins/flow-next/templates/usage.mdMODIFIEDCANONICALplugins/flow-next/skills/flow-next-work/references/no-plan-route.mdSTEP4. July codex caveats retired into dated watches, fn-98 R2 folded in — The codex reach page's in-host row states fn-98's measured facts (steering works on both paths since 0.146.0, the precedence rule, the two dispatch gotchas) and its shell-out row drops the flat-child condition for a dated watch on openai/codex#33267 with the version scope and the clean repro. The platforms note and the usage guide's self-bridge line drop the July wording. fn-98 is closed with a pointer; its R4 and R5 to R9 are recorded as undone there. The usage guide's watch line omits the model identifier because a standing guard test forbids slugs in that region; the identifier lives on the reach page.Evidence: source:s-t1, source:s-c1, source:s-c3, source:s-r4, source:s-r5, R-ID:R4, R-ID:R5, task:fn-245-bridge-child-owns-the-task-worker.1
MODIFIEDCANONICALplugins/flow-next/docs/reach/codex.mdMODIFIEDCANONICALplugins/flow-next/docs/platforms.mdGenerated/mechanical files (2)
MODIFIEDMECHANICAL.flow/specs/fn-98-re-check-codex-mav2-subagent-model.mdMODIFIEDMECHANICAL.flow/specs/fn-98-re-check-codex-mav2-subagent-model.jsonSTEP5. Changelog and memory — An Unreleased entry names the worker path, the license restoration, the retired caveats, and the fn-98 fold, referencing #431, #436, and #437's diagnosis. Two bug memory entries record the #436 widening (symptom, the three checks that missed it, the July-caveat root cause, the clause-by-clause prevention rule) and the review-round finding that a forwarded license carried the wrong holder's commit contract.Evidence: source:s-t1, source:s-c1, source:s-c3, source:s-r9, source:s-r10, R-ID:R9, R-ID:R10, task:fn-245-bridge-child-owns-the-task-worker.1
MODIFIEDCANONICALCHANGELOG.mdGenerated/mechanical files (2)
NEWMECHANICAL.flow/memory/bug/build-errors/implementer-brief-widened-never-list-2026-09-14.mdNEWMECHANICAL.flow/memory/bug/integration/forwarded-license-carried-the-wrong-2026-09-14.mdKEPT6. What did not change — No hook, flowctl code, or config key. No reach page other than codex changes, so Cursor, Droid, Grok Build, and Claude Code carry no new restriction. The other never clauses stand. No worker-side parallel bridge calls or worktree integration. fn-98's R5 to R9 stay out of scope. The site's work page, model-routing guide, cookbook entry, and landing card are the release walk's. Closing PR #437 and replying on #431 wait for the maintainer.Evidence: source:s-spec, source:s-r11, R-ID:R11
VERIFY7. Gate, mirror regeneration, and task state — Full parallel suite green (4991 ran), ruff clean, sync-codex.sh run twice with a clean second diff. The Codex mirror files are regenerated output; the .flow files are the spec, the minted implicit-owner task, and its receipt.Evidence: source:s-t1, task:fn-245-bridge-child-owns-the-task-worker.1
Generated/mechanical files (10)
MODIFIEDGENERATEDplugins/flow-next/codex/agents/worker.tomlMODIFIEDGENERATEDplugins/flow-next/codex/docs/flow-next/platforms.mdMODIFIEDGENERATEDplugins/flow-next/codex/docs/flow-next/reach/codex.mdMODIFIEDGENERATEDplugins/flow-next/codex/skills/flow-next-work/phases.mdMODIFIEDGENERATEDplugins/flow-next/codex/skills/flow-next-work/references/no-plan-route.mdMODIFIEDGENERATEDplugins/flow-next/codex/templates/usage.mdCOPIEDMECHANICAL.flow/specs/fn-245-bridge-child-owns-the-task-worker.jsonNEWMECHANICAL.flow/specs/fn-245-bridge-child-owns-the-task-worker.mdNEWMECHANICAL.flow/tasks/fn-245-bridge-child-owns-the-task-worker.1.jsonNEWMECHANICAL.flow/tasks/fn-245-bridge-child-owns-the-task-worker.1.mdCritical changes
plugins/flow-next/agents/worker.md— the new Phase 1b, always loaded by every worker; highest canonical churn.plugins/flow-next/templates/usage.md— the brief every bridged child inherits: never-list narrowed back to five clauses, license added, self-bridge line becomes a watch.STRATEGY.mdand.flow/criteria.md— the principle and the standing criterion that guard it; capture and completion review read both.plugins/flow-next/docs/reach/codex.md— the user-facing claims about Codex steering and child fan-out, rewritten from measured facts.How to review this PR
The pipeline already verified this — you don't re-check it from scratch:
sync-codex.shidempotent; six prose-contract suites green per the task evidence.Your job — the calls the pipeline can't make:
IMPLEMENTERdispatch line the review round added is a field you want.Review plan
Must review (~20%)
plugins/flow-next/agents/worker.md— highest-churn canonical file and the always-loaded worker contract — Does Phase 1b keep judgment with the worker (range review, gates, review dispatch, done) while leaving investigation and delegation entirely to the child, with no worker-side scouting or parallel bridges anywhere? — open "Phase 1b: Bridged implementer" (also touched byf5d0a877).plugins/flow-next/templates/usage.md— the brief inherited by every bridged child — Is the never-list exactly push, history, scope, verdict, nested bridge, and does the license sentence read as the same license the in-host worker holds? — open theBranch: <branch>, already checked outblock and the paragraph below it (watch line adjusted in79bc5ad9).STRATEGY.md/.flow/criteria.md— standing policy read on every capture and completion review — Would this principle and G3 have caught the Bridged implementer may commit checkpoints; timebox-free brief for long bridged tasks (#431) #436 widening at review time? — open the fifth design principle and G3.Spot-check
plugins/flow-next/docs/reach/codex.md— fn-98's measured facts and the #33267 watch; check the version scope reads as a watch, not a rule.plugins/flow-next/skills/flow-next-work/references/no-plan-route.md— the license names the owner as holder and defers the commit convention to the owner's path.plugins/flow-next/skills/flow-next-work/phases.mdandscripts/sync-codex.sh— 3c paragraph and the optionalIMPLEMENTERline, mirrored into the SECTION3C heredoc with grep guards.plugins/flow-next/docs/platforms.mdandCHANGELOG.md— one sentence and one Unreleased entry.Safe to skim (~80%)
plugins/flow-next/codex/— regenerated bysync-codex.sh, idempotent on the second run — skim..flow/— the spec, the minted implicit-owner task and receipt, fn-98's close addendum, and two bug memory entries; task-state, not hand-written code — skim.Decisions made
No decision-track memory entries were written for this spec. The rationale lives in the spec's Decision Context: PR #437's diagnosis is adopted (the worker never consulted the tier) but its shape is not, because it moved fan-out to the Claude worker as parallel bridge calls with per-child worktrees, inherited the agent-spawn ban, and added integration machinery to an always-loaded prompt. The caveats become watches rather than deletions because the upstream issue is still open for older builds.
Memory left behind
Bugs captured during this spec:
bug/build-errors/implementer-brief-widened-never-list-2026-09-14— the Bridged implementer may commit checkpoints; timebox-free brief for long bridged tasks (#431) #436 widening: the worker generalized the July flat-child caveats into a never-list; three checks missed it; prevention is a clause-by-clause diff against the spec.bug/integration/forwarded-license-carried-the-wrong-2026-09-14— a forwarded license carried the in-host commit contract into the bridged child's brief, contradicting the checkpoint convention; found in review round 1.Open items
Generated by
/flow-next:make-prfrom fn-245-bridge-child-owns-the-task-worker againstorigin/mainon 2026-09-14.https://claude.ai/code/session_01JFYv5JtK8HAsshpWRAT5YL