Repository navigation
Tell operators from participants on every connect request - #843
Conversation
Opening a project to its members is how a colleague's question reaches the agent at all, but a project's membership is not a list of people whose word should authorize a merge or a deploy. So each request line now says which, as the local agent connector's lines do: `role` is "operator" for the operator and anyone named with --allow, and "participant" for a member admitted only by --trust project. --allow now combines with --trust project, so one setup can name who operates the agent and open it to the project at once. Participants reach the agent by mention and by comment on a thread it follows. Their completions are discarded as operators_only; an assignment was already the operator's alone in every mode. The role is the lesser of the performer's and, for mentioned and subscribed, the author's: words a participant wrote stay a participant's request whoever brought them in. A record admitted without a role, or with one this build does not know, is handed off as a participant's. What a participant's request may lead to is the session's policy, and the skill gets that rule.
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
All reported issues were addressed across 15 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
|
Codex Review: Didn't find any major issues. Hooray! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review |
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@cubic-dev-ai review |
@jeremy I have started the AI code review. It will take a few minutes to complete. |
Review state at head 164bb78
Jeremy's decision: ask in the thread. b0015df drops the private-ping approval path: no ping, no ask or done records, no transcript scan. When a participant's request needs an operator's word, the agent says in the thread what's ready and mentions the operator. The go is the operator's mention of the agent there, as in local-connector #57. The five open ping threads are resolved on that decision. Folded in after:
Declined, with reasons in the threads:
Diff against main: 552+/79− across 14 files before the revert, 513+/79− just after it, and 537+/82− at this head. Stacked: #847 (assignment opt-in) and #848 (request-line contract), both rebased onto 164bb78. Separate: #853 (stale ping comments). |
A completion is context with no acknowledgement, like a comment on a thread the agent follows, which a participant already reaches it by. Dropping it at the gate kept the agent from hearing that a member finished something it had a stake in; the role already tells the session whose it was.
|
@codex review |
|
@cubic-dev-ai review |
@jeremy I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b0015df22a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…keep participants from mapping repos through AGENTS.md The step that pushes and opens a pull request now stops for a participant's request: commit locally and ask in the thread, push only on an operator's go. The go is a role operator request whose content is only go, so its handling moves out of the participant-only block. And a project AGENTS.md mapping, which any member may be able to edit, decides a participant's repo only when it agrees with the mapping the operator confirmed.
|
@codex review |
|
@cubic-dev-ai review |
@jeremy I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 14 files
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
|
@codex review |
|
@cubic-dev-ai review |
@jeremy I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4294a69c10
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…e, and keep AGENTS.md from lifting the participant rules
|
@codex review |
|
@cubic-dev-ai review |
@jeremy I have started the AI code review. It will take a few minutes to complete. |
|
Codex Review: Didn't find any major issues. Keep it up! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Ports basecamp-local-agent-connector#57 to
basecamp connect.Opening a project to its members is how a colleague's question reaches the agent at all. But a project's membership is not a list of people whose word should authorize a merge or a deploy. So each
"type":"request"line now carriesrole, with the key and values the local connector emits:"operator": the operator, or someone named with--allow."participant": a member admitted only by--trust project.What changes
--allowcombines with--trust project.connect setup --trust project --allow 111names operators and opens the agent to the project's members as participants.connect.jsonkeepstrust.mode: "project"withallowlist_ids, andPolicy.Validatenow accepts that pairing with the same per-id checks as allowlist mode.--allowon its own still implies allowlist. A run that passes--allowreplaces the list, a run that passes none keeps it, and--trust operatorclears it.--trust operator --allowis refused.*.completedis admitted as context, with no acknowledgement androle: participant, the same as a followed-thread comment. Assignments were already the operator's alone in every mode, and they still are.mentionedandsubscribed, the author's. So when the operator moves a member's to-do in, the request is still a participant's, and the other way round.participant.POST /circles.jsonfind-or-create, then a line in it), and tells the participant only that it's been passed on. The go-ahead is still an operator's @mention of the agent on the thread, since the connector doesn't watch pings. A line withoutrolegets the participant rules. Setup's phrase table and trust explanation cover the combination. The same wording is in basecamp-local-agent-connector#58.Not ported
--allow-domain. It's email-keyed, and Basecamp masks colleagues' addresses for non-admins, so the domain rule matches nobody unless the operator is an account admin.basecamp connectkeys all trust on Person id, and project trust covers the use.--allow-assignments-from-authorized: ported separately, in Let named operators assign the agent work, when the operator opts them in #847.ignored … by a participantline. A member's assignment is already logged as a"type":"event"line with reasonassignment_not_operator, Event lines carry pointers, never names, by design.Tests
Each of these fails without the change:
TestOperatorsAndParticipants(admission): the roles, the combination, a member's completion as participant context, and author-versus-performer.TestTheLineSaysWhoseRequestItIs(handoff): the operator value, the participant value, a missing role, and an unknown role.TestApplyTrust/allow_names_operators_alongside_project_trustandTestConnectSetupNamesOperatorsAlongsideProjectTrust(setup).The two assignment subtests are regression guards that also pass on main's behavior.
make checkis green on linux. On darwin,golangci-lintreports two existing issues indriver/proctime_darwin.go, which this PR doesn't touch.Summary by cubic
Opening a project to its members lets a colleague's question reach the agent, but membership shouldn't authorize merges or deploys. Each request line now carries
role—"operator"for the operator and anyone named with--allow,"participant"for a member admitted only by--trust project.What changes
--allownow works with--trust projectto name operators beside the project's members; alone it implies allowlist,--trust operator --allowis refused, a run with--allowreplaces the list, one without keeps it, and--trust operatorclears it.mentionedandsubscribed, the author's: words a participant wrote stay a participant's request whoever brings them in, and the requester the line names is the person who wrote them.participant.roleoperator,mentionedrequest whose content is "go" approves — an operator's reply without the mention is context, not the word — and a member-editable AGENTS.md shapes the work without lifting any of these rules. A line withoutrolegets the participant rules.Not ported:
--allow-domain(Basecamp masks colleagues' addresses for non-admins) and--allow-assignments-from-authorized(assignments remain the operator's alone in every mode).Written for commit 164bb78. Summary will update on new commits.