Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
06c5a6c
merge(#2908 slice-4): merge slice-4 base (slice-1+2+3 work) into code…
Jun 2, 2026
bf8ddb3
feat(#2908 slice-4 task-4-1): flip EGG_BRC_EVENT_PUMP and EGG_BRC_MEM…
Jun 2, 2026
d78ebe0
merge(#2908 slice-4): merge slice-4 base (slice-1+2+3 work) into docu…
Jun 2, 2026
169417c
docs(#2908 slice-4 task-4-4): post-deletion consensus wrapper docs
Jun 2, 2026
15664e8
feat(#2908 slice-4 task-4-2): delete legacy capped-restart template a…
Jun 2, 2026
09c7ebd
docs(#2908 slice-4 task-4-4 v2): address reviewer_code v1 NACK
Jun 2, 2026
f3fb61e
merge(#2908 slice-4): merge documenter task-4-4 docs commit into code…
Jun 2, 2026
38b08e4
Merge remote-tracking branch 'origin/egg/issue-2908-impl2/slice-4' in…
Jun 2, 2026
eaca39c
docs(#2908 slice-4 task-4-4 v3): address reviewer_code v2 NACK
Jun 2, 2026
3bcf2af
Merge remote-tracking branch 'origin/egg/issue-2908-impl2/slice-4' in…
Jun 2, 2026
d6fc959
docs(#2908 slice-4 task-4-4 v3 follow-up): EGG_BRC_EVENT_PUMP removed…
Jun 2, 2026
04048c3
fix(#2908 slice-4 v2): address reviewer_code_holistic NACK on v1
Jun 2, 2026
66028aa
Merge remote-tracking branch 'origin/egg/issue-2908-impl2/slice-4' in…
Jun 2, 2026
e093f67
fix(#2908 slice-4 v3): address reviewer_code v1 NACK on coder v2
Jun 2, 2026
b63a42b
fix(#2908 slice-4 v3 follow-up): address reviewer_code_holistic v2 bl…
Jun 2, 2026
fd1a8b6
fix(#2908 slice-4 v4): restore _auto_populate_contract + ruff I001 fi…
Jun 3, 2026
4fafcb8
fix(#2908 slice-4 v7): address reviewer_code NACK — 4 ruff failures
Jun 3, 2026
518558c
Persist BRC history for slice-4 (#2548)
Jun 3, 2026
efa1fab
docs(#2908 slice-5 task-5-4): prose-arg channels + brc verb-level CLI
Jun 3, 2026
0a8a7f6
feat(#2908 slice-5 task-5-1/5-2/5-3): prose-arg channels + brc CLI su…
Jun 3, 2026
50159eb
docs(#2908 slice-5 task-5-4 v2): address reviewer_code v1 NACK
Jun 3, 2026
3b63b83
fix(#2908 slice-5 v2): address tester v1 NACK — catch UnicodeDecodeEr…
Jun 3, 2026
78cc951
test(#2908 slice-5 task-5-7): MCP-surface latency baseline capture
Jun 3, 2026
26696b4
Persist BRC history for slice-5 (#2548)
Jun 3, 2026
268a7d6
Fix mypy errors: assert file_path non-None before open() in orch_cli
james-in-a-box[bot] Jun 3, 2026
40da4f6
docs(#2908 slice-6 task-6-5): MCP→CLI retirement docs
Jun 3, 2026
bdace09
feat(#2908 slice-6 task-6-1..6-6): retire agent MCP surface for CLI
Jun 3, 2026
494a80e
docs(#2908 slice-6 task-6-5 v2): address reviewer_code v1 NACK
Jun 3, 2026
15e77d5
test(#2908 slice-6 tester): MCP surface retirement hardening + ruff f…
Jun 3, 2026
451ba3f
Merge branch 'egg/issue-2908-impl2/slice-6' of https://github.com/jwb…
Jun 3, 2026
a71b8ac
fix(#2908 slice-6 v2): address reviewer_code_holistic v1 NACK
Jun 3, 2026
8df66ee
fix(#2908 slice-6 v2 follow-up): address reviewer_code v1 NACK
Jun 3, 2026
99b60c0
test(#2908 slice-6 tester v2 follow-up): ruff format fix in gateway test
Jun 3, 2026
aa6beb6
fix(#2908 slice-6 v3): address tester v2 NACK — ruff format
Jun 3, 2026
4140fb3
Merge origin/egg/issue-2908-impl2/slice-3 into egg/issue-2908-impl2/s…
jwbron Jun 3, 2026
109f959
Persist BRC history for slice-6 (#2548)
Jun 3, 2026
1c491bb
Fix lint: allowlist contract_cli.py for file-size check (issue #2908)
james-in-a-box[bot] Jun 3, 2026
85660f4
fix(#2908 slice-4): migrate test assertions off deleted capped-restar…
james-in-a-box[bot] Jun 3, 2026
5144091
Merge slice-4 into slice-5: pull PR #2951 into PR #2952
jwbron Jun 3, 2026
a8ee7ee
Merge slice-5 into slice-6: pull PR #2952 into PR #2953
jwbron Jun 3, 2026
9259b97
Merge origin/egg/issue-2908-impl2/slice-3 into slice-4: resolve dual-…
jwbron Jun 3, 2026
2eb7834
Merge branch 'egg/issue-2908-impl2/slice-4' into egg/issue-2908-impl2…
jwbron Jun 3, 2026
efda107
Merge branch 'egg/issue-2908-impl2/slice-5' into egg/issue-2908-impl2…
jwbron Jun 3, 2026
db48fb5
fix(#2908 slice-4): restore _slice_agents_alive, parent-branch probe,…
james-in-a-box[bot] Jun 3, 2026
b2380bb
Merge remote-tracking branch 'origin/egg/issue-2908-impl2/slice-4' in…
james-in-a-box[bot] Jun 3, 2026
272bb6b
Merge remote-tracking branch 'origin/egg/issue-2908-impl2/slice-4' in…
jwbron Jun 3, 2026
a02545c
Merge branch 'egg/issue-2908-impl2/slice-5' into egg/issue-2908-impl2…
jwbron Jun 3, 2026
2d8fa0f
Merge origin/egg/issue-2908-impl2/slice-3 into slice-4
jwbron Jun 3, 2026
6db4dd7
Merge branch 'egg/issue-2908-impl2/slice-4' into egg/issue-2908-impl2…
jwbron Jun 3, 2026
8f910e7
Merge branch 'egg/issue-2908-impl2/slice-5' into egg/issue-2908-impl2…
jwbron Jun 3, 2026
4c59c13
Sweep stale agent-MCP references from slice-6 deletion
egg-reviewer[bot] Jun 3, 2026
d601cda
Sweep residual slice-6 stale references and tense-correct docs
egg-reviewer[bot] Jun 3, 2026
b561a89
Past-tense slice-6 references in agent-tools reference doc
egg-reviewer[bot] Jun 3, 2026
99880bf
Merge origin/main into slice-6: resolve docs/tests/code conflicts
jwbron Jun 3, 2026
251b611
Past-tense stale mcp__* references re-exposed by merge
egg-reviewer[bot] Jun 3, 2026
c8bb00b
Merge origin/main into slice-6: resolve conflicts in concurrent-execu…
jwbron Jun 3, 2026
06ddc12
Merge origin/main into slice-6: resolve conflicts in agent-tools.md a…
jwbron Jun 3, 2026
399e98f
Merge origin/main into slice-6: resolve conflicts in docs, gateway, a…
jwbron Jun 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14,845 changes: 14,845 additions & 0 deletions .egg-state/brc-history/issue-2908-impl2-implement-slice-6.json

Large diffs are not rendered by default.

16,556 changes: 16,556 additions & 0 deletions .egg-state/brc-history/issue-2908-impl2-implement-slice-6.md

Large diffs are not rendered by default.

17 changes: 12 additions & 5 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,9 +39,16 @@ If `.venv` is absent, run `make deps` to install everything. This installs `uv`
## Key Entry Points

- **Headless agents** use the Agent SDK (`egg_agent` package)
- **Agent work** goes through the MCP server — see
[`submit_task`](docs/guides/sdlc-pipeline.md) (full
refine → plan → implement). The legacy interactive-mode CLI
(`bin/egg`) was removed in
[#1762](https://github.com/jwbron/egg/issues/1762).
- **Operators submit work** through the orchestrator MCP server's
[`submit_task`](docs/guides/sdlc-pipeline.md) tool (full
refine → plan → implement). That MCP server is operator-facing
(port 9850); sandbox agents drive pipeline lifecycle operations
through the `egg-orch` / `egg-contract` / `egg-checkpoint` shell
CLIs. The legacy interactive-mode CLI (`bin/egg`) was removed in
[#1762](https://github.com/jwbron/egg/issues/1762); the
in-process agent-side MCP tool surface was retired alongside
these docs in [#2908](https://github.com/jwbron/egg/issues/2908)
slice-6 (the operator-facing orchestrator MCP server is
unaffected). See
[Agent Pipeline-Lifecycle Surface](docs/reference/agent-tools.md).
- See [CONTRIBUTING.md](CONTRIBUTING.md) for dev setup, branching, and PR workflow
4 changes: 2 additions & 2 deletions docs/architecture/git-isolation.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ This document focuses on the specific challenge of **multi-agent git isolation**
| Agent accesses another agent's workspace | Filesystem isolation---other workspaces don't exist in container's view |
| Agent pushes to unauthorized branches | Gateway enforces branch ownership policy |
| Agent pushes malicious code directly to main | Gateway blocks direct pushes to protected branches; PRs require human review |
| Agent bypasses BRC consensus in pipeline session | Gateway blocks direct `git push` for pipeline sessions; requires `consensus_push` marker from `mcp__brc__propose` (or fallback `egg-orch consensus propose --push`) |
| Agent bypasses BRC consensus in pipeline session | Gateway blocks direct `git push` for pipeline sessions; requires `consensus_push` marker from `egg-orch consensus propose --push` (the agent-side `mcp__brc__propose` MCP tool was retired alongside this surface in [#2908](https://github.com/jwbron/egg/issues/2908) slice-6 — the CLI is the single agent surface) |
| Agent uses `git rebase origin/main` to contaminate pipeline branch | Gateway blocks any `git rebase` where the bare-form upstream or the `--onto` target is a protected base ref (`origin/main`, `main`, `origin/HEAD`, `FETCH_HEAD`) in pipeline sessions (#2224); base-branch rebase runs only via orchestrator-controlled `_rebase_pipeline_branch_onto_base` |
| Agent discovers or exfiltrates credentials | Credentials only exist in gateway; container never sees them |
| Agent modifies git config to bypass security | Container has no access to git metadata; config is gateway-controlled |
Expand Down Expand Up @@ -259,7 +259,7 @@ Each agent works on its own isolated worktree with its own staging area. This ap

**Pipeline agents:** In concurrent pipeline execution, all agents push to the same shared branch (e.g., `egg/issue-{N}`) but each agent has its own worktree. Since each role has mutually exclusive file write permissions (coder → source code, tester → tests, documenter → docs), push rebases cannot conflict. Reviewer agents sync their worktrees before reviewing by fetching and merging the pipeline branch, ensuring they evaluate up-to-date code from producers. See [Concurrent Execution Guide](../guides/concurrent-execution.md#per-agent-worktree-isolation) for details.

**Pipeline-session push enforcement:** For all pipeline sessions (refine/plan/implement), the gateway blocks direct `git push` — all pushes must go through `mcp__brc__propose` (which pushes to origin and sends CONSENSUS_PROPOSE in one step; push is on by default). The fallback CLI is `egg-orch consensus propose --push`. This structurally enforces the "all changes must be reviewed" invariant rather than relying on agent compliance. See [Gateway README — Pipeline Push Enforcement](../../gateway/README.md#pipeline-push-enforcement-brc-sessions) for details.
**Pipeline-session push enforcement:** For all pipeline sessions (refine/plan/implement), the gateway blocks direct `git push` — all pushes must go through `egg-orch consensus propose --push` (which pushes to origin and sends CONSENSUS_PROPOSE in one step; `--push` is opt-in and is the flag that carries the `consensus_push` marker the gateway requires). The agent-side `mcp__brc__propose` MCP tool was retired alongside this surface in [#2908](https://github.com/jwbron/egg/issues/2908) slice-6 — the CLI is the single agent surface. This structurally enforces the "all changes must be reviewed" invariant rather than relying on agent compliance. See [Gateway README — Pipeline Push Enforcement](../../gateway/README.md#pipeline-push-enforcement-brc-sessions) for details.

**Worktree-aware APIs:** All gateway APIs that access the filesystem use `map_container_path_to_worktree()` to resolve container repo paths to worktree paths. This includes git operations and contract operations (`egg-contract show`, `add-commit`, `add-decision`, etc.). The mapping is transparent to agents --- they use their normal repo path and the gateway resolves it to the correct worktree.

Expand Down
4 changes: 2 additions & 2 deletions docs/architecture/orchestrator.md
Original file line number Diff line number Diff line change
Expand Up @@ -896,7 +896,7 @@ WS7-observed 10–13 min idle ceiling on real BRC phases).

| `EGG_BRC_IDLE_BUDGET_MIN` | Behaviour |
|---------------------------|-----------|
| default `30` (minutes) | At budget threshold, wrapper emits `mcp__progress__overseer_alert` (anomaly `stuck-phase-transition`, priority `high`) **and keeps blocking**. At `2 ×` budget, the alert priority escalates and the wrapper still keeps blocking. Idleness is **not** a FAILED transition. |
| default `30` (minutes) | At budget threshold, wrapper emits an `OVERSEER_ALERT` (via `egg-orch overseer alert`, anomaly `stuck-phase-transition`, priority `high`) **and keeps blocking**. At `2 ×` budget, the alert priority escalates and the wrapper still keeps blocking. Idleness is **not** a FAILED transition. |

The slice-2/-3 era also exposed an `EGG_BRC_EVENT_PUMP=false` escape
to the legacy capped-restart wrapper; that escape is gone after
Expand Down Expand Up @@ -1334,7 +1334,7 @@ if is_orchestrator_mode():
| `EGG_ORCH_SLICE_FAILURE_GRACE_SECONDS` | Slice-DAG: grace window before failure-cascade marks downstream subtree `BLOCKED_ON_FAILED_DEPENDENCY` (#2137) | `60.0` |
| `EGG_ORCH_STACKED_PR_RECONCILER_INTERVAL_SECONDS` | Slice-DAG: stacked-PR reconciler polling cadence for orphaned child PRs (#2137) | `30.0` |
| `EGG_BRC_EVENT_PUMP` | **Removed in [#2908](https://github.com/jwbron/egg/issues/2908) slice-4 task-4-2.** During the slice-2/-3 rollout this flag selected between the legacy `_CONSENSUS_WRAPPER_TEMPLATE` (`false`) and the new `_EVENT_PUMP_WRAPPER_TEMPLATE` (`true`). Slice-4 deleted the legacy template, the surrounding selector logic, and the env var read itself — the orchestrator no longer consults this variable. Operators that referenced it in helm values / pod-spec env can drop the row. The supported regression path is `git revert` of slices 1–3 / slice-4 in reverse-merge order (see [Rollback plan](#rollback-plan)); reverting slice-4 restores the env var alongside the legacy template. | n/a (removed) |
| `EGG_BRC_IDLE_BUDGET_MIN` | BRC consensus wrapper idle / no-progress safety budget in minutes ([#2908](https://github.com/jwbron/egg/issues/2908)). Replaced the legacy 3-restart FAIL cap with an overseer-alert escalation that does not transition the pipeline to FAILED. At budget threshold the wrapper emits `mcp__progress__overseer_alert` (anomaly `stuck-phase-transition`, priority `high`) and keeps blocking; at `2 ×` budget the priority escalates and the wrapper still keeps blocking. Default 30 min is well above the WS7-observed 10–13 min idle ceiling on real BRC phases. See [Idle / no-progress safety budget](#idle--no-progress-safety-budget). | `30` |
| `EGG_BRC_IDLE_BUDGET_MIN` | BRC consensus wrapper idle / no-progress safety budget in minutes ([#2908](https://github.com/jwbron/egg/issues/2908)). Replaced the legacy 3-restart FAIL cap with an overseer-alert escalation that does not transition the pipeline to FAILED. At budget threshold the wrapper emits an `OVERSEER_ALERT` (via `egg-orch overseer alert`, anomaly `stuck-phase-transition`, priority `high`) and keeps blocking; at `2 ×` budget the priority escalates and the wrapper still keeps blocking. Default 30 min is well above the WS7-observed 10–13 min idle ceiling on real BRC phases. See [Idle / no-progress safety budget](#idle--no-progress-safety-budget). | `30` |

### Constants

Expand Down
4 changes: 2 additions & 2 deletions docs/guides/agent-teams.md
Original file line number Diff line number Diff line change
Expand Up @@ -163,7 +163,7 @@ The reasoning layer combines two complementary mechanisms with different purpose

> **Tester `checks_passed` requirement:** The Tester's attestation must include a `checks_passed` list naming every configured check that **passed** (e.g. `["lint", "test"]`). Only include checks with a clean exit — do not include checks that failed. The server validates that all checks listed in `repositories.yaml` appear in this list and rejects the proposal if any are missing. Running tests alone is not sufficient — all configured checks must pass and be reported.

> **Tester `attestation.tests_run` vs propose `tests_run`:** The `attestation.tests_run` field is an **integer count** of tests executed (e.g. `42`). This is distinct from the propose call's top-level `tests_run` argument, which is a **list of test identifiers** (e.g. `["tests/test_foo.py::test_bar"]`). Passing a list for `attestation.tests_run` (or leaving it at the default `0`) causes a validation error. The `mcp__brc__propose` handler validates tester attestation locally before sending to the orchestrator, so misconfigured payloads fail with an actionable error rather than a 400 from the server (#2338).
> **Tester `attestation.tests_run` vs propose `tests_run`:** The `attestation.tests_run` field is an **integer count** of tests executed (e.g. `42`). This is distinct from the propose call's top-level `tests_run` argument, which is a **list of test identifiers** (e.g. `["tests/test_foo.py::test_bar"]`). Passing a list for `attestation.tests_run` (or leaving it at the default `0`) causes a validation error. The `egg-orch consensus propose` handler validates tester attestation locally before sending to the orchestrator, so misconfigured payloads fail with an actionable error rather than a 400 from the server (#2338).

**Reviewer evaluations (`CONSENSUS_ACK/NACK`):**

Expand Down Expand Up @@ -238,7 +238,7 @@ When a producer pushes new commits after proposing, existing reviews become stal

This mechanism enforces the principle that **all changes must be reviewed**: post-proposal pushes cannot bypass the review process. The `check_confirm_guard()` provides a server-side blocking mechanism even if a reviewer misses the `CONSENSUS_RE_REVIEW` notification. See [Concurrent Execution — Auto Re-Propose on Push/Commit](concurrent-execution.md#auto-re-propose-on-pushcommit) for the full details.

Additionally, the gateway enforces that **direct `git push` is blocked** for pipeline sessions — agents must use `mcp__brc__propose` (or the fallback CLI `egg-orch consensus propose --push`) to bundle the push with a BRC proposal. This makes the review invariant structural rather than relying on auto-repropose detection. See [Concurrent Execution — Gateway-Level Push Enforcement](concurrent-execution.md#gateway-level-push-enforcement-pipeline-sessions) for details.
Additionally, the gateway enforces that **direct `git push` is blocked** for pipeline sessions — agents must use `egg-orch consensus propose --push` to bundle the push with a BRC proposal (the agent-side `mcp__brc__propose` MCP tool was retired alongside this surface in [#2908](https://github.com/jwbron/egg/issues/2908) slice-6 — the CLI is the single agent surface). This makes the review invariant structural rather than relying on auto-repropose detection. See [Concurrent Execution — Gateway-Level Push Enforcement](concurrent-execution.md#gateway-level-push-enforcement-pipeline-sessions) for details.

### Agent Crash Mid-Protocol

Expand Down
Loading
Loading