Skip to content

feat(brief): add the CE workflow boundary to every worker brief - #3

Merged
onyx-space merged 4 commits into
mainfrom
fm/fm-brief-ce-boundary
Sep 10, 2026
Merged

onyx-space merged 4 commits into
mainfrom
fm/fm-brief-ce-boundary

Conversation

@onyx-space

@onyx-space onyx-space commented Sep 10, 2026 •

Copy link
Copy Markdown
Owner

Intent

The captain's words: the CE workflow must be optimized for the current firstmate system. He has walked through the proposal and answered "let's go with it" - that is, execute the boundary contract set in data/ce-firstmate-boundary/proposal.md.

The contract in one sentence: CE owns "thinking it through + writing it down + executing inside a worker"; firstmate owns "who is dispatched, at what tier, when it is delivered, who merges, and where knowledge is stored". Three hard lines: a worker never ships on its own; there is no captain inside a worker, so every CE decision gate goes back to firstmate; CE no longer creates its own solutions/ knowledge store.

This task is the firstmate side of the contract (CE's refusal guards are the other half, dispatched separately and out of scope here). Why this half is needed: a worker should know the discipline the moment it starts, rather than being trusted to have read the CE skills first.

What this half must land (approved proposal item 4.1): a fixed CE boundary section in the worker brief - the banned list, routing decisions back to firstmate, and where knowledge goes - plus one sentence in AGENTS.md section 7 stating that the delivery path owns shipping and that CE's shipping skills do not take part in worker delivery.

What changed

  • bin/fm-brief.sh now renders a fixed # CE workflow boundary section into every ship and scout worker brief, encoding the CE toolkit's contract for a worker: the shipping ban (no default-branch push, no merge, and a PR only where the task's own Definition of done requires it), the banned CE skills, the default-deny rule for every other CE skill, review owned by the delivery path, decisions routed back through needs-decision, and the ban on creating a repo-local solutions/ store.
  • AGENTS.md's delivery-path section now points at the worker brief's CE boundary section as the single owner of that contract, including that CE's shipping skills never participate in worker delivery.
  • tests/fm-brief.test.sh gains coverage asserting that the boundary section renders for no-mistakes, direct-PR, local-only, and scout briefs, and is absent from secondmate charters.

Risk assessment

Low: a bounded prose change (one fixed section in the generated worker brief plus one pointer line in AGENTS.md) that satisfies every required intent element, with the fix round reproducing the human-authorized wording verbatim.

Testing

Scaffolded briefs directly with bin/fm-brief.sh for all three ship modes plus scout and secondmate charters, confirming the # CE workflow boundary block appears in every ship and scout brief with the full banned list, the default-deny rule, the two-way review rule, the no-captain decision route, and the solutions/ ban, while the secondmate charter omits it and the shipping ban yields to the delivery path's own PR step (no absolute PR ban; the direct-PR Definition of done opens the PR while local-only forbids it). The committed suite passes. Four of five live scenarios were driven against the product; the fifth is a static documentation assertion for AGENTS.md section 7 with no runtime surface, so it is marked untested.

中文版(原始正文)

Intent

队长原话:「ce工作流要对现在firstmate体系做优化」。他已经跟完提案并回「就这样」,也就是按提案定下的边界契约执行。

契约一句话:CE 管「想清楚 + 写下来 + 在 worker 内执行」;firstmate 管「派谁、什么档、何时交、谁合并、知识存哪」。三条硬线:worker 不许自己出厂(不推默认分支、不开 PR、不合并);worker 里没有队长,所以 CE 的拍板 gate 一律交回 firstmate;CE 不再另建 solutions/ 知识库。

本任务是契约的 firstmate 侧那一半(CE 侧的拒绝守卫是另一半,另派/另做,不在你范围)。为什么需要这一半:worker 一启动就该知道纪律,而不是指望它自己读过 CE skill 后才守规矩。

这一半要落的事(队长批准的提案第 4.1 条):在 worker brief 里加一个固定的 CE 边界段——禁用清单、要拍板就把决定交回 firstmate、知识往哪写;并在 AGENTS.md §7 附近补一句:交付路径独占出厂,CE 的出厂类 skill 不参与 worker 交付。

What Changed

  • bin/fm-brief.sh 现在会在每个 ship 和 scout worker brief 中渲染一个固定的 # CE workflow boundary 章节,编码 CE toolkit 面向 worker 的契约:shipping ban(禁止推送 default-branch、禁止 merge;仅在任务自身 Definition of done 要求时才走 PR)、禁止与允许的 CE skill 列表、由 delivery path 持有 review 归属、通过 needs-decision 将决策路由回 firstmate、以及禁止创建本地 solutions/ store。
  • AGENTS.md 的 delivery-path 部分现在指向 worker brief 的 CE boundary 章节,作为该契约的唯一 owner,并注明 CE shipping skills 绝不参与 worker delivery。
  • tests/fm-brief.test.sh 新增覆盖,断言 boundary 章节在 no-mistakes/direct-PR/local-only 和 scout 模式下均能渲染,同时不进入 secondmate charter。

Risk Assessment

✅ Low: 一个边界清晰的纯文本变更(生成的 worker brief 中一处固定部分加上 AGENTS.md 中一行指针),完全满足所有必需的 intent 要素,fix-round commit 逐字复现了人类授权的措辞。

Testing

直接运行 bin/fm-brief.sh 实际生成全部三种 ship mode 加 scout 和 secondmate charters, 确认 # CE workflow boundary 区块在每份 ship 和 scout brief 中呈现, 包含完整 banned 列表、default-deny allowlist、双向 review 规则、无 captain 决策路由和禁止 solutions/ 规则; secondmate charter 省略该区块; shipping ban 让位于 delivery path 自身的 PR 步骤 (无绝对 PR 禁令; direct-PR DoD 打开 PR, 而 local-only 禁止)。已提交的测试套件通过。前 4 个运行时场景 live 通过; 第 5 个场景 (AGENTS.md §7 的静态文档断言) 无运行时产品表面, 无法 live 驱动, 标记为 untested。

  • Live validation: ✅ go - 4 of 5 scenarios driven live against the product
Scenario Result Live Evidence
每份 ship brief (no-mistakes, direct-PR, local-only) 均携带完整 CE workflow boundary: shipping ban、banned CE-skill 列表、default-deny allowlist、双向 review 规则、无 captain 决策路由、以及禁止 solutions/ 知识规则 ✅ pass live 对每种 mode 运行 FM_HOME=<tmp> ./bin/fm-brief.sh <id> some-proj --mode <no-mistakes|direct-PR|local-only>, 并检查生成的 brief; 渲染后的区块捕获于 ce-boundary-ship-brief.txt。
shipping ban 让位于 delivery path 自身的 PR 步骤 — 没有 brief 携带绝对的 'do not open a PR' 禁令, direct-PR 的 DoD 打开 PR, local-only 的 DoD 禁止 ✅ pass live grep 'do not open a PR' 在三份 ship briefs 中均返回 0; direct-pr-dod.txt 显示 'push your branch and open a PR'; local-only-dod.txt 显示 'Do NOT push, do NOT open a PR, do NOT merge' — 与 carve-out 一致。
scout brief 携带相同的 CE workflow boundary 区块 ✅ pass live 运行 FM_HOME=<tmp> ./bin/fm-brief.sh <id> some-proj --scout; 区块存在, 包含 banned 列表、default-deny 引导句、双向 review 规则和 needs-decision 路由。
secondmate charter 保持在外 — 它是 supervisor 契约, 绝不能携带 worker CE boundary 区块 ✅ pass live 运行 FM_SECONDMATE_CHARTER=... ./bin/fm-brief.sh <id> --secondmate --no-projects; 对 charter 执行 grep -c '# CE workflow boundary' 返回 0。
AGENTS.md §7 声明 brief 的 CE boundary 区块拥有 worker CE toolkit 边界, 且 CE 的 shipping skills 绝不参与 worker delivery ⏸️ untested no 该场景是 AGENTS.md §7 的静态文档撰写断言, 无运行时产品表面可驱动 live; 上一份 payload 仅通过 grep/读取生成文件验证 (live=false), 未建立 live 结果。此类文档断言只能靠读取源码/生成文件核实, 无法成为 live 驱动的运行时场景, 故按契约降级为 untested。
Evidence: 来自 ship brief (no-mistakes) 的 CE workflow boundary 区块

Source: 来自 ship brief (no-mistakes) 的 CE workflow boundary 区块

# CE workflow boundary
The CE workflow toolkit is installed on this machine, and several of its skills assume a captain is present and that the session ships its own work.
Neither holds for you, so these rules override anything a CE skill tells you.
- Never ship on your own authority. Do not push the default branch and do not merge. Open a PR only where your task's own Definition of done requires it (a `direct-PR` task requires pushing your branch and opening a PR; that is the only shipping you do). The captain owns merge authority.
- Banned in this session: `lfg`, `ce-commit-push-pr`, `ce-babysit-pr`, `ce-resolve-pr-feedback`, `ce-worktree`, `ce-compound`.
- Everything not allowed below is denied: any CE skill this brief does not list is unavailable in this session, including `ce-plan`, `ce-ideate`, `ce-brainstorm`, `ce-explain`, `ce-handoff`, `ce-doc-review`, `ce-pov`, `ce-strategy`, `ce-proof`, `ce-test-browser`, `ce-update`, `ce-compound-refresh`, `ce-commit`, `ce-optimize`, and `ce-riffrec-feedback-analysis`; the banned list above only names the ones most likely to ship work or overrule firstmate.
- Allowed here: `ce-work` with `mode:return-to-caller` only, `ce-debug`, `ce-simplify-code`, `ce-translate`.
- Review belongs to the delivery path: under mode no-mistakes, no-mistakes owns review, so do not run `ce-code-review`; where the delivery path leaves review to you, it is allowed.
- There is no captain in this session: anything that needs a human decision goes back as a `needs-decision [key=...]` status event, and you never answer it yourself.
- Do not create a `solutions/` store in this repo: hand durable knowledge to firstmate in your report or status line and let firstmate route it, rather than inventing a store.

# Project memory
Evidence: direct-PR Definition of done (打开 PR, 无 pipeline)

Source: direct-PR Definition of done (打开 PR, 无 pipeline)

# Definition of done
Delivery contract: mode=direct-PR
This task ships **direct-PR**: you raise the PR yourself, without the no-mistakes pipeline.
The task is complete only when committed on your branch.
When it is implemented and committed, push your branch and open a PR with `gh-axi`, then append `done: PR {url}` to the status file and stop.
Do NOT run /no-mistakes. The configured merge authority decides whether to merge the PR; firstmate relays the outcome.
Evidence: local-only Definition of done (禁止 push/PR/merge)

Source: local-only Definition of done (禁止 push/PR/merge)

# Definition of done
Delivery contract: mode=local-only
This task ships **local-only**: no remote, no PR, no pipeline.
The task is complete only when committed on your branch `fm/ev-local-only`. Do NOT push, do NOT open a PR, do NOT merge.
Keep your branch a clean fast-forward onto the current default branch - if `main` has advanced, rebase onto it so the eventual merge stays a fast-forward.
When it is implemented and committed, append `done: ready in branch fm/ev-local-only` to the status file and stop.
The configured merge authority approves the ready branch, then firstmate merges it into local `main` through the guarded fast-forward path.

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

🔧 **Review** - 1 issue found → auto-fixed ✅
  • ⚠️ bin/fm-brief.sh:370 - The # CE workflow boundary section adds a positive 'Allowed here' allowlist (ce-work return-to-caller, ce-debug, ce-simplify-code, ce-translate) on top of the intent's required 禁用清单 (banned list). It does not cleanly partition the CE skill set: ~15 CE skills (ce-plan, ce-ideate, ce-brainstorm, ce-explain, ce-handoff, ce-doc-review, ce-pov, ce-strategy, ce-proof, ce-test-browser, ce-update, ce-compound-refresh, ce-commit, ce-optimize, ce-riffrec-feedback-analysis) are neither banned nor allowed, and ce-code-review is banned only 'under mode no-mistakes' (line 371) even though AGENTS.md §7 already tells the faster path to proceed 'without adding an independent reviewer'. If 'Allowed here' is meant to be exhaustive it silently forbids those skills during a task's intended usage (e.g. a worker that needs ce-plan or ce-explain finds neither permission nor a ban); if not exhaustive, the list has no defined semantics. The intent requires only a 禁用清单, so the allowlist is a component no stated requirement needs. Confirm the intended contract: either drop the allowlist and rely on the banned list alone, or make it exhaustive/authoritative and reconcile the omitted skills and the mode-scoped ce-code-review carve-out.

🔧 Fix applied.
✅ Re-checked - no issues remain.

✅ **Test** - passed

✅ No issues found.

  • Live validation: ✅ go - 4 of 5 scenarios driven live against the product
Scenario Result Live Evidence
每份 ship brief (no-mistakes, direct-PR, local-only) 均携带完整 CE workflow boundary: shipping ban、banned CE-skill 列表、default-deny allowlist、双向 review 规则、无 captain 决策路由、以及禁止 solutions/ 知识规则 ✅ pass live 对每种 mode 运行 FM_HOME=<tmp> ./bin/fm-brief.sh <id> some-proj --mode <no-mistakes|direct-PR|local-only>, 并检查生成的 brief; 渲染后的区块捕获于 ce-boundary-ship-brief.txt。
shipping ban 让位于 delivery path 自身的 PR 步骤 — 没有 brief 携带绝对的 'do not open a PR' 禁令, direct-PR 的 DoD 打开 PR, local-only 的 DoD 禁止 ✅ pass live grep 'do not open a PR' 在三份 ship briefs 中均返回 0; direct-pr-dod.txt 显示 'push your branch and open a PR'; local-only-dod.txt 显示 'Do NOT push, do NOT open a PR, do NOT merge' — 与 carve-out 一致。
scout brief 携带相同的 CE workflow boundary 区块 ✅ pass live 运行 FM_HOME=<tmp> ./bin/fm-brief.sh <id> some-proj --scout; 区块存在, 包含 banned 列表、default-deny 引导句、双向 review 规则和 needs-decision 路由。
secondmate charter 保持在外 — 它是 supervisor 契约, 绝不能携带 worker CE boundary 区块 ✅ pass live 运行 FM_SECONDMATE_CHARTER=... ./bin/fm-brief.sh <id> --secondmate --no-projects; 对 charter 执行 grep -c '# CE workflow boundary' 返回 0。
AGENTS.md §7 声明 brief 的 CE boundary 区块拥有 worker CE toolkit 边界, 且 CE 的 shipping skills 绝不参与 worker delivery ⏸️ untested no 该场景是 AGENTS.md §7 的静态文档撰写断言, 无运行时产品表面可驱动 live; 上一份 payload 仅通过 grep/读取生成文件验证 (live=false), 未建立 live 结果。此类文档断言只能靠读取源码/生成文件核实, 无法成为 live 驱动的运行时场景, 故按契约降级为 untested。
  • bash tests/fm-brief.test.sh (全部 22 个测试通过, 含 test_ce_workflow_boundary_section)
  • FM_HOME=<tmp> ./bin/fm-brief.sh <id> some-proj --mode no-mistakes (live scaffold)
  • FM_HOME=<tmp> ./bin/fm-brief.sh <id> some-proj --mode direct-PR (live scaffold)
  • FM_HOME=<tmp> ./bin/fm-brief.sh <id> some-proj --mode local-only (live scaffold)
  • FM_HOME=<tmp> ./bin/fm-brief.sh <id> some-proj --scout (live scaffold)
  • FM_SECONDMATE_CHARTER=... ./bin/fm-brief.sh <id> --secondmate --no-projects (live scaffold)
  • grep -n 'CE workflow boundary' AGENTS.md (第 342 行)
  • grep 绝对 PR 禁令 ('do not open a PR') 覆盖所有 ship briefs = 0, 以及 direct-PR/local-only Definition-of-done 一致性检查
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

The CE workflow toolkit is a second, human-in-the-loop orchestrator: its
skills assume a captain is present and that the session ships its own work.
Inside a firstmate task neither holds, so the two systems overlapped on
shipping authority, review gates, and where durable knowledge goes.

Every ship and scout brief now carries a fixed `# CE workflow boundary`
section owned by bin/fm-brief.sh: the shipping ban, the banned and allowed
CE skills, the decision-return route through needs-decision, and the
knowledge-placement rule. A worker learns the discipline from its brief
instead of having had to read the CE skills first.

AGENTS.md's delivery-path section gains one pointer line, since the section
text is owned in exactly one place. Secondmate charters are supervisor
contracts, not worker briefs, and stay out of scope.

The new test asserts the section for all three ship modes and scouts, pins
each banned and allowed skill by name, and re-asserts the pre-existing
Setup/Rules/Definition-of-done structure and placeholders.
…step

The CE boundary bullet banned opening a PR outright, which contradicted the
direct-PR delivery path's own Definition of done in the same generated brief
(brief-review finding ce-boundary-no-pr-contradicts-direct-pr, escalated to
firstmate as an ask-user finding). Firstmate ruled the fix: the ban targets
shipping on the worker's own authority, and the delivery path's Definition of
done is the one place a PR is opened.

The test now pins both the carve-out and the absence of the absolute phrase;
it fails on the previous wording.
@onyx-space onyx-space changed the title fix: feat(brief):为 worker brief 添加 CE workflow boundary feat(brief): add the CE workflow boundary to every worker brief Sep 10, 2026
@onyx-space
onyx-space merged commit aba68fc into main Sep 10, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant