diff --git a/.gitea/workflows/agent.yml b/.gitea/workflows/agent.yml index aff171e..4400e85 100644 --- a/.gitea/workflows/agent.yml +++ b/.gitea/workflows/agent.yml @@ -104,7 +104,7 @@ jobs: fi fi - # --- Autopilot gate: read the `fully-automatic` label FRESH every run. --- + # --- Autopilot gate: read the `auto` label FRESH every run. --- # Presence of this label is the opt-in switch (and the kill switch: remove it mid-flight # and the next run reverts to normal human-approval behavior). When @qa is triggered on a # PR thread, the label lives on the ORIGIN issue (ai/issue-N), so resolve N from the branch. @@ -113,10 +113,10 @@ jobs: [ -z "$issnum" ] && issnum="$NUM" autopilot=false if curl -sS -H "Authorization: token $GT" "$API/issues/$issnum/labels" 2>/dev/null \ - | jq -e 'any(.[]?; .name=="fully-automatic")' >/dev/null 2>&1; then + | jq -e 'any(.[]?; .name=="auto")' >/dev/null 2>&1; then autopilot=true fi - echo "autopilot (fully-automatic label on #$issnum)=$autopilot" + echo "autopilot (auto label on #$issnum)=$autopilot" { echo "autopilot=$autopilot"; echo "issnum=$issnum"; } >> "$GITHUB_OUTPUT" - name: Install opencode + provider config (+ Playwright MCP for browser agents) @@ -458,7 +458,7 @@ jobs: does NOT auto-start any dev — the maintainer @mentions an agent on each sub-issue when ready." if [ "$AUTOPILOT" = "true" ]; then ACTION="$ACTION - AUTOPILOT MODE IS ACTIVE (this issue carries the 'fully-automatic' label). This OVERRIDES the + AUTOPILOT MODE IS ACTIVE (this issue carries the 'auto' label). This OVERRIDES the two-phase approval gate above: do NOT ask '@ffaerber ready to start building?' and do NOT wait for a 'yes'. When the task is clear, present your SHORT plan naming the best teammate to build it AND end your reply with a 'DELEGATE: @' line in the SAME turn to hand off immediately. @@ -474,14 +474,14 @@ jobs: a human does that." if [ "$AUTOPILOT" = "true" ]; then ACTION="$ACTION - AUTOPILOT MODE IS ACTIVE (this issue/PR carries the 'fully-automatic' label). This grants you a + AUTOPILOT MODE IS ACTIVE (this issue/PR carries the 'auto' label). This grants you a NARROW, one-time merge authority for THIS PR only: - If, after verifying, the PR is correct and any CI checks are green, end your reply with EXACTLY one line: 'MERGE_PR'. The automation will then merge the PR and close the linked issue for you. Do NOT merge via any other means; only the MERGE_PR marker triggers the merge. - If you find ANY bug, doubt, or the change is not clearly correct, do NOT merge. Instead describe the problem clearly and end your reply with EXACTLY one line: 'HALT_AUTOPILOT'. The automation - removes the 'fully-automatic' label (returning this issue to normal human control) and leaves + removes the 'auto' label (returning this issue to normal human control) and leaves it for @ffaerber to decide next steps. Never auto-bounce back to a dev. Emit AT MOST one of MERGE_PR or HALT_AUTOPILOT, and only after you have actually verified. When in doubt, prefer HALT_AUTOPILOT." @@ -603,18 +603,18 @@ jobs: hdr=(-H "Authorization: token $TOK" -H "Content-Type: application/json") post() { curl -sS -w 'comment -> HTTP %{http_code}\n' -X POST "${hdr[@]}" \ "$API/issues/$NUM/comments" -d "$(jq -nc --arg b "$1" '{body:$b}')"; } - # Remove the 'fully-automatic' label from an issue by resolving its ID first (Gitea's + # Remove the 'auto' label from an issue by resolving its ID first (Gitea's # DELETE label endpoint is by ID, not name). Arg $1 = issue number. del_autopilot_label() { local iss="$1" local lid lid=$(curl -sS "${hdr[@]}" "$API/issues/$iss/labels" 2>/dev/null \ - | jq -r 'if type=="array" then ([.[]|select(.name=="fully-automatic")][0].id // empty) else empty end') + | jq -r 'if type=="array" then ([.[]|select(.name=="auto")][0].id // empty) else empty end') if [ -n "$lid" ]; then curl -sS -X DELETE "${hdr[@]}" "$API/issues/$iss/labels/$lid" \ -w '\nunlabel -> HTTP %{http_code}\n' || true else - echo "no 'fully-automatic' label found on #$iss to remove" + echo "no 'auto' label found on #$iss to remove" fi } @@ -651,7 +651,7 @@ jobs: fi # --- AUTOPILOT: @qa's narrow, label-gated merge / halt authority --- - # Only @qa, only when 'fully-automatic' is set, and only on a PR thread. The MERGE_PR / + # Only @qa, only when 'auto' is set, and only on a PR thread. The MERGE_PR / # HALT_AUTOPILOT markers come from the QA prompt. Merge uses TOKEN_QA (the QA user's PAT, # which the maintainer must grant write+merge scope); label removal uses it too. if [ "$NAME" = "qa" ] && [ "$AUTOPILOT" = "true" ]; then @@ -674,14 +674,14 @@ jobs: # Merge failed (checks not green, conflicts, or TOKEN_QA lacks merge scope) — do # NOT silently proceed: drop the label so it reverts to human control and report. del_autopilot_label "${ISSNUM:-$NUM}" - post "$(printf '🤖 **@qa** — ⚠️ tried to merge PR #%s but the API returned HTTP %s (checks not green, a conflict, or missing merge permission on TOKEN_QA). Removed the `fully-automatic` label — @ffaerber please take a look.' "$NUM" "$mc")" + post "$(printf '🤖 **@qa** — ⚠️ tried to merge PR #%s but the API returned HTTP %s (checks not green, a conflict, or missing merge permission on TOKEN_QA). Removed the `auto` label — @ffaerber please take a look.' "$NUM" "$mc")" ;; esac fi elif grep -qiE '^[[:space:]]*HALT_AUTOPILOT[[:space:]]*$' /tmp/agent_out.md; then - echo "@qa autopilot: HALT — removing 'fully-automatic' label from #${ISSNUM:-$NUM}" + echo "@qa autopilot: HALT — removing 'auto' label from #${ISSNUM:-$NUM}" del_autopilot_label "${ISSNUM:-$NUM}" - post "$(printf '🤖 **@qa** — 🛑 found a problem, so I did NOT merge. Removed the `fully-automatic` label (back to human control). @ffaerber please decide next steps (details above).')" + post "$(printf '🤖 **@qa** — 🛑 found a problem, so I did NOT merge. Removed the `auto` label (back to human control). @ffaerber please decide next steps (details above).')" fi fi # BREAKDOWN: from a BEGIN_SUBTASKS block, create a milestone + one sub-issue per line @@ -795,7 +795,7 @@ jobs: echo "autopilot: auto-triggering @qa to review PR #$prnum" curl -sS -X POST -H "Authorization: token $AGENT_TOKEN" -H "Content-Type: application/json" \ "$API/issues/$prnum/comments" \ - -d "$(jq -nc --arg b "@qa please verify this PR (autopilot: issue #$NUM is labeled fully-automatic). Merge it if correct, or halt and remove the label if you find a problem." '{body:$b}')" \ + -d "$(jq -nc --arg b "@qa please verify this PR (autopilot: issue #$NUM is labeled auto). Merge it if correct, or halt and remove the label if you find a problem." '{body:$b}')" \ -w '\ntrigger-qa -> HTTP %{http_code}\n' || true fi else diff --git a/AGENTS.md b/AGENTS.md index 1a37452..2fd54af 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -12,21 +12,21 @@ the loop guards. - You may edit **any file**. **NEVER push to `main`, NEVER merge a PR** — all work goes on a branch and becomes a PR a human reviews and merges. - **Narrow exception — `@qa` autopilot merge:** `@qa` (and only `@qa`) MAY merge a single PR **only** - when the linked issue carries the `fully-automatic` label, the PR is clearly correct, and any CI + when the linked issue carries the `auto` label, the PR is clearly correct, and any CI checks are green. `@qa` triggers the merge by ending its reply with the `MERGE_PR` marker (the workflow performs the merge + closes the issue). On **any** doubt or bug, `@qa` must NOT merge: - it ends with `HALT_AUTOPILOT` instead, which removes the `fully-automatic` label and returns the + it ends with `HALT_AUTOPILOT` instead, which removes the `auto` label and returns the issue to human control. No other agent may merge, and `@qa` may not merge without the label. - **Never print, exfiltrate, or invent secret values.** - Keep changes **minimal** and match the conventions already in the file you're editing. - Do the work on a **branch** — never paste code or diffs into the issue thread. -## Autopilot (`fully-automatic` label) -An issue labeled **`fully-automatic`** runs without the usual human checkpoints: +## Autopilot (`auto` label) +An issue labeled **`auto`** runs without the usual human checkpoints: - `@pm` plans **and** delegates in the same turn (skips the "ready to build? reply yes" gate). - After the dev's PR is opened, `@qa` is auto-triggered to verify it, and merges + closes on success (see the QA merge exception above). -- **Kill switch:** remove the `fully-automatic` label at any time. The label is re-read fresh at the +- **Kill switch:** remove the `auto` label at any time. The label is re-read fresh at the start of every run, so the next agent turn reverts to normal human-approval behavior. `@qa` also removes the label itself whenever it halts on a bug or a failed merge. No label (the default) = today's behavior, unchanged.