Files
manual_slop/conductor/tier2/commands/tier-2-auto-execute.md
T
ed 03c9df8450 fix(tier2): deny %TEMP% writes - use app-data dir for temp files
The Tier 2 agent wrote audit_exception_handling.py output to
C:\\Users\\Ed\\AppData\\Local\\Temp\\audit_initial.json via shell
redirection. This is OUTSIDE the sandbox allowlist (which is
C:\\projects\\manual_slop_tier2 + C:\\Users\\Ed\\AppData\\Local\\
manual_slop\\tier2 + C:\\Users\\Ed\\AppData\\Local\\manual_slop\\
tier2_failures). The OpenCode session-level guard fires the 'ask'
prompt for paths outside the project root, which has no answer in an
autonomous session, so ops halted mid-track.

Fix (3 layers):

1. opencode.json.fragment: add bash deny rule
   '*AppData\\Local\\Temp\\*': 'deny' to BOTH the top-level
   permission.bash (for default agents) and the tier2-autonomous
   agent's permission.bash. The agent physically cannot run shell
   commands that target the global Temp dir.

2. conductor/tier2/agents/tier2-autonomous.md: add 'Temp files'
   convention telling the agent to use
   C:\\Users\\Ed\\AppData\\Local\\manual_slop\\tier2\\ for scratch
   / audit-output / intermediate files, NOT %TEMP%.

3. conductor/tier2/commands/tier-2-auto-execute.md: same convention
   in the slash command so the agent sees it at slash-command time.

Tests (default-on):
- test_agent_denies_temp_writes: agent prompt has the Temp deny in
  frontmatter bash + the app-data dir note
- test_config_fragment_denies_temp_writes: both top-level and agent
  bash have the deny rule

All 16 tier 2 slash command tests pass.

Also: cleaned up the leaked audit_initial.json + audit.json +
audit_after*.json from %TEMP% (they were leftovers from a prior
run). Re-ran setup against the live clone; opencode.json's agent
bash and top-level bash both have the deny rule.
2026-06-17 16:13:19 -04:00

3.8 KiB

description, agent
description agent
Autonomously execute a conductor track in the Tier 2 sandbox tier2-autonomous

/tier-2-auto-execute

Run a track autonomously in the Tier 2 sandboxed mode. No permission: ask prompts.

Arguments

$ARGUMENTS - Track name (required). Examples: result_migration_review_pass, data_structure_strengthening_20260606. Optional flags: --resume (continue from last completed task), --toast (Windows toast on give-up).

Pre-flight

  1. Verify sandbox is active. This slash command must be invoked from a sandboxed OpenCode session. If manual-slop_get_ui_performance returns an error or the run_tier2_sandboxed.ps1 wrapper is not in the parent process, refuse to start.
  2. Load the track spec. Read conductor/tracks/<track-name>/spec.md and plan.md from the current branch. If the track does not exist, abort.
  3. Check for a previous run. If <app-data>/tier2/<track-name>/state.json exists AND --resume is NOT set, abort with: "Previous run found for this track. Use --resume to continue, or delete the state file to start fresh."

Protocol

  1. git fetch origin master (NOTE: this repo uses master, not main; added 2026-06-17)
  2. git switch -c tier2/<track-name> origin/master (NOT git checkout - it is banned)
  3. Initialize failcount state at <app-data>/tier2/<track-name>/state.json (use load_state or fresh state)
  4. For each task in plan.md: a. Red: delegate test creation to @tier3-worker b. Run tests via uv run python scripts/run_tests_batched.py (NEVER uv run pytest directly; the batched runner provides tier filtering, parallelization, and the summary table — added 2026-06-17) c. If pass unexpectedly, call record_red_failure and check should_give_up d. Green: delegate implementation to @tier3-worker e. Run tests via scripts/run_tests_batched.py; if fail, call record_green_failure and check should_give_up f. On green: record_commit and record_green_success (resets counters) g. Commit per task with git add <specific files> && git commit -m "..." and attach git note h. Update plan.md with commit SHA
  5. After all tasks complete, write the end-of-track report (see step 7) and print success summary.
  6. On give-up: call write_failure_report from scripts.tier2.write_report, print "TRACK ABORTED, see report at ".
  7. End-of-track report (added 2026-06-17): on success, write docs/reports/TRACK_COMPLETION_<track-name>.md following the precedent set by TRACK_COMPLETION_tier2_autonomous_sandbox_20260616.md. Update conductor/tracks/<track-name>/state.toml to status = "completed". The user reads this report to decide merge.

Conventions (MUST follow - added 2026-06-17)

  • Test runner: use uv run python scripts/run_tests_batched.py (NOT uv run pytest)
  • Default branch: master (this repo never had main)
  • Line endings: preserve existing (CRLF stays CRLF, LF stays LF)
  • Throw-away scripts: write to scripts/tier2/artifacts/<track-name>/, NOT the base directory
  • Run-time expectation: tracks are 1-4 hours. If context runs out, note progress to disk and continue.
  • Temp files (added 2026-06-17): NEVER write to C:\Users\Ed\AppData\Local\Temp\ or %TEMP%. Use C:\Users\Ed\AppData\Local\manual_slop\tier2\ for scratch / audit-output / intermediate files. The bash deny *AppData\Local\Temp\* will block writes; the OpenCode session's outer guard will fire the "ask" prompt for reads — both halt autonomous ops.

Hard Bans (enforced by 3 layers)

  • git restore* (any form) — denied
  • git push* (any push) — denied
  • git checkout* (any form) — denied; use git switch instead
  • git reset* (any form) — denied

Filesystem access is restricted to the Tier 2 clone + <app-data>/manual_slop/tier2/. The Windows restricted token blocks reads/writes outside these paths at the OS level.