Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,7 @@ Worktrees are fresh checkouts. Document dependency/environment initialization an
- `Depends on:` is a DAG. Open dependencies outside the candidate set block the issue. Dependencies inside the set create scheduling edges, but a downstream worker still waits for the dependency issue to close and land on the default branch; PR + CI success alone is not a merge substitute.
- High-overlap changes are serialized with the same merge barrier. If independence cannot be established, show the uncertain path estimate before implementation and ask the user whether to serialize or exclude.
- Multiple-issue concurrency defaults to 3 and is capped by the user's value, runtime limit, and currently independent Ready issue count. A failed worker blocks only its dependents; unrelated workers continue.
- Codex CLI write workers use `codex exec --approve-for-me --worktree`; `--approve-for-me` runs the worker in `workspace-write` and routes sandbox-boundary approval requests to Auto-review. Git metadata mutations such as `fetch`, `switch`, `add`, `commit`, and `push` are requested from their first attempt as narrowly scoped escalations for one exact command at a time. If Auto-review is unavailable, denied, or times out, the worker is blocked; it does not retry with broader permissions, writable-root additions, `--add-dir`, or manual worktree fallbacks. IssueKit does not choose the worktree path or manage its Git metadata / cleanup.
- Codex CLI write workers use `codex exec --approve-for-me --worktree`; `--approve-for-me` runs the worker in `workspace-write` and routes sandbox-boundary approval requests to Auto-review. Git metadata mutations such as `fetch`, `switch`, `add`, `commit`, and `push` are requested from their first attempt as narrowly scoped escalations for one exact command at a time. For Codex `cross-review`, the diff is generated in a 0600 temporary file inside the worker sandbox; only the nested reviewer process launch is requested as one exact escalation, and the child remains fixed to `--ask-for-approval never` + `--sandbox read-only`. If Auto-review is unavailable, denied, or times out, the worker is blocked; it does not retry with broader permissions, another reviewer backend, writable-root additions, `--add-dir`, or manual worktree fallbacks. IssueKit does not choose the worktree path or manage its Git metadata / cleanup.
- Current Codex native subagents may be used for read-only analysis, but not parallel writes unless the runtime explicitly guarantees a dedicated cwd / worktree per worker. Claude Code write workers use `isolation: worktree`, Agent view isolation, or an equivalent official primitive; non-isolated Agent teams are not used.
- Codex App top-level Worktree chats and Handoff remain App-owned. When the surface cannot guarantee automated per-issue worktrees, return the plan and launch prompts; do not automate the UI.
- The parent waits for every worker to succeed, fail, block, or remain waiting, then aggregates issue number, state, branch, PR URL, CI, and blocker. It never auto-merges or auto-cleans worker state.
Expand All @@ -106,7 +106,7 @@ Worktrees are fresh checkouts. Document dependency/environment initialization an

`cross-review` is defined as a second-opinion review from an independent reviewer session, not as a guarantee that a different backend or different model is used.

- Codex runtime uses Codex CLI (`codex exec --sandbox read-only` with stdin diff pipe) to start a fresh reviewer session.
- Codex runtime uses Codex CLI (`codex --ask-for-approval never exec --sandbox read-only` with diff supplied through stdin) to start a fresh reviewer session. Inside a Codex managed worker, diff generation stays inside the worker sandbox and only the reviewer process launch crosses the outer boundary through exact-command Auto-review; the child process remains non-interactive and read-only, so it cannot request an escalation. A denial, timeout, or launch failure is a blocker without permission broadening or implicit fallback.
- Claude Code runtime uses Claude CLI headless (`claude -p` with stdin diff) to start a fresh reviewer session.

The runtime must be determined from the running agent's explicit environment, not inferred from whichever CLI exists on `PATH`. Environment-variable backend overrides and auto-detection fallback are intentionally not part of the workflow. If a different backend / different model review is needed, track that as a separate issue instead of keeping it inside `cross-review`.
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,7 @@ Before `issue-implement` writes files or commits, it classifies the current loca

| Runtime | Isolation contract on the default branch |
| --- | --- |
| Codex CLI | A single `issue-implement` request on the default branch hands the issue to `issue-dispatch`. The parent starts one non-interactive worker with [`codex exec --approve-for-me --worktree`](https://developers.openai.com/codex/cli/reference), without migrating its own cwd. `--approve-for-me` runs the worker in `workspace-write` and routes sandbox-boundary approval requests to Auto-review; Codex owns the managed worktree path and lifecycle; the worker verifies isolation and establishes its expected issue branch before editing. |
| Codex CLI | A single `issue-implement` request on the default branch hands the issue to `issue-dispatch`. The parent starts one non-interactive worker with [`codex exec --approve-for-me --worktree`](https://developers.openai.com/codex/cli/reference), without migrating its own cwd. `--approve-for-me` runs the worker in `workspace-write` and routes sandbox-boundary approval requests to Auto-review; Codex owns the managed worktree path and lifecycle; the worker verifies isolation and establishes its expected issue branch before editing. Git metadata mutations and the nested Codex `cross-review` process launch require exact-command Auto-review approval. Cross-review diff generation stays inside the worker sandbox, and the child reviewer uses `--ask-for-approval never` + `--sandbox read-only`, so it cannot request an escalation. |
| Codex App | Start the chat in an App-managed **Worktree**, or use **Handoff** from Local to Worktree. These are App-owned features; issuekit does not create or control managed worktrees. See [Codex Worktrees](https://learn.chatgpt.com/docs/environments/git-worktrees). |
| Claude Code CLI | Start isolated with `claude --worktree <name>`, or let `worktree-start` use `EnterWorktree` from an interactive session. See [Claude Code worktrees](https://code.claude.com/docs/en/worktrees). |
| Claude Code subagent | Set `isolation: worktree` in the agent frontmatter or spawn configuration. See [Claude Code subagents](https://code.claude.com/docs/en/sub-agents). |
Expand All @@ -138,7 +138,7 @@ Multiple-issue runs default to three concurrent workers. The effective limit is

Runtime behavior is deliberately asymmetric:

- **Codex CLI:** the parent launches one `codex exec --approve-for-me --worktree` worker per issue. `--approve-for-me` runs the worker in `workspace-write` and routes sandbox-boundary approval requests to Auto-review. Each Git metadata mutation is requested from its first attempt as a narrowly scoped escalation for one exact command. If Auto-review is unavailable, denied, or times out, the worker is blocked without broadening permissions or falling back to writable-root additions, `--add-dir`, or manual worktrees. Codex owns worktree creation and lifecycle. Each prompt carries the issue, dedicated-worker assignment, expected branch, and `issue-implement <N>` instruction; the worker verifies the linked worktree, establishes the branch before editing, and continues through PR and CI.
- **Codex CLI:** the parent launches one `codex exec --approve-for-me --worktree` worker per issue. `--approve-for-me` runs the worker in `workspace-write` and routes sandbox-boundary approval requests to Auto-review. Each Git metadata mutation is requested from its first attempt as a narrowly scoped escalation for one exact command. For nested Codex `cross-review`, diff generation stays inside the worker sandbox in a 0600 temporary file and only the reviewer process launch is requested as one exact escalation; the child stays fixed to `--ask-for-approval never` + `--sandbox read-only`. If either approval is unavailable, denied, times out, or the approved command fails, the worker is blocked without broadening permissions, switching reviewer backends, or falling back to writable-root additions, `--add-dir`, or manual worktrees. Codex owns worktree creation and lifecycle. Each prompt carries the issue, dedicated-worker assignment, expected branch, and `issue-implement <N>` instruction; the worker verifies the linked worktree, establishes the branch before editing, and continues through PR and CI.
- **Claude Code:** use a subagent with `isolation: worktree`, Agent view's worktree-isolated background session, or an equivalent official isolation primitive. Do not use non-isolated Agent teams for write workers.
- **Codex App:** top-level Worktree chats and Handoff are App-owned. When the current surface cannot create one isolated chat per issue, the skill returns the worktree plan and per-issue launch prompts instead of automating the UI.

Expand Down
Loading
Loading