self-development: add review-derived agent conventions - #1249
Open
kelos-bot[bot] wants to merge 40 commits into
Open
kelos-bot[bot] wants to merge 40 commits into
kelos-bot[bot] wants to merge 40 commits into
Conversation
kelos-bot
Bot
force-pushed
the
kelos-config-update-latest
branch
from
July 15, 2026 18:06
09c630c to
33e9563
Compare
kelos-bot
Bot
force-pushed
the
kelos-config-update-latest
branch
from
July 27, 2026 18:10
33e9563 to
446a4b3
Compare
kelos-bot
Bot
force-pushed
the
kelos-config-update-latest
branch
7 times, most recently
from
August 14, 2026 18:10
0a910f5 to
8d4d143
Compare
kelos-bot
Bot
force-pushed
the
kelos-config-update-latest
branch
from
August 15, 2026 18:10
8d4d143 to
db0c2c7
Compare
Roving tabindex removes inactive controls from sequential focus, so custom tablists and menus need explicit Arrow and Home/End navigation. Extend the existing focus-restoration rule to cover the complete keyboard interaction model and browser-level navigation tests.
kelos-bot
Bot
force-pushed
the
kelos-config-update-latest
branch
from
September 24, 2026 18:06
0997f47 to
f7e5c53
Compare
Broaden the lease-refresh rule in AGENTS.md and the Kelos development AgentConfig to cover every best-effort enhancement: a failed added lookup, optional-view inspection, or heartbeat degrades only that enhancement with a logged, visible diagnostic and a later retry, instead of aborting startup or discarding a primary result. Invalid configuration and required writes remain fail-fast. Add the matching check to the Kelos reviewer so it weighs this case against the existing fail-fast check. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviews on three Session runtime and controller changes found waits and lifecycle gates with no guaranteed exit: an interaction's ready channel left open so interrupts stalled until timeout, forced interruption that waited unboundedly on a provider ignoring cancellation, a non-deadline interrupt error that left a draining Session interrupting, a recreated RoleBinding that revoked the access a drain needed, and background or housekeeping tasks that kept a Session active and blocked idle and update drains. Require waiters to be released on every exit path, bounded waits with escalation for external work, gates only on signals that terminate, and tests for failed, canceled, and never-finishing work. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviews of the Console background-task indicator found live runtime state that outlived the runtime it described: the background-task count stayed visible after the Session was suspended, and resuming restarted the elapsed-time timer for a turn from the stopped runtime before fresh runtime events arrived. Extend the UI lifecycle rule in AGENTS.md and the Kelos development AgentConfig to cover live runtime activity such as progress indicators and Session suspension/resume. Runtime-derived state must be cleared in current and cached views once the runtime is no longer valid, and tests must cover resume before fresh runtime events arrive. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviews on three merged PRs found RBAC permissions or credentials that reached beyond the code that used them: cluster-wide Secret list/watch where named gets sufficed, an unused TaskSpawner RBAC marker on the Task controller, a GitHub token inherited by the whole integration-test step, and a privileged ServiceAccount token shared with an OAuth2 Proxy sidecar. Add a least-privilege rule to the project conventions and the Kelos development AgentConfig, and a matching security check to the reviewer prompt, which had raised the sidecar token only as an optional suggestion and missed the CI token. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Two independent reviews of a Console change found a scroll-position control whose visibility refreshed only from scroll events. It was measured before a scheduled bottom anchor ran, so it flashed visible, and late image loads moved the bottom without a scroll event, so it stayed hidden. An earlier review found the same gap when a hidden view was revealed, which is the only case the existing rule named. Generalize the rule to recompute derived state after deferred programmatic scrolls and late content growth, and to test those changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What type of PR is this?
/kind cleanup
What this PR does / why we need it:
Adds evidence-backed conventions and workflow safeguards to the project
instructions, shared Kelos development AgentConfig, and reviewer prompts.
Compare forwarded streams exactly. PR Stream agent output through kelos-capture instead of writing to /tmp #1189's
review comment
found that per-line substring assertions could not detect dropped, duplicated,
or reordered output. The printer/formatter test rule now also requires full
normalized equality for stream-forwarding tests.
Scope autonomous triggers to trusted authors and intended subjects. PR
Add kanon-development TaskSpawners for autonomous kanon development #1241 was corrected because a
review trigger lacked an author filter
and a
PR-only command also matched issue comments.
The TaskSpawner convention now requires both author allowlists and
commentOnscoping where applicable.
Classify request failures by cause. PR feat: add WebhookGateway CRD for per-channel webhook auth and multi-instance GitHub #1238's reviews found that
TaskSpawner list errors silently returned success
and
all gateway
Geterrors became 404s.PR Support file attachments in Sessions #1630 then showed the broader form of the same mistake:
message matching mapped server-side storage failures to 400.
Error-to-status mappings must use typed or sentinel causes, reserve
4xxforclient-correctable failures, and return
5xxfor lookup, RBAC, storage, andtransport failures.
Honor reduced-motion preferences. PRs
#1481
and
#1482
independently added continuous running-state animation without a reduced-motion
fallback. New nonessential animation must retain a distinguishable static state
when motion is disabled.
Protect credentials in configuration and transport. PR feat: Add native OpenTelemetry (OTLP) support for metrics and traces #1559's
review
found authorization headers rendered from plaintext Helm values, while PR feat: add GitHub App auth to HTTP context sources #1564's
review
found that an HTTP endpoint exposed a GitHub App JWT. Credential-bearing values
must use Secret references, and their endpoints must use HTTPS unless explicitly
opted into insecure transport.
Protect state-dependent transitions from stale work. PR Add section choosers to the Session server #1548's
review
found that an old dialog request could mutate a newly opened Session dialog. PR
Allow Session interruption while draining #1618's
review
similarly required an interrupt to be revalidated against the snapped active turn.
PR Use inline session section selector #1649 then left a
finding
because an async failure path rendered a captured pre-request Session after
polling had refreshed the selected Session. PR Add Session goal and shell commands #1650 exposed the interaction-level
form of the same problem: a
stale goal notification could complete a new message,
interrupt could race goal startup,
completion used provider-global goal state,
and
goal control matched the wrong active turn kind.
PR Keep kelos logs -f open after empty streams #1654 then exposed the same precedence problem across independently updated
lifecycle signals: a
failed Pod was treated as retryable while Task status lagged,
and a
non-zero terminated container was also treated as retryable.
Async completions and controls must re-read current state, bind to the exact
operation identity and kind, and coordinate startup and handoff so stale work
cannot render or mutate another operation. When lifecycle signals disagree or
lag, terminal and failure evidence must be inspected before returning a
transient or retry decision.
Test behavior through the layer that owns it and assert the primary effect.
PR Add section choosers to the Session server #1548's same
review
found that source-fragment assertions did not exercise stateful UI behavior. PR
feat: Add optional Prometheus Operator PodMonitor to Helm chart #1560's
review
found that a render test never exercised the non-default namespace branch it
claimed to cover. PR Display and manage pending Session messages #1648's
review
also found that an exact minified CSS-rule assertion was brittle while failing
to exclude declarations that would restore the regression. PR Support file attachments in Sessions #1630 had a
download fake that discarded the requested attachment ID,
PR Monitor pull request checks in Sessions #1639 had an
end-to-end fixture that omitted the changed check-rollup response,
and PR Reduce Session GitHub API usage #1652 had a
command fixture that accepted any GraphQL query and could not detect duplicate calls.
PR Add Session goal and shell commands #1650 also had an
interrupt test that checked journal status without checking process death,
while PR Reduce Session GitHub API usage #1652 had a
periodic test whose blocking callback leaked its goroutine.
PR Keep kelos logs -f open after empty streams #1654's
test review
also found that new terminal, transient, and unknown lifecycle branches were
left unvalidated.
Tests must execute the owning layer and important non-default branches, assert
the real routed or lifecycle effect rather than a bookkeeping proxy, and make
appropriate static assertions on behavior instead of serialization details.
State-dependent decision tests must cover each relevant terminal, transient,
and unknown class plus combinations where status sources can lag one another.
Fakes, fixtures, and command shims must exercise changed response fields,
validate complete request shapes, reject unexpected calls, and expose call
counts when batching or request reduction is part of the contract. Background
goroutines and child processes must also be cancellation-aware and verified
stopped before the test returns.
Keep all documentation surfaces complete and consistent. Recent reviews
repeatedly found partial documentation updates: PR Show sessions waiting for input #1604
claimed header styling that was not implemented,
PR Track sticky issue validity verdicts #1611 left
per-spawner sections inconsistent with its overview,
PR Paginate Session terminal history #1613
removed documentation for still-supported flags,
and PR Add Session turn duration separator #1616
omitted newly observable terminal behavior.
Agents must search related overviews, component sections, tables, setup examples,
and command/flag references and update all affected mentions together.
Separate historical replay from live event handling. PR Paginate Session terminal history #1613's
review
found that older terminal pages could be rendered as continuations of the active
live stream and that duplicate history requests reused a cursor. PR Paginate Session web chat history #1621's
review
found that web history replay could emit a false live interruption toast, omit
independently needed current file state, and leave viewport preservation untested.
PR Browse Session prompts in terminal chat and console #1739's review found two related failures: the web dialog
retried an expired cursor indefinitely,
while the terminal
reused cached prompt history and its cursor after reconnecting.
The author confirmed the
web reload fix
and
terminal reconnect fix,
and the merged diff includes executable tests for both paths.
Replay must keep its rendering, state, and side effects separate while preserving
valid cursors, request state, current state, order, and viewport behavior.
The history rule in
AGENTS.mdandself-development/agentconfig.yamlalsorequires clearing stale cursors and cached pages when reconnecting to replacement
history or recovering from an expired cursor, so the next request starts at the
first page. Tests must cover recovery from expired cursors as well as reconnects.
Use lease-protected pushes after rebasing published branches. PR Add full spawner fleet for kelos-dev/open-actions #1622's
reviews independently found that the
worker existing-PR path
and
PR responder
rebased already-published branches and then attempted normal pushes, which fail
as non-fast-forward updates. The shared instructions now require
git push --force-with-lease, never an unleased force-push, after rebasing apublished branch.
Treat controller-generated Kubernetes names as durable identities. PR
Bound Session workload names #1629's reviews found that dropping the Session workload prefix would
collide with legacy workloads
and
abandon retained persistent workspaces.
The independent
Kelos Claude review
also found that a 63-character StatefulSet bound still left no room for
ControllerRevision and Pod-label suffixes. The
review on PR #1631
then showed that a Session name valid under DNS-1123 can still be invalid for
its governing Service under DNS-1035. Name derivation must validate the exact
grammar of every generated kind and account for all downstream suffix and label
limits, and controller-owned resources must not be renamed without a
collision-safe migration that preserves ownership and data.
Keep shared feature contracts consistent across clients. PR Support file attachments in Sessions #1630's
review found that the plain terminal
did not enforce the TUI's eight-file limit,
the TUI
accepted an empty
/sendthat the plain terminal rejected,and the plain terminal
omitted
/sendfrom command help.The
independent Kelos Claude review
also identified the cross-client limit mismatch. Shared web, TUI, and CLI
features must apply the same limits, empty-input rules, failure semantics, and
discoverability, with each surface tested explicitly.
Preserve prompt contracts when consolidating instructions. PR Simplify session spawner prompts #1641
removed detailed worker and PR-responder prompts on the assumption that shared
configuration supplied the same behavior. Reviewers found the same missing-owner
failure across
Open Actions workers,
Agora workers,
the Kanon responder,
the Agora responder,
the Open Actions responder,
and the Kelos responder.
Separate comments also found the
persistent-workspace test contract
and
Agora documentation
out of sync. Before consolidating prompt instructions, agents must map every
removed requirement to a concrete source the spawned agent actually loads and
update contract tests and documentation in the same change.
Audit responsive rules when changing web controls. Three recent web
changes independently missed existing phone behavior:
PR #1630 left the attachment button below the mobile touch-target size,
PR #1638 resized the composer without resizing its adjacent attachment control,
and
PR #1647 omitted its new textarea from the mobile anti-zoom selector.
Agents must sweep every relevant selector group and breakpoint override for
new or renamed controls, preserving mobile font sizing, touch targets, and
sibling alignment.
Use production identities and collection cardinality in tests. PR
Handle rotated CRD CA bundles during install #1656 had a
multi-certificate review finding
because singleton-only expected bundles did not exercise whether every
required certificate was present. PR fix(slack): stop retrying replies rejected with cannot_reply_to_message #1660 then used an empty Task UID in
a
keyed-suppression test,
so the test passed without exercising the production identity path.
Fixtures must populate identity fields used as keys and use multi-element
inputs when behavior depends on collection membership or aggregation.
Test API mutability through updates. PR Make Session idle policy mutable #1665's
API review
and
general review
independently found that making
Session.spec.idlePolicymutable was testedonly for one non-nil replacement. A
separate inline finding
also found that create-only negative cases did not prove validation remained
enforced on updates. Mutability changes must cover the newly allowed presence
transitions and at least one invalid update.
Preserve keyboard operability in dynamic web controls. PR Add per-session actions menu to session server #1663's reviews
found that keyboard-invoked actions
lost focus after rerendering their trigger,
menu items
removed the visible focus ring,
and
Tab left the menu open after focus moved away.
PR Show Task logs in the Console #1673 was then independently flagged by
Cubic
and the
Kelos Claude reviewer
because roving
tabindexmade the inactive Manifest tab unreachable withoutArrow/Home/End handling. Custom widgets must implement their expected keyboard
interaction model; dynamic menus and dialogs must also retain a visible focus
indicator, dismiss on expected keyboard navigation, restore focus after success
and failure, and test those interactions through the browser behavior layer.
Make component renames upgrade-safe. PR Turn the Session server into the Kelos Console #1670's current-head reviews
found that the Console rename
dropped the persisted namespace selection
and
left legacy installed objects, uninstall RBAC, and Helm values without an upgrade path.
Component renames must inventory prior deployed identifiers, migrate stored
state, clean up resources that non-pruning installs leave behind, retain
uninstall cleanup for old names, and reject unsupported stale configuration
actionably. Upgrade-state tests are required alongside fresh-install tests.
Test every distinct behavior path independently. PR Add Session suspend action to console #1681 reviews found that the suspend tests depended on an earlier test global, omitted a runtime dependency and could not execute, and left the idempotent API branch untested. PR Visualize resource relationships in the console #1682 then had an independent review find that an exact-set relationship test skipped core derivation branches while a dependency edge was missing. Tests must now establish their prerequisites, include runtime dependencies, prove that the intended path is reached, and inventory relevant mapping variants.
Centralize behavior that must stay in lockstep. A
review on PR #1673
found duplicate authentication and error handling across two request helpers.
A
review on PR #1681
found duplicated suspend and resume bookkeeping that could drift, and a
review on PR #1683
found the Console build commands duplicated instead of routed through the
existing Makefile target. Code paths that intentionally implement the same
behavior and differ only by an input or action must share the implementation,
and repeated build or generation commands must use one Makefile target. The
rule explicitly excludes incidental similarity to avoid unnecessary
abstraction.
Preserve touch-accessible actions across breakpoints. The Claude review on PR #1686 found that the mobile breakpoint hid the only touch-usable path for Session section assignment while drag-and-drop was not reliable on touch devices. An independent inline review also found that the redesigned mobile tabs fell below the established 44px touch target. Responsive changes must keep every supported action available through an equivalent touch-operable path and test that path.
Preserve readable contrast across supported themes. A review on PR #1663 found that removing an explicit focus outline left only a weak dark-mode indicator, and PR #1686 reused a light-theme label color that produced roughly 2.5:1 contrast in dark mode. Color and theme changes must verify text, interactive labels, and focus indicators in every supported theme against the applicable WCAG AA contrast requirement.
Preserve Unicode semantics in text processing. A review on PR #1673 found that byte-offset truncation could split a multibyte rune and emit invalid UTF-8. A review on PR #1692 then found that
len()enforced a documented character threshold in bytes, causing non-ASCII false negatives and misleading diagnostics. Character limits must count Unicode code points, byte-bounded truncation must preserve UTF-8 boundaries, and affected limits must be tested with non-ASCII input.Preserve UI behavior when restructuring web views. PR Make console sidebar controls scrollable #1688 moved
Console sidebar scrolling to a new container but left
menu dismissal attached to the old non-scrolling list.
PR Keep the current request visible in console #1702 later let
hidden-view geometry updates clear current-request state without recomputing it on reveal.
Web view restructuring must migrate behavior bindings to the actual
containers, avoid deriving state from hidden layout geometry, recompute
derived state when a view becomes visible, and test the affected scroll and
hide/reveal interactions.
Bound work and persisted state on long-lived data and hot paths. PR Show Task logs in the Console #1673 reviews found
an entire accumulated WorkerPool log read into memory
and a later
fallback that still scanned the unbounded log.
PR Visualize resource relationships in the console #1682 then had a
quadratic TaskBudget-to-resource scan,
while PR Keep the current request visible in console #1702 performed
synchronous geometry reads and DOM writes on every scroll event,
independently echoed by its
Claude review.
The current-head API review on PR API: Add TaskPipeline for multi-stage orchestration #1698 then found that
copying every child output into CR status
could exceed Kubernetes object-size limits and wedge status updates. Agents
must bound long-lived input and persisted summaries, use references or
explicit truncation for high-cardinality status, prefilter nested matching,
and coalesce high-frequency UI work while avoiding unchanged DOM writes.
Revalidate preservation data during API conversion. The resolved
review on PR Match Slack spawner events by exclusion rules #1703 found that a user-writable preservation annotation could
bypass the destination field's pattern and item-count schema
after a syntactically valid JSON decode. PR Match GitHub webhook events by pull request author #1708 then repeated the same
omission for another preserved field, where a
current-head review found missing item-count and length validation.
Conversion code must treat preservation storage as user-controlled, enforce
the destination field's complete schema before restoring it, and test
syntactically valid but out-of-schema values as well as malformed encodings.
Keep configurable ServiceAccount identities in lockstep. PR feat: add WebhookGateway CRD for per-channel webhook auth and multi-instance GitHub #1238
repeatedly exposed incomplete handling of a Helm-configurable identity: the
gateway Pod could use a
ServiceAccount that lacked the required RBAC binding,
a second review found the
same custom-name drift across rendered resources,
and a later review found that
reserved chart-managed names rendered duplicate ServiceAccounts.
Helm-controlled ServiceAccount names must reach the workload, account, and
every RBAC subject; chart-owned collisions must be rejected and both valid
non-default and reserved values must be render-tested.
Keep auxiliary failures from breaking primary work. In three PRs, a
best-effort step broke work that would otherwise have succeeded. Each fix
degraded only the enhancement:
hard prerequisite for Session pull-request status,
which the
Kelos Claude API review
also flagged. The merged change logs the lookup failure and falls back to
the pull request's checks.
single transient heartbeat write error tore down the live Console bridge,
which the
Kelos Claude review
confirmed independently.
aborted Session runtime startup when Git inspection for the Changes tab failed,
for example on a workspace with dubious ownership. The author
confirmed the fix:
directory configuration is still validated, but inspection failures are
logged, reported in snapshot responses, and retried on later requests.
The rule in
AGENTS.mdandself-development/agentconfig.yamlpreviouslycovered only lease refresh. It now covers any best-effort enhancement: keep
the primary result, log the failure, report it where the enhancement is shown,
and retry later, without aborting startup or tearing down a healthy
connection. Invalid configuration and required writes remain fail-fast. The
Kelos reviewer did not flag the Fix console workspace changes across agents #1779 startup abort at the head cubic reviewed
(
dccd90f). Its checklist flags only silent degradation (as P1), sokelos-reviewer.yamlnow includes the converse check at P2.Keep provider integrations isolated end to end. PR Add GitLab source and webhook support for TaskSpawners #1721 repeatedly mixed the new GitLab path with GitHub assumptions: spawner reporting received a GitHub-only token resolver, GitHub App keys could suppress GitLab token injection, and a GitLab-mode reporting controller could reconcile GitHub Tasks. A separate self-hosted URL finding, confirmed and fixed by the author, found that deriving the project path dropped the instance URL prefix. Provider additions must route credentials, configuration shapes, and work by explicit provider identity and test coexistence and self-hosted forms.
Verify downloaded artifacts fail closed. Two reviews on PR Add GitLab source and webhook support for TaskSpawners #1721 found that
sha256sum --ignore-missingcould install an unverified glab package when its checksum entry was absent, independently flagging the Cursor image and Gemini image. Artifact verification must select exactly one checksum for the downloaded filename and fail when no unambiguous match exists.Synchronize state shared with test goroutines. PR Add GitLab source and webhook support for TaskSpawners #1721 introduced two HTTP-handler tests where handler goroutines wrote variables read unsafely by the test goroutine: the GitLab source request fixture and GitLab reporting assertions. Shared test state must use mutexes, atomics, or channels and remain clean under the race detector.
Validate collection semantics in generated CRDs. PR Add GitLab source and webhook support for TaskSpawners #1721 documented
allowed values for two list fields, but review found that the
generated CRD omitted both item enums.
The field-specific reviews confirmed that the markers for
gitlabWebhook.eventsand
gitlab.typesdid not constrain
items, while another review found thatduplicate types caused duplicate discovery work.
Slice enums must be verified in generated YAML, and duplicate values must
be rejected when they have no semantic meaning. The API reviewer prompts
now check these generated collection semantics explicitly.
Keep CLI resource detail output aligned with configuration. PR Add GitLab source and webhook support for TaskSpawners #1721
repeatedly added TaskSpawner settings without exposing them to operators:
GitLab webhook
excludeAuthorswas omitted,and the polling source hid both
reviewStateandpipelineStatus.New user-visible fields must be added to every applicable detail printer,
compared with sibling provider branches, and covered by distinct full-line
assertions. The general reviewer prompts now check this surface explicitly.
Page unbounded Kubernetes and API lists. PR Remove v1alpha1 API #1725 attempted to migrate
all stored Kelos resources with
one unpaginated list request,
which can fail once the API server response limit is exceeded. The existing
bounded-work rule now requires limits and continuation-token loops whenever
result cardinality is not contractually bounded.
Keep skill discovery metadata aligned with skill behavior. Reviews on PR
Narrow Kelos skill discovery scope #1720 found that narrowing the skill frontmatter
left supported documentation uses undiscoverable
and
removed distinctive kind names needed for reliable triggering.
Skill descriptions are now treated as discovery contracts: their positive
terms, exclusions, and body-level usage guidance must remain aligned.
Verify required filesystem outputs. PR feat: support optional skills packages #1726 accepted a successful
required skill installation when it
created an empty output directory,
then a follow-up review found that its relocation loop
silently omitted dot-prefixed entries.
Setup and install scripts must validate usable required artifacts rather than
only exit status or directory existence, preserve supported hidden entries,
and exercise those postconditions with executable tests.
Verify external contracts before reporting defects. Two review threads
on PR Add GitLab source and webhook support for TaskSpawners #1721 were resolved after the author corrected unsupported assumptions:
GITLAB_HOSTaccepts a URL,and
head_pipelinerequires the single-MR endpoint.The GitLab CLI documentation,
pinned glab v1.116.0 host parser,
and merge-request response documentation
support those corrections. Both general reviewer prompts now require
verification of endpoint fields and accepted inputs against the relevant
official documentation or upstream implementation, a supporting source link,
and omission of unverified external-contract claims. The provider-isolation
evidence above uses the confirmed relative-URL parsing defect, so the rejected
host-only claim is no longer presented as a valid finding.
Use shared criteria for new source exclusion filters. The maintainer
requested the same rule-based exclusion model in the
Slack review on #1703
and the
GitHub review on #1708,
and the author
accepted the shared direction.
Both the
API review
and
general review
then confirmed at head
1661bf4that reusing the matcher without validatingevent-specific criteria could make a label exclusion reject every push;
explicitly empty criteria could also become an unintended match-all rule.
AGENTS.mdand the Kelos development AgentConfig now require shared typedcriteria under source-level
excludeFilters, AND within each rule,rejection on any matching exclusion regardless of accepting filters, and
preservation of shipped positive-filter semantics. Agents must validate
empty and inapplicable criteria and test intended matches, missing attributes,
empty values, and exclusion precedence across supported trigger paths.
Keep stream control and teardown responsive under backpressure. In
PR Add interactive shell terminals to Console sessions #1736, review found that
blocked stdin prevented reading disconnect messages
and that
the bridge returned without stopping its workers.
The author confirmed the fixes for
bounded input and responsive control handling
and
cancellation, socket interruption, and worker completion;
both threads are resolved and the merged diff contains the fixes. PR Increase Session attachment limit to 100 MiB #1735's
download review
also verifies that closing a stream cancels exec and unblocks a pending pipe
write.
AGENTS.mdand the Kelos development AgentConfig now require controlhandling to remain responsive when consumers stall, bounded queues with
explicit overflow handling, and bridge teardown that interrupts I/O and
waits for its workers. Executable bridge tests must exercise blocked
consumers, control delivery, overflow, and worker termination.
Preserve UI behavior across view and resource lifecycles. In PR
Add a native Session terminal tab with shell completion #1737, both the
inline review
and the independent Console review found that page departure disposed the
terminal while leaving its tab selected and Reconnect disabled. The author
confirmed the fix:
close the shell, select a usable view, and allow Terminal to reopen after
restoration. PR Add browser alerts to the console #1744 exposed another missing lifecycle transition:
browser notifications survived Session deletion or recreation.
The author
confirmed cleanup by namespace/name/UID on accepted Session refreshes,
covering selected and background Sessions. Both inline threads are resolved,
and the merged diffs contain the accepted fixes. The existing UI convention
in
AGENTS.mdandself-development/agentconfig.yamlnow includes page andSession lifecycles, cleanup of invalid resources, usable views and controls
after teardown, and tests for cleanup and restoration or reopening.
Verify child identity before reusing a generated resource. On PR API: Add TaskPipeline for multi-stage orchestration #1698,
both the API review
and general review
found that a matrix stage
reviewand a single-Task stagereview-0couldgenerate the same Task name. The
AlreadyExistspath checked only thepipeline owner, so the later stage reused the earlier stage's successful
Task and reported success without running. The maintainer
confirmed the fix and reconciliation test
in merged head
d823e10: reuse requires matching ownership, stage, and index;a different child's name collision fails explicitly. The existing generated-name
convention in
AGENTS.mdandself-development/agentconfig.yamlnow requireschecking the intended child's identity as well as ownership and testing
collisions between children of the same parent. This extends the existing
identity guidance with a confirmed controller contract.
Preserve pending UI intent and keyboard dismissal. PR Move browser notifications into console Settings #1746's Cubic review found that a pending browser-permission render reset the user's switch, keyboard focus could leave the Settings popover without dismissing it (pending state, focus dismissal), and the browser test double dropped repeated listeners (test-double semantics). The shared rules now preserve in-progress UI intent during asynchronous actions, require focus-leaving dismissal or an intentional focus trap, and require browser test doubles to preserve relevant platform semantics.
Pin CSS/layout fixes with owning tests. PR Fix session conversation alignment with long headers #1747's Kelos Claude review found that the new
.conversationlayout declaration was not included in the existing style assertions. The shared testing rule now requires a focused assertion for each behavior-critical CSS declaration in the owning test.Guarantee that waits and lifecycle gates can finish. Three PRs shipped
waits or lifecycle gates with no guaranteed exit. Each finding was fixed
before merge:
forced interruption waited without a bound on a provider that ignores cancellation,
and a
non-deadline interrupt error left a draining Session
Interruptingindefinitely.Both were addressed in
aba5bda.dropped the old Pod's access and left the drain waiting indefinitely.
The merged code keeps drain access when it creates or repairs the binding.
and the Kelos review at
1e5a9a1found thatcompleteInteractionleftreadyopen, so interrupting a new goal stalled until timeout and thenrestarted Codex. The
Kelos review
was edited in place. Its versions at
e0a02c6andb9588e2found twomore problems: a background task that never ends kept the Session
Activeforever and blocked idle-policy and runtime-update drains, andClaude Code's persistent
ambientmonitor tasks were counted asbackground work. The merged commit
dcf7b3aclosesready, skipsambienttasks, applies the task gate only to the idle drain, anddocuments that effect.
AGENTS.mdandself-development/agentconfig.yamlnow require:path;
escalating when the bound expires;
a terminal state, and limiting unbounded user-work gates to the
transitions that need them, with the effect documented;
The existing stale-work rule covers the wrong operation acting on shared
state, and the backpressure rule covers only stream bridges. Neither
requires a wait to finish.
Two findings of the same shape are not used as evidence:
turn.acceptedwas never closed after a journalfailure. Its thread is unresolved, and the fix could not be confirmed.
author rebutted it.
Clear runtime-derived UI state across Session suspension. PR Show background task progress between Session turns #1786 adds
a Console background-task indicator. Two reviews found live runtime state
that outlived the runtime it described:
found that the count stayed visible after the Session was suspended or
stopped being Ready. It noted that a stale active turn already had the
same gap on
main.then found that resuming restarted the elapsed-time timer for a turn
from the stopped runtime before fresh runtime events arrived.
The author fixed both
(suspension,
resume).
An unavailable Session now clears foreground activity and the
background-task count in the current view and its cache. Tests cover
resume before fresh runtime events and cached-view restoration. The PR is
still open, and both fixes are in its current head
d3e6a82.Item 40 applied the lifecycle rule to terminals and browser notifications
across page departure and Session deletion. It did not cover suspension or
live activity indicators.
AGENTS.mdandself-development/agentconfig.yamlnow also cover live runtime activityand Session suspension/resume. They require clearing runtime-derived state
in current and cached views, and testing resume before fresh runtime events
arrive.
Grant only the access a component uses. Reviews on three merged PRs
found RBAC permissions or credentials that reached beyond the code that
used them. Each was fixed before merge:
P1 review
found cluster-wide
list/watchon Secrets when the webhook onlyneeded named reads. The author
replied "Done",
and the merged diff contains no RBAC change.
TaskSpawner RBAC marker on the Task controller, which never reads TaskSpawners.
cubic marked it addressed in
940e7ed, and the marker is absent onmain.GH_TOKENwas inherited by the whole integration-test step,which runs pull-request code, and that
the OAuth2 Proxy sidecar shared the Console ServiceAccount token.
The author
confirmed the sidecar fix,
and
mainsetsGH_TOKENonly on the download step.The Kelos review on #1787
raised the sidecar token only as an optional P3 suggestion and did not
flag the CI token.
AGENTS.mdandself-development/agentconfig.yamlnowrequire RBAC scoped to the API calls the code makes and credentials exposed
only to the container, process, or CI step that uses them.
kelos-reviewer.yamladds a matching security check: P1 when a credentialor Secret is exposed, P2 otherwise.
Recompute geometry-derived UI state on every geometry change. PR Fix console prompt jumps and add Jump to latest #1793
added a Jump to latest button whose visibility depends on distance from
the bottom of the conversation. Two independent reviews found that it was
refreshed only from scroll events:
found that visibility was measured right after a bottom anchor was
scheduled but before it ran. The anchor callback then moved
scrollTopwithout refreshing the button, which flashed visible onopen and on cached Session switches. The author
fixed it
by refreshing the button in the anchor callback before paint.
late image loads grew the conversation after the one-shot anchor
without firing a scroll event, so the button stayed hidden away from
the bottom. The author
confirmed it with lazy images and fixed it
by refreshing the button when image previews load.
Both fixes are in the merged commit
dce3dd0. PR Keep the current request visible in console #1702 had the sameshape:
hidden-view geometry cleared current-request state and was not recomputed on reveal.
That is the only non-scroll case the rule from item 24 named. In
AGENTS.mdandself-development/agentconfig.yaml, the rule now requiresrecomputing geometry-derived state whenever the underlying geometry
changes, not only on scroll events. That covers reveal, deferred
programmatic scrolls (after they run, not when scheduled), and late
content growth such as image loads. It also requires testing those
changes. The Kelos review also noted that the harness mocked the anchor
and checked only the end state. The existing rule that browser test
doubles must preserve platform semantics already covers that.
Files updated:
AGENTS.mdself-development/agentconfig.yamlself-development/kelos-api-reviewer.yamlself-development/kelos-reviewer.yamlself-development/base-agent.yamlis intentionally unchanged because none ofthese changes are an upstream
gjkim42/kanon-reposynchronization.Which issue(s) this PR is related to:
N/A
Special notes for your reviewer:
The existing unassigned configuration PR was reused. It had become unmergeable
after #1762 deleted
self-development/kelos-claude-reviewer.yamlandself-development/kelos-claude-api-reviewer.yamland folded their content intokelos-reviewer.yamlandkelos-api-reviewer.yaml. This branch had made the sameadditions to both files in each pair, so the branch was rebased onto
mainandpushed with
--force-with-lease. The rebase keeps the additions in the survivingreviewers and drops the edits to the deleted files. The added lines in
AGENTS.md,self-development/agentconfig.yaml, and both surviving reviewersare unchanged by the rebase.
Validation after the rebase:
make verify— passedgo test ./internal/examples/...— passed (self-development manifest, reviewerprompt, and model/effort tests, including those rewritten by self-development: run every spawner on Claude Code #1762)
git diff --check origin/main HEAD— passedReviewed PR activity from September 17 through September 24. None of it
supported a new convention:
about stale spawner counts left in the Open Actions README after sections were
deleted. The author fixed it in
c982e7dand swept the sibling READMEs. Theexisting "Keep documentation complete and internally consistent" rule already
requires updating all affected mentions together, and this is a single finding,
so no rule was added.
and cubic found no issues.
item 36 already reflects.
Reviewed PR activity from September 24 through September 29. Only item 28's
broadening was supported by findings in more than one PR. The update is a
fast-forward commit;
mainhas moved on only in files this PR does not touch,so no rebase was needed. Validation for that commit:
make verify— passedgo test ./internal/examples/...— passedgit diff --check— passedFindings from this window that were not turned into rules:
Kelos review
traced three P2s to turn-end cleanup lost when
RunTurnwas split, and cubicflagged a
git diffrun while holding the event mutex.The author fixed both. One of the three P2s, the
readychannel left open,is now cited in item 44 alongside later findings with the same liveness
shape. The other two P2s (the lost provider stop error and a prompt claimed
from pending too early) and the mutex finding still appear only here. The
fake-helper findings are already covered by the rule that test doubles must
preserve protocol semantics.
Kelos review
found that Git stderr was dropped from errors and that snapshot payloads could
exceed the console's 8 MiB line limit. Both were fixed. Losing a failure's
underlying cause appears elsewhere only in Preserve Session background replies across user turns #1780's provider-exit case, which
has a different shape. The bounded-work rule already forbids buffering
unbounded output, which covers cubic's follow-up about
capping only after Git's full name list is buffered.
A per-message transport limit came up only in this PR. The unchanged-DOM finding is covered by the existing "skip unchanged
DOM updates" rule. The author rebutted two cubic findings (request bursts and
reset handling) with the existing tests.
RoleBinding recreation finding
and the Kelos review's
PodConflictpreemption and ServiceAccounttrust-boundary findings were all addressed before merge. The trust boundary
is now documented. Each is a single, feature-specific finding.
repositories' configuration PRs.
Reviewed PR activity from September 29 through September 30. The only new
review activity was two further Kelos reviews on #1780, at
e0a02c6andb9588e2. Their gate findings, together with earlier confirmed findings on#1618, #1774, and #1780, support item 44. This is a fast-forward commit, and
mainhas not changedAGENTS.mdorself-development/since this branchwas last rebased. Validation for that commit:
make verify: passedgo test ./internal/examples/...: passedgit diff --check: passedFindings from this window that were not turned into rules:
e0a02c6also found that theActiveconditionrow in
docs/reference.mdand the condition message still described onlyunfinished turns. The existing "Keep documentation complete and internally
consistent" rule already covers this. The
ambientfinding came fromchecking the pinned Claude Code binary, which the reviewers' external-contract
verification (item 37) already requires.
comments. Add the TaskRouter CRD, controller, and TaskSpawner triggerMode #1761 and Isolate Codex Session notifications by thread #1740: no review activity.
Reviewed PR activity from September 30 through October 1. Only #1786
supported a change (item 45). This is a fast-forward commit, and
mainhasnot changed
AGENTS.mdorself-development/since this branch was lastrebased. Validation for that commit:
make verify: passedgo test ./internal/examples/...: passedgit diff --check: passedFindings from this window that were not turned into rules:
need them. Both were fixed. This window's keyword search found no earlier
finding of this kind, so no rule was added then. It missed fix: grant list/watch on secrets for webhook RBAC and fall back to global GitHub token resolver #1363 and
feat: add Task-native budget enforcement via TaskBudget and TaskRecord CRDs #1426, which item 46 now cites with these findings.
comparison rejected non-canonical external URLs. The
Kelos review
also found a documented cookie-secret command whose output the pinned
OAuth2 Proxy rejects. Both were fixed, and both are specific to this
feature. The author
rebutted the
subclaim findingusing the pinned upstream source. Item 37 already requires reviewers to make
that check. The author declined the JSON Schema suggestion and gave a
reason. The existing rule that fakes must validate the complete request
shape already covers cubic's finding about a fetch mock that accepts any
request.
rebutted
cubic's partial-update test finding because runtime-status events are
complete snapshots. The composer-resize finding was fixed. It is a single
TUI layout finding.
Kelos review
found an earlier Console suspend-and-resume problem. It is not used as
evidence for item 45, because no reply or merged change confirms a fix.
Add the TaskRouter CRD, controller, and TaskSpawner triggerMode #1761 and Isolate Codex Session notifications by thread #1740: no review activity.
Reviewed PR activity from October 1 through October 2. Only item 46 was
added. This is a fast-forward commit, and
mainhas not changedAGENTS.mdor
self-development/since this branch was last rebased. Validation forthat commit:
make verify: passedgo test ./internal/examples/...: passedgit diff --check: passedFindings from this window that were not turned into rules:
P2
says the Console ServiceAccount gains cluster-wide RoleBinding
get/list/delete. This fits item 46, but cubic says the access may berequired, so it is not used as evidence. Its
P1
says a render test would not catch added RBAC verbs. The existing rule
already requires exact-set assertions when omissions matter. This is the
only finding about extra entries, and it is unconfirmed. The
pending-input finding is covered by the existing rule to preserve
in-progress UI intent. The stale-error and README-fragment findings are
single, feature-specific findings.
fixed the fetch-mock finding,
which the existing request-shape rule already covers. The author also
deferred cubic's optional CI cache suggestion
and gave a reason.
Show background task progress between Session turns #1786: no new review activity. Improve Open Actions compatibility reviews and implementation guidance #1627 is another repository's configuration
PR.
Reviewed PR activity from October 2 through October 3. Only item 47 was
added. This is a fast-forward commit, and
mainhas not changedAGENTS.mdor
self-development/since this branch was last rebased. Validation forthat commit:
make verify: passedgo test ./internal/examples/...: passedgit diff --check: passedFindings from this window that were not turned into rules:
a reconnect could move focus back to the composer after Jump to latest.
The author
fixed it
by keeping transcript focus when the socket opens. The existing stale-work
rule already requires re-reading current state when asynchronous work
completes, and this is the only finding of this kind.
rebutted
cubic's overlay finding after Chromium hit testing showed that only the
button's own area intercepts clicks.
repository's configuration PR, and it had no review activity.
new review activity.
Existing instructions already cover stale responses, history cursor recovery,
mobile controls, keyboard behavior, filesystem output checks, and meaningful
test coverage. PR #1749 already added screenshot guidance on
main, so it isnot duplicated here. Optional or conflicting UI suggestions, isolated nits,
and speculative future capabilities were excluded. No runtime code or upstream
base-agent content changes.
Does this PR introduce a user-facing change?
🤖 Generated with Claude Code