12 KiB
作成
LocalTicketBackend によって作成されました。
Decision
Worker 側が持つ workspace 情報は Option<WorkspaceId> に留める。WorkspaceBackendRef、endpoint、auth/SecretRef、adapter/client の materialization は Runtime/host 側の責務とし、Worker は Runtime から注入された scoped WorkspaceClient / handle 経由で workspace-aware API に request する。
Plan
整理結果:
-
00001KX6Y2A9Q WorkerFilesystemAuthority
- hard dependency なし。
- no-workdir を filesystem authority none として型で表現する基盤。
-
00001KX6WVNPD Embedded no-workdir Worker authority policy
- depends_on: 00001KX6Y2A9Q。
- UI/API の workdir 任意化と embedded no-workdir tool surface 制御を実装する。
-
00001KX6Y6ZEA WorkspaceBackend / workspace_id 分離
- depends_on: 00001KX6Y2A9Q。
- workspace_root path 依存を workspace_id + Runtime-injected WorkspaceClient へ移行する。
- embedded no-workdir MVP をブロックしない。
Hard dependencies は WorkerFilesystemAuthority を共通前提に限定する。WorkspaceBackend 分離は embedded no-workdir policy の MVP には related だが depends_on にはしない。
Decision
Clarification: this ticket should remove Worker-level workspace_root: PathBuf, not leave it as a staged authority surface. Local paths may remain only inside Runtime/host backend adapters or WorkerFilesystemAuthority::Local; Worker workspace identity is Option<WorkspaceId> and workspace operations go through an injected WorkspaceClient / handle.
Intake summary
Marked ready by yoi ticket state.
State changed
Marked ready by yoi ticket state.
State changed
Ticket を workspace-panel が queued にしました。
Decision
Routing decision: blocked_by_dependency
Reason:
- Dashboard queue authorization was inspected, but this Ticket has an explicit typed
depends_onrelation to00001KX6Y2A9Q。 00001KX6Y2A9Qis currentlyinprogressand is refactoring Worker filesystem authority / cwd removal / no-workdir boundaries。- This Ticket replaces Worker
workspace_rootpath usage withWorkspaceBackend, which builds on the same Worker struct/context/constructor boundary。 - Starting now would likely conflict with the active filesystem-authority refactor and obscure review boundaries。
- Therefore this routing pass leaves the Ticket
queuedand does not recordqueued -> inprogress, create a worktree, or spawn role Pods。
Evidence checked:
- Ticket body / recent thread / artifacts。
TicketRelationQuery(00001KX6Y6ZEA): includes dependency on00001KX6Y2A9Q。TicketList(inprogress):00001KX6Y2A9Qis the active inprogress Ticket。- Orchestrator worktree status: clean。
Next action:
- Re-route this Ticket after
00001KX6Y2A9Qis approved, merged, validated, and closed。 - Escalate only if a human explicitly requests combined implementation in the same branch/worktree。
Decision
Routing decision: hold_queued_due_migration_boundary_conflict
Reason:
- 前提
00001KX6Y2A9Qは closed になったため dependency 自体は解消済み。 - ただし、この routing pass では
00001KX6WVNPDを先に受理した。 00001KX6WVNPDは embedded no-workdir policy MVP であり、WorkspaceBackend migration を必要としない小さい境界変更である。- この Ticket は Worker
workspace_rootpath をWorkspaceBackendに置き換える refactor で、Worker struct/context/constructor/runtime spawn/UI API 周辺に触れる。 00001KX6WVNPDも同じ Worker create / embedded runtime / no-workdir authority surface に触るため、並行 branch で進めると conflict と review boundary 混濁の可能性が高い。- よって、この Ticket は
queuedのまま保持し、00001KX6WVNPDが reviewed/merged/closed になってから再 routing する。
Evidence checked:
- Ticket body / thread / relations / orchestration plan。
TicketRelationQuery(00001KX6Y6ZEA): prerequisite00001KX6Y2A9Qは closed。TicketList(inprogress): routing pass 中に00001KX6WVNPDを accepted for implementation。- Orchestrator worktree status: clean。
Next action:
00001KX6WVNPDの implementation/review/merge/close を完了後、この Ticket を再 routing する。- 人間が combined branch を明示希望する場合のみ、この待機判断を再検討する。
Decision
Routing decision: implementation_ready
Reason:
- 前提
00001KX6Y2A9Qは closed 済みで、WorkerFilesystemAuthority::{None, Local}と cwd 除去境界が merge 済み。 - 関連
00001KX6WVNPDも closed 済みで、embedded no-workdir Worker policy / UI/API optionality が merge 済み。 - この Ticket の typed
depends_on 00001KX6Y2A9Qは解消済み。00001KX6WVNPDはrelatedであり blocker ではなく、直前の conflict/migration-boundary waiting note もその Ticket の merge/close により解消済み。 TicketList(inprogress)は 0 件で、Orchestrator worktree は clean。- Ticket body/thread に Worker-level local path identity をなくし、Runtime/host-owned backend/client 境界へ移す binding decision が記録されている。
Evidence checked:
- Ticket body / thread / relations / orchestration plan。
- Closed prerequisite
00001KX6Y2A9Qand closed related policy Ticket00001KX6WVNPD。 TicketRelationQuery(00001KX6Y6ZEA): outgoingdepends_on 00001KX6Y2A9Qis closed; other relations arerelatedonly。TicketOrchestrationPlanQuery(00001KX6Y6ZEA): prior waiting notes were dependency/conflict notes now resolved by prerequisite and related Ticket closure。TicketList(inprogress): 0 件。- Orchestrator worktree status: clean。
IntentPacket:
Intent:
- Worker の workspace identity/context を local path (
workspace_root: PathBuf) から path-free identity (Option<WorkspaceId>) と Runtime/host injected workspace client/handle 境界へ移行する。 - Filesystem authority は
WorkerFilesystemAuthorityに閉じ込め、workspace identity/client が local filesystem authority を意味しないようにする。
Binding decisions / invariants:
- Worker struct は durable/context identity として local workspace path を保持しない。
- Worker-level
workspace_root: PathBuffield と local path-returning workspace identity accessor を削除する。 - Worker が
WorkspaceBackendRef/ endpoint / auth / SecretRef / adapter を直接解決しない。 - Runtime/host 側が backend binding source を保持・解決し、Worker には narrow
WorkspaceClient/ handle を注入する。 workspace_id = Some(...)かつfilesystem = Noneを表現できること。workspace_id = Noneかつfilesystem = Noneの会話専用 Worker も表現できること。- local path が必要な処理は Runtime/host backend adapter または
WorkerFilesystemAuthority::Localの内側に閉じ込める。 - capability を導入する場合でも authority source にせず、tool registration / UX / discovery hint として扱い、enforcement は backend 側に置く。
WorkerFilesystemAuthority/ embedded no-workdir policy を崩さない。workspace root fallback や process cwd fallback を filesystem authority として復活させない。
Requirements / acceptance criteria:
- Worker context に
workspace_id: Option<WorkspaceId>equivalent と injected workspace client/handle equivalent を持てる。 - Worker struct に
workspace_root: PathBufが存在しない。 - workspace-aware features(Ticket / memory / workflow / project records / workspace metadata)は local workspace path authority ではなく injected workspace client/handle 経由へ移行する、または移行が必要な箇所を fail-closed / unavailable diagnostic にする。
- Runtime/host が
WorkspaceBackendRefequivalent を保持・解決し、Worker launch/restore/embedded/spawn path へ安全に materialize できる。 - No-workdir Worker は workspace API access と local filesystem authority の有無を独立に表現できる。
- Existing local/workdir Workers still work with
WorkerFilesystemAuthority::Localand local-path-only operations confined there。 - Tests cover no local workspace path identity on Worker, workspace_id/client injection shape, no filesystem authority mixing, and representative workspace-aware API/tool behavior。
Implementation latitude:
WorkspaceId,WorkspaceBackendRef,WorkspaceClient/ handle の exact placement/name/API surface は existing crate boundaries に合わせてよい。- Minimal client/handle can support only currently needed workspace-aware operations if broad API migration would exceed Ticket scope, but it must not leave Worker-local path authority as the active path。
- If a currently path-backed feature cannot be migrated safely in this Ticket, prefer explicit unavailable/fail-closed diagnostic with follow-up note rather than hidden path fallback。
- Capability discovery is optional unless needed for safe tool registration/UX。
Escalate if:
- Removing
workspace_rootfrom Worker requires changing product semantics for memory/Ticket/workflow availability beyond local refactor。 - A workspace-aware feature cannot be migrated without introducing a broad external backend/protocol design not captured by this Ticket。
- You need to reintroduce Worker-held local workspace path as identity/authority。
- You need to weaken no-workdir fs/Bash tool omission or
WorkerFilesystemAuthorityinvariants。 - Public API/serialization migration requires incompatible durable-state handling beyond existing restore/test coverage。
Validation:
rg "workspace_root" crates/worker crates/worker-runtime crates/yoi-pod-client crates/yoi-workspace-serverwith expected remaining hits only outside Worker identity/authority or documented adapter boundaries。rg "worker\.workspace_root|workspace_root\(\)" cratesor equivalent showing Worker local path accessor removed。git diff --checkcargo test -p worker --lib --testscargo test -p worker-runtime --features ws-server,fs-storecargo test -p yoi-workspace-server --libcargo check -p yoicd web/workspace && deno task check && deno task testif API/types/UI are touched。yoi ticket doctornix build .#yoi --no-link
Current code map / likely touch points:
crates/worker/src/worker.rsfor Worker context fields and accessors。crates/worker/src/controller.rsfor workspace-aware tool/resource setup currently tied to workspace path。crates/worker-runtime/src/worker_backend.rsfor Runtime/embedded/restore construction and backend binding materialization。- workspace-server/client crates if backend/client DTOs or Worker launch summaries expose workspace identity。
- tests around no-workdir Workers, restore, child spawn, Ticket/memory/workflow availability。
Critical risks / reviewer focus:
- Hidden local path authority retained in Worker under a renamed field/accessor。
- Workspace identity/client being treated as filesystem authority。
- WorkspaceBackendRef/endpoint/secret leaking into Worker-owned state。
- Breaking local/workdir Workers or child spawn/restore while removing path identity。
- Regressing embedded no-workdir policy or filesystem/Bash tool omission。
- Over-broad migration that invents a large remote-workspace protocol instead of the minimal safe boundary needed here。
State changed
Prerequisite and prior conflict/migration-boundary Ticket are now closed. This Ticket is accepted for implementation before creating a worktree or spawning role Pods.