ren worker folder adding orig, mv new one into root

This commit is contained in:
2026-09-25 10:34:29 -04:00
parent 10f0668e32
commit 5b010039d7
1308 changed files with 44597 additions and 1511 deletions

View File

@@ -17,10 +17,15 @@ the workspace, and nothing outside it. A task fits that world when everything
is totally verifiable from within the repo: offline-completable and
offline-verifiable, because the setup happened before the network went away.
Setup installs what the repo's own manifests and lockfiles declare at the
pinned commit — nothing more. A library the ask requires the agent to *add*
was never installed, so acquiring it means `bundle add`, `npm install <pkg>`,
`pip install` — a registry fetch, mid-task.
Setup installs what the repo's own manifests and lockfiles declare **after
`environment/workspace.patch` has been applied** — the image copies the patched
workspace in and only *then* runs the dependency install. So a package the
author added, upgraded, downgraded or re-pinned in the patch is present in the
sandbox, and is never a completability finding; judge the manifests as the
patch leaves them, not as the pinned commit left them. What is never installed
is a library the ask requires the *agent* to add: acquiring that means `bundle
add`, `npm install <pkg>`, `pip install` — a registry fetch, mid-task, after
the network is gone.
**Do not consider the task's network policy. At all.** `task.toml`'s
`allow_internet` / `network_mode` / `allowed_hosts` fields are not about the
@@ -96,8 +101,8 @@ Break that into the two halves:
**This half has a mechanical check, and it is not optional.** List every
library, framework, runner, or binary the ask or the rubric's criteria
name, then check each against every manifest and lockfile in the repo
(`Gemfile`/`Gemfile.lock`, `package.json` + its lockfile,
name, then check each against every manifest and lockfile in the repo **as
the workspace patch leaves it** (`Gemfile`/`Gemfile.lock`, `package.json` + its lockfile,
`pyproject.toml`/`requirements*.txt`/`uv.lock`, `go.mod`, the Dockerfile).
Read the files — never settle this from knowledge of what the framework
supports. When a name is absent from all of them, the deciding question is