feat(ws3): auto-dispatch node wiring (keeps agent-apply human gate) #45

Merged
amoussa1229 merged 4 commits from feat/ws3-auto-dispatch-remove-env into main 2026-06-23 19:48:24 +00:00
amoussa1229 commented 2026-06-23 01:32:10 +00:00 (Migrated from github.com)

Summary (reworked 2026-06-23 after GPT-4.1 cross-review BLOCK)

This PR adds the auto-dispatch LangGraph node so the coordinator can fire the apply/verify workflow when the verifier approves a plan — while keeping the agent-apply GitHub Environment human-approval gate in place.

  • agent_team/nodes/dispatch_invoker.py (new): make_dispatch_node() wraps dispatcher.dispatch_apply_verify() as a LangGraph node. Reads thread_id, candidate_diff, plan.scope from state; owner/repo/base injected at startup. Fail-safe: any error parks the task rather than crashing the graph.
  • agent_team/graph.py: DISPATCH_NODE constant + opt-in dispatch_node param to build_graph. Default None = inert (no topology change).
  • agent_team/coordinator.py: DispatchNodeFactory alias; dispatch_node_wiring threaded through __init__/setup(). Default None = no dispatch.
  • .github/workflows/agent-team-apply-verify.yml: environment gate RETAINED. Adds only an additive, unconditional audit-log step (detective control that supplements the required-reviewer gate). The fail-open Slack step from the first revision was removed.
  • tests/: test_ws3_dispatch_invoker.py (new); test_apply_verify_workflow_hardening.py keeps the MANDATORY-INVARIANT assertion (env must be present) + asserts the audit step is retained.

Behavior: the dispatch node fires workflow_dispatch; GitHub then pauses at the agent-apply environment until the human reviewer (amoussa1229) approves. Auto-dispatch up to the approval, then one click — the preventive human gate is preserved.

Why reworked

The original revision removed the environment gate and replaced it with detective controls (Slack notice that fails open + audit log). The mandatory GPT-4.1 cross-family review BLOCKED that as trading a preventive boundary for after-the-fact signals. This revision keeps the gate and drops the fail-open control.

CI

ruff check/ruff format --check clean · hardening + WS3 suites pass (59 tests).

OUTSTANDING (attended)

  • GPT-4.1 cross-family re-review confirms the BLOCK is cleared
  • dispatch_node_wiring is still inert (default None); wiring it live in run-team.py serve is a separate, gated step

🤖 Reworked with Claude Code

## Summary (reworked 2026-06-23 after GPT-4.1 cross-review BLOCK) This PR adds the **auto-dispatch LangGraph node** so the coordinator can fire the apply/verify workflow when the verifier approves a plan — **while keeping the `agent-apply` GitHub Environment human-approval gate in place**. - **`agent_team/nodes/dispatch_invoker.py`** (new): `make_dispatch_node()` wraps `dispatcher.dispatch_apply_verify()` as a LangGraph node. Reads `thread_id`, `candidate_diff`, `plan.scope` from state; `owner`/`repo`/`base` injected at startup. Fail-safe: any error parks the task rather than crashing the graph. - **`agent_team/graph.py`**: `DISPATCH_NODE` constant + opt-in `dispatch_node` param to `build_graph`. Default `None` = inert (no topology change). - **`agent_team/coordinator.py`**: `DispatchNodeFactory` alias; `dispatch_node_wiring` threaded through `__init__`/`setup()`. Default `None` = no dispatch. - **`.github/workflows/agent-team-apply-verify.yml`**: **environment gate RETAINED.** Adds only an additive, unconditional **audit-log step** (detective control that *supplements* the required-reviewer gate). The fail-open Slack step from the first revision was **removed**. - **`tests/`**: `test_ws3_dispatch_invoker.py` (new); `test_apply_verify_workflow_hardening.py` keeps the MANDATORY-INVARIANT assertion (env must be present) + asserts the audit step is retained. **Behavior:** the dispatch node fires `workflow_dispatch`; GitHub then **pauses at the `agent-apply` environment** until the human reviewer (amoussa1229) approves. Auto-dispatch up to the approval, then one click — the preventive human gate is preserved. ### Why reworked The original revision removed the environment gate and replaced it with detective controls (Slack notice that fails open + audit log). The mandatory GPT-4.1 cross-family review **BLOCKED** that as trading a preventive boundary for after-the-fact signals. This revision keeps the gate and drops the fail-open control. ## CI `ruff check`/`ruff format --check` clean · hardening + WS3 suites pass (59 tests). ## OUTSTANDING (attended) - [x] GPT-4.1 cross-family re-review confirms the BLOCK is cleared - [x] `dispatch_node_wiring` is still inert (default `None`); wiring it live in `run-team.py serve` is a separate, gated step 🤖 Reworked with [Claude Code](https://claude.com/claude-code)
This repo is archived. You cannot comment on pull requests.
No description provided.