roadmap: Stage 2 complete — CB-205 bridge_ask, CB-202 reviewer skill, CB-201 descoped

Record the rich-message-semantics stage as done: CB-205 reverse rendezvous
(bridge_ask, live e2e), CB-202 reviewer-role skill, and CB-201 intentionally
descoped from a {from,to,corr} envelope to a lightweight QUESTION kind + turn_id
(connection identity already routes replies). CB-203/CB-204 shipped earlier.
Bump suite to 147 green (+13). Resolve the reviewer-skill open decision (skill,
not CLAUDE.md snippet) and move bridge_ask out of Stage 3's delivers line.
Dai Ha
2026-07-16 16:12:36 +02:00
parent cea7ddc196
commit 0c81b51956
+27 -5
@@ -30,7 +30,7 @@ gantt
|---|---|---|
| **1 — Walking skeleton** | One review, happy path | Opus mounts `bridged` (MCP), calls `bridge_send` with a diff, gets a review back from a real `ccs gx00-vllm claude` worker. Single hardcoded profile, same host, no guard/lifecycle. |
| **2 — Contract + guard** | Trust the reply, trust the boundary | Structured [envelope](7-Use-Cases#mechanism-4--the-id-contract-envelope) + worker `bridge_reply`; reply rendezvous; subscription guard via `ccs env`; reviewer skill. |
| **3 — Lifecycle + discovery** | Reuse, recycle, choose | Session manager (spawn/reuse/recycle Ralph loop, `idle_ttl`); `bridge_list` roster+live; multiple profiles; `bridge_ask`. |
| **3 — Lifecycle + discovery** | Reuse, recycle, choose | Session manager (spawn/reuse/recycle Ralph loop, `idle_ttl`); `bridge_list` roster+live; multiple profiles. (`bridge_ask` landed early in Stage 2.) |
| **4 — Async + split-host** | Detached + cross-host | `block:false` (detached dispatch) + idle-pane injection; internal queue (durability); split-host `Stop`-hook adapter that polls `bridged`. |
| **5 — Harden** | Production shape | Auth/TLS, `/metrics` + `/healthz`, mock-socket CI, systemd unit, per-session authz + audit. |
@@ -128,8 +128,9 @@ comes in Stage 2). This is the thinnest end-to-end vertical slice.
**Definition of done for the stage:** `CB-107` demo passes.
> **Build status — Stage 1 COMPLETE** (in `bridged/`, Maven · Java 25 · **134 tests green — 128
> unit/acceptance + 6 live-herdr contract**). The `CB-107` end-to-end demo gate passes and the
> **Build status — Stage 1 COMPLETE** (in `bridged/`, Maven · Java 25 · **147 tests green — 141
> unit/acceptance + 6 live-herdr contract**; the suite has grown with the Stage 2 work noted
> below). The `CB-107` end-to-end demo gate passes and the
> bridge is **dogfooded**: an Opus primary delegates real tasks to off-subscription workers that
> reply through it (delegated code reviews have produced committed bug fixes).
> ✅ **CB-101** herdr client — connection-per-call, contract-tested vs live 0.7.0.
@@ -166,6 +167,25 @@ comes in Stage 2). This is the thinnest end-to-end vertical slice.
> the scrape cap (CB-118). Verified by a single-worker conversation harness, a **1-primary /
> N-worker fan-out issue-hunt**, and a **sustained 5-minute stateful back-and-forth** (30 turns,
> every one a clean `bridge_reply`, running total held) — all under `e2e/`.
>
> **Stage 2 — rich message semantics COMPLETE.** The contract-and-guard stage has landed (the
> +13 tests above are its coverage):
> ✅ **CB-205** `bridge_ask` reverse rendezvous — a worker pauses its delegated turn to ask the
> primary and resumes the **same** turn with the answer. The question surfaces on the primary's own
> blocked `bridge_send` carrying a `turn_id`, and the primary answers by sending on that `turn_id`.
> Live e2e (`e2e/bridge_ask_test.py`): the worker asked in ~9s and, after the primary answered,
> resumed and replied via a clean `bridge_reply`.
> ✅ **CB-202** reviewer-role skill (`.claude/skills/reviewer/SKILL.md`) — the playbook a worker
> loads to review a scoped assignment, ask the lead via `bridge_ask` when the call is genuinely
> theirs, and report exactly one structured finding via `bridge_reply`. Pairs the already-shipped
> `bridge_reply`/`bridge_ask` tools with the role guidance for using them.
> ⚠️ **CB-201 descoped** — the planned `{from,to,corr}` envelope schema + codec was **not** built.
> Connection identity (loopback peer PID → herdr pane) already routes every reply and question to
> the right session robustly, so CB-201 shipped as a *lightweight* addition only where the reverse
> path needs it: a `QUESTION` message kind + `turn_id` correlation. No heavyweight envelope.
> ✅ **CB-203 / CB-204** (reply rendezvous · subscription guard) shipped earlier in the CB-1xx
> sequence — completion-fallback resolution on the `working→idle` edge, and the per-profile
> `base_url` allowlist checked before any herdr call. **All five Stage 2 tickets are done.**
---
@@ -263,8 +283,10 @@ end-to-end gate.*
- **ccs worker profiles** — which existing ccs profiles (or new `ccs api` profiles) back the
`gx00-vllm` / local workers, and their exact `base_url` hosts for the allowlist.
- **Reviewer system prompt** — ship the reviewer skill as a `CLAUDE.md` snippet vs a
slash-command/skill the worker loads at spawn.
- **Reviewer system prompt** — ✅ **Decided (CB-202):** shipped as a loadable **skill**
(`.claude/skills/reviewer/SKILL.md`), not a `CLAUDE.md` snippet. Workers inherit the repo cwd, so
the skill is available to every reviewer worker without polluting the developer-facing project
`CLAUDE.md`.
- **Envelope-as-text (Stage 1) → structured (Stage 2)** — confirm the Stage-1 shortcut (request
body inlined as prompt text, reply scraped) is acceptable before the envelope lands.