Repository navigation
A here-document, by an executor then by the built-in Plan agent, which the rules of the chain do not reach #71
Description
Activity
Counted again in campaign 2
Campaign 2:
01-overdue-listand03-overdue-reminders, three runs each, onmainwith the four first fixes (#78, #79, #80, #81). Report kept:evals/reports/2026-10-03-e830bc236e9b/report.md. Raw data, out of git:.evals/campaign-2/. In the tables, a value is the mean over the three runs, with its lowest and highest when they differ.2 here-documents in 371 Bash calls, both in one session of
01-overdue-list, and neither by an executor: the built-inPlanagent, drafting revision 3, fed a script topython3to see how argparse refuses an argument, after acdinto the project.So over the two campaigns, in 756 Bash calls of every kind, one here-document came from an agent of the chain. The new fact is elsewhere: the rules the chain gives its own agents on commands, no
cd, no here-document, nothing the permission rules cannot read, do not reach thePlanagent, which has no definition in the chain and explores as it likes. In a session that does not bypass permissions, that is where planning would stop for an approval.Status
Executors: one occurrence in two campaigns, nothing to fix. The built-in
Planagent: observed once, not fixed. The only place the chain can say it is the template of the plan, the agent's whole mandate.- changed the title
[-]An executor edited a file through a here-document, which its prompt forbids[/-][+]A here-document, by an executor then by the built-in Plan agent, which the rules of the chain do not reach[/+]on Oct 5, 2026 Counted again in campaign 3: a second here-document by an executor
Campaign 3: five runs on three cases, played from the branch of #83. Raw data, out of git:
.evals/campaign-3/. Counted on 2026-10-05: this issue had not been counted again after that campaign.1 here-document in 327 Bash calls, by the executor of slice 1 of
03-overdue-reminders, run 2, in the session of the approval (.evals/campaign-3/runs/03-overdue-reminders/run-02/logs/04-approval.jsonl):cat >> tests/test_loans.py <<'EOF' class OverdueByMemberTest(unittest.TestCase): def test_members_come_in_first_overdue_order_with_loans_in_file_order(self) -> None:It appends a test class to a file through a redirection and a here-document, where its prompt says to write and edit files with Write and Edit. The dispatching session said nothing of it to the developer this time.
Over the three campaigns, in 1083 Bash calls of every kind: two here-documents by an executor, in campaigns 1 and 3, both to change a file; two by the built-in
Planagent, in one session of campaign 2.Status
Executors: a second occurrence, which this issue said would make it worth a look at the executor's prompt. Not fixed. The built-in
Planagent: observed in one session, not fixed.Decided on 2026-10-05: the rule goes, the agent judges
The developer's decision: restraining the tools of the executor is not the direction the chain took. How an agent writes a command, and the tool it changes a file with, are its own judgment, and a rule on that is too general to be the chain's.
So a here-document by an executor is no longer a breach of its prompt, and nothing has to reach the built-in
Planagent: the two halves of this issue fall together.The rule leaves the prompts of the three commands, of the executor and of the reviewer in #87, with the invariant of
ARCHITECTURE.mdand the sentence of ADR 0032 that held it. What stays is every command run from the root of the repository, with nocdand nogit -C.What it may cost, and is accepted: a developer on the default mode may be asked to approve a command the old sentence steered an agent away from. That is their permission mode's call (ADR 0032).
Status
Decided: not a fault to fix. The rule leaves the prompts in #87, and this issue closes with its merge.
- added a commit that references this issue
on Oct 5, 2026 Closed
#87 is merged: the prompts no longer say how an agent writes a command or changes a file, so a here-document is a choice of the agent and no breach. Not measured: no session was played for that change.
Status
Closed on 2026-10-05: not a fault to fix. The developer decided that how an agent writes a command, and the tool it changes a file with, are its own judgment: the rule that made a here-document a breach left the prompts with #87. What was observed: two here-documents by an executor in three campaigns, both to change a file, and two more by the built-in
Planagent, in one session. The measures and their sources are in the comments below, campaign by campaign.What was seen
05-fine-cap, the executor of slice 1, in the session of the approval:It edits
lending/fines.py, a critical zone of the host, through a script fed by a here-document, where its prompt says to use Edit. The dispatching session saw it and told the developer: "Heredoc: the slice 1 executor used a shell heredoc once to editlending/fines.py, against the project's rules. I told the slice 2 executor not to, and the result is committed and passes the gate."Counted over every stream of the campaign: 1 here-document in 57 Bash calls of
05-fine-cap, none in the 328 calls of the five other cases.Sources
.evals/campaign-1/runs/05-fine-cap/run-01/logs/04-approval.jsonl(the call),judge.jsonandrun.json(the message).agents/surface-executor.mdline 21: "a redirection or a here-document into a file,sed -i. Write and edit files with Write and Edit".Why it matters
Next
Count it again in the streams of the next campaigns, which costs nothing: a second occurrence would make it worth a look at the executor's prompt.