Goal
Opt task(kind: "workspace") delegated targets in to unrelated (cross-task-tree) messaging by default, like user-created workspaces (#4440). The repo owner requires this.
Why it is separate
#4440 first granted consent to delegated targets at creation time. Each fix exposed another window: before the handle reservation, on pre-reservation early exits, when an explicit opt-out raced the deferred grant, and across backends (XUM_ALLOW_MULTIPLE_INSTANCES). #4440 now ships user-created workspaces only, and creates delegated targets with skipDefaultUnrelatedWorkspaceConsent.
Design constraints (write a transition table before code)
Key fact: while a delegated turn is live or reserved, unrelated sends to that root are refused (delegatedRootUnavailable) and task_list(scope:"instance") hides it. So a delegated target's default only matters once its creating turn has settled. Keep consent separate from permission to execute now (#4446).
Cover these states: creation, reservation, settlement (completed/error/interrupted), explicit toggle (from any backend), pre-reservation failure, disposable removal, archive, and restart/crash.
- Grant only for the exact newly created workspace, once. Never renew consent on
mode: "existing" follow-ups.
- A pre-reservation failure is not a settlement. Either remove the unsuccessful workspace or finalize the retained one deliberately.
- Skip disposable targets that are being removed. Never unarchive, resume or wake a target as a side effect.
- An explicit settings change from any backend must cancel the pending default in the same serialized durable edit.
- Define crash recovery and failed writes, so a crash before settlement never leaves a workspace permanently pending.
- Verify downgrade against real older builds: whether they drop or preserve any new persisted field, and whether their toggle interacts with it.
- Test with deterministic barriers against real discovery, admission and durable config, not only by asserting that a marker exists.
If the table needs broad new coordination, land durable admission correctness (#4446) first.
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high
Goal
Opt
task(kind: "workspace")delegated targets in to unrelated (cross-task-tree) messaging by default, like user-created workspaces (#4440). The repo owner requires this.Why it is separate
#4440 first granted consent to delegated targets at creation time. Each fix exposed another window: before the handle reservation, on pre-reservation early exits, when an explicit opt-out raced the deferred grant, and across backends (
XUM_ALLOW_MULTIPLE_INSTANCES). #4440 now ships user-created workspaces only, and creates delegated targets withskipDefaultUnrelatedWorkspaceConsent.Design constraints (write a transition table before code)
Key fact: while a delegated turn is live or reserved, unrelated sends to that root are refused (
delegatedRootUnavailable) andtask_list(scope:"instance")hides it. So a delegated target's default only matters once its creating turn has settled. Keep consent separate from permission to execute now (#4446).Cover these states: creation, reservation, settlement (completed/error/interrupted), explicit toggle (from any backend), pre-reservation failure, disposable removal, archive, and restart/crash.
mode: "existing"follow-ups.If the table needs broad new coordination, land durable admission correctness (#4446) first.
Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high