{"record":{"id":"59d1bca522f399a9","repo":"Hmbown/CodeWhale","slug":"fleet-task-is-write-capable-but-declares-no-workspace","errorCode":null,"errorMessage":"Fleet task '{}' is write-capable but declares no workspace.writable_paths or metadata.coordination_contracts","messagePattern":"Fleet task '(.+?)' is write-capable but declares no workspace\\.writable_paths or metadata\\.coordination_contracts","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/fleet/worker_runtime.rs","lineNumber":453,"sourceCode":"    requested_runtime.provider = explicit_fleet_provider_id(agent_profile);\n    if let Some(reasoning_effort) = effective_fleet_reasoning_effort(agent_profile) {\n        requested_runtime.reasoning_effort = Some(reasoning_effort);\n    }\n    if let Some(agent_profile) = agent_profile\n        && let Some(profile_depth) = agent_profile.profile.delegation.max_spawn_depth\n    {\n        requested_runtime.max_spawn_depth = requested_runtime.max_spawn_depth.min(profile_depth);\n    }\n    let runtime_profile = parent_runtime_profile\n        .map(|parent| parent.derive_child(&requested_runtime))\n        .unwrap_or(requested_runtime);\n    let writable_roots = fleet_write_roots(task_spec)?;\n    let coordination_contracts = fleet_coordination_contracts(task_spec)?;\n    if runtime_profile.permissions.write\n        && writable_roots.is_empty()\n        && coordination_contracts.is_empty()\n    {\n        bail!(\n            \"Fleet task '{}' is write-capable but declares no workspace.writable_paths or metadata.coordination_contracts\",\n            task_spec.id\n        );\n    }\n    let session_name = format!(\"fleet-{}-{}\", worker_id, task_spec.id);\n    let launch_manifest = ChildLaunchManifest {\n        owner_session: run_id.to_string(),\n        child_id: worker_id.to_string(),\n        profile: runtime_profile.clone(),\n        prompt: objective.clone(),\n        cwd: Some(workspace.display().to_string()),\n        worktree: worker_workspace_is_isolated(coordination_workspace, workspace),\n        writable_roots,\n        writable_files: Vec::new(),\n        coordination_contracts,\n        expected_artifact: None,\n        deliverables: Vec::new(),\n        resume_identity: Some(session_name.clone()),","sourceCodeStart":435,"sourceCodeEnd":471,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/fleet/worker_runtime.rs#L435-L471","documentation":"fleet_task_to_worker_spec_with_profiles refuses to launch a write-capable Fleet worker that has neither workspace.writable_paths nor metadata.coordination_contracts. A worker with write permissions must declare a bounded claim — where it may write or which contracts it coordinates under — so mutations cannot be unbounded (see fleet_write_roots / fleet_coordination_contracts).","triggerScenarios":"Building a worker spec from a FleetTaskSpec whose runtime_profile.permissions.write is true while fleet_write_roots(task_spec) returns an empty list and fleet_coordination_contracts(task_spec) returns an empty vec — i.e. no writable_paths in workspace config and no coordination_contracts metadata key.","commonSituations":"Defining a fleet task with a write-enabled role but forgetting `workspace.writable_paths`; copying a read-only task template and flipping permissions.write without adding a claim; profiles where the claim lives only in the parent profile and the task spec omits it.","solutions":["Add `workspace.writable_paths` entries (repo-relative paths) to the task spec.","Add a `metadata.coordination_contracts` array (at most 16 string entries) to the task spec.","Set permissions.write to false if the task should not write at all.","Use an agent profile that contributes the bounded write claim for this role."],"exampleFix":"// before\n[tasks.refactor]\npermissions.write = true\n\n// after\n[tasks.refactor]\npermissions.write = true\n[tasks.refactor.workspace]\nwritable_paths = [\"src/refactor/\"]","handlingStrategy":"validation","validationCode":"if task.permissions.write && task.workspace.writable_paths.is_empty() && task.metadata.get(\"coordination_contracts\").is_none() {\n    return Err(\"write-capable task needs writable_paths or coordination_contracts\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Pair every write-enabled role with an explicit bounded claim.","Default write permissions off unless a claim is defined.","Review task templates after permission changes."],"tags":["fleet","permissions","workspace","write-access"],"backgroundTag":"missing-required-config-field","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}