Problem
The three practice GCUs (tig/xuss, tig/xuss-c, tig/xuss-lame) are asked to do two jobs at once, and the current workflow only serves one of them well.
| Job |
Need |
| Public template |
Anyone who clones the repo as guidance should see a pristine product-only tree (README + spec / thin product docs)—not last session’s plate, firmware, or build residue. |
| Harness runway |
Maintainers re-run first ship often: mutate, push, prove host gate + CI + metal, without re-cloning every time. |
What I do today
- Try to remember to reset
xuss-c (etc.) to clean start.
cd an existing checkout (I generally do not re-clone).
- Start the agent and run getting-started / first ship.
What actually happens
- A previous run leaves
main mid-flight (scaffold, firmware, product face, build trees).
- The next session is contaminated: agents and operators are not looking at a cold-start template.
- Public “example product” remotes stop looking like examples and start looking like abandoned WIP.
- First-ship honesty rules (clean start before mutate, no past-HEAD salvage) fight the leftover tree every time.
Live symptom class: main on a practice GCU is often not at the product-only clean start (message / tags/clean-start), even though that is what the next eval and the next reader both need.
Why “just fix CI triggers” is not enough
Each session still needs to prove CI. Today that pressure often means pushes to main (practice GCUs are steered “always land on main”).
Broadening CI to PRs / all branches / workflow_dispatch would reduce one reason to pollute main, but:
- It does not restore a pristine template face for users.
- It does not remove the “remember to reset” operator load.
- It does not close the loop (archive attempt → return to clean start).
So CI-on-main friction is a symptom amplifier, not the root design bug.
Root design bug
AGENTS.md currently hard-codes practice GCUs as always commit to main (to avoid PR theater on harness trees). That rule optimizes the harness runway and systematically destroys the public template face after every successful (or abandoned) run.
We already have pieces of the right model (tags/clean-start, occasional attempt-* tags, silico session start provenance + a print-only hard-reset recipe)—but nothing prepares, isolates, and tears down a session so main stays pristine by default.
Related: hero-video capture (docs/hero-video, PR #86) also requires a clean-start practice GCU before honest recording—the same memory hole.
Goals
- Pristine by default —
main on each xuss-family remote is a trustworthy cold-start template for humans and for the next agent.
- Repeatable harness — automate prepare → run → prove CI → archive → restore without re-clone theater.
- No contamination between sessions — local build artifacts and git history of attempts do not silently become the next start state.
- Honest Stage E — CI can go green without leaving finished firmware on public
main.
- Operator gates stay — destructive reset / force-update of
main never becomes silent agent habit.
Non-goals: invent a multi-PR product workflow for real customer GCUs; soft-fork Bedside; re-clone from GitHub on every run as the only fix.
Proposed solution
Product rule: dual surface
| Surface |
Role |
main |
Always product-only clean start (what users clone). Held at / restored to tags/clean-start. |
session/<date>-<agent> (or eval/…) |
Harness runway: first-ship commits land here; CI runs here. |
tags/clean-start |
Immutable baseline (already exists on the practice remotes). |
tags/attempt-… |
Archive of finished or failed runs (pattern already used). |
Replace “practice GCUs always land on main” with:
- Start from clean-start (gate if not).
- Land commits on a session branch (default for evaluation mode).
- End with archive + restore
main to clean-start (operator go on destructive remote update).
- Optional later: a deliberate
demo/latest (or separate demo remote) for a published finished face—not everyday main.
One-liner for agents and docs:
Pristine main is the product; session branches are the lab. CI proves the lab. Tags archive the lab. Teardown restores the product face.
CLI: silico practice (extends #84 session)
| Command |
Behavior |
status |
Remote, HEAD vs clean-start, dirty files, build artifacts, open .silico/session.toml |
prepare |
Fetch; create/switch session branch from clean-start; optional worktree; fail loud if baseline missing |
archive |
Tag attempt-YYYYMMDD-<agent> (or named) at HEAD |
restore-main |
Gated: point local + origin/main at clean-start |
reset |
Gated local hard reset to clean-start + clean of build dirs |
silico session start should check prepare/status for known practice remotes (xuss / xuss-c / xuss-lame), not only print a reset recipe to the session-start SHA.
Agent path hooks (AGENTS.md)
- Stage B on known practice remotes: run
practice status before mutate.
- If not clean-start: one structured gate — prepare-fresh / continue-dirty / restore-main-first.
- Stage E: push session branch, watch Actions; do not require “must be on main” for CI proof.
- Evaluation exit / compound: archive + restore-main (or explicit open TODO if operator defers teardown).
CI (supporting, not the whole fix)
- Plate + practice GCU workflows: run on session branches / all pushes +
pull_request + workflow_dispatch as needed so Stage E does not argue for polluting main.
- Treat this as support for the dual-surface model, not a standalone fix.
Hero video / capture path
- Document
practice prepare (or status green) before recording first-ship takes.
- After capture: archive attempt; restore template face so the next take (and the next reader) is honest.
- CI clip can be session-branch Actions green, not “firmware forever on main.”
One-time hygiene
- When implementing: restore practice remotes whose
main is mid-flight back to clean-start (operator go), after archiving any keep-worthy tip as attempt-* or optional demo/latest.
- Make
tags/clean-start a single machine-readable baseline for status.
Interim fallback (if dual-surface slips)
Keep land-on-main, but make reset-to-clean-start mandatory pre- and post-session (practice status / reset) with operator gates.
Ship this only as a short bridge: it still leaves public main dirty during every session and fails open if teardown is skipped.
Explicitly not the fix
| Avoid |
Why |
| Only broaden CI, keep always-main |
Band-aid; template face still dies mid-flight |
Silent agent force-push of main after every run |
Scary without a gate; races two sessions |
| “Just re-clone every time” as policy |
Rejects the desired UX; automation can use session branches / worktrees instead |
| Soft-fork clean rules per agent |
One silico verb + AGENTS rule |
Treating finished firmware on main as the public template |
Users cannot tell cold start from finished demo |
Acceptance sketch
Related
Problem
The three practice GCUs (
tig/xuss,tig/xuss-c,tig/xuss-lame) are asked to do two jobs at once, and the current workflow only serves one of them well.What I do today
xuss-c(etc.) to clean start.cdan existing checkout (I generally do not re-clone).What actually happens
mainmid-flight (scaffold, firmware, product face, build trees).Live symptom class:
mainon a practice GCU is often not at the product-only clean start (message /tags/clean-start), even though that is what the next eval and the next reader both need.Why “just fix CI triggers” is not enough
Each session still needs to prove CI. Today that pressure often means pushes to
main(practice GCUs are steered “always land on main”).Broadening CI to PRs / all branches /
workflow_dispatchwould reduce one reason to pollutemain, but:So CI-on-main friction is a symptom amplifier, not the root design bug.
Root design bug
AGENTS.mdcurrently hard-codes practice GCUs as always commit tomain(to avoid PR theater on harness trees). That rule optimizes the harness runway and systematically destroys the public template face after every successful (or abandoned) run.We already have pieces of the right model (
tags/clean-start, occasionalattempt-*tags,silico session startprovenance + a print-only hard-reset recipe)—but nothing prepares, isolates, and tears down a session somainstays pristine by default.Related: hero-video capture (
docs/hero-video, PR #86) also requires a clean-start practice GCU before honest recording—the same memory hole.Goals
mainon each xuss-family remote is a trustworthy cold-start template for humans and for the next agent.main.mainnever becomes silent agent habit.Non-goals: invent a multi-PR product workflow for real customer GCUs; soft-fork Bedside; re-clone from GitHub on every run as the only fix.
Proposed solution
Product rule: dual surface
maintags/clean-start.session/<date>-<agent>(oreval/…)tags/clean-starttags/attempt-…Replace “practice GCUs always land on
main” with:mainto clean-start (operator go on destructive remote update).demo/latest(or separate demo remote) for a published finished face—not everydaymain.One-liner for agents and docs:
CLI:
silico practice(extends #84 session)status.silico/session.tomlprepareclean-start; optional worktree; fail loud if baseline missingarchiveattempt-YYYYMMDD-<agent>(or named) at HEADrestore-mainorigin/mainat clean-startresetsilico session startshould check prepare/status for known practice remotes (xuss / xuss-c / xuss-lame), not only print a reset recipe to the session-start SHA.Agent path hooks (
AGENTS.md)practice statusbefore mutate.CI (supporting, not the whole fix)
pull_request+workflow_dispatchas needed so Stage E does not argue for pollutingmain.Hero video / capture path
practice prepare(or status green) before recording first-ship takes.One-time hygiene
mainis mid-flight back to clean-start (operator go), after archiving any keep-worthy tip asattempt-*or optionaldemo/latest.tags/clean-starta single machine-readable baseline forstatus.Interim fallback (if dual-surface slips)
Keep land-on-main, but make reset-to-clean-start mandatory pre- and post-session (
practice status/reset) with operator gates.Ship this only as a short bridge: it still leaves public
maindirty during every session and fails open if teardown is skipped.Explicitly not the fix
mainafter every runmainas the public templateAcceptance sketch
mainmatches clean-start after a normal evaluation teardown.silico practice status|prepare|archive|restore-main(names flexible) exist and are gated where destructive.main.main(e.g. mid-flight xuss-c) restored once as hygiene, with attempt archived if worth keeping.Related
silico session start/ past-HEAD salvage)