Skip to main content

Current limitations

autodev is pre-release software. Its four trust rules are the design contract, but the current 0.1.0 implementation does not enforce every rule on every path. Review these limits before a live fleet; story IDs name corrective work on the repository board.

Inspect the evidence for important changes

A delivery record is part of the trust chain, not a substitute for it. For consequential changes, inspect the landed commit, candidate diff, criterion evidence, independent review, and post-merge gate together.

Delivery and planning integrity​

  • Criterion handles are not wired end to end (A-105). Per-criterion command, test, and artifact handles can be declared in planning metadata, but handoffs still bind repository-level evidence more broadly than those handles imply. Confirm that each acceptance criterion is actually covered by the recorded checks.
  • A Refs: trailer can retire a story nobody implemented (A-158). The scheduler uses trailers to identify work already present on the base branch. A commit touching non-document configuration, such as .autodev/fleet.toml, can therefore count as implementation when its trailer names a story for context. Put a story in Refs: only when the commit delivers it; mention contextual IDs in prose instead.
  • Planning state and delivery state remain separate. A direct board transition to done proves only that the transition's gates passed. It is not interchangeable with a fleet delivery record that binds handoff, review, integrated revision, gate, and base-ref advancement.

Confinement and agent connectivity​

  • Codex extra_args can weaken the declared sandbox (A-121). Validation does not recognize every sandbox-bypass or profile flag. Do not pass --dangerously-bypass-approvals-and-sandbox, --yolo, or --profile through extra_args.
  • Coding agents are local CLI processes today. Native adapters exist for Codex and Claude Code; direct model-provider API turns are roadmap work (A-160 and A-161).
  • Generic command bridges are intentionally thin (A-162). The adapter substitutes {prompt} and observes the process and Git result, but does not provide vendor-specific usage parsing, model routing, or arbitrary writable state. Pin and smoke-test every non-native harness setup.

Daemon and process lifecycle​

  • The daemon owns state and the drive loop. Starting it starts one drive per registered workspace unless --no-drive is supplied. A competing hand-run drive is refused by name.
  • daemon stop and daemon restart do not supervise or re-exec. Run bounded fleet shutdown for each dispatching workspace, require frozen, then let the external supervisor replace the daemon and run fleet start after verification.
  • Registration is local-machine infrastructure. The daemon is loopback-only, its bearer token is local, and all registered workspaces share one SQLite file with workspace-scoped records. Postgres tenancy, hosted TLS, remote execution, and cross-host exclusion remain roadmap work.
  • The daemon is required for a registered workspace. There is no repository-local fallback for registered runtime history. An unregistered repository can still use its local store in process. This keeps board-only and single-repository use service-optional without allowing two histories for one registered workspace.
  • Superseded. autodev serve remains as a temporary standalone compatibility path. The supported combined runtime is one daemon start process with separate client and machine listeners.

Operator workspace and connectors​

  • Requests are durable; tasks are not published yet. The Operate surface can record requests and answers, but no typed classification event currently binds a request to a task with owner, workflow, and status. The Tasks tab reports that boundary as unavailable.
  • Connect is a catalogue and credential-wiring surface, not a general connector executor. It can show compiled providers and operations and store/revoke declared credentials, but this build does not turn every catalogued operation into an executable product action.
  • The default connector credential store is not encrypted. It is an atomic file outside the repository with a 0600 file in a 0700 directory, and widened modes are refused. Set AUTODEV_CREDENTIAL_STORE=memory to keep nothing at rest and accept that every credential is lost on restart. A Vault binding is not shipped in this runtime.
  • The UI is loopback-only and locally authenticated. The act token is a local capability, not OAuth, SSO, or a multi-user authorization system. Do not expose the control endpoint through a reverse proxy and assume its current token model became internet-safe.

Measurement​

  • Older cost records remain as recorded. New Codex pricing separates cached input correctly, but records written before that fix were not rewritten. Historical totals spanning those turns can be overstated; inspect the coverage and model breakdown instead of treating the aggregate as exact.
  • Unknown remains unknown. A harness with no usage report, an unpriced model, a story with no Git lifetime, or a forecast with no measured delivery rate cannot contribute a zero. Some aggregates will therefore remain partial even when the command succeeds.

Recovery and maintenance​

  • An unpark deferral is not represented in JSON (A-191). When another live wave owns the needed area, fleet unpark writes nothing. Human output names the holder, while JSON shows the unchanged parked record and original reason. Do not treat that JSON document alone as proof that an unpark was never attempted.
  • Some orphaned processes still require judgment (A-135). Ordinary dead workers are recovered, but a missing process group or refused kill can leave a live wave the reconciler cannot safely terminate. Inspect fleet status, fleet doctor, and events; use park, unpark, or retire with a reason rather than deleting state.
  • Publication and deployment are outside the delivery boundary. Landing a gated commit does not push a remote branch, merge a forge request, publish a package, deploy an environment, or notify an external system unless a separately granted surrounding workflow performs that action.

These are active boundaries, not accepted permanent behavior. Check the board and installed binary you intend to operate: this page describes the repository revision that published it, while the development branch moves quickly.