Version: daemon 2.1.0, codex-acp runtime, scratch workspace
What happens
An agent edited one of its own installed skills under .agents/skills/<name>: it changed SKILL.md and added a references/ file. That's possible whenever the runtime can write to the workspace. The next time the daemon re-installed skills, every turn for that agent failed with:
SkillLedgerSafetyError: skill installation failed and the prior executable set could not be restored (installation failure: confined skill workspace mutation was refused: confined skill workspace mutation failed: agentconnect skill mutation: refusing to replace unowned skill: skill mutation source changed)
The user only sees "Agent failed to respond". The ledger stays in phase applying, and every later message hits the same error. It clears only when someone puts the skill directory back exactly as the receipt recorded it.
Expected
- A previously owned bundle that no longer matches its receipt should be skipped with a warning and reported as a conflict, the same way a foreign bundle is today (
skills: skipped unowned skill … in skill-install-ledger.ts). It shouldn't fail the whole turn or block the other skills.
- The error shouldn't say "the prior executable set could not be restored" when nothing was moved. Here the reservation was refused before the rename, no quarantine or trash entries existed, and every prior bundle was still in place.
Repro
- Give an agent a git skill source and let it install.
- Change any file inside one installed skill directory in the agent workspace.
- Change something that forces skill re-installation, such as the source ref or the agent's integrations, then message the agent.
Version: daemon 2.1.0,
codex-acpruntime, scratch workspaceWhat happens
An agent edited one of its own installed skills under
.agents/skills/<name>: it changedSKILL.mdand added areferences/file. That's possible whenever the runtime can write to the workspace. The next time the daemon re-installed skills, every turn for that agent failed with:The user only sees "Agent failed to respond". The ledger stays in phase
applying, and every later message hits the same error. It clears only when someone puts the skill directory back exactly as the receipt recorded it.Expected
skills: skipped unowned skill …inskill-install-ledger.ts). It shouldn't fail the whole turn or block the other skills.Repro