[{"data":1,"prerenderedAt":772},["ShallowReactive",2],{"navigation_docs":3,"-reference-chain-nodes-subprocess-tasks":270,"-reference-chain-nodes-subprocess-tasks-surround":767},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":190,"body":272,"description":760,"extension":761,"links":762,"meta":763,"navigation":764,"path":191,"seo":765,"stem":192,"__hash__":766},"docs\u002F4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks.md",{"type":273,"value":274,"toc":753},"minimark",[275,289,294,348,386,390,455,459,473,550,561,565,568,672,694,698,705,739,749],[276,277,278,279,283,284,288],"p",{},"A ",[280,281,282],"code",{},"kind: subprocess"," task runs one command in the item's worktree. This page is\nthe contract between that command and Kraft. For the task's keys, see\n",[285,286,184],"a",{"href":287},"\u002Freference\u002Fchain-nodes#other-task-kinds",".",[290,291,293],"h2",{"id":292},"the-command","The command",[295,296,301],"pre",{"className":297,"code":298,"language":299,"meta":300,"style":300},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","tasks:\n  lint:\n    kind: subprocess\n    command: sh -c 'npm run lint && npx tsc --noEmit'\n","yaml","",[280,302,303,316,324,337],{"__ignoreMap":300},[304,305,308,312],"span",{"class":306,"line":307},"line",1,[304,309,311],{"class":310},"swJcz","tasks",[304,313,315],{"class":314},"sMK4o",":\n",[304,317,319,322],{"class":306,"line":318},2,[304,320,321],{"class":310},"  lint",[304,323,315],{"class":314},[304,325,327,330,333],{"class":306,"line":326},3,[304,328,329],{"class":310},"    kind",[304,331,332],{"class":314},":",[304,334,336],{"class":335},"sfazB"," subprocess\n",[304,338,340,343,345],{"class":306,"line":339},4,[304,341,342],{"class":310},"    command",[304,344,332],{"class":314},[304,346,347],{"class":335}," sh -c 'npm run lint && npx tsc --noEmit'\n",[276,349,350,351,354,355,358,359,362,363,366,367,370,371,374,375,378,379,381,382,385],{},"Kraft does not run ",[280,352,353],{},"command"," through a shell. It splits the string into\narguments the way a shell would (Python's ",[280,356,357],{},"shlex.split",") and runs the first one\ndirectly. So ",[280,360,361],{},"&&",", ",[280,364,365],{},"||",", pipes, redirects and ",[280,368,369],{},"$VAR"," do nothing on their own:\n",[280,372,373],{},"npm run lint && npx tsc"," runs ",[280,376,377],{},"npm"," with ",[280,380,361],{}," as an argument. Wrap anything\nthat needs a shell in ",[280,383,384],{},"sh -c '...'",". A command Kraft cannot split, such as one\nwith an unclosed quote, stops the item before it runs.",[290,387,389],{"id":388},"where-it-runs","Where it runs",[391,392,393,412,421,430,444],"ul",{},[394,395,396,400,401,404,405,408,409,288],"li",{},[397,398,399],"strong",{},"Working directory."," The item's worktree. A ",[280,402,403],{},"scope: each_repository"," task\non a workspace item runs once per selected repository, in that repository's\ncheckout and with its ",[280,406,407],{},"repos.yaml"," entry, and stops at the first run that\ndoes not end ",[280,410,411],{},"done",[394,413,414,417,418,288],{},[397,415,416],{},"Input."," stdin is ",[280,419,420],{},"\u002Fdev\u002Fnull",[394,422,423,426,427,288],{},[397,424,425],{},"Output."," stdout and stderr go to the session log. Read it with\n",[280,428,429],{},"kraft view logs ID --session SESSION",[394,431,432,435,436,439,440,443],{},[397,433,434],{},"Processes."," The command gets a process group of its own. When it exits,\nKraft sends ",[280,437,438],{},"SIGTERM"," to whatever it left running in that group, then\n",[280,441,442],{},"SIGKILL"," 10 seconds later.",[394,445,446,449,450,454],{},[397,447,448],{},"Sandbox."," In a ",[285,451,453],{"href":452},"\u002Freference\u002Fconfiguration\u002Frepos#sandboxed-workers","sandboxed","\nrepo, the command runs inside the sandbox like every other task, and its\nresult file is mounted into the container.",[290,456,458],{"id":457},"environment","Environment",[276,460,461,462,465,466,469,470,472],{},"The command gets the worker allowlist and the repo's ",[280,463,464],{},"env"," and\n",[280,467,468],{},"env_passthrough"," (see\n",[285,471,180],{"href":181},"), plus:",[474,475,476,489],"table",{},[477,478,479],"thead",{},[480,481,482,486],"tr",{},[483,484,485],"th",{},"Variable",[483,487,488],{},"Value",[490,491,492,507,520],"tbody",{},[480,493,494,500],{},[495,496,497],"td",{},[280,498,499],{},"KRAFT_RESULT_PATH",[495,501,502,503,506],{},"The session's ",[285,504,505],{"href":199},"result file",". Writing it is optional.",[480,508,509,514],{},[495,510,511],{},[280,512,513],{},"PYTHONDONTWRITEBYTECODE",[495,515,516,519],{},[280,517,518],{},"1",", so a fix loop's re-run never imports bytecode left over from the code before the fix.",[480,521,522,536],{},[495,523,524,362,527,362,530,362,533],{},[280,525,526],{},"GIT_AUTHOR_NAME",[280,528,529],{},"GIT_AUTHOR_EMAIL",[280,531,532],{},"GIT_COMMITTER_NAME",[280,534,535],{},"GIT_COMMITTER_EMAIL",[495,537,538,539,542,543,546,547,549],{},"The server's own values when it has them, otherwise ",[280,540,541],{},"user.name"," and ",[280,544,545],{},"user.email"," from the repo's git config. The repo's ",[280,548,464],{}," wins over them.",[276,551,552,553,556,557,560],{},"Kraft does not set ",[280,554,555],{},"KRAFT_WORK_ITEM_ID"," or ",[280,558,559],{},"KRAFT_SESSION_ID"," for a subprocess\ntask.",[290,562,564],{"id":563},"how-the-status-is-decided","How the status is decided",[276,566,567],{},"A result file, when there is one, wins over the exit code.",[474,569,570,580],{},[477,571,572],{},[480,573,574,577],{},[483,575,576],{},"What happened",[483,578,579],{},"Status",[490,581,582,596,609,618,627,638,647,662],{},[480,583,584,590],{},[495,585,586,587],{},"The command wrote a result file with a known ",[280,588,589],{},"status",[495,591,592,593,288],{},"That status. See ",[285,594,198],{"href":595},"\u002Freference\u002Fchain-nodes\u002Fresult-file#status",[480,597,598,604],{},[495,599,600,601,603],{},"The result file has no ",[280,602,589],{},", an unknown one, or is not valid JSON",[495,605,606],{},[280,607,608],{},"failed",[480,610,611,614],{},[495,612,613],{},"No result file, or an empty one, and exit code 0",[495,615,616],{},[280,617,411],{},[480,619,620,623],{},[495,621,622],{},"No result file, or an empty one, and any other exit code",[495,624,625],{},[280,626,608],{},[480,628,629,632],{},[495,630,631],{},"The command or the working directory does not exist",[495,633,634,637],{},[280,635,636],{},"config_error",": the item stops for you, and no fix loop runs",[480,639,640,643],{},[495,641,642],{},"The command cannot be split",[495,644,645],{},[280,646,636],{},[480,648,649,656],{},[495,650,278,651,655],{},[285,652,654],{"href":653},"\u002Fconcepts\u002Fcaps-and-budgets#time-caps","time cap"," ran out",[495,657,658,661],{},[280,659,660],{},"capped_out",": the process group is killed and the item stops for you",[480,663,664,667],{},[495,665,666],{},"You paused the item",[495,668,669],{},[280,670,671],{},"paused",[276,673,674,542,676,679,680,682,683,686,687,690,691,288],{},[280,675,411],{},[280,677,678],{},"done_with_concerns"," let the node go on. ",[280,681,608],{}," sends the node to\nits recovery and ",[285,684,685],{"href":195},"fix loop",". ",[280,688,689],{},"needs_context","\nstops the item with the result file's ",[280,692,693],{},"question",[290,695,697],{"id":696},"what-a-fix-loop-sees","What a fix loop sees",[276,699,700,701,704],{},"A failing subprocess task that reports no findings becomes one ",[280,702,703],{},"critical","\nfinding. It holds:",[391,706,707,710,727,733],{},[394,708,709],{},"the task's path and the command that ran;",[394,711,712,713,362,716,719,720,556,723,726],{},"up to five lines from the end of its output: the lines marked ",[280,714,715],{},"FAILED",[280,717,718],{},"Error:",",\n",[280,721,722],{},"Traceback",[280,724,725],{},"✘"," if there are any, otherwise the last five;",[394,728,729,732],{},[280,730,731],{},"Confirm the fix with:"," and the command;",[394,734,735,736,738],{},"the ",[280,737,429],{}," command for the full log.",[276,740,741,742,745,746,288],{},"A command that writes ",[280,743,744],{},"findings"," into its result file reports those instead,\nin the same shape a review agent uses. See\n",[285,747,198],{"href":748},"\u002Freference\u002Fchain-nodes\u002Fresult-file#findings",[750,751,752],"style",{},"html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":300,"searchDepth":318,"depth":318,"links":754},[755,756,757,758,759],{"id":292,"depth":318,"text":293},{"id":388,"depth":318,"text":389},{"id":457,"depth":318,"text":458},{"id":563,"depth":318,"text":564},{"id":696,"depth":318,"text":697},"What Kraft passes a subprocess task, how it runs, and how its exit code and result file become a status.","md",null,{},true,{"title":190,"description":760},"8uI6skcAhWBNe1mV3zmLNeovWTK7kI5o8Kdge1GMiJ4",[768,770],{"title":10,"path":185,"stem":186,"description":769,"children":-1},"Node keys, task kinds, read_only, extends, and canonical paths in chain files.",{"title":194,"path":195,"stem":196,"description":771,"children":-1},"When a node's fix loop opens, what its repair tasks are told, when the judge runs, and what each verdict does.",1790824510012]