From dd39cb68358c1cdbd3438ca74a7232c4e57e6fde Mon Sep 17 00:00:00 2001 From: patrick Date: Sat, 2 May 2026 23:42:38 -0700 Subject: [PATCH 1/4] feat(memory): . fix(memory): fix embedder type error + update README date for seedgo 100% Co-Authored-By: @memory --- src/aipass/memory/README.md | 2 +- src/aipass/memory/apps/handlers/vector/embedder.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/src/aipass/memory/README.md b/src/aipass/memory/README.md index a9f41ddd..63dbc172 100644 --- a/src/aipass/memory/README.md +++ b/src/aipass/memory/README.md @@ -5,7 +5,7 @@ **Purpose:** Central memory archive — vector search, rollover, and memory management for all AIPass branches. **Module:** `aipass.memory` **Created:** 2026-03-07 -**Last Updated:** 2026-04-22 +**Last Updated:** 2026-05-02 **Citizen Class:** builder --- diff --git a/src/aipass/memory/apps/handlers/vector/embedder.py b/src/aipass/memory/apps/handlers/vector/embedder.py index 6c2e8e58..d01e8e53 100644 --- a/src/aipass/memory/apps/handlers/vector/embedder.py +++ b/src/aipass/memory/apps/handlers/vector/embedder.py @@ -126,7 +126,7 @@ class EmbeddingService: ) # Restore original order - ordered_embeddings = [None] * len(texts) + ordered_embeddings: List[Any] = [None] * len(texts) for original_idx, sorted_idx in enumerate(sorted_indices): ordered_embeddings[sorted_idx] = embeddings[original_idx] From a530c83a63a64f5fa2bc30f545fa7ec183f41039 Mon Sep 17 00:00:00 2001 From: patrick Date: Sun, 3 May 2026 08:57:18 -0700 Subject: [PATCH 2/4] =?UTF-8?q?feat(system):=20fix(setup):=20add=20ensurep?= =?UTF-8?q?ip=20check=20to=20prevent=20broken=20venv=20on=20Debian/Ubuntu?= =?UTF-8?q?=20=E2=80=94=20closes=20#495?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: @devpulse --- setup.sh | 13 +++++++++++++ src/aipass/prax/README.md | 3 +-- src/aipass/spawn/README.md | 4 +--- .../builder/.spawn/.template_registry.json | 4 ++-- src/aipass/trigger/README.md | 2 +- 5 files changed, 18 insertions(+), 8 deletions(-) diff --git a/setup.sh b/setup.sh index 923927ff..f279ada9 100755 --- a/setup.sh +++ b/setup.sh @@ -133,6 +133,19 @@ if [ "$PY_OK" != "1" ]; then fi fi +# --- Check ensurepip (Debian/Ubuntu split it into python3-venv apt package) --- +if ! $PYTHON -c 'import ensurepip' &>/dev/null 2>&1; then + echo "" + echo "FAIL: ensurepip is unavailable for $PYTHON." + echo " Without it, 'python3 -m venv' creates a broken venv (no pip, no activate)." + echo "" + echo " Debian/Ubuntu: sudo apt install python3-venv python3-pip" + echo " Fedora/RHEL: sudo dnf install python3-pip" + echo " Arch: (included in base python — file a bug if you hit this)" + echo "" + exit 1 +fi + # --- Create venv --- if [ "$IS_WINDOWS" -eq 1 ] && [ -f ".venv/Scripts/python.exe" ]; then # Windows: skip venv recreation if python.exe exists (rm -rf unreliable due to file locking) diff --git a/src/aipass/prax/README.md b/src/aipass/prax/README.md index 01f7cfc0..4c7ae120 100644 --- a/src/aipass/prax/README.md +++ b/src/aipass/prax/README.md @@ -143,8 +143,7 @@ prax/ │ └── watcher/ # Background system watchers ├── prax_json/ # Auto-created per-module config/data/log files ├── templates/ # Dashboard template schema (DASHBOARD.template.json) -├── tests/ # 375 tests across 16 files -└── tools/ # Standalone utilities (inbox_watchdog.py, verify_branch.py) +└── tests/ # 911 tests across 16 files ``` ### Design Pattern diff --git a/src/aipass/spawn/README.md b/src/aipass/spawn/README.md index ba507bd8..0f9c3d2d 100644 --- a/src/aipass/spawn/README.md +++ b/src/aipass/spawn/README.md @@ -139,9 +139,7 @@ spawn/ │ └── json_handler.py # Standard JSON I/O, operation logging, 7 API functions ├── templates/ │ ├── builder/ # Full scaffold template (45 files, 24 dirs) -│ ├── birthright/ # Minimal template -│ └── .archive/ -│ └── agent_mock_branch/ # Reference implementation +│ └── birthright/ # Minimal template ├── tests/ # 13 test files, 253 tests ├── spawn_json/ # JSON tracking directory ├── tools/ # Branch verification utilities diff --git a/src/aipass/spawn/templates/builder/.spawn/.template_registry.json b/src/aipass/spawn/templates/builder/.spawn/.template_registry.json index ea2fc27f..e096093c 100644 --- a/src/aipass/spawn/templates/builder/.spawn/.template_registry.json +++ b/src/aipass/spawn/templates/builder/.spawn/.template_registry.json @@ -155,7 +155,7 @@ "content_hash": "a4cf0a8e3b4f", "has_branch_placeholder": false }, - "f015": { + "f026": { "path": "apps/modules/__init__.py", "name": "__init__.py", "content_hash": "e3b0c44298fc", @@ -263,7 +263,7 @@ "content_hash": "28e9ae373563", "has_branch_placeholder": false }, - "f026": { + "f015": { "path": "apps/plugins/__init__.py", "name": "__init__.py", "content_hash": "e3b0c44298fc", diff --git a/src/aipass/trigger/README.md b/src/aipass/trigger/README.md index e4dca03f..a96723d3 100644 --- a/src/aipass/trigger/README.md +++ b/src/aipass/trigger/README.md @@ -5,7 +5,7 @@ **Purpose:** Event bus and error dispatch for AIPass. Branches fire events, registered handlers react. Medic watches logs for errors, fingerprints them, gates dispatch through an 8-stage pipeline, and notifies the responsible branch. **Module:** `aipass.trigger` **Version:** 2.2.0 -**Last Updated:** 2026-04-22 +**Last Updated:** 2026-05-02 ## Commands From c7bc27b7b871dedcfe1d0537966f620a975bdb1a Mon Sep 17 00:00:00 2001 From: patrick Date: Sun, 3 May 2026 09:26:47 -0700 Subject: [PATCH 3/4] =?UTF-8?q?feat(system):=20fix(setup):=20add=20ensurep?= =?UTF-8?q?ip=20check=20(#495)=20+=20git=20identity=20config=20(#500)=20?= =?UTF-8?q?=E2=80=94=20closes=20#495,=20closes=20#500?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: @devpulse --- setup.sh | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/setup.sh b/setup.sh index f279ada9..b290931f 100755 --- a/setup.sh +++ b/setup.sh @@ -264,6 +264,34 @@ if [ ! -f "$SECRETS_DIR/.env" ] && [ -f ".env.example" ]; then echo " Copied .env.example → ~/.secrets/aipass/.env (add your API keys there)" fi +# --- Git identity (commits fail without user.email / user.name) --- +GIT_EMAIL=$(git config --global user.email 2>/dev/null || true) +GIT_NAME=$(git config --global user.name 2>/dev/null || true) +if [ -z "$GIT_EMAIL" ] || [ -z "$GIT_NAME" ]; then + echo "" + echo "Git identity not configured — commits will fail without it." + DEFAULT_EMAIL="aipass.system@gmail.com" + DEFAULT_NAME="AIOSAI" + if [ -t 0 ]; then + # Interactive — prompt with defaults + read -r -p " Git user.email [$DEFAULT_EMAIL]: " INPUT_EMAIL + read -r -p " Git user.name [$DEFAULT_NAME]: " INPUT_NAME + GIT_EMAIL="${INPUT_EMAIL:-$DEFAULT_EMAIL}" + GIT_NAME="${INPUT_NAME:-$DEFAULT_NAME}" + else + # Non-interactive — use defaults + GIT_EMAIL="$DEFAULT_EMAIL" + GIT_NAME="$DEFAULT_NAME" + echo " Non-interactive mode — using defaults ($GIT_EMAIL / $GIT_NAME)" + fi + git config --global user.email "$GIT_EMAIL" + git config --global user.name "$GIT_NAME" + git config --global pull.rebase true + echo " Git identity set: $GIT_NAME <$GIT_EMAIL>" +else + echo "Git identity: $GIT_NAME <$GIT_EMAIL>" +fi + # --- Generate branch registry --- if [ ! -f "AIPASS_REGISTRY.json" ]; then echo "Generating AIPASS_REGISTRY.json ..." From 1d02f412f6c6b16616bb753a346c441968fd9032 Mon Sep 17 00:00:00 2001 From: patrick Date: Sun, 3 May 2026 09:29:14 -0700 Subject: [PATCH 4/4] =?UTF-8?q?feat(system):=20fix(setup):=20protect=20~/.?= =?UTF-8?q?secrets/=20with=20permissions.deny=20+=20fix=20chmod=20on=20inn?= =?UTF-8?q?er=20dir=20=E2=80=94=20closes=20#496?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: @devpulse --- setup.sh | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/setup.sh b/setup.sh index b290931f..c848de3c 100755 --- a/setup.sh +++ b/setup.sh @@ -253,6 +253,7 @@ if [ ! -d "$SECRETS_DIR" ]; then echo "Creating secrets directory at $SECRETS_DIR ..." mkdir -p "$SECRETS_DIR" chmod 700 "$HOME/.secrets" + chmod 700 "$SECRETS_DIR" echo " ~/.secrets/aipass/ ... created" else echo "Secrets directory already exists — skipping" @@ -570,6 +571,24 @@ if "MSYS" in msys or "msys" in msys or "MINGW" in msys: env_block["PYTHONUTF8"] = "1" settings["env"] = env_block +# Deny rules — hard-block tool access to secrets +permissions = settings.get("permissions", {}) +deny = permissions.get("deny", []) +secrets_deny = [ + "Read(~/.secrets/**)", + "Read(/home/*/.secrets/**)", + "Bash(cat *~/.secrets*)", + "Bash(less *~/.secrets*)", + "Bash(head *~/.secrets*)", + "Bash(tail *~/.secrets*)", + "Bash(*~/.secrets*)", +] +for rule in secrets_deny: + if rule not in deny: + deny.append(rule) +permissions["deny"] = deny +settings["permissions"] = permissions + settings_path.write_text(json.dumps(settings, indent=2) + "\n") print(f" hooks -> {settings_path}") print(f" AIPASS_HOME -> {repo_root} (in settings.json env)")