88 Commits
Author SHA1 Message Date
AIOSAI 73baa0005f feat(hooks): sound layer across the hook fleet + temporal grounding handler — sounds mirror the log (2465 green, audit 100, compass #157); new prompt/temporal.py injects live local date/time every turn, host-tz, wired both wires (hooks.json + provider manifest). Built by @hooks 2026-07-21 18:04:08 -07:00
AIOSAI 33a1510cbb feat(hooks): auto-compact prep - context gauge + snapshot stamp (DPLAN-0253). context_gauge (UserPromptSubmit) reads live transcript fill each prompt and nudges /prep at 80 pct of the compact trigger, escalates at 95, once per threshold per session; pre_compact_prep (PreCompact) stamps AUTO-COMPACT SNAPSHOT (fill, dispatch locks, open plans, git, inbox) into the compacting branch local.json; shared context_window resolver (env > branch settings.local.json > 200k). Round 2 root cause: name-scoped events (UserPromptSubmit/PreCompact) invoke the bridge per-handler - hooks.json alone never fires; provider_manifest.json entries added for both + @hooks branch prompt corrected with provider-wire reminder (Patrick-directed). 36 new tests, suite 1190 green, seedgo 100 pct, both re-run by devpulse. Built by @hooks, 2 rounds. Go-live: user syncs ~/.claude/settings.json from manifest + fresh session 2026-07-20 13:13:43 -07:00
AIOSAI 71e5198d4c feat(onboarding): install ends in a conversation — TDPLAN-0014 chain complete + v2.7.3 bump. Dead-end kills: empty-template init runs handoff+report (default path reaches the conversation), non-interactive completes with defaults exit 0 (was EOFError crash — caught by live door-test after green suites), aipass new TTY auto-launch into the manager w/ printed fallback + escape line. Install-to-chat handoff: launch_inline @aipass with authored first prompt + install report context, ONE unified INIT_PROMPT, headless print-only. Welcome Mode branch prompt (opener spec, name-ask, turn-5 triage, hooks-first via real dispatch, WSL beat, exact-command principle) behaviorally door-tested over a live multi-turn run incl second-session momentum. Feedback pulse (@hooks): 10-turn one-liner, aipass feedback on/off alias, disabled on host, live-proven cadence+persistence. README: install-ends-in-conversation story, aipass new documented, non-interactive truth. CHANGELOG + version 2.7.3 both files. seedgo 17/17 100%, local CI gate green 2026-07-18 15:28:44 -07:00
AIOSAI 1902775812 feat(compass): Track 2 ambient recall — compass_recall hook + pure governance (memory) + recall API w/ rare-token scoring (devpulse), verbatim tidbit injection, live acceptance matrix green (DPLAN-0246/FPLAN-0332). 446+1011+1129 tests, seedgo 100% 2026-07-16 20:43:49 -07:00
AIOSAIandClaude Fable 5 222a9c8382 docs(navmap): open-source status is fleet-wide identity, not a coding footnote (Patrick ruling)
Every agent's tier1 navmap now states AIPass is open source in the intro
and reframes the house rule as write-as-if-it-ships. External scans are
contributions, not intrusions.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEAyLFCuo4uD934fwFxocz
2026-07-15 18:23:13 -07:00
AIOSAIandClaude Fable 5 a8b1ce6658 feat(hooks): DPLAN-0244 hooks.json trust model hardening — Layer A engine gates + Layer B registry/CLI
Closes a zero-interaction RCE where a hostile repo's .aipass/hooks.json
(discovered via loader CWD walk-up, bridge wired globally) could run an
arbitrary command-type hook on SessionStart. Defense-in-depth:

Layer A (engine): refuse command-type hooks from per-project configs via
unconditional _source clobber; gate handler paths to aipass.* namespace.
Layer B (loader+CLI): trusted-project registry (path+sha256), fail-closed
trust-check, $AIPASS_HOME-only bootstrap (no TOFU), aipass init auto-enroll
+ new aipass trust/revoke commands.

Live acceptance test (real bridge, real payload) proves both gates block
independently. 1105 hooks + 133 aipass tests green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEAyLFCuo4uD934fwFxocz
2026-07-15 18:23:02 -07:00
AIOSAI be68d23d6a fix: CI green pass on PR#696 — lint (ruff format on trigger runaway tests), seedgo 100% both red branches (@hooks: new json_handler + persistent_alert/alert_dismiss wired through it, cc_sessions introspection gate, _menu_live nesting extraction, 1071 tests; @prax: rate_tracker DI refactor — module layer injects logs_dir + trigger.fire via configure(), 1028 tests), navmap trim 9.3k→7.9k under injection cap. All owner-fixed via dispatch, devpulse-verified: both audits 100% independently re-run, full runaway chain re-proven live post-refactor (332 lines/min storm → WARNING at 130s → trigger → @aipass triage → alert banner rendered in-session → dismiss clears). Burst-evasion design finding (pre-existing, not regression) filed to @prax by mail. 2026-07-15 08:49:21 -07:00
AIOSAI 81658ce0ea feat: runaway-log detection + escalation (DPLAN-0242, agent-designed) + citizen wake-back. Prax-led three-branch build via TDPLAN-0013: prax rate_tracker (disk-persisted volume detection, WARNING >100 l/min 2min / CRITICAL >10 l/s 1min, 4th monitor thread) + drone @prax log-health; trigger runaway_log_detected event + handler (per-file 30min cooldown independent of medic breaker, UNKNOWN->prax, writes .aipass/alerts.json); hooks persistent_alert banner + drone @hooks dismiss (devpulse fixed nearest-.aipass path bug in both + wired settings.json - registration is not deployment). Live-fire proven: planted 240 l/min storm -> detect 257 l/min -> event -> dispatch -> @aipass autonomous no-action triage -> banner -> dismiss. ai_mail wake ruling: owner-gate removed (citizen wake-back live-proven), devpulse structurally unwakeable (manager check all paths), self-wake loop found+fixed same night (guard + senderless wake-back sessions). Navmap comms section, 4 branch READMEs + root README + CHANGELOG. ~77 new tests, suites green: prax 1028, trigger 619, hooks 1071, ai_mail 765 2026-07-15 00:05:02 -07:00
AIOSAI b791af2372 feat: medic revival + concurrent monitor viewers — pytest logs route to tmp (PYTEST_CURRENT_TEST, fixture storms cant pollute prod logs), breaker self-heals (half-open on read, close on probe, cooldown decay), TTL mutes (mute/off auto-expire 24h, --for/--forever, temp off keeps detection), footer+navmap mute breadcrumbs; prax monitor lock scoped to TG relay role (relay.pid) so viewers always start — Patrick ruling: processes are not agents. Loop proven live: planted commons bug fixed by medic dispatch in 105s byte-identical. 993 prax + 603 trigger green 2026-07-14 14:57:40 -07:00
AIOSAI 5c82db6729 feat: TG user-comment mirror — user messages from ALL doors (terminal/remote) now mirror to the branch TG chat with origin tag. UserPromptSubmit relay handler (self-contained in telegram skill, crash-isolated last entry in hooks.json), human-only noise fences (system/task notifications, slash-command output, dispatch wakes, subagents, TG-echo, dupes), inbound hardening (stale-pending clean before write, undelivered-overwrite warning). 47 new TG tests, execution proven via engine.jsonl, positive path live-verified to real TG chat. 2026-07-14 02:42:41 -07:00
AIOSAI 364cefa5fd fix: DPLAN-0241 session-mgmt overhaul — boot shim passthrough (only bare/permission-mode intercepted), session_boot 3-option boot menu (resume/new-closes-old/close, per-kind proper stops, never kill for bg), presence_gate repaired (session-file PID resolver, bg sessions gated) + wired OBSERVE-ONLY, wire_verify flags unwired security hooks as ERROR, new drone @hooks sessions + reclaim, PID-first session naming. Plus S304 discovery report + DPLAN-0241. Verified live: gate's first production run logged correct would-block, no self-block; 987 hooks tests green. 2026-07-13 22:50:27 -07:00
AIOSAI 0886c9013c #620: git_gate block messages guide instead of dead-end — explain WHY git is enforced, list key drone @git commands, point to --help, show disable path (git_gate.enabled=false in .aipass/hooks.json, verified engine skips disabled hooks per-hook). Split GIT_GH_REDIRECT -> GIT_REDIRECT + GH_REDIRECT; EDIT_REDIRECT shows disable too. Init notice in project_hooks.json template, on/off in README. 6 tests, seedgo 31/31. 2026-07-10 21:30:35 -07:00
AIOSAI 0878afbc81 #676 aipass: init update now refreshes AGENTS.md + prunes stale managed cruft. GAP1 — update_project synced AGENTS.md from a .aipass/project_AGENTS.md template that never existed, so AGENTS.md was a SILENT no-op on every 'aipass init update' (only CLAUDE.md, whose template exists, synced). Added the template + reconciled create/update to one source. GAP2 — update was additive-only; added a whitelist-scoped cleanup pass (_STALE_MANAGED_FILES, currently the retired aipass_global_prompt.md) that removes only positively-identified managed artifacts, logs each removal, never touches user files (registry/README/.gitignore/src/.trinity). SHIP-GAP caught in verify: .aipass/project_AGENTS.md was gitignored by the .aipass/.gitignore allowlist — added !project_AGENTS.md negation or the template would never distribute (the fix would be inert on real installs). Built by @aipass, verified by devpulse: 83 bootstrap tests green (+7), seedgo 31/31, live repro proves update emits AGENTS.md (name-interpolated) AND removes a planted cruft file. 2026-07-10 03:07:01 -07:00
AIOSAI 874c7fed2e #678 owner-capability: seal project ownership in the registry + wake the OWNER back on dispatch completion. TDPLAN-0012 — 3 parts built in parallel against a frozen is_owner contract, verified end-to-end by devpulse.
@spawn: owner + registry_id written into the SEALED registry entries (authority lives in registry, not the self-editable passport). ensure_project_has_owner() now keys off citizen_class=manager (was earliest-created, which mislabeled @aipass) and writes the registry entry. get_owner()/is_owner() resolvers added. 315 tests, seedgo 100%.
@hooks: new registry_gate PreToolUse handler seals *_REGISTRY.json — blocks raw writes/tee/sed/rm + Edit/Write/MultiEdit, redirects to drone @spawn; per-clause bypass defeats compound-command smuggling; reads allowed. 82 tests, seedgo 100%.
@ai_mail: wake-back reslope — SKIP_SENDERS blocklist replaced by an is_owner allowlist. Only the project owner is woken when their dispatched agent completes; all other guards intact (depth cap, lock, occupancy, honest messaging, dispatch_wake.log). seedgo 100% on the changed file.

devpulse cross-part verify (REAL unmocked resolver): is_owner resolves devpulse-only; gate 13/13 incl compound-smuggle blocked + reads/drone-@spawn allowed; wake-back wakes owner / skips non-owner / respects depth-cap; 195 new-suite tests green together. Note: AIPASS_REGISTRY.json is gitignored — this ships the CODE; owner data regenerates per-install via ensure_project_has_owner. Still open (PART 4): gate watchdog+feedback on is_owner; portability of owner-only privileges across projects.
2026-07-10 00:46:17 -07:00
AIOSAI 5fea5bbf44 seedgo+hooks: json_handler empty-guard (#667) + fix silent hook-wiring break — new wire_verify guard fails loud on empty/orphaned/dup provider hook events (the real bug: half-wired hooks written silently); presence_gate marked provider_wired:false (dormant by design, not a break); snapshot fixture corrected (drop presence_gate, add SessionStart:cadence_reset); load_json empty-guard. Live SessionStart orphan re-wired separately. 1138 seedgo + 831 hooks green 2026-07-09 16:12:44 -07:00
AIOSAI 195b9f081c backup: drive-sync respects .backupignore on sync path + PosixPath log fix — stale-store junk can't cause 8hr syncs (built by @backup) 2026-07-07 21:18:39 -07:00
AIOSAI 5fd8c6a015 cadence fresh-context reset + aipass misroute guidance: SessionStart wiring (handler/config/setup.sh), loaders period-5, kernel+navmap aipass-exception, guide-not-crash (drone/aipass) 2026-07-07 20:02:45 -07:00
AIOSAIandClaude Opus 4.8 e1ac4e365f docs(prompts): .trinity entry-cap awareness — point at live *_meta line, no hardcoded numbers
Navmap (@hooks): one bullet in the Memory section — caps are hook-enforced,
the live cap is rendered in each file's *_meta line; read it before writing,
draft to ~80%, one-pass rewrite if rejected. Devpulse branch prompt: same
behavior, explicitly notes caps are NOT listed (single source =
memory.config.json → entry_limits, auto-rendered by @memory's tab_renderer).
Change the config → enforcement + in-file docs follow mechanically; prompts
never go stale.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Q3mZT61WsKVN3srCwVDBiW
2026-07-02 05:41:24 -07:00
AIOSAIandClaude Opus 4.8 beb048dadf fix(hooks): presence_gate keys per-branch via hook_data cwd; engine propagates block exit code (FPLAN-0289 P1)
Activation fixes for the single-session presence gate. Two bugs blocked it,
both caught by live testing after all units were green:

1) Wrong branch key. presence_gate used Path.cwd().name, but under the Claude
   Code bridge the hook process cwd is the project root, so every session keyed
   to "AIPass": the gate never enforced one-live-session-per-branch and would
   have rejected sessions project-globally (any 2nd interactive session in any
   branch). Now _resolve_branch(hook_data) reads the event payload's cwd (the
   real session dir) and walks up to the branch root (.trinity/ or apps/),
   mirroring branch_loader. Applied in handle() and handle_stop().

2) Block never reached Claude Code. engine.dispatch() returned only stdout, so
   the bridge could not surface a non-zero exit. dispatch() now returns
   (stdout, exit_code) and the bridge exits with it on a block. Pre-existing gap
   affecting every block hook on every event; now fixed engine-wide. An
   intentional block (exit 2 + {"decision":"block"}) propagates; a crashing hook
   (exit 2, non-JSON stdout) is logged and falls through, so the gate fails open.

Proven: 110 hooks unit tests pass (6 new for branch resolution); seedgo @hooks
100%, no type errors. Live bridge end-to-end (real live holder + real bridge):
duplicate into a held branch -> exit 2 + block reason naming the branch; a
different free branch -> exit 0 (per-branch isolation intact). Gate remains
dormant: not yet wired into provider settings.

Design: DPLAN-0225 / FPLAN-0289 P1 activation. Build by @hooks.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CqoxFdbDMirzkQ5kjRVVos
2026-06-29 17:46:09 -07:00
AIOSAIandClaude Opus 4.8 40602702ef docs(backup): correct backup/.backup/.backupignore docs across the system
Streamlined prompts had drifted from reality. Full-context investigation
(3 agents + @memory storyline) corrected:

- .backup/ documented as a SHARED runtime namespace (3 writers: @backup
  snapshot stores, @memory rollover safety copies, @flow processed_plans),
  not @backup-exclusive.
- @backup README: full 11-command coverage, .backup/ store layout, and a
  .backupignore (gitignore-for-backups: pathspec/gitwildmatch, BUILTIN_IGNORES,
  self-exclusion, ships as config) section.
- @backup branch prompt: stale .backup_system/ -> .backup/ (3x), drive_test.py
  -> drive_check.py (was misleading the agent every turn).
- Root README: @backup added to roster + uninstall covers .backup/.backupignore.
  navmap @backup line corrected (Drive planned + shared namespace).
- Shipped root /.backupignore realigned to BUILTIN_IGNORES (dropped stale
  .backup_system/, removed over-broad *logs).
- Removed dead backup/run/ test dir.

@backup verified: 220 tests green, seedgo 100%. Closes td-218.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QEQZXCtgnF3NQtcttTErpq
2026-06-24 06:51:18 -07:00
AIOSAI 6db606eb01 fix(memory,prompts): rollover repair + retire-for-all + seedgo #37 path cleanup
Batch of S243/S244 work held for PR640. Only devpulse has git write, so all
branches' changes (@memory, @prax, @hooks, @aipass, @skills, @flow, @backup,
@seedgo) land through this single commit.

Memory rollover (correctness):
- @hooks rollover hook now delegates to drone @memory rollover check/run — it
  had been reading stale .trinity limits (moved to memory.config.json by
  DPLAN-0210), falling back to a 600-line check that never fired, so rollover was
  silently dead for weeks. compact.py reads the current list schema. Both fail loud.
- @memory removed the v1 line-count/600 fallback entirely — v2-only, fail-loud
  (959 tests).

Retire-for-all (DPLAN-0215):
- Legacy global prompt fully removed across every runtime: global_loader.py +
  tests deleted, hooks.json/project_hooks.json blocks stripped, bootstrap global
  seeding removed, cadence default + bypass cleaned, global .md files archived.
  Codex SessionStart + Claude cadence read the same tier files.

Hardcoded-path cleanup (seedgo #37):
- New HARDCODED_PATH checker (#37). @memory symbolic.py + @prax branch_detector.py
  home paths -> dynamic/generic. Both 100% Hardcoded_Path.
- seedgo provider_hooks_snapshot.json fixture refreshed to the tiered baseline.

Genericization: patrick -> user across tracked source, docs, templates.
CHANGELOG: 2026-06-19 + 2026-06-23 sections added.
2026-06-23 16:17:10 -07:00
AIOSAI 2c91f79f2f feat(hooks): tiered prompt injection — Tier 0 kernel + Tier 1 navmap by cadence (FPLAN-0284 P2-P4, DPLAN-0214)
Replaces the single 8k always-injected global prompt with cadence-tiered injection:
- Tier 0 (.aipass/tier0_kernel.md, ~2k) injects EVERY turn — identity grounding, the drone --help reflex, disaster-preventer rules. Folds DPLAN-0213 C1 (faithful-reporting) + C2 (no-gold-plating sub-agent brief).
- Tier 1 (.aipass/tier1_navmap.md, ~7.7k) injects every 5th turn + session-start + post-compaction — full agent roster, framework, conventions, plus a new Terminology section migrated from the S211 backup.
- Old global_prompt loader retired (disabled in hooks.json, removed from cadence wiring); aipass_global_prompt.md kept as a reference snapshot.

Engine (built by @hooks): per-loader period in cadence.py should_fire() (back-compatible: unset period falls back to global); new tier0_kernel + navmap handlers; bypass.json extended to cover the two new dynamically-dispatched handlers. 614/614 tests pass, seedgo @hooks 100%.

Live-verified: tier0 fires every turn, navmap on turn 0/5/10, turn counter advances once per turn (not per loader), no double-injection. Machine-local wiring (cadence_config.json, ~/.claude/settings.json bridge) updated on this host; fresh-clone seeding of those is a tracked follow-up.

PROMPT_STYLE.md reference updated to point at the tier files as canonical examples.
2026-06-18 17:48:35 -07:00
AIOSAI b698dd8ce0 style(prompts): CC prompt-craft steals + cleaned S241 prompts (DPLAN-0213 A/B, FPLAN-0284 P1)
- PROMPT_STYLE.md: new 'Writing voice' section (file_path:line refs, no-colon-before-tool-call, no emojis, write-for-a-person, three-tier where-detail-lives) — harvested from Claude Code's own prompt
- devpulse local: blast-radius habit before any drone write-op (reversibility + scope)
- global + devpulse-local: S241 whitespace/structure cleanup (readable English restored)
2026-06-18 17:13:18 -07:00
AIOSAIandClaude Opus 4.8 16848daf54 docs(prompts): complete agent list in global, trim+restyle devpulse local, smooth culture doc
Add @skills/@daemon/@commons/@backup to global prompt agent list; trim+restyle
devpulse local prompt to PROMPT_STYLE (single # headers, no emphasis, de-dup vs
global); smooth .claude culture doc (kill repeats, drop mechanical overlap).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-16 02:49:45 -07:00
AIOSAIandClaude Opus 4.8 392f5d83b0 feat(skills): port Dev-Pass Telegram bridge as self-contained AIPass skill (FPLAN-0277 P1-P3)
P1 @api: get-secret command + auth/secrets.py (reads ~/.secrets/aipass/).
P2 @skills: 14-file bridge (~5300L) + ~424 tests ported to .aipass/skills/telegram/, seams rewired to services (prax logging, @api secrets).
P3 @hooks: telegram_response.py Stop hook (3-layer SubagentStop/sidechain/cursor defense) registered via the hooks engine.
P5 audit (TELEGRAM_PORT_MAP.md, 366 tags): 288 verified, 23 gaps (top conftest log-isolation fixture fixed), 55 live-deferred.
Lint: 5 F841 unused-var autofixes in ported tests. Known gaps + live bring-up (creds, systemd, telethon, round-trip) pending. CI red unrelated; land-only, no merge.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 06:50:15 -07:00
AIOSAIandClaude Fable 5 2aafade678 feat(prompt): slim global prompt to context-on-demand map, 13.8KB->7.8KB (DPLAN-0201)
Rewrite the always-injected global prompt from a ~13.8KB encyclopedia
into a ~7.8KB navigation map. The prompt now carries AWARENESS; detail
is fetched on demand via 'drone @agent --help'. Dissolves the harness
~10k-char truncation bug — the old prompt's tail (Hard Rules onward)
silently never arrived; the slim one injects whole.

- drone pinned at top as the router; one drilled reflex: --help before use
- framework tree restored; all 13 agents as 2-3 sentence bios
- introspection named as our term; breadcrumb-first navigation flow
- git its own section (raw git/gh blocked, drone-only, devpulse-writes)
- plans section (DPLAN/FPLAN/PPLAN/RPLAN + 'drone @flow templates')
- @memory chroma awareness (local + global stores, search before cold)
- sub-agent usage section incl. model practice (never fable)
- PROMPT_STYLE-conformant; 7855 chars (cap 8000, measured in chars)

Backup retained: .aipass/aipass_global_prompt.BACKUP-2026-06-09-S211.md

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-09 20:16:29 -07:00
AIOSAIandClaude Opus 4.8 626ab81a46 refactor(status): decommission entire STATUS flow — STATUS.local.md + central STATUS.md retired, replaced by local.json todos[] + dashboard count (TDPLAN-0007)
Cross-branch coordinated change. Per-branch STATUS.local.md (13) + central
STATUS.md deleted; all prompts/docs/skills/hooks/footer/scaffolding scrubbed.
Status-sync engine kept intact-but-inert (trigger registry unwired, 3 lines).
Replacement: operational todos[] in .trinity/local.json (@memory schema, capped,
rollover-exempt), pushed to all 13 branches + surfaced as dashboard todo_count.

Owners: memory (schema+global push+template), prax (dashboard todo_section +
engine dormant), trigger (unwire), aipass (init scaffolding), spawn (template
delete + todos[] seed), hooks (compact recovery), ai_mail (footer), seedgo
(_RUNTIME_ARTIFACTS cleanup), devpulse (scrub+delete+assemble).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 21:53:24 -07:00
AIOSAI 1ef1e2e89c feat(memory): auto-process memory pool + rollover on session-start/pre-compact (TDPLAN-0005) 2026-06-06 20:28:19 -07:00
AIOSAI e63a4e9945 feat(#630): retire blanket rm deny + aipass doctor migration
Phase 2 of #630. The rm_gate hook + drone rm now own destructive-delete
protection (cross-provider, path-aware, teaching), so the Claude-only blanket
deny is redundant AND harmful (it short-circuits before the hook, suppressing
the teaching message).

- setup.sh: removed Bash(rm -rf*) + Bash(rm -r *) from git_deny (new installs)
- bootstrap.py: removed Bash(rm -rf *) shipped via aipass init (project settings)
- doctor_wire.reconcile_stale_deny(): aipass doctor WARNs on stale rules;
  --fix removes them (idempotent, preserves all else) — migration for existing
  installs (the 'aipass update should be trusted' goal)
- .aipass/project_hooks.json template: added rm_gate (new projects get it)

Tests: 8 reconcile + 432 aipass total, seedgo 99%. CHANGELOG W23.
2026-06-02 20:24:21 -07:00
AIOSAI 2f5ce5ac87 feat(#630): drone rm safe-delete + rm_gate block-and-teach hook
Provider-agnostic temp/scratch cleanup that doesn't trip the rm -rf block.

- drone rm <path>: contained recursive delete (project root + /tmp + $TMPDIR),
  refuses outside roots and hard-carves .git/.trinity/.aipass/.codex/.agents +
  sibling-branch worktrees. Mirrors Codex's OS-sandbox boundary in software so
  behavior is consistent across CLIs. Pure-python, red-team tested.
- rm_gate (PreToolUse hook): blocks raw recursive rm, teaches 'drone rm',
  cross-provider, conservative-block on unparseable targets. Mirrors git_gate.
- Wired rm_gate into .aipass/hooks.json; CHANGELOG W23.

Tests: 56 drone rm + 56 rm_gate, seedgo 99% both. Phase 2 (remove the now-
redundant rm deny from setup.sh + aipass doctor migration) tracked separately.
2026-06-02 20:05:16 -07:00
AIOSAI 35a63b9540 fix: bootstrap @hooks as 13th branch + correct stale 12-counts
setup.sh never bootstrapped @hooks (hardcoded 12-branch list, stale comment from before hooks existed). Fresh clones got no @hooks passport + an absolute registry path -> drone @hooks commands failed ('path escapes project root'). Engine still fired (runs from AIPASS_HOME) but the citizen was non-functional.

- setup.sh: + bootstrap_branch hooks, 12->13 count + comment
- .aipass/aipass_global_prompt.md: 12->13 core branches, + hooks (injected every turn)
- devpulse local prompt: 13 Core Branches, + @hooks experts row
- dashboard dispatch_section docstring: 12->13

Found via Docker clone-from-dev test (DPLAN-0190 Phase D).
2026-05-28 19:51:27 -07:00
AIOSAI 574ae79b1a feat(hooks): ship .aipass/hooks.json on aipass init (DPLAN-0190 Phase A)
- bootstrap.py: write hooks.json from template at init, union-merge on update (preserves user on/off), remove dead _ship_hooks/HOOKS_TO_SHIP
- doctor.py: check .aipass/hooks.json presence
- .aipass/project_hooks.json: base template (all 14 handlers)
- .aipass/.gitignore: whitelist template so it ships in clones
- +13 tests, 421 pass, seedgo 99%
2026-05-28 19:41:10 -07:00
AIOSAI 2b31df3e02 feat: demo assets + project templates — demo.gif, project CLAUDE.md template, simplified startup protocol, prompt arg restored for handoff 2026-05-24 12:57:58 -07:00
AIOSAI 7d02c3d753 feat: shared hook sound module — mute all 14 handlers via drone @hooks hooksound on/off 2026-05-22 19:52:42 -07:00
AIOSAI 2215fcb260 feat: engine audio mute support — hooks.json audio tag + engine skips muted hooks 2026-05-22 18:10:03 -07:00
AIOSAI 40eb295e41 feat: Sunday release prep — hooks.json tracked, CHANGELOG.md, prax fix, gitignore cleanup 2026-05-22 16:52:03 -07:00
AIOSAI adb85b03a8 feat: DPLAN-0184 Phase 2 complete + DPLAN-0186 post-migration sweep — 14 native handlers, bridge routing, docs/setup alignment 2026-05-22 14:53:14 -07:00
AIOSAI ece29256f4 feat: hooks branch — hook engine + bridge wiring (DPLAN-0184 Phase 1) 2026-05-18 20:43:30 -07:00
AIOSAI 0d321c9d71 feat: add sub-agent section to global prompt + cleanup init pollution 2026-05-15 16:46:43 -07:00
AIOSAI 2bd4d72cdc fix(flow): repair fplan_registry counter corruption + add registry-no-edit rule to global prompt 2026-05-15 15:35:50 -07:00
AIOSAIandClaude Opus 4.6 974d697563 feat: devpulse 100% seedgo compliance, global prompt cleanup, init pollution removal
- Strip all 31 stale seedgo bypasses, re-evaluate from zero (10 legitimate kept)
- Create json_handler + wire 9 handler/module files (json_structure 0→100%)
- Add test_devpulse.py (17 tests: CLI routing, module discovery, error resilience)
- Add conftest fixtures: mock_logger, mock_json_handler
- Fix devpulse.py: add print_help(), feedback.py: META block + introspection
- README: fix stale content, update test count 130→236, add json/ handler
- Global prompt: remove secrets path, collapse duplicates, add branch_json breadcrumb
- Delete init pollution: aipass/status/ dir (15 files), 2 stale per-branch global prompts
- Seedgo: add README content accuracy checks (test count + dead links, 26 tests)
- Prax: fix _parse_agent_activity() reverse iteration (thinking entries hidden)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-05-15 12:45:51 -07:00
AIOSAI e7de852d4a feat: aipass init pip-ready structure + flow close self-healing + S146-S148 changes 2026-05-14 19:15:30 -07:00
AIOSAIand@devpulse 3b8fa1fa5a feat(system): test
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-12 17:33:34 -07:00
AIOSAIand@devpulse 67bfb18888 feat(system): docs: update README + global prompt to reflect git_gate v2 (branch/tag/remote split, owner bypass, sudo optional)
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-03 23:34:07 -07:00
patrickand@devpulse c94e231e84 feat(system): ai_mail vectorization: sys.executable fallback when memory venv missing + mechanical-guardrails prompt docs
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-03 21:51:27 -07:00
patrickand@devpulse ccafca881d feat(system): feat(system): add settings terminology to global prompt, fix template registry IDs, add auto_watchdog hook
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-02 23:26:35 -07:00
AIOSAIand@devpulse 5fda6e9b8f feat(system): fix: DPLAN-0157 pre-commit hook + DPLAN-0158 watchdog reply detection
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-26 22:26:44 -07:00
AIOSAIand@devpulse fd4f524895 feat(system): fix: add PR lock retry instruction to global prompt — agents must wait and retry, never skip PRs
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-26 00:30:45 -07:00
AIOSAIand@devpulse c2805e6963 feat(system): docs: lowercase shouting imperatives in local+global prompts (volume isn't the fix)
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-21 15:41:10 -07:00
AIOSAIand@devpulse f90816a29b feat(system): docs+settings: drill no-merge rule + add git branch-creation deny patterns (Track F repo-side)
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-21 10:07:40 -07:00