Commit Graph
1038 Commits
Author SHA1 Message Date
AIPass 1deb786c8a Merge pull request #637 from AIOSAI/dev
security(ci): least-privilege token on e2e-wheel workflow + W24 changelog (also carries playbook commit 6b89fcd)
v2.5.2
2026-06-08 10:36:14 -07:00
AIOSAIandClaude Opus 4.8 2e96ddc302 chore(release): bump version 2.5.1 -> 2.5.2 (security patch)
Mid-week patch release for the CI/release security hardening:
least-privilege e2e-wheel token + Sigstore-signed GitHub Releases.
Bumps both pyproject.toml and src/aipass/__init__.py __version__.

Versioning scheme: patch (2.5.x) = small mid-week fixes, minor (2.x.0)
= Sunday main-merge batches.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 10:28:48 -07:00
AIOSAIandClaude Opus 4.8 076110a2fb security(release): sign GitHub Release artifacts with Sigstore (keyless)
publish.yml github-release job now signs the wheel + sdist via
sigstore/gh-action-sigstore-python (pinned v3.3.0 / 04cffa1d), keyless OIDC,
and attaches the .sigstore.json bundles to the GitHub Release through the
existing dist/* glob. Added id-token: write to the job for OIDC.

PyPI uploads were already attested (Trusted Publishing); Scorecard's
Signed-Releases check inspects GitHub Releases, which only carried bare wheels
-> score 0. .sigstore.json is in Scorecard's recognized signatureExtensions.
Verified: action globs ./dist/*.whl ./dist/*.tar.gz (action.py:202), auto-attach
gated on release-event (we trigger on push:tags) so we upload via dist/* and set
release-signing-artifacts:false. First live proof = next v* tag.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 10:19:51 -07:00
AIOSAIandClaude Opus 4.8 dab8d29645 security(ci): add least-privilege permissions block to e2e-wheel workflow
e2e-wheel.yml was the only workflow missing a top-level permissions: block
(added during cross-OS work after PR #624 hardened the rest), so it ran with
default broad GITHUB_TOKEN scopes -> OpenSSF Scorecard Token-Permissions = 0.
Add 'permissions: contents: read' to match the other 7 workflows. CHANGELOG
W24 entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 10:09:00 -07:00
AIOSAI c7055de5e2 docs(playbook): sunday_merge — bump BOTH version files, pre-flight version check, clearer manual tag step (from this run's friction) 2026-06-08 10:09:00 -07:00
AIPass e7d2d8c396 Merge pull request #633 from AIOSAI/dependabot/github_actions/github/codeql-action-4.36.2
ci(deps): bump github/codeql-action from 4.36.0 to 4.36.2
2026-06-08 10:08:58 -07:00
dependabot[bot] 4e2ead98a6 ci(deps): bump github/codeql-action from 4.36.0 to 4.36.2
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/7211b7c8077ea37d8641b6271f6a365a22a5fbfa...8aad20d150bbac5944a9f9d289da16a4b0d87c1e)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 16:09:17 +00:00
AIPass 45d55dd353 Merge pull request #632 from AIOSAI/dependabot/github_actions/actions/checkout-6.0.3
ci(deps): bump actions/checkout from 6.0.2 to 6.0.3
2026-06-08 09:07:17 -07:00
dependabot[bot] 285a8a5b5f ci(deps): bump actions/checkout from 6.0.2 to 6.0.3
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 07:20:25 +00:00
AIPass 2a54ed8446 Merge pull request #631 from AIOSAI/dev
Seedgo hook-cruft purge + raise CI standards floor to 100%

Two changes:
1. refactor(seedgo): archive pre-DPLAN-0184 hook cruft (FPLAN-0241) — orphaned bridge/probe/manifest modules + tests moved to .archive/; README/bypass/prompts updated. 1045 tests green.
2. ci(seedgo-audit): raise the standards floor 80%->100%.

NOTE — the seedgo-audit check will go RED by design. With the 100% floor, the 6 branches at 99% (aipass/api/drone/flow/prax/seedgo) are now caught. This PR is to OBSERVE the gate enforcing in CI; it is not merge-bound until those 6 branches reach a genuine 100%.
v2.5.1
2026-06-08 00:18:23 -07:00
AIOSAI 91b3f437fe chore(release): bump __version__ 2.5.0->2.5.1 to match pyproject + v2.5.1 release tag 2026-06-08 00:08:33 -07:00
AIOSAI 1e00119d9b fix(init): correct aipass init scaffold — project-specific AGENTS.md, README paths, my-agent->my_agent default, drop dead registry_path 2026-06-07 23:58:41 -07:00
AIOSAIandClaude Opus 4.8 9a64db9093 fix(spawn): seed todos[] into builder template .trinity/local.json (TDPLAN-0007 follow-up)
Verification audit caught a gap: spawn create copies templates/builder/ tree
directly (DEFAULT_TEMPLATE), but builder/.trinity/local.json lacked the todos[]
schema — so freshly spawned branches would not inherit it. Seeded todos[] +
max_todos:10 + todo_text_max_chars:200 + operational note to match @memory's
LOCAL.template.json. Now both spawn-create and template-push paths produce
todos[].

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 22:30:35 -07:00
AIOSAIandClaude Opus 4.8 626ab81a46 refactor(status): decommission entire STATUS flow — STATUS.local.md + central STATUS.md retired, replaced by local.json todos[] + dashboard count (TDPLAN-0007)
Cross-branch coordinated change. Per-branch STATUS.local.md (13) + central
STATUS.md deleted; all prompts/docs/skills/hooks/footer/scaffolding scrubbed.
Status-sync engine kept intact-but-inert (trigger registry unwired, 3 lines).
Replacement: operational todos[] in .trinity/local.json (@memory schema, capped,
rollover-exempt), pushed to all 13 branches + surfaced as dashboard todo_count.

Owners: memory (schema+global push+template), prax (dashboard todo_section +
engine dormant), trigger (unwire), aipass (init scaffolding), spawn (template
delete + todos[] seed), hooks (compact recovery), ai_mail (footer), seedgo
(_RUNTIME_ARTIFACTS cleanup), devpulse (scrub+delete+assemble).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 21:53:24 -07:00
AIOSAI f4b203a74e feat(standards): enforce Rich introspection formatting + 13 branches to seedgo 100%
- seedgo: new check_introspection_rich_formatting (delegation-aware) + introspection.md richness section + tests
- 13 branches: wrap print_introspection in Rich markup -> all at seedgo 100%
- S202 CLI polish: @hooks --help rewrite (hooksound on/off/status surfaced), spawn repair help clarity, drone Rich colour restore for --help/introspection/status
- flow: playbook plan-type (PPLAN) self-serve templates (default.md, sunday_merge.md SOP) + register-overrides-auto fix + --help rewrite
- hooks: setup.sh installs auto_process bridges + seedgo snapshot fixture learns them (TDPLAN-0005 followup, clears commit-gate blocker)
- remove orphaned devpulse/SETUP.md (vectorized to @memory)
- CHANGELOG [2026.W23]
2026-06-07 18:51:21 -07:00
AIOSAIandClaude Opus 4.8 e80e524dfe refactor(spawn): backups to single .spawn/.recovery namespace (TDPLAN-0006 P4)
Spawn's pre-merge JSON backups dropped a .recovery/ dir at each branch root,
which had accumulated 242 stale auto-gen DASHBOARD backups across 10 branches
(the original .recovery report that started this whole investigation).

- aipass.common.json_ops.backup_json gained optional backup_dir param
  (default unchanged = file_path.parent/.recovery, backward-compatible).
- spawn update engine (update_ops.py _merge_json) now passes
  branch_dir/.spawn/.recovery as the backup dest -> backups land under the
  spawn-managed .spawn/ dir, one namespace, not cluttering branch roots.
- Memory stays in the safety net: no memory-exclusion added; the engine just
  never touches .trinity/DASHBOARD on update so it never backs them up.
- 2 new tests (unit: custom backup_dir; integration: backup lands in
  .spawn/.recovery). 315 spawn + 438 aipass tests green; seedgo 100% both.

Stale .recovery backups swept separately (untracked/gitignored, local hygiene).
.recovery/ gitignore pattern already covers .spawn/.recovery/.

TDPLAN-0006 P4 — final phase. Closes the spawn update-safety + consolidation
work (P0 dry-run-default, P1 #636 engine, P2 shared lib, P3 import kill, P4
backup relocate).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 00:24:31 -07:00
AIOSAIandClaude Opus 4.8 59a6fcee13 refactor(aipass): subprocess to drone @spawn sync-registry — kill last cross-branch engine import (TDPLAN-0006 P3)
init_flow.py:896 was the one place aipass imported spawn's Python directly:
  from aipass.spawn.apps.modules.sync_registry import sync_registry
Replaced with subprocess.run(['drone','@spawn','sync-registry','--fix']) — the
command spawn already exposes — matching the aipass init agent -> drone @spawn
create pattern. Graceful degradation preserved: FileNotFoundError (no drone),
non-zero exit, and timeout are all silently skipped so a registry-sync hiccup
never hard-fails an init update. Safe because init update runs on an existing
project where drone is installed (NOT the pre-drone fresh-init path).

aipass branch now has ZERO direct imports of another branch's ENGINE code.
Remaining cross-branch imports are shared SERVICE layers only (cli Rich UI,
prax logger used in 347 files, trigger events) — infrastructure, not duplication.

Verified: zero aipass.spawn imports in .py code; fresh aipass init still
scaffolds (bootstrap pre-drone intact, 69 tests); 438 tests green (4 new for
the subprocess path: success/failure/missing-drone/timeout); seedgo 100%.

TDPLAN-0006 P3. P4 (.recovery relocate) is the last phase.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 00:14:28 -07:00
AIOSAIandClaude Opus 4.8 14e134b8e6 refactor(common): extract aipass.common shared lib — dedup spawn/aipass (TDPLAN-0006 P2)
@spawn and @aipass each maintained their own copy of the JSON merge/handler
utilities and registry discovery. Collapsed into ONE branch-free package both
import: src/aipass/common/ (json_ops: deep_merge + backup_json ;
json_handler.JsonHandler ; registry_discovery.find_registry).

- aipass.common imports ZERO branch code → aipass/bootstrap.py (runs pre-drone)
  can depend on it without breaking the pre-infrastructure constraint. Verified:
  bootstrap zero-import intact, real aipass init still scaffolds a fresh project.
- Duplicate copies deleted: spawn keeps a thin re-export shim; aipass json_handler
  shrank 254 -> 88 lines; aipass find_registry dedup'd across structure_scanner,
  doctor, doctor_fix.
- save_json contract UNIFIED: raises ValueError on invalid structure (was
  return-False in aipass). All call sites + tests updated to the raise contract.
- find_registry dedup scoped to spawn<->aipass only; seedgo/drone copies flagged
  as follow-up.

Verified: 313 spawn + 434 aipass tests green; seedgo 100% both; aipass.common
branch-free; aipass init scaffolds post-refactor.

TDPLAN-0006 P2. P3 (move project-update into spawn, kill init_flow import) +
P4 (.recovery relocate) to follow.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 00:03:15 -07:00
AIOSAIandClaude Opus 4.8 ccc8d6a97b fix(spawn): dry-run-default + path-based update engine — kill #636 branch-scrambler (TDPLAN-0006 P0+P1)
#636: drone @spawn update would scramble every branch's identity/memory in
one command. On a branch created seconds earlier, --dry-run proposed 30 renames
rotating identity dirs (apps->.trinity->.seedgo->.claude->.archive->.aipass),
README->DASHBOARD, and deep-merged stale template into live .trinity/. Root
cause: the CREATE path regenerated template-registry IDs in filesystem-walk
order (!= the master's hand-crafted IDs), so content-hash + rename-detection
saw a mismatch on a pristine branch. update --all would have destroyed all 13
citizens at once.

P0 — safety by default:
- update + repair are now dry-run by default; --apply required to write.
  Forgotten flag = safe preview-only no-op. --dry-run kept as alias.
- doctor_fix.py repair suggestions emit the matching --apply form
  (+ aipass test_doctor_fix updated to the new contract).

P1 — engine rebuild (update_ops.py v2.0):
- Path-based named-managed-files model replaces whole-tree hash-diff +
  rename-detection. ID divergence is moot — IDs are no longer used.
- .trinity/*, DASHBOARD.local.json, artifacts/birth_certificate.json,
  .seedgo/bypass.json = delivered on CREATE only, NEVER touched on update.
- Old ID engine (change_detection.py, reconcile.py) + orphaned tests deleted.

Verified on fresh sandbox: update --dry-run = 0 renames / 0 updates / 0
additions (create==update invariant); no-flag run = dry-run preview, filesystem
byte-identical; 313 spawn tests green; seedgo 100% (all 36 standards).

Closes #636. P2/P3/P4 (shared lib, seam, .recovery relocate) to follow.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 22:54:09 -07:00
AIOSAI 1ef1e2e89c feat(memory): auto-process memory pool + rollover on session-start/pre-compact (TDPLAN-0005) 2026-06-06 20:28:19 -07:00
AIOSAIandClaude Opus 4.8 8efb204486 fix(seedgo): de-git readme_check — audit reads local files only (DPLAN-0198)
Drops git check-ignore + git log from readme_check. Runtime dirs tolerated via
static list (_is_runtime_artifact); freshness checks date-presence only, no
history comparison. Local-CI parity proven 13/13 both ways (working tree +
git archive clean checkout). Invariant: a checker never consults git or
.gitignore; only bypass.json excludes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 16:31:38 -07:00
AIOSAI 0661949c15 docs(readme): use official HVTracker dynamic badge 2026-06-06 07:06:55 -07:00
AIOSAI 0f26efd706 docs(readme): add HVTracker badge to cluster (closes #628) 2026-06-06 07:06:05 -07:00
AIOSAIandClaude Opus 4.8 a242489c6d ci: remove path filter from Windows/macOS Test so required checks always run
Windows Test + macOS Test only triggered on changes to setup.sh / drone/cli.py
/ handlers/__init__.py / pyproject.toml, but branch protection requires their
checks (windows-setup / macos-setup). On any PR not touching those paths the
workflows never ran, so GitHub parked the required checks as 'Expected —
waiting for status' forever, blocking merge — exactly what happened to PR #631
(the tests last ran + passed yesterday on the version-bump commit; tonight's
commits didn't match the filter so they never fired). The OS code is fine:
e2e-wheel's windows-latest + macos-latest passed on the same commits.

Fix: drop the paths filter; run on every push/PR to main/dev like the other
required lanes (CI/lint/coverage/security/e2e are none of them path-filtered).
A required status check must never be path-filtered or it stalls PRs.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 05:30:40 -07:00
AIOSAIandClaude Opus 4.8 1ee51f3295 ci(security): upgrade pip in dependency-scan, drop stale ignores
dependency-scan (pip-audit) was red: it scans the whole env, and the runner's
bundled pip 26.1.1 carries PYSEC-2026-196 (fixed in 26.1.2). The job was the
only CI job not upgrading pip. Now runs 'python -m pip install --upgrade pip'
before auditing — removes the vulnerable version outright instead of
suppressing it.

pip 26.1.2 also fixes CVE-2026-3219 and CVE-2026-6357 (both were pip vulns, per
pip-audit attributing them to the pip package), so the two now-stale
--ignore-vuln entries are removed — stale security ignores mask the exact CVEs
they name if those reappear elsewhere.

Verified in a clean reproduction of the job env (fresh venv, upgrade pip, pip
install -e ., pip-audit --skip-editable with NO ignores): 'No known
vulnerabilities found', exit 0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 04:54:11 -07:00
AIOSAIandClaude Opus 4.8 27a175b2c9 ci(seedgo-audit): install memory extra so pyright resolves chromadb/numpy (DPLAN-0195)
Final straggler: memory scored 98% (diagnostics 55% = 9 pyright errors) in CI
while 100% locally. Proven cause: the diagnostics standard runs pyright over
every branch; memory's handlers import chromadb/numpy at module level. These
are declared in the 'memory' optional-dependencies group, NOT 'dev' — and the
audit job installed only '.[dev]', so pyright flagged them unresolved
(reportMissingImports=error) → 9 false errors. My local .venv happens to have
chromadb, which is why local audits read 100%.

Fix: audit job installs '.[dev,memory]'. pyright now resolves memory's real,
declared deps and the standard measures actual type-correctness (and matches a
local audit). api imports openai (llm extra) but guards it lazily, so it stays
100% without that extra — only memory needed this.

12/13 were already green after the readme check-ignore fix; this clears the
13th.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 00:32:29 -07:00
AIOSAIandClaude Opus 4.8 4c7e14a255 fix(seedgo): readme check-ignore must match dir-only patterns on clean checkout (DPLAN-0195)
The last 1%: 7 branches scored 99% in CI while 100% locally. Root cause proven
by reproducing CI's exact path (tracked-only tree + real .git): .gitignore
dir-only patterns (trailing slash — logs/, **/*_json/, .trinity/) do NOT match
via 'git check-ignore <bare-path>' when the path is absent from disk (clean
checkout), because git cannot infer 'directory' to apply a dir-only pattern.
The working tree has those dirs on disk, so it matched there — the exact
working-tree-vs-clean-checkout divergence.

_is_gitignored now also tests the trailing-slash form; all 7 readme failures
(cli_json/logs/artifacts/.trinity/ etc flagged 'missing on disk') clear.
Regression test builds a real git repo with dir-only patterns + non-existent
paths. CI gate also now prints failing standards + check messages (says WHY).

Verified: clean tree w/ real .git 13/13 100%; working tree 13/13 100%; seedgo
1053 tests green; pyright 0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 00:19:38 -07:00
AIOSAIandClaude Opus 4.8 24065f11b3 fix(seedgo): audit committed source not working tree — seedgo-audit CI gate green (DPLAN-0195)
Four standards checkers validated the working tree, so CI (clean checkout =
tracked files only) scored ~97% while local audits passed at 100%. Fix each
to measure what git actually ships:

- log_structure: skip absent gitignored logs/ dir (keeps hardcoded-path checks)
- readme: cross-ref .gitignore (git check-ignore + fallback), skip ignored
  dirs/links in tree + dead-link checks
- encapsulation: infer branch from path when gitignored REGISTRY absent; fix
  aipass-branch collision
- architecture: skip cleanly when gitignored passport.json absent

Clean-tree AND working-tree audits both 13/13 = 100%. seedgo 1052 tests green,
pyright 0.

Also: git_gate read-verb allowlist (22 read verbs raw, write stays drone-gated);
update devpulse test_git_gate contract to match; devpulse local-prompt git
breadcrumb.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 23:58:53 -07:00
AIOSAI 176f68439c ci(standards): full-history checkout for audit + honest aipass README refresh 2026-06-05 22:29:19 -07:00
AIOSAI c58fd263ab ci(standards): all 13 branches to genuine 100% — file-size advisory + readme-freshness git-history 2026-06-05 21:56:46 -07:00
AIOSAI d5829f80e8 ci(seedgo-audit): raise standards floor 80%->100%
The seedgo-audit gate passed everything at >=80% while all branches sit
at 99-100%, so it caught nothing. 100% is the floor: any drift names the
branch and reds the build. Expected to fail until the 6 branches at 99%
(aipass/api/drone/flow/prax/seedgo) reach a genuine 100%.
2026-06-05 19:44:35 -07:00
AIOSAI cc8f809a50 refactor(seedgo): archive pre-DPLAN-0184 hook cruft (FPLAN-0241)
Archive orphaned hook bridge/probe/manifest modules + their tests to
.archive/ — their only callers were the .claude/hooks scripts disabled
by DPLAN-0184. Seedgo audits hooks via standards; the hooks branch owns
the engine/bridge/handlers. README + bypass.json + prompts updated to
match. 1045 tests green, pyright clean.
2026-06-05 19:44:35 -07:00
AIPass 8a843429ca Merge pull request #629 from AIOSAI/dev
Fix dashboard plan-count zeroing + aipass bare-command introspection

Two verified bug fixes:

1. fix(flow): dashboard refresh no longer zeroes non-flow branch plan counts.
   PLANS.central.json now comprehensive (all branches grouped per-branch).
   Devpulse shows its 12 open plans again. +1 regression test, 734 pass.

2. fix(aipass): bare 'aipass <command>' runs instead of showing introspection
   banner. All 7 modules fixed; 'aipass doctor' runs the health check.
   Introspection moved to --info. seedgo standard bypassed for binary-invoked
   modules. 424 tests pass.

Both verified independently: dashboard refresh writes active_plans=12 (was 0);
bare 'aipass doctor' runs the full check.
2026-06-04 18:01:57 -07:00
AIOSAIandClaude Opus 4.8 8bd270287d chore(release): bump 2.5.0 -> 2.5.1
- pyproject: patch bump (cross-OS e2e wiring harness + Windows portability
  fixes landed this week; CHANGELOG [2026.W23] documents the work)
- tests/CROSS_OS_TESTING.md: add manual layer-3 cross-OS acceptance checklist
  (living draft; refined as real Win/Mac VM runs surface gaps)
- prax dashboard: drop commons_mentions from quick-status calc

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-04 17:52:23 -07:00
AIOSAI 80aac59423 style(e2e): ruff format conftest.py (fixes CI lint lane)
tests/e2e/conftest.py shipped unformatted in cd1af34, so 'ruff format
--check src/ tests/' failed the CI lint job. Pure formatting (string
concat join); no logic change. ruff check + ruff format --check + e2e
14/14 all green locally.
2026-06-04 01:24:52 -07:00
AIOSAIandClaude Opus 4.8 668841417f fix(portability): aipass init UTF-8 stdout on Windows + CI e2e lane (DPLAN-0194)
The real T1 Windows bug (diagnosed via the now-reverted error-surfacing
probe): aipass init scaffolds fine, then crashes printing its success
banner — Rich writes the success glyphs through a cp1252 stdout
(UnicodeEncodeError 'charmap'). Same class as the drone fix. The aipass
entry point now reconfigure()s stdout/stderr to UTF-8 in place on Windows.

Also: ci.yml's broad 'pytest --rootdir=.' swept in tests/e2e (which build
a wheel via the dedicated e2e-wheel.yml), failing the unit lane since the
harness landed; now --ignore=tests/e2e in both pytest jobs.

route_command error-surfacing probe reverted to honor 'no function change'
(the masked-error mislabel is noted as a separate @aipass recommendation).

Local: e2e 14/14 green, aipass units 24/24, ruff clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-04 01:17:56 -07:00
AIOSAIandClaude Opus 4.8 89fa2c1db2 fix(aipass): surface module errors instead of masking as 'Unknown command'
route_command swallowed any handle_command exception and let main() print
a misleading 'Unknown command', hiding real failures (e.g. the Windows
aipass-init error the e2e harness hit). It now also prints the failing
module + traceback to stderr. Bool contract unchanged; 24/24 aipass unit
tests pass. This makes the masked Windows init failure diagnosable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-04 01:06:36 -07:00
AIOSAIandClaude Opus 4.8 f3b3ebad9b fix(portability): Windows aipass init + drone stdout (DPLAN-0194)
Two latent Windows portability bugs caught by the new e2e wiring harness:

- aipass init: _preflight_check ancestor walk crashed on OSError from
  un-enumerable Windows drive-root entries (pagefile.sys), swallowed by
  route_command as 'Unknown command: init'. Walk now skips unreadable
  entries (logged).
- drone @branch: crashed with UnicodeEncodeError ('charmap') printing a
  routed branch's captured output via Rich on cp1252 stdout. PYTHONUTF8
  only affects child interpreters; entry point now reconfigure()s the live
  stdout/stderr to UTF-8.

Pure portability — Linux/macOS behaviour unchanged. e2e suite 14/14 green
locally on Linux. Lets the 3-OS CI verify Windows.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-04 01:00:01 -07:00
AIOSAIandClaude Opus 4.8 cd1af34be8 test(e2e): cross-OS wiring harness + 3-OS CI, red-first (FPLAN-0239)
Build-wheel -> install-clean -> assert 4-tier wiring ladder (install/init/
hooks-fire/drone-route). Validated green on Linux; Windows red-first by design
(symlink/venv-path/tmp gaps = DPLAN-0194 P3 fix-list).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-04 00:03:37 -07:00
AIOSAI 3ad0580070 docs(readme): add OpenSSF Best Practices passing badge (DPLAN-0193) 2026-06-03 14:37:43 -07:00
AIOSAI 4383c6c9d8 security(docker): pin ubuntu:24.04 base image by digest (DPLAN-0193 step 2) 2026-06-03 11:51:32 -07:00
AIOSAI ee78c39e80 security(deps): pin requests>=2.34.2 to clear 6 OSV advisories (DPLAN-0193 step 1) 2026-06-03 11:34:02 -07:00
AIOSAI 87d131218e feat(hooks): log agent_type/agent_id per hook fire for visibility (#606) 2026-06-02 22:02:22 -07:00
AIOSAI e63a4e9945 feat(#630): retire blanket rm deny + aipass doctor migration
Phase 2 of #630. The rm_gate hook + drone rm now own destructive-delete
protection (cross-provider, path-aware, teaching), so the Claude-only blanket
deny is redundant AND harmful (it short-circuits before the hook, suppressing
the teaching message).

- setup.sh: removed Bash(rm -rf*) + Bash(rm -r *) from git_deny (new installs)
- bootstrap.py: removed Bash(rm -rf *) shipped via aipass init (project settings)
- doctor_wire.reconcile_stale_deny(): aipass doctor WARNs on stale rules;
  --fix removes them (idempotent, preserves all else) — migration for existing
  installs (the 'aipass update should be trusted' goal)
- .aipass/project_hooks.json template: added rm_gate (new projects get it)

Tests: 8 reconcile + 432 aipass total, seedgo 99%. CHANGELOG W23.
2026-06-02 20:24:21 -07:00
AIOSAI 2f5ce5ac87 feat(#630): drone rm safe-delete + rm_gate block-and-teach hook
Provider-agnostic temp/scratch cleanup that doesn't trip the rm -rf block.

- drone rm <path>: contained recursive delete (project root + /tmp + $TMPDIR),
  refuses outside roots and hard-carves .git/.trinity/.aipass/.codex/.agents +
  sibling-branch worktrees. Mirrors Codex's OS-sandbox boundary in software so
  behavior is consistent across CLIs. Pure-python, red-team tested.
- rm_gate (PreToolUse hook): blocks raw recursive rm, teaches 'drone rm',
  cross-provider, conservative-block on unparseable targets. Mirrors git_gate.
- Wired rm_gate into .aipass/hooks.json; CHANGELOG W23.

Tests: 56 drone rm + 56 rm_gate, seedgo 99% both. Phase 2 (remove the now-
redundant rm deny from setup.sh + aipass doctor migration) tracked separately.
2026-06-02 20:05:16 -07:00
AIOSAIandClaude Opus 4.8 895b8f04fd fix(drone): protect dev on merge + live-remote branches + scope footer (#625, #623)
#625 (HIGH): drone @git merge passed --delete-branch to gh pr merge
unconditionally, so merging a dev->main PR DELETED the persistent dev branch
on the remote and left the tree on main (next commit silently on main). Now:
- merge looks up the PR head ref and only appends --delete-branch for
  non-protected branches; dev/main are never deleted. Unknown head ref fails
  SAFE (no delete) — devpulse hardening on top of @drone's protected-branch set.
- after merge, return the working tree to dev (loud warning if it can't).
- branches_handler runs git fetch --prune before git branch -r (no more
  'cached lies' reporting deleted branches as live).
- new drone @git prune-temp cleans merged temp PR branches (citizen/*).

#623: status/diff append a '(showing <branch> scope — use --all for full repo)'
footer when scoped, so an empty scoped view isn't mistaken for a clean repo.
Blank-output sub-item not reproducible — documented.

@drone built fixes 1-5 (FPLAN-0236); devpulse added the unknown-head-ref
fail-safe + test and verified independently. drone suite 716 pass, seedgo 99%.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 17:39:01 -07:00
AIOSAIandClaude Opus 4.8 bedf58e7b5 fix(drone): external projects can resolve AIPass branches (#618)
resolve_branch() validated branch path containment against the primary
registry root even when the branch was found via the AIPASS_HOME fallback,
so external projects (Vera, Daemon) were blocked from calling @api and any
other AIPass branch with 'path escapes project root'.

Add get_branch_with_registry() (non-breaking sibling to get_branch_by_name)
that returns the branch plus the registry it was found in. resolve_branch()
now validates containment against that registry's root. Security preserved:
each branch stays contained within its own declaring registry; genuine
escapes still blocked. 4 new cross-project resolver tests, 58 resolver
tests pass, drone suite 702 pass, seedgo @drone 99%.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 16:25:46 -07:00
AIOSAIandClaude Opus 4.8 cc449c4a18 docs(readme): trim badge cluster — remove OSS Health metric badge
Cluster was getting busy; dropped the OSS Health monitor badge to keep the
top row focused (Status/Python/License/PyPI/Feedback/codecov/Scorecard).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 15:48:07 -07:00
AIOSAIandClaude Opus 4.8 da46dde7ce chore(aipass): purge stale placeholder bypass entries + refresh metadata
Removed 5 stale Phase-0/Phase-4 bypasses (verified seedgo passes without them
now that aipass is fully built). Restored 3 aipass.py entries (cli/debug_print/
introspection) with accurate current reasons — thin command router, not a
module. Metadata description updated to current operational state. 58→53 entries.
424 tests pass, seedgo 99%.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 15:46:26 -07:00
AIOSAIandClaude Opus 4.8 a880139a1e docs(readme): move OpenSSF Scorecard badge into the top badge cluster
Was orphaned in its own centered block between the logo and demo gif, and the
only badge in raw HTML. Moved up with the other 7 badges and converted to
markdown for consistency. Grouped with codecov/OSS-Health (security-health).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 15:33:07 -07:00