.gitignore exceptions still pointed at templates/builder/ after the TDPLAN-0010 rename (13463c0), so DASHBOARD.local.json + 10 other template dirs/files under templates/aipass_framework/ were silently gitignored — on disk (dirty tree passed) but absent in clean clones/CI. Result: spawn produced no DASHBOARD.local.json and test_full_spawn failed only in a clean checkout. Fixed all 23 .gitignore exception paths + tracked the now-visible template files (all placeholder/seed content: {{BRANCHNAME}}/{{DATE}}/{{CITIZEN_NUMBER}}).
Root-cause fixes for PR#646 red (dev broke after DPLAN-0226/FPLAN-0289/TDPLAN-0010 batch):
- seedgo: branch_audit honors ADVISORY (template_check no longer averaged into gate) + presence_gate added to hooks-snapshot fixture (4 tests)
- hooks: cc_sessions README entry + seedgo modules bypass (reads external ~/.claude, not branch data)
- spawn: retire passport(disabled).py/passport_ops(disabled).py to .archive/ (disabled suffix kept broken cross-import visible to type checker)
- ai_mail: broker-fd test gives testbranch a real .trinity/passport.json for the new marker-walk resolution (f914ab6)
core.py adopt-path read the passport via json.loads(read_text()) — a direct
file op that fails the json_handler standard and the CI seedgo-audit gate.
Switch to json_handler.read_json() (matches the pattern ~90 lines above),
drop the now-unused 'import json as _json'. @spawn 100%; 315 spawn tests green.
- memory.config.json is the single source of truth: char caps (entry_limits, global) + rollover counts (per_branch, materialized from registry); .trinity files stripped to a one-line _usage header
- changed_entries gate now matches by content identity, not array position — prepending a new entry never re-flags unchanged legacy entries (old=old, new=new; no trimming required on a cap change)
- rollover push command + top-level 'drone @memory push' alias; corrected config _note + --help (rollover push surfaced, labeled destructive system-wide reset)
- removed 3 dead functions: seed_per_branch, its orphaned write_config, add_learning + its tests
- spawn birthright/builder + LOCAL/OBSERVATIONS templates aligned to the stripped shape
- 966 tests, seedgo 100%
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
src/aipass/common was the only non-citizen directory in the agent namespace.
Per @seedgo design review: moved into @aipass (owner) as aipass.aipass.shared,
content byte-identical. @spawn imports across (blessed shared-infra category,
same as aipass.prax/cli). New subprocess guard test pins the bootstrap-safety
invariant (shared/ loads zero branch deps — aipass init stays pre-drone-safe).
9 import/doc sites updated, 9 documented seedgo bypasses (pre-infra leaf,
stdlib-only by design). aipass 480 + spawn 315 tests green, both audits 100%,
repo-wide zero refs to the old path.
Verification audit caught a gap: spawn create copies templates/builder/ tree
directly (DEFAULT_TEMPLATE), but builder/.trinity/local.json lacked the todos[]
schema — so freshly spawned branches would not inherit it. Seeded todos[] +
max_todos:10 + todo_text_max_chars:200 + operational note to match @memory's
LOCAL.template.json. Now both spawn-create and template-push paths produce
todos[].
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Spawn's pre-merge JSON backups dropped a .recovery/ dir at each branch root,
which had accumulated 242 stale auto-gen DASHBOARD backups across 10 branches
(the original .recovery report that started this whole investigation).
- aipass.common.json_ops.backup_json gained optional backup_dir param
(default unchanged = file_path.parent/.recovery, backward-compatible).
- spawn update engine (update_ops.py _merge_json) now passes
branch_dir/.spawn/.recovery as the backup dest -> backups land under the
spawn-managed .spawn/ dir, one namespace, not cluttering branch roots.
- Memory stays in the safety net: no memory-exclusion added; the engine just
never touches .trinity/DASHBOARD on update so it never backs them up.
- 2 new tests (unit: custom backup_dir; integration: backup lands in
.spawn/.recovery). 315 spawn + 438 aipass tests green; seedgo 100% both.
Stale .recovery backups swept separately (untracked/gitignored, local hygiene).
.recovery/ gitignore pattern already covers .spawn/.recovery/.
TDPLAN-0006 P4 — final phase. Closes the spawn update-safety + consolidation
work (P0 dry-run-default, P1 #636 engine, P2 shared lib, P3 import kill, P4
backup relocate).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
#636: drone @spawn update would scramble every branch's identity/memory in
one command. On a branch created seconds earlier, --dry-run proposed 30 renames
rotating identity dirs (apps->.trinity->.seedgo->.claude->.archive->.aipass),
README->DASHBOARD, and deep-merged stale template into live .trinity/. Root
cause: the CREATE path regenerated template-registry IDs in filesystem-walk
order (!= the master's hand-crafted IDs), so content-hash + rename-detection
saw a mismatch on a pristine branch. update --all would have destroyed all 13
citizens at once.
P0 — safety by default:
- update + repair are now dry-run by default; --apply required to write.
Forgotten flag = safe preview-only no-op. --dry-run kept as alias.
- doctor_fix.py repair suggestions emit the matching --apply form
(+ aipass test_doctor_fix updated to the new contract).
P1 — engine rebuild (update_ops.py v2.0):
- Path-based named-managed-files model replaces whole-tree hash-diff +
rename-detection. ID divergence is moot — IDs are no longer used.
- .trinity/*, DASHBOARD.local.json, artifacts/birth_certificate.json,
.seedgo/bypass.json = delivered on CREATE only, NEVER touched on update.
- Old ID engine (change_detection.py, reconcile.py) + orphaned tests deleted.
Verified on fresh sandbox: update --dry-run = 0 renames / 0 updates / 0
additions (create==update invariant); no-flag run = dry-run preview, filesystem
byte-identical; 313 spawn tests green; seedgo 100% (all 36 standards).
Closes#636. P2/P3/P4 (shared lib, seam, .recovery relocate) to follow.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>