Closes a zero-interaction RCE where a hostile repo's .aipass/hooks.json
(discovered via loader CWD walk-up, bridge wired globally) could run an
arbitrary command-type hook on SessionStart. Defense-in-depth:
Layer A (engine): refuse command-type hooks from per-project configs via
unconditional _source clobber; gate handler paths to aipass.* namespace.
Layer B (loader+CLI): trusted-project registry (path+sha256), fail-closed
trust-check, $AIPASS_HOME-only bootstrap (no TOFU), aipass init auto-enroll
+ new aipass trust/revoke commands.
Live acceptance test (real bridge, real payload) proves both gates block
independently. 1105 hooks + 133 aipass tests green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEAyLFCuo4uD934fwFxocz
Activation fixes for the single-session presence gate. Two bugs blocked it,
both caught by live testing after all units were green:
1) Wrong branch key. presence_gate used Path.cwd().name, but under the Claude
Code bridge the hook process cwd is the project root, so every session keyed
to "AIPass": the gate never enforced one-live-session-per-branch and would
have rejected sessions project-globally (any 2nd interactive session in any
branch). Now _resolve_branch(hook_data) reads the event payload's cwd (the
real session dir) and walks up to the branch root (.trinity/ or apps/),
mirroring branch_loader. Applied in handle() and handle_stop().
2) Block never reached Claude Code. engine.dispatch() returned only stdout, so
the bridge could not surface a non-zero exit. dispatch() now returns
(stdout, exit_code) and the bridge exits with it on a block. Pre-existing gap
affecting every block hook on every event; now fixed engine-wide. An
intentional block (exit 2 + {"decision":"block"}) propagates; a crashing hook
(exit 2, non-JSON stdout) is logged and falls through, so the gate fails open.
Proven: 110 hooks unit tests pass (6 new for branch resolution); seedgo @hooks
100%, no type errors. Live bridge end-to-end (real live holder + real bridge):
duplicate into a held branch -> exit 2 + block reason naming the branch; a
different free branch -> exit 0 (per-branch isolation intact). Gate remains
dormant: not yet wired into provider settings.
Design: DPLAN-0225 / FPLAN-0289 P1 activation. Build by @hooks.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CqoxFdbDMirzkQ5kjRVVos
Cadence redo — verified against the live execution model, not unit tests:
- Counter now advances exactly once per real turn (mtime debounce +
transcript-size token + flock). Fixes the separate-process leapfrog where
global/branch loaders double-incremented and fired erratically.
- Structured [HOOKS] cadence fired|skipped logging; prax monitor renders
hook events distinctly for live visibility.
- Action-gated sound: handlers return a 'sound' key the engine plays only on
real action — skipped loaders are silent (no more false piper every turn).
- Fixed auto_fix.py: leftover speak() NameError (swallowed by broad except)
meant diagnostics silently never ran on any edit. Removed; sound moved to
the error path.
- Tests rewritten to model separate-process execution (leapfrog regression
test added); sound assertions across all refactored handlers. 438 pass.
prax: hook fire/skip event rendering in the live monitor. 913 pass.
README: hardcoded metrics (version/tests/PRs/standards) -> live PyPI+codecov
badges and qualitative wording; killed the 33-vs-36 drift. CHANGELOG W24.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>