Commit Graph
854 Commits
Author SHA1 Message Date
AIOSAI 702e335cb8 fix(skills): TG routine read-timeouts silenced on OSError path + outage episode-start demoted ERROR→WARNING per Patrick ruling — ends medic wake-loop. 825 TG tests green 2026-07-15 23:21:41 -07:00
AIOSAI 73e9ededd4 fix(flow): CLOSED_PLANS append race — O_EXCL lockfile with retry/backoff, surface silent append failures (S314 sweep lost 18/21 entries). 730 tests green 2026-07-15 23:21:26 -07:00
AIOSAI bad08e9b03 fix(memory): unwedge plan vectorization — salt vector IDs with source file, per-file batches with incremental manifest (DPLAN-0245). Backlog drained 229/229, 990 tests green 2026-07-15 23:21:11 -07:00
AIOSAIandClaude Fable 5 851988abbc fix(seedgo): DPLAN-0244 trust files to 100% standards — json_handler + justified bypasses
CI seedgo gate is strict 100%. trust_registry.py now uses json_handler for
registry I/O (log_operation on writes only — no per-hook-event flood);
unused_function bypassed (cross-branch public API, static analysis can't see
callers). trust.py gained print_introspection + --help/no-args gates;
genuinely-N/A standards (json_structure delegated to trust_registry,
frozen cross-branch import) bypassed with justification. Both branches 100%,
all tests green, live acceptance re-verified (attack still blocked both gates).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEAyLFCuo4uD934fwFxocz
2026-07-15 19:17:45 -07:00
AIOSAIandClaude Fable 5 a8b1ce6658 feat(hooks): DPLAN-0244 hooks.json trust model hardening — Layer A engine gates + Layer B registry/CLI
Closes a zero-interaction RCE where a hostile repo's .aipass/hooks.json
(discovered via loader CWD walk-up, bridge wired globally) could run an
arbitrary command-type hook on SessionStart. Defense-in-depth:

Layer A (engine): refuse command-type hooks from per-project configs via
unconditional _source clobber; gate handler paths to aipass.* namespace.
Layer B (loader+CLI): trusted-project registry (path+sha256), fail-closed
trust-check, $AIPASS_HOME-only bootstrap (no TOFU), aipass init auto-enroll
+ new aipass trust/revoke commands.

Live acceptance test (real bridge, real payload) proves both gates block
independently. 1105 hooks + 133 aipass tests green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEAyLFCuo4uD934fwFxocz
2026-07-15 18:23:02 -07:00
AIOSAI 989d19020d chore(release): bump 2.7.0 -> 2.7.1 — supply-chain hardening (DPLAN-0243: commit signing, hash-pinned CI tooling, release provenance attestation), TG streaming v2 polish, rate_tracker burst-evasion fix, CI green pass 2026-07-15 13:24:41 -07:00
AIOSAI b4f66ce84d docs(flow): merge playbook template — DPLAN-0243 new-setup notes (auto-SSH-signing, hash-pinned CI advisory mode, provenance attestation step). Built by @flow, 730/730 green, seedgo 100% 2026-07-15 13:19:29 -07:00
AIOSAI 25fc02d07a feat: TG streaming v2 polish (DPLAN-0229) — logs_were_active + multi-chunk (>4096) finalize now honor the streaming flag: logs-active reconcile-edits the streamed message instead of Done.+fresh, multi-chunk edits chunk 1 in place + sends [2/N] continuations, edit-fail falls back safely. Batch path verified zero-change via regression tests. 6 new tests, 1077 hooks green + seedgo 100% devpulse-verified. Live streamed-turn proof pending Patrick's next streaming session. 2026-07-15 11:14:05 -07:00
AIOSAI 9dc2ecd604 feat: rate_tracker v1.2.0 burst-evasion fix — severity evaluates max(instant_rate, 60s window avg): bursty runaways (20 lines/6s retry-loop shape, 200/min avg, previously 4min undetected live) now sustain through gap windows; continuous unchanged, subsidence clears. 4 new burst tests, 1032 green + seedgo 100% devpulse-verified, live-proven from running service: RUNAWAY WARNING prax_burst_storm_test.log 191 lines/min sustained 120s. 2026-07-15 10:45:38 -07:00
AIOSAI 13ae64cbae fix: unpark the parked CI reds — Patrick ruling: red CI is never parked. @prax: relay mtime-cache flake root-caused (test relied on two writes sharing one mtime-granularity window — true locally, false on CI) — os.utime pins mtime so the cache contract tests deterministically, 50/50+20/20 loops green. @hooks: 4 Windows session_boot reds — _tmux_session_exists() real subprocess spawn (no tmux on Windows, WinError 2) mocked per ca096295 convention, execvp already mocked = zero real spawns left. 1028 prax + 102 session_boot green, devpulse-verified. 2026-07-15 10:26:09 -07:00
AIOSAI 024cf5a104 fix: pin sys.platform=linux in test_is_pid_alive_dead — Windows runners take the OpenProcess path so the os.kill mock never fires; test reds whenever PID 1234 is alive on the runner (first hit today, 6/6 sibling tests were already pinned by ca096295). 38 presence tests green. 2026-07-15 09:03:01 -07:00
AIOSAI be68d23d6a fix: CI green pass on PR#696 — lint (ruff format on trigger runaway tests), seedgo 100% both red branches (@hooks: new json_handler + persistent_alert/alert_dismiss wired through it, cc_sessions introspection gate, _menu_live nesting extraction, 1071 tests; @prax: rate_tracker DI refactor — module layer injects logs_dir + trigger.fire via configure(), 1028 tests), navmap trim 9.3k→7.9k under injection cap. All owner-fixed via dispatch, devpulse-verified: both audits 100% independently re-run, full runaway chain re-proven live post-refactor (332 lines/min storm → WARNING at 130s → trigger → @aipass triage → alert banner rendered in-session → dismiss clears). Burst-evasion design finding (pre-existing, not regression) filed to @prax by mail. 2026-07-15 08:49:21 -07:00
AIOSAI 81658ce0ea feat: runaway-log detection + escalation (DPLAN-0242, agent-designed) + citizen wake-back. Prax-led three-branch build via TDPLAN-0013: prax rate_tracker (disk-persisted volume detection, WARNING >100 l/min 2min / CRITICAL >10 l/s 1min, 4th monitor thread) + drone @prax log-health; trigger runaway_log_detected event + handler (per-file 30min cooldown independent of medic breaker, UNKNOWN->prax, writes .aipass/alerts.json); hooks persistent_alert banner + drone @hooks dismiss (devpulse fixed nearest-.aipass path bug in both + wired settings.json - registration is not deployment). Live-fire proven: planted 240 l/min storm -> detect 257 l/min -> event -> dispatch -> @aipass autonomous no-action triage -> banner -> dismiss. ai_mail wake ruling: owner-gate removed (citizen wake-back live-proven), devpulse structurally unwakeable (manager check all paths), self-wake loop found+fixed same night (guard + senderless wake-back sessions). Navmap comms section, 4 branch READMEs + root README + CHANGELOG. ~77 new tests, suites green: prax 1028, trigger 619, hooks 1071, ai_mail 765 2026-07-15 00:05:02 -07:00
AIOSAI de109846bf fix: prax TG relay offline backoff — network-class send failures enter offline mode (1s-60s doubling, flush gate skips sends, monitor loop never blocks, viewers keep rendering), log-once (enter + 5min summary + recovery w/ drop count), full reset on first success. Found live in Patrick's plug-pull: bots went quiet right, relay spun Send failed every 5s (89 lines) + self-fed via log watcher re-ingest. 11 new tests, 1007 prax green devpulse-verified 2026-07-14 17:01:23 -07:00
AIOSAI 5744073c11 fix: TG bot offline hot-spin — network-class poll errors (DNS/connection/socket) back off exponentially 1s-60s cap, reset on first successful poll; log-once semantics (1 unreachable line + 5min summaries + 1 recovery line) instead of 13 err/sec; routine long-poll read-timeouts silent (863/day medic noise class gone). Found live: Patrick's tether outage spun all 5 bots for an hour. 25 new tests, 822 TG + 252 skills green devpulse-verified 2026-07-14 16:29:57 -07:00
AIOSAI b791af2372 feat: medic revival + concurrent monitor viewers — pytest logs route to tmp (PYTEST_CURRENT_TEST, fixture storms cant pollute prod logs), breaker self-heals (half-open on read, close on probe, cooldown decay), TTL mutes (mute/off auto-expire 24h, --for/--forever, temp off keeps detection), footer+navmap mute breadcrumbs; prax monitor lock scoped to TG relay role (relay.pid) so viewers always start — Patrick ruling: processes are not agents. Loop proven live: planted commons bug fixed by medic dispatch in 105s byte-identical. 993 prax + 603 trigger green 2026-07-14 14:57:40 -07:00
AIOSAI af12158cbc fix: TG bot heartbeat race — generation counter kills resurrected heartbeat threads (shared stop Event cleared by next start let a >5s-stuck thread overwrite delivered replies with Processing...), delivered re-check before every edit in batch+streaming loops, superseded pending placeholders finalized in message+file paths (rapid-fire single-slot strand). Root-caused live from Patrick's frozen bubble; 6 new heartbeat tests, full TG suite 797 green devpulse-verified. 2026-07-14 11:00:48 -07:00
AIOSAI 62d047cac1 fix: TG mirror live-test round — agent_type filter unblocked main chats (daemon-backed sessions carry agent_type=claude; subagents never fire UserPromptSubmit; skip is now agent_id-based) + TG-echo gate (bot stores injected_prompt in pending file, relay skips fresh undelivered text-match; raw injections carry no marker). Found live by Patrick's morning door-tests; mirror proven both directions. 791 TG tests green (incl. cross-file mock fix @skills missed). 2026-07-14 09:16:02 -07:00
AIOSAI 5c82db6729 feat: TG user-comment mirror — user messages from ALL doors (terminal/remote) now mirror to the branch TG chat with origin tag. UserPromptSubmit relay handler (self-contained in telegram skill, crash-isolated last entry in hooks.json), human-only noise fences (system/task notifications, slash-command output, dispatch wakes, subagents, TG-echo, dupes), inbound hardening (stale-pending clean before write, undelivered-overwrite warning). 47 new TG tests, execution proven via engine.jsonl, positive path live-verified to real TG chat. 2026-07-14 02:42:41 -07:00
AIOSAI 116c4e9d69 fix: DPLAN-0241 round 4 — R6 extra_args threaded through ALL launch paths (user flags survive resume/takeover/continue/dead-window/headless), R7 auto-namer stamps --name branch-shortid on every launch (flag live-verified 2.1.209, user -n/--name wins), new-over-all aborts on failed daemon stop, honest close-all hint, exit/q/quit in all menus. op:kill per-job stop found in daemon socket protocol — documented, not shipped (undocumented internal). 1048 hooks tests green (102 session_boot, 11 CLI contract). 2026-07-14 02:10:44 -07:00
AIOSAI 0b739ac525 fix: DPLAN-0241 rounds 2-3 — Enter IS the takeover. Phantom claude-agents-stop removed (bg close honest, never SIGTERM), bg resume = daemon stop --any (returncode-checked, blast-radius y/N confirm) + --resume in tmux with bypass, ALL interactive launches tmux-wrapped, multi-session menu shows real names + explicit pick + honest new/close, real-binary CLI contract test tier (20 tests, phantom-subcommand class unshippable). 1025 hooks tests green, all facts live-verified vs claude 2.1.208. Plus DPLAN north-star: one conversation per branch, surfaces are views, agents bind to machine not interface. 2026-07-13 23:49:57 -07:00
AIOSAI 364cefa5fd fix: DPLAN-0241 session-mgmt overhaul — boot shim passthrough (only bare/permission-mode intercepted), session_boot 3-option boot menu (resume/new-closes-old/close, per-kind proper stops, never kill for bg), presence_gate repaired (session-file PID resolver, bg sessions gated) + wired OBSERVE-ONLY, wire_verify flags unwired security hooks as ERROR, new drone @hooks sessions + reclaim, PID-first session naming. Plus S304 discovery report + DPLAN-0241. Verified live: gate's first production run logged correct would-block, no self-block; 987 hooks tests green. 2026-07-13 22:50:27 -07:00
AIOSAI e9b86c3ebb feat: TG log-stream control — /logs on branch bots (persisted pref, honored by auto-start) + prax_monitor receiver bot (/pause /resume /errors /all /status, menu registered) + relay honors shared control file each flush. 84 new tests, all suites green; live-verified end-to-end from Telegram Web (errors filter kicked in within one flush). 2026-07-12 11:22:19 -07:00
AIOSAI e0811fcf93 fix: #692 builder->aipass_framework legacy migration + birth-cert template; #694 test-order pollution (prax fixture scope + skills hermetic tests). Verified: repro pair passes, 1576 tests green, Vera dry-run plans exactly 2 migrations zero writes. 2026-07-12 00:02:32 -07:00
AIOSAI c0d2d77428 release: bump version 2.6.1 -> 2.7.0 (pyproject.toml + src/aipass/__init__.py, both in lockstep for the v2.7.0 tag guard). MINOR bump per Patrick: PR659 ships new user-facing capability - owner-capability model + spawn sync-registry --check/--fix + aipass doctor owner health/repair (DPLAN-0231/0239), fleet-wide subcommand help contract (#686). Rides PR659 ahead of the merge so origin/main carries 2.7.0 for the tag. 2026-07-11 21:56:26 -07:00
AIOSAI b206832209 devpulse watchdog: banner off stdout -> stderr, kills the spurious arm-time wake (VERA feedback 315c005e, #693 follow-on). The 'invoke via Monitor tool' reminder printed via console.print to STDOUT at arm time; the Monitor tool treats every stdout line as a wake event -> every armed watchdog double-fired (spurious wake at ~0s, real wake at completion). Hit EVERYONE: my night-shift telegram logs show me repeatedly dismissing 'the known invoke-via-Monitor noise banners' instead of fixing them; VERA, cold, got woken with no completion attached. Fix: route via err_console (Monitor ignores stderr; stdout = completion/stall events only per the #634 contract; error() stays wrong -> #661 exit-code fail-flag). Verified live: watchdog agent @spawn -> stdout carries ONLY the completion result, banner+debug on stderr. 142 watchdog tests pass, ruff clean. 2026-07-11 21:04:03 -07:00
AIOSAI 90048069d0 fix seedgo-audit red on PR659 (2 branches 99%, from S300 commits) + kill the flake that blocked this commit's first gate run. AUDIT: aipass doctor.py _fix_owner_seating had 2 silent catches (FileNotFoundError/TimeoutExpired returned WARN without logging) -> added logger.info/warning matching sibling _check_owner_seating; devpulse README claimed 407 tests (pytest pass count incl parametrized) but readme checker counts test FUNCTIONS -> corrected to 309 (grep-verified). Both re-audit 100% locally; aipass doctor tests 133 pass. FLAKE: test_watchdog_agent bounce/lock-removal/replied tests patched GLOBAL time.sleep with unguarded fakes (agent_handler.time IS the time module) -> prax daemon threads ran the side effect concurrently, re-truncating last_bounce.json mid-read in _classify_exit -> JSONDecodeError path -> exit_code None != 1 (failed the gate suite run, passes isolated). Fix: _agent_only_sleep caller-frame guard (same as yesterdays _fake_clock_sleep, 766d697e) on all 3 tests; 17 pass 3x deterministic. 2026-07-11 18:46:36 -07:00
AIOSAI 766d697e08 devpulse: watchdog/feedback README rewrite (was stale, missed everything that tripped VERA) + fix thread-unsafe watchdog test + true up branch-prompt timeout. README (last touched 06-23) predated the owner gate and Monitor-tool wake: now documents owner-only gating (seated owner:true, doctor --fix repairs), the 3-step wake mechanic (dispatch -> arm via Monitor TOOL -> Monitor return IS the wake; '1 monitor' IS the indicator), why passive wake-back can NEVER reach an interactive session (BLOCKED line = by design), cross-project @target resolution, 600s default + --timeout, stall events; feedback re-documented as THE owner-to-owner cross-project channel (Patrick ruling: cross-project comms impossible by design except feedback). TEST FIX: test_watchdog_agent _fake_clock_sleep patched GLOBAL time.sleep with a stateful fake -> prax logger's 3 daemon threads raced the fake clock forward and unlinked the fixture lock before watch_agent read it (nondeterministic 'no active lock' + uptime-sized elapsed; failed 4x today, passed in the same-day full-repo sweep). Fix: thread-scope the fake via caller-frame check (only agent-module sleeps advance the clock; foreign threads get a real 1ms sleep). Verified 17 pass 3x deterministic, devpulse suite 407 green. Branch prompt: watchdog default timeout claim corrected 1800s -> 600s (hit live: 3 watchdogs expired mid-build at ~600s). 2026-07-11 17:58:18 -07:00
AIOSAI d511576fc0 DPLAN-0239 owner seating permanent+self-healing, fixes #693 (VERA seated, is_owner @vera=True). ROOT CAUSE: pre-2026-07-10 projects seated owner only in the self-editable passport, never the sealed registry (old ensure_project_has_owner bailed on passport owner:true without writing registry) -> 8/8 external projects unseated, get_owner None -> guard refused @vera watchdog/feedback/wake; + registry_id was a PROJECT id copied everywhere (13 AIPass entries shared one, metadata.id absent), drifting on registry recreation. IDENTITY MODEL (Patrick ruled): metadata.id=project credential (passports conform, majority-consensus restore); entry registry_id=set-once PER-CITIZEN UUID minted at add_to_registry; entry owner:true=the gate, ONE heuristic pick_owner_branch (manager->passport-owner->first-created) shared by create+reconcile. NEW: spawn sync-registry --check(--json, 7 flags, pinned schema)/--fix(--dry-run fully read-only, idempotent, never moves a seated owner); aipass doctor renders flags, doctor --fix/install/init-update delegate repair to spawn (the missing 0231 PART-4 retro-trigger, works from external project dirs); adopt path now seats; placeholders resolves registry from target dir not CWD, fails loud; hooks auto_watchdog injects real Monitor-tool command w/ @target (was dead one-liner + run_in_background which cannot wake). 4 dispatch rounds; devpulse verify caught 4 gaps round-1 tests missed (schema divergence->pinned v2, dry-run wrote via old-sync fix=True, unanimous->majority consensus vs BACKUP outlier, dual seating heuristic). DEPLOYED: AIPass dogfooded (restore metadata.id 7087bb93 majority 13/14, 16 citizen UIDs, --check clean, doctor owner OK) + 6 external projects reconciled/verified clean incl Vera-Studio (Seat VERA + 3 UIDs). Suites: spawn 343, aipass 673, hooks 961; full-repo 9364 pass (1 pre-existing skills litter -> #694). CHANGELOG updated. 2026-07-11 17:15:47 -07:00
AIOSAI 380eca813b ai_mail: make 2 non-hermetic tests deterministic (flaked CI on PR659). test_get_pid_cwd_darwin_failure called real lsof (subprocess.run) + test_is_zombie_linux_no_proc called real open(/proc/...) for fixed PIDs 999/99999 -> on runners where that PID exists they returned non-None -> intermittent test(3.10) failures. Mocked subprocess.run + builtins.open so both assert the failure contract without touching real process/proc state. Test-only (test_wake.py). Verified 79 pass 5x deterministic. Pre-existing (not from the Windows campaign). 2026-07-11 12:30:36 -07:00
AIOSAI ca096295a3 Windows CI cross-platform fixes (14 failures -> windows-setup green, PR659). Unmasked by the #691 collection fix; 6 branches. CAUSE 1 pid-liveness (ai_mail/flow/hooks/skills): production _is_pid_alive already cross-plat (ctypes OpenProcess on win32), but tests mocked os.kill which the win32 path never reaches -> pinned sys.platform=linux (or patched _is_pid_alive) so tests exercise the POSIX contract on every platform. CAUSE 2 path assumptions: prax jsonl str(Path) backslash, hooks rollover repr()/%r, ai_mail darwin lsof fixed posix path, seedgo is_bypassed Path.as_posix normalization (only production change). 10 files (9 test, 1 code). Owners self-fixed; devpulse verified diffs + Linux no-regression 525 changed-test green. CI Windows verifies. 2026-07-11 12:16:28 -07:00
AIOSAI 7c9309cf88 prax: make flaky test_deletes_old_system_log deterministic (was blocking green CI on PR659). Root cause = dual module identity: test_logging_handlers.py sys.modules.pop+reimports log_watchdog, so test_sweep's string-path patch of _get_system_logs_dir could hit a different object than the function __globals__ -> sweep scanned real (empty) system_logs -> files_removed=0 -> intermittent assert 0==1 (same commit passed one CI run, failed another). Fix: direct 'import log_watchdog as lw' + patch.object(lw,...) (shared __dict__) + patch json_handler to block real IO. Test-only (1 file). Verified: prax 978 green, interacting pair 5x deterministic, @prax full-repo 2x 11019 pass. 2026-07-11 10:35:41 -07:00
AIOSAI 74a08df800 #691 fix full-repo RUNTIME collision: fully-qualify handler.py lazy imports + test_handler_routing patch targets. CI (not isolation) exposed it: handler.py used bare 'from apps.handlers.X import Y' and the tests patched bare 'apps.handlers.X' -> in a whole-repo run bare apps resolves to the WRONG branch (AttributeError/ModuleNotFoundError, 17 test_handler_routing failures). FQ'd both to aipass.skills.lib.telegram.apps.handlers.* (handler.py 7 lazy imports now house-rule compliant; skill runtime verified via drone @skills run telegram status). Verified full-repo: 0 test_handler_routing failures (was 17), 11019 passed, isolation telegram 663 pass (no collateral). Only remaining local fail is pre-existing skills_json/ghost_config.json litter (gitignored, green in CI). 2026-07-11 09:53:32 -07:00
AIOSAI 8a606c8c2b #691 ruff format the 6 telegram test files @skills left unformatted (lint job runs ruff format --check). Whitespace/line-wrap only, 0 semantic change; ruff check + format --check now clean, 289 tests on the 6 files green. Fixes the lint red on deffa0c. 2026-07-11 09:11:14 -07:00
AIOSAI deffa0c912 #691 telegram tests CI-safe: fully-qualified imports + hermetic network-block fixture. 16 test files bare 'from apps.handlers' -> 'aipass.skills.lib.telegram.apps.handlers' (+ patch targets) — bare 'apps' collided with other branches' apps at full-repo collection -> ~16 collection errors -> CI red. Verify caught ~11 tests hitting live api.telegram.org (base_bot->set_bot_commands->urlopen, never ran in CI before); added session autouse _block_network conftest fixture patching urlopen on 4 telegram modules (bare+fq, guarded) so live calls fail loud not hang. Test-infra only, product byte-unchanged, 0 assertion changes. Full-repo collect 0 errors (11028); telegram 663 pass/0 fail/0 hang. devpulse independently re-verified. 2026-07-11 09:06:34 -07:00
AIOSAI c244b7bf3f test(drone): isolate cwd in test_pr_no_branch_dir + test_pr_no_args. Both called handle_command('pr', ...) expecting exit 1 (auth error) but lacked monkeypatch.chdir(tmp_path) — a real checkout's findable passport made auth PASS -> exit 0, failing only when run from the repo root (full-suite run). Added chdir(tmp_path) isolation matching sibling test_status_no_branch_dir; assertions unchanged. drone 864 pass / 0 fail. Pre-existing flake surfaced by the night-shift full-repo run. 2026-07-11 03:42:04 -07:00
AIOSAI 84177485ce #686/#661 night shift wave 5 completion (commons): Output_Routing 61->100% (worst score in the fleet). 22 modules route status/error console.print through cli error()/success()/warning() with ImportError-safe fallback binding. No test changes needed; 449 tests pass. FLEET COMPLETE: all 14 offenders at 100%, 17/17 branches at 100% seedgo. 2026-07-11 03:20:05 -07:00
AIOSAI 497ab98abc #686/#661 night shift wave 4 completion (aipass): -> 100% seedgo. aipass.py main() intercepts <cmd> --help before dispatch (Subcommand_Help ->100). Output_Routing ->100: 31 status prints across doctor/init_flow/handoff/profile routed via cli success()/error()/warning(). Modules ->100: auto_wire_provider extracted to NEW handler provider_wire.py, prompt_auto_wire made private (doctor_wire.py). Tests updated (test_doctor patch targets, test_init_flow success routing). Full suite re-run by devpulse: 657 pass / 0 fail. Audit 100% incl Modules. 2026-07-11 03:04:28 -07:00
AIOSAI 2defe9d615 #686/#661 night shift wave 5 (cli): -> 100% seedgo. cli.py main() intercepts <cmd> --help before dispatch (Subcommand_Help ->100). display.py error()/warning()/fatal() refactored from markup-string console.print to Rich Text objects — SAME output, avoids the output_routing flag on cli's own shared helpers (Output_Routing ->100). Behavior-preserving (identical stderr/emoji/color, fatal still exits 1), zero fleet blast radius. 140 tests pass. aipass + commons still in flight. 2026-07-11 02:58:47 -07:00
AIOSAI 7fb65f0255 #686/#661 night shift wave 4 (trigger + api): both -> 100% seedgo. trigger.py + api.py main() intercept <cmd> --help before dispatch (Subcommand_Help ->100). Output_Routing ->100: trigger (branch_log_events/errors/log_events/medic) + api (5 client/secrets modules) route status/error output via cli error()/success()/warning(). Test assertions updated to match routing (trigger 8 across 4 files). Suites re-run by devpulse: trigger 564, api 515, both green. aipass still in flight. 2026-07-11 02:46:51 -07:00
AIOSAI 80badb784a #686/#661 night shift wave 3 completion (memory): -> 100% seedgo. memory.py --help guard (Subcommand_Help ->100). symbolic.py + 6 modules route console.print status/error through cli error()/success()/warning() (Output_Routing ->100). 27 test assertions updated to match the routing (test_symbolic_cli.py, test_symbolic_module.py). Full suite 990 pass / 0 fail (devpulse re-ran the suite; the first agent report wrongly claimed no changes and skipped tests — caught by verify, re-dispatched, now green). 2026-07-11 02:40:26 -07:00
AIOSAI 90296b80f0 #686/#661 night shift wave 3 (backup + seedgo): both -> 100% seedgo. backup.py --help guard + error() routing in 6 modules (Subcommand_Help + Output_Routing ->100). seedgo.py --help guard + output_routing across 13 files + README standards-count refresh + test fixtures flipped for now-compliant seedgo/ai_mail entry points (Subcommand_Help + Output_Routing + Readme ->100). Tests green: backup 247, seedgo 1217. memory held this wave (its changes broke 27 tests, re-dispatched to fix). 2026-07-11 02:17:55 -07:00
AIOSAI de45e1cd2f #686/#661 night shift wave 2: daemon + prax + ai_mail -> 100% seedgo. daemon.py + ai_mail.py main() intercept <cmd> --help before dispatch (Subcommand_Help 0->100). Output_Routing ->100: daemon timer_install/update, prax dashboard/log_audit, ai_mail central_writer route status via cli warning()/error(); ai_mail introspection doc-glyphs -> markup. Tests green: daemon 300, prax 978, ai_mail 765. 2026-07-11 01:34:36 -07:00
AIOSAI f7e2584304 #686/#661 night shift wave 1: spawn + drone + flow -> 100% seedgo. spawn.py main() intercepts <cmd> --help before dispatch (Subcommand_Help 0->100). drone rm.py + flow aggregate_central/registry_monitor route status output via cli success()/error() (Output_Routing ->100). Tests green: spawn 316, drone 864, flow 730. 2026-07-11 01:19:15 -07:00
AIOSAI a54d21033e #688 follow-up: probe hygiene SOP + test hygiene. @aipass added docs/probe_hygiene.md (principle: temp=used+deleted+gone, no permanent pointer at a temp path, all 4 defenses + correct probe workflow). Test location-independence: TestRunInit gets a _isolate_cwd autouse fixture (monkeypatch.chdir) so it passes from ANY cwd incl an agent branch dir; 5 test_bootstrap env.AIPASS_HOME tests patch is_throwaway_path->False so they assert correctly even when the repo itself lives under a temp path. Devpulse caught+fixed the 2 update_project tests @aipass missed (same monkeypatch pattern). Verified: 657/657 green in REAL tree AND a fresh /tmp clean-room extraction (was 2 failing in clean-room before the last 2 fixes). --all 2026-07-11 00:30:35 -07:00
AIOSAI 22b4577ec1 #688 aipass: install from throwaway path can no longer hijack machine-wide AIPASS_HOME. Root cause: probe 'aipass install' from a /tmp scratchpad rewrote ~/.claude/settings.json env.AIPASS_HOME -> every CC session machine-wide ran a dead temp tree (stale python+hooks, bogus ImportErrors). 3 defenses: bootstrap.is_throwaway_path() gates the settings write (tempdir/tmp/scratchpad never written to global settings); run_install refuses throwaway home LOUDLY, --force-global-home = explicit override (+help text); doctor _check_global_aipass_home() flags nonexistent/throwaway env.AIPASS_HOME with fix guidance. +11 tests. Built by @aipass; devpulse verified: diffs read, is_throwaway_path live-caught the actual hijack path, doctor check live-green against repointed settings, 201/201 changed-file tests in real env. Suite deltas root-caused environmental: 3 init_flow fails = pre-existing cwd-dependence (pass from repo root), 5 clean-copy fails = the gate working as designed under a scratchpad extraction. 2026-07-11 00:12:26 -07:00
AIOSAI f72515e7bc #677 + #635 hooks: -p headless short-circuit + Codex bridge + portable hook test runner. #677: session_boot.py detects -p in extra_args and execvp's claude directly — headless one-shots never register in ~/.claude/sessions, so tmux/session-lookup/live-attach logic was wrong for them (DPLAN-0226 fine-tune debt; +5 tests, 39 pass). #635: new bridges/codex.py mirrors claude.py with Codex protocol normalization (stdin input->tool_input, stdout hookSpecificOutput envelope, permissionDecision+permissionDecisionReason — fixes DPLAN-0205 bugs) + new hook_test module: drone @hooks test fires every hook from .aipass/hooks.json with per-event mock data, reports fired/blocked/disabled/crashed with timing (23 tests). codex.py bypass entries exactly mirror shipped claude.py set. Built by @hooks; devpulse verified: 62/62 tests re-run against real repo, seedgo 31/31 all three files. 2026-07-10 23:50:37 -07:00
AIOSAI 98d52fa944 #681 owner-cap PART4: watchdog+feedback gate on sealed-registry owner (is_owner), cross-project. The old cwd.name=='devpulse' check was a NO-OP through drone (routed module runs cwd=branch_path, so Path.cwd() is always devpulse; a @flow caller sailed through). New shared handlers/owner/guard.py resolves the REAL caller via AIPASS_CALLER_BRANCH/CWD and checks the frozen is_owner(email,start_path) contract — portable to any project. feedback send stays open (inbound channel); mailbox mgmt owner-only. Fail-safe: legacy devpulse-path heuristic when no owner sealed / resolver import fails. Live-verified owner-allow + flow-deny (both tools) + send-open. 18 tests (15 guard + 3 gate), branch audit 100%. 2026-07-10 22:32:24 -07:00
AIOSAI fdb0086d6c #643 follow-up: check_branch_post honors .seedgo/bypass.json — threaded bypass_rules through branch_audit -> check_branch_post -> _check_json_dir_structure so a branch can sanction a legitimate data subdir (is_bypassed matches branch-relative path); unsanctioned+unbypassed splits still fail. Applied devpulse compass bypass (SQLite/FTS5 store needs own dir). audit @devpulse Json_Structure 100%. +2 tests. 2026-07-10 21:42:59 -07:00
AIOSAI 2112f458fb #643: codify custom_config/ as a json_structure standard — ALLOWED_JSON_SUBDIRS allowlist + check_branch_post() validates {branch}_json/ subdirs (custom_config/ + hidden dirs pass, other splits flagged); json_structure_content.py documents the structure + operator-config location. 5 tests. Surfaced devpulse_json/compass/ as unsanctioned (devpulse bypass next commit). 2026-07-10 21:33:38 -07:00