Fresh-install testing on macOS 12 Intel surfaced five friction points that
blocked or silently broke installation for users without admin rights.
All fixes are Mac-only, gated behind a new IS_MACOS flag. Linux and
Windows paths are untouched. See #353 for full context.
1. Stock macOS 12 ships /usr/bin/python3 at 3.9.6; setup.sh aborts at
the 3.10+ minimum check. Fix: probe versioned python3.10-3.13
binaries before falling back to plain python3.
2. Homebrew auto-install is not a universal fallback. Non-admin Mac
accounts cannot install Homebrew at all because its installer
requires admin/sudo. Fix: add uv (astral.sh/uv) as a no-sudo,
no-admin fallback. uv drops into ~/.local/bin via curl and downloads
a prebuilt standalone Python 3.11 to ~/.local/share/uv/python; the
venv is created from that.
3. macOS defaults to zsh since Catalina (2019). Writing AIPASS_HOME to
~/.bashrc silently fails because zsh does not source it. Fix: on
Mac, pick ~/.zshrc (or ~/.bash_profile for bash) based on SHELL.
4. The final symlink used sudo ln -sf /usr/local/bin/drone, which
prompts for a password on Mac and breaks entirely for non-admin
users. Fix: on Mac, link into ~/.local/bin (user-writable, no sudo)
and ensure it is on PATH via the profile rc.
5. HOOK_PYTHON was set to plain python3 on Unix. On Mac that resolves
to /usr/bin/python3 (3.9.6), which cannot parse hook scripts using
PEP 604 union syntax (X | None). Hooks silently crash on every
prompt. Fix: on Mac, point HOOK_PYTHON at the venv python (3.11)
that setup just built.
Tested end-to-end on a fresh clone, non-admin user, zsh, Intel: all 11
branches bootstrapped, drone CLI works, hooks fire and execute cleanly,
ai_mail delivery verified, sub-agents spawn successfully.
Refs #353
Co-authored-by: Paddy <padddypaddypaddy-boop@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
feat(seedgo): fix(bypass): resolve relative registry paths in get_branch_from_path and _load_bypass_for_file — bypass.json entries silently failed for all checklist invocations because branch paths from registry are relative (src/aipass/seedgo) but were compared directly against absolute resolved file paths
feat(system): fix(windows-ci): activate venv in Verify step so drone binary is on PATH
PR #330 fixed the pip bootstrap (ensurepip error-swallowing in setup.sh). With that fix working, the Verify step in windows-test.yml now fails at 'drone: command not found' (exit 127). Root cause: each CI step spawns a fresh shell, so the venv activation from setup.sh doesn't carry to Verify. drone lives at .venv/Scripts/drone.exe which isn't on the default PATH.
Fix: prepend 'source .venv/Scripts/activate' to the Verify step so drone is findable.
Stacked on PR #330 conceptually — both fixes needed for windows-test.yml to actually pass.
Combines both fixes needed to get windows-test.yml actually passing:
1. setup.sh: stop swallowing ensurepip errors (quiet + 2>/dev/null + || true was
hiding real failures — pip was silently not installed). Add get-pip.py fallback
and hard pip verification.
2. windows-test.yml: add 'source .venv/Scripts/activate' to Verify step. Each CI
step gets a fresh shell — setup.sh's venv activation doesn't carry over, so
drone wasn't on PATH in the subsequent step.
Together, these should take Windows CI from the 'silent failure every run since
creation' state to actually green. Supersedes PRs #330 and #331 which had the
fixes on separate branches (neither green alone).
Co-authored-by: @devpulse <devpulse@aipass>
* feat(system): fix(windows-ci): combine pip bootstrap fix + venv activation in Verify step
Combines both fixes needed to get windows-test.yml actually passing:
1. setup.sh: stop swallowing ensurepip errors (quiet + 2>/dev/null + || true was
hiding real failures — pip was silently not installed). Add get-pip.py fallback
and hard pip verification.
2. windows-test.yml: add 'source .venv/Scripts/activate' to Verify step. Each CI
step gets a fresh shell — setup.sh's venv activation doesn't carry over, so
drone wasn't on PATH in the subsequent step.
Together, these should take Windows CI from the 'silent failure every run since
creation' state to actually green. Supersedes PRs #330 and #331 which had the
fixes on separate branches (neither green alone).
Co-Authored-By: @devpulse <devpulse@aipass>
* feat(system): chore(lint): ruff auto-fix sweep — 303 errors across 178 files (F401 unused imports + F541 f-string placeholders + F811 redefined); restored report_error re-export + added logger call in errors.py
Co-Authored-By: @devpulse <devpulse@aipass>
---------
Co-authored-by: @devpulse <devpulse@aipass>
PR #330 fixed the pip bootstrap (ensurepip error-swallowing in setup.sh). With that fix working, the Verify step in windows-test.yml now fails at 'drone: command not found' (exit 127). Root cause: each CI step spawns a fresh shell, so the venv activation from setup.sh doesn't carry to Verify. drone lives at .venv/Scripts/drone.exe which isn't on the default PATH.
Fix: prepend 'source .venv/Scripts/activate' to the Verify step so drone is findable.
Stacked on PR #330 conceptually — both fixes needed for windows-test.yml to actually pass.
Co-Authored-By: @devpulse <devpulse@aipass>
Every Windows CI run since windows-test.yml was created has failed silently on the same line: pip missing after venv creation. Root cause: ensurepip invocation was wrapped with --quiet, 2>/dev/null, and || true — three layers of error-hiding. ensurepip was running, failing silently, and the script continued to pip install which exploded with 'No module named pip'.
Fix removes the error-suppression so real errors surface, adds a get-pip.py fallback if ensurepip whiffs, and hard-verifies pip exists before continuing. If this fix itself fails on CI, we'll see the actual error for the first time.
Co-Authored-By: @devpulse <devpulse@aipass>
feat(system): fix(windows): hooks use venv python not python3 (#307), identity_injector reads identity.name fallback (#309), Path.rename→os.replace for Windows (#310), RotatingFileHandler catches PermissionError on rotation (#311)
feat(system): ci: add Windows setup test workflow — runs setup.sh + drone CLI verification on windows-latest GitHub Actions runner. Triggers on changes to setup.sh, handler __init__.py files, cli.py, or pyproject.toml. Closes the 'we never tested on Windows' gap.
* feat(system): ci: add Windows setup test workflow — runs setup.sh + drone CLI verification on windows-latest GitHub Actions runner. Triggers on changes to setup.sh, handler __init__.py files, cli.py, or pyproject.toml. Closes the 'we never tested on Windows' gap.
Co-Authored-By: @devpulse <devpulse@aipass>
* feat(system): fix(windows): SIGPIPE guard in flow.py (#301) + fcntl platform guards in trigger/config.py and watchdog/registry.py (#302) — lazy import fcntl on Unix only, no-op on Windows. inbox_lock.py already cross-platform (msvcrt). ai_mail.py already guarded (hasattr check).
Co-Authored-By: @devpulse <devpulse@aipass>
* feat(system): fix(windows): handler guard backslash path fix — all 11 __init__.py files (#304). caller_file.replace('\\', '/') normalizes Windows paths before the same-branch check. This is the actual fix for #293 which was incorrectly closed. drone is completely broken on Windows without this.
Co-Authored-By: @devpulse <devpulse@aipass>
---------
Co-authored-by: @devpulse <devpulse@aipass>
feat(system): fix(windows): PYTHONUTF8=1 in drone cli.py for Rich Unicode on Windows (#296) + STATUS.md reset to stub (#291) + README.md platform honesty (Linux tested, macOS untested, Windows in progress)
feat(system): fix(setup): Windows 10 hardening — python3 MS Store alias fallback (#292), venv file-locking workaround (#294-C), pip bootstrap via explicit venv python (#294-B/E), strip stale .venv from PATH (#294-D), PYTHONUTF8 for Rich Unicode (#296). All fixes from Input-X's Windows 10 test session. Linux path unchanged — same python3 detection, same venv flow.
* feat(system): fix(windows): PYTHONUTF8=1 in drone cli.py for Rich Unicode on Windows (#296) + STATUS.md reset to stub (#291) + README.md platform honesty (Linux tested, macOS untested, Windows in progress)
Co-Authored-By: @devpulse <devpulse@aipass>
* feat(system): fix: gitignore STATUS.md + STATUS.local.md — interim fix for #291/#298. Auto-generated status files contain developer session data that shouldn't ship in the public repo. Will be un-gitignored when prax sync produces clean public output.
Co-Authored-By: @devpulse <devpulse@aipass>
---------
Co-authored-by: @devpulse <devpulse@aipass>
feat(system): fix(setup): remove stale bootstrap_branch calls for backup, daemon, commons, skills — these branches were removed in S82/S87 and moved to external repos. setup.sh was creating ghost directories with .trinity/ scaffolding that confused new users and made drone route to non-existent agents. Also removed commons/skills from registry generator. Fixes#294 Part 2, relates to #291.
Email delivery to external branches (e.g. @strategy in Vera-Studio) worked
because delivery.py already had a caller-registry fallback, but wake failed
with "Branch not found" because resolve_branch() only checked AIPASS_REGISTRY.
Extracted the shared registry-walking logic into
registry/read.py::get_caller_project_branches(), then:
- wake.py resolve_branch() now checks AIPASS_REGISTRY first, then falls back
to the caller's project registry via AIPASS_CALLER_CWD (cross-project wake)
- delivery.py _load_caller_project_branches() delegates to the shared function
(eliminates duplicate implementation)
Fixes#283.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add checklist, proof, proof_query, test_map to the Commands list (were
missing from the branch prompt even though the commands work)
- Note that proof/proof_query/test_map are not in --help output yet (TODO)
- Add Hook Ownership section: full inventory of the 8 hooks seedgo owns,
their wiring state (including the unwired subagent_stop_gate), and the
three-location drift. Points at DPLAN-0131 for the consolidation plan.
- Update audit line count from "all branches" to "all 11 agents (33 audit
lines)" to match current reality
- Remove a 38-line branch section from STATUS.md that belongs to an
external private project
- Strip scattered external-project mentions from devpulse session logs in
STATUS.md (S87/S88 entries, DPLAN-0128 T4 line, S90 prax delivery notes,
Track G log leak references)
- Remove an injected reference from .aipass/aipass_global_prompt.md that
pointed at an out-of-scope style guide
- Remove unverified "original convention" literature from
.aipass/PROMPT_STYLE.md
- Remove matching external-project reference from README.md project status
- Remove matching reference from HERALD.md S74 session line
- Add policy note to .aipass/.gitignore: do not add other exceptions here
Empty __init__.py files were failing both checkers as false positives:
- imports: zero-check result scored 0% and reported "Failed (no details)"
- naming: __init__ fails snake_case regex ^[a-z][a-z0-9_]*$
Python package markers don't require imports by convention and cannot
be renamed (Python-reserved). Short-circuit both checkers to return
PASS for any file named __init__.py.
Reported by @devpulse while adding navigator/__init__.py to compass.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>