Phase 2 of #630. The rm_gate hook + drone rm now own destructive-delete
protection (cross-provider, path-aware, teaching), so the Claude-only blanket
deny is redundant AND harmful (it short-circuits before the hook, suppressing
the teaching message).
- setup.sh: removed Bash(rm -rf*) + Bash(rm -r *) from git_deny (new installs)
- bootstrap.py: removed Bash(rm -rf *) shipped via aipass init (project settings)
- doctor_wire.reconcile_stale_deny(): aipass doctor WARNs on stale rules;
--fix removes them (idempotent, preserves all else) — migration for existing
installs (the 'aipass update should be trusted' goal)
- .aipass/project_hooks.json template: added rm_gate (new projects get it)
Tests: 8 reconcile + 432 aipass total, seedgo 99%. CHANGELOG W23.
Adds .claude/hooks/git_gate.py and wires it in setup.sh PreToolUse so all fresh AIPass installs ship with mechanical enforcement of the drone-only git policy.
Why this exists: dispatched agents spawn with bypassPermissions which skips all permissions.deny rules in every settings tier. PreToolUse hooks remain the only mechanical chokepoint that survives bypass mode (verified via official Claude Code docs and live dispatch test).
Behavior — blocks with redirect to drone:
- Bash raw git write verbs and stash drop/clear/pop/apply
- Bash gh write subcommands and all gh api calls
- Edit/Write/MultiEdit on .claude/settings*.json, .claude/hooks/, .git/hooks/
Allows:
- Read-only git and gh
- All drone-prefixed commands (drone uses Python subprocess for git, never the agent Bash tool)
- Devpulse and seedgo working from their own branches can edit the enforcement layer (trusted-editor bypass)
- Quote-stripping: text inside double or single quotes is treated as data not code (so PR descriptions and commit messages can mention git verbs freely)
Verified end-to-end S124: live dispatch to prax, hook fired on raw git chain, agent pivoted to drone @git pr cleanly. 79 unit-test cases pass total. See DPLAN-0162.
Co-Authored-By: @devpulse <devpulse@aipass>
- pyproject.toml: add memory = ["numpy>=2.0", "chromadb>=1.0"] optional-deps group
- setup.sh: install .[dev,memory] so fresh-clone pytest works end-to-end
- test_vector.py: gate with pytest.importorskip("numpy"/"chromadb") — skip cleanly without extras
- memory_watcher.py: _check_vector_deps() probes venv at startup; health report now honest when chromadb absent
- bypass.json: 4 entries covering test_vector.py seedgo false-positives (architecture/docs/encapsulation/meta)
- dispatch/daemon.py: resolve relative branch_path to absolute before use
- dispatch/dispatch_monitor.py: resolve lock_file path so claude cwd is always absolute
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Fresh-install testing on macOS 12 Intel surfaced five friction points that
blocked or silently broke installation for users without admin rights.
All fixes are Mac-only, gated behind a new IS_MACOS flag. Linux and
Windows paths are untouched. See #353 for full context.
1. Stock macOS 12 ships /usr/bin/python3 at 3.9.6; setup.sh aborts at
the 3.10+ minimum check. Fix: probe versioned python3.10-3.13
binaries before falling back to plain python3.
2. Homebrew auto-install is not a universal fallback. Non-admin Mac
accounts cannot install Homebrew at all because its installer
requires admin/sudo. Fix: add uv (astral.sh/uv) as a no-sudo,
no-admin fallback. uv drops into ~/.local/bin via curl and downloads
a prebuilt standalone Python 3.11 to ~/.local/share/uv/python; the
venv is created from that.
3. macOS defaults to zsh since Catalina (2019). Writing AIPASS_HOME to
~/.bashrc silently fails because zsh does not source it. Fix: on
Mac, pick ~/.zshrc (or ~/.bash_profile for bash) based on SHELL.
4. The final symlink used sudo ln -sf /usr/local/bin/drone, which
prompts for a password on Mac and breaks entirely for non-admin
users. Fix: on Mac, link into ~/.local/bin (user-writable, no sudo)
and ensure it is on PATH via the profile rc.
5. HOOK_PYTHON was set to plain python3 on Unix. On Mac that resolves
to /usr/bin/python3 (3.9.6), which cannot parse hook scripts using
PEP 604 union syntax (X | None). Hooks silently crash on every
prompt. Fix: on Mac, point HOOK_PYTHON at the venv python (3.11)
that setup just built.
Tested end-to-end on a fresh clone, non-admin user, zsh, Intel: all 11
branches bootstrapped, drone CLI works, hooks fire and execute cleanly,
ai_mail delivery verified, sub-agents spawn successfully.
Refs #353
Co-authored-by: Paddy <padddypaddypaddy-boop@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat(system): fix(windows-ci): combine pip bootstrap fix + venv activation in Verify step
Combines both fixes needed to get windows-test.yml actually passing:
1. setup.sh: stop swallowing ensurepip errors (quiet + 2>/dev/null + || true was
hiding real failures — pip was silently not installed). Add get-pip.py fallback
and hard pip verification.
2. windows-test.yml: add 'source .venv/Scripts/activate' to Verify step. Each CI
step gets a fresh shell — setup.sh's venv activation doesn't carry over, so
drone wasn't on PATH in the subsequent step.
Together, these should take Windows CI from the 'silent failure every run since
creation' state to actually green. Supersedes PRs #330 and #331 which had the
fixes on separate branches (neither green alone).
Co-Authored-By: @devpulse <devpulse@aipass>
* feat(system): chore(lint): ruff auto-fix sweep — 303 errors across 178 files (F401 unused imports + F541 f-string placeholders + F811 redefined); restored report_error re-export + added logger call in errors.py
Co-Authored-By: @devpulse <devpulse@aipass>
---------
Co-authored-by: @devpulse <devpulse@aipass>
BLOCKER 1 (bootstrap.py): Replace bash dirname/while loop in _claude_settings()
with a cross-platform python3 -c one-liner using pathlib.Path.parents. The bash
loop broke on Windows because root is 'C:\' not '/'. Python pathlib handles all
OS path separators correctly.
BLOCKER 2 (setup.sh): Add OS detection (IS_WINDOWS via OSTYPE/uname). On Windows
(Git Bash/MSYS2/Cygwin), skip the sudo ln -sf symlink step and print manual
PATH-extension instructions for PowerShell, CMD, and Git Bash. Also make venv
activation OS-aware (Scripts/activate on Windows, bin/activate elsewhere).
BLOCKER 3 (setup.py): New cross-platform Python installer at repo root. Does
everything setup.sh does — create venv, install editable, verify entry points,
seed secrets dir, .env, registry, bootstrap branch identity files — and works
natively on Windows without Git Bash. Uses sys.executable (no python3 vs python
ambiguity), pathlib throughout, and prints PATH instructions on Windows instead
of attempting symlink creation.
Closes#261.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* docs: rewrite README with verified claims + add HERALD.md progress tracker
README rewritten and verified against live system:
- All commands tested and confirmed working
- drone systems shows 23 (15 core + 8 test), documented correctly
- seedgo at 33 standards (was incorrectly stated as 34)
- Docker setup-workspace.sh fork URL noted
- setup.sh sudo requirement documented
- prax monitor marked as interactive
- Added Standards, Communication, and Structure sections
- Removed session tracking (moved to HERALD.md)
- Branch table expanded with roles and descriptions
HERALD.md: Living progress doc for Patrick to read between sessions.
Contains session history, active DPLANs, milestones, known issues.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix(install): registry format mismatch + seedgo CLI entry point
Bugs found via fresh Docker install test:
1. setup.sh generated AIPASS_REGISTRY.json with branches as dict (keyed
by name), but seedgo's discovery.py expected a list of dicts. Result:
`drone @seedgo audit aipass` was completely broken on any fresh install.
Fix: setup.sh now generates list format (matching existing registry).
2. setup.sh verified `seedgo --help` but seedgo has no CLI entry point —
it's only accessible via `drone @seedgo`. Fix: check `drone @seedgo --help`
instead, remove broken symlink attempt.
3. seedgo discovery.py now handles both list and dict registry formats
defensively (in case old registries exist).
4. README updated to remove seedgo standalone CLI claims.
Verified: full fresh install in Docker container — setup.sh completes
successfully, drone systems shows 15 branches, seedgo audit runs clean.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
setup.sh now copies .env.example to ~/.secrets/aipass/.env so new users
get the key template in the right place automatically. Updated .env.example
header to point to the secrets location.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
- setup.sh now creates .trinity/, .seedgo/, .ai_mail.local/ for all 15 branches
- Registry includes commons + skills (was 13, now 15)
- spawn: fix registry format mismatch (dict vs list) that crashed every command on fresh install
- spawn: skip existing files during create (never overwrite)
- README: quick start guide rewritten for new users
- commons/skills README: rebuilt from birthright scaffold to real docs
- .env.example added for OpenAI/OpenRouter API keys
Tested end-to-end in Docker: clone → setup.sh → 15 branches → all identity files valid.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Full standards audit traced every doc through its checker into the codebase.
All 20 standards rated NEEDS UPDATE. This PR fixes the systemic issues:
Checker bugs fixed:
- encapsulation_check: continue/break bug falsely flagging allowed handlers
- error_handling_check: now accepts canonical prax import (not just shorthand)
- cli_check: import detection now matches aipass.cli prefix (was bare cli.)
- meta_check: AIPass header accepted (was only META), legacy compat preserved
Doc fixes:
- Checker paths corrected in 10 docs (added standards/aipass/ segment)
- naming.md rewritten: marketplace removed, json_handler.py promoted to
standard, verbs descriptive not prescriptive, module naming section added
- imports.md: both prax import forms now valid (canonical + shorthand)
- architecture/testing/trigger/encapsulation/json_structure/cli_flags/
log_handler: stale paths, Dev-Pass refs, outdated data fixed
Code fixes:
- parents[4]→parents[3] in 16 handler files (backup/daemon/memory)
- AIPass header marker in all 42 checker .py files
- pyproject.toml: added pyright to dev deps
- Removed agent_mock_branch template (replaced by builder/birthright)
- Removed stale branch_system_prompt.md files (renamed to aipass_local_prompt.md)
- New devpulse local prompt + FPLAN-0010
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>