Commit Graph
1291 Commits
Author SHA1 Message Date
AIOSAI ca096295a3 Windows CI cross-platform fixes (14 failures -> windows-setup green, PR659). Unmasked by the #691 collection fix; 6 branches. CAUSE 1 pid-liveness (ai_mail/flow/hooks/skills): production _is_pid_alive already cross-plat (ctypes OpenProcess on win32), but tests mocked os.kill which the win32 path never reaches -> pinned sys.platform=linux (or patched _is_pid_alive) so tests exercise the POSIX contract on every platform. CAUSE 2 path assumptions: prax jsonl str(Path) backslash, hooks rollover repr()/%r, ai_mail darwin lsof fixed posix path, seedgo is_bypassed Path.as_posix normalization (only production change). 10 files (9 test, 1 code). Owners self-fixed; devpulse verified diffs + Linux no-regression 525 changed-test green. CI Windows verifies. 2026-07-11 12:16:28 -07:00
AIOSAI 7c9309cf88 prax: make flaky test_deletes_old_system_log deterministic (was blocking green CI on PR659). Root cause = dual module identity: test_logging_handlers.py sys.modules.pop+reimports log_watchdog, so test_sweep's string-path patch of _get_system_logs_dir could hit a different object than the function __globals__ -> sweep scanned real (empty) system_logs -> files_removed=0 -> intermittent assert 0==1 (same commit passed one CI run, failed another). Fix: direct 'import log_watchdog as lw' + patch.object(lw,...) (shared __dict__) + patch json_handler to block real IO. Test-only (1 file). Verified: prax 978 green, interacting pair 5x deterministic, @prax full-repo 2x 11019 pass. 2026-07-11 10:35:41 -07:00
AIOSAI 74a08df800 #691 fix full-repo RUNTIME collision: fully-qualify handler.py lazy imports + test_handler_routing patch targets. CI (not isolation) exposed it: handler.py used bare 'from apps.handlers.X import Y' and the tests patched bare 'apps.handlers.X' -> in a whole-repo run bare apps resolves to the WRONG branch (AttributeError/ModuleNotFoundError, 17 test_handler_routing failures). FQ'd both to aipass.skills.lib.telegram.apps.handlers.* (handler.py 7 lazy imports now house-rule compliant; skill runtime verified via drone @skills run telegram status). Verified full-repo: 0 test_handler_routing failures (was 17), 11019 passed, isolation telegram 663 pass (no collateral). Only remaining local fail is pre-existing skills_json/ghost_config.json litter (gitignored, green in CI). 2026-07-11 09:53:32 -07:00
AIOSAI 8a606c8c2b #691 ruff format the 6 telegram test files @skills left unformatted (lint job runs ruff format --check). Whitespace/line-wrap only, 0 semantic change; ruff check + format --check now clean, 289 tests on the 6 files green. Fixes the lint red on deffa0c. 2026-07-11 09:11:14 -07:00
AIOSAI deffa0c912 #691 telegram tests CI-safe: fully-qualified imports + hermetic network-block fixture. 16 test files bare 'from apps.handlers' -> 'aipass.skills.lib.telegram.apps.handlers' (+ patch targets) — bare 'apps' collided with other branches' apps at full-repo collection -> ~16 collection errors -> CI red. Verify caught ~11 tests hitting live api.telegram.org (base_bot->set_bot_commands->urlopen, never ran in CI before); added session autouse _block_network conftest fixture patching urlopen on 4 telegram modules (bare+fq, guarded) so live calls fail loud not hang. Test-infra only, product byte-unchanged, 0 assertion changes. Full-repo collect 0 errors (11028); telegram 663 pass/0 fail/0 hang. devpulse independently re-verified. 2026-07-11 09:06:34 -07:00
AIOSAI c244b7bf3f test(drone): isolate cwd in test_pr_no_branch_dir + test_pr_no_args. Both called handle_command('pr', ...) expecting exit 1 (auth error) but lacked monkeypatch.chdir(tmp_path) — a real checkout's findable passport made auth PASS -> exit 0, failing only when run from the repo root (full-suite run). Added chdir(tmp_path) isolation matching sibling test_status_no_branch_dir; assertions unchanged. drone 864 pass / 0 fail. Pre-existing flake surfaced by the night-shift full-repo run. 2026-07-11 03:42:04 -07:00
AIOSAI 84177485ce #686/#661 night shift wave 5 completion (commons): Output_Routing 61->100% (worst score in the fleet). 22 modules route status/error console.print through cli error()/success()/warning() with ImportError-safe fallback binding. No test changes needed; 449 tests pass. FLEET COMPLETE: all 14 offenders at 100%, 17/17 branches at 100% seedgo. 2026-07-11 03:20:05 -07:00
AIOSAI 497ab98abc #686/#661 night shift wave 4 completion (aipass): -> 100% seedgo. aipass.py main() intercepts <cmd> --help before dispatch (Subcommand_Help ->100). Output_Routing ->100: 31 status prints across doctor/init_flow/handoff/profile routed via cli success()/error()/warning(). Modules ->100: auto_wire_provider extracted to NEW handler provider_wire.py, prompt_auto_wire made private (doctor_wire.py). Tests updated (test_doctor patch targets, test_init_flow success routing). Full suite re-run by devpulse: 657 pass / 0 fail. Audit 100% incl Modules. 2026-07-11 03:04:28 -07:00
AIOSAI 2defe9d615 #686/#661 night shift wave 5 (cli): -> 100% seedgo. cli.py main() intercepts <cmd> --help before dispatch (Subcommand_Help ->100). display.py error()/warning()/fatal() refactored from markup-string console.print to Rich Text objects — SAME output, avoids the output_routing flag on cli's own shared helpers (Output_Routing ->100). Behavior-preserving (identical stderr/emoji/color, fatal still exits 1), zero fleet blast radius. 140 tests pass. aipass + commons still in flight. 2026-07-11 02:58:47 -07:00
AIOSAI 7fb65f0255 #686/#661 night shift wave 4 (trigger + api): both -> 100% seedgo. trigger.py + api.py main() intercept <cmd> --help before dispatch (Subcommand_Help ->100). Output_Routing ->100: trigger (branch_log_events/errors/log_events/medic) + api (5 client/secrets modules) route status/error output via cli error()/success()/warning(). Test assertions updated to match routing (trigger 8 across 4 files). Suites re-run by devpulse: trigger 564, api 515, both green. aipass still in flight. 2026-07-11 02:46:51 -07:00
AIOSAI 80badb784a #686/#661 night shift wave 3 completion (memory): -> 100% seedgo. memory.py --help guard (Subcommand_Help ->100). symbolic.py + 6 modules route console.print status/error through cli error()/success()/warning() (Output_Routing ->100). 27 test assertions updated to match the routing (test_symbolic_cli.py, test_symbolic_module.py). Full suite 990 pass / 0 fail (devpulse re-ran the suite; the first agent report wrongly claimed no changes and skipped tests — caught by verify, re-dispatched, now green). 2026-07-11 02:40:26 -07:00
AIOSAI 90296b80f0 #686/#661 night shift wave 3 (backup + seedgo): both -> 100% seedgo. backup.py --help guard + error() routing in 6 modules (Subcommand_Help + Output_Routing ->100). seedgo.py --help guard + output_routing across 13 files + README standards-count refresh + test fixtures flipped for now-compliant seedgo/ai_mail entry points (Subcommand_Help + Output_Routing + Readme ->100). Tests green: backup 247, seedgo 1217. memory held this wave (its changes broke 27 tests, re-dispatched to fix). 2026-07-11 02:17:55 -07:00
AIOSAI de45e1cd2f #686/#661 night shift wave 2: daemon + prax + ai_mail -> 100% seedgo. daemon.py + ai_mail.py main() intercept <cmd> --help before dispatch (Subcommand_Help 0->100). Output_Routing ->100: daemon timer_install/update, prax dashboard/log_audit, ai_mail central_writer route status via cli warning()/error(); ai_mail introspection doc-glyphs -> markup. Tests green: daemon 300, prax 978, ai_mail 765. 2026-07-11 01:34:36 -07:00
AIOSAI f7e2584304 #686/#661 night shift wave 1: spawn + drone + flow -> 100% seedgo. spawn.py main() intercepts <cmd> --help before dispatch (Subcommand_Help 0->100). drone rm.py + flow aggregate_central/registry_monitor route status output via cli success()/error() (Output_Routing ->100). Tests green: spawn 316, drone 864, flow 730. 2026-07-11 01:19:15 -07:00
AIOSAI dbeb8c3122 #688 changelog: note probe-hygiene SOP + location-independent tests 2026-07-11 00:30:51 -07:00
AIOSAI a54d21033e #688 follow-up: probe hygiene SOP + test hygiene. @aipass added docs/probe_hygiene.md (principle: temp=used+deleted+gone, no permanent pointer at a temp path, all 4 defenses + correct probe workflow). Test location-independence: TestRunInit gets a _isolate_cwd autouse fixture (monkeypatch.chdir) so it passes from ANY cwd incl an agent branch dir; 5 test_bootstrap env.AIPASS_HOME tests patch is_throwaway_path->False so they assert correctly even when the repo itself lives under a temp path. Devpulse caught+fixed the 2 update_project tests @aipass missed (same monkeypatch pattern). Verified: 657/657 green in REAL tree AND a fresh /tmp clean-room extraction (was 2 failing in clean-room before the last 2 fixes). --all 2026-07-11 00:30:35 -07:00
AIOSAI 22b4577ec1 #688 aipass: install from throwaway path can no longer hijack machine-wide AIPASS_HOME. Root cause: probe 'aipass install' from a /tmp scratchpad rewrote ~/.claude/settings.json env.AIPASS_HOME -> every CC session machine-wide ran a dead temp tree (stale python+hooks, bogus ImportErrors). 3 defenses: bootstrap.is_throwaway_path() gates the settings write (tempdir/tmp/scratchpad never written to global settings); run_install refuses throwaway home LOUDLY, --force-global-home = explicit override (+help text); doctor _check_global_aipass_home() flags nonexistent/throwaway env.AIPASS_HOME with fix guidance. +11 tests. Built by @aipass; devpulse verified: diffs read, is_throwaway_path live-caught the actual hijack path, doctor check live-green against repointed settings, 201/201 changed-file tests in real env. Suite deltas root-caused environmental: 3 init_flow fails = pre-existing cwd-dependence (pass from repo root), 5 clean-copy fails = the gate working as designed under a scratchpad extraction. 2026-07-11 00:12:26 -07:00
AIOSAI f72515e7bc #677 + #635 hooks: -p headless short-circuit + Codex bridge + portable hook test runner. #677: session_boot.py detects -p in extra_args and execvp's claude directly — headless one-shots never register in ~/.claude/sessions, so tmux/session-lookup/live-attach logic was wrong for them (DPLAN-0226 fine-tune debt; +5 tests, 39 pass). #635: new bridges/codex.py mirrors claude.py with Codex protocol normalization (stdin input->tool_input, stdout hookSpecificOutput envelope, permissionDecision+permissionDecisionReason — fixes DPLAN-0205 bugs) + new hook_test module: drone @hooks test fires every hook from .aipass/hooks.json with per-event mock data, reports fired/blocked/disabled/crashed with timing (23 tests). codex.py bypass entries exactly mirror shipped claude.py set. Built by @hooks; devpulse verified: 62/62 tests re-run against real repo, seedgo 31/31 all three files. 2026-07-10 23:50:37 -07:00
AIOSAI 98d52fa944 #681 owner-cap PART4: watchdog+feedback gate on sealed-registry owner (is_owner), cross-project. The old cwd.name=='devpulse' check was a NO-OP through drone (routed module runs cwd=branch_path, so Path.cwd() is always devpulse; a @flow caller sailed through). New shared handlers/owner/guard.py resolves the REAL caller via AIPASS_CALLER_BRANCH/CWD and checks the frozen is_owner(email,start_path) contract — portable to any project. feedback send stays open (inbound channel); mailbox mgmt owner-only. Fail-safe: legacy devpulse-path heuristic when no owner sealed / resolver import fails. Live-verified owner-allow + flow-deny (both tools) + send-open. 18 tests (15 guard + 3 gate), branch audit 100%. 2026-07-10 22:32:24 -07:00
AIOSAI fdb0086d6c #643 follow-up: check_branch_post honors .seedgo/bypass.json — threaded bypass_rules through branch_audit -> check_branch_post -> _check_json_dir_structure so a branch can sanction a legitimate data subdir (is_bypassed matches branch-relative path); unsanctioned+unbypassed splits still fail. Applied devpulse compass bypass (SQLite/FTS5 store needs own dir). audit @devpulse Json_Structure 100%. +2 tests. 2026-07-10 21:42:59 -07:00
AIOSAI 2112f458fb #643: codify custom_config/ as a json_structure standard — ALLOWED_JSON_SUBDIRS allowlist + check_branch_post() validates {branch}_json/ subdirs (custom_config/ + hidden dirs pass, other splits flagged); json_structure_content.py documents the structure + operator-config location. 5 tests. Surfaced devpulse_json/compass/ as unsanctioned (devpulse bypass next commit). 2026-07-10 21:33:38 -07:00
AIOSAI 0886c9013c #620: git_gate block messages guide instead of dead-end — explain WHY git is enforced, list key drone @git commands, point to --help, show disable path (git_gate.enabled=false in .aipass/hooks.json, verified engine skips disabled hooks per-hook). Split GIT_GH_REDIRECT -> GIT_REDIRECT + GH_REDIRECT; EDIT_REDIRECT shows disable too. Init notice in project_hooks.json template, on/off in README. 6 tests, seedgo 31/31. 2026-07-10 21:30:35 -07:00
AIOSAI b4e2370ee8 #644: gate Telegram /create + /cancel to base @aipass bot only — base_bot.py guards on branch_name (branch bots return False in _dispatch_command + omit from get_custom_commands; base bot None still routes both). Rides along @skills #669.2/#669.3 fail-loud (botfather_client _load_telethon_config raises RuntimeError naming config path vs silent None) + #668 offset tests. 133 TG tests, seedgo 31/31 both files. 2026-07-10 21:19:04 -07:00
AIOSAI c8b7250995 #675: seedgo skips throwaway code — is_throwaway_path (cross-plat temp+scratchpad) + is_prototype_file (# seedgo: prototype marker) in skip_dirs.py; wired into branch_audit._collect_py_files + checklist --prototype early-return. A disposable POC no longer fires 8 violations. 6 tests, live-verified skip. 2026-07-10 21:16:02 -07:00
AIOSAI d8aa300d6b #666: claude() boot shim now ships + installs on onboarding — root .gitignore negation tracks only hooks/tools/install_boot_shim.sh (README stays ignored); setup.sh runs it after hook install (idempotent marker check, non-fatal, venv resolved from script location). Fixes dev-local-only boot feature (macOS user couldn't attach/resume). @hooks did gitignore+installer, devpulse wired setup.sh. 2026-07-10 21:01:07 -07:00
AIOSAI d229ee5df5 #680: cross-platform _is_branch_occupied + _read_session_type (wake.py + daemon.py) — extracted _get_pid_cwd (Linux /proc, macOS lsof -Fn) + _read_session_type_darwin (ps -wwE); macOS occupancy no longer always-False so wake-back won't double-session an interactive branch. Fail-safe on unreadable cwd/env. +11 tests, seedgo 31/31 both files. 2026-07-10 20:43:01 -07:00
AIOSAI 39d979302c #606: SubagentStop gate skips ~600ms seedgo check on empty agent_type (internal CC turns) — early-return _ALLOW at top of handle(); real sub-agents (non-empty agent_type) still get the full modified-files check, Piper untouched (separate hook). +3 tests, 17/17 green, seedgo 31/31. 2026-07-10 20:39:25 -07:00
AIOSAI a4d00e2068 CHANGELOG: #684 os.kill(pid,0) fleet migration (9 sites Windows-guarded, git_lock_tool -> #687). 2026-07-10 19:00:11 -07:00
AIOSAI 663c801c05 #684 os.kill(pid,0) fleet migration: Windows-guard 8 liveness probes — @ai_mail (daemon.py x2, wake.py x2), @drone (lock_handler.py), @flow (lock_ops.py), @hooks (cc_sessions.py, presence.py). Each early-returns to OpenProcess+GetExitCodeProcess on win32 (os.kill(pid,0)=TerminateProcess, KILLS target). Fleet sweep now clears all but git_lock_tool.py (deferred #687). ai_mail 168 / flow 17 tests green, drone/hooks import-clean. 2026-07-10 18:58:49 -07:00
AIOSAI d872d7101f #684 (devpulse): registry.py is_pid_alive Windows-guards its os.kill(pid,0) — win32 early-returns to OpenProcess+GetExitCodeProcess (os.kill(pid,0)=TerminateProcess on Windows, KILLS the target). #682 checker no longer flags it; 26 registry tests green. git_lock_tool.py:120 deferred to a separate cleanup (pre-existing tool debt: 42 prints/no-meta/architecture fail the gate). 2026-07-10 18:49:06 -07:00
AIOSAI cac79b4b1a CHANGELOG: record this session's closes — #682 os.kill detector, #665 (full close, items 1/2/4/5/8), #685 subcommand_help standard, #673 append_jsonl + sweep + fleet adoption. 2026-07-10 18:37:22 -07:00
AIOSAI 4404b60305 #673 offenders adopt prax append_jsonl: @backup (1 .jsonl site), @hooks (2 .jsonl sites), @trigger (11 raw .log appenders across 8 files -> .jsonl + downstream medic_state/medic/log_watcher readers + 5 tests). Zero raw open('a') log appenders remain fleet-wide. Verified: backup 18 / hooks 114 / trigger 189 tests green, no recursion regression, append_jsonl wired at every site. 2026-07-10 18:24:06 -07:00
AIOSAI dfd6732f5b #673 prax-side: append_jsonl (sanctioned .jsonl writer — 500KB/1-backup atomic os.replace rotation) + drone @prax log-audit sweep (30-day stale-log sweep over system + branch logs). Replaces the raw open('a') rotation-bypass. 15 tests. Offenders hooks/backup/trigger adopt next. 2026-07-10 18:00:12 -07:00
AIOSAI 948d2ed535 #685 seedgo: subcommand_help standard — enforces every entry point intercepts <cmd> --help before dispatch (explicit guard or argparse parse_known_args), else <cmd> --help executes the command. 21 tests, cwd-portable (_AIPASS_ROOT anchor). Checker verified independently: 7/17 comply, 10 offenders. 2026-07-10 17:58:41 -07:00
AIOSAI f4d067a3cc #665 item 5: bare-mode hints point to working commands. @daemon (daemon.py) — 'daemon --help' (no such binary) -> 'drone @daemon --help' in hint/USAGE/error (3 spots). @memory (memory.py) — 'drone @memory help' -> standard 'drone @memory --help' (L78,L356; --help already wired). Both verified live. 2026-07-10 15:34:14 -07:00
AIOSAI 9dab0ca3f4 #665 item 4 (spawn): sync_registry_ops derives branch description from passport purpose/role/README, not the hardcoded 'Auto-registered branch' placeholder — wired into new-registration AND --fix backfill of existing placeholders. Root fix that ships + survives regen (the gitignored registry data edit didn't). 0 placeholders in drone systems. 2026-07-10 15:21:14 -07:00
AIOSAI b75a8d272a #665 items 1,2,8 (aipass CLI): --version wired to package metadata (was hardcoded 0.1.0), --help lists real COMMAND names not file stems (help not help_chat, init not init_flow), crash-vs-unknown distinguished (handler raise/import fail surfaces real cause, not 'Unknown command'). +5 tests. 2026-07-10 12:42:39 -07:00
AIOSAI 43afe14017 #682 seedgo: os.kill(pid,0) signal-0 detector — recognizes early-return platform guard (agent.py:187 ref no longer false-flagged), catches 10 genuine fleet offenders. 43/43 tests. 2026-07-10 12:12:35 -07:00
AIOSAI 01fe4fe6e3 #665 (items 6-7) install progress + README audit command fix.
Item 6 — aipass install pip step looked hung. setup.sh ran the heavy editable install of the [dev,memory] extras with pip --quiet, so it went SILENT for minutes during memory wheel builds (looks frozen to a first-time user). Dropped --quiet on that step so pip streams progress, and set the expectation in the echo ('can take a few minutes while the memory wheels build'). Left the fast pip-upgrade step quiet.

Item 7 — README quick-start command errored. README.md:147 showed 'drone @seedgo audit my_project', but audit takes a registered PACK name, so it fails with Unknown pack. Corrected to 'audit aipass' (matches the working example at :119).

Remaining #665 items (version hardcode, --help command names, subcommand --help contract, placeholder descriptions, bare-mode hints, crash-vs-unknown) span aipass/drone/daemon/memory/spawn and stay open for a coordinated per-owner pass. setup.sh syntax-checked (bash -n).

Rides PR#659 (issue-clearing, no main-merge).
2026-07-10 10:37:01 -07:00
AIOSAI 4d9e691e04 #668+#669 skills/telegram: poll offset re-drain, systemd suicide-loop, silent config fallback.
#668 — poll loop re-drained a rate-limited backlog in a flood loop. The offset advanced AFTER process_update, so a rate-limited/rejected/erroring update never advanced it and the same backlog was re-fetched. Fix: advance the offset BEFORE process_update, so a consumed update never pins it (base_bot.py run loop).

#669 — three fixes: (1) systemd unit gets KillMode=process so a Restart is not killed by the old instance's cgroup teardown (the suicide-loop); (2) create_bot_via_botfather now RAISES RuntimeError with an actionable message (names the set-secret command) instead of silently returning None when telethon config is missing/unready — fail-honestly (botfather_client.py); (3) stale config-mechanism docstrings corrected (bot_factory/bot_operations).

Bonus (unbriefed but correct + beneficial): @skills also Windows-hardened _is_pid_alive (OpenProcess+GetExitCodeProcess on win32, os.kill moved into the POSIX branch) + refactored _check_lock to use it, and switched TEMP_DIR to tempfile.gettempdir(). Side effect: base_bot.py os.kill is now platform-guarded.

Built by @skills, verified by devpulse: 653 telegram tests green (incl lock/pid tests exercising the refactor); #668 offset-before-process verified by inspection; #669.2 raise covered by test_botfather_client. Note: @skills dispatch bounced on a usage-limit retry AFTER completing the work — verified the on-disk result independently.

Rides PR#659 (issue-clearing, no main-merge). Source: devpulse todos #41/#52.
2026-07-10 10:32:20 -07:00
AIOSAI e302df6ec0 #683 hooks: rollover _find_repo_root fails loud + edit_gate soft entry-count guard (#664 follow-up).
Two hardening items surfaced during #664 that @memory could not touch (cross-branch edit gate blocked it).

ITEM 1 — _find_repo_root fail-loud (lifecycle/rollover.py). The PreCompact rollover hook's _find_repo_root() returned None SILENTLY when AIPASS_HOME/cwd was wrong -> rollover no-ops invisibly (the exact silent-skip that hid #664 for months). Now logs a logger.error with the AIPASS_HOME value + cwd before returning None (still degrades, just visibly).

ITEM 2 — edit_gate soft entry-count guard (security/edit_gate.py). edit_gate enforced per-entry CHARACTER caps but not entry COUNTS, so a branch could drift past its count cap between rollovers. New _check_section_counts warns (NEVER blocks) when a rolling section exceeds its cap, reading the SAME memory.config.json rollover caps @memory uses (config_loader.section('rollover') -> per_branch/defaults -> count); wrapped so a config-import failure degrades silently.

Built by @hooks, verified by devpulse: 70 tests green (+14 incl never-blocks guarantee, boundary cases, per-branch override, import-failure resilience); LIVE repro proves item1 logs the error on a bad root and item2 warns over-cap (20/15) without blocking; config structure confirmed to match memory's real caps (not inert).

Rides PR#659 (issue-clearing, no main-merge). Source: #664 verify (S292).
2026-07-10 10:27:03 -07:00
AIOSAI a3a476f59d #679 spawn: is_owner() case-folds — is_owner('DEVPULSE') == is_owner('devpulse').
registry.is_owner (apps/handlers/registry.py:382) @-normalized the email but never lowercased, so a mixed-case branch name (registry names are mixed-case: DEVPULSE vs devpulse) returned False against the seated owner while the lowercase form returned True. Harmless today — the only live caller (@ai_mail dispatch_monitor._wake_sender) lowercases first — but the frozen TDPLAN-0012 contract promises a normalized email, and PART-4 owner-gating of watchdog/feedback may pass a raw branch name.

Fix: lowercase BOTH sides of the comparison (passed-in email AND registry owner email), @-strip preserved. +1 case-insensitivity test. Built by @spawn, verified by devpulse: LIVE repro — every case variant of the owner (DEVPULSE/@DEVPULSE/DevPulse) resolves True, non-owners (seedgo/@SEEDGO) and empty stay False; 316 spawn tests green (+1), seedgo 100%.

Rides PR#659 (issue-clearing, no main-merge). Source: #678/TDPLAN-0012 verify.
2026-07-10 04:06:19 -07:00
AIOSAI c970c5761f #634 devpulse: watchdog stall detector — kill false-positives on long tool calls + surface stall live.
Two rough edges on the JSONL stall detector, both hardened in one pass on my own module (apps/handlers/watchdog/agent.py).

PART 1 (false-positive): _has_jsonl_activity inferred liveness purely from JSONL file-size growth over the 120s window. An agent doing ONE genuinely long operation (big Read, long Bash, heavy compute) writes no new JSONL lines for that span -> read as idle -> STALLED fires WHILE the agent is actively working. Fix: watch_agent now also treats an in-flight tool_use as activity. While a tool runs, the assistant's tool_use is the last transcript entry; new _last_entry_is_inflight_tool() tail-reads the newest .jsonl and detects it (fully defensive -> False on any parse/shape drift, degrading to size-based). LIVE-PROVEN against real Claude Code transcripts: sampled my own session across a 10s in-flight bash -> tool_use line is written at tool START and persists the whole call (the sub-second flush lag is irrelevant at the 120s horizon).

PART 2 (invisible stall): the stall only hit _stderr()+logger. The Monitor tool that arms the watchdog turns each STDOUT line into a live event but only captures stderr to a file (never surfaced) -> devpulse never saw the stall until the 600s timeout. Fix: new _stdout_event() emits the stall (+ a long-running-tool advisory for a possibly-hung tool, + a resumed signal) to stdout so Monitor relays it live; the verbose trail stays on stderr+logger.

Stall logic extracted into a StallTracker class (kills deep-nesting). +9 tests (unit + full-loop stdout proofs + real-transcript schema check); 142 watchdog tests green, seedgo audit 100%, no type errors.

Rides PR#659 (issue-clearing campaign, no main-merge).
2026-07-10 03:57:19 -07:00
AIOSAI cded2993f5 #664 memory: external-project branches now auto-roll (rollover discovery no longer cwd-scoped). Branch discovery only saw registries reachable by walking up from the caller cwd, so branches living solely in an external project's *_REGISTRY.json were never reached by rollovers fired from the AIPass tree (PreCompact hook runs cwd=repo root) — their .trinity grew unbounded (one hit 110 key_learnings vs a 15 cap) and vectors went stale. @memory added a persisted known_registries.json (gitignored per-install data) recording every external registry seen via the cwd walk, so discovery reaches them regardless of caller cwd; stale/deleted paths filtered on load. Plus a soft entry-COUNT guard at write time (warns, never blocks) since gates only enforced char caps. Remaining hooks-side harden (_find_repo_root fail-loud + edit_gate count-guard) filed for @hooks. Built by @memory, verified by devpulse: 70 changed-file tests green (+12), memory_json gitignored (data local, code ships), LIVE REPRO proves a rollover fired from AIPass root now reaches an external-registry branch (was invisible before). 2026-07-10 03:28:34 -07:00
AIOSAI 0878afbc81 #676 aipass: init update now refreshes AGENTS.md + prunes stale managed cruft. GAP1 — update_project synced AGENTS.md from a .aipass/project_AGENTS.md template that never existed, so AGENTS.md was a SILENT no-op on every 'aipass init update' (only CLAUDE.md, whose template exists, synced). Added the template + reconciled create/update to one source. GAP2 — update was additive-only; added a whitelist-scoped cleanup pass (_STALE_MANAGED_FILES, currently the retired aipass_global_prompt.md) that removes only positively-identified managed artifacts, logs each removal, never touches user files (registry/README/.gitignore/src/.trinity). SHIP-GAP caught in verify: .aipass/project_AGENTS.md was gitignored by the .aipass/.gitignore allowlist — added !project_AGENTS.md negation or the template would never distribute (the fix would be inert on real installs). Built by @aipass, verified by devpulse: 83 bootstrap tests green (+7), seedgo 31/31, live repro proves update emits AGENTS.md (name-interpolated) AND removes a planted cruft file. 2026-07-10 03:07:01 -07:00
AIOSAI 739dada015 #671 prax: single-instance lock on the monitor — stop duplicate/orphan monitors from double-sending Telegram relay. New instance_lock handler writes a liveness-checked pidfile (prax_json/monitor.pid, outside the tailed system_logs/): acquire() before relay init refuses to start (fail-loud, names the holding PID) when a live monitor holds the lock, reclaims a stale pidfile on a dead PID, release() clears it on shutdown. Liveness probe platform-branched — POSIX os.kill(pid,0), Windows OpenProcess/GetExitCodeProcess (a raw os.kill(pid,0) TERMINATES the target on Windows; reused the canonical devpulse/watchdog/agent.py:137 impl). monitor.py split under the 600-line limit (pid_cache extracted). Built by @prax, verified by devpulse: 120 tests green across the 4 touched files (+25 new incl 3 Windows-path), seedgo 31/31 on all 3 sources. Verify caught the Windows os.kill hazard on the first pass; filed the seedgo windows_compat detector gap as #682. 2026-07-10 02:53:29 -07:00
AIOSAI 10a8f738a0 #660 install: aipass install no longer hard-exits 2 (silently) when it cannot create global symlinks. setup.sh runs under set -euo pipefail; the #660 safe_symlink refactor returns 2 on ln failure, but the call sites read rc on the NEXT line (rc=$?) — so set -e killed the installer at the symlink step BEFORE the ~/.local/bin fallback (built for exactly the no-sudo case) could run. Any sudo-less env (containers, CI, locked-down machines) got a silent exit 2 + no symlinks despite an otherwise-complete install. Fixed all 3 call sites to rc=0; safe_symlink ... || rc=$? (set-e-safe). Found by the #678 owner-capability docker verify. +tests/docker_owner_verify.sh (owner-capability SOP harness) +tests/_install_diag.sh. 2026-07-10 01:07:35 -07:00
AIOSAI 550839003e changelog: 2026-07-10 — #678 owner-capability model + #661 watchdog exit-code fix 2026-07-10 00:47:10 -07:00
AIOSAI 874c7fed2e #678 owner-capability: seal project ownership in the registry + wake the OWNER back on dispatch completion. TDPLAN-0012 — 3 parts built in parallel against a frozen is_owner contract, verified end-to-end by devpulse.
@spawn: owner + registry_id written into the SEALED registry entries (authority lives in registry, not the self-editable passport). ensure_project_has_owner() now keys off citizen_class=manager (was earliest-created, which mislabeled @aipass) and writes the registry entry. get_owner()/is_owner() resolvers added. 315 tests, seedgo 100%.
@hooks: new registry_gate PreToolUse handler seals *_REGISTRY.json — blocks raw writes/tee/sed/rm + Edit/Write/MultiEdit, redirects to drone @spawn; per-clause bypass defeats compound-command smuggling; reads allowed. 82 tests, seedgo 100%.
@ai_mail: wake-back reslope — SKIP_SENDERS blocklist replaced by an is_owner allowlist. Only the project owner is woken when their dispatched agent completes; all other guards intact (depth cap, lock, occupancy, honest messaging, dispatch_wake.log). seedgo 100% on the changed file.

devpulse cross-part verify (REAL unmocked resolver): is_owner resolves devpulse-only; gate 13/13 incl compound-smuggle blocked + reads/drone-@spawn allowed; wake-back wakes owner / skips non-owner / respects depth-cap; 195 new-suite tests green together. Note: AIPASS_REGISTRY.json is gitignored — this ships the CODE; owner data regenerates per-install via ensure_project_has_owner. Still open (PART 4): gate watchdog+feedback on is_owner; portability of owner-only privileges across projects.
2026-07-10 00:46:17 -07:00
AIOSAI ae8f4a843a #661 watchdog: 'invoke via Monitor tool' reminder no longer trips the exit-code fail-flag. _handle_agent printed this unconditional info banner through cli error() -> post-#661 every SUCCESSFUL watchdog agent run exited non-zero with a red X. Rerouted to a dim console note (exit 0); genuine arg-errors still error()->exit 2. Caught + verified by dogfooding (S289). 2026-07-10 00:46:01 -07:00