Commit Graph
1084 Commits
Author SHA1 Message Date
AIOSAIandClaude Opus 4.8 e47d4f0463 feat(memory): FPLAN-0270 Phase 1 — entry_limits config (warn-first, enforce:false) + load_entry_limits reader + 14 tests
Config-driven char caps for .trinity memory entries. Phase 1 = foundation only:
adds entry_limits section to memory.config.json (4 caps: learnings 200, sessions
300, todos 200, observations 600) and the load_entry_limits(branch) reader
(deep-merge per_branch overrides, safe-defaults on missing/malformed). Reader has
NO callers yet (Phase 3 wires it) — unused_function bypass is intentional.
Verified by artifact: 14/14 tests, seedgo 100%, scope clean. enforce:false →
zero behavior change. Part of DPLAN-0205.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 01:15:54 -07:00
AIOSAI d9a2a48a1e fix(ai_mail): retire dashboard_sync writer — stop writing the ai_mail dashboard section (prax self-sources) 2026-06-13 00:13:23 -07:00
AIOSAI 37fb07ca16 fix(prax): quick_status self-sources mail counts from inbox.json (decouple from ai_mail section) 2026-06-12 23:57:08 -07:00
AIOSAI fc49928a4b fix(prax): slim dashboard to lean glance — drop session/todo/ai_mail sections, quick_status is the count home 2026-06-12 23:41:30 -07:00
AIOSAI 58bd70beac fix(prax): prune deprecated dashboard sections on refresh (bulletin_board et al) 2026-06-12 23:20:33 -07:00
AIOSAI 1057be65a4 fix(prax): slim devpulse dashboard — drop duplicated todos[] bodies, keep count (startup-context fix) 2026-06-12 23:09:42 -07:00
AIOSAIandClaude Opus 4.8 c5a96cbdcf fix(backup): rename store dir .backup_system to .backup + remove dead versions/ (FPLAN-0269 follow-up)
Backup root is now .backup/ via BACKUP_DIR (builder.py:19); tracker.py uses backup_root() not a hardcoded path; patterns.py BUILTIN_IGNORES + docstrings/README updated. Removed the orphaned per-timestamp versions/ scaffold (setup.py) and unused build_versioned_path() — both superseded by the Phase-3 versioned/ baseline+diff store. .backup/ coexists with flow's .backup/processed_plans/. Repo-root .backupignore now ignores both .backup/ and (until manual deletion) .backup_system/ (also carries Patrick's *logs rule). Verified by artifact (seedgo 100%, 220 tests) + live (throwaway writes to .backup/, no versions/, Drive reads .backup/versioned/).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 22:06:50 -07:00
AIOSAIandClaude Opus 4.8 a0016669b7 chore(backup): track repo-root .backupignore — it is the single source of truth now (FPLAN-0269 follow-up)
.backupignore is now AIPass's managed backup filter (true gitignore semantics via pathspec), so it belongs in version control like .gitignore — a fresh clone gets the curated rules, not just the auto-seed default. Includes the .ruff_cache/ + .coverage additions.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 21:38:28 -07:00
AIOSAIandClaude Opus 4.8 f4b776949e fix(backup): .backupignore = true .gitignore via pathspec — single source of truth + Drive stops dropping dotfiles (FPLAN-0269)
Replace hand-rolled fnmatch+part-loop matcher with pathspec gitwildmatch (leading-slash anchoring, !negation, dir-only foo/, *-not-crossing-/, last-match-wins). Demote BUILTIN_IGNORES to a seed-only default (written when absent, never merged at runtime); delete IGNORE_EXCEPTIONS/is_exception (exceptions are native ! lines). snapshot+versioned+all+mirror-cleanup all obey one .backupignore. Remove the drive_sync dotfile-skip so .trinity/.chroma/.aipass/.ai_mail.local (4558 files incl memories) now reach Drive. Add a Drive-sync output panel matching snapshot/versioned. Declare pathspec (pure-python, cross-OS). Verified by artifact (seedgo 100%, 220 tests incl 26 new gitignore-parity) + live (dotfile flows into store, !negation re-includes end-to-end).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 21:36:08 -07:00
AIOSAI c63a43af30 docs: de-hardcode branch count in devpulse README + branch prompt (→ 'the other branches' / 'drone systems' for the live list) + sync AGENTS.md startup protocol to match CLAUDE.md (dashboard-refresh flow) 2026-06-12 18:52:34 -07:00
AIOSAI 9e5ff4e6c3 fix(backup): Google Drive folder duplication + dedup-wipe — restore GOLD's lock scope (whole-method _folder_cache_lock on project/nested folders, lock-free backup-folder short-circuit, guarded tracker reset). Fix drive_* underscore command routing + declare 3 google libs. Verified by artifact (seedgo 100%, 197 tests incl. 5-thread concurrency) + live (real Drive backup, no duplicate folders) 2026-06-12 18:47:47 -07:00
AIOSAI ffc5f3b919 fix(memory): rollover no longer silently loses rolled-off learnings — restore pre-trim backup on empty-embeddings path + honor skipped-extraction flag to close the concurrent-rollover race (orchestrator.py + extractor.py, +4 tests). Verified by artifact (seedgo 100%, 876 tests) + live (drone @memory search returns a rolled-off item at 91%) 2026-06-12 18:01:17 -07:00
AIOSAIandClaude Opus 4.8 1049bc308b feat(backup): FPLAN-0268 — Google Drive sync pipeline + restore command (restoration Phase 4, final)
Faithful port of GOLD's GoogleDriveSync against the live @api gateway. Completes
the backup restoration (master FPLAN-0264).

Drive pipeline (handlers/drive/):
- DriveClient: folder hierarchy 'AIPass Backups/<project>/', thread-safe cache,
  retry-with-rebuild. Auth via aipass.api get_drive_service + api_call_with_retry
  (never console-OAuth).
- upload.py: resumable MediaFileUpload, 3 threaded workers, single + batch.
- tracker.py: mtime+size dedup (.backup_system/drive_tracker.json) — no re-upload
  of unchanged files.
- test.py: connectivity check.
All 4 drive_* modules un-stubbed. all = snapshot->versioned->drive-sync, drive
step FAILS HONESTLY if creds absent (no silent skip, snapshot+versioned still run).

restore command (modules/restore.py -> handlers/diff/restore.py):
- 'restore <project> list <file>'  (baseline + current + diffs)
- 'restore <project> file <file> <out>'  (reconstruct + write)

pyright/cleanup (Patrick's call): removed backup's standalone pyrightconfig.json
(pre-namespace leftover, archived) so it inherits the repo-root config like every
citizen; dead PyQt5 ui/settings_window.py archived.

Drive tests fully mocked — ZERO real Google calls in CI. Live Drive upload awaits
Google OAuth creds (~/.secrets/aipass/google_client_secret.json + drone @api
reauth google) — Patrick's setup step.

Verified by artifact (devpulse): seedgo 100% all 36 standards / 37 files, 187
tests, ruff clean; restore list/file round-trip confirmed live.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 14:53:42 -07:00
AIOSAIandClaude Opus 4.8 a8cd576bae feat(backup): FPLAN-0267 — versioned baseline + per-file diff engine (restoration Phase 3, the heart)
Faithful port of the GOLD versioned engine (no reinvention). Replaces the mtime
full-copy-into-per-run-dirs remnant with ONE persistent store
(.backup_system/versioned/) using GOLD's file-folder packaging:

  <parent>/<name>/<name>                       current (copy2, mtime preserved)
  <parent>/<name>/<stem>-baseline-<date>.<ext> first-run full copy, never touched
  <parent>/<name>/<name>_diffs/<name>_v<old-mtime>.diff  unified-diff per change

Patrick's laws, all enforced + tested:
- versioned backs up the EXACT same files as snapshot (same scan/ignore;
  all.py shares one scan between modes)
- first versioned run = baseline snapshot of that state
- append-only: versioned NEVER deletes (cleanup stays snapshot-only)
- change detection is LEDGER-FREE (source mtime vs store-current mtime) —
  removes versioned's use of shared timestamps.json, killing the
  snapshot-starves-versioned regression

New diff/restore.py (list_versions + restore_file); diff/generator.py wired
(binary detection, DIFF include/ignore patterns); path/builder.py file-folder
versioned branch (root/ wrap, >50-char hash shortening). +15 tests -> 125.

Verified by artifact (audit 100% all 36, pytest 125, ruff clean) + LIVE
end-to-end: snapshot-first-then-versioned baselines all 5 files (starvation
dead) -> edit -> diff with old-mtime timestamp + current overwritten + baseline
intact -> source delete -> versioned store untouched while snapshot
mirror-deletes -> restore round-trip byte-identical.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 13:55:03 -07:00
AIOSAIandClaude Opus 4.8 826ffcd54c feat(backup): FPLAN-0266 — snapshot fidelity + shared core (restoration Phase 2)
Restore the snapshot-side machinery the 2026-04-23 rewrite degraded, ported from
the GOLD archive onto the current per-project handlers.

- handlers/cleanup/mirror.py cleanup_deleted_files: exception-aware mirror-delete
  (vanished source files are removed from the snapshot, respecting ignore
  exceptions) — replaces the blind rmtree+recopy.
- copy/snapshot.py: mtime-skip quick-check (unchanged files no longer re-copied),
  long-path guard (>260), read-only handling.
- report/result.py BackupResult: critical vs non-critical errors + warnings +
  files_deleted + success.
- ignore/patterns.py: IGNORE_EXCEPTIONS + is_exception().
- modules/snapshot.py: quick-check fast path.
- +16 tests (test_snapshot_fidelity.py) -> 110 total.

Verified by artifact (devpulse): seedgo audit 100%, pytest 110 passed, ruff clean,
AND a live throwaway-project test — deleted two source files, re-snapshotted, both
mirror-deleted, kept files preserved, 3 skipped/0 re-copied (quick-check working).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 13:19:02 -07:00
AIOSAIandClaude Opus 4.8 5ab257e569 feat(backup): FPLAN-0265 — seedgo 100% + 94-test green foundation (restoration Phase 1)
Safety net under backup before the feature rebuild (master FPLAN-0264 Phase 1).
No new features — harness + standards only.

Tests (new src/aipass/backup/tests/): 94 tests across json_handler, CLI routing,
filesystem handlers, error resilience, mocked drive — ported from the canonical
citizen conftest pattern (autouse mock_infrastructure, env log-redirect, tmp_path).
Hermetic + stdlib-only (passes 3.10-3.13), ruff clean. Module coverage 27%.

Standards to 100% (all 35): shared --help/-h/help guard in all 10 modules'
handle_command (Cli 92->100, Introspection 86->100); 6 Phase-3 drive/diff/ui
stubs wired-or-bypassed (Dead_Code 82->100, Unused_Function 81->100);
requirements.project.txt (Architecture); README module list (Readme 87->100);
display.handle_command no-op (Modules); create_progress_bar->build_progress_bar
(Trigger). Overall 95->100.

Verified by artifact (devpulse): seedgo audit 100% + pytest 94 passed + ruff clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 12:51:24 -07:00
AIOSAI 43a6ab2212 fix(drone): route @backup through interactive passthrough — add 'backup' to INTERACTIVE_BRANCHES so snapshot/versioned/all inherit the TTY instead of capture_output=True. Drone was flattening backup's Rich output (non-TTY -> color stripped, transient progress bar rendered to nothing) and the 30s capture timeout would kill large backups. Mirrors the existing 'cli' entry. Verified live: full rich output now flows through drone. + CHANGELOG. 2026-06-12 11:35:25 -07:00
AIOSAI 1747a23e5c feat(backup): restore full 9-stage rich CLI output (FPLAN-0263) — new backup_timestamps state handler + display.py 5-stage pipeline (last_backups panel -> boxed header -> live Rich progress bar -> result summary -> backups_now panel), extend BackupResult with files_checked/files_skipped/backup_path, emit on_progress callbacks from copy/snapshot+versioned, rewire snapshot/versioned/all to the rich pipeline. Faithful port from gold archive source. Verified live under pty: full color + animated transient progress bar. seedgo 95%, ruff clean. 2026-06-12 11:35:18 -07:00
AIOSAI 1f3727d4fc fix(backup): split top-level --help from bare introspection — drone @backup --help now shows a curated Rich command reference (boxed header + USAGE + COMMANDS), bare drone @backup shows the discovered-modules self-map. Previously both fell through to one conflated module-list block. Also revives the dead print_introspection() (was unused). Matches the commons/skills citizen pattern. ruff clean, both paths verified live (S220) 2026-06-12 09:05:20 -07:00
AIOSAI bbe3f43835 feat(backup): namespace migration standalone -> aipass.backup.* citizen — convert 47 internal imports across 11 files (apps.* -> aipass.backup.apps.*), fix importlib discovery string, drop sys.path/PROJECT_ROOT hack, add root __init__.py package marker. Diagnostics 0%->100%, Imports 99%->100%, overall 92%->95% (S220). Verified-by-artifact: all 10 drone cmds live, register+status e2e clean, ruff clean, zero standalone imports. Test_Quality (no suite) stays separate build (td-018) 2026-06-12 07:33:20 -07:00
AIOSAI dea91bc613 feat(backup): revive dormant citizen (revive-to-working) — path-depth parents[4]->[3], fill branch prompt, archive stray upgrade/ to .archive, Handler_Import + happy-path central logging (DPLAN-0203 night shift). CLI runs clean. seedgo 92%: structural gaps (Diagnostics=standalone sys.path/pyright, Test_Quality=no test suite) flagged for Patrick, not forced overnight 2026-06-12 01:38:29 -07:00
AIOSAI ee004c4568 feat(daemon): revive dormant citizen (revive-to-working ONLY) — scrub 6 stale @vera refs, add happy-path logger.info() central logging, fix Ruff/Introspection/Windows_Compat/Handler_Import/Imports (DPLAN-0203 night shift). 387 tests, seedgo 100%. Scheduler .daemon/ redesign deferred to DPLAN-0204 2026-06-12 01:29:58 -07:00
AIOSAI 8379f88fd7 feat(commons): revive dormant citizen — verify namespace migration (172 imports/67 files) + path-depth + 4 bug fixes, add E501/CLI/Windows_Compat cleanup + happy-path logger.info() central logging (DPLAN-0203 night shift). 449 tests, seedgo 100% 2026-06-12 01:12:10 -07:00
AIOSAI 1871e55b51 feat(skills): revive dormant citizen — namespace skills.*→aipass.skills.* (48 imports), path-depth parents[3]→[4], happy-path logger.info() central logging (DPLAN-0203 night shift). 252 tests, seedgo 100% 2026-06-12 00:25:11 -07:00
AIOSAI a797f9d3d3 fix(git): kill post-merge friction — sync FF-only realign (not rebase), merge-not-squash docs, deterministic spawn registry 2026-06-11 15:21:58 -07:00
AIOSAI 83e65b3374 chore: gitignore PPLAN-*.md for plan-type consistency + spawn builder template registry id refresh 2026-06-11 13:53:40 -07:00
AIOSAI 2af856d81d chore(release): v2.5.3 — date-based CHANGELOG headers + rename sunday_merge playbook to merge (drop weekly cadence) 2026-06-11 12:49:07 -07:00
AIOSAI 54d55abebc feat(aipass): init detects missing Claude Code, offers install (yes/no) 2026-06-11 00:12:32 -07:00
AIOSAI ed17630b76 fix(drone): broker start_background blocks until listening — kill connect-before-bind race 2026-06-10 23:23:56 -07:00
AIOSAI 707f54a6f2 fix(ci): guard remaining AF_UNIX broker tests for Windows — ai_mail + aipass 2026-06-10 23:04:52 -07:00
AIOSAIandClaude Opus 4.8 e33cf2bfbe fix(ci): guard Linux-only sandbox tests for Windows — skipif(sys.platform != linux)
test_broker.py (AF_UNIX sockets + openat2) and test_sandbox.py (bwrap) are
Linux-only; module-level pytestmark skips them on windows-latest while leaving
Linux runs unchanged. Unblocks the windows-setup CI check (red since the
sandbox build 0b4ba63).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-10 22:50:44 -07:00
AIOSAIandClaude Opus 4.8 53340ab169 fix(seedgo): audit local==CI parity — output-dir skips + diagnostics fail-honesty + pyright determinism (FPLAN-0261)
Hoist per-checker SKIP_DIRS to shared SOURCE_SKIP_DIRS (artifacts/dropbox are
output dirs, not source; no git coupling). Diagnostics: python3->sys.executable,
parse/run failures now fail loud instead of silent 0-errors-clean, and pin
pyright resolution with --pythonpath sys.executable. drone bypasses test-only
broker start_background. Proven all-13-branches-100% deterministic in an
unactivated shell (local==CI).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-10 22:09:01 -07:00
AIOSAI 17863ac4c5 refactor(shared): re-home aipass.common into its steward — src/aipass/aipass/shared (FPLAN-0260)
src/aipass/common was the only non-citizen directory in the agent namespace.
Per @seedgo design review: moved into @aipass (owner) as aipass.aipass.shared,
content byte-identical. @spawn imports across (blessed shared-infra category,
same as aipass.prax/cli). New subprocess guard test pins the bootstrap-safety
invariant (shared/ loads zero branch deps — aipass init stays pre-drone-safe).
9 import/doc sites updated, 9 documented seedgo bypasses (pre-infra leaf,
stdlib-only by design). aipass 480 + spawn 315 tests green, both audits 100%,
repo-wide zero refs to the old path.
2026-06-10 18:26:26 -07:00
AIOSAIandClaude Opus 4.8 0b4ba63fae feat(sandbox): kernel filesystem boundary for agent containment (DPLAN-0202/FPLAN-0250)
Every autonomous agent can launch inside a kernel-enforced mount namespace
(srt -> bwrap+seccomp): reads stay open (shared live FS preserved, bind-mount not
isolation; own-tree writes land live), but rm/python/find/Write on .git or sibling
trees hit EROFS. /tmp + own tree writable; .git RW devpulse, RO builders. Inert by
default behind AIPASS_SANDBOX_ENABLED (off); flag-off path byte-identical to old.

hooks: srt wrapper + per-role build_policy + broker_secret mask; rm_gate demoted.
drone: out-of-sandbox broker (identity allowlist, openat2 RESOLVE_BENEATH, HMAC
handshake over inherited fd, audit); drone rm via broker when sandboxed.
ai_mail: dispatch gate + broker-fd wiring (fail-loud exit -4, never silent).
aipass: doctor Sandbox group + setup.sh prereqs (LOUD on missing).

Proven by a live 16-check red-team suite. seedgo 100% + 2859 tests green across
all 5 touched branches.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-10 13:16:22 -07:00
AIOSAIandClaude Opus 4.8 0c6e8ac425 fix(hooks): auto_watchdog sound-migration (FPLAN-0249 tail)
Same action-gated pattern as the notification handlers — speak() -> 'sound'
return-key. Missed in b26bd7c. Hooks suite green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-10 13:10:27 -07:00
AIOSAIandClaude Opus 4.8 b26bd7c853 fix(hooks): cadence sound-migration tail — action-gated sound via return-key (FPLAN-0249)
Notification handlers (announce, email, stop_sound, tool_sound) return a
'sound' key the engine plays on action instead of calling speak() on every
invocation — quieter and honest (skipped loaders stay silent). Slim
cadence_investigation.md. Tests updated to assert the return-key form. 472/472
hooks green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-10 13:09:32 -07:00
AIOSAIandClaude Fable 5 00edd8b3a0 fix(hooks): auto_fix ruff legs were silently dead — invoke via venv interpreter
Three ruff call sites called bare `ruff`, absent from the hook subprocess
PATH (ruff lives only in .venv) — logged 'ruff not found' 177x over ~a month,
silently skipping lint+format on every edit. Also `--output-format=text` was
removed from modern ruff. Fixed all three sites to `sys.executable -m ruff`
(the pattern the working pyright leg already uses) + concise format + honest
rc>=2 error logging. Tests now pin the invocation (argv == sys.executable -m
ruff) so a regression fails loud — the subprocess-mock is how this hid.
438/438 hooks tests green; live-verified through the real hook pipeline.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-09 22:34:38 -07:00
AIOSAIandClaude Fable 5 c3c6c2dde7 docs(changelog): slim global prompt (DPLAN-0201) + prax hook-color fix (td-007)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-09 20:17:19 -07:00
AIOSAIandClaude Fable 5 2aafade678 feat(prompt): slim global prompt to context-on-demand map, 13.8KB->7.8KB (DPLAN-0201)
Rewrite the always-injected global prompt from a ~13.8KB encyclopedia
into a ~7.8KB navigation map. The prompt now carries AWARENESS; detail
is fetched on demand via 'drone @agent --help'. Dissolves the harness
~10k-char truncation bug — the old prompt's tail (Hard Rules onward)
silently never arrived; the slim one injects whole.

- drone pinned at top as the router; one drilled reflex: --help before use
- framework tree restored; all 13 agents as 2-3 sentence bios
- introspection named as our term; breadcrumb-first navigation flow
- git its own section (raw git/gh blocked, drone-only, devpulse-writes)
- plans section (DPLAN/FPLAN/PPLAN/RPLAN + 'drone @flow templates')
- @memory chroma awareness (local + global stores, search before cold)
- sub-agent usage section incl. model practice (never fable)
- PROMPT_STYLE-conformant; 7855 chars (cap 8000, measured in chars)

Backup retained: .aipass/aipass_global_prompt.BACKUP-2026-06-09-S211.md

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-09 20:16:29 -07:00
AIOSAIandClaude Fable 5 73aedef20f fix(prax): hook events render styled in monitor — regex required phantom action= field (td-007)
Root cause: _HOOK_PATTERN required an action= key that cadence never
emits — it logs the action as the bare second word (fired/skipped).
Extraction failed, so events never reached the styled print_hook_event
renderer (bold-green lightning / dim dot). Pipeline was already correct.

- _HOOK_PATTERN -> bare-word capture: r'\[HOOKS\]\s+(\w+)\s+(\w+)'
- enriched hook event detail (period, offset, short session id)
- corrected docstring that documented the phantom action= format
- tests updated to real production format + real-pipeline test added
- type:ignore on watchdog imports (repo convention)

Verified: 914/914 prax suite green (90 log_watcher). @prax dispatched
for full-pipeline trace; stale monitor process explained the no-show.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-09 20:16:16 -07:00
AIOSAIandClaude Fable 5 fc4b263504 fix(hooks): cadence separate-process race + action-gated sound + auto_fix diagnostics regression (DPLAN-0200, FPLAN-0249)
Cadence redo — verified against the live execution model, not unit tests:
- Counter now advances exactly once per real turn (mtime debounce +
  transcript-size token + flock). Fixes the separate-process leapfrog where
  global/branch loaders double-incremented and fired erratically.
- Structured [HOOKS] cadence fired|skipped logging; prax monitor renders
  hook events distinctly for live visibility.
- Action-gated sound: handlers return a 'sound' key the engine plays only on
  real action — skipped loaders are silent (no more false piper every turn).
- Fixed auto_fix.py: leftover speak() NameError (swallowed by broad except)
  meant diagnostics silently never ran on any edit. Removed; sound moved to
  the error path.
- Tests rewritten to model separate-process execution (leapfrog regression
  test added); sound assertions across all refactored handlers. 438 pass.

prax: hook fire/skip event rendering in the live monitor. 913 pass.

README: hardcoded metrics (version/tests/PRs/standards) -> live PyPI+codecov
badges and qualitative wording; killed the 33-vs-36 drift. CHANGELOG W24.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-09 16:28:26 -07:00
AIOSAI 2bccf0311e feat(hooks): prompt injection cadence — fire loaders every Nth turn, config-tunable (DPLAN-0200, FPLAN-0249)
Stop re-injecting the global + branch prompts every turn (~3k tokens/turn).
They now fire together every 5th turn; the prior injection persists in context
between fires. Identity + email stay every-turn.

- apps/modules/cadence.py: per-session turn counter (/tmp/aipass-cadence-
  {session_id}.json), should_fire(loader)/reset_counter(), DEFAULTS + deep-merge
  config (api provider.py pattern). 'drone @hooks cadence' introspection.
- global_loader.py + branch_loader.py: cadence guard via importlib (crash-
  isolated); non-fire turn returns empty.
- compact.py: PreCompact resets counter to -1 -> next turn = 0 = all fire
  (rebuild context after compaction). New session = fresh counter = all fire.
- hooks_json/custom_config/cadence_config.json: tunable knob (period/offsets/
  enabled), one file, no code edits. Data lives in the json home, not the code
  dir. Missing file = code DEFAULTS = safe.
- .seedgo/bypass: documented stdlib-json config read (json_handler N/A for a
  dispatch engine).

435 tests pass (26 new), seedgo 100%, pyright 0.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 23:07:36 -07:00
AIOSAI d24887b7f5 feat(memory): template-conformance normalize + auto-heal on triggers (DPLAN-0200)
Memory files now reconcile to template, not just clean known fields:
- normalize.py: rewrote from field-targeted cleanup to template-conformance —
  strips ANY key not in the template at every level (root/metadata/limits/status).
  Kills legacy orphans (old 'st' blocks, active_tasks, current_lines, max_lines)
  that field-targeted cleanup was blind to. Fixed _MEMORY_ROOT path (parents[3])
  that silently skipped template loading in production.
- memory_watcher.py: wired normalize_memory_file into both scan paths
  (check_and_rollover + on_modified) with a write-loop guard — drift now
  self-heals on every trigger, no manual run needed.
- line_counter.py: stop writing current_lines (entry-count is the only metric).
- LOCAL/OBSERVATIONS templates: removed line-count fields.

Entry-count is the sole rollover metric, both files, all branches.
873 tests pass, seedgo 100%.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 23:07:24 -07:00
AIOSAI a53ea93b17 fix(ai_mail): preserve multi-line reply/send bodies — join args[1:]
Reply and send silently truncated multi-line bodies to the first CLI arg.
handle_reply(args[1]) and parse_send_args(rest[1]) dropped args[2:]/rest[2:]
when a body word-split into multiple args. Now join all remaining args.
Backwards-compatible; single-arg messages unchanged. +6 tests (718 total).

Found via @hooks replies arriving as first-line-only (60/48 chars).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 21:27:23 -07:00
AIOSAI ff9cc3f3b5 docs(playbook): strengthen — never move HEAD lightly (Patrick's rule) 2026-06-08 11:29:48 -07:00
AIOSAI e97130ffbc docs(playbook)+memory: git law — local=truth, never checkout main / move heads lightly; squash vs ff realign corrected 2026-06-08 11:28:33 -07:00
AIPass 1deb786c8a Merge pull request #637 from AIOSAI/dev
security(ci): least-privilege token on e2e-wheel workflow + W24 changelog (also carries playbook commit 6b89fcd)
v2.5.2
2026-06-08 10:36:14 -07:00
AIOSAIandClaude Opus 4.8 2e96ddc302 chore(release): bump version 2.5.1 -> 2.5.2 (security patch)
Mid-week patch release for the CI/release security hardening:
least-privilege e2e-wheel token + Sigstore-signed GitHub Releases.
Bumps both pyproject.toml and src/aipass/__init__.py __version__.

Versioning scheme: patch (2.5.x) = small mid-week fixes, minor (2.x.0)
= Sunday main-merge batches.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 10:28:48 -07:00
AIOSAIandClaude Opus 4.8 076110a2fb security(release): sign GitHub Release artifacts with Sigstore (keyless)
publish.yml github-release job now signs the wheel + sdist via
sigstore/gh-action-sigstore-python (pinned v3.3.0 / 04cffa1d), keyless OIDC,
and attaches the .sigstore.json bundles to the GitHub Release through the
existing dist/* glob. Added id-token: write to the job for OIDC.

PyPI uploads were already attested (Trusted Publishing); Scorecard's
Signed-Releases check inspects GitHub Releases, which only carried bare wheels
-> score 0. .sigstore.json is in Scorecard's recognized signatureExtensions.
Verified: action globs ./dist/*.whl ./dist/*.tar.gz (action.py:202), auto-attach
gated on release-event (we trigger on push:tags) so we upload via dist/* and set
release-signing-artifacts:false. First live proof = next v* tag.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 10:19:51 -07:00
AIOSAIandClaude Opus 4.8 dab8d29645 security(ci): add least-privilege permissions block to e2e-wheel workflow
e2e-wheel.yml was the only workflow missing a top-level permissions: block
(added during cross-OS work after PR #624 hardened the rest), so it ran with
default broad GITHUB_TOKEN scopes -> OpenSSF Scorecard Token-Permissions = 0.
Add 'permissions: contents: read' to match the other 7 workflows. CHANGELOG
W24 entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 10:09:00 -07:00