Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2a54ed8446 | ||
|
|
91b3f437fe | ||
|
|
1e00119d9b | ||
|
|
9a64db9093 | ||
|
|
626ab81a46 | ||
|
|
f4b203a74e | ||
|
|
e80e524dfe | ||
|
|
59a6fcee13 | ||
|
|
14e134b8e6 | ||
|
|
ccc8d6a97b | ||
|
|
1ef1e2e89c | ||
|
|
8efb204486 | ||
|
|
0661949c15 | ||
|
|
0f26efd706 | ||
|
|
a242489c6d | ||
|
|
1ee51f3295 | ||
|
|
27a175b2c9 | ||
|
|
4c7e14a255 | ||
|
|
24065f11b3 | ||
|
|
176f68439c | ||
|
|
c58fd263ab | ||
|
|
d5829f80e8 | ||
|
|
cc8f809a50 | ||
|
|
8a843429ca | ||
|
|
8bd270287d | ||
|
|
80aac59423 | ||
|
|
668841417f | ||
|
|
89fa2c1db2 | ||
|
|
f3b3ebad9b | ||
|
|
cd1af34be8 | ||
|
|
3ad0580070 | ||
|
|
4383c6c9d8 | ||
|
|
ee78c39e80 | ||
|
|
87d131218e | ||
|
|
e63a4e9945 | ||
|
|
2f5ce5ac87 | ||
|
|
895b8f04fd | ||
|
|
bedf58e7b5 | ||
|
|
cc449c4a18 | ||
|
|
da46dde7ce | ||
|
|
a880139a1e | ||
|
|
f7d7f78c63 | ||
|
|
ed58eb7aa6 | ||
|
|
740ba30f59 | ||
|
|
85f0292828 | ||
|
|
0a617586d5 | ||
|
|
62e639794f | ||
|
|
95894e4ca7 | ||
|
|
efa5aced74 |
@@ -17,7 +17,7 @@ Goal: signal density over prose. Prompts are injected every turn — every line
|
||||
|
||||
# What NOT to put in a prompt
|
||||
|
||||
- Session state, current work, in-flight issues. That goes in `STATUS.local.md` and `.trinity/local.json`.
|
||||
- Session state, current work, in-flight issues. That goes in `.trinity/local.json` (todos[]) and `DASHBOARD.local.json`.
|
||||
- Long explanations of how a system works. Plant a breadcrumb ("see `@branch --help`") and move on.
|
||||
- Personal notes ("remember, you like short replies"). That goes in `.trinity/observations.json`.
|
||||
- Version numbers, PR numbers, dates. Those rot within days.
|
||||
|
||||
@@ -11,7 +11,7 @@ Patterns here are exact. Don't guess command syntax — examples are the API. Mi
|
||||
|
||||
# AIPL — Terse Writing Convention
|
||||
|
||||
When writing .trinity/, ai_mail, STATUS.local.md, plans: use AIPL. Human-facing output (CLI, logs, README): use English.
|
||||
When writing .trinity/, ai_mail, plans: use AIPL. Human-facing output (CLI, logs, README): use English.
|
||||
|
||||
Rules:
|
||||
- Drop grammar: the, a, an, for, with, on, in, at, to, from, of, by, and, but, or, was, were, been
|
||||
@@ -151,19 +151,16 @@ Never create plan files manually. Always `drone @flow create`. Flow handles numb
|
||||
|
||||
`.trinity/` files are your memories — experiential, personal, yours. How you persist across sessions.
|
||||
|
||||
`STATUS.local.md` is different — live status beacon for ecosystem. Auto-synced to central `STATUS.md` on PR create/merge. Other agents read STATUS to see your state without digging into memories. Crossover with `local.json` fine — same fact, different purpose: `local.json` for you, `STATUS.local.md` for ecosystem.
|
||||
|
||||
Four files:
|
||||
Three files:
|
||||
- `passport.json` — IDENTITY. Role, purpose, principles. Update only when identity genuinely evolves.
|
||||
- `local.json` — YOUR MEMORY. Session log (`sessions[]`) + `key_learnings`. What happened, what learned, what matters next.
|
||||
- `local.json` — YOUR MEMORY. Session log (`sessions[]`) + `key_learnings` + `todos[]`. What happened, what learned, what matters next.
|
||||
- `observations.json` — MEMORY OF THE USER. Preferences, style, friction, breakthroughs. Skip if nothing new this session.
|
||||
- `STATUS.local.md` — PUBLIC BEACON. Current work, issues, todos, recently completed. Notepad for quick captures.
|
||||
|
||||
Where to put what:
|
||||
- "Worked on DPLAN-0125, learned about peak hours" → `local.json`
|
||||
- "User prefers short replies" → `observations.json`
|
||||
- "PR #266 needs merge, Track G blocked" → `STATUS.local.md`
|
||||
- "Fix drone help formatting" as reminder → `STATUS.local.md` Notepad
|
||||
- "PR #266 needs merge, Track G blocked" → `local.json` todos[]
|
||||
- "Fix drone help formatting" as reminder → `local.json` todos[]
|
||||
- "Role shifted from builder to orchestrator" → `passport.json`
|
||||
|
||||
Save proactively. Triggers: after milestone, decision, learning, before switching topics.
|
||||
@@ -195,7 +192,7 @@ Use sub-agents for:
|
||||
Do it yourself only when:
|
||||
- User explicitly asks you to read or look at something
|
||||
- Tiny edits — fix a typo, update a memory file, small config change
|
||||
- Writing memories, STATUS, plan updates (your own files)
|
||||
- Writing memories, plan updates (your own files)
|
||||
- Quick one-line commands — drone status, inbox check
|
||||
|
||||
How to use them:
|
||||
@@ -247,7 +244,7 @@ Small knowledge traces trigger awareness. Not full knowledge — enough to know
|
||||
|
||||
Prompts: plant breadcrumbs, not encyclopedias. Two lines ("this exists, look here") beat twenty explaining how.
|
||||
|
||||
Prompts are signposts, not journals. Injected every turn — keep minimal. Never track state/sessions/context in prompts. State → `.trinity/` + `STATUS.local.md`. Prompts guide; memories record; registries catalog.
|
||||
Prompts are signposts, not journals. Injected every turn — keep minimal. Never track state/sessions/context in prompts. State → `.trinity/` + `DASHBOARD.local.json`. Prompts guide; memories record; registries catalog.
|
||||
|
||||
If `drone` can't find the AIPass registry, set `AIPASS_HOME=/path/to/AIPass` in shell profile and `~/.claude/settings.json` env block.
|
||||
|
||||
|
||||
@@ -22,6 +22,12 @@
|
||||
"enabled": true,
|
||||
"handler": "aipass.hooks.apps.handlers.prompt.global_loader.handle",
|
||||
"matcher": ""
|
||||
},
|
||||
"auto_process": {
|
||||
"enabled": true,
|
||||
"handler": "aipass.hooks.apps.handlers.lifecycle.auto_process.handle",
|
||||
"matcher": "",
|
||||
"timeout": 120
|
||||
}
|
||||
},
|
||||
|
||||
@@ -41,6 +47,11 @@
|
||||
"handler": "aipass.hooks.apps.handlers.security.git_gate.handle",
|
||||
"matcher": "Bash|Edit|MultiEdit|Write|NotebookEdit"
|
||||
},
|
||||
"rm_gate": {
|
||||
"enabled": true,
|
||||
"handler": "aipass.hooks.apps.handlers.security.rm_gate.handle",
|
||||
"matcher": "Bash"
|
||||
},
|
||||
"engine_test_sound": {
|
||||
"enabled": false,
|
||||
"command": "python3 $AIPASS_HOME/.claude/hooks/engine_test_sound.py",
|
||||
@@ -99,6 +110,12 @@
|
||||
"handler": "aipass.hooks.apps.handlers.lifecycle.rollover.handle",
|
||||
"matcher": "",
|
||||
"timeout": 120
|
||||
},
|
||||
"auto_process": {
|
||||
"enabled": true,
|
||||
"handler": "aipass.hooks.apps.handlers.lifecycle.auto_process.handle",
|
||||
"matcher": "",
|
||||
"timeout": 120
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -6,7 +6,7 @@ Agent workspace powered by AIPass.
|
||||
|
||||
On any greeting, silently run this sequence — no narration, no announcing steps. Just do it and respond with the status.
|
||||
|
||||
- Read: `.trinity/passport.json`, `.trinity/local.json`, `.trinity/observations.json`, `README.md`, `STATUS.local.md`
|
||||
- Read: `.trinity/passport.json`, `.trinity/local.json`, `.trinity/observations.json`, `README.md`
|
||||
|
||||
Use drone commands for all operations. Never raw git, gh, file access, or python -m when drone provides it.
|
||||
|
||||
|
||||
@@ -40,6 +40,11 @@
|
||||
"enabled": true,
|
||||
"handler": "aipass.hooks.apps.handlers.security.git_gate.handle",
|
||||
"matcher": "Bash|Edit|MultiEdit|Write|NotebookEdit"
|
||||
},
|
||||
"rm_gate": {
|
||||
"enabled": true,
|
||||
"handler": "aipass.hooks.apps.handlers.security.rm_gate.handle",
|
||||
"matcher": "Bash"
|
||||
}
|
||||
},
|
||||
|
||||
|
||||
@@ -14,9 +14,8 @@ Purpose: Button up everything at the end of a session — or before a /compact.
|
||||
Each memory file plays a distinct role. Update based on what actually changed this session.
|
||||
|
||||
- **`.trinity/passport.json`** — IDENTITY. Who you are: role, capabilities, principles. Only update if identity genuinely evolved this session.
|
||||
- **`.trinity/local.json`** — YOUR MEMORY. Add/update session entry with a summary of work done. Add key_learnings for anything learned. Trim oldest sessions if over 20.
|
||||
- **`.trinity/local.json`** — YOUR MEMORY. Add/update session entry with a summary of work done. Add key_learnings for anything learned. Update todos[] with current in-flight items. Trim oldest sessions if over 20.
|
||||
- **`.trinity/observations.json`** — YOUR MEMORY OF THE USER. Collaboration insights, preferences, friction points. Skip if nothing new about the user this session.
|
||||
- **`STATUS.local.md`** — PUBLIC STATUS BEACON. Current work, known issues, todos, notepad. Auto-synced to central STATUS.md on PR events — this is how other branches see you. Keep Current Work accurate.
|
||||
|
||||
## 2. Active Plans
|
||||
|
||||
@@ -38,7 +37,7 @@ Each memory file plays a distinct role. Update based on what actually changed th
|
||||
## 5. Loose Ends
|
||||
|
||||
- Flag anything in-flight: running background agents, dispatched branches waiting for replies, pending decisions
|
||||
- If anything can't survive compaction (e.g., agent IDs needed for resume), write it to STATUS.local.md Notepad
|
||||
- If anything can't survive compaction (e.g., agent IDs needed for resume), write it to local.json todos[]
|
||||
|
||||
## Confirm
|
||||
|
||||
@@ -47,7 +46,6 @@ List everything updated. Format:
|
||||
Prep complete:
|
||||
- local.json: [what was added]
|
||||
- observations.json: [updated / skipped]
|
||||
- STATUS.local.md: [updated / skipped]
|
||||
- Plans: [which ones updated]
|
||||
- Git: [branch, uncommitted count, suggestion]
|
||||
- Inbox: [count, action taken]
|
||||
|
||||
@@ -14,9 +14,8 @@ Purpose: Update branch memory files after completing work this session.
|
||||
Each memory file plays a distinct role. Update based on what actually changed this session.
|
||||
|
||||
- **`.trinity/passport.json`** — IDENTITY. Who you are: role, capabilities, principles. Only update if identity genuinely evolved this session. Don't touch it just to touch it.
|
||||
- **`.trinity/local.json`** — YOUR MEMORY. Session history and key_learnings. Add a session entry for significant work. Add key_learnings for facts you'd need next time. Trim oldest sessions if over 20.
|
||||
- **`.trinity/local.json`** — YOUR MEMORY. Session history, key_learnings, and todos[]. Add a session entry for significant work. Add key_learnings for facts you'd need next time. Update todos[] with open items. Trim oldest sessions if over 20.
|
||||
- **`.trinity/observations.json`** — YOUR MEMORY OF THE USER. Collaboration insights, preferences, friction points, flow states. Skip entirely if nothing new about the user this session.
|
||||
- **`STATUS.local.md`** — PUBLIC STATUS BEACON. Current work, known issues, todos, notepad. Auto-synced to central STATUS.md on PR events — this is how other branches see you. Keep Current Work accurate and drop quick notes in the Notepad section.
|
||||
|
||||
## If Relevant
|
||||
|
||||
|
||||
@@ -25,4 +25,3 @@ Purpose: Update branch memory files after completing work this session.
|
||||
|
||||
- **.trinity/passport.json** — Evolve identity when the branch's role, capabilities, or principles have genuinely changed. Don't update just to update — but don't leave placeholders forever either.
|
||||
- **README.md** — Does it reflect current state? Update if stale.
|
||||
- **STATUS.local.md** — Drop quick notes on issues, todos, or ideas in the Notepad section.
|
||||
|
||||
@@ -38,7 +38,7 @@ Purpose: Button up everything at the end of a session — or before a /compact.
|
||||
## 5. Loose Ends
|
||||
|
||||
- Flag anything in-flight: running background agents, dispatched branches waiting for replies, pending decisions
|
||||
- If anything can't survive compaction, write it to STATUS.local.md Notepad
|
||||
- If anything can't survive compaction, write it to local.json todos[]
|
||||
|
||||
## Confirm
|
||||
|
||||
|
||||
@@ -6,7 +6,7 @@ from pathlib import Path
|
||||
from aipass.seedgo.apps.handlers.audit.branch_audit import audit_branch
|
||||
from aipass.seedgo.apps.handlers.bypass.bypass_handler import load_bypass_rules
|
||||
|
||||
THRESHOLD = 80
|
||||
THRESHOLD = 100
|
||||
|
||||
src = Path("src/aipass")
|
||||
pack = src / "seedgo/apps/handlers/aipass_standards"
|
||||
@@ -30,12 +30,27 @@ for branch in branches:
|
||||
avg = result.get("average", 0)
|
||||
print(f" {branch['name']:>12}: {avg:.0f}%")
|
||||
if avg < THRESHOLD:
|
||||
failed.append((branch["name"], avg))
|
||||
failed.append((branch["name"], avg, result))
|
||||
|
||||
if failed:
|
||||
print(f"\nFAILED: {len(failed)} branch(es) below {THRESHOLD}%")
|
||||
for name, score in failed:
|
||||
for name, score, result in failed:
|
||||
print(f" {name}: {score:.0f}%")
|
||||
# Name the failing standards + the specific checks that did not pass,
|
||||
# so CI logs say WHY (not just the percentage). Critical for diagnosing
|
||||
# working-tree-vs-clean-checkout divergence.
|
||||
scores = result.get("scores", {})
|
||||
results = result.get("results", {})
|
||||
for std, sc in scores.items():
|
||||
if sc < 100:
|
||||
checks = results.get(std, {}).get("checks", [])
|
||||
msgs = [
|
||||
c.get("message", "")
|
||||
for c in checks
|
||||
if not c.get("passed", True)
|
||||
]
|
||||
detail = " | ".join(m for m in msgs if m)[:400]
|
||||
print(f" └ {std}: {sc:.0f}% {detail}")
|
||||
sys.exit(1)
|
||||
else:
|
||||
print(f"\nAll {len(branches)} branches pass (>={THRESHOLD}%)")
|
||||
|
||||
+30
-12
@@ -6,6 +6,9 @@ on:
|
||||
pull_request:
|
||||
branches: [main, dev]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
|
||||
|
||||
@@ -13,8 +16,8 @@ jobs:
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: pip install ruff
|
||||
@@ -28,26 +31,41 @@ jobs:
|
||||
python-version: ["3.10", "3.11", "3.12", "3.13"]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: ${{ matrix.python-version }}
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install -e ".[dev]"
|
||||
- run: coverage run -m pytest -v --tb=short --rootdir=.
|
||||
# tests/e2e build a wheel + clean venv per the dedicated e2e-wheel.yml
|
||||
# workflow — they are not part of the fast unit lane.
|
||||
- run: coverage run -m pytest -v --tb=short --rootdir=. --ignore=tests/e2e
|
||||
|
||||
standards:
|
||||
name: seedgo-audit
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
with:
|
||||
# Full history: the README-freshness check reads `git log` to find the
|
||||
# last commit touching each branch's .py. A shallow (depth-1) checkout
|
||||
# makes every file look born at HEAD, so every README false-fails as
|
||||
# "stale". Full history makes CI match a local audit exactly.
|
||||
fetch-depth: 0
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install -e ".[dev]"
|
||||
# Install the `memory` extra (numpy/chromadb/fastembed) alongside dev:
|
||||
# the diagnostics standard runs pyright over every branch, and memory's
|
||||
# handlers import chromadb/numpy. Without these deps installed, pyright
|
||||
# reports them as unresolved imports (reportMissingImports=error) and
|
||||
# memory scores <100 — a false failure from a missing CI dep, not a code
|
||||
# defect. Installing the declared extra lets pyright resolve them so the
|
||||
# audit measures real type-correctness (and matches a local audit).
|
||||
pip install -e ".[dev,memory]"
|
||||
- name: Run seedgo standards audit
|
||||
run: python .github/scripts/seedgo_audit.py
|
||||
|
||||
@@ -56,16 +74,16 @@ jobs:
|
||||
needs: [test]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install -e ".[dev]"
|
||||
- run: coverage run -m pytest --rootdir=.
|
||||
- run: coverage run -m pytest --rootdir=. --ignore=tests/e2e
|
||||
- run: coverage xml
|
||||
- uses: codecov/codecov-action@v6
|
||||
- uses: codecov/codecov-action@e79a6962e0d4c0c17b229090214935d2e33f8354 # v6.0.1
|
||||
with:
|
||||
files: ./coverage.xml
|
||||
fail_ci_if_error: false
|
||||
|
||||
@@ -0,0 +1,50 @@
|
||||
name: e2e-wheel
|
||||
|
||||
# Cross-OS end-to-end WIRING test (FPLAN-0239, P1 of DPLAN-0194).
|
||||
# Builds the wheel, installs it into a clean venv (handled by the pytest
|
||||
# fixtures in tests/e2e/conftest.py), and runs the 4-tier wiring ladder.
|
||||
#
|
||||
# RED-FIRST: Windows is EXPECTED to fail in known places (symlink init,
|
||||
# bin-vs-Scripts, /tmp). Do not "fix" Windows here — the red is the deliverable.
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main, dev]
|
||||
paths:
|
||||
- "tests/e2e/**"
|
||||
- ".github/workflows/e2e-wheel.yml"
|
||||
- "pyproject.toml"
|
||||
- "src/**"
|
||||
pull_request:
|
||||
paths:
|
||||
- "tests/e2e/**"
|
||||
- ".github/workflows/e2e-wheel.yml"
|
||||
- "pyproject.toml"
|
||||
- "src/**"
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
e2e-wheel:
|
||||
name: e2e-wheel (${{ matrix.os }})
|
||||
runs-on: ${{ matrix.os }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [ubuntu-latest, windows-latest, macos-latest]
|
||||
python-version: ["3.12"]
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
|
||||
- name: Set up Python ${{ matrix.python-version }}
|
||||
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: ${{ matrix.python-version }}
|
||||
|
||||
- name: Install build tooling
|
||||
run: python -m pip install --upgrade pip build pytest
|
||||
|
||||
- name: Run cross-OS e2e wiring harness
|
||||
# conftest.py builds the wheel + clean venv internally; the outer env
|
||||
# only needs build + pytest.
|
||||
run: python -m pytest tests/e2e -v
|
||||
@@ -2,27 +2,25 @@ name: macOS Test
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
# Run on every push/PR to main/dev — NOT path-filtered. This is a branch-
|
||||
# protection *required* check; a path filter makes it skip on unrelated PRs,
|
||||
# which GitHub then parks as "Expected — waiting for status" forever, blocking
|
||||
# the merge. Required checks must run on every PR to report a status.
|
||||
push:
|
||||
branches: [main, dev]
|
||||
paths:
|
||||
- 'setup.sh'
|
||||
- 'src/aipass/*/apps/handlers/__init__.py'
|
||||
- 'src/aipass/drone/cli.py'
|
||||
- 'pyproject.toml'
|
||||
pull_request:
|
||||
paths:
|
||||
- 'setup.sh'
|
||||
- 'src/aipass/*/apps/handlers/__init__.py'
|
||||
- 'src/aipass/drone/cli.py'
|
||||
- 'pyproject.toml'
|
||||
branches: [main, dev]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
macos-setup:
|
||||
runs-on: macos-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: '3.12'
|
||||
|
||||
@@ -44,7 +42,7 @@ jobs:
|
||||
|
||||
- name: Upload test results
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v7
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: macos-pytest-results
|
||||
path: pytest-output.txt
|
||||
|
||||
@@ -5,17 +5,20 @@ on:
|
||||
tags:
|
||||
- "v*"
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: pip install build
|
||||
- run: python -m build
|
||||
- uses: actions/upload-artifact@v7
|
||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: dist
|
||||
path: dist/
|
||||
@@ -27,11 +30,11 @@ jobs:
|
||||
permissions:
|
||||
id-token: write
|
||||
steps:
|
||||
- uses: actions/download-artifact@v4
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
||||
with:
|
||||
name: dist
|
||||
path: dist/
|
||||
- uses: pypa/gh-action-pypi-publish@release/v1
|
||||
- uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0
|
||||
|
||||
github-release:
|
||||
needs: publish
|
||||
@@ -39,8 +42,8 @@ jobs:
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/download-artifact@v4
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
||||
with:
|
||||
name: dist
|
||||
path: dist/
|
||||
|
||||
@@ -41,6 +41,6 @@ jobs:
|
||||
retention-days: 5
|
||||
|
||||
- name: "Upload to code-scanning"
|
||||
uses: github/codeql-action/upload-sarif@e46ed2cbd01164d986452f91f178727624ae40d7 # v4.35.3
|
||||
uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0
|
||||
with:
|
||||
sarif_file: results.sarif
|
||||
|
||||
@@ -8,6 +8,9 @@ on:
|
||||
schedule:
|
||||
- cron: "0 6 * * 1"
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
|
||||
|
||||
@@ -15,22 +18,31 @@ jobs:
|
||||
dependency-scan:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: pip install pip-audit
|
||||
# Upgrade pip first: pip-audit scans the whole environment, and the
|
||||
# runner's bundled pip (26.1.1) carries advisory PYSEC-2026-196 (fixed in
|
||||
# 26.1.2). Upgrading removes the vulnerable version outright rather than
|
||||
# suppressing it — and 26.1.2 also resolves CVE-2026-3219 / CVE-2026-6357,
|
||||
# which is why those two stale --ignore-vuln entries are no longer needed.
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install pip-audit
|
||||
- run: pip install -e .
|
||||
- name: Pip audit
|
||||
run: pip-audit --skip-editable --ignore-vuln CVE-2026-3219 --ignore-vuln CVE-2026-6357
|
||||
run: pip-audit --skip-editable
|
||||
|
||||
codeql:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: read
|
||||
actions: read
|
||||
security-events: write
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: github/codeql-action/init@v3
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- uses: github/codeql-action/init@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0
|
||||
with:
|
||||
languages: python
|
||||
- uses: github/codeql-action/analyze@v3
|
||||
- uses: github/codeql-action/analyze@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0
|
||||
|
||||
@@ -4,11 +4,17 @@ on:
|
||||
schedule:
|
||||
- cron: "0 0 * * 1"
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
stale:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
steps:
|
||||
- uses: actions/stale@v10
|
||||
- uses: actions/stale@eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899 # v10.3.0
|
||||
with:
|
||||
stale-issue-message: "This issue has been inactive for 30 days. It will be closed in 7 days if no further activity occurs."
|
||||
days-before-stale: 30
|
||||
|
||||
@@ -2,27 +2,25 @@ name: Windows Test
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
# Run on every push/PR to main/dev — NOT path-filtered. This is a branch-
|
||||
# protection *required* check; a path filter makes it skip on unrelated PRs,
|
||||
# which GitHub then parks as "Expected — waiting for status" forever, blocking
|
||||
# the merge. Required checks must run on every PR to report a status.
|
||||
push:
|
||||
branches: [main, dev]
|
||||
paths:
|
||||
- 'setup.sh'
|
||||
- 'src/aipass/*/apps/handlers/__init__.py'
|
||||
- 'src/aipass/drone/cli.py'
|
||||
- 'pyproject.toml'
|
||||
pull_request:
|
||||
paths:
|
||||
- 'setup.sh'
|
||||
- 'src/aipass/*/apps/handlers/__init__.py'
|
||||
- 'src/aipass/drone/cli.py'
|
||||
- 'pyproject.toml'
|
||||
branches: [main, dev]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
windows-setup:
|
||||
runs-on: windows-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: '3.12'
|
||||
|
||||
@@ -49,7 +47,7 @@ jobs:
|
||||
|
||||
- name: Upload test results
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v7
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: windows-pytest-results
|
||||
path: pytest-output.txt
|
||||
|
||||
+2
-2
@@ -110,7 +110,6 @@ src/aipass/*/apps/integrations/**
|
||||
!src/aipass/spawn/templates/builder/docs.local/
|
||||
!src/aipass/spawn/templates/builder/docs.local/**
|
||||
!src/aipass/spawn/templates/builder/DASHBOARD.local.json
|
||||
!src/aipass/spawn/templates/builder/STATUS.local.md
|
||||
|
||||
# CI artifacts
|
||||
windows-pytest-results/
|
||||
@@ -125,4 +124,5 @@ branch_audits/
|
||||
claude_4_7_transition_notes.md
|
||||
README_ORIGINAL_DISABLED.md
|
||||
*.bak
|
||||
test/
|
||||
test/
|
||||
sandbox_test/
|
||||
|
||||
@@ -8,7 +8,7 @@ User: user
|
||||
|
||||
On any greeting, silently read these files from CWD and run the commands — no narration, no announcing steps. Just do it and respond with the status.
|
||||
|
||||
- Read: `.trinity/passport.json`, `.trinity/local.json`, `.trinity/observations.json`, `README.md`, `STATUS.local.md`
|
||||
- Read: `.trinity/passport.json`, `.trinity/local.json`, `.trinity/observations.json`, `README.md`
|
||||
- Check: `drone @ai_mail inbox` — process any mail, don't ask.
|
||||
- Run: `drone @git status`
|
||||
|
||||
|
||||
+341
@@ -8,6 +8,347 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format
|
||||
|
||||
---
|
||||
|
||||
## [2026.W23] - 2026-06-02
|
||||
|
||||
### Fixed
|
||||
|
||||
- **`aipass init` scaffold correctness.** A fresh `aipass init` now generates a
|
||||
project-specific `AGENTS.md` (new `agents_md()` generator) instead of falling
|
||||
back to copying AIPass's own repo-root `AGENTS.md` boilerplate — Codex users
|
||||
were getting the wrong file. Project `README.md` quick-start/structure paths
|
||||
now reflect the real `src/<package>/<agent>/` layout.
|
||||
- **First-agent default name `my-agent` → `my_agent`.** `aipass init` seeded its
|
||||
default agent with a hyphen, the lone source of a long-standing dir-vs-module
|
||||
mismatch (the directory kept the hyphen while the importable module, `@address`
|
||||
and registry name all normalize to underscore). Defaulting to `my_agent` makes
|
||||
directory, module, `@address` and the README example all consistent.
|
||||
- **Dead `citizenship.registry_path` removed from spawn templates.** The field
|
||||
pointed at a non-existent `.aipass/registry.json`; it was never read anywhere
|
||||
(registry is located by `find_registry()` glob), so it's dropped from the
|
||||
`builder` and `birthright` passport templates.
|
||||
|
||||
### Removed
|
||||
|
||||
- **The entire STATUS flow is decommissioned (TDPLAN-0007).** The per-branch
|
||||
hand-maintained `STATUS.local.md` beacon and the auto-aggregated central
|
||||
`STATUS.md` (853 lines / 70 KB nobody read) are gone — deleted from disk
|
||||
across all 13 branches and scrubbed from every prompt, doc, startup protocol,
|
||||
`/prep` + `/memo` skill, the compact-recovery hook, the email footer, and
|
||||
`aipass init` / spawn scaffolding. Live branch state was already fully covered
|
||||
by `DASHBOARD.local.json` (prax) and history by `.trinity/local.json`. The
|
||||
status-sync engine is kept **intact but inert** — made dormant by unwiring its
|
||||
3-line trigger registration (`trigger registry.py`), so the code stays
|
||||
revivable. The one thing STATUS uniquely gave us — a quick scratch todo — is
|
||||
replaced by an operational `todos[]` section in `.trinity/local.json`
|
||||
(@memory-owned schema, capped, never vectorized by rollover), pushed to all 13
|
||||
branches and surfaced as a `todo_count` on the dashboard. Shipped as one
|
||||
coordinated cross-branch change (memory, prax, trigger, aipass, spawn, hooks,
|
||||
ai_mail, seedgo + devpulse).
|
||||
|
||||
### Changed
|
||||
|
||||
- **All 13 branches at seedgo 100% under the new introspection standard.**
|
||||
Wrapped `print_introspection()` output in Rich markup across ai_mail, drone,
|
||||
spawn, trigger, prax and devpulse (the rest were already compliant) —
|
||||
presentation only, no logic change — so `drone @branch` with no args renders
|
||||
consistent styled output everywhere.
|
||||
- **CLI polish for human-facing output.** `drone @hooks --help` rewritten (Rich,
|
||||
with `hooksound on/off/status` now surfaced); `drone @spawn` repair help
|
||||
clarified as distinct from `update` and showing the preview/`--apply` flow;
|
||||
drone restores Rich colour on human-facing routed output (`--help`,
|
||||
introspection, `status`) via the inherit path.
|
||||
- **Spawn backups land in one namespace `.spawn/.recovery/` (TDPLAN-0006 P4).**
|
||||
Spawn's pre-merge JSON backups previously dropped a `.recovery/` directory at
|
||||
each branch root (which had accumulated 242 stale auto-generated `DASHBOARD`
|
||||
backups across 10 branches). `aipass.common.json_ops.backup_json` gained an
|
||||
optional `backup_dir` parameter (default unchanged), and spawn's update engine
|
||||
now directs backups to `{branch}/.spawn/.recovery/` — tucked under the
|
||||
spawn-managed `.spawn/` dir instead of cluttering the branch root. Memory stays
|
||||
in the safety net (the engine simply never touches `.trinity/`/`DASHBOARD` on
|
||||
update, so it never needs to back them up). Stale `.recovery/` backups cleaned
|
||||
up. (315 tests, seedgo 100%.)
|
||||
- **No more cross-branch engine imports — `aipass init update` calls spawn via
|
||||
subprocess (TDPLAN-0006 P3).** `init_flow.py` previously did
|
||||
`from aipass.spawn.apps.modules.sync_registry import sync_registry` — the one
|
||||
place aipass reached directly into spawn's Python. Replaced with a subprocess
|
||||
call to the already-existing `drone @spawn sync-registry --fix` (same pattern as
|
||||
`aipass init agent` → `drone @spawn create`), preserving graceful degradation
|
||||
(a missing `drone`, non-zero exit, or timeout is silently skipped — registry
|
||||
sync never hard-fails an update). The aipass branch now has **zero** direct
|
||||
imports of another branch's engine code; the remaining cross-branch imports are
|
||||
shared service layers only (cli Rich UI, prax logging, trigger events). (438
|
||||
tests, seedgo 100%.)
|
||||
- **`aipass.common` shared library — dedup spawn/aipass scaffold machinery
|
||||
(TDPLAN-0006 P2).** `@spawn` and `@aipass` each carried their own copy of the
|
||||
JSON merge/handler utilities and registry discovery. Extracted them into a new
|
||||
branch-free package `src/aipass/common/` (`json_ops` = `deep_merge` +
|
||||
`backup_json`; `json_handler.JsonHandler`; `registry_discovery.find_registry`)
|
||||
that both branches now import. `aipass.common` imports **zero** branch code, so
|
||||
`aipass/bootstrap.py` (which runs before the drone runtime exists) can depend on
|
||||
it without breaking the pre-infrastructure constraint. The duplicated copies are
|
||||
deleted (spawn keeps a thin re-export shim; aipass's `json_handler` shrank
|
||||
254 → 88 lines). The `save_json` contract is unified to **raise `ValueError`**
|
||||
on invalid structure across both branches. (313 spawn + 434 aipass tests, both
|
||||
seedgo 100%.)
|
||||
|
||||
### Fixed
|
||||
|
||||
- **Flow plan-type self-serve UX — register override, help, orphan cleanup.**
|
||||
Explicit `drone @flow register <dir> <PREFIX>` now overrides an auto-derived
|
||||
prefix instead of silently failing (guarded — refuses if the auto-registered
|
||||
type already holds plans), so custom prefixes are settable when adding a new
|
||||
plan type. `create`/`templates --help` rewritten to dynamically list registered
|
||||
types + templates and document the add-a-new-type workflow. Stale orphan plan
|
||||
registries removed; dead `prefix_exists()` dropped. (728 tests, seedgo 100%.)
|
||||
- **`drone @spawn update` no longer scrambles branches (#636, critical — TDPLAN-0006
|
||||
P0+P1).** The update engine compared a freshly-created branch against the class
|
||||
template by *content hash* with rename-detection, and because the CREATE path
|
||||
regenerated template-registry IDs in filesystem-walk order (≠ the master's
|
||||
hand-crafted IDs), a branch created seconds earlier produced **30 proposed renames**
|
||||
that rotated identity/memory dirs into each other
|
||||
(`apps→.trinity→.seedgo→.claude→.archive→.aipass`), turned `README` into
|
||||
`DASHBOARD`, and deep-merged stale template into live `.trinity/` memory —
|
||||
`update <class> --all` would have destroyed every citizen in one command. Rebuilt
|
||||
`update_ops.py` (v2.0) on an explicit **named-managed-files + path-based** model:
|
||||
`.trinity/*`, `DASHBOARD.local.json`, `artifacts/birth_certificate.json` and
|
||||
`.seedgo/bypass.json` are delivered on **create only** and never touched on update;
|
||||
the create==update invariant now yields **0 renames / 0 merges** on a fresh branch.
|
||||
The old ID-based engine (`change_detection.py`, `reconcile.py`) is deleted.
|
||||
- **Destructive spawn ops are now dry-run by default (TDPLAN-0006 P0).** `drone @spawn
|
||||
update` and `drone @spawn repair` preview by default and require an explicit
|
||||
`--apply` to write — forgetting a flag is now a safe no-op instead of irreversible
|
||||
damage (`--dry-run` kept as an alias). `aipass doctor` repair suggestions emit the
|
||||
matching `--apply` form.
|
||||
|
||||
### Added
|
||||
|
||||
- **Introspection Rich-formatting standard (seedgo).** New
|
||||
`check_introspection_rich_formatting` checker enforces that each branch's
|
||||
`print_introspection()` output uses Rich markup (delegation-aware — it walks
|
||||
`_`-prefixed helper functions), keeping no-arg `drone @branch` output styled and
|
||||
consistent. Documented in `introspection.md`; all 13 branches brought into
|
||||
compliance (see Changed).
|
||||
- **Playbook plan type (`PBPLAN`) — reusable SOP checklists (flow).** A new
|
||||
`playbook_plans` template family for throwaway, vectorize-on-close operational
|
||||
runbooks (first SOP: the Sunday merge). Drop a `.md` under
|
||||
`templates/playbook_plans/`, register once, then
|
||||
`drone @flow create . "subject" <sop>` stamps a run to tick through and close.
|
||||
- **Memory-pool auto-processing (TDPLAN-0005)** — dropped files in
|
||||
`memory/memory_pool/` are now vectorized and archived automatically on
|
||||
session-start and pre-compact, instead of requiring a manual
|
||||
`drone @memory pool process`. A 3-branch build: `@memory` gains an intake
|
||||
handler + `pool` module (processes then empties the pool, `keep_recent=0`),
|
||||
`@hooks` adds a `lifecycle/auto_process` handler (session-guarded via
|
||||
`CLAUDE_CODE_SESSION_ID`, since Claude Code has no SessionStart hook), and
|
||||
`@trigger` gains event #15 (`memory_pool_auto_processed`) with a Medic error
|
||||
path. Runtime pool dirs (`memory_pool/`, `memory_pool_archive/`) are now
|
||||
gitignored.
|
||||
- **HVTracker badge** added to the README badge cluster, linking to the public
|
||||
agent profile at hvtracker.net (closes #628).
|
||||
- **`git_gate` read-verb allowlist — raw read-only git for every branch.** The
|
||||
PreToolUse `git_gate` previously blocked *all* raw git (forcing `drone @git`
|
||||
even for harmless reads), which left agents unable to inspect what git ships —
|
||||
the exact forensics needed to diagnose the audit gap above. It now allows 22
|
||||
read-only verbs raw (`ls-files`, `ls-tree`, `show`, `cat-file`, `rev-parse`,
|
||||
`rev-list`, `log`, `status`, `diff`, `blame`, `archive`, `grep`, …) while
|
||||
write operations stay `drone`-gated. Global options (`-C`, `-c`, `--git-dir`,
|
||||
…) are skipped when extracting the verb, and chained commands are split on
|
||||
`&&`/`||`/`;`/`|` so a read piped into a write still blocks the whole line.
|
||||
(81 tests)
|
||||
- **Cross-OS end-to-end WIRING test (`tests/e2e/`, `e2e-wheel.yml`)** — the first
|
||||
CI gate that proves real AIPass *wiring* (not units-with-mocks) by building the
|
||||
wheel, installing it into a clean venv, and asserting a 4-tier ladder: package
|
||||
install + console scripts (T0), `aipass init` scaffolding (T1), a hook actually
|
||||
firing via the bridge with an observable `engine.jsonl` record (T2a), and
|
||||
`drone` resolving + subprocess-executing a real branch (T3). Runs on a 3-OS
|
||||
matrix (ubuntu/windows/macos, `fail-fast: false`). Ran red-first on Windows by
|
||||
design and immediately earned its keep — it caught two real, *previously
|
||||
uncovered* Windows wiring bugs (`aipass init` preflight + `drone` stdout
|
||||
encoding, both fixed below). Notably the layers we most feared — clean-wheel
|
||||
install (T0) and hook firing (T2a) — passed on Windows. (DPLAN-0194 /
|
||||
FPLAN-0239)
|
||||
- **`drone rm` — provider-agnostic safe delete** — a contained recursive delete
|
||||
that lets agents clean up scratch dirs without tripping the `rm -rf` block.
|
||||
Deletes are confined to the project root and the system temp dirs (`/tmp` and
|
||||
`$TMPDIR`), refusing anything outside (home, `/etc`, `/`, etc.). Even inside
|
||||
those roots it hard-refuses protected internals — `.git`, `.trinity/`,
|
||||
`.aipass/`, `.codex/`, `.agents/`, and sibling-branch worktrees — mirroring the
|
||||
filesystem boundary an OS-sandboxed agent (e.g. Codex) enforces, so behavior is
|
||||
consistent across CLIs. Pure-Python (`shutil.rmtree`), with a red-team test
|
||||
suite for containment escapes (symlinks, traversal, sibling branches). (#630)
|
||||
- **`rm_gate` hook — block raw recursive `rm`, teach the safe path** — a
|
||||
PreToolUse gate (mirroring `git_gate`) that blocks raw `rm -r`/`-rf`/`-fr`/
|
||||
`--recursive` and redirects the agent to `drone rm`. Provider-agnostic (runs in
|
||||
the hook engine, not tied to Claude Code permission rules), conservative
|
||||
(unparseable targets are blocked, not allowed), and skips `drone rm` itself.
|
||||
This makes the safe-delete path discoverable at the moment of friction. (#630)
|
||||
- **Hook engine logs `agent_type` / `agent_id` per fire** — the engine now
|
||||
records which agent triggered each hook (e.g. `agent=main` vs `agent=Explore`)
|
||||
in both `engine.jsonl` and the prax monitor stream. Previously the payload
|
||||
flowed into handlers but was never logged, leaving no way to tell an internal
|
||||
main-turn fire from a real sub-agent fire. Pure visibility; no behavior change.
|
||||
Groundwork for #606. (#606)
|
||||
- **OpenSSF Best Practices passing badge** — AIPass earned the OpenSSF Best
|
||||
Practices (CII) **passing** badge (100% of criteria), added to the README badge
|
||||
cluster. Self-certified across all six categories — basics, change control,
|
||||
reporting, quality, security, and analysis. Complements the existing OpenSSF
|
||||
Scorecard, lifting the `CII-Best-Practices` check from 0. (DPLAN-0193)
|
||||
|
||||
### Changed
|
||||
|
||||
- **Standards floor raised to genuine 100% across all 13 branches** — completed
|
||||
the campaign that lifted the seedgo gate threshold from 80 to 100. Rather than
|
||||
bypass failing files, two check *flaws* were fixed at the root: (1) the
|
||||
**file-size / architecture check is now advisory** (warn-only for 700–1500 line
|
||||
files with no docstring nudge, hard-fail only above 1500) — large files are a
|
||||
smell, not a defect; (2) **readme-freshness now compares against git history,
|
||||
not file mtime** — `git checkout`/`merge` reset mtimes without any semantic
|
||||
change, so the old check false-positived (flow + prax shared an identical
|
||||
mtime from one git event, not real edits). It now diffs the README's "Last
|
||||
Updated" against the last commit that touched `.py`. Genuine content fixes
|
||||
where warranted (aipass requirements template + handler routing; honest README
|
||||
content refreshes on flow, prax, devpulse). The readme-freshness **failure
|
||||
message now teaches** the right fix ("update README content, then set the date
|
||||
— don't just bump it"). Also optimized the devpulse watchdog poll cadence
|
||||
(2s → 5s; the loop is cheap, so the tighter interval was wasted CPU). (#631)
|
||||
|
||||
- **Retired the blanket `rm` deny from provider settings** — `setup.sh` and
|
||||
`aipass init` no longer ship `Bash(rm -rf*)` / `Bash(rm -r *)` deny rules
|
||||
(they were mis-filed among git rules, blocked all `/tmp` cleanup, and gave a
|
||||
bare "permission denied" with no guidance). The `rm_gate` hook + `drone rm`
|
||||
now own this — cross-provider, path-aware, and they teach. `aipass doctor`
|
||||
detects the stale rules on existing installs and `aipass doctor --fix` removes
|
||||
them (idempotent, preserves all other rules). Claude Code still natively
|
||||
circuit-breaks `rm -rf /` and `rm -rf ~`. (#630)
|
||||
|
||||
### Fixed
|
||||
|
||||
- **`Windows Test` / `macOS Test` are no longer path-filtered — they were
|
||||
stalling PRs as required checks.** Both workflows only triggered when
|
||||
`setup.sh`/`drone/cli.py`/`handlers/__init__.py`/`pyproject.toml` changed, but
|
||||
branch protection lists `windows-setup`/`macos-setup` as *required*. On any PR
|
||||
that didn't touch those paths the workflows never ran, so GitHub parked the
|
||||
required checks as "Expected — waiting for status" indefinitely, blocking the
|
||||
merge (the tests themselves were green — they simply didn't fire). They now run
|
||||
on every push/PR to main/dev, like the other required lanes. (A required check
|
||||
must never be path-filtered.)
|
||||
- **`seedgo-audit` CI gate was red despite 100% local audits — four checkers
|
||||
validated the working tree instead of committed source.** CI audits a clean
|
||||
`git checkout` (tracked files only — git ships no empty or gitignored dirs),
|
||||
but the working tree carries runtime dirs (`logs/`, `*_json/`, `artifacts/`,
|
||||
`.trinity/`, `passport.json`), so every branch scored ~97% in CI while passing
|
||||
at 100% locally. Reproduced exactly with a tracked-only tree (`git archive HEAD`
|
||||
audits to CI's 97%). Four checkers now measure what git actually ships:
|
||||
`log_structure` no longer fails when the gitignored `logs/` dir is absent (it
|
||||
still enforces no-hardcoded-paths); `readme` cross-references `.gitignore`
|
||||
(via `git check-ignore` with a fallback list) and skips gitignored dirs/links
|
||||
in the directory-tree and dead-link checks; `encapsulation` infers the branch
|
||||
from the path when the gitignored `AIPASS_REGISTRY.json` is unavailable (and no
|
||||
longer collides on the `aipass` branch); `architecture` skips cleanly when the
|
||||
gitignored `passport.json` is absent. A follow-up refined `readme`'s
|
||||
`git check-ignore` use: `.gitignore` dir-only patterns (trailing slash —
|
||||
`logs/`, `**/*_json/`, `.trinity/`) don't match a clean checkout's
|
||||
non-existent paths unless directory intent is signalled, so the check now
|
||||
also tests the trailing-slash form (this was the last 1% — `readme` flagged
|
||||
`cli_json`/`logs`/`artifacts` as "missing on disk" in CI only). The CI gate
|
||||
(`.github/scripts/seedgo_audit.py`) now also prints the failing standards and
|
||||
their check messages, so a sub-100 result says *why*, not just the percentage.
|
||||
Finally, the `seedgo-audit` CI job now installs the `memory` extra
|
||||
(`pip install -e ".[dev,memory]"`): the `diagnostics` standard runs pyright over
|
||||
every branch, and memory's handlers import `chromadb`/`numpy` at module level —
|
||||
without those declared deps installed, pyright reported them as unresolved
|
||||
(`reportMissingImports=error`) and memory scored 55%, a false failure from a
|
||||
missing CI dep rather than a code defect. Clean-tree and working-tree audits
|
||||
both report 13/13 = 100%. (DPLAN-0195)
|
||||
- **Two latent Windows portability bugs caught by the new e2e harness** — both
|
||||
were always present in the code; they only surfaced now because this is the
|
||||
first CI to run `aipass init` scaffolding and real-branch `drone` routing on
|
||||
Windows (the old Windows CI ran an editable install, `aipass`-less, and only
|
||||
routed to in-process modules, so both paths had zero Windows coverage). Pure
|
||||
portability fixes — Linux/macOS behaviour is unchanged.
|
||||
- **`aipass init` crashed on Windows (surfaced as a misleading "Unknown
|
||||
command: init").** Init scaffolded the project correctly, then crashed
|
||||
*printing its `✓ Project initialized` banner* — Rich wrote the ✓/box glyphs
|
||||
through a cp1252 stdout, raising `UnicodeEncodeError ('charmap')`; the error
|
||||
handler's `✗` message hit the same wall, bubbling up to the command router
|
||||
which mislabeled it. The `aipass` entry point now reconfigures stdout/stderr
|
||||
to UTF-8 in place on Windows. (The init preflight ancestor-walk was also
|
||||
hardened to skip un-enumerable Windows drive-root entries — defensive, not
|
||||
the trigger.)
|
||||
- **`drone @branch` crashed on Windows with the same `UnicodeEncodeError
|
||||
('charmap')`.** `drone` resolved + subprocessed the branch correctly, then
|
||||
crashed *printing* the captured output through cp1252 stdout. The existing
|
||||
`PYTHONUTF8` guard only affected child interpreters, not the live process
|
||||
streams — `drone`'s entry point now also `reconfigure()`s stdout/stderr to
|
||||
UTF-8 in place.
|
||||
- **CI unit lane no longer runs the e2e wheel tests.** `ci.yml`'s
|
||||
`pytest --rootdir=.` swept in `tests/e2e/` (which build a wheel per the
|
||||
dedicated `e2e-wheel.yml`), failing the unit lane; it now `--ignore`s them.
|
||||
(DPLAN-0194)
|
||||
- **A release merge can no longer destroy the `dev` branch** — `drone @git merge`
|
||||
passed `--delete-branch` to `gh pr merge` unconditionally, so merging a
|
||||
`dev`→`main` PR deleted the persistent `dev` branch on the remote and stranded
|
||||
the working tree on `main` (the next commit silently landing on main). Merge now
|
||||
looks up the PR's head ref and **only deletes non-protected branches** — `dev`
|
||||
and `main` are never deleted, and an undeterminable head ref fails safe (no
|
||||
delete). After a merge it returns the working tree to `dev` (loud warning if it
|
||||
can't). `drone @git branches` now runs `fetch --prune` before listing so it
|
||||
reflects the live remote instead of stale cached refs, and a new
|
||||
`drone @git prune-temp` cleans up merged temp PR branches. (#625)
|
||||
- **`drone @git status`/`diff` show their scope** — when scoped to a branch (no
|
||||
`--all`), output now appends "(showing <branch> scope — use --all for full
|
||||
repo)", so an empty scoped view is no longer mistaken for a clean repo. (#623)
|
||||
- **External projects can call AIPass branches via drone** — `drone @api ...`
|
||||
(and any `drone @X`) now resolves from a non-AIPass project CWD instead of
|
||||
being blocked with "path escapes project root." The resolver was validating a
|
||||
branch's path against the *primary* registry root even when the branch was
|
||||
found via the `AIPASS_HOME` fallback, so any external project (Vera Studio,
|
||||
Daemon) hit a false security block. `resolve_branch()` now validates
|
||||
containment against the registry the branch was actually found in. Security is
|
||||
unchanged — each branch is still contained within its own declaring registry's
|
||||
root; genuine path escapes remain blocked. (#618)
|
||||
- **`aipass <command>` runs instead of printing an introspection banner** —
|
||||
`aipass` is a user-facing binary, so `aipass doctor` (and every other command)
|
||||
must execute, not describe itself. All 7 modules (`doctor`, `doctor_fix`,
|
||||
`doctor_wire`, `handoff`, `help_chat`, `init_flow`, `profile`) previously hit a
|
||||
no-args→introspection gate (a standard meant for `drone @branch <module>`
|
||||
discovery) and showed a banner on bare invocation. Now bare invocation runs the
|
||||
command or shows usage; the introspection banner moved to `--info`. The seedgo
|
||||
introspection standard is bypassed for these binary-invoked modules (documented).
|
||||
- **Dashboard plan counts no longer zeroed on refresh** — a branch's
|
||||
`active_plans` was reset to `0` by every `drone @prax dashboard refresh`, because
|
||||
`PLANS.central.json` only held Flow's own plans (`location==FLOW_ROOT` filter).
|
||||
The central file is now comprehensive: all plans grouped per-branch, so refresh
|
||||
reports each branch's real count (e.g. devpulse now shows its 12 open plans
|
||||
instead of 0).
|
||||
|
||||
### Security
|
||||
|
||||
- **`dependency-scan` (pip-audit) green again — upgrade pip, drop stale ignores.**
|
||||
The `Security Scan` workflow's `dependency-scan` job had gone red: pip-audit
|
||||
scans the whole environment, and the runner's bundled pip (26.1.1) carries
|
||||
advisory PYSEC-2026-196 (fixed in 26.1.2). The job now runs
|
||||
`python -m pip install --upgrade pip` before auditing (it was the only CI job
|
||||
not upgrading pip), removing the vulnerable version outright rather than
|
||||
suppressing it. 26.1.2 also resolves CVE-2026-3219 and CVE-2026-6357, so the
|
||||
two now-stale `--ignore-vuln` entries were removed — verified against a clean
|
||||
reproduction of the job's environment, which audits to "No known
|
||||
vulnerabilities found" with nothing ignored.
|
||||
- **Pinned the `requests` floor to a non-vulnerable version** — raised
|
||||
`requests` to `>=2.34.2` in `pyproject.toml` and the API branch's
|
||||
`requirements.project.txt` (which previously listed it unconstrained). This
|
||||
clears six OSV advisories the OpenSSF Scorecard flagged against the dependency
|
||||
(PYSEC-2014-13, PYSEC-2014-14, PYSEC-2018-28, GHSA-9wx4-h78v-vm56,
|
||||
GHSA-9hjg-9r4m-mvj7, GHSA-gc5v-m9x4-r6x2) — the oldest surfaced only because the
|
||||
dependency was declared without a version bound. No runtime change (the AIPass
|
||||
venv already ran a fixed release). (DPLAN-0193)
|
||||
- **Pinned the test container base image by digest** — `Dockerfile.test` now pins
|
||||
`ubuntu:24.04` to its registry digest (`sha256:786a8b55…`) so the test image is
|
||||
reproducible and tamper-evident, clearing the Scorecard `containerImage not
|
||||
pinned by hash` finding. (DPLAN-0193)
|
||||
|
||||
---
|
||||
|
||||
## [2026.W22] - 2026-05-30
|
||||
|
||||
### Added
|
||||
|
||||
@@ -10,10 +10,9 @@ On any greeting, silently run this sequence — no narration, no announcing step
|
||||
|
||||
These steps are sequential and dependent — run each ONCE, wait for the result, then proceed. Never batch a command with its own follow-up read, and never fire duplicate calls. If output looks blank, wait — don't retry.
|
||||
|
||||
- Read: `.trinity/passport.json`, `.trinity/local.json`, `.trinity/observations.json`, `README.md`, `STATUS.local.md`
|
||||
- Read: `.trinity/passport.json`, `.trinity/local.json`, `.trinity/observations.json`, `README.md`
|
||||
- Refresh: `drone @prax dashboard refresh @<self>` — where `<self>` is your branch name (CWD directory name)
|
||||
- Dashboard: Read `DASHBOARD.local.json` — act on what needs attention (new mail → check inbox, active plans → note them). This is your single status glance.
|
||||
- Refresh: If `STATUS.local.md` is stale (last updated date older than latest session in local.json), update it from your memories. Keep Current Work accurate.
|
||||
|
||||
Use drone commands for all operations. Never raw git, gh, file access, or python -m when drone provides it.
|
||||
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
FROM ubuntu:24.04
|
||||
FROM ubuntu:24.04@sha256:786a8b558f7be160c6c8c4a54f9a57274f3b4fb1491cf65146521ae77ff1dc54
|
||||
|
||||
ENV DEBIAN_FRONTEND=noninteractive
|
||||
|
||||
|
||||
@@ -2,19 +2,17 @@
|
||||
[](pyproject.toml)
|
||||
[](LICENSE)
|
||||
[](https://pypi.org/project/aipass/)
|
||||
[](#cli-support)
|
||||
[](https://github.com/AIOSAI/AIPass/issues/new?template=feedback.yml)
|
||||
[](https://codecov.io/gh/AIOSAI/AIPass)
|
||||
[](https://github.com/volotat/OSS-Health-Monitor)
|
||||
[](https://scorecard.dev/viewer/?uri=github.com/AIOSAI/AIPass)
|
||||
[](https://www.bestpractices.dev/projects/13095)
|
||||
[](https://hvtracker.net/agents/aipass)
|
||||
|
||||
<p align="center">
|
||||
<img src="assets/logo.png" alt="AIPass" width="400" />
|
||||
</p>
|
||||
<p align="center"><strong>Persistent Agent Workspace</strong></p>
|
||||
<p align="center"><em>AI agents that remember, collaborate, and never start from zero.</em></p>
|
||||
<p align="center">
|
||||
<a href="https://scorecard.dev/viewer/?uri=github.com/AIOSAI/AIPass"><img src="https://api.scorecard.dev/projects/github.com/AIOSAI/AIPass/badge" alt="OpenSSF Scorecard" /></a>
|
||||
</p>
|
||||
|
||||

|
||||
|
||||
@@ -266,7 +264,7 @@ AIPass stores everything locally in your project directory. To remove it:
|
||||
```bash
|
||||
# Remove AIPass files from your project
|
||||
rm -rf .aipass/ .claude/ .ai_mail.local/ hooks/ src/
|
||||
rm -f CLAUDE.md AGENTS.md STATUS.local.md *_REGISTRY.json .gitignore
|
||||
rm -f CLAUDE.md AGENTS.md *_REGISTRY.json .gitignore
|
||||
|
||||
# If you installed via pip
|
||||
pip uninstall aipass
|
||||
|
||||
+2
-2
@@ -4,7 +4,7 @@ build-backend = "hatchling.build"
|
||||
|
||||
[project]
|
||||
name = "aipass"
|
||||
version = "2.5.0"
|
||||
version = "2.5.1"
|
||||
description = "A local multi-agent framework where your AI agents keep their memory, work together, and never ask you to re-explain context"
|
||||
readme = "README.md"
|
||||
license = "MIT"
|
||||
@@ -28,7 +28,7 @@ classifiers = [
|
||||
dependencies = [
|
||||
"rich>=13.0",
|
||||
"watchdog>=3.0",
|
||||
"requests>=2.28",
|
||||
"requests>=2.34.2",
|
||||
"psutil>=5.9",
|
||||
"questionary>=2.0",
|
||||
]
|
||||
|
||||
@@ -540,15 +540,16 @@ else:
|
||||
settings = {}
|
||||
|
||||
# Build hooks config — bridge pattern
|
||||
# UserPromptSubmit: 4 separate entries (EventType:hook_name) to avoid output merging
|
||||
# UserPromptSubmit: 5 separate entries (EventType:hook_name) to avoid output merging
|
||||
# PreToolUse, PostToolUse, SubagentStop, Stop, Notification: single aggregate entries
|
||||
# PreCompact: 2 hooks x 2 matchers (manual + auto) = 4 entries
|
||||
# PreCompact: 3 hooks x 2 matchers (manual + auto) = 6 entries
|
||||
settings["hooks"] = {
|
||||
"UserPromptSubmit": [
|
||||
{"hooks": [{"type": "command", "command": f"{bridge} UserPromptSubmit:global_prompt"}]},
|
||||
{"hooks": [{"type": "command", "command": f"{bridge} UserPromptSubmit:branch_prompt"}]},
|
||||
{"hooks": [{"type": "command", "command": f"{bridge} UserPromptSubmit:identity_injector"}]},
|
||||
{"hooks": [{"type": "command", "command": f"{bridge} UserPromptSubmit:email_notification"}]},
|
||||
{"hooks": [{"type": "command", "command": f"{bridge} UserPromptSubmit:auto_process", "timeout": 120}]},
|
||||
],
|
||||
"PreToolUse": [
|
||||
{"matcher": "Bash|Edit|MultiEdit|Write|Read|Grep|Glob|WebSearch|WebFetch|Task",
|
||||
@@ -572,6 +573,8 @@ settings["hooks"] = {
|
||||
{"matcher": "auto", "hooks": [{"type": "command", "command": f"{bridge} PreCompact:pre_compact", "timeout": 60}]},
|
||||
{"matcher": "manual", "hooks": [{"type": "command", "command": f"{bridge} PreCompact:pre_compact_rollover", "timeout": 120}]},
|
||||
{"matcher": "auto", "hooks": [{"type": "command", "command": f"{bridge} PreCompact:pre_compact_rollover", "timeout": 120}]},
|
||||
{"matcher": "manual", "hooks": [{"type": "command", "command": f"{bridge} PreCompact:auto_process", "timeout": 120}]},
|
||||
{"matcher": "auto", "hooks": [{"type": "command", "command": f"{bridge} PreCompact:auto_process", "timeout": 120}]},
|
||||
],
|
||||
}
|
||||
|
||||
@@ -606,7 +609,6 @@ git_deny = [
|
||||
"Bash(git push -f *)",
|
||||
"Bash(git rebase*)",
|
||||
"Bash(git clean*)",
|
||||
"Bash(rm -rf*)",
|
||||
"Bash(git reset*)",
|
||||
"Bash(git merge*)",
|
||||
"Bash(git config*)",
|
||||
@@ -617,7 +619,6 @@ git_deny = [
|
||||
"Bash(git branch -D*)",
|
||||
"Bash(git stash drop*)",
|
||||
"Bash(git stash clear*)",
|
||||
"Bash(rm -r *)",
|
||||
"Bash(git checkout -b*)",
|
||||
"Bash(git switch -c*)",
|
||||
"Bash(git switch --create*)",
|
||||
|
||||
@@ -4,4 +4,4 @@ pip install aipass
|
||||
https://github.com/AIOSAI/AIPass
|
||||
"""
|
||||
|
||||
__version__ = "2.5.0"
|
||||
__version__ = "2.5.1"
|
||||
|
||||
@@ -22,7 +22,6 @@ STANDARD_FOOTER = """
|
||||
⚠️ TASK CHECKLIST (before marking complete):
|
||||
□ SEEDGO CHECK → drone @seedgo audit @branch (80%+)
|
||||
□ UPDATE MEMORIES → Your .trinity/local.json records this work
|
||||
□ UPDATE STATUS → Your STATUS.local.md reflects current state
|
||||
□ CLOSE FPLAN → drone @flow close <plan_id>
|
||||
□ EMAIL SENDER → drone @ai_mail email @<sender> "Subject" "Summary"
|
||||
|
||||
|
||||
@@ -408,23 +408,26 @@ def _orchestrate_daemon() -> bool:
|
||||
def print_introspection():
|
||||
"""Display module introspection info."""
|
||||
console.print()
|
||||
console.print("dispatch Module")
|
||||
console.print("[bold cyan]dispatch Module[/bold cyan]")
|
||||
console.print(
|
||||
"Orchestrates dispatch commands: combined send+wake, status tracking, daemon management, and manual wake."
|
||||
"[dim]Orchestrates dispatch commands: combined send+wake,"
|
||||
" status tracking, daemon management, and manual wake.[/dim]"
|
||||
)
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/dispatch/")
|
||||
console.print(" - status.py (load_dispatch_log — load dispatch log entries)")
|
||||
console.print(" - status.py (check_pid_status — check if a spawned process is still running)")
|
||||
console.print(" - status.py (calculate_age — calculate age string from timestamp)")
|
||||
console.print(" - wake.py (wake_branch — manually wake a branch by spawning an agent)")
|
||||
console.print(" - daemon.py (run_daemon — start the continuous dispatch daemon)")
|
||||
console.print(" handlers/email/ (used by combined dispatch)")
|
||||
console.print(" - send.py (resolve_sender_info, send_to_single — send email pipeline)")
|
||||
console.print(" - create.py (create_email_file, load_email_file — email file creation)")
|
||||
console.print(" - delivery.py (deliver_email_to_branch — inbox delivery)")
|
||||
console.print(" - header.py (prepend_dispatch_header — dispatch header injection)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/dispatch/[/cyan]")
|
||||
console.print(" - [cyan]status.py[/cyan] [dim](load_dispatch_log — load dispatch log entries)[/dim]")
|
||||
console.print(
|
||||
" - [cyan]status.py[/cyan] [dim](check_pid_status — check if a spawned process is still running)[/dim]"
|
||||
)
|
||||
console.print(" - [cyan]status.py[/cyan] [dim](calculate_age — calculate age string from timestamp)[/dim]")
|
||||
console.print(" - [cyan]wake.py[/cyan] [dim](wake_branch — manually wake a branch by spawning an agent)[/dim]")
|
||||
console.print(" - [cyan]daemon.py[/cyan] [dim](run_daemon — start the continuous dispatch daemon)[/dim]")
|
||||
console.print(" [cyan]handlers/email/[/cyan] [dim](used by combined dispatch)[/dim]")
|
||||
console.print(" - [cyan]send.py[/cyan] [dim](resolve_sender_info, send_to_single — send email pipeline)[/dim]")
|
||||
console.print(" - [cyan]create.py[/cyan] [dim](create_email_file, load_email_file — email file creation)[/dim]")
|
||||
console.print(" - [cyan]delivery.py[/cyan] [dim](deliver_email_to_branch — inbox delivery)[/dim]")
|
||||
console.print(" - [cyan]header.py[/cyan] [dim](prepend_dispatch_header — dispatch header injection)[/dim]")
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -250,18 +250,18 @@ def _send_broadcast(subject, message, user_info, auto_execute, no_memory_save, r
|
||||
|
||||
def print_introspection():
|
||||
"""Print module introspection for seedgo compliance."""
|
||||
console.print("\n" + "=" * 70)
|
||||
console.print("EMAIL SEND ORCHESTRATION")
|
||||
console.print("=" * 70)
|
||||
console.print("\nFunctions provided:")
|
||||
console.print(" - handle_send(args) -> bool")
|
||||
console.print(" - _send_direct(...) -> bool")
|
||||
console.print(" - _send_interactive() -> bool")
|
||||
console.print(" - _send_broadcast(...) -> bool")
|
||||
console.print(" - _fire_dispatch_trigger(to_branch, subject) -> None")
|
||||
console.print(" - _delivery_callback(branch_path, new_count, opened_count, total)")
|
||||
console.print()
|
||||
console.print("=" * 70 + "\n")
|
||||
console.print("[bold cyan]email_send Module[/bold cyan]")
|
||||
console.print("[dim]Send orchestration — direct, interactive, and broadcast email delivery.[/dim]")
|
||||
console.print()
|
||||
console.print("[yellow]Functions provided:[/yellow]")
|
||||
console.print(" - [cyan]handle_send[/cyan][dim](args) -> bool[/dim]")
|
||||
console.print(" - [cyan]_send_direct[/cyan][dim](...) -> bool[/dim]")
|
||||
console.print(" - [cyan]_send_interactive[/cyan][dim]() -> bool[/dim]")
|
||||
console.print(" - [cyan]_send_broadcast[/cyan][dim](...) -> bool[/dim]")
|
||||
console.print(" - [cyan]_fire_dispatch_trigger[/cyan][dim](to_branch, subject) -> None[/dim]")
|
||||
console.print(" - [cyan]_delivery_callback[/cyan][dim](branch_path, new_count, opened_count, total)[/dim]")
|
||||
console.print()
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
|
||||
@@ -1708,7 +1708,7 @@ class TestEmailSendIntrospection:
|
||||
|
||||
print_introspection()
|
||||
combined = "\n".join(printed)
|
||||
assert "EMAIL SEND ORCHESTRATION" in combined
|
||||
assert "email_send Module" in combined
|
||||
assert "handle_send" in combined
|
||||
assert "_send_direct" in combined
|
||||
assert "_send_broadcast" in combined
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# AIPASS — Branch Prompt
|
||||
|
||||
*Injected every turn. Breadcrumbs only — details: README, --help, .trinity/ memories, STATUS.local.md.*
|
||||
*Injected every turn. Breadcrumbs only — details: README, --help, .trinity/ memories.*
|
||||
|
||||
## Identity
|
||||
|
||||
|
||||
@@ -2,8 +2,8 @@
|
||||
"metadata": {
|
||||
"version": "2.0.0",
|
||||
"created": "2026-04-16",
|
||||
"description": "Bypass config for @aipass citizen. While under construction (DPLAN-0136 Phase 0-3), module and handler files exist as documented placeholders with no implementation body. Each placeholder raises NotImplementedError and declares its phase. Bypass standards that fire on structural requirements the placeholders intentionally skip — json_handler import, print_introspection, CLI service wiring. Remove these entries in Phase N as each module gets its real body.",
|
||||
"last_updated": "2026-04-16"
|
||||
"description": "Bypass config for @aipass citizen. Modules operational: concierge/init/doctor/handoff/profile built and tested. Bypasses cover: binary-invocation introspection pattern (bare aipass <cmd> runs, --info for introspection), thin entry-point router (aipass.py uses bare print, no CLI imports), pure-python bootstrap (bootstrap.py/scaffold_content.py run before AIPass services exist), test-isolation patterns (architecture/encapsulation for tests/ directory), and CLI flag name references (permission_flags in test assertions and handoff platform).",
|
||||
"last_updated": "2026-06-02"
|
||||
},
|
||||
"bypass": [
|
||||
{
|
||||
@@ -31,45 +31,20 @@
|
||||
"standard": "cli",
|
||||
"reason": "Session info must print immediately after tmux spawn — returning data to module layer would lose the timing context. User needs attach/kill instructions right when the session starts."
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/handoff.py",
|
||||
"standard": "introspection",
|
||||
"reason": "Phase 4 placeholder — print_introspection() added with handoff build."
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/handoff.py",
|
||||
"standard": "json_structure",
|
||||
"reason": "Phase 4 placeholder — json_handler import added with handoff build."
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/handoff.py",
|
||||
"standard": "cli",
|
||||
"reason": "Phase 4 placeholder — CLI service imports added with handoff build."
|
||||
},
|
||||
{
|
||||
"file": "apps/aipass.py",
|
||||
"standard": "architecture",
|
||||
"reason": "Phase 0 entry-point stub from spawn template. Full 3-layer wiring (modules/ discovery, handlers/ imports) added when first module comes online (Phase 1)."
|
||||
},
|
||||
{
|
||||
"file": "apps/aipass.py",
|
||||
"standard": "cli",
|
||||
"reason": "Phase 0 entry-point stub — CLI service imports (console, header) added when modules come online (Phase 1+)."
|
||||
"reason": "Thin command router — discovers and routes to modules, which own the CLI service layer. Adding console/header imports here couples the bootstrap entry point to Rich for 4 status lines."
|
||||
},
|
||||
{
|
||||
"file": "apps/aipass.py",
|
||||
"standard": "debug_print",
|
||||
"reason": "Phase 0 entry-point stub uses bare print() for scaffold visibility. Replaced with console.print() when CLI services are wired in Phase 1+."
|
||||
"reason": "Thin command router uses bare print() for version output and help banner (4 calls). These run before module discovery — importing Rich console for bootstrap output adds startup overhead for minimal benefit."
|
||||
},
|
||||
{
|
||||
"file": "apps/aipass.py",
|
||||
"standard": "introspection",
|
||||
"reason": "Phase 0 — spawn template does not emit print_introspection(). Added when modules come online (Phase 1+)."
|
||||
},
|
||||
{
|
||||
"file": "apps/aipass.py",
|
||||
"standard": "log_structure",
|
||||
"reason": "Phase 0 — logs/ directory exists (spawn-created), but prax logger import not wired yet. Added when first module uses it."
|
||||
"reason": "Thin command router, not a module — it has no domain to introspect. Modules handle their own introspection via --info. No print_introspection() needed."
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/doctor.py",
|
||||
@@ -260,6 +235,46 @@
|
||||
"file": "apps/handlers/init/scaffold_content.py",
|
||||
"standard": "json_structure",
|
||||
"reason": "scaffold_content.py is Pure Python only (no module/prax/cli imports) by design — pure string-returning template generators extracted from bootstrap.py. Same constraint as bootstrap.py."
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/doctor.py",
|
||||
"standard": "introspection",
|
||||
"reason": "aipass is binary-invoked: aipass doctor runs the command; introspection via --info"
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/doctor_fix.py",
|
||||
"standard": "introspection",
|
||||
"reason": "aipass is binary-invoked: bare invocation shows usage; introspection via --info"
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/doctor_wire.py",
|
||||
"standard": "introspection",
|
||||
"reason": "aipass is binary-invoked: bare invocation shows usage; introspection via --info"
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/handoff.py",
|
||||
"standard": "introspection",
|
||||
"reason": "aipass is binary-invoked: aipass handoff shows usage; introspection via --info"
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/help_chat.py",
|
||||
"standard": "introspection",
|
||||
"reason": "aipass is binary-invoked: aipass help shows usage; introspection via --info"
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/init_flow.py",
|
||||
"standard": "introspection",
|
||||
"reason": "aipass is binary-invoked: aipass init shows usage; introspection via --info"
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/profile.py",
|
||||
"standard": "introspection",
|
||||
"reason": "aipass is binary-invoked: aipass profile runs the command; introspection via --info"
|
||||
},
|
||||
{
|
||||
"file": "apps/handlers/json/json_handler.py",
|
||||
"standard": "test_quality",
|
||||
"reason": "save_json now raises ValueError on invalid structure (aipass.common contract, TDPLAN-0006 P2). Tested via pytest.raises — no False return path to test."
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -17,9 +17,9 @@ aipass/
|
||||
│ ├── modules/
|
||||
│ │ ├── doctor.py # System health aggregation
|
||||
│ │ ├── doctor_fix.py # Remediation report (--fix, --json)
|
||||
│ │ ├── doctor_wire.py # Auto-wire prompt helpers
|
||||
│ │ ├── doctor_wire.py # Auto-wire provider settings + stale-deny re-export
|
||||
│ │ ├── handoff.py # CLI handoff (placeholder)
|
||||
│ │ ├── help_chat.py # README-backed Q&A
|
||||
│ │ ├── help_chat.py # README-backed Q&A (reads via readme_map handler)
|
||||
│ │ ├── init_flow.py # 12-stage guided setup
|
||||
│ │ └── profile.py # User profile read/write
|
||||
│ ├── handlers/
|
||||
@@ -27,12 +27,14 @@ aipass/
|
||||
│ │ ├── init/ # bootstrap.py, scaffold_content.py
|
||||
│ │ ├── json/ # JSON read/write utilities
|
||||
│ │ ├── ping_sweep/ # Branch reachability verification
|
||||
│ │ ├── provider_reconcile.py # Stale deny-rule detection + fix
|
||||
│ │ ├── readme_map/ # Live file reads + branch routing
|
||||
│ │ ├── structure_scan/ # Agent placement + pollution detection
|
||||
│ │ ├── system_detect/ # OS, shell, Python, RAM, CPU
|
||||
│ │ └── ui/ # Progress bars, menus, banners
|
||||
│ └── plugins/
|
||||
├── tests/ # 412 passing
|
||||
├── tests/ # 432 passing
|
||||
├── requirements.project.txt # Project-specific Python dependencies
|
||||
├── .trinity/ # Identity + session history + observations
|
||||
└── README.md
|
||||
```
|
||||
@@ -68,7 +70,7 @@ Humans only. Nothing in AIPass depends on this branch.
|
||||
|
||||
## Tests
|
||||
|
||||
412 passing — `pytest src/aipass/aipass/tests/`
|
||||
432 passing — `pytest src/aipass/aipass/tests/`
|
||||
|
||||
## Known Issues
|
||||
|
||||
@@ -76,4 +78,4 @@ Humans only. Nothing in AIPass depends on this branch.
|
||||
|
||||
## Last Updated
|
||||
|
||||
Last Updated: 2026-05-28
|
||||
Last Updated: 2026-06-05
|
||||
|
||||
@@ -15,11 +15,25 @@ Auto-discovery architecture:
|
||||
- No manual imports or routing needed
|
||||
"""
|
||||
|
||||
import os
|
||||
import sys
|
||||
import importlib
|
||||
from pathlib import Path
|
||||
from typing import List, Any
|
||||
|
||||
# Windows terminals/pipes default to cp1252, which can't encode the Unicode
|
||||
# Rich emits (✓/✗, box-drawing, arrows). PYTHONUTF8 only affects child
|
||||
# interpreters, not this process's already-open stdout/stderr — so we also
|
||||
# reconfigure the live streams to UTF-8 in place (Python 3.7+). Without this,
|
||||
# `aipass init` scaffolds correctly but crashes printing its success banner
|
||||
# with UnicodeEncodeError ('charmap') on Windows. Mirrors drone/cli.py.
|
||||
if sys.platform == "win32":
|
||||
os.environ.setdefault("PYTHONUTF8", "1") # for child subprocesses
|
||||
for _stream in (sys.stdout, sys.stderr):
|
||||
_reconfigure = getattr(_stream, "reconfigure", None)
|
||||
if _reconfigure is not None:
|
||||
_reconfigure(encoding="utf-8", errors="replace")
|
||||
|
||||
from aipass.prax import logger
|
||||
|
||||
# =============================================================================
|
||||
|
||||
@@ -15,11 +15,10 @@ Business logic for `aipass init`. Creates the project scaffold:
|
||||
3. CLAUDE.md — project prompt (Claude Code reads this)
|
||||
4. AGENTS.md — Codex equivalent of CLAUDE.md
|
||||
5. README.md — getting started guide
|
||||
6. STATUS.local.md — project status
|
||||
7. .gitignore — standard AIPass ignores
|
||||
8. .claude/settings.json — Claude Code hooks configuration
|
||||
9. src/ — directory where agents live
|
||||
10. .ai_mail.local/inbox.json — empty project mailbox
|
||||
6. .gitignore — standard AIPass ignores
|
||||
7. .claude/settings.json — Claude Code hooks configuration
|
||||
8. src/ — directory where agents live
|
||||
9. .ai_mail.local/inbox.json — empty project mailbox
|
||||
|
||||
Projects are NOT citizens — no .trinity/ directory. Identity lives in the
|
||||
registry JSON. Init is re-runnable: existing files are skipped, not errors.
|
||||
@@ -213,7 +212,6 @@ def _claude_settings(aipass_home: str | None = None) -> str:
|
||||
|
||||
data["permissions"] = {
|
||||
"deny": [
|
||||
"Bash(rm -rf *)",
|
||||
"Bash(git push --force*)",
|
||||
"Bash(git reset --hard*)",
|
||||
"EnterPlanMode",
|
||||
@@ -350,6 +348,9 @@ def init_project(target: Path, project_name: str | None = None) -> dict:
|
||||
content = template.read_text(encoding="utf-8").replace("{name}", name)
|
||||
dest.write_text(content, encoding="utf-8")
|
||||
created.append(str(dest))
|
||||
elif md_name == "AGENTS.md":
|
||||
dest.write_text(sc.agents_md(name), encoding="utf-8")
|
||||
created.append(str(dest))
|
||||
else:
|
||||
source = Path(aipass_home) / md_name if aipass_home else None
|
||||
if source and source.is_file():
|
||||
@@ -365,16 +366,7 @@ def init_project(target: Path, project_name: str | None = None) -> dict:
|
||||
readme_md_path.write_text(readme_content, encoding="utf-8")
|
||||
created.append(str(readme_md_path))
|
||||
|
||||
# 7. STATUS.local.md
|
||||
status_md_path = target / "STATUS.local.md"
|
||||
if not status_md_path.exists():
|
||||
status_md_path.write_text(
|
||||
f"# {name}\n\n**State:** New\n**Last update:** {today}\n\n## Current Work\n\n## Known Issues\n- None\n",
|
||||
encoding="utf-8",
|
||||
)
|
||||
created.append(str(status_md_path))
|
||||
|
||||
# 8. .gitignore
|
||||
# 7. .gitignore
|
||||
gitignore_path = target / ".gitignore"
|
||||
if not gitignore_path.exists():
|
||||
gitignore_path.write_text(sc.gitignore(), encoding="utf-8")
|
||||
@@ -451,7 +443,7 @@ def update_project(target: Path) -> dict:
|
||||
"""Update managed scaffold files in an existing AIPass project.
|
||||
|
||||
Overwrites managed prompt and config files with the latest templates while
|
||||
leaving all user-owned files (registry, README, STATUS.local.md, .gitignore,
|
||||
leaving all user-owned files (registry, README, .gitignore,
|
||||
src/) untouched.
|
||||
|
||||
Args:
|
||||
@@ -587,7 +579,6 @@ def update_project(target: Path) -> dict:
|
||||
for skip_name in (
|
||||
str(registry_path),
|
||||
str(target / "README.md"),
|
||||
str(target / "STATUS.local.md"),
|
||||
str(target / ".gitignore"),
|
||||
):
|
||||
skipped.append(skip_name)
|
||||
|
||||
@@ -37,11 +37,11 @@ def readme_md(name: str) -> str:
|
||||
"aipass init agent my_agent\n"
|
||||
"\n"
|
||||
"# 2. Start a session\n"
|
||||
"cd src/my_agent/\n"
|
||||
f"cd src/{name.lower()}/my_agent/\n"
|
||||
"claude # or your preferred AI CLI\n"
|
||||
"\n"
|
||||
"# 3. Check project status\n"
|
||||
"cat STATUS.local.md\n"
|
||||
"# 3. Check project health\n"
|
||||
"drone @seedgo audit .\n"
|
||||
"```\n"
|
||||
"\n"
|
||||
"## Project Structure\n"
|
||||
@@ -52,8 +52,7 @@ def readme_md(name: str) -> str:
|
||||
" .aipass/ # Prompts (injected per-turn)\n"
|
||||
" CLAUDE.md # Claude Code instructions\n"
|
||||
" AGENTS.md # Codex instructions\n"
|
||||
" STATUS.local.md # Project status\n"
|
||||
" src/ # Agent directories live here\n"
|
||||
f" src/{name.lower()}/ # Project package\n"
|
||||
" <agent_name>/ # Created via aipass init agent\n"
|
||||
"```\n"
|
||||
"\n"
|
||||
@@ -83,6 +82,30 @@ def readme_md(name: str) -> str:
|
||||
)
|
||||
|
||||
|
||||
def agents_md(name: str) -> str:
|
||||
"""Generate AGENTS.md content — Codex equivalent of CLAUDE.md for projects."""
|
||||
return (
|
||||
f"# {name}\n"
|
||||
"\n"
|
||||
"Agent workspace powered by AIPass.\n"
|
||||
"\n"
|
||||
"# Startup protocol\n"
|
||||
"\n"
|
||||
"On any greeting, silently run this sequence — no narration, no announcing "
|
||||
"steps. Just do it and respond with the status.\n"
|
||||
"\n"
|
||||
" - Read: `.trinity/passport.json`, `.trinity/local.json`, "
|
||||
"`.trinity/observations.json`, `README.md`\n"
|
||||
"\n"
|
||||
"Use drone commands for all operations. Never raw git, gh, or file access "
|
||||
"when drone provides it.\n"
|
||||
"\n"
|
||||
"# Memories\n"
|
||||
"\n"
|
||||
"Update `.trinity/` at natural breakpoints, after milestones, and on `/memo`.\n"
|
||||
)
|
||||
|
||||
|
||||
def global_prompt_md(name: str) -> str:
|
||||
"""Generate .aipass/aipass_global_prompt.md — injected every turn."""
|
||||
return (
|
||||
@@ -212,7 +235,6 @@ def gitignore() -> str:
|
||||
".trinity/\n"
|
||||
".ai_mail.local/\n"
|
||||
"*.local.*\n"
|
||||
"!STATUS.local.md\n"
|
||||
"\n"
|
||||
"# Plans (local working docs)\n"
|
||||
"DPLAN-*\n"
|
||||
@@ -279,9 +301,6 @@ def prep_md() -> str:
|
||||
"- **`.trinity/observations.json`** — YOUR MEMORY OF THE USER. "
|
||||
"Collaboration insights, preferences, friction points. Skip if nothing "
|
||||
"new about the user this session.\n"
|
||||
"- **`STATUS.local.md`** — PUBLIC STATUS BEACON. Current work, known "
|
||||
"issues, todos, notepad. Auto-synced to central STATUS.md on PR events "
|
||||
"— this is how other branches see you. Keep Current Work accurate.\n"
|
||||
"\n"
|
||||
"## 2. Active Plans\n"
|
||||
"\n"
|
||||
@@ -308,7 +327,7 @@ def prep_md() -> str:
|
||||
"- Flag anything in-flight: running background agents, dispatched "
|
||||
"branches waiting for replies, pending decisions\n"
|
||||
"- If anything can't survive compaction (e.g., agent IDs needed for "
|
||||
"resume), write it to STATUS.local.md Notepad\n"
|
||||
"resume), write it to local.json key_learnings\n"
|
||||
"\n"
|
||||
"## Confirm\n"
|
||||
"\n"
|
||||
@@ -317,7 +336,6 @@ def prep_md() -> str:
|
||||
"Prep complete:\n"
|
||||
"- local.json: [what was added]\n"
|
||||
"- observations.json: [updated / skipped]\n"
|
||||
"- STATUS.local.md: [updated / skipped]\n"
|
||||
"- Plans: [which ones updated]\n"
|
||||
"- Git: [branch, uncommitted count, suggestion]\n"
|
||||
"- Inbox: [count, action taken]\n"
|
||||
|
||||
@@ -1,254 +1,88 @@
|
||||
# =================== AIPass ====================
|
||||
# Name: json_handler.py
|
||||
# Description: Auto-Creating JSON Handler for aipass branch
|
||||
# Version: 1.0.0
|
||||
# Description: Branch-local shim — delegates to aipass.common.json_handler
|
||||
# Version: 2.0.0
|
||||
# Created: 2026-04-16
|
||||
# Modified: 2026-04-16
|
||||
# Modified: 2026-06-06
|
||||
# =============================================
|
||||
|
||||
"""
|
||||
JSON Handler - Auto-Creating & Self-Healing JSON System
|
||||
"""Branch-local JSON handler — thin shim over the shared ``aipass.common`` library.
|
||||
|
||||
Handles default JSON files (config, data, log) for aipass modules.
|
||||
Never manually create JSONs - they build themselves.
|
||||
All logic lives in ``aipass.common.json_handler.JsonHandler``.
|
||||
This module binds a ``JsonHandler`` instance to the aipass branch's
|
||||
``aipass_json/`` directory and re-exports the public API as module-level
|
||||
functions so existing callers (``json_handler.log_operation(...)``) keep working.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import inspect
|
||||
import json
|
||||
import os
|
||||
import tempfile
|
||||
from datetime import datetime
|
||||
from pathlib import Path
|
||||
from typing import Any, Dict, Optional
|
||||
|
||||
from aipass.prax import logger
|
||||
from aipass.common.json_handler import JsonHandler
|
||||
|
||||
|
||||
def _get_caller_module_name() -> str:
|
||||
"""Auto-detect calling module name from call stack."""
|
||||
stack = inspect.stack()
|
||||
if len(stack) > 2:
|
||||
caller_path = Path(stack[2].filename)
|
||||
module_name = caller_path.stem
|
||||
if module_name and not module_name.startswith("_"):
|
||||
return module_name
|
||||
return "unknown"
|
||||
|
||||
# =============================================================================
|
||||
# INFRASTRUCTURE SETUP
|
||||
# =============================================================================
|
||||
|
||||
# json_handler.py lives at: src/aipass/aipass/apps/handlers/json/json_handler.py
|
||||
# parents[0] = json/, [1] = handlers/, [2] = apps/, [3] = aipass/, [4] = src/aipass/
|
||||
_PKG_ROOT = Path(__file__).resolve().parents[4]
|
||||
|
||||
# Constants
|
||||
AIPASS_BRANCH_ROOT = _PKG_ROOT / "aipass"
|
||||
AIPASS_JSON_DIR = AIPASS_BRANCH_ROOT / "aipass_json"
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# INTERNAL HELPERS
|
||||
# =============================================================================
|
||||
def _handler() -> JsonHandler:
|
||||
"""Create a handler bound to the current AIPASS_JSON_DIR."""
|
||||
return JsonHandler(AIPASS_JSON_DIR)
|
||||
|
||||
|
||||
def _get_caller_module_name() -> str:
|
||||
"""Auto-detect calling module name from call stack.
|
||||
|
||||
Returns:
|
||||
Module name (e.g., "doctor" from doctor.py)
|
||||
"""
|
||||
try:
|
||||
stack = inspect.stack()
|
||||
# Skip frames: [0]=this function, [1]=log_operation, [2]=actual caller
|
||||
if len(stack) > 2:
|
||||
caller_frame = stack[2]
|
||||
caller_path = Path(caller_frame.filename)
|
||||
module_name = caller_path.stem
|
||||
|
||||
if module_name and not module_name.startswith("_"):
|
||||
return module_name
|
||||
|
||||
return "unknown"
|
||||
except Exception as exc:
|
||||
logger.warning("[json_handler] Failed to detect caller module name: %s", exc)
|
||||
return "unknown"
|
||||
def load_path(file_path: Path) -> Optional[dict]:
|
||||
"""Load JSON from an arbitrary file path."""
|
||||
return JsonHandler.read_json(file_path)
|
||||
|
||||
|
||||
def _default_template(json_type: str, module_name: str) -> Any:
|
||||
"""Return inline default structure for a JSON type — no file templates needed."""
|
||||
today = datetime.now().date().isoformat()
|
||||
if json_type == "config":
|
||||
return {
|
||||
"module_name": module_name,
|
||||
"version": "1.0.0",
|
||||
"config": {
|
||||
"max_log_entries": 100,
|
||||
},
|
||||
"created": today,
|
||||
}
|
||||
if json_type == "data":
|
||||
return {
|
||||
"created": today,
|
||||
"last_updated": today,
|
||||
}
|
||||
if json_type == "log":
|
||||
return []
|
||||
return None
|
||||
|
||||
|
||||
def _atomic_write_json(target_path: Path, data: Any) -> None:
|
||||
"""Write JSON data atomically via temp file + rename.
|
||||
|
||||
Prevents corruption from concurrent processes writing the same file.
|
||||
"""
|
||||
fd, tmp_path = tempfile.mkstemp(dir=str(target_path.parent), suffix=".tmp", prefix=target_path.stem)
|
||||
succeeded = False
|
||||
try:
|
||||
with os.fdopen(fd, "w", encoding="utf-8") as f:
|
||||
json.dump(data, f, indent=2, ensure_ascii=False)
|
||||
os.replace(tmp_path, str(target_path))
|
||||
succeeded = True
|
||||
finally:
|
||||
if not succeeded and Path(tmp_path).exists():
|
||||
logger.warning("[json_handler] Cleaning up temp file after write failure: %s", tmp_path)
|
||||
os.unlink(tmp_path)
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# VALIDATION
|
||||
# =============================================================================
|
||||
def save_path(file_path: Path, data: Any, indent: int = 2) -> bool:
|
||||
"""Write JSON data to an arbitrary file path atomically."""
|
||||
return JsonHandler.write_json(file_path, data, indent)
|
||||
|
||||
|
||||
def validate_json_structure(data: Any, json_type: str) -> bool:
|
||||
"""Validate JSON structure matches expected type."""
|
||||
if json_type == "config":
|
||||
if not isinstance(data, dict):
|
||||
return False
|
||||
required = ["module_name", "version", "config"]
|
||||
return all(key in data for key in required)
|
||||
|
||||
elif json_type == "data":
|
||||
if not isinstance(data, dict):
|
||||
return False
|
||||
required = ["created", "last_updated"]
|
||||
return all(key in data for key in required)
|
||||
|
||||
elif json_type == "log":
|
||||
return isinstance(data, list)
|
||||
|
||||
return False
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# PUBLIC API
|
||||
# =============================================================================
|
||||
|
||||
|
||||
def load_path(path: Path) -> Any:
|
||||
"""Load JSON from an arbitrary file path with consistent error handling."""
|
||||
try:
|
||||
with open(path, "r", encoding="utf-8") as f:
|
||||
return json.load(f)
|
||||
except (json.JSONDecodeError, OSError) as exc:
|
||||
logger.warning("[json_handler] Failed to load %s: %s", path, exc)
|
||||
return None
|
||||
|
||||
|
||||
def save_path(path: Path, data: Any) -> bool:
|
||||
"""Write JSON data to an arbitrary file path atomically."""
|
||||
os.makedirs(path.parent, exist_ok=True)
|
||||
fd, tmp_path = tempfile.mkstemp(dir=str(path.parent), suffix=".tmp", prefix=path.stem)
|
||||
succeeded = False
|
||||
try:
|
||||
with os.fdopen(fd, "w", encoding="utf-8") as f:
|
||||
json.dump(data, f, indent=2, ensure_ascii=False)
|
||||
f.write("\n")
|
||||
os.replace(tmp_path, str(path))
|
||||
succeeded = True
|
||||
return True
|
||||
except OSError as exc:
|
||||
logger.warning("[json_handler] Failed to save %s: %s", path, exc)
|
||||
return False
|
||||
finally:
|
||||
if not succeeded and Path(tmp_path).exists():
|
||||
os.unlink(tmp_path)
|
||||
"""Validate that data matches the expected shape for json_type."""
|
||||
return JsonHandler.validate_json_structure(data, json_type)
|
||||
|
||||
|
||||
def get_json_path(module_name: str, json_type: str) -> Path:
|
||||
"""Get path for module JSON file."""
|
||||
filename = f"{module_name}_{json_type}.json"
|
||||
return AIPASS_JSON_DIR / filename
|
||||
"""Return the filesystem path for a module's JSON file."""
|
||||
return _handler().get_json_path(module_name, json_type)
|
||||
|
||||
|
||||
def ensure_json_exists(module_name: str, json_type: str) -> bool:
|
||||
"""Ensure JSON file exists, create from template if missing."""
|
||||
AIPASS_JSON_DIR.mkdir(parents=True, exist_ok=True)
|
||||
|
||||
json_path = get_json_path(module_name, json_type)
|
||||
|
||||
if json_path.exists():
|
||||
try:
|
||||
with open(json_path, "r", encoding="utf-8") as f:
|
||||
data = json.load(f)
|
||||
|
||||
if validate_json_structure(data, json_type):
|
||||
return True
|
||||
except Exception as exc:
|
||||
logger.warning(
|
||||
"[json_handler] Corrupted JSON file for '%s/%s', regenerating: %s",
|
||||
module_name,
|
||||
json_type,
|
||||
exc,
|
||||
)
|
||||
|
||||
template = _default_template(json_type, module_name)
|
||||
if template is None:
|
||||
return False
|
||||
|
||||
try:
|
||||
_atomic_write_json(json_path, template)
|
||||
return True
|
||||
except Exception as exc:
|
||||
logger.error(
|
||||
"[json_handler] Failed to write JSON template for '%s/%s': %s",
|
||||
module_name,
|
||||
json_type,
|
||||
exc,
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
def load_json(module_name: str, json_type: str) -> Optional[Any]:
|
||||
"""Load JSON file, auto-create if missing."""
|
||||
if not ensure_json_exists(module_name, json_type):
|
||||
return None
|
||||
|
||||
json_path = get_json_path(module_name, json_type)
|
||||
|
||||
try:
|
||||
with open(json_path, "r", encoding="utf-8") as f:
|
||||
return json.load(f)
|
||||
except Exception as exc:
|
||||
logger.error("[json_handler] Failed to load JSON for '%s/%s': %s", module_name, json_type, exc)
|
||||
return None
|
||||
|
||||
|
||||
def save_json(module_name: str, json_type: str, data: Any) -> bool:
|
||||
"""Save JSON file."""
|
||||
json_path = get_json_path(module_name, json_type)
|
||||
|
||||
if not validate_json_structure(data, json_type):
|
||||
return False
|
||||
|
||||
if json_type == "data" and isinstance(data, dict):
|
||||
data["last_updated"] = datetime.now().date().isoformat()
|
||||
|
||||
try:
|
||||
_atomic_write_json(json_path, data)
|
||||
return True
|
||||
except Exception as exc:
|
||||
logger.error("[json_handler] Failed to save JSON for '%s/%s': %s", module_name, json_type, exc)
|
||||
return False
|
||||
"""Ensure a single JSON file exists; create with defaults if missing."""
|
||||
return _handler().ensure_json_exists(module_name, json_type)
|
||||
|
||||
|
||||
def ensure_module_jsons(module_name: str) -> bool:
|
||||
"""Ensure all 3 JSON files exist for a module."""
|
||||
ensure_json_exists(module_name, "config")
|
||||
ensure_json_exists(module_name, "data")
|
||||
ensure_json_exists(module_name, "log")
|
||||
return True
|
||||
"""Ensure all three JSON files (config, data, log) exist for a module."""
|
||||
return _handler().ensure_module_jsons(module_name)
|
||||
|
||||
|
||||
def load_json(module_name: str, json_type: str) -> Optional[Any]:
|
||||
"""Load a module's JSON file, auto-creating it if missing."""
|
||||
return _handler().load_json(module_name, json_type)
|
||||
|
||||
|
||||
def save_json(module_name: str, json_type: str, data: Any) -> bool:
|
||||
"""Save JSON file. Raises ValueError on invalid structure."""
|
||||
return _handler().save_json(module_name, json_type, data)
|
||||
|
||||
|
||||
def log_operation(
|
||||
@@ -256,42 +90,7 @@ def log_operation(
|
||||
data: Dict[str, Any] | None = None,
|
||||
module_name: str | None = None,
|
||||
) -> bool:
|
||||
"""Add entry to module log with automatic rotation.
|
||||
|
||||
Auto-detects calling module if module_name not provided.
|
||||
Implements config-controlled log limits to prevent unbounded growth.
|
||||
When max_log_entries is reached, removes oldest entries (FIFO).
|
||||
|
||||
Args:
|
||||
operation: Operation name to log
|
||||
data: Optional data dict
|
||||
module_name: Optional module name (auto-detected if not provided)
|
||||
|
||||
Returns:
|
||||
True if successful, False otherwise
|
||||
"""
|
||||
"""Add entry to module operation log with automatic rotation."""
|
||||
if module_name is None:
|
||||
module_name = _get_caller_module_name()
|
||||
|
||||
ensure_module_jsons(module_name)
|
||||
|
||||
config = load_json(module_name, "config")
|
||||
max_entries = 100
|
||||
if config and "config" in config:
|
||||
max_entries = config["config"].get("max_log_entries", 100)
|
||||
|
||||
log = load_json(module_name, "log")
|
||||
if log is None:
|
||||
log = []
|
||||
|
||||
entry: Dict[str, Any] = {"timestamp": datetime.now().isoformat(), "operation": operation}
|
||||
|
||||
if data:
|
||||
entry["data"] = data
|
||||
|
||||
log.append(entry)
|
||||
|
||||
if len(log) > max_entries:
|
||||
log = log[-max_entries:]
|
||||
|
||||
return save_json(module_name, "log", log)
|
||||
return _handler().log_operation(operation, data, module_name)
|
||||
|
||||
@@ -0,0 +1,81 @@
|
||||
# =================== AIPass ====================
|
||||
# Name: provider_reconcile.py
|
||||
# Description: Detect and fix stale rules in provider settings
|
||||
# Version: 1.0.0
|
||||
# Created: 2026-06-05
|
||||
# Modified: 2026-06-05
|
||||
# =============================================
|
||||
|
||||
"""provider_reconcile — detect and fix stale rules in ~/.claude/settings.json."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from pathlib import Path
|
||||
|
||||
from aipass.prax import logger
|
||||
|
||||
from aipass.aipass.apps.handlers.json import json_handler
|
||||
|
||||
_MODULE_NAME = "provider_reconcile"
|
||||
|
||||
_STALE_RM_DENY_RULES = frozenset({"Bash(rm -rf*)", "Bash(rm -r *)"})
|
||||
|
||||
GLYPH_PASS = "[green]✓[/green]"
|
||||
GLYPH_WARN = "[yellow]![/yellow]"
|
||||
|
||||
|
||||
def reconcile_stale_deny(fix: bool = False) -> list:
|
||||
"""Detect and optionally remove stale rm deny rules from provider settings.
|
||||
|
||||
Returns list of (label, glyph, detail, remediation) tuples matching
|
||||
doctor.CheckResult shape — imported as tuples to avoid circular import.
|
||||
"""
|
||||
results: list = []
|
||||
settings_path = Path.home() / ".claude" / "settings.json"
|
||||
|
||||
if not settings_path.exists():
|
||||
json_handler.log_operation(
|
||||
"reconcile_stale_deny",
|
||||
data={"fix": fix, "skipped": "no settings file"},
|
||||
module_name=_MODULE_NAME,
|
||||
)
|
||||
return results
|
||||
|
||||
data = json_handler.load_path(settings_path)
|
||||
if data is None:
|
||||
json_handler.log_operation(
|
||||
"reconcile_stale_deny",
|
||||
data={"fix": fix, "skipped": "could not load settings"},
|
||||
module_name=_MODULE_NAME,
|
||||
)
|
||||
return results
|
||||
|
||||
deny = data.get("permissions", {}).get("deny", [])
|
||||
stale = [r for r in deny if r in _STALE_RM_DENY_RULES]
|
||||
|
||||
if not stale:
|
||||
results.append(("rm deny migration", GLYPH_PASS, "no stale rules", ""))
|
||||
elif fix:
|
||||
deny_cleaned = [r for r in deny if r not in _STALE_RM_DENY_RULES]
|
||||
data.setdefault("permissions", {})["deny"] = deny_cleaned
|
||||
json_handler.save_path(settings_path, data)
|
||||
removed = ", ".join(stale)
|
||||
results.append(("rm deny migration", GLYPH_PASS, f"removed: {removed}", ""))
|
||||
logger.info("[doctor] removed stale deny rules: %s", stale)
|
||||
else:
|
||||
found = ", ".join(stale)
|
||||
results.append(
|
||||
(
|
||||
"rm deny migration",
|
||||
GLYPH_WARN,
|
||||
f"stale rules: {found}",
|
||||
"Run aipass doctor --fix to remove (rm_gate + drone rm replace these)",
|
||||
)
|
||||
)
|
||||
|
||||
json_handler.log_operation(
|
||||
"reconcile_stale_deny",
|
||||
data={"fix": fix, "stale_found": len(stale)},
|
||||
module_name=_MODULE_NAME,
|
||||
)
|
||||
return results
|
||||
@@ -117,3 +117,18 @@ def list_branches() -> list[str]:
|
||||
Reflects the filesystem state at the time the map was first built.
|
||||
"""
|
||||
return list(_get_map().keys())
|
||||
|
||||
|
||||
def read_readme_lines(branch: str) -> list[str] | None:
|
||||
"""Live-read README.md for a branch. Returns list of lines, or None on error.
|
||||
|
||||
Content is NEVER cached — every call reads the current file.
|
||||
"""
|
||||
readme_path = get_readme_path(branch)
|
||||
if readme_path is None:
|
||||
return None
|
||||
try:
|
||||
with open(readme_path, encoding="utf-8") as fh:
|
||||
return fh.readlines()
|
||||
except OSError:
|
||||
return None
|
||||
|
||||
@@ -283,12 +283,6 @@ def detect_pollution(agents: List[AgentInfo]) -> List[PollutionHit]:
|
||||
# =============================================================================
|
||||
|
||||
|
||||
def find_registry(project_root: Path) -> Optional[Path]:
|
||||
"""Find *_REGISTRY.json under project_root."""
|
||||
candidates = list(project_root.glob("*_REGISTRY.json"))
|
||||
return candidates[0] if candidates else None
|
||||
|
||||
|
||||
def check_registry_consistency(
|
||||
registry_path: Path,
|
||||
agents: List[AgentInfo],
|
||||
|
||||
@@ -20,6 +20,8 @@ from typing import Dict, List, NamedTuple
|
||||
from aipass.cli.apps.modules import console
|
||||
from aipass.prax import logger
|
||||
|
||||
from aipass.common.registry_discovery import find_registry as _discover_registry
|
||||
|
||||
from aipass.aipass.apps.handlers.json import json_handler
|
||||
from aipass.aipass.apps.handlers.structure_scan.structure_scanner import (
|
||||
check_placement,
|
||||
@@ -28,7 +30,6 @@ from aipass.aipass.apps.handlers.structure_scan.structure_scanner import (
|
||||
check_root_artifacts,
|
||||
detect_pollution,
|
||||
find_project_root,
|
||||
find_registry,
|
||||
scan_agents,
|
||||
)
|
||||
from aipass.aipass.apps.modules.doctor_fix import (
|
||||
@@ -38,6 +39,7 @@ from aipass.aipass.apps.modules.doctor_fix import (
|
||||
from aipass.aipass.apps.modules.doctor_wire import (
|
||||
_auto_wire_provider,
|
||||
prompt_auto_wire,
|
||||
reconcile_stale_deny,
|
||||
)
|
||||
from aipass.aipass.apps.handlers.system_detect.system_detector import (
|
||||
detect_cpu,
|
||||
@@ -68,26 +70,10 @@ class CheckResult(NamedTuple):
|
||||
remediation: str
|
||||
|
||||
|
||||
# --- Identity helpers ---
|
||||
|
||||
|
||||
def _find_registry() -> Path | None:
|
||||
"""Walk up from CWD first (user's project), then branch root."""
|
||||
cwd = Path.cwd()
|
||||
for parent in (cwd, *cwd.parents):
|
||||
candidates = list(parent.glob("*_REGISTRY.json"))
|
||||
if candidates:
|
||||
return candidates[0]
|
||||
if parent == parent.parent:
|
||||
break
|
||||
for parent in (_BRANCH_ROOT, *_BRANCH_ROOT.parents):
|
||||
candidate = parent / "AIPASS_REGISTRY.json"
|
||||
if candidate.exists():
|
||||
return candidate
|
||||
return None
|
||||
|
||||
|
||||
# --- Check groups ---
|
||||
"""Find *_REGISTRY.json via shared discovery (walk-up from CWD + branch root)."""
|
||||
result = _discover_registry(package_root=str(_BRANCH_ROOT))
|
||||
return result if result.exists() else None
|
||||
|
||||
|
||||
def _check_system() -> List[CheckResult]:
|
||||
@@ -147,11 +133,10 @@ def _check_identity() -> List[CheckResult]:
|
||||
"""Run Identity group checks."""
|
||||
results: List[CheckResult] = []
|
||||
|
||||
# Project root — derived from registry location
|
||||
reg = _find_registry()
|
||||
project_root = str(reg.parent) if reg else ""
|
||||
if project_root:
|
||||
results.append(CheckResult("AIPASS_HOME", GLYPH_PASS, project_root, ""))
|
||||
# Project root + registry — single lookup
|
||||
reg_path = _find_registry()
|
||||
if reg_path:
|
||||
results.append(CheckResult("AIPASS_HOME", GLYPH_PASS, str(reg_path.parent), ""))
|
||||
else:
|
||||
home = os.environ.get("AIPASS_HOME", "")
|
||||
if home:
|
||||
@@ -166,8 +151,6 @@ def _check_identity() -> List[CheckResult]:
|
||||
)
|
||||
)
|
||||
|
||||
# Registry present
|
||||
reg_path = _find_registry()
|
||||
if reg_path is None:
|
||||
results.append(CheckResult("registry", GLYPH_FAIL, "not found", "Run 'aipass init' to create registry"))
|
||||
return results
|
||||
@@ -451,6 +434,10 @@ def _check_services(verbose: bool = False) -> List[CheckResult]:
|
||||
manifest_checks = _check_provider_manifest()
|
||||
results.extend(manifest_checks)
|
||||
|
||||
# stale rm deny rules — detect only (fix runs in run_doctor when --fix)
|
||||
for tup in reconcile_stale_deny(fix=False):
|
||||
results.append(CheckResult(*tup))
|
||||
|
||||
return results
|
||||
|
||||
|
||||
@@ -525,8 +512,8 @@ def _check_structure() -> List[CheckResult]:
|
||||
results.append(CheckResult("pollution", GLYPH_PASS, "no duplicates", ""))
|
||||
|
||||
# Registry consistency
|
||||
reg_path = find_registry(project_root)
|
||||
if reg_path:
|
||||
reg_path = _discover_registry(start_path=project_root)
|
||||
if reg_path and reg_path.exists():
|
||||
reg_issues = check_registry_consistency(reg_path, agents)
|
||||
if reg_issues:
|
||||
for issue in reg_issues:
|
||||
@@ -588,6 +575,12 @@ def run_doctor(verbose: bool = False, interactive: bool = False, fix: bool = Fal
|
||||
r for r in groups.get("Services", []) if r.label not in ("hooks", "env vars", "permissions")
|
||||
] + manifest_results
|
||||
|
||||
if fix:
|
||||
stale_results = [CheckResult(*tup) for tup in reconcile_stale_deny(fix=True)]
|
||||
if stale_results:
|
||||
services = groups.get("Services", [])
|
||||
groups["Services"] = [r for r in services if r.label != "rm deny migration"] + stale_results
|
||||
|
||||
pass_count = 0
|
||||
warn_count = 0
|
||||
error_count = 0
|
||||
@@ -664,15 +657,11 @@ def handle_command(command: str, args: list[str]) -> bool:
|
||||
if command != "doctor":
|
||||
return False
|
||||
|
||||
if not args:
|
||||
print_introspection()
|
||||
return True
|
||||
|
||||
if args[0] in ("--help", "-h", "help"):
|
||||
if args and args[0] in ("--help", "-h", "help"):
|
||||
print_help()
|
||||
return True
|
||||
|
||||
if args[0] == "--info":
|
||||
if args and args[0] == "--info":
|
||||
print_introspection()
|
||||
return True
|
||||
|
||||
|
||||
@@ -25,6 +25,8 @@ from typing import List, NamedTuple
|
||||
from aipass.cli.apps.modules import console
|
||||
from aipass.prax import logger
|
||||
|
||||
from aipass.common.registry_discovery import find_registry as _discover_registry
|
||||
|
||||
from aipass.aipass.apps.handlers.json import json_handler
|
||||
from aipass.aipass.apps.handlers.structure_scan.structure_scanner import (
|
||||
check_placement,
|
||||
@@ -32,7 +34,6 @@ from aipass.aipass.apps.handlers.structure_scan.structure_scanner import (
|
||||
check_registry_consistency,
|
||||
check_root_artifacts,
|
||||
detect_pollution,
|
||||
find_registry,
|
||||
scan_agents,
|
||||
)
|
||||
|
||||
@@ -58,8 +59,8 @@ class RemediationItem(NamedTuple):
|
||||
|
||||
def detect_project_name(project_root: Path) -> str:
|
||||
"""Derive project name from registry filename or directory name."""
|
||||
reg = find_registry(project_root)
|
||||
if reg:
|
||||
reg = _discover_registry(start_path=project_root)
|
||||
if reg and reg.exists():
|
||||
name = reg.stem.replace("_REGISTRY", "").lower()
|
||||
if name:
|
||||
return name
|
||||
@@ -83,7 +84,7 @@ def _build_pollution_items(agents: list, project: str) -> List[RemediationItem]:
|
||||
f"Registry pollution: {len(hit.locations)} copies of "
|
||||
f"{hit.agent_name} share registry_id {hit.registry_id}"
|
||||
),
|
||||
fix_command=f"drone @spawn repair @{project} --clean-pollution",
|
||||
fix_command=f"drone @spawn repair @{project} --clean-pollution --apply",
|
||||
)
|
||||
)
|
||||
return items
|
||||
@@ -104,7 +105,7 @@ def _build_placement_items(agents: list, project_root: Path, project: str) -> Li
|
||||
severity="warning",
|
||||
category="placement",
|
||||
description=f"Misplaced agent: {issue.agent_name} at {rel_path}",
|
||||
fix_command=f"drone @spawn repair @{project} --relocate {rel_path} {suggested}",
|
||||
fix_command=f"drone @spawn repair @{project} --relocate {rel_path} {suggested} --apply",
|
||||
)
|
||||
)
|
||||
return items
|
||||
@@ -113,8 +114,8 @@ def _build_placement_items(agents: list, project_root: Path, project: str) -> Li
|
||||
def _build_registry_items(project_root: Path, agents: list, project: str) -> List[RemediationItem]:
|
||||
"""Build remediation items for registry consistency issues."""
|
||||
items: List[RemediationItem] = []
|
||||
reg_path = find_registry(project_root)
|
||||
if not reg_path:
|
||||
reg_path = _discover_registry(start_path=project_root)
|
||||
if not reg_path or not reg_path.exists():
|
||||
return items
|
||||
for issue in check_registry_consistency(reg_path, agents):
|
||||
items.append(
|
||||
@@ -122,7 +123,7 @@ def _build_registry_items(project_root: Path, agents: list, project: str) -> Lis
|
||||
severity="warning",
|
||||
category="registry",
|
||||
description=f"Registry {issue.problem}: {issue.branch_name} at {issue.registered_path}",
|
||||
fix_command=f"drone @spawn repair @{project} --dedup-registry",
|
||||
fix_command=f"drone @spawn repair @{project} --dedup-registry --apply",
|
||||
)
|
||||
)
|
||||
return items
|
||||
@@ -145,7 +146,7 @@ def generate_remediation(project_root: Path) -> List[RemediationItem]:
|
||||
severity="info",
|
||||
category="pyproject",
|
||||
description="Missing pyproject.toml",
|
||||
fix_command=f"drone @spawn repair @{project} --add-pyproject",
|
||||
fix_command=f"drone @spawn repair @{project} --add-pyproject --apply",
|
||||
)
|
||||
)
|
||||
|
||||
@@ -156,7 +157,7 @@ def generate_remediation(project_root: Path) -> List[RemediationItem]:
|
||||
severity=severity,
|
||||
category="root_artifact",
|
||||
description=f"{hit.description}: {hit.name}/",
|
||||
fix_command=f"drone @spawn repair @{project} --relocate-root {hit.name}",
|
||||
fix_command=f"drone @spawn repair @{project} --relocate-root {hit.name} --apply",
|
||||
)
|
||||
)
|
||||
|
||||
@@ -184,7 +185,8 @@ def format_text_report(items: List[RemediationItem], project_name: str) -> str:
|
||||
lines.append(f"[{item.severity.upper()}] {item.description}")
|
||||
lines.append(f" Fix: {item.fix_command}")
|
||||
lines.append("")
|
||||
lines.append(f"Preview all fixes: drone @spawn repair @{project_name} --dry-run")
|
||||
lines.append(f"Preview all fixes: drone @spawn repair @{project_name}")
|
||||
lines.append(f"Apply all fixes: drone @spawn repair @{project_name} --apply")
|
||||
return "\n".join(lines)
|
||||
|
||||
|
||||
@@ -304,12 +306,12 @@ def handle_command(command: str, args: list[str]) -> bool:
|
||||
return False
|
||||
|
||||
if not args:
|
||||
print_introspection()
|
||||
json_handler.log_operation("doctor_fix_info", {"command": command})
|
||||
console.print("[dim]Helper module — use: aipass doctor --fix [--json][/dim]")
|
||||
json_handler.log_operation("doctor_fix_usage", {"command": command})
|
||||
return True
|
||||
|
||||
if args[0] in ("--help", "-h", "help"):
|
||||
print_introspection()
|
||||
console.print("[dim]Helper module — use: aipass doctor --fix [--json][/dim]")
|
||||
json_handler.log_operation("doctor_fix_help", {"command": command})
|
||||
return True
|
||||
|
||||
|
||||
@@ -51,6 +51,11 @@ ENV_DESCRIPTIONS: Dict[str, str] = {
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# STALE DENY RULE MIGRATION (implementation in handler; re-exported here)
|
||||
# =============================================================================
|
||||
|
||||
from aipass.aipass.apps.handlers.provider_reconcile import reconcile_stale_deny # noqa: E402, F401
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# AUTO-WIRE
|
||||
@@ -283,13 +288,13 @@ def handle_command(command: str, args: list[str]) -> bool:
|
||||
return False
|
||||
|
||||
if not args:
|
||||
print_introspection()
|
||||
json_handler.log_operation("doctor_wire_info", {"command": command})
|
||||
console.print("[dim]Helper module — use: aipass doctor (auto-wire runs when needed)[/dim]")
|
||||
json_handler.log_operation("doctor_wire_usage", {"command": command})
|
||||
return True
|
||||
|
||||
if args[0] in ("--help", "-h", "help"):
|
||||
print_introspection()
|
||||
json_handler.log_operation("doctor_wire_info", {"command": command})
|
||||
console.print("[dim]Helper module — use: aipass doctor (auto-wire runs when needed)[/dim]")
|
||||
json_handler.log_operation("doctor_wire_help", {"command": command})
|
||||
return True
|
||||
|
||||
if args[0] in ("--info", "info"):
|
||||
|
||||
@@ -134,13 +134,17 @@ def handle_command(command: str, args: list[str]) -> bool:
|
||||
return False
|
||||
|
||||
if not args:
|
||||
print_introspection()
|
||||
print_help()
|
||||
return True
|
||||
|
||||
if args[0] in ("--help", "-h", "help"):
|
||||
print_help()
|
||||
return True
|
||||
|
||||
if args[0] == "--info":
|
||||
print_introspection()
|
||||
return True
|
||||
|
||||
if args[0] == "launch":
|
||||
cli, cwd, flag_variant = _parse_launch_args(args[1:])
|
||||
if cli not in CLI_CHOICES:
|
||||
|
||||
@@ -27,7 +27,7 @@ from __future__ import annotations
|
||||
from pathlib import Path
|
||||
|
||||
from aipass.aipass.apps.handlers.json import json_handler
|
||||
from aipass.aipass.apps.handlers.readme_map import get_readme_path, list_branches
|
||||
from aipass.aipass.apps.handlers.readme_map import get_readme_path, list_branches, read_readme_lines
|
||||
from aipass.cli.apps.modules import console, error, header
|
||||
from aipass.prax import logger
|
||||
|
||||
@@ -54,6 +54,20 @@ def print_introspection() -> None:
|
||||
console.print(f"[bold cyan]Version:[/bold cyan] {_VERSION}")
|
||||
|
||||
|
||||
def print_help() -> None:
|
||||
"""Print usage help for the help command."""
|
||||
console.print()
|
||||
console.print("[bold cyan]aipass help[/bold cyan] — README-backed Q&A")
|
||||
console.print()
|
||||
console.print("[yellow]USAGE:[/yellow]")
|
||||
console.print(" [green]aipass help <question>[/green] [dim]# Search branch READMEs[/dim]")
|
||||
console.print()
|
||||
console.print("[yellow]EXAMPLES:[/yellow]")
|
||||
console.print(" [green]aipass help what does drone do[/green]")
|
||||
console.print(" [green]aipass help how does ai_mail work[/green]")
|
||||
console.print()
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# KEYWORD EXTRACTION
|
||||
# =============================================================================
|
||||
@@ -152,17 +166,15 @@ def _match_branches(keywords: list[str]) -> list[str]:
|
||||
# =============================================================================
|
||||
|
||||
|
||||
def _search_readme(readme_path: Path, keywords: list[str]) -> list[tuple[int, str]]:
|
||||
"""Live-read readme_path. Return (line_num, line_text) for matching lines.
|
||||
def _search_readme(branch: str, keywords: list[str]) -> list[tuple[int, str]]:
|
||||
"""Live-read branch README via handler. Return (line_num, line_text) for matching lines.
|
||||
|
||||
Reads every call — never cached. Scores lines by number of keyword hits.
|
||||
Returns up to 5 best matches.
|
||||
"""
|
||||
try:
|
||||
with open(readme_path, encoding="utf-8") as fh:
|
||||
lines = fh.readlines()
|
||||
except OSError as exc:
|
||||
logger.warning("[help_chat] Could not read README %s: %s", readme_path, exc)
|
||||
lines = read_readme_lines(branch)
|
||||
if lines is None:
|
||||
logger.warning("[help_chat] Could not read README for branch %s", branch)
|
||||
return []
|
||||
|
||||
scored: list[tuple[int, int, str]] = [] # (score, line_num, line_text)
|
||||
@@ -219,10 +231,14 @@ def handle_command(command: str, args: list[str]) -> bool:
|
||||
json_handler.ensure_module_jsons(_MODULE_NAME)
|
||||
|
||||
if not args:
|
||||
print_introspection()
|
||||
print_help()
|
||||
return True
|
||||
|
||||
if args[0] in ("--help", "-h", "help"):
|
||||
print_help()
|
||||
return True
|
||||
|
||||
if args[0] == "--info":
|
||||
print_introspection()
|
||||
return True
|
||||
|
||||
@@ -244,7 +260,7 @@ def handle_command(command: str, args: list[str]) -> bool:
|
||||
readme_path = get_readme_path(branch)
|
||||
if not readme_path:
|
||||
continue
|
||||
matches = _search_readme(readme_path, keywords)
|
||||
matches = _search_readme(branch, keywords)
|
||||
if matches:
|
||||
found_any = True
|
||||
answer = _format_answer(branch, readme_path, matches)
|
||||
|
||||
@@ -454,9 +454,9 @@ def stage_8_first_agent(non_interactive: bool = False, dry_run: bool = False) ->
|
||||
console.print("Let's create your first AI agent (citizen).")
|
||||
|
||||
if non_interactive:
|
||||
agent_name = "my-agent"
|
||||
agent_name = "my_agent"
|
||||
else:
|
||||
agent_name = _prompt("Agent name (letters, hyphens, no spaces)", "my-agent") or "my-agent"
|
||||
agent_name = _prompt("Agent name (letters, underscores, no spaces)", "my_agent") or "my_agent"
|
||||
|
||||
package_dir = _resolve_package_dir()
|
||||
if package_dir:
|
||||
@@ -560,7 +560,7 @@ def stage_10_smoke_test(non_interactive: bool = False, dry_run: bool = False) ->
|
||||
def stage_11_handoff(
|
||||
cli_choice: str = "claude",
|
||||
flag_variant: str = "default",
|
||||
agent_path: str = "src/my-agent",
|
||||
agent_path: str = "src/my_agent",
|
||||
non_interactive: bool = False,
|
||||
dry_run: bool = False,
|
||||
accumulated: Dict[str, Any] | None = None,
|
||||
@@ -645,13 +645,18 @@ def _write_init_report(agent_path: str, accumulated: Dict[str, Any], dry_run: bo
|
||||
"cli_choice": accumulated.get("cli", "claude"),
|
||||
"total_agents": 1,
|
||||
"system": system_data,
|
||||
"note": "You are the first agent created in this project. You are the orchestrator. After dispatching work to other agents, monitor them with: drone @devpulse watchdog agent @target",
|
||||
"note": (
|
||||
"You are the first agent created in this project. You are the orchestrator."
|
||||
" After dispatching work to other agents, monitor them with:"
|
||||
" drone @devpulse watchdog agent @target"
|
||||
),
|
||||
}
|
||||
provider_gaps = accumulated.get("provider_gaps", {})
|
||||
if provider_gaps:
|
||||
report["provider_gaps"] = provider_gaps
|
||||
report["provider_action"] = (
|
||||
"Provider settings need configuring. Tell the user what is missing and point them to provider_manifest.json for details."
|
||||
"Provider settings need configuring. Tell the user what is missing"
|
||||
" and point them to provider_manifest.json for details."
|
||||
)
|
||||
report_path = dropbox / "init_report.json"
|
||||
report_path.write_text(json.dumps(report, indent=2) + "\n", encoding="utf-8")
|
||||
@@ -685,10 +690,24 @@ def _preflight_check() -> str | None:
|
||||
"This directory is an agent branch (has .trinity/passport.json).\n"
|
||||
"Agents are managed by 'drone @spawn', not 'aipass init'."
|
||||
)
|
||||
# Block if inside an existing AIPass project (registry above us)
|
||||
# Block if inside an existing AIPass project (registry above us).
|
||||
# Walking up to the filesystem root can hit ancestors that can't be
|
||||
# enumerated or stat'd — e.g. locked Windows system entries at the drive
|
||||
# root (pagefile.sys) raise OSError. Skip those rather than crash; on
|
||||
# POSIX everything up to / is readable so behaviour is unchanged there.
|
||||
for parent in [cwd] + list(cwd.parents):
|
||||
for f in parent.iterdir():
|
||||
if f.is_file() and f.name.endswith("_REGISTRY.json"):
|
||||
try:
|
||||
entries = list(parent.iterdir())
|
||||
except OSError as exc:
|
||||
logger.info("[init_flow] skipping unreadable ancestor %s: %s", parent, exc)
|
||||
entries = []
|
||||
for f in entries:
|
||||
try:
|
||||
is_registry = f.is_file() and f.name.endswith("_REGISTRY.json")
|
||||
except OSError as exc:
|
||||
logger.info("[init_flow] skipping unstattable entry %s: %s", f, exc)
|
||||
continue
|
||||
if is_registry:
|
||||
return (
|
||||
f"Already inside an AIPass project (found {f.name} at {parent}).\n"
|
||||
"Use 'aipass init update' to upgrade an existing project."
|
||||
@@ -752,7 +771,7 @@ def run_init(
|
||||
lambda: stage_11_handoff(
|
||||
accumulated.get("cli", "claude"),
|
||||
accumulated.get("flag_variant", "default"),
|
||||
accumulated.get("agent_path", "src/my-agent"),
|
||||
accumulated.get("agent_path", "src/my_agent"),
|
||||
non_interactive,
|
||||
dry_run=dry_run,
|
||||
accumulated=accumulated,
|
||||
@@ -874,12 +893,14 @@ def _handle_init_update(args: list[str]) -> int:
|
||||
console.print(f" ({len(current)} already up to date)")
|
||||
# Heal registry: prune stale entries (e.g. cross-project ../paths)
|
||||
try:
|
||||
from aipass.spawn.apps.modules.sync_registry import sync_registry
|
||||
|
||||
sync_result = sync_registry(fix=True)
|
||||
pruned = sync_result.get("stale", [])
|
||||
if pruned:
|
||||
console.print(f" [green]Registry healed:[/green] removed {len(pruned)} stale entry(ies)")
|
||||
sync_proc = subprocess.run(
|
||||
["drone", "@spawn", "sync-registry", "--fix"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
timeout=30,
|
||||
)
|
||||
if sync_proc.returncode == 0:
|
||||
console.print(" [green]Registry synced.[/green]")
|
||||
except Exception as sync_exc:
|
||||
logger.warning("[init_flow] registry sync during update skipped: %s", sync_exc)
|
||||
|
||||
@@ -917,13 +938,17 @@ def handle_command(command: str, args: list[str]) -> bool:
|
||||
return False
|
||||
|
||||
if not args:
|
||||
print_introspection()
|
||||
print_help()
|
||||
return True
|
||||
|
||||
if args[0] in ("--help", "-h", "help"):
|
||||
print_help()
|
||||
return True
|
||||
|
||||
if args[0] == "--info":
|
||||
print_introspection()
|
||||
return True
|
||||
|
||||
if args[0] == "agent":
|
||||
sys.exit(_handle_init_agent(args[1:]))
|
||||
return True
|
||||
|
||||
@@ -141,6 +141,10 @@ def handle_command(command: str, args: list[str]) -> bool:
|
||||
print_help()
|
||||
return True
|
||||
|
||||
if args[0] == "--info":
|
||||
print_introspection()
|
||||
return True
|
||||
|
||||
if args[0] == "set":
|
||||
if len(args) < 3:
|
||||
error("Usage: aipass profile set <field> <value>")
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
# Project-specific Python dependencies beyond the base AIPass install.
|
||||
# Add packages here that the aipass branch requires but are not in the root pyproject.toml.
|
||||
# Install with: pip install -r requirements.project.txt
|
||||
@@ -102,7 +102,6 @@ def test_init_project_creates_all_expected_files(tmp_path):
|
||||
target / "CLAUDE.md",
|
||||
target / "AGENTS.md",
|
||||
target / "README.md",
|
||||
target / "STATUS.local.md",
|
||||
target / ".gitignore",
|
||||
target / ".claude" / "settings.json",
|
||||
target / ".claude" / "commands" / "prep.md",
|
||||
@@ -127,7 +126,7 @@ def test_init_project_creates_all_expected_files(tmp_path):
|
||||
created_basenames = [Path(f).name for f in result["created_files"]]
|
||||
for f in expected_files:
|
||||
assert f.name in created_basenames or f.exists(), f"Expected {f.name} in created_files"
|
||||
assert len(result["created_files"]) >= 12
|
||||
assert len(result["created_files"]) >= 11
|
||||
|
||||
|
||||
def test_init_project_return_dict_structure(tmp_path):
|
||||
@@ -235,15 +234,15 @@ def test_init_project_raises_on_empty_name(tmp_path):
|
||||
|
||||
|
||||
def test_init_project_agents_md_content(tmp_path):
|
||||
"""AGENTS.md is copied from AIPass source of truth."""
|
||||
"""AGENTS.md contains project-specific content from generator."""
|
||||
target = tmp_path / "proj"
|
||||
target.mkdir()
|
||||
|
||||
init_project(target, project_name="alpha")
|
||||
|
||||
content = (target / "AGENTS.md").read_text(encoding="utf-8")
|
||||
assert "# AIPass" in content
|
||||
assert "Multi-agent framework" in content
|
||||
assert "# ALPHA" in content
|
||||
assert "AIPass" in content
|
||||
|
||||
|
||||
def test_init_project_gitignore_content(tmp_path):
|
||||
@@ -325,7 +324,7 @@ def test_init_project_auto_creates_target_dir(tmp_path):
|
||||
|
||||
assert target.is_dir()
|
||||
assert result["project_name"] == "NESTED"
|
||||
assert len(result["created_files"]) >= 12
|
||||
assert len(result["created_files"]) >= 11
|
||||
|
||||
|
||||
def test_init_project_defaults_name_from_directory(tmp_path):
|
||||
@@ -364,7 +363,6 @@ def test_init_project_skips_existing_optional_files(tmp_path):
|
||||
(target / "CLAUDE.md").write_text("# Custom CLAUDE\n", encoding="utf-8")
|
||||
(target / "AGENTS.md").write_text("# Custom AGENTS\n", encoding="utf-8")
|
||||
(target / "README.md").write_text("# Custom README\n", encoding="utf-8")
|
||||
(target / "STATUS.local.md").write_text("# Custom status\n", encoding="utf-8")
|
||||
(target / ".gitignore").write_text("# Custom\n", encoding="utf-8")
|
||||
|
||||
claude_dir = target / ".claude"
|
||||
@@ -413,16 +411,15 @@ def test_init_project_returns_dict(tmp_path):
|
||||
|
||||
|
||||
def test_init_project_agents_md_no_trinity(tmp_path):
|
||||
"""AGENTS.md is copied from AIPass source (may reference .trinity/ as part of agent docs)."""
|
||||
"""AGENTS.md references .trinity/ as part of startup protocol docs."""
|
||||
target = tmp_path / "proj"
|
||||
target.mkdir()
|
||||
|
||||
init_project(target, project_name="keep")
|
||||
|
||||
content = (target / "AGENTS.md").read_text(encoding="utf-8")
|
||||
# Source file legitimately references .trinity/ as part of startup protocol docs
|
||||
assert "# AIPass" in content
|
||||
assert "Multi-agent framework" in content
|
||||
assert "# KEEP" in content
|
||||
assert ".trinity/" in content
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
@@ -518,7 +515,6 @@ def test_update_project_never_touches_user_owned_files(tmp_path):
|
||||
|
||||
# Modify user-owned files
|
||||
(target / "README.md").write_text("# My custom README\n", encoding="utf-8")
|
||||
(target / "STATUS.local.md").write_text("# Custom status\n", encoding="utf-8")
|
||||
(target / ".gitignore").write_text("# custom\n", encoding="utf-8")
|
||||
|
||||
result = update_project(target)
|
||||
@@ -526,12 +522,10 @@ def test_update_project_never_touches_user_owned_files(tmp_path):
|
||||
skipped = result["skipped_files"]
|
||||
assert any("REGISTRY" in s for s in skipped)
|
||||
assert any("README.md" in s for s in skipped)
|
||||
assert any("STATUS.local.md" in s for s in skipped)
|
||||
assert any(".gitignore" in s for s in skipped)
|
||||
|
||||
# User customisations are preserved
|
||||
assert (target / "README.md").read_text(encoding="utf-8") == "# My custom README\n"
|
||||
assert (target / "STATUS.local.md").read_text(encoding="utf-8") == "# Custom status\n"
|
||||
|
||||
|
||||
def test_update_project_creates_missing_managed_dirs(tmp_path):
|
||||
@@ -556,15 +550,15 @@ def test_update_project_creates_missing_managed_dirs(tmp_path):
|
||||
|
||||
|
||||
def test_update_project_skipped_files_count(tmp_path):
|
||||
"""update_project skips 4 user-owned files + existing mailbox = 5 total."""
|
||||
"""update_project skips 3 user-owned files."""
|
||||
target = tmp_path / "proj"
|
||||
target.mkdir()
|
||||
init_project(target, project_name="count")
|
||||
|
||||
result = update_project(target)
|
||||
|
||||
# 4 user-owned (registry, README, STATUS, .gitignore)
|
||||
assert len(result["skipped_files"]) == 4
|
||||
# 3 user-owned (registry, README, .gitignore)
|
||||
assert len(result["skipped_files"]) == 3
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
@@ -612,3 +612,133 @@ class TestHooksJsonCheck:
|
||||
assert len(hooks_results) == 1
|
||||
assert hooks_results[0].glyph == GLYPH_WARN
|
||||
assert "init update" in hooks_results[0].remediation
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# TestReconcileStaleDeny
|
||||
# =============================================================================
|
||||
|
||||
|
||||
class TestReconcileStaleDeny:
|
||||
"""Tests for stale rm deny rule migration (DPLAN-0192 Phase 2)."""
|
||||
|
||||
def test_no_settings_file_returns_empty(self, tmp_path) -> None:
|
||||
"""Missing settings.json returns no results."""
|
||||
from aipass.aipass.apps.modules.doctor_wire import reconcile_stale_deny
|
||||
|
||||
with patch("aipass.aipass.apps.modules.doctor_wire.Path.home", return_value=tmp_path):
|
||||
results = reconcile_stale_deny(fix=False)
|
||||
assert results == []
|
||||
|
||||
def test_no_stale_rules_returns_pass(self, tmp_path) -> None:
|
||||
"""Settings with no stale rm rules returns PASS."""
|
||||
from aipass.aipass.apps.modules.doctor_wire import reconcile_stale_deny
|
||||
|
||||
settings = tmp_path / ".claude" / "settings.json"
|
||||
settings.parent.mkdir(parents=True)
|
||||
settings.write_text(
|
||||
json.dumps({"permissions": {"deny": ["Bash(git push --force*)", "Bash(git reset --hard*)"]}}),
|
||||
encoding="utf-8",
|
||||
)
|
||||
with patch("aipass.aipass.apps.modules.doctor_wire.Path.home", return_value=tmp_path):
|
||||
results = reconcile_stale_deny(fix=False)
|
||||
assert len(results) == 1
|
||||
assert results[0][1] == GLYPH_PASS
|
||||
assert "no stale" in results[0][2]
|
||||
|
||||
def test_stale_rules_detected_without_fix(self, tmp_path) -> None:
|
||||
"""Stale rm rules present returns WARN when fix=False."""
|
||||
from aipass.aipass.apps.modules.doctor_wire import reconcile_stale_deny
|
||||
|
||||
settings = tmp_path / ".claude" / "settings.json"
|
||||
settings.parent.mkdir(parents=True)
|
||||
settings.write_text(
|
||||
json.dumps({"permissions": {"deny": ["Bash(rm -rf*)", "Bash(git push --force*)", "Bash(rm -r *)"]}}),
|
||||
encoding="utf-8",
|
||||
)
|
||||
with patch("aipass.aipass.apps.modules.doctor_wire.Path.home", return_value=tmp_path):
|
||||
results = reconcile_stale_deny(fix=False)
|
||||
assert len(results) == 1
|
||||
assert results[0][1] == GLYPH_WARN
|
||||
assert "rm -rf" in results[0][2]
|
||||
assert "rm -r " in results[0][2]
|
||||
|
||||
def test_fix_removes_stale_rules(self, tmp_path) -> None:
|
||||
"""fix=True removes stale rules and preserves others."""
|
||||
from aipass.aipass.apps.modules.doctor_wire import reconcile_stale_deny
|
||||
|
||||
settings = tmp_path / ".claude" / "settings.json"
|
||||
settings.parent.mkdir(parents=True)
|
||||
original = {
|
||||
"permissions": {"deny": ["Bash(rm -rf*)", "Bash(git push --force*)", "Bash(rm -r *)"]},
|
||||
"env": {"AIPASS_HOME": "/test"},
|
||||
}
|
||||
settings.write_text(json.dumps(original), encoding="utf-8")
|
||||
with patch("aipass.aipass.apps.modules.doctor_wire.Path.home", return_value=tmp_path):
|
||||
results = reconcile_stale_deny(fix=True)
|
||||
assert len(results) == 1
|
||||
assert results[0][1] == GLYPH_PASS
|
||||
assert "removed" in results[0][2]
|
||||
updated = json.loads(settings.read_text(encoding="utf-8"))
|
||||
assert "Bash(rm -rf*)" not in updated["permissions"]["deny"]
|
||||
assert "Bash(rm -r *)" not in updated["permissions"]["deny"]
|
||||
assert "Bash(git push --force*)" in updated["permissions"]["deny"]
|
||||
assert updated["env"]["AIPASS_HOME"] == "/test"
|
||||
|
||||
def test_fix_single_stale_rule(self, tmp_path) -> None:
|
||||
"""fix=True works when only one of two stale rules is present."""
|
||||
from aipass.aipass.apps.modules.doctor_wire import reconcile_stale_deny
|
||||
|
||||
settings = tmp_path / ".claude" / "settings.json"
|
||||
settings.parent.mkdir(parents=True)
|
||||
settings.write_text(
|
||||
json.dumps({"permissions": {"deny": ["Bash(rm -rf*)", "Bash(git reset --hard*)"]}}),
|
||||
encoding="utf-8",
|
||||
)
|
||||
with patch("aipass.aipass.apps.modules.doctor_wire.Path.home", return_value=tmp_path):
|
||||
results = reconcile_stale_deny(fix=True)
|
||||
assert len(results) == 1
|
||||
assert results[0][1] == GLYPH_PASS
|
||||
updated = json.loads(settings.read_text(encoding="utf-8"))
|
||||
assert updated["permissions"]["deny"] == ["Bash(git reset --hard*)"]
|
||||
|
||||
def test_fix_idempotent(self, tmp_path) -> None:
|
||||
"""Running fix twice is safe — second run returns PASS with no stale rules."""
|
||||
from aipass.aipass.apps.modules.doctor_wire import reconcile_stale_deny
|
||||
|
||||
settings = tmp_path / ".claude" / "settings.json"
|
||||
settings.parent.mkdir(parents=True)
|
||||
settings.write_text(
|
||||
json.dumps({"permissions": {"deny": ["Bash(rm -rf*)", "Bash(rm -r *)"]}}),
|
||||
encoding="utf-8",
|
||||
)
|
||||
with patch("aipass.aipass.apps.modules.doctor_wire.Path.home", return_value=tmp_path):
|
||||
reconcile_stale_deny(fix=True)
|
||||
results = reconcile_stale_deny(fix=True)
|
||||
assert len(results) == 1
|
||||
assert results[0][1] == GLYPH_PASS
|
||||
assert "no stale" in results[0][2]
|
||||
|
||||
def test_empty_deny_list_returns_pass(self, tmp_path) -> None:
|
||||
"""Empty deny list returns PASS."""
|
||||
from aipass.aipass.apps.modules.doctor_wire import reconcile_stale_deny
|
||||
|
||||
settings = tmp_path / ".claude" / "settings.json"
|
||||
settings.parent.mkdir(parents=True)
|
||||
settings.write_text(json.dumps({"permissions": {"deny": []}}), encoding="utf-8")
|
||||
with patch("aipass.aipass.apps.modules.doctor_wire.Path.home", return_value=tmp_path):
|
||||
results = reconcile_stale_deny(fix=False)
|
||||
assert len(results) == 1
|
||||
assert results[0][1] == GLYPH_PASS
|
||||
|
||||
def test_no_permissions_key_returns_pass(self, tmp_path) -> None:
|
||||
"""Settings without permissions key returns PASS."""
|
||||
from aipass.aipass.apps.modules.doctor_wire import reconcile_stale_deny
|
||||
|
||||
settings = tmp_path / ".claude" / "settings.json"
|
||||
settings.parent.mkdir(parents=True)
|
||||
settings.write_text(json.dumps({"env": {"FOO": "bar"}}), encoding="utf-8")
|
||||
with patch("aipass.aipass.apps.modules.doctor_wire.Path.home", return_value=tmp_path):
|
||||
results = reconcile_stale_deny(fix=False)
|
||||
assert len(results) == 1
|
||||
assert results[0][1] == GLYPH_PASS
|
||||
|
||||
@@ -65,8 +65,14 @@ class TestDetectProjectName:
|
||||
|
||||
def test_fallback_to_dirname(self, tmp_path: Path) -> None:
|
||||
"""Falls back to directory name when no registry."""
|
||||
result = detect_project_name(tmp_path)
|
||||
assert result == tmp_path.name.lower()
|
||||
no_reg = tmp_path / "empty_project"
|
||||
no_reg.mkdir()
|
||||
with patch(
|
||||
"aipass.aipass.apps.modules.doctor_fix._discover_registry",
|
||||
return_value=no_reg / "MISSING_REGISTRY.json",
|
||||
):
|
||||
result = detect_project_name(no_reg)
|
||||
assert result == "empty_project"
|
||||
|
||||
def test_registry_name_lowered(self, tmp_path: Path) -> None:
|
||||
"""Registry name is lowercased."""
|
||||
@@ -248,10 +254,13 @@ class TestFormatTextReport:
|
||||
assert "drone @spawn repair @test --relocate a b" in result
|
||||
|
||||
def test_dry_run_hint(self) -> None:
|
||||
"""Report ends with dry-run suggestion."""
|
||||
"""Report shows preview (dry-run default) and explicit --apply hints."""
|
||||
items = [RemediationItem("info", "pyproject", "missing", "fix")]
|
||||
result = format_text_report(items, "myproj")
|
||||
assert "drone @spawn repair @myproj --dry-run" in result
|
||||
# Repair is dry-run by default now: preview form has no flag, apply form is explicit
|
||||
assert "Preview all fixes:" in result
|
||||
assert "drone @spawn repair @myproj" in result
|
||||
assert "drone @spawn repair @myproj --apply" in result
|
||||
|
||||
def test_critical_sorted_first(self) -> None:
|
||||
"""Critical items appear before warning and info."""
|
||||
@@ -364,14 +373,15 @@ class TestDoctorFixHandleCommand:
|
||||
assert handle_command("doctor", []) is False
|
||||
assert handle_command("help", []) is False
|
||||
|
||||
def test_no_args_calls_introspection(self) -> None:
|
||||
"""No args triggers print_introspection."""
|
||||
def test_no_args_shows_usage(self) -> None:
|
||||
"""No args shows usage message (not introspection banner)."""
|
||||
from aipass.aipass.apps.modules.doctor_fix import handle_command
|
||||
|
||||
with patch("aipass.aipass.apps.modules.doctor_fix.print_introspection") as mock:
|
||||
with patch("aipass.aipass.apps.modules.doctor_fix.console") as mock_console:
|
||||
result = handle_command("doctor_fix", [])
|
||||
assert result is True
|
||||
mock.assert_called_once()
|
||||
printed = " ".join(str(c) for c in mock_console.print.call_args_list)
|
||||
assert "aipass doctor --fix" in printed
|
||||
|
||||
def test_info_flag(self) -> None:
|
||||
"""--info triggers print_introspection."""
|
||||
|
||||
@@ -52,20 +52,6 @@ _ENCODING = "utf-8"
|
||||
# =============================================================================
|
||||
|
||||
|
||||
def _call_handle_command_no_args():
|
||||
"""Call handle_command('help', []) with json_handler and console mocked."""
|
||||
mock_console = MagicMock()
|
||||
patches = [
|
||||
patch("aipass.aipass.apps.modules.help_chat.json_handler"),
|
||||
patch("aipass.aipass.apps.modules.help_chat.console", mock_console),
|
||||
]
|
||||
with ExitStack() as stack:
|
||||
for p in patches:
|
||||
stack.enter_context(p)
|
||||
result = handle_command("help", [])
|
||||
return result, mock_console
|
||||
|
||||
|
||||
def _call_handle_command_drone_question(readme_content: str, readme_path: Path):
|
||||
"""Call handle_command for 'what does drone do' with file I/O mocked."""
|
||||
patches = [
|
||||
@@ -254,54 +240,57 @@ class TestMatchBranches:
|
||||
|
||||
|
||||
class TestSearchReadme:
|
||||
"""Tests for _search_readme: live file reads, scoring, and error handling."""
|
||||
"""Tests for _search_readme: live file reads via handler, scoring, and error handling."""
|
||||
|
||||
def _mock_lines(self, content):
|
||||
"""Return a patch that makes read_readme_lines return content as lines."""
|
||||
lines = content.splitlines(keepends=True)
|
||||
return patch("aipass.aipass.apps.modules.help_chat.read_readme_lines", return_value=lines)
|
||||
|
||||
def test_returns_matching_lines_with_line_numbers(self):
|
||||
"""Matching lines must be returned as (int, str) tuples."""
|
||||
with patch("builtins.open", mock_open(read_data=_SAMPLE_README)):
|
||||
results = _search_readme(_FAKE_README_PATH, ["drone"])
|
||||
with self._mock_lines(_SAMPLE_README):
|
||||
results = _search_readme("drone", ["drone"])
|
||||
assert len(results) > 0
|
||||
assert all(isinstance(ln, int) for ln, _ in results)
|
||||
|
||||
def test_line_numbers_are_1_indexed(self):
|
||||
"""Line numbers in results must start at 1, not 0."""
|
||||
with patch("builtins.open", mock_open(read_data=_SAMPLE_README)):
|
||||
results = _search_readme(_FAKE_README_PATH, ["drone"])
|
||||
with self._mock_lines(_SAMPLE_README):
|
||||
results = _search_readme("drone", ["drone"])
|
||||
assert all(ln >= 1 for ln, _ in results)
|
||||
|
||||
def test_returns_at_most_5_matches(self):
|
||||
"""Result list must contain no more than 5 entries."""
|
||||
content = "\n".join([f"drone line {i}" for i in range(10)])
|
||||
with patch("builtins.open", mock_open(read_data=content)):
|
||||
results = _search_readme(_FAKE_README_PATH, ["drone"])
|
||||
with self._mock_lines(content):
|
||||
results = _search_readme("drone", ["drone"])
|
||||
assert len(results) <= 5
|
||||
|
||||
def test_no_keyword_match_returns_empty(self):
|
||||
"""Keyword with no hits in the README must return an empty list."""
|
||||
with patch("builtins.open", mock_open(read_data=_SAMPLE_README)):
|
||||
results = _search_readme(_FAKE_README_PATH, ["xyzzy999"])
|
||||
with self._mock_lines(_SAMPLE_README):
|
||||
results = _search_readme("drone", ["xyzzy999"])
|
||||
assert results == []
|
||||
|
||||
def test_oserror_returns_empty_and_logs_warning(self):
|
||||
"""OSError on open must return [] and call logger.warning exactly once."""
|
||||
with patch("builtins.open", side_effect=OSError("not found")):
|
||||
def test_handler_returns_none_returns_empty_and_logs(self):
|
||||
"""None from handler must return [] and call logger.warning."""
|
||||
with patch("aipass.aipass.apps.modules.help_chat.read_readme_lines", return_value=None):
|
||||
with patch("aipass.aipass.apps.modules.help_chat.logger") as mock_logger:
|
||||
results = _search_readme(_FAKE_README_PATH, ["drone"])
|
||||
results = _search_readme("nonexistent", ["drone"])
|
||||
assert results == []
|
||||
mock_logger.warning.assert_called_once()
|
||||
|
||||
def test_matching_is_case_insensitive(self):
|
||||
"""Uppercase keyword in README must still match a lowercase query keyword."""
|
||||
content = "DRONE does routing\n"
|
||||
with patch("builtins.open", mock_open(read_data=content)):
|
||||
results = _search_readme(_FAKE_README_PATH, ["drone"])
|
||||
with self._mock_lines("DRONE does routing\n"):
|
||||
results = _search_readme("drone", ["drone"])
|
||||
assert len(results) == 1
|
||||
|
||||
def test_higher_scoring_lines_ranked_first(self):
|
||||
"""Lines matching more keywords must appear before lines matching fewer."""
|
||||
content = "drone flow spawn\ndrone only\nflow only\n"
|
||||
with patch("builtins.open", mock_open(read_data=content)):
|
||||
results = _search_readme(_FAKE_README_PATH, ["drone", "flow"])
|
||||
with self._mock_lines("drone flow spawn\ndrone only\nflow only\n"):
|
||||
results = _search_readme("drone", ["drone", "flow"])
|
||||
first_text = results[0][1]
|
||||
assert "drone" in first_text and "flow" in first_text
|
||||
|
||||
@@ -367,11 +356,21 @@ class TestHandleCommand:
|
||||
"""COMMAND module constant must equal the string 'help'."""
|
||||
assert COMMAND == "help"
|
||||
|
||||
def test_no_args_returns_true_and_calls_console(self):
|
||||
"""handle_command('help', []) must return True and print usage via console."""
|
||||
result, mock_console = _call_handle_command_no_args()
|
||||
def test_no_args_returns_true_and_shows_help(self):
|
||||
"""handle_command('help', []) must return True and print usage help."""
|
||||
with patch("aipass.aipass.apps.modules.help_chat.print_help") as mock_help:
|
||||
with patch("aipass.aipass.apps.modules.help_chat.json_handler"):
|
||||
result = handle_command("help", [])
|
||||
assert result is True
|
||||
mock_console.print.assert_called()
|
||||
mock_help.assert_called_once()
|
||||
|
||||
def test_info_flag_calls_introspection(self):
|
||||
"""--info flag triggers print_introspection."""
|
||||
with patch("aipass.aipass.apps.modules.help_chat.print_introspection") as mock_intro:
|
||||
with patch("aipass.aipass.apps.modules.help_chat.json_handler"):
|
||||
result = handle_command("help", ["--info"])
|
||||
assert result is True
|
||||
mock_intro.assert_called_once()
|
||||
|
||||
def test_valid_drone_question_returns_true(self):
|
||||
"""A well-formed question about drone must return True."""
|
||||
|
||||
@@ -19,6 +19,7 @@ from aipass.aipass.apps.modules.init_flow import (
|
||||
TOTAL_STAGES,
|
||||
_get_last_completed_stage,
|
||||
_get_setup_progress,
|
||||
_handle_init_update,
|
||||
_save_stage,
|
||||
handle_command,
|
||||
print_help,
|
||||
@@ -198,11 +199,18 @@ class TestHandleCommand:
|
||||
assert handle_command("doctor", []) is False
|
||||
assert handle_command("profile", ["set", "name", "X"]) is False
|
||||
|
||||
def test_no_args_shows_introspection(self, tmp_local_json) -> None:
|
||||
"""'init' with no args calls print_introspection."""
|
||||
with patch("aipass.aipass.apps.modules.init_flow.print_introspection") as mock_intro:
|
||||
def test_no_args_shows_help(self, tmp_local_json) -> None:
|
||||
"""'init' with no args calls print_help (not introspection banner)."""
|
||||
with patch("aipass.aipass.apps.modules.init_flow.print_help") as mock_help:
|
||||
result = handle_command("init", [])
|
||||
assert result is True
|
||||
mock_help.assert_called_once()
|
||||
|
||||
def test_info_flag_calls_introspection(self, tmp_local_json) -> None:
|
||||
"""--info flag calls print_introspection."""
|
||||
with patch("aipass.aipass.apps.modules.init_flow.print_introspection") as mock_intro:
|
||||
result = handle_command("init", ["--info"])
|
||||
assert result is True
|
||||
mock_intro.assert_called_once()
|
||||
|
||||
def test_help_flag(self) -> None:
|
||||
@@ -499,14 +507,14 @@ class TestStages:
|
||||
assert result["docker"] == "skipped"
|
||||
|
||||
def test_stage_8_non_interactive_creates_my_agent(self, tmp_local_json) -> None:
|
||||
"""non_interactive=True uses 'my-agent' as default name."""
|
||||
"""non_interactive=True uses 'my_agent' as default name."""
|
||||
mock_proc = MagicMock(returncode=0)
|
||||
with patch(f"{_MOD}.console"):
|
||||
with patch(f"{_MOD}.subprocess.run", return_value=mock_proc):
|
||||
with patch(f"{_MOD}._resolve_package_dir", return_value=None):
|
||||
result = stage_8_first_agent(non_interactive=True)
|
||||
assert result["agent_name"] == "my-agent"
|
||||
assert result["agent_path"] == "src/my-agent"
|
||||
assert result["agent_name"] == "my_agent"
|
||||
assert result["agent_path"] == "src/my_agent"
|
||||
|
||||
def test_stage_8_drone_not_found(self, tmp_local_json) -> None:
|
||||
"""FileNotFoundError from drone is handled gracefully."""
|
||||
@@ -567,3 +575,87 @@ class TestStages:
|
||||
assert result == {}
|
||||
stored = json.loads(tmp_local_json.read_text())
|
||||
assert stored["setup_progress"]["last_completed_stage"] == 12
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# init_update_registry_sync: subprocess_sync
|
||||
# =============================================================================
|
||||
|
||||
|
||||
_MOD_UPDATE = "aipass.aipass.apps.modules.init_flow"
|
||||
|
||||
|
||||
class TestInitUpdateRegistrySync:
|
||||
"""Tests for registry sync subprocess call in _handle_init_update."""
|
||||
|
||||
def test_sync_success_prints_message(self, tmp_path: Path) -> None:
|
||||
"""Successful drone sync-registry prints 'Registry synced.'"""
|
||||
mock_result = MagicMock(returncode=0)
|
||||
with (
|
||||
patch(
|
||||
"aipass.aipass.apps.handlers.init.bootstrap.update_project",
|
||||
return_value={"updated_files": [], "already_current": []},
|
||||
),
|
||||
patch(f"{_MOD_UPDATE}.subprocess.run", return_value=mock_result) as mock_run,
|
||||
patch(f"{_MOD_UPDATE}.console") as mock_console,
|
||||
patch(f"{_MOD_UPDATE}.json_handler"),
|
||||
):
|
||||
rc = _handle_init_update([str(tmp_path)])
|
||||
assert rc == 0
|
||||
mock_run.assert_called_once_with(
|
||||
["drone", "@spawn", "sync-registry", "--fix"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
timeout=30,
|
||||
)
|
||||
sync_calls = [c for c in mock_console.print.call_args_list if "Registry synced" in str(c)]
|
||||
assert len(sync_calls) == 1
|
||||
|
||||
def test_sync_failure_degrades_silently(self, tmp_path: Path) -> None:
|
||||
"""Non-zero exit from drone sync-registry is silently skipped."""
|
||||
mock_result = MagicMock(returncode=1)
|
||||
with (
|
||||
patch(
|
||||
"aipass.aipass.apps.handlers.init.bootstrap.update_project",
|
||||
return_value={"updated_files": [], "already_current": []},
|
||||
),
|
||||
patch(f"{_MOD_UPDATE}.subprocess.run", return_value=mock_result),
|
||||
patch(f"{_MOD_UPDATE}.console") as mock_console,
|
||||
patch(f"{_MOD_UPDATE}.json_handler"),
|
||||
):
|
||||
rc = _handle_init_update([str(tmp_path)])
|
||||
assert rc == 0
|
||||
sync_calls = [c for c in mock_console.print.call_args_list if "Registry synced" in str(c)]
|
||||
assert len(sync_calls) == 0
|
||||
|
||||
def test_sync_missing_drone_degrades_silently(self, tmp_path: Path) -> None:
|
||||
"""FileNotFoundError (no drone binary) degrades gracefully."""
|
||||
with (
|
||||
patch(
|
||||
"aipass.aipass.apps.handlers.init.bootstrap.update_project",
|
||||
return_value={"updated_files": [], "already_current": []},
|
||||
),
|
||||
patch(f"{_MOD_UPDATE}.subprocess.run", side_effect=FileNotFoundError("drone not found")),
|
||||
patch(f"{_MOD_UPDATE}.console") as mock_console,
|
||||
patch(f"{_MOD_UPDATE}.json_handler"),
|
||||
):
|
||||
rc = _handle_init_update([str(tmp_path)])
|
||||
assert rc == 0
|
||||
sync_calls = [c for c in mock_console.print.call_args_list if "Registry synced" in str(c)]
|
||||
assert len(sync_calls) == 0
|
||||
|
||||
def test_sync_timeout_degrades_silently(self, tmp_path: Path) -> None:
|
||||
"""subprocess.TimeoutExpired degrades gracefully."""
|
||||
import subprocess as _sp
|
||||
|
||||
with (
|
||||
patch(
|
||||
"aipass.aipass.apps.handlers.init.bootstrap.update_project",
|
||||
return_value={"updated_files": [], "already_current": []},
|
||||
),
|
||||
patch(f"{_MOD_UPDATE}.subprocess.run", side_effect=_sp.TimeoutExpired(cmd="drone", timeout=30)),
|
||||
patch(f"{_MOD_UPDATE}.console"),
|
||||
patch(f"{_MOD_UPDATE}.json_handler"),
|
||||
):
|
||||
rc = _handle_init_update([str(tmp_path)])
|
||||
assert rc == 0
|
||||
|
||||
@@ -9,11 +9,12 @@
|
||||
"""Tests for json_handler — default_factory, validate, get_path, ensure_exists, load, save, ensure_module."""
|
||||
|
||||
import json
|
||||
|
||||
import pytest
|
||||
from unittest.mock import patch
|
||||
|
||||
from aipass.aipass.apps.handlers.json.json_handler import (
|
||||
AIPASS_JSON_DIR,
|
||||
_default_template,
|
||||
ensure_json_exists,
|
||||
ensure_module_jsons,
|
||||
get_json_path,
|
||||
@@ -30,31 +31,39 @@ from aipass.aipass.apps.handlers.json.json_handler import (
|
||||
|
||||
|
||||
class TestDefaultFactory:
|
||||
"""Tests for _default_template factory function."""
|
||||
"""Tests for default JSON creation via ensure_json_exists."""
|
||||
|
||||
def test_config_template(self):
|
||||
def test_config_template(self, tmp_path):
|
||||
"""Config template includes module_name, version, config, created."""
|
||||
result = _default_template("config", "test_mod")
|
||||
with patch("aipass.aipass.apps.handlers.json.json_handler.AIPASS_JSON_DIR", tmp_path):
|
||||
ensure_json_exists("test_mod", "config")
|
||||
result = json.loads((tmp_path / "test_mod_config.json").read_text())
|
||||
assert result["module_name"] == "test_mod"
|
||||
assert result["version"] == "1.0.0"
|
||||
assert "config" in result
|
||||
assert "created" in result
|
||||
|
||||
def test_data_template(self):
|
||||
def test_data_template(self, tmp_path):
|
||||
"""Data template includes created and last_updated."""
|
||||
result = _default_template("data", "test_mod")
|
||||
with patch("aipass.aipass.apps.handlers.json.json_handler.AIPASS_JSON_DIR", tmp_path):
|
||||
ensure_json_exists("test_mod", "data")
|
||||
result = json.loads((tmp_path / "test_mod_data.json").read_text())
|
||||
assert "created" in result
|
||||
assert "last_updated" in result
|
||||
|
||||
def test_log_template(self):
|
||||
def test_log_template(self, tmp_path):
|
||||
"""Log template is an empty list."""
|
||||
result = _default_template("log", "test_mod")
|
||||
with patch("aipass.aipass.apps.handlers.json.json_handler.AIPASS_JSON_DIR", tmp_path):
|
||||
ensure_json_exists("test_mod", "log")
|
||||
result = json.loads((tmp_path / "test_mod_log.json").read_text())
|
||||
assert result == []
|
||||
|
||||
def test_unknown_type_returns_none(self):
|
||||
"""Unknown json_type returns None."""
|
||||
result = _default_template("unknown_type", "test_mod")
|
||||
assert result is None
|
||||
def test_unknown_type_raises(self):
|
||||
"""Unknown json_type raises ValueError."""
|
||||
from aipass.common.json_handler import JsonHandler
|
||||
|
||||
with pytest.raises(ValueError):
|
||||
JsonHandler._create_default("unknown_type", "test_mod")
|
||||
|
||||
|
||||
# =============================================================================
|
||||
@@ -200,10 +209,20 @@ class TestSave:
|
||||
assert saved["module_name"] == "s"
|
||||
|
||||
def test_save_invalid_structure_rejected(self, tmp_path):
|
||||
"""Invalid structure is rejected with False."""
|
||||
"""Invalid structure raises ValueError."""
|
||||
with patch("aipass.aipass.apps.handlers.json.json_handler.AIPASS_JSON_DIR", tmp_path):
|
||||
result = save_json("s", "config", {"bad": True})
|
||||
assert result is False
|
||||
with pytest.raises(ValueError):
|
||||
save_json("s", "config", {"bad": True})
|
||||
|
||||
def test_save_unknown_returns_false(self, tmp_path):
|
||||
"""save_json returns False when write fails (e.g. read-only dir)."""
|
||||
ro_dir = tmp_path / "readonly"
|
||||
ro_dir.mkdir()
|
||||
with patch("aipass.aipass.apps.handlers.json.json_handler.AIPASS_JSON_DIR", ro_dir):
|
||||
data = {"module_name": "s", "version": "1.0.0", "config": {}, "created": "2026-01-01"}
|
||||
with patch("aipass.common.json_handler.JsonHandler.write_json", return_value=False):
|
||||
result = save_json("s", "config", data)
|
||||
assert result is False
|
||||
|
||||
|
||||
# =============================================================================
|
||||
@@ -239,7 +258,7 @@ class TestLoadPath:
|
||||
result = load_path(f)
|
||||
assert result == {"key": "value"}
|
||||
|
||||
def test_load_missing_file(self, tmp_path):
|
||||
def test_unknown_file_returns_none(self, tmp_path):
|
||||
"""Missing file returns None."""
|
||||
result = load_path(tmp_path / "nope.json")
|
||||
assert result is None
|
||||
@@ -290,7 +309,9 @@ class TestReturnTypeContracts:
|
||||
"""Doctor handle_command returns True for match, False otherwise."""
|
||||
from aipass.aipass.apps.modules.doctor import handle_command as doctor_cmd
|
||||
|
||||
assert doctor_cmd("doctor", []) is True
|
||||
with patch("aipass.aipass.apps.modules.doctor.run_doctor", return_value=0):
|
||||
with patch("aipass.aipass.apps.modules.doctor.json_handler"):
|
||||
assert doctor_cmd("doctor", []) is True
|
||||
assert doctor_cmd("not_doctor", []) is False
|
||||
|
||||
def test_help_chat_handle_command_returns_bool(self):
|
||||
@@ -324,14 +345,14 @@ class TestExceptionContracts:
|
||||
"""Tests that invalid inputs raise appropriate exceptions."""
|
||||
|
||||
def test_invalid_mode_raises(self, tmp_path):
|
||||
"""save_json with invalid structure returns False (not silent pass)."""
|
||||
"""save_json with invalid structure raises ValueError."""
|
||||
with patch("aipass.aipass.apps.handlers.json.json_handler.AIPASS_JSON_DIR", tmp_path):
|
||||
result = save_json("x", "config", [])
|
||||
assert result is False
|
||||
result = save_json("x", "data", "string")
|
||||
assert result is False
|
||||
result = save_json("x", "log", {"not": "a list"})
|
||||
assert result is False
|
||||
with pytest.raises(ValueError):
|
||||
save_json("x", "config", [])
|
||||
with pytest.raises(ValueError):
|
||||
save_json("x", "data", "string")
|
||||
with pytest.raises(ValueError):
|
||||
save_json("x", "log", {"not": "a list"})
|
||||
|
||||
|
||||
# =============================================================================
|
||||
@@ -355,3 +376,13 @@ class TestInfrastructureMocking:
|
||||
assert callable(jh_mod.load_json)
|
||||
assert callable(jh_mod.save_json)
|
||||
assert callable(jh_mod.load_path)
|
||||
|
||||
|
||||
# =============================================================================
|
||||
# success_failure_paths: unknown_returns_false
|
||||
# =============================================================================
|
||||
|
||||
|
||||
def test_unknown_returns_false():
|
||||
"""validate_json_structure returns False for unrecognized json_type."""
|
||||
assert validate_json_structure({}, "bogus") is False
|
||||
|
||||
@@ -170,12 +170,19 @@ class TestHandleCommand:
|
||||
assert handle_command("init", ["run"]) is False
|
||||
|
||||
def test_no_args_calls_introspection(self, tmp_local_json) -> None:
|
||||
"""'profile' with no args calls print_introspection."""
|
||||
"""'profile' with no args shows the profile (runs the command)."""
|
||||
with patch("aipass.aipass.apps.modules.profile.print_introspection") as mock_pi:
|
||||
result = handle_command("profile", [])
|
||||
assert result is True
|
||||
mock_pi.assert_called_once()
|
||||
|
||||
def test_info_flag_calls_introspection(self, tmp_local_json) -> None:
|
||||
"""--info flag calls print_introspection."""
|
||||
with patch("aipass.aipass.apps.modules.profile.print_introspection") as mock_pi:
|
||||
result = handle_command("profile", ["--info"])
|
||||
assert result is True
|
||||
mock_pi.assert_called_once()
|
||||
|
||||
def test_help_flag_returns_true(self) -> None:
|
||||
"""--help flag is handled."""
|
||||
with patch("aipass.aipass.apps.modules.profile.print_help"):
|
||||
|
||||
@@ -20,7 +20,6 @@ from aipass.aipass.apps.handlers.structure_scan.structure_scanner import (
|
||||
check_root_artifacts,
|
||||
detect_pollution,
|
||||
find_project_root,
|
||||
find_registry,
|
||||
scan_agents,
|
||||
)
|
||||
from aipass.aipass.apps.handlers.ui.progress import GLYPH_FAIL, GLYPH_WARN
|
||||
@@ -357,16 +356,22 @@ class TestRegistryConsistency:
|
||||
|
||||
class TestFindRegistry:
|
||||
def test_finds_registry(self, tmp_path: Path) -> None:
|
||||
"""Finds *_REGISTRY.json in project root."""
|
||||
"""Shared find_registry finds *_REGISTRY.json from start_path."""
|
||||
from aipass.common.registry_discovery import find_registry
|
||||
|
||||
(tmp_path / "AIPASS_REGISTRY.json").write_text("{}", encoding="utf-8")
|
||||
result = find_registry(tmp_path)
|
||||
result = find_registry(start_path=tmp_path)
|
||||
assert result is not None
|
||||
assert result.name == "AIPASS_REGISTRY.json"
|
||||
|
||||
def test_returns_none(self, tmp_path: Path) -> None:
|
||||
"""Returns None when no registry file."""
|
||||
result = find_registry(tmp_path)
|
||||
assert result is None
|
||||
def test_fallback_when_missing(self, tmp_path: Path) -> None:
|
||||
"""Shared find_registry returns fallback when no registry in isolated dir."""
|
||||
from aipass.common.registry_discovery import find_registry
|
||||
|
||||
isolated = tmp_path / "no_registry"
|
||||
isolated.mkdir()
|
||||
result = find_registry(start_path=isolated)
|
||||
assert result.parent != isolated or not result.exists()
|
||||
|
||||
|
||||
# =============================================================================
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
# These are beyond the base AIPass requirements
|
||||
# Install with: pip install -r requirements.project.txt
|
||||
|
||||
requests
|
||||
requests>=2.34.2
|
||||
rich
|
||||
google-auth
|
||||
google-auth-oauthlib
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
# aipass.common — shared leaf utilities (no branch dependencies)
|
||||
@@ -0,0 +1,303 @@
|
||||
# =================== AIPass ====================
|
||||
# Name: json_handler.py
|
||||
# Description: Shared JSON handler with injectable storage directory
|
||||
# Version: 1.0.0
|
||||
# Created: 2026-06-06
|
||||
# Modified: 2026-06-06
|
||||
# =============================================
|
||||
|
||||
"""Shared JSON handler — auto-creating, self-healing JSON system.
|
||||
|
||||
Dependency-free: uses only stdlib. Importable before drone/prax exist.
|
||||
|
||||
Each branch creates a JsonHandler instance with its own json_dir.
|
||||
Contract: save_json raises ValueError on validation failure.
|
||||
"""
|
||||
|
||||
import inspect
|
||||
import json
|
||||
import logging
|
||||
import os
|
||||
import tempfile
|
||||
from datetime import datetime
|
||||
from pathlib import Path
|
||||
from typing import Any, Dict, Optional
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
_JSON_TYPES: tuple[str, ...] = ("config", "data", "log")
|
||||
|
||||
|
||||
class JsonHandler:
|
||||
"""JSON file handler with injectable storage directory.
|
||||
|
||||
Provides JSON I/O utilities, validation, and operation logging
|
||||
for the three-JSON system (config, data, log).
|
||||
|
||||
Args:
|
||||
json_dir: Directory for module JSON files (config/data/log).
|
||||
"""
|
||||
|
||||
MAX_LOG_ENTRIES = 100
|
||||
|
||||
def __init__(self, json_dir: Path):
|
||||
self._json_dir = Path(json_dir)
|
||||
|
||||
@staticmethod
|
||||
def read_json(file_path: Path) -> Optional[dict]:
|
||||
"""Read and parse a JSON file.
|
||||
|
||||
Args:
|
||||
file_path: Path to the JSON file.
|
||||
|
||||
Returns:
|
||||
Parsed dict, or None on failure.
|
||||
"""
|
||||
try:
|
||||
return json.loads(Path(file_path).read_text(encoding="utf-8"))
|
||||
except (json.JSONDecodeError, FileNotFoundError) as e:
|
||||
logger.warning("Failed to read JSON from %s: %s", file_path, e)
|
||||
return None
|
||||
|
||||
@staticmethod
|
||||
def write_json(file_path: Path, data: Any, indent: int = 2) -> bool:
|
||||
"""Write data to a JSON file atomically (temp file + os.replace).
|
||||
|
||||
Args:
|
||||
file_path: Target path.
|
||||
data: JSON-serializable data.
|
||||
indent: JSON indentation level.
|
||||
|
||||
Returns:
|
||||
True on success, False on OS error.
|
||||
"""
|
||||
file_path = Path(file_path)
|
||||
try:
|
||||
file_path.parent.mkdir(parents=True, exist_ok=True)
|
||||
content = json.dumps(data, indent=indent) + "\n"
|
||||
fd, tmp_path = tempfile.mkstemp(dir=file_path.parent, suffix=".tmp")
|
||||
closed = False
|
||||
try:
|
||||
os.write(fd, content.encode("utf-8"))
|
||||
os.fsync(fd)
|
||||
os.close(fd)
|
||||
closed = True
|
||||
os.replace(tmp_path, file_path)
|
||||
except BaseException:
|
||||
if not closed:
|
||||
os.close(fd)
|
||||
if os.path.exists(tmp_path):
|
||||
os.unlink(tmp_path)
|
||||
raise
|
||||
return True
|
||||
except OSError as e:
|
||||
logger.error("Failed to write JSON to %s: %s", file_path, e)
|
||||
return False
|
||||
|
||||
@staticmethod
|
||||
def validate_json_structure(data: Any, json_type: str) -> bool:
|
||||
"""Validate that data matches the expected shape for json_type.
|
||||
|
||||
Args:
|
||||
data: Parsed JSON data to validate.
|
||||
json_type: One of "config", "data", "log".
|
||||
|
||||
Returns:
|
||||
True when the structure is valid, False otherwise.
|
||||
"""
|
||||
if json_type == "config":
|
||||
if not isinstance(data, dict):
|
||||
return False
|
||||
return all(key in data for key in ("module_name", "version", "config"))
|
||||
if json_type == "data":
|
||||
if not isinstance(data, dict):
|
||||
return False
|
||||
return all(key in data for key in ("created", "last_updated"))
|
||||
if json_type == "log":
|
||||
return isinstance(data, list)
|
||||
return False
|
||||
|
||||
@staticmethod
|
||||
def _create_default(json_type: str, module_name: str) -> Any:
|
||||
"""Return default content for a given JSON type.
|
||||
|
||||
Args:
|
||||
json_type: One of "config", "data", "log".
|
||||
module_name: Logical module name.
|
||||
|
||||
Returns:
|
||||
Default data structure.
|
||||
|
||||
Raises:
|
||||
ValueError: For unknown json_type.
|
||||
"""
|
||||
today = datetime.now().date().isoformat()
|
||||
if json_type == "config":
|
||||
return {
|
||||
"module_name": module_name,
|
||||
"version": "1.0.0",
|
||||
"config": {
|
||||
"max_log_entries": JsonHandler.MAX_LOG_ENTRIES,
|
||||
},
|
||||
"created": today,
|
||||
"last_updated": today,
|
||||
}
|
||||
if json_type == "data":
|
||||
return {
|
||||
"created": today,
|
||||
"last_updated": today,
|
||||
}
|
||||
if json_type == "log":
|
||||
return []
|
||||
raise ValueError(f"Unknown json_type: {json_type!r}")
|
||||
|
||||
def get_json_path(self, module_name: str, json_type: str) -> Path:
|
||||
"""Return the filesystem path for a module's JSON file.
|
||||
|
||||
Args:
|
||||
module_name: Logical module name.
|
||||
json_type: One of "config", "data", "log".
|
||||
|
||||
Returns:
|
||||
Absolute Path to the JSON file.
|
||||
"""
|
||||
return self._json_dir / f"{module_name}_{json_type}.json"
|
||||
|
||||
def ensure_json_exists(self, module_name: str, json_type: str) -> bool:
|
||||
"""Ensure a single JSON file exists; create with defaults if missing.
|
||||
|
||||
If the file exists but fails validation it is regenerated.
|
||||
|
||||
Args:
|
||||
module_name: Logical module name.
|
||||
json_type: One of "config", "data", "log".
|
||||
|
||||
Returns:
|
||||
True after the file is confirmed present and valid.
|
||||
"""
|
||||
self._json_dir.mkdir(parents=True, exist_ok=True)
|
||||
json_path = self.get_json_path(module_name, json_type)
|
||||
|
||||
if json_path.exists():
|
||||
try:
|
||||
if json_path.stat().st_size == 0:
|
||||
logger.warning("ensure_json_exists: empty file at %s, regenerating", json_path)
|
||||
else:
|
||||
data = json.loads(json_path.read_text(encoding="utf-8"))
|
||||
if self.validate_json_structure(data, json_type):
|
||||
return True
|
||||
except Exception as exc:
|
||||
logger.warning("ensure_json_exists: failed to read %s, regenerating: %s", json_path, exc)
|
||||
|
||||
default = self._create_default(json_type, module_name)
|
||||
self.write_json(json_path, default)
|
||||
return True
|
||||
|
||||
def ensure_module_jsons(self, module_name: str) -> bool:
|
||||
"""Ensure all three JSON files (config, data, log) exist for a module.
|
||||
|
||||
Args:
|
||||
module_name: Logical module name.
|
||||
|
||||
Returns:
|
||||
True when all files are present and valid.
|
||||
"""
|
||||
for json_type in _JSON_TYPES:
|
||||
self.ensure_json_exists(module_name, json_type)
|
||||
return True
|
||||
|
||||
def load_json(self, module_name: str, json_type: str) -> Any | None:
|
||||
"""Load a module's JSON file, auto-creating it if missing.
|
||||
|
||||
Args:
|
||||
module_name: Logical module name.
|
||||
json_type: One of "config", "data", "log".
|
||||
|
||||
Returns:
|
||||
Parsed JSON data, or None on failure.
|
||||
"""
|
||||
if not self.ensure_json_exists(module_name, json_type):
|
||||
return None
|
||||
|
||||
json_path = self.get_json_path(module_name, json_type)
|
||||
try:
|
||||
return json.loads(json_path.read_text(encoding="utf-8"))
|
||||
except (json.JSONDecodeError, OSError) as exc:
|
||||
logger.warning("load_json: failed to read %s: %s", json_path, exc)
|
||||
return self._create_default(json_type, module_name)
|
||||
|
||||
def save_json(self, module_name: str, json_type: str, data: Any) -> bool:
|
||||
"""Write data to a module's JSON file after validation.
|
||||
|
||||
For "data" type files the last_updated field is refreshed automatically.
|
||||
|
||||
Args:
|
||||
module_name: Logical module name.
|
||||
json_type: One of "config", "data", "log".
|
||||
data: The data structure to persist.
|
||||
|
||||
Returns:
|
||||
True on success.
|
||||
|
||||
Raises:
|
||||
ValueError: When data fails structure validation.
|
||||
"""
|
||||
if not self.validate_json_structure(data, json_type):
|
||||
raise ValueError(f"Invalid structure for {json_type} JSON")
|
||||
|
||||
if json_type == "data" and isinstance(data, dict):
|
||||
data["last_updated"] = datetime.now().date().isoformat()
|
||||
|
||||
json_path = self.get_json_path(module_name, json_type)
|
||||
return self.write_json(json_path, data)
|
||||
|
||||
def log_operation(self, operation: str, data: Dict[str, Any] | None = None, module_name: str | None = None) -> bool:
|
||||
"""Add entry to module operation log with automatic rotation.
|
||||
|
||||
Auto-detects calling module if module_name not provided.
|
||||
|
||||
Args:
|
||||
operation: Operation name to log.
|
||||
data: Optional data dict.
|
||||
module_name: Optional module name (auto-detected if not provided).
|
||||
|
||||
Returns:
|
||||
True if successful, False otherwise.
|
||||
"""
|
||||
if module_name is None:
|
||||
module_name = _get_caller_module_name()
|
||||
|
||||
try:
|
||||
self.ensure_module_jsons(module_name)
|
||||
|
||||
log = self.load_json(module_name, "log")
|
||||
if log is None:
|
||||
log = []
|
||||
|
||||
entry: Dict[str, Any] = {
|
||||
"timestamp": datetime.now().isoformat(),
|
||||
"operation": operation,
|
||||
}
|
||||
if data:
|
||||
entry["data"] = data
|
||||
|
||||
log.append(entry)
|
||||
|
||||
if len(log) > self.MAX_LOG_ENTRIES:
|
||||
log = log[-self.MAX_LOG_ENTRIES :]
|
||||
|
||||
return self.save_json(module_name, "log", log)
|
||||
except Exception as exc:
|
||||
logger.warning("log_operation: failed for %s/%s: %s", module_name, operation, exc)
|
||||
return False
|
||||
|
||||
|
||||
def _get_caller_module_name() -> str:
|
||||
"""Auto-detect calling module name from call stack."""
|
||||
stack = inspect.stack()
|
||||
if len(stack) > 2:
|
||||
caller_path = Path(stack[2].filename)
|
||||
module_name = caller_path.stem
|
||||
if module_name and not module_name.startswith("_"):
|
||||
return module_name
|
||||
return "unknown"
|
||||
@@ -0,0 +1,115 @@
|
||||
# =================== AIPass ====================
|
||||
# Name: json_ops.py
|
||||
# Description: Shared JSON operations — deep merge and backup
|
||||
# Version: 1.0.0
|
||||
# Created: 2026-06-06
|
||||
# Modified: 2026-06-06
|
||||
# =============================================
|
||||
|
||||
"""Shared JSON operations — deep merge and backup utilities.
|
||||
|
||||
Dependency-free: uses only stdlib. Importable before drone/prax exist.
|
||||
"""
|
||||
|
||||
import logging
|
||||
import shutil
|
||||
from datetime import datetime
|
||||
from pathlib import Path
|
||||
from typing import Any
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
def deep_merge(template_data: Any, existing_data: Any) -> Any:
|
||||
"""Recursively merge template structure with existing data.
|
||||
|
||||
Merge strategy:
|
||||
- Both dicts: merge keys. Template defines structure, existing fills values.
|
||||
- Template has key that existing doesn't: add from template (default).
|
||||
- Existing has key that template doesn't: KEEP existing key (don't prune).
|
||||
- Both lists: keep existing list (don't overwrite user data).
|
||||
- Scalar values: keep existing value (don't overwrite).
|
||||
- If existing is None/empty but template has value: use template value.
|
||||
|
||||
Args:
|
||||
template_data: Template structure (provides fields and defaults).
|
||||
existing_data: Existing data (provides values to preserve).
|
||||
|
||||
Returns:
|
||||
Merged result combining template structure with existing values.
|
||||
"""
|
||||
if existing_data is None:
|
||||
return template_data
|
||||
|
||||
if template_data is None:
|
||||
return existing_data
|
||||
|
||||
if isinstance(template_data, dict) and isinstance(existing_data, dict):
|
||||
result = {}
|
||||
|
||||
for key in template_data:
|
||||
if key in existing_data:
|
||||
result[key] = deep_merge(template_data[key], existing_data[key])
|
||||
else:
|
||||
result[key] = template_data[key]
|
||||
|
||||
for key in existing_data:
|
||||
if key not in result:
|
||||
result[key] = existing_data[key]
|
||||
|
||||
return result
|
||||
|
||||
if isinstance(template_data, list) and isinstance(existing_data, list):
|
||||
if len(existing_data) > 0:
|
||||
return existing_data
|
||||
if len(template_data) > 0:
|
||||
return template_data
|
||||
return []
|
||||
|
||||
if existing_data is not None:
|
||||
if isinstance(existing_data, str) and existing_data == "" and template_data:
|
||||
return template_data
|
||||
return existing_data
|
||||
|
||||
return template_data
|
||||
|
||||
|
||||
def backup_json(file_path: Path, backup_dir: Path | None = None) -> Path:
|
||||
"""Create a timestamped backup of a JSON file.
|
||||
|
||||
By default the backup is placed in a ``.recovery/`` directory alongside the
|
||||
file. Callers can override with ``backup_dir`` to consolidate backups
|
||||
elsewhere (e.g. ``.spawn/.recovery/``).
|
||||
|
||||
Args:
|
||||
file_path: Path to the JSON file to back up.
|
||||
backup_dir: Optional override for the backup destination directory.
|
||||
Defaults to ``file_path.parent / ".recovery"``.
|
||||
|
||||
Returns:
|
||||
Path to the backup file.
|
||||
|
||||
Raises:
|
||||
FileNotFoundError: If the source file doesn't exist.
|
||||
IOError: If the backup copy fails.
|
||||
"""
|
||||
file_path = Path(file_path)
|
||||
|
||||
if not file_path.exists():
|
||||
raise FileNotFoundError(f"Cannot backup — file not found: {file_path}")
|
||||
|
||||
if backup_dir is None:
|
||||
backup_dir = file_path.parent / ".recovery"
|
||||
backup_dir = Path(backup_dir)
|
||||
backup_dir.mkdir(parents=True, exist_ok=True)
|
||||
|
||||
timestamp = datetime.now().strftime("%Y%m%d_%H%M%S")
|
||||
backup_name = f"{file_path.name}.{timestamp}.backup"
|
||||
backup_path = backup_dir / backup_name
|
||||
|
||||
try:
|
||||
shutil.copy2(file_path, backup_path)
|
||||
return backup_path
|
||||
except (IOError, OSError) as exc:
|
||||
logger.error("Backup failed for %s: %s", file_path.name, exc)
|
||||
raise
|
||||
@@ -0,0 +1,67 @@
|
||||
# =================== AIPass ====================
|
||||
# Name: registry_discovery.py
|
||||
# Description: Shared registry file discovery (walk-up search)
|
||||
# Version: 1.0.0
|
||||
# Created: 2026-06-06
|
||||
# Modified: 2026-06-06
|
||||
# =============================================
|
||||
|
||||
"""Registry discovery — find *_REGISTRY.json by walking up the directory tree.
|
||||
|
||||
Dependency-free: uses only stdlib. Importable before drone/prax exist.
|
||||
"""
|
||||
|
||||
import os
|
||||
from pathlib import Path
|
||||
|
||||
|
||||
def _glob_registry(directory):
|
||||
"""Find *_REGISTRY.json in a single directory.
|
||||
|
||||
Args:
|
||||
directory: Path to search in.
|
||||
|
||||
Returns:
|
||||
Path to the registry file, or None if not found.
|
||||
"""
|
||||
matches = sorted(directory.glob("*_REGISTRY.json"))
|
||||
return matches[0] if matches else None
|
||||
|
||||
|
||||
def find_registry(start_path=None, package_root=None):
|
||||
"""Find *_REGISTRY.json — walks up from start_path/cwd, then package_root.
|
||||
|
||||
The first *_REGISTRY.json found while walking up IS the project boundary.
|
||||
If multiple exist in the same directory, picks the first alphabetically.
|
||||
|
||||
Priority:
|
||||
1. AIPASS_REGISTRY environment variable
|
||||
2. Walk up from start_path/cwd — first dir containing *_REGISTRY.json
|
||||
3. Walk up from package_root (caller's __file__ location) — fallback
|
||||
4. Last resort: cwd / AIPASS_REGISTRY.json (backwards compat)
|
||||
|
||||
Args:
|
||||
start_path: Directory to start searching from (default: cwd).
|
||||
package_root: Optional fallback directory for package-relative search.
|
||||
|
||||
Returns:
|
||||
Path to *_REGISTRY.json.
|
||||
"""
|
||||
env_path = os.environ.get("AIPASS_REGISTRY")
|
||||
if env_path:
|
||||
return Path(env_path)
|
||||
|
||||
current = Path(start_path).resolve() if start_path else Path.cwd()
|
||||
for parent in [current] + list(current.parents):
|
||||
found = _glob_registry(parent)
|
||||
if found:
|
||||
return found
|
||||
|
||||
if package_root:
|
||||
pkg_dir = Path(package_root).resolve()
|
||||
for parent in [pkg_dir] + list(pkg_dir.parents):
|
||||
found = _glob_registry(parent)
|
||||
if found:
|
||||
return found
|
||||
|
||||
return Path.cwd() / "AIPASS_REGISTRY.json"
|
||||
@@ -1,6 +1,6 @@
|
||||
# DEVPULSE — Branch Prompt
|
||||
|
||||
Injected every turn. Breadcrumbs only — details in README, --help, .trinity/, STATUS.local.md.
|
||||
Injected every turn. Breadcrumbs only — details in README, --help, .trinity/, DASHBOARD.local.json.
|
||||
|
||||
## Identity
|
||||
|
||||
@@ -9,7 +9,7 @@ DEVPULSE — Patrick's primary AI collaborator, orchestration hub. Design, plan,
|
||||
## How You Work
|
||||
|
||||
- DRONE FOR EVERYTHING. Never raw git, gh, or python -m. `drone` is on PATH — run it directly. No which, no path lookup, no verification. Just `drone @git ...`, `drone @flow ...`, `drone @ai_mail ...`. If blocked, drone is the fix — not a workaround.
|
||||
- Build own directly: modules, DPLANs, FPLANs, memories, STATUS — yours, edit freely.
|
||||
- Build own directly: modules, DPLANs, FPLANs, memories — yours, edit freely.
|
||||
- Prototype to explore shape, hand real build to sub-agent.
|
||||
- Investigate other branches freely: read, debug, test, fix small bugs. CWD stays devpulse.
|
||||
- Full multi-file implementations → `drone @ai_mail dispatch @branch`.
|
||||
@@ -35,9 +35,15 @@ Task belongs to specialist domain → ask them. Investigate/fix small things you
|
||||
| User onboarding, init | @aipass | Concierge, aipass init, doctor, scanner |
|
||||
| Hooks, engine, gates | @hooks | Hook engine, bridges, per-project config, sound |
|
||||
|
||||
## Git — Dev Branch, Drone Only, You Are Gatekeeper
|
||||
## Git — Dev Branch, You Are Gatekeeper
|
||||
|
||||
Only branch with git write access. All git/gh blocked at project level. Drone bypasses via subprocess — tier system grants write to devpulse only.
|
||||
Only branch with git WRITE access. WRITE git (commit, push, checkout, merge, reset, rebase, clean, pull, fetch, tag, branch -D, clone, worktree…) is blocked raw → use `drone @git` (tier grants write to devpulse only).
|
||||
|
||||
**READ git is allowed RAW** (S193, git_gate read allowlist) — just run it, no drone needed. Use this for investigation/forensics instead of reaching for drone or `find` fallbacks:
|
||||
- Allowed verbs: `ls-files, ls-tree, show, cat-file, rev-parse, rev-list, log, status, diff, blame, describe, for-each-ref, show-ref, symbolic-ref, shortlog, grep, archive, count-objects, var, help, version`.
|
||||
- NOT yet allowed (gap, S193): `check-ignore` → use `git ls-files <path>` (empty = ignored/untracked) or read `.gitignore` directly.
|
||||
- Reproduce a clean checkout (tracked-only, like CI): `git archive HEAD | tar -x -C /tmp/<dir>` (`drone rm` the dir first; `rm -rf` is gated).
|
||||
- Chained read+write blocks the whole command (e.g. `git log && git push` → blocked). Keep read and write in separate invocations.
|
||||
|
||||
Three rules:
|
||||
1. Work on dev, merge to main when satisfied. `drone @git merge dev` squash-merges.
|
||||
@@ -91,7 +97,7 @@ drone, seedgo, prax, cli, ai_mail, api, flow, spawn, trigger, memory, aipass, ho
|
||||
|
||||
- Lean on branches for expertise. Email for architecture questions. Investigate/debug/test freely.
|
||||
- Use memories freely. Rollover to @memory by design. Update .trinity/ often.
|
||||
- STATUS.local.md Notepad for friction notes. Address in batches.
|
||||
- local.json todos[] for friction notes. Address in batches.
|
||||
- Own things → build directly. Heavy refactors → delegate sub-agent.
|
||||
- CWD = identity. Visit other branches, don't move in.
|
||||
- Git awareness: after completing work, `drone @git status`. Suggest commit if coherent. Don't force, don't let pile up.
|
||||
@@ -122,10 +128,10 @@ Find agent via `.trinity/passport.json`. Use `dangerouslyDisableSandbox: true`.
|
||||
|
||||
## Memory & Tracking
|
||||
|
||||
- `.trinity/local.json` — session history, key learnings
|
||||
- `.trinity/local.json` — session history, key learnings, todos[]
|
||||
- `.trinity/observations.json` — collaboration patterns
|
||||
- `STATUS.local.md` — current work, issues, todos, notepad. Feeds central STATUS.md.
|
||||
- `DASHBOARD.local.json` — live state glance (refreshed by prax)
|
||||
|
||||
Update proactively — after milestones, /memo, topic shifts, 5+ actions without saving.
|
||||
|
||||
This prompt = lightweight signposts. State → .trinity/ + STATUS.local.md.
|
||||
This prompt = lightweight signposts. State → .trinity/ + DASHBOARD.local.json.
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
# DevPulse
|
||||
|
||||
> Orchestration hub for AIPass. The user's primary AI collaborator — designs, plans, debugs, coordinates all 11 branches, and builds its own modules.
|
||||
> Orchestration hub for AIPass. The user's primary AI collaborator — designs, plans, debugs, coordinates all 12 other branches, and builds its own modules.
|
||||
|
||||
DevPulse handles the day-to-day: working with the user to plan, design, troubleshoot, and adjust. It builds its own modules directly (watchdog, feedback, json_handler), manages all git operations for the project, dispatches heavy multi-file builds to sub-agents, and ventures into other branches to investigate, debug, and fix small bugs. The only branch with git write access.
|
||||
|
||||
@@ -10,7 +10,7 @@ DevPulse handles the day-to-day: working with the user to plan, design, troubles
|
||||
|
||||
| You want to | Read |
|
||||
|---|---|
|
||||
| What's happening right now | [STATUS.local.md](STATUS.local.md) |
|
||||
| What's happening right now | `DASHBOARD.local.json` |
|
||||
| Identity, memory, session history | [`.trinity/`](.trinity/) |
|
||||
| Active plans | `drone @flow list open` |
|
||||
| Branch list | `drone systems` |
|
||||
@@ -42,11 +42,11 @@ src/aipass/devpulse/
|
||||
│ │ └── watchdog/ # Agent, timer, schedule, registry
|
||||
│ └── plugins/ # Plugin extension point
|
||||
├── devpulse_json/ # JSON handler storage (config, data, logs per module)
|
||||
├── tests/ # 252 tests
|
||||
├── tests/ # 236 tests
|
||||
├── artifacts/ # Birth certificate, reports
|
||||
├── dropbox/ # Received files, archived plans, install audit
|
||||
├── docs/ # Transition notes
|
||||
└── STATUS.local.md # Current work beacon
|
||||
└── DASHBOARD.local.json # Live state (refreshed by prax)
|
||||
```
|
||||
|
||||
## Commands
|
||||
@@ -107,7 +107,7 @@ drone @git log # Recent commits
|
||||
|
||||
All branches via dispatch orchestration. Watchdog monitoring for any dispatched agent. Feedback channel for cross-branch communication. Git operations (commit, PR, merge) for the entire project.
|
||||
|
||||
*Last Updated: 2026-05-16*
|
||||
*Last Updated: 2026-06-05*
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -1,225 +0,0 @@
|
||||
[← Back to DevPulse](README.md)
|
||||
|
||||
# DevPulse Setup, Uninstall, Troubleshooting
|
||||
|
||||
Everything you need to install, run, maintain, or remove DevPulse (and AIPass as a whole). Kept here so the DevPulse README can stay lean and loads quickly on every session startup.
|
||||
|
||||
---
|
||||
|
||||
## Platform support at a glance
|
||||
|
||||
| Platform | Install status | Notes |
|
||||
|---|---|---|
|
||||
| **Linux** (Ubuntu, Debian, Fedora, Arch) | Supported | Primary development target. `setup.sh` works out of the box. |
|
||||
| **macOS** (Intel and Apple Silicon) | Supported | `setup.sh` works with minor caveats (see macOS section). |
|
||||
| **Windows 10 / 11** | **In progress** | Native Windows support is actively being built. Track progress in [issue #261](https://github.com/AIOSAI/AIPass/issues/261). For now: use WSL2 (Ubuntu), or wait for the cross-platform `setup.py` landing in a PR soon. |
|
||||
|
||||
---
|
||||
|
||||
## Linux install
|
||||
|
||||
### Requirements
|
||||
|
||||
- Python 3.10 or newer (`python3 --version`)
|
||||
- `git`, `bash`, `sudo`
|
||||
- Claude Code CLI installed and authenticated (`claude --version`)
|
||||
- ~500 MB disk for the venv and dependencies
|
||||
|
||||
### Install
|
||||
|
||||
```bash
|
||||
git clone https://github.com/AIOSAI/AIPass.git ~/Projects/AIPass
|
||||
cd ~/Projects/AIPass
|
||||
bash setup.sh
|
||||
```
|
||||
|
||||
`setup.sh` will:
|
||||
1. Create a Python venv at `.venv/`
|
||||
2. Install AIPass in editable mode (`pip install -e .`)
|
||||
3. Verify the `drone` and `aipass` CLI entry points
|
||||
4. Create `~/.secrets/aipass/` with `chmod 700` and seed an `.env.example`
|
||||
5. Generate the AIPass branch registry
|
||||
6. Bootstrap branch identity files (`.trinity/passport.json` per branch)
|
||||
7. Wire Claude Code hooks into `~/.claude/settings.json`
|
||||
8. Create a global symlink at `/usr/local/bin/drone` (asks for `sudo`)
|
||||
|
||||
### Post-install
|
||||
|
||||
```bash
|
||||
# Verify
|
||||
drone systems
|
||||
|
||||
# Enter the DevPulse branch
|
||||
cd ~/Projects/AIPass/src/aipass/devpulse
|
||||
claude
|
||||
```
|
||||
|
||||
You should see DevPulse greet you, read its memory, and be ready.
|
||||
|
||||
### Optional
|
||||
|
||||
- Add API keys to `~/.secrets/aipass/.env` if you want LLM routing beyond Claude Code
|
||||
- Set `AIPASS_HOME=~/Projects/AIPass` in your shell rc if you plan to use AIPass from other projects
|
||||
- Add `export AIPASS_HOME=~/Projects/AIPass` to `~/.bashrc` **and** `~/.claude/settings.json` (the `env` section) — both are needed for full cross-project access
|
||||
|
||||
---
|
||||
|
||||
## macOS install
|
||||
|
||||
Same as Linux. `setup.sh` uses bash and runs on macOS out of the box.
|
||||
|
||||
**Caveats**:
|
||||
- `chmod 700` and `chown` work correctly on macOS's HFS+ and APFS
|
||||
- `sudo ln -sf /usr/local/bin/drone` works but may prompt for your admin password
|
||||
- Homebrew users: if you have multiple Python installs, make sure `python3` points to Python 3.10+ before running `setup.sh`
|
||||
|
||||
---
|
||||
|
||||
## Windows install
|
||||
|
||||
**Short version**: use [WSL2](https://learn.microsoft.com/en-us/windows/wsl/install) (Ubuntu) and follow the Linux instructions. Full native Windows support is landing in a PR soon — follow [issue #261](https://github.com/AIOSAI/AIPass/issues/261) for status.
|
||||
|
||||
**Why it's in progress**: the current `setup.sh` uses bash, `sudo`, and `ln -sf /usr/local/bin/drone`, none of which translate to Windows. The `aipass init` command also writes a shell loop into `.claude/settings.json` that assumes Unix root `/`. Fixes are in flight:
|
||||
- A cross-platform `setup.py` that replaces `setup.sh` on Windows
|
||||
- A Python-based directory traversal replacing the bash loop in `aipass init`
|
||||
- OS detection in `setup.sh` to skip the symlink step on Windows and print PATH instructions instead
|
||||
|
||||
**Interim workaround**: install WSL2 with an Ubuntu distribution, then clone and run `setup.sh` inside WSL. Claude Code also runs well inside WSL.
|
||||
|
||||
---
|
||||
|
||||
## Uninstall
|
||||
|
||||
### Full removal (Linux / macOS)
|
||||
|
||||
```bash
|
||||
# 1. Remove the venv and repo
|
||||
rm -rf ~/Projects/AIPass
|
||||
|
||||
# 2. Remove the global drone symlink
|
||||
sudo rm /usr/local/bin/drone
|
||||
|
||||
# 3. Remove secrets (if you won't reinstall)
|
||||
rm -rf ~/.secrets/aipass
|
||||
|
||||
# 4. Clean Claude Code hooks
|
||||
# Edit ~/.claude/settings.json and remove any "hooks" sections that reference AIPass paths.
|
||||
# Safer: back up the file first.
|
||||
cp ~/.claude/settings.json ~/.claude/settings.json.bak
|
||||
nano ~/.claude/settings.json # or your editor of choice
|
||||
|
||||
# 5. Clean your shell rc
|
||||
# Remove any AIPASS_HOME export from ~/.bashrc, ~/.zshrc, etc.
|
||||
```
|
||||
|
||||
### Partial removal (keeping secrets for reinstall)
|
||||
|
||||
Skip step 3 above. Your `~/.secrets/aipass/.env` will persist and be reused on next install.
|
||||
|
||||
### Windows (WSL2)
|
||||
|
||||
Same as Linux, inside the WSL distribution. To also remove the WSL distribution itself: `wsl --unregister Ubuntu` from PowerShell.
|
||||
|
||||
---
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### `drone: command not found`
|
||||
|
||||
Your venv is not activated or the `/usr/local/bin/drone` symlink is missing.
|
||||
|
||||
```bash
|
||||
# Option A: activate the venv
|
||||
source ~/Projects/AIPass/.venv/bin/activate
|
||||
drone systems
|
||||
|
||||
# Option B: run via full path
|
||||
~/Projects/AIPass/.venv/bin/drone systems
|
||||
|
||||
# Option C: reinstall the symlink
|
||||
sudo ln -sf ~/Projects/AIPass/.venv/bin/drone /usr/local/bin/drone
|
||||
```
|
||||
|
||||
### `AIPASS_HOME not set` warnings
|
||||
|
||||
```bash
|
||||
# In your shell rc (~/.bashrc or ~/.zshrc)
|
||||
export AIPASS_HOME=~/Projects/AIPass
|
||||
|
||||
# Then restart the shell or:
|
||||
source ~/.bashrc
|
||||
```
|
||||
|
||||
Also add it to `~/.claude/settings.json` under the `env` block for Claude Code sessions to pick it up.
|
||||
|
||||
### DevPulse greets you but doesn't read its memory
|
||||
|
||||
Check that `.trinity/passport.json`, `.trinity/local.json`, and `.trinity/observations.json` exist in `src/aipass/devpulse/`. If they don't, run `bash setup.sh` again to re-bootstrap the identity files.
|
||||
|
||||
### `drone @git system-pr` fails with a lock error
|
||||
|
||||
```bash
|
||||
drone @git lock # check the lock state
|
||||
drone @git fix # attempt to fix broken git state
|
||||
```
|
||||
|
||||
Do NOT use raw `git reset --hard` — merge conflicts are easier to resolve than lost work.
|
||||
|
||||
### Branch mail not arriving
|
||||
|
||||
```bash
|
||||
drone @ai_mail inbox # check your inbox
|
||||
drone @prax watch # watch the monitoring dashboard
|
||||
```
|
||||
|
||||
A known issue at the end of S90 affected wake delivery; see the wake investigation in DPLAN-0125 Track E if you're running a recent build.
|
||||
|
||||
### Tests fail on a fresh clone
|
||||
|
||||
```bash
|
||||
cd ~/Projects/AIPass
|
||||
source .venv/bin/activate
|
||||
python -m pytest src/aipass/<branch>/tests/
|
||||
```
|
||||
|
||||
If tests fail because `AIPASS_HOME` leaks the real registry into test results, that's a known pattern — the tests need `monkeypatch.delenv("AIPASS_HOME")`. See S90 notes for the fixture pattern.
|
||||
|
||||
### `.claude/settings.json` has hardcoded absolute paths
|
||||
|
||||
You pulled an old clone. The hardcoded paths were removed in commit `867dad0` (April 5, 2026). Pull the latest main and re-run `setup.sh`, which generates the settings dynamically from your local repo root.
|
||||
|
||||
---
|
||||
|
||||
## Environment variables
|
||||
|
||||
| Variable | Purpose | Set where |
|
||||
|---|---|---|
|
||||
| `AIPASS_HOME` | Lets external projects find the AIPass registry | `~/.bashrc` + `~/.claude/settings.json` env block |
|
||||
| `AIPASS_CALLER_BRANCH` | Auto-set by dispatch; identifies the sending branch for feedback/mail | Runtime only, do not set manually |
|
||||
| `AIPASS_CALLER_CWD` | Auto-set by dispatch; identifies the caller's project directory | Runtime only, do not set manually |
|
||||
|
||||
Sensitive values (API keys, tokens, recovery codes) belong in `~/.secrets/aipass/.env`, not in shell rc or repo files.
|
||||
|
||||
---
|
||||
|
||||
## Reporting bugs
|
||||
|
||||
File issues at https://github.com/AIOSAI/AIPass/issues.
|
||||
|
||||
Helpful info to include:
|
||||
- OS and version
|
||||
- Python version (`python3 --version`)
|
||||
- Claude Code version (`claude --version`)
|
||||
- The exact command you ran and the full error output
|
||||
- Whether you cloned recently or have been on the same checkout for a while (clone age helps us distinguish current bugs from fixed-but-stale-clone issues)
|
||||
|
||||
The first external bug report was [#261 by Gavin Rooney](https://github.com/AIOSAI/AIPass/issues/261) — that template is a good example of a useful report.
|
||||
|
||||
---
|
||||
|
||||
## See also
|
||||
|
||||
- [DevPulse README](README.md) — the lean entry point
|
||||
- [AIPass root README](../../../README.md) — the whole framework
|
||||
- [STATUS.local.md](STATUS.local.md) — current work and loose ends
|
||||
- [issue #261](https://github.com/AIOSAI/AIPass/issues/261) — Windows compat tracking
|
||||
@@ -319,7 +319,7 @@ def _classify_exit(
|
||||
def watch_agent(
|
||||
agent_id: str,
|
||||
timeout_seconds: int = 600,
|
||||
poll_interval: float = 2.0,
|
||||
poll_interval: float = 5.0,
|
||||
) -> dict:
|
||||
"""Block until the dispatched agent at `agent_id` exits.
|
||||
|
||||
@@ -327,7 +327,10 @@ def watch_agent(
|
||||
agent_id: Branch token like ``@drone`` (or bare ``drone``).
|
||||
timeout_seconds: Maximum wait. Default 10 min — catches crashes + silent-finishes
|
||||
fast; long agent watches should pass an explicit ``--timeout``.
|
||||
poll_interval: Seconds between checks. Default 2.0.
|
||||
poll_interval: Seconds between checks. Default 5.0 — the per-tick work (lock
|
||||
stat, PID liveness, one-dir JSONL size scan) is cheap, so a tight cadence
|
||||
just burns CPU. 5s keeps completion latency invisible on multi-minute
|
||||
dispatches while the 120s stall threshold has ample resolution.
|
||||
|
||||
Returns:
|
||||
dict with keys: woke, reason, elapsed, agent_state, exit_code, agent_id.
|
||||
|
||||
@@ -50,11 +50,11 @@ HELP_TEXT = """\
|
||||
def print_introspection() -> None:
|
||||
"""Display module introspection info."""
|
||||
console.print()
|
||||
console.print("feedback Module")
|
||||
console.print("DevPulse personal feedback mailbox. Receives cross-project")
|
||||
console.print("feedback messages from any agent via drone routing.")
|
||||
console.print("[bold cyan]feedback Module[/bold cyan]")
|
||||
console.print("[dim]DevPulse personal feedback mailbox. Receives cross-project[/dim]")
|
||||
console.print("[dim]feedback messages from any agent via drone routing.[/dim]")
|
||||
console.print()
|
||||
console.print("Subcommands: inbox, view, reply, send, clear")
|
||||
console.print("[yellow]Subcommands:[/yellow] [cyan]inbox, view, reply, send, clear[/cyan]")
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -97,18 +97,18 @@ Examples:
|
||||
def print_introspection() -> None:
|
||||
"""Display module introspection info."""
|
||||
console.print()
|
||||
console.print("watchdog Module")
|
||||
console.print("Devpulse-local directed wake system. Wakes devpulse when a")
|
||||
console.print("watched condition fires (agent exit, timer, schedule).")
|
||||
console.print("[bold cyan]watchdog Module[/bold cyan]")
|
||||
console.print("[dim]Devpulse-local directed wake system. Wakes devpulse when a[/dim]")
|
||||
console.print("[dim]watched condition fires (agent exit, timer, schedule).[/dim]")
|
||||
console.print()
|
||||
console.print("Subcommands:")
|
||||
console.print("[yellow]Subcommands:[/yellow]")
|
||||
for sub in _VALID_SUBCOMMANDS:
|
||||
marker = "active" if sub in ("agent", "status") else f"phase {_PHASE_BY_SUB.get(sub, '?')}"
|
||||
console.print(f" {sub:<10} ({marker})")
|
||||
console.print(f" [cyan]{sub:<10}[/cyan] [dim]({marker})[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/watchdog/")
|
||||
console.print(" - agent.py (watch_agent — block until dispatched agent exits)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/watchdog/[/cyan]")
|
||||
console.print(" [dim]- agent.py (watch_agent — block until dispatched agent exits)[/dim]")
|
||||
console.print()
|
||||
|
||||
|
||||
@@ -360,7 +360,8 @@ def _handle_agent(sub_args: List[str]) -> bool:
|
||||
if state == "completed_silent":
|
||||
console.print(
|
||||
f"watchdog: {agent_id} stopped (state={state}) -- CHECK DELIVERABLES. "
|
||||
f'Next: drone @ai_mail dispatch {agent_id} "check in" "You finished your last task but did not send a reply. '
|
||||
f'Next: drone @ai_mail dispatch {agent_id} "check in" '
|
||||
'"You finished your last task but did not send a reply. '
|
||||
f'Please reply with your results now via drone @ai_mail email @devpulse."'
|
||||
)
|
||||
elif state == "completed_replied":
|
||||
|
||||
@@ -0,0 +1,116 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# DPLAN-0194 — P1 cross-OS e2e wiring harness PROTOTYPE (Linux/Docker dev loop).
|
||||
# Runs INSIDE a clean container with the repo bind-mounted read-only at /repo.
|
||||
# Builds a wheel, installs into a CLEAN venv, then asserts the 4 tiers:
|
||||
# T0 install+binaries T1 aipass init scaffold T2a synthetic hook fire T3 drone routing
|
||||
# Tolerant: never exits on first failure — runs every assertion so we see the full red/green ladder.
|
||||
#
|
||||
set -uo pipefail
|
||||
|
||||
P=0; F=0
|
||||
ok(){ echo " ok $1"; P=$((P+1)); }
|
||||
no(){ echo " XX $1"; F=$((F+1)); }
|
||||
chk(){ if eval "$2" >/dev/null 2>&1; then ok "$1"; else no "$1"; fi; }
|
||||
hdr(){ echo; echo "=== $1 ==="; }
|
||||
|
||||
SRC=~/src
|
||||
BUILDENV=/tmp/buildenv
|
||||
CLEANENV=/tmp/cleanenv
|
||||
DIST=/tmp/dist
|
||||
PY=$CLEANENV/bin/python
|
||||
AIPASS=$CLEANENV/bin/aipass
|
||||
DRONE=$CLEANENV/bin/drone
|
||||
|
||||
hdr "SETUP — copy repo (writable), build wheel"
|
||||
rm -rf "$SRC" "$DIST" "$BUILDENV" "$CLEANENV"
|
||||
cp -r /repo "$SRC" 2>/dev/null || true # .trinity memory files are perm-restricted; harmless, code copies fine
|
||||
cd "$SRC"
|
||||
# A real fresh-clone runs setup.sh to GENERATE the registry (the host's AIPASS_REGISTRY.json
|
||||
# is mode 0600 and won't copy across uids anyway). Synthesize a minimal one pointing at the
|
||||
# copied branches — faithful to what setup.sh produces, lets Tier 3 prove routing plumbing.
|
||||
cat > "$SRC/AIPASS_REGISTRY.json" <<JSON
|
||||
{ "metadata": { "name": "AIPASS", "version": "1.0.0", "total_branches": 2 },
|
||||
"branches": [
|
||||
{ "name": "drone", "path": "$SRC/src/aipass/drone" },
|
||||
{ "name": "seedgo", "path": "$SRC/src/aipass/seedgo" }
|
||||
] }
|
||||
JSON
|
||||
python3 -m venv "$BUILDENV"
|
||||
"$BUILDENV/bin/pip" -q install --upgrade pip build 2>&1 | tail -2
|
||||
echo " building wheel..."
|
||||
"$BUILDENV/bin/python" -m build --wheel --outdir "$DIST" . 2>&1 | tail -4
|
||||
WHEEL=$(ls "$DIST"/*.whl 2>/dev/null | head -1)
|
||||
echo " wheel: ${WHEEL:-<NONE>}"
|
||||
|
||||
hdr "TIER 0 — clean-venv wheel install + binaries"
|
||||
python3 -m venv "$CLEANENV"
|
||||
if [ -n "${WHEEL:-}" ]; then
|
||||
"$CLEANENV/bin/pip" -q install "$WHEEL" 2>&1 | tail -3
|
||||
fi
|
||||
chk "wheel built" "[ -n '${WHEEL:-}' ]"
|
||||
chk "clean venv has pip (not silent-broken venv, #495)" "[ -x '$CLEANENV/bin/pip' ]"
|
||||
chk "aipass console_script installed" "[ -x '$AIPASS' ]"
|
||||
chk "drone console_script installed" "[ -x '$DRONE' ]"
|
||||
chk "drone --version runs" "'$DRONE' --version"
|
||||
chk "aipass entrypoint imports (aipass init --help)" "'$AIPASS' init --help"
|
||||
|
||||
hdr "TIER 1 — aipass init scaffolds correctly"
|
||||
PROJ=/tmp/proj; rm -rf "$PROJ"
|
||||
# AIPASS_HOME left UNSET on purpose: tests core scaffold independent of venv/templates,
|
||||
# and sidesteps the .venv symlink (the symlink bug is a Windows-only failure — N/A on Linux).
|
||||
"$AIPASS" init "$PROJ" demo > /tmp/init.out 2>&1
|
||||
echo " init exit=$? (see /tmp/init.out)"; tail -3 /tmp/init.out | sed 's/^/ | /'
|
||||
chk "DEMO_REGISTRY.json exists" "[ -f '$PROJ/DEMO_REGISTRY.json' ]"
|
||||
chk "DEMO_REGISTRY.json is valid JSON" "jq -e . '$PROJ/DEMO_REGISTRY.json'"
|
||||
chk "registry metadata.name == DEMO" "[ \"\$(jq -r .metadata.name '$PROJ/DEMO_REGISTRY.json')\" = DEMO ]"
|
||||
chk ".claude/settings.json exists" "[ -f '$PROJ/.claude/settings.json' ]"
|
||||
chk "settings deny has EnterPlanMode" "jq -e '.permissions.deny|index(\"EnterPlanMode\")' '$PROJ/.claude/settings.json'"
|
||||
chk "src/demo/__init__.py exists" "[ -f '$PROJ/src/demo/__init__.py' ]"
|
||||
chk ".gitignore mentions .venv" "grep -q '.venv' '$PROJ/.gitignore'"
|
||||
chk ".trinity/ NOT created (projects!=citizens)" "[ ! -e '$PROJ/.trinity' ]"
|
||||
chk "no passport.json created" "[ ! -e '$PROJ/.trinity/passport.json' ]"
|
||||
|
||||
hdr "TIER 2a — synthetic hook fire (module form, sentinel UUID, engine.jsonl)"
|
||||
HOOKP=/tmp/hookproj; rm -rf "$HOOKP"; mkdir -p "$HOOKP/.aipass"
|
||||
# minimal isolated config: ONLY rm_gate enabled -> no git_gate/sound noise
|
||||
cat > "$HOOKP/.aipass/hooks.json" <<'JSON'
|
||||
{ "hooks_enabled": true,
|
||||
"PreToolUse": {
|
||||
"rm_gate": { "enabled": true, "handler": "aipass.hooks.apps.handlers.security.rm_gate.handle", "matcher": "Bash" }
|
||||
} }
|
||||
JSON
|
||||
UUID="PROTOUUID12345"
|
||||
LOG=$(find "$CLEANENV" -path '*/aipass/hooks/logs/engine.jsonl' 2>/dev/null | head -1)
|
||||
LOGDIR=$(dirname "$(find "$CLEANENV" -path '*/aipass/hooks' -type d 2>/dev/null | head -1)")
|
||||
[ -n "$LOG" ] && : > "$LOG" # truncate if present
|
||||
# fire: rm -rf -> expect block (exit 2)
|
||||
OUT=$(cd "$HOOKP" && echo "{\"tool_name\":\"Bash\",\"tool_input\":{\"command\":\"rm -rf /tmp/x\"},\"agent_id\":\"$UUID\"}" \
|
||||
| AIPASS_HOME="$HOOKP" "$PY" -m aipass.hooks.apps.handlers.bridges.claude "PreToolUse:rm_gate" 2>/tmp/hook.err)
|
||||
HX=$?
|
||||
# relocate LOG now if it didn't exist before
|
||||
[ -z "$LOG" ] && LOG=$(find "$CLEANENV" -path '*/aipass/hooks/logs/engine.jsonl' 2>/dev/null | head -1)
|
||||
printf '%s' "$OUT" > /tmp/hook.out # write to file: never eval-interpolate captured JSON
|
||||
echo " hook exit=$HX stdout=${OUT:0:80}"
|
||||
[ -s /tmp/hook.err ] && echo " stderr: $(head -1 /tmp/hook.err)"
|
||||
# REAL contract (discovered by prototype): rm_gate blocks via {"decision":"block"} on STDOUT, exit 0 — NOT exit 2.
|
||||
chk "rm_gate decision==block (stdout JSON)" "jq -e '.decision==\"block\"' /tmp/hook.out"
|
||||
chk "bridge exit 0 (block via JSON not code)" "[ '$HX' = 0 ]"
|
||||
chk "engine.jsonl exists" "[ -n '$LOG' ] && [ -f '$LOG' ]"
|
||||
chk "engine.jsonl logged sentinel UUID" "[ -n '$LOG' ] && grep -q '$UUID' '$LOG'"
|
||||
chk "logged record hook==rm_gate" "[ -n '$LOG' ] && grep '$UUID' '$LOG' | grep -q rm_gate"
|
||||
# negative: harmless echo -> allow (exit 0)
|
||||
OUT2=$(cd "$HOOKP" && echo "{\"tool_name\":\"Bash\",\"tool_input\":{\"command\":\"echo hi\"},\"agent_id\":\"$UUID-neg\"}" \
|
||||
| AIPASS_HOME="$HOOKP" "$PY" -m aipass.hooks.apps.handlers.bridges.claude "PreToolUse:rm_gate" 2>/dev/null)
|
||||
HX2=$?
|
||||
chk "rm_gate allows echo (exit 0)" "[ '$HX2' = 0 ]"
|
||||
|
||||
hdr "TIER 3 — drone routing (against real repo registry)"
|
||||
chk "drone systems runs (reads registry)" "cd '$SRC' && '$DRONE' systems"
|
||||
chk "drone systems lists a known branch" "cd '$SRC' && '$DRONE' systems 2>/dev/null | grep -qi seedgo"
|
||||
chk "drone @drone --help routes" "cd '$SRC' && '$DRONE' @drone --help"
|
||||
|
||||
hdr "RESULT"
|
||||
echo " PASS=$P FAIL=$F"
|
||||
[ "$F" -eq 0 ] && echo " ALL GREEN" || echo " $F red — that's the truth we wanted"
|
||||
exit 0
|
||||
@@ -140,8 +140,8 @@ class TestEscapedQuoteBypass:
|
||||
assert _is_blocked(_bash(cmd)) == should_block, f"{'Should block' if should_block else 'Should allow'}: {cmd}"
|
||||
|
||||
|
||||
class TestReadOnlyBlocked:
|
||||
"""New handler blocks ALL raw git — read-only included. Use drone."""
|
||||
class TestReadVerbsAllowed:
|
||||
"""Read-only git verbs in the allowlist run raw (S193, DPLAN-0195)."""
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
"cmd",
|
||||
@@ -149,15 +149,49 @@ class TestReadOnlyBlocked:
|
||||
"git status",
|
||||
"git log --oneline",
|
||||
"git diff",
|
||||
"git show HEAD",
|
||||
"git ls-files",
|
||||
"git ls-tree HEAD",
|
||||
"git rev-parse --show-toplevel",
|
||||
"git blame README.md",
|
||||
"git grep TODO",
|
||||
"git archive HEAD",
|
||||
"git for-each-ref",
|
||||
"git -C /tmp/x log",
|
||||
],
|
||||
)
|
||||
def test_allows_read_verbs(self, cmd):
|
||||
"""Allowlisted read verbs are not blocked — raw is fine."""
|
||||
assert not _is_blocked(_bash(cmd)), f"Read verb should be allowed: {cmd}"
|
||||
|
||||
|
||||
class TestNonAllowlistedGitBlocked:
|
||||
"""Git verbs outside the read allowlist stay blocked — conservative."""
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
"cmd",
|
||||
[
|
||||
"git fetch",
|
||||
"git branch",
|
||||
"git tag",
|
||||
"git remote -v",
|
||||
],
|
||||
)
|
||||
def test_blocks_read_only_raw_git(self, cmd):
|
||||
"""Read-only raw git is also blocked — use drone instead."""
|
||||
assert _is_blocked(_bash(cmd)), f"Should block raw git (use drone): {cmd}"
|
||||
def test_blocks_non_allowlisted(self, cmd):
|
||||
"""Reads not on the allowlist (fetch/branch/tag/remote) still block."""
|
||||
assert _is_blocked(_bash(cmd)), f"Should block (use drone): {cmd}"
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
"cmd",
|
||||
[
|
||||
"git log && git push",
|
||||
"git status; git commit -m x",
|
||||
"git diff | git apply",
|
||||
],
|
||||
)
|
||||
def test_blocks_chained_read_then_write(self, cmd):
|
||||
"""A read chained with a write blocks the whole command."""
|
||||
assert _is_blocked(_bash(cmd)), f"Chained read+write should block: {cmd}"
|
||||
|
||||
|
||||
class TestDroneNotBlocked:
|
||||
|
||||
@@ -158,6 +158,31 @@
|
||||
"standard": "architecture",
|
||||
"reason": "Test file — intentionally outside 3-layer structure. tests/ is a peer of apps/, not part of it."
|
||||
},
|
||||
{
|
||||
"file": "tests/test_rm.py",
|
||||
"standard": "architecture",
|
||||
"reason": "Test file — intentionally outside 3-layer structure. tests/ is a peer of apps/, not part of it."
|
||||
},
|
||||
{
|
||||
"file": "tests/test_rm.py",
|
||||
"standard": "encapsulation",
|
||||
"reason": "Test file imports rm_handler directly to test its public interface. Unit tests require direct access to implementation components."
|
||||
},
|
||||
{
|
||||
"file": "tests/test_rm.py",
|
||||
"standard": "documentation",
|
||||
"reason": "Test class docstrings describe intent; per-method docstrings would be noise for assertion-named test methods."
|
||||
},
|
||||
{
|
||||
"file": "tests/test_rm.py",
|
||||
"standard": "meta",
|
||||
"reason": "Test file — META blocks are for production source files, not test suites."
|
||||
},
|
||||
{
|
||||
"file": "tests/test_rm.py",
|
||||
"standard": "trigger",
|
||||
"reason": "Test file exercises .unlink() to verify deletion behavior — not a production file operation requiring trigger events."
|
||||
},
|
||||
{
|
||||
"file": "CLAUDE.md",
|
||||
"standard": "architecture",
|
||||
@@ -174,6 +199,12 @@
|
||||
"standard": "unused_function",
|
||||
"lines": [108],
|
||||
"reason": "create_pr() is deprecated per FPLAN-0210 — pr command blocked at auth tier. Handler kept for backwards compatibility; still tested in test_git_module.py."
|
||||
},
|
||||
{
|
||||
"file": "apps/modules/git_module.py",
|
||||
"standard": "unused_function",
|
||||
"lines": [655],
|
||||
"reason": "get_introspective() called dynamically via getattr() by module_registry_handler.py:219 for internal module introspection. Also tested in test_git_module, test_system_pr, test_devpulse_plugins, test_git_access."
|
||||
}
|
||||
],
|
||||
"notes": {
|
||||
|
||||
@@ -243,6 +243,14 @@ By default, drone captures subprocess output (`capture_output=True`) with a 30s
|
||||
|
||||
Commands in the interactive tuple bypass capture and inherit the terminal directly — enabling live Rich output, colors, and no timeout.
|
||||
|
||||
**Always interactive** — these presentational commands always inherit the terminal for Rich color on a TTY, plain when piped:
|
||||
|
||||
| Pattern | Reason |
|
||||
|----------------|---------------------------------------------|
|
||||
| `@branch` | No-args introspection (branch overview) |
|
||||
| `@branch --help` | Help output with Rich formatting |
|
||||
| `@branch -h` | Short help flag (same as --help) |
|
||||
|
||||
**Per-command allowlist** (in `apps/drone.py`):
|
||||
|
||||
| Command | Reason |
|
||||
@@ -250,6 +258,7 @@ Commands in the interactive tuple bypass capture and inherit the terminal direct
|
||||
| `monitor` | Prax real-time monitoring (live TUI) |
|
||||
| `audit` | Seedgo audit (Rich progress bars) |
|
||||
| `watchdog` | Devpulse watchdog (live monitoring) |
|
||||
| `status` | Branch status with Rich formatted output |
|
||||
|
||||
**Per-branch allowlist** — all commands from these branches get interactive mode:
|
||||
|
||||
@@ -339,7 +348,7 @@ Run tests: `cd src/aipass/drone && python -m pytest tests/ -q`
|
||||
|
||||
---
|
||||
|
||||
**Seedgo:** 99% | **Tests:** 704 pass, 4 skip | **Last Updated:** 2026-05-12
|
||||
**Seedgo:** 100% | **Tests:** 775 pass, 4 skip | **Last Updated:** 2026-06-07
|
||||
|
||||
---
|
||||
[← Back to AIPass](../../../README.md)
|
||||
|
||||
@@ -25,7 +25,6 @@ from rich.text import Text
|
||||
from aipass.prax import logger
|
||||
from aipass.cli.apps.modules import console, err_console
|
||||
from aipass.drone.apps.modules import BranchNotFoundError, CommandExecutionError, RegistryError
|
||||
from aipass.drone.apps.modules.discovery import get_help
|
||||
from aipass.drone.apps.modules.resolver import get_all_branches
|
||||
from aipass.drone.apps.modules.router import route_command
|
||||
from aipass.drone.apps.modules.module_registry import (
|
||||
@@ -41,7 +40,7 @@ VERSION = "1.1.0"
|
||||
MODULES_DIR = Path(__file__).parent / "modules"
|
||||
|
||||
# Interactive mode — commands/branches that bypass capture + timeout for live terminal output.
|
||||
INTERACTIVE_COMMANDS = ("monitor", "audit", "watchdog")
|
||||
INTERACTIVE_COMMANDS = ("monitor", "audit", "watchdog", "status")
|
||||
INTERACTIVE_BRANCHES = ("cli",)
|
||||
|
||||
|
||||
@@ -85,6 +84,7 @@ def show_help() -> None:
|
||||
table.add_row("activate @target", "Register all commands from a branch")
|
||||
table.add_row("list", "List registered custom commands")
|
||||
table.add_row("remove <name>", "Remove a custom command")
|
||||
table.add_row("rm <path> [<path>...]", "Contained safe-delete (project + tmp)")
|
||||
table.add_row("--help", "Show this help")
|
||||
table.add_row("--version", "Show version")
|
||||
|
||||
@@ -110,12 +110,7 @@ def print_help() -> None:
|
||||
|
||||
|
||||
def print_introspection() -> None:
|
||||
"""Alias for seedgo standard compliance (audit expects print_introspection)."""
|
||||
show_introspection()
|
||||
|
||||
|
||||
def show_introspection() -> None:
|
||||
"""Show discovery view (no args) — auto-discovers modules."""
|
||||
"""Display branch overview — auto-discovers modules."""
|
||||
console.print()
|
||||
console.print("[bold cyan]Drone - Command Router & Discovery[/bold cyan]")
|
||||
console.print()
|
||||
@@ -310,6 +305,18 @@ def _handle_remove(name: str) -> int:
|
||||
return 0 if success else 1
|
||||
|
||||
|
||||
def _handle_rm(args: list[str]) -> int:
|
||||
"""Handle ``drone rm <path> [<path>...]`` — contained safe-delete."""
|
||||
from aipass.drone.apps.modules.rm import handle_command, print_help
|
||||
|
||||
if not args or args[0] in ("--help", "-h"):
|
||||
print_help()
|
||||
return 0
|
||||
|
||||
result = handle_command(args[0], args[1:] if len(args) > 1 else None)
|
||||
return 0 if result else 1
|
||||
|
||||
|
||||
def _handle_custom_command(args: list[str]) -> int:
|
||||
"""Handle a custom command shortcut by matching and routing.
|
||||
|
||||
@@ -400,8 +407,9 @@ def _handle_target(args: List[str]) -> int:
|
||||
rest = args[1:]
|
||||
module_name = target.lstrip("@").lower()
|
||||
|
||||
first_cmd = rest[0] if rest and rest[0] != "--help" else None
|
||||
needs_interactive = first_cmd in INTERACTIVE_COMMANDS or module_name in INTERACTIVE_BRANCHES
|
||||
first_cmd = rest[0] if rest and rest[0] not in ("--help", "-h") else None
|
||||
is_presentational = not rest or first_cmd is None
|
||||
needs_interactive = is_presentational or first_cmd in INTERACTIVE_COMMANDS or module_name in INTERACTIVE_BRANCHES
|
||||
|
||||
# Route to internal module — unless command needs interactive terminal,
|
||||
# in which case fall through to branch (subprocess) routing so Rich
|
||||
@@ -409,10 +417,10 @@ def _handle_target(args: List[str]) -> int:
|
||||
if is_module(module_name) and not needs_interactive:
|
||||
return _handle_module(module_name, rest)
|
||||
|
||||
# No args = pass through to branch (introspection)
|
||||
# No args = pass through to branch (introspection — inherit terminal for color)
|
||||
if not rest:
|
||||
try:
|
||||
result = route_command(target)
|
||||
result = route_command(target, interactive=True)
|
||||
except (BranchNotFoundError, CommandExecutionError, RegistryError) as exc:
|
||||
if isinstance(exc, BranchNotFoundError) and is_module(module_name):
|
||||
logger.info("Falling back to module routing for @%s (not in local registry)", module_name)
|
||||
@@ -422,30 +430,22 @@ def _handle_target(args: List[str]) -> int:
|
||||
if isinstance(exc, BranchNotFoundError) and not os.environ.get("AIPASS_HOME"):
|
||||
err_console.print(" Tip: set AIPASS_HOME=/path/to/AIPass to access core branches.")
|
||||
return 1
|
||||
if result.stdout:
|
||||
console.print(result.stdout, end="", highlight=False)
|
||||
if result.stderr:
|
||||
err_console.print(result.stderr, end="", highlight=False)
|
||||
return result.exit_code
|
||||
|
||||
# --help = show help
|
||||
if rest == ["--help"]:
|
||||
# --help / -h = help (inherit terminal for color)
|
||||
if rest in (["--help"], ["-h"]):
|
||||
try:
|
||||
result = get_help(target)
|
||||
if result.text:
|
||||
console.print(result.text, end="", highlight=False)
|
||||
else:
|
||||
console.print(f"No help available for {target}.")
|
||||
result = route_command(target, rest[0], interactive=True)
|
||||
except (BranchNotFoundError, CommandExecutionError, RegistryError) as exc:
|
||||
if isinstance(exc, BranchNotFoundError) and is_module(module_name):
|
||||
logger.info("Falling back to module routing for @%s --help (not in local registry)", module_name)
|
||||
logger.info("Falling back to module routing for @%s %s (not in local registry)", module_name, rest[0])
|
||||
return _handle_module(module_name, rest)
|
||||
logger.warning("Help lookup failed for %s: %s", target, exc)
|
||||
err_console.print(f"drone: {exc}")
|
||||
if isinstance(exc, BranchNotFoundError) and not os.environ.get("AIPASS_HOME"):
|
||||
err_console.print(" Tip: set AIPASS_HOME=/path/to/AIPass to access core branches.")
|
||||
return 1
|
||||
return 0
|
||||
return result.exit_code
|
||||
|
||||
# drone @branch command [args...]
|
||||
command = rest[0]
|
||||
@@ -557,6 +557,10 @@ def main() -> int:
|
||||
return 1
|
||||
return _handle_remove(args[1])
|
||||
|
||||
# rm — contained safe-delete
|
||||
if command == "rm":
|
||||
return _handle_rm(args[1:])
|
||||
|
||||
# @target — route to branch or module
|
||||
if command.startswith("@"):
|
||||
return _handle_target(args)
|
||||
|
||||
@@ -25,6 +25,19 @@ def list_remote_branches() -> dict:
|
||||
"""
|
||||
repo_root = find_repo_root()
|
||||
|
||||
# Prune stale remote-tracking refs before listing
|
||||
try:
|
||||
prune = subprocess.run(
|
||||
["git", "fetch", "--prune"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
cwd=str(repo_root),
|
||||
)
|
||||
if prune.returncode != 0:
|
||||
logger.warning("git fetch --prune failed (listing stale refs): %s", prune.stderr.strip())
|
||||
except (OSError, subprocess.SubprocessError) as exc:
|
||||
logger.warning("git fetch --prune unavailable (offline?), listing may include stale refs: %s", exc)
|
||||
|
||||
try:
|
||||
result = subprocess.run(
|
||||
["git", "branch", "-r"],
|
||||
@@ -52,3 +65,46 @@ def list_remote_branches() -> dict:
|
||||
logger.info("Listed %d remote branches", len(branches))
|
||||
|
||||
return {"branches": branches, "count": len(branches), "message": f"{len(branches)} remote branches"}
|
||||
|
||||
|
||||
def prune_temp_branches() -> dict:
|
||||
"""Delete local and remote temp PR branches (citizen/*) that are already merged.
|
||||
|
||||
Returns:
|
||||
Dict with pruned list, count, and message.
|
||||
"""
|
||||
repo_root = find_repo_root()
|
||||
pruned: list[str] = []
|
||||
|
||||
try:
|
||||
merged = subprocess.run(
|
||||
["git", "branch", "--merged", "main"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
cwd=str(repo_root),
|
||||
)
|
||||
if merged.returncode != 0:
|
||||
return {"pruned": [], "count": 0, "message": f"git branch --merged failed: {merged.stderr.strip()}"}
|
||||
|
||||
for line in merged.stdout.splitlines():
|
||||
name = line.strip().lstrip("* ")
|
||||
if name.startswith("citizen/"):
|
||||
local_del = subprocess.run(
|
||||
["git", "branch", "-d", name],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
cwd=str(repo_root),
|
||||
)
|
||||
if local_del.returncode == 0:
|
||||
pruned.append(name)
|
||||
logger.info("Pruned merged temp branch: %s", name)
|
||||
else:
|
||||
logger.warning("Failed to delete local branch %s: %s", name, local_del.stderr.strip())
|
||||
|
||||
except (OSError, subprocess.SubprocessError) as exc:
|
||||
logger.error("prune_temp_branches failed: %s", exc)
|
||||
return {"pruned": [], "count": 0, "message": f"Prune failed: {exc}"}
|
||||
|
||||
json_handler.log_operation("prune_temp_branches", {"count": len(pruned)})
|
||||
msg = f"Pruned {len(pruned)} merged temp branch(es)" if pruned else "No merged temp branches to prune"
|
||||
return {"pruned": pruned, "count": len(pruned), "message": msg}
|
||||
|
||||
@@ -396,3 +396,35 @@ def get_branch_by_name(name: str) -> Optional[Dict[str, Any]]:
|
||||
logger.warning("get_branch_by_name: AIPass home registry unavailable for '%s': %s", name, exc)
|
||||
|
||||
return None
|
||||
|
||||
|
||||
def get_branch_with_registry(name: str) -> Optional[tuple]:
|
||||
"""Get a branch and the registry path it was found in.
|
||||
|
||||
Same two-step lookup as get_branch_by_name (primary then AIPASS_HOME),
|
||||
but returns (branch_dict, registry_path) so callers can determine
|
||||
which project root the branch belongs to.
|
||||
"""
|
||||
lower_name = name.lower()
|
||||
|
||||
try:
|
||||
primary_path = get_registry_path()
|
||||
registry = load_registry()
|
||||
branch = registry.get("branches", {}).get(lower_name)
|
||||
if branch is not None:
|
||||
return branch, primary_path
|
||||
except (RegistryNotFoundError, RegistryCorruptError, RegistryPermissionError) as exc:
|
||||
logger.warning("get_branch_with_registry: primary registry unavailable for '%s': %s", name, exc)
|
||||
primary_path = None
|
||||
|
||||
home_path = _get_aipass_home_registry_path()
|
||||
if home_path is not None and home_path != primary_path:
|
||||
try:
|
||||
home_data = _load_registry_data(home_path)
|
||||
branch = home_data.get("branches", {}).get(lower_name)
|
||||
if branch is not None:
|
||||
return branch, home_path
|
||||
except (RegistryNotFoundError, RegistryCorruptError, RegistryPermissionError) as exc:
|
||||
logger.warning("get_branch_with_registry: AIPass home registry unavailable for '%s': %s", name, exc)
|
||||
|
||||
return None
|
||||
|
||||
@@ -0,0 +1,204 @@
|
||||
# =================== AIPass ====================
|
||||
# Name: rm_handler.py
|
||||
# Description: Contained safe-delete handler
|
||||
# Version: 1.1.0
|
||||
# Created: 2026-06-02
|
||||
# Modified: 2026-06-02
|
||||
# =============================================
|
||||
|
||||
"""Contained safe-delete handler.
|
||||
|
||||
Deletes paths using shutil.rmtree (directories) or Path.unlink (files),
|
||||
constrained to project root and system temp directories. Provider-agnostic
|
||||
alternative to shell ``rm``.
|
||||
|
||||
Matches Codex sandbox boundaries: writable = {project, /tmp, $TMPDIR}.
|
||||
Hard carve-outs protect .git, .trinity, .aipass, .codex, .agents, and
|
||||
sibling branch worktrees even inside allowed roots.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import shutil
|
||||
import tempfile
|
||||
from pathlib import Path
|
||||
|
||||
from aipass.prax import logger
|
||||
from aipass.drone.apps.handlers.json import json_handler
|
||||
|
||||
_CARVEOUT_DIRS = frozenset((".git", ".trinity", ".aipass", ".codex", ".agents"))
|
||||
|
||||
|
||||
def _find_project_root() -> Path | None:
|
||||
"""Walk up from CWD to find *_REGISTRY.json; return its parent as project root."""
|
||||
cwd = Path.cwd()
|
||||
for parent in [cwd, *cwd.parents]:
|
||||
if list(parent.glob("*_REGISTRY.json")):
|
||||
return parent.resolve()
|
||||
aipass_home = os.environ.get("AIPASS_HOME")
|
||||
if aipass_home:
|
||||
home = Path(aipass_home)
|
||||
if home.is_dir() and list(home.glob("*_REGISTRY.json")):
|
||||
return home.resolve()
|
||||
return None
|
||||
|
||||
|
||||
def get_allowed_roots() -> list[Path]:
|
||||
"""Return resolved roots under which deletion is permitted.
|
||||
|
||||
Union of: project root, ``/tmp``, and ``tempfile.gettempdir()`` (which
|
||||
honors ``$TMPDIR``). Deduplicated by resolved path.
|
||||
"""
|
||||
seen: set[Path] = set()
|
||||
roots: list[Path] = []
|
||||
|
||||
project_root = _find_project_root()
|
||||
if project_root is not None and project_root not in seen:
|
||||
seen.add(project_root)
|
||||
roots.append(project_root)
|
||||
|
||||
for tmp_candidate in (Path("/tmp"), Path(tempfile.gettempdir())):
|
||||
resolved = tmp_candidate.resolve()
|
||||
if resolved not in seen:
|
||||
seen.add(resolved)
|
||||
roots.append(resolved)
|
||||
|
||||
return roots
|
||||
|
||||
|
||||
def _detect_current_branch(project_root: Path | None) -> str | None:
|
||||
"""Return the branch name the CWD lives in, or None."""
|
||||
if project_root is None:
|
||||
return None
|
||||
cwd = Path.cwd().resolve()
|
||||
aipass_src = project_root / "src" / "aipass"
|
||||
if not cwd.is_relative_to(aipass_src):
|
||||
return None
|
||||
rel = cwd.relative_to(aipass_src)
|
||||
return rel.parts[0] if rel.parts else None
|
||||
|
||||
|
||||
def _resolve_git_dir(path: Path) -> Path | None:
|
||||
"""If *path* is a ``.git`` file (worktree pointer), return the resolved gitdir."""
|
||||
try:
|
||||
if path.is_file():
|
||||
text = path.read_text(encoding="utf-8", errors="replace").strip()
|
||||
if text.startswith("gitdir:"):
|
||||
return Path(text.split(":", 1)[1].strip()).resolve()
|
||||
except OSError as exc:
|
||||
logger.warning("Failed to read .git file at %s: %s", path, exc)
|
||||
return None
|
||||
|
||||
|
||||
def check_carveouts(resolved: Path, project_root: Path | None) -> tuple[bool, str]:
|
||||
"""Refuse deletion of protected paths even inside allowed roots.
|
||||
|
||||
Returns ``(blocked, reason)``. ``blocked=True`` means the path must
|
||||
NOT be deleted.
|
||||
"""
|
||||
parts = resolved.parts
|
||||
for i, part in enumerate(parts):
|
||||
if part in _CARVEOUT_DIRS:
|
||||
return True, f"Protected directory: path is inside {part}/"
|
||||
|
||||
if part == ".git":
|
||||
git_path = Path(*parts[: i + 1]) if i > 0 else Path(part)
|
||||
real_gitdir = _resolve_git_dir(git_path)
|
||||
if real_gitdir and resolved.is_relative_to(real_gitdir):
|
||||
return True, "Protected: path resolves inside .git worktree gitdir"
|
||||
|
||||
if project_root is not None:
|
||||
aipass_src = project_root / "src" / "aipass"
|
||||
if resolved.is_relative_to(aipass_src):
|
||||
rel = resolved.relative_to(aipass_src)
|
||||
if rel.parts:
|
||||
target_branch = rel.parts[0]
|
||||
current_branch = _detect_current_branch(project_root)
|
||||
if current_branch is None or target_branch != current_branch:
|
||||
return True, (f"Protected: path is inside sibling branch src/aipass/{target_branch}/")
|
||||
|
||||
return False, ""
|
||||
|
||||
|
||||
def check_containment(path: Path, roots: list[Path]) -> tuple[bool, str]:
|
||||
"""Check if *path* (already resolved) is a strict child of any allowed root.
|
||||
|
||||
Returns ``(allowed, reason)``. Refuses the root directories themselves.
|
||||
When multiple roots are nested (e.g. /tmp and /tmp/claude-1000), the path
|
||||
must not equal ANY root — checked upfront before containment.
|
||||
"""
|
||||
root_set = frozenset(roots)
|
||||
if path in root_set:
|
||||
return False, f"Refusing to delete root directory itself: {path}"
|
||||
|
||||
for root in roots:
|
||||
if path.is_relative_to(root):
|
||||
return True, ""
|
||||
|
||||
allowed_str = ", ".join(str(r) for r in roots)
|
||||
return False, (f"Path {path} is outside allowed roots.\n Allowed: {allowed_str}")
|
||||
|
||||
|
||||
def safe_delete(paths: list[str]) -> list[tuple[str, bool, str]]:
|
||||
"""Delete *paths* with containment checks.
|
||||
|
||||
Returns a list of ``(original_path, success, message)`` tuples.
|
||||
Every path is checked independently; a refused path does not block others.
|
||||
"""
|
||||
roots = get_allowed_roots()
|
||||
if not roots:
|
||||
return [(p, False, "No allowed roots found (no project registry, no temp dir)") for p in paths]
|
||||
|
||||
project_root = _find_project_root()
|
||||
json_handler.log_operation("rm", {"paths": paths, "roots": [str(r) for r in roots]})
|
||||
|
||||
results: list[tuple[str, bool, str]] = []
|
||||
for path_str in paths:
|
||||
original = Path(path_str)
|
||||
absolute = original if original.is_absolute() else (Path.cwd() / original)
|
||||
|
||||
exists_on_disk = absolute.exists() or absolute.is_symlink()
|
||||
if not exists_on_disk:
|
||||
results.append((path_str, False, f"Path does not exist: {absolute}"))
|
||||
logger.info("rm: nonexistent path %s", absolute)
|
||||
continue
|
||||
|
||||
resolved = absolute.resolve()
|
||||
|
||||
allowed, reason = check_containment(resolved, roots)
|
||||
if not allowed:
|
||||
results.append((path_str, False, reason))
|
||||
logger.warning(
|
||||
"rm: containment refused %s (resolved %s): %s",
|
||||
path_str,
|
||||
resolved,
|
||||
reason,
|
||||
)
|
||||
continue
|
||||
|
||||
blocked, carveout_reason = check_carveouts(resolved, project_root)
|
||||
if blocked:
|
||||
results.append((path_str, False, carveout_reason))
|
||||
logger.warning(
|
||||
"rm: carveout refused %s (resolved %s): %s",
|
||||
path_str,
|
||||
resolved,
|
||||
carveout_reason,
|
||||
)
|
||||
continue
|
||||
|
||||
try:
|
||||
if absolute.is_symlink():
|
||||
absolute.unlink()
|
||||
elif absolute.is_dir():
|
||||
shutil.rmtree(absolute)
|
||||
else:
|
||||
absolute.unlink()
|
||||
results.append((path_str, True, f"Deleted: {resolved}"))
|
||||
logger.info("rm: deleted %s (resolved %s)", path_str, resolved)
|
||||
except Exception as exc:
|
||||
results.append((path_str, False, f"Delete failed: {exc}"))
|
||||
logger.error("rm: delete failed for %s: %s", path_str, exc)
|
||||
|
||||
return results
|
||||
@@ -155,13 +155,15 @@ def print_introspection() -> None:
|
||||
console = Console()
|
||||
|
||||
console.print()
|
||||
console.print("commands Module")
|
||||
console.print("Custom command shortcuts — map short names to full drone commands.")
|
||||
console.print("[bold cyan]commands Module[/bold cyan]")
|
||||
console.print("[dim]Custom command shortcuts — map short names to full drone commands.[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/command_registry/")
|
||||
console.print(" - ops.py (add_command, remove_command, update_command, command_exists)")
|
||||
console.print(" - lookup.py (lookup_command, match_command, list_commands, list_commands_by_branch)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/command_registry/[/cyan]")
|
||||
console.print(" - [cyan]ops.py[/cyan] [dim](add_command, remove_command, update_command, command_exists)[/dim]")
|
||||
console.print(
|
||||
" - [cyan]lookup.py[/cyan] [dim](lookup_command, match_command, list_commands, list_commands_by_branch)[/dim]"
|
||||
)
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -37,14 +37,20 @@ def print_introspection():
|
||||
console = Console()
|
||||
|
||||
console.print()
|
||||
console.print("config Module")
|
||||
console.print("Registry configuration management — path resolution and overrides.")
|
||||
console.print("[bold cyan]config Module[/bold cyan]")
|
||||
console.print("[dim]Registry configuration management — path resolution and overrides.[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/")
|
||||
console.print(" - registry_handler.py (get_registry_path — return current registry file path)")
|
||||
console.print(" - registry_handler.py (set_registry_path — override registry file location)")
|
||||
console.print(" - registry_handler.py (reset_registry_path — restore default registry path)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/[/cyan]")
|
||||
console.print(
|
||||
" - [cyan]registry_handler.py[/cyan] [dim](get_registry_path — return current registry file path)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]registry_handler.py[/cyan] [dim](set_registry_path — override registry file location)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]registry_handler.py[/cyan] [dim](reset_registry_path — restore default registry path)[/dim]"
|
||||
)
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -93,19 +93,25 @@ def print_introspection():
|
||||
console = Console()
|
||||
|
||||
console.print()
|
||||
console.print("discovery Module")
|
||||
console.print("Module and command discovery for AIPass branch introspection.")
|
||||
console.print("[bold cyan]discovery Module[/bold cyan]")
|
||||
console.print("[dim]Module and command discovery for AIPass branch introspection.[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/")
|
||||
console.print(" - discovery_handler.py (HelpResult — structured help query result)")
|
||||
console.print(" - discovery_handler.py (discover_modules — list available commands for a branch)")
|
||||
console.print(" - discovery_handler.py (get_help — get structured help for a branch/command)")
|
||||
console.print(" - discovery_handler.py (get_system_help — aggregate help across all branches)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/[/cyan]")
|
||||
console.print(" - [cyan]discovery_handler.py[/cyan] [dim](HelpResult — structured help query result)[/dim]")
|
||||
console.print(
|
||||
" - [cyan]discovery_handler.py[/cyan] [dim](discover_modules — list available commands for a branch)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]discovery_handler.py[/cyan] [dim](get_help — get structured help for a branch/command)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]discovery_handler.py[/cyan] [dim](get_system_help — aggregate help across all branches)[/dim]"
|
||||
)
|
||||
console.print()
|
||||
console.print("Connected Modules:")
|
||||
console.print(" modules/")
|
||||
console.print(" - resolver.py (resolve_branch, list_branches — branch name resolution)")
|
||||
console.print("[yellow]Connected Modules:[/yellow]")
|
||||
console.print(" [cyan]modules/[/cyan]")
|
||||
console.print(" - [cyan]resolver.py[/cyan] [dim](resolve_branch, list_branches — branch name resolution)[/dim]")
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -61,6 +61,7 @@ _COMMANDS = (
|
||||
"smart-sync",
|
||||
"fix",
|
||||
"pr",
|
||||
"prune-temp",
|
||||
)
|
||||
|
||||
_GH_PASSTHROUGH_COMMANDS = ("issue", "run", "workflow")
|
||||
@@ -167,6 +168,8 @@ def handle_command(command: str | None = None, args: list[str] | None = None) ->
|
||||
return _handle_fix(args, caller)
|
||||
if command == "pr":
|
||||
return _handle_pr(args)
|
||||
if command == "prune-temp":
|
||||
return _handle_prune_temp()
|
||||
|
||||
available = ", ".join(_COMMANDS)
|
||||
return {
|
||||
@@ -219,6 +222,15 @@ def _handle_branches() -> dict:
|
||||
return {"stdout": result["message"], "stderr": "", "exit_code": 0}
|
||||
|
||||
|
||||
def _handle_prune_temp() -> dict:
|
||||
"""Handle the prune-temp subcommand — delete merged citizen/* branches."""
|
||||
result = branches_handler.prune_temp_branches()
|
||||
lines = [result["message"]]
|
||||
for name in result.get("pruned", []):
|
||||
lines.append(f" deleted: {name}")
|
||||
return {"stdout": "\n".join(lines), "stderr": "", "exit_code": 0}
|
||||
|
||||
|
||||
def _handle_pr(args: list[str]) -> dict:
|
||||
"""Handle the pr subcommand — push current branch and create PR to main."""
|
||||
if not args:
|
||||
@@ -356,6 +368,8 @@ def _handle_status(args: list[str] | None = None) -> dict:
|
||||
|
||||
_, branch_dir = detected
|
||||
|
||||
branch_name = detected[0]
|
||||
|
||||
if show_all:
|
||||
repo_root = lock_handler.find_repo_root()
|
||||
result = status_handler.get_branch_status(repo_root)
|
||||
@@ -367,6 +381,9 @@ def _handle_status(args: list[str] | None = None) -> dict:
|
||||
for f in result["files"]:
|
||||
lines.append(f" {f['status']:>2} {f['path']}")
|
||||
|
||||
if not show_all:
|
||||
lines.append(f"(showing {branch_name} scope — use --all for full repo)")
|
||||
|
||||
return {
|
||||
"stdout": "\n".join(lines),
|
||||
"stderr": "",
|
||||
@@ -384,18 +401,18 @@ def _handle_diff(args: list[str]) -> dict:
|
||||
"exit_code": 1,
|
||||
}
|
||||
|
||||
_, branch_dir = detected
|
||||
branch_name, branch_dir = detected
|
||||
staged = "--staged" in args
|
||||
show_all = "--all" in args
|
||||
|
||||
target_dir = lock_handler.find_repo_root() if show_all else branch_dir
|
||||
result = diff_handler.get_branch_diff(target_dir, staged=staged)
|
||||
|
||||
return {
|
||||
"stdout": result["diff"] if result["diff"] else result["message"],
|
||||
"stderr": "",
|
||||
"exit_code": 0,
|
||||
}
|
||||
output = result["diff"] if result["diff"] else result["message"]
|
||||
if not show_all:
|
||||
output += f"\n(showing {branch_name} scope — use --all for full repo)"
|
||||
|
||||
return {"stdout": output, "stderr": "", "exit_code": 0}
|
||||
|
||||
|
||||
def _handle_log(args: list[str]) -> dict:
|
||||
@@ -610,17 +627,16 @@ def get_help(command: str | None = None) -> str:
|
||||
|
||||
return (
|
||||
"git — Tier-based git workflow (dev branch model)\n"
|
||||
"\n"
|
||||
"Global (all branches):\n"
|
||||
" status Show git status for your branch\n"
|
||||
" diff [--staged] Show git diff for your branch\n"
|
||||
" log [count] Show recent git log (default: 10)\n"
|
||||
" lock Check lock status\n"
|
||||
" branches List remote branches\n"
|
||||
" prune-temp Delete merged citizen/* temp branches\n"
|
||||
" issue [args] Passthrough to gh issue\n"
|
||||
" run [args] Passthrough to gh run\n"
|
||||
" workflow [args] Passthrough to gh workflow\n"
|
||||
"\n"
|
||||
"Owner (devpulse only):\n"
|
||||
" commit <msg> [--all | files] Commit changes (selective or --all)\n"
|
||||
" checkout <main|dev> Switch branches\n"
|
||||
@@ -642,52 +658,60 @@ def get_introspective() -> str:
|
||||
"@git — Tier-based git workflow, dev branch model (v3.0.0)\n"
|
||||
"Connected Handlers:\n"
|
||||
" handlers/git/\n"
|
||||
" - lock_handler.py (acquire_lock, release_lock, check_lock_status, force_unlock)\n"
|
||||
" - status_handler.py (get_branch_status — scoped git status)\n"
|
||||
" - diff_handler.py (get_branch_diff — scoped git diff)\n"
|
||||
" - log_handler.py (get_git_log — recent log entries)\n"
|
||||
" - commit_handler.py (commit_changes — selective files, --all, or pre-staged)\n"
|
||||
" - checkout_handler.py (checkout_branch — main/dev only)\n"
|
||||
" - sync_handler.py (sync_main — safe main synchronization)\n"
|
||||
" - dev_pr_handler.py (create_branch_pr, create_dev_pr — PR to main)\n"
|
||||
" - branches_handler.py (list_remote_branches)\n"
|
||||
" - delete_branch_handler.py (delete_remote_branch — protected: main/dev)\n"
|
||||
" - close_pr_handler.py (close_pr — close PR by number)\n"
|
||||
"\n"
|
||||
" - lock_handler.py, status_handler.py, diff_handler.py, log_handler.py\n"
|
||||
" - commit_handler.py, checkout_handler.py, sync_handler.py\n"
|
||||
" - dev_pr_handler.py, branches_handler.py, delete_branch_handler.py, close_pr_handler.py\n"
|
||||
" plugins/devpulse_ops/\n"
|
||||
" - auth.py (verify_git_access — tier-based authorization)\n"
|
||||
" - merge_plugin.py (merge_pr — merge PR + sync)\n"
|
||||
" - sync_plugin.py (smart_sync — fetch + rebase if behind)\n"
|
||||
" - fix_plugin.py (fix_git_state — detect/fix broken states)\n"
|
||||
"\n"
|
||||
" gh passthrough:\n"
|
||||
" - issue, run, workflow → subprocess gh <cmd> [args]\n"
|
||||
"\n"
|
||||
"Access Tiers: global (status, diff, log, lock, branches, issue, run, workflow) | owner (pr, commit, checkout, dev-pr, delete-branch, close-pr, sync, unlock, merge, smart-sync, fix)\n"
|
||||
" - auth.py, merge_plugin.py, sync_plugin.py, fix_plugin.py\n"
|
||||
" gh passthrough: issue, run, workflow\n"
|
||||
"Tiers: global (status,diff,log,lock,branches,prune-temp,issue,run,workflow)"
|
||||
" | owner (pr,commit,checkout,dev-pr,delete-branch,close-pr,sync,unlock,merge,smart-sync,fix)\n"
|
||||
)
|
||||
|
||||
|
||||
def _get_console():
|
||||
try:
|
||||
from aipass.cli.apps.modules.display import console
|
||||
|
||||
return console
|
||||
except ImportError:
|
||||
logger.warning("CLI console not available, using fallback")
|
||||
from rich.console import Console
|
||||
|
||||
return Console()
|
||||
|
||||
|
||||
def print_introspection() -> None:
|
||||
"""Print introspection (seedgo compliance)."""
|
||||
try:
|
||||
from aipass.cli.apps.modules.display import console
|
||||
except ImportError:
|
||||
logger.warning("CLI console not available, using fallback")
|
||||
from rich.console import Console
|
||||
|
||||
console = Console()
|
||||
|
||||
console.print(get_introspective())
|
||||
c = _get_console()
|
||||
c.print()
|
||||
c.print("[bold cyan]@git[/bold cyan] [dim]— Tier-based git workflow, dev branch model (v3.0.0)[/dim]")
|
||||
c.print("[yellow]Connected Handlers:[/yellow]")
|
||||
c.print(" [cyan]handlers/git/[/cyan]")
|
||||
c.print(
|
||||
" - [cyan]lock_handler.py[/cyan], [cyan]status_handler.py[/cyan],"
|
||||
" [cyan]diff_handler.py[/cyan], [cyan]log_handler.py[/cyan]"
|
||||
)
|
||||
c.print(" - [cyan]commit_handler.py[/cyan], [cyan]checkout_handler.py[/cyan], [cyan]sync_handler.py[/cyan]")
|
||||
c.print(
|
||||
" - [cyan]dev_pr_handler.py[/cyan], [cyan]branches_handler.py[/cyan],"
|
||||
" [cyan]delete_branch_handler.py[/cyan], [cyan]close_pr_handler.py[/cyan]"
|
||||
)
|
||||
c.print(" [cyan]plugins/devpulse_ops/[/cyan]")
|
||||
c.print(
|
||||
" - [cyan]auth.py[/cyan], [cyan]merge_plugin.py[/cyan],"
|
||||
" [cyan]sync_plugin.py[/cyan], [cyan]fix_plugin.py[/cyan]"
|
||||
)
|
||||
c.print(" [dim]gh passthrough: issue, run, workflow[/dim]")
|
||||
c.print(
|
||||
"[yellow]Tiers:[/yellow] [dim]global[/dim]"
|
||||
" [dim](status,diff,log,lock,branches,prune-temp,issue,run,workflow)[/dim]"
|
||||
" | [dim]owner[/dim]"
|
||||
" [dim](pr,commit,checkout,dev-pr,delete-branch,close-pr,sync,unlock,merge,smart-sync,fix)[/dim]"
|
||||
)
|
||||
c.print()
|
||||
|
||||
|
||||
def print_help() -> None:
|
||||
"""Print help (seedgo compliance)."""
|
||||
try:
|
||||
from aipass.cli.apps.modules.display import console
|
||||
except ImportError:
|
||||
logger.warning("CLI console not available, using fallback")
|
||||
from rich.console import Console
|
||||
|
||||
console = Console()
|
||||
|
||||
console.print(get_help())
|
||||
_get_console().print(get_help())
|
||||
|
||||
@@ -54,19 +54,34 @@ def print_introspection():
|
||||
console = Console()
|
||||
|
||||
console.print()
|
||||
console.print("module_registry Module")
|
||||
console.print("Internal module registry for drone — dynamic module loading and command delegation.")
|
||||
console.print("[bold cyan]module_registry Module[/bold cyan]")
|
||||
console.print("[dim]Internal module registry for drone — dynamic module loading and command delegation.[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/")
|
||||
console.print(" - module_registry_handler.py (ModuleInfo — module metadata dataclass)")
|
||||
console.print(" - module_registry_handler.py (list_modules — list registered module names)")
|
||||
console.print(" - module_registry_handler.py (is_module — check if a module is registered)")
|
||||
console.print(" - module_registry_handler.py (get_module_info — retrieve module metadata)")
|
||||
console.print(" - module_registry_handler.py (route_module_command — delegate command to module)")
|
||||
console.print(" - module_registry_handler.py (get_module_help — get help text for a module)")
|
||||
console.print(" - module_registry_handler.py (get_module_introspective — introspect module adapter)")
|
||||
console.print(" - module_registry_handler.py (register_module — register a new module adapter)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/[/cyan]")
|
||||
console.print(" - [cyan]module_registry_handler.py[/cyan] [dim](ModuleInfo — module metadata dataclass)[/dim]")
|
||||
console.print(
|
||||
" - [cyan]module_registry_handler.py[/cyan] [dim](list_modules — list registered module names)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]module_registry_handler.py[/cyan] [dim](is_module — check if a module is registered)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]module_registry_handler.py[/cyan] [dim](get_module_info — retrieve module metadata)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]module_registry_handler.py[/cyan] [dim](route_module_command — delegate command to module)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]module_registry_handler.py[/cyan] [dim](get_module_help — get help text for a module)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]module_registry_handler.py[/cyan]"
|
||||
" [dim](get_module_introspective — introspect module adapter)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]module_registry_handler.py[/cyan] [dim](register_module — register a new module adapter)[/dim]"
|
||||
)
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -37,14 +37,20 @@ def print_introspection():
|
||||
console = Console()
|
||||
|
||||
console.print()
|
||||
console.print("registry Module")
|
||||
console.print("Registry operations for branch management — loading and querying AIPASS_REGISTRY.json.")
|
||||
console.print("[bold cyan]registry Module[/bold cyan]")
|
||||
console.print("[dim]Registry operations for branch management — loading and querying AIPASS_REGISTRY.json.[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/")
|
||||
console.print(" - registry_handler.py (load_registry — load and parse the registry file)")
|
||||
console.print(" - registry_handler.py (get_all_branches — list branches with type/status filters)")
|
||||
console.print(" - registry_handler.py (get_branch_by_name — look up a single branch by name)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/[/cyan]")
|
||||
console.print(
|
||||
" - [cyan]registry_handler.py[/cyan] [dim](load_registry — load and parse the registry file)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]registry_handler.py[/cyan] [dim](get_all_branches — list branches with type/status filters)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]registry_handler.py[/cyan] [dim](get_branch_by_name — look up a single branch by name)[/dim]"
|
||||
)
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -25,7 +25,7 @@ from aipass.drone.apps.handlers.registry_handler import (
|
||||
load_registry,
|
||||
get_all_branches,
|
||||
get_branch_by_name,
|
||||
get_registry_path,
|
||||
get_branch_with_registry,
|
||||
_validate_branch_path,
|
||||
)
|
||||
|
||||
@@ -112,15 +112,21 @@ def print_introspection():
|
||||
console = Console()
|
||||
|
||||
console.print()
|
||||
console.print("resolver Module")
|
||||
console.print("Branch resolution logic — resolves symbolic @branch names to paths and metadata.")
|
||||
console.print("[bold cyan]resolver Module[/bold cyan]")
|
||||
console.print("[dim]Branch resolution logic — resolves symbolic @branch names to paths and metadata.[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/")
|
||||
console.print(" - registry_handler.py (load_registry — load and parse AIPASS_REGISTRY.json)")
|
||||
console.print(" - registry_handler.py (get_all_branches — list branches with optional filters)")
|
||||
console.print(" - registry_handler.py (get_branch_by_name — look up a single branch)")
|
||||
console.print(" - exceptions.py (BranchNotFoundError — raised when branch not in registry)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/[/cyan]")
|
||||
console.print(
|
||||
" - [cyan]registry_handler.py[/cyan] [dim](load_registry — load and parse AIPASS_REGISTRY.json)[/dim]"
|
||||
)
|
||||
console.print(
|
||||
" - [cyan]registry_handler.py[/cyan] [dim](get_all_branches — list branches with optional filters)[/dim]"
|
||||
)
|
||||
console.print(" - [cyan]registry_handler.py[/cyan] [dim](get_branch_by_name — look up a single branch)[/dim]")
|
||||
console.print(
|
||||
" - [cyan]exceptions.py[/cyan] [dim](BranchNotFoundError — raised when branch not in registry)[/dim]"
|
||||
)
|
||||
console.print()
|
||||
|
||||
|
||||
@@ -156,13 +162,14 @@ def resolve_branch(symbolic_name: str) -> str:
|
||||
raise BranchNotFoundError(f"Branch name must use @ prefix: '@{symbolic_name}' (got '{symbolic_name}')")
|
||||
|
||||
name = normalize_branch_name(symbolic_name).lower()
|
||||
branch = get_branch_by_name(name)
|
||||
result = get_branch_with_registry(name)
|
||||
|
||||
if branch is None:
|
||||
if result is None:
|
||||
raise BranchNotFoundError(f"Branch '{symbolic_name}' not found in registry")
|
||||
|
||||
branch, source_registry = result
|
||||
branch_path = Path(branch["path"])
|
||||
project_root = get_registry_path().parent
|
||||
project_root = source_registry.parent
|
||||
if not branch_path.is_absolute():
|
||||
branch_path = project_root / branch_path
|
||||
if not _validate_branch_path(branch_path, project_root, name):
|
||||
|
||||
@@ -0,0 +1,101 @@
|
||||
# =================== AIPass ====================
|
||||
# Name: rm.py
|
||||
# Description: Module orchestrator for contained safe-delete
|
||||
# Version: 1.0.0
|
||||
# Created: 2026-06-02
|
||||
# Modified: 2026-06-02
|
||||
# =============================================
|
||||
|
||||
"""Module orchestrator for contained safe-delete.
|
||||
|
||||
Thin orchestrator that delegates to rm_handler for path containment
|
||||
checks and deletion. Provider-agnostic alternative to shell ``rm``.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from aipass.prax import logger
|
||||
from aipass.cli.apps.modules import console
|
||||
from aipass.drone.apps.handlers.json import json_handler
|
||||
from aipass.drone.apps.handlers.rm_handler import (
|
||||
safe_delete as _safe_delete,
|
||||
)
|
||||
|
||||
DRONE_MODULE = {
|
||||
"name": "rm",
|
||||
"version": "1.0.0",
|
||||
"description": "Contained safe-delete (project + tmp)",
|
||||
}
|
||||
|
||||
|
||||
def safe_delete(paths: list[str]) -> list[tuple[str, bool, str]]:
|
||||
"""Delete paths with containment checks.
|
||||
|
||||
Returns list of ``(original_path, success, message)`` tuples.
|
||||
"""
|
||||
logger.info("rm: requested deletion of %d path(s)", len(paths))
|
||||
return _safe_delete(paths)
|
||||
|
||||
|
||||
def handle_command(command: str | None = None, args: list[str] | None = None) -> bool:
|
||||
"""Entry point for ``drone rm`` module routing."""
|
||||
if not args:
|
||||
if command is None:
|
||||
print_introspection()
|
||||
return True
|
||||
args = []
|
||||
if command in ("--help", "-h") or (args and args[0] in ("--help", "-h")):
|
||||
print_help()
|
||||
return True
|
||||
|
||||
json_handler.log_operation("rm_command", {"command": command, "args": args})
|
||||
|
||||
paths: list[str] = []
|
||||
if command is not None:
|
||||
paths.append(command)
|
||||
if args:
|
||||
paths.extend(args)
|
||||
|
||||
if not paths:
|
||||
print_help()
|
||||
return True
|
||||
|
||||
results = _safe_delete(paths)
|
||||
ok = True
|
||||
for _path_str, success, message in results:
|
||||
if success:
|
||||
console.print(f"[green]✓[/green] {message}")
|
||||
else:
|
||||
console.print(f"[red]✗[/red] {message}")
|
||||
ok = False
|
||||
return ok
|
||||
|
||||
|
||||
def print_introspection() -> None:
|
||||
"""Display module overview (no args)."""
|
||||
console.print()
|
||||
console.print("[bold cyan]rm — Contained Safe-Delete[/bold cyan]")
|
||||
console.print()
|
||||
console.print("[dim]Deletes files and directories constrained to project root and system tmp.[/dim]")
|
||||
console.print()
|
||||
console.print("Run [green]'drone rm --help'[/green] for usage information")
|
||||
console.print()
|
||||
|
||||
|
||||
def print_help() -> None:
|
||||
"""Display help (--help flag)."""
|
||||
console.print("Usage: drone rm <path> [<path>...]")
|
||||
console.print()
|
||||
console.print("Contained safe-delete. Removes files and directories using pure Python")
|
||||
console.print("(shutil.rmtree), constrained to the project root and system temp directory.")
|
||||
console.print()
|
||||
console.print("[bold]Rules:[/bold]")
|
||||
console.print(" • Path must resolve under the project root or system temp dir")
|
||||
console.print(" • Cannot delete the project root or temp root itself")
|
||||
console.print(" • Symlinks are resolved; refuses if target escapes allowed roots")
|
||||
console.print(" • Nonexistent paths produce a clean error")
|
||||
console.print()
|
||||
console.print("[bold]Examples:[/bold]")
|
||||
console.print(" [green]drone rm /tmp/scratch_dir[/green]")
|
||||
console.print(" [green]drone rm build/ dist/[/green]")
|
||||
console.print(" [green]drone rm /tmp/aipass_test_abc123[/green]")
|
||||
@@ -126,17 +126,19 @@ def print_introspection():
|
||||
console = Console()
|
||||
|
||||
console.print()
|
||||
console.print("router Module")
|
||||
console.print("Command routing logic for the AIPass drone module.")
|
||||
console.print("[bold cyan]router Module[/bold cyan]")
|
||||
console.print("[dim]Command routing logic for the AIPass drone module.[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/")
|
||||
console.print(" - router_handler.py (execute_branch_command — resolves and executes branch commands)")
|
||||
console.print(" - executor.py (CommandResult — subprocess execution result dataclass)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/[/cyan]")
|
||||
console.print(
|
||||
" - [cyan]router_handler.py[/cyan] [dim](execute_branch_command — resolves and executes branch commands)[/dim]"
|
||||
)
|
||||
console.print(" - [cyan]executor.py[/cyan] [dim](CommandResult — subprocess execution result dataclass)[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Modules:")
|
||||
console.print(" modules/")
|
||||
console.print(" - resolver.py (resolve_branch, list_branches — branch name resolution)")
|
||||
console.print("[yellow]Connected Modules:[/yellow]")
|
||||
console.print(" [cyan]modules/[/cyan]")
|
||||
console.print(" - [cyan]resolver.py[/cyan] [dim](resolve_branch, list_branches — branch name resolution)[/dim]")
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -76,17 +76,17 @@ def print_introspection() -> None:
|
||||
console = Console()
|
||||
|
||||
console.print()
|
||||
console.print("scan Module")
|
||||
console.print("Branch command scanning -- discover available commands in a branch.")
|
||||
console.print("[bold cyan]scan Module[/bold cyan]")
|
||||
console.print("[dim]Branch command scanning -- discover available commands in a branch.[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Handlers:")
|
||||
console.print(" handlers/scanning/")
|
||||
console.print(" - scanner.py (scan_branch, scan_help_output, scan_module_files)")
|
||||
console.print(" - formatters.py (format_scan_results, format_no_commands)")
|
||||
console.print("[yellow]Connected Handlers:[/yellow]")
|
||||
console.print(" [cyan]handlers/scanning/[/cyan]")
|
||||
console.print(" - [cyan]scanner.py[/cyan] [dim](scan_branch, scan_help_output, scan_module_files)[/dim]")
|
||||
console.print(" - [cyan]formatters.py[/cyan] [dim](format_scan_results, format_no_commands)[/dim]")
|
||||
console.print()
|
||||
console.print("Connected Modules:")
|
||||
console.print(" modules/")
|
||||
console.print(" - resolver.py (resolve_branch -- branch name resolution)")
|
||||
console.print("[yellow]Connected Modules:[/yellow]")
|
||||
console.print(" [cyan]modules/[/cyan]")
|
||||
console.print(" - [cyan]resolver.py[/cyan] [dim](resolve_branch -- branch name resolution)[/dim]")
|
||||
console.print()
|
||||
|
||||
|
||||
|
||||
@@ -22,6 +22,9 @@ from aipass.drone.apps.handlers.json import json_handler
|
||||
from aipass.drone.apps.handlers.git.lock_handler import find_repo_root
|
||||
|
||||
|
||||
PROTECTED_BRANCHES = ("dev", "main")
|
||||
|
||||
|
||||
def merge_pr(pr_number: str, caller: str) -> dict:
|
||||
"""Merge a PR and sync local main.
|
||||
|
||||
@@ -43,9 +46,30 @@ def merge_pr(pr_number: str, caller: str) -> dict:
|
||||
}
|
||||
|
||||
try:
|
||||
# Step 1: Merge the PR
|
||||
# Step 0: Get PR head ref to decide delete-branch behavior
|
||||
head_proc = subprocess.run(
|
||||
["gh", "pr", "view", pr_number, "--json", "headRefName", "--jq", ".headRefName"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
cwd=str(repo_root),
|
||||
)
|
||||
head_ref = head_proc.stdout.strip() if head_proc.returncode == 0 else ""
|
||||
|
||||
# Step 1: Merge the PR — only delete the head branch when we can
|
||||
# POSITIVELY confirm it is a non-protected branch. If the head ref is
|
||||
# unknown (gh lookup failed → empty string), fail SAFE and never delete:
|
||||
# this is the exact path that destroyed `dev` in S183.
|
||||
merge_cmd = ["gh", "pr", "merge", pr_number, "--merge"]
|
||||
if head_ref and head_ref not in PROTECTED_BRANCHES:
|
||||
merge_cmd.append("--delete-branch")
|
||||
elif not head_ref:
|
||||
logger.warning(
|
||||
"merge_pr: could not determine PR #%s head ref — skipping --delete-branch (fail-safe)",
|
||||
pr_number,
|
||||
)
|
||||
|
||||
merge = subprocess.run(
|
||||
["gh", "pr", "merge", pr_number, "--merge", "--delete-branch"],
|
||||
merge_cmd,
|
||||
capture_output=True,
|
||||
text=True,
|
||||
cwd=str(repo_root),
|
||||
@@ -126,6 +150,27 @@ def merge_pr(pr_number: str, caller: str) -> dict:
|
||||
)
|
||||
title = title_proc.stdout.strip() if title_proc.returncode == 0 else "unknown"
|
||||
|
||||
# Step 5: Return to dev branch
|
||||
current_branch = subprocess.run(
|
||||
["git", "rev-parse", "--abbrev-ref", "HEAD"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
cwd=str(repo_root),
|
||||
)
|
||||
on_branch = current_branch.stdout.strip() if current_branch.returncode == 0 else ""
|
||||
if on_branch != "dev":
|
||||
checkout_dev = subprocess.run(
|
||||
["git", "checkout", "dev"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
cwd=str(repo_root),
|
||||
)
|
||||
if checkout_dev.returncode != 0:
|
||||
logger.warning(
|
||||
"merge_pr: WARNING — could not return to dev (on '%s'). Next commit may land on wrong branch!",
|
||||
on_branch,
|
||||
)
|
||||
|
||||
result["success"] = True
|
||||
result["title"] = title
|
||||
result["merge_commit"] = merge_commit
|
||||
|
||||
+22
-1
@@ -1,3 +1,11 @@
|
||||
# =================== AIPass ====================
|
||||
# Name: cli.py
|
||||
# Description: Drone CLI entry point — console_scripts wrapper
|
||||
# Version: 1.0.0
|
||||
# Created: 2026-03-05
|
||||
# Modified: 2026-06-04
|
||||
# =============================================
|
||||
|
||||
"""
|
||||
Drone CLI — command-line interface for aipass.drone.
|
||||
|
||||
@@ -19,8 +27,21 @@ import sys
|
||||
# Windows terminals default to cp1252 which can't encode Rich's Unicode
|
||||
# characters (box-drawing, em dashes, arrows). Force UTF-8 before any
|
||||
# imports that trigger Rich output.
|
||||
#
|
||||
# PYTHONUTF8 only affects *child* interpreters launched afterward — it does
|
||||
# nothing for this process's already-open stdout/stderr, which were created
|
||||
# with the cp1252 codec at interpreter startup. Rich writes through those
|
||||
# live streams, so we must reconfigure them in place (Python 3.7+). Without
|
||||
# this, `drone @branch` crashes with UnicodeEncodeError ('charmap') when it
|
||||
# prints a routed branch's captured output on Windows.
|
||||
if sys.platform == "win32":
|
||||
os.environ.setdefault("PYTHONUTF8", "1")
|
||||
os.environ.setdefault("PYTHONUTF8", "1") # for child subprocesses
|
||||
for _stream in (sys.stdout, sys.stderr):
|
||||
# getattr guard: streams replaced by a capture layer (e.g. pytest) or
|
||||
# not backed by a TextIOWrapper simply lack reconfigure — skip them.
|
||||
_reconfigure = getattr(_stream, "reconfigure", None)
|
||||
if _reconfigure is not None:
|
||||
_reconfigure(encoding="utf-8", errors="replace")
|
||||
|
||||
from aipass.drone.apps.drone import main as _drone_main
|
||||
|
||||
|
||||
@@ -597,17 +597,17 @@ class TestHandleTarget:
|
||||
patch(f"{_DRONE}.is_module", return_value=True),
|
||||
patch(f"{_DRONE}._handle_module", return_value=0) as mock_hm,
|
||||
):
|
||||
result = _handle_target(["@git", "status"])
|
||||
result = _handle_target(["@git", "diff"])
|
||||
assert result == 0
|
||||
mock_hm.assert_called_once_with("git", ["status"])
|
||||
mock_hm.assert_called_once_with("git", ["diff"])
|
||||
|
||||
def test_no_args_introspection(self) -> None:
|
||||
"""@target with no args routes via route_command for introspection."""
|
||||
"""@target with no args routes via route_command with interactive=True."""
|
||||
from aipass.drone.apps.drone import _handle_target
|
||||
from aipass.drone.apps.handlers.executor import CommandResult
|
||||
|
||||
mock_result = CommandResult(
|
||||
stdout="introspection",
|
||||
stdout="",
|
||||
stderr="",
|
||||
exit_code=0,
|
||||
branch="seedgo",
|
||||
@@ -615,22 +615,31 @@ class TestHandleTarget:
|
||||
)
|
||||
with (
|
||||
patch(f"{_DRONE}.is_module", return_value=False),
|
||||
patch(f"{_DRONE}.route_command", return_value=mock_result),
|
||||
patch(f"{_DRONE}.route_command", return_value=mock_result) as mock_route,
|
||||
):
|
||||
result = _handle_target(["@seedgo"])
|
||||
assert result == 0
|
||||
mock_route.assert_called_once_with("@seedgo", interactive=True)
|
||||
|
||||
def test_help_flag(self) -> None:
|
||||
"""@target --help routes via get_help."""
|
||||
"""@target --help routes via route_command with interactive=True."""
|
||||
from aipass.drone.apps.drone import _handle_target
|
||||
from aipass.drone.apps.handlers.executor import CommandResult
|
||||
|
||||
mock_help = type("H", (), {"text": "Help text"})()
|
||||
mock_result = CommandResult(
|
||||
stdout="",
|
||||
stderr="",
|
||||
exit_code=0,
|
||||
branch="seedgo",
|
||||
command="--help",
|
||||
)
|
||||
with (
|
||||
patch(f"{_DRONE}.is_module", return_value=False),
|
||||
patch(f"{_DRONE}.get_help", return_value=mock_help),
|
||||
patch(f"{_DRONE}.route_command", return_value=mock_result) as mock_route,
|
||||
):
|
||||
result = _handle_target(["@seedgo", "--help"])
|
||||
assert result == 0
|
||||
mock_route.assert_called_once_with("@seedgo", "--help", interactive=True)
|
||||
|
||||
def test_command_routing(self) -> None:
|
||||
"""@target command routes via route_command."""
|
||||
@@ -651,6 +660,49 @@ class TestHandleTarget:
|
||||
result = _handle_target(["@seedgo", "audit", "aipass"])
|
||||
assert result == 0
|
||||
|
||||
def test_short_help_flag(self) -> None:
|
||||
"""@target -h routes via route_command with interactive=True."""
|
||||
from aipass.drone.apps.drone import _handle_target
|
||||
from aipass.drone.apps.handlers.executor import CommandResult
|
||||
|
||||
mock_result = CommandResult(stdout="", stderr="", exit_code=0, branch="seedgo", command="-h")
|
||||
with (
|
||||
patch(f"{_DRONE}.is_module", return_value=False),
|
||||
patch(f"{_DRONE}.route_command", return_value=mock_result) as mock_route,
|
||||
):
|
||||
result = _handle_target(["@seedgo", "-h"])
|
||||
assert result == 0
|
||||
mock_route.assert_called_once_with("@seedgo", "-h", interactive=True)
|
||||
|
||||
def test_status_routes_interactive(self) -> None:
|
||||
"""status command routes with interactive=True for Rich color output."""
|
||||
from aipass.drone.apps.drone import _handle_target
|
||||
from aipass.drone.apps.handlers.executor import CommandResult
|
||||
|
||||
mock_result = CommandResult(stdout="", stderr="", exit_code=0, branch="hooks", command="status")
|
||||
with (
|
||||
patch(f"{_DRONE}.is_module", return_value=False),
|
||||
patch(f"{_DRONE}.route_command", return_value=mock_result) as mock_route,
|
||||
):
|
||||
result = _handle_target(["@hooks", "status"])
|
||||
assert result == 0
|
||||
call_kwargs = mock_route.call_args.kwargs
|
||||
assert call_kwargs["interactive"] is True
|
||||
|
||||
def test_help_flag_module_fallback(self) -> None:
|
||||
"""--help BranchNotFoundError for a module falls back to _handle_module."""
|
||||
from aipass.drone.apps.drone import _handle_target
|
||||
from aipass.drone.apps.modules import BranchNotFoundError
|
||||
|
||||
with (
|
||||
patch(f"{_DRONE}.is_module", side_effect=[False, True]),
|
||||
patch(f"{_DRONE}.route_command", side_effect=BranchNotFoundError("not found")),
|
||||
patch(f"{_DRONE}._handle_module", return_value=0) as mock_hm,
|
||||
):
|
||||
result = _handle_target(["@seedgo", "--help"])
|
||||
assert result == 0
|
||||
mock_hm.assert_called_once_with("seedgo", ["--help"])
|
||||
|
||||
def test_branch_not_found_module_fallback(self) -> None:
|
||||
"""BranchNotFoundError for a module falls back to _handle_module."""
|
||||
from aipass.drone.apps.drone import _handle_target
|
||||
|
||||
@@ -842,9 +842,14 @@ def _run_merge_success(cmd: list[str], **kwargs: object) -> MagicMock:
|
||||
r.stderr = ""
|
||||
r.stdout = ""
|
||||
if cmd[0] == "gh" and cmd[1] == "pr" and cmd[2] == "view":
|
||||
r.stdout = "Fix the thing\n"
|
||||
if "--jq" in cmd and ".headRefName" in cmd:
|
||||
r.stdout = "citizen/test-branch\n"
|
||||
else:
|
||||
r.stdout = "Fix the thing\n"
|
||||
elif cmd[1:3] == ["rev-parse", "HEAD"]:
|
||||
r.stdout = "abc123def456\n"
|
||||
elif cmd[1:3] == ["rev-parse", "--abbrev-ref"]:
|
||||
r.stdout = "dev\n"
|
||||
return r
|
||||
|
||||
|
||||
@@ -909,3 +914,380 @@ class TestTriggerFireIntegration:
|
||||
|
||||
assert result["success"] is True
|
||||
mock_trigger.fire.assert_any_call("pr_merged", pr_number="42", title="Fix the thing")
|
||||
|
||||
|
||||
# ===========================================================================
|
||||
# Fix 1 & 2: Protected-branch merge + return-to-dev (#625)
|
||||
# ===========================================================================
|
||||
|
||||
_MERGE_MOD = "aipass.drone.apps.plugins.devpulse_ops.merge_plugin"
|
||||
|
||||
|
||||
def _merge_side_effect(head_ref: str, current_branch: str = "main"):
|
||||
"""Build a subprocess mock for merge_pr with configurable head ref."""
|
||||
|
||||
def _run(cmd: list[str], **kwargs: object) -> MagicMock:
|
||||
r = MagicMock()
|
||||
r.returncode = 0
|
||||
r.stderr = ""
|
||||
r.stdout = ""
|
||||
if cmd[0] == "gh" and "view" in cmd:
|
||||
if ".headRefName" in cmd:
|
||||
r.stdout = f"{head_ref}\n"
|
||||
else:
|
||||
r.stdout = "PR Title\n"
|
||||
elif cmd[1:3] == ["rev-parse", "HEAD"]:
|
||||
r.stdout = "abc123\n"
|
||||
elif cmd[1:3] == ["rev-parse", "--abbrev-ref"]:
|
||||
r.stdout = f"{current_branch}\n"
|
||||
elif cmd[1:3] == ["checkout", "dev"]:
|
||||
r.returncode = 0
|
||||
return r
|
||||
|
||||
return _run
|
||||
|
||||
|
||||
class TestMergeProtectedBranch:
|
||||
"""Fix 1: --delete-branch omitted for protected branches (dev, main)."""
|
||||
|
||||
def test_dev_head_no_delete_branch(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""When PR head is dev, merge command must NOT include --delete-branch."""
|
||||
from aipass.drone.apps.plugins.devpulse_ops.merge_plugin import merge_pr
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
calls: list[list[str]] = []
|
||||
|
||||
def _capture(cmd: list[str], **kw: object) -> MagicMock:
|
||||
calls.append(list(cmd))
|
||||
return _merge_side_effect("dev", "dev")(cmd, **kw)
|
||||
|
||||
with patch(f"{_MERGE_MOD}.subprocess.run", side_effect=_capture):
|
||||
result = merge_pr("10", "devpulse")
|
||||
|
||||
assert result["success"] is True
|
||||
merge_calls = [c for c in calls if c[:3] == ["gh", "pr", "merge"]]
|
||||
assert len(merge_calls) == 1
|
||||
assert "--delete-branch" not in merge_calls[0]
|
||||
|
||||
def test_temp_branch_has_delete_branch(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""When PR head is a temp branch, merge command includes --delete-branch."""
|
||||
from aipass.drone.apps.plugins.devpulse_ops.merge_plugin import merge_pr
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
calls: list[list[str]] = []
|
||||
|
||||
def _capture(cmd: list[str], **kw: object) -> MagicMock:
|
||||
calls.append(list(cmd))
|
||||
return _merge_side_effect("citizen/feature-x", "dev")(cmd, **kw)
|
||||
|
||||
with patch(f"{_MERGE_MOD}.subprocess.run", side_effect=_capture):
|
||||
result = merge_pr("20", "devpulse")
|
||||
|
||||
assert result["success"] is True
|
||||
merge_calls = [c for c in calls if c[:3] == ["gh", "pr", "merge"]]
|
||||
assert "--delete-branch" in merge_calls[0]
|
||||
|
||||
def test_unknown_head_ref_fails_safe_no_delete(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""When the PR head ref can't be determined (empty), fail SAFE: never delete.
|
||||
|
||||
Guards the exact path that destroyed `dev` in S183 — if gh can't report
|
||||
the head ref we must not fall back to deleting the branch.
|
||||
"""
|
||||
from aipass.drone.apps.plugins.devpulse_ops.merge_plugin import merge_pr
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
calls: list[list[str]] = []
|
||||
|
||||
def _capture(cmd: list[str], **kw: object) -> MagicMock:
|
||||
calls.append(list(cmd))
|
||||
return _merge_side_effect("", "dev")(cmd, **kw)
|
||||
|
||||
with patch(f"{_MERGE_MOD}.subprocess.run", side_effect=_capture):
|
||||
result = merge_pr("30", "devpulse")
|
||||
|
||||
assert result["success"] is True
|
||||
merge_calls = [c for c in calls if c[:3] == ["gh", "pr", "merge"]]
|
||||
assert len(merge_calls) == 1
|
||||
assert "--delete-branch" not in merge_calls[0]
|
||||
|
||||
|
||||
class TestMergeReturnToDev:
|
||||
"""Fix 2: After merge+sync, checkout dev (or warn if can't)."""
|
||||
|
||||
def test_checkout_dev_after_merge(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""merge_pr issues 'git checkout dev' when not already on dev."""
|
||||
from aipass.drone.apps.plugins.devpulse_ops.merge_plugin import merge_pr
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
calls: list[list[str]] = []
|
||||
|
||||
def _capture(cmd: list[str], **kw: object) -> MagicMock:
|
||||
calls.append(list(cmd))
|
||||
return _merge_side_effect("citizen/x", "main")(cmd, **kw)
|
||||
|
||||
with patch(f"{_MERGE_MOD}.subprocess.run", side_effect=_capture):
|
||||
result = merge_pr("30", "devpulse")
|
||||
|
||||
assert result["success"] is True
|
||||
checkout_calls = [c for c in calls if c[1:3] == ["checkout", "dev"]]
|
||||
assert len(checkout_calls) == 1
|
||||
|
||||
def test_no_checkout_when_already_on_dev(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""merge_pr skips checkout dev when already on dev."""
|
||||
from aipass.drone.apps.plugins.devpulse_ops.merge_plugin import merge_pr
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
calls: list[list[str]] = []
|
||||
|
||||
def _capture(cmd: list[str], **kw: object) -> MagicMock:
|
||||
calls.append(list(cmd))
|
||||
return _merge_side_effect("citizen/y", "dev")(cmd, **kw)
|
||||
|
||||
with patch(f"{_MERGE_MOD}.subprocess.run", side_effect=_capture):
|
||||
result = merge_pr("31", "devpulse")
|
||||
|
||||
assert result["success"] is True
|
||||
checkout_calls = [c for c in calls if c[1:3] == ["checkout", "dev"]]
|
||||
assert len(checkout_calls) == 0
|
||||
|
||||
|
||||
# ===========================================================================
|
||||
# Fix 3: Live-remote branches — fetch --prune before listing (#625)
|
||||
# ===========================================================================
|
||||
|
||||
_BRANCHES_MOD = "aipass.drone.apps.handlers.git.branches_handler"
|
||||
|
||||
|
||||
class TestBranchesFetchPrune:
|
||||
"""Fix 3: list_remote_branches runs fetch --prune before git branch -r."""
|
||||
|
||||
def test_fetch_prune_before_list(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""fetch --prune is called before git branch -r."""
|
||||
from aipass.drone.apps.handlers.git.branches_handler import list_remote_branches
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
calls: list[list[str]] = []
|
||||
|
||||
def _capture(cmd: list[str], **kw: object) -> MagicMock:
|
||||
calls.append(list(cmd))
|
||||
r = MagicMock()
|
||||
r.returncode = 0
|
||||
r.stderr = ""
|
||||
r.stdout = " origin/main\n origin/dev\n"
|
||||
return r
|
||||
|
||||
with patch(f"{_BRANCHES_MOD}.subprocess.run", side_effect=_capture):
|
||||
result = list_remote_branches()
|
||||
|
||||
assert result["count"] == 2
|
||||
cmd_summaries = [" ".join(c[:3]) for c in calls]
|
||||
assert "git fetch --prune" in cmd_summaries
|
||||
prune_idx = cmd_summaries.index("git fetch --prune")
|
||||
branch_idx = cmd_summaries.index("git branch -r")
|
||||
assert prune_idx < branch_idx
|
||||
|
||||
def test_deleted_branch_not_listed(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""After prune, deleted remote branches do not appear."""
|
||||
from aipass.drone.apps.handlers.git.branches_handler import list_remote_branches
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
def _run(cmd: list[str], **kw: object) -> MagicMock:
|
||||
r = MagicMock()
|
||||
r.returncode = 0
|
||||
r.stderr = ""
|
||||
if cmd[1:3] == ["branch", "-r"]:
|
||||
r.stdout = " origin/main\n origin/dev\n"
|
||||
else:
|
||||
r.stdout = ""
|
||||
return r
|
||||
|
||||
with patch(f"{_BRANCHES_MOD}.subprocess.run", side_effect=_run):
|
||||
result = list_remote_branches()
|
||||
|
||||
assert "deleted-branch" not in result["branches"]
|
||||
assert result["branches"] == ["main", "dev"]
|
||||
|
||||
def test_offline_graceful(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""When fetch --prune fails (offline), listing still works with warning."""
|
||||
from aipass.drone.apps.handlers.git.branches_handler import list_remote_branches
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
call_count = {"prune": 0}
|
||||
|
||||
def _run(cmd: list[str], **kw: object) -> MagicMock:
|
||||
r = MagicMock()
|
||||
r.returncode = 0
|
||||
r.stderr = ""
|
||||
if cmd[1:3] == ["fetch", "--prune"]:
|
||||
call_count["prune"] += 1
|
||||
r.returncode = 1
|
||||
r.stderr = "fatal: Could not read from remote repository."
|
||||
elif cmd[1:3] == ["branch", "-r"]:
|
||||
r.stdout = " origin/main\n"
|
||||
else:
|
||||
r.stdout = ""
|
||||
return r
|
||||
|
||||
with patch(f"{_BRANCHES_MOD}.subprocess.run", side_effect=_run):
|
||||
result = list_remote_branches()
|
||||
|
||||
assert call_count["prune"] == 1
|
||||
assert result["count"] == 1
|
||||
assert result["branches"] == ["main"]
|
||||
|
||||
|
||||
# ===========================================================================
|
||||
# Fix 4: Temp-branch hygiene — prune_temp_branches (#625)
|
||||
# ===========================================================================
|
||||
|
||||
|
||||
class TestPruneTempBranches:
|
||||
"""Fix 4: prune_temp_branches deletes merged citizen/* branches."""
|
||||
|
||||
def test_prunes_merged_citizen_branches(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""Merged citizen/* branches are deleted."""
|
||||
from aipass.drone.apps.handlers.git.branches_handler import prune_temp_branches
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
def _run(cmd: list[str], **kw: object) -> MagicMock:
|
||||
r = MagicMock()
|
||||
r.returncode = 0
|
||||
r.stderr = ""
|
||||
if cmd[1:3] == ["branch", "--merged"]:
|
||||
r.stdout = " main\n dev\n citizen/drone-fix\n citizen/seedgo-pr\n"
|
||||
elif cmd[1:3] == ["branch", "-d"]:
|
||||
r.stdout = f"Deleted branch {cmd[3]}\n"
|
||||
return r
|
||||
|
||||
with patch(f"{_BRANCHES_MOD}.subprocess.run", side_effect=_run):
|
||||
result = prune_temp_branches()
|
||||
|
||||
assert result["count"] == 2
|
||||
assert "citizen/drone-fix" in result["pruned"]
|
||||
assert "citizen/seedgo-pr" in result["pruned"]
|
||||
|
||||
def test_skips_non_citizen_branches(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""Non-citizen branches (main, dev, feature/*) are not pruned."""
|
||||
from aipass.drone.apps.handlers.git.branches_handler import prune_temp_branches
|
||||
|
||||
registry = tmp_path / "AIPASS_REGISTRY.json"
|
||||
registry.write_text("{}", encoding="utf-8")
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
def _run(cmd: list[str], **kw: object) -> MagicMock:
|
||||
r = MagicMock()
|
||||
r.returncode = 0
|
||||
r.stderr = ""
|
||||
if cmd[1:3] == ["branch", "--merged"]:
|
||||
r.stdout = "* main\n dev\n feature/old\n"
|
||||
return r
|
||||
|
||||
with patch(f"{_BRANCHES_MOD}.subprocess.run", side_effect=_run):
|
||||
result = prune_temp_branches()
|
||||
|
||||
assert result["count"] == 0
|
||||
assert result["pruned"] == []
|
||||
|
||||
|
||||
# ===========================================================================
|
||||
# Fix 5: Scope clarity footer on status/diff (#623)
|
||||
# ===========================================================================
|
||||
|
||||
_GIT_MOD = "aipass.drone.apps.modules.git_module"
|
||||
|
||||
|
||||
_AUTH = "aipass.drone.apps.plugins.devpulse_ops.auth.verify_git_access"
|
||||
|
||||
|
||||
class TestScopeFooter:
|
||||
"""Fix 5: Scoped status/diff shows footer, --all does not."""
|
||||
|
||||
@patch(_AUTH, return_value="test_branch")
|
||||
def test_status_scoped_shows_footer(
|
||||
self, _mock_auth: MagicMock, tmp_path: Path, monkeypatch: pytest.MonkeyPatch
|
||||
) -> None:
|
||||
"""Scoped status output includes scope footer."""
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
with patch(f"{_GIT_MOD}._detect_branch_dir", return_value=("drone", tmp_path / "src" / "drone")):
|
||||
with patch(
|
||||
f"{_GIT_MOD}.status_handler.get_branch_status",
|
||||
return_value={"files": [], "total": 0, "message": "0 file(s) changed under src/drone"},
|
||||
):
|
||||
result = handle_command("status", [])
|
||||
|
||||
assert "(showing drone scope" in result["stdout"]
|
||||
assert "--all for full repo)" in result["stdout"]
|
||||
|
||||
@patch(_AUTH, return_value="test_branch")
|
||||
def test_status_all_no_footer(self, _mock_auth: MagicMock, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""--all status output does NOT include scope footer."""
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
with patch(f"{_GIT_MOD}._detect_branch_dir", return_value=("drone", tmp_path / "src" / "drone")):
|
||||
with patch(f"{_GIT_MOD}.lock_handler.find_repo_root", return_value=tmp_path):
|
||||
with patch(
|
||||
f"{_GIT_MOD}.status_handler.get_branch_status",
|
||||
return_value={"files": [], "total": 0, "message": "0 file(s) changed in repo"},
|
||||
):
|
||||
result = handle_command("status", ["--all"])
|
||||
|
||||
assert "showing drone scope" not in result["stdout"]
|
||||
|
||||
@patch(_AUTH, return_value="test_branch")
|
||||
def test_diff_scoped_shows_footer(
|
||||
self, _mock_auth: MagicMock, tmp_path: Path, monkeypatch: pytest.MonkeyPatch
|
||||
) -> None:
|
||||
"""Scoped diff output includes scope footer."""
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
with patch(f"{_GIT_MOD}._detect_branch_dir", return_value=("drone", tmp_path / "src" / "drone")):
|
||||
with patch(
|
||||
f"{_GIT_MOD}.diff_handler.get_branch_diff",
|
||||
return_value={"diff": "", "files_changed": 0, "message": "0 file(s) changed"},
|
||||
):
|
||||
result = handle_command("diff", [])
|
||||
|
||||
assert "(showing drone scope" in result["stdout"]
|
||||
|
||||
@patch(_AUTH, return_value="test_branch")
|
||||
def test_diff_all_no_footer(self, _mock_auth: MagicMock, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||
"""--all diff output does NOT include scope footer."""
|
||||
monkeypatch.chdir(tmp_path)
|
||||
|
||||
with patch(f"{_GIT_MOD}._detect_branch_dir", return_value=("drone", tmp_path / "src" / "drone")):
|
||||
with patch(f"{_GIT_MOD}.lock_handler.find_repo_root", return_value=tmp_path):
|
||||
with patch(
|
||||
f"{_GIT_MOD}.diff_handler.get_branch_diff",
|
||||
return_value={"diff": "some diff", "files_changed": 1, "message": "1 file(s)"},
|
||||
):
|
||||
result = handle_command("diff", ["--all"])
|
||||
|
||||
assert "showing drone scope" not in result["stdout"]
|
||||
|
||||
@@ -447,3 +447,95 @@ class TestResolverPathContainment:
|
||||
assert "legit" in result
|
||||
finally:
|
||||
reset_registry_path()
|
||||
|
||||
|
||||
# ===========================================================================
|
||||
# Cross-project resolution (issue #618)
|
||||
# ===========================================================================
|
||||
|
||||
|
||||
class TestCrossProjectResolution:
|
||||
"""resolve_branch() uses the source registry root for containment, not always the primary."""
|
||||
|
||||
def test_cross_project_resolves_via_aipass_home(self, tmp_path: Path, monkeypatch):
|
||||
"""Branch found via AIPASS_HOME resolves even when primary registry is a different project."""
|
||||
# External project with its own registry
|
||||
ext_project = tmp_path / "external_project"
|
||||
ext_project.mkdir()
|
||||
ext_reg = ext_project / "EXT_REGISTRY.json"
|
||||
_write_registry(ext_reg, [_make_branch("local_branch", "src/local_branch")])
|
||||
|
||||
# AIPass project with @target branch
|
||||
aipass_root = tmp_path / "aipass"
|
||||
target_dir = aipass_root / "src" / "aipass" / "target"
|
||||
target_dir.mkdir(parents=True)
|
||||
aipass_reg = aipass_root / "AIPASS_REGISTRY.json"
|
||||
_write_registry(
|
||||
aipass_reg,
|
||||
[_make_branch("target", str(target_dir))],
|
||||
)
|
||||
|
||||
# Primary registry = external project, AIPASS_HOME = aipass root
|
||||
set_registry_path(ext_reg)
|
||||
monkeypatch.setenv("AIPASS_HOME", str(aipass_root))
|
||||
try:
|
||||
result = resolve_branch("@target")
|
||||
assert str(target_dir) in result
|
||||
finally:
|
||||
reset_registry_path()
|
||||
|
||||
def test_genuine_escape_still_blocked(self, tmp_path: Path, monkeypatch):
|
||||
"""Branch whose path escapes its OWN declaring registry root is still blocked."""
|
||||
ext_project = tmp_path / "external_project"
|
||||
ext_project.mkdir()
|
||||
ext_reg = ext_project / "EXT_REGISTRY.json"
|
||||
_write_registry(ext_reg, [])
|
||||
|
||||
aipass_root = tmp_path / "aipass"
|
||||
aipass_root.mkdir()
|
||||
aipass_reg = aipass_root / "AIPASS_REGISTRY.json"
|
||||
_write_registry(
|
||||
aipass_reg,
|
||||
[_make_branch("evil", "../../../tmp/escape")],
|
||||
)
|
||||
|
||||
set_registry_path(ext_reg)
|
||||
monkeypatch.setenv("AIPASS_HOME", str(aipass_root))
|
||||
try:
|
||||
with pytest.raises(BranchNotFoundError):
|
||||
resolve_branch("@evil")
|
||||
finally:
|
||||
reset_registry_path()
|
||||
|
||||
def test_same_project_regression(self, tmp_path: Path, monkeypatch):
|
||||
"""Same-project resolution still works (no regression)."""
|
||||
branch_dir = tmp_path / "src" / "aipass" / "mybranch"
|
||||
branch_dir.mkdir(parents=True)
|
||||
reg_file = tmp_path / "AIPASS_REGISTRY.json"
|
||||
_write_registry(
|
||||
reg_file,
|
||||
[_make_branch("mybranch", "src/aipass/mybranch")],
|
||||
)
|
||||
|
||||
set_registry_path(reg_file)
|
||||
monkeypatch.delenv("AIPASS_HOME", raising=False)
|
||||
try:
|
||||
result = resolve_branch("@mybranch")
|
||||
assert "mybranch" in result
|
||||
finally:
|
||||
reset_registry_path()
|
||||
|
||||
def test_branch_exists_still_works(self, tmp_path: Path, monkeypatch):
|
||||
"""branch_exists() is unaffected by the get_branch_with_registry change."""
|
||||
branch_dir = tmp_path / "src" / "aipass" / "alpha"
|
||||
branch_dir.mkdir(parents=True)
|
||||
reg_file = tmp_path / "AIPASS_REGISTRY.json"
|
||||
_write_registry(reg_file, [_make_branch("alpha", "src/aipass/alpha")])
|
||||
|
||||
set_registry_path(reg_file)
|
||||
monkeypatch.delenv("AIPASS_HOME", raising=False)
|
||||
try:
|
||||
assert branch_exists("@alpha") is True
|
||||
assert branch_exists("@nonexistent") is False
|
||||
finally:
|
||||
reset_registry_path()
|
||||
|
||||
@@ -0,0 +1,571 @@
|
||||
"""Tests for drone rm — contained safe-delete.
|
||||
|
||||
Red-team containment tests verify that paths outside allowed roots
|
||||
are refused, including symlink escapes and traversal attempts.
|
||||
Carve-out tests verify .git, .trinity, .aipass, .codex, .agents,
|
||||
and sibling branches are protected even inside allowed roots.
|
||||
"""
|
||||
|
||||
import os
|
||||
import shutil
|
||||
import tempfile
|
||||
from pathlib import Path
|
||||
from unittest.mock import patch
|
||||
|
||||
import pytest
|
||||
|
||||
from aipass.drone.apps.handlers.rm_handler import (
|
||||
check_carveouts,
|
||||
check_containment,
|
||||
get_allowed_roots,
|
||||
safe_delete,
|
||||
)
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Fixtures
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
@pytest.fixture()
|
||||
def project_dir(tmp_path):
|
||||
"""Fake project root with a registry file and src/aipass layout."""
|
||||
(tmp_path / "AIPASS_REGISTRY.json").write_text("{}")
|
||||
return tmp_path
|
||||
|
||||
|
||||
@pytest.fixture()
|
||||
def project_with_branches(project_dir):
|
||||
"""Project root with src/aipass/<branch> layout for sibling tests."""
|
||||
for branch in ("drone", "api", "flow"):
|
||||
d = project_dir / "src" / "aipass" / branch
|
||||
d.mkdir(parents=True)
|
||||
(d / "README.md").write_text(f"# {branch}")
|
||||
return project_dir
|
||||
|
||||
|
||||
@pytest.fixture()
|
||||
def _patch_roots(project_dir):
|
||||
"""Patch get_allowed_roots to use deterministic test roots."""
|
||||
tmpdir = Path(tempfile.gettempdir()).resolve()
|
||||
slash_tmp = Path("/tmp").resolve()
|
||||
roots = [project_dir.resolve()]
|
||||
seen = set(roots)
|
||||
for r in (slash_tmp, tmpdir):
|
||||
if r not in seen:
|
||||
seen.add(r)
|
||||
roots.append(r)
|
||||
with patch(
|
||||
"aipass.drone.apps.handlers.rm_handler.get_allowed_roots",
|
||||
return_value=roots,
|
||||
):
|
||||
yield
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# get_allowed_roots
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class TestGetAllowedRoots:
|
||||
def test_includes_temp_dir(self):
|
||||
roots = get_allowed_roots()
|
||||
tmpdir = Path(tempfile.gettempdir()).resolve()
|
||||
assert tmpdir in roots
|
||||
|
||||
def test_includes_slash_tmp(self):
|
||||
roots = get_allowed_roots()
|
||||
assert Path("/tmp").resolve() in roots
|
||||
|
||||
def test_includes_project_root_when_in_project(self, project_dir, monkeypatch):
|
||||
monkeypatch.chdir(project_dir)
|
||||
roots = get_allowed_roots()
|
||||
assert project_dir.resolve() in roots
|
||||
|
||||
def test_temp_dir_always_present_even_without_project(self, tmp_path, monkeypatch):
|
||||
monkeypatch.chdir(tmp_path)
|
||||
roots = get_allowed_roots()
|
||||
tmpdir = Path(tempfile.gettempdir()).resolve()
|
||||
assert tmpdir in roots
|
||||
|
||||
def test_tmpdir_and_slash_tmp_both_present_when_different(self, monkeypatch):
|
||||
"""When $TMPDIR != /tmp, both must appear in roots."""
|
||||
fake_tmpdir = "/tmp/claude-9999"
|
||||
os.makedirs(fake_tmpdir, exist_ok=True)
|
||||
try:
|
||||
monkeypatch.setenv("TMPDIR", fake_tmpdir)
|
||||
tempfile.tempdir = None
|
||||
roots = get_allowed_roots()
|
||||
resolved_roots = {r for r in roots}
|
||||
assert Path("/tmp").resolve() in resolved_roots
|
||||
assert Path(fake_tmpdir).resolve() in resolved_roots
|
||||
finally:
|
||||
tempfile.tempdir = None
|
||||
|
||||
def test_roots_are_deduplicated(self):
|
||||
roots = get_allowed_roots()
|
||||
assert len(roots) == len(set(roots))
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# check_containment
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class TestCheckContainment:
|
||||
def test_allows_child_of_root(self, tmp_path):
|
||||
root = tmp_path.resolve()
|
||||
child = (tmp_path / "sub" / "file.txt").resolve()
|
||||
allowed, reason = check_containment(child, [root])
|
||||
assert allowed is True
|
||||
assert reason == ""
|
||||
|
||||
def test_refuses_root_itself(self, tmp_path):
|
||||
root = tmp_path.resolve()
|
||||
allowed, reason = check_containment(root, [root])
|
||||
assert allowed is False
|
||||
assert "root directory itself" in reason
|
||||
|
||||
def test_refuses_outside_path(self, tmp_path):
|
||||
root = tmp_path.resolve()
|
||||
outside = Path("/etc/passwd").resolve()
|
||||
allowed, reason = check_containment(outside, [root])
|
||||
assert allowed is False
|
||||
assert "outside allowed roots" in reason
|
||||
|
||||
def test_allows_second_root(self, tmp_path):
|
||||
root1 = (tmp_path / "a").resolve()
|
||||
root2 = (tmp_path / "b").resolve()
|
||||
child = (tmp_path / "b" / "file.txt").resolve()
|
||||
allowed, _ = check_containment(child, [root1, root2])
|
||||
assert allowed is True
|
||||
|
||||
def test_refuses_empty_roots(self, tmp_path):
|
||||
child = (tmp_path / "file.txt").resolve()
|
||||
allowed, _reason = check_containment(child, [])
|
||||
assert allowed is False
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# ALLOW: valid deletions
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class TestAllowDeletion:
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_delete_dir_in_tmp(self):
|
||||
target = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
(target / "file.txt").write_text("data")
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
assert not target.exists()
|
||||
finally:
|
||||
if target.exists():
|
||||
shutil.rmtree(target)
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_delete_nested_tmp_dir(self):
|
||||
"""e.g. /tmp/claude-1000/<x>."""
|
||||
parent = Path(tempfile.mkdtemp())
|
||||
target = parent / "nested"
|
||||
target.mkdir()
|
||||
(target / "data.txt").write_text("hello")
|
||||
try:
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
assert not target.exists()
|
||||
finally:
|
||||
if parent.exists():
|
||||
shutil.rmtree(parent)
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_delete_file_in_project(self, project_dir):
|
||||
target = project_dir / "build" / "output.o"
|
||||
target.parent.mkdir(parents=True)
|
||||
target.write_text("binary")
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
assert not target.exists()
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_delete_subdir_in_project(self, project_dir):
|
||||
target = project_dir / "sub" / "scratch"
|
||||
target.mkdir(parents=True)
|
||||
(target / "temp.txt").write_text("scratch")
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
assert not target.exists()
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_delete_multiple_paths(self):
|
||||
t1 = Path(tempfile.mkdtemp())
|
||||
t2 = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
results = safe_delete([str(t1), str(t2)])
|
||||
assert all(r[1] for r in results)
|
||||
assert not t1.exists()
|
||||
assert not t2.exists()
|
||||
finally:
|
||||
for t in [t1, t2]:
|
||||
if t.exists():
|
||||
shutil.rmtree(t)
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_pure_python_no_subprocess(self):
|
||||
"""Verify shutil.rmtree is used, not subprocess rm."""
|
||||
target = Path(tempfile.mkdtemp())
|
||||
(target / "f.txt").write_text("x")
|
||||
with patch("subprocess.run") as mock_run, patch("subprocess.Popen") as mock_popen:
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
mock_run.assert_not_called()
|
||||
mock_popen.assert_not_called()
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_project_build_dir_allowed(self, project_dir):
|
||||
"""Regression guard: ordinary project dirs are still deletable."""
|
||||
target = project_dir / "build"
|
||||
target.mkdir()
|
||||
(target / "out.js").write_text("x")
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_project_dist_dir_allowed(self, project_dir):
|
||||
"""Regression guard: dist/ is not a carve-out."""
|
||||
target = project_dir / "dist"
|
||||
target.mkdir()
|
||||
(target / "bundle.js").write_text("x")
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_slash_tmp_literal_allowed(self):
|
||||
"""/tmp/<x> must succeed even if $TMPDIR differs."""
|
||||
target = Path("/tmp") / f"rm_test_{os.getpid()}"
|
||||
target.mkdir(exist_ok=True)
|
||||
try:
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
assert not target.exists()
|
||||
finally:
|
||||
if target.exists():
|
||||
shutil.rmtree(target)
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_tmpdir_env_allowed(self):
|
||||
"""$TMPDIR/<x> must succeed."""
|
||||
target = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
results = safe_delete([str(target)])
|
||||
assert results[0][1] is True
|
||||
assert not target.exists()
|
||||
finally:
|
||||
if target.exists():
|
||||
shutil.rmtree(target)
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# REFUSE: red-team containment
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class TestRefuseDeletion:
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_home_dir(self):
|
||||
results = safe_delete([str(Path.home())])
|
||||
assert results[0][1] is False
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_etc(self):
|
||||
results = safe_delete(["/etc"])
|
||||
assert results[0][1] is False
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_root_filesystem(self):
|
||||
results = safe_delete(["/"])
|
||||
assert results[0][1] is False
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_project_root_itself(self, project_dir):
|
||||
results = safe_delete([str(project_dir)])
|
||||
assert results[0][1] is False
|
||||
assert "root directory itself" in results[0][2]
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_tmp_root_itself(self):
|
||||
tmpdir = tempfile.gettempdir()
|
||||
results = safe_delete([tmpdir])
|
||||
assert results[0][1] is False
|
||||
assert "root directory itself" in results[0][2]
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_traversal_escape(self, project_dir, monkeypatch):
|
||||
"""../../etc from inside project should resolve outside and be refused."""
|
||||
subdir = project_dir / "deep" / "nested"
|
||||
subdir.mkdir(parents=True)
|
||||
monkeypatch.chdir(subdir)
|
||||
results = safe_delete(["../../../../../../etc"])
|
||||
assert results[0][1] is False
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_absolute_outside_roots(self):
|
||||
results = safe_delete(["/usr/local/bin"])
|
||||
assert results[0][1] is False
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_symlink_escape_from_tmp(self):
|
||||
"""Symlink under /tmp pointing to /home/user should be refused."""
|
||||
target_outside = Path.home()
|
||||
link_dir = Path(tempfile.mkdtemp())
|
||||
link = link_dir / "escape_link"
|
||||
try:
|
||||
link.symlink_to(target_outside)
|
||||
results = safe_delete([str(link)])
|
||||
assert results[0][1] is False
|
||||
finally:
|
||||
if link.exists() or link.is_symlink():
|
||||
link.unlink()
|
||||
if link_dir.exists():
|
||||
shutil.rmtree(link_dir)
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_nonexistent_path_clean_error(self):
|
||||
results = safe_delete(["/tmp/this_path_does_not_exist_abc123xyz"])
|
||||
assert results[0][1] is False
|
||||
assert "does not exist" in results[0][2]
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_mixed_valid_and_invalid(self, project_dir):
|
||||
"""Valid paths succeed; invalid paths fail independently."""
|
||||
valid = project_dir / "ok_to_delete"
|
||||
valid.mkdir()
|
||||
results = safe_delete([str(valid), "/etc/shadow"])
|
||||
assert results[0][1] is True
|
||||
assert results[1][1] is False
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_home_patrick(self):
|
||||
results = safe_delete(["/home/patrick"])
|
||||
assert results[0][1] is False
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_refuse_var_tmp(self):
|
||||
"""/var/tmp is NOT in the default allowed set (Codex excludes it)."""
|
||||
results = safe_delete(["/var/tmp"])
|
||||
assert results[0][1] is False
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Carve-outs: .git, .trinity, .aipass, .codex, .agents, siblings
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class TestCarveouts:
|
||||
def test_refuse_dot_git_dir(self, project_dir):
|
||||
"""<repo>/.git directory must be refused."""
|
||||
git_dir = project_dir / ".git"
|
||||
git_dir.mkdir()
|
||||
resolved = git_dir.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is True
|
||||
assert ".git" in reason
|
||||
|
||||
def test_refuse_inside_dot_git(self, project_dir):
|
||||
"""Files inside .git/ must be refused."""
|
||||
git_dir = project_dir / ".git" / "objects"
|
||||
git_dir.mkdir(parents=True)
|
||||
resolved = git_dir.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is True
|
||||
assert ".git" in reason
|
||||
|
||||
def test_refuse_dot_trinity(self, project_dir):
|
||||
trinity = project_dir / ".trinity"
|
||||
trinity.mkdir()
|
||||
resolved = trinity.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is True
|
||||
assert ".trinity" in reason
|
||||
|
||||
def test_refuse_inside_dot_trinity(self, project_dir):
|
||||
passport = project_dir / ".trinity" / "passport.json"
|
||||
passport.parent.mkdir(parents=True)
|
||||
passport.write_text("{}")
|
||||
resolved = passport.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is True
|
||||
assert ".trinity" in reason
|
||||
|
||||
def test_refuse_dot_aipass(self, project_dir):
|
||||
aipass_dir = project_dir / ".aipass"
|
||||
aipass_dir.mkdir()
|
||||
resolved = aipass_dir.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is True
|
||||
assert ".aipass" in reason
|
||||
|
||||
def test_refuse_dot_codex(self, project_dir):
|
||||
codex = project_dir / ".codex"
|
||||
codex.mkdir()
|
||||
resolved = codex.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is True
|
||||
assert ".codex" in reason
|
||||
|
||||
def test_refuse_dot_agents(self, project_dir):
|
||||
agents = project_dir / ".agents"
|
||||
agents.mkdir()
|
||||
resolved = agents.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is True
|
||||
assert ".agents" in reason
|
||||
|
||||
def test_allow_normal_project_dir(self, project_dir):
|
||||
"""build/ is not a carve-out."""
|
||||
build = project_dir / "build"
|
||||
build.mkdir()
|
||||
resolved = build.resolve()
|
||||
blocked, _reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is False
|
||||
|
||||
def test_refuse_sibling_branch(self, project_with_branches, monkeypatch):
|
||||
"""From drone CWD, deleting src/aipass/api must be refused."""
|
||||
drone_dir = project_with_branches / "src" / "aipass" / "drone"
|
||||
monkeypatch.chdir(drone_dir)
|
||||
target = project_with_branches / "src" / "aipass" / "api"
|
||||
resolved = target.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_with_branches.resolve())
|
||||
assert blocked is True
|
||||
assert "sibling branch" in reason
|
||||
assert "api" in reason
|
||||
|
||||
def test_allow_own_branch(self, project_with_branches, monkeypatch):
|
||||
"""Deleting a subdir inside own branch must be allowed."""
|
||||
drone_dir = project_with_branches / "src" / "aipass" / "drone"
|
||||
monkeypatch.chdir(drone_dir)
|
||||
target = drone_dir / "build"
|
||||
target.mkdir()
|
||||
resolved = target.resolve()
|
||||
blocked, _reason = check_carveouts(resolved, project_with_branches.resolve())
|
||||
assert blocked is False
|
||||
|
||||
def test_refuse_all_branches_when_outside(self, project_with_branches, monkeypatch):
|
||||
"""When CWD isn't inside any branch, ALL src/aipass/<branch> are refused."""
|
||||
monkeypatch.chdir(project_with_branches)
|
||||
for branch in ("drone", "api", "flow"):
|
||||
target = project_with_branches / "src" / "aipass" / branch
|
||||
resolved = target.resolve()
|
||||
blocked, _reason = check_carveouts(resolved, project_with_branches.resolve())
|
||||
assert blocked is True, f"Expected {branch} to be blocked"
|
||||
|
||||
def test_git_file_worktree_pointer(self, project_dir):
|
||||
"""A .git FILE (worktree pointer) should protect the resolved gitdir."""
|
||||
real_git = project_dir / "real_git_dir"
|
||||
real_git.mkdir()
|
||||
git_file = project_dir / ".git"
|
||||
git_file.write_text(f"gitdir: {real_git}")
|
||||
resolved = git_file.resolve()
|
||||
blocked, reason = check_carveouts(resolved, project_dir.resolve())
|
||||
assert blocked is True
|
||||
assert ".git" in reason
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Carve-outs via safe_delete (integration)
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class TestCarveoutIntegration:
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_safe_delete_refuses_dot_git(self, project_dir):
|
||||
git_dir = project_dir / ".git"
|
||||
git_dir.mkdir()
|
||||
results = safe_delete([str(git_dir)])
|
||||
assert results[0][1] is False
|
||||
assert ".git" in results[0][2]
|
||||
assert git_dir.exists()
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_safe_delete_refuses_trinity(self, project_dir):
|
||||
trinity = project_dir / ".trinity"
|
||||
trinity.mkdir()
|
||||
results = safe_delete([str(trinity)])
|
||||
assert results[0][1] is False
|
||||
assert trinity.exists()
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_safe_delete_refuses_dot_aipass(self, project_dir):
|
||||
aipass_dir = project_dir / ".aipass"
|
||||
aipass_dir.mkdir()
|
||||
results = safe_delete([str(aipass_dir)])
|
||||
assert results[0][1] is False
|
||||
assert aipass_dir.exists()
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_safe_delete_allows_build_dir(self, project_dir):
|
||||
"""Regression guard: build/ and dist/ still allowed."""
|
||||
build = project_dir / "build"
|
||||
build.mkdir()
|
||||
results = safe_delete([str(build)])
|
||||
assert results[0][1] is True
|
||||
assert not build.exists()
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Edge cases
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class TestEdgeCases:
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_relative_path_resolved_from_cwd(self, project_dir, monkeypatch):
|
||||
monkeypatch.chdir(project_dir)
|
||||
target = project_dir / "relative_target"
|
||||
target.mkdir()
|
||||
results = safe_delete(["relative_target"])
|
||||
assert results[0][1] is True
|
||||
assert not target.exists()
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_single_file_deletion(self):
|
||||
fd, path = tempfile.mkstemp()
|
||||
os.close(fd)
|
||||
results = safe_delete([path])
|
||||
assert results[0][1] is True
|
||||
assert not Path(path).exists()
|
||||
|
||||
@pytest.mark.usefixtures("_patch_roots")
|
||||
def test_empty_paths_list(self):
|
||||
results = safe_delete([])
|
||||
assert results == []
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Module orchestrator (rm.py)
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class TestRmModule:
|
||||
def test_handle_command_help(self):
|
||||
from aipass.drone.apps.modules.rm import handle_command
|
||||
|
||||
result = handle_command("--help")
|
||||
assert result is True
|
||||
|
||||
def test_handle_command_introspection(self):
|
||||
from aipass.drone.apps.modules.rm import handle_command
|
||||
|
||||
result = handle_command(None, None)
|
||||
assert result is True
|
||||
|
||||
def test_print_introspection(self):
|
||||
from aipass.drone.apps.modules.rm import print_introspection
|
||||
|
||||
print_introspection()
|
||||
|
||||
def test_print_help(self):
|
||||
from aipass.drone.apps.modules.rm import print_help
|
||||
|
||||
print_help()
|
||||
@@ -6,7 +6,7 @@
|
||||
**Module:** `aipass.flow`
|
||||
**Version:** 2.2.1
|
||||
**Created:** 2025-11-15
|
||||
**Last Updated:** 2026-05-16
|
||||
**Last Updated:** 2026-06-05
|
||||
|
||||
---
|
||||
|
||||
@@ -98,7 +98,7 @@ flow/
|
||||
│ ├── team_dev_plans/ # TDPLAN templates (default)
|
||||
│ └── audit_plans/ # APLAN templates (default)
|
||||
├── flow_json/ # Per-type registries + template_registry.json
|
||||
├── tests/ # 733 tests, 24 test files
|
||||
├── tests/ # 734 tests, 22 test files
|
||||
└── .archive/ # Archived legacy code
|
||||
```
|
||||
|
||||
@@ -159,27 +159,28 @@ Vector verification displays in console: "Vectorized: N chunks in chroma" or "NO
|
||||
### Provides To
|
||||
- All branches — plan creation, tracking, closure, and archival
|
||||
- `aipass.devpulse` — plan status aggregation for system dashboards
|
||||
- Central reporting — `PLANS.central.json` via aggregate
|
||||
- Central reporting — `PLANS.central.json` with per-branch plan sections (all branches, not just flow)
|
||||
|
||||
---
|
||||
|
||||
## Quality
|
||||
|
||||
- **Seedgo:** 100% (35/35 standards)
|
||||
- **Tests:** 733 passed, 87/87 public functions tested (100%)
|
||||
- **Source files:** 39 tracked by seedgo
|
||||
- **Last audit:** 2026-05-16
|
||||
- **Tests:** 734 passed, 87/87 public functions tested (100%)
|
||||
- **Source files:** 40 tracked by seedgo
|
||||
- **Last audit:** 2026-06-05
|
||||
- **Battle test:** 16/16 commands pass via drone CLI (2026-04-22)
|
||||
|
||||
### Known Issues
|
||||
- Registry scan fires trigger events that are never handled (by design — foreground close handles everything)
|
||||
- Dashboard push warns on some closes
|
||||
- `mbank/process.py` at 669 lines (nearing 700 limit)
|
||||
- `close_ops.py` split into `close_ops.py` (647 lines) + `close_helpers.py` (260 lines) in 2026-05-16
|
||||
- `close_ops.py` split into `close_ops.py` (647 lines) + `close_helpers.py` (260 lines)
|
||||
- `push_central.py` comprehensive rewrite (2026-06-02): now pushes all branches' plans, not just flow's — fixed dashboard refresh zeroing other branches' plan counts
|
||||
|
||||
---
|
||||
|
||||
*Last Updated: 2026-05-16*
|
||||
*Last Updated: 2026-06-05*
|
||||
|
||||
---
|
||||
[← Back to AIPass](../../../README.md)
|
||||
|
||||
@@ -9,14 +9,13 @@
|
||||
"""
|
||||
Push to Plans Central Handler
|
||||
|
||||
Pushes Flow's plan data to the central PLANS.central.json file at .ai_central.
|
||||
Pushes plan data for ALL branches to the central PLANS.central.json file at .ai_central.
|
||||
This handler follows the 3-tier logging standard (no Prax imports, no logging).
|
||||
|
||||
Features:
|
||||
- Reads fplan_registry.json to get Flow's plans
|
||||
- Extracts only plans where location='flow' (Flow's own plans)
|
||||
- Updates branches.flow section in PLANS.central.json
|
||||
- Preserves all other branch sections
|
||||
- Reads all per-type plan registries
|
||||
- Groups plans by branch (derived from location path)
|
||||
- Updates per-branch sections in PLANS.central.json
|
||||
- Calls aggregate_central_impl to rebuild top-level active_plans
|
||||
- Calculates global statistics across all branches
|
||||
- Pure handler - returns boolean for success/failure
|
||||
@@ -124,26 +123,29 @@ def _load_registry() -> Dict[str, Any]:
|
||||
return merged
|
||||
|
||||
|
||||
def _extract_flow_plans(registry: Dict[str, Any]) -> tuple[List[Dict], List[Dict]]:
|
||||
"""Extract Flow's own plans from registry
|
||||
def _extract_plans_by_branch(registry: Dict[str, Any]) -> Dict[str, Dict[str, Any]]:
|
||||
"""Extract plans from registry grouped by branch.
|
||||
|
||||
Args:
|
||||
registry: The fplan_registry.json data
|
||||
registry: Merged registry data (all plan types)
|
||||
|
||||
Returns:
|
||||
Tuple of (active_plans, recently_closed_plans)
|
||||
Dict mapping branch_name -> branch section with active_plans,
|
||||
recently_closed, and statistics.
|
||||
"""
|
||||
plans = registry.get("plans", {})
|
||||
active = []
|
||||
closed = []
|
||||
branch_buckets: Dict[str, Dict[str, List]] = {}
|
||||
|
||||
for plan_key, plan_data in plans.items():
|
||||
# Only include plans where location is 'flow' (Flow's own plans)
|
||||
location = plan_data.get("location", "")
|
||||
if location != str(FLOW_ROOT):
|
||||
if not location:
|
||||
continue
|
||||
|
||||
# plan_key is composite PREFIX-NNNN from merged registry
|
||||
branch_name = Path(location).name
|
||||
|
||||
if branch_name not in branch_buckets:
|
||||
branch_buckets[branch_name] = {"active": [], "closed": [], "location": location}
|
||||
|
||||
plan_entry = {
|
||||
"plan_id": plan_key,
|
||||
"subject": plan_data.get("subject", ""),
|
||||
@@ -151,24 +153,35 @@ def _extract_flow_plans(registry: Dict[str, Any]) -> tuple[List[Dict], List[Dict
|
||||
"created": plan_data.get("created", ""),
|
||||
"file_path": plan_data.get("file_path", ""),
|
||||
"relative_path": plan_data.get("relative_path", ""),
|
||||
"branch": branch_name,
|
||||
}
|
||||
|
||||
if plan_data.get("status") == "open":
|
||||
active.append(plan_entry)
|
||||
branch_buckets[branch_name]["active"].append(plan_entry)
|
||||
else:
|
||||
# Add closed metadata
|
||||
plan_entry["closed"] = plan_data.get("closed", "")
|
||||
plan_entry["closed_reason"] = plan_data.get("closed_reason", "")
|
||||
closed.append(plan_entry)
|
||||
branch_buckets[branch_name]["closed"].append(plan_entry)
|
||||
|
||||
# Sort active by created date (newest first)
|
||||
active.sort(key=lambda x: x.get("created", ""), reverse=True)
|
||||
result: Dict[str, Dict[str, Any]] = {}
|
||||
for branch_name, bucket in branch_buckets.items():
|
||||
active = sorted(bucket["active"], key=lambda x: x.get("created", ""), reverse=True)
|
||||
closed = sorted(bucket["closed"], key=lambda x: x.get("closed", ""), reverse=True)
|
||||
recently_closed = closed[:5]
|
||||
|
||||
# Sort closed by closed date (newest first) and limit to last 5
|
||||
closed.sort(key=lambda x: x.get("closed", ""), reverse=True)
|
||||
recently_closed = closed[:5]
|
||||
result[branch_name] = {
|
||||
"branch_name": branch_name.upper(),
|
||||
"branch_path": bucket["location"],
|
||||
"active_plans": active,
|
||||
"recently_closed": recently_closed,
|
||||
"statistics": {
|
||||
"active_count": len(active),
|
||||
"total_closed": len(closed),
|
||||
"recently_closed_included": len(recently_closed),
|
||||
},
|
||||
}
|
||||
|
||||
return active, recently_closed
|
||||
return result
|
||||
|
||||
|
||||
def _load_central() -> Dict[str, Any]:
|
||||
@@ -223,80 +236,45 @@ def _calculate_global_statistics(central_data: Dict[str, Any]) -> Dict[str, int]
|
||||
|
||||
|
||||
def push_to_plans_central() -> bool:
|
||||
"""Push Flow's plan data to .ai_central/PLANS.central.json
|
||||
"""Push plan data for ALL branches to .ai_central/PLANS.central.json
|
||||
|
||||
Algorithm:
|
||||
1. Read fplan_registry.json
|
||||
2. Extract only plans where location='flow' (Flow's own plans)
|
||||
3. Format for central structure with branch metadata
|
||||
4. Read existing PLANS.central.json if exists
|
||||
5. Update ONLY branches.flow section
|
||||
6. Update global_statistics (total counts across all branches)
|
||||
7. Preserve ALL other branch sections
|
||||
8. Write back to PLANS.central.json
|
||||
9. Call aggregate_central_impl to rebuild top-level active_plans with validation
|
||||
1. Read all per-type plan registries
|
||||
2. Group plans by branch (derived from location path)
|
||||
3. Build per-branch sections with active/closed/stats
|
||||
4. Write all branch sections to PLANS.central.json
|
||||
5. Update global_statistics (total counts across all branches)
|
||||
6. Call aggregate_central_impl to rebuild top-level active_plans with validation
|
||||
|
||||
Returns:
|
||||
True on success, False on failure
|
||||
"""
|
||||
try:
|
||||
# Ensure .ai_central directory exists
|
||||
AI_CENTRAL_DIR.mkdir(parents=True, exist_ok=True)
|
||||
|
||||
# Load registry
|
||||
registry = _load_registry()
|
||||
branch_sections = _extract_plans_by_branch(registry)
|
||||
|
||||
# Extract Flow's plans
|
||||
active_plans, recently_closed = _extract_flow_plans(registry)
|
||||
|
||||
# Build Flow's branch section
|
||||
now = datetime.now(timezone.utc).isoformat()
|
||||
flow_section = {
|
||||
"branch_name": "FLOW",
|
||||
"branch_path": str(FLOW_ROOT),
|
||||
"last_updated": now,
|
||||
"active_plans": active_plans,
|
||||
"recently_closed": recently_closed,
|
||||
"statistics": {
|
||||
"active_count": len(active_plans),
|
||||
"total_closed": len(
|
||||
[
|
||||
p
|
||||
for p in registry.get("plans", {}).values()
|
||||
if p.get("location") == str(FLOW_ROOT) and p.get("status") == "closed"
|
||||
]
|
||||
),
|
||||
},
|
||||
}
|
||||
for section in branch_sections.values():
|
||||
section["last_updated"] = now
|
||||
|
||||
# Load existing central file
|
||||
central_data = _load_central()
|
||||
|
||||
# Update Flow's section
|
||||
if "branches" not in central_data:
|
||||
central_data["branches"] = {}
|
||||
central_data["branches"]["flow"] = flow_section
|
||||
|
||||
# Update global statistics
|
||||
central_data["branches"] = branch_sections
|
||||
central_data["global_statistics"] = _calculate_global_statistics(central_data)
|
||||
|
||||
# Update generated_at timestamp
|
||||
central_data["generated_at"] = now
|
||||
|
||||
# Write back to central file
|
||||
with open(CENTRAL_FILE, "w", encoding="utf-8") as f:
|
||||
json.dump(central_data, f, indent=2, ensure_ascii=False)
|
||||
|
||||
# Call aggregate_central_impl to rebuild top-level arrays with validation
|
||||
# This ensures active_plans is built from all branches and validates files exist
|
||||
aggregate_central_impl(heal=True, central_file=CENTRAL_FILE, central_dir=AI_CENTRAL_DIR)
|
||||
|
||||
total_active = sum(len(s.get("active_plans", [])) for s in branch_sections.values())
|
||||
json_handler.log_operation(
|
||||
"plans_central_pushed",
|
||||
{
|
||||
"active_plans": len(active_plans),
|
||||
"recently_closed": len(recently_closed),
|
||||
"branches_reporting": central_data["global_statistics"].get("branches_reporting", 0),
|
||||
"active_plans": total_active,
|
||||
"branches_reporting": len(branch_sections),
|
||||
"success": True,
|
||||
},
|
||||
)
|
||||
|
||||
@@ -278,6 +278,45 @@ def save_registry(data: Dict[str, Any]) -> bool:
|
||||
return False
|
||||
|
||||
|
||||
def _try_override_auto_entry(registry: Dict[str, Any], dir_name: str, new_prefix: str) -> str | None:
|
||||
"""Remove an auto-registered entry so add_type() can re-add with explicit prefix.
|
||||
|
||||
Returns an error message on failure, or None on success.
|
||||
"""
|
||||
existing = registry["types"][dir_name]
|
||||
old_shorthand = existing.get("shorthand", existing.get("prefix", "").lower())
|
||||
old_prefix = existing.get("prefix", "")
|
||||
|
||||
if old_prefix.upper() != new_prefix.upper():
|
||||
old_reg = FLOW_ROOT / "flow_json" / f"{old_shorthand}_registry.json"
|
||||
if old_reg.exists():
|
||||
has_plans = _auto_reg_has_plans(old_reg)
|
||||
if has_plans:
|
||||
return f"Cannot override auto-registered '{dir_name}' — {old_reg.name} has existing plans"
|
||||
old_reg.unlink()
|
||||
|
||||
del registry["types"][dir_name]
|
||||
logger.info(
|
||||
"[%s] Overriding auto-registered type '%s' (%s -> %s)",
|
||||
MODULE_NAME,
|
||||
dir_name,
|
||||
old_prefix,
|
||||
new_prefix,
|
||||
)
|
||||
return None
|
||||
|
||||
|
||||
def _auto_reg_has_plans(reg_path: Path) -> bool:
|
||||
"""Check whether a plan registry file contains any plans."""
|
||||
try:
|
||||
with open(reg_path, "r", encoding="utf-8") as fh:
|
||||
data = json.load(fh)
|
||||
return bool(data.get("plans"))
|
||||
except (json.JSONDecodeError, OSError) as exc:
|
||||
logger.warning("[%s] Could not read plan registry %s: %s", MODULE_NAME, reg_path.name, exc)
|
||||
return False
|
||||
|
||||
|
||||
def add_type(
|
||||
dir_name: str,
|
||||
prefix: str,
|
||||
@@ -304,17 +343,26 @@ def add_type(
|
||||
"""
|
||||
registry = load_registry()
|
||||
|
||||
# Validate: dir_name not already registered
|
||||
if dir_name in registry["types"]:
|
||||
# Allow override of auto-registered entries with explicit prefix
|
||||
existing = registry["types"].get(dir_name)
|
||||
if existing and existing.get("registered_by") != "auto":
|
||||
logger.error(
|
||||
"[%s] Type '%s' is already registered",
|
||||
"[%s] Type '%s' is already registered (by %s)",
|
||||
MODULE_NAME,
|
||||
dir_name,
|
||||
existing.get("registered_by", "unknown"),
|
||||
)
|
||||
return False
|
||||
|
||||
# Validate: prefix not already taken (case-insensitive)
|
||||
if prefix_exists(prefix):
|
||||
if existing and existing.get("registered_by") == "auto":
|
||||
override_err = _try_override_auto_entry(registry, dir_name, prefix)
|
||||
if override_err:
|
||||
logger.error("[%s] %s", MODULE_NAME, override_err)
|
||||
return False
|
||||
|
||||
# Validate: prefix not already taken by another type (case-insensitive)
|
||||
upper = prefix.upper()
|
||||
if any(entry.get("prefix", "").upper() == upper for d, entry in registry["types"].items() if d != dir_name):
|
||||
logger.error(
|
||||
"[%s] Prefix '%s' is already in use by another type",
|
||||
MODULE_NAME,
|
||||
@@ -427,20 +475,6 @@ def remove_type(dir_name: str) -> bool:
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
def prefix_exists(prefix: str) -> bool:
|
||||
"""Check whether any registered type uses *prefix* (case-insensitive).
|
||||
|
||||
Args:
|
||||
prefix: The prefix to look for.
|
||||
|
||||
Returns:
|
||||
True if the prefix is already in use.
|
||||
"""
|
||||
registry = load_registry()
|
||||
upper = prefix.upper()
|
||||
return any(entry.get("prefix", "").upper() == upper for entry in registry["types"].values())
|
||||
|
||||
|
||||
def get_prefix_map() -> Dict[str, str]:
|
||||
"""Return ``{dir_name: prefix}`` for all registered types.
|
||||
|
||||
|
||||
@@ -33,6 +33,7 @@ import sys
|
||||
from pathlib import Path
|
||||
from typing import Any, Dict, Tuple, List
|
||||
|
||||
# ruff: noqa: E402
|
||||
# INFRASTRUCTURE IMPORT PATTERN
|
||||
_PKG_ROOT = Path(__file__).resolve().parents[3] # file.py -> modules/ -> apps/ -> flow/ -> aipass/
|
||||
FLOW_ROOT = _PKG_ROOT / "flow"
|
||||
@@ -124,26 +125,51 @@ def print_introspection():
|
||||
|
||||
def print_help():
|
||||
"""Print help information for create_plan module"""
|
||||
from aipass.flow.apps.handlers.template.registry_ops import load_registry
|
||||
|
||||
console.print()
|
||||
console.print("[bold cyan]create_plan[/bold cyan] — Create new PLAN file")
|
||||
console.print()
|
||||
console.print("[yellow]USAGE:[/yellow]")
|
||||
console.print(' drone @flow create <location> "Subject" [type]')
|
||||
console.print(' drone @flow create <location> "Subject" [template] [type]')
|
||||
console.print()
|
||||
console.print("[yellow]TEMPLATES:[/yellow]")
|
||||
console.print(" default Single task [dim](default)[/dim]")
|
||||
console.print(" master Multi-phase project")
|
||||
console.print()
|
||||
|
||||
registry = load_registry()
|
||||
types = registry.get("types", {})
|
||||
console.print("[yellow]TYPES:[/yellow]")
|
||||
console.print(" (none) FPLAN [dim](default)[/dim]")
|
||||
console.print(" dplan DPLAN")
|
||||
for dir_name, entry in sorted(types.items()):
|
||||
prefix = entry.get("prefix", "???")
|
||||
shorthand = entry.get("shorthand", prefix.lower())
|
||||
if dir_name == "flow_plans":
|
||||
continue
|
||||
templates_dir = FLOW_ROOT / "templates" / dir_name
|
||||
templates = sorted(p.stem for p in templates_dir.glob("*.md")) if templates_dir.is_dir() else []
|
||||
tmpl_hint = f" [dim]templates: {', '.join(templates)}[/dim]" if len(templates) > 1 else ""
|
||||
console.print(f" {shorthand:<12} {prefix}{tmpl_hint}")
|
||||
console.print()
|
||||
|
||||
console.print("[yellow]TEMPLATE SELECTION:[/yellow]")
|
||||
console.print(" The 4th arg selects a non-default template within a type.")
|
||||
console.print(" Any .md file stem in the type's templates/ dir works.")
|
||||
console.print(' [dim]drone @flow create . "Subject" sunday_merge pplan[/dim]')
|
||||
console.print(' [dim]drone @flow create . "Subject" master[/dim] # FPLAN master')
|
||||
console.print()
|
||||
|
||||
console.print("[yellow]EXAMPLES:[/yellow]")
|
||||
console.print(' [dim]drone @flow create . "Implementation task"[/dim] # FPLAN default')
|
||||
console.print(' [dim]drone @flow create . "Multi-phase project" master[/dim] # FPLAN master')
|
||||
console.print(' [dim]drone @flow create . "Design investigation" dplan[/dim] # DPLAN')
|
||||
console.print()
|
||||
|
||||
console.print("[bold]ADD A NEW PLAN TYPE:[/bold]")
|
||||
console.print(" 1. Create templates/<dirname>/ with .md template files")
|
||||
console.print(" 2. drone @flow register <dirname> <PREFIX>")
|
||||
console.print(' 3. drone @flow create . "Subject" <shorthand>')
|
||||
console.print(" [dim]See: drone @flow templates --help[/dim]")
|
||||
console.print()
|
||||
|
||||
|
||||
# =============================================
|
||||
# ORCHESTRATION WORKFLOWS (thin wrappers)
|
||||
|
||||
@@ -26,6 +26,7 @@ import sys
|
||||
from pathlib import Path
|
||||
from typing import List
|
||||
|
||||
# ruff: noqa: E402
|
||||
# INFRASTRUCTURE IMPORT PATTERN
|
||||
_PKG_ROOT = Path(__file__).resolve().parents[3] # file.py -> modules/ -> apps/ -> flow/ -> aipass/
|
||||
FLOW_ROOT = _PKG_ROOT / "flow"
|
||||
@@ -85,6 +86,19 @@ def print_help():
|
||||
console.print(" drone @flow unregister <dir> Remove plan type registration")
|
||||
console.print(" drone @flow scan Find unregistered template directories")
|
||||
console.print()
|
||||
console.print("[bold]HOW TO ADD A NEW PLAN TYPE / SOP TEMPLATE:[/bold]")
|
||||
console.print(" 1. Create a directory under templates/ (e.g. templates/playbook_plans/)")
|
||||
console.print(" 2. Add one or more .md template files (e.g. default.md, sunday_merge.md)")
|
||||
console.print(" 3. Register with your chosen prefix:")
|
||||
console.print(" drone @flow register playbook_plans PBPLAN")
|
||||
console.print(" 4. Create plans:")
|
||||
console.print(' drone @flow create . "Subject" pbplan')
|
||||
console.print(' drone @flow create . "Subject" sunday_merge pbplan')
|
||||
console.print()
|
||||
console.print(" [dim]Auto-registration runs on any flow command if you skip step 3,[/dim]")
|
||||
console.print(" [dim]but derives the prefix automatically. Use register to choose your own.[/dim]")
|
||||
console.print(" [dim]Register overrides an auto-derived prefix if no plans exist yet.[/dim]")
|
||||
console.print()
|
||||
console.print("[yellow]EXAMPLES:[/yellow]")
|
||||
console.print(" [dim]# Register testing/ as TPLAN[/dim]")
|
||||
console.print(" drone @flow register testing TPLAN")
|
||||
|
||||
@@ -0,0 +1,67 @@
|
||||
# {plan_number} - {subject} (PLAYBOOK)
|
||||
|
||||
**Created**: {today}
|
||||
**Branch**: {location}
|
||||
**Status**: Active
|
||||
**Type**: Playbook (SOP run)
|
||||
|
||||
---
|
||||
|
||||
## What Are Playbooks?
|
||||
|
||||
Playbooks (PBPLANs) are **throwaway SOP runs** — a checklist stamped from a reusable
|
||||
template for a recurring operation (Sunday merge, release cut, branch onboarding,
|
||||
incident response). You tick steps off as you go, log what happened, then close.
|
||||
|
||||
- **The template = the SOP.** Stable. Refine it over time as the process improves.
|
||||
- **The instance (this file) = one run.** Disposable. Close when the run is done.
|
||||
|
||||
Closing vectorizes the run to @memory — so the **Run Summary** below (with PR numbers,
|
||||
tags, anything that broke) becomes a searchable trail. Costs nothing, gives history.
|
||||
|
||||
**This is NOT for:** building features (FPLAN), design/investigation (DPLAN),
|
||||
research (RPLAN), or multi-branch builds (TDPLAN). Playbooks are for *operating the
|
||||
system*, not changing it.
|
||||
|
||||
**Add a new SOP:** drop `templates/playbook_plans/<sop_name>.md`, then
|
||||
`drone @flow create . "Subject" <sop_name>`. No registration needed (the type is
|
||||
already registered; the file stem is the shorthand).
|
||||
|
||||
---
|
||||
|
||||
## Steps
|
||||
|
||||
Replace with the actual checklist for this SOP.
|
||||
|
||||
- [ ] Step 1
|
||||
- [ ] Step 2
|
||||
- [ ] Step 3
|
||||
|
||||
---
|
||||
|
||||
## Run Summary
|
||||
|
||||
Fill as you go — this is the vectorized trail. Be specific: PR numbers, tags, SHAs,
|
||||
anything that broke and how it was handled.
|
||||
|
||||
- **Date:** {today}
|
||||
- **Outcome:**
|
||||
- **PRs / tags / commits:**
|
||||
- **Issues hit:**
|
||||
- **Notes for next run:**
|
||||
|
||||
---
|
||||
|
||||
## Listen (TTS-friendly summary)
|
||||
|
||||
Write a plain English summary of this run here. No markdown, no symbols, no tables,
|
||||
no code blocks, no asterisks, no bullet points. Just natural sentences for text to speech.
|
||||
|
||||
---
|
||||
|
||||
## Close Command
|
||||
|
||||
When all steps are ticked and the Run Summary is filled:
|
||||
```bash
|
||||
drone @flow close {plan_number}
|
||||
```
|
||||
@@ -0,0 +1,122 @@
|
||||
# {plan_number} - {subject} (SUNDAY MERGE)
|
||||
|
||||
**Created**: {today}
|
||||
**Branch**: {location}
|
||||
**Status**: Active
|
||||
**Type**: Playbook — Sunday Merge SOP
|
||||
|
||||
---
|
||||
|
||||
## Purpose
|
||||
|
||||
The weekly `dev → main` merge + release tag. Run by **devpulse** (only branch with git
|
||||
write). Tick each step as you go; fill the **Run Summary** with PR numbers and tags for
|
||||
the vectorized trail. Close when done.
|
||||
|
||||
> All git writes go through `drone @git` — **run drone from a branch dir** (it needs
|
||||
> `.trinity/passport.json` in the cwd; running from the repo root fails with "No
|
||||
> passport found"). Read git (`status`, `log`, `diff`, `rev-parse`) is allowed raw.
|
||||
> ⚠️ `drone @git` has **no `tag` verb** — pushing the release tag is a MANUAL step
|
||||
> (Patrick, or raw `git tag`/`push` via `!`). All other writes go through drone.
|
||||
|
||||
---
|
||||
|
||||
## 1. Pre-flight
|
||||
|
||||
- [ ] On `dev`, working tree understood: `drone @git status --all`
|
||||
- [ ] Confirm what's shipping this week — scan uncommitted changes + already-pushed dev commits ahead of main: `git rev-list --count main..dev` (read git, raw ok)
|
||||
- [ ] No surprise files (stray `/tmp` artifacts, test pollution, `.recovery`/`.archive` churn). Clean = archive, never delete.
|
||||
- [ ] Decide: **release tag this week?** (tag = PyPI publish + GitHub Release). If yes, note target version.
|
||||
|
||||
## 2. Verify, commit, CHANGELOG
|
||||
|
||||
- [ ] **Run the CI audit gate LOCALLY before pushing** (local == CI, S199 parity — catches red before the PR): `cd <repo-root> && .venv/bin/python .github/scripts/seedgo_audit.py` → expect all 13 branches `>=100%`, exit 0. Uses a relative `src/aipass` path, so run from the repo **root**, not a branch dir.
|
||||
- [ ] Update `CHANGELOG.md` — add entries under the current week's `[YYYY.WNN]` section (don't batch; mostly done as work landed). Sort into Added / Changed / Fixed.
|
||||
- [ ] Commit: `drone @git commit "msg" --all` (from a branch dir, e.g. devpulse). New/untracked files (e.g. new templates) — confirm they got staged: `git ls-files <path>` after; `--all` may not pick up untracked.
|
||||
- [ ] Every commit pushed — local-only commits are invisible
|
||||
|
||||
## 3. Open / update the PR
|
||||
|
||||
- [ ] `drone @git dev-pr "Week summary: what's shipping"`
|
||||
- [ ] "PR already open" in output = push succeeded onto the existing PR (expected on re-runs)
|
||||
- [ ] Record the PR number → Run Summary
|
||||
|
||||
## 4. Wait for CI green (ALL required checks)
|
||||
|
||||
The PR gate (verified against `.github/workflows/`):
|
||||
- [ ] `ci.yml` → **lint**, **test**, **standards** (= seedgo-audit / the README + 100%-floor check, runs `.github/scripts/seedgo_audit.py`), **coverage**
|
||||
- [ ] `security.yml` → Security Scan / dependency-scan
|
||||
- [ ] `e2e-wheel.yml` → 3-OS wheel smoke (path-filtered: fires on `src/**`, `tests/e2e/**`, `pyproject.toml`)
|
||||
- [ ] `windows-test.yml` / `macos-test.yml` → required checks, run on every PR (must NEVER be path-filtered or they park as "Expected/waiting" forever and block merge)
|
||||
- [ ] If "all green but can't merge": it's usually post-push mergeability **lag**. Confirm ground truth via the public API (no gh, no gate):
|
||||
- `curl -s https://api.github.com/repos/AIOSAI/AIPass/commits/<sha>/check-runs` → all check-runs success (incl. app checks: codecov, CodeQL)
|
||||
- `curl -s https://api.github.com/repos/AIOSAI/AIPass/pulls/<n>` → `mergeable_state: clean`
|
||||
|
||||
## 5. Merge to main
|
||||
|
||||
- [ ] **User's call to merge** — confirm GO
|
||||
- [ ] `drone @git merge <PR#>` (squash-merge)
|
||||
- [ ] ⚠️ **Verify `dev` SURVIVES the merge** (the #625 scar — empirical, every time): `drone @git branches` → `dev` still present; `git rev-parse dev` resolves
|
||||
|
||||
## 6. Post-merge realign
|
||||
|
||||
- [ ] Pull main locally: `drone @git sync`
|
||||
- [ ] If merged via GitHub UI (bypassing `drone @git merge`), fast-forward dev to main so dev doesn't fall behind / revert main-only commits (e.g. Dependabot): dev is an ancestor → `git merge --ff-only main` is clean (via `drone @git`)
|
||||
- [ ] Dependabot / other PRs targeting main: they go green once main has the fix + bots rebase — check after the push
|
||||
|
||||
## 7. Release tag (only if cutting a release)
|
||||
|
||||
**Versioning rule — bump by SIGNIFICANCE, not cadence** (keeps the version from inflating weekly):
|
||||
- **PATCH** (`x.y.Z+1`) = fix / internal / standards / UX only → the default, most weeks
|
||||
- **MINOR** (`x.Y+1.0`) = a new backward-compatible user-facing feature shipped
|
||||
- **MAJOR** (`X+1.0.0`) = breaking public-API change
|
||||
|
||||
(aipass is a 2.x library others pin → keep SemVer; the CHANGELOG keeps its `YYYY.WNN` header as a date index.)
|
||||
|
||||
How the release fires (verified `publish.yml`): a `v*` **git tag push** runs build → PyPI publish → GitHub Release. Key facts:
|
||||
- PyPI version = `pyproject.toml [project] version` at the tagged commit — **NOT** the tag string (the tag only *triggers* the build).
|
||||
- Tag and `pyproject` version **must match** (`v2.5.2` ⇄ `version = "2.5.2"`), or PyPI publishes the wrong number while the Release is named the tag.
|
||||
- PyPI **rejects a duplicate version** → if shipping, you MUST bump.
|
||||
- GitHub Release notes = the **topmost `## [...]` CHANGELOG block** (awk-extracted).
|
||||
|
||||
Steps:
|
||||
- [ ] Bump `pyproject.toml` version per the rule above, **on dev so it rides into the PR** (then main's merge commit carries the right version)
|
||||
- [ ] Confirm the CHANGELOG top section is the release notes you want
|
||||
- [ ] **Push the tag — MANUAL (drone has no `tag` verb):** Patrick, or raw `git tag v<version> <main-sha>` + `git push origin v<version>` via `!`, on the merged main commit
|
||||
- [ ] Verify PyPI shows the new version + the GitHub Release appeared
|
||||
- [ ] Record the tag → Run Summary
|
||||
|
||||
## 8. Wrap
|
||||
|
||||
- [ ] Update `.trinity/` memories (session log: what merged, PR#, tag)
|
||||
- [ ] Fill **Run Summary** below (PR numbers, tag, anything that broke)
|
||||
- [ ] Close this playbook → vectorizes the run
|
||||
|
||||
---
|
||||
|
||||
## Run Summary
|
||||
|
||||
- **Date:** {today}
|
||||
- **Outcome:** (merged clean / issues / no-merge)
|
||||
- **PR(s) merged:** #
|
||||
- **Release tag:** v
|
||||
- **CI notes:** (any flaky/red checks + how cleared)
|
||||
- **dev survived merge:** yes / no
|
||||
- **Issues hit:**
|
||||
- **Notes for next run:** (refine this SOP — what was missing or wrong?)
|
||||
|
||||
---
|
||||
|
||||
## Listen (TTS-friendly summary)
|
||||
|
||||
Write a plain English summary of this Sunday merge here when done. No markdown, no symbols,
|
||||
no tables, no code blocks, no asterisks, no bullet points. Just natural sentences for text to speech.
|
||||
|
||||
---
|
||||
|
||||
## Close Command
|
||||
|
||||
When all steps are ticked and the Run Summary is filled:
|
||||
```bash
|
||||
drone @flow close {plan_number}
|
||||
```
|
||||
@@ -939,89 +939,6 @@ class TestDiscoverPlanTypes:
|
||||
assert result == {}
|
||||
|
||||
|
||||
# ===================================================================
|
||||
# 9. template/registry_ops.py — prefix_exists
|
||||
# ===================================================================
|
||||
|
||||
|
||||
class TestPrefixExists:
|
||||
def test_existing_prefix_returns_true(self, tmp_path):
|
||||
"""prefix_exists returns True for a registered prefix."""
|
||||
registry = {
|
||||
"types": {
|
||||
"flow_plans": {"prefix": "FPLAN", "shorthand": "fplan"},
|
||||
},
|
||||
"metadata": {"version": "1.0.0", "last_updated": "2026-03-18", "type_count": 1},
|
||||
}
|
||||
reg_path = tmp_path / "template_registry.json"
|
||||
reg_path.write_text(json.dumps(registry), encoding="utf-8")
|
||||
|
||||
# Also create the templates dir so auto-heal does not prune
|
||||
templates_dir = tmp_path / "templates" / "flow_plans"
|
||||
templates_dir.mkdir(parents=True)
|
||||
|
||||
with (
|
||||
patch(
|
||||
"aipass.flow.apps.handlers.template.registry_ops.REGISTRY_PATH",
|
||||
reg_path,
|
||||
),
|
||||
patch("aipass.flow.apps.handlers.template.registry_ops.FLOW_ROOT", tmp_path),
|
||||
):
|
||||
from aipass.flow.apps.handlers.template.registry_ops import prefix_exists
|
||||
|
||||
assert prefix_exists("FPLAN") is True
|
||||
|
||||
def test_case_insensitive_match(self, tmp_path):
|
||||
"""prefix_exists is case-insensitive."""
|
||||
registry = {
|
||||
"types": {
|
||||
"flow_plans": {"prefix": "FPLAN", "shorthand": "fplan"},
|
||||
},
|
||||
"metadata": {"version": "1.0.0", "last_updated": "2026-03-18", "type_count": 1},
|
||||
}
|
||||
reg_path = tmp_path / "template_registry.json"
|
||||
reg_path.write_text(json.dumps(registry), encoding="utf-8")
|
||||
|
||||
templates_dir = tmp_path / "templates" / "flow_plans"
|
||||
templates_dir.mkdir(parents=True)
|
||||
|
||||
with (
|
||||
patch(
|
||||
"aipass.flow.apps.handlers.template.registry_ops.REGISTRY_PATH",
|
||||
reg_path,
|
||||
),
|
||||
patch("aipass.flow.apps.handlers.template.registry_ops.FLOW_ROOT", tmp_path),
|
||||
):
|
||||
from aipass.flow.apps.handlers.template.registry_ops import prefix_exists
|
||||
|
||||
assert prefix_exists("fplan") is True
|
||||
|
||||
def test_nonexistent_prefix_returns_false(self, tmp_path):
|
||||
"""prefix_exists returns False for an unregistered prefix."""
|
||||
registry = {
|
||||
"types": {
|
||||
"flow_plans": {"prefix": "FPLAN", "shorthand": "fplan"},
|
||||
},
|
||||
"metadata": {"version": "1.0.0", "last_updated": "2026-03-18", "type_count": 1},
|
||||
}
|
||||
reg_path = tmp_path / "template_registry.json"
|
||||
reg_path.write_text(json.dumps(registry), encoding="utf-8")
|
||||
|
||||
templates_dir = tmp_path / "templates" / "flow_plans"
|
||||
templates_dir.mkdir(parents=True)
|
||||
|
||||
with (
|
||||
patch(
|
||||
"aipass.flow.apps.handlers.template.registry_ops.REGISTRY_PATH",
|
||||
reg_path,
|
||||
),
|
||||
patch("aipass.flow.apps.handlers.template.registry_ops.FLOW_ROOT", tmp_path),
|
||||
):
|
||||
from aipass.flow.apps.handlers.template.registry_ops import prefix_exists
|
||||
|
||||
assert prefix_exists("ZPLAN") is False
|
||||
|
||||
|
||||
# ===================================================================
|
||||
# 10. template/registry_ops.py — get_prefix_map
|
||||
# ===================================================================
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user