b3d1a4b552
CHANGELOG: add the 3 post-S300 fix entries under [2026-07-11] for the PR659 merge (watchdog Monitor double-fire -> stderr banner fix + README rewrite note; watchdog test thread-race flakes thread-scoped; seedgo-audit 99%->100% regression fixes). Docs-only, per merge PPLAN-0007 step 2.
AIOSAI2026-07-11 21:45:03 -07:00
b206832209
devpulse watchdog: banner off stdout -> stderr, kills the spurious arm-time wake (VERA feedback 315c005e, #693 follow-on). The 'invoke via Monitor tool' reminder printed via console.print to STDOUT at arm time; the Monitor tool treats every stdout line as a wake event -> every armed watchdog double-fired (spurious wake at ~0s, real wake at completion). Hit EVERYONE: my night-shift telegram logs show me repeatedly dismissing 'the known invoke-via-Monitor noise banners' instead of fixing them; VERA, cold, got woken with no completion attached. Fix: route via err_console (Monitor ignores stderr; stdout = completion/stall events only per the #634 contract; error() stays wrong -> #661 exit-code fail-flag). Verified live: watchdog agent @spawn -> stdout carries ONLY the completion result, banner+debug on stderr. 142 watchdog tests pass, ruff clean.
AIOSAI2026-07-11 21:04:03 -07:00
90048069d0
fix seedgo-audit red on PR659 (2 branches 99%, from S300 commits) + kill the flake that blocked this commit's first gate run. AUDIT: aipass doctor.py _fix_owner_seating had 2 silent catches (FileNotFoundError/TimeoutExpired returned WARN without logging) -> added logger.info/warning matching sibling _check_owner_seating; devpulse README claimed 407 tests (pytest pass count incl parametrized) but readme checker counts test FUNCTIONS -> corrected to 309 (grep-verified). Both re-audit 100% locally; aipass doctor tests 133 pass. FLAKE: test_watchdog_agent bounce/lock-removal/replied tests patched GLOBAL time.sleep with unguarded fakes (agent_handler.time IS the time module) -> prax daemon threads ran the side effect concurrently, re-truncating last_bounce.json mid-read in _classify_exit -> JSONDecodeError path -> exit_code None != 1 (failed the gate suite run, passes isolated). Fix: _agent_only_sleep caller-frame guard (same as yesterdays _fake_clock_sleep, 766d697e) on all 3 tests; 17 pass 3x deterministic.
AIOSAI2026-07-11 18:46:36 -07:00
766d697e08
devpulse: watchdog/feedback README rewrite (was stale, missed everything that tripped VERA) + fix thread-unsafe watchdog test + true up branch-prompt timeout. README (last touched 06-23) predated the owner gate and Monitor-tool wake: now documents owner-only gating (seated owner:true, doctor --fix repairs), the 3-step wake mechanic (dispatch -> arm via Monitor TOOL -> Monitor return IS the wake; '1 monitor' IS the indicator), why passive wake-back can NEVER reach an interactive session (BLOCKED line = by design), cross-project @target resolution, 600s default + --timeout, stall events; feedback re-documented as THE owner-to-owner cross-project channel (Patrick ruling: cross-project comms impossible by design except feedback). TEST FIX: test_watchdog_agent _fake_clock_sleep patched GLOBAL time.sleep with a stateful fake -> prax logger's 3 daemon threads raced the fake clock forward and unlinked the fixture lock before watch_agent read it (nondeterministic 'no active lock' + uptime-sized elapsed; failed 4x today, passed in the same-day full-repo sweep). Fix: thread-scope the fake via caller-frame check (only agent-module sleeps advance the clock; foreign threads get a real 1ms sleep). Verified 17 pass 3x deterministic, devpulse suite 407 green. Branch prompt: watchdog default timeout claim corrected 1800s -> 600s (hit live: 3 watchdogs expired mid-build at ~600s).
AIOSAI2026-07-11 17:58:18 -07:00
d511576fc0
DPLAN-0239 owner seating permanent+self-healing, fixes#693 (VERA seated, is_owner @vera=True). ROOT CAUSE: pre-2026-07-10 projects seated owner only in the self-editable passport, never the sealed registry (old ensure_project_has_owner bailed on passport owner:true without writing registry) -> 8/8 external projects unseated, get_owner None -> guard refused @vera watchdog/feedback/wake; + registry_id was a PROJECT id copied everywhere (13 AIPass entries shared one, metadata.id absent), drifting on registry recreation. IDENTITY MODEL (Patrick ruled): metadata.id=project credential (passports conform, majority-consensus restore); entry registry_id=set-once PER-CITIZEN UUID minted at add_to_registry; entry owner:true=the gate, ONE heuristic pick_owner_branch (manager->passport-owner->first-created) shared by create+reconcile. NEW: spawn sync-registry --check(--json, 7 flags, pinned schema)/--fix(--dry-run fully read-only, idempotent, never moves a seated owner); aipass doctor renders flags, doctor --fix/install/init-update delegate repair to spawn (the missing 0231 PART-4 retro-trigger, works from external project dirs); adopt path now seats; placeholders resolves registry from target dir not CWD, fails loud; hooks auto_watchdog injects real Monitor-tool command w/ @target (was dead one-liner + run_in_background which cannot wake). 4 dispatch rounds; devpulse verify caught 4 gaps round-1 tests missed (schema divergence->pinned v2, dry-run wrote via old-sync fix=True, unanimous->majority consensus vs BACKUP outlier, dual seating heuristic). DEPLOYED: AIPass dogfooded (restore metadata.id 7087bb93 majority 13/14, 16 citizen UIDs, --check clean, doctor owner OK) + 6 external projects reconciled/verified clean incl Vera-Studio (Seat VERA + 3 UIDs). Suites: spawn 343, aipass 673, hooks 961; full-repo 9364 pass (1 pre-existing skills litter -> #694). CHANGELOG updated.
AIOSAI2026-07-11 17:15:47 -07:00
380eca813b
ai_mail: make 2 non-hermetic tests deterministic (flaked CI on PR659). test_get_pid_cwd_darwin_failure called real lsof (subprocess.run) + test_is_zombie_linux_no_proc called real open(/proc/...) for fixed PIDs 999/99999 -> on runners where that PID exists they returned non-None -> intermittent test(3.10) failures. Mocked subprocess.run + builtins.open so both assert the failure contract without touching real process/proc state. Test-only (test_wake.py). Verified 79 pass 5x deterministic. Pre-existing (not from the Windows campaign).
AIOSAI2026-07-11 12:30:36 -07:00
ca096295a3
Windows CI cross-platform fixes (14 failures -> windows-setup green, PR659). Unmasked by the #691 collection fix; 6 branches. CAUSE 1 pid-liveness (ai_mail/flow/hooks/skills): production _is_pid_alive already cross-plat (ctypes OpenProcess on win32), but tests mocked os.kill which the win32 path never reaches -> pinned sys.platform=linux (or patched _is_pid_alive) so tests exercise the POSIX contract on every platform. CAUSE 2 path assumptions: prax jsonl str(Path) backslash, hooks rollover repr()/%r, ai_mail darwin lsof fixed posix path, seedgo is_bypassed Path.as_posix normalization (only production change). 10 files (9 test, 1 code). Owners self-fixed; devpulse verified diffs + Linux no-regression 525 changed-test green. CI Windows verifies.
AIOSAI2026-07-11 12:16:28 -07:00
7c9309cf88
prax: make flaky test_deletes_old_system_log deterministic (was blocking green CI on PR659). Root cause = dual module identity: test_logging_handlers.py sys.modules.pop+reimports log_watchdog, so test_sweep's string-path patch of _get_system_logs_dir could hit a different object than the function __globals__ -> sweep scanned real (empty) system_logs -> files_removed=0 -> intermittent assert 0==1 (same commit passed one CI run, failed another). Fix: direct 'import log_watchdog as lw' + patch.object(lw,...) (shared __dict__) + patch json_handler to block real IO. Test-only (1 file). Verified: prax 978 green, interacting pair 5x deterministic, @prax full-repo 2x 11019 pass.
AIOSAI2026-07-11 10:35:41 -07:00
74a08df800#691 fix full-repo RUNTIME collision: fully-qualify handler.py lazy imports + test_handler_routing patch targets. CI (not isolation) exposed it: handler.py used bare 'from apps.handlers.X import Y' and the tests patched bare 'apps.handlers.X' -> in a whole-repo run bare apps resolves to the WRONG branch (AttributeError/ModuleNotFoundError, 17 test_handler_routing failures). FQ'd both to aipass.skills.lib.telegram.apps.handlers.* (handler.py 7 lazy imports now house-rule compliant; skill runtime verified via drone @skills run telegram status). Verified full-repo: 0 test_handler_routing failures (was 17), 11019 passed, isolation telegram 663 pass (no collateral). Only remaining local fail is pre-existing skills_json/ghost_config.json litter (gitignored, green in CI).
AIOSAI2026-07-11 09:53:32 -07:00
8a606c8c2b#691 ruff format the 6 telegram test files @skills left unformatted (lint job runs ruff format --check). Whitespace/line-wrap only, 0 semantic change; ruff check + format --check now clean, 289 tests on the 6 files green. Fixes the lint red on deffa0c.
AIOSAI2026-07-11 09:11:14 -07:00
deffa0c912#691 telegram tests CI-safe: fully-qualified imports + hermetic network-block fixture. 16 test files bare 'from apps.handlers' -> 'aipass.skills.lib.telegram.apps.handlers' (+ patch targets) — bare 'apps' collided with other branches' apps at full-repo collection -> ~16 collection errors -> CI red. Verify caught ~11 tests hitting live api.telegram.org (base_bot->set_bot_commands->urlopen, never ran in CI before); added session autouse _block_network conftest fixture patching urlopen on 4 telegram modules (bare+fq, guarded) so live calls fail loud not hang. Test-infra only, product byte-unchanged, 0 assertion changes. Full-repo collect 0 errors (11028); telegram 663 pass/0 fail/0 hang. devpulse independently re-verified.
AIOSAI2026-07-11 09:06:34 -07:00
c244b7bf3f
test(drone): isolate cwd in test_pr_no_branch_dir + test_pr_no_args. Both called handle_command('pr', ...) expecting exit 1 (auth error) but lacked monkeypatch.chdir(tmp_path) — a real checkout's findable passport made auth PASS -> exit 0, failing only when run from the repo root (full-suite run). Added chdir(tmp_path) isolation matching sibling test_status_no_branch_dir; assertions unchanged. drone 864 pass / 0 fail. Pre-existing flake surfaced by the night-shift full-repo run.
AIOSAI2026-07-11 03:42:04 -07:00
84177485ce
#686/#661 night shift wave 5 completion (commons): Output_Routing 61->100% (worst score in the fleet). 22 modules route status/error console.print through cli error()/success()/warning() with ImportError-safe fallback binding. No test changes needed; 449 tests pass. FLEET COMPLETE: all 14 offenders at 100%, 17/17 branches at 100% seedgo.
AIOSAI2026-07-11 03:20:05 -07:00
497ab98abc
#686/#661 night shift wave 4 completion (aipass): -> 100% seedgo. aipass.py main() intercepts <cmd> --help before dispatch (Subcommand_Help ->100). Output_Routing ->100: 31 status prints across doctor/init_flow/handoff/profile routed via cli success()/error()/warning(). Modules ->100: auto_wire_provider extracted to NEW handler provider_wire.py, prompt_auto_wire made private (doctor_wire.py). Tests updated (test_doctor patch targets, test_init_flow success routing). Full suite re-run by devpulse: 657 pass / 0 fail. Audit 100% incl Modules.
AIOSAI2026-07-11 03:04:28 -07:00
2defe9d615
#686/#661 night shift wave 5 (cli): -> 100% seedgo. cli.py main() intercepts <cmd> --help before dispatch (Subcommand_Help ->100). display.py error()/warning()/fatal() refactored from markup-string console.print to Rich Text objects — SAME output, avoids the output_routing flag on cli's own shared helpers (Output_Routing ->100). Behavior-preserving (identical stderr/emoji/color, fatal still exits 1), zero fleet blast radius. 140 tests pass. aipass + commons still in flight.
AIOSAI2026-07-11 02:58:47 -07:00
7fb65f0255
#686/#661 night shift wave 4 (trigger + api): both -> 100% seedgo. trigger.py + api.py main() intercept <cmd> --help before dispatch (Subcommand_Help ->100). Output_Routing ->100: trigger (branch_log_events/errors/log_events/medic) + api (5 client/secrets modules) route status/error output via cli error()/success()/warning(). Test assertions updated to match routing (trigger 8 across 4 files). Suites re-run by devpulse: trigger 564, api 515, both green. aipass still in flight.
AIOSAI2026-07-11 02:46:51 -07:00
80badb784a
#686/#661 night shift wave 3 completion (memory): -> 100% seedgo. memory.py --help guard (Subcommand_Help ->100). symbolic.py + 6 modules route console.print status/error through cli error()/success()/warning() (Output_Routing ->100). 27 test assertions updated to match the routing (test_symbolic_cli.py, test_symbolic_module.py). Full suite 990 pass / 0 fail (devpulse re-ran the suite; the first agent report wrongly claimed no changes and skipped tests — caught by verify, re-dispatched, now green).
AIOSAI2026-07-11 02:40:26 -07:00
90296b80f0
#686/#661 night shift wave 3 (backup + seedgo): both -> 100% seedgo. backup.py --help guard + error() routing in 6 modules (Subcommand_Help + Output_Routing ->100). seedgo.py --help guard + output_routing across 13 files + README standards-count refresh + test fixtures flipped for now-compliant seedgo/ai_mail entry points (Subcommand_Help + Output_Routing + Readme ->100). Tests green: backup 247, seedgo 1217. memory held this wave (its changes broke 27 tests, re-dispatched to fix).
AIOSAI2026-07-11 02:17:55 -07:00
a54d21033e#688 follow-up: probe hygiene SOP + test hygiene. @aipass added docs/probe_hygiene.md (principle: temp=used+deleted+gone, no permanent pointer at a temp path, all 4 defenses + correct probe workflow). Test location-independence: TestRunInit gets a _isolate_cwd autouse fixture (monkeypatch.chdir) so it passes from ANY cwd incl an agent branch dir; 5 test_bootstrap env.AIPASS_HOME tests patch is_throwaway_path->False so they assert correctly even when the repo itself lives under a temp path. Devpulse caught+fixed the 2 update_project tests @aipass missed (same monkeypatch pattern). Verified: 657/657 green in REAL tree AND a fresh /tmp clean-room extraction (was 2 failing in clean-room before the last 2 fixes). --all
AIOSAI2026-07-11 00:30:35 -07:00
22b4577ec1#688 aipass: install from throwaway path can no longer hijack machine-wide AIPASS_HOME. Root cause: probe 'aipass install' from a /tmp scratchpad rewrote ~/.claude/settings.json env.AIPASS_HOME -> every CC session machine-wide ran a dead temp tree (stale python+hooks, bogus ImportErrors). 3 defenses: bootstrap.is_throwaway_path() gates the settings write (tempdir/tmp/scratchpad never written to global settings); run_install refuses throwaway home LOUDLY, --force-global-home = explicit override (+help text); doctor _check_global_aipass_home() flags nonexistent/throwaway env.AIPASS_HOME with fix guidance. +11 tests. Built by @aipass; devpulse verified: diffs read, is_throwaway_path live-caught the actual hijack path, doctor check live-green against repointed settings, 201/201 changed-file tests in real env. Suite deltas root-caused environmental: 3 init_flow fails = pre-existing cwd-dependence (pass from repo root), 5 clean-copy fails = the gate working as designed under a scratchpad extraction.
AIOSAI2026-07-11 00:12:26 -07:00
f72515e7bc#677 + #635 hooks: -p headless short-circuit + Codex bridge + portable hook test runner. #677: session_boot.py detects -p in extra_args and execvp's claude directly — headless one-shots never register in ~/.claude/sessions, so tmux/session-lookup/live-attach logic was wrong for them (DPLAN-0226 fine-tune debt; +5 tests, 39 pass). #635: new bridges/codex.py mirrors claude.py with Codex protocol normalization (stdin input->tool_input, stdout hookSpecificOutput envelope, permissionDecision+permissionDecisionReason — fixes DPLAN-0205 bugs) + new hook_test module: drone @hooks test fires every hook from .aipass/hooks.json with per-event mock data, reports fired/blocked/disabled/crashed with timing (23 tests). codex.py bypass entries exactly mirror shipped claude.py set. Built by @hooks; devpulse verified: 62/62 tests re-run against real repo, seedgo 31/31 all three files.
AIOSAI2026-07-10 23:50:37 -07:00
98d52fa944#681 owner-cap PART4: watchdog+feedback gate on sealed-registry owner (is_owner), cross-project. The old cwd.name=='devpulse' check was a NO-OP through drone (routed module runs cwd=branch_path, so Path.cwd() is always devpulse; a @flow caller sailed through). New shared handlers/owner/guard.py resolves the REAL caller via AIPASS_CALLER_BRANCH/CWD and checks the frozen is_owner(email,start_path) contract — portable to any project. feedback send stays open (inbound channel); mailbox mgmt owner-only. Fail-safe: legacy devpulse-path heuristic when no owner sealed / resolver import fails. Live-verified owner-allow + flow-deny (both tools) + send-open. 18 tests (15 guard + 3 gate), branch audit 100%.
AIOSAI2026-07-10 22:32:24 -07:00
fdb0086d6c#643 follow-up: check_branch_post honors .seedgo/bypass.json — threaded bypass_rules through branch_audit -> check_branch_post -> _check_json_dir_structure so a branch can sanction a legitimate data subdir (is_bypassed matches branch-relative path); unsanctioned+unbypassed splits still fail. Applied devpulse compass bypass (SQLite/FTS5 store needs own dir). audit @devpulse Json_Structure 100%. +2 tests.
AIOSAI2026-07-10 21:42:59 -07:00
2112f458fb#643: codify custom_config/ as a json_structure standard — ALLOWED_JSON_SUBDIRS allowlist + check_branch_post() validates {branch}_json/ subdirs (custom_config/ + hidden dirs pass, other splits flagged); json_structure_content.py documents the structure + operator-config location. 5 tests. Surfaced devpulse_json/compass/ as unsanctioned (devpulse bypass next commit).
AIOSAI2026-07-10 21:33:38 -07:00
0886c9013c#620: git_gate block messages guide instead of dead-end — explain WHY git is enforced, list key drone @git commands, point to --help, show disable path (git_gate.enabled=false in .aipass/hooks.json, verified engine skips disabled hooks per-hook). Split GIT_GH_REDIRECT -> GIT_REDIRECT + GH_REDIRECT; EDIT_REDIRECT shows disable too. Init notice in project_hooks.json template, on/off in README. 6 tests, seedgo 31/31.
AIOSAI2026-07-10 21:30:35 -07:00
b4e2370ee8#644: gate Telegram /create + /cancel to base @aipass bot only — base_bot.py guards on branch_name (branch bots return False in _dispatch_command + omit from get_custom_commands; base bot None still routes both). Rides along @skills #669.2/#669.3 fail-loud (botfather_client _load_telethon_config raises RuntimeError naming config path vs silent None) + #668 offset tests. 133 TG tests, seedgo 31/31 both files.
AIOSAI2026-07-10 21:19:04 -07:00
c8b7250995#675: seedgo skips throwaway code — is_throwaway_path (cross-plat temp+scratchpad) + is_prototype_file (# seedgo: prototype marker) in skip_dirs.py; wired into branch_audit._collect_py_files + checklist --prototype early-return. A disposable POC no longer fires 8 violations. 6 tests, live-verified skip.
AIOSAI2026-07-10 21:16:02 -07:00
d8aa300d6b#666: claude() boot shim now ships + installs on onboarding — root .gitignore negation tracks only hooks/tools/install_boot_shim.sh (README stays ignored); setup.sh runs it after hook install (idempotent marker check, non-fatal, venv resolved from script location). Fixes dev-local-only boot feature (macOS user couldn't attach/resume). @hooks did gitignore+installer, devpulse wired setup.sh.
AIOSAI2026-07-10 21:01:07 -07:00
d229ee5df5#680: cross-platform _is_branch_occupied + _read_session_type (wake.py + daemon.py) — extracted _get_pid_cwd (Linux /proc, macOS lsof -Fn) + _read_session_type_darwin (ps -wwE); macOS occupancy no longer always-False so wake-back won't double-session an interactive branch. Fail-safe on unreadable cwd/env. +11 tests, seedgo 31/31 both files.
AIOSAI2026-07-10 20:43:01 -07:00
39d979302c#606: SubagentStop gate skips ~600ms seedgo check on empty agent_type (internal CC turns) — early-return _ALLOW at top of handle(); real sub-agents (non-empty agent_type) still get the full modified-files check, Piper untouched (separate hook). +3 tests, 17/17 green, seedgo 31/31.
AIOSAI2026-07-10 20:39:25 -07:00
663c801c05#684 os.kill(pid,0) fleet migration: Windows-guard 8 liveness probes — @ai_mail (daemon.py x2, wake.py x2), @drone (lock_handler.py), @flow (lock_ops.py), @hooks (cc_sessions.py, presence.py). Each early-returns to OpenProcess+GetExitCodeProcess on win32 (os.kill(pid,0)=TerminateProcess, KILLS target). Fleet sweep now clears all but git_lock_tool.py (deferred #687). ai_mail 168 / flow 17 tests green, drone/hooks import-clean.
AIOSAI2026-07-10 18:58:49 -07:00
d872d7101f#684 (devpulse): registry.py is_pid_alive Windows-guards its os.kill(pid,0) — win32 early-returns to OpenProcess+GetExitCodeProcess (os.kill(pid,0)=TerminateProcess on Windows, KILLS the target). #682 checker no longer flags it; 26 registry tests green. git_lock_tool.py:120 deferred to a separate cleanup (pre-existing tool debt: 42 prints/no-meta/architecture fail the gate).
AIOSAI2026-07-10 18:49:06 -07:00
4404b60305#673 offenders adopt prax append_jsonl: @backup (1 .jsonl site), @hooks (2 .jsonl sites), @trigger (11 raw .log appenders across 8 files -> .jsonl + downstream medic_state/medic/log_watcher readers + 5 tests). Zero raw open('a') log appenders remain fleet-wide. Verified: backup 18 / hooks 114 / trigger 189 tests green, no recursion regression, append_jsonl wired at every site.
AIOSAI2026-07-10 18:24:06 -07:00
dfd6732f5b#673 prax-side: append_jsonl (sanctioned .jsonl writer — 500KB/1-backup atomic os.replace rotation) + drone @prax log-audit sweep (30-day stale-log sweep over system + branch logs). Replaces the raw open('a') rotation-bypass. 15 tests. Offenders hooks/backup/trigger adopt next.
AIOSAI2026-07-10 18:00:12 -07:00
948d2ed535#685 seedgo: subcommand_help standard — enforces every entry point intercepts <cmd> --help before dispatch (explicit guard or argparse parse_known_args), else <cmd> --help executes the command. 21 tests, cwd-portable (_AIPASS_ROOT anchor). Checker verified independently: 7/17 comply, 10 offenders.
AIOSAI2026-07-10 17:58:41 -07:00
f4d067a3cc#665 item 5: bare-mode hints point to working commands. @daemon (daemon.py) — 'daemon --help' (no such binary) -> 'drone @daemon --help' in hint/USAGE/error (3 spots). @memory (memory.py) — 'drone @memory help' -> standard 'drone @memory --help' (L78,L356; --help already wired). Both verified live.
AIOSAI2026-07-10 15:34:14 -07:00
9dab0ca3f4#665 item 4 (spawn): sync_registry_ops derives branch description from passport purpose/role/README, not the hardcoded 'Auto-registered branch' placeholder — wired into new-registration AND --fix backfill of existing placeholders. Root fix that ships + survives regen (the gitignored registry data edit didn't). 0 placeholders in drone systems.
AIOSAI2026-07-10 15:21:14 -07:00
b75a8d272a#665 items 1,2,8 (aipass CLI): --version wired to package metadata (was hardcoded 0.1.0), --help lists real COMMAND names not file stems (help not help_chat, init not init_flow), crash-vs-unknown distinguished (handler raise/import fail surfaces real cause, not 'Unknown command'). +5 tests.
AIOSAI2026-07-10 12:42:39 -07:00
c970c5761f#634 devpulse: watchdog stall detector — kill false-positives on long tool calls + surface stall live.
AIOSAI2026-07-10 03:57:19 -07:00
cded2993f5#664 memory: external-project branches now auto-roll (rollover discovery no longer cwd-scoped). Branch discovery only saw registries reachable by walking up from the caller cwd, so branches living solely in an external project's *_REGISTRY.json were never reached by rollovers fired from the AIPass tree (PreCompact hook runs cwd=repo root) — their .trinity grew unbounded (one hit 110 key_learnings vs a 15 cap) and vectors went stale. @memory added a persisted known_registries.json (gitignored per-install data) recording every external registry seen via the cwd walk, so discovery reaches them regardless of caller cwd; stale/deleted paths filtered on load. Plus a soft entry-COUNT guard at write time (warns, never blocks) since gates only enforced char caps. Remaining hooks-side harden (_find_repo_root fail-loud + edit_gate count-guard) filed for @hooks. Built by @memory, verified by devpulse: 70 changed-file tests green (+12), memory_json gitignored (data local, code ships), LIVE REPRO proves a rollover fired from AIPass root now reaches an external-registry branch (was invisible before).
AIOSAI2026-07-10 03:28:34 -07:00
0878afbc81#676 aipass: init update now refreshes AGENTS.md + prunes stale managed cruft. GAP1 — update_project synced AGENTS.md from a .aipass/project_AGENTS.md template that never existed, so AGENTS.md was a SILENT no-op on every 'aipass init update' (only CLAUDE.md, whose template exists, synced). Added the template + reconciled create/update to one source. GAP2 — update was additive-only; added a whitelist-scoped cleanup pass (_STALE_MANAGED_FILES, currently the retired aipass_global_prompt.md) that removes only positively-identified managed artifacts, logs each removal, never touches user files (registry/README/.gitignore/src/.trinity). SHIP-GAP caught in verify: .aipass/project_AGENTS.md was gitignored by the .aipass/.gitignore allowlist — added !project_AGENTS.md negation or the template would never distribute (the fix would be inert on real installs). Built by @aipass, verified by devpulse: 83 bootstrap tests green (+7), seedgo 31/31, live repro proves update emits AGENTS.md (name-interpolated) AND removes a planted cruft file.
AIOSAI2026-07-10 03:07:01 -07:00
739dada015#671 prax: single-instance lock on the monitor — stop duplicate/orphan monitors from double-sending Telegram relay. New instance_lock handler writes a liveness-checked pidfile (prax_json/monitor.pid, outside the tailed system_logs/): acquire() before relay init refuses to start (fail-loud, names the holding PID) when a live monitor holds the lock, reclaims a stale pidfile on a dead PID, release() clears it on shutdown. Liveness probe platform-branched — POSIX os.kill(pid,0), Windows OpenProcess/GetExitCodeProcess (a raw os.kill(pid,0) TERMINATES the target on Windows; reused the canonical devpulse/watchdog/agent.py:137 impl). monitor.py split under the 600-line limit (pid_cache extracted). Built by @prax, verified by devpulse: 120 tests green across the 4 touched files (+25 new incl 3 Windows-path), seedgo 31/31 on all 3 sources. Verify caught the Windows os.kill hazard on the first pass; filed the seedgo windows_compat detector gap as #682.
AIOSAI2026-07-10 02:53:29 -07:00
10a8f738a0#660 install: aipass install no longer hard-exits 2 (silently) when it cannot create global symlinks. setup.sh runs under set -euo pipefail; the #660 safe_symlink refactor returns 2 on ln failure, but the call sites read rc on the NEXT line (rc=$?) — so set -e killed the installer at the symlink step BEFORE the ~/.local/bin fallback (built for exactly the no-sudo case) could run. Any sudo-less env (containers, CI, locked-down machines) got a silent exit 2 + no symlinks despite an otherwise-complete install. Fixed all 3 call sites to rc=0; safe_symlink ... || rc=$? (set-e-safe). Found by the #678 owner-capability docker verify. +tests/docker_owner_verify.sh (owner-capability SOP harness) +tests/_install_diag.sh.
AIOSAI2026-07-10 01:07:35 -07:00
874c7fed2e#678 owner-capability: seal project ownership in the registry + wake the OWNER back on dispatch completion. TDPLAN-0012 — 3 parts built in parallel against a frozen is_owner contract, verified end-to-end by devpulse.
AIOSAI2026-07-10 00:46:17 -07:00
ae8f4a843a#661 watchdog: 'invoke via Monitor tool' reminder no longer trips the exit-code fail-flag. _handle_agent printed this unconditional info banner through cli error() -> post-#661 every SUCCESSFUL watchdog agent run exited non-zero with a red X. Rerouted to a dim console note (exit 0); genuine arg-errors still error()->exit 2. Caught + verified by dogfooding (S289).
AIOSAI2026-07-10 00:46:01 -07:00
6a757a21f1#674 trigger: debounce trigger_data.json writes + confirm bulletin_created retired. Branch log watcher persisted dedup hashes + positions with 2 full-file rewrites PER log event (44K file churned 1-2x/sec under load). Now: dirty-flag + coalesced writer, both keys in ONE atomic write at most every 5s, force-flush on watcher stop. bulletin_created confirmed retired (archived, 0 live refs, 0 warnings on load). Built by @trigger, verified by devpulse: 564 tests (+6 debounce), seedgo 31/31 on changed file (output_routing clean), live load 0 bulletin warnings, correct live file (branch watcher, not stale dup).
AIOSAI2026-07-09 22:06:17 -07:00
f5554158f9#660 install: aipass install no longer silently repoints global drone/aipass symlinks. setup.sh safe_symlink guard refuses to hijack a symlink pointing at a DIFFERENT install (loud from->to warning, left untouched) unless --force-symlink; --no-symlink opts out entirely. Both flags thread through install.py -> _run_setup. Fresh/same-location installs unchanged. +tests/setup_symlink_guard_test.sh (10 asserts) +3 flag-forwarding tests; touched install output migrated to cli success() (#661). Verified: 635 aipass tests, seedgo 31/31, live dry-run forwarding + guard test all-pass.
AIOSAI2026-07-09 21:34:17 -07:00
bc0d403da9#662 flow: close no longer false-reports 'timed out after 30s' on a committed close. close_plan_impl now honors spawn_background — single close fires the detached _spawn_background_runner (same path as close_all) and returns right after archive; the synchronous 30s 'drone @memory process-plans' that drone was killing is gone. Removed cross-handler imports (archive/trigger injected). Fix built by @flow, verified by devpulse: 730 flow tests green (+2), seedgo 31/31 x3, live repro close=5.1s exit 0 (was 30s-timeout->false exit 1).
AIOSAI2026-07-09 21:15:18 -07:00
26a5f3a2ee#663 doctor: isatty guard — aipass doctor no longer hangs on non-interactive/blocking stdin. prompt_auto_wire now declines auto-wire when stdin isn't a tty (was: input() blocked forever on a stdin that never EOFs — read as a crash to CI/subprocess callers of the flagship health command). +3 regression tests; output_routing migrated to cli success(). Live-repro proven: blocking non-tty stdin completes instead of hanging.
AIOSAI2026-07-09 20:50:47 -07:00
1edea552bf
backup: fix Windows-incompat test — test_log_operation_handles_path_objects asserted a hardcoded POSIX '/some/project'; default=str serializes with platform separators, so compare against str(Path(...)). Pre-existing (S284 195b9f0), the sole repo-wide Windows CI red
AIOSAI2026-07-09 16:53:14 -07:00
9a06a2fa47
hooks: wire_verify introspection gate — handle_command no-args path now prints introspection first (seedgo 85%->100%; this was the CI seedgo-audit red on the 100% gate). Verify behavior + non-zero-on-error exit preserved, 831 hooks green
AIOSAI2026-07-09 16:32:06 -07:00
cdbd1dc821
setup.sh + aipass doctor: recurrence-prevention for silent hook-wiring break — setup.sh merge now drops orphaned empty hook events (the exact bug: an event left as [] fires nothing, written silently) and announces the drop; aipass doctor surfaces a wire_verify check under Services + re-verifies after --fix. Proven: orphan dropped / valid kept / user hooks preserved; doctor shows green. 629 aipass green
AIOSAI2026-07-09 16:25:35 -07:00
5fea5bbf44
seedgo+hooks: json_handler empty-guard (#667) + fix silent hook-wiring break — new wire_verify guard fails loud on empty/orphaned/dup provider hook events (the real bug: half-wired hooks written silently); presence_gate marked provider_wired:false (dormant by design, not a break); snapshot fixture corrected (drop presence_gate, add SessionStart:cadence_reset); load_json empty-guard. Live SessionStart orphan re-wired separately. 1138 seedgo + 831 hooks green
AIOSAI2026-07-09 16:12:44 -07:00
195b9f081c
backup: drive-sync respects .backupignore on sync path + PosixPath log fix — stale-store junk can't cause 8hr syncs (built by @backup)
AIOSAI2026-07-07 21:18:39 -07:00
a20d191f87
tests: dev-docker verify script (bridge-era, 19 assertions) — proven vs real dev clone; supersedes stale docker_clone_test.sh
AIOSAI2026-07-07 20:07:32 -07:00