macOS ships bash 3.2 as /bin/bash, which `#!/usr/bin/env bash` resolves to
when no newer bash is on PATH. Two builtins the repo relies on do not exist
there, and both failed SILENTLY:
- `mapfile` in the three surgical-commit helpers left every array empty, so
the scope guards passed on nothing (fail-OPEN) and the commits degraded to
"nothing pending — no-op" while reporting success. deploy-commit.test.sh
went 4/16; memory and doc commits simply never happened.
- `declare -A` in the session-start hook errored on every session and left
each plugin cost at 0, so the passive-budget warning could never fire.
`_read_lines_into` is the portable equivalent of `mapfile`, space-safe and
resetting its target first — expanding a never-assigned array trips `set -u`
on bash < 4.4, which is how the empty arrays surfaced as "unbound variable".
Plugin costs move to a `case`.
source-scope.sh's header prescribed `mapfile` to its callers; it now shows
the read loop, and its own test plus run-reconcile.sh stop using the builtin.
deploy-commit 16/16, source-scope 34/34, run-reconcile 25 GREEN / 0 RED,
session-start stderr empty.
Ending a turn right after spawning a subagent fired the bell and a toast
saying the response was finished, while the work continued. The Stop
payload carries background_tasks, so skip the signal when it is not
empty; the next turn end signals once the work is really done.
Interaction requests still signal during background work. A missing
field still signals, so an older client loses nothing. Also drop the
message suffix when it merely restates the label.
Only turn end and the moments needing the user should signal. Any other
event reaching the hook, such as agent_completed or auth_success, now
exits without emitting, so a subagent finishing rings nothing even if the
Notification matcher is ignored.
The toast body showed Claude's own message when present and the raw
notification_type otherwise, so permission_prompt and idle_prompt reached
the user as snake_case. Map every event the matcher covers to a readable
label, and keep Claude's message as a suffix when it adds detail.
Notification matcher covers input-needed events only; end of turn had no
signal but idle_prompt, ~60s late. Wire notify-attention.sh on Stop too,
branching on hook_event_name for the message. Signal only: returns
terminalSequence + suppressOutput, never blocks (guard vs BDR-083).
Header documents both client-side prerequisites found in BLK-020.
Notification hook (permission_prompt|idle_prompt|agent_needs_input|
elicitation_*) returns BEL x2 + OSC 777 via the terminalSequence JSON
field (hooks have no controlling TTY). Client side over Remote-SSH:
VS Code accessibility.signals.terminalBell sound:on for the beep,
wenbopan.vscode-terminal-osc-notifier extension for the Windows toast.
3rd tightening pass (series LRN-1005/1007): bare "ux" matched inside
French prose (2 logged FPs, both FR — latest "changement ux vu").
\bui\b kept: zero logged FP, one logged true positive, now locked by a
must-fire test row. Flip-tested: quiet row fired pre-change.
Full removal per user request: the PreToolUse hook that blocked model
Edit/Write on quality-gate files (settings.json, gitflow.sh, .githooks,
doctor.sh, hooks, lib/tests, lint configs) plus its one-shot sentinel.
- delete hooks/config-protection.sh
- delete lib/tests/config-protection.test.sh
- deregister the hook from settings.json (rtk-rewrite PreToolUse kept)
- drop the README mention
Residual protection unchanged: gitflow pre-commit guard + Gitea branch
protection still block direct code commits to main/develop.
The session-start line-count guard warned 'density pass requis' every session since
job1 without the 275 target (BDR-031) or even the 280 threshold ever being met —
CLAUDE.md sits at 305 (319→305 at job1, never re-inflated). A gate that never goes
green is noise. BDR-062 supersedes BDR-031's 275 TARGET only (principle kept, append-
only): 305 assumed final, guard warns past a 320 margin so real regressions still
surface. Review A6 (verifier-amended MINEUR).
Any single-pipeline printenv/env dump now gets a redaction pipe appended
before it can reach stdout/transcript; `env VAR=x cmd` (legitimate
subprocess launch) is left intact. Compound commands (;, &, ||) bail
untouched — appending the pipe at the end would attach to the wrong
segment.
Discovered mid-implementation: rtk rewrite classifies any command
containing "env" as exit-code 2 ("deny"), with no settings.json rule
backing it — the command still reaches native evaluation and can run.
Adjusted case 2/1 handling so the redaction check runs regardless.
Env-var-only seam (§3.2), zero logic change (diff is one added
condition): the version-check `git fetch` at :215 now skips when
SESSION_START_OFFLINE is set (non-empty), leaving _remote_ver empty
(same as any other offline/fetch-failure path already handled) instead
of hitting the network.
Unlocks (BACKLOG, not built here): a HOME-injected truth-table + smoke
test for session-start.sh (J4-14), without every run paying a network
round-trip or depending on origin/main being reachable.
Verified: bash -n clean, shellcheck clean (pre-existing SC1091 info
only, unrelated). Behavioral: SESSION_START_OFFLINE=1 runs in ~15ms
(no fetch) vs ~740ms unset (fetch attempted) — identical banner output
either way (v4.0.0 == CONFIG_VERSION, no update line in both). Full
`make test` exit 0.
The 07-02 tightening left bare tokens common in non-UI talk (design, component, theme, transition, frontend, palette) -> ~6 false-fires/session during the ECC config audit. Dropped them; dashboard now word-boundary matched (kills the ecc_dashboard.py filename match, keeps 'admin dashboard'); kept animation; added 'front-end design' bigram. Each fire now logs time+token+excerpt to a light file so 're-firing?' is measured, not argued. Regression test 18/18, shellcheck clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
Blocks Edit/Write to guardrails (settings.json + .claude/settings*, lib/gitflow.sh, .githooks/*, doctor.sh, hooks/*.sh self-guard, lib/tests/*, lint) so a gate can't be weakened to pass an error. Bypass = one-shot sentinel .claude/.config-edit-ok (non-empty reason, logged+consumed), not an env-var. Adaptation from the ECC second-look (BDR-047 corrob): own bash idiom, not ECC's Node dispatcher. shellcheck clean, test 20/20.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
The exit-0 branch emitted permissionDecision:allow, making rtk's internal
Rust registry a PARALLEL permission authority: a rewritten command
bypassed settings.json deny/ask entirely (audit #11). Both rewrite paths
now emit updatedInput only; the rewritten command goes through native
evaluation. Companion allow rules for read-only 'rtk <tool>' forms land
in settings.json (audit-hardening branch) to keep the safe majority
frictionless. Re-pinned.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
page/pages/form/menu/card/carte/style/look/screen/interface/color/shadow
fired on a large share of non-UI prompts (~200 tokens of reminder each;
measured 6 fires during a pure config audit, including on task
notifications). Specific compounds stay: formulaire, styling, stylesheet,
styliser, écran, couleur, palette… FR aesthetic words kept.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
- ALWAYS_ON derived from settings.json:enabledPlugins (true entries)
minus toggle-owned names — the hardcoded pair under-reported newly
enabled plugins (pr-review-toolkit enabled yet invisible). LRN-005.
- Display 'graphify' (the CLI/skill name); graphifyy stays the pipx
package name everywhere it IS the package.
- Overflow split = greedy width-fill: the fixed 3-name cut overflowed
line 1 and printed an empty line 2 with 3 long names.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
git show origin/master:version.txt fatal-ed since the gitflow migration
(2026-06-29): the 'update available' banner could never fire while a
synchronous git fetch was still paid every session for a discarded result.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
rtk lives at ~/.cargo/bin but the hand-managed .bashrc lost the cargo
line: command -v failed in hook AND tool shell, so the hook no-op'd with
a stderr warn on every Bash call — input compression silently OFF.
- Resolve RTK_BIN by probing known install dirs (LRN-036 class).
- Substitute the ABSOLUTE path at the rewrite head: a bare 'rtk …'
exits 127 in the tool shell, whose PATH the hook cannot fix (proven).
- Compound rewrites carrying further bare rtk segments pass through
unrewritten: quoted text (commit messages) makes a global substitution
unsafe — lose compression, never emit a command that 127s (proven:
a commit chain 127'd mid-flow).
- detect_rtk probes the same dirs so the banner reports capability.
- Re-pinned .rtk-hook.sha256: the rtk BINARY verifies the hook against
it at execution time and refuses a modified hook — the pin is live
machinery, not a vestige; coupling documented in the header.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
Two-mode capitalize: default pre-wipe flush, --ritual adds the 3-question
end-of-session reflection (now deduped, unlike legacy /close). New STEP 2B
reconciles .claude/tasks/TODO.md — PASS A done-detection (only on an
unambiguous task<->commit map), PASS B explicit-only capture with an
anti-noise filter (never track commit/deploy/push/release/tag) and BDR
routing for orientation directives. STEP 3 gate gains a separate TODO block;
journal/handoff report TODO ops. /close becomes a thin alias for
/capitalize --ritual (zero duplicated logic).
Built via superpowers:writing-skills TDD: RED baseline (no skill) folded a
push/tag parasite into the TODO, invented a subtask, and wrote with no gate;
GREEN re-run on the same fixture stops at the gate, drops both dups (footer
shows existing IDs), logs one learning, checks only the cleanly-done task,
ignores the parasite, and routes the GraphQL directive to BDR.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3e8LaH2vymmxyh36h3jFU
Add a tiered-by-scope "Design work — full toolchain" rule to the global
CLAUDE.md: trivial tweaks stay on /hotfix, building UI mobilizes ui-ux-pro-max,
frontend-design, Magic MCP, emil-design-eng, design-motion-principles, and
design-html; design systems start with design-consultation; reviews use
design-review + emil + motion audit. In doubt about scope, do not silently
skip the toolchain — ask or default to the Build tier.
Reinforce it with a design-toolchain-reminder UserPromptSubmit hook that
detects UI/design signals (broad FR+EN keyword set, \b-guarded against
substring false matches) and injects the tiered guidance into context. Soft
nudge, always exits 0, falls back to raw stdin when the hook JSON is missing.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Windows/cross-platform statusline hook for caveman mode indicator.
Reads .caveman-active flag with symlink and size guards to prevent
injection via crafted flag files.
Co-Authored-By: Claude <noreply@anthropic.com>
Drop the `PLAN` (Max/Pro) segment — user wants runtime context, not
account-tier info. Add prefixes for clarity:
- `profile: <name>` reads `<repo>/.active-profile` (already wired in
the previous commit).
- `effort: <level>` reads `.effortLevel` from `<repo>/settings.json`
via jq — picks up `/effort` changes automatically since settings.json
is the source-of-truth (symlinked into `~/.claude/settings.json`).
Sample output:
Opus 4.7 | claude (master) | profile: full | effort: xhigh | ███░░ 42% | 3m
`lib/detect-plugins.sh` is left untouched — still used by
hooks/session-start.sh, doctor.sh, update-all.sh, install-plugins.sh.
Co-Authored-By: Claude <noreply@anthropic.com>
`bash lib/profile.sh current` is 12s+ — far too slow to call from the
statusline hook (runs on every keystroke). Add a one-line cache file at
`<repo>/.active-profile`, written by `cmd_apply` and `cmd_reset`. The
statusline reads the file directly with a single `head -n1`, no
sub-shell into `profile.sh`.
Behavior:
- `bash lib/profile.sh set <name>` (which ends in `cmd_apply`) and
`bash lib/profile.sh apply <name>` both write `<name>` to
`<repo>/.active-profile`.
- `bash lib/profile.sh reset` writes the literal `none`.
- Statusline inserts the cached profile name between the plan segment
and the context-bar segment, e.g.
`Opus 4.7 | claude (master) | Max | full | ████░░░░░░ 42% | 3m`.
- Missing or empty cache → statusline shows `?`.
Cache file is gitignored — it tracks runtime state, not source.
Co-Authored-By: Claude <noreply@anthropic.com>
Two interlocked bugs masking each other:
1. install-plugins.sh installed but never enabled marketplace plugins.
`claude plugin install` only writes to ~/.claude/plugins/cache; without
a separate `claude plugin enable` the plugin sits dormant in the
user's enabledPlugins map. security-guidance and superpowers shipped
as ALWAYS-ON in CLAUDE.md/README/installer banner but in practice
landed disabled on every fresh install.
2. session-start.sh hardcoded the literal "security-guidance rtk
superpowers" in the ✅ ON row, so the misleading banner agreed with
the misleading documentation. The bug stayed invisible.
Fixes:
- install-plugins.sh now calls enable_plugin (added in the caveman
commit) for security-guidance and superpowers immediately after
install. Idempotent: skips if already in enabledPlugins.
- session-start.sh builds the ALWAYS-ON row dynamically from RTK
binary detection + plugin_enabled() lookups against
settings.json. Plugins that are not enabled are omitted, so the
banner reflects reality. Wider strings split across two lines like
the toggle row.
- settings.json: ship security-guidance and superpowers in
enabledPlugins so this user's machine matches the contract until
install-plugins.sh runs again.
Out of scope (separate bug, not addressed here): the marketplace-aware
detect_security_guidance / detect_plugin_dev cache scans miss plugins
nested under cache/<marketplace>/<plugin>/<version>/. They aren't on
the always-on path so the symptom is hidden — left for a follow-up.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- detect_plan() auto-detects Max/Pro/Free from ~/.claude.json
- session-start budget adapts to plan (Max=20k, Pro=11k, Free=5k)
- token counting now uses only ACTIVE plugins, not installed binaries
- statusline shows plan label + session duration instead of start time
- plugin-advisor: complexity assessment (0-100%) drives tool selection
- plugin-advisor: auto-activation with confirmation (PHASE 4)
- ruflo OFF by default, GSD v2 preferred for multi-session
- init-project: ctx7 pre-fetch + graphify scaffold + graphify full
- ship-feature: ctx7 cache check before implementation
- frontend-design disabled in installer (doublon with ui-ux-pro-max)
- python3 -c moved from deny to ask (unblocks graphify)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>