Commit Graph
850 Commits
Author SHA1 Message Date
Bastien Chanot 3b0167c6cb feat(settings): rebuild destructive-command cover in autoMode, scope the classifier environment
`permissions.ask` gates nothing under `defaultMode: auto` (LRN-146,
verified live), so the ten rules that left the static tiers had no cover
left: rsync / kill -9 / killall / pkill out of deny, and python3 -c /
python -c / xargs / sed / cp / mv out of ask.

autoMode.soft_deny (7 rules) takes over what an explicit instruction
should be able to clear: writes outside the working directory,
rsync --delete, SIGKILL and kill-by-name, in-place edits spanning more
than one file, directory moves, and inline interpreters or xargs that
delete or write outside the cwd. Intent clears a soft block for the
current turn only, stated as a rule since no setting expresses it.

autoMode.hard_deny (3 rules) takes the classes no command pattern can
express: secret exfiltration, production deployment, and disarming the
guardrails. Adding a restriction stays allowed, removing one does not.

permissions.deny gains ten .env reader rules (sed awk cut tr sort uniq
diff od xxd strings). Six of those tools sat in permissions.allow, so
reading a .env through them triggered nothing.

autoMode.environment named another project, its FTP deploy target and its
customer data, inside the file link.sh:21 symlinks to
~/.claude/settings.json, where it reached every repo and contradicted
this one's Gitea remote. Rewritten machine-generic; the project facts
moved to that project's gitignored .claude/settings.local.json. All three
lists now open with "$defaults", which the original omitted, so the
built-in classifier entries are inherited rather than replaced.

doctor.sh check_automode backstops both defects. SETTINGS.md documents
the block and a tier-choice table. README no longer claims the ask tier
makes every mcp__magic__* call require a live confirmation.
2026-09-15 19:44:24 +02:00
Bastien Chanot 3228acabfc Merge feature/gstack-playwright-lib into develop 2026-09-15 16:55:38 +02:00
Bastien Chanot 8843970425 docs: Playwright browser-cache report + bump re-applied on update 2026-09-15 16:54:33 +02:00
Bastien Chanot a0876a2976 chore(memory): BDR-088/089, LRN-150/151/152, EVAL-029 — gstack Playwright lib 2026-09-15 16:49:23 +02:00
Bastien Chanot 2cebecbb91 feat(gstack): share the Playwright bump, report the browser cache
Extract gstack_bump_playwright_if_unsupported from install-plugins.sh into
lib/gstack-playwright.sh and call it from update-all.sh too. A submodule
update no longer leaves the OS-support bump unapplied until the next
`make plugin` — that was BDR-029's open caveat.

The update helper never touches the submodule working tree: on failure it
prints git's own message and points at `make plugin`, and returns non-zero
so the existing `else warn` arm still handles it.

Add a read-only `Playwright browsers` section to doctor.sh: cache size,
which registered install requires each revision, and counts of unreferenced
directories and broken links. No pruning is written — Playwright's own
`install` already unions the required set across every registered install,
and all three installs here are live (rev 1228 for gstack + gsd-pi 1.61,
rev 1243 for gsd-pi 1.63).

Carries two latent-bug fixes from the moved code: the ostag capture exited
1 on every non-Ubuntu host and aborted the caller under inherited errexit,
and the bun calls had no timeout.
2026-09-15 14:57:31 +02:00
Bastien Chanot a53a5a26a8 Merge release/1.5.0 into develop 2026-09-13 21:26:44 +02:00
Bastien Chanot 9b3b96a8f2 chore(release): 1.5.0 — version.txt + CHANGELOG 2026-09-13 21:25:37 +02:00
Bastien Chanot 8d5d154c28 chore(memory): LRN-149 — background_tasks gates the turn-end signal 2026-09-10 03:03:22 +02:00
Bastien Chanot 0e8018ae7b fix(hooks): no turn-end signal while background work runs
Ending a turn right after spawning a subagent fired the bell and a toast
saying the response was finished, while the work continued. The Stop
payload carries background_tasks, so skip the signal when it is not
empty; the next turn end signals once the work is really done.

Interaction requests still signal during background work. A missing
field still signals, so an older client loses nothing. Also drop the
message suffix when it merely restates the label.
2026-09-10 03:03:22 +02:00
Bastien Chanot 12d7fc1483 fix(hooks): stay silent on events that need no attention
Only turn end and the moments needing the user should signal. Any other
event reaching the hook, such as agent_completed or auth_success, now
exits without emitting, so a subagent finishing rings nothing even if the
Notification matcher is ignored.
2026-09-03 02:56:49 +02:00
Bastien Chanot e801b90307 Merge chore/notify-terminal-preflight into develop 2026-09-03 02:26:16 +02:00
Bastien Chanot 92eb27c4e2 Merge feature/notify-event-labels into develop 2026-09-03 02:25:38 +02:00
Bastien Chanot 679c2cda7b feat(hooks): label each attention event in the toast
The toast body showed Claude's own message when present and the raw
notification_type otherwise, so permission_prompt and idle_prompt reached
the user as snake_case. Map every event the matcher covers to a readable
label, and keep Claude's message as a suffix when it adds detail.
2026-09-03 02:24:51 +02:00
Bastien Chanot 2c0439a0a8 chore(memory): LRN-148 — pre-flight terminal test; LRN-147 mechanism too narrow 2026-09-03 02:22:24 +02:00
Bastien Chanot 2ed51573f7 Merge chore/notify-restored-terminal into develop 2026-09-03 02:00:47 +02:00
Bastien Chanot a627201bee chore(memory): LRN-147 — restored terminals never instrumented by OSC ext 2026-09-03 02:00:22 +02:00
Bastien Chanot f90ee74a19 Merge feature/notify-stop-event into develop 2026-09-03 00:31:07 +02:00
Bastien Chanot 6aca40a810 chore(memory): BDR-087 + LRN-146 + BLK-020 — capitalize 2026-09-03 00:28:45 +02:00
Bastien Chanot ea9e5c1dab feat(hooks): ring terminal on turn end via Stop hook
Notification matcher covers input-needed events only; end of turn had no
signal but idle_prompt, ~60s late. Wire notify-attention.sh on Stop too,
branching on hook_event_name for the message. Signal only: returns
terminalSequence + suppressOutput, never blocks (guard vs BDR-083).

Header documents both client-side prerequisites found in BLK-020.
2026-09-03 00:28:40 +02:00
Bastien Chanot de34e3f167 Merge chore/reconcile-todo into develop 2026-09-01 16:55:55 +02:00
Bastien Chanot 069a73338a chore(todo): reconcile 2026-09-01 — T4 gate ticked, T6 residuals corrected, Makefile item re-verified open 2026-09-01 16:54:15 +02:00
Bastien Chanot 1940a0a22a Merge chore/notify-attention-bell into develop 2026-09-01 16:40:51 +02:00
Bastien Chanot c4e6ef1e2b chore(memory): BLK-019 notify-attention bell silent (VS Code client default) 2026-09-01 16:30:39 +02:00
Bastien Chanot 08e38876ee Merge chore/notify-attention-hook into develop 2026-09-01 15:42:25 +02:00
Bastien Chanot f08c3ab51c chore(memory): LRN-145 terminalSequence pattern + journal 2026-09-01 2026-09-01 15:32:51 +02:00
Bastien Chanot 6c04ada6a8 chore(settings): default model opus[1m] (was claude-fable-5[1m]) 2026-09-01 15:32:25 +02:00
Bastien Chanot 1d7faa32b5 chore(hooks): notify-attention — bell + OSC 777 toast when Claude needs input
Notification hook (permission_prompt|idle_prompt|agent_needs_input|
elicitation_*) returns BEL x2 + OSC 777 via the terminalSequence JSON
field (hooks have no controlling TTY). Client side over Remote-SSH:
VS Code accessibility.signals.terminalBell sound:on for the beep,
wenbopan.vscode-terminal-osc-notifier extension for the Windows toast.
2026-09-01 15:32:18 +02:00
Bastien Chanot 726464f387 Merge feature/darwin-optimize-20260825 into develop 2026-08-27 11:54:35 +02:00
Bastien Chanot a51a65e1d5 chore(memory): LRN-143 index row — re-escape pipes (sed a-command unescaped them) 2026-08-26 23:01:16 +02:00
Bastien Chanot a15854aa87 chore(memory): EVAL-028 + LRN-143/144 + BDR-086 + journal — darwin run capitalized; TODO round-count corrected 2026-08-26 23:00:41 +02:00
Bastien Chanot 7f457f09fd docs(darwin): result card PNG 2026-08-26 23:00:41 +02:00
Bastien Chanot 12823181d1 chore(darwin): Phase 3 — optimization report + TODO T5/T6 ticked 2026-08-26 22:45:03 +02:00
Bastien Chanot e157a98e0b fix(hotfix): rewrap RULES bullet — census greps the no-verifier phrase on one line 2026-08-26 22:40:04 +02:00
Bastien Chanot 6eac7fbca9 fix(hotfix): batch-skeptic residuals — RULES restore mandate file-scoped; hotfixer FILE(S) marks created files (new) 2026-08-26 22:28:31 +02:00
Bastien Chanot b5ce280fc0 fix(fixtures): plugin-check expects PLUGIN CHECK block + real plugin names; onboard archetype nextjs-app-router 2026-08-26 21:59:56 +02:00
Bastien Chanot 6c69ae1670 fix(prune-memory,code-clean): stale v1-untested note reflects real tests/; executor attribution code-cleaner (refactorer inline); audit-only fixture matches flow 2026-08-26 21:59:40 +02:00
Bastien Chanot ad4985f410 fix(security-auditor,close): hotfix no-verifier carve-out documented; close enumerates STEP 5C + --no-push passthrough 2026-08-26 21:59:08 +02:00
Bastien Chanot c983f1ff94 fix(handover-writers): stale ch.4 refs post-NAP-renumbering (glossary/tone->6, cross-links/THRESHOLD->5); 14.5 verification deferred to post-write; anchor gate ordered into STEP 16 2026-08-26 21:55:13 +02:00
Bastien Chanot 27f17939d7 fix(plan-challenger): ERROR verdict added to the load-bearing OUTPUT grammar (STEP 1 emitted it, parser enum omitted it) 2026-08-26 21:54:35 +02:00
Bastien Chanot ab75fc5e1f fix(harden): severity rule defers to the calibrated guide; SSL Labs late-finalize gets an assigned actor (main loop edits HARDEN.md row) 2026-08-26 20:35:35 +02:00
Bastien Chanot 1743f7683f fix(init-project,commit-change,tour): allowed-tools +Agent+Skill; conflict grep covers all unmerged codes; report-only never commits 2026-08-26 20:35:06 +02:00
Bastien Chanot 6eceedb8d3 fix(hotfix): revert paths — stash-create PRE snapshot + file-scoped restore (git restore . wiped tolerated user edits); security gate fresh-dispatch only 2026-08-26 20:34:45 +02:00
Bastien Chanot 796b52ea6b optimize gitflow r1-amend: judge-suggested precisions (re-checkout source before re-run; purge warning is pre-merge, finish continues) 2026-08-26 19:59:24 +02:00
Bastien Chanot 056f82b25f optimize gitflow: d3 — mechanical failure table keyed to lib return codes (rc=4 conflict resume, rc=2/3/1 start paths, best-effort purge, socle abort) 2026-08-26 19:57:21 +02:00
Bastien Chanot 9428b86880 optimize status-reporter r2: d5 — passive cost sourced from doctor.sh constants (skeptic's find), count-only fallback kept 2026-08-26 19:44:03 +02:00
Bastien Chanot a3f1624b15 optimize status-reporter: d5 — unproducible token field replaced by /plugin-check deferral; dead ROADMAP.md row rewritten for post-ADR-013 gsd layout 2026-08-26 19:35:46 +02:00
Bastien Chanot e9c6bf52fa optimize analyze-system: d1 triggers in skill description + d2 ordered TASKS mapped to OUTPUT sections in analyzer 2026-08-26 19:22:36 +02:00
Bastien Chanot 080d2d9f03 optimize plugin-probe+advisor: d8 — FRAMEWORK-DEPS exact dep@version (no preact false-hit, fallback fires), advisor derives frontend/fast-libs from it, PLAN echoed-or-unknown (no invention) 2026-08-26 19:16:09 +02:00
Bastien Chanot e92becf609 optimize profile: d3 — failure-mode table (script absent, unknown name/verb rc=1, partial toggle, split plugin leg, current-contradiction) + fixture de-drift 2026-08-26 19:11:18 +02:00
Bastien Chanot c0a2a8069d optimize refactor-system: d4 — no-tests STOP gate (agent) + user arbitration loop (dispatcher) + mid-run test-failure revert; code-cleaner inline carve-out 2026-08-26 19:05:29 +02:00