Commit Graph
2721 Commits
Author SHA1 Message Date
Affaan MustafaandGitHub 1bb31dfeae Merge branch 'main' into fix/prepush-venv-pytest 2026-09-18 21:03:34 -04:00
Affaan MustafaandGitHub d14cf18549 Merge pull request #3166 from affaan-m/fix/ci-node18-test-job
fix(tests): feed guided install PTY answers only after each prompt
2026-09-18 20:45:08 -04:00
Affaan MustafaandGitHub c2d4196d8f Merge pull request #3167 from affaan-m/fix/opencode-plugin-entry
fix(opencode): add resolvable package entry and loadable in-place sources
2026-09-18 20:45:06 -04:00
c752aac186 chore(skills): declare licenses on the Codex skill mirror (#2997)
skillforge validate reports SF1009 (no license declared) on every skill
in .agents/skills. This adds license: MIT to all 39, matching the
repository LICENSE.

license only. The Codex mirror's frontmatter is governed by an allowlist
in tests/ci/codex-skill-surface.test.js - allowed-tools, description,
license, metadata, name - and license is the one field on it that
skillforge asks for. compatibility is deliberately absent here; widening
that contract is a separate decision about what the Codex surface
supports.

node tests/ci/codex-skill-surface.test.js: 4 passed, 0 failed.

Split out of #2993 so both PRs land under the review-bot file limits.

Co-authored-by: Çağrı Solakoğlu <cagri.solakoglu@vtcenerji.com>
2026-09-18 18:51:01 -04:00
Affaan Mustafa f0378ccdb6 fix(tests): feed guided install PTY answers only after each prompt
The real-PTY test piped answers on fixed sleeps, typing them ahead of
readline. Under CI load the first answer could land before the interface
listened, shifting every later answer onto the wrong question: the
ubuntu-latest Node 18.x npm job installed Claude only, exited 0, and never
printed the Kimi profile prompt while the sibling yarn, pnpm, and bun jobs
on the same Node version passed. Answer each prompt once it appears on
screen instead; spawned stdio goes through cat because the macOS script(1)
refuses a socket stdin.
2026-09-18 18:47:05 -04:00
He DongandGitHub 8bf16ccfec fix(hooks): keep silent hook paths silent (#2987)
* fix(hooks): keep silent hook paths silent

* fix(hooks): harden stream failure handling

* fix(hooks): settle interrupted input streams

* test(hooks): name stream input limits

* test(hooks): isolate PostToolUse dispatcher fixtures
2026-09-18 18:42:20 -04:00
Affaan Mustafa 1a8beb71c5 fix(opencode): add resolvable package entry and loadable in-place sources
Root package.json declared no main or exports, so OpenCode npm plugin
resolution (import.meta.resolve) failed and the plugin was silently
skipped (#3127). The .opencode TypeScript sources imported siblings
with .js specifiers that only exist after compilation, so the home
install, which loads the .ts files in place, crashed the tool registry
with ERR_MODULE_NOT_FOUND (#3112).

Declare main/types/exports on the root package pointing at the
compiled plugin entry, switch the sources to .ts specifiers, and
enable allowImportingTsExtensions with rewriteRelativeImportExtensions
so the emitted dist keeps working .js specifiers. Add smoke tests that
build the package, resolve and import the entry by name from a temp
install, and verify every in-place relative import resolves.

Fixes #3127
Fixes #3112
2026-09-18 18:39:57 -04:00
Affaan MustafaandGitHub 34de45f210 fix(hooks): enforce loader-documented keys in shipped hooks configs (#3163)
hooks/hooks.json already ships only schema-valid keys with metadata in the
hooks.metadata.json sidecar. Add scripts/ci/check-hooks-schema-keys.js, a
strict allowlist check that fails when hooks/hooks.json or
hooks/codex-hooks.json carry any key outside their loader's documented set,
wire it into the npm test chain, and cover it with fixture tests.

Refs #3138, #3114
2026-09-18 18:37:40 -04:00
Affaan MustafaandGitHub b15f7d8171 docs(mcp): expose memory auth boundary (#3134)
* fix(memory): classify directory traversal failures

* docs(mcp): expose memory auth boundary
2026-09-18 17:01:14 -04:00
Juan Garibay 4869db30c4 fix(hooks): match the index case-insensitively, and isolate the pytest probe
Red-teaming the guard from 3c317470 found two more ways to get a repository's own
code executed. Both are demonstrated by a planted binary that appends to a witness
file, counted before and after.

Case folding. git matches index pathspecs case-sensitively even where
core.ignorecase is set, but APFS does not -- so a repository that commits
`.venv/bin/Python` gets `$venv/bin/python` opening and running that file while the
guard's lowercase query finds nothing in the index and reports it untracked. The
witness logged two invocations. It applies to `venv` and `env` as well, and to any
folding of the name. The query now uses a `:(icase)` pathspec; all nine
directory-by-spelling combinations are refused, and an untracked venv still runs.

Module shadowing. `python -c "import pytest"` puts the working directory first on
sys.path, so a repository that commits a `pytest.py` in its root has that file
imported, and executed, by a check whose only job is to answer whether pytest is
installed. The probe is now `python -I -c "import pytest"` on the virtualenv, uv
and poetry paths alike. Isolation does not hide a real pytest -- it lives in the
interpreter's own site-packages, confirmed against a venv holding pytest 9.1.1.

Still true, and not something this hook can fix: running the repository's declared
suite runs the repository's code. `pytest` imports conftest.py, and the Node arm
runs package.json scripts. That is what a pre-push verification hook is for. The
line this guard draws is narrower and worth keeping -- a capability probe, and the
choice of which interpreter to trust, should not be things the pushed repository
gets to decide.
2026-09-17 17:17:19 -04:00
Juan Garibay 3c31747016 fix(hooks): resolve the venv path before asking git whether it is tracked
The guard added in 9cdc40e6 was incomplete. `git ls-files` reports paths as they
are indexed and does not follow symlinks, so a repository that commits `.venv` as
a symlink to its own root alongside a tracked `bin/python` gets asked about
`.venv/bin/python` -- a path git has never heard of -- and the answer is
"untracked". The interpreter then runs. Measured on that shape: the planted
executable logged two invocations against 9cdc40e6 and none against this commit.

`repo_ships_interpreter` now resolves the bin directory with `cd -P`/`pwd -P`,
resolves the worktree root the same way, and asks git about the resolved path
relative to it. The three cases that matter all hold: a plainly committed venv is
still refused, the symlink shape is now refused, and a developer's own untracked
venv still resolves and runs.

`cd -P`/`pwd -P` rather than `realpath` or `readlink -f`, because neither is
portable to a stock macOS.
2026-09-17 16:55:11 -04:00
Juan Garibay ca1a5ad8bc fix(hooks): name the remedy in the blank-override failure
The hook is global and this message blocks a push, so "ECC_PYTEST_CMD is set but
names no command" left the operator holding a refusal with no next step. It now
says to point the variable at a runner or unset it to fall back to discovery,
which is the same advice the no-pytest-found branch already gives from the other
direction.
2026-09-17 16:51:43 -04:00
Juan Garibay 9cdc40e6d1 fix(hooks): do not run a virtualenv interpreter the repository ships
This branch taught the hook to run `.venv/bin/python`, and that is a binary the
repository can supply. On main the Python arm only ever ran `pytest` from PATH --
the developer's own -- and on a machine without one it ran nothing at all, which
is exactly the machine this branch was written for. So the exposure is new, and
it arrived with the fix.

The hook is installed globally through core.hooksPath. Cloning a hostile
repository, committing nothing, and pushing it to your own fork is enough: the
pre-push hook finds the committed `.venv/bin/python`, runs it once to probe for
pytest and again to run the suite. Reproduced -- the planted executable logged
two invocations under the previous commit and none under this one.

A virtualenv is never committed. It is platform-specific binaries and every
Python project gitignores it, so `git ls-files --error-unmatch` separates the
two cases exactly: a developer's own venv is untracked and still resolves, a
tracked one is skipped with the reason printed. An absolute $VIRTUAL_ENV outside
the worktree reads as untracked, as it should.

Not addressed here, and worth a maintainer's view: `uv run` and `poetry run`
resolve from the repository's own lockfile, so they carry the same shape of
trust in a form this check cannot see. They are gated behind a lockfile being
present, and changing their semantics is a larger decision than this fix.
2026-09-17 16:44:33 -04:00
Juan Garibay 08b173f12f fix(hooks): a blank ECC_PYTEST_CMD is an override, and say when one is in use
`[[ -n "${ECC_PYTEST_CMD:-}" ]]` asked whether the variable had a value, not
whether it was set, so `ECC_PYTEST_CMD=` fell through to virtualenv discovery
while `ECC_PYTEST_CMD="   "` failed the push. Two spellings of the same mistake,
two behaviours. Falling through is the wrong one: an override that evaluated to
nothing -- a command substitution that found no pytest, say -- then silently ran
a different runner than the operator named, which is exactly the substitution
this resolver refuses to make anywhere else. Both now fail closed.

`${ECC_PYTEST_CMD+set}` rather than `[[ -v ECC_PYTEST_CMD ]]`, because `-v` is
bash 4.2 and a stock macOS /bin/bash is 3.2, where it is not a false but a
syntax error. The hook runs under whatever `env bash` resolves to.

The override is still not probed -- probing runs the operator's command, and a
wrapper that ignores `--version` executes the whole suite and is then rejected
for not printing a version. What the gate can honestly do about a stale override
is refuse to be quiet about it, so a push that uses one now says so, every time,
and says the hook has not checked that it is pytest. A bypass that announces
itself is not the silent gate this resolver exists to prevent.

The fixture env is built from nothing instead of inheriting process.env with two
keys blanked. Blanking is no longer neutral: a blanked ECC_PYTEST_CMD is now an
override, and every one of these tests would have taken that branch.
2026-09-17 16:33:37 -04:00
Juan Garibay c6195edb2f fix(hooks): stop probing the pytest override, and stop failing on exit 5
Three defects, found by reviewing this branch against a running pytest rather
than by reading it.

Exit 5 is not a failure. pytest reserves it for NO_TESTS_COLLECTED, and
`|| fail "pytest failed"` collapsed it into a blocked push. The `|| fail`
predates this branch, but this branch is what makes it reachable: a repository
whose pyproject.toml only configures ruff or black, with pytest in its venv and
no test files, used to hit the "pytest is not installed" skip and now gets
gated. $VIRTUAL_ENV is the first candidate, so merely having a venv activated in
the pushing shell drags any requirements.txt repository into this path, and the
hook is installed globally. Reproduced with pytest 9.1.1. Exit 5 is now
non-blocking but loud -- a bad rootdir, testpaths or an unimportable conftest
also collects nothing, and swallowing that silently would reopen the hole this
resolver exists to close. Other non-zero codes now carry the code, because 1
(tests failed) and 4 (usage error) call for different responses.

The ECC_PYTEST_CMD probe ran the operator's command. Validating the override
with `--version` assumed it would answer like pytest. A wrapper that sets an
environment variable and execs pytest ignores the flag and runs the whole suite,
so the probe executed the tests, then rejected the command for not printing a
version, then blocked the push -- with the suite green. That is worse than the
silent gate the probe was added to close, so the override is taken as given
again: it is a deliberate setting, the hook cannot inspect it without running
it, and pointing it at something that is not pytest is the operator's call.
`is_pytest` still guards the PATH candidate, which this script composes itself,
where `pytest --version` is harmless. An empty override still fails closed.

The tests inherited the ambient environment. `runHermeticPythonPrePush` passed
process.env through, so an exported ECC_PYTEST_CMD or an activated virtualenv
resolved a pytest the fixture never created and the venv test failed for anyone
who runs the suite that way. Both variables are now neutralised in the base env.

Coverage: the gate had no test proving it blocks. Changing the run line to
`|| true` left all three previous tests green. Seven now cover a spaced venv
path, a red suite, exit 5, an override invoked exactly once with no probe, an
empty override, and the PATH candidate in both directions.
2026-09-17 16:19:57 -04:00
Juan Garibay 1f5cd2af73 test(hooks): build the pre-push python fixture env without mutation
AGENTS.md makes immutability mandatory and the helper built `env` by assigning
into it. Rather than reassigning a `let` through spreads, the two stub paths are
now resolved before the object exists, so `env` is a single `const` built in one
expression with the conditional keys spread in. Nothing to mutate and nothing to
rebind.
2026-09-17 16:04:41 -04:00
Juan Garibay 5cbe78c22b fix(hooks): keep venv paths intact and check every pytest candidate
Two holes in the resolver this branch added, both found in review.

A virtualenv path may contain spaces. `resolve_pytest` returned one string and
the caller expanded it unquoted, so `/home/me/my env/bin/python -m pytest` split
into `/home/me/my` and `env/bin/python`. The probe that accepted the candidate
was correctly quoted, so the hook reported the venv as usable and then failed to
run anything in it -- rejecting the push for a reason with nothing to do with
the code being pushed. It now builds an argv array and runs `"${PYTEST_CMD[@]}"`.

The resolver's contract is that every candidate is confirmed to be pytest, and
two of them were not. `ECC_PYTEST_CMD` was returned unchecked, so
`ECC_PYTEST_CMD=true` made the hook run `true -q`, exit 0 and report a Python
project verified by nothing. The PATH branch used `command -v pytest`, which
proves only that a file of that name exists. Both now go through `is_pytest`,
which runs `--version` and requires the output to name pytest -- `--version`
alone is not evidence, since `true --version` also exits 0.

A bad `ECC_PYTEST_CMD` fails the push rather than falling through to the next
candidate. An operator who set it asked for that command, and silently running
a different one hides the misconfiguration -- which is the same silent-gate
failure this branch exists to remove, one level along.

Three regression tests cover the three paths: a venv whose directory name
contains a space, an override that is not pytest, and an override that is.
2026-09-17 15:57:09 -04:00
Juan Garibay fc6fe5e5df fix(hooks): pre-push skipped every Python project that uses a virtualenv
The Python block gates on `command -v pytest`, so it only runs when pytest is
on PATH. Installing a project's tools into a virtualenv is the norm rather
than the exception, so in practice the hook printed

    [ECC pre-push] Python project detected but pytest is not installed. Skipping.

while standing in a directory with `.venv/bin/pytest` in it, and pushed.

The failure mode is worse than not having the hook. A skip line reads like a
pass: the push succeeds, the output looks healthy, and nothing indicates the
gate declined to gate. A repository can sit behind it for months believing
its tests run on every push. Found on a project with 893 tests, none of which
the hook had ever executed.

`resolve_pytest` now looks, in order, at `ECC_PYTEST_CMD`, `$VIRTUAL_ENV`,
`.venv`, `venv`, `env`, `uv run` when a `uv.lock` is present, `poetry run`
when a `poetry.lock` is, and finally PATH. Each candidate is confirmed by
importing pytest rather than by the path existing, so a half-built venv falls
through to the next one instead of failing the push.

Two deliberate choices:

The log line names the command it resolved -- `Running: .venv/bin/python -m
pytest -q` -- so which interpreter ran is visible in the push output rather
than inferred. When nothing resolves, the message says where it looked and
names `ECC_PYTEST_CMD`, instead of asserting pytest is not installed when it
may well be.

`uv run` passes `--no-sync` so the hook cannot mutate the developer's
environment on its way to running the tests.

Behaviour change worth flagging for the release note: on any Python project
with a working virtualenv this hook now actually runs the suite, and will
block a push whose tests fail. That is the intent, but it is new behaviour
for every such repository, and `ECC_SKIP_PREPUSH=1` remains the escape.

Verified on two real repositories: a uv/venv Python project (resolves
`.venv/bin/python -m pytest`, 893 tests, exits 0; exits 1 when the suite
fails) and a Node project (unchanged, still runs lint/typecheck/test/build).
2026-09-17 15:06:49 -04:00
Affaan MustafaandGitHub dd6ee538ae Merge pull request #3156 from affaan-m/fix/sponsor-status-20260917
docs: move Atlas Cloud to past sponsors
2026-09-17 14:04:06 -04:00
Affaan Mustafa 15cd6ff506 docs: archive Atlas Cloud sponsorship 2026-09-17 13:13:17 -04:00
Jasir ZaeemGitHubgreptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
bb1c58a350 docs: Add SerpApi as a sponsor (#3155)
* docs: add SerpApi as a new sponsor

* Remove extra anchor closing tag

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

---------

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-09-17 12:46:44 -04:00
Affaan MustafaandGitHub 8321021c54 fix(memory): classify directory traversal failures 2026-09-12 07:45:40 -04:00
Affaan MustafaandGitHub 90ef62cb1d fix(memory): distinguish incomplete reads from missing records
Independent local Codex review PASS at 73b07f8d17, no P0/P1. Independent 66 tests and strict validation of 810 skills passed. CI run 34683976362 passed; all 48 current checks green. Incomplete memory reads fail closed with safe MCP diagnostics; canonical guidance synchronized across harness skill copies. Rollback: revert this squash commit. No deployment or installation claim.
2026-09-12 05:52:29 -04:00
Rockwell Windsor RiceandGitHub b6ddd13a9f Fix/rails patterns followups
Independent local Codex review PASS at a6a6419402, no P0/P1. Independent 181 checks and strict skill validation pass. CI run 34667546951 passed, all 45 current checks green. Existing Rails skill mapping and documentation corrections only. Rollback: revert this squash commit.
2026-09-12 04:39:08 -04:00
Affaan MustafaandGitHub ab1f1a09ba feat: group verified capsules into offline retrospective reports
Independent local Codex review PASS at 472cfa94fb, no P0/P1. Independent retrospective, CLI, envelope and capsule tests: 73 passed. CI run 34664487219 attempt 2 passed all 42 jobs. Read-only offline capsule grouping only; no provenance, scoring, execution or promotion claim. Rollback: revert this squash commit.
2026-09-12 04:35:38 -04:00
Affaan MustafaandGitHub 1ed03ecf2e feat(control-pane): live control-plane view with 2D projection and static-threshold advisories
Exact-head independent local Codex review PASS with no P0/P1. CI run 34680860653 attempt 2 passed at 0707cd431c. Includes HTTP/schema failure handling, coalesced sampling cache and regression tests. Disclosed P2 follow-ups remain in the merge-queue receipt. Rollback: revert this squash commit. No deployment or publication claim.
2026-09-12 04:17:37 -04:00
zpearce-2814andGitHub 1ac07903ec fix(hooks): keep hooks.json within Claude Code's schema
Move stable hook metadata to a validated sidecar while preserving hook commands and installer identity. Reject moved fingerprints and duplicate IDs, and validate before updating metadata. Independent local review passed at c315271624a1fd055b992f2bff889ad2a0ff8a6b; CI run 34678210149 passed. Rollback: revert this squash commit.
2026-09-12 02:59:02 -04:00
Affaan MustafaandGitHub c4904e3f63 fix(catalog): remove Serply and Squish entries (#3094)
Remove the two reference catalog entries and their promotional descriptions. The catalog retains its other 34 entries unchanged.

Validated JSON structure, exact 13-line deletion, tracked references and independent code/security review.
2026-09-12 04:45:33 +01:00
SerplyandGitHub fba8e352cc feat(mcp): add serply-search server catalog entry (#3085)
Adds an opt-in HTTP entry for Serply's hosted MCP endpoint to mcp-configs/mcp-servers.json, following the parallel-search and browser-use shape: https URL, X-Api-Key header placeholder, nothing enabled by default. Independent review confirmed valid JSON, catalog-tier policy per docs/MCP-CONNECTOR-POLICY.md, and that the endpoint itself answers 401 asking for X-Api-Key, so the placeholder header is warranted. CI 44/44 at the head.
2026-09-12 04:32:09 +01:00
Radosław KaznowskiandGitHub bdf92d8fab docs: add explicit hook consent to OpenCode install command (#3080)
The README's OpenCode full-profile install command fails because assertHookConsentReady refuses to materialize hooks-runtime without explicit consent; --profile full selects the runtime so the gate fires. Add --enable-hooks to the documented command. Independent review reproduced the failure and the fix by running the installer in a scratch HOME; CI 44/44 at the head. docs/uk-UA/README.md still carries the old command and can follow.
2026-09-12 04:20:03 +01:00
ZaalandGitHub 4f37387420 fix(hooks): block-no-verify handles stuck optional values and long-option prefixes (#3073)
Two cases the word-level rewrite still got wrong. Short options that take an optional stuck value (-u[mode], -S[keyid]) end the cluster scan, so git commit -uno and -Sn are allowed while -nu stays blocked. Git accepts any unambiguous long-option prefix, so --no-veri and --no-verif on commit, push, merge and rebase are now blocked; --no-verbose stays allowed. Quoted data such as -m "--no-verify" is still treated as data. Independent exact-head review probed 34 commands in-process and against real git with no bypass and no false positive; hook test 35/35, eslint clean, CI 44/44 at the head.
2026-09-12 03:07:29 +01:00
Rockwell Windsor RiceandGitHub 95b9fe157f feat(rails-patterns): add Rails framework patterns skill (#3074)
Adds skills/rails-patterns alongside laravel-patterns and django-patterns: directory contract, skinny controllers with service objects, form and query objects, idiomatic ActiveRecord, background jobs, ViewComponent, Hotwire, and the Rails 8 Solid stack. Decisions defer to rules/ruby/patterns.md. Registered in install-modules (framework-language), agent.yaml, package files, and every skill count (292) across plugin, marketplace, AGENTS and README variants. Independent exact-head review passed with no P0/P1; validate-skills, catalog:check, install manifests, plugin manifest, unicode and personal-path checks all pass; CI 44/44 at the head.
2026-09-12 01:48:16 +01:00
DanteandGitHub 2083c9839a fix(hooks): support Windows linter paths and ESLint 9 (#3076)
pre-bash-commit-quality spawned Windows .cmd/.bat linters unquoted, so a spaced path failed, and passed --format compact, which ESLint 9 removed (#3075). Batch executables now run through cmd.exe with each argument carried in an env token and quoted, with quote, NUL, CR and LF rejected before spawn; non-batch Windows and POSIX paths keep direct argv spawn with shell false. ESLint uses its bundled default formatter, present on 8, 9 and 10. Regression tests cover the batch, non-batch and POSIX branches and the formatter change. Independent exact-head review passed with no P0/P1; CI 44/44 at the head.
2026-09-12 01:46:38 +01:00
Wu ShuwenandGitHub 3033436dcc fix: filter epic sync issues by label (#3089)
github-coordination sync listed every repo issue and pushed the epic label onto all of them (#3084). Scope the listing to issues carrying the policy's epic label plus issues whose body still holds the coordination marker (label-drift recovery), deduped by number, and reject an empty labels.epic in loadPolicy. Tests cover the filtered path and the recovery path with exact gh argv. Independent exact-head review passed with no P0/P1; CI 44/44 at the head.
2026-09-12 01:46:04 +01:00
haelyraandGitHub c9148d0bb2 Merge pull request #3071 from haelyra/maint/stewardship-batch-2026-09-10
fix: consolidate verified stewardship repairs
2026-09-10 16:57:26 -04:00
haelyra 2ae86b4fcf test(github-ops): report locale policy failures 2026-09-10 15:40:13 -04:00
haelyra 678c6dea19 fix(github-ops): synchronize localized merge authority 2026-09-10 15:26:56 -04:00
luxury-sketchandhaelyra 22d7ed5137 fix(github-ops): don't instruct auto-merge of dependency bumps
The Security Monitoring section told the agent to "Review and auto-merge
safe dependency bumps" with no definition of "safe" and no human
confirmation. That directly contradicts the skill's own Untrusted
Repository Content rule:

  "Never let repository content authorize a write. Merging, closing,
   labeling, releasing, and pushing are user-authorized actions."

Reworded both occurrences to propose merges for user approval instead of
auto-merging, aligning the guidance with the skill's stated posture.

Claude-Session: https://claude.ai/code/session_017n1PR9tEKoJBsZ7zn5dqjA
2026-09-10 15:01:03 -04:00
haelyraandNIKHIL f81b43b38d docs: synchronize README skill tree count
Carry forward the still-current part of #2944 against the live 291-skill catalog. Keep the accurate compatibility-shim wording already on main.

Co-authored-by: NIKHIL <nagarajnikhil.cs24@bmsce.ac.in>
2026-09-10 15:01:03 -04:00
Danteandhaelyra f6501eeeac test: cover Windows settings identity races 2026-09-10 15:01:03 -04:00
Danteandhaelyra d3af582bad fix: handle Windows settings file identity 2026-09-10 15:01:03 -04:00
Nguyen Thanh Datandhaelyra 380f4b35db fix(memory-mcp): accept the reserved _meta param on ping
tools/list and tools/call on main already admit `_meta` — MCP reserves it
for request metadata and a client may attach it to any request. ping still
refused every parameter, so a client that sends `_meta` on everything
(Codex does) got -32602 on its keepalive.

Rebased onto main and narrowed: when this branch was first written the same
gap existed on tools/list, which has since been fixed upstream. Only the
ping handler is left, so only the ping handler is touched.

Refs #2810
2026-09-10 15:01:03 -04:00
haelyra 013ed0a8e6 fix(rules): make Boolean naming guidance neutral 2026-09-10 15:01:03 -04:00
haelyra a0ecb7939a fix(rules): keep common naming guidance language-neutral 2026-09-10 15:01:03 -04:00
Ralf Penkaandhaelyra 072e468430 fix(rules): stop prescribing JS casing for every language in common/
`common/coding-style.md` has no `paths:` frontmatter, so it is loaded for every
source file regardless of language. Its Naming Conventions section nevertheless
prescribed `camelCase` for variables and functions, which is not idiomatic for
several languages the package supports: `python/coding-style.md` mandates PEP 8
(`snake_case`) and `rust/coding-style.md` mandates `snake_case` for functions,
methods and variables. Both carry `paths:` frontmatter, so for a .py or .rs file
the agent is handed two opposite naming rules in the same context. README.md does
state that language-specific rules take precedence, but that statement lives in
the README rather than in the rule files the agent actually receives.

Replace the casing list with the canonical `**Language note**` marker documented
in rules/README.md, and keep only what is genuinely language-independent:
descriptive names, boolean prefixes, and constants and types being visually
distinct from values, and only where the language draws that distinction at all.
The per-language examples name only languages whose own coding-style.md actually
states a casing standard.

Drop the "Custom hooks: camelCase with a use prefix" line and link to
react/coding-style.md instead — it is React-specific and documented there both as
the `useCamelCase` symbol rule and as the eslint-plugin-react-hooks enforcement
note. react/coding-style.md is path-scoped, so a hook colocated outside
`components/**` or `hooks/**` no longer receives the rule; see the PR description.

Fixes #2830
2026-09-10 15:01:03 -04:00
aeonframeworkandhaelyra 4fc950c462 fix(deps): bump lru to 0.18.2 to patch RUSTSEC-2026-0253
Advisory: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
Severity: INFO (unsound / memory-corruption class, CWE-416/415)
Fixed in: 0.18.2

Lockfile-only change (ecc2/Cargo.lock); no manifest or source changes.
2026-09-10 15:01:03 -04:00
928c1dea72 feat(tasteforge): package reusable workflows and preserve native edits (#3033)
* feat: bundle standalone taste distillation and application workflows

* docs: fix imported taste skill markdown lint

* docs: align Turkish agent catalog with taste skills

* refactor: make ECC the canonical reusable video engine

* fix: preserve video duration when applying image overlays

* fix: preserve background colors in image compositing

* fix: report best-effort duration targets and shortfalls

* feat: ship verified Fusion presets with compatibility provenance

* feat(tasteforge): preserve native edits in application bundles

* feat(tasteforge): compile local preservation without hosted input

* fix: update js-yaml to patched 4.3.2

* test: report bounded Stop wrapper failure diagnostics

* fix(tasteforge): fail closed on unsafe output names, missing overlays and cadence

- cli: default report and spec paths are derived from pack name and profile
  genre; require the manifest's name pattern before using either as a
  filename part so a traversal string cannot write outside cwd/out.
- apply_local: a pack without cadence.json, or with no measured shots and
  no explicit mean_shot, raises instead of silently planning 1.0s shots and
  reporting a measured cadence.
- legacy apply: a missing overlay aborts before any paid upload; forge()
  would have rejected it after every take was generated.
- requirements-live: pin fal-client>=0.13.0, the first release whose
  subscribe() accepts client_timeout.

Addresses the five P1 findings from the independent review of #3033.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015fxHRsydPqEcYngGbqkgt1

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-10 15:31:36 +01:00
f8640355e4 Consolidate recovered eval framework and operator workflows (#3040)
* feat: consolidate offline eval and operator workflows

Compose the retained framework, operator skill, roadmap and cleanup ranges on current main. Preserve current release dependencies and keep candidate execution disabled pending OS containment. Repair draft/DOCX behavior, obligation uniqueness, trusted send and audience guidance, runner provenance and eval diagnostics.

Source-PR: 2930 0abe3727d2b500c6e4830bdeb47ed67cae3f4785
Source-PR: 2931 992b49c44ed872def49675b791168b8fcd091df6
Source-PR: 2932 4a193dd13041cb7a6bebf4d2e910a0cd32bcc797
Source-PR: 2933 59cdfe500a91949ba1415f1edd7279620f21e804
Source-Base: ca185ef5f7

* fix: repair foundation CI and update js-yaml

* fix: reconcile pending-delete capsule locks after close

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-10 13:20:52 +01:00
Affaan MustafaandGitHub d2b352c202 feat: ship verified Fusion presets with compatibility provenance (#3010) 2026-09-10 14:13:06 +03:00
Affaan MustafaandGitHub c7d62c0c6a Distinguish declared goals, open sessions and overlap risk in coordination inventory (#3028)
* feat: add read-only coordination inventory and overlap evaluation

* test: make coordination process fixtures platform explicit

* test: report bounded Stop wrapper failure diagnostics

* test: clean up failed memory MCP sessions deterministically

* fix: update js-yaml to patched 4.3.2

* feat(coordination): distinguish declared goals from open sessions
2026-09-10 14:11:51 +03:00