Harden deterministic edit authorization and post-edit anchors - #37
Merged
Conversation
- Issue receipt-correlated post-edit editAnchors; reuse confirmed capabilities - Require nonempty project/path/run scope for capability minting - Reject empty/duplicate commit action IDs; thread+revalidate cordinator scope - Remove internal str_replace mint paths (failure re-signing, pre-confirmation anchors) - Redact capabilities/post-edit content in CLI rendering - Reconcile reviewer blockers and persist anchors across compaction - Add regression coverage across agents, cli, common, sdk, agent-runtime
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Re-run generate-tool-definitions so committed tools.ts outputs match current Zod param descriptions and clear the CI drift gate.
- Issue receipt-correlated post-edit editAnchors; reuse confirmed capabilities - Require nonempty project/path/run scope for capability minting - Reject empty/duplicate commit action IDs; thread+revalidate cordinator scope - Remove internal str_replace mint paths (failure re-signing, pre-confirmation anchors) - Redact capabilities/post-edit content in CLI rendering - Reconcile reviewer blockers and persist anchors across compaction - Add regression coverage across agents, cli, common, sdk, agent-runtime
Remove the missing-path pending prune that emptied synthetic and resumed pending files during CI/gate runs. Restore the list_jobs description phrase for unchanged digests. Cap compact proactive results on usable rows, reject host-like path segments after URL capture, and add M4 regression coverage.
Option-only set was treated as an environment dump, which blocked legitimate basher strict-mode preludes. Classify set/export/env more carefully and deny wrapped dump forms (busybox, env -0, command/nice wrappers, substitutions) across non-full-access profiles, including tmux-test.
Parent workflow requirementCoverage (commit/push, full validation, CI green) was falsely elevating specialist repair loops. Filter those rows at finalization and repair consumers, scope specialist spawn briefs, document the contract, and unwrap nested editor set_output envelopes.
Call-site filters must re-check structured requirementCoverage evidence the same way finalization does, so evidence-only parent ownership credits LOOKS_GOOD without spawning repair-editor. Regen gate helpers, unit tests, and docs.
Parent-owned process tasks are out of scope for specialist BLOCKING, so the prompt assertion must match the in-scope requirementCoverage wording or CI stays red on PR #37.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This change is