Skip to content

Harden deterministic edit authorization and post-edit anchors - #37

Merged
AnzoBenjamin merged 8 commits into
mainfrom
fix/windows-binary-ci-smoke
Aug 6, 2026
Merged

Harden deterministic edit authorization and post-edit anchors#37
AnzoBenjamin merged 8 commits into
mainfrom
fix/windows-binary-ci-smoke

Conversation

@AnzoBenjamin

@AnzoBenjamin AnzoBenjamin commented Aug 5, 2026

Copy link
Copy Markdown
Owner
  • Issue receipt-correlated post-edit editAnchors; reuse confirmed capabilities
  • Require nonempty project/path/run scope for capability minting
  • Reject empty/duplicate commit action IDs; thread+revalidate cordinator scope
  • Remove internal str_replace mint paths (failure re-signing, pre-confirmation anchors)
  • Redact capabilities/post-edit content in CLI rendering
  • Reconcile reviewer blockers and persist anchors across compaction
  • Add regression coverage across agents, cli, common, sdk, agent-runtime

This change is Reviewable

- Issue receipt-correlated post-edit editAnchors; reuse confirmed capabilities
- Require nonempty project/path/run scope for capability minting
- Reject empty/duplicate commit action IDs; thread+revalidate cordinator scope
- Remove internal str_replace mint paths (failure re-signing, pre-confirmation anchors)
- Redact capabilities/post-edit content in CLI rendering
- Reconcile reviewer blockers and persist anchors across compaction
- Add regression coverage across agents, cli, common, sdk, agent-runtime
@vercel

vercel Bot commented Aug 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
openbuff Ready Ready Preview, v0 Aug 6, 2026 4:57am

Re-run generate-tool-definitions so committed tools.ts outputs match current Zod param descriptions and clear the CI drift gate.
- Issue receipt-correlated post-edit editAnchors; reuse confirmed capabilities
- Require nonempty project/path/run scope for capability minting
- Reject empty/duplicate commit action IDs; thread+revalidate cordinator scope
- Remove internal str_replace mint paths (failure re-signing, pre-confirmation anchors)
- Redact capabilities/post-edit content in CLI rendering
- Reconcile reviewer blockers and persist anchors across compaction
- Add regression coverage across agents, cli, common, sdk, agent-runtime
Remove the missing-path pending prune that emptied synthetic and resumed pending files during CI/gate runs. Restore the list_jobs description phrase for unchanged digests. Cap compact proactive results on usable rows, reject host-like path segments after URL capture, and add M4 regression coverage.
Option-only set was treated as an environment dump, which blocked legitimate basher strict-mode preludes. Classify set/export/env more carefully and deny wrapped dump forms (busybox, env -0, command/nice wrappers, substitutions) across non-full-access profiles, including tmux-test.
Parent workflow requirementCoverage (commit/push, full validation, CI green) was falsely elevating specialist repair loops. Filter those rows at finalization and repair consumers, scope specialist spawn briefs, document the contract, and unwrap nested editor set_output envelopes.
Call-site filters must re-check structured requirementCoverage evidence the same way finalization does, so evidence-only parent ownership credits LOOKS_GOOD without spawning repair-editor. Regen gate helpers, unit tests, and docs.
Parent-owned process tasks are out of scope for specialist BLOCKING, so the prompt assertion must match the in-scope requirementCoverage wording or CI stays red on PR #37.
@AnzoBenjamin
AnzoBenjamin merged commit 560b1ac into main Aug 6, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant