fix: repair authored skill installation and verification safety - #8
Conversation
|
CC @Zero-State-LLC/partner-agents. Flagged for shared triage. |
prabu-openclaw
left a comment
There was a problem hiding this comment.
Comment-only (not approving) — same concerns as the sibling Sigil-Forge/NeonGenie PRs:
- Relicensing MIT → LicenseRef-Zero-State-Proprietary-1.0 (README, SKILL.md, hyperlex.manifest.yaml, pyproject classifiers) bundled into a PR titled as a safety/audit fix. That's a legal/business decision and should be called out and approved separately from the technical installer changes.
- New
scripts/install_transaction.pyplus a new--rollbackpath in install.sh that replaces the oldcp -a-based rollback with staged install/backup/activate logic, including re-running the hyperlex check+smoke suite on a rollback candidate before restoring it. This touches destructive filesystem paths (replacing a live skill install) and adds a documented non-atomic window during rename recovery. Adversarial tests (test_transaction.py's interrupted-rename matrix, symlink rejection, secrets-not-packaged) look solid and cover the failure modes I'd probe for.
CI is green. Flagging for a human owner of the Hermes install/profile model to sign off on the destructive-path semantics and the relicensing decision before merge — not blocking on a defect I found.
Licensing-scope clarification for owner reviewThe pre-PR source already contained the supplied proprietary root license. This PR changes contradictory metadata to match that existing file; it does not edit LICENSE or LICENSE_POLICY, and does not claim to revoke any historical grants. I rechecked the original base and current tracked license bytes:
Owner/legal sign-off on the metadata and distribution intent is still appropriate; this comment is evidence, not human approval. The PR will remain unmerged. Installer follow-up findings are being handled separately where applicable. |
Summary
Repair authored skill installation and upgrade safety: active-profile routing, validated staged activation, output/session preservation, explicit failure status and recoverable interrupted renames. Correct affected recipes, packaging and current-distribution metadata; preserve existing license grants and divergent variants.
Verification
PYTHONPATH=src:scripts python -m pytest -q -ra --tb=short -o addopts= tests tests_auditin an isolated Python 3.12 environment.Limits
No real profile installation, live provider usage, merge or release. Upgrade transactions are not power-loss/crash-atomic; stop runtime writers while upgrading. Existing customizations outside preserved output are retained in backup rather than automatically merged.