Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions .agents/pm/extensions/.managed-extensions.json
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
{
"version": 1,
"updated_at": "2026-08-28T20:03:27.382Z",
"updated_at": "2026-09-27T07:41:16.478Z",
"entries": [
{
"name": "pm-github",
"directory": "pm-github",
"scope": "project",
"manifest_version": "2026.8.18",
"manifest_version": "2026.9.26",
"manifest_entry": "./dist/index.js",
"capabilities": [
"commands",
Expand Down Expand Up @@ -94,13 +94,13 @@
]
},
"installed_at": "2026-08-28T20:03:27.138Z",
"updated_at": "2026-08-28T20:03:27.138Z",
"updated_at": "2026-09-27T07:15:44.450Z",
"source": {
"kind": "npm",
"input": "npm:pm-github",
"input": "npm:pm-github@2026.9.26",
Comment thread
greptile-apps[bot] marked this conversation as resolved.
"location": "package",
"package": "pm-github",
"version": "2026.8.18"
"version": "2026.9.26"
}
}
]
Expand Down
47 changes: 47 additions & 0 deletions .agents/pm/history/pm-graph-ipvn.jsonl

Large diffs are not rendered by default.

79 changes: 79 additions & 0 deletions .agents/pm/issues/pm-graph-ipvn.toon
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
id: pm-graph-ipvn
title: Refresh managed pm-github extension for project-local PM CLI 2026.9.27
description: "The tracker began with a managed pm-github 2026.8.18 copy and package tools at 2026.9.23. Refresh the project-scoped extension to 2026.9.26, pin current PM CLI/SDK 2026.9.27 with published pm-ops 2026.9.28 and pm-changelog 2026.9.25, and copy the published canonical merge-driver launcher. Install the extension through the project-local CLI so its SDK link resolves to that same host version. Preserve the disabled scheduled sync workflow."
type: Issue
status: blocked
priority: 1
tags: []
created_at: "2026-09-27T07:07:21.121Z"
updated_at: "2026-10-02T22:42:12.299Z"
author: codex
acceptance_criteria: "Install published pm-github 2026.9.26 in project scope and verify its exact managed source, activation, strict health, release gate, and privacy diff.; Keep scheduled GitHub sync disabled until its pre-push privacy gate exists.; The package manifest and lockfile resolve CLI 2026.9.27, pm-ops 2026.9.28, and pm-changelog 2026.9.25 exactly.; The launcher is byte-identical to the published pm-ops template.; CI and the disabled sync workflow use the canonical project-local package installer and pin the same pm-github version recorded in managed metadata.; Real child checkout tests reject an incomplete pm-ops directory and a dangling package link without registering merge drivers."
severity: medium
environment: Candidate project-local ./node_modules/.bin/pm at CLI 2026.9.27; original report used global CLI 2026.9.26
repro_steps: Run pm health --strict-exit --json in fleet/pm-graph; inspect extension_host_pm_cli_version_skew and .agents/pm/extensions/pm-github/package.json.
expected_result: Managed pm-github 2026.9.26 resolves against pinned project-local CLI 2026.9.27; strict tracker health exits zero.
actual_result: "Original failure: managed pm-github 2026.8.18 failed strict health under global CLI 2026.9.26. Current candidate: local CLI 2026.9.27 activates pinned pm-github 2026.9.26 and strict health exits zero, as recorded in verification comments."
comments[6]{created_at,author,text}:
"2026-09-28T06:01:57.284Z",claude-hub,"2026-09-28: pinned pm-ops 2026.9.28 and re-copied its templates/prepare-merge-driver.ts (pm-ops#124: the omit-dev skip now checks every Node resolution path for an incomplete hoisted pm-ops, so a broken ancestor install fails instead of silently skipping the merge drivers). release:check and changelog:check pass on this branch."
"2026-10-02T21:42:45.135Z",codex-sol-land,"Resumed PR #116 preparation from remote e4d745d. Live PR: CI green, zero unresolved inline threads. Existing findings and replies retained. Checking current base, full release gate and final-head review availability; no merge or item closure."
"2026-10-02T21:47:55.226Z",codex-sol-land,"The PM-linked full gate injects a fixed PM_PATH into all real CLI child-workspace tests, conflicting with their independent tracker initialization. Stopped that unsuitable-context invocation; the unchanged CI release gate now runs directly with its normal environment under the heavy lock. A focused PM-linked workflow regression will supply linked execution evidence."
"2026-10-02T22:02:16.434Z",codex-sol-land,"Fresh npm ci and direct locked npm run release:check exit 0. Full suite: 293 pass, 0 failures/skips; configured coverage remains 99.65% lines, 94.06% branches, 100% functions. PM-linked release-workflow regression passes 8/8 and local pinned CLI strict health with required merge drivers passes. All prior findings remain resolved; unavailable substantive reviews remain blockers, and existing pm-graph-6zil owns the wider coverage target. No gate, code, hosted service or release changes."
"2026-10-02T22:27:43.750Z",codex-sol-land,"Second-round feedback: shared CI/sync installer regression failed 5/5 before extraction and passes 5/5 after, covering argv pin, tracked/untracked registry state, version mismatch and install failure. Current title/environment/expected result now reflect local CLI 2026.9.27; original failure remains explicitly labeled in actual_result, with current green result separate. The mutable docs link now identifies #124 as the source of already-published pm-ops 2026.9.28; dated history is preserved. Refuse the EACCES/ELOOP proposal because unresolved filesystem state must fail closed and original diagnostics are useful; retain the canonical byte-identical launcher. Canonical v2026.09.28 owns the real ancestor-install regression, so the duplicate consumer fixture request remains unnecessary."
"2026-10-02T22:42:10.346Z",codex-sol-land,"Round-two review fixes: shared exact-pin extension installer now serves both workflows; five installer regressions failed before the fix and pass after it; current CLI metadata and the already-published launcher reference are corrected. Canonical lstat failure handling and duplicate ancestor coverage requests are technically refused, with evidence in their review replies. Resumed verification: npm ci, current-base rebase, fresh committed-dist comparison, strict local tracker health with required merge drivers, npm run release:check, and bun install --no-save all passed. Full gate: 298 tests, 298 pass, 0 skips; configured coverage thresholds unchanged. PM-linked test/release-workflow.test.ts passed. Earlier findings and technical refusals retained; workflow fixes are included in this gate. Exact pushed-head CI and substantive reviewer availability remain separate checks; no merge, release, publication or item closure."
notes[8]{created_at,author,text}:
"2026-09-27T07:15:27.801Z",codex,"First full release:check ran 292 tests and failed exactly one assertion: the prepare launcher was not the unmodified published pm-ops template. Copied the installed pm-ops 2026.9.26 template byte for byte; will rerun the full gate. This is the published local broken-install guard, not the unmerged hoisted guard from pm-ops #124."
"2026-09-27T07:21:59.571Z",codex,"The npm registry published @unbrained/pm-cli 2026.9.27 while pm-github latest remains 2026.9.26. A real local CLI 2026.9.27 probe failed strict health with extension_host_pm_cli_version_skew:2026.9.27:2026.9.26:pm-github. Reverted the development CLI pin to the newest compatible published pair (2026.9.26) and retained the verified green release gate. Fleet certification must revisit this after pm-github 2026.9.27 is published; do not call this latest-CLI certification."
"2026-09-27T07:28:56.699Z",codex,"Greptile exact-head PR #116 found two valid gaps. Both workflows installed unversioned pm-github despite pinned managed metadata, and the launcher lacked a consumer-level test for incomplete directories and dangling links. Pinned both workflow installs to npm:pm-github@2026.9.26, removed the obsolete npm 10 and legacy manifest rewrites, added package-version readback, and added real child-checkout regression cases. Targeted 7/7 launcher tests and typecheck pass; the complete gate is being repeated."
"2026-09-27T07:35:25.509Z",codex,"Correction to prior release-order note: the 2026.9.27 health failure was caused by the project extension installer creating a pm-cli symlink to the global 2026.9.26 CLI. The latest published pm-github 2026.9.26 is compatible when installed through the project-local CLI 2026.9.27. Reinstalled it with that local CLI, verified the extension now resolves node_modules/@unbrained/pm-cli 2026.9.27, and strict health passes. The package pin now targets latest CLI/SDK 2026.9.27. This correction is append-only; the earlier inference was wrong."
"2026-09-27T07:41:37.622Z",codex,"Final local candidate after Greptile fixes: @unbrained/pm-cli 2026.9.27, pm-github 2026.9.26, pm-ops 2026.9.26, pm-changelog 2026.9.25. The canonical project-local pm package install succeeded with activation ok and extension SDK resolving to local CLI 2026.9.27. Strict health exits zero with two stale-item advisories. npm run release:check passed 293/293 tests, zero skips, 99.65% lines, 94.06% branches, 100% functions, statement coverage unmeasured, zero production audit findings, and changelog current. GitHub workflow remains disabled_manually. The four-way 100% mandate remains open in pm-graph-6zil."
"2026-09-27T08:17:04.361Z",codex,"2026-09-27: Applied defense in depth to the still-disabled GitHub issue-sync pilot after a valid CodeRabbit finding on sibling pm-jira PR #119: the checked-in sync job has if: false, so schedule/manual triggers cannot run the write-capable import even if workflow state is re-enabled accidentally. The required fail-closed pre-push privacy gate remains separate and unimplemented; this is not authorization to enable sync. The package release gate and exact-head review must rerun after this change."
"2026-09-27T08:26:18.652Z",codex,"2026-09-27 final local rerun after checked-in sync job if: false: npm run release:check exits 0, including the existing 293/293 source tests, honest 99.65% line / 94.06% branch / 100% function coverage, packed npm/Bun acceptance, changelog and release attestation gates. GitHub workflow remains disabled_manually; no fail-closed pre-push privacy gate exists yet. This candidate must stay unmerged until exact-head CI and bot review are complete, and cannot be certified at requested 100/100/100/100 coverage."
"2026-09-27T08:35:52.784Z",codex,"2026-09-27 downstream Greptile P1 on pm-todos #103 revealed the published pm-ops 2026.9.26 launcher copied here misses incomplete hoisted installs in ancestor node_modules. Canonical source issue ops-jzp5 and unmerged pm-ops #124 already fix and test this path. This PR is blocked until the reviewed source is published, this package pins and copies its new template byte for byte, full release gate and strict health pass, and exact-head bot review repeats. Earlier green CI/Greptile status does not certify this edge case."
files[10]:
- path: .agents/pm/extensions/.managed-extensions.json
scope: project
note: Exact project-scoped pm-github source
- path: .github/workflows/ci.yml
scope: project
note: Exact extension install in CI
- path: .github/workflows/pm-github-sync.yml
scope: project
note: Exact extension install while workflow remains disabled
- path: package-lock.json
scope: project
note: Resolved dependency lock
- path: package.json
scope: project
note: Compatible exact development tool pins
- path: scripts/install-pm-github.sh
scope: project
- path: scripts/prepare-merge-driver.ts
scope: project
note: Published pm-ops 2026.9.28 canonical launcher copy
- path: test/install-pm-github.test.ts
scope: project
- path: test/prepare-merge-driver.test.ts
scope: project
note: Broken directory and dangling link acceptance
- path: test/release-workflow.test.ts
scope: project
tests[5]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}:
"npm run release:check",project,600,codex,"2026-09-27T07:22:23.666Z",local_mutation,fix/pm-graph-github-extension-cli-compat-2026-09-27
node --test test/prepare-merge-driver.test.ts,project,120,codex,"2026-09-27T07:28:56.044Z",local_mutation,fix/pm-graph-github-extension-cli-compat-2026-09-27
./node_modules/.bin/pm health --strict-exit --json,project,120,codex,"2026-09-27T07:35:24.855Z",local_mutation,fix/pm-graph-github-extension-cli-compat-2026-09-27
node --test test/release-workflow.test.ts,project,120,codex-sol-land,"2026-10-02T21:47:56.173Z",local_mutation,fix/pm-graph-github-extension-cli-compat-2026-09-27
node --test test/install-pm-github.test.ts,project,120,codex-sol-land,"2026-10-02T22:25:05.974Z",local_mutation,fix/pm-graph-github-extension-cli-compat-2026-09-27
docs[4]:
- path: "https://github.com/unbraind/pm-cli-companion/blob/main/.agents/pm/features/pm-cli-website-377e.toon"
scope: global
note: Fleet GitHub sync rollout
- path: "https://github.com/unbraind/pm-ops/blob/main/.agents/pm/issues/ops-jzp5.toon"
scope: global
note: Canonical hoisted broken-install source issue
- path: "https://github.com/unbraind/pm-ops/pull/124"
scope: global
note: Canonical source of the already-published pm-ops 2026.9.28 hoisted-install fix
- path: "https://github.com/unbraind/pm-graph/pull/116"
scope: project
body: ""
20 changes: 1 addition & 19 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,25 +39,7 @@ jobs:

- name: Install project pm-github extension
shell: bash
run: |
set -euo pipefail
# npm 12 emits object-shaped `npm pack --json` output, while the
# current pm installer accepts npm 10's array-shaped response.
npm10_root="${RUNNER_TEMP}/pm-npm10"
npm install --prefix "${npm10_root}" --no-save --ignore-scripts npm@10.9.3
PATH="${npm10_root}/node_modules/.bin:${PATH}" ./node_modules/.bin/pm install npm:pm-github --project
# The published 2026.8.18 artifact still carries the obsolete `pm`
# manifest key. Normalize it to the source manifest's enforced floor
# before the strict health gate; the installed artifact is ignored.
extension_manifest=".agents/pm/extensions/pm-github/manifest.json"
jq 'del(.pm) | .pm_min_version = "2026.8.20"' "${extension_manifest}" > "${RUNNER_TEMP}/pm-github-manifest.json"
mv "${RUNNER_TEMP}/pm-github-manifest.json" "${extension_manifest}"
managed_registry=".agents/pm/extensions/.managed-extensions.json"
if git ls-files --error-unmatch "${managed_registry}" > /dev/null 2>&1; then
git restore -- "${managed_registry}"
else
rm -f "${managed_registry}"
fi
run: bash scripts/install-pm-github.sh

- name: Verify tracked pm project health
shell: bash
Expand Down
21 changes: 3 additions & 18 deletions .github/workflows/pm-github-sync.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ concurrency:

jobs:
sync:
# Imported issue bodies need a fail-closed pre-push privacy gate first.
if: ${{ false }}
runs-on: ubuntu-latest
env:
GH_TOKEN: ${{ github.token }}
Expand Down Expand Up @@ -54,24 +56,7 @@ jobs:

- name: Install project pm-github extension
shell: bash
run: |
set -euo pipefail
# npm 12 emits object-shaped `npm pack --json` output, while the
# current pm installer accepts npm 10's array-shaped response.
npm10_root="${RUNNER_TEMP}/pm-npm10"
npm install --prefix "${npm10_root}" --no-save --ignore-scripts npm@10.9.3
PATH="${npm10_root}/node_modules/.bin:${PATH}" ./node_modules/.bin/pm install npm:pm-github --project
# The published 2026.8.18 artifact still carries the obsolete `pm`
# manifest key. Normalize it to the source manifest's enforced floor.
extension_manifest=".agents/pm/extensions/pm-github/manifest.json"
jq 'del(.pm) | .pm_min_version = "2026.8.20"' "${extension_manifest}" > "${RUNNER_TEMP}/pm-github-manifest.json"
mv "${RUNNER_TEMP}/pm-github-manifest.json" "${extension_manifest}"
managed_registry=".agents/pm/extensions/.managed-extensions.json"
if git ls-files --error-unmatch "${managed_registry}" > /dev/null 2>&1; then
git restore -- "${managed_registry}"
else
rm -f "${managed_registry}"
fi
run: bash scripts/install-pm-github.sh

- name: Validate GitHub access
run: ./node_modules/.bin/pm github validate --repo "${REPOSITORY}"
Expand Down
Loading
Loading