Compare commits
merge into: mosaicstack/stack:main
mosaicstack/stack:main
mosaicstack/stack:feat/push-guard-null-case-verification
mosaicstack/stack:feat/mos-ste-writing-standard
mosaicstack/stack:mos-comms-live
mosaicstack/stack:docs/heartbeat-framework-layering-ms-lead
mosaicstack/stack:feat/869-c4-version-coupling
mosaicstack/stack:feat/869-c2-install-ordering-guard
mosaicstack/stack:feat/869-c5-doctor-activation-check
mosaicstack/stack:feat/per-agent-gitea-identity
mosaicstack/stack:fix/875-belongs-case-insensitive-slug
mosaicstack/stack:fix/ci-queue-wait-404-branch-absent
mosaicstack/stack:feat/869-c1-activation-probe
mosaicstack/stack:feat/869-c3-broker-supervisor
mosaicstack/stack:fix/865-tea-cli-comment-invocation
mosaicstack/stack:feat/glpi-skills
mosaicstack/stack:fix/860-deflake-mutator-lease-gate
mosaicstack/stack:fix/850-detect-platform-port-normalization
mosaicstack/stack:fix/856-worktree-deps-preflight
mosaicstack/stack:fix/835-pr-review-approve-reject-comment-flag
mosaicstack/stack:fix/848-truthful-evidence
mosaicstack/stack:fix/812-pr-review-comment
mosaicstack/stack:fix/849-recovery-runtime-fixture-race
mosaicstack/stack:docs/758-ledger-m5-001-sync
mosaicstack/stack:feat/834-tc-server-side-doc
mosaicstack/stack:feat/833-constrained-recovery-command
mosaicstack/stack:feat/827-gate0-probe
mosaicstack/stack:governance/gate0-probe3-amendment
mosaicstack/stack:fix/795-codex-pr-diff
mosaicstack/stack:fix/795-ci-base-jq
mosaicstack/stack:fix/795-ci-base-git
mosaicstack/stack:feat/791-pr3-fleet-regen
mosaicstack/stack:feat/791-pr2-snapshot-restore
mosaicstack/stack:fix/807-glpi-206
mosaicstack/stack:fix/808-agent-send-false-sender
mosaicstack/stack:feat/791-upgrade-config-protection
mosaicstack/stack:feat/790-mosaic-yolo-claudex-pr2
mosaicstack/stack:feat/790-mosaic-yolo-claudex
mosaicstack/stack:feat/758-v1-v2-migrator
mosaicstack/stack:fix/766-exact-fleet-comms
mosaicstack/stack:test/758-reconciler-lifecycle-gates
mosaicstack/stack:docs/771-kbn101-db-role-split
mosaicstack/stack:test/758-example-profile-dispositions
mosaicstack/stack:feat/758-shared-role-resolution
mosaicstack/stack:feat/mos-logical-identity-fencing
mosaicstack/stack:feat/769-kbn100-unified-schema
mosaicstack/stack:docs/753-kbn010-threat-gate
mosaicstack/stack:feat/758-roster-v2-compiler
mosaicstack/stack:feat/756-official-discord-plugin
mosaicstack/stack:docs/758-fleet-config-management
mosaicstack/stack:fix/mos-option2-qualification-format
mosaicstack/stack:docs/issue-758-m0
mosaicstack/stack:docs/mos-option2-qualification
mosaicstack/stack:mos-comms
mosaicstack/stack:feat/tess-interaction-agent
mosaicstack/stack:fix/tess-docs-format
mosaicstack/stack:next
mosaicstack/stack:draft/mosaic-platform-prd
mosaicstack/stack:fix/installer-provider-gate-and-local-gateway-redis
mosaicstack/stack:release/mosaic-cli-0.0.37
mosaicstack/stack:feat/framework-constitution-alpha
mosaicstack/stack:fix/git-wrapper-repo-detection
mosaicstack/stack:fix/woodpecker-wrapper-legacy-mosaic
mosaicstack/stack:fix/t-a292e96f-gitea-pr-metadata
mosaicstack/stack:fix/gitea-pr-metadata-login-t-a292e96f
mosaicstack/stack:fix/t_a292e96f-pr-metadata-gitea
mosaicstack/stack:fix/t_3a368a52-gitea-usc-login
mosaicstack/stack:fix/bootstrap-hotfix
mosaicstack/stack:fix/populate-known-packages-list
mosaicstack/stack:fix/idempotent-init
mosaicstack/stack:v0.0.39-alpha
mosaicstack/stack:mosaic-v0.0.31
mosaicstack/stack:fed-v0.2.0-m2
mosaicstack/stack:fed-v0.1.0-m1
mosaicstack/stack:mosaic-v0.0.29
mosaicstack/stack:mosaic-v0.0.28
mosaicstack/stack:mosaic-v0.0.27
mosaicstack/stack:mosaic-v0.0.26
mosaicstack/stack:mosaic-v0.0.25
mosaicstack/stack:mosaic-v0.0.24
mosaicstack/stack:v0.2.0
mosaicstack/stack:v0.1.0
mosaicstack/stack:v0.0.8
mosaicstack/stack:v0.0.7
mosaicstack/stack:v0.0.6
mosaicstack/stack:v0.0.5
mosaicstack/stack:v0.0.4
..
pull from: mosaicstack/stack:feat/push-guard-null-case-verification
mosaicstack/stack:main
mosaicstack/stack:feat/push-guard-null-case-verification
mosaicstack/stack:feat/mos-ste-writing-standard
mosaicstack/stack:mos-comms-live
mosaicstack/stack:docs/heartbeat-framework-layering-ms-lead
mosaicstack/stack:feat/869-c4-version-coupling
mosaicstack/stack:feat/869-c2-install-ordering-guard
mosaicstack/stack:feat/869-c5-doctor-activation-check
mosaicstack/stack:feat/per-agent-gitea-identity
mosaicstack/stack:fix/875-belongs-case-insensitive-slug
mosaicstack/stack:fix/ci-queue-wait-404-branch-absent
mosaicstack/stack:feat/869-c1-activation-probe
mosaicstack/stack:feat/869-c3-broker-supervisor
mosaicstack/stack:fix/865-tea-cli-comment-invocation
mosaicstack/stack:feat/glpi-skills
mosaicstack/stack:fix/860-deflake-mutator-lease-gate
mosaicstack/stack:fix/850-detect-platform-port-normalization
mosaicstack/stack:fix/856-worktree-deps-preflight
mosaicstack/stack:fix/835-pr-review-approve-reject-comment-flag
mosaicstack/stack:fix/848-truthful-evidence
mosaicstack/stack:fix/812-pr-review-comment
mosaicstack/stack:fix/849-recovery-runtime-fixture-race
mosaicstack/stack:docs/758-ledger-m5-001-sync
mosaicstack/stack:feat/834-tc-server-side-doc
mosaicstack/stack:feat/833-constrained-recovery-command
mosaicstack/stack:feat/827-gate0-probe
mosaicstack/stack:governance/gate0-probe3-amendment
mosaicstack/stack:fix/795-codex-pr-diff
mosaicstack/stack:fix/795-ci-base-jq
mosaicstack/stack:fix/795-ci-base-git
mosaicstack/stack:feat/791-pr3-fleet-regen
mosaicstack/stack:feat/791-pr2-snapshot-restore
mosaicstack/stack:fix/807-glpi-206
mosaicstack/stack:fix/808-agent-send-false-sender
mosaicstack/stack:feat/791-upgrade-config-protection
mosaicstack/stack:feat/790-mosaic-yolo-claudex-pr2
mosaicstack/stack:feat/790-mosaic-yolo-claudex
mosaicstack/stack:feat/758-v1-v2-migrator
mosaicstack/stack:fix/766-exact-fleet-comms
mosaicstack/stack:test/758-reconciler-lifecycle-gates
mosaicstack/stack:docs/771-kbn101-db-role-split
mosaicstack/stack:test/758-example-profile-dispositions
mosaicstack/stack:feat/758-shared-role-resolution
mosaicstack/stack:feat/mos-logical-identity-fencing
mosaicstack/stack:feat/769-kbn100-unified-schema
mosaicstack/stack:docs/753-kbn010-threat-gate
mosaicstack/stack:feat/758-roster-v2-compiler
mosaicstack/stack:feat/756-official-discord-plugin
mosaicstack/stack:docs/758-fleet-config-management
mosaicstack/stack:fix/mos-option2-qualification-format
mosaicstack/stack:docs/issue-758-m0
mosaicstack/stack:docs/mos-option2-qualification
mosaicstack/stack:mos-comms
mosaicstack/stack:feat/tess-interaction-agent
mosaicstack/stack:fix/tess-docs-format
mosaicstack/stack:next
mosaicstack/stack:draft/mosaic-platform-prd
mosaicstack/stack:fix/installer-provider-gate-and-local-gateway-redis
mosaicstack/stack:release/mosaic-cli-0.0.37
mosaicstack/stack:feat/framework-constitution-alpha
mosaicstack/stack:fix/git-wrapper-repo-detection
mosaicstack/stack:fix/woodpecker-wrapper-legacy-mosaic
mosaicstack/stack:fix/t-a292e96f-gitea-pr-metadata
mosaicstack/stack:fix/gitea-pr-metadata-login-t-a292e96f
mosaicstack/stack:fix/t_a292e96f-pr-metadata-gitea
mosaicstack/stack:fix/t_3a368a52-gitea-usc-login
mosaicstack/stack:fix/bootstrap-hotfix
mosaicstack/stack:fix/populate-known-packages-list
mosaicstack/stack:fix/idempotent-init
mosaicstack/stack:v0.0.39-alpha
mosaicstack/stack:mosaic-v0.0.31
mosaicstack/stack:fed-v0.2.0-m2
mosaicstack/stack:fed-v0.1.0-m1
mosaicstack/stack:mosaic-v0.0.29
mosaicstack/stack:mosaic-v0.0.28
mosaicstack/stack:mosaic-v0.0.27
mosaicstack/stack:mosaic-v0.0.26
mosaicstack/stack:mosaic-v0.0.25
mosaicstack/stack:mosaic-v0.0.24
mosaicstack/stack:v0.2.0
mosaicstack/stack:v0.1.0
mosaicstack/stack:v0.0.8
mosaicstack/stack:v0.0.7
mosaicstack/stack:v0.0.6
mosaicstack/stack:v0.0.5
mosaicstack/stack:v0.0.4
11
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
1806b3a57a |
style(git): prettier-format push-guard README to the repo's format gate
ci/woodpecker/pr/ci Pipeline was successful
The prior commit passed a standalone 'prettier --check README.md' in the author's environment but FAILED 'pnpm format:check' in the repository, which applies the repo's own prettier configuration. Same tool, different configuration, opposite answer — and I pushed past the warning rather than stopping at it. Formatting only; no content change. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01YKj59Qadrb2WBLaePvkM7H |
||
|
|
fc80138326 |
docs(git): correct push-guard README excluded-case provenance
ci/woodpecker/pr/ci Pipeline was canceled
The 46-vs-43 explanation named w2-fixture and g1-fixture as excluded. Neither runs
inside test-push-guard.sh — w2-fixture is in test-verify-clean-clone.sh and
g1-fixture is in test-mutate-push-guard.sh — so neither could contribute to its
tally. A reader auditing the denominator would have hunted them in the wrong files
with no way to tell whether the number or the explanation was wrong.
True excluded set, re-derived from the actual run output: the two z1 warning
assertions (which assert on a whole CLASS of output rather than an exit code, so
they carry no '(exit N)' for the parser) plus the e9-fixture precondition line
printed in 'ok' form. All three still RUN and still gate the suite — excluded from
ATTRIBUTION, not from EXECUTION. That distinction was missing and is what a reader
needs.
Blocking rather than cosmetic: this section exists to make a GENERATED coverage
number auditable, and every figure in the table is generated while the sentence
explaining it was typed from memory. The generated/typed boundary is where this
class of defect keeps landing.
Documentation only. All six script blobs are byte-identical to
|
||
|
|
8fdc8738ed |
fix(git): push-guard harness — resolve three re-review blockers + two corrections
ci/woodpecker/pr/ci Pipeline was successful
Authored by installer-7; committed by mos-claude (no credential for this remote). push-guard.sh and test-push-guard.sh are BYTE-IDENTICAL to the previously cleared versions — every change this round is in the harness, confirming the reviewer's framing that none of the three blockers was in the guard itself. B1 verify-clean-clone.sh could not verify the artifact in its real monorepo location: it resolved ROOT but kept artifacts as bare basenames, so running it in place reported all artifacts NOT TRACKED. Its own suite missed this because every fixture installed artifacts at fixture ROOT — a fixture encoding a layout the real subject does not have. PREFIX now comes from 'git rev-parse --show-prefix' and is threaded through the ls-tree pathspec, the cloned stat, and the suite cwd; the verifier PRINTS the prefix. Three needles: nested-layout pass, prefix-reported (else a green only means the prefix was ignored harmlessly), and mode-needle-still- bites-nested (a prefix threaded into the clone but not ls-tree would silently stop checking modes). B2 the generator reported full coverage and exited 0 on a RED baseline — any pre-existing failure marked every mutant killed. Now refuses unless baseline is exit 0 with zero failures, prints the actual tally on refusal, emits no table, and scores kills by NAMED DELTA rather than a raw red count. B3 the generator mutated the reviewed source in place; SIGKILL stranded a mutant and contaminated a following run. Guard and suite are now copied into a temp dir and mutations apply to that copy — no restore step to fail. The author's first control for this was itself vacuous (a 3s kill lands during baseline, before any mutation, so it passed against the unfixed mechanism too); the real control drives the kill from inside the run on the second suite invocation, plus a needle proving the reconstructed pre-fix mechanism DOES strand. Corrections: 'shellcheck clean' had been measured at -S warning and published unqualified — a filtered measurement stated as an unfiltered claim. Now clean at DEFAULT severity across six files with one scoped, documented SC2016 disable. ARTIFACTS extended five -> six so the test files no longer omit themselves. Verified before commit: six files sha256-matched to the author's hashes; shellcheck exit 0 at default severity; push-guard 46/46 and verifier 9/9 run directly; the in-place verifier resolved the real nested prefix against this tree. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01YKj59Qadrb2WBLaePvkM7H |
||
|
|
8310075d33 |
fix(git): push-guard — resolve re-review blockers; mutation table now generated
ci/woodpecker/pr/ci Pipeline was successful
Authored by installer-7; committed by mos-claude (no credential for this remote). BLOCKER 1 — verify-clean-clone.sh had B1's own defect: it copied WORKING-TREE files into a scratch repo and asserted the SCRATCH index, so a stale local exec bit was laundered in and it reported success while the committed artifact was still 100644. v2 reads mode from 'git ls-tree' of the SOURCE COMMIT and runs from 'git clone --no-local --no-hardlinks' of that commit; there is no 'cp' in the file. Proven by A/B against one laundered repo: v1 EXIT=0, v2 EXIT=1 (both observed, not asserted). New test-verify-clean-clone.sh 6/6, incl. a fixture that first proves it really is git=100644 disk=755 before testing it. BLOCKER 2 — empty-merge needle + non-empty-merge control, both asserting on OUTPUT; the fixture first proves it IS a merge with a tree identical to both parents. The 'non-blocking' README item was not documentation: regenerating its mutation table (now generated by mutate-push-guard.sh, not hand-numbered) found TWO genuinely surviving mutants against a 46/46 green suite — staged-but-uncommitted opt-out honoured, and unparseable committed config ignored. Both still exit 6 under mutation because control falls to a SIBLING refusal, so an exit-code-only assertion would have been satisfied by the wrong branch. It also found a live instance of the substring-anchor defect already in the suite: three branches print 'OPT-OUT IS NOT REVIEWABLE', so deleting one let the needle RE-POINT to a sibling instead of failing. Re-anchored. Suite 44 -> 46. Verifier 6/6. 13 mutants, 0 survived. Also: README reformatted to satisfy 'pnpm format:check' (prettier), which was failing CI at both prior heads — a gate neither author nor reviewer had exercised. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01YKj59Qadrb2WBLaePvkM7H |
||
|
|
b0fb208b89 |
fix(git): push-guard — resolve 5 review blockers + a 6th self-found instance
ci/woodpecker/pr/ci Pipeline failed
Authored by installer-7; committed by mos-claude (installer-7 has no credential for this remote).
All five blockers from rev-974's review were REPRODUCED before any fix.
B1 mode 100644: the artifact was never executable, so an untouched clone could not run the
suite at all (exit 126) — both prior 32/32 runs used a local exec bit set at creation.
Fixed in the INDEX (git update-index --chmod=+x), plus verify-clean-clone.sh which asserts
the mode via 'git ls-files -s' (not disk) and executes the suite DIRECTLY ('bash script'
masks a missing bit). Negative control: chmod 644 makes the verifier refuse.
B2 mapfile < <(git diff) observed mapfile's status, not the producer's — a fatal pathspec
error reported a clean scan, exit 0. pipefail governs PIPELINES; a process substitution is
an async child whose status is never collected.
B3 OFF accepted from an untracked working-tree config, defeating the committed-artifact
asymmetry — and write_config() wrote untracked configs, so every opt-out control asserted
the forbidden provenance and passed green. OFF is now re-read from HEAD; untracked,
staged-uncommitted, committed-symlink, and committed-ON-flipped-locally are all refused.
B4 --since-head proved inequality, not ancestry: an unrelated pre-existing commit passed as
new work.
B5 empty ROOT commit exempted by parent-count, then reported PUSH CONFIRMED. Emptiness is now
defined as 'tree identical to every parent' rather than exempted by category.
B6 (self-found by sweeping for the CONSTRUCT, not the report) same < <(git diff) in
cmd_check_staged — fails closed but published a wrong diagnosis. Both callers now route
through one staged_files_z().
41/41 needles, executed directly from a clean clone. Known gap, stated: B2's second instance is
fixed but UNNEEDLED — a corrupt index aborts earlier at 128, so no fault injection reaches it.
Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01YKj59Qadrb2WBLaePvkM7H
|
||
|
|
62e3bf9e28 |
fix(git): push-guard.README.md — required repo config (#975) + heredoc-in-substitution warning
ci/woodpecker/pr/ci Pipeline is pending
|
||
|
|
b7d391f9f4 |
fix(git): test-push-guard.sh — required repo config (#975) + heredoc-in-substitution warning
ci/woodpecker/pr/ci Pipeline was canceled
|
||
|
|
1036449b57 | fix(git): push-guard.sh — required repo config (#975) + heredoc-in-substitution warning | ||
|
|
63c5d2056f |
feat(git): add push-guard.README.md
ci/woodpecker/pr/ci Pipeline failed
Mechanical closure of 'a verification that passes when the thing it verifies never happened.' |
||
|
|
1288ce3721 |
feat(git): add test-push-guard.sh
Mechanical closure of 'a verification that passes when the thing it verifies never happened.' |
||
|
|
92272a6400 |
feat(git): add push-guard.sh
Mechanical closure of 'a verification that passes when the thing it verifies never happened.' |