Repository navigation
Record scheduled memory learning and daily native lifecycle evidence - #116
Conversation
…EAD) (#118) gitleaks' git mode scans every fetched ref by default, and the job checks out with fetch-depth 0, so one open branch's finding failed every other pull request: PR #116's branch (four generic-api-key hits on 64-hex fingerprint values, commit b801fe4) failed PR #117's required secret-scan. Scanning HEAD's ancestry covers a pull request's merge commit or main on push; each branch is still scanned by its own pull request. Records the resolution of the scope decision .gitleaks.toml and docs/github-automation.md had left to the coordinator. Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Heads-up from the coordinating session: #135 merged ( |
|
Diagnosis of this PR's The findings are false positives. All 4 are The fix is in #155. It adds a rule-scoped, exact-file, whole-line allowlist with regression tests showing that real What this PR then needs. Merge |
…rom generic-api-key (#155) * Exempt ai-memory's SHA-256 rejection fingerprints in #116's evidence from generic-api-key learning.report.aggregate.repeated_rejection_fingerprints[].key in observability/memory-scheduled-20260923.json is ai-memory's rejection_fingerprint (hex_sha256 over normalized rejection fields), a content digest. Rule-scoped, exact-file, whole-line allowlist with regression tests (test_e, test_e2) that an api_key in the file and the same lines elsewhere stay detected. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Pin the 4 reviewed rejection fingerprints by value; an unreviewed 64-hex key stays detected Review of #155 (optional hardening, adopted): the allowlist names the 4 reviewed digests instead of any 64-hex value, like the QuantConnect entry, so a later value under "key" in the same file is still a finding; test_e2 now asserts that case. Comment date aligned to 2026-09-23. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Run the gitleaks allowlist regression tests in CI with the pinned binary (Codex review of #155) The validate job has no gitleaks, so tests/test_gitleaks_config.py skipped entirely in CI. The secret-scan job now runs it with the pinned binary on PATH and GITLEAKS_TESTS_REQUIRED=1, under which a missing binary fails instead of skipping; test_workflow_hardening pins the step. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
#155 has merged ( |
Resolves conflicts in manifests/evidence.json (both branches' additive receipts and files[] entries kept) and observability/grand-dashboard/state.json (recorded_at_utc taken from main's later checkpoint; both sides' lane content was already preserved by git's auto-merge). sha256/bytes for the touched files[] entries were regenerated with scripts/host_receipts.py's register_file() helper rather than hand-typed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ory assistant capture opt-in, ignore Claude Code local state (#159) * Adoption hygiene: native Claude Code pin is a floor (2.1.281), ai-memory assistant capture is opt-in, ignore Claude Code local state bootstrap-macos.sh's install_native ran `"$bin" install <pin>` even when Claude Code's native auto-updater had already installed something newer, so re-running the bootstrap downgraded it. It now keeps a ~/.local/bin/<bin> whose --version is at or above the pin (logs "Kept", downloads and installs nothing); a missing, older or unreadable launcher takes the unchanged checksum-verified install. The check lives inside install_native because tests/test_adoption_bootstrap.py runs that function on its own. Bash 3.2 safe. Both claude-code pins move to 2.1.281 together (shared components keep one version on both platforms). darwin-arm64 a922981f... comes from the official 2.1.281 manifest.json and matches, byte for byte, the copy the native updater installed on a Mac. linux-x64 56fe3da8... comes from the same manifest and was not re-hashed; fetch() checks it before running anything. 2.1.281 fixes a recursive rm of command-substitution output running unprompted in auto and --dangerously-skip-permissions mode. The macOS page's pin table and the generated new-host grand list follow the pins. The Claude settings template no longer passes --capture-assistant to ai-memory's Stop hook. render_config.py adds it only when AI_MEMORY_CAPTURE_ASSISTANT=true (host value file or --set) and rejects any value other than true, false or empty. defaultMode and skipDangerousModePermissionPrompt are unchanged. .gitignore adds .claude/settings.local.json and .claude/worktrees/. Not included, because open PRs #116, #145 and #151 own these files: the manifests/evidence.json re-hash of the 12 changed files, and the adoption/bootstrap.md "changed after `v2026.09.23.1`" marker for the three changed install inputs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Re-hash evidence and mark the Claude Code floor in the bootstrap guide Records the SHA-256/byte entries for every file this branch changes and adds the "changed after `v2026.09.23.1`" note that the docs-consistency test requires for the new install behavior (pins 2.1.281, floor instead of unconditional reinstall). Both files are also edited by open PRs; whichever lands later re-runs the same host_receipts.register_file helper. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Scout <scout@local>
…loor (stacked on #159) (#177) * Adoption hygiene: native Claude Code pin is a floor (2.1.281), ai-memory assistant capture is opt-in, ignore Claude Code local state bootstrap-macos.sh's install_native ran `"$bin" install <pin>` even when Claude Code's native auto-updater had already installed something newer, so re-running the bootstrap downgraded it. It now keeps a ~/.local/bin/<bin> whose --version is at or above the pin (logs "Kept", downloads and installs nothing); a missing, older or unreadable launcher takes the unchanged checksum-verified install. The check lives inside install_native because tests/test_adoption_bootstrap.py runs that function on its own. Bash 3.2 safe. Both claude-code pins move to 2.1.281 together (shared components keep one version on both platforms). darwin-arm64 a922981f... comes from the official 2.1.281 manifest.json and matches, byte for byte, the copy the native updater installed on a Mac. linux-x64 56fe3da8... comes from the same manifest and was not re-hashed; fetch() checks it before running anything. 2.1.281 fixes a recursive rm of command-substitution output running unprompted in auto and --dangerously-skip-permissions mode. The macOS page's pin table and the generated new-host grand list follow the pins. The Claude settings template no longer passes --capture-assistant to ai-memory's Stop hook. render_config.py adds it only when AI_MEMORY_CAPTURE_ASSISTANT=true (host value file or --set) and rejects any value other than true, false or empty. defaultMode and skipDangerousModePermissionPrompt are unchanged. .gitignore adds .claude/settings.local.json and .claude/worktrees/. Not included, because open PRs #116, #145 and #151 own these files: the manifests/evidence.json re-hash of the 12 changed files, and the adoption/bootstrap.md "changed after `v2026.09.23.1`" marker for the three changed install inputs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Re-hash evidence and mark the Claude Code floor in the bootstrap guide Records the SHA-256/byte entries for every file this branch changes and adds the "changed after `v2026.09.23.1`" note that the docs-consistency test requires for the new install behavior (pins 2.1.281, floor instead of unconditional reinstall). Both files are also edited by open PRs; whichever lands later re-runs the same host_receipts.register_file helper. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Keep a newer native Claude Code on Linux/WSL2: the pin is a floor there too adoption/bootstrap-linux.sh's install_native ran `"$bin" install <pin>` unconditionally, so on a Linux/WSL2 host whose native updater (latest channel) was ahead of the pin, re-running the bootstrap moved Claude Code back to the pin and dropped newer fixes. install_native is now the same function as bootstrap-macos.sh's (#159): a ~/.local/bin/<bin> whose --version first word is a dotted numeric version at or above the pin is kept (nothing downloaded or installed; install_pin logs "Kept installed ..." instead of "Installed ..."); a missing, older, non-numeric or failing launcher takes the unchanged checksum-verified install. Tests: NativeInstallFloorTests in tests/test_adoption_bootstrap.py run the verbatim fetch/install_native/install_pin against a one-pin fixture (curl shimmed; a shasum-backed sha256sum shim only where GNU --check --status is missing), plus an identity check that both scripts share one install_native. Docs: the Linux claude-code install_note describes the floor; bootstrap.md step 2's stale "Linux/WSL2's script and pins are the same at v2026.09.23 as on main" now says what differs at that tag; the claude-code floor notes on bootstrap.md, linux-wsl2.md and macos-arm64.md name the currently pinned release v2026.09.24.1 (#171), which the docs-consistency test requires. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * linux-wsl2.md: keep the changed-after marker on one line (docs-consistency) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Scout <scout@local>
# Conflicts: # manifests/evidence.json
|
Merged current main into this branch (native-agent-stack-9a, foundation PR queue): kept the retained September 23 memory evidence, the lifecycle doc update and the additive memory-scheduled-learning gate row; manifests/evidence.json taken from main and the four changed files re-registered. validate.py passes; grand-dashboard, native-dashboard-data and new-host-grand-list tests: 49 OK. |
The memory lifecycle handbook still described hourly learned writes and a future daily wake as unobserved. Record the actual September 23 native task heartbeat and bounded read-only follow-up. The existing hourly scheduler applied two pages, confirmed independently through its journal, proposal store and native MCP page reads. A later HTTP response-decoding failure has no persisted learning run and remains explicitly unresolved.
Retain sanitized native command/tool returns, genuine completed-session consolidation, exact source agreement for one SocratiCode result and QMD document, and an independent snapshot of the existing monitoring services. Add the dated memory checkpoint to the dashboard and rebuilt HTML handbook. Existing gateway/swap warnings, old token-counter timestamps, unknown restart persistence and absent quality/savings measurements stay visible. No installation, service restart, manual learning run, new monitor or broker action occurred.
Validation: 60 relevant project tests, public integrity/privacy validation and the generated HTML check passed under the host's bounded runner. Independent review caught journal identifiers before publication; the final output uses consistent aliases and retains the initial failed privacy check. These are project publication checks; prior upstream execution evidence is not relabeled as a new run.
Integrated with the latest published catalog layout: generated HTML remains ignored and is rebuilt locally/CI. The current base adds three relevant tests; all 63 passed. Its new sorted-manifest check identified two appended entries, resolved with the repository's supported manifest writer before publication.