Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .agents/checks/attribution-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ set -euo pipefail
check=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)/attribution.sh

readonly owner_name='nothingnesses'
readonly owner_display_name='Jesse Abadilla'
readonly owner_email='18732253+nothingnesses@users.noreply.github.com'

export GIT_CONFIG_GLOBAL=/dev/null
Expand Down Expand Up @@ -117,6 +118,16 @@ add_commit "${repository}" "${owner_name}" "${owner_email}" \
add_commit "${repository}" "${owner_name}" "${owner_email}" 'docs: describe the second change'
expect_pass 'a valid history passes' "${repository}"

repository=$(new_repository display-name-history)
add_commit "${repository}" "${owner_display_name}" "${owner_email}" 'feat: add the first change'
expect_pass 'the owner display name passes' "${repository}"

repository=$(new_repository mixed-owner-history)
add_commit "${repository}" "${owner_name}" "${owner_email}" 'feat: add the first change'
add_commit "${repository}" "${owner_display_name}" "${owner_email}" 'feat: add the second change'
add_commit "${repository}" "${owner_name}" "${owner_email}" 'docs: describe both changes'
expect_pass 'both owner identities pass in one history' "${repository}"

repository=$(new_repository foreign-author)
add_commit "${repository}" "${owner_name}" "${owner_email}" 'feat: add the first change'
add_commit "${repository}" 'Some Agent' 'agent@example.invalid' 'feat: add a foreign change'
Expand All @@ -139,6 +150,27 @@ add_commit "${repository}" "${owner_name}" 'nothingnesses@example.invalid' \
expect_failure 'the owner name under another email fails' "${repository}" \
"$(git -C "${repository}" rev-parse HEAD)" "${foreign_author}"

repository=$(new_repository display-name-another-email)
add_commit "${repository}" "${owner_display_name}" 'nothingnesses@example.invalid' \
'feat: add a rerouted change'
expect_failure 'the owner display name under another email fails' "${repository}" \
"$(git -C "${repository}" rev-parse HEAD)" "${foreign_author}"

for name in 'Nothingnesses' 'jesse abadilla'; do
repository=$(new_repository "case-sensitive-name-${name}")
add_commit "${repository}" "${name}" "${owner_email}" 'feat: add a renamed change'
expect_failure "the name ${name} with different case fails" "${repository}" \
"$(git -C "${repository}" rev-parse HEAD)" "${foreign_author}"
done

for name in "${owner_name}" "${owner_display_name}"; do
repository=$(new_repository "case-sensitive-email-${name}")
add_commit "${repository}" "${name}" '18732253+Nothingnesses@users.noreply.github.com' \
'feat: add a rerouted change'
expect_failure "the name ${name} with a different email case fails" "${repository}" \
"$(git -C "${repository}" rev-parse HEAD)" "${foreign_author}"
done

repository=$(new_repository co-author-trailer)
add_commit "${repository}" "${owner_name}" "${owner_email}" \
$'feat: add a shared change\n\nCo-Authored-By: Some Agent <agent@example.invalid>'
Expand Down
15 changes: 7 additions & 8 deletions .agents/checks/attribution.sh
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
#!/usr/bin/env bash
# The attribution gate. It reads every commit reachable from its target and holds
# two rules the human selected: each commit carries the repository owner's raw
# author identity, and no commit message carries an attribution line.
# This check reads every commit reachable from its target.
# Each commit must carry an approved raw owner identity and no attribution line.
#
# The second rule lives in `.agents/checks/attribution-lines.sh`, which
# `.agents/checks/attribution-metadata.sh` holds over a pull request's title and
Expand All @@ -23,9 +22,9 @@
# the branch commits are what the rules are about.
set -euo pipefail

# The allowlist, as one exact name and one exact email. It takes no environment
# override, so nothing that runs the gate can widen it.
# The human approved both names with the same exact email. No environment override can widen this list.
readonly owner_name='nothingnesses'
readonly owner_display_name='Jesse Abadilla'
readonly owner_email='18732253+nothingnesses@users.noreply.github.com'

repository=${1:-.}
Expand Down Expand Up @@ -63,9 +62,9 @@ scan() {
commit=${lines[0]}
name=${lines[1]}
email=${lines[2]}
if [[ ${name} != "${owner_name}" || ${email} != "${owner_email}" ]]; then
printf 'error: %s: author "%s <%s>" is not the repository owner "%s <%s>"\n' \
"${commit}" "${name}" "${email}" "${owner_name}" "${owner_email}" >&2
if [[ (${name} != "${owner_name}" && ${name} != "${owner_display_name}") || ${email} != "${owner_email}" ]]; then
printf 'error: %s: author "%s <%s>" is not the repository owner (expected "%s" or "%s" with email "%s")\n' \
"${commit}" "${name}" "${email}" "${owner_name}" "${owner_display_name}" "${owner_email}" >&2
failures=$((failures + 1))
fi
# The report names the rule and the commit, never the offending line: the line
Expand Down
58 changes: 39 additions & 19 deletions .agents/work.toml
Original file line number Diff line number Diff line change
@@ -1,26 +1,46 @@
version = 1
selected_action = "preserve-post-reset-context"
selected_action = "accept-github-owner-name"

[[step]]
id = "preserve-post-reset-context"
status = "active"
status = "complete"
blocked_by = []
user_problem = """
The reviewed 114-decision report did not reach main. Later research and library-trial conclusions remain outside normal repository discovery. A new session can miss retained decisions or mistake proposals for approved work.
"""
change = """
Preserve the exact reviewed revalidation report and add one concise, sanitised report about the alternatives research and library trial. Include a separately dated OpenShell assessment and the related VeriGuard paper. Record formal methods for deterministic checks as a retained preference, without a dependency or implementation choice. Add README links to the reports.
"""
user_problem = "The reviewed decisions and later research lacked reliable repository discovery."
change = "Preserved the decision report and a sanitised research report through PR #9, with README links."
acceptance = [
"The original approved criteria remain at 1ab27cf53fe8c8421362b04ae7b5af263978974c:.agents/work.toml.",
]
why_next = "The human marked this delivery complete after the merge. This compact entry retains that outcome."

[[step]]
id = "accept-github-owner-name"
status = "active"
blocked_by = ["preserve-post-reset-context"]
user_problem = "GitHub used the owner's public display name for a squash commit. The exact-name check rejects that identity and blocks main CI."
change = "Accept the two approved owner names with the existing exact email. Add regression tests without other attribution policy changes."
acceptance = [
"Exactly nothingnesses or Jesse Abadilla passes with 18732253+nothingnesses@users.noreply.github.com. Other name and email combinations fail.",
"Regression tests exercise both allowed identities and incorrect combinations.",
"Complete-history checks and the shallow-history and raw-identity safeguards remain intact.",
"Commit-message and pull-request attribution prohibitions remain unchanged.",
"Existing commits and remote settings remain unchanged. Local commits retain the configured nothingnesses identity.",
"Focused tests and host just ci pass. An independent reviewer examines the complete diff against these criteria.",
]
why_next = "The human selected this CI repair before adoption and approved at most five worker dispatches, including failures. Publication and completion require separate direction."

[[step]]
id = "document-existing-project-adoption"
status = "pending"
blocked_by = ["accept-github-owner-name"]
user_problem = "Existing projects lack a tested adoption walkthrough. The README mixes onboarding with lengthy reference material. Agents lack a bounded adoption prompt."
change = "Add an adoption guide and shipped user prompt. Shorten the README and relocate useful reference material. Keep runtime behaviour unchanged."
acceptance = [
"The revalidation report is byte-identical to a64d6c27a2171b5fe311f7ab05f1d8cbe8aeff2d:docs/audits/2026-09-09-historical-decision-revalidation.md.",
"The new report preserves the twelve-source study boundary, checker qualifications, library outcomes, failed verdicts and complete worker accounting.",
"The OpenShell assessment distinguishes current permission-risk checks from the containment spike, and states empirical and model limits.",
"The VeriGuard reference distinguishes verified policy code from generated specifications, runtime argument extraction and actual enforcement.",
"Retained directions, unresolved proposals and evidence remain distinct. No adoption, implemented guarantee or new execution authority is inferred.",
"The report uses source references and states its conclusions without dependence on ignored scratch. No raw sessions or private execution evidence enter Git.",
"Changes remain limited to the work brief, README links and the two reports. Existing report bytes and all product code remain unchanged.",
"The host just ci checks pass, and an independent reviewer examines the complete documentation diff against these criteria.",
"The README provides a concise introduction, accurate installation guidance and links to adoption and reference pages.",
"The guide identifies its tested version and preserves existing project guidance, plans and checks.",
"The prompt asks about unresolved authority and conflicts before edits, imports only agreed current work, validates the result and requests human review.",
"Adoption creates no automatic implementation, commit, publication, hook installation or legacy plan conversion.",
"The prompt is discoverable before adoption, ships through the default pack and satisfies scaffold limits and repeat-run tests.",
"Focused tests and a disposable-repository rehearsal exercise adoption commands and preservation of existing project files.",
"Runtime commands, existing delivery-role contracts, audit reports and released history remain unchanged. Host just ci and independent review cover the candidate.",
]
why_next = """
The human approved local preservation before further design work, with at most five worker dispatches. The sequence permits an author, independent review and conditional triage, one scoped fix and focused verification. Failed launches count. Publication, merge, task completion and private backup require separate direction.
"""
why_next = "The human approved this onboarding change with at most five worker dispatches, including failures. Use one author, independent review and conditional triage, one fix and focused verification. Stop before publication or completion."
Loading