mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-16 01:45:29 +02:00
* feat: add a restricted and supervised Claude Code runner Preserve configured authentication and models while enforcing tool access, strict completion JSON, bounded output and process cleanup. Cover argv, failure handling, session metadata and Windows process containment. * feat: route outside reviews by harness and migrate wrapper installs Use Claude Code from Codex and Codex from other supported hosts, with shared invocation rendering, positive gate validation and per-phase provenance. Rename /claude to /claude-code, repair managed shared and copied installations safely, and generate native Kiro skills. Add installed-workflow, failure-injection and live cross-harness regression coverage. * test: recognize CEO mode labels without terminal spacing The paid workflow rendered SCOPEEXPANSION at option 4, but its driver required a literal space. Match the leading mode title without cursor-spacing artifacts and ignore adjacent preview text. Preserve missing-target failures and downstream posture assertions. * test: isolate plan-count fixtures before starting review workflows Seed the complete test plan in a private git repository before launching Claude, so a bare slash command cannot review the live workspace while a delayed fixture message remains queued. Preserve count thresholds, parsers and budgets. Add initial-context and installed-discovery tests, and retain startup/terminal diagnostics on failed evaluations. * test: stabilize review fixtures and Claude eval startup Preserve source boundaries in workflow judge inputs, isolate CEO mode plans, and wait for interactive trust input readiness. Keep startup failure evidence and retain existing models, budgets, and assertions. Co-Authored-By: OpenAI Codex <noreply@openai.com> * test: classify collapsed review modes and isolate seeded findings Keep review questions out of the setup count when terminal cursor positioning removes spaces. State existing webhook safeguards so the five-finding control measures its seeded defects without accidental extra security and concurrency gaps. Preserve question bands and the paired control. Co-Authored-By: OpenAI Codex <noreply@openai.com> * test: isolate browser daemon state across free shards Co-Authored-By: OpenAI Codex <noreply@openai.com> * test: stabilize native review counting and interactive navigation Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: prepare v1.82.0.0 release Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix: eliminate browser and process-cleanup test flakes Pin every CI surface to Bun 1.4.0 to avoid extra-stdio finalizers closing reused live sockets. Add an isolated GC/listener regression that fails on Bun 1.3.13, and prevent coordinated rollback to an affected CI runtime. Check renderer cleanup against the render's own staging directory so concurrent renders cannot invalidate the assertion. Make the no-pgrep process-tree walk tolerate disappearing /proc entries, and synchronize its test fixture through child readiness and pipe EOF instead of sleeps. Validation: 9,157 passed, 31 skipped, zero failures across 556 files with retries disabled. Build, all-host generation freshness, and skill checks passed. All three races have failing-before/passing-after regressions. * fix: count completed native review questions in evals * fix: drive review navigation from confirmed native choices * fix: require complete section-loading eval reports * test: isolate telemetry HTTP transport from local assertions * fix: keep review input on the active native question * test: let tunnel revocation daemon choose an available port * test: allocate available ports for pairing and watchdog fixtures * fix: stabilize planning eval navigation and phase reporting * test: isolate installed runtime paths in planning evals * test: stabilize review evidence and concurrent refresh fixtures * fix: resolve design findings before editing the plan * fix: honor and persist disabled outside plan reviews * fix: preserve planning decisions and terminal evidence Load installed host reviews at autoplan phase entry and wait for completed reviewers and saved artifacts. Reuse approved remedies while preserving individual finding decisions. Drive interactive evals from the current terminal viewport, bind native questions across scrolling, and require complete native report evidence. Cover captured stale menus, permission lifecycles, setup classification, and disabled-review tool availability with deterministic regressions. Advance release metadata and the upgrade migration to the unclaimed 1.83.0.0 slot. * fix: drive native review questions and preserve current plans Use the native single-choice keyboard protocol and current terminal viewport, with per-question navigation inside packets and completed-call coverage. Keep permissions, multi-select menus, and Submit controls distinct. Send Autoplan reviewers the amended implementation plan, keep its review record separate, and supply retained application contracts in the chain fixture. Clarify individual DevEx decisions and complete CEO fix options; use one active plan destination for the section-loading report. * fix: preserve complete plan-review decisions * fix: recognize native plan dialogs and reviewer controls * fix: preserve review decisions and phase completion * fix: recognize completed reviews without losing findings * fix: preserve review continuity and native eval completion * test: fix native review completion and eval retry isolation * test: handle native review menus and complete eval fixtures * test: fix native review setup, completion, and isolation failures * test: limit native skill discovery to runtime assets * fix: bind Autoplan reviews to full ordered phase inputs * test: fix planning eval routing, counting, and timeout handling * chore: advance queued release to v1.84.0.0 * fix: preserve complete review inputs and planning decisions * fix: reconcile review approvals and preserve phase obligations * fix: preserve review obligations and unblock eval permissions Carry recorded Autoplan requirements into blind phase inputs, require Eng review approvals before exit, and exercise combined asynchronous flows in CEO reviews. Correct native finding and handoff classification and unblock repeated report edits using scoped request identities. * fix: retain plan requirements and complete native review dialogs * fix: complete native review prompts and retain plan references * fix: preserve review inputs and classify native eval evidence * fix: check competing completion orders in CEO reviews * fix: recognize review decisions and require phase methodology Require the current phase methodology before Autoplan snapshots. Correct substantive decision, closed handoff, and cache-finding classification, and honor the recommended implementation approach in native review dialogs. Add captured-transcript regressions without changing review thresholds, provider models, retries, or deadlines. * test: bind native review decisions and close completed handoffs * fix: complete review dialogs and verify methodology delivery * fix: preserve review evidence and unblock native eval prompts * fix: handle native review question completions * fix: recognize native review narration and controls * fix: count native review decisions and isolate eval fixtures * test: verify seeded review coverage and current artifact permissions * test: isolate model and brain-aware skill renders * fix: repair native workflow evaluation and clarify review steps * fix: stabilize workflow eval evidence and review guidance * test: repair native workflow observation and fixture isolation * fix: recognize completed workflow evidence and owned skill reads * test: repair seeded workflow delivery and completion evidence * test: recognize current review evidence across native forms * test: handle native review variants and permission redraws * fix: honor review preferences and recognize native eval evidence * test: recognize completed review decisions and queued permissions * test: match current review contracts and partial-line edits * test: recognize completed workflow evidence and bounded human waits * fix: preserve review entry gates and native eval interactions * fix: recognize native workflow evidence and preserve review gates * test: recognize current review evidence and preconfigure workflow fixtures * test: recognize completed review findings and scoped artifact permissions * fix: stabilize native workflow review and permission evidence * fix: recognize current review evidence and scoped edit confirmations Clarify Design and engineering review entry instructions and Design scoring. Recognize required legacy coverage and public Autoplan completion recaps. Bind the pending Edit confirmation to its exact file, ordered digest, and one-request approval when a preceding command display remains visible. Keep reviews within their existing size limits and preserve scope gates when extracting workflow fixtures from either supported preamble header. Keep failure outcomes, review thresholds, provider choices, and eval budgets. * fix: recover review workflow progress and eval evidence * fix: recognize valid review evidence and scope selection * test: fix review evidence parsing and repeated artifact prompts * test: recognize valid review decisions and pending native cards * fix(plan-eng-review): keep final navigation consistent with approved tasks * test: recognize valid review evidence and bind legacy diff requests * fix: stabilize review eval evidence and harness repair guidance * docs: update project documentation for v1.85.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * test: fix Windows CI fixtures and credential scan Rebase captured JSON values and filesystem evidence using the appropriate path convention. Compile native fake CLIs on Windows and synchronize pipe holder readiness, with cleanup retained when assertions fail. Assemble synthetic credential fixtures at runtime so the added-line scan keeps enforcing the same gate without flagging its own rejection controls. Discover generated skills directly for the empty-find regression check, avoiding a recursive scan through saved evaluation artifacts and dependencies. * fix: preserve source renders on Windows Compare canonical generator paths using native separators so an output sidecar pointing at the source cannot overwrite its skill or metadata. Keep the regression fixture isolated from the real checkout and expose freshness diagnostics before asserting subprocess status. Detach Windows drain-test pipe holders from the fake provider's automatic child cleanup while preserving the enclosing runner job and its assertions. * fix: clarify outside review fallback and CEO decisions Render one applicable own-harness fallback path and retain native review, disabled policy, and missing-coverage semantics. Align report field names and mode labels, and make the existing per-cut scope approval explicit. Regenerate skill outputs and keep the workflow judge's model, thresholds, and retry policy unchanged. * chore: move release to free version slot (v1.86.0.0) PR #2852 now claims v1.85.0.0. Align the release metadata and rename migration so upgrades from that version still receive it. Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix: include engineering review prerequisites and restore branch context * fix: recognize coverage diagrams and clarify design review instructions * fix: preserve file identities and join Windows test processes --------- Co-authored-by: OpenAI Codex <noreply@openai.com>
628 lines
35 KiB
Bash
Executable File
628 lines
35 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# gstack-config — read/write ~/.gstack/config.yaml
|
|
#
|
|
# Usage:
|
|
# gstack-config get <key> — read a config value (falls back to DEFAULTS)
|
|
# gstack-config has <key> — exit 0 iff the key is literally present in the
|
|
# config file (get returns DEFAULTS for absent keys,
|
|
# so callers that need provenance use this instead)
|
|
# gstack-config set <key> <value> — write a config value
|
|
# gstack-config list — show all config (values + defaults)
|
|
# gstack-config defaults — show just the defaults table
|
|
#
|
|
# Env overrides (for testing):
|
|
# GSTACK_STATE_ROOT — override ~/.gstack state directory (highest priority,
|
|
# matches D16 cathedral isolation convention)
|
|
# GSTACK_HOME — override ~/.gstack state directory (aligns with writer scripts)
|
|
# GSTACK_STATE_DIR — legacy alias for GSTACK_HOME (kept for backwards compat)
|
|
set -euo pipefail
|
|
|
|
STATE_DIR="${GSTACK_STATE_ROOT:-${GSTACK_HOME:-${GSTACK_STATE_DIR:-$HOME/.gstack}}}"
|
|
CONFIG_FILE="$STATE_DIR/config.yaml"
|
|
|
|
# Swap a freshly-rendered tmp dir into the live render location (#2569
|
|
# hardening). Installed skills SYMLINK into the live dir, so it is only ever
|
|
# replaced AFTER a successful render — a failed render leaves the previous
|
|
# render (and every link into it) fully intact. Keep in sync with setup's
|
|
# _swap_in_render (same contract, both pinned by
|
|
# test/user-render-out-dir-install.test.ts).
|
|
_swap_in_render() {
|
|
local render_dir="$1" render_tmp="$2"
|
|
local render_old="$render_dir.old.$$"
|
|
rm -rf "$render_old"
|
|
if [ -e "$render_dir" ] || [ -L "$render_dir" ]; then mv "$render_dir" "$render_old"; fi
|
|
mv "$render_tmp" "$render_dir"
|
|
rm -rf "$render_old"
|
|
}
|
|
|
|
# Annotated header for new config files. Written once on first `set`.
|
|
# Default semantics: DEFAULTS table below is the canonical source. Header text
|
|
# is documentation that must stay in sync with DEFAULTS.
|
|
CONFIG_HEADER='# gstack configuration — edit freely, changes take effect on next skill run.
|
|
# Docs: https://github.com/garrytan/gstack
|
|
#
|
|
# ─── Behavior ────────────────────────────────────────────────────────
|
|
# proactive: true # Auto-invoke skills when your request matches one.
|
|
# # Set to false to only run skills you type explicitly.
|
|
#
|
|
# routing_declined: false # Set to true to skip the CLAUDE.md routing injection
|
|
# # prompt. Set back to false to be asked again.
|
|
#
|
|
# ─── Telemetry ───────────────────────────────────────────────────────
|
|
# telemetry: off # off | anonymous | community
|
|
# # off — no data sent, no local analytics (default)
|
|
# # anonymous — counter only, no device ID
|
|
# # community — usage data + stable device ID
|
|
#
|
|
# ─── Updates ─────────────────────────────────────────────────────────
|
|
# auto_upgrade: false # true = silently upgrade on session start
|
|
# update_check: true # false = suppress version check notifications
|
|
#
|
|
# ─── Skill naming ────────────────────────────────────────────────────
|
|
# skill_prefix: false # true = namespace skills as /gstack-qa, /gstack-ship
|
|
# # false = short names /qa, /ship
|
|
#
|
|
# ─── Checkpoint ──────────────────────────────────────────────────────
|
|
# checkpoint_mode: explicit # explicit | continuous
|
|
# # explicit — commit only when you run /ship or /checkpoint
|
|
# # continuous — auto-commit after each significant change
|
|
# # with WIP: prefix + [gstack-context] body
|
|
#
|
|
# checkpoint_push: false # true = push WIP commits to remote as you go
|
|
# # false = keep WIP commits local only (default)
|
|
# # Pushing can trigger CI/deploy hooks — opt in carefully.
|
|
#
|
|
# ─── Writing style (V1) ──────────────────────────────────────────────
|
|
# explain_level: default # default = jargon-glossed, outcome-framed prose
|
|
# # (V1 default — more accessible for everyone)
|
|
# # terse = V0 prose style, no glosses, no outcome-framing layer
|
|
# # (for power users who know the terms)
|
|
# # Unknown values default to "default" with a warning.
|
|
# # See docs/designs/PLAN_TUNING_V1.md for rationale.
|
|
#
|
|
# ─── Artifacts sync (renamed from gbrain_sync_mode in v1.27.0.0) ─────
|
|
# artifacts_sync_mode: off # off | artifacts-only | full
|
|
# # off — no sync (default)
|
|
# # artifacts-only — sync plans/designs/retros/learnings only
|
|
# # (skip behavioral data: question-log,
|
|
# # developer-profile, timeline)
|
|
# # full — sync everything allowlisted
|
|
# # Set by the first-run privacy stop-gate. See docs/gbrain-sync.md.
|
|
#
|
|
# artifacts_sync_mode_prompted: false
|
|
# # Set to true once the privacy gate has asked the user.
|
|
# # Flip back to false to be re-prompted.
|
|
#
|
|
# ─── Timeline Stop hook ──────────────────────────────────────────────
|
|
# timeline_stop_hook: yes # Controls whether ./setup registers the timeline
|
|
# # Stop hook (closes dangling session entries).
|
|
# # yes — register on every setup (default)
|
|
# # no — never register; setup also removes a
|
|
# # live registration (persistent opt-out;
|
|
# # --no-team stays a one-shot teardown, #2677)
|
|
#
|
|
# ─── Plan-tune hooks ─────────────────────────────────────────────────
|
|
# plan_tune_hooks: prompt # Controls whether ./setup installs the plan-tune
|
|
# # Claude Code hooks (PostToolUse capture +
|
|
# # PreToolUse preference enforcement).
|
|
# # prompt — ask on a real TTY, skip otherwise (default)
|
|
# # yes — install non-interactively
|
|
# # no — skip non-interactively
|
|
# # Override per-run: ./setup --plan-tune-hooks /
|
|
# # --no-plan-tune-hooks, or env GSTACK_PLAN_TUNE_HOOKS.
|
|
#
|
|
# ─── Memorable recall bridge (opt-in, third party) ──────────────────
|
|
# memorable_recall: off # The gstack-side consent gate for the Memorable
|
|
# # UserPromptSubmit bridge (bin/gstack-memorable).
|
|
# # off — the hook does nothing, spawns nothing (default)
|
|
# # on — the hook hands each prompt to the local
|
|
# # `memorable` CLI, receipted as memorable-recall
|
|
# # Written by `gstack-memorable enable|disable`. An
|
|
# # invalid value is REJECTED and the stored value kept:
|
|
# # a typo must never flip a third-party consent.
|
|
# # The vendor capture consent (`memorable enable`)
|
|
# # is separate; gstack never sets it.
|
|
#
|
|
# ─── Advanced ────────────────────────────────────────────────────────
|
|
# codex_reviews: enabled # Workflow outside review (Codex or Claude Code by harness).
|
|
# # enabled: /review, /ship, /document-release, plan reviews,
|
|
# # and /autoplan use their existing external + fallback rules.
|
|
# # disabled: /review, /ship, /autoplan keep native passes;
|
|
# # plan/document reviews skip the entire extra review step.
|
|
# # Office hours/design/spec/manual wrappers keep their own
|
|
# # opt-in/skip controls. Invalid values preserve the old value.
|
|
# design_detector_install_prompted: false
|
|
# # true once you answered the one-time offer from the
|
|
# # design skills to download the impeccable engine with
|
|
# # "never ask again"; flip back to false to be asked again.
|
|
# design_detector: auto # Deterministic design pre-pass through a user-installed
|
|
# # impeccable engine (/design-review, /review, /ship,
|
|
# # /design-html). auto = use the engine when the probe
|
|
# # finds one (gstack never installs or downloads it);
|
|
# # off = no probe, no scan, no hint, no /impeccable
|
|
# # handoff lines. An invalid value is REJECTED (existing
|
|
# # value preserved) so a typo cannot silently disable it.
|
|
# gstack_contributor: false # true = file field reports when gstack misbehaves
|
|
# skip_eng_review: false # true = skip eng review gate in /ship (not recommended)
|
|
#
|
|
# ─── Workspace-aware ship ────────────────────────────────────────────
|
|
# workspace_root: $HOME/conductor/workspaces # Where /ship looks for sibling
|
|
# # Conductor worktrees when picking a VERSION slot.
|
|
# # Set to "null" to disable sibling scanning entirely.
|
|
# # Non-Conductor users can point this at any directory
|
|
# # that holds parallel worktrees of the same repo.
|
|
#
|
|
'
|
|
|
|
# DEFAULTS table — canonical default values for known keys.
|
|
# `get <key>` returns DEFAULTS[key] when the key is absent from the config file
|
|
# AND the env override is not set. Keep in sync with the CONFIG_HEADER comments.
|
|
lookup_default() {
|
|
case "$1" in
|
|
proactive) echo "true" ;;
|
|
routing_declined) echo "false" ;;
|
|
telemetry) echo "off" ;;
|
|
auto_upgrade) echo "false" ;;
|
|
update_check) echo "true" ;;
|
|
skill_prefix) echo "false" ;;
|
|
checkpoint_mode) echo "explicit" ;;
|
|
checkpoint_push) echo "false" ;;
|
|
explain_level) echo "default" ;;
|
|
codex_reviews) echo "enabled" ;;
|
|
design_detector) echo "auto" ;; # auto | off — impeccable engine pre-pass in the design skills
|
|
design_detector_install_prompted) echo "false" ;; # true once the user answered the one-time engine install offer with "never ask again"
|
|
gstack_contributor) echo "false" ;;
|
|
skip_eng_review) echo "false" ;;
|
|
workspace_root) echo "$HOME/conductor/workspaces" ;;
|
|
cross_project_learnings) echo "" ;; # intentionally empty → unset triggers first-time prompt
|
|
artifacts_sync_mode) echo "off" ;;
|
|
artifacts_sync_mode_prompted) echo "false" ;;
|
|
plan_tune_hooks) echo "prompt" ;; # prompt | yes | no — controls ./setup plan-tune hook install
|
|
timeline_stop_hook) echo "yes" ;; # yes | no — controls ./setup timeline Stop hook registration (#2677)
|
|
|
|
redact_repo_visibility) echo "" ;; # empty → fall through to gh/glab detection
|
|
redact_prepush_hook) echo "false" ;;
|
|
pair_agent) echo "off" ;; # remote tunnel consent — fail-closed until /pair-agent asks
|
|
memorable_recall) echo "off" ;; # on | off — Memorable bridge gate, fail-closed until `gstack-memorable enable`
|
|
founder_resources) echo "true" ;; # office-hours resource pitch — #538 permanent opt-out sets false
|
|
# Brain-aware planning (v1.48 / T5+T10+T16). Defaults documented inline:
|
|
# brain_trust_policy@<endpoint-id> — unset on fresh install; setup-gbrain
|
|
# writes 'personal' for local engines,
|
|
# asks the user for remote-ambiguous.
|
|
# salience_allowlist — empty falls through to
|
|
# SALIENCE_DEFAULT_ALLOWLIST (D9).
|
|
# user_slug_at_<endpoint-id> — empty triggers resolve-user-slug
|
|
# fallback chain (D4 A3) on first call.
|
|
brain_trust_policy*) echo "unset" ;;
|
|
salience_allowlist) echo "" ;;
|
|
user_slug_at_*) echo "" ;;
|
|
# Read by skill preambles but missing from this table, so they fell through
|
|
# to the catch-all and came back "" with exit 0. Values below are the ones
|
|
# the callers already assume in their own `|| echo "<default>"` fallback.
|
|
question_tuning) echo "false" ;;
|
|
team_mode) echo "false" ;;
|
|
transcript_ingest_mode) echo "off" ;;
|
|
# repo_mode: EMPTY is load-bearing — gstack-repo-mode treats any non-empty
|
|
# answer as a user override and skips its own classification entirely, so
|
|
# a synthesized "unknown" default turns the classifier into dead code.
|
|
# Empty + exit 0 = "no override set, go classify".
|
|
repo_mode) echo "" ;;
|
|
# Unknown key: exit non-zero instead of printing "". The fallback pattern
|
|
# the preambles use,
|
|
# VAR=$(gstack-config get <key> 2>/dev/null || echo "<default>")
|
|
# only fires on a non-zero exit, so a catch-all echoing "" with exit 0 left
|
|
# VAR empty and the written default unreachable.
|
|
# Deliberately *only* the unknown-key path: the keys above whose default is
|
|
# intentionally empty (cross_project_learnings, salience_allowlist,
|
|
# user_slug_at_*, redact_repo_visibility) keep exit 0, because "" is their
|
|
# real answer and their callers rely on it.
|
|
*) return 1 ;;
|
|
esac
|
|
}
|
|
|
|
# ──────────────────────────────────────────────────────────────────────
|
|
# Brain-integration helpers (T5+T10+T16)
|
|
# ──────────────────────────────────────────────────────────────────────
|
|
|
|
# Compute sha8 of a string. Used for endpoint hashing.
|
|
# shasum is macOS/perl; most Linux distros ship only coreutils sha256sum —
|
|
# resolve whichever exists (same fallback chain as the codex-probe timeout
|
|
# wrapper). Without this, any Linux user with a git email hit exit 127 in
|
|
# resolve-user-slug's Layer-3 fallback.
|
|
sha8_of() {
|
|
if command -v sha256sum >/dev/null 2>&1; then
|
|
printf '%s' "$1" | sha256sum | cut -c1-8
|
|
else
|
|
printf '%s' "$1" | shasum -a 256 | cut -c1-8
|
|
fi
|
|
}
|
|
|
|
# Detect the active brain endpoint hash. Reads ~/.claude.json for the gbrain
|
|
# MCP server URL. Falls back to the literal 'local' when no MCP is configured.
|
|
endpoint_hash() {
|
|
_claude_json="$HOME/.claude.json"
|
|
if [ -f "$_claude_json" ] && command -v jq >/dev/null 2>&1; then
|
|
_url=$(jq -r '.mcpServers.gbrain.url // .mcpServers.gbrain.transport.url // empty' "$_claude_json" 2>/dev/null)
|
|
if [ -n "$_url" ] && [ "$_url" != "null" ]; then
|
|
sha8_of "$_url"
|
|
return 0
|
|
fi
|
|
fi
|
|
printf '%s' "local"
|
|
}
|
|
|
|
# Detect endpoint hash collisions. When two distinct endpoints share the same
|
|
# sha8 prefix (rare but possible), escalate to sha16 by emitting the longer
|
|
# hash. Detection: scan config file for existing brain_trust_policy@<hash> or
|
|
# user_slug_at_<hash> keys; if any non-active hash equals the active sha8 but
|
|
# would differ at sha16, the active endpoint needs sha16.
|
|
endpoint_hash_with_collision_check() {
|
|
_active=$(endpoint_hash)
|
|
if [ "$_active" = "local" ]; then
|
|
printf '%s' "$_active"
|
|
return 0
|
|
fi
|
|
# If a different endpoint (different URL) shares this sha8, escalate.
|
|
# We only catch this when the config has another endpoint recorded.
|
|
_matching=$(grep -E "^(brain_trust_policy|user_slug_at)@${_active}" "$CONFIG_FILE" 2>/dev/null | head -1 || true)
|
|
_claude_json="$HOME/.claude.json"
|
|
if [ -n "$_matching" ] && [ -f "$_claude_json" ] && command -v jq >/dev/null 2>&1; then
|
|
_url=$(jq -r '.mcpServers.gbrain.url // .mcpServers.gbrain.transport.url // empty' "$_claude_json" 2>/dev/null)
|
|
if command -v sha256sum >/dev/null 2>&1; then
|
|
_sha16=$(printf '%s' "$_url" | sha256sum | cut -c1-16)
|
|
else
|
|
_sha16=$(printf '%s' "$_url" | shasum -a 256 | cut -c1-16)
|
|
fi
|
|
# Look for any sha16-namespaced key that conflicts. If a stored sha16 exists
|
|
# and differs from current sha16, that's the collision evidence; emit sha16.
|
|
_stored16=$(grep -E "^(brain_trust_policy|user_slug_at)@${_sha16}" "$CONFIG_FILE" 2>/dev/null | head -1 || true)
|
|
if [ -n "$_stored16" ]; then
|
|
printf '%s' "$_sha16"
|
|
return 0
|
|
fi
|
|
fi
|
|
printf '%s' "$_active"
|
|
}
|
|
|
|
# Resolve the user-slug per D4 A3 chain:
|
|
# 1. mcp__gbrain__whoami.client_name (best effort via gbrain CLI shell-out)
|
|
# 2. $USER env
|
|
# 3. sha8($(git config user.email))
|
|
# 4. anonymous-<sha8(hostname)>
|
|
# Persists result via gstack-config set user_slug_at_<endpoint-hash> on first call.
|
|
resolve_user_slug() {
|
|
_hash=$(endpoint_hash_with_collision_check)
|
|
_stored=$(grep -E "^user_slug_at_${_hash}:" "$CONFIG_FILE" 2>/dev/null | tail -1 | awk '{print $2}' | tr -d '[:space:]' || true)
|
|
if [ -n "$_stored" ]; then
|
|
printf '%s' "$_stored"
|
|
return 0
|
|
fi
|
|
|
|
_slug=""
|
|
|
|
# Layer 1: gbrain whoami
|
|
if command -v gbrain >/dev/null 2>&1; then
|
|
_whoami=$(gbrain whoami --json 2>/dev/null || true)
|
|
if [ -n "$_whoami" ] && command -v jq >/dev/null 2>&1; then
|
|
_client_name=$(printf '%s' "$_whoami" | jq -r '.client_name // .token_name // empty' 2>/dev/null || true)
|
|
if [ -n "$_client_name" ] && [ "$_client_name" != "null" ]; then
|
|
_slug=$(printf '%s' "$_client_name" | tr '[:upper:] ' '[:lower:]-' | tr -dc '[:alnum:]-')
|
|
fi
|
|
fi
|
|
fi
|
|
|
|
# Layer 2: $USER
|
|
if [ -z "$_slug" ] && [ -n "${USER:-}" ]; then
|
|
_slug=$(printf '%s' "$USER" | tr '[:upper:] ' '[:lower:]-' | tr -dc '[:alnum:]-')
|
|
fi
|
|
|
|
# Layer 3: sha8 of git email
|
|
if [ -z "$_slug" ]; then
|
|
_email=$(git config user.email 2>/dev/null || true)
|
|
if [ -n "$_email" ]; then
|
|
_slug="email-$(sha8_of "$_email")"
|
|
fi
|
|
fi
|
|
|
|
# Layer 4: anonymous-<sha8(hostname)>
|
|
if [ -z "$_slug" ]; then
|
|
_slug="anonymous-$(sha8_of "$(hostname 2>/dev/null || echo unknown)")"
|
|
fi
|
|
|
|
# Persist via direct file write (avoid recursion into gstack-config set)
|
|
mkdir -p "$STATE_DIR"
|
|
if [ ! -f "$CONFIG_FILE" ]; then
|
|
printf '%s' "$CONFIG_HEADER" > "$CONFIG_FILE"
|
|
fi
|
|
if ! grep -qE "^user_slug_at_${_hash}:" "$CONFIG_FILE" 2>/dev/null; then
|
|
echo "user_slug_at_${_hash}: ${_slug}" >> "$CONFIG_FILE"
|
|
fi
|
|
|
|
printf '%s' "$_slug"
|
|
}
|
|
|
|
read_config_value() {
|
|
local key="$1"
|
|
if [ ! -f "$CONFIG_FILE" ]; then
|
|
return 0
|
|
fi
|
|
grep -E "^${key}:" "$CONFIG_FILE" 2>/dev/null \
|
|
| tail -1 \
|
|
| sed -E "s/^${key}:[[:space:]]*//; s/[[:space:]]+$//"
|
|
}
|
|
|
|
case "${1:-}" in
|
|
get)
|
|
KEY="${2:?Usage: gstack-config get <key>}"
|
|
# Validate key (alphanumeric + underscore + optional @<endpoint-id> suffix for
|
|
# endpoint-namespaced keys introduced by the brain-aware planning layer).
|
|
# Endpoint ids are sha8/sha16 hex for remote MCP URLs, or the literal
|
|
# "local" for stdio/PGLite engines (see endpoint_hash).
|
|
if ! printf '%s' "$KEY" | LC_ALL=C grep -qE '^[a-zA-Z0-9_]+(@[a-zA-Z0-9]+)?$'; then
|
|
echo "Error: key must contain only alphanumeric characters, underscores, and an optional @<endpoint-id> suffix" >&2
|
|
exit 1
|
|
fi
|
|
VALUE=$(read_config_value "$KEY" || true)
|
|
if [ -z "$VALUE" ]; then
|
|
# lookup_default exits non-zero for a key it does not know. Propagate
|
|
# that, so the caller's `|| echo "<default>"` can fire. A known key whose
|
|
# default is empty still exits 0 and prints "".
|
|
if ! VALUE=$(lookup_default "$KEY"); then
|
|
exit 1
|
|
fi
|
|
fi
|
|
printf '%s' "$VALUE"
|
|
;;
|
|
has)
|
|
KEY="${2:?Usage: gstack-config has <key>}"
|
|
if ! printf '%s' "$KEY" | LC_ALL=C grep -qE '^[a-zA-Z0-9_]+(@[a-zA-Z0-9]+)?$'; then
|
|
echo "Error: key must contain only alphanumeric characters, underscores, and an optional @<endpoint-id> suffix" >&2
|
|
exit 1
|
|
fi
|
|
grep -qE "^${KEY}:" "$CONFIG_FILE" 2>/dev/null
|
|
;;
|
|
set)
|
|
KEY="${2:?Usage: gstack-config set <key> <value>}"
|
|
VALUE="${3:?Usage: gstack-config set <key> <value>}"
|
|
# Validate key (alphanumeric + underscore + optional @<endpoint-id> suffix).
|
|
# Accepts hex hashes and the literal "local" from endpoint_hash.
|
|
if ! printf '%s' "$KEY" | LC_ALL=C grep -qE '^[a-zA-Z0-9_]+(@[a-zA-Z0-9]+)?$'; then
|
|
echo "Error: key must contain only alphanumeric characters, underscores, and an optional @<endpoint-id> suffix" >&2
|
|
exit 1
|
|
fi
|
|
# Validate brain_trust_policy value domain (D4 / D11)
|
|
if printf '%s' "$KEY" | grep -qE '^brain_trust_policy(@|$)' && \
|
|
[ "$VALUE" != "personal" ] && [ "$VALUE" != "shared" ] && [ "$VALUE" != "unset" ]; then
|
|
echo "Warning: brain_trust_policy '$VALUE' not recognized. Valid values: personal, shared, unset. Using unset." >&2
|
|
VALUE="unset"
|
|
fi
|
|
# V1: whitelist values for keys with closed value domains. Unknown values warn + default.
|
|
if [ "$KEY" = "explain_level" ] && [ "$VALUE" != "default" ] && [ "$VALUE" != "terse" ]; then
|
|
echo "Warning: explain_level '$VALUE' not recognized. Valid values: default, terse. Using default." >&2
|
|
VALUE="default"
|
|
fi
|
|
if [ "$KEY" = "artifacts_sync_mode" ] && [ "$VALUE" != "off" ] && [ "$VALUE" != "artifacts-only" ] && [ "$VALUE" != "full" ]; then
|
|
echo "Warning: artifacts_sync_mode '$VALUE' not recognized. Valid values: off, artifacts-only, full. Using off." >&2
|
|
VALUE="off"
|
|
fi
|
|
# redact_repo_visibility: a LOCAL override for repos gh/glab can't read (e.g.
|
|
# self-hosted GitLab). It lives in ~/.gstack/config.yaml (never committed), so
|
|
# it can't be used to weaken the gate repo-wide for other contributors.
|
|
if [ "$KEY" = "redact_repo_visibility" ] && [ "$VALUE" != "public" ] && [ "$VALUE" != "private" ] && [ "$VALUE" != "unknown" ]; then
|
|
echo "Warning: redact_repo_visibility '$VALUE' not recognized. Valid values: public, private, unknown. Using unknown." >&2
|
|
VALUE="unknown"
|
|
fi
|
|
if [ "$KEY" = "redact_prepush_hook" ] && [ "$VALUE" != "true" ] && [ "$VALUE" != "false" ]; then
|
|
echo "Warning: redact_prepush_hook '$VALUE' not recognized. Valid values: true, false. Using false." >&2
|
|
VALUE="false"
|
|
fi
|
|
if [ "$KEY" = "pair_agent" ] && [ "$VALUE" != "on" ] && [ "$VALUE" != "off" ]; then
|
|
echo "Warning: pair_agent '$VALUE' not recognized. Valid values: on, off. Using off." >&2
|
|
VALUE="off"
|
|
fi
|
|
if [ "$KEY" = "founder_resources" ] && [ "$VALUE" != "true" ] && [ "$VALUE" != "false" ]; then
|
|
echo "Warning: founder_resources '$VALUE' not recognized. Valid values: true, false. Using true." >&2
|
|
VALUE="true"
|
|
fi
|
|
if [ "$KEY" = "plan_tune_hooks" ] && [ "$VALUE" != "prompt" ] && [ "$VALUE" != "yes" ] && [ "$VALUE" != "no" ]; then
|
|
echo "Warning: plan_tune_hooks '$VALUE' not recognized. Valid values: prompt, yes, no. Using prompt." >&2
|
|
VALUE="prompt"
|
|
fi
|
|
if [ "$KEY" = "timeline_stop_hook" ] && [ "$VALUE" != "yes" ] && [ "$VALUE" != "no" ]; then
|
|
echo "Warning: timeline_stop_hook '$VALUE' not recognized. Valid values: yes, no. Using yes." >&2
|
|
VALUE="yes"
|
|
fi
|
|
# codex_reviews controls workflow outside CLI calls. Unlike the warn-and-default keys above,
|
|
# an invalid value is REJECTED and the existing setting is left unchanged — a typo
|
|
# must never silently flip the switch and turn paid Codex calls on or off.
|
|
if [ "$KEY" = "codex_reviews" ] && [ "$VALUE" != "enabled" ] && [ "$VALUE" != "disabled" ]; then
|
|
echo "Error: codex_reviews '$VALUE' not recognized. Valid values: enabled, disabled. Existing value left unchanged." >&2
|
|
exit 1
|
|
fi
|
|
# design_detector_install_prompted records "never ask again" for the one-time
|
|
# engine install offer. Rejecting a typo keeps the offer from silently coming
|
|
# back (or never coming back) because of a mistyped value.
|
|
if [ "$KEY" = "design_detector_install_prompted" ] && [ "$VALUE" != "true" ] && [ "$VALUE" != "false" ]; then
|
|
echo "Error: design_detector_install_prompted '$VALUE' not recognized. Valid values: true, false. Existing value left unchanged." >&2
|
|
exit 1
|
|
fi
|
|
# design_detector gates a third-party binary the user installed. Reject a typo
|
|
# rather than coerce it: "of" must not silently re-enable or disable the scan.
|
|
if [ "$KEY" = "design_detector" ] && [ "$VALUE" != "auto" ] && [ "$VALUE" != "off" ]; then
|
|
echo "Error: design_detector '$VALUE' not recognized. Valid values: auto, off. Existing value left unchanged." >&2
|
|
exit 1
|
|
fi
|
|
# cross_project_learnings: empty get is the first-run prompt sentinel.
|
|
# Skills enable only on the literal "true". A typo must not persist — that
|
|
# keeps the feature off and suppresses the prompt. Reject, like
|
|
# codex_reviews; do not coerce (a stored default still kills the sentinel).
|
|
if [ "$KEY" = "cross_project_learnings" ] && [ "$VALUE" != "true" ] && [ "$VALUE" != "false" ]; then
|
|
echo "Error: cross_project_learnings '$VALUE' not recognized. Valid values: true, false. Existing value left unchanged." >&2
|
|
exit 1
|
|
fi
|
|
# memorable_recall is a CONSENT key: `on` lets a Claude Code hook hand every
|
|
# prompt to a third-party binary. Reject like codex_reviews -- a typo must
|
|
# never flip consent in either direction, so nothing is coerced or stored.
|
|
if [ "$KEY" = "memorable_recall" ] && [ "$VALUE" != "on" ] && [ "$VALUE" != "off" ]; then
|
|
echo "Error: memorable_recall '$VALUE' not recognized. Valid values: on, off. Existing value left unchanged." >&2
|
|
exit 1
|
|
fi
|
|
mkdir -p "$STATE_DIR"
|
|
# Write annotated header on first creation
|
|
if [ ! -f "$CONFIG_FILE" ]; then
|
|
printf '%s' "$CONFIG_HEADER" > "$CONFIG_FILE"
|
|
fi
|
|
# Drop embedded newlines, then escape sed replacement metacharacters.
|
|
SAFE_VALUE="$(printf '%s' "$VALUE" | head -1)"
|
|
ESC_VALUE="$(printf '%s' "$SAFE_VALUE" | sed 's/[&/\]/\\&/g')"
|
|
if grep -qE "^${KEY}:" "$CONFIG_FILE" 2>/dev/null; then
|
|
# Portable in-place edit (BSD sed uses -i '', GNU sed uses -i without arg)
|
|
_tmpfile="$(mktemp "${CONFIG_FILE}.XXXXXX")"
|
|
sed "/^${KEY}:/s/.*/${KEY}: ${ESC_VALUE}/" "$CONFIG_FILE" > "$_tmpfile" && mv "$_tmpfile" "$CONFIG_FILE"
|
|
else
|
|
echo "${KEY}: ${SAFE_VALUE}" >> "$CONFIG_FILE"
|
|
fi
|
|
# Auto-relink skills when prefix setting changes (skip during setup to avoid recursive call)
|
|
if [ "$KEY" = "skill_prefix" ] && [ -z "${GSTACK_SETUP_RUNNING:-}" ]; then
|
|
GSTACK_RELINK="$(dirname "$0")/gstack-relink"
|
|
[ -x "$GSTACK_RELINK" ] && "$GSTACK_RELINK" || true
|
|
fi
|
|
;;
|
|
list)
|
|
if [ -f "$CONFIG_FILE" ]; then
|
|
cat "$CONFIG_FILE"
|
|
fi
|
|
echo ""
|
|
echo "# ─── Active values (including defaults for unset keys) ───"
|
|
for KEY in proactive routing_declined telemetry auto_upgrade update_check \
|
|
skill_prefix checkpoint_mode checkpoint_push explain_level \
|
|
codex_reviews gstack_contributor skip_eng_review workspace_root \
|
|
artifacts_sync_mode artifacts_sync_mode_prompted plan_tune_hooks \
|
|
timeline_stop_hook design_detector design_detector_install_prompted memorable_recall; do
|
|
VALUE=$(read_config_value "$KEY" || true)
|
|
SOURCE="default"
|
|
if [ -n "$VALUE" ]; then
|
|
SOURCE="set"
|
|
else
|
|
VALUE=$(lookup_default "$KEY")
|
|
fi
|
|
printf ' %-24s %s (%s)\n' "$KEY:" "$VALUE" "$SOURCE"
|
|
done
|
|
;;
|
|
defaults)
|
|
echo "# gstack-config defaults"
|
|
for KEY in proactive routing_declined telemetry auto_upgrade update_check \
|
|
skill_prefix checkpoint_mode checkpoint_push explain_level \
|
|
codex_reviews gstack_contributor skip_eng_review workspace_root \
|
|
artifacts_sync_mode artifacts_sync_mode_prompted plan_tune_hooks \
|
|
timeline_stop_hook design_detector design_detector_install_prompted memorable_recall; do
|
|
printf ' %-24s %s\n' "$KEY:" "$(lookup_default "$KEY")"
|
|
done
|
|
;;
|
|
endpoint-hash)
|
|
# Brain integration helper (T10): print active brain endpoint sha8
|
|
endpoint_hash_with_collision_check
|
|
;;
|
|
resolve-user-slug)
|
|
# Brain integration helper (T16 / D4 A3): resolve + persist user-slug
|
|
resolve_user_slug
|
|
;;
|
|
gbrain-refresh)
|
|
# Brain integration helper: re-detect gbrain installation state and
|
|
# persist to ~/.gstack/gbrain-detection.json. gen-skill-docs reads this
|
|
# file (when invoked with --respect-detection) to decide whether to
|
|
# render GBRAIN_CONTEXT_LOAD and GBRAIN_SAVE_RESULTS blocks in
|
|
# generated SKILL.md files.
|
|
#
|
|
# Run this after installing or uninstalling gbrain so your locally
|
|
# generated SKILL.md files match your installation state.
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
DETECT_BIN="$SCRIPT_DIR/gstack-gbrain-detect"
|
|
DETECTION_FILE="$STATE_DIR/gbrain-detection.json"
|
|
mkdir -p "$STATE_DIR"
|
|
if [ ! -x "$DETECT_BIN" ]; then
|
|
echo "gstack-gbrain-detect not found at $DETECT_BIN" >&2
|
|
exit 1
|
|
fi
|
|
if ! "$DETECT_BIN" > "$DETECTION_FILE.tmp" 2>/dev/null; then
|
|
printf '{"gbrain_on_path":false,"gbrain_local_status":"no-cli"}\n' > "$DETECTION_FILE.tmp"
|
|
fi
|
|
mv "$DETECTION_FILE.tmp" "$DETECTION_FILE"
|
|
|
|
# Summarize for the user. Use python (already required elsewhere) to
|
|
# parse the JSON portably; fall back to grep if python is unavailable.
|
|
PYTHON_CMD=$(command -v python3 || command -v python || true)
|
|
if [ -n "$PYTHON_CMD" ]; then
|
|
STATUS=$("$PYTHON_CMD" -c "import json,sys; d=json.load(open('$DETECTION_FILE')); print(d.get('gbrain_local_status','unknown'))" 2>/dev/null || echo unknown)
|
|
VERSION=$("$PYTHON_CMD" -c "import json,sys; d=json.load(open('$DETECTION_FILE')); print(d.get('gbrain_version') or 'unknown')" 2>/dev/null || echo unknown)
|
|
else
|
|
STATUS=$(grep -o '"gbrain_local_status":[[:space:]]*"[^"]*"' "$DETECTION_FILE" | sed 's/.*"\([^"]*\)"$/\1/')
|
|
VERSION=$(grep -o '"gbrain_version":[[:space:]]*"[^"]*"' "$DETECTION_FILE" | sed 's/.*"\([^"]*\)"$/\1/')
|
|
[ -z "$STATUS" ] && STATUS=unknown
|
|
[ -z "$VERSION" ] && VERSION=unknown
|
|
fi
|
|
|
|
case "$STATUS" in
|
|
ok|timeout|thin-client|engine-locked)
|
|
# "timeout" = slow-but-healthy engine (#1964); "thin-client" =
|
|
# remote-HTTP MCP brain, no local engine by design (#2051);
|
|
# "engine-locked" = same class (#2456): PGLite is single-writer, so a
|
|
# live `gbrain serve` (typically an MCP server) holds the embedded DB.
|
|
# gbrain is installed and healthy; a transient lock must not strip
|
|
# brain blocks out of every SKILL.md. All get the same treatment as
|
|
# "ok", matching gstack-gbrain-detect --is-ok and gen-skill-docs.
|
|
echo "Detected gbrain v$VERSION (local-status: $STATUS)."
|
|
# Render brain-aware blocks into an UNTRACKED out-dir (#2569) and
|
|
# repoint the installed skills at it — the old in-place render wrote
|
|
# into TRACKED files of the global install checkout, so the checkout
|
|
# stayed permanently dirty and every upgrade grew a redundant stash.
|
|
# Guards (never mutate an arbitrary directory): the install must
|
|
# exist, not be a symlink (a symlinked install points at a dev
|
|
# worktree — bin/dev-setup owns that flow), and look like a real
|
|
# gstack clone.
|
|
INSTALL_DIR="$HOME/.claude/skills/gstack"
|
|
RENDER_DIR="${GSTACK_USER_RENDER_DIR:-${GSTACK_HOME:-$HOME/.gstack}/render/claude}"
|
|
if [ ! -d "$INSTALL_DIR" ]; then
|
|
echo "No global install at $INSTALL_DIR — nothing to render. (Dev workspaces get blocks via bin/dev-setup.)"
|
|
elif [ -L "$INSTALL_DIR" ]; then
|
|
echo "Skip: $INSTALL_DIR is a symlink (likely a dev worktree). Run bin/dev-setup in that worktree instead."
|
|
elif [ ! -f "$INSTALL_DIR/VERSION" ] || [ ! -f "$INSTALL_DIR/package.json" ]; then
|
|
echo "Skip: $INSTALL_DIR doesn't look like a gstack clone (missing VERSION/package.json) — refusing to modify it."
|
|
elif ! command -v bun >/dev/null 2>&1; then
|
|
echo "Skip: bun not on PATH — can't render. Install bun, then re-run 'gstack-config gbrain-refresh'."
|
|
else
|
|
# Render into a tmp dir and swap it in only on SUCCESS. Installed
|
|
# skills SYMLINK into $RENDER_DIR (gstack-relink prefers it), so
|
|
# wiping it before the render meant one transient failure (bun
|
|
# error, disk full, broken template) left every brain-aware
|
|
# SKILL.md link dangling — the whole skill set vanished from
|
|
# Claude Code until a successful re-render. A failed render now
|
|
# leaves the previous render fully intact.
|
|
RENDER_TMP="$RENDER_DIR.tmp.$$"
|
|
rm -rf "$RENDER_TMP"
|
|
if ( cd "$INSTALL_DIR" && bun run gen:skill-docs:user --host claude --out-dir "$RENDER_TMP" --link-root "$RENDER_DIR" >/dev/null 2>&1 ); then
|
|
_swap_in_render "$RENDER_DIR" "$RENDER_TMP"
|
|
# Repoint installed skills at the render — gstack-relink prefers
|
|
# the render dir when present.
|
|
"$INSTALL_DIR/bin/gstack-relink" >/dev/null 2>&1 || true
|
|
echo "Rendered brain-aware blocks into $RENDER_DIR — now live across all your projects' Claude sessions."
|
|
echo "The install checkout stays clean: upgrades no longer stash generated render dirt (#2569)."
|
|
else
|
|
rm -rf "$RENDER_TMP"
|
|
echo "Warning: render failed — previous render (if any) left in place, links stay valid."
|
|
echo "Run 'cd $INSTALL_DIR && bun run gen:skill-docs:user --host claude --out-dir $RENDER_DIR' manually to see the error."
|
|
fi
|
|
fi
|
|
;;
|
|
*)
|
|
echo "gbrain not detected (local-status: $STATUS) → brain-aware blocks will be suppressed in planning-skill SKILL.md files."
|
|
echo "Install gbrain (see /setup-gbrain) and re-run 'gstack-config gbrain-refresh' once it's configured."
|
|
;;
|
|
esac
|
|
;;
|
|
*)
|
|
echo "Usage: gstack-config {get|set|list|defaults|endpoint-hash|resolve-user-slug|gbrain-refresh} [key] [value]"
|
|
exit 1
|
|
;;
|
|
esac
|