Skip to content

Adopt agentseam 0.3.4: PowerShell shell matcher, Codex write gate, clean verdict channel - #173

Merged
jothimani-rajendran merged 10 commits into
mainfrom
chore/adopt-agentseam-0.3.4
Sep 27, 2026
Merged

jothimani-rajendran merged 10 commits into
mainfrom
chore/adopt-agentseam-0.3.4

Conversation

@jothimani-rajendran

Copy link
Copy Markdown
Collaborator

What

This PR moves the pin to agentseam==0.3.4 (now on PyPI) and regenerates everything that depends on it.

  • Claude Code: the shell matcher becomes Bash|PowerShell. Claude Code's default shell tool on Windows is PowerShell, so guards that matched only Bash never fired there.
  • Codex: a new codex_cli-write-hooks.json adds a pre-write gate on apply_patch.
  • Stdout: a policy handler's stray stdout can no longer turn a deny into an allow. agentseam diverts stdout and fd 1 while a handler runs.
  • Copilot CLI: its camelCase payloads are read.
  • Name clash: inside the single-file runtime, chock's edit_image._tool_input shadowed agentseam 0.3.4's new vscode_copilot _tool_input, so every Copilot guard and gate allowed everything. It is renamed to _edit_call_input, and test_chock_handler_shadows_no_agentseam_name[agent] fails on any future clash.
  • Copilot PowerShell entries:
  • requirements/brand-assets.txt pins agentseam 0.3.4 (recompiled with --upgrade-package agentseam; no other pin moves).
  • Merged main (Portable agent hooks: one committed launcher, and gates that refuse when they cannot judge #172). The generated wiring and goldens are regenerated. The launcher test keeps both main's every-shell case and this branch's unwrap of PowerShell-only fields.

Definition of done

  • chock check → 0 failures
  • chock check --only matrix passes (part of chock check)
  • chock sync --repo . --check clean
  • chock check --only verify clean
  • Registry rescanned; no stale entries (CI registry freshness check)
  • pytest -q green (1596 passed, 3 skipped, agentseam 0.3.4 from PyPI); the shadowing test covers every vendor runtime
  • Acceptance suite green (21 passed)
  • Existing artifacts migrated in this PR (chock's own wiring regenerated)
  • Changelog entry under Unreleased
  • ruff check . and ruff format --check . clean

Claims

  • No surface is described as enforcing more than it installs

After this merges, chock is ready to release (probably 0.12.0). chock-catalog's .framework-ref then gets re-pinned to that tag.

🤖 Generated with Claude Code

https://claude.ai/code/session_016DapRw9Ce9z6jRd11uiuyu


Generated by Claude Code

…rdict channel

Regenerated with agentseam 0.3.4: Claude Code's shell guards match
Bash|PowerShell (Windows' default shell tool), Codex gets a pre-write gate on
apply_patch, and every vendored runtime keeps a handler's stdout off the
verdict channel. Sync now prints the trust step Codex needs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
…reader

The vendored runtime is one flat module. agentseam 0.3.4 added
vscode_copilot's _tool_input(raw) (tool_input, else Copilot CLI's
toolArgs); edit_image's own _tool_input(event), spliced in after it,
rebound the name, so parse() read no command and every Copilot guard
and gate allowed the call, in VS Code and the CLI alike.

Rename chock's helper and pin that no top-level name in chock's handler
rebinds one of agentseam's bundle (PRE_TOOL, equal on both sides,
excepted). Runtime goldens and this repo's runtimes regenerated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
agentseam 0.3.4 records PowerShell as a Claude Code shell tool; the
hooks reference says "The matcher `Bash|PowerShell` covers the
PowerShell tool as well as Bash", and its input carries
tool_input.command like Bash. The wire-fact alarm, the settings
install and the Claude plugin now pin that matcher.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
agentseam 0.3.4 records apply_patch as Codex's write tool, so gate_reach
answers ("apply_patch", True) and a Codex gate package hooks PreToolUse
as well as Stop. Codex leaves the stop-only package test; the catalog
page's stop-only wording is now pinned through _explain directly, since
no page tree publishes a stop-only gate, and the Codex page is pinned to
say the write is judged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
`pwsh -Command` reports any failing native command as exit 1, so the
launcher's exit 2 (no working Python: refuse) reached VS Code as a
non-blocking error. The powershell/windows keys now carry
`& <launcher command>; exit $LASTEXITCODE`, agentseam 0.3.4's own Windows form.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
….3.4

Generated wiring and goldens regenerated with agentseam 0.3.4; the
launcher test keeps main's every-shell case and this branch's unwrap
of PowerShell-only fields.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
Copilot's powershell/windows entries end `; exit $LASTEXITCODE`. With
git or sh missing no native command runs, $LASTEXITCODE is $null, and
`exit $null` is 0 -- an allow. Exit 2 then, as agentseam 0.3.4 does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
Recompiled with --upgrade-package agentseam; no other pin moves.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
@jothimani-rajendran
jothimani-rajendran marked this pull request as ready for review September 27, 2026 19:22
@jothimani-rajendran
jothimani-rajendran merged commit dbfd4ec into main Sep 27, 2026
33 checks passed
@jothimani-rajendran jothimani-rajendran mentioned this pull request Sep 27, 2026
11 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants