Adopt agentseam 0.3.4: PowerShell shell matcher, Codex write gate, clean verdict channel - #173
Merged
Merged
Conversation
…rdict channel Regenerated with agentseam 0.3.4: Claude Code's shell guards match Bash|PowerShell (Windows' default shell tool), Codex gets a pre-write gate on apply_patch, and every vendored runtime keeps a handler's stdout off the verdict channel. Sync now prints the trust step Codex needs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
…reader The vendored runtime is one flat module. agentseam 0.3.4 added vscode_copilot's _tool_input(raw) (tool_input, else Copilot CLI's toolArgs); edit_image's own _tool_input(event), spliced in after it, rebound the name, so parse() read no command and every Copilot guard and gate allowed the call, in VS Code and the CLI alike. Rename chock's helper and pin that no top-level name in chock's handler rebinds one of agentseam's bundle (PRE_TOOL, equal on both sides, excepted). Runtime goldens and this repo's runtimes regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
agentseam 0.3.4 records PowerShell as a Claude Code shell tool; the hooks reference says "The matcher `Bash|PowerShell` covers the PowerShell tool as well as Bash", and its input carries tool_input.command like Bash. The wire-fact alarm, the settings install and the Claude plugin now pin that matcher. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
agentseam 0.3.4 records apply_patch as Codex's write tool, so gate_reach
answers ("apply_patch", True) and a Codex gate package hooks PreToolUse
as well as Stop. Codex leaves the stop-only package test; the catalog
page's stop-only wording is now pinned through _explain directly, since
no page tree publishes a stop-only gate, and the Codex page is pinned to
say the write is judged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
`pwsh -Command` reports any failing native command as exit 1, so the launcher's exit 2 (no working Python: refuse) reached VS Code as a non-blocking error. The powershell/windows keys now carry `& <launcher command>; exit $LASTEXITCODE`, agentseam 0.3.4's own Windows form. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
….3.4 Generated wiring and goldens regenerated with agentseam 0.3.4; the launcher test keeps main's every-shell case and this branch's unwrap of PowerShell-only fields. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
Copilot's powershell/windows entries end `; exit $LASTEXITCODE`. With git or sh missing no native command runs, $LASTEXITCODE is $null, and `exit $null` is 0 -- an allow. Exit 2 then, as agentseam 0.3.4 does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
Recompiled with --upgrade-package agentseam; no other pin moves. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
This PR moves the pin to
agentseam==0.3.4(now on PyPI) and regenerates everything that depends on it.Bash|PowerShell. Claude Code's default shell tool on Windows isPowerShell, so guards that matched onlyBashnever fired there.codex_cli-write-hooks.jsonadds a pre-write gate onapply_patch.edit_image._tool_inputshadowed agentseam 0.3.4's new vscode_copilot_tool_input, so every Copilot guard and gate allowed everything. It is renamed to_edit_call_input, andtest_chock_handler_shadows_no_agentseam_name[agent]fails on any future clash.powershell/windowskeys are& <launcher cmd>; if ($null -eq $LASTEXITCODE) { exit 2 }; exit $LASTEXITCODE.$nullguard is new in this PR (2f85287). With git or sh missing, no native command runs, andexit $nullwould be 0, which is an allow. This matches the fix in 0.3.4: keep the verdict channel clean, read Copilot CLI's camelCase, keep PowerShell exit codes agentseam#161.requirements/brand-assets.txtpins agentseam 0.3.4 (recompiled with--upgrade-package agentseam; no other pin moves).main(Portable agent hooks: one committed launcher, and gates that refuse when they cannot judge #172). The generated wiring and goldens are regenerated. The launcher test keeps bothmain's every-shell case and this branch's unwrap of PowerShell-only fields.Definition of done
chock check→ 0 failureschock check --only matrixpasses (part ofchock check)chock sync --repo . --checkcleanchock check --only verifycleanpytest -qgreen (1596 passed, 3 skipped, agentseam 0.3.4 from PyPI); the shadowing test covers every vendor runtimeruff check .andruff format --check .cleanClaims
After this merges, chock is ready to release (probably 0.12.0). chock-catalog's
.framework-refthen gets re-pinned to that tag.🤖 Generated with Claude Code
https://claude.ai/code/session_016DapRw9Ce9z6jRd11uiuyu
Generated by Claude Code