refactor(permission): consume structured bash payload

- require @gotgenes/pi-permission-system >=25.3.0 and read the complete local bash command from PromptPermissionDetails.payload instead of session-walking recovery
- remove the @sikongjueluo/pi-permission-shared package
- pass the triggering command unit to handlers via HandlerContext.unit in place of details.command
- add shadow-only AI judge modules for evidence projection, structured verdict requests, and prompt building, with vitest coverage
- record ADR 0004 and mark the ADR 0001 recovery mechanism superseded
- exclude pi-permission-system 25.3.0 from the pnpm minimumReleaseAge guard
This commit is contained in:
2026-08-16 23:08:45 +08:00
parent 6008c9e817
commit 1afcbd3118
29 changed files with 1540 additions and 587 deletions
@@ -229,6 +229,31 @@ describe("permissions:ready -> registerAuthorizer lifecycle", () => {
source: "tool_call",
agentName: "child",
message: "forwarded ask",
payload: {
kind: "forwarded",
request: {
requester: {
agentName: "child",
forwarded: true,
sessionId: "s1",
},
surface: "bash",
toolName: "bash",
invokedToolName: null,
value: "bash",
matchedPattern: null,
commandContext: null,
executedUnit: null,
},
evidence: [
{
label: "requested",
text: "forwarded ask",
detail: null,
},
],
annotations: [],
},
toolCallId: "call_1",
toolName: "bash",
forwarding: {