Commit Graph
27 Commits
Author SHA1 Message Date
SikongJueluo 061c60c344 feat(ai-judge): rework enforce mode as user-assumed-risk contract
- add config v2 with fixed judge model selection and fail-closed v1 enforce migration to shadow
- add built-in high-risk override for irreversible, publish, system, and credential shapes that always defers to the human
- remove the promotion gate, promotion records tool, and their tests
- fail closed with judge_model_unavailable when a configured judge model cannot be resolved
- notify once per session in enforce mode with the judge model and risk contract
- add ADR 0008 and update README and CONTEXT
2026-08-21 23:11:40 +08:00
SikongJueluo f4ba739878 docs(ai-judge): add package README
- document shadow and enforce usage, configuration, logs, and tools
- reorder the project authorizer chain to inner-cmd then ai-bash-judge
2026-08-21 23:11:34 +08:00
SikongJueluo d57892d5ab feat(ai-judge): promotion-gate records seam and truth-table wiring (PIEXTENSIO-21) 2026-08-20 17:45:07 +08:00
SikongJueluo 45e91a700d fix(ai-judge): defer irreversible destructive operations regardless of intent (prompt v4, PIEXTENSIO-20) 2026-08-20 16:25:11 +08:00
SikongJueluo efc73c0f5c feat(ai-judge): prompt v3 few-shot calibration and corpus replay harness (PIEXTENSIO-18) 2026-08-19 23:45:47 +08:00
SikongJueluo 232bad549e feat(ai-judge): judge-owned audit log with local health gate (ADR 0006) 2026-08-19 23:45:43 +08:00
SikongJueluo 0637784f5f feat(ai-judge): conversation evidence with bounded whitelist capture
- add conversation.ts: compaction-aware active-branch capture, user-text-only whitelist, 16-item and 12,000-char bounds with latest-user preservation
- bump prompt to bash-shadow-v2 with explicit-user-intent authority rules and quoted untrusted intent evidence
- capture the requesting cwd and per-ask conversation state; flip evidence-quality flags from placeholders to measured values
- record the candidate-identity change for prior cohorts in the scenario-set doc
2026-08-17 22:25:06 +08:00
SikongJueluo 1d701ca0b0 feat(ai-judge): review sink with telemetry health and fail-closed truth table
- add review.ts sink adapter with session-start review-log toggle detection and a privacy key denylist enforced before delegation
- add judge.ts enforce truth table: allow requires mode, host contract, telemetry health, cohort qualification, owner approval, activation, judgment result, allow verdict, review acknowledgement, and current generation — each independently forces defer with a distinct reason
- route the authorizer callback through the sink and the v0.1 production gate state, which is structurally unreachable and therefore fail-closed
2026-08-17 21:37:48 +08:00
SikongJueluo 3f3bbb4c28 feat(ai-judge): capture model per permission request 2026-08-17 20:00:18 +08:00
SikongJueluo 0546a80497 feat(ai-judge): global config module with validation and cohort identity 2026-08-17 19:53:48 +08:00
SikongJueluo 0a1b9f259d build: align permission-system to 25.4 2026-08-17 19:20:49 +08:00
SikongJueluo 6c0e26bc6e fix(ai-judge): restore authoritative 15s default timeout 2026-08-17 19:17:40 +08:00
SikongJueluo 850f36c7a4 docs(research): archive shadow replay rounds and analyzer round-1 fixes
- rejoin round-1 rows hidden by terminal-event handling: normalize denied_with_reason, collapse forwarded double terminal rows, print quarantine counts, add --before window bound
- archive rounds 1-3 reports with blind-deny protocol, cross-round totals, and PIEXTENSIO-11 latency evidence
2026-08-17 18:59:19 +08:00
SikongJueluo 92cabb6b7c fix(ai-judge): classify provider aborts after timeout as timeout 2026-08-17 16:58:10 +08:00
SikongJueluo 6407b7429a feat(ai-judge): offline shadow analyzer with reconstructed join 2026-08-17 16:58:10 +08:00
SikongJueluo 42f0a0aaab feat(permission): complete shadow review events for offline analysis
- key inner-cmd decisive review events by requestId so link decisions join offline
- record judge runtime id, prompt and tool schema versions, end-to-end and model latency, input and output usage, and evidence-quality flags on every judge result row
- record forwarded and session-mismatch preflight defers so they stay visible in the offline denominator
2026-08-17 16:58:10 +08:00
SikongJueluo f632fa34d1 fix(permission): raise verdict output budget for reasoning tokens 2026-08-16 23:54:58 +08:00
SikongJueluo 1afcbd3118 refactor(permission): consume structured bash payload
- require @gotgenes/pi-permission-system >=25.3.0 and read the complete local bash command from PromptPermissionDetails.payload instead of session-walking recovery
- remove the @sikongjueluo/pi-permission-shared package
- pass the triggering command unit to handlers via HandlerContext.unit in place of details.command
- add shadow-only AI judge modules for evidence projection, structured verdict requests, and prompt building, with vitest coverage
- record ADR 0004 and mark the ADR 0001 recovery mechanism superseded
- exclude pi-permission-system 25.3.0 from the pnpm minimumReleaseAge guard
2026-08-16 23:08:45 +08:00
SikongJueluo 6008c9e817 fix(pi-permission-inner-cmd): unwrap timeout in real-world command forms
- accept GNU timeout durations without a unit suffix and with decimals (timeout 240 …)
- detect the wrapper on details.command and strip it from the full command so scaffolded inputs (cd … && timeout … | tail) unwrap
- re-evaluate the full de-wrapped compound so sibling commands cannot hide behind the wrapper allow
- defer fail-closed when the unit is not a unique substring of the full command
- amend ADR 0001 with the relaxed grammar and the scaffolded-command handling
2026-08-12 11:20:46 +08:00
SikongJueluo 43ae2db90b feat(pi-permission-inner-cmd): defer xargs as a non-transparent wrapper
- add handlers/xargs.ts mirroring env: claim xargs-leading commands and defer
- register xargsHandler so leading-xargs commands log and defer instead of falling through silently
- add CONTEXT.md xargs example and ADR 0003 (xargs args come from stdin, so even the AI judge cannot know them)
2026-08-12 00:36:09 +08:00
SikongJueluo 5134e85d32 refactor(pi-permission-inner-cmd): dispatch commands through a handler registry
- replace the hardcoded timeout switch with an engine that iterates registered handlers
- extract the timeout logic into handlers/timeout.ts and add handlers/env.ts that defers env as non-transparent
- thread a partial-evidence bag so the engine exception log retains handler-derived values like innerCommand
- add CONTEXT.md with the transparent vs non-transparent wrapper glossary
- record ADR 0002: env always defers to the AI judge and is never unwrapped
2026-08-12 00:12:41 +08:00
SikongJueluo 2014e7f793 refactor(pi-permission): extract shared bash-recovery package
- add @sikongjueluo/pi-permission-shared with recoverNativeBashCommand and its tests
- move the recovery module out of pi-permission-inner-cmd and import it from the shared package
- wire pi-permission-ai-judge to capture the UI-root session and recover the full bash command
- gate pi-permission-ai-judge registration on a UI-present root session
- add @types/node to pi-permission-ai-judge and allow its test script to pass with no tests
2026-08-11 21:53:46 +08:00
SikongJueluo 06b21a28a6 refactor(pi-permission-inner-cmd): narrow bash recovery uniqueness to one message
- walk entries in reverse and stop at the latest assistant message containing the id
- require the id to match exactly one block within that message rather than across the whole session
- resolve a cross-message id reuse to the latest call being authorized
- update ADR 0001 wording for the narrowed scope
- add a regression test for cross-message id reuse
2026-08-11 21:53:46 +08:00
SikongJueluo f21cf54ff1 fix(pi): install inner-cmd runtime dependency 2026-08-11 19:50:34 +08:00
SikongJueluo 24153412c9 feat(pi-permission-inner-cmd): authorize inner commands behind timeout wrappers
- recover the full bash command from the session by tool-call id
- add recognizer for the strict timeout wrapper grammar
- add authorizer mapping inner allow/ask/deny and forwarding agent name
- defer fail-closed on session mismatch, nested wrappers, and errors
- add unit tests for recovery, recognizer, authorizer, and lifecycle
- document the decision in ADR 0001
2026-08-11 16:33:08 +08:00
SikongJueluo c4d76ad284 feat(pi-permission-inner-cmd): scaffold inner-command permission package
- add package.json with pi extension entry and vitest setup
- add tsconfig and minimal session-start entry stub
- register package in pnpm lockfile
2026-08-11 16:33:07 +08:00
SikongJueluo f62a073de7 feat(pi-permission-ai-judge): add deferring authorizer extension
- add pnpm workspace scaffold with shared TypeScript config
- register an ai-bash-judge authorizer with pi-permission-system
- log permission request details and deterministic policy verdicts
- record review entries and defer to the next authorizer
2026-08-08 19:43:21 +08:00