The project-local .pi/settings.json that mounted
../packages/pi-permission-ai-judge was removed in kyxsszlx, leaving
ai-bash-judge with no loader and the global authorizer chain with a
dangling link: inner-cmd loaded but no "Enforce active" notice appeared.
- add the ai-judge entry point next to inner-cmd in pi.extensions so
the git package ships both authorizers
- rely on the loader's bundled aliases for @earendil-works/pi-ai
(value-imported only for the Type schema helper) so no runtime
dependency is needed
- resolve the permissions service by the live session id in both
tryRegister paths, so a mid-session republish re-keys via the re-emitted
permissions:ready channel
- read the session probe instead of the start-time snapshot for inner-cmd
- pass the session key to publish/unpublishPermissionsService in tests and
drop the removed PromptPermissionDetails.message field
- raise the ai-judge peer floor to @gotgenes/pi-permission-system >=32.0.0
- bump dev deps: pi-coding-agent 0.85.1, vitest 5, typescript 7
- require @gotgenes/pi-permission-system >=25.3.0 and read the complete local bash command from PromptPermissionDetails.payload instead of session-walking recovery
- remove the @sikongjueluo/pi-permission-shared package
- pass the triggering command unit to handlers via HandlerContext.unit in place of details.command
- add shadow-only AI judge modules for evidence projection, structured verdict requests, and prompt building, with vitest coverage
- record ADR 0004 and mark the ADR 0001 recovery mechanism superseded
- exclude pi-permission-system 25.3.0 from the pnpm minimumReleaseAge guard
- add pnpm workspace scaffold with shared TypeScript config
- register an ai-bash-judge authorizer with pi-permission-system
- log permission request details and deterministic policy verdicts
- record review entries and defer to the next authorizer