Skip to content

fix(skills): preserve package identity through install and review - #6753

Merged
Hmbown merged 3 commits into
mainfrom
fix/skill-package-inputs
Sep 29, 2026
Merged

Hmbown merged 3 commits into
mainfrom
fix/skill-package-inputs

Conversation

@Hmbown

@Hmbown Hmbown commented Sep 29, 2026

Copy link
Copy Markdown
Owner

No-Issue: verified package input and review consistency findings.

Skill discovery, agent profiles and package installation now use one frontmatter reader. It handles Unicode indentation, leading BOMs, standalone fences and wrapped descriptions consistently. Archive extraction preserves executable intent for the owner and keeps installer-owned root receipts separate from package input. Plugin trust continues to use its existing state store.

Package review hashes all payload files with their relative paths, including hidden/backup files. Relative roots and filesystem aliases now produce the same digest, while moving a file within the package changes it. Ambiguous metadata names, unreadable entries and unsupported file types are refused; actual reads are bounded even if a file grows. Changed coverage can make an existing trust receipt stale, requiring review again. Missing-home discovery omits global roots, and registry sync refuses before configuration or network work when it has no cache destination.

Validation on final source:

  • Production cargo check -p codewhale-tui --lib --locked: passed.
  • Focused skills, plugin installation, profile and cache-command tests: 330 passed, 0 failed, 0 ignored.
  • CLI installation integration tests using local HTTP fixtures: 16 passed, 0 failed, 0 ignored.
  • Root npm test: 636 passed, 0 failed; npm run check:web: passed.
  • Independent source review and formatting/whitespace checks passed. The first focused run exposed an invalid-name fixture that APFS cannot create; that unchanged validation case is now Linux-only and awaits hosted Linux CI.

Non-ASCII skill-name collision handling requires a separate activation-state migration and is tracked separately. Hosted CI remains required before merge.

Scope: shared skill frontmatter boundaries, remote skill metadata and digest coverage, unavailable-home discovery, and archive executable modes in the seven declared paths. Skill slug migration is deferred to preserve exact-name disabled state. No implementation edits or gates run at this checkpoint.
Seven declared paths are preserved for review. Formatting and diff whitespace checks passed; production, Rust, npm and web gates have not run. Review identified pending digest fail-closed/read-cap corrections, no-home cache sync guard, and the integration harness include boundary. This is an unqualified intermediate checkpoint, not a ready-to-land change. Unicode slug migration remains deferred.
Reuse one frontmatter reader for discovery, profiles and install. Preserve
owner executable intent in archives, keep local receipts out of package
input, include all payload files and relative paths in bounded digests,
and refuse global cache work when a home directory is unavailable.

Validation: production cargo check passed; 330 focused Rust tests and
16 CLI install integration tests passed, 0 failed/ignored; npm test 636
passed, 0 failed; npm run check:web passed. Linux exercises the non-UTF8
filename fixture because APFS refuses creating it. Hosted CI pending.

Signed-off-by: Hunter B <hmbown@gmail.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 12:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Hmbown
Hmbown merged commit d38ede4 into main Sep 29, 2026
35 checks passed
@Hmbown
Hmbown deleted the fix/skill-package-inputs branch September 29, 2026 17:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants