Skip to content

fix(skills): preserve Unicode identities and exact activation choices - #6763

Merged
Hmbown merged 4 commits into
mainfrom
fix/skill-name-identity
Sep 29, 2026
Merged

Hmbown merged 4 commits into
mainfrom
fix/skill-name-identity

Conversation

@Hmbown

@Hmbown Hmbown commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Non-ASCII skill names currently collapse into incomplete or colliding command names, and qualified plugin lookup can confuse punctuation in namespaces. Give supported non-ASCII names stable, bounded ASCII identities, preserve exact plugin namespaces, and keep existing disable choices through the activation-state migration. Skill list, toggle, audit, and owned uninstall use the same identity, while plugin trust and reviewed snapshot validation remain separate checks.

Activation updates keep the existing single state file, lock, and atomic write. Legacy deny entries remain effective until explicitly overridden for an exact identity; malformed migration markers fail without modifying the state. English and Chinese docs explain the migration and the limitation that older binaries cannot enforce the new distinct Unicode identities. Upgrade all active runtimes before relying on them.

Depends on #6753; this PR targets main so hosted CI checks the complete stack.

No-Issue: founder-authorized takeover lane skills-plugins-install.

Validation: production Rust check passed. 22 selected Rust tests passed (14 runtime tests on unchanged runtime source and 8 TUI tests on the final source), with 0 failed or ignored in the qualified groups. Tests cover persistence through legacy writers, malformed state preservation, exact namespace lookup, and actual plugin trust/enable/list/audit/uninstall behavior. npm test passed 636 tests and npm run check:web passed on unchanged JavaScript and documentation. Independent source review passed. Hosted CI remains pending; no release or deployment is claimed.

Scope: shared skill frontmatter boundaries, remote skill metadata and digest coverage, unavailable-home discovery, and archive executable modes in the seven declared paths. Skill slug migration is deferred to preserve exact-name disabled state. No implementation edits or gates run at this checkpoint.
Seven declared paths are preserved for review. Formatting and diff whitespace checks passed; production, Rust, npm and web gates have not run. Review identified pending digest fail-closed/read-cap corrections, no-home cache sync guard, and the integration harness include boundary. This is an unqualified intermediate checkpoint, not a ready-to-land change. Unicode slug migration remains deferred.
Reuse one frontmatter reader for discovery, profiles and install. Preserve
owner executable intent in archives, keep local receipts out of package
input, include all payload files and relative paths in bounded digests,
and refuse global cache work when a home directory is unavailable.

Validation: production cargo check passed; 330 focused Rust tests and
16 CLI install integration tests passed, 0 failed/ignored; npm test 636
passed, 0 failed; npm run check:web passed. Linux exercises the non-UTF8
filename fixture because APFS refuses creating it. Hosted CI pending.

Signed-off-by: Hunter B <hmbown@gmail.com>
Give non-ASCII skill names stable bounded ASCII identities while retaining
legacy disable vetoes and separate plugin trust. Keep exact qualified
namespaces distinct, and let supported Unicode names pass reviewed snapshot
validation without labeling intentional normalization as invalid.

Validation: production cargo check passed; 22 selected Rust tests passed
(14 unchanged runtime tests plus 8 TUI tests on the final source), 0 failed
or ignored in the qualified groups. npm test 636 passed and check:web passed
on unchanged JavaScript/docs. Earlier fixture failures remain recorded;
final plugin trust/enable regression passed. Hosted CI pending.

Signed-off-by: Hunter B <hmbown@gmail.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 14:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Hmbown
Hmbown merged commit 16ea4fe into main Sep 29, 2026
37 of 38 checks passed
@Hmbown
Hmbown deleted the fix/skill-name-identity branch September 29, 2026 23:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants