fix(skills): preserve Unicode identities and exact activation choices - #6763
Merged
Merged
Conversation
Scope: shared skill frontmatter boundaries, remote skill metadata and digest coverage, unavailable-home discovery, and archive executable modes in the seven declared paths. Skill slug migration is deferred to preserve exact-name disabled state. No implementation edits or gates run at this checkpoint.
Seven declared paths are preserved for review. Formatting and diff whitespace checks passed; production, Rust, npm and web gates have not run. Review identified pending digest fail-closed/read-cap corrections, no-home cache sync guard, and the integration harness include boundary. This is an unqualified intermediate checkpoint, not a ready-to-land change. Unicode slug migration remains deferred.
Reuse one frontmatter reader for discovery, profiles and install. Preserve owner executable intent in archives, keep local receipts out of package input, include all payload files and relative paths in bounded digests, and refuse global cache work when a home directory is unavailable. Validation: production cargo check passed; 330 focused Rust tests and 16 CLI install integration tests passed, 0 failed/ignored; npm test 636 passed, 0 failed; npm run check:web passed. Linux exercises the non-UTF8 filename fixture because APFS refuses creating it. Hosted CI pending. Signed-off-by: Hunter B <hmbown@gmail.com>
Give non-ASCII skill names stable bounded ASCII identities while retaining legacy disable vetoes and separate plugin trust. Keep exact qualified namespaces distinct, and let supported Unicode names pass reviewed snapshot validation without labeling intentional normalization as invalid. Validation: production cargo check passed; 22 selected Rust tests passed (14 unchanged runtime tests plus 8 TUI tests on the final source), 0 failed or ignored in the qualified groups. npm test 636 passed and check:web passed on unchanged JavaScript/docs. Earlier fixture failures remain recorded; final plugin trust/enable regression passed. Hosted CI pending. Signed-off-by: Hunter B <hmbown@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Non-ASCII skill names currently collapse into incomplete or colliding command names, and qualified plugin lookup can confuse punctuation in namespaces. Give supported non-ASCII names stable, bounded ASCII identities, preserve exact plugin namespaces, and keep existing disable choices through the activation-state migration. Skill list, toggle, audit, and owned uninstall use the same identity, while plugin trust and reviewed snapshot validation remain separate checks.
Activation updates keep the existing single state file, lock, and atomic write. Legacy deny entries remain effective until explicitly overridden for an exact identity; malformed migration markers fail without modifying the state. English and Chinese docs explain the migration and the limitation that older binaries cannot enforce the new distinct Unicode identities. Upgrade all active runtimes before relying on them.
Depends on #6753; this PR targets main so hosted CI checks the complete stack.
No-Issue: founder-authorized takeover lane
skills-plugins-install.Validation: production Rust check passed. 22 selected Rust tests passed (14 runtime tests on unchanged runtime source and 8 TUI tests on the final source), with 0 failed or ignored in the qualified groups. Tests cover persistence through legacy writers, malformed state preservation, exact namespace lookup, and actual plugin trust/enable/list/audit/uninstall behavior.
npm testpassed 636 tests andnpm run check:webpassed on unchanged JavaScript and documentation. Independent source review passed. Hosted CI remains pending; no release or deployment is claimed.