Skip to content

Commit fd08ef1

Browse files
committed
docs(agent): refresh grant remediation memory across PT .agent
Update workspace, saga, decisions JSONL, CodeRabbit Batch G, semantic DECISIONS, and graduate five lessons (replay state machine, canonical payload, same-user boundary, HMAC override, path hygiene).
1 parent 4ca359b commit fd08ef1

13 files changed

Lines changed: 446 additions & 46 deletions
Lines changed: 55 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,55 @@
1+
{
2+
"id": "1a6dc6bccad0",
3+
"key": "manual_1a6dc6",
4+
"name": "manual_1a6dc6",
5+
"claim": "Tracked .agent memory and working chronicles must not embed ephemeral scratch path literals \u2014 repo_hygiene flags them like workstation home paths and blocks PT CI.",
6+
"conditions": [
7+
"agent",
8+
"blocks",
9+
"chronicles",
10+
"embed",
11+
"ephemeral",
12+
"flags",
13+
"home",
14+
"like",
15+
"literals",
16+
"memory",
17+
"path",
18+
"paths",
19+
"repo_hygiene",
20+
"scratch",
21+
"them",
22+
"tracked",
23+
"working",
24+
"workstation"
25+
],
26+
"evidence_ids": [
27+
"2026-08-02T04:07:28.914652+00:00"
28+
],
29+
"cluster_size": 1,
30+
"canonical_salience": 8.0,
31+
"staged_at": "2026-08-02T04:07:28.914652+00:00",
32+
"status": "accepted",
33+
"decisions": [
34+
{
35+
"ts": "2026-08-02T04:07:28.914652+00:00",
36+
"action": "staged",
37+
"reviewer": "learn"
38+
},
39+
{
40+
"ts": "2026-08-02T04:07:29.049005+00:00",
41+
"action": "graduated",
42+
"reviewer": "learn.py",
43+
"notes": "PT #320 Actions failed on saga /tmp worktree names; use neutral worktree labels in memory.",
44+
"provisional": false,
45+
"evidence_snapshot": [
46+
"2026-08-02T04:07:28.914652+00:00"
47+
],
48+
"lessons_sha": "2d792c79eb15"
49+
}
50+
],
51+
"rejection_count": 0,
52+
"accepted_at": "2026-08-02T04:07:29.048986+00:00",
53+
"reviewer": "learn.py",
54+
"rationale": "PT #320 Actions failed on saga /tmp worktree names; use neutral worktree labels in memory."
55+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"id": "446162929cb3",
3+
"key": "manual_446162",
4+
"name": "manual_446162",
5+
"claim": "Same-user Keychain HMAC for PR-body grants is escalation control not cryptographic human identity \u2014 agent shells with PTY can read the secret or ack file; MVP raises effort; WebAuthn deferred to security-sentinel v2.1.",
6+
"conditions": [
7+
"ack",
8+
"agent",
9+
"control",
10+
"cryptographic",
11+
"deferred",
12+
"effort",
13+
"escalation",
14+
"file",
15+
"grants",
16+
"hmac",
17+
"human",
18+
"identity",
19+
"keychain",
20+
"mvp",
21+
"pr-body",
22+
"pty",
23+
"raises",
24+
"read",
25+
"same-user",
26+
"secret",
27+
"security-sentinel",
28+
"shells",
29+
"webauthn"
30+
],
31+
"evidence_ids": [
32+
"2026-08-02T04:07:28.049022+00:00"
33+
],
34+
"cluster_size": 1,
35+
"canonical_salience": 8.0,
36+
"staged_at": "2026-08-02T04:07:28.049022+00:00",
37+
"status": "accepted",
38+
"decisions": [
39+
{
40+
"ts": "2026-08-02T04:07:28.049022+00:00",
41+
"action": "staged",
42+
"reviewer": "learn"
43+
},
44+
{
45+
"ts": "2026-08-02T04:07:28.177266+00:00",
46+
"action": "graduated",
47+
"reviewer": "learn.py",
48+
"notes": "Remediation F3 F4; honest security doctrine per research and autoplan CEO review.",
49+
"provisional": false,
50+
"evidence_snapshot": [
51+
"2026-08-02T04:07:28.049022+00:00"
52+
],
53+
"lessons_sha": "c0a5b0b7048b"
54+
}
55+
],
56+
"rejection_count": 0,
57+
"accepted_at": "2026-08-02T04:07:28.177254+00:00",
58+
"reviewer": "learn.py",
59+
"rationale": "Remediation F3 F4; honest security doctrine per research and autoplan CEO review."
60+
}
Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
{
2+
"id": "720dedfdd2c8",
3+
"key": "manual_720ded",
4+
"name": "manual_720ded",
5+
"claim": "operator-grant-v2 HMAC canonical payload is fixed-order UTF-8 bytes grant-v2|repo|pr|nonce|issued_at|action|content_digest with no trailing newline; mint and verify must use identical bytes; golden vector test locks regression.",
6+
"conditions": [
7+
"action",
8+
"bytes",
9+
"canonical",
10+
"content_digest",
11+
"fixed-order",
12+
"golden",
13+
"grant-v2",
14+
"hmac",
15+
"identical",
16+
"issued_at",
17+
"locks",
18+
"mint",
19+
"newline",
20+
"nonce",
21+
"operator-grant-v2",
22+
"payload",
23+
"regression",
24+
"repo",
25+
"test",
26+
"trailing",
27+
"use",
28+
"utf-8",
29+
"vector",
30+
"verify"
31+
],
32+
"evidence_ids": [
33+
"2026-08-02T04:07:27.549926+00:00"
34+
],
35+
"cluster_size": 1,
36+
"canonical_salience": 8.0,
37+
"staged_at": "2026-08-02T04:07:27.549926+00:00",
38+
"status": "accepted",
39+
"decisions": [
40+
{
41+
"ts": "2026-08-02T04:07:27.549926+00:00",
42+
"action": "staged",
43+
"reviewer": "learn"
44+
},
45+
{
46+
"ts": "2026-08-02T04:07:27.694086+00:00",
47+
"action": "graduated",
48+
"reviewer": "learn.py",
49+
"notes": "Remediation F1; prevents silent canonicalization drift between mint and verify.",
50+
"provisional": false,
51+
"evidence_snapshot": [
52+
"2026-08-02T04:07:27.549926+00:00"
53+
],
54+
"lessons_sha": "0d29d707962f"
55+
}
56+
],
57+
"rejection_count": 0,
58+
"accepted_at": "2026-08-02T04:07:27.694075+00:00",
59+
"reviewer": "learn.py",
60+
"rationale": "Remediation F1; prevents silent canonicalization drift between mint and verify."
61+
}
Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
{
2+
"id": "cd51f7e6bf6c",
3+
"key": "manual_cd51f7",
4+
"name": "manual_cd51f7",
5+
"claim": "PR-body operator grant v2 replay state machine: append-pr-body.sh must reserve nonce before gh pr edit, mark-applied only after remote success, consume last; release reservation on edit failure; reconcile CLI consumes when follow-up block already on remote (crash recovery). Never consume before gh pr edit succeeds.",
6+
"conditions": [
7+
"after",
8+
"already",
9+
"append-pr-body",
10+
"before",
11+
"block",
12+
"cli",
13+
"consume",
14+
"consumes",
15+
"crash",
16+
"edit",
17+
"failure",
18+
"follow-up",
19+
"grant",
20+
"last",
21+
"machine",
22+
"mark-applied",
23+
"never",
24+
"nonce",
25+
"only",
26+
"operator",
27+
"pr-body",
28+
"reconcile",
29+
"recovery",
30+
"release",
31+
"remote",
32+
"replay",
33+
"reservation",
34+
"reserve",
35+
"state",
36+
"succeeds",
37+
"success"
38+
],
39+
"evidence_ids": [
40+
"2026-08-02T04:07:27.047829+00:00"
41+
],
42+
"cluster_size": 1,
43+
"canonical_salience": 8.0,
44+
"staged_at": "2026-08-02T04:07:27.047829+00:00",
45+
"status": "accepted",
46+
"decisions": [
47+
{
48+
"ts": "2026-08-02T04:07:27.047829+00:00",
49+
"action": "staged",
50+
"reviewer": "learn"
51+
},
52+
{
53+
"ts": "2026-08-02T04:07:27.202666+00:00",
54+
"action": "graduated",
55+
"reviewer": "learn.py",
56+
"notes": "Remediation F2 on orama #260 PT #320; closes replay window and crash-after-edit gap.",
57+
"provisional": false,
58+
"evidence_snapshot": [
59+
"2026-08-02T04:07:27.047829+00:00"
60+
],
61+
"lessons_sha": "d481593ae533"
62+
}
63+
],
64+
"rejection_count": 0,
65+
"accepted_at": "2026-08-02T04:07:27.202651+00:00",
66+
"reviewer": "learn.py",
67+
"rationale": "Remediation F2 on orama #260 PT #320; closes replay window and crash-after-edit gap."
68+
}
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
{
2+
"id": "d1f3789d4592",
3+
"key": "manual_d1f378",
4+
"name": "manual_d1f378",
5+
"claim": "Human-authorized PR body edits require operator-grant-v2 HMAC ack from grant-pr-body-human-override.sh matching append bytes \u2014 not CURSOR_PR_BODY_HUMAN_OVERRIDE_ACK env exports or operator-grant-v1 plaintext ack.",
6+
"conditions": [
7+
"ack",
8+
"append",
9+
"body",
10+
"bytes",
11+
"cursor_pr_body_human_override_ack",
12+
"edits",
13+
"env",
14+
"exports",
15+
"grant-pr-body-human-override",
16+
"hmac",
17+
"human-authorized",
18+
"matching",
19+
"operator-grant-v1",
20+
"operator-grant-v2",
21+
"plaintext",
22+
"require"
23+
],
24+
"evidence_ids": [
25+
"2026-08-02T04:07:28.486548+00:00"
26+
],
27+
"cluster_size": 1,
28+
"canonical_salience": 8.0,
29+
"staged_at": "2026-08-02T04:07:28.486548+00:00",
30+
"status": "accepted",
31+
"decisions": [
32+
{
33+
"ts": "2026-08-02T04:07:28.486548+00:00",
34+
"action": "staged",
35+
"reviewer": "learn"
36+
},
37+
{
38+
"ts": "2026-08-02T04:07:28.611464+00:00",
39+
"action": "graduated",
40+
"reviewer": "learn.py",
41+
"notes": "Supersedes env override lesson; v1 and env paths closed on orama #255 and grant v2 remediation.",
42+
"provisional": false,
43+
"evidence_snapshot": [
44+
"2026-08-02T04:07:28.486548+00:00"
45+
],
46+
"lessons_sha": "7cab2604b3de"
47+
}
48+
],
49+
"rejection_count": 0,
50+
"accepted_at": "2026-08-02T04:07:28.611439+00:00",
51+
"reviewer": "learn.py",
52+
"rationale": "Supersedes env override lesson; v1 and env paths closed on orama #255 and grant v2 remediation."
53+
}

.agent/memory/episodic/AGENT_LEARNINGS.jsonl

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -492,3 +492,8 @@
492492
{"timestamp": "2026-08-01T16:22:59.457445+00:00", "skill": "learn", "action": "manual-stage:64e972d330c2", "result": "success", "detail": "Manually staged lesson 64e972d330c2 via .agent/tools/learn.py: 'When markdownlint-cli2 v0.17.2 lints explicit file globs in CI, root .markdownlint.json filter overrides do not apply to catalog SKILL.md files outside the skills tree \u2014 add a per-directory .markdownlint-cli2.jsonc (e.g. line_length 500 for bin/orama-system/) and delete conflicting .markdownlint.json.'", "pain_score": 1, "importance": 6, "reflection": "", "confidence": 0.9, "source": {"skill": "learn", "profile": "manual", "run_id": "manual_64e972"}, "evidence_ids": ["2026-08-01T16:22:59.457445+00:00"]}
493493
{"timestamp": "2026-08-01T16:22:59.581970+00:00", "skill": "learn", "action": "manual-stage:82c94865243e", "result": "success", "detail": "Manually staged lesson 82c94865243e via .agent/tools/learn.py: 'Guard-sync divergence checks must discover workspace siblings via git -C path rev-parse --show-toplevel (not test -d path/.git), reject surplus CLI arguments with exit 2, fail-closed when check-guard-sync-divergence.sh is missing, and scan the full outgoing pre-push commit range for scripts/git/ touches.'", "pain_score": 1, "importance": 6, "reflection": "", "confidence": 0.9, "source": {"skill": "learn", "profile": "manual", "run_id": "manual_82c948"}, "evidence_ids": ["2026-08-01T16:22:59.581970+00:00"]}
494494
{"timestamp": "2026-08-01T16:22:59.706278+00:00", "skill": "learn", "action": "manual-stage:8c5f6349aa87", "result": "success", "detail": "Manually staged lesson 8c5f6349aa87 via .agent/tools/learn.py: 'PR body Layer 0: Cursor agents comment only (post_comment or gh pr comment). Body writes require an operator TTY grant via grant-pr-body-human-override.sh; only append-pr-body.sh is allowed after grant \u2014 never update_pr body=, gh pr edit, gh api body mutations, or agent-forgeable env exports.'", "pain_score": 1, "importance": 6, "reflection": "", "confidence": 0.9, "source": {"skill": "learn", "profile": "manual", "run_id": "manual_8c5f63"}, "evidence_ids": ["2026-08-01T16:22:59.706278+00:00"]}
495+
{"timestamp": "2026-08-02T04:07:27.047829+00:00", "skill": "learn", "action": "manual-stage:cd51f7e6bf6c", "result": "success", "detail": "Manually staged lesson cd51f7e6bf6c via .agent/tools/learn.py: 'PR-body operator grant v2 replay state machine: append-pr-body.sh must reserve nonce before gh pr edit, mark-applied only after remote success, consume last; release reservation on edit failure; reconcile CLI consumes when follow-up block already on remote (crash recovery). Never consume before gh pr edit succeeds.'", "pain_score": 1, "importance": 6, "reflection": "", "confidence": 0.9, "source": {"skill": "learn", "profile": "manual", "run_id": "manual_cd51f7"}, "evidence_ids": ["2026-08-02T04:07:27.047829+00:00"]}
496+
{"timestamp": "2026-08-02T04:07:27.549926+00:00", "skill": "learn", "action": "manual-stage:720dedfdd2c8", "result": "success", "detail": "Manually staged lesson 720dedfdd2c8 via .agent/tools/learn.py: 'operator-grant-v2 HMAC canonical payload is fixed-order UTF-8 bytes grant-v2|repo|pr|nonce|issued_at|action|content_digest with no trailing newline; mint and verify must use identical bytes; golden vector test locks regression.'", "pain_score": 1, "importance": 6, "reflection": "", "confidence": 0.9, "source": {"skill": "learn", "profile": "manual", "run_id": "manual_720ded"}, "evidence_ids": ["2026-08-02T04:07:27.549926+00:00"]}
497+
{"timestamp": "2026-08-02T04:07:28.049022+00:00", "skill": "learn", "action": "manual-stage:446162929cb3", "result": "success", "detail": "Manually staged lesson 446162929cb3 via .agent/tools/learn.py: 'Same-user Keychain HMAC for PR-body grants is escalation control not cryptographic human identity \u2014 agent shells with PTY can read the secret or ack file; MVP raises effort; WebAuthn deferred to security-sentinel v2.1.'", "pain_score": 1, "importance": 6, "reflection": "", "confidence": 0.9, "source": {"skill": "learn", "profile": "manual", "run_id": "manual_446162"}, "evidence_ids": ["2026-08-02T04:07:28.049022+00:00"]}
498+
{"timestamp": "2026-08-02T04:07:28.486548+00:00", "skill": "learn", "action": "manual-stage:d1f3789d4592", "result": "success", "detail": "Manually staged lesson d1f3789d4592 via .agent/tools/learn.py: 'Human-authorized PR body edits require operator-grant-v2 HMAC ack from grant-pr-body-human-override.sh matching append bytes \u2014 not CURSOR_PR_BODY_HUMAN_OVERRIDE_ACK env exports or operator-grant-v1 plaintext ack.'", "pain_score": 1, "importance": 6, "reflection": "", "confidence": 0.9, "source": {"skill": "learn", "profile": "manual", "run_id": "manual_d1f378"}, "evidence_ids": ["2026-08-02T04:07:28.486548+00:00"]}
499+
{"timestamp": "2026-08-02T04:07:28.914652+00:00", "skill": "learn", "action": "manual-stage:1a6dc6bccad0", "result": "success", "detail": "Manually staged lesson 1a6dc6bccad0 via .agent/tools/learn.py: 'Tracked .agent memory and working chronicles must not embed ephemeral scratch path literals \u2014 repo_hygiene flags them like workstation home paths and blocks PT CI.'", "pain_score": 1, "importance": 6, "reflection": "", "confidence": 0.9, "source": {"skill": "learn", "profile": "manual", "run_id": "manual_1a6dc6"}, "evidence_ids": ["2026-08-02T04:07:28.914652+00:00"]}

.agent/memory/semantic/DECISIONS.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,22 @@
33
> Record architectural or workflow choices that would be costly to re-debate.
44
> Use this template for each entry:
55
6+
## 2026-08-02: PR-body grant v2 remediation — replay state machine + honest MVP boundary
7+
8+
**Decision:** Close remediation review F1–F7 on paired branches orama #260 / PT #320. HMAC grant uses fixed-order UTF-8 canonical payload bytes; append flow is `reserve``gh pr edit``mark-applied``consume` with `reconcile` for crash recovery. Same-user Keychain HMAC is **escalation control**, not proof of human presence. Human override is `operator-grant-v2` ack file, not `CURSOR_PR_BODY_HUMAN_OVERRIDE_ACK` env exports.
9+
10+
**Rationale:** v1 plaintext ack and env override were forgeable; consume-before-remote left replay window; plan and memory had to stop claiming “signed human capability.” PT CI failed on ephemeral path literals in saga chronicle — tracked `.agent` memory follows same hygiene as workstation paths.
11+
12+
**Alternatives considered:** Consume nonce before remote edit (rejected — replay risk); WebAuthn in orama scripts (rejected — v2.1 sentinel orbit).
13+
14+
**Status:** active (pending merge of #260 and #320)
15+
16+
**Links:**
17+
- Saga: `.agent/memory/working/PR_BODY_GRANT_HMAC_MVP_SAGA_2026-08-02.md`
18+
- Decisions JSONL: `.agent/memory/working/PR_BODY_GRANT_HMAC_DECISIONS_2026-08-02.jsonl`
19+
- Plan: orama `docs/plans/2026-08-02-pr-body-grant-security-remediation.md`
20+
- CodeRabbit wave: `.agent/memory/working/CODERABBIT_REVIEW_WAVE_4835024659_4835288649_2026-08-01.md` (Batch G)
21+
622
## 2026-07-29: Periscope modernization — PR #20 over PR #17; never synthetic SHA replay
723

824
**Decision:** Close periscope PR #17 without merge. Preserve `cursor/agentsview-modernization-3way-f559` as a permanent bad-example branch. Integrate via PR #20 (`cursor/agentsview-purified-onto-kenn-f559`): original `kenn-io/agentsview` SHAs + 9 Periscope-unique cherry-picks, byte-identical tree to PR #17 tip.

0 commit comments

Comments
 (0)