The previous wording implied a global max_depth-style setting had been
considered generically; the only such key in Codex's schema is
network_proxy.glob_scan_max_depth, which bounds glob expansion for the
network proxy feature and has nothing to do with agents. Claude Code
exposes no comparable key either.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bash's manifest reader stripped only the trailing newline, so a
CRLF-terminated manifest left a stray \r on every hash, a UTF-8 BOM on the
header line was folded into the "path" field, and an uppercase hash never
matched sha256sum's lowercase output. Reproduced against a real
manifest written by an earlier version of the PowerShell installer, where
every single managed file was misreported as locally modified.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Windows PowerShell 5.1's -Encoding UTF8 always prepends a BOM, and
Get-FileHash returns uppercase hex. Bash's manifest reader expects neither,
so a manifest written by this module and later read by the Bash
equivalent (or vice versa) mismatched on every single entry: the BOM
folded into the header's first field, and every hash comparison failed on
case alone. Hashes are now lowercased on read and write, and the manifest
file itself is written UTF-8 without a BOM.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
doctor.ps1 already exited 1 on failure but relied on the implicit process
exit code on success, which a stale $LASTEXITCODE from an earlier native
call (e.g. codex --version) could turn into a false failure in CI.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Without it, a stale $LASTEXITCODE left over from an earlier native
command in the same PowerShell session could cause a CI step to be
reported as failed even though the script itself completed successfully.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
All tracked .sh files were stored as mode 100644 (non-executable), even
though the CI workflow and normal usage invoke several of them directly
(./scripts/build.sh) rather than through `bash`. On a fresh Linux
checkout this fails with a permission error.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Runs build, doctor, the platform-package tests, the managed-manifest
tests, the build-validation tests, and an install dry run on both
ubuntu-latest and windows-latest for every push to main and every pull
request.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Only the Stop hook (flashbang) is wired into the generated client
configuration. Validate-CommandSafety and Invoke-PostChangeVerification
are utility scripts nothing here invokes automatically; the previous
wording could be read as implying otherwise.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
tkinter was imported at module level, before the try/except that was
meant to catch a missing display or toolkit. On a Python install without
the (often separately packaged) tkinter module, the script crashed
instead of falling back to notify-send. The import is now wrapped in its
own try/except with the same fallback.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The Stop hook only runs a ~500ms visual flash; 20 seconds was far more
than any realistic process-start latency needs, including the one-time
native shim compile on Windows.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
max_threads is a legacy alias; the current Codex config sample only
documents max_concurrent_threads_per_session under [agents]. Confirmed
against the official sample configuration before renaming.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bash equivalent of the PowerShell build-validation test, using a tar-based
repo copy per case to check the same four rejected-defect scenarios.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Runs the build against temporary full-repo copies, each with one injected
defect, and asserts the build rejects it: invalid Claude settings.json,
a duplicate agent name, a duplicate plugin name, and a leftover template
placeholder.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bash equivalent of the PowerShell managed-manifest test, covering the same
idempotency, stale-removal, modified-file-protection, foreign-file, and
side-effect-free dry-run scenarios against sync_managed_destination.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Exercises Sync-ManagedDestination directly against a throwaway
source/destination pair: idempotent second install (no writes, no
backups), removal of a stale-and-untouched file, protection of a
stale-but-locally-modified file (backed up, left in place, warned), a
foreign file that was never installed staying untouched, and a dry run
that reports the planned removal without any side effects.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bash equivalent of the PowerShell doctor change: dynamic agent/skill count
checks, JSON validation of installed settings.json (jq, falling back to a
functional python3 probe), a config.toml balance check, a fast tree-wide
placeholder scan, and managed-manifest missing/modified-file reporting.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Doctor now compares generated agent/skill counts against the source
directories and the rule-skills manifest, parses installed settings.json
as JSON, sanity-checks installed config.toml for balanced quotes and
brackets, scans generated output for leftover template placeholders, and
reports missing or locally modified files from each destination's managed
manifest. All checks stay local and file-based; no network calls.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bash equivalent of the PowerShell installer change: delegates to
sync_managed_destination, adds --client/--platform for non-interactive
runs (falling back to the existing interactive prompts when omitted), and
requires --update-plugins to update already-installed plugins instead of
doing so by default.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
install.ps1 now delegates every destination to Sync-ManagedDestination
instead of a blind copy-and-backup loop, so repeated installs are cheap
and safe by default.
Adds -Client and -Platform parameters so CI or scripts can run fully
non-interactively (install.ps1 -Client Both -Platform Windows); both fall
back to the existing interactive prompts when omitted. Plugin updates now
require an explicit -UpdatePlugins switch instead of always updating
already-installed plugins, so a configuration update never silently
changes third-party plugin code.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bash equivalent of the PowerShell manifest module: sync_managed_destination
plus its read/write/hash helpers, using sha256sum and a TSV manifest so
the same idempotent-install, stale-detection, and local-modification
protection behavior is available without a PowerShell dependency.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds Sync-ManagedDestination and its manifest helpers: a per-destination
TSV of path -> SHA-256 that makes installation idempotent (unchanged files
are neither rewritten nor backed up), detects files this setup previously
installed that the source no longer ships (removed after backup, unless
changed locally, in which case they are backed up and left in place with
a warning), and never touches a file it never installed. Backups for a
run land together under backups/<stamp>/ instead of one suffix per file.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bash equivalent of the PowerShell test change. Also relaxes the platform
dry-run assertion to match on "-$platform" instead of "-$platform/", since
the installer now reports one destination summary line per sync instead of
one line per copied file.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Replaces the hardcoded 5-agent/22-skill expectations with counts computed
from shared/agents, shared/skills, and the new rule-skills manifest, so
adding an agent, skill, or Claude rule skill no longer requires touching
an unrelated magic number in this test.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Bash equivalent of the PowerShell build change: Claude gets general.md
inlined into CLAUDE.md plus one generated skill per rule-skills.tsv entry;
Codex keeps every rule as a plain file with unchanged AGENTS.md text.
Adds the same build-time validation as the PowerShell script: duplicate
agent/plugin/rule-skill names, JSON validity (jq, falling back to a
functional python3 probe), balanced TOML quotes/brackets, and a
tree-wide (not per-file) leftover-placeholder scan for speed.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude's package now gets general.md inlined into CLAUDE.md plus one
generated skill per rule-skills.tsv entry under skills/rules/, instead of
copying every rule file into the always-loaded rules/ directory. Codex is
unaffected: it still receives every rule as a plain file and the original
rule-loading text, byte-for-byte.
Also adds build-time validation: duplicate agent/plugin/rule-skill names
fail the build, generated settings.json must parse as JSON, generated
config.toml must have balanced quotes/brackets, and no __PLACEHOLDER__
tokens may remain unresolved (__AI_CONFIG_ROOT__ excepted, since it is
only resolved at install time).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds adapters/claude/rule-skills.tsv, mapping each technology- or
situation-specific rule to a Claude skill name and trigger description.
Replaces the hardcoded rule-loading block in the shared instructions
template with a __RULE_LOADING__ placeholder so each client's build step
can substitute its own loading mechanism without duplicating the shared
orchestration text.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Ensures shell scripts keep LF and PowerShell scripts keep CRLF across
Windows and Linux checkouts.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>