docs: a negative result is usually your own filter (skill + AGENTS.md)
Lint / hadolint (push) Successful in 13s
Lint / actionlint (push) Successful in 16s

Three false negatives in one session, all self-inflicted, all convincing
because the command "succeeded": a `| head -20` proved an SSH peer absent
that sits at line 454 of a ~500-line config; `ssh mac 'docker ps'` proved
the host had no Docker, when the non-interactive PATH simply lacks
/usr/local/bin; and `grep 'ssh '` proved no ControlMaster was running,
when those processes rename themselves to `ssh: <path> [mux]`. Same root
cause each time, so it goes in the skill rather than in a commit message:
a positive result carries its own evidence, absence has to be earned.

The skill (rootfs/, symlinked into ~/.agents/skills) is BAKED, so this is
an image change and is logged in CHANGELOG Unreleased accordingly. Its §3
also now records that a live ControlMaster socket makes later commands
authenticate not at all -- after editing a peer's authorized_keys, "it
still works" proves nothing; prove it with -o ControlPath=none, or the
breakage waits for a future session that has no memory of the edit.

AGENTS.md: corrected a stale CI claim while placing the pointer. It said a
tag push produces two runs including lint; lint.yml has since been scoped
to branches: ['**'], which excludes tag refs, and refs/tags/v1.8.4 duly
produced run 571 (publish) and nothing else. Kept the head_sha + workflow
path filter advice, which is cheap and guards against a future v*-triggered
workflow. Added a short section on verifying this repo from inside a
container, including that docker-compose.yml here is a TEMPLATE pinning
:latest while a real host runs its own per-machine file -- recreating from
the repo copy can silently move a host off :latest-studio.

Placement note: AGENTS.md is only auto-read when the cwd is this repo, so
the durable rule lives in the skill, which loads by description match in
any pi-devbox session.
This commit is contained in:
Joakim Persson
2026-08-22 22:56:41 +02:00
parent 2ebf00d6d4
commit fbc1f86612
3 changed files with 124 additions and 4 deletions
+36
View File
@@ -11,6 +11,42 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
---
## Unreleased
Docs only so far, but one of the two files ships **inside** the image.
### Changed
- **`pi-devbox-environment` skill — new §2 subsection "A negative result is
usually your own filter", plus ControlMaster masking in §3.** This is baked
(`rootfs/usr/local/share/pi-devbox/skills/`, symlinked to
`~/.agents/skills/`), so it is an image-behaviour change even though no
package moved. Motivated by three false negatives an agent produced in a
single session, each from its own filter rather than from the world: a
`| head -20` "proved" an SSH peer absent that was defined at **line 454** of a
~500-line config; `ssh mac 'docker ps'` "proved" the host had no Docker, when
the non-interactive SSH `PATH` simply lacks `/usr/local/bin`; and a `grep 'ssh
'` "proved" no ControlMaster was running, when master processes **rename
themselves** to `ssh: <controlpath> [mux]`. The rule now stated: a positive
result carries its own evidence, absence has to be *earned*. §3 additionally
documents that a live master socket makes later commands authenticate **not at
all**, so "it still works" proves nothing after editing a peer's
`authorized_keys` — verify with `-o ControlPath=none -o ControlMaster=no`, or
the breakage surfaces in a future session with no memory of the edit.
- **`AGENTS.md`: a stale CI claim corrected.** It said "a tag push produces two
runs, not one — `lint.yml` fires on every push (including tag refs)". That
stopped being true when lint was scoped to `branches: ['**']`, which excludes
tag refs by design; `refs/tags/v1.8.4` produced run 571 (publish) and nothing
else. The `head_sha` + workflow-`path` filter advice stays, because it costs
nothing and any future `v*`-triggered workflow would reintroduce the
ambiguity. Also adds a short "Verifying this repo's reality from inside a
container" section, including the trap that **this repo's `docker-compose.yml`
is a template pinning `:latest`** while a real host runs its own per-machine
file — so recreating from the repo copy can silently move a host off
`:latest-studio`.
---
## v1.8.4 — 2026-08-22
Patch release, and the one that ends an eight-week bug: **the baked