docs: a negative result is usually your own filter (skill + AGENTS.md)
Three false negatives in one session, all self-inflicted, all convincing because the command "succeeded": a `| head -20` proved an SSH peer absent that sits at line 454 of a ~500-line config; `ssh mac 'docker ps'` proved the host had no Docker, when the non-interactive PATH simply lacks /usr/local/bin; and `grep 'ssh '` proved no ControlMaster was running, when those processes rename themselves to `ssh: <path> [mux]`. Same root cause each time, so it goes in the skill rather than in a commit message: a positive result carries its own evidence, absence has to be earned. The skill (rootfs/, symlinked into ~/.agents/skills) is BAKED, so this is an image change and is logged in CHANGELOG Unreleased accordingly. Its §3 also now records that a live ControlMaster socket makes later commands authenticate not at all -- after editing a peer's authorized_keys, "it still works" proves nothing; prove it with -o ControlPath=none, or the breakage waits for a future session that has no memory of the edit. AGENTS.md: corrected a stale CI claim while placing the pointer. It said a tag push produces two runs including lint; lint.yml has since been scoped to branches: ['**'], which excludes tag refs, and refs/tags/v1.8.4 duly produced run 571 (publish) and nothing else. Kept the head_sha + workflow path filter advice, which is cheap and guards against a future v*-triggered workflow. Added a short section on verifying this repo from inside a container, including that docker-compose.yml here is a TEMPLATE pinning :latest while a real host runs its own per-machine file -- recreating from the repo copy can silently move a host off :latest-studio. Placement note: AGENTS.md is only auto-read when the cwd is this repo, so the durable rule lives in the skill, which loads by description match in any pi-devbox session.
This commit is contained in:
@@ -11,6 +11,42 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
|
||||
|
||||
---
|
||||
|
||||
## Unreleased
|
||||
|
||||
Docs only so far, but one of the two files ships **inside** the image.
|
||||
|
||||
### Changed
|
||||
|
||||
- **`pi-devbox-environment` skill — new §2 subsection "A negative result is
|
||||
usually your own filter", plus ControlMaster masking in §3.** This is baked
|
||||
(`rootfs/usr/local/share/pi-devbox/skills/`, symlinked to
|
||||
`~/.agents/skills/`), so it is an image-behaviour change even though no
|
||||
package moved. Motivated by three false negatives an agent produced in a
|
||||
single session, each from its own filter rather than from the world: a
|
||||
`| head -20` "proved" an SSH peer absent that was defined at **line 454** of a
|
||||
~500-line config; `ssh mac 'docker ps'` "proved" the host had no Docker, when
|
||||
the non-interactive SSH `PATH` simply lacks `/usr/local/bin`; and a `grep 'ssh
|
||||
'` "proved" no ControlMaster was running, when master processes **rename
|
||||
themselves** to `ssh: <controlpath> [mux]`. The rule now stated: a positive
|
||||
result carries its own evidence, absence has to be *earned*. §3 additionally
|
||||
documents that a live master socket makes later commands authenticate **not at
|
||||
all**, so "it still works" proves nothing after editing a peer's
|
||||
`authorized_keys` — verify with `-o ControlPath=none -o ControlMaster=no`, or
|
||||
the breakage surfaces in a future session with no memory of the edit.
|
||||
- **`AGENTS.md`: a stale CI claim corrected.** It said "a tag push produces two
|
||||
runs, not one — `lint.yml` fires on every push (including tag refs)". That
|
||||
stopped being true when lint was scoped to `branches: ['**']`, which excludes
|
||||
tag refs by design; `refs/tags/v1.8.4` produced run 571 (publish) and nothing
|
||||
else. The `head_sha` + workflow-`path` filter advice stays, because it costs
|
||||
nothing and any future `v*`-triggered workflow would reintroduce the
|
||||
ambiguity. Also adds a short "Verifying this repo's reality from inside a
|
||||
container" section, including the trap that **this repo's `docker-compose.yml`
|
||||
is a template pinning `:latest`** while a real host runs its own per-machine
|
||||
file — so recreating from the repo copy can silently move a host off
|
||||
`:latest-studio`.
|
||||
|
||||
---
|
||||
|
||||
## v1.8.4 — 2026-08-22
|
||||
|
||||
Patch release, and the one that ends an eight-week bug: **the baked
|
||||
|
||||
Reference in New Issue
Block a user