Skip to content

feat(exec): raw-exec guard matches the real process; LOOK-debt guard refuses page-creating scripts (#228 #232) - #257

Draft
MendixMau wants to merge 2 commits into
masterfrom
feat/exec-raw-and-look-guards
Draft

MendixMau wants to merge 2 commits into
masterfrom
feat/exec-raw-and-look-guards

Conversation

@MendixMau

Copy link
Copy Markdown
Owner

What changed and why

Draft until one field run on a laptop (instrument rule 4). Two commits, two guards in project-bin/exec.sh.

#228 raw-exec guard (project-bin/_common.sh gains mxtk_proc_list and mxtk_raw_exec_on). A process counts only when argv0 is mxcli/mxcli.exe, exec is an argument, and the args name this model's path or file name. The exec.sh shell's own ancestors and descendants are excluded by pid from one process snapshot (the $(...) subshells running the check used to show up under the caller's argv and made the guard refuse itself). A confirmed raw exec on the same model refuses with exit 1 and a BUILD-LOG row; FORCE_EXEC=1 overrides; MXTK_NO_RAW_GUARD=1 opts out. When no process list is available it warns and continues. Fixture tests/wave2/test-exec-raw-guard.sh 10/10, fails 4 against the pre-fix exec.sh.

#232 LOOK-debt guard (supersedes #188). project-bin/look-ledger.sh gains unseen and creates. exec.sh step 4b refuses a script that CREATEs pages (exit 3, BUILD-LOG row) when more than LOOK_OWED_MAX (default 5, 0 = off) built pages are unseen. These pass: ALTER-only scripts, --patch, a -- PROOF-OF-LOOK line in the first 30 script lines, a Waived obligation look/<Module or Module.Page> register line or a PROOF-OF-LOOK citation in a ui-review report, FORCE_EXEC=1, MXTK_NO_LOOK_GUARD=1. With no look-ledger Read hook in .claude/settings*.json it warns once and steps aside. Fixture tests/wave2/test-exec-look-guard.sh 17/17, fails 4 against the pre-fix exec.sh; existing test-look-ledger.sh 11/0.

Not in this PR: gate-check.sh Stage 5 still computes its own inline unseen count (size cap); the #232 residuals (fidelity mean/floor gate, content-aware Stage 6, owed count in build-plan-status, stub-overwrite guard, breadcrumb skill edits) stay open.

Field evidence

None yet. Fixtures only. The Windows process probe (PowerShell Get-CimInstance) is unexercised; the Linux fixture parses this host's real ps output rather than a committed golden capture.

Checklist

  • Size cap: 6 files excluding fixtures and CHANGELOG
  • Test tier: T1 (shell fixtures with fake mxcli and mxbuild); needs a T2 field run before relying on the LOOK threshold
  • Instrument rules: accepts outside evidence (PROOF-OF-LOOK, waivers, ui-review citations); never blocks the remedy (ALTER and --patch pass; env opt-outs); both layouts via _common.sh roots; Windows branch guarded but unrun
  • CHANGELOG line per commit under Unreleased
  • bash -n, check-portability, check-scripts 102/102, leak guard, check-pr-discipline clean

🤖 Generated with Claude Code

https://claude.ai/code/session_01VJgWP5vEoAsNsJYqCDMGNw


Generated by Claude Code

claude added 2 commits October 8, 2026 15:13
…s safely (#228)

Replaces `pgrep -fl "mxcli exec" | grep -qv $$` (substring match on every process, no log row,
absent under Git Bash) with mxtk_proc_list + mxtk_raw_exec_on in _common.sh: argv0 is mxcli, `exec`
is an argument, args name this model, own ancestry/descendants excluded by exact pid. A hit logs a
BUILD-LOG row and refuses (FORCE_EXEC=1 overrides); no process list -> warn and continue.
MXTK_NO_RAW_GUARD=1 opts out. Windows branch (PowerShell CIM) is unexercised here: no Windows host,
no golden capture committed; the fixture asserts parsing on the host's real ps output instead.

Checked: bash -n, check-portability, check-scripts, leak guard clean; test-exec-raw-guard.sh 10/10
(against the pre-fix exec.sh 4 cases fail).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VJgWP5vEoAsNsJYqCDMGNw
…WED_MAX unseen (#232)

Supersedes #188 (its shipped parts are #193/#191). look-ledger.sh gains `unseen` (OWED rows not
cleared by a PROOF-OF-LOOK report citation or a `Waived obligation look/...` register line) and
`creates` (CREATE-only page list). exec.sh step 4b refuses (exit 3, BUILD-LOG row) a script that
CREATEs pages while unseen > LOOK_OWED_MAX (default 5, 0 = off). ALTER-only scripts and --patch
pass; a `-- PROOF-OF-LOOK` line in the first 30 script lines, FORCE_EXEC=1 and MXTK_NO_LOOK_GUARD=1
lift it; no Read hook in .claude/settings*.json -> warn once, continue. gate-check.sh Stage 5 keeps
its own inline join (not refactored here); build-plan-status/fidelity-floor residuals untouched.
No field run yet: fixture only (the pre-fix exec.sh fails the refusal cases).

Checked: bash -n, check-portability, check-scripts, leak guard clean; test-exec-look-guard.sh 17/17;
test-exec-raw-guard.sh 10/10; test-look-ledger.sh result above.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VJgWP5vEoAsNsJYqCDMGNw
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants