Skip to content

v0.1.24 — gate-caught classification fixes

Choose a tag to compare

@androidStern androidStern released this 10 Jun 13:22
· 13 commits to main since this release

Gate-caught classification fixes

The v0.1.23 VM release gates caught two honesty bugs in the published artifact;
this release fixes them and re-runs the gates.

What was broken (user-visible):

  • A signed-out X user was told "Retry shortly — this is usually a temporary X
    or network failure" instead of "Open x.com in Chrome and sign in". The
    product's own "auth cookies missing" message wasn't recognized as a
    signed-out state, so it mis-classified as blocked_bug instead of
    needs_auth.
  • Before the Notes automation prompt is answered, Apple events time out with
    AppleEvent -1712; this classified as blocked_bug ("looks like a Nutshell
    bug") instead of needs_permission with the approve-automation fix.

Root cause: classification regexes in the X session checker and the Notes
permission-error matcher missed these two real-world strings; both were found
by the signed-out and permissions-pre VM gates running against v0.1.23, with
frozen evidence reports.

Also fixed (harness, not product): the permissions-pre gate contract now
encodes macOS reality — Chrome's cookie store is not Full-Disk-Access
protected (browser sources may legitimately pass pre-grant) and a fresh VM has
no Podcasts library; the gate asserts the FDA root cause, Notes
needs_permission, and Podcasts needs_permission-or-honest-no-library. The
signed-out gate now accepts only *_signed_out codes with needs_auth
guidance. New contracts were replay-verified against the frozen v0.1.23
evidence before this release.

Validation status: local certification passed (typecheck, 246 tests, lint,
builds, tarball, certify). Split gates re-run against this artifact follows;
permissions-post + live-sync remain queued on the one-time post-permission
snapshot session. Install paths: Homebrew tap and tarball (npm deferred).
Dependency fence: unchanged.