You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Added
Add oh harness <list|install|status> to install optional harnesses into a running sandbox without a rebuild, persisting the choice to install.<key> for the next build (#821).
Add oh runtime <list|install|status>, reporting the container runtime in use and gating a MicroSandbox install on the measured glibc and /dev/kvm blockers. It selects no runtime (#823).
Add oh tool <list|install|status> for sandbox tooling that is neither an agent CLI nor a runtime, making agent-browser installable without a rebuild behind a ~1 GB download gate (#824).
Add oh stop|restart|logs|ps, closing the lifecycle gap where make had verbs the CLI did not, and publish one make vs oh mapping doc that the other docs link to (#825).
Document running Open Harness on MicroSandbox by pointing msb at the published image, and re-scope the microsandbox blockers as devcontainer measurements that say nothing about the reader's host.
Add a "which door am I?" table plus two guard probes: harness-yaml-schema-parity.sh and oh-init-headless-config.sh.
Add ssh.enabled/ssh.port and sandbox.docker_socket prompts to the oh init wizard, the two settings most likely to need hand-editing.
Require .oh/tasks/<slug>/evidence.md before /spec execute undrafts a PR, and refuse an untracked one, so the reviewer gets the build's answer back to the plan they approved (#817).
Add a "why this is better" question to the reviewer evidence contract, ahead of the four correctness questions, with unmeasured benefits labelled as such (#817).
Add protected-path-deletion.sh, which reads .claude/protected-paths.txt at the merge base and fails when a listed path is deleted without a justification in a committed evidence.md (#817).
Add memory-probe-claims-resolve.sh and context-tier-size-budget.sh to hold the memory ledger's enforcement claims and the always-on context budget (#817).
Changed
Run /eval once per cycle instead of three times: /spec execute publishes a commit-keyed eval-result.json the downstream gates read, cutting 318 probe executions to 110 (#817).
Promote progress.txt into the PR body, so the build narrative reaches the reviewer instead of ending at the STATUS: COMPLETE sentinel (#817).
Write install.sh's non-secret answers to harness.yaml rather than the lower-precedence .devcontainer/.env, keeping DOCKER_SOCKET in .env as a documented exception.
Lead the README and quickstart with the two scripted installers and demote the untested manual clone sequence into the collapsed section, merging its two duplicate copies into one.
Fixed
Match the release-notes heading with index() instead of a regex built by string concatenation, so extraction does not depend on whether the runner's awk is mawk or gawk (#820).
Fix the build session launching headless: the prompt travels as argv instead of stdin and no arm carries --print, so the child no longer answers once and exits (#817).
Stop | tee in the launch path taking the child's TTY; tmux attaches pipe-pane after the pane exists and foreground mode inherits the caller's stdio (#817).
Fix firstmate.sh --kill exiting 1 silently while leaving the session running, the lock claimed, and no FIRSTMATE-INCOMPLETE line appended (#817).
Stop the /audit boundary exporting its lifecycle identity to the agent it launches, which made probes grade their caller and flipped one tree's verdict between runs (#817).
Rewrite 76 unbacked probe: claims in the memory ledger to explicit probe: none via a tracked idempotent script (#817).
Correct the MicroSandbox runner walkthrough: set entrypoint: explicitly, without which the seed and provider linking never run; drop the unsubstituted GH_TOKEN; and re-rank the untested inferences so the boot-breaking one leads.
Collapse the two disagreeing harness.yaml line editors into one setKeyInSection in lib/harness-yaml.ts; the wizard's section-blind copy silently dropped answers for keys absent from the template.
Reconcile .oh/templates/harness.yaml with harness.yaml.example, restoring the sandbox.docker_socket/image/pull_policy, paths.worktrees, crons, autopilot, slack, and compose keys that had no home to be written into.
Correct harness.yaml.example's claim that pull_policy reaches the VS Code "Reopen in Container" path — it does not, and no key in the file does.
Removed
Remove the critique/approve gate; the operator's approval of prd.md is the commitment gate, and no critic agents are spent per plan (#817).
Collapse three build executors to one, deleting .oh/scripts/ralph.sh and every executor toggle rather than reducing them to a single accepted value (#817).
Absorb /ship-spec into /spec execute and delete the skill, so the build mechanics read top to bottom in one file with no deferral (#817).
Delete .oh/prompts/, .pi/prompts/advisor/, and the First Mate charter, leaving .oh/skills/firstmate/templates/session-prompt.md as the only description of the build workflow (#817).
Delete /teach and its pipeline step; evidence.md carries the model to the reviewer, and the wiki half was already a gate in step 5 (#817).
Delete the DeepWiki comparison from the wiki gate, which regenerates on no schedule the gate can depend on, and rename the schema section to state its own requirements (#817).
Delete four STATUS: SPEC-* tokens with no executable consumer and drop the groom triad from the per-cycle path (#817).