Repository navigation
Fixed
- Resolve Git readonly-file instructions conflicting with authorized repository operations. Normal requested staging, commit and push are allowed; force pushes, deletion refspecs and prune require exact-command approval. Remaining destructive denials and active-writer restrictions are retained.
- Add DevOps direct native claim access and align writer ask/deny, coordinator and reviewer/security guidance.
- Add all-17 agent contract tests, runtime/generated identity checks and isolated native Git/DevOps acceptance; regenerate agents and update knowledge.
Verification
679 tests, lint/typecheck/build, sync/package/release gates, 4 e2e tests and Linux/macOS CI PASS.
Both rebuilt OpenCode 2.0.24 isolated smokes PASS, including local bare push without approval, rejected force approval with no execution/retry, active-lease restrictions and DevOps claim/edit plus four denials. Cleanup PASS; no external push or production/global changes.
Deep review and Security APPROVE after remote-deletion/prune approval fix; metadata review APPROVE.
Limits
Explicit task intent remains model guidance. Wildcard permission rules are not exhaustive shell-safety enforcement; expanded-rule redundancy remains advisory. All-agent contract tests do not imply an individual live run of every agent. No dependency/compatibility or global installation changes.
PR: #17