Skip to content

feat(plugin): 1.7.0 — /lua-devices, device credentials, lua-cli 3.44/3.45 re-check - #16

Merged
lua-stefan-kruger merged 2 commits into
mainfrom
stefan/devices-skill
Oct 5, 2026
Merged

lua-stefan-kruger merged 2 commits into
mainfrom
stefan/devices-skill

Conversation

@lua-stefan-kruger

Copy link
Copy Markdown
Contributor

Summary

Some commands need lua-cli 3.45.0 (in review); fallbacks documented.

This release adds a devices slash and re-checks the plugin against lua-cli 3.44.0 (npm latest) and 3.45.0 (in review). Before starting, I confirmed the installed 1.6.0 copy is identical to main.

Security fixes (please review first)

  • Production-gate bypass. Since lua-cli 3.44.0, lua skills production deploy --skill-name x --skill-version y deploys non-interactively. The same goes for the prod/prd/live × deploy/publish spellings. lib/tokenizer.mjs did not classify any of them, so confirm-deploy let them through.
    • They are now production verbs with a smoke label.
    • The prefixed form is allowed.
    • The mirror test covers every spelling.
  • New hook block-device-secret. It blocks lua devices credential|credentials|key unless --out <file> is given, because the CLI otherwise prints the secret into the conversation.
    • An out target of /dev/stdout or /proc/… does not count.
    • The message is headless-safe.
    • Coverage is 100%.
    • lint-cli-flags also fails on any shipped credential command without --out.
  • New permission ask rows:
    • mutating lua devices verbs and all their aliases;
    • lua push device* and every push-type alias, carved out of the generic push allow, because a pushed defineDevice is live on the next turn;
    • lua logs export, which lua logs --ci export used to reach through the lua logs --ci* allow rule;
    • lua drains confirm|replay.
    • Existing projects must re-run /lua-doctor to merge these. Until they do, /lua-devices and /lua-push detect the missing row and stop.

New

  • commands/lua-devices.md (/lua-devices): a guided setup plus list, status, credential, client, push, test, test-trigger, logs, enable, disable, remove and troubleshoot. It covers:
    • self-describing vs defineDevice;
    • issuing a credential with --out into a git-ignored mode-600 file that is never read back;
    • Node, Python and Pico W client scaffolds;
    • going live: a pushed device is live on the next turn, and a device-trigger is published only by --auto-deploy, which stays denied, so the line is printed for the user's own terminal;
    • testing and logs;
    • troubleshooting: AUTH_FAILED with a scoped key, MQTT CONNACK rc=5, offline after disable then enable, DEVICE_OFFLINE, TIMEOUT, and the 24 h command-list expiry.
    • Every 3.45-only verb names its 3.44 fallback.
  • lib/knowledge/devices.md: the 3.44 vs 3.45 action matrix, credentials, go-live, clients, limits and troubleshooting.
  • hooks/block-device-secret.mjs, with its test.

Stale behaviour fixed (lua-cli 3.44.0)

  • Devices and device-triggers were routed through an agent-version promote. Devices are not part of agent versions, so this did nothing.
  • lua push agent now stages the persona, and promote re-points the persona to the version's pin. The pilot now deploys it, or on a versioned agent pins it with --persona-version and then promotes.
  • lua push all no longer activates workflows.
  • push all and deploy all exit 1 on a failed item, and a lua test that throws exits non-zero.
  • 3.44's lua devices test and test-trigger always prompt, so they are not usable under --ci.
  • Integrations: the --hide-sensitive default flipped to false, and --interval now accepts 1–2880.
  • lua drains: six new destination types plus confirm and replay.
  • lua evals now has verbs.

Test plan

  • LUA_CLI_SRC=…/lua-cli npm run lint: all 17 lints pass, including lint-knowledge-commands against the 3.45.0 source.
  • npm run test:coverage: 855 tests pass, hooks are at 100% and lib at 90% or more.
  • mcp/lua-platform: 149 tests pass. The bundle was rebuilt (0.50 MB) and the standalone check confirms 1.7.0.
  • I spawned confirm-deploy and block-device-secret against every command /lua-devices emits. All pass, except the intended blocks.
  • Not yet run: a live /lua-devices setup against a real device on lua-cli 3.45.0, once it is published.

Version 1.6.0 → 1.7.0, with a CHANGELOG entry. The repo has no eval suite; its checks are the lints and the jest tests. Please don't merge until the persona and device routing is reviewed.

🤖 Generated with Claude Code

lua-stefan-kruger and others added 2 commits October 5, 2026 14:46
…3.45 re-check

New /lua-devices slash and lib/knowledge/devices.md. They cover:
- choosing self-describing vs defineDevice;
- issuing a device credential only with --out, into a git-ignored mode-600 file;
- Node / Python / Pico W client scaffolds;
- push and go-live (devices are not part of agent versions);
- status / test --command / test-trigger --trigger, and device logs;
- troubleshooting.
Some commands need lua-cli 3.45.0 (in review); each one documents its 3.44 fallback.

Security:
- New block-device-secret hook: refuses `lua devices credential` without --out.
- The new non-interactive `lua skills production deploy` (lua-cli 3.44.0) is now a gated production verb.
- `lua push device*`, the mutating `lua devices` verbs, `lua logs export` and `lua drains confirm|replay` now sit in the ask tier.

Stale against lua-cli 3.44.0, fixed:
- device go-live (it was routed through an agent-version promote);
- persona staging on push;
- push-all workflow activation;
- push/deploy all and lua test exit codes;
- the devices test prompts;
- the integrations --hide-sensitive default and --interval range;
- drain types and verbs;
- lua evals verbs.

Bump 1.6.0 -> 1.7.0; dist/server.js rebuilt.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… --out targets

- block-device-secret names no slash command under LUA_PLUGIN_HEADLESS=1. headless.test.mjs now covers it.
- An --out target under /dev/ or /proc/ (/dev/stdout, /dev/fd/1, /dev/tty) no longer counts as an out file.
- /lua-devices and /lua-push check for the 1.7.0 `lua push device` ask row. If it is missing, they stop and point at /lua-doctor: in a project merged under 1.6.0 the push would go live unprompted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@richard-lua richard-lua left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review — LOW risk

This release is primarily documentation (device knowledge base, command specs, CHANGELOG) plus two focused security-hardening code changes: a new lib/tokenizer.mjs rule classifying lua skills production deploy (closing a real gate-bypass introduced by lua-cli 3.44.0) and a new block-device-secret PreToolUse hook that prevents lua devices credential from printing a device secret into the conversation. Both are well-tested (new hook at 100%, mirror tests extended across canonical/alias/mixed-case spellings), the permission template's new ask rows correctly carve go-live device pushes out of the generic push allow, and the versions/lockfiles are bumped consistently. The change strengthens the safety model rather than weakening it. Findings below are advisory.

Minor

  • hooks/block-device-secret.mjs:21 — The terminal-target guard only rejects /dev/ and /proc/ literals. A --out target that resolves to the terminal through a symlink or a shell substitution ($(tty)) would pass and still leak the secret. Treat a dynamic --out value (containing $(, backtick, ${) as "no safe out file" and fail closed, mirroring the tokenizer's dynamic-token handling.
  • lib/permissions-template.json:170 — New ask rows (device go-live push, credential, logs export) only apply after a user re-runs /lua-doctor to merge them into their own settings. Until then a direct lua push device / lua logs --ci export rides the old broad allow rules with no confirmation. The in-command detect-and-stop guard mitigates this for slash flows; make the stale-permissions warning prominent in /lua-doctor output and upgrade notes.
  • lib/permissions-template.json:191 — Bash(lua logs * export*) is broad enough to turn an ordinary lua logs read into an ask prompt if an argument value contains the token export. Tighten the glob or add a mirror test asserting reads with 'export' in a value are not caught.

Otherwise the change looks solid and safe to merge once the advisory items are considered.


PR Risk Reviewer — automated senior review of f0cca19 · risk: low · confidence: 0.72

@lua-stefan-kruger
lua-stefan-kruger merged commit e967dce into main Oct 5, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants