Repository navigation
feat(plugin): 1.7.0 — /lua-devices, device credentials, lua-cli 3.44/3.45 re-check - #16
Conversation
…3.45 re-check New /lua-devices slash and lib/knowledge/devices.md. They cover: - choosing self-describing vs defineDevice; - issuing a device credential only with --out, into a git-ignored mode-600 file; - Node / Python / Pico W client scaffolds; - push and go-live (devices are not part of agent versions); - status / test --command / test-trigger --trigger, and device logs; - troubleshooting. Some commands need lua-cli 3.45.0 (in review); each one documents its 3.44 fallback. Security: - New block-device-secret hook: refuses `lua devices credential` without --out. - The new non-interactive `lua skills production deploy` (lua-cli 3.44.0) is now a gated production verb. - `lua push device*`, the mutating `lua devices` verbs, `lua logs export` and `lua drains confirm|replay` now sit in the ask tier. Stale against lua-cli 3.44.0, fixed: - device go-live (it was routed through an agent-version promote); - persona staging on push; - push-all workflow activation; - push/deploy all and lua test exit codes; - the devices test prompts; - the integrations --hide-sensitive default and --interval range; - drain types and verbs; - lua evals verbs. Bump 1.6.0 -> 1.7.0; dist/server.js rebuilt. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… --out targets - block-device-secret names no slash command under LUA_PLUGIN_HEADLESS=1. headless.test.mjs now covers it. - An --out target under /dev/ or /proc/ (/dev/stdout, /dev/fd/1, /dev/tty) no longer counts as an out file. - /lua-devices and /lua-push check for the 1.7.0 `lua push device` ask row. If it is missing, they stop and point at /lua-doctor: in a project merged under 1.6.0 the push would go live unprompted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
richard-lua
left a comment
There was a problem hiding this comment.
Code review — LOW risk
This release is primarily documentation (device knowledge base, command specs, CHANGELOG) plus two focused security-hardening code changes: a new lib/tokenizer.mjs rule classifying lua skills production deploy (closing a real gate-bypass introduced by lua-cli 3.44.0) and a new block-device-secret PreToolUse hook that prevents lua devices credential from printing a device secret into the conversation. Both are well-tested (new hook at 100%, mirror tests extended across canonical/alias/mixed-case spellings), the permission template's new ask rows correctly carve go-live device pushes out of the generic push allow, and the versions/lockfiles are bumped consistently. The change strengthens the safety model rather than weakening it. Findings below are advisory.
Minor
hooks/block-device-secret.mjs:21— The terminal-target guard only rejects/dev/and/proc/literals. A--outtarget that resolves to the terminal through a symlink or a shell substitution ($(tty)) would pass and still leak the secret. Treat a dynamic--outvalue (containing$(, backtick,${) as "no safe out file" and fail closed, mirroring the tokenizer's dynamic-token handling.lib/permissions-template.json:170— Newaskrows (device go-live push, credential, logs export) only apply after a user re-runs/lua-doctorto merge them into their own settings. Until then a directlua push device/lua logs --ci exportrides the old broad allow rules with no confirmation. The in-command detect-and-stop guard mitigates this for slash flows; make the stale-permissions warning prominent in/lua-doctoroutput and upgrade notes.lib/permissions-template.json:191—Bash(lua logs * export*)is broad enough to turn an ordinarylua logsread into an ask prompt if an argument value contains the tokenexport. Tighten the glob or add a mirror test asserting reads with 'export' in a value are not caught.
Otherwise the change looks solid and safe to merge once the advisory items are considered.
PR Risk Reviewer — automated senior review of f0cca19 · risk: low · confidence: 0.72
Summary
Some commands need lua-cli 3.45.0 (in review); fallbacks documented.
This release adds a devices slash and re-checks the plugin against lua-cli 3.44.0 (npm
latest) and 3.45.0 (in review). Before starting, I confirmed the installed 1.6.0 copy is identical tomain.Security fixes (please review first)
lua skills production deploy --skill-name x --skill-version ydeploys non-interactively. The same goes for theprod/prd/live×deploy/publishspellings.lib/tokenizer.mjsdid not classify any of them, soconfirm-deploylet them through.block-device-secret. It blockslua devices credential|credentials|keyunless--out <file>is given, because the CLI otherwise prints the secret into the conversation./dev/stdoutor/proc/…does not count.lint-cli-flagsalso fails on any shipped credential command without--out.askrows:lua devicesverbs and all their aliases;lua push device*and every push-type alias, carved out of the generic push allow, because a pusheddefineDeviceis live on the next turn;lua logs export, whichlua logs --ci exportused to reach through thelua logs --ci*allow rule;lua drains confirm|replay./lua-doctorto merge these. Until they do,/lua-devicesand/lua-pushdetect the missing row and stop.New
commands/lua-devices.md(/lua-devices): a guidedsetuppluslist,status,credential,client,push,test,test-trigger,logs,enable,disable,removeandtroubleshoot. It covers:defineDevice;--outinto a git-ignored mode-600 file that is never read back;--auto-deploy, which stays denied, so the line is printed for the user's own terminal;AUTH_FAILEDwith a scoped key,MQTT CONNACK rc=5, offline afterdisablethenenable,DEVICE_OFFLINE,TIMEOUT, and the 24 h command-list expiry.lib/knowledge/devices.md: the 3.44 vs 3.45 action matrix, credentials, go-live, clients, limits and troubleshooting.hooks/block-device-secret.mjs, with its test.Stale behaviour fixed (lua-cli 3.44.0)
lua push agentnow stages the persona, and promote re-points the persona to the version's pin. The pilot now deploys it, or on a versioned agent pins it with--persona-versionand then promotes.lua push allno longer activates workflows.push allanddeploy allexit 1 on a failed item, and alua testthat throws exits non-zero.lua devices testandtest-triggeralways prompt, so they are not usable under--ci.--hide-sensitivedefault flipped to false, and--intervalnow accepts 1–2880.lua drains: six new destination types plusconfirmandreplay.lua evalsnow has verbs.Test plan
LUA_CLI_SRC=…/lua-cli npm run lint: all 17 lints pass, includinglint-knowledge-commandsagainst the 3.45.0 source.npm run test:coverage: 855 tests pass, hooks are at 100% and lib at 90% or more.mcp/lua-platform: 149 tests pass. The bundle was rebuilt (0.50 MB) and the standalone check confirms 1.7.0.confirm-deployandblock-device-secretagainst every command/lua-devicesemits. All pass, except the intended blocks./lua-devices setupagainst a real device on lua-cli 3.45.0, once it is published.Version 1.6.0 → 1.7.0, with a CHANGELOG entry. The repo has no eval suite; its checks are the lints and the jest tests. Please don't merge until the persona and device routing is reviewed.
🤖 Generated with Claude Code