docs: design a re-runnable machine profile and place it in claude-ops - #5494
Conversation
Records the read/write split, storage location, per-domain document shape, verdict vocabulary, manual-change policy, and the machine-health handoff for a machine profile. Setup contract, invocation-mode class (ii) and version bumps stay out of scope pending the owner's ruling. Refs #4666 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude encountered an error after 0s —— View job I'll analyze this and get back to you. |
|
Claude encountered an error after 0s —— View job I'll analyze this and get back to you. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c06c909d90
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
PR body contract — issue linkage This PR body does not yet satisfy the issue-linkage contract:
Edit the body and this comment updates itself on the next run. |
Give default-unexamined a skipped_because reason instead of observed_by, specify the per-tree gh configuration probe, isolate npm cache state in the read-only fixture, mark the park record superseded in part, and drop the settled placement from the open questions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 4m 36s —— View job Code review (
|
|
Claude finished @kyle-sexton's task in 1m 43s —— View job Security review (
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 57s —— View job Security review (
|
|
Claude finished @kyle-sexton's task in 2m 30s —— View job Code review (
|
Refs: #4666 ## Summary Adds `/claude-ops:machine-profile` per the owner decision of 2026-10-01 on #4666 (ratify `docs/specs/machine-profile-design.md`, build the claude-ops skill, scripts and tests, bump claude-ops only). It discovers machine facts and per-tree identity domains, stores them as a profile with the observation behind every value, and diffs the stored profile against the host. Read-only unless the operator confirms a write. ## Fix - `plugins/claude-ops/skills/machine-profile/`: SKILL.md, `scripts/profile.sh` (discover, record, diff, apply), `scripts/profile.test.sh`, and `evals/evals.json`. - Every key discovery derives from host text (`binary.<tool>`, `git_include_file:<path>`) passes through `rec`, which brackets the first letter of each `token`, `secret`, `password` or `credential` word (`binary.[s]ecret-tool`). A declared binary such as `secret-tool` or `docker-credential-pass`, or an `includeIf` path under a `token` directory, no longer matches the validator's credential-key refusal and aborts discover. One pattern feeds both `rec` and the validator. The refusal is unchanged: hand-supplied records never pass through `rec`, so a record keyed `api_token` is still refused, and the credential-value check still runs on every record. Regression tests run discover, record, diff and explain over credential-named binaries and include paths. - Docs: ADR 0041 and the design spec record the rulings; `docs/out-of-scope/machine-profile.md` no longer says the skill is parked and now records only the declined options, with its Prior requests log kept; the ledger README no longer lists it as an unruled proposal. - claude-ops 0.79.1 to 0.80.0 with a CHANGELOG entry, README and prerequisites wiring, catalog and cheat-sheet rows. - The issue stays open: its AC1 asks for an invocation-mode doc update under option 2, which the owner ruled out, and the owner's Next step does not say to close. Closing stays with the owner. ## Verification - `bash plugins/claude-ops/skills/machine-profile/scripts/profile.test.sh`: all cases passed, including the include-path and credential-named binary regressions (record, diff and explain round trip). - `scripts/validate-plugins.sh`: all plugin manifests and the catalog validated. - `scripts/check-changelog-parity.sh --check`, `--check-order`, `--check-bump origin/main`: pass. - Merged origin/main (conflicts in the claude-ops manifest and CHANGELOG resolved, keeping 0.80.0 above main's 0.79.1). ## Related - Issue #4666; design doc PR #5494 (merged). 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Refs #4666
Summary
Owner decision (2026-09-29) on #4666 narrowed option 2 to a design doc first. This adds that design doc and the ADR-style placement record. It changes no setup contract, no invocation-mode class and no plugin. The issue stays open: acceptance criteria 4-6 need the built skill, and the invocation-mode change in criterion 1 waits on the owner's later decision.
Fix
docs/specs/machine-profile-design.md: storage location, per-domain document shape, the default-verified / default-unexamined verdict vocabulary, and the manual-change policy, plus the reuse boundary with machine-health.docs/adr/0041-place-the-machine-profile-as-a-claude-ops-skill.md: placement decision relative to machine-health.docs/out-of-scope/machine-profile.mdnor PR docs: remove agent-encoded decisions and correct decision records #5288 (that PR only corrects facts in the park doc), so the two do not conflict.Verification
git merge origin/main: clean, no conflicts.scripts/check-changelog-parity.sh --check --check-order: pass.scripts/validate-plugins.sh: all manifests and the catalog validated.scripts/check-adr-numbers.sh: ADR numbers unique.scripts/check-docs-naming.sh: docs names lower-kebab-case.Related
🤖 Generated with Claude Code