Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions code-mower-package-manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -1212,6 +1212,11 @@
"source": "src/code_mower/doctor_checks/self_hosted_runner.py",
"target": "src/code_mower/doctor_checks/self_hosted_runner.py"
},
{
"kind": "core",
"source": "src/code_mower/doctor_checks/share_safe.py",
"target": "src/code_mower/doctor_checks/share_safe.py"
},
{
"kind": "core",
"source": "src/code_mower/doctor_checks/supervised_pilot.py",
Expand Down
17 changes: 10 additions & 7 deletions docs/install.md
Original file line number Diff line number Diff line change
Expand Up @@ -441,26 +441,29 @@ run Codex or Claude local CLI audits itself, keep the GitHub/cloud/setup checks
but skip local CLI probes:

```bash
code-mower doctor --adoption --hosted-builders --repo OWNER/REPO --json
code-mower doctor --adoption --orchestrator-only --repo OWNER/REPO --json
code-mower doctor --adoption --hosted-builders --repo OWNER/REPO --json --share-safe
code-mower doctor --adoption --orchestrator-only --repo OWNER/REPO --json --share-safe
```

Those commands expect the current checkout to contain `code-mower.yml`. On a
remote-only host with no repository checkout, select the maintained packaged
starter explicitly through the easy preset:

```bash
code-mower doctor --easy --orchestrator-only --repo OWNER/REPO --json
code-mower doctor --easy --orchestrator-only --repo OWNER/REPO --json --share-safe
```

The resulting filesystem and generated-workflow checks describe the packaged
starter, not the remote repository. Use them for installation posture; use
`lanes status --repo OWNER/REPO` for current remote PR and gate visibility.

Doctor JSON is local diagnostic evidence. It can include bounded local paths
such as the selected config, executable, or workflow path. Review or redact it
before attaching it to an issue or uploading it; the concise text view is the
safer first status summary.
Adoption and hosted-posture doctor output is share-safe by default. JSON keeps
its existing fields and check IDs, reports `local_paths: redacted`, and replaces
local config, executable, checkout, workflow, and packaged-template paths with
`[local path hidden]`. Maintained copy/paste commands also pass `--share-safe`
explicitly. For private local debugging, `--include-local-paths` restores the
legacy values and the legacy top-level key set for strict machine consumers;
review that output locally and do not attach or upload it.

In those observer/coordinator postures, missing local wrapper environment
variables and missing `DISPATCH_TOKEN` setup are surfaced as owner setup or
Expand Down
5 changes: 3 additions & 2 deletions docs/launch-command-surface.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ The default `code-mower next-steps` and `code-mower --help` focus on this path.
| `code-mower lanes status --repo OWNER/REPO` | Show active PR lanes, gate/check state, local board/process hints, stale audit requeue guidance, and the next action. | no | GitHub optional |
| `code-mower productivity report --repo OWNER/REPO` | Summarize local Board history, reviewer spend, provider scorecards, promotion caveats, quality catches, fix rounds, owner actions, and optional cloud aggregate productivity events. | no | no |
| `code-mower board serve --repo OWNER/REPO` | Serve redacted lane status plus owner queue and local verdict/spend timelines in a local read-only browser board. | no | GitHub optional |
| `code-mower doctor --adoption --repo OWNER/REPO --json` | Check Python, GitHub, provider CLIs, cloud token posture, and private-repo cost traps. | no | optional GitHub/provider probes |
| `code-mower doctor --adoption --repo OWNER/REPO --json --share-safe` | Check Python, GitHub, provider CLIs, cloud token posture, and private-repo cost traps with local paths redacted. | no | optional GitHub/provider probes |
| `code-mower next-steps --profile recommended --repo OWNER/REPO` | Print the next recommended setup actions. | no | no |

## Later Workflows
Expand Down Expand Up @@ -54,7 +54,8 @@ Select any additional builder or reviewer explicitly.
| `code-mower board events` | Print recent local board-history events without calling GitHub. | no | no |
| `code-mower board doctor --repo OWNER/REPO` | Diagnose Board inputs, local history, gate alerts, owner queue, and optional agent cards with redacted local paths by default. | no | GitHub optional |
| `code-mower board reset --repo OWNER/REPO --yes` | Delete only the local Board history file after explicit confirmation. | yes, local only | no |
| `code-mower doctor --adoption --hosted-builders --repo OWNER/REPO --json` | Check hosted-builder or orchestrator setup without requiring local Codex/Claude CLIs on this machine. | no | optional GitHub/provider probes |
| `code-mower doctor --adoption --hosted-builders --repo OWNER/REPO --json --share-safe` | Check hosted-builder or orchestrator setup without requiring local Codex/Claude CLIs on this machine; local paths stay redacted. | no | optional GitHub/provider probes |
| `code-mower doctor --adoption --repo OWNER/REPO --json --include-local-paths` | Restore local diagnostic path values for private debugging; do not attach or upload this output. | no | optional GitHub/provider probes |
| `code-mower doctor --supervised-pilot --repo OWNER/REPO --json` | Summarize manual-pilot readiness with blockers, owner actions, warnings, promotion to-dos, cloud token, and Board visibility. | no | optional GitHub/provider probes |
| `code-mower doctor --promoted-pilot --repo OWNER/REPO --json` | Check the stricter posture needed before green audits may drive auto-merge. | no | optional GitHub/provider probes |
| `code-mower migration setup-drift --repo-path .` | Classify existing generated setup files before an upgrade PR without printing source or diffs. | no | no |
Expand Down
19 changes: 10 additions & 9 deletions docs/orchestrator-prompt-pack.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,11 +81,11 @@ before any init --apply. Preserve repository policy and copy only the intended
generated files in the upgrade PR.

Run the posture-appropriate doctor:
- local reviewer/builder machine: code-mower doctor --adoption --repo OWNER/REPO --json
- hosted builder or observer: code-mower doctor --adoption --hosted-builders --repo OWNER/REPO --json
- orchestrator-only host: code-mower doctor --adoption --orchestrator-only --repo OWNER/REPO --json
- remote-only host with no checkout config: code-mower doctor --adoption --orchestrator-only --repo OWNER/REPO --json
- supervised pilot readiness: code-mower doctor --supervised-pilot --repo OWNER/REPO --json
- local reviewer/builder machine: code-mower doctor --adoption --repo OWNER/REPO --json --share-safe
- hosted builder or observer: code-mower doctor --adoption --hosted-builders --repo OWNER/REPO --json --share-safe
- orchestrator-only host: code-mower doctor --adoption --orchestrator-only --repo OWNER/REPO --json --share-safe
- remote-only host with no checkout config: code-mower doctor --adoption --orchestrator-only --repo OWNER/REPO --json --share-safe
- supervised pilot readiness: code-mower doctor --supervised-pilot --repo OWNER/REPO --json --share-safe

Read the posture-scoped summary first by rerunning the same posture with
--concise instead of --json: every check still runs, and the summary leads with
Expand All @@ -99,10 +99,11 @@ checks. Repository Actions secret and variable presence still comes from the
target repository through `gh`; that is separate from `GITHUB_TOKEN` or local
checkout-path requirements used by direct local-audit wrappers.

That packaged-starter remote-observer JSON uses stable package labels and does
not include local config, executable, checkout, or workflow paths. Other doctor
JSON can contain local paths; review or redact it before attaching or uploading
it.
Adoption and hosted-posture output is share-safe by default. The explicit
`--share-safe` in this maintained prompt makes that boundary reviewable: local
config, executable, checkout, workflow, and packaged-template paths retain
their fields but use `[local path hidden]`. Use `--include-local-paths` only for
private local debugging; do not attach that form to an issue or upload it.

Provider selection and a working CLI do not qualify an orchestrator. Devin is
currently limited to bounded builder work and informational review; use a
Expand Down
4 changes: 2 additions & 2 deletions docs/quickstart.md
Original file line number Diff line number Diff line change
Expand Up @@ -384,8 +384,8 @@ shows `"app_id": 15368`, remove and re-add the required check from Any source.
Now run the preflight:

```bash
code-mower doctor --adoption --repo OWNER/REPO --json
code-mower doctor --supervised-pilot --repo OWNER/REPO --json
code-mower doctor --adoption --repo OWNER/REPO --json --share-safe
code-mower doctor --supervised-pilot --repo OWNER/REPO --json --share-safe
```

`doctor --adoption` is the recommended early-adopter preset for GitHub auth,
Expand Down
2 changes: 1 addition & 1 deletion docs/try-in-10-minutes.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ setup behavior from drifting.
```bash
code-mower init --easy
code-mower init --easy --apply --output-dir .code-mower.generated
code-mower doctor --adoption --repo OWNER/REPO --json
code-mower doctor --adoption --repo OWNER/REPO --json --share-safe
```

4. Open the setup pull request and request independent Claude and Codex audits
Expand Down
56 changes: 50 additions & 6 deletions src/code_mower/doctor.py
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,9 @@
_local_cli_probe_remediation = _doctor_checks.local_cli_probe_remediation
render_doctor_summary = _doctor_checks.render_doctor_summary
render_doctor_text = _doctor_checks.render_doctor_text
doctor_report_payload = _doctor_checks.doctor_report_payload
redact_local_path_text = _doctor_checks.redact_local_path_text
share_safe_doctor_report = _doctor_checks.share_safe_doctor_report
resolve_doctor_config_path = _doctor_checks.resolve_doctor_config_path
resolve_doctor_config_path_for_script = _doctor_checks.resolve_doctor_config_path_for_script
resolve_doctor_provider_templates_path = _doctor_checks.resolve_doctor_provider_templates_path
Expand Down Expand Up @@ -111,7 +114,9 @@ def _doctor_config_source_label(
return "repository_config"


def _doctor_config_error_message(exc: Exception, *, config_arg: str) -> str:
def _doctor_config_error_message(
exc: Exception, *, config_arg: str, include_local_paths: bool = True
) -> str:
requested = str(config_arg)
lines = [
f"error: {exc}",
Expand All @@ -129,7 +134,8 @@ def _doctor_config_error_message(exc: Exception, *, config_arg: str) -> str:
"the repository checkout with `code-mower doctor --adoption "
"--repo OWNER/REPO`."
)
return "\n".join(lines)
message = "\n".join(lines)
return message if include_local_paths else redact_local_path_text(message)


_DOCTOR_COMPAT_EXPORTS = (
Expand Down Expand Up @@ -358,6 +364,23 @@ def main(argv: Sequence[str] | None = None) -> int:
"remaining warnings by group"
),
)
path_group = parser.add_mutually_exclusive_group()
path_group.add_argument(
"--share-safe",
action="store_true",
help=(
"redact local config, checkout, executable, workflow, and template "
"paths from text and JSON output"
),
)
path_group.add_argument(
"--include-local-paths",
action="store_true",
help=(
"include local diagnostic paths; adoption and hosted postures redact "
"them by default"
),
)
detail_group.add_argument(
"--advanced",
action="store_true",
Expand All @@ -375,6 +398,11 @@ def main(argv: Sequence[str] | None = None) -> int:
args.adoption = True
if args.adoption:
args.preflight = True
include_local_paths = args.include_local_paths or not (
args.share_safe
or args.adoption
or args.adoption_posture in {"hosted-builders", "orchestrator-only"}
)
cloud_explicit = "--cloud" in raw_args
runtime_probe_explicit = "--probe-runtime" in raw_args
explicit_config = args.config is not None
Expand Down Expand Up @@ -461,7 +489,14 @@ def main(argv: Sequence[str] | None = None) -> int:
**({'context_state_dir': args.context_state_dir} if args.context_state_dir is not None else {}),
)
except (code_mower_config.ConfigError, ValueError) as exc:
print(_doctor_config_error_message(exc, config_arg=args.config), file=sys.stderr)
print(
_doctor_config_error_message(
exc,
config_arg=args.config,
include_local_paths=include_local_paths,
),
file=sys.stderr,
)
return 1

if args.operational_evidence is not None:
Expand Down Expand Up @@ -489,12 +524,21 @@ def main(argv: Sequence[str] | None = None) -> int:
# modes keep the full text view: a concise run only changes what a default
# text run reads first.
concise = args.concise and not args.advanced and not args.campaign
output_report = (
report if include_local_paths else share_safe_doctor_report(report)
)
if args.json:
print(json.dumps(report.as_dict(), indent=2, sort_keys=True))
print(
json.dumps(
doctor_report_payload(report, include_local_paths=include_local_paths),
indent=2,
sort_keys=True,
)
)
elif concise:
print(render_doctor_summary(report), end="")
print(render_doctor_summary(output_report), end="")
else:
print(render_doctor_text(report), end="")
print(render_doctor_text(output_report), end="")
if report.failures:
return 1
if args.strict and report.warnings:
Expand Down
12 changes: 12 additions & 0 deletions src/code_mower/doctor_checks/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -113,6 +113,13 @@
check_runner_workflow_labels,
check_self_hosted_runner,
)
from .share_safe import (
LOCAL_PATH_REDACTION,
doctor_report_payload,
redact_local_path_text,
redact_local_paths,
share_safe_doctor_report,
)
from .runner import run_doctor

__all__ = [
Expand All @@ -130,6 +137,7 @@
"DoctorCheckGroup",
"DoctorCheckStage",
"DoctorReport",
"LOCAL_PATH_REDACTION",
"STATUS_FAIL",
"STATUS_PASS",
"STATUS_SKIP",
Expand Down Expand Up @@ -182,6 +190,7 @@
"detect_repo_slug",
"doctor_check_group_id",
"doctor_output_group",
"doctor_report_payload",
"effective_lane",
"evaluate_json_probe",
"gate_automerge_token_config",
Expand All @@ -192,6 +201,8 @@
"local_cli_probe_remediation",
"normalize_repo_slug",
"provider_template_coverage",
"redact_local_path_text",
"redact_local_paths",
"render_doctor_summary",
"render_doctor_text",
"resolve_doctor_config_path",
Expand All @@ -200,5 +211,6 @@
"repo_slug_from_remote",
"run_doctor",
"selected_lanes",
"share_safe_doctor_report",
"token_file_mentions_cloud_token",
]
Loading
Loading