diff --git a/CHANGELOG.md b/CHANGELOG.md index 7bb234c..743e6d4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,13 @@ # Changelog +## 0.1.16 — 2026-10-04 + +Patch koreksi pasca-0.1.15 untuk atribusi aset anti-slop, pemulihan catatan penundaan upstream c44ef22, dan penyempurnaan emulasi Playwright QA (permissions geolokasi). Katalog tetap 65 (50 model + 15 manual). Closed intents tetap 25. Tidak ada penambahan atau pensiun skill (`vendor/skill-allowlist.txt` dan `vendor/skill-policy.json` tidak berubah). + +- **Koreksi**: Klaim pada 0.1.15 "memperbaiki pemeriksaan terbalik" adalah salah atribusi; upstream `e8c4880` tidak pernah memiliki bug tersebut, melainkan sinkronisasi 0.1.15 memulihkan drift lokal yang ada di OCH sejak bootstrap 0.1.0 (`202cc46`). Catatan evaluasi upstream `c44ef22` (3 generic rules, 4 Effect rules, shared helpers, vendored eslint-stylistic) dipulihkan ke `docs/source-wave.md` dengan status DEFERRED. +- **Penyempurnaan emulasi Playwright QA (geolokasi & permissions)**: Menegaskan bahwa emulasi geolokasi pada launch config `.playwright/cli.config.json` wajib menyertakan `contextOptions.permissions: ["geolocation"]` agar tidak ditolak dengan `"User denied Geolocation"`. Menjelaskan pemisahan runtime `run-code`: geolokasi menggunakan API Playwright standar (`grantPermissions`/`setGeolocation`) yang lintas-browser, sedangkan emulasi runtime timezone dan locale spesifik Chromium via CDP (`setTimezoneOverride`/`setLocaleOverride`). +- **Versi Produk**: Bump versi ke `0.1.16` (`VERSION`, `vendor/sources.json`, `vendor/provenance.json`, `vendor/license-audit.json`, `README.md`, `docs/CATALOG-FREEZE.md`). + ## 0.1.15 — 2026-10-04 Rilis pemeliharaan Wave 0.1.15 untuk sinkronisasi aset vendored anti-slop, standardisasi emulasi Playwright QA, dan pembersihan impor mati. Katalog tetap 65 (50 model + 15 manual). Closed intents tetap 25. Tidak ada penambahan atau pensiun skill (`vendor/skill-allowlist.txt` dan `vendor/skill-policy.json` tidak berubah). diff --git a/README.md b/README.md index f83780e..44f6d94 100644 --- a/README.md +++ b/README.md @@ -4,7 +4,7 @@ OpenCode 2 overlay: 65 frozen routed skills, thin `AGENTS.md`, `opencode-he`. Installer and runtime overlay for [OpenCode 2](https://opencode.ai/v2/docs/). -Version **0.1.15**. The 65-skill catalog is strictly frozen. +Version **0.1.16**. The 65-skill catalog is strictly frozen. ## What it is diff --git a/VERSION b/VERSION index c34958a..e8e277f 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -0.1.15 +0.1.16 diff --git a/docs/CATALOG-FREEZE.md b/docs/CATALOG-FREEZE.md index 3794d08..db00978 100644 --- a/docs/CATALOG-FREEZE.md +++ b/docs/CATALOG-FREEZE.md @@ -2,9 +2,10 @@ This contract defines the immutable boundary and governance for the OpenCodeHighEnd catalog. The 65-skill catalog is strictly frozen. -- **Product version**: 0.1.15 +- **Product version**: 0.1.16 - **Catalog**: 65 names. 50 model-invoked under `skills/`. 15 manual under `manual-skills/` + `commands/`. -- **Wave 0.1.15 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions. Upstream sync and hygiene: synchronized vendored Oxlint ruleset assets in `skills/install-anti-slop` from `dmmulroy/anti-slop@e8c4880471b23ab7f216fba7b27d173a6ef07d4c` (v0.1.2) fixing inverted variable kind check in `no-widen-then-assert.ts`; standardized Playwright QA timezone/locale/geolocation emulation doctrine with `.playwright/cli.config.json` context options as primary cross-browser method and `run-code` as Chromium CDP runtime alternative; removed dead imports `repo_root` from `lib/design_v2/bootstrap.py` and `tarfile` from `tests/test_design_bootstrap.py`. +- **Wave 0.1.16 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions. Post-release correction and Playwright emulation refinement: restored c44ef22 upstream deferral record in docs/source-wave.md and corrected attribution of anti-slop asset synchronization (restoring 0.1.0 local drift to upstream e8c4880, not fixing upstream); documented mandatory permissions array for Playwright QA geolocation emulation and clarified runtime split (cross-browser grantPermissions/setGeolocation vs Chromium CDP timezone/locale overrides). +- **Wave 0.1.15 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions. Upstream sync and hygiene: synchronized vendored Oxlint ruleset assets in `skills/install-anti-slop` from `dmmulroy/anti-slop@e8c4880471b23ab7f216fba7b27d173a6ef07d4c` (v0.1.2) restoring upstream no-widen-then-assert.ts (local drift since 0.1.0); standardized Playwright QA timezone/locale/geolocation emulation doctrine with `.playwright/cli.config.json` context options as primary cross-browser method and `run-code` as Chromium CDP runtime alternative; removed dead imports `repo_root` from `lib/design_v2/bootstrap.py` and `tarfile` from `tests/test_design_bootstrap.py`. - **Wave 0.1.14 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions. Post-release fixes for 0.1.13: corrected crawl4ai commit pin in `vendor/sources.json` to official `v0.9.4` release (`133e1d92e37885dfccc03ea2e3687d06c98b7ceb`); completed retirement of Design Bank fallback #4 from runtime and tests with fail-closed Drive error propagation; corrected Playwright CLI config path documentation (`.playwright/cli.config.json`) and clarified timezone/locale emulation via `run-code`; aligned reflect invariant enforcement hierarchy wording (5-level OCH adaptation). - **Wave 0.1.13 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions. Upstream sync across 6 discrete scopes: pins updated for `shadcn@4.21.1`, `@reticlehq/server@3.5.0`, `markitdown-mcp==0.0.1a7` with `markitdown[all]==0.1.8`, `crawl4ai` `/mcp/sse`; refreshed `playwright-qa` with device emulation, media feature toggles, and WebMCP security boundaries, `install-anti-slop` with `update` mode, `scroll-craft` dual-door browser handoffs; doctrines adopted: Emil Kowalski `break-ui` adversarial UI stress testing into `skills/impeccable/reference/break-ui.md`, pstack `/correct` invariant enforcement hierarchy into `manual-skills/reflect/references/correct.md`, `motion-designer` scored review / phone review / motion blur into `business-motion-film`, `architect` agent contributor lens; attribution and governance synchronized; serena GPL-3.0-or-later boundary preserved as external pointer. - **Wave 0.1.12 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions. Upstream hyperframes refreshed to v0.8.119 (declarative data attributes, CLI render pipeline); awesome-opus5-5-videos added as first-party POINTER_ONLY prompt patterns reference; Matt Pocock cluster migrated to GLOSSARY.md convention with legacy CONTEXT.md fallback; dead game-asset-core references removed; humanizer bumped to v3.1.0 with patterns 25 & 26; diagram-design pinned to 2.6.51; impeccable v4.5.0 deferred. diff --git a/docs/source-wave.md b/docs/source-wave.md index 254d8a4..3f66a5c 100644 --- a/docs/source-wave.md +++ b/docs/source-wave.md @@ -6,7 +6,7 @@ Recorded per Phase 0 contract. | Source | Upstream Commit / Ref | Nature / Contents | Disposition | Survivor in OCBF | Notes / Rationale | |---|---|---|:---:|---|---| | [miqdadbadjuber/anti-slop](https://github.com/miqdadbadjuber/anti-slop) | `91f12ec67e9de6043cfd93b846404986ba73c3f4` (v3.2.20) | UI/copy filter (38 rules R-01–R-38), 3 tiers (Hard Gate, Purpose-Gate, Quality Locks), Delivery Gate checklist, Liveliness dials, during/after usage modes. MIT. | **MERGE** | `skills/impeccable` (taste-guard + direction), `skills/humanizer`, `rules/03-prose-discipline.md` | Filter, not a style guide. Do not vendor as 65th skill (`antislop` or `antislop-ui`). Distinct from Oxlint. | -| [dmmulroy/anti-slop](https://github.com/dmmulroy/anti-slop) | `e8c4880471b23ab7f216fba7b27d173a6ef07d4c` (v0.1.2) | TypeScript/JavaScript Oxlint static linter ruleset. MIT. | **DONE** | `skills/install-anti-slop` | Vendored and pinned at v0.1.2 with full assets synchronized in 0.1.15. `update` mode is first-party OCH. | +| [dmmulroy/anti-slop](https://github.com/dmmulroy/anti-slop) | `e8c4880471b23ab7f216fba7b27d173a6ef07d4c` (v0.1.2) | TypeScript/JavaScript Oxlint static linter ruleset. MIT. | **DONE** | `skills/install-anti-slop` | Vendored and pinned at v0.1.2. 23 assets blob-identical to e8c4880 since 0.1.15 (restored local drift in rules/no-widen-then-assert.ts from 0.1.0 bootstrap; upstream was correct). update mode is first-party OCH. c44ef22 evaluated: 3 generic rules, 4 Effect rules, shared helpers, vendored eslint-stylistic (MIT) DEFERRED (not vendored). | | [microsoft/markitdown](https://github.com/microsoft/markitdown) | `b8f79c57ebc0044be41323d89b2a45d3fda8460e` (v0.1.8) | File to Markdown converter (Office/PDF/HTML/CSV/XLSX/PPTX/EPUB/ZIP). MIT. | **PIN_ONLY** | `skills/markitdown` | Pinned to v0.1.8 (commit `b8f79c57`). Skill body unchanged. Enable writes `uvx --from markitdown-mcp==0.0.1a7 --with markitdown[all]==0.1.8 markitdown-mcp`. Output remains data-only. SmartDoc keeps contract/QA/render. MCP remains FOREIGN_ON_DEMAND. | | [affaan-m/ECC](https://github.com/affaan-m/ECC) | `dd6ee538aee0f548d4a6b520118f875431fd749e` | External agent control plane (68 agents, 292 skills, hooks, learning runtime). | **REJECT** | None (`FOREIGN_ON_DEMAND`) | Do not vendor harness control plane or 292 skills. No installer mutator. Doctor does not fail when absent. Individual warehouse ports remain first-party MIT. | | [Leonxlnx/taste-skill](https://github.com/Leonxlnx/taste-skill) | `e79ca9ec7e071eb3a3b623c4fb752e853fc3ed58` (`ccbc156` base) | Design taste dials (VARIANCE, MOTION, DENSITY), quality rules, GSAP/Tailwind references. MIT. | **MERGE** | `skills/impeccable/reference/taste/direction.md`, `taste-guard.md` | Dials already integrated into Impeccable surface brief. Fenced after Design Bank or DESIGN.md direction exists. Never a frontend-design twin. | diff --git a/rules/00-routing.md b/rules/00-routing.md index ad3748c..91cec25 100644 --- a/rules/00-routing.md +++ b/rules/00-routing.md @@ -150,7 +150,7 @@ The specialist architecture forms a deterministic graph connected by file artifa - Photoreal stills / ads / identity with no UI surface: `/visual-studio`. - Motion after Impeccable: `/emil-design-eng`. - Image/video generation: use OpenCode native image tools if the session exposes them. Otherwise write prompt files and mark DEGRADED. Do not invent `image_gen`. -- Exploratory application UI QA: `/playwright-qa` is the primary adapter (navigation, form inputs, state inspection, snapshot, screenshot, device and viewport emulation: `--device`, `resize`, `set-color-scheme`, `set-reduced-motion`, `set-forced-colors`, `set-contrast`, `set-media`; timezone/locale/geolocation via `.playwright/cli.config.json`, or Chromium `run-code`). Never launch for backend/non-UI. +- Exploratory application UI QA: `/playwright-qa` is the primary adapter (navigation, form inputs, state inspection, snapshot, screenshot, device and viewport emulation: `--device`, `resize`, `set-color-scheme`, `set-reduced-motion`, `set-forced-colors`, `set-contrast`, `set-media`; timezone/locale/geolocation via `.playwright/cli.config.json` with permissions, or `run-code`). Never launch for backend/non-UI. - Explicit multi-account or persistent browser sessions: `/browser-act`. Load the skill before any `browser-act` command. Never `--type chrome-direct`. - Observed browser cause: `/chrome-devtools-axi` after `opencode-chromium-cdp start` on `http://127.0.0.1:9223`. Never Google Chrome. - Deterministic browser regression: existing project test suite (Playwright Test, Cypress, etc.) using project scripts/package manager. diff --git a/skills/playwright-qa/SKILL.md b/skills/playwright-qa/SKILL.md index 65e5a4f..03aa3d3 100644 --- a/skills/playwright-qa/SKILL.md +++ b/skills/playwright-qa/SKILL.md @@ -23,7 +23,7 @@ This skill provides an interactive, token-efficient browser interface for agents 7. **Privacy & Hygiene**: Storage state, cookies, HAR recordings, traces, and screenshots must never be committed to git or printed with sensitive credentials. 8. **No Browser for Backend**: Never start browser sessions when only backend, API, database, or non-UI code changed. 9. **No Data Gathering**: Web and social data gathering is not UI QA; route extraction tasks to `research` (`references/web-data.md`). -10. **Emulation & Responsive QA**: Emulate devices (`open --device`), resize viewports (`resize `), and toggle media features (`set-color-scheme`, `set-reduced-motion`, `set-forced-colors`, `set-contrast`, `set-media`). Timezone, locale, and geolocation are configured via `.playwright/cli.config.json` (`contextOptions`), or runtime Chromium CDP via `run-code`. +10. **Emulation & Responsive QA**: Emulate devices (`open --device`), resize viewports (`resize `), and toggle media features (`set-color-scheme`, `set-reduced-motion`, `set-forced-colors`, `set-contrast`, `set-media`). Timezone, locale, and geolocation are configured via `.playwright/cli.config.json` (`contextOptions`, with `permissions: ["geolocation"]`), or runtime via `run-code` (cross-browser API for geolocation; Chromium CDP for timezone/locale). ## Workflow diff --git a/skills/playwright-qa/references/workflow.md b/skills/playwright-qa/references/workflow.md index 4fb2556..3d30b99 100644 --- a/skills/playwright-qa/references/workflow.md +++ b/skills/playwright-qa/references/workflow.md @@ -64,7 +64,7 @@ Use device presets at launch and session commands to toggle media features. playwright-cli -s= set-media print playwright-cli -s= clear-media ``` -- **Timezone / Locale / Geolocation**: Not available as CLI flags. Configure via JSON config file at launch (default `.playwright/cli.config.json` or `--config=` specifying `contextOptions.timezoneId`, `contextOptions.locale`, `contextOptions.geolocation`). Alternatively, use `run-code` for Chromium-specific runtime session overrides via CDP. +- **Timezone / Locale / Geolocation**: Not available as CLI flags. Configure via JSON config file at launch (default `.playwright/cli.config.json` or `--config=` specifying `contextOptions.timezoneId`, `contextOptions.locale`, `contextOptions.geolocation` with mandatory `contextOptions.permissions: ["geolocation"]`). At runtime via `run-code`: geolocation uses cross-browser Playwright API (`page.context().grantPermissions(['geolocation'])` + `page.context().setGeolocation({latitude, longitude})`); timezone and locale runtime overrides require Chromium CDP session (`Emulation.setTimezoneOverride` / `Emulation.setLocaleOverride`). 7. **Clean up**: ```bash diff --git a/tests/test_playwright_qa.py b/tests/test_playwright_qa.py index 81ec35e..201fc94 100644 --- a/tests/test_playwright_qa.py +++ b/tests/test_playwright_qa.py @@ -64,6 +64,8 @@ def test_session_isolation_and_discipline(self): self.assertIn("resize", workflow) self.assertNotIn("--viewport-size=", workflow) self.assertNotIn("--color-scheme=", workflow) + self.assertIn("permissions", workflow) + self.assertIn("grantPermissions", workflow) self.assertIn("WebMCP and Security Boundaries", workflow) def test_doctor_browser_findings_safe(self): diff --git a/vendor/license-audit.json b/vendor/license-audit.json index 84954da..6c6cb86 100644 --- a/vendor/license-audit.json +++ b/vendor/license-audit.json @@ -1,7 +1,7 @@ { "schemaVersion": 1, "product": "OpenCodeHighEnd", - "productVersion": "0.1.15", + "productVersion": "0.1.16", "note": "Evidence-based. A missing frontmatter license is not a grant. Adapted \u2260 first-party.", "skills": { "demo-video": { diff --git a/vendor/provenance.json b/vendor/provenance.json index 7588395..2ce7e2c 100644 --- a/vendor/provenance.json +++ b/vendor/provenance.json @@ -1,7 +1,7 @@ { "schemaVersion": 1, "product": "OpenCodeHighEnd", - "productVersion": "0.1.15", + "productVersion": "0.1.16", "firstPartyLicense": "MIT", "components": [ { @@ -504,7 +504,7 @@ "copyright": "Copyright (c) 2026 Dillon Mulroy", "modified": true, "redistribution": "mit", - "notes": "Vendored rule snapshot with 4 modes (audit, recommended, strict, custom) and opt-in Effect rules." + "notes": "Vendored rule snapshot with 5 modes (audit, recommended, strict, custom, update) and opt-in Effect rules." }, { "component": "taste-guard", diff --git a/vendor/sources.json b/vendor/sources.json index d6d31ab..a1f47b3 100644 --- a/vendor/sources.json +++ b/vendor/sources.json @@ -1,7 +1,7 @@ { "schemaVersion": 1, "product": "OpenCodeHighEnd", - "productVersion": "0.1.15", + "productVersion": "0.1.16", "sources": { "codebase-memory": { "repository": "https://github.com/DeusData/codebase-memory-mcp", @@ -224,7 +224,7 @@ "license": "MIT", "copyright": "Copyright (c) 2026 Dillon Mulroy", "licenseFile": "vendor/licenses/DMMULROY-ANTI-SLOP-MIT.txt", - "note": "Vendored rule snapshot for TS/JS projects with 4 modes (audit, recommended, strict, custom) and opt-in Effect rules." + "note": "Vendored rule snapshot for TS/JS projects with 5 modes (audit, recommended, strict, custom, update) and opt-in Effect rules." }, "json-render": { "repository": "https://github.com/vercel-labs/json-render",