test(headless): read both ways an adapter names a mounted repo file - #2316

Merged
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority
Aug 6, 2026
Merged

test(headless): read both ways an adapter names a mounted repo file#2316
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority

Conversation

@Astro-Han

Copy link
Copy Markdown
Contributor

Summary

Each arm is mounted exactly the repo files it declares, and the check that holds those declarations to what the adapters actually read is the only thing standing between a missed entry and a trial that aborts inside the container. #2298 added that check for the Maka adapter after run-host-cell.mjs — probed by install() in every cell-mode branch — was left out of the declaration. It left the competitor half as it was.

The competitor half saw less than it looked like it saw. It scanned adapter sources for bare filenames and resolved them against packages/headless/harbor, so it could only ever notice a read of a file in that one directory. A competitor adapter reaching for packages/headless/dist/index.js — a path the Maka adapter already reads — matched nothing and passed. It was also matching by coincidence in the other direction: any string literal equal to some filename under harbor/ counted as a read of it.

Both halves now share one reader that matches the two forms adapters actually write:

  • the mounted path spelled out in full (codex_agent.py's _DEEPSEEK_MODELS_PATH),
  • the same path built by joining segments onto the mount root (opencode_agent.py, maka_agent.py).

Bare-filename matching is gone; both forms above cover every read in the adapters today, so nothing is lost with it. The reader is also exercised directly, so it is no longer worth only what today's adapters happen to spell.

Refs #2298.

Verification

  • Red: pointed opencode_agent.py at packages/headless/dist/index.js (a path outside harbor/, undeclared, unmounted). On main all 19 mount tests pass — the gap, reproduced. With this change: opencode_agent.py names packages/headless/dist/index.js, which opencode is not mounted.
  • Green: @maka/headless 1431 pass / 0 fail. npm run lint and npm run format clean.

Not run: desktop E2E and Storybook — test-only change in headless.

Review focus

The reader is a regex over Python source, which is a heuristic, not a parser: an adapter that builds a container path through a variable or an f-string is still invisible to it. That limit is unchanged from #2298; what changes here is that the limit is now the same on both sides and is stated in one place instead of being an accident of which directory the matcher scanned.

The check that holds the mount declarations to what the adapters actually
read is worth exactly what its reader sees, and the competitor half of it
saw less than it looked. It scanned for bare filenames and resolved them
against `packages/headless/harbor`, so a read of any repo file outside
that one directory matched nothing and passed — `dist/index.js`, which
the Maka adapter already reads, would have been invisible had a
competitor adapter reached for it.
This is the gap that cost `run-host-cell.mjs`: the Maka side had no
authority check at all, `install()` probed for a file nobody declared,
and a missing probe target aborts the trial before the arm runs. Closing
it for Maka left the same weakness on the other side.
Both halves now share one reader that matches the two forms adapters
actually write — the mounted path spelled out in full, and the same path
joined onto the mount root — and it is exercised directly rather than
only through whichever forms today's adapters happen to use.
…nothing
Two gaps the first round left, both of the same kind: a regex guard that
stops matching still passes.
The reader recognised the join form only when it hung off `maka_repo`,
and `maka_agent.py` hangs its own headless CLI path off a
`Path("/opt/maka-agent")` constant instead — that read was invisible, and
covered only by the directory mount it happens to fall inside. Match the
chain rather than what it hangs off: the root expression varies per
adapter and nothing stops the next one from binding its own name, while
a repo path necessarily starts at a repo directory.
And nothing held the reader to seeing anything at all. Rewriting the
adapters into a form it does not parse left the read set empty and the
suite green — the check silently no longer checking, which is exactly how
its predecessor rotted. An adapter with files declared for it is one
whose source names them, so an empty read set there is now a failure.
@Astro-Han
Astro-Han marked this pull request as ready for review August 6, 2026 07:11
@Astro-Han
Astro-Han merged commit 397f44a into mainAug 6, 2026
21 of 23 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

test(headless): read both ways an adapter names a mounted repo file - #2316

Merged
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority
Aug 6, 2026
Merged

test(headless): read both ways an adapter names a mounted repo file#2316
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority

Conversation

@Astro-Han

Copy link
Copy Markdown
Contributor

Summary

Each arm is mounted exactly the repo files it declares, and the check that holds those declarations to what the adapters actually read is the only thing standing between a missed entry and a trial that aborts inside the container. #2298 added that check for the Maka adapter after run-host-cell.mjs — probed by install() in every cell-mode branch — was left out of the declaration. It left the competitor half as it was.

The competitor half saw less than it looked like it saw. It scanned adapter sources for bare filenames and resolved them against packages/headless/harbor, so it could only ever notice a read of a file in that one directory. A competitor adapter reaching for packages/headless/dist/index.js — a path the Maka adapter already reads — matched nothing and passed. It was also matching by coincidence in the other direction: any string literal equal to some filename under harbor/ counted as a read of it.

Both halves now share one reader that matches the two forms adapters actually write:

  • the mounted path spelled out in full (codex_agent.py's _DEEPSEEK_MODELS_PATH),
  • the same path built by joining segments onto the mount root (opencode_agent.py, maka_agent.py).

Bare-filename matching is gone; both forms above cover every read in the adapters today, so nothing is lost with it. The reader is also exercised directly, so it is no longer worth only what today's adapters happen to spell.

Refs #2298.

Verification

  • Red: pointed opencode_agent.py at packages/headless/dist/index.js (a path outside harbor/, undeclared, unmounted). On main all 19 mount tests pass — the gap, reproduced. With this change: opencode_agent.py names packages/headless/dist/index.js, which opencode is not mounted.
  • Green: @maka/headless 1431 pass / 0 fail. npm run lint and npm run format clean.

Not run: desktop E2E and Storybook — test-only change in headless.

Review focus

The reader is a regex over Python source, which is a heuristic, not a parser: an adapter that builds a container path through a variable or an f-string is still invisible to it. That limit is unchanged from #2298; what changes here is that the limit is now the same on both sides and is stated in one place instead of being an accident of which directory the matcher scanned.

The check that holds the mount declarations to what the adapters actually
read is worth exactly what its reader sees, and the competitor half of it
saw less than it looked. It scanned for bare filenames and resolved them
against `packages/headless/harbor`, so a read of any repo file outside
that one directory matched nothing and passed — `dist/index.js`, which
the Maka adapter already reads, would have been invisible had a
competitor adapter reached for it.
This is the gap that cost `run-host-cell.mjs`: the Maka side had no
authority check at all, `install()` probed for a file nobody declared,
and a missing probe target aborts the trial before the arm runs. Closing
it for Maka left the same weakness on the other side.
Both halves now share one reader that matches the two forms adapters
actually write — the mounted path spelled out in full, and the same path
joined onto the mount root — and it is exercised directly rather than
only through whichever forms today's adapters happen to use.
…nothing
Two gaps the first round left, both of the same kind: a regex guard that
stops matching still passes.
The reader recognised the join form only when it hung off `maka_repo`,
and `maka_agent.py` hangs its own headless CLI path off a
`Path("/opt/maka-agent")` constant instead — that read was invisible, and
covered only by the directory mount it happens to fall inside. Match the
chain rather than what it hangs off: the root expression varies per
adapter and nothing stops the next one from binding its own name, while
a repo path necessarily starts at a repo directory.
And nothing held the reader to seeing anything at all. Rewriting the
adapters into a form it does not parse left the read set empty and the
suite green — the check silently no longer checking, which is exactly how
its predecessor rotted. An adapter with files declared for it is one
whose source names them, so an empty read set there is now a failure.
@Astro-Han
Astro-Han marked this pull request as ready for review August 6, 2026 07:11
@Astro-Han
Astro-Han merged commit 397f44a into mainAug 6, 2026
21 of 23 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test(headless): read both ways an adapter names a mounted repo file - #2316

Merged
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority
Aug 6, 2026
Merged

test(headless): read both ways an adapter names a mounted repo file#2316
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority

Conversation

@Astro-Han

Copy link
Copy Markdown
Contributor

Summary

Each arm is mounted exactly the repo files it declares, and the check that holds those declarations to what the adapters actually read is the only thing standing between a missed entry and a trial that aborts inside the container. #2298 added that check for the Maka adapter after run-host-cell.mjs — probed by install() in every cell-mode branch — was left out of the declaration. It left the competitor half as it was.

The competitor half saw less than it looked like it saw. It scanned adapter sources for bare filenames and resolved them against packages/headless/harbor, so it could only ever notice a read of a file in that one directory. A competitor adapter reaching for packages/headless/dist/index.js — a path the Maka adapter already reads — matched nothing and passed. It was also matching by coincidence in the other direction: any string literal equal to some filename under harbor/ counted as a read of it.

Both halves now share one reader that matches the two forms adapters actually write:

  • the mounted path spelled out in full (codex_agent.py's _DEEPSEEK_MODELS_PATH),
  • the same path built by joining segments onto the mount root (opencode_agent.py, maka_agent.py).

Bare-filename matching is gone; both forms above cover every read in the adapters today, so nothing is lost with it. The reader is also exercised directly, so it is no longer worth only what today's adapters happen to spell.

Refs #2298.

Verification

  • Red: pointed opencode_agent.py at packages/headless/dist/index.js (a path outside harbor/, undeclared, unmounted). On main all 19 mount tests pass — the gap, reproduced. With this change: opencode_agent.py names packages/headless/dist/index.js, which opencode is not mounted.
  • Green: @maka/headless 1431 pass / 0 fail. npm run lint and npm run format clean.

Not run: desktop E2E and Storybook — test-only change in headless.

Review focus

The reader is a regex over Python source, which is a heuristic, not a parser: an adapter that builds a container path through a variable or an f-string is still invisible to it. That limit is unchanged from #2298; what changes here is that the limit is now the same on both sides and is stated in one place instead of being an accident of which directory the matcher scanned.

The check that holds the mount declarations to what the adapters actually
read is worth exactly what its reader sees, and the competitor half of it
saw less than it looked. It scanned for bare filenames and resolved them
against `packages/headless/harbor`, so a read of any repo file outside
that one directory matched nothing and passed — `dist/index.js`, which
the Maka adapter already reads, would have been invisible had a
competitor adapter reached for it.
This is the gap that cost `run-host-cell.mjs`: the Maka side had no
authority check at all, `install()` probed for a file nobody declared,
and a missing probe target aborts the trial before the arm runs. Closing
it for Maka left the same weakness on the other side.
Both halves now share one reader that matches the two forms adapters
actually write — the mounted path spelled out in full, and the same path
joined onto the mount root — and it is exercised directly rather than
only through whichever forms today's adapters happen to use.
…nothing
Two gaps the first round left, both of the same kind: a regex guard that
stops matching still passes.
The reader recognised the join form only when it hung off `maka_repo`,
and `maka_agent.py` hangs its own headless CLI path off a
`Path("/opt/maka-agent")` constant instead — that read was invisible, and
covered only by the directory mount it happens to fall inside. Match the
chain rather than what it hangs off: the root expression varies per
adapter and nothing stops the next one from binding its own name, while
a repo path necessarily starts at a repo directory.
And nothing held the reader to seeing anything at all. Rewriting the
adapters into a form it does not parse left the read set empty and the
suite green — the check silently no longer checking, which is exactly how
its predecessor rotted. An adapter with files declared for it is one
whose source names them, so an empty read set there is now a failure.
@Astro-Han
Astro-Han marked this pull request as ready for review August 6, 2026 07:11
@Astro-Han
Astro-Han merged commit 397f44a into mainAug 6, 2026
21 of 23 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test(headless): read both ways an adapter names a mounted repo file - #2316

Merged
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority
Aug 6, 2026
Merged

test(headless): read both ways an adapter names a mounted repo file#2316
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority

Conversation

@Astro-Han

Copy link
Copy Markdown
Contributor

Summary

Each arm is mounted exactly the repo files it declares, and the check that holds those declarations to what the adapters actually read is the only thing standing between a missed entry and a trial that aborts inside the container. #2298 added that check for the Maka adapter after run-host-cell.mjs — probed by install() in every cell-mode branch — was left out of the declaration. It left the competitor half as it was.

The competitor half saw less than it looked like it saw. It scanned adapter sources for bare filenames and resolved them against packages/headless/harbor, so it could only ever notice a read of a file in that one directory. A competitor adapter reaching for packages/headless/dist/index.js — a path the Maka adapter already reads — matched nothing and passed. It was also matching by coincidence in the other direction: any string literal equal to some filename under harbor/ counted as a read of it.

Both halves now share one reader that matches the two forms adapters actually write:

  • the mounted path spelled out in full (codex_agent.py's _DEEPSEEK_MODELS_PATH),
  • the same path built by joining segments onto the mount root (opencode_agent.py, maka_agent.py).

Bare-filename matching is gone; both forms above cover every read in the adapters today, so nothing is lost with it. The reader is also exercised directly, so it is no longer worth only what today's adapters happen to spell.

Refs #2298.

Verification

  • Red: pointed opencode_agent.py at packages/headless/dist/index.js (a path outside harbor/, undeclared, unmounted). On main all 19 mount tests pass — the gap, reproduced. With this change: opencode_agent.py names packages/headless/dist/index.js, which opencode is not mounted.
  • Green: @maka/headless 1431 pass / 0 fail. npm run lint and npm run format clean.

Not run: desktop E2E and Storybook — test-only change in headless.

Review focus

The reader is a regex over Python source, which is a heuristic, not a parser: an adapter that builds a container path through a variable or an f-string is still invisible to it. That limit is unchanged from #2298; what changes here is that the limit is now the same on both sides and is stated in one place instead of being an accident of which directory the matcher scanned.

The check that holds the mount declarations to what the adapters actually
read is worth exactly what its reader sees, and the competitor half of it
saw less than it looked. It scanned for bare filenames and resolved them
against `packages/headless/harbor`, so a read of any repo file outside
that one directory matched nothing and passed — `dist/index.js`, which
the Maka adapter already reads, would have been invisible had a
competitor adapter reached for it.
This is the gap that cost `run-host-cell.mjs`: the Maka side had no
authority check at all, `install()` probed for a file nobody declared,
and a missing probe target aborts the trial before the arm runs. Closing
it for Maka left the same weakness on the other side.
Both halves now share one reader that matches the two forms adapters
actually write — the mounted path spelled out in full, and the same path
joined onto the mount root — and it is exercised directly rather than
only through whichever forms today's adapters happen to use.
…nothing
Two gaps the first round left, both of the same kind: a regex guard that
stops matching still passes.
The reader recognised the join form only when it hung off `maka_repo`,
and `maka_agent.py` hangs its own headless CLI path off a
`Path("/opt/maka-agent")` constant instead — that read was invisible, and
covered only by the directory mount it happens to fall inside. Match the
chain rather than what it hangs off: the root expression varies per
adapter and nothing stops the next one from binding its own name, while
a repo path necessarily starts at a repo directory.
And nothing held the reader to seeing anything at all. Rewriting the
adapters into a form it does not parse left the read set empty and the
suite green — the check silently no longer checking, which is exactly how
its predecessor rotted. An adapter with files declared for it is one
whose source names them, so an empty read set there is now a failure.
@Astro-Han
Astro-Han marked this pull request as ready for review August 6, 2026 07:11
@Astro-Han
Astro-Han merged commit 397f44a into mainAug 6, 2026
21 of 23 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

test(headless): read both ways an adapter names a mounted repo file - #2316

Merged
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority
Aug 6, 2026
Merged

test(headless): read both ways an adapter names a mounted repo file#2316
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority

Conversation

@Astro-Han

Copy link
Copy Markdown
Contributor

Summary

Each arm is mounted exactly the repo files it declares, and the check that holds those declarations to what the adapters actually read is the only thing standing between a missed entry and a trial that aborts inside the container. #2298 added that check for the Maka adapter after run-host-cell.mjs — probed by install() in every cell-mode branch — was left out of the declaration. It left the competitor half as it was.

The competitor half saw less than it looked like it saw. It scanned adapter sources for bare filenames and resolved them against packages/headless/harbor, so it could only ever notice a read of a file in that one directory. A competitor adapter reaching for packages/headless/dist/index.js — a path the Maka adapter already reads — matched nothing and passed. It was also matching by coincidence in the other direction: any string literal equal to some filename under harbor/ counted as a read of it.

Both halves now share one reader that matches the two forms adapters actually write:

  • the mounted path spelled out in full (codex_agent.py's _DEEPSEEK_MODELS_PATH),
  • the same path built by joining segments onto the mount root (opencode_agent.py, maka_agent.py).

Bare-filename matching is gone; both forms above cover every read in the adapters today, so nothing is lost with it. The reader is also exercised directly, so it is no longer worth only what today's adapters happen to spell.

Refs #2298.

Verification

  • Red: pointed opencode_agent.py at packages/headless/dist/index.js (a path outside harbor/, undeclared, unmounted). On main all 19 mount tests pass — the gap, reproduced. With this change: opencode_agent.py names packages/headless/dist/index.js, which opencode is not mounted.
  • Green: @maka/headless 1431 pass / 0 fail. npm run lint and npm run format clean.

Not run: desktop E2E and Storybook — test-only change in headless.

Review focus

The reader is a regex over Python source, which is a heuristic, not a parser: an adapter that builds a container path through a variable or an f-string is still invisible to it. That limit is unchanged from #2298; what changes here is that the limit is now the same on both sides and is stated in one place instead of being an accident of which directory the matcher scanned.

The check that holds the mount declarations to what the adapters actually
read is worth exactly what its reader sees, and the competitor half of it
saw less than it looked. It scanned for bare filenames and resolved them
against `packages/headless/harbor`, so a read of any repo file outside
that one directory matched nothing and passed — `dist/index.js`, which
the Maka adapter already reads, would have been invisible had a
competitor adapter reached for it.
This is the gap that cost `run-host-cell.mjs`: the Maka side had no
authority check at all, `install()` probed for a file nobody declared,
and a missing probe target aborts the trial before the arm runs. Closing
it for Maka left the same weakness on the other side.
Both halves now share one reader that matches the two forms adapters
actually write — the mounted path spelled out in full, and the same path
joined onto the mount root — and it is exercised directly rather than
only through whichever forms today's adapters happen to use.
…nothing
Two gaps the first round left, both of the same kind: a regex guard that
stops matching still passes.
The reader recognised the join form only when it hung off `maka_repo`,
and `maka_agent.py` hangs its own headless CLI path off a
`Path("/opt/maka-agent")` constant instead — that read was invisible, and
covered only by the directory mount it happens to fall inside. Match the
chain rather than what it hangs off: the root expression varies per
adapter and nothing stops the next one from binding its own name, while
a repo path necessarily starts at a repo directory.
And nothing held the reader to seeing anything at all. Rewriting the
adapters into a form it does not parse left the read set empty and the
suite green — the check silently no longer checking, which is exactly how
its predecessor rotted. An adapter with files declared for it is one
whose source names them, so an empty read set there is now a failure.
@Astro-Han
Astro-Han marked this pull request as ready for review August 6, 2026 07:11
@Astro-Han
Astro-Han merged commit 397f44a into mainAug 6, 2026
21 of 23 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test(headless): read both ways an adapter names a mounted repo file - #2316

Merged
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority
Aug 6, 2026
Merged

test(headless): read both ways an adapter names a mounted repo file#2316
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority

Conversation

@Astro-Han

Copy link
Copy Markdown
Contributor

Summary

Each arm is mounted exactly the repo files it declares, and the check that holds those declarations to what the adapters actually read is the only thing standing between a missed entry and a trial that aborts inside the container. #2298 added that check for the Maka adapter after run-host-cell.mjs — probed by install() in every cell-mode branch — was left out of the declaration. It left the competitor half as it was.

The competitor half saw less than it looked like it saw. It scanned adapter sources for bare filenames and resolved them against packages/headless/harbor, so it could only ever notice a read of a file in that one directory. A competitor adapter reaching for packages/headless/dist/index.js — a path the Maka adapter already reads — matched nothing and passed. It was also matching by coincidence in the other direction: any string literal equal to some filename under harbor/ counted as a read of it.

Both halves now share one reader that matches the two forms adapters actually write:

  • the mounted path spelled out in full (codex_agent.py's _DEEPSEEK_MODELS_PATH),
  • the same path built by joining segments onto the mount root (opencode_agent.py, maka_agent.py).

Bare-filename matching is gone; both forms above cover every read in the adapters today, so nothing is lost with it. The reader is also exercised directly, so it is no longer worth only what today's adapters happen to spell.

Refs #2298.

Verification

  • Red: pointed opencode_agent.py at packages/headless/dist/index.js (a path outside harbor/, undeclared, unmounted). On main all 19 mount tests pass — the gap, reproduced. With this change: opencode_agent.py names packages/headless/dist/index.js, which opencode is not mounted.
  • Green: @maka/headless 1431 pass / 0 fail. npm run lint and npm run format clean.

Not run: desktop E2E and Storybook — test-only change in headless.

Review focus

The reader is a regex over Python source, which is a heuristic, not a parser: an adapter that builds a container path through a variable or an f-string is still invisible to it. That limit is unchanged from #2298; what changes here is that the limit is now the same on both sides and is stated in one place instead of being an accident of which directory the matcher scanned.

The check that holds the mount declarations to what the adapters actually
read is worth exactly what its reader sees, and the competitor half of it
saw less than it looked. It scanned for bare filenames and resolved them
against `packages/headless/harbor`, so a read of any repo file outside
that one directory matched nothing and passed — `dist/index.js`, which
the Maka adapter already reads, would have been invisible had a
competitor adapter reached for it.
This is the gap that cost `run-host-cell.mjs`: the Maka side had no
authority check at all, `install()` probed for a file nobody declared,
and a missing probe target aborts the trial before the arm runs. Closing
it for Maka left the same weakness on the other side.
Both halves now share one reader that matches the two forms adapters
actually write — the mounted path spelled out in full, and the same path
joined onto the mount root — and it is exercised directly rather than
only through whichever forms today's adapters happen to use.
…nothing
Two gaps the first round left, both of the same kind: a regex guard that
stops matching still passes.
The reader recognised the join form only when it hung off `maka_repo`,
and `maka_agent.py` hangs its own headless CLI path off a
`Path("/opt/maka-agent")` constant instead — that read was invisible, and
covered only by the directory mount it happens to fall inside. Match the
chain rather than what it hangs off: the root expression varies per
adapter and nothing stops the next one from binding its own name, while
a repo path necessarily starts at a repo directory.
And nothing held the reader to seeing anything at all. Rewriting the
adapters into a form it does not parse left the read set empty and the
suite green — the check silently no longer checking, which is exactly how
its predecessor rotted. An adapter with files declared for it is one
whose source names them, so an empty read set there is now a failure.
@Astro-Han
Astro-Han marked this pull request as ready for review August 6, 2026 07:11
@Astro-Han
Astro-Han merged commit 397f44a into mainAug 6, 2026
21 of 23 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test(headless): read both ways an adapter names a mounted repo file - #2316

Merged
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority
Aug 6, 2026
Merged

test(headless): read both ways an adapter names a mounted repo file#2316
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority

Conversation

@Astro-Han

Copy link
Copy Markdown
Contributor

Summary

Each arm is mounted exactly the repo files it declares, and the check that holds those declarations to what the adapters actually read is the only thing standing between a missed entry and a trial that aborts inside the container. #2298 added that check for the Maka adapter after run-host-cell.mjs — probed by install() in every cell-mode branch — was left out of the declaration. It left the competitor half as it was.

The competitor half saw less than it looked like it saw. It scanned adapter sources for bare filenames and resolved them against packages/headless/harbor, so it could only ever notice a read of a file in that one directory. A competitor adapter reaching for packages/headless/dist/index.js — a path the Maka adapter already reads — matched nothing and passed. It was also matching by coincidence in the other direction: any string literal equal to some filename under harbor/ counted as a read of it.

Both halves now share one reader that matches the two forms adapters actually write:

  • the mounted path spelled out in full (codex_agent.py's _DEEPSEEK_MODELS_PATH),
  • the same path built by joining segments onto the mount root (opencode_agent.py, maka_agent.py).

Bare-filename matching is gone; both forms above cover every read in the adapters today, so nothing is lost with it. The reader is also exercised directly, so it is no longer worth only what today's adapters happen to spell.

Refs #2298.

Verification

  • Red: pointed opencode_agent.py at packages/headless/dist/index.js (a path outside harbor/, undeclared, unmounted). On main all 19 mount tests pass — the gap, reproduced. With this change: opencode_agent.py names packages/headless/dist/index.js, which opencode is not mounted.
  • Green: @maka/headless 1431 pass / 0 fail. npm run lint and npm run format clean.

Not run: desktop E2E and Storybook — test-only change in headless.

Review focus

The reader is a regex over Python source, which is a heuristic, not a parser: an adapter that builds a container path through a variable or an f-string is still invisible to it. That limit is unchanged from #2298; what changes here is that the limit is now the same on both sides and is stated in one place instead of being an accident of which directory the matcher scanned.

The check that holds the mount declarations to what the adapters actually
read is worth exactly what its reader sees, and the competitor half of it
saw less than it looked. It scanned for bare filenames and resolved them
against `packages/headless/harbor`, so a read of any repo file outside
that one directory matched nothing and passed — `dist/index.js`, which
the Maka adapter already reads, would have been invisible had a
competitor adapter reached for it.
This is the gap that cost `run-host-cell.mjs`: the Maka side had no
authority check at all, `install()` probed for a file nobody declared,
and a missing probe target aborts the trial before the arm runs. Closing
it for Maka left the same weakness on the other side.
Both halves now share one reader that matches the two forms adapters
actually write — the mounted path spelled out in full, and the same path
joined onto the mount root — and it is exercised directly rather than
only through whichever forms today's adapters happen to use.
…nothing
Two gaps the first round left, both of the same kind: a regex guard that
stops matching still passes.
The reader recognised the join form only when it hung off `maka_repo`,
and `maka_agent.py` hangs its own headless CLI path off a
`Path("/opt/maka-agent")` constant instead — that read was invisible, and
covered only by the directory mount it happens to fall inside. Match the
chain rather than what it hangs off: the root expression varies per
adapter and nothing stops the next one from binding its own name, while
a repo path necessarily starts at a repo directory.
And nothing held the reader to seeing anything at all. Rewriting the
adapters into a form it does not parse left the read set empty and the
suite green — the check silently no longer checking, which is exactly how
its predecessor rotted. An adapter with files declared for it is one
whose source names them, so an empty read set there is now a failure.
@Astro-Han
Astro-Han marked this pull request as ready for review August 6, 2026 07:11
@Astro-Han
Astro-Han merged commit 397f44a into mainAug 6, 2026
21 of 23 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

test(headless): read both ways an adapter names a mounted repo file - #2316

Merged
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority
Aug 6, 2026
Merged

test(headless): read both ways an adapter names a mounted repo file#2316
Astro-Han merged 2 commits into
mainfrom
test/headless-mount-declaration-authority

Conversation

@Astro-Han

Copy link
Copy Markdown
Contributor

Summary

Each arm is mounted exactly the repo files it declares, and the check that holds those declarations to what the adapters actually read is the only thing standing between a missed entry and a trial that aborts inside the container. #2298 added that check for the Maka adapter after run-host-cell.mjs — probed by install() in every cell-mode branch — was left out of the declaration. It left the competitor half as it was.

The competitor half saw less than it looked like it saw. It scanned adapter sources for bare filenames and resolved them against packages/headless/harbor, so it could only ever notice a read of a file in that one directory. A competitor adapter reaching for packages/headless/dist/index.js — a path the Maka adapter already reads — matched nothing and passed. It was also matching by coincidence in the other direction: any string literal equal to some filename under harbor/ counted as a read of it.

Both halves now share one reader that matches the two forms adapters actually write:

  • the mounted path spelled out in full (codex_agent.py's _DEEPSEEK_MODELS_PATH),
  • the same path built by joining segments onto the mount root (opencode_agent.py, maka_agent.py).

Bare-filename matching is gone; both forms above cover every read in the adapters today, so nothing is lost with it. The reader is also exercised directly, so it is no longer worth only what today's adapters happen to spell.

Refs #2298.

Verification

  • Red: pointed opencode_agent.py at packages/headless/dist/index.js (a path outside harbor/, undeclared, unmounted). On main all 19 mount tests pass — the gap, reproduced. With this change: opencode_agent.py names packages/headless/dist/index.js, which opencode is not mounted.
  • Green: @maka/headless 1431 pass / 0 fail. npm run lint and npm run format clean.

Not run: desktop E2E and Storybook — test-only change in headless.

Review focus

The reader is a regex over Python source, which is a heuristic, not a parser: an adapter that builds a container path through a variable or an f-string is still invisible to it. That limit is unchanged from #2298; what changes here is that the limit is now the same on both sides and is stated in one place instead of being an accident of which directory the matcher scanned.

The check that holds the mount declarations to what the adapters actually
read is worth exactly what its reader sees, and the competitor half of it
saw less than it looked. It scanned for bare filenames and resolved them
against `packages/headless/harbor`, so a read of any repo file outside
that one directory matched nothing and passed — `dist/index.js`, which
the Maka adapter already reads, would have been invisible had a
competitor adapter reached for it.
This is the gap that cost `run-host-cell.mjs`: the Maka side had no
authority check at all, `install()` probed for a file nobody declared,
and a missing probe target aborts the trial before the arm runs. Closing
it for Maka left the same weakness on the other side.
Both halves now share one reader that matches the two forms adapters
actually write — the mounted path spelled out in full, and the same path
joined onto the mount root — and it is exercised directly rather than
only through whichever forms today's adapters happen to use.
…nothing
Two gaps the first round left, both of the same kind: a regex guard that
stops matching still passes.
The reader recognised the join form only when it hung off `maka_repo`,
and `maka_agent.py` hangs its own headless CLI path off a
`Path("/opt/maka-agent")` constant instead — that read was invisible, and
covered only by the directory mount it happens to fall inside. Match the
chain rather than what it hangs off: the root expression varies per
adapter and nothing stops the next one from binding its own name, while
a repo path necessarily starts at a repo directory.
And nothing held the reader to seeing anything at all. Rewriting the
adapters into a form it does not parse left the read set empty and the
suite green — the check silently no longer checking, which is exactly how
its predecessor rotted. An adapter with files declared for it is one
whose source names them, so an empty read set there is now a failure.
@Astro-Han
Astro-Han marked this pull request as ready for review August 6, 2026 07:11
@Astro-Han
Astro-Han merged commit 397f44a into mainAug 6, 2026
21 of 23 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Astro-Han