feat(plugin): 1.3.0 — per-step model classes, workflow autonomy and consent, source-verified against lua-cli - #11
Merged
Conversation
…onsent, source-verified against lua-cli Two shipped platform features reach the knowledge base, slash commands and subagents, every claim read from lua-core-services rather than the docs: - Per-step model classes (lua-cli main 12cefb7ec: WMC-E7 #2969, H7 #3053, H8 #3051, stage-all fix #3024): agentStep taskClass / model 'class/<c>' / requires / modelReason / effort (recorded, not applied until `lua push --apply-effort`); `lua models list --workflows`; `lua workflows policy models get|set` with every flag and value set; `clear-gate --kind model_policy`; `recompose`; the consent card on `start`; `status` By-model roll-up, step-row model fields, the approver-fallback line; `status --strict` exit 6 on a gated run; `lua workflows logs` model events; the push-time refusals (local vocabulary codes, server task-class-without-model and model-class-resolution-off). - Workflow autonomy (feat/workflow-autonomy 378403322): the consent ladder (15 steps / 20 credits / 3600 s expected wall, refuse when askAboveThresholds is false, agent legs only), the autonomy envelope (defaults 20/15/86400/consentActions/20/graph,static; ceilings 40/604800/caps.maxCreditsPerRun/200), the one ask→auto flip, goal and batch starts never auto-start, the hourly bucket degrades to ask; `lua workflows policy autonomy get|set` flags incl. --clear and the refused --agent; the `Consent: auto (policy)` line. - Architect composes for starting without a question; debug/status/workflow slashes read exit 6, the model_policy park, the Consent line and the approver fallback; push/deploy surfaces warn that the next lua-cli's `lua push all` also activates workflows. Version decision: npm latest lua-cli is 3.35.0 (tag 8d65d1ba8, 2026-09-15) and carries none of it; both refs still say 3.35.0 in package.json and no release PR is open, so the features are described as "requires lua-cli > 3.35.0 (unreleased as of 2026-09-18)" and PINNED_MIN_LUA_CLI stays 3.33.0. Machinery: permission template (policy get allowed; policy set, clear-gate, recompose ask), mirror test, lint-knowledge-commands verb list, lint-cli-flags denylist; bump 1.2.2 → 1.3.0 everywhere; MCP bundle rebuilt. No hook behaviour changed (no hook reads a `lua workflows` exit code). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…unreleased)" wording replaced Coordinator decision: the next lua-cli release is 3.36.0, published today after the autonomy production merge, carrying the model-classes verbs, H7/H8 and the autonomy verbs. - Every "requires lua-cli > 3.35.0 (unreleased as of 2026-09-18)" site now reads "requires lua-cli 3.36.0 or later" (⏳ legend in the knowledge headers: "3.33.0 base · 3.36.0 additions marked ⏳"). - PINNED_MIN_LUA_CLI 3.33.0 → 3.36.0 (hooks/check-lua-version.mjs); the warning names /lua-update and `npm i -g lua-cli@latest` and says which verbs are missing below the pin; test updated. - /lua-init, /lua-update, /lua-doctor, docs/USER_GUIDE.md (intro, prerequisites, hooks table, FAQ), both READMEs, the permission template comment, lint comments and the CHANGELOG entry say 3.36.0. scripts/lint-pinned-version.mjs stays red until 3.36.0 is on npm (it compares the pin with dist-tags.latest and was not weakened); every other lint and the tests are green. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Plugin 1.3.0: the knowledge base, slash commands, subagents and user guide learn two shipped platform features, with every claim read from lua-core-services source (never the docs), per the standing rule. Both ship in lua-cli 3.36.0, so the plugin's pinned minimum moves 3.33.0 → 3.36.0.
Per-step model classes — lua-cli
main12cefb7ec(WMC-E7 #2969, hotfixes H7 #3053 / H8 #3051, stage-all fix #3024)agentSteptaskClass(classify extract transform draft research reason code judge),model: 'class/fast|balanced|strong',requires(vision structured largeContext codeExecution),modelReason(≤ 160),effort(low medium high) — marked recorded, not applied untillua push workflow --apply-effort.lua models list --workflows;lua workflows policy models get|set(--compose --max-class --consent-actions --allow --class-fast|balanced|strong --class-map --pins --fallback);clear-gate <runId> --kind model_policy;recompose; the consent card onstart;status🧠 By model, step-row model fields, the⇅ approver escalatedline;status --strictexit 6 on a gated run;lua workflows logsmodel events; push-time refusals (local vocabulary codes; servertask-class-without-model,model-class-resolution-off).lua push allalso pushes and activates workflows (#3024) —/lua-push,/lua-deploy, the pilot and cli-reference say so.Workflow autonomy and consent —
feat/workflow-autonomy378403322decide(): 15 steps / 20 credits / 3600 s expected wall; refuse whenaskAboveThresholds: false; agent legs only —lua workflows startis not scored), thestart-consentgate a person clears (approvecannot).enabledabsent ⇒ false; defaults 20 / 15 / 86 400 / orgconsentActions/ 20 /graph,static; ceilings 40 / 604 800 /caps.maxCreditsPerRun/ 200), the one ask→auto flip, goal and batch starts never auto-start, the hourly bucket degrades to ask.lua workflows policy autonomy get|set(--enabled --max-credits --max-steps --max-duration --max-actions --max-runs-per-hour --forms --clear;--agentrefused), theConsent: auto (policy) — ≤ …line.policy autonomy setline otherwise.Version
Coordinator decision (2026-09-18): the next lua-cli release is 3.36.0, cut from those two refs and published to npm today after the autonomy production merge. 3.35.0 (tag
8d65d1ba8) carries none of the verbs (0 matches in itscommand-definitions.ts), so every addition is marked ⏳ requires lua-cli 3.36.0 or later andPINNED_MIN_LUA_CLIis 3.36.0 — the session hook's warning now names/lua-updateandnpm i -g lua-cli@latestand says which verbs are missing below the pin.Machinery
lib/permissions-template.json: allowlua workflows policy * get*; askpolicy * set*,clear-gate/ungate,recompose/recompile(+ mirror test rows).scripts/lint-knowledge-commands.mjs:policy,clear-gate,recomposein theworkflowsverb list;scripts/lint-cli-flags.mjs: two new denylist rows.mcp/lua-platform/dist/server.jsrebuilt. The pin is the only hook change (no hook reads alua workflowsexit code).Verification
LUA_CLI_SRC=<lua-cli feat/workflow-autonomy 378403322 worktree> node scripts/lint-knowledge-commands.mjs→ ✓ 804 references (716 before); also ✓ againstmain.npm test→ 18 suites / 428 tests ✓ ·mcp/lua-platformnpm test→ 9 suites / 147 tests ✓ · eslint ✓ · 17 of 18 lint scripts ✓.scripts/lint-pinned-version.mjsis red until lua-cli 3.36.0 is on npm (it compares the pin withdist-tags.latest, currently 3.35.0, and was deliberately not weakened) — so CI on this PR shows that one failure until the publish; it is re-run before the merge.lua-docs-v2-plan/plan-model-routing/reviews/plugin-audit-2026-09-18.md.Merge plan
Hold until "3.36.0 is on npm" → verify
npm view lua-cli version= 3.36.0 →npm run lintall green →gh pr merge 11 --squash --admin→ watchrelease-prod.yml(publishes 1.3.0).Open questions (not changed here)
lua push allshould become hook-gated now that 3.36.0 activates workflows in stage-all.lua workflows recomposeof a dynamic (chat-composed) workflow makes the new version live at once — it sits inaskfor now.🤖 Generated with Claude Code