Skip to content

feat(plugin): 1.3.0 — per-step model classes, workflow autonomy and consent, source-verified against lua-cli - #11

Merged
lua-stefan-kruger merged 2 commits into
mainfrom
feat/knowledge-model-classes-autonomy
Sep 18, 2026
Merged

lua-stefan-kruger merged 2 commits into
mainfrom
feat/knowledge-model-classes-autonomy

Conversation

@lua-stefan-kruger

@lua-stefan-kruger lua-stefan-kruger commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

What

Plugin 1.3.0: the knowledge base, slash commands, subagents and user guide learn two shipped platform features, with every claim read from lua-core-services source (never the docs), per the standing rule. Both ship in lua-cli 3.36.0, so the plugin's pinned minimum moves 3.33.0 → 3.36.0.

Per-step model classes — lua-cli main 12cefb7ec (WMC-E7 #2969, hotfixes H7 #3053 / H8 #3051, stage-all fix #3024)

  • agentStep taskClass (classify extract transform draft research reason code judge), model: 'class/fast|balanced|strong', requires (vision structured largeContext codeExecution), modelReason (≤ 160), effort (low medium high) — marked recorded, not applied until lua push workflow --apply-effort.
  • lua models list --workflows; lua workflows policy models get|set (--compose --max-class --consent-actions --allow --class-fast|balanced|strong --class-map --pins --fallback); clear-gate <runId> --kind model_policy; recompose; the consent card on start; status 🧠 By model, step-row model fields, the ⇅ approver escalated line; status --strict exit 6 on a gated run; lua workflows logs model events; push-time refusals (local vocabulary codes; server task-class-without-model, model-class-resolution-off).
  • Forward warning: 3.36.0's lua push all also pushes and activates workflows (#3024) — /lua-push, /lua-deploy, the pilot and cli-reference say so.

Workflow autonomy and consent — feat/workflow-autonomy 378403322

  • The consent ladder (decide(): 15 steps / 20 credits / 3600 s expected wall; refuse when askAboveThresholds: false; agent legs only — lua workflows start is not scored), the start-consent gate a person clears (approve cannot).
  • The envelope (enabled absent ⇒ false; defaults 20 / 15 / 86 400 / org consentActions / 20 / graph,static; ceilings 40 / 604 800 / caps.maxCreditsPerRun / 200), the one ask→auto flip, goal and batch starts never auto-start, the hourly bucket degrades to ask.
  • lua workflows policy autonomy get|set (--enabled --max-credits --max-steps --max-duration --max-actions --max-runs-per-hour --forms --clear; --agent refused), the Consent: auto (policy) — ≤ … line.
  • The architect now composes workflows that start without asking when the org allows it and writes the admin's policy autonomy set line otherwise.

Version

Coordinator decision (2026-09-18): the next lua-cli release is 3.36.0, cut from those two refs and published to npm today after the autonomy production merge. 3.35.0 (tag 8d65d1ba8) carries none of the verbs (0 matches in its command-definitions.ts), so every addition is marked ⏳ requires lua-cli 3.36.0 or later and PINNED_MIN_LUA_CLI is 3.36.0 — the session hook's warning now names /lua-update and npm i -g lua-cli@latest and says which verbs are missing below the pin.

Machinery

  • lib/permissions-template.json: allow lua workflows policy * get*; ask policy * set*, clear-gate/ungate, recompose/recompile (+ mirror test rows).
  • scripts/lint-knowledge-commands.mjs: policy, clear-gate, recompose in the workflows verb list; scripts/lint-cli-flags.mjs: two new denylist rows.
  • Bump 1.2.2 → 1.3.0 everywhere; mcp/lua-platform/dist/server.js rebuilt. The pin is the only hook change (no hook reads a lua workflows exit code).

Verification

  • LUA_CLI_SRC=<lua-cli feat/workflow-autonomy 378403322 worktree> node scripts/lint-knowledge-commands.mjs → ✓ 804 references (716 before); also ✓ against main.
  • npm test → 18 suites / 428 tests ✓ · mcp/lua-platform npm test → 9 suites / 147 tests ✓ · eslint ✓ · 17 of 18 lint scripts ✓.
  • ⚠ scripts/lint-pinned-version.mjs is red until lua-cli 3.36.0 is on npm (it compares the pin with dist-tags.latest, currently 3.35.0, and was deliberately not weakened) — so CI on this PR shows that one failure until the publish; it is re-run before the merge.
  • Audit report with the findings table: lua-docs-v2-plan/plan-model-routing/reviews/plugin-audit-2026-09-18.md.

Merge plan

Hold until "3.36.0 is on npm" → verify npm view lua-cli version = 3.36.0 → npm run lint all green → gh pr merge 11 --squash --admin → watch release-prod.yml (publishes 1.3.0).

Open questions (not changed here)

  1. Whether lua push all should become hook-gated now that 3.36.0 activates workflows in stage-all.
  2. Whether lua workflows recompose of a dynamic (chat-composed) workflow makes the new version live at once — it sits in ask for now.

🤖 Generated with Claude Code

lua-stefan-kruger and others added 2 commits September 18, 2026 09:54
…onsent, source-verified against lua-cli

Two shipped platform features reach the knowledge base, slash commands and
subagents, every claim read from lua-core-services rather than the docs:

- Per-step model classes (lua-cli main 12cefb7ec: WMC-E7 #2969, H7 #3053,
  H8 #3051, stage-all fix #3024): agentStep taskClass / model 'class/<c>' /
  requires / modelReason / effort (recorded, not applied until
  `lua push --apply-effort`); `lua models list --workflows`; `lua workflows
  policy models get|set` with every flag and value set; `clear-gate --kind
  model_policy`; `recompose`; the consent card on `start`; `status` By-model
  roll-up, step-row model fields, the approver-fallback line; `status
  --strict` exit 6 on a gated run; `lua workflows logs` model events; the
  push-time refusals (local vocabulary codes, server task-class-without-model
  and model-class-resolution-off).
- Workflow autonomy (feat/workflow-autonomy 378403322): the consent ladder
  (15 steps / 20 credits / 3600 s expected wall, refuse when
  askAboveThresholds is false, agent legs only), the autonomy envelope
  (defaults 20/15/86400/consentActions/20/graph,static; ceilings
  40/604800/caps.maxCreditsPerRun/200), the one ask→auto flip, goal and
  batch starts never auto-start, the hourly bucket degrades to ask;
  `lua workflows policy autonomy get|set` flags incl. --clear and the
  refused --agent; the `Consent: auto (policy)` line.
- Architect composes for starting without a question; debug/status/workflow
  slashes read exit 6, the model_policy park, the Consent line and the
  approver fallback; push/deploy surfaces warn that the next lua-cli's
  `lua push all` also activates workflows.

Version decision: npm latest lua-cli is 3.35.0 (tag 8d65d1ba8, 2026-09-15)
and carries none of it; both refs still say 3.35.0 in package.json and no
release PR is open, so the features are described as "requires lua-cli >
3.35.0 (unreleased as of 2026-09-18)" and PINNED_MIN_LUA_CLI stays 3.33.0.

Machinery: permission template (policy get allowed; policy set, clear-gate,
recompose ask), mirror test, lint-knowledge-commands verb list,
lint-cli-flags denylist; bump 1.2.2 → 1.3.0 everywhere; MCP bundle rebuilt.
No hook behaviour changed (no hook reads a `lua workflows` exit code).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…unreleased)" wording replaced

Coordinator decision: the next lua-cli release is 3.36.0, published today
after the autonomy production merge, carrying the model-classes verbs,
H7/H8 and the autonomy verbs.

- Every "requires lua-cli > 3.35.0 (unreleased as of 2026-09-18)" site now
  reads "requires lua-cli 3.36.0 or later" (⏳ legend in the knowledge
  headers: "3.33.0 base · 3.36.0 additions marked ⏳").
- PINNED_MIN_LUA_CLI 3.33.0 → 3.36.0 (hooks/check-lua-version.mjs); the
  warning names /lua-update and `npm i -g lua-cli@latest` and says which
  verbs are missing below the pin; test updated.
- /lua-init, /lua-update, /lua-doctor, docs/USER_GUIDE.md (intro,
  prerequisites, hooks table, FAQ), both READMEs, the permission template
  comment, lint comments and the CHANGELOG entry say 3.36.0.

scripts/lint-pinned-version.mjs stays red until 3.36.0 is on npm (it
compares the pin with dist-tags.latest and was not weakened); every other
lint and the tests are green.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@lua-stefan-kruger
lua-stefan-kruger merged commit ed6ea52 into main Sep 18, 2026
3 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant