* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures
Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.
Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.
* fix(scripts): keep guarded portable scripts bash 3.2 compatible
* fix(scripts): keep macOS Bash CI coverage green
Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.
Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.
* docs(install): use system Bash in install and recovery commands
Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.
Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.
* fix(scripts): preserve streamed installs and CI packing
Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.
Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.
Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
* fix(update): preserve explicit plugin capability consent
* fix(update): bind plugin consent to staged artifacts
Use the canonical artifact consent adapter for channel migrations and preserve
explicit consent through the update wizard. Keep prior usable payloads on denial
and record the exact accepted surface through the existing install-record owner.
Cover parser boundaries, staged artifact changes, and packaged update/repair
handoffs without treating --yes as consent or granting future permission.
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
* test(update): register consent scenario with probe
Route the packaged consent scenario through the existing plugin-update probe
so Knip discovers the implementation through its normal entry graph. Initialize
scenario state only when the consent command runs, preserving other probe modes.
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
* fix(update): retain consent with compatible finalizers
Inspect the installed update command before forwarding explicit consent so
older and same-version target CLIs keep finalization in the existing parent
path when they lack the option. Preserve the installed compatibility host
through plugin convergence and reuse the update step timeout for inspection.
Use built-in streaming SHA256 for the packaged proof rather than requiring
an undeclared checksum binary.
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
* fix(update): keep convergence code loaded across replacement
Link the mandatory registry repair before the core package swap removes the
old updater's chunks. This keeps current-process finalization runnable when
the installed target cannot receive explicit capability consent, without
retaining old runtime files or changing plugin policy.
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
* test(cli): await MCP Doctor batch readiness
Synchronize the concurrency test at the fourth credential check instead of
polling command startup with a wall-clock deadline. Release blocked checks
and await Doctor in finally, including early command or assertion failures.
Keep the exact concurrency, total-check and sorted-result assertions.
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>