Skip to content

Claude/youthful dirac vd1ei1 - #93

Closed
thisguymartin wants to merge 24 commits into
ericlitman:mainfrom
thisguymartin:claude/youthful-dirac-vd1ei1
Closed

thisguymartin wants to merge 24 commits into
ericlitman:mainfrom
thisguymartin:claude/youthful-dirac-vd1ei1

Conversation

@thisguymartin

Copy link
Copy Markdown

No description provided.

thisguymartin and others added 22 commits September 27, 2026 21:43
Fork of ericlitman/open-pstack at v1.4.1 (de67e6b). UPSTREAM-FLEX.md adds
the second sync layer (cursor -> open-pstack -> flex) with the merge
rehearsal procedure and the expected conflict surface for upstream 1.5.0.
NOTICE.md records the provenance chain, LICENSE adds the fork copyright
line without removing existing holders, and the README gains a fork
section stating what flex adds and that a stock install behaves exactly
like upstream.
New gateway lanes run the stock claude binary against each lab's
Anthropic-compatible endpoint, reusing the exact claude argv and the
existing spawn path. flex-providers.ts owns the per-provider env maps:
endpoint (overridable), ANTHROPIC_AUTH_TOKEN from DEEPSEEK_API_KEY or
MINIMAX_API_KEY, model pins, nonessential-traffic and attribution-header
hygiene, and an isolated CLAUDE_CONFIG_DIR under ~/.pstack-flex.
childEnvironment deletes inherited ANTHROPIC_* values before injection so
a parent session's credentials or endpoint never bleed into a gateway
child.

- Preflight is claude --version: auth-status semantics under token auth
  are undocumented, credentials are checked in-process, and the one-shot
  invocation is the real auth test.
- Gateway receipts force costUsd to null (the CLI prices total_cost_usd
  at Anthropic rates, fiction for third-party traffic); token usage stays.
- Served models match case-insensitively (MiniMax-M3 vs minimax-m3) and
  otherwise fall back to modelEvidence pinned-argv like Codex.
- provider==parent stays rejected; gateway providers are distinct, so
  they run under both parents through the external runner.
A gateway lane refuses to start, in-process and before any subprocess,
when its API key variable is missing or its isolated config dir carries
a claude.ai OAuth credentials file (or one that cannot be parsed). The
refusal is an unauthenticated receipt (exit 77) whose evidence names the
path and never the contents. This guarantees a claude.ai login can never
be pointed at a third-party endpoint through the runner. Endpoint
authentication errors from the one-shot invocation classify as
unauthenticated through the existing stderr matching. Tests cover the
key-missing, OAuth-refusal, garbage-file, env-injection, happy-path,
case-shifted-model, pinned-argv, and endpoint-401 paths, plus the
zero-subscription scenario with mocked binaries; nothing performs
network I/O.
PROVIDERS now spreads GATEWAY_PROVIDERS, and the preflight, invocation,
parse, and preflight-pass paths branch on isGatewayProvider instead of
naming deepseek and minimax in each switch. Adding an Anthropic-compatible
gateway is one GATEWAY_PROVIDERS entry plus one GATEWAY_SPECS row; the
Record type makes a missing spec a compile error.
provider-dispatch.md gains an additive Flex model matrix section (the
stock matrix and its parser contract stay byte-identical), deepseek/
minimax columns in the route table (external runner under both parents),
the gateway preflight and receipt semantics, and the panel diversity
rule: arena runners and interrogate reviewers span at least two distinct
providers unless the operator explicitly confirms otherwise. codex-tools
notes that flex descriptors are never spawn_agent lanes.
Mirrors upstream PR ericlitman#73 (issue ericlitman#72): role assignments are chosen first,
only assigned families get effort questions and probes, and there is no
requirement to assign every matrix family. A failed model demands
explicit repair or role reassignment before saving; the fail-closed
write rules and the first-run sheet bytes are unchanged. The probe table
gains DeepSeek and MiniMax rows (key present, config dir free of OAuth
credentials, one-turn probe doubling as the base-URL confirmation), and
render-time validation enforces non-empty roles, at least two architect
runners, and the two-provider panel diversity rule. model-matrix.test.ts
is updated in the same commit because it pins the setup prose, and gains
a flex-matrix section check cross-validated against the runner's
gateway specs.
LANES.md covers lane kinds, the gateway environment reference, dated
prices including DeepSeek's off-peak window, the zero-subscription
walkthrough (parent session env-pointed at DeepSeek, MiniMax through the
runner), safety rules (unsupported-not-prohibited, never a claude.ai
login on a gateway path, per-project privacy opt-in, no silent
substitution), the optional OpenRouter and future Ollama lanes, and the
live post-merge validation checklist. CHANGES.md records the flex delta.
docs/USAGE.md walks the whole plugin: what pstack-flex is and how it
relates to thisguyskills, a mermaid map of task -> poteto-mode ->
playbooks -> lane fan-out -> receipts, fork install commands, key
handling for gateway lanes, the assignment-first /setup-pstack flow
with three worked configurations (full frontier, hybrid saver,
zero-subscription duo), copy-paste prompts for poteto-mode,
interrogate, arena, swarm, and architect with panel diagrams, a
sequence diagram of gateway lane execution including the OAuth guard,
a receipt field cheat-sheet, a cost playbook, and a troubleshooting
table keyed to receipt statuses.

docs/LANES.md gains a "Storing keys" section: macOS Keychain
load-on-demand recipe, pass/secret-tool and 1Password CLI
alternatives, the direnv plaintext caveat, the honest threat model,
and provider spend caps as the real blast-radius control.
The fork section now points newcomers at docs/USAGE.md, and the
install commands move from ericlitman/open-pstack to this repository.
The marketplace and plugin names are unchanged (pstack@open-pstack),
so only the marketplace-add commands change.
Lists the four touch points (GATEWAY_PROVIDERS, GATEWAY_SPECS, the flex
matrix row, the setup probe row) and which check fails when each is missing.
feat(runner): DeepSeek and MiniMax gateway lanes
feat(setup): flex dispatch matrix, assignment-first setup, and lane docs
Add DeepSeek Pro and MiniMax preview model choices
Add Astra, GPT-6 Sol, and Luna as optional model families for setup-pstack. Keep upstream defaults intact and validate their provider routes and effort flags.
# Conflicts:
#	plugins/pstack/skills/poteto-mode/scripts/runner/model-matrix.test.ts
Add the astra, sol-6, and luna families to the lane guide, usage guide,
reference, README, and fork-ownership list. Existing sheets and first-run
defaults stay on codex:gpt-5.6-sol@max.
feat(pstack): support GPT-6 role families
Bring the README up to date with the merged fork changes:

- List all three lane kinds with every family setup accepts: the stock
  four, the optional GPT-6 Codex families, and the four gateway families
  (DeepSeek Flash / V4 Pro, MiniMax M3 / M3.1 Flash Preview) with the key
  each needs.
- Add a short "how a role becomes a lane" diagram: model sheet -> parent
  resolves the route once -> native subagent or pstack-runner -> receipt.
  State the dropout rule and the two-provider panel diversity rule.
- Mention gateway keys and any-subset setups in Install, and the
  assignment-first, probe-before-write setup flow plus the sheet's
  location in Get started.
- Add a gateway row to the Claude Code / Codex table and a cost note that
  points at the USAGE.md cost playbook.
- Point badges, issue links, and the contributing section at this
  repository, and state the live-evidence merge gate from AGENTS.md.
- Add a Roadmap section linking the planned skill issues (#10-#15) and
  the open lane ideas (#3, #7).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N3mzNDcZhX9LN5mWCDthg9
This reverts commit 66e5a46 and restores README.md to its state on main.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N3mzNDcZhX9LN5mWCDthg9
@mergify

mergify Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again.

Astra, GPT-6 Sol, and Luna move from the "additional" matrix into the
stock model matrix. The first-run sheet now uses them: GPT-6 Sol for
the solo code-writing roles, Luna for exploration and swarm workers,
and Astra in place of GPT-5.6 Sol on every panel. GPT-5.6 Sol stays a
selectable family for existing sheets.

provider-dispatch gains a "## Default panel" line that is the single
source for the four panel lanes; setup-pstack, arena, architect, and
interrogate copy it verbatim and the static invariant reads it instead
of deriving the panel from every matrix row. The solo-code invariant
now checks the sol-6 row. The matrix test asserts the seven stock rows,
the GPT-6 rows in the first-run sheet, and the panel contract.

Tracked in #17.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N3mzNDcZhX9LN5mWCDthg9
@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 2/5

[Medium risk] Adds optional gateway providers and model families to the plugin.

The PR is not ready to merge until gateway children stop inheriting unrelated credentials and reported-model verification rejects distinct substituted slugs.

Findings

  1. P1 Security Gateway children inherit unrelated credentials ▶
  2. P1 Different models pass verification ▶
  3. P2 Native Claude roles misrepresented ▶
  4. P2 Installed setup remains unvalidated ▶

Summary

Adds optional GPT-6 and gateway model families, assignment-first setup, and DeepSeek/MiniMax execution through an environment-configured Claude CLI.

  • Gateway child isolation still carries unrelated parent credentials into a model-controlled process.
  • Gateway model verification can accept a distinct, hyphen-suffixed model as the requested one.
  • The zero-subscription guidance and installed setup validation need correction before rollout.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  P[Parent session] --> S[Selected role and model]
  S --> G{Gateway family?}
  G -- No --> N[Native agent or existing external runner]
  G -- Yes --> E[Copy and configure child environment]
  E --> C[claude subprocess with Bash]
  C --> A[DeepSeek or MiniMax endpoint]
  C --> R[Parsed output and model-verification receipt]
Loading

Reviews (1) · Last reviewed commit: "Revert "docs(readme): describe the flex ..."

Comment on lines +149 to +154
if (isGatewayProvider(provider)) {
for (const key of Object.keys(result)) {
if (key.startsWith("ANTHROPIC_")) delete result[key];
}
for (const key of GATEWAY_INHERITED_CONFLICTS) delete result[key];
Object.assign(result, gatewayEnvironment(provider, model, source));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Gateway children inherit unrelated credentials

If the parent environment contains a MiniMax key or other unrelated credentials, a DeepSeek lane passes them to its Claude subprocess. That subprocess allows Bash even in read-only mode, so the gateway model can cause it to read and disclose those secrets. Pass only the environment the selected lane needs.

How this was verified: The gateway child retains non-ANTHROPIC_* environment variables and enables Bash while sending model requests to a third-party endpoint.

// (e.g. MiniMax-M3 vs minimax-m3); compare case-insensitively.
const wanted = requested.toLowerCase();
const got = reported.toLowerCase();
return got === wanted || got.startsWith(`${wanted}-`);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Different models pass verification

If a request for deepseek-flash is reported as deepseek-flash-preview, this prefix check treats the different slug as a verified match. The lane then completes with modelVerified: true instead of rejecting the reported model. Require an exact case-insensitive match or recognize only known revision suffixes.

Comment thread docs/LANES.md
export ANTHROPIC_MODEL="deepseek-flash"
export CLAUDE_CODE_SUBAGENT_MODEL="deepseek-flash"
export CLAUDE_CONFIG_DIR="$HOME/.pstack-flex/parent-deepseek"
claude

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Native Claude roles misrepresented

The walkthrough says the default Fable and Opus slots will ride DeepSeek, but those slots launch native agents pinned to fable and opus. They do not receive the gateway runner’s DeepSeek model pins. A reader who keeps those defaults may encounter failed setup probes or run a different model than the guide promises. Tell readers to reassign every stock Claude role they intend to use to a gateway family.

Comment on lines +26 to +30
These single short probes establish authentication, model selection, and successful completion through the runner. They do not rank coding quality or speed, prove hidden reasoning depth, or verify CLI request-body effort forwarding. The prompt included the expected marker, so completion does not independently prove a file tool was used.

## Remaining release gate

Install the exact candidate and run setup from both real Claude Code and Codex user surfaces. Verify independent model effort choices, per-model probes, mixed-provider panels, saved-sheet readback, and unchanged configuration on failed access. Record installed version, surface, action, and observed result before merge or rollout. Changing only the runner's `--parent` flag would not satisfy this gate.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Installed setup remains unvalidated

The recorded probes exercised direct runner calls, while this document says the candidate has not been installed and setup from both parent surfaces remains untested. That leaves the new assignment flow and mixed-family routing without end-to-end evidence, making a setup regression harder to catch before rollout. Record installed Claude Code and Codex setup results, including the unchanged sheet after a failed preview probe.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

…ults

README is now the fork's own page: titled pstack-flex, one table of every
family setup accepts with what each needs and its first-run role, the
default panel, a "how a role becomes a lane" diagram, and install, setup,
cost, and contributing sections written for this repository. No roadmap;
issues carry that.

LANES.md, USAGE.md, and reference.md describe the GPT-6 families as stock
and show the new first-run defaults. UPSTREAM.md and UPSTREAM-FLEX.md
record that the matrix and first-run sheet are now fork-owned and will
conflict on every upstream sync. CHANGES.md gets the entry.

Tracked in #17.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N3mzNDcZhX9LN5mWCDthg9
@thisguymartin
thisguymartin deleted the claude/youthful-dirac-vd1ei1 branch September 28, 2026 19:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant