Skip to content

docs(catalog): pin plex-axi to v0.8.0 and admit in full - #230

Merged
kunchenguid merged 6 commits into
kunchenguid:mainfrom
dmealing:fm/plex-axi-catalog
Oct 5, 2026
Merged

kunchenguid merged 6 commits into
kunchenguid:mainfrom
dmealing:fm/plex-axi-catalog

Conversation

@dmealing

@dmealing dmealing commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Intent

Pin the plex-axi entry (https://github.com/dmealing/plex-axi) in the AXI community catalog to release v0.8.0, tag commit f31149dfdc4e8424f43aa5e17c1252ff7c873a88. plex-axi is structured, per-field music search and diagnosis over the Plex Media Server API, with writes and playback off unless explicitly enabled. v0.8.0 fixes two safety defects found by live testing against a real Plex server: the raw api command could forward state-changing GET requests past the write and playback gates, and api /myplex/account printed the account's plex.tv token unredacted. It also closes the partial AXI principles recorded for the earlier pin, so the entry is admitted in full rather than as an exception. The catalog entry and the generated README and docs regions are updated together, keeping the hass-axi entry already on main. The skill command is plex-axi skill.

What Changed

  • Updated plex-axi entry in catalog.yaml with v0.8.0 (commit f31149dfdc4e8424f43aa5e17c1252ff7c873a88), fixing two safety defects: raw api command could forward state-changing GET requests past write/playback gates; api /myplex/account printed plex.tv token unredacted
  • Changed plex-axi admission status from exception to fully admitted, closing partial AXI principles review with complete component coverage
  • Regenerated README.md and docs/index.html from catalog.yaml to keep documentation in sync

Risk Assessment

✅ Low: Catalog/docs-only change; new entry correctly drops the prior exception (admitted in full), pin matches intent's tag/commit exactly, safety-fix claims (api GET-only state-changing-path refusal, token redaction) are consistent with source_observations, and generated README/docs regions mirror the catalog entry with no hand-edits visible.

Testing

All 5 user-intent scenarios passed live: catalog entry pinned to v0.8.0 with full admission, reviewed_components complete, documentation regenerated and in sync, hass-axi entry preserved, security fixes documented. Regression test suite passed: 11 catalog rendering tests and 185 SDK tests all green. No blocking issues found.

  • Live validation: ✅ go - 5 of 5 scenarios driven live against the product
Scenario Result Live Evidence
Catalog entry pinned to v0.8.0 with full admission status ✅ pass live grep shows reviewed_revision: f31149dfdc4e8424f43aa5e17c1252ff7c873a88 and status: admitted
All reviewed_components including item.py are listed ✅ pass live grep finds src/plex_axi/commands/item.py in reviewed_components list
Documentation regenerated and in sync with catalog ✅ pass live pnpm run docs:check reports: docs:check ok — generated regions match their sources
hass-axi entry preserved from main branch ✅ pass live grep shows hass-axi entry present with status: exception and reviewed_revision: 5555f1323d8b27c5aa1dd36ebbf6b7b6f2e8222c
Security defects documented in source_observations ✅ pass live Observations cite credential redaction (covers /myplex/account token) and STATE_CHANGING_PATH gate (blocks state-changing GET)
Evidence: Test evidence
TEST SCENARIOS FOR: docs(catalog): re-pin plex-axi to v0.8.0 and admit it in full

SCENARIO 1: Catalog entry is properly pinned to v0.8.0 and admitted in full
Command: grep -A 8 "name: plex-axi" catalog.yaml | grep "reviewed_revision\|status:"
Result: 
  status: admitted
  reviewed_revision: f31149dfdc4e8424f43aa5e17c1252ff7c873a88
Status: PASS - Entry is pinned to v0.8.0 tag commit and status is "admitted" (not exception)

SCENARIO 2: All reviewed_components including item.py are listed
Command: sed -n '/name: plex-axi/,/name: /p' catalog.yaml | grep "reviewed_components:" -A 30 | grep "item.py"
Result: - src/plex_axi/commands/item.py
Status: PASS - item.py is in reviewed_components list (was added in earlier review round)

SCENARIO 3: Documentation is regenerated and in sync
Command: pnpm run docs:check
Result: docs:check ok — generated regions match their sources
Status: PASS - README.md and docs/index.html match catalog.yaml

SCENARIO 4: Hass-axi entry is preserved
Command: grep -A 8 "name: hass-axi" catalog.yaml | head -10
Result: Shows hass-axi entry with status: exception and reviewed_revision: 5555f1323d8b27c5aa1dd36ebbf6b7b6f2e8222c
Status: PASS - hass-axi entry is present and unchanged from main

SCENARIO 5: Security defects are documented in observations
Tokens redaction check:
  - Finds: "any response attribute whose name marks a credential (is_credential_name: token, secret, password, authkey, apikey, credential) prints as `<redacted>` and is registered as a secret, which covers the account token in `/myplex/account`"
State-changing-GET gate check:
  - Finds: "Before connecting it also refuses, with STATE_CHANGING_PATH (exit 2), a path whose GET changes server state"
Status: PASS - Both v0.8.0 security fixes (token redaction and state-changing-GET gate) are documented

REGRESSION TEST SUITE: pnpm run docs:test
Result:
  ✔ 11 tests passed
  ✔ All catalog rendering tests pass
  ✔ Both mesheryctl-axi and plane-axi pinned admission records verified
Status: PASS

REGRESSION TEST SUITE: packages/axi-sdk-js: pnpm test
Result:
  ✓ test/output.test.ts (7 tests)
  ✓ test/release-ci-exclusions.test.ts (6 tests)
  ✓ test/update.test.ts (53 tests)
  ✓ test/hooks.test.ts (54 tests)
  ✓ test/fast-path.test.ts (29 tests)
  ✓ test/cli.test.ts (36 tests)
  Total: 185 tests passed
Status: PASS

ARTIFACT VERIFICATION:
- plex-axi appears in README.md community catalog table
- plex-axi appears in docs/index.html (2 occurrences)
- Git working tree clean: git status shows "nothing to commit, working tree clean"
- Commit message documents the fix clearly and is properly attributed
Status: PASS

OVERALL: All 5 scenarios pass, regression tests pass, no unfixable issues.

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

⏭️ **Rebase** - skipped
  • ⚠️ README.md - merge conflict rebasing onto origin/main
  • ⚠️ catalog.yaml - merge conflict rebasing onto origin/main
  • ⚠️ docs/index.html - merge conflict rebasing onto origin/main
✅ **Review** - passed

✅ No issues found.

✅ **Test** - passed

✅ No issues found.

  • Live validation: ✅ go - 5 of 5 scenarios driven live against the product
Scenario Result Live Evidence
Catalog entry pinned to v0.8.0 with full admission status ✅ pass live grep shows reviewed_revision: f31149dfdc4e8424f43aa5e17c1252ff7c873a88 and status: admitted
All reviewed_components including item.py are listed ✅ pass live grep finds src/plex_axi/commands/item.py in reviewed_components list
Documentation regenerated and in sync with catalog ✅ pass live pnpm run docs:check reports: docs:check ok — generated regions match their sources
hass-axi entry preserved from main branch ✅ pass live grep shows hass-axi entry present with status: exception and reviewed_revision: 5555f1323d8b27c5aa1dd36ebbf6b7b6f2e8222c
Security defects documented in source_observations ✅ pass live Observations cite credential redaction (covers /myplex/account token) and STATE_CHANGING_PATH gate (blocks state-changing GET)
  • grep -A 8 "name: plex-axi" catalog.yaml | grep reviewed_revision
  • grep item.py in plex-axi reviewed_components
  • pnpm run docs:check
  • grep "name: hass-axi" catalog.yaml
  • grep credential redaction and STATE_CHANGING_PATH in plex-axi observations
  • pnpm run docs:test (11 tests)
  • pnpm test in packages/axi-sdk-js (185 tests)
  • grep plex-axi in README.md
  • grep plex-axi in docs/index.html
  • git status verification
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

@greptile-apps

greptile-apps Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Low risk] Adds a community tool to the catalog documentation.

The PR appears safe to merge based on the reviewed changes.

Reviews (6) · Last reviewed commit: "docs(catalog): re-pin plex-axi to v0.8.0..."

@dmealing
dmealing force-pushed the fm/plex-axi-catalog branch from 0eef10c to 792e9db Compare October 3, 2026 14:57

Copy link
Copy Markdown
Owner

Speaking as Kun's firstmate: first-time fork workflows approved (docs-check and Guard generated files are green).

Blocked on no-mistakes CI. The required check failed with "This PR was not raised through no-mistakes." The PR body has the HTML no-mistakes-pipeline-attestation comment, but it is missing the signed ## Pipeline / Updates from [git push no-mistakes](...) section that the verifier expects (compare a passing raise like #228).

Please re-raise via git push no-mistakes so the Pipeline section lands in the body and the check goes green. Independent source review of plex-axi at pin 3f4edb61… is in progress separately; I will not merge until no-mistakes is green.

Copy link
Copy Markdown
Owner

Speaking as Kun's firstmate: independent source review of dmealing/plex-axi at pin 3f4edb61b70072c1477fb64b88a064df606dc5a1 (tag v0.6.1).

Contract-class (catalog PR): opt-in.

VISION per-rule (so far)

  • AXI principles: aligns — no principle-semantics change.
  • Catalog: aligns for admit-with-exception once CI is green — inspected pyproject.toml, src/plex_axi/{cli,argspec,writes,playback,hooks,errors,output,music}.py, commands/{home,search,api,rate,playlist,play,recent,skill,setup}.py. Direct observations: writes need PLEX_AXI_ALLOW_WRITES=true + --write (else preview); playback commands hidden unless PLEX_AXI_ALLOW_PLAYBACK=true and play previews until --now; api is GET-only with --depth bound; unknown flags rejected in argspec; skill command is plex-axi skill (not setup skill); bare home sets __exit_code__=1 when unconfigured/unreachable; track/album default field lists are five columns; playlist create errors if title exists rather than confirming state; setup hooks installs SessionStart only (no status/remove or session-end in the setup surface). Compare v0.6.0→v0.6.1 touches only version/docs/dev-setup/tests — no runtime modules under src/plex_axi except __init__.py version. No security concern on gated writes/playback.
  • SDKs: aligns — no SDK change.

Still blocked: no-mistakes required check red (missing signed Pipeline section). Docs-check + Guard generated files green after fork approval. Will merge only after no-mistakes is green; no captain flag (author/CI wait).

@dmealing
dmealing force-pushed the fm/plex-axi-catalog branch from 792e9db to 56ebf38 Compare October 3, 2026 16:34
Resolve catalog/README/docs conflicts after kunchenguid#231 by retaining both
exception admissions and regenerating catalog-community regions.

Copy link
Copy Markdown
Owner

Speaking as Kun's firstmate: re-triage after newer activity (Pipeline section + Greptile).

CI / conflict: Before merge, tip 56ebf385… went fully green (no-mistakes, docs-check/drift, Guard generated files, Greptile) once the signed ## Pipeline + attestation landed. Meanwhile #231 (hass-axi) landed on main and dirtied this PR. I merged main into fm/plex-axi-catalog as 0463de68…, kept both hass-axi and plex-axi entries, and regenerated the catalog-community regions (docs:check / Guard green on the new tip). no-mistakes is red again because the body attestation still binds head_sha to 56ebf385…, not tip 0463de68….

@dmealing please re-run git push no-mistakes on this branch so the Pipeline attestation binds to the current head — then I will squash-merge. Catalog content and pin are otherwise ready.

Contract-class: opt-in.

VISION (this fire)

  • AXI principles: aligns — catalog-only; no principle-semantics change.
  • Catalog: aligns for admit-with-exception — pin unchanged at 3f4edb61b70072c1477fb64b88a064df606dc5a1 (v0.6.1); prior independent source review (writes gated by PLEX_AXI_ALLOW_WRITES+--write, playback hidden unless PLEX_AXI_ALLOW_PLAYBACK, GET-only api, skill=plex-axi skill, six partial principles 2/3/6/7/8/9) still applies; tip catalog retains that pin beside hass-axi after the conflict resolve.
  • SDKs: aligns — no SDK change.

No captain flag (author/CI wait on attestation re-bind).

v0.8.0 (f31149d) closes the principle gaps recorded for the v0.6.1 pin:
four-field list defaults, size-bounded api output, idempotent playlist
writes, hook status/removal plus session-end capture, a home view that
exits 0 without configuration, and recent follow-ups that keep --type.
It also refuses state-changing GET paths in api and redacts credential
attributes in api responses.
@dmealing dmealing changed the title docs(catalog): add plex-axi to the community catalog docs(catalog): pin plex-axi to v0.8.0 and admit in full Oct 5, 2026
Comment thread catalog.yaml
Comment on lines +1306 to +1307
status: admitted
reviewed_revision: f31149dfdc4e8424f43aa5e17c1252ff7c873a88

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Admission contradicts stated intent The PR’s Intent calls for plex-axi v0.6.1 to be listed as an exception with six partial principles. This entry instead marks v0.8.0 as admitted and omits those exceptions. Catalog readers therefore see a different version and verdict than the accepted Intent specifies, violating the repository directive to respect that Intent.

Context Used: If there is a VISION.md file at the root of the repo, the PR must not conflict / diverge / drift from it. If the PR description has an "Intent" section, respect that as the accepted user intent. - Do make comments if anything in the implementation ... (source)

@dmealing

dmealing commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

@greptileai re-review — this review started while the PR description still carried the earlier v0.6.1 exception intent. The description was updated seconds later to the current intent (pin v0.8.0, admitted in full), which matches the catalog change.

@kunchenguid
kunchenguid merged commit be87151 into kunchenguid:main Oct 5, 2026
5 checks passed
@kunchenguid

Copy link
Copy Markdown
Owner

Speaking as Kun's firstmate: re-triage after the v0.8.0 re-pin, with an independent source review of dmealing/plex-axi at pin f31149dfdc4e8424f43aa5e17c1252ff7c873a88 (tag v0.8.0, release commit for plex-axi#33).

Contract-class (catalog PR): opt-in. It updates one community catalog entry and changes no axi default behavior.

VISION per-rule

  • AXI principles: aligns. This is a catalog-only change with no principle-semantics change.
  • Catalog: aligns for full admission. Here's what I saw directly in the source at the pin:
    • src/plex_axi/commands/api.py runs _reject_token_in_query and _refuse_action before ctx.server(). src/plex_axi/toolkit/shapes.py acts_on_get percent-decodes, collapses slashes, and lower-cases the path, then refuses action prefixes (/:/, /player/, /playqueues, /butler, /updater, /actions/) and endings (/refresh, /scrobble, and others) with STATE_CHANGING_PATH. Dot segments are refused, and so are non-GET methods, by name.
    • _render replaces any credential-named attribute (is_credential_name) with <redacted> and registers its value as a secret. output.py runs redact() on every stdout and stderr write. That covers the v0.8.0 token-leak fix.
    • api output is bounded by --depth (default 3, ceiling 8), by MAX_CHILDREN = 20 with an "N of M shown" count, and by an 800-character value preview. It suggests --full or --depth only when a bound was hit.
    • music.py ROW_FIELDS defaults are four fields for tracks and albums and three for artists. That closes the earlier principle 2 gap.
    • writes.require is called before the connection in rate.py and playlist.py. rate to the value it already holds, and playlist create/add/remove whose desired state already holds, return a no-op with exit 0 (_no_op). PLAYLIST_EXISTS is kept only when the contents differ. That closes the earlier principle 6 gap.
    • hooks.py installs SessionStart for Claude Code and Codex, a managed OpenCode plugin, and a Claude SessionEnd hook (sessionlog.py, which records command names, never arguments). setup status and setup remove exist and remove only marker-tagged entries. That closes the earlier principle 7 gap. Codex has no session-end event, and the catalog states that.
    • home.py exits 0 when unconfigured or the server is unreachable. It still prints the bin, description, write-gate state, and next setup step. That closes the earlier principle 8 gap. recent.py carries --type and --fields into its follow-up hint, which closes the principle 9 gap.
    • cli.py is the single error boundary (INTERNAL_ERROR, no raw traceback). argspec.py uses UNKNOWN_FLAG, and -v/-V/--version work. Playback stays hidden unless PLEX_AXI_ALLOW_PLAYBACK=true.
    • Unverified claims: I didn't check real Plex server or PlexAPI behavior, or the contributor's live-test transcripts. These observations apply to the pinned wrapper source only.
  • SDKs: aligns. There's no SDK change.

CI: no-mistakes, drift, Guard generated files, and Greptile are green on tip 6e241c75, and the attestation binds to that head. Greptile's earlier P1 ("admission contradicts stated intent") was against the stale v0.6.1 description. The body now matches the v0.8.0 full-admission entry, and the latest Greptile pass on the tip is 5/5. Main's one newer commit (#233) only touches the hey-axi lines in catalog.yaml, so the generated regions here stay in sync.

Squash-merged as be87151e6ff3d068522a591c3fa6757a96049d68.

@kunchenguid

Copy link
Copy Markdown
Owner

Speaking as Kun's firstmate: this is merged. Thank you @dmealing — really appreciate you taking the time on this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants