← NightshiftCONTENT HISTORY

Update to Nightshift

Snapshot Sep 30, 2026 · 23:14 UTC · version 0.25.3

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Begin the shift from the punch list without asking, so scheduled and headless runs behave like interactive ones.",
  "included_files": [],
  "name": "start",
  "skill_md_contents": "---\nname: start\ndescription: Begin the shift from the punch list without asking, so scheduled and headless runs behave like interactive ones.\nlicense: MIT\n---\n\nStart a Nightshift run in the host-opened project.\n\nResolve the installed plugin root to an absolute `$NIGHTSHIFT_PLUGIN_ROOT` — `${CLAUDE_PLUGIN_ROOT}`\non Claude Code, `$PLUGIN_ROOT` on Codex when set, otherwise the absolute path this skill was\nattached from (`skills/start/SKILL.md`). Run every command below through\n`\"$NIGHTSHIFT_PLUGIN_ROOT/runtime/ns\"` — native Windows: `& \"$NIGHTSHIFT_PLUGIN_ROOT\\runtime\\windows\\ns.ps1\"`\nin the PowerShell tool, same verbs — which resolves the host and the workspace; `ns help` lists the\nverbs, and `ns bind` prints the six resolved facts (`TASK_ROOT`, `NIGHTSHIFT_WORKSPACE`, `NS`,\n`NIGHTSHIFT_PLUGIN_ROOT`, `HOST`, `SOURCE`); `$NS` below is that `NS`. Never a bare relative path: the working\ndirectory persists between calls. Each `$NS/...` path below is where the current layout keeps that file;\n`ns path <key>` prints where this workspace keeps it, and `ns path --list` names every key.\n\nWhen a verdict names your host — permission modes, resume commands, the sandbox and identity\nrules that belong to it — open\n`$NIGHTSHIFT_PLUGIN_ROOT/skills/nightshift/references/hosts/<host>.md` for the host you are on,\nand no other. Not before a verdict names it.\n\n## 1. Preflight — one helper, one verdict per line\n\n**With work in the punch list, this command asks nothing.** It reads the list, arms the site and\nworks — which is what lets cron run it at 04:00 and lets the watchman revive it after a crash. It\npromotes nothing on its own: what is in the punch list is the shift, exactly as the owner left it.\n\nThe one time it speaks is when the punch list is **empty**. Then there is no work to do silently,\nso it looks at staged drafts and pending Hunt orders and asks which to promote.\n\n```bash\n\"$NIGHTSHIFT_PLUGIN_ROOT/runtime/ns\" start-preflight --host claude\n```\n\nPass the host you are actually running on (`claude`, `codex`, or `cursor`). Every line it prints is\none verdict, and it explains itself:\n\n- **`ok <topic> <detail>`** — a resolved fact. Report it if the owner asked; otherwise continue.\n- **`warn <topic> <detail>`** — say it once in plain English, then arm anyway. The choice stays the\n  owner's.\n- **`refuse <topic> <detail>`** — do not arm. Print the `explain` and `repair` lines that follow it\n  verbatim and stop.\n\nExit status 0 means the shift may arm; non-zero is a refusal; 2 is a usage error in the call you\njust made. An `explain` line says what the verdict means and a `repair` line is the exact action —\nrelay them, do not restate them, and never invent an explanation the helper did not print.\n\nTwo rules are policy rather than mechanics, so they are yours to hold whatever a verdict says:\nnever kill a live watchman and never start a second shift beside one; and never clear `STOP` or\ninvent a time budget for a paused shift whose deadline has passed.\n\n## 2. The punch list is the shift\n\n**Inspect capabilities in the skill.** Read manifests, lockfiles, and `## Gates` in the work\ntarget. `$NS/run/capabilities.json` is a cache the model may update after a successful tooling commit\nonly; no detector is required.\n\n**Permission gaps are parked, never asked.** Run\n`\"$NIGHTSHIFT_PLUGIN_ROOT/runtime/ns\" preflight-needs` against every item now in\n`## Items`. For each item with a gap, run\n`\"$NIGHTSHIFT_PLUGIN_ROOT/runtime/ns\" park-needs` to add its entry to\n`$NS/inbox/parking-lot.md` naming the missing category, then append one `$NS/run/shift-log.md` line listing\nevery gapped item. Work everything else. If either helper exits because no JSON parser is\ninstalled, park the gaps in the skill and continue; neither is on the armed path.\n\nIf `$NS/punch-list.md` has at least one open `- [ ]` under `## Items`, that is the work — start it.\nDo not promote, cut, or add anything: parked orders and drafts stay exactly where the owner left\nthem. An empty `## Items` section still keeps the Shift contract and Gates; they bind whatever Hunt\nor Start cuts next.\n\n**Resume the active product cycle before rediscovery.** When the open item is product evolution,\ninspect `$NS/product/opportunity-map.md` for its single `Status: building` entry before doing new research\nor selecting work. Its `Next` action and `Verify remaining` are the continuation point. More than\none building entry is inconsistent state: keep the earliest one active, mark the others\n`candidate`, record the repair in `$NS/run/shift-log.md`, and continue.\n\n**Only when the punch list is empty, offer what is staged.** The `ok staged` verdict already counts\n`$NS/staging/work-orders.md` and `$NS/staging/drafting-table.md`. Read both (a file that is not there\nholds nothing), show what they hold in one short list,\nand ask which to work now. On the owner's choice, **cut it — move, never copy**: the item goes\nunder `## Items` and is removed from the file it came from, so it never exists in two places. An\nimported draft (`Status: proposed` and a canonical `Source:` GitHub URL) is cut the same way in the\nskill — move the item under `## Items` and remove it from the drafting table. The import-issues\nhelper is optional. Do not require Python. A flagged import stays refused unless the owner\noverrides after seeing the flags. From a work order, remove the whole `## Work order` section\n(heading, hours, and item), not just the checkbox, then write `$NS/run/deadline` as a UNIX epoch from\nthe recorded hours (`now + hours*3600`; compute now with `date +%s` on POSIX, or `Get-NSUnixTime`\nafter importing the module on native Windows); an order marked finite with no hours writes no\ndeadline. A product-evolution item gets its notebook first: `ns scaffold product` creates\n`$NS/product/opportunity-map.md` and `$NS/product/product-research.md` and keeps any already there.\n\nIf the punch list is empty and nothing is staged, stop and say so: Setup if the project is new,\nHunt to compose a shift, or write an item by hand. Give host-native invocation when needed: slash\ncommands on Claude Code, or ask Nightshift for the named skill on Codex.\n\nThe working tree should be clean enough to commit per item; warn if it is not.\n\n## 3. Deadline — read, never asked\n\nThe deadline value is decided when the work is composed (Hunt's cut, the owner's own edit, or\nStart's own start-defaults), never asked here. **The deadline is cleared only if it has already passed** — the preflight does that, because a shift that reached the whistle\nwould otherwise clock tonight out at zero items. A deadline still in the future is tonight's plan and is kept.\n\nAct on the deadline verdict:\n\n- `ok deadline <epoch> (policy …)` — the shift policy is the authority. Write that epoch to\n  `$NS/run/deadline`.\n- `ok deadline <epoch> (file …)` — keep the file as it is and record that epoch as the policy's\n  `deadlineEpoch`, logging the adoption in `$NS/run/shift-log.md`. Never delete the marker.\n- `ok deadline none (finite list …)` — correct. Their natural end is the last tick, and a stuck run\n  is red-flagged in the shift log and held for review.\n- `refuse deadline` — an `Ending: open-ended` marker with no clock. Refuse to start, say so in one\n  line, and point at Hunt, which asks for hours; never invent a number.\n\nOne deadline governs the whole shift: finite items first, the walkthrough soaks up the rest.\n\n## 4. Arm the gate\n\nEvery check has passed and the work is known, so the shift begins here. First record tonight's\nsnapshot, the contract and items the gate holds this shift to, now that any cut item is in the list:\n\n```bash\n\"$NIGHTSHIFT_PLUGIN_ROOT/runtime/ns\" start-preflight --phase snapshot\n```\n\nRelay a `warn` line once and arm anyway; a composed shift keeps the policy it already has. Then\ncreate the marker:\n\n```bash\ntouch \"$(\"$NIGHTSHIFT_PLUGIN_ROOT/runtime/ns\" path armed)\"\n```\n\nNative Windows:\n\n```powershell\nNew-Item -ItemType File -Force (& \"$NIGHTSHIFT_PLUGIN_ROOT\\runtime\\windows\\ns.ps1\" path armed) | Out-Null\n```\n\n**This, and nothing else, is what puts a session on shift.** Until it exists the punch list is an\nordinary to-do file: the clock-out gate holds nobody and hardhat's guards apply to no one, so a\nsession that writes items while planning still stops freely. Write it only after the preflight\nreturned zero. A marker left behind by a preflight that stopped early would put the next session on\na shift it never started.\n\n### Bind this session — before any other tool\n\nImmediately after writing `$NS/run/.shift-armed`, make this the next tool call on either host:\n\n```bash\n: nightshift-binding-probe\n```\n\nOn native Windows, the immediate PowerShell probe is:\n\n```powershell\n$null = 'nightshift-binding-probe'\n```\n\nThis harmless host-shell probe makes the hardhat record this conversation in `$NS/run/.shift-session`\nand claim generation 1 in `$NS/run/.shift-lease` before item work or the watchman begins. Its\ndistinctive marker also makes a concurrent second Start fail explicitly if another session won the\natomic session-file claim. Do not read files, search, call MCP, or yield between the marker and the\nprobe: only the probe makes the first session claim, and until it runs no conversation is on shift.\nNever create or edit the lease directly.\n\nThe probe must execute cleanly with no hook denial or hook error. On native Windows this is also\nthe live check that the filesystem can make an atomic private session claim and lease. If it fails,\nremove `$NS/run/.shift-armed`, run Stop, and follow the stale-lease reset the preflight prints as a\nrepair; do not begin item work or arm a watchman on an assumed claim.\n\n### Codex identity checkpoint — before the watchman\n\nCodex exposes the current task identity through hook payloads, not as a shell environment variable,\nso this runs after the probe and before the watchman:\n\n```bash\n\"$NIGHTSHIFT_PLUGIN_ROOT/runtime/ns\" start-preflight --phase bind\n```\n\nIt classifies `$NS/run/.shift-session` line 1 with `ns_codex_identity_kind` (native Windows:\n`Get-NSCodexIdentityKind` after\n`Import-Module \"$NIGHTSHIFT_PLUGIN_ROOT\\lib\\Nightshift.psm1\" -Force`).\n\n- `ok codex-identity resumable`, or `not-applicable` on another host — continue.\n- `warn codex-identity missing` — continue with the fresh-session fallback and say plainly that\n  same-thread recovery is unavailable until an identity is recorded.\n- `refuse codex-identity` — stop the unattended start.\n  Remove only the markers this start created (`$NS/run/.shift-armed` and its\n  new `$NS/run/.shift-session`) and reset the lease with `ns_lease_reset_stale` in the same Bash call,\n  so no hook call in between can bootstrap the aborted lease again. On native Windows,\n  `Reset-NSStaleLease \"$NS\"` with no other command between marker removal and the reset. Append one\n  failed-preflight line to `$NS/run/shift-log.md` and stop before the watchman or item work. Never\n  pass the value to Codex, print it, or guess a replacement.\n\nThis capture-and-check is part of Start, not an owner instruction to remember. An attended session\nthat does not request an unattended shift remains unaffected.\n\n## 5. Heads-up\n\nSurface any still-unanswered entries in `$NS/inbox/parking-lot.md` (read-only) so the owner sees what the\nlast shift parked — printed, never waited on. Append a `shift started` line to `$NS/run/shift-log.md`.\nThe preflight rotates that journal itself when it grows past ~500 KB, into the last ended shift's\narchive folder at `run/shift-log.md`, beside anything Archive already filed there, or into a folder\nclaimed for today (`date +%Y-%m-%d` on POSIX, `Get-Date -Format yyyy-MM-dd` on native Windows)\nwhen no shift is on record. Only the\nmechanical journal auto-rotates — `snag-log.md` and `parking-lot.md`\nare the owner's review material, and Archive files those on the owner's order.\n\n## 6. Arm the night watchman\n\nEach host has its own watchman; all of them read their cadence from the rules file, and each\nstands down on a shift another host owns. Unless the `ok watch-minutes 0 (watchman disarmed)`\nverdict says otherwise, launch it with the host you are on:\n\n```bash\n\"$NIGHTSHIFT_PLUGIN_ROOT/runtime/ns\" start-watchman --host claude\n```\n\nNative Windows:\n\n```powershell\n& \"$NIGHTSHIFT_PLUGIN_ROOT\\runtime\\windows\\ns.ps1\" start-watchman -HostName claude\n```\n\nIt hands the watchman the workspace explicitly, keeps the watchman's own output in\n`$NS/run/watchman.log`, and returns only once the watchman holds its pid file and the shift log\nshows it armed: `watchman started (pid N)`, or `watchman already watching (pid N)` when one is\nalready running. Any other result means nothing is watching this shift. Do not begin item work:\nrelay its output verbatim — it quotes why the watchman did not arm — and stop until the owner has\nfixed the cause and Start has been run again.\n\nIt revives a session that DIES mid-shift — an API outage, a crash, a killed terminal — by spawning\na fresh session that resumes from the punch list. Every host stands down on done, a stop-work\norder, or quitting time; per-host revival detail is in `hosts/<host>.md`. `STOP` remains the\nstop-work order on every host, and the only stop a headless run can receive.\n\n## 7. Work\n\nRead `$NS/punch-list.md` in full, then begin item 1 and follow the nightshift skill, which owns the loop, the gates, the receipts and cited\nresearch: one item at a time, tick only after the item is complete, park don't\nask, leave pushing to the owner unless the punch list says otherwise. From here the clock-out gate\nowns the session — it will not let you stop while any box is open. When the gate logs\n`JSON parser unavailable`, write the morning page by hand from\n`$NIGHTSHIFT_PLUGIN_ROOT/skills/nightshift/references/receipts/morning.md`, which names the file\nto write and the fields to fill. Every shift leaves a receipt.\n"
}

SHA-256 of public snapshot: da28ba5db45b730d0619d4b27cc20ed5fc3efa6fdae8329c7597caf0a8b30576