feat: phase 2 — audit config + update --rollback (closes #63 #64)

Axe 8 (sécurité) :
- am audit : checksums SHA-256 des configs (embarquée, utilisateur,
  locale) stockés dans state.json, croisement avec events.jsonl pour
  dater les changements, détection des modifications manuelles hors de
  am (statut MANUAL), rapport lisible + --json stable (contrat)
- backup automatique avant chaque am update (agent ou --all) : état +
  config utilisateur + répertoires d'installation + shims dans
  <state>/backups/<ts>/ avec manifest.json
- am update --rollback [point] : restaure le dernier backup (ou un id
  précis, préfixe accepté), arrête les agents concernés d'abord,
  événement EventKind::Rollback journalisé
- am update --rollback list : liste les points de restauration
- rétention settings.backups_keep (défaut 5) appliquée après chaque backup
- événements EventKind::Backup / EventKind::Rollback pour l'audit

REPL : commande audit + update --rollback (parse, complétion), help specs,
tip cheat sheet, man pages régénérées (50 pages). Version 0.4.6,
ROADMAP cases cochées, 272 tests verts.
This commit is contained in:
2026-08-18 09:44:16 -04:00
parent 22bc529818
commit d9ffc34156
21 changed files with 971 additions and 33 deletions
+13
View File
@@ -0,0 +1,13 @@
.ie \n(.g .ds Aq \(aq
.el .ds Aq '
.TH am-audit 1 "audit "
.SH NAME
audit \- Audit the configuration: who changed what, when (issue #63)
.SH SYNOPSIS
\fBaudit\fR [\fB\-h\fR|\fB\-\-help\fR]
.SH DESCRIPTION
Audit the configuration: who changed what, when (issue #63)
.SH OPTIONS
.TP
\fB\-h\fR, \fB\-\-help\fR
Print help
+4 -1
View File
@@ -4,7 +4,7 @@
.SH NAME
update \- Update an installed agent to the latest available version
.SH SYNOPSIS
\fBupdate\fR [\fB\-\-all\fR] [\fB\-h\fR|\fB\-\-help\fR] [\fIAGENT\fR]
\fBupdate\fR [\fB\-\-all\fR] [\fB\-\-rollback\fR] [\fB\-h\fR|\fB\-\-help\fR] [\fIAGENT\fR]
.SH DESCRIPTION
Update an installed agent to the latest available version
.SH OPTIONS
@@ -12,6 +12,9 @@ Update an installed agent to the latest available version
\fB\-\-all\fR
Update every installed managed agent
.TP
\fB\-\-rollback\fR [\fI<ROLLBACK>\fR]
Roll back to a pre\-update backup instead of updating ("latest" or a backup id; "\-\-rollback list" shows them)
.TP
\fB\-h\fR, \fB\-\-help\fR
Print help
.TP
+5 -2
View File
@@ -1,6 +1,6 @@
.ie \n(.g .ds Aq \(aq
.el .ds Aq '
.TH am 1 "am 0.4.5"
.TH am 1 "am 0.4.6"
.SH NAME
am \- agent\-manager (am) — manage local AI coding agents
.SH SYNOPSIS
@@ -93,6 +93,9 @@ Manage command aliases (cc \-> claude\-code)
am\-secret(1)
Manage secrets in the OS keyring (never in plaintext config)
.TP
am\-audit(1)
Audit the configuration: who changed what, when (issue #63)
.TP
am\-models(1)
List local models (ollama, llama.cpp, LM Studio) and prune unused ones
.TP
@@ -189,4 +192,4 @@ Export the configuration and installation state (backup)
am\-import(1)
Import a previously exported configuration and state
.SH VERSION
v0.4.5
v0.4.6