feat(gates): wire GATE 0 into the four orchestrator skill restatements

The include is authoritative, but feat/bugfix/ship-feature/init-project
each restate the verify loop inline — an orchestrator following the
restatement alone would have skipped the floor. Each now carries the
GATE 0 bullet ahead of GATE 1 (4 new structure locks, flip-tested).
The contract-interview weight table stops promising a hotfix oracle
nothing executes: hotfix runs no floor, the hotfixer runs the suite
itself. CHANGELOG extended with the wiring + the RED result.
This commit is contained in:
Bastien Chanot
2026-08-24 13:36:32 +02:00
parent abb4ea7650
commit 33f5356c82
9 changed files with 41 additions and 7 deletions
+6 -1
View File
@@ -172,6 +172,11 @@ Parse the `BUGFIX-EXEC REPORT`:
1. Run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` with
`CONTRACT` = the STEP 3.5 path, `DIFF` = the executor's working-tree diff,
`TEST` = the suite named in its report:
- GATE 0 — deterministic floor, no dispatch: `bash ~/.claude/lib/gates.sh
run "$CONTRACT"` executes the criteria's declared oracles fail-closed
(the regression-test criterion included). UNMET → re-dispatch a FRESH
bugfixer with the NOT-MET rows verbatim — no verifier is spent on a red
floor; own budget, max 3 → escalate. MET → GATE 1.
- GATE 1 — a FRESH verifier judges the fix against the contract (bug gone
+ regression test present). CONFORME on the first pass → straight to
GATE 2, no loop. ECARTS → the "dev" of the loop is the dispatched
@@ -183,7 +188,7 @@ Parse the `BUGFIX-EXEC REPORT`:
path; re-verify the request THEN re-scan, max 3 → escalate.
Loop decisions stay HERE, in the main loop (LRN-083). Nominal = one
executor + one verifier + one security dispatch.
executor + a free floor run + one verifier + one security dispatch.
2. **Pre-commit confirmation gate.** Before running `git commit`, present the diff
summary and the proposed message, then wait for approval:
+7 -2
View File
@@ -161,6 +161,11 @@ Run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` with
`CONTRACT` = the STEP 0.7 path, `DIFF` = the working-tree diff the executor
produced, `TEST` = the suite named in its report:
- GATE 0 — deterministic floor, no dispatch: `bash ~/.claude/lib/gates.sh
run "$CONTRACT"` executes the criteria's declared oracles fail-closed.
UNMET → re-dispatch a FRESH feater with the NOT-MET rows verbatim — no
verifier is spent on a red floor; own budget, max 3 → escalate.
MET (an all-manual contract too) → GATE 1.
- GATE 1 — a FRESH verifier judges the diff against the contract (blind).
CONFORME on the first pass → straight to GATE 2, no loop. ECARTS → the
"dev" of the loop is the dispatched executor: re-dispatch a FRESH feater
@@ -171,8 +176,8 @@ produced, `TEST` = the suite named in its report:
CONTRACT path; re-verify the request THEN re-scan, max 3 → escalate.
Loop decisions stay HERE, in the main loop (LRN-083). Nominal (clear
request, conform first pass, clean diff) = one executor + one
verifier + one security dispatch.
request, conform first pass, clean diff) = one executor + a free floor
run + one verifier + one security dispatch.
## STEP 5 — COMMIT
+5
View File
@@ -227,6 +227,11 @@ If `graphify` not installed or complexity < 30% → skip silently.
Run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` with
`CONTRACT` = the STEP 1 path (ENRICHED at STEP 4), `DIFF` = the MVP branch
diff (`develop..HEAD`), `TEST` = the project suite:
- GATE 0 — deterministic floor, no dispatch: `bash ~/.claude/lib/gates.sh
run "$CONTRACT"` executes the criteria's declared oracles fail-closed.
UNMET → hand the dev with the NOT-MET rows verbatim — no
verifier is spent on a red floor; own budget, max 3 → escalate.
MET (an all-manual contract too) → GATE 1.
- GATE 1 — a FRESH verifier judges the MVP against the enriched contract (V1
features + `[gated]` design criteria). CONFORME → GATE 2. ECARTS → fix,
re-verify, max 3 → STOP + human escalation with the CRITERIA table.
+5
View File
@@ -210,6 +210,11 @@ OPTIONS :
Run the two fresh gates per `$HOME/.claude/lib/verify-secure-loop.md` with
`CONTRACT` = the STEP 0e path (ENRICHED at STEP 3), `DIFF` = the branch diff
(`develop..HEAD`), `TEST` = the project suite:
- GATE 0 — deterministic floor, no dispatch: `bash ~/.claude/lib/gates.sh
run "$CONTRACT"` executes the criteria's declared oracles fail-closed.
UNMET → hand the dev with the NOT-MET rows verbatim — no
verifier is spent on a red floor; own budget, max 3 → escalate.
MET (an all-manual contract too) → GATE 1.
- GATE 1 — a FRESH verifier judges the branch against the ENRICHED contract
(all criteria, including the `[gated]` design ones). CONFORME → GATE 2.
ECARTS → hand the dev the gap list, fix, re-verify, max 3 → STOP + human