feat(skills): push state read from facts, never pushed by the skills

Run C2 of manual-push mode (BDR-111/BDR-112). The four flows that pushed
on their own, or claimed the branch was on origin, now read the truth
after the fact and hand the user the exact command:

- client-handover-writer: the "Push to origin now?" question and its
  push block are gone (the hooks had already pushed in auto-push mode;
  push-guard denies it in manual mode). A reusable PUSH STATE READ
  (branch, origin probe, `git rev-list --count origin/<br>..<br>`, the
  verb only to word the reason) runs after commit-change, at the top of
  the deploy pause, after "Deployed" and before each end report. The
  branch name is validated against an allowlist before it is placed in
  any command or hint (a hostile branch name is otherwise a shell
  injection). Pending → the user pushes BEFORE the deploy pause; the
  deploy brief says "after your push". `Push:` line in both reports.
- release-candidate STEP 6: two ahead counts + the verb; anything other
  than auto with both counts 0 prints one user command
  `! git push --atomic origin main develop v<X.Y.Z>` and stops; the tag
  gate stays for auto mode; `hold` notes --follow-tags; version regex.
- release-executor: push claims qualified (auto-push mode, best effort).
- tour: mode-agnostic rule; STEP 3 reads one `git -C <project>` fact per
  project (suffix-aware branch, --remotes=origin, origin probe) and the
  summary row says on origin / local only with the user command.
This commit is contained in:
bchanot
2026-10-07 14:02:51 +02:00
parent 5cf049d235
commit 6104545e76
5 changed files with 108 additions and 55 deletions
+9 -7
View File
@@ -77,15 +77,17 @@ actual branch; never finish whatever happens to be checked out.
output verbatim; do not attempt to resolve it yourself.
2. **Tag AFTER finish, on `main`** — never before:
`git tag -a v<X.Y.Z> main -m "release <X.Y.Z>"` (annotated, so it lands on
main's release-merge commit). Finish has already pushed `main` and
`develop` through the lib's hooks (BDR-095); the tag stays local until
the dispatcher's tag-push gate.
main's release-merge commit). In auto-push mode finish pushes `main`
and `develop` (best effort: the lib warns and returns 0 on a failed
push; the dispatcher re-verifies with ahead counts) (BDR-095); in
manual push mode they stay local. The tag stays local until the
dispatcher's tag-push gate.
### Forbidden in this span
`git push` (any remote, any ref — `main`/`develop` ride the lib's hook
pushes during finish; the dispatcher owns the tag-push gate), deciding the
version number, the when-to-release decision, attribution trailers of any
kind.
`git push` (any remote, any ref — `main`/`develop` ride the lib's
pushes during finish in auto-push mode; the dispatcher owns the tag-push
gate), deciding the version number, the when-to-release decision,
attribution trailers of any kind.
---