docs(skills): invalid autopush value is fail-closed everywhere; prose aligned

Run D3 of manual-push mode (BDR-114). With every reader now failing
closed, the skill prose stops saying the lib and hooks still push on an
invalid value:

- capitalize STEP 5C / STEP 6: the invalid outcome is split on the ahead
  count (nothing pushed vs pushed anyway by a stale fail-open hook or a
  manual push); the verb's stderr line is quoted verbatim; neighbouring
  closing lines carry push-mode qualifiers so none shadows the invalid
  case; the --no-push lines follow the same rule.
- client-handover: "COMMIT + PUSH" labels become "COMMIT + PUSH STATE
  READ"; the STEP 5 residual sentences no longer imply the pipeline
  pushes; the invalid value is named as a case where the user pushes.
- release-executor: prep span checks the version format by reading the
  string (never in a Bash command); manual mode and an invalid value
  both leave main/develop local.
This commit is contained in:
bchanot
2026-10-07 17:11:58 +02:00
parent 3c59333fcf
commit 64ca0f8e09
4 changed files with 21 additions and 16 deletions
+7 -7
View File
@@ -533,7 +533,7 @@ After loops finish (success, stall, or override), capture:
---
## STEP 5 — COMMIT + PUSH (only if files changed)
## STEP 5 — COMMIT + PUSH STATE READ (only if files changed)
```bash
CHANGED_DURING_PIPELINE=$(git diff --name-only "$PIPELINE_BASE_SHA"..HEAD)
@@ -542,18 +542,18 @@ PENDING_CHANGES=$(git status --porcelain)
If both empty → skip to STEP 6.
**Gitflow precondition (report-only fallback).** Before any commit or push,
confirm this is a gitflow repo:
**Gitflow precondition (report-only fallback).** Before any commit,
confirm this is a gitflow repo (the pipeline never pushes):
```bash
git rev-parse --verify -q develop >/dev/null 2>&1 && echo DEVELOP_OK
[ -f "$HOME/.claude/lib/gitflow.sh" ] && echo LIB_OK
```
If `develop` is missing OR the gitflow lib is unavailable → **do NOT commit,
do NOT push.** Leave the changes in the working tree and record in the STEP 8
summary: "Commit/push skipped — no gitflow model in this repo; publish the
listed changes manually before deploy." Continue to STEP 6.
If `develop` is missing OR the gitflow lib is unavailable → **do NOT commit
(and never push).** Leave the changes in the working tree and record in the
STEP 8 summary: "Commit skipped — no gitflow model in this repo; publish the
listed changes by hand before deploy." Continue to STEP 6.
If `PENDING_CHANGES` non-empty → invoke /commit-change skill via subagent:
+4 -1
View File
@@ -31,6 +31,9 @@ stop and report — never chain into the other span yourself.
### Input
`<X.Y.Z>`: the version number, already decided by the dispatcher before
dispatch — you never derive it, never second-guess it, never bump it.
Format check only, by reading the string (never inside a Bash command):
<X.Y.Z> must match ^[0-9]+\.[0-9]+\.[0-9]+$ (literal regex text, single
backslashes); anything else → STATUS: BLOCKED, nothing created.
### Steps
1. `bash "$HOME/.claude/lib/gitflow.sh" start release <X.Y.Z>` — forks from
@@ -80,7 +83,7 @@ actual branch; never finish whatever happens to be checked out.
main's release-merge commit). In auto-push mode finish pushes `main`
and `develop` (best effort: the lib warns and returns 0 on a failed
push; the dispatcher re-verifies with ahead counts) (BDR-095); in
manual push mode they stay local. The tag stays local until the
manual push mode, or with an invalid gitflow.autopush, they stay local. The tag stays local until the
dispatcher's tag-push gate.
### Forbidden in this span