chore(memory): journal + TODO — manual-push-mode merged into develop (669db06)

This commit is contained in:
bchanot
2026-10-07 17:37:57 +02:00
parent 669db06485
commit 6b528dc85f
2 changed files with 3 additions and 2 deletions
+2 -2
View File
@@ -2056,14 +2056,14 @@ dans un runner; capitalize reste main-loop.
- [ ] P34 USAGE + agents/plugin-advisor.md "gstack ON/OFF", "context7 ON" vocabulary — gstack is per-profile, ctx7 is a CLI; move both together
- [ ] P41 templates/settings/settings.json: `permissions.ask` entries (npx, docker rm, make deploy, psql…) inert under defaultMode auto → config fix, not doc
## manual-push-mode (2026-10-06, /feat × 3)
## manual-push-mode (2026-10-06, /feat × 3) — MERGED into develop 669db06 (2026-10-07, user go)
- [x] run A — `gitflow.autopush=false` honoured by `_gitflow_push_branch`, quiet unpushed-guard, doctrine line; plan `.claude/tasks/plans/2026-10-06-manual-push-mode-1632.md` → commit 2fc8830 on feature/manual-push-mode; verifier ECARTS(1) = AC6 only (design-tool-gate env red, pre-existing on develop) → human waiver; merge human-gated
- [x] run B — `hooks/push-guard.sh` PreToolUse (deny `git push` in manual mode) + 71-check test + settings.json (own hook group Bash|Monitor timeout 10; 18 write-form deny entries on the toggle; soft_deny on manual-mode pushes with no per-turn clearance; prose) + banner → a2ac018 + hardening commit; verifier CONFORME then ECARTS(1) closed by gated clarification (fail-closed cap/unenterable dir also in auto mode); security PASS ×2
- [x] run D also (closed in D2 3c59333 — push-guard residuals, security gate 2026-10-07): tokens with inner quotes/backslashes (`cd /m/'a b'`) resolve to the wrong dir → treat as unresolvable + deny or document; unparseable payload (lone surrogate) → jq fails → silent allow → grep raw payload for `push` and deny; `case "$mode"` default `*) deny`; up-front `command -v grep sed sort head jq` check; header line > 80 cols; T42 compares against HEAD (vacuous once committed) → compare against a pinned base or drop; no test sets the key to literal `true`
- [x] run C (C1 5cf049d, C2 6104545; split C1: lib verb `push-mode` + T11 tests + capitalize STEP 5C + close hint, plan `.claude/tasks/plans/2026-10-07-manual-push-skills-c1-1304.md`; C2: client-handover skill+agent, release-candidate STEP 6, tour rule) — skills that push on their own, gate on the mode through a NEW lib verb `bash ~/.claude/lib/gitflow.sh push-mode` (prints auto|manual|invalid; the bare `git config … gitflow.autopush` read is denied for Claude after run B — a trailing ` *` glob also matches end-of-string): capitalize STEP 5C (`git push origin develop`), client-handover SKILL:48 + agents/client-handover-writer.md:586, release-candidate:96 + tour:273 "already on origin" claims
- [ ] run B also: fail-CLOSED on an unparseable `gitflow.autopush` value in every reader at once (lib `_gitflow_push_off`, the two emitted push hooks, unpushed-guard) — run A keeps fail-open for consistency with the untouched emitters (security gate MEDIUM, 2026-10-06); `--end-of-options`/`--` on refname args and `printf %q` in copy-paste hints (LOW); `gitflow_delete`: check `_gitflow_checkout_containing_base` rc before `--unset-upstream` (LOW, 2nd gate)
- [x] C1/C2 polish pass → 3881f46 (verifier CONFORME, security PASS; items were: capitalize STEP 5C heading still says "(finish + push)"; :372 paragraph glued to the :371 bullet and tells the WORKING-branch path to read `origin/chore/<name>..` (no such ref there; that path never uses the mode); on finish rc 5/2/6 calls 2-3 are skipped so a manual-mode user gets no `! git push origin develop` hint; the "unknown + manual" closing line (:377) lacks the `once a remote exists` hint present in 5C (:348); STEP 6 "auto-persisted … pushed" bullet (:371) not tied to `ahead = 0` (security MEDIUM); verb stderr: cap `raw` to 64 printable chars; T11b "default auto" relies on the Makefile's hermetic env (fine under `make test`, spurious when run bare on a global-manual machine) → export in the suite header like line 257. C2 polish (verifier non-gaps): client-handover-writer PUSH STATE READ states need explicit precedence (uncommitted/no-commits first, then no-origin, then ahead); tour STEP 3 item 5 only when a branch exists (report-only / dirty-tree rows have none); 9.7 `STATUS: BLOCKED` branch lacks the `- Push:` bullet; release-executor:85-86 line > 80 cols
- [x] ORDER constraint lifted: A + B + C all on feature/manual-push-mode; merge (human gate) then the work machine may set `gitflow.autopush false`. Still pending before relying on it at work: user probe `! git push --dry-run` in a scratch repo under autopush=false (bang commands assumed hook-free); run D below.
- [x] MERGED 669db06 (user go, final suite green, shellcheck clean). Work machine: the user's dotfiles installer will set `git config --global gitflow.autopush` with a prompt, default false; its gitconfig template must also carry `core.hooksPath = ~/.claude/githooks` (the 15:39 install wiped it). Still pending before relying on it at work: user probe `! git push --dry-run` in a scratch repo under autopush=false (bang commands assumed hook-free); run D below.
- [x] run D (D1 472cccb, D2 3c59333, D3 64ca0f8 — all verifier CONFORME + security PASS; split 2026-10-07: D1 fail-closed readers — lib `_gitflow_push_off` via the verb, emitted push hooks POSIX rule + regen, unpushed-guard via the verb, plan `.claude/tasks/plans/2026-10-07-manual-push-failclosed-d1-1522.md`; D2 push-guard residuals + session-start banner on invalid + tour `<abs project>` quoting; D3 skill/agent prose: drop the "until run D" caveats, stale COMMIT + PUSH headings, release-executor version regex, + doc-sync) — fail-CLOSED on an unparseable `gitflow.autopush` in every reader at once (lib `_gitflow_push_off`, the two emitted push hooks + githooks regen, unpushed-guard) so the "invalid → lib/hooks still push" caveat in CHANGELOG/SETTINGS/skills can be removed; push-guard residuals (inner-quote/backslash tokens, lone-surrogate payload, `*) deny` default, up-front tool check, T42 base, literal `true` test); verb stderr: `LC_ALL=C` done, truncation marker + sanitizer test; client-handover: stale "COMMIT + PUSH" headings, `<abs project>` quoting in tour hints; release-executor own version regex
## test hermeticity (2026-10-06, found during manual-push-mode run A)