From dab25636c874405155d8fe83ebcdc4e2bd71936f Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Tue, 25 Aug 2026 19:48:06 +0200 Subject: [PATCH] =?UTF-8?q?chore(memory):=20BDR-085=20+=20journal=20+=20TO?= =?UTF-8?q?DO=20=E2=80=94=20user=20permanent=20rules=20integrated?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .claude/memory/decisions.md | 9 +++++++++ .claude/memory/journal.md | 3 +++ .claude/tasks/TODO.md | 19 +++++++++++++++++++ 3 files changed, 31 insertions(+) diff --git a/.claude/memory/decisions.md b/.claude/memory/decisions.md index f35ce82..3400471 100644 --- a/.claude/memory/decisions.md +++ b/.claude/memory/decisions.md @@ -94,6 +94,7 @@ rules: | BDR-080 | 2026-07-21 | Bug routing inverted: /bugfix primary, /investigate explicit-only | accepted | | BDR-083 | 2026-08-24 | Contract gates: deterministic floor (GATE 0) under the fresh verifier | accepted | | BDR-084 | 2026-08-24 | /tour multi-project: parallel runners (LRN-083 derogation, bounded), runner inherits session model | accepted | +| BDR-085 | 2026-08-25 | User permanent rules: writing-style always-on in rules/, web build+security path-scoped | accepted | --- @@ -1096,3 +1097,11 @@ ONE real sequential-but-independent candidate: /tour multi-project (independent Decision: STEP 0 routes (1 project = inline unchanged; ≥2 = STEP 0b fan-out). One general-purpose runner per project, ALL in ONE message, dispatched with NO model override — inherits the session model (model-gate already validated big; a runner carries tour's reflection: fix decisions, convergence). Inside a runner every agent keeps its defined tier (security-auditor sonnet, Phase B opus, doc-syncer sonnet two-mode). Dead/mute runner ⇒ explicit `RUNNER FAILED` summary row (mute is never a pass). Capitalize offer stays MAIN LOOP ONLY (registries = shared state). LRN-083 derogation, bounded: per-project fix loop + convergence now run INSIDE the dispatched runner. Bounded because nothing a runner decides touches shared state — independent repos, per-repo chore branches, branches stay UNMERGED for human review exactly as inline (report-as-approval-gate design unchanged). Precedent: client-handover-writer already a dispatched orchestrator running parallel audit loops (BDR-077). Alternatives rejected: report-only-only parallel (my recommendation — user overrode: full parallel wanted); one sub-orchestrator agent .md file (drift risk vs SKILL.md, the runner reads the skill from disk instead — client-handover→/seo precedent); pinning the runner (would put tour reflection on an executor tier — inverts BDR-076); global CLAUDE.md parallelism line (duplicate of harness injection). Census §12: 6 locks (fan-out present, no-pin, single-message, capitalize main-loop, RUNNER FAILED, no pinned runner), flip-tested. Branch feature/tour-parallel, UNMERGED (human gate). + +### BDR-085 — user permanent rules: writing-style always-on in rules/, web rules path-scoped [accepted] (2026-08-25) +User supplied 4-block permanent rule text (writing / website / code security / self-check), asked: coverage check, conflict check, integrate. Coverage verdict: security CORE (parameterized queries, input validation, env-var secrets, AuthN/AuthZ split + default deny, no stack traces, fail closed, least privilege) ALREADY in CLAUDE.global.md §Security — NOT duplicated. NEW: entire writing-style block, design anti-default list, public-site done-checklist, web-app specifics (browser-exposed keys, service-key/client split, RLS, server-side auth, IDOR, hashed passwords + cookie flags, field minimization, rate limiting, upload restrictions). +Placement: CLAUDE.global.md at 308/320 (session-start density guard) → no room for ~30 always-on lines. Decision: rules/writing-style.md WITHOUT paths: (always-on load, same session cost, outside the 320 budget) + rules/web-building.md + rules/web-security.md WITH paths: (lazy-load = token win, fire only on web/code files). Project CLAUDE.md doctrine line amended with the budget exception. Feeds C2 self-contradiction audit. +Conflict carve-outs, stated INSIDE the rules: registries keep caveman format (fragments, em-dashes, bullets); code comments keep code style; structured skill/report templates keep their formats; robuste/transformer banned in buzzword sense only (robustness lens, math transform allowed); no-Inter default rule carries "existing brand identities keep their fonts" (ZenQuality deliverables use Inter+Playfair by brand decision — client-handover BDR). +Self-check rule scoped to DELIVERABLES (text, site, feature), not every conversational reply — literal "avant de me rendre quoi que ce soit" would append a compliance note to every chat answer, pure noise. User can re-widen. +Alternatives rejected: compress into CLAUDE.global.md (~11 lines to fit → loses the carve-outs, zero headroom left); path-scope writing-style (applies to conversation, not file reads → would never fire in chat-only sessions); one merged web file (two concerns, one-rule-one-file). +Branch feature/user-writing-web-rules, UNMERGED (human gate). diff --git a/.claude/memory/journal.md b/.claude/memory/journal.md index f7d5cff..de675b5 100644 --- a/.claude/memory/journal.md +++ b/.claude/memory/journal.md @@ -440,3 +440,6 @@ rules: - `make test` rc 0, shellcheck clean, 64 new assertions, e2e on a real contract. Branch feature/contract-gates UNMERGED (human gate). - Locks caught a reflow regression (5 red on rewrapped phrases, zero doctrine lost) → [[LRN-142]]. Skill-adoption pattern → [[LRN-141]]. - Parallelism audit (user ask "est-ce actif ?"): measured, not assumed — nested probe proves concurrent fan-out (9.1s vs 18s), doctrine already prescribed everywhere safe, remaining serializations motivated. One candidate found: /tour multi-project → parallel runners shipped ([[BDR-084]], user gate "tout paralléliser" + model invariant). Branch feature/tour-parallel UNMERGED. + +## 2026-08-25 +- User permanent rules integrated: rules/writing-style.md (always-on) + web-building.md + web-security.md (path-scoped). Security core already in §Security, not duplicated. Carve-outs protect caveman registries + skill templates + brand fonts. [[BDR-085]]. Branch feature/user-writing-web-rules UNMERGED (human gate). diff --git a/.claude/tasks/TODO.md b/.claude/tasks/TODO.md index 270ecc5..7297242 100644 --- a/.claude/tasks/TODO.md +++ b/.claude/tasks/TODO.md @@ -1,5 +1,24 @@ # TODO +## 2026-08-25 — user permanent rules: writing + web build + web security (feature/user-writing-web-rules) +User supplied 4-block rule text (écris / site / code / vérification); asked: +coverage check, conflict check, integrate. Verdict: security CORE already in +CLAUDE.global.md §Security (parameterized queries, env-var secrets, +AuthN/AuthZ, fail closed) — NOT duplicated. NEW: writing-style block, design +anti-default list, site done-checklist, web-app specifics (RLS, service key, +IDOR, cookie flags, rate limit, field minimization). Placement: global at +308/320 budget → rules/ instead. +- [x] R1 rules/writing-style.md — always-on (no paths:), scope carve-outs + (registries caveman, code comments, skill templates) + self-check +- [x] R2 rules/web-building.md — paths: web globs; anti-defaults + done + checklist (report missing, never invent) + skill pointers +- [x] R3 rules/web-security.md — paths: code globs; web-app specifics + extending §Security, zero dup of the core +- [x] R4 CLAUDE.md (project) — amend always-on doctrine line (320-budget + exception → rules/), feeds C2 audit +- [x] R5 capitalize BDR-085 + journal + CHANGELOG +- [ ] NO merge — human gate + ## 2026-07-30 — adapt config for Claude 5 family / Opus 5 (feature/opus5-config-tuning) User: Opus 5 "needs more freedom" → research (official migration guide + web + registres) confirms: over-delegates (inverts LRN-030 Opus 4.8 trait),