chore(memory): BDR-112 amendment — manual-push mode user-tested, dotfiles prompt handed over
This commit is contained in:
@@ -1377,7 +1377,8 @@ Branch feature/user-writing-web-rules, UNMERGED (human gate).
|
||||
- **Why**: `ask` inert under auto ([[LRN-155]]); `hooks/guard-bash.sh` withheld ([[BLK-022]]) → one narrow rule instead. Trailing ` *` glob matches end-of-string ([[LRN-194]]) → no infix rule spares the bare read → Claude loses `git config … gitflow.autopush`; hooks/lib keep it; run C gets `gitflow.sh push-mode`. Text-only guard cannot see scripts/aliases → soft_deny is the declared backstop.
|
||||
- **Alternatives rejected**: no-jq fallback (greps whole payload, denies in auto, untestable without shim; jq hard dep); `-C` dir unresolvable → allow (fail-open; now skipped, cwd still checked); `rev-parse` work-tree gate (drops the global key); `--default true` read (hides git failure); narrowing deny to spare the read (impossible with end-matching globs).
|
||||
- **Gates**: 3 lenses CONCERNS(2)/CONCERNS(5)/FATAL(7) + confirmation FATAL(8) → r2 (BSD sed, oracle naming denied tokens, read loss); feater ×3 (58 → 61 → 71 checks); GATE 0 MET ×3; verifier CONFORME, then ECARTS(1) on hardening closed by gated clarification; security PASS ×2 (3 MEDIUM closed: 20k-token flood denied in 0.15 s, git absent → deny, `bash -c 'cd … && git push'` extracted; residuals → run D).
|
||||
- **Refs**: contract `.claude/tasks/contracts/2026-10-07-manual-push-guard-1003.md`, plan `.claude/tasks/plans/2026-10-07-manual-push-guard-1003.md`, commits a2ac018 + 6468eda (feature/manual-push-mode, UNMERGED). Links [[BDR-095]], [[BDR-100]], [[LRN-069]], [[LRN-196]]. Open: user probe `! git push --dry-run` under autopush=false (bang commands assumed hook-free).
|
||||
- **Refs**: contract `.claude/tasks/contracts/2026-10-07-manual-push-guard-1003.md`, plan `.claude/tasks/plans/2026-10-07-manual-push-guard-1003.md`, commits a2ac018 + 6468eda (feature/manual-push-mode, UNMERGED). Links [[BDR-095]], [[BDR-100]], [[LRN-069]], [[LRN-196]].
|
||||
- **Amendment 2026-10-07**: user probe done on their machine (`autopush=false` repo): no auto push, the bang-prefixed dry-run passes → `!` commands bypass the PreToolUse guard, design confirmed. Dotfiles installer will prompt for the key (default false) and carry `core.hooksPath` in the gitconfig template.
|
||||
|
||||
## BDR-113 — Skills never push; truth from `rev-list` facts, mode verb only words the reason [accepted] (2026-10-07)
|
||||
- **Decision**: run C of [[BDR-111]]. New lib verb `gitflow.sh push-mode` (stdout `auto|manual|invalid`, rc 0, raw value on stderr, printable ≤64 chars; ignores GITFLOW_NO_PUSH) = the one reader skills may call (bare `git config … gitflow.*` denied, [[BDR-112]]). Skills push NOTHING on their own except the release tag in auto mode on explicit go. Every "on origin / not pushed" line comes from `git rev-list --count origin/<br>..<br>` (or `<br> --not --remotes=origin` for the tour) read AFTER the action, in its own Bash call; the verb only words the reason (manual vs push FAILED vs invalid). Removed as redundant since BDR-095: `/close` STEP 5C `git push origin develop` (finish pushes develop itself, mode-aware since run A) and `/client-handover`'s "Push to origin now?" question + push block (hooks had pushed; push-guard denies in manual). User hints are complete `! git …` commands (`-u`, `--atomic origin main develop vX`, `-C <abs project>`), branch name allowlisted `^[A-Za-z0-9._/][A-Za-z0-9._/-]*$` before any interpolation. `/release-candidate` manual/invalid or any count ≠ 0 → one user command, STOP, no question; tag gate kept for auto with both counts 0. `/tour`: one `-C` fact per project after the report commit, suffix-aware branch name, summary row `on origin | local only → cmd`.
|
||||
|
||||
@@ -575,4 +575,5 @@ rules:
|
||||
- /feat manual-push-mode run C (user: "enchaine"), split C1+C2. C1: lib verb `gitflow.sh push-mode` (auto|manual|invalid, value on stderr, rc 0) + T11b; /close STEP 5C `git push origin develop` REMOVED (finish has pushed develop since BDR-095; shell gate would be denied whole by push-guard, `$mode` dies between Bash calls) → finish, verb, `rev-list --count origin/develop..develop`, prose outcomes incl. finish-failure; `--no-push` line from the branch's own count. Challenge 3 lenses (1 BLOCKER) + confirm CONCERNS(3); verifier CONFORME; security PASS. C2: client-handover GO question + push block removed (hooks pushed already in auto; guard denies in manual) → PUSH STATE READ re-run before every claim, branch-name allowlist (security BLOCK(1) → fixed, PASS); release-candidate: two counts + verb, `! git push --atomic origin main develop vX`, tag gate kept for auto/0/0; tour: `-C` fact per project, suffix-aware branch, `--remotes=origin`. Verifier CONFORME ×2. Commits 5cf049d + 6104545, UNMERGED. Polish pass in flight.
|
||||
- /feat manual-push-mode run D (user: "enchaine"), split D1/D2/D3, 9 lenses + 3 confirmations. D1: every autopush reader fails closed AND names an invalid value (lib `_gitflow_push_off` via the verb; emitted hooks POSIX `case "$rc:$v"` + stderr line; unpushed-guard via the verb, no temp file); regen files-only via `emit-hook >` after the confirmation showed `install-hook` writes a local hooks-path and `global-hooks` writes the GLOBAL config when it lacks the value — which it did: user's dotfiles installer had overwritten `~/.gitconfig` (@USER@ placeholders, no hooksPath) + `~/.zshrc` at 15:39; user confirmed (own machine setup) and restored from the installer's backup before execution. D2: push-guard sources the lib, whole-word tokens (mixed quoting → deny), payload fallback, cap BEFORE classification (security BLOCK(1) caught the reorder: 1,600 tokens = 13 s > 10 s timeout → fixed, 20k tokens 0.13 s), T42 base main, banner `autopush bad`. D3: prose aligned (invalid outcome split on the ahead count, labels COMMIT + PUSH STATE READ, executor version check by reading). Commits 472cccb, 3c59333, 64ca0f8 on feature/manual-push-mode, UNMERGED. Residuals in TODO.
|
||||
- Merge (user go "tu peux merge dans develop"): final full suite green (46 suites minus the declared env red) + Health Stack shellcheck clean on the branch tip → `gitflow finish feature manual-push-mode` → develop 669db06, pushed, branch removed local + origin. 19 commits (runs A, B, C1/C2, D1/D2/D3 + docs + memory). User answered: only pushes change; commits/branches/local merges untouched; invalid value now fail-closed everywhere. User plan: dotfiles installer prompts for `gitflow.autopush` (default false) — told them the gitconfig template also needs `core.hooksPath` (the install wiped it). Open: user probe `! git push --dry-run` under autopush=false; AC6 env red (design-tool-gate); post-run-D residuals in TODO.
|
||||
- User tested manual-push mode on their machine: works (no auto push under `false`, bang-prefixed dry-run passes). Prompt handed over for the dotfiles repo: gitconfig template gets `core.hooksPath = ~/.claude/githooks` + `[gitflow] autopush = @AUTOPUSH@` rendered from an install question (default false, true/false only, unrendered placeholder = render failure). BDR-112 amended.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user