chore(memory): BDR-112 amendment — manual-push mode user-tested, dotfiles prompt handed over

This commit is contained in:
bchanot
2026-10-07 17:45:01 +02:00
parent 6b528dc85f
commit f24682b3f3
3 changed files with 4 additions and 2 deletions
+2 -1
View File
@@ -1377,7 +1377,8 @@ Branch feature/user-writing-web-rules, UNMERGED (human gate).
- **Why**: `ask` inert under auto ([[LRN-155]]); `hooks/guard-bash.sh` withheld ([[BLK-022]]) → one narrow rule instead. Trailing ` *` glob matches end-of-string ([[LRN-194]]) → no infix rule spares the bare read → Claude loses `git config … gitflow.autopush`; hooks/lib keep it; run C gets `gitflow.sh push-mode`. Text-only guard cannot see scripts/aliases → soft_deny is the declared backstop.
- **Alternatives rejected**: no-jq fallback (greps whole payload, denies in auto, untestable without shim; jq hard dep); `-C` dir unresolvable → allow (fail-open; now skipped, cwd still checked); `rev-parse` work-tree gate (drops the global key); `--default true` read (hides git failure); narrowing deny to spare the read (impossible with end-matching globs).
- **Gates**: 3 lenses CONCERNS(2)/CONCERNS(5)/FATAL(7) + confirmation FATAL(8) → r2 (BSD sed, oracle naming denied tokens, read loss); feater ×3 (58 → 61 → 71 checks); GATE 0 MET ×3; verifier CONFORME, then ECARTS(1) on hardening closed by gated clarification; security PASS ×2 (3 MEDIUM closed: 20k-token flood denied in 0.15 s, git absent → deny, `bash -c 'cd … && git push'` extracted; residuals → run D).
- **Refs**: contract `.claude/tasks/contracts/2026-10-07-manual-push-guard-1003.md`, plan `.claude/tasks/plans/2026-10-07-manual-push-guard-1003.md`, commits a2ac018 + 6468eda (feature/manual-push-mode, UNMERGED). Links [[BDR-095]], [[BDR-100]], [[LRN-069]], [[LRN-196]]. Open: user probe `! git push --dry-run` under autopush=false (bang commands assumed hook-free).
- **Refs**: contract `.claude/tasks/contracts/2026-10-07-manual-push-guard-1003.md`, plan `.claude/tasks/plans/2026-10-07-manual-push-guard-1003.md`, commits a2ac018 + 6468eda (feature/manual-push-mode, UNMERGED). Links [[BDR-095]], [[BDR-100]], [[LRN-069]], [[LRN-196]].
- **Amendment 2026-10-07**: user probe done on their machine (`autopush=false` repo): no auto push, the bang-prefixed dry-run passes → `!` commands bypass the PreToolUse guard, design confirmed. Dotfiles installer will prompt for the key (default false) and carry `core.hooksPath` in the gitconfig template.
## BDR-113 — Skills never push; truth from `rev-list` facts, mode verb only words the reason [accepted] (2026-10-07)
- **Decision**: run C of [[BDR-111]]. New lib verb `gitflow.sh push-mode` (stdout `auto|manual|invalid`, rc 0, raw value on stderr, printable ≤64 chars; ignores GITFLOW_NO_PUSH) = the one reader skills may call (bare `git config … gitflow.*` denied, [[BDR-112]]). Skills push NOTHING on their own except the release tag in auto mode on explicit go. Every "on origin / not pushed" line comes from `git rev-list --count origin/<br>..<br>` (or `<br> --not --remotes=origin` for the tour) read AFTER the action, in its own Bash call; the verb only words the reason (manual vs push FAILED vs invalid). Removed as redundant since BDR-095: `/close` STEP 5C `git push origin develop` (finish pushes develop itself, mode-aware since run A) and `/client-handover`'s "Push to origin now?" question + push block (hooks had pushed; push-guard denies in manual). User hints are complete `! git …` commands (`-u`, `--atomic origin main develop vX`, `-C <abs project>`), branch name allowlisted `^[A-Za-z0-9._/][A-Za-z0-9._/-]*$` before any interpolation. `/release-candidate` manual/invalid or any count ≠ 0 → one user command, STOP, no question; tag gate kept for auto with both counts 0. `/tour`: one `-C` fact per project after the report commit, suffix-aware branch name, summary row `on origin | local only → cmd`.