Commit Graph
1030 Commits
Author SHA1 Message Date
bastien 6104ee5c6b chore(memory): journal + TODO — hotfix full-profile-web-doc-skills 2026-09-25 18:44:27 +02:00
bastien d7ac457376 docs: CHANGELOG full profile +4 gstack skills — hotfix full-profile-web-doc-skills 2026-09-25 18:44:27 +02:00
bastien bbe1087bd8 fix(profiles): full lacked the web/doc gstack tools superpowers does not cover
`scrape`, `skillify` (Browser + dogfooding) and `diagram`, `make-pdf`
(Docs + translation) join the default profile, user go. The rest of the
BDR-017 exclusion list (ios-*, connect-chrome duplicate of
open-gstack-browser, gstack-internal tooling) stays out; enable it per
session with `profile apply` when needed.
2026-09-25 18:12:15 +02:00
bastien 4cd6e6ece9 chore(memory): journal, default profile merged to develop 2026-09-25 2026-09-25 17:06:13 +02:00
bastien 1ee6cf667b Merge feature/default-profile-full into develop 2026-09-25 17:05:59 +02:00
bastien 16fea1106d add .env without magix api 2026-09-25 17:05:33 +02:00
bastien 1b418cae84 chore(memory): BDR-101 + LRN-170 + LRN-171 + EVAL-031 — feat default-profile-full 2026-09-25 16:38:53 +02:00
bastien 0926cc74b5 docs: README profile default + 21st section, CHANGELOG default-profile entries — feat default-profile-full 2026-09-25 16:38:39 +02:00
bastien 1bbdad039c feat(install): apply the default profile at the end of make plugin
New Step 11 after the link.sh refresh: no profile selected → `profile.sh
reset` (default = full); an existing selection → `profile.sh set <sel>`, so
its state comes back after Step 2 re-parks gstack and Step 10 re-links the
design externals. Both calls are `|| warn`-guarded (installer runs under
set -e). Step 8.7 no longer parks the 21st pack unconditionally: the
selected profile governs it (full links the five design skills, the two
publishing skills stay on demand). Plugin legs stay install-immutable
(BDR-028 EXIT guard); the committed enabledPlugins already match full.
2026-09-25 16:28:22 +02:00
bastien 0d035fcab6 feat(profile): default profile = full; reset applies it, current is label-driven
No profile selected (.active-profile absent, empty or legacy "none") now
means the `full` profile is in force: DEFAULT_PROFILE declared once in
lib/profile.sh, resolved by active_profile(); the statusline reads the
constant and shows `full` instead of `?`; `gstack off` trims to it instead
of erroring. `reset` goes to the default profile (= `set full`: enables its
list, parks any non-listed gstack or managed item). `current` names the
active label and scores that profile only, saying `default — not applied
yet` until a set/apply/reset wrote the cache; the "none" sentinel and the
cross-profile best-guess scan are gone (they keyed on the parked-gstack
count, which says nothing under BDR-030's gstack-off default). Hermetic
suite lib/tests/profile-default.test.sh (29 checks) seeds gstack as OFF like
a real tree. Citers updated: profile SKILL, Makefile help, plugin-advisor
PROFILE line + reset paragraph, toggle-external header.
2026-09-25 16:28:21 +02:00
bastien e1963284d2 chore(21st): drop magic MCP residue
The magic MCP wiring left with BDR-093; this removes the prose that still
described it: gitleaks allowlist note, Step 8.7 header, plugins.lock note,
profile.sh comments and the usage() NOTE that still claimed `set` toggles
"the magic MCP", the managed-set test header, README (one history sentence
kept; MCP-era risk paragraph and the retired bashrc wrapper claim dropped).
.env.example carries the same scrub in the working tree; staging it is
denied to the agent (`git add .env*`), the user stages it.
2026-09-25 16:06:20 +02:00
bastien b40dc1e8d4 chore(memory): journal, guardrail mechanisms merged to develop 2026-09-25 2026-09-25 12:07:48 +02:00
bastien 771bb77d79 Merge feature/guardrail-evasion-citers into develop 2026-09-25 12:07:34 +02:00
bastien 2adf985c07 chore(memory): BDR-100 mechanisms, EVAL-030 self-audit, journal + TODO 2026-09-24 2026-09-24 20:58:26 +02:00
bastien 27f201d4aa feat(guardrails): refusal ends the attempt; doctrine-citers census; make test suite=
Root causes of the 2026-09-24 errors turned into mechanisms (BDR-100). hard_deny 'Routing around a guardrail': a refused command is never rerun through a wrapper, alias, heredoc, Makefile target, env file, other shell or other agent; the same clause in 14 agents and in the doctrine's sub-agent rule. make test suite=<file> runs one suite hermetically so the denied env-prefix form is never needed by hand. lib/tests/doctrine-citers.test.sh: every CLAUDE.md "Section" / § Label citation across skills, agents, lib, rules and hooks must resolve to a heading or bold label (flip-tested); its first run fixed rest-api-node.md. Doctrine 'After code changes' step 4: a changed rule, heading, label or threshold → grep every citer in the same commit.
2026-09-24 20:58:25 +02:00
bastien 8f10047ac4 chore(memory): journal, C2 coherence merged to develop 2026-09-24 2026-09-24 20:50:39 +02:00
bastien c0efc8f1c0 Merge feature/c2-coherence into develop 2026-09-24 20:50:28 +02:00
bastien 34132b27e6 chore(memory): BDR-099 C2 coherence, LRN-169 audit method, journal + TODO 2026-09-24 2026-09-24 20:25:41 +02:00
bastien 4a16106940 docs(changelog): C2 coherence pass, gitflow init fix, removed knobs 2026-09-24 20:25:40 +02:00
bastien d82c06f572 refactor(doctrine): C2 coherence — 30 doctrine/skill tensions resolved, doctrine wins (BDR-099)
One ask policy; mandated executors exempt from the delegation rule; skill plan satisfies the planning rule; journal line exempt from the approval gate; chore = maintenance without new behaviour; small fix on develop = bugfix; BDR-068 written as the one auto-finish exception; deploy routes to /deploy. Skills and agents follow: hotfix types by base + skips the design gate on trivial; capitalize/close create missing registries; commit-change asks the branch type; doc/seo/web-validate/refactor branch through the aiguillage; tour reports BREAKING fixes as needs-decision and runs doc-syncer two-mode; client-handover applies audit bundles from its main loop behind one gate; init-project/onboard use the 200-file graphify signal and bootstrap memory; release-candidate gates the tag push only; push wording aligned with the BDR-095 hooks; stale pointers fixed (§ Language, .gsd/ROADMAP.md, handover script path, design-gate lists).
2026-09-24 20:25:40 +02:00
bastien 1b20beccda fix(gitflow): init on an existing repo under the machine-wide hooks lands the socle via a chore/gitflow-adopt merge (T2c) 2026-09-24 20:25:39 +02:00
bastien fe90291cc6 Merge chore/reconcile-2026-09-24 into develop 2026-09-24 18:05:02 +02:00
bastien 2cba37109a chore(memory): journal, reconcile + prune 2026-09-24 2026-09-24 14:44:33 +02:00
bastien 65f8cd1b4c chore(memory): prune-memory 2026-09-24 — index backfill (66 rows), 15 headings normalised, 4 statuses flagged, 6 merges (LRN-163..168), 23 entries compressed
D: every body entry now has an Index row; BDR-074..085, LRN-136, EVAL-026/027 were filed under ### and invisible to the engine and to /reconcile. A: BDR-011/015/031/038 index statuses reflect their supersession; LRN-010 dated path update. B: LRN-147+148, 106+113, 105+107, 142+144, 116+117, 131+132 merged into LRN-163..168, sources kept verbatim and marked superseded. C: tier-1 caveman pass on 23 entries under the negation guard (-5% words: most sentences carry a negation and stay verbatim). Fidelity census: file-level token counts never drop; the per-entry flags on BDR-073 and EVAL-025 are attribution artifacts of the ### fix (bodies byte-identical).
2026-09-24 14:44:32 +02:00
bastien 72a68cca2b chore(reconcile): TODO reconciled 2026-09-24 — T6b done, make link / tmp / synced / 21st notes, Makefile re-verified open 2026-09-24 14:07:18 +02:00
bastien 1e45237ffc chore(memory): journal, settings + synced-skills chore merged to develop 2026-09-24 2026-09-24 13:36:16 +02:00
bastien 87b2615948 Merge chore/settings-and-synced-skills into develop 2026-09-24 13:36:03 +02:00
bastien 128e40616b chore(config): feedbackDrafts off; ignore the app-managed skills/synced mirror
settings.json: the user's hand-edit (feedbackDrafts: off) committed as is. .gitignore: skills/synced/ and its .bucket-* marker are Claude Code's mirror of the claude.ai synced skills (UUID bucket, manifest.json, Anthropic stock skills incl. 117 ISO xsd schemas), rewritten at each sync — same treatment as the graphify and impeccable machine-owned copies (BDR-028, LRN-154).
2026-09-24 13:36:02 +02:00
bastien f08899cf45 chore(memory): journal + TODO, density pass and graphify banner merged to develop 2026-09-24 2026-09-24 13:25:40 +02:00
bastien 10532e3467 Merge feature/graphify-threshold-banner into develop 2026-09-24 13:24:52 +02:00
bastien abec66e11e Merge chore/claude-global-density into develop 2026-09-24 13:24:27 +02:00
bastien 5db2a65fe1 chore(memory): BDR-098 density pass, journal + TODO 2026-09-24 2026-09-24 12:59:12 +02:00
bastien 17ac67c541 chore(doctrine): CLAUDE.global.md density pass, 352 to 270 lines by compression only
Prose tightened section by section, blank lines after headings removed, the six classic Security subsections folded into one labelled list (Destructive tools & data loss kept as a heading), numbered lists collapsed, memory-registries and gitflow paragraphs re-flowed. Deliberately dropped: the release-candidate, audit-delta and init-project/onboard routing lines (name-obvious, BDR-031 criterion) and rationale clauses. Every ## heading verbatim; graphify section byte-identical so the pending feature branch merges clean. Words 2694 to 2302. BDR-098.
2026-09-24 12:59:11 +02:00
bastien 566fcfe1ec chore(memory): BDR-097 graphify threshold, LRN-162 graphify measurements, journal + TODO 2026-09-24 2026-09-24 12:12:16 +02:00
bastien c81b1731af feat(graphify): threshold signal from 200 tracked code files, the banner informs and the user decides
lib/graphify-gate.sh counts tracked code files (graphify's AST extension set, vendored trees excluded) and, from 200 with no graphify-out/graph.json, prints one banner-sized line; session-start shows it with the /graphify hint. Nothing is built, installed or updated: the rule is the user's (BDR-097), grounded in the LRN-162 measurements (AST build 2.3 s, 0 tokens, a query 2 to 3k tokens). Doctrine section and plugin-advisor thresholds follow the same rule; graphify claude install stays rejected. Test: 11 checks. GRAPHIFY_MIN_CODE_FILES overrides the threshold.
2026-09-24 12:12:16 +02:00
bastien 76ad5bb8d5 chore(memory): journal + TODO, remote-branch-cleanup merged to develop 2026-09-24 2026-09-24 11:54:06 +02:00
bastien 91859fe406 Merge feature/remote-branch-cleanup into develop 2026-09-24 11:53:38 +02:00
bastien 0d770123e4 chore(memory): BDR-096 amendment (remote copy cleanup), journal + TODO D8 2026-09-24 2026-09-24 11:50:34 +02:00
bastien 68c9df354b feat(gitflow): remove the origin copy of a branch once its merge is verified
`gitflow_delete` now ends with `_gitflow_delete_remote`: after the local
copy is gone, the remote tip is read with `ls-remote --exit-code`, checked
against develop/main with the same ancestor test, and only then removed
with `push origin --delete`. Same contract as the pushes (BDR-095): best
effort, warn never fail. No origin, `GITFLOW_NO_PUSH=1` or
`gitflow.autopush false` skip it; an unreachable origin or a remote tip
holding commits the bases lack keeps the remote branch, loudly. A base is
never targeted, by construction and by an explicit guard.

The static deny on hand `git push --delete` stays: it matches the Bash
tool's command string, the lib is the sanctioned path. Prose (hard_deny,
environment), doctrine, gitflow SKILL (table, op, warning row),
SETTINGS.md and CHANGELOG updated. T24: 9 checks (finish removes the
copy, bases untouched, unmerged remote tip kept, never pushed silent,
unreachable origin loud, autopush opt-out). 161/163, the 2 failures are
the pre-existing T16a (gitleaks absent on this host).
2026-09-24 11:50:16 +02:00
bastien abd1254d66 chore(memory): journal + TODO, branch-delete-guard merged to develop 2026-09-24 2026-09-24 11:44:41 +02:00
bastien b2e252e58d Merge feature/branch-delete-guard into develop 2026-09-24 11:44:01 +02:00
bastien 0d717d9bfc chore(memory): BDR-096 branch deletion guard, LRN-161 -d checks the upstream, journal + TODO 2026-09-24 2026-09-24 11:35:01 +02:00
bastien 32d8f981df feat(gitflow): delete a branch only after a verified merge, main/develop undeletable
Since BDR-095 `start` sets an auto-pushed upstream, so `git branch -d`
checked "merged into origin/<branch>" (always true, the post-commit hook
keeps it in sync) instead of "merged into develop". T22a proves it: an
unmerged feature with its upstream in sync is deleted by `-d` alone.

- `gitflow_delete` is the single delete path (finish + CLI `delete`):
  refuses main/develop (rc 6) and any branch that is not an ancestor of
  develop or main (rc 5, `gitflow_merged_into_base`, fail closed when
  neither base exists), then `-d` as a second layer. CLI `merged`, `hooks`.
- Fourth generated hook `reference-transaction`: in the `prepared` call,
  a deletion of refs/heads/main or refs/heads/develop exits 1, whatever
  issued it (branch -d/-D, update-ref -d, rename, script, sub-agent).
  `git config gitflow.protect false` opts a foreign clone out.
- `GITFLOW_HOOKS` is the one hook list: write/emit/reconcile, T19d and
  doctor.sh (`gitflow.sh hooks`) read it. `.githooks/` and `githooks/`
  regenerated with the fourth hook.
- settings.json: static deny on hand `git branch -d/--delete/-dr/-rd` and
  on renames of main/develop; hard_deny "Branch deletion by hand"; the
  Disarming entry covers all four hooks and `gitflow.*` config; the
  protected-branches environment line states the rule.
- Doctrine (CLAUDE.global.md gitflow section), gitflow SKILL (`delete`
  op, rc 5/6 rows, common mistake), guard-bash spec T8w flips to deny,
  SETTINGS.md, README, CHANGELOG.
- Tests: T22 (12) lib guard incl. the premise proof, T23 (11) hook;
  T19 covers the fourth hook. 152/154, the 2 failures are the
  pre-existing T16a (gitleaks absent on this host).
2026-09-24 11:35:01 +02:00
bastien 72d4662289 chore(memory): journal, guardrails merged to develop 2026-09-22 2026-09-22 16:36:26 +02:00
bastien cbb87f65bb Merge feature/destructive-guardrails into develop 2026-09-22 16:36:03 +02:00
bastien 2d25c2fa04 chore(memory): BDR-095 amendment, BLK-021 cause established, journal + TODO G8 2026-09-22 16:34:34 +02:00
bastien f608d34c3e feat(gitflow): hooks in every repo, no per-project step
Global: `make link` generates githooks/ from lib/gitflow.sh and sets git's
global core.hooksPath to ~/.claude/githooks, so every repo on the machine
runs the pre-commit protection and the post-commit / post-merge push, even
one that never ran gitflow init. A repo's own local core.hooksPath still
wins, so hooks/session-start.sh calls `gitflow reconcile-hooks` once per
session and rewrites a .githooks/ that lags the lib (LRN-114 automated);
the pre-commit exemption now covers .githooks/** next to .claude/**.

Per-repo opt-outs for a foreign clone: `git config gitflow.protect false`
(branch model) and `git config gitflow.autopush false` (push). Both, and
the GIT_CONFIG_GLOBAL= / GIT_CONFIG= env bypass, are static deny rules.

`make test` and the two suites that commit on main export
GIT_CONFIG_GLOBAL=/dev/null so the machine's global hooks never fire in
throwaway repos. doctor gains "Git hooks" (global setting, githooks/ equal
to the emitters) and "Scratchpad" (warn when TMPDIR sits on a tmpfs with
usrquota: systemd caps each user at 80% of it, which killed two shells
today, BLK-021). Tests: T18h, T19d, T20 (reconcile), T21 (whitelist and
protect opt-out); this repo's own stale .githooks/ refreshed.
2026-09-22 16:34:27 +02:00
bastien e600394acc chore(memory): BDR-095 LRN-160 BLK-022, journal + TODO 2026-09-22 2026-09-22 07:43:13 +02:00
bastien 9da5d8d52c feat(guardrails): push every commit, static deny for destructive tools, brief carries no user authority
Layer C of the plan written after the 2026-09-21 wipe (BDR-095): a reviewer
sub-agent traced `lftp mirror --delete` against a local file:// tree, the
prose tiers named neither lftp nor a local trace, the brief had authorized
it, and four days of commits had never left the machine.

- gitflow: `start` pushes the branch with its upstream, merge targets are
  pushed after each merge, and `init`/`install-hook` write post-commit and
  post-merge hooks that push every commit as it lands (warn, never block;
  GITFLOW_NO_PUSH=1 for throwaway repos). T18 + T19 (installed == emitted).
- hooks/unpushed-guard.sh on SessionStart and Stop: branch ahead of its
  upstream, no upstream, or no origin. Non-blocking systemMessage.
- settings.json: static deny for transfer and mirror tools, rsync --delete,
  xargs rm, pipe-to-shell, chmod/chown -R, sudo/doas/pkexec, disk tools,
  chattr, docker volume drops/prune/--privileged/socket/-v /:, git history
  destruction, --no-verify and core.hooksPath; new hard_deny "destructive
  tool against a local path, brief carries no user authority"; soft_deny
  reworded + discarding uncommitted work; environment records the incident.
- CLAUDE.global.md "Destructive tools & data loss"; the four report-only
  agents trace by reading, never by running, whatever the brief says.
- lib/tests/guard-bash.test.sh: executable spec of the PreToolUse guard
  (214 cases). The hook itself is not shipped (BLK-022); the spec skips.
2026-09-22 07:43:12 +02:00
bastien 475200bc83 chore(memory): journal + TODO, lots merged to develop 2026-09-22 2026-09-22 06:55:05 +02:00