Compare commits
15
Commits
v1.3.1
...
709cf9bf0b
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
709cf9bf0b | ||
|
|
550b39043e | ||
|
|
c3d3f4d465 | ||
|
|
0f7b565bb0 | ||
|
|
eab2a10cd5 | ||
|
|
f05ca86ef2 | ||
|
|
817a866b7c | ||
|
|
2940134c86 | ||
|
|
78a25aeb5e | ||
|
|
9b89da29be | ||
|
|
95ddd28992 | ||
|
|
1ef6e6e694 | ||
|
|
6c489ebcfb | ||
|
|
33f9529b9e | ||
|
|
f82ea1e4f8 |
@@ -208,3 +208,10 @@ rules:
|
||||
- **Real cause**: two viable-looking paths, both dead. (API KEY) is per-user not per-site (docs), but IS the account identity → one key per client account, exactly what the user feared; non-scoped, no expiry, passed in query string. (OAuth) is the right delegation model (like GSC) but a swamp: Redirect URI rejects ALL local forms (http/https/127.0.0.1 — user-tested); refresh tokens are ROTATED + single-use, self-described non-compliant with OAuth 2.0 → store rewrite every call, AND our parallel seo‖geo dispatch would race the rotation → `invalid_grant` + dead token; undocumented "Could not extract expected anti-forgery token" on refresh, unanswered on MS Q&A; docs contradict themselves on grant_type + token endpoint; no library. MS's own advisor recommends falling back to the API key.
|
||||
- **Verified live**: the Webmaster API itself is ALIVE (`GetUserSites?apikey=INVALID` → HTTP 400 `{"ErrorCode":3,"Message":"InvalidApiKey"}`, 0.4s) — distinct from Bing SEARCH API (retired 2025-08-11). So the block is auth/model, not availability.
|
||||
- **Status**: open/deferred. REVIVAL: a client already on Bing adds the user as Read-Only → test in ~10 min whether one API key sees DELEGATED sites (undocumented, nobody knows). If yes → W2 is cheap+clean (one key, client-owned verification, revocable, read-only, zero OAuth). Value RAISED by [[BDR-071]]: GetUrlLinks is now the only free viable backlink source (first-party only).
|
||||
|
||||
## BLK-018 — release-executor finish span blocked by permission classifier (human signal invisible to subagent) — 2026-07-20
|
||||
- **Friction**: v1.3.1 release — `SPAN: finish` dispatch denied at tool-permission layer: classifier flagged "Merge Without Review" (`gitflow.sh finish` in subagent transcript carries no explicit human merge signal). Executor correctly refused workaround, reported BLOCKED. v1.2.0/v1.3.0 same span passed → classifier behavior change, not skill regression.
|
||||
- **Real cause**: gitflow doctrine "finish only on explicit human signal" lives in DISPATCHER transcript (user ask + STEP 4 AskUserQuestion go); subagent transcript starts fresh → classifier sees consequential merge with zero authorization evidence. Structural: any human-gated action dispatched to a subagent loses its gate evidence.
|
||||
- **Solution** (workaround): dispatcher ran `gitflow.sh finish` + tag inline after its own human gate — where the signal is real. Release completed clean (main `648bc6e`, tag v1.3.1).
|
||||
- **Status**: open. Candidate fixes: (a) quote gate evidence verbatim in span prompt — untested vs classifier; (b) move finish+tag span permanently inline in /release-candidate — keeps prep span dispatched, costs the sonnet pin on ~5 mechanical commands, cheap; (c) permission rule allowing subagent `gitflow.sh finish` — weakens the guard, refused. Decide at next release.
|
||||
- **Reference**: skill `release-candidate` STEP 5. Pattern adjacent [[LRN-089]] (ambient-state/context assumptions across boundaries). Journal 2026-07-20.
|
||||
|
||||
@@ -91,6 +91,7 @@ rules:
|
||||
| BDR-071 | 2026-07-17 | No viable free backlink source → Off-page axis stays brand-mentions-only (FINAL, not placeholder) | accepted |
|
||||
| BDR-072 | 2026-07-17 | SPA: honest refuse (On-page N/A, not zero), no headless browser (R2 over R1) | accepted |
|
||||
| BDR-073 | 2026-07-17 | Scoring: LLM judges findings+severity, engine does the arithmetic (deterministic /20) | accepted |
|
||||
| BDR-080 | 2026-07-21 | Bug routing inverted: /bugfix primary, /investigate explicit-only | accepted |
|
||||
|
||||
---
|
||||
|
||||
@@ -980,6 +981,7 @@ rules:
|
||||
- **Why**: user call 2026-07-14 — registries already capture decisions; a stale plan describes a superseded intermediate state and misleads future readers; accumulation pollutes the repo. Precedent: gsc-crux cleanup (8a1fac0, 2026-07-10) did the same — this makes it law, not habit.
|
||||
- **Alternatives rejected**: never-commit (gitignore docs/superpowers) — breaks mid-run: briefs, reviewers, other-machine checkouts need the files; superpowers brainstorming commits the spec by convention. Keep-forever — the drift + pollution complained about.
|
||||
- **Reference**: project CLAUDE.md; cleanup commit this chore; precedent 8a1fac0. Linked [[BDR-064]], [[LRN-124]].
|
||||
- **Amendment (2026-07-22)**: DELETE side now AUTOMATED — `lib/gitflow.sh` `_gitflow_purge_transient` at `gitflow finish` (feature/bugfix, pre-merge, on HEAD) git-rm's `docs/superpowers/{specs,plans}` + scoped commit → develop TIP clean, feature commits stay reachable (`git show <sha>:…` archive intact). Best-effort: NEVER aborts finish (nothing-tracked no-op / dirty-path skip / commit-fail index+tree restore). Opt-out `GITFLOW_PURGE_TRANSIENT=0`. Retires the manual chore that slipped (655e364). Universal via `~/.claude/lib`→repo symlink (ship-feature STEP 9 + init-project STEP 11 both finish through it). gitignore STILL rejected — unchanged: breaks superpowers' `git add` of the spec (silently skipped, no travel to SDD worktree). `.claude/tasks/{contracts,plans}` kept versioned (user call — durable, referenced by decisions.md). Tests: gitflow-test.sh T17 a-d. [[LRN-138]].
|
||||
|
||||
---
|
||||
|
||||
@@ -1068,3 +1070,9 @@ Amendment (same session): skills/find-docs = machine-owned dist (gitignored, ctx
|
||||
|
||||
### BDR-079 — profile `set` symmetric on managed externals + MCPs [accepted] (2026-07-20)
|
||||
Audit (user ask "profile toggles externals both ways?"): ASYMMETRIC. Enable side OK — gstack on-demand from submodule when pack off (shared `skills-disabled/gstack__*` convention with toggle-external.sh, interoperable), externals restored from parked, magic delegated to toggle-external. Disable side MISSING: `cmd_set` trimmed only gstack + MANAGED_PLUGINS → `set backend` left emil/frontend-design/design-motion/impeccable active + magic registered; SKILL.md claimed both-ways toggle (true only at enable). Shipped: (1) `MANAGED_EXTERNALS` (emil-design-eng, frontend-design, design-motion-principles, impeccable = exact union of profile `external` usage; darwin-skill excluded — not task-type-driven) + `MANAGED_MCPS` (magic) allowlists, same doctrine as MANAGED_PLUGINS; (2) cmd_set refactored to 4 trim helpers (`disable_{gstack,plugins,externals,mcps}_not_in`) — symmetric, nothing outside allowlists ever auto-touched; (3) enable_skill external += from-source fallback (`ln -sf skills-external/<name>`, mirrors toggle-external) — closes the "missing symlink" warn; (4) stale usage() NOTE ("NOT toggled automatically") + SKILL.md fixed. Hermetic test profile-set-managed.test.sh 16 checks: fixture repo (both *_REPO_OVERRIDE), fake `claude` shim on PATH logging calls + flat-file MCP registry — gstack on-demand, external from-source, park/restore round-trip, magic add/remove calls, non-managed untouched. shellcheck + make test green. Branch feature/profile-managed-externals, unmerged (human gate).
|
||||
|
||||
### BDR-080 — bug routing inverted: /bugfix primary, /investigate explicit-only [accepted] (2026-07-21)
|
||||
Old routing "Bug → investigate (bugfix if gstack off)" + gstack ON by default → every bug took path bypassing own quality pipeline (gitflow aiguillage, contract, fresh verifier + security gates, doc-sync, `.claude/memory` registries) — /bugfix relegated to near-never fallback. Skill comparison: same core doctrine (root-cause iron law, hypothesis loop, regression test, 3-strike stop, >5-files alert) but incompatible wrappers — investigate monolithic (same context investigates+fixes+verifies, ~1075-line SKILL.md w/ gstack preamble/telemetry/onboarding, capitalizes to `~/.gstack` learnings.jsonl framework never reads at session start); bugfix orchestrator (reflection inline, sonnet bugfixer executor, fresh gates — BDR-066, LRN-083). Composition rejected: skills superpose in context, don't compose — invoking investigate inside bugfix = two full workflows, two completion protocols, two memory systems loaded at once. Decision: CLAUDE.global.md routing line inverted — bugfix primary; investigate ONLY on explicit ask for gstack ecosystem (cross-project learnings, /freeze scope lock, long no-commit investigation). Alternatives rejected: keep investigate primary (bypasses framework), embed investigate inside bugfix (context conflict, dual memory). Known drift noted at write time: Index table rows BDR-074..079 missing (pre-existing, /prune-memory scope).
|
||||
|
||||
### BDR-081 — Config recalibrated for Claude 5 family (Opus 5 dispatch tier) [accepted] (2026-07-30)
|
||||
Opus 5 (released 2026-07-24) now backs every `model: opus` pin (BDR-076/077) + any `/model opus` session. Research (official migration guide + web + registries): Opus 5 OVER-delegates (inverts LRN-030 Opus 4.8 trait that CLAUDE.global.md:43-47 compensated), self-verifies (explicit verify instructions → over-verification, "removing them reduces wasted tokens with no loss in quality"), literal following (conservative-reporting clauses depress recall; MUST/CRITICAL over-triggers), scope expansion = named regression, written deliverables +30-40%. Claude Code injects Opus-5-only anti-delegation prompt sections (heron_brook + subagent_steer_delegation, issue #80988, server-gated, no opt-out) — prose caps would triple-stack. Shipped: delegation block → model-neutral WHEN-guidance + explicit gates carve-out (verifier/security/challenge still dispatch as written); "staff engineer" self-check bar dropped; finish-whole-task clause folded into Deviations (gone-WRONG→STOP still wins); deliverable-length rule; design hook `\bux\b` dropped (`\bui\b` KEPT — 0 FP, 1 logged TP, lock-tested); plan-challenger grounded-doubt→[MINOR] in-place reword (grammar byte-identical). Plan challenged by 3 blind Opus 5 plan-challengers: correctness CONCERNS(4) / robustness FATAL(5, BLOCKER: all surfaces symlink-deployed LIVE — gates fire post-deployment) / simplicity CONCERNS(4); every fix adopted as prescribed (scratch-validation before live hook write, minimal diffs, ux-only, MINOR-routing). Alternatives rejected: leave as-is (nudge actively counter-productive); hard spawn caps in prose (harness injects one); confidence axis on challenger grammar (consumer unwired); dropping \bui\b (no evidence). NOT touched: verify-secure-loop + fresh gates (harness architecture BDR-049/050, ≠ model self-check prose); Security/Architecture sections (BDR-021); settings effortLevel xhigh (user pref — Opus 5 carry-over trap → LRN-139); superpowers plugin wording (external upstream). Plan+synthesis: .claude/tasks/plans/2026-07-30-opus5-config-tuning-1238.md. Branch feature/opus5-config-tuning, unmerged (human gate).
|
||||
|
||||
@@ -419,3 +419,14 @@ rules:
|
||||
- v1.2.0 cut + pushed (release-candidate flow: prep/finish via release-executor, tag on main 51b6572). CHANGELOG backfilled at prep: 10 entries added to Unreleased (plan-challenge, seo-data verbs, model-tiering v2, integrity pass, safe_fetch/url-guard) — was ctx7-only. /doc full post-release: README model-routing table v1→v2 reframe + ctx7 two-surface wording, chore/doc-sync-v1.2.0 merged. All pushed on explicit go.
|
||||
- profile↔toggle-external audit (user) → enable side already symmetric (gstack on-demand LIVE), disable side missing → BDR-079: MANAGED_EXTERNALS+MANAGED_MCPS trim at set, external from-source fallback, 16-check hermetic test (claude shim). feature/profile-managed-externals, UNMERGED.
|
||||
- README rebuilt: short pitch (what/how/why) top, old content → reference manual below separator. Dedup title/overview/install block, hardcoded version dropped from footer (staleness risk). chore/readme-v2 merged → develop, pushed.
|
||||
- v1.3.1 cut + pushed (docs-only: README rebuild). prep span via release-executor OK; finish span BLOCKED by permission classifier on subagent (no human signal in its transcript) → ran inline after both gates. [[BLK-018]].
|
||||
|
||||
## 2026-07-21
|
||||
- Skill audit (user ask "pourquoi pas investigate dans bugfix ?") → same core doctrine, incompatible wrappers: investigate = monolithic gstack (own memory ~/.gstack, no gitflow/gates, ~1075-line preamble), bugfix = orchestrator (contract, fresh verifier+security gates, registries). Routing inverted in CLAUDE.global.md: bugfix primary, investigate explicit-only → BDR-080. chore/skill-routing-bugfix, UNMERGED.
|
||||
|
||||
## 2026-07-22
|
||||
- User: auto-gitignore+delete transient pipeline artifacts in all projects. Investigation reframed the ask — gitignore = WRONG tool (files read from disk during run; would break superpowers SDD `git add` of spec). BDR-065 already rejected gitignore + its DELETE side was doctrine-only (no code, manual chore slipped once — 655e364). User picks (2 recommended): keep committed-during-run + AUTOMATE delete; keep `.claude/tasks/{contracts,plans}` versioned.
|
||||
- Built `lib/gitflow.sh` `_gitflow_purge_transient` at finish (feature/bugfix, pre-merge, best-effort never-abort, opt-out `GITFLOW_PURGE_TRANSIENT=0`) + `purge-transient` CLI verb. Universal via `~/.claude/lib`→repo symlink. gitflow-test T17 a-d (10 checks, `--full-history` recovery), shellcheck clean, make test exit 0. BDR-065 amendment + [[LRN-138]]. feature/gitflow-auto-purge-transient.
|
||||
|
||||
## 2026-07-30
|
||||
- User: Opus 5 "needs more freedom" → analyse config + adapt. Research 3-agent (registries / config audit / web) + official migration guide: over-delegation (inverts LRN-030), over-verification, literal following, scope expansion, #80988 injections. Plan challenged 3 blind Opus 5 plan-challengers — robustness FATAL (BLOCKER: symlink-live deployment), all fixes adopted. Shipped: CLAUDE.global.md recalibrated (delegation when-guidance, staff-bar dropped, finish-whole-task, deliverable-length; 308/320), design hook \bux\b dropped flip-tested (22/0), plan-challenger grounded-doubt→[MINOR] (44/0). BDR-081 + LRN-139. feature/opus5-config-tuning, UNMERGED.
|
||||
|
||||
@@ -1349,3 +1349,15 @@ rules:
|
||||
- **fail-safe pin rule**: keep the HIGHEST tier as the frontmatter pin and override DOWN at call sites — a forgotten override then over-tiers (costs money) instead of silently downgrading judgment (costs correctness).
|
||||
- **future application**: before splitting any agent across model tiers, try MODE + `model=` first; create a new agent file only for a genuinely new role. Run-scoped `.audit/<name>-<RUNID>` files + completeness sentinel + fail-closed consumer for any cross-dispatch artifact.
|
||||
- **cousin**: [[LRN-125]] [[LRN-126]] [[BDR-077]].
|
||||
|
||||
## LRN-138 — gitignore ≠ delete for run-time artifacts read from disk (2026-07-22)
|
||||
- **pattern**: gitignore is the WRONG tool for an artifact a pipeline READS FROM DISK during a run — it blocks the commit but leaves the file (cleans nothing) AND breaks git-travel flows (superpowers commits the spec via `git add` so it reaches the SDD worktree; a gitignored path is silently skipped w/o `-f`). Right tool = commit-during-run + AUTO-DELETE at the integration boundary (`gitflow finish`, pre-merge, on the working branch → history keeps the archive, develop tip clean).
|
||||
- **context**: user asked to gitignore transient planning artifacts (`docs/superpowers/{specs,plans}`, `.claude/tasks/{contracts,plans}`) to stop them merging. BDR-065 had already REJECTED gitignore for docs/superpowers on the git-travel ground; the real gap was the DELETE side never being coded (doctrine-only manual chore, slipped once — 655e364). Built `_gitflow_purge_transient`.
|
||||
- **future application**: "don't merge transient X" → ask: does the run read X from disk? does X travel via git (worktree, foreign checkout)? Yes → auto-purge at finish, not gitignore. Scoped commit `-- <paths>` avoids sweeping a dirty index; `git diff --quiet HEAD -- paths` precheck makes `git rm` all-or-nothing safe; keep the purge best-effort so cleanup NEVER blocks a merge. Prove archive-reachability with `git log --full-history` / `git show <sha>:path` — plain `git log -- path` prunes the purged add-commit via history simplification (bit me writing T17).
|
||||
- **link**: [[BDR-065]].
|
||||
|
||||
## LRN-139 — model-trait compensations invert across generations; state WHEN-guidance, not direction (2026-07-30)
|
||||
- **pattern**: config rules that COMPENSATE a model trait become counter-productive when the next generation inverts the trait. LRN-030 (Opus 4.8 under-delegates → "Default to delegation… counters under-delegation") inverted by Opus 5 (delegates MORE readily, official guide) — the rule pushed the failure the model now has. Same class: explicit verify instructions → over-verification; conservative-reporting clauses → literal recall suppression; MUST/CRITICAL → over-triggering.
|
||||
- **Opus 5 traps found**: (a) Claude Code injects Opus-5-only anti-delegation prompt sections (heron_brook + subagent_steer_delegation, issue #80988; server-gated, no opt-out, absent from transcripts) — own prose stacks on top blindly; (b) NO model-default effort hold on Opus 5 — persisted effortLevel (xhigh, settings.json) silently carries over, against "start high, sweep low/medium"; run /effort sweep per model; (c) effort does NOT shorten visible output/deliverables — only prose length rules do (+30-40% docs).
|
||||
- **future application**: at every model-generation bump, grep config for trait-compensating language ("counters model tendency…", "default to X") and re-verify the premise; prefer WHEN-guidance (conditions where X pays) over directional nudges — survives inversions unchanged.
|
||||
- **link**: [[LRN-030]] [[BDR-081]].
|
||||
|
||||
@@ -1,5 +1,51 @@
|
||||
# TODO
|
||||
|
||||
## 2026-07-30 — adapt config for Claude 5 family / Opus 5 (feature/opus5-config-tuning)
|
||||
User: Opus 5 "needs more freedom" → research (official migration guide +
|
||||
web + registres) confirms: over-delegates (inverts LRN-030 Opus 4.8 trait),
|
||||
over-verifies if told to verify, literal instruction following, scope
|
||||
expansion named regression, harness already injects anti-delegation on
|
||||
Opus 5 (#80988). Plan: .claude/tasks/plans/2026-07-30-opus5-config-tuning-1238.md
|
||||
— to be challenged by 3 blind plan-challengers (opus pins → Opus 5), then
|
||||
executed on feature branch. NO merge (human gate).
|
||||
Challenged 2026-07-30: correctness CONCERNS(4) · robustness FATAL(5, 1
|
||||
BLOCKER: symlink-live deployment) · simplicity CONCERNS(4) — all fixes
|
||||
adopted as prescribed (plan §5bis, v2 items below).
|
||||
- [x] W0 branch first (eab2a10 parent); hook regex validated on scratch copy
|
||||
(bash -n + shellcheck + 5 replays, HOME sandboxed) before live write
|
||||
- [x] W1 delegation block v2 (when-guidance + gates carve-out + scoped don't-redo) — 0f7b565
|
||||
- [x] W2 "staff engineer" bar line deleted — 0f7b565
|
||||
- [x] W3 finish-whole-task folded into Deviations (+ gone-WRONG→STOP) — 0f7b565
|
||||
- [x] W4 deliverable-length rule — 0f7b565
|
||||
- [x] W5 line budget: 308/320
|
||||
- [x] W6 hook \bux\b dropped, \bui\b kept + F10 must-fire lock, D11 quiet row
|
||||
flip-tested (fire before/quiet after) — eab2a10, suite 22/0
|
||||
- [x] W7 plan-challenger :82-83 reworded → [MINOR] routing, census row — c3d3f4d, 44/0
|
||||
- [x] W8 BDR-081 + LRN-139 + journal + CHANGELOG
|
||||
- [ ] W9 final gate: make test full suite
|
||||
- [ ] W10 no gitflow finish (human gate) — merge only on explicit user signal
|
||||
|
||||
## 2026-07-22 — auto-purge transient superpowers artifacts at finish (feature/gitflow-auto-purge-transient)
|
||||
User: transient planning artifacts (`docs/superpowers/{specs,plans}`) leak into
|
||||
develop; BDR-065 "post-merge cleanup" is DOCTRINE ONLY (no code) — manual chore,
|
||||
already missed once (655e364). Decision (user 2026-07-22, 2 recommended picks):
|
||||
keep committed-during-run (SDD worktree + reviewers read them), AUTOMATE the
|
||||
delete at `gitflow finish`. NO gitignore (would break superpowers' `git add` of
|
||||
the spec → no travel to SDD worktree). `.claude/tasks/{contracts,plans}` stay
|
||||
versioned (durable, referenced by decisions.md e.g. BDR-076). Universal via the
|
||||
`~/.claude/lib` → repo `lib` symlink: every project's finish gets it.
|
||||
- [x] lib/gitflow.sh: `_gitflow_purge_transient` (clean-precheck → git rm →
|
||||
scoped commit `-- paths`; best-effort, NEVER aborts finish; opt-out
|
||||
`GITFLOW_PURGE_TRANSIENT=0`) wired into finish `feature|bugfix` pre-merge;
|
||||
`purge-transient` CLI verb.
|
||||
- [x] lib/gitflow-test.sh T17 a/b/c/d (purge+recover-from-history via
|
||||
--full-history+`git show`, no-op when absent, opt-out keeps, chore scope).
|
||||
Also fixed 2 pre-existing SC2034 warnings (T16 gl_out/noleaks_out).
|
||||
- [x] Gate: shellcheck lib/*.sh CLEAN + `make test` exit 0 (gitflow 106/0, full
|
||||
suite green). Universal via ~/.claude/lib → repo lib symlink (verified).
|
||||
- [x] CLAUDE.md §Transient planning artifacts: → "AUTO-PURGED by gitflow finish".
|
||||
- [ ] Capitalize: BDR-065 amendment (delete side now automated) + LRN — pending user OK.
|
||||
|
||||
## 2026-07-20 — pending merge gates (reconcile)
|
||||
- [x] merge feature/profile-managed-externals → develop (BDR-079 profile
|
||||
symmetry + /doc clean pass: README/USAGE/ARCHITECTURE.md) — 37c79f0
|
||||
|
||||
@@ -0,0 +1,255 @@
|
||||
# PLAN — Adapt claude-config for the Claude 5 family (Opus 5 focus)
|
||||
|
||||
Date: 2026-07-30 · Branch (planned): feature/opus5-config-tuning (off develop)
|
||||
KIND: build-plan · Author: main-loop session (Fable 5)
|
||||
|
||||
## 1. Context & evidence
|
||||
|
||||
Opus 5 (`claude-opus-5`, released 2026-07-24) now backs every `model: opus`
|
||||
agent pin in this repo (analyzer, plan-challenger, seo/geo-analyzer,
|
||||
plugin-advisor — BDR-076/077) and any session the user switches to via
|
||||
`/model opus`. Its documented behavioral profile differs from Opus 4.8 in
|
||||
ways that make parts of this config counterproductive:
|
||||
|
||||
- E1 **Over-delegation**: Opus 5 "delegates to subagents more readily than
|
||||
prior models" (official prompting guide). Opus 4.8 had the OPPOSITE trait
|
||||
(LRN-030), and `CLAUDE.global.md:43-47` was written to counter it
|
||||
("Counters model tendency to under-delegate"). The premise is inverted.
|
||||
- E2 **Anti-delegation already injected by the harness**: Claude Code
|
||||
v2.1.219 server-gates an Opus-5-only prompt section (`heron_brook` +
|
||||
`subagent_steer_delegation`, GitHub issue #80988) that says "Do not call
|
||||
the AgentTool unless the user requested it" and "Subagents multiply cost
|
||||
and time…". Stacking our own hard cap on top would triple-constrain;
|
||||
keeping a pro-delegation nudge would fight the injection. Model-neutral
|
||||
when-guidance is the stable middle.
|
||||
- E3 **Over-verification**: official guidance — "If your prompt contains
|
||||
explicit verification instructions … remove them: instructions like these
|
||||
cause over-verification on Claude Opus 5, and removing them reduces wasted
|
||||
tokens with no loss in quality." Also true of per-prompt "double-check"
|
||||
phrasing. Targets PROSE told to the model, not harness-level gates.
|
||||
- E4 **Scope expansion**: named Opus 5 regression ("can expand the scope of
|
||||
a task, adding steps that weren't requested"). Anthropic ships a literal
|
||||
counter-block; tested to reduce scope changes "to nearly zero".
|
||||
- E5 **Literal instruction following** (since 4.7, stronger now): aggressive
|
||||
MUST/CRITICAL language over-triggers; conservative-reporting instructions
|
||||
("only report high-severity") measurably depress recall in review/challenge
|
||||
harnesses.
|
||||
- E6 **Longer written deliverables**: files written to disk run ~30-40%
|
||||
longer; `effort` does NOT control visible/deliverable length — only prose
|
||||
instructions do.
|
||||
- E7 **Overconstraint costs reasoning**: Anthropic removed >80% of Claude
|
||||
Code's system prompt for Claude-5-generation models "with no measurable
|
||||
loss"; named mechanism = tokens burned resolving conflicting rules.
|
||||
- E8 **Hook false positive (today)**: `\bux\b` in
|
||||
`hooks/design-toolchain-reminder.sh:47` fired on French prose ("changement
|
||||
ux vu" — matches after apostrophe/slash/space); 2nd `ux` FP in the log,
|
||||
both French. Continues the LRN-1005/1007 false-positive series. No test
|
||||
row covers `\bui\b`/`\bux\b`.
|
||||
- E9 **Effort carry-over trap**: Opus 5 has no model-default effort hold in
|
||||
Claude Code — a persisted `xhigh` (our `settings.json:333`) silently
|
||||
carries onto Opus 5 sessions, against Anthropic's "start at high, sweep
|
||||
low/medium" guidance for that model.
|
||||
|
||||
## 2. Design decisions
|
||||
|
||||
- D1 The global instruction layer must be MODEL-NEUTRAL across the Claude 5
|
||||
family (sessions run Fable 5 by default; dispatched judgment agents run
|
||||
Opus 5; executors Sonnet). Fixes therefore express WHEN-guidance and
|
||||
outcome bars, not directional compensation for one model's trait.
|
||||
- D2 Harness-level quality gates (fresh blind verifier + security-auditor,
|
||||
BDR-049/050; plan-challenge, BDR-075) are architecture, not model
|
||||
self-check prompting. They stay. E3 applies only to prose that tells the
|
||||
MODEL to verify its own work.
|
||||
- D3 Per BDR-021, the Security and Architecture-decisions sections of
|
||||
CLAUDE.global.md stay verbatim (deliberate policy). No softening there.
|
||||
- D4 Registries are append-only: LRN-030 is not edited; a new LRN records
|
||||
the trait inversion and points back to it.
|
||||
- D5 Deterministic backstops (gitflow pre-commit, Gitea protection,
|
||||
permissions.deny, rtk pinning) are explicitly out of "more freedom" scope
|
||||
— community reports show Opus 5 working AROUND soft controls, which argues
|
||||
for keeping hard ones.
|
||||
|
||||
## 3. Work items
|
||||
|
||||
### W1 — CLAUDE.global.md: rewrite the delegation block (:43-47)
|
||||
Replace the 5-line block (incl. "Default to delegation for multi-file
|
||||
exploration. Counters model tendency to under-delegate.") with model-neutral
|
||||
when-guidance, same footprint (≤5 lines):
|
||||
|
||||
```
|
||||
- Sub-agents: one task per sub-agent, main context stays clean.
|
||||
Delegate genuinely independent, sizeable tracks (wide multi-file
|
||||
exploration, parallel audits) — not work doable in a few tool
|
||||
calls, and not self-verification (harness gates own that). Brief
|
||||
precisely, then commit to the delegation — don't redo its work.
|
||||
```
|
||||
Rationale: E1+E2. No hard spawn cap in prose (harness already injects one on
|
||||
Opus 5; Fable benefits from delegation).
|
||||
|
||||
### W2 — CLAUDE.global.md: reframe "After code changes" (:75-83)
|
||||
Keep the concrete quality bar; drop the proof-mandate/self-check phrasing
|
||||
(E3). Replace steps 2-4 with faithful-outcome reporting:
|
||||
|
||||
```
|
||||
## After code changes
|
||||
1. Run tests, lint, build, type-check if available.
|
||||
2. Report outcomes faithfully: what passed, what wasn't run,
|
||||
remaining risks, surviving deviations. Completion claims only
|
||||
for verified work.
|
||||
3. Correction or notable event → capitalize to right registry.
|
||||
```
|
||||
Net: -2 lines. "Would staff engineer approve?" bar and "Don't mark complete
|
||||
without proof" are removed as self-check choreography; honest-reporting
|
||||
line preserves the intent (grounded completion claims) without mandating an
|
||||
extra verification pass.
|
||||
|
||||
### W3 — CLAUDE.global.md: add scope fence (Workflow section)
|
||||
Append (adapted from Anthropic's tested block, caveman-compressed, ~5 lines):
|
||||
|
||||
```
|
||||
- Scope: deliver what was asked, at the scope intended. Routine
|
||||
judgment calls → decide alone; materially different readings →
|
||||
ask. Better approach spotted → say so in one line, still do the
|
||||
task as asked. Finish the whole task; genuinely blocked → do the
|
||||
rest, state plainly what's missing.
|
||||
```
|
||||
Rationale: E4. Complements existing "Scope changes to task — no unrelated
|
||||
edits" (line ~15) without contradicting it.
|
||||
|
||||
### W4 — CLAUDE.global.md: add deliverable-length rule (Code style / Comments area)
|
||||
~2 lines:
|
||||
|
||||
```
|
||||
- Written deliverables (docs, reports, .md): length matched to what
|
||||
the task needs — no filler sections, no boilerplate summaries.
|
||||
```
|
||||
Rationale: E6. Registries already covered by caveman rule.
|
||||
|
||||
### W5 — Line budget
|
||||
After W1-W4: expected ~309 lines. Hard check: `wc -l CLAUDE.global.md` ≤ 320
|
||||
(session-start.sh warning threshold at :202-213).
|
||||
|
||||
### W6 — hooks/design-toolchain-reminder.sh: drop `\bui\b` and `\bux\b`
|
||||
- Remove the two 2-char alternatives from the pattern at :47. Keep
|
||||
`ui/ux|ux/ui|ui kit` and all other tokens.
|
||||
- Add a dated header comment (3rd tightening pass, 2026-07-30, cites the
|
||||
two French-prose `ux` FPs; series LRN-1005/1007).
|
||||
- Trade-off accepted: a bare "améliore l'ux" prompt with no other design
|
||||
token goes quiet — the CLAUDE.global.md "Design work" section still
|
||||
routes it (the hook is a belt, self-described soft nudge).
|
||||
- Update `lib/tests/design-toolchain-reminder.test.sh`: add 2 quiet rows
|
||||
(the real FP prompt excerpt; a bare "l'ui" French sentence) — flip-tested
|
||||
per LRN-096. Existing 9 must-fire rows unaffected (none uses ui/ux).
|
||||
|
||||
### W7 — agents/plan-challenger.md: coverage-first reporting line
|
||||
Add one clause to the findings rules (add-only, no removal): uncertain or
|
||||
low-severity findings are REPORTED with an explicit confidence + severity
|
||||
tag rather than self-censored — severity filtering happens in the
|
||||
orchestrator's synthesis, not in the challenger. Rationale: E5 (literal
|
||||
Opus 5 + "manufactured concern is a failure" wording risks suppressing real
|
||||
low-confidence findings). Must not touch: verdict grammar, MANDATORY PROOF
|
||||
clause, blind-dispatch rules (test-locked in plan-challenger.test.sh).
|
||||
|
||||
### W8 — Memory + docs capitalization (same branch, follows the work)
|
||||
- decisions.md: new BDR (config adapted for Claude 5 family — scope,
|
||||
rationale, alternatives incl. "leave config as-is" and "hard spawn caps"
|
||||
rejected).
|
||||
- learnings.md: new LRN — Opus 5 behavioral profile (over-delegation
|
||||
inverts LRN-030's Opus 4.8 trait; over-verification; literal following;
|
||||
no effort hold on Opus 5 in Claude Code; heron_brook/#80988 injection).
|
||||
- journal.md: one line.
|
||||
- CHANGELOG.md: entry under Unreleased.
|
||||
|
||||
### W9 — Gates (before commit)
|
||||
- `shellcheck hooks/design-toolchain-reminder.sh` clean.
|
||||
- Manual flip-test of the hook: FP prompt → quiet; "redesign the navbar" →
|
||||
fires.
|
||||
- `make test` full suite green (design-toolchain-reminder.test.sh,
|
||||
plan-challenger.test.sh, model-routing.test.sh untouched-but-must-pass,
|
||||
curated-config-guard, loops-light…).
|
||||
- `wc -l CLAUDE.global.md` ≤ 320.
|
||||
|
||||
### W10 — Gitflow
|
||||
`bash ~/.claude/lib/gitflow.sh start feature opus5-config-tuning` off
|
||||
develop; atomic commits (hook+test / CLAUDE.global.md / agent / memory+docs);
|
||||
NO `gitflow finish` — merge only on explicit human signal.
|
||||
|
||||
## 4. Explicitly NOT doing (considered, rejected)
|
||||
|
||||
- N1 Touching lib/verify-secure-loop.md or the fresh-verifier/security
|
||||
gates: harness architecture (BDR-049/050, D2), verifies SONNET executor
|
||||
output — not Opus 5 self-check prose.
|
||||
- N2 Softening the Security / Architecture sections (BDR-021, D3).
|
||||
- N3 Editing the superpowers plugin's "1% chance → MUST invoke" language:
|
||||
external upstream code; flagged as residual over-triggering risk in the
|
||||
new LRN, revisit as its own decision if observed.
|
||||
- N4 Changing `settings.json` `effortLevel: "xhigh"`: user preference,
|
||||
optimal for the Fable 5 session default; the Opus 5 carry-over trap (E9)
|
||||
is documented in the LRN + surfaced to the user for a manual decision.
|
||||
- N5 De-prescribing seo-analyzer.md / geo-analyzer.md (1528/1106 lines,
|
||||
heavy MUST density): separate project, backlog note in TODO.md.
|
||||
- N6 Removing or session-gating the design/ctx7 reminder hooks: soft
|
||||
nudges, cheap, deliberately built; tightened only (W6).
|
||||
- N7 Any model pin change: `model: opus` pins now resolve to Opus 5 —
|
||||
desired outcome, census (model-routing.test.sh) untouched.
|
||||
- N8 Committing settings.json for any reason (LRN-098/1049 /model-churn
|
||||
trap): file is currently clean; keep it out of every commit.
|
||||
|
||||
## 5bis. CHALLENGE SYNTHESIS (2026-07-30) — FINAL amendments (v2)
|
||||
|
||||
Verdicts: correctness CONCERNS(4) · robustness FATAL(5, 1 BLOCKER) ·
|
||||
simplicity CONCERNS(4). Every fix below is the challenger's own named FIX,
|
||||
adopted as written. No re-challenge pass: scope narrowed, no new dependency;
|
||||
W0 is an execution-time safety procedure, not a new config mechanism.
|
||||
|
||||
- **W0 (NEW — robustness BLOCKER)**: all edited surfaces are symlink-deployed
|
||||
LIVE (~/.claude/CLAUDE.md, hooks/, agents/ → this repo); edits take effect
|
||||
machine-wide at save time, before any W9 gate. Mitigations:
|
||||
(a) `gitflow start` BEFORE any live-file edit; never checkout develop
|
||||
mid-work; (b) hook regex change validated on a SCRATCH copy first
|
||||
(bash -n + shellcheck + pattern replay), then written to the live file in
|
||||
ONE atomic Edit; (c) named reverts: `git show develop:<file> > <file>`;
|
||||
escape hatch = remove the hook registration block from settings.json.
|
||||
- **W1 v2** (robustness#3, correctness#2): replacement text carves out the
|
||||
mandated gates explicitly and scopes "don't redo":
|
||||
"Skill-mandated gates (fresh verifier/security/challenge) always dispatch
|
||||
as written. Don't redo delegated work by hand — failed gates re-dispatch
|
||||
fresh executors instead."
|
||||
- **W2 v2** (simplicity#2): minimal diff — delete ONLY the line
|
||||
`Bar: "would staff engineer approve?"`. Steps 1-4 + capitalize step stay.
|
||||
- **W3 v2** (simplicity#1, robustness#4): no new bullet. Fold the only new
|
||||
clause into the existing Deviations bullet: "Finish the whole task:
|
||||
blocked on an independent sub-part → do the rest, state what's missing.
|
||||
Gone WRONG → still STOP, re-plan." (net +2 lines, no conflict with :53).
|
||||
- **W4**: unchanged (+2 lines). Budget v2: 304 +1 −1 +2 +2 = 308 ≤ 320.
|
||||
- **W6 v2** (all lenses): drop `\bux\b` ONLY — keep `\bui\b` (zero evidenced
|
||||
FP; one logged true positive). Accepted trade-off: the 2026-07-21 "ameliore
|
||||
le tutoriel…gamifier" ux row (plausible TP) goes quiet; CLAUDE.global.md
|
||||
design-routing section remains the router. Header comment notes the log
|
||||
records `head -1` only → per-token FP rate not fully derivable. Tests:
|
||||
quiet row = synthetic "changement ux vu…" (verified matches pre-change →
|
||||
flips); must-fire row = "revois l'ui du panneau admin" (locks `\bui\b`;
|
||||
apostrophe escaped correctly, doubles as JSON-path control per
|
||||
robustness#7). No log-excerpt rows (vacuous — 100-char truncation).
|
||||
- **W7 v2** (all lenses): in-place reword of the `:82-83` sentence (NOT
|
||||
test-locked; plan v1 misstated that) instead of an add-only clause:
|
||||
"No invention — ungrounded is noise. Silently dropping a grounded doubt is
|
||||
equally a failure: file it as `[MINOR]` with the uncertainty stated in
|
||||
`WHY:`. Nothing real at all → `SOLID` with `FINDINGS: none`."
|
||||
OUTPUT grammar byte-identical; no confidence axis; no consumer change.
|
||||
Census: add `has "$A" "grounded doubt"` row to plan-challenger.test.sh in
|
||||
the same commit.
|
||||
- **W9 v2**: adds the W0 scratch-validation step; rest unchanged.
|
||||
- **W10 v2**: branch creation moves FIRST in execution order.
|
||||
|
||||
## 5. Constraints for challengers
|
||||
|
||||
- Registries append-only; curation only via /prune-memory.
|
||||
- Census tests lock behavior: any hook/agent edit must land with its test
|
||||
update in the same commit; `make test` must stay green.
|
||||
- CLAUDE.global.md ≤ 320 lines (runtime warning threshold).
|
||||
- BDR-021: Security + Architecture sections verbatim.
|
||||
- Gitflow: feature branch off develop, no merge without human signal.
|
||||
- The global file serves ALL models (Fable sessions, Opus 5 dispatches,
|
||||
Sonnet executors read skill/agent prompts instead) — no Opus-5-only
|
||||
wording in CLAUDE.global.md.
|
||||
@@ -6,6 +6,47 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
### Changed
|
||||
- **Global instruction layer recalibrated for the Claude 5 family (BDR-081)** —
|
||||
delegation block is now model-neutral when-guidance (the Opus 4.8
|
||||
under-delegation counter inverted on Opus 5, which over-delegates and gets
|
||||
an injected harness cap); "staff engineer" self-check bar dropped (Opus 5
|
||||
over-verification trigger); finish-whole-task clause added to Deviations;
|
||||
written-deliverable length rule added. 308/320 lines.
|
||||
- **design-toolchain hook** — dropped `\bux\b` (2 French-prose false
|
||||
positives; 3rd tightening pass, series LRN-1005/1007); `\bui\b` kept and
|
||||
locked by a must-fire test row.
|
||||
- **plan-challenger** — grounded-but-uncertain findings now file as `[MINOR]`
|
||||
with the uncertainty stated, instead of being self-censored (Opus 5 follows
|
||||
conservative-reporting clauses literally).
|
||||
|
||||
## [1.4.0] — 2026-07-22
|
||||
|
||||
### Added
|
||||
- **Transient planning artifacts auto-purged at feature-finish (BDR-065)** —
|
||||
`gitflow finish` on a `feature`/`bugfix` branch now removes the run-time
|
||||
superpowers artifacts (`docs/superpowers/{specs,plans}`) on the working
|
||||
branch just before the directed merge, so `develop`'s tip lands clean while
|
||||
the feature commits stay reachable as the archive (`git show <sha>:…`). This
|
||||
automates the manual post-merge cleanup that BDR-065 had left as doctrine —
|
||||
the step that slipped in 1.3.0 and needed a hand purge. Best-effort by
|
||||
contract: a purge that finds nothing, meets uncommitted changes under those
|
||||
paths, or fails to commit never aborts the finish (index/tree restored); opt
|
||||
out with `GITFLOW_PURGE_TRANSIENT=0`. New `gitflow.sh purge-transient` verb.
|
||||
`.claude/tasks/{contracts,plans}` are deliberately out of scope (durable,
|
||||
versioned, referenced by the decision registry). Live in every project via
|
||||
the `~/.claude/lib` symlink; covered by `lib/gitflow-test.sh` T17 (a–d).
|
||||
|
||||
### Changed
|
||||
- **Bug routing inverted: `/bugfix` primary, `/investigate` explicit-only
|
||||
(BDR-080)** — a bug / error / 500 now routes to `/bugfix` by default (the
|
||||
full framework: gitflow, contract, fresh verifier + security gates,
|
||||
registries). The gstack `/investigate` monolith — its own `~/.gstack`
|
||||
memory, no gitflow or gates — is reserved for explicit requests
|
||||
(cross-project learnings, `/freeze` scope lock, long investigation with no
|
||||
immediate commit intent). Same core debugging doctrine, incompatible
|
||||
wrappers; the default now favours the gated, integrated path.
|
||||
|
||||
## [1.3.1] — 2026-07-20
|
||||
|
||||
### Changed
|
||||
|
||||
+14
-7
@@ -22,6 +22,8 @@ Apply unless repo-specific instructions override.
|
||||
- Document intent, not mechanics. Use project doc style (docstring, JSDoc…).
|
||||
- Explicit, consistent, meaningful names. Straight control flow,
|
||||
no hidden side effects.
|
||||
- Written deliverables (docs, reports, .md): length matched to what
|
||||
the task needs — no filler sections, no boilerplate summaries.
|
||||
|
||||
## Refactoring
|
||||
- Priority: safety → readability → consistency.
|
||||
@@ -40,11 +42,12 @@ Apply unless repo-specific instructions override.
|
||||
- Confirm before implementing only when real trade-offs exist (multiple
|
||||
valid approaches, breaking change, destructive action) — else proceed.
|
||||
- Minimal changes unless broader refactor requested. State trade-offs.
|
||||
- Sub-agents keep main context clean — one task per sub-agent.
|
||||
More compute on hard problems. Task fans out across independent
|
||||
items (many files, parallel searches, multi-point checks) → delegate
|
||||
to sub-agents, don't iterate serially. Default to delegation for
|
||||
multi-file exploration. Counters model tendency to under-delegate.
|
||||
- Sub-agents: one task per sub-agent, main context stays clean.
|
||||
Delegate genuinely independent, sizeable tracks (wide multi-file
|
||||
exploration, parallel audits) — not work doable in a few tool
|
||||
calls. Skill-mandated gates (fresh verifier/security/challenge)
|
||||
always dispatch as written. Don't redo delegated work by hand —
|
||||
failed gates re-dispatch fresh executors instead.
|
||||
- One question upfront if needed — don't interrupt mid-task.
|
||||
*Exception: skill-mandated gates and checkpoints (orchestrator
|
||||
validation gates, approval gates, darwin checkpoints) always fire.*
|
||||
@@ -53,6 +56,8 @@ Apply unless repo-specific instructions override.
|
||||
- Something goes wrong → STOP, re-plan. Never push through.
|
||||
- Deviations: minor or clearly justified → do, explain after.
|
||||
Significant or shaky justification → ask before deviating.
|
||||
Finish the whole task: blocked on an independent sub-part → do
|
||||
the rest, state what's missing. Gone WRONG → still STOP, re-plan.
|
||||
- Root causes only. No temp fixes. Never assume — verify paths, APIs,
|
||||
variables before use.
|
||||
|
||||
@@ -77,7 +82,6 @@ Apply unless repo-specific instructions override.
|
||||
2. Report what verified, what not.
|
||||
3. List remaining risks, surviving deviations.
|
||||
4. Don't mark complete without proof it works.
|
||||
Bar: "would staff engineer approve?"
|
||||
5. Correction or notable event → capitalize to right registry
|
||||
(see "Memory registries").
|
||||
|
||||
@@ -252,7 +256,10 @@ description fits (full list is in context). Rules below cover only the
|
||||
non-obvious cases: gstack fallbacks, disambiguation, cryptic names.
|
||||
|
||||
- Product idea, "worth building?" → office-hours
|
||||
- Bug / error / 500 → investigate (bugfix if gstack off)
|
||||
- Bug / error / 500 → bugfix (full framework: gitflow, contract, fresh
|
||||
verifier/security gates, registries). investigate ONLY on explicit ask
|
||||
for the gstack ecosystem (cross-project learnings, /freeze scope lock,
|
||||
long investigation with no immediate commit intent)
|
||||
- feat / hotfix / bugfix distinguished by file count → see descriptions
|
||||
- Ship / deploy / PR → ship (ship-feature if gstack off)
|
||||
- Cut a release / tag a version (develop ahead of main) → release-candidate
|
||||
|
||||
@@ -32,8 +32,13 @@ or re-run `make plugin`.
|
||||
|
||||
`docs/superpowers/specs/**` and `docs/superpowers/plans/**` are run-time
|
||||
artifacts of a feature pipeline (subagent briefs, reviewer references).
|
||||
They are committed DURING the run and DELETED in the post-merge cleanup
|
||||
(BDR-065) — git history at the feature commits is their archive. Durable
|
||||
knowledge goes to `.claude/memory/` registries, never to these files.
|
||||
Derived scan/audit outputs (`.audit/**`) are gitignored and never
|
||||
committed, even redacted (LRN-124).
|
||||
They are committed DURING the run (the SDD worktree + reviewers read them
|
||||
from disk — NOT gitignored), then AUTO-PURGED by `gitflow finish` on a
|
||||
`feature`/`bugfix` branch, before the merge, so develop's tip stays clean
|
||||
(BDR-065, `lib/gitflow.sh` `_gitflow_purge_transient`). The feature commits
|
||||
stay reachable from develop, so `git show <sha>:docs/…` is still the archive.
|
||||
Opt out with `GITFLOW_PURGE_TRANSIENT=0`. NOT in scope: `.claude/tasks/{contracts,plans}`
|
||||
(durable, versioned, referenced by decisions.md). Durable knowledge goes to
|
||||
`.claude/memory/` registries, never to these files. Derived scan/audit
|
||||
outputs (`.audit/**`) are gitignored and never committed, even redacted
|
||||
(LRN-124).
|
||||
|
||||
@@ -79,8 +79,9 @@ PROOF: read <n> files, inspected <what>, checked plan §<…>
|
||||
|
||||
- Report-only. Never edit, write, or implement — naming the flaw precisely is
|
||||
the whole job.
|
||||
- No invention. If your lens finds nothing real, return `SOLID` with
|
||||
`FINDINGS: none` — a manufactured concern is a failure, not diligence.
|
||||
- No invention — ungrounded is noise. Silently dropping a grounded doubt is
|
||||
equally a failure: file it as `[MINOR]` with the uncertainty stated in
|
||||
`WHY:`. Nothing real at all → `SOLID` with `FINDINGS: none`.
|
||||
- `PROOF` is MANDATORY. A verdict without a `PROOF` line is a structural failure
|
||||
the orchestrator discards.
|
||||
- Stay in your lens. A finding outside it belongs to another challenger.
|
||||
|
||||
@@ -44,7 +44,11 @@ lc="$(printf '%s' "$prompt" | tr '[:upper:]' '[:lower:]')"
|
||||
# "design system", "redesign", "front-?end design". dashboard -> \bdashboard\b
|
||||
# so a filename like ecc_dashboard.py no longer matches while "admin dashboard"
|
||||
# still does. animation kept (rarely non-UI).
|
||||
pattern='redesign|refonte|refont|ui/ux|ux/ui|\bui\b|\bux\b|ui kit|design system|design-system|front-?end design|\bnavbar\b|\bsidebar\b|\bmodal\b|\bbouton\b|\bbutton\b|formulaire|\bhero\b|\bheader\b|\bfooter\b|dropdown|tooltip|\bbadge\b|\bchart\b|graphique|accordion|carousel|\bslider\b|landing|\bdashboard\b|homepage|home page|\baccueil\b|\bécran\b|\becran\b|portfolio|maquette|mockup|wireframe|prototype|\bjoli\b|\bjolie\b|\bbeau\b|\bbelle\b|esth[eé]tique|aesthetic|\bvisuel\b|\bvisual\b|embellir|fignol|peaufin|polish|styliser|styling|stylesheet|\bskin\b|charte graphique|\bbrand\b|branding|\blogo\b|favicon|ic[oô]ne|\bicon\b|\bcss\b|tailwind|shadcn|couleur|gradient|d[eé]grad[eé]|\bombre\b|spacing|espacement|\bmarge\b|\bpadding\b|\bmargin\b|\bradius\b|arrondi|\bhover\b|dark mode|light mode|typograph|\bfont\b|\bfonts\b|font pairing|\bpolice\b|animation|\bmotion\b|micro-interaction|keyframe|glassmorph|neumorph|claymorph|skeuomorph|brutalis|bento|minimalis|responsive|figma'
|
||||
# Tightened 2026-07-30 (3rd pass): dropped \bux\b — bare "ux" matched inside
|
||||
# French prose ("changement ux vu…"; 2 logged FPs, both FR). \bui\b KEPT
|
||||
# (zero logged FP, one logged true positive). NB: the log records only the
|
||||
# FIRST match per fire (head -1), so per-token FP rates aren't derivable.
|
||||
pattern='redesign|refonte|refont|ui/ux|ux/ui|\bui\b|ui kit|design system|design-system|front-?end design|\bnavbar\b|\bsidebar\b|\bmodal\b|\bbouton\b|\bbutton\b|formulaire|\bhero\b|\bheader\b|\bfooter\b|dropdown|tooltip|\bbadge\b|\bchart\b|graphique|accordion|carousel|\bslider\b|landing|\bdashboard\b|homepage|home page|\baccueil\b|\bécran\b|\becran\b|portfolio|maquette|mockup|wireframe|prototype|\bjoli\b|\bjolie\b|\bbeau\b|\bbelle\b|esth[eé]tique|aesthetic|\bvisuel\b|\bvisual\b|embellir|fignol|peaufin|polish|styliser|styling|stylesheet|\bskin\b|charte graphique|\bbrand\b|branding|\blogo\b|favicon|ic[oô]ne|\bicon\b|\bcss\b|tailwind|shadcn|couleur|gradient|d[eé]grad[eé]|\bombre\b|spacing|espacement|\bmarge\b|\bpadding\b|\bmargin\b|\bradius\b|arrondi|\bhover\b|dark mode|light mode|typograph|\bfont\b|\bfonts\b|font pairing|\bpolice\b|animation|\bmotion\b|micro-interaction|keyframe|glassmorph|neumorph|claymorph|skeuomorph|brutalis|bento|minimalis|responsive|figma'
|
||||
|
||||
if printf '%s' "$lc" | grep -Eq "$pattern"; then
|
||||
# Counter: log the fire (time, matched token, excerpt) — best-effort, never blocks.
|
||||
|
||||
@@ -239,6 +239,7 @@ gitflow_start feature glwork >/dev/null 2>&1
|
||||
# proving this backstop is NOT gated by the branch-protection check above it)
|
||||
printf 'aws_access_key_id = AKIA%s\n' "GDR5XRBXYARW2I5N" > secret.txt
|
||||
git add secret.txt
|
||||
# shellcheck disable=SC2034 # gl_out is used in the deferred chk eval strings
|
||||
gl_out="$(git commit -q -m "add secret" 2>&1)"; gl_rc=$?
|
||||
chk "T16a fake secret on feature branch → blocked" "[ $gl_rc -ne 0 ]"
|
||||
chk "T16a message mentions gitleaks" 'printf "%s" "$gl_out" | grep -qi gitleaks'
|
||||
@@ -252,10 +253,57 @@ chk "T16b clean commit still succeeds" 'git commit -q -m "clean work" 2>/dev/nul
|
||||
# T16c — gitleaks missing from PATH → warn, never block (defense in depth
|
||||
# must not become a new single point of failure)
|
||||
echo clean2 > clean2.txt; git add clean2.txt
|
||||
# shellcheck disable=SC2034 # noleaks_out is used in the deferred chk eval strings
|
||||
noleaks_out="$(PATH=/usr/bin:/bin git commit -q -m "clean work 2" 2>&1)"; noleaks_rc=$?
|
||||
chk "T16c missing-gitleaks → still commits (rc0)" "[ $noleaks_rc -eq 0 ]"
|
||||
chk "T16c missing-gitleaks → warns" 'printf "%s" "$noleaks_out" | grep -qi "not installed"'
|
||||
|
||||
echo "T17 — finish auto-purges transient superpowers artifacts (BDR-065)"
|
||||
# T17a — feature carrying docs/superpowers spec+plan: purged before merge,
|
||||
# develop TIP clean, artifacts still recoverable from history (archive property)
|
||||
newrepo purgefeat; echo a>a; hookon; gitflow_init >/dev/null 2>&1
|
||||
gitflow_start feature pf >/dev/null 2>&1
|
||||
mkdir -p docs/superpowers/specs docs/superpowers/plans
|
||||
echo spec > docs/superpowers/specs/s.md
|
||||
echo plan > docs/superpowers/plans/p.md
|
||||
echo code > feat.txt
|
||||
git add -A; git commit -q -m "feat + transient spec/plan"
|
||||
gitflow_finish >/dev/null 2>&1
|
||||
# the add-commit stays reachable from develop via the --no-ff merge's 2nd parent;
|
||||
# --full-history defeats the path simplification that hides it, and `git show
|
||||
# <sha>:path` proves BDR-065's "git history = the archive" recovery.
|
||||
# shellcheck disable=SC2034 # pf_add_sha is used in the deferred chk eval string
|
||||
pf_add_sha="$(git log develop --full-history --format=%H -- docs/superpowers/specs/s.md | tail -1)"
|
||||
chk "T17a merged into develop" 'git log develop --oneline | grep -q "Merge feature/pf into develop"'
|
||||
chk "T17a develop TIP has no transient" '[ -z "$(git ls-tree -r develop --name-only -- docs/superpowers)" ]'
|
||||
chk "T17a purge commit on record" 'git log develop --oneline | grep -q "purge transient planning artifacts"'
|
||||
chk "T17a artifact recoverable from history" '[ "$(git show "$pf_add_sha":docs/superpowers/specs/s.md 2>/dev/null)" = spec ]'
|
||||
chk "T17a non-transient code survives" 'git ls-tree -r develop --name-only | grep -qx feat.txt'
|
||||
chk "T17a feature branch deleted" '! git rev-parse --verify -q refs/heads/feature/pf >/dev/null'
|
||||
|
||||
# T17b — no artifacts → purge is a silent no-op, no spurious commit
|
||||
newrepo purgenone; echo a>a; hookon; gitflow_init >/dev/null 2>&1
|
||||
gitflow_start feature pn >/dev/null 2>&1; echo w>w.txt; git add w.txt; git commit -q -m w
|
||||
gitflow_finish >/dev/null 2>&1
|
||||
chk "T17b merged into develop" 'git log develop --oneline | grep -q "Merge feature/pn into develop"'
|
||||
chk "T17b no purge commit created" '! git log develop --oneline | grep -q "purge transient"'
|
||||
|
||||
# T17c — opt-out (GITFLOW_PURGE_TRANSIENT=0) keeps the artifacts on develop
|
||||
newrepo purgeoff; echo a>a; hookon; gitflow_init >/dev/null 2>&1
|
||||
gitflow_start feature po >/dev/null 2>&1
|
||||
mkdir -p docs/superpowers/specs; echo spec > docs/superpowers/specs/s.md
|
||||
git add -A; git commit -q -m "feat + spec"
|
||||
GITFLOW_PURGE_TRANSIENT=0 gitflow_finish >/dev/null 2>&1
|
||||
chk "T17c opt-out keeps transient on develop TIP" '[ -n "$(git ls-tree -r develop --name-only -- docs/superpowers)" ]'
|
||||
|
||||
# T17d — chore is OUT of purge scope (only feature/bugfix originate artifacts)
|
||||
newrepo purgechore; echo a>a; hookon; gitflow_init >/dev/null 2>&1
|
||||
gitflow_start chore pc >/dev/null 2>&1
|
||||
mkdir -p docs/superpowers/specs; echo spec > docs/superpowers/specs/s.md
|
||||
git add -A; git commit -q -m "chore + spec"
|
||||
gitflow_finish >/dev/null 2>&1
|
||||
chk "T17d chore leaves transient (not in scope)" '[ -n "$(git ls-tree -r develop --name-only -- docs/superpowers)" ]'
|
||||
|
||||
echo
|
||||
echo "==== RESULT: $PASS passed, $FAIL failed ===="
|
||||
[ "$FAIL" -eq 0 ]
|
||||
|
||||
+48
-2
@@ -18,6 +18,12 @@ GITFLOW_MAIN="main"
|
||||
GITFLOW_DEVELOP="develop"
|
||||
# template resolved relative to the lib; overridable for tests.
|
||||
GITFLOW_GITIGNORE_TEMPLATE="${GITFLOW_GITIGNORE_TEMPLATE:-$_GITFLOW_LIB_DIR/../templates/gitignore/standard.gitignore}"
|
||||
# Transient planning artifacts (superpowers spec/plan). A feature/bugfix run
|
||||
# COMMITS them (SDD worktree + reviewers read them from disk); finish PURGES
|
||||
# them before the merge reaches develop's tip (BDR-065). Fixed path list;
|
||||
# read GITFLOW_PURGE_TRANSIENT=0 at finish time to opt out (read in the helper,
|
||||
# never cached here, so an inline `VAR=0 gitflow_finish` override works).
|
||||
GITFLOW_TRANSIENT_PATHS=("docs/superpowers/specs" "docs/superpowers/plans")
|
||||
|
||||
# ── predicates / pure helpers ────────────────────────────────────────────────
|
||||
|
||||
@@ -97,6 +103,42 @@ _gitflow_delete() { # <branch>
|
||||
git branch -q -d "$br" || { echo "gitflow: '$br' not fully merged — branch kept" >&2; return 5; }
|
||||
}
|
||||
|
||||
# _gitflow_purge_transient → remove the committed transient planning artifacts
|
||||
# (BDR-065) from the CURRENT branch just before the directed merge. Result: the
|
||||
# removal rides the feature/bugfix branch, whose earlier commits stay reachable
|
||||
# from develop through the --no-ff merge (`git show <sha>:…` = the archive),
|
||||
# while develop's TIP lands clean. Automates the manual post-merge chore that
|
||||
# BDR-065 left as doctrine (and that slipped once — commit 655e364).
|
||||
#
|
||||
# BEST-EFFORT BY CONTRACT: this NEVER aborts a finish. Nothing tracked → no-op;
|
||||
# uncommitted changes under those paths, or a failed commit → warn + degrade to
|
||||
# the old manual-cleanup behaviour, index/tree restored, merge still proceeds.
|
||||
# The scoped commit (`-- <paths>`) records only the deletions, so a dirty index
|
||||
# is never swept in. Opt out with GITFLOW_PURGE_TRANSIENT=0.
|
||||
_gitflow_purge_transient() {
|
||||
[ "${GITFLOW_PURGE_TRANSIENT:-1}" = 1 ] || return 0
|
||||
local p; local -a tracked=()
|
||||
for p in "${GITFLOW_TRANSIENT_PATHS[@]}"; do
|
||||
[ -n "$(git ls-files -- "$p")" ] && tracked+=("$p")
|
||||
done
|
||||
[ "${#tracked[@]}" -gt 0 ] || return 0 # nothing tracked → no-op
|
||||
# only purge paths with no pending changes → git rm is all-or-nothing safe and
|
||||
# never discards uncommitted work under docs/superpowers.
|
||||
if ! git diff --quiet HEAD -- "${tracked[@]}" 2>/dev/null; then
|
||||
echo "gitflow: transient artifacts have uncommitted changes — purge skipped, finishing without it (clean up by hand)" >&2
|
||||
return 0
|
||||
fi
|
||||
if git rm -r -q -- "${tracked[@]}" >/dev/null 2>&1 \
|
||||
&& git commit -q -m "chore: purge transient planning artifacts (BDR-065)" -- "${tracked[@]}"; then
|
||||
echo "gitflow: purged transient planning artifacts before merge (${tracked[*]})" >&2
|
||||
else
|
||||
echo "gitflow: transient-artifact purge failed — finishing without it (clean up by hand)" >&2
|
||||
git reset -q HEAD -- "${tracked[@]}" 2>/dev/null || true # unstage any partial rm
|
||||
git checkout -q -- "${tracked[@]}" 2>/dev/null || true # restore working tree
|
||||
fi
|
||||
return 0
|
||||
}
|
||||
|
||||
# gitflow_finish [<type> <name>] → directed merge of the CURRENT branch per its
|
||||
# type, then delete. WHEN to call this is the human gate (SKILL.md).
|
||||
#
|
||||
@@ -117,7 +159,10 @@ gitflow_finish() {
|
||||
fi
|
||||
type="$(gitflow_branch_type "$br")"
|
||||
case "$type" in
|
||||
feature|bugfix|chore)
|
||||
feature|bugfix)
|
||||
_gitflow_purge_transient # BDR-065 auto-cleanup, on HEAD, pre-merge; never blocks
|
||||
_gitflow_merge_into "$GITFLOW_DEVELOP" "$br" && _gitflow_delete "$br" ;;
|
||||
chore)
|
||||
_gitflow_merge_into "$GITFLOW_DEVELOP" "$br" && _gitflow_delete "$br" ;;
|
||||
release)
|
||||
_gitflow_merge_into "$GITFLOW_MAIN" "$br" \
|
||||
@@ -283,8 +328,9 @@ if [ "${BASH_SOURCE[0]}" = "${0}" ]; then
|
||||
finish) gitflow_finish "$@" ;;
|
||||
init) gitflow_init "$@" ;;
|
||||
reconcile) gitflow_reconcile_gitignore "$@" ;;
|
||||
purge-transient) _gitflow_purge_transient ;;
|
||||
install-hook) gitflow_install_hook "$@" ;;
|
||||
emit-hook) _gitflow_emit_pre_commit ;;
|
||||
*) echo "usage: gitflow.sh {type|protected-base|base-for|release-open|start|finish|init|reconcile|install-hook|emit-hook}" >&2; exit 2 ;;
|
||||
*) echo "usage: gitflow.sh {type|protected-base|base-for|release-open|start|finish|init|reconcile|purge-transient|install-hook|emit-hook}" >&2; exit 2 ;;
|
||||
esac
|
||||
fi
|
||||
|
||||
@@ -22,6 +22,7 @@ check D8-dash-file "$(fire 'ecc_dashboard.py')" quiet
|
||||
# --- Harness-generated inputs must be QUIET even with UI tokens ---
|
||||
check D9-tasknotif "$(fire '<task-notification> <task-id>x</task-id> add css header fonts')" quiet
|
||||
check D10-notif-file "$(fire '<task-notification> design-motion-principles keyframe done')" quiet
|
||||
check D11-bare-ux "$(fire 'changement ux vu de tes trouvailles')" quiet
|
||||
|
||||
# --- Real UI signals must still FIRE ---
|
||||
check F1-button "$(fire 'add a button')" fire
|
||||
@@ -33,6 +34,7 @@ check F6-frontdesign "$(fire 'frontend design work')" fire
|
||||
check F7-admin-dash "$(fire 'admin dashboard screen')" fire
|
||||
check F8-animation "$(fire 'add an animation')" fire
|
||||
check F9-designsys "$(fire 'our design system')" fire
|
||||
check F10-bare-ui "$(fire 'revois l'\''ui du panneau admin')" fire
|
||||
|
||||
# --- Fire is logged (time + token + excerpt) ---
|
||||
tmp="$(mktemp -d)"
|
||||
|
||||
@@ -24,6 +24,7 @@ has "$A" "correctness"
|
||||
has "$A" "robustness"
|
||||
has "$A" "simplicity"
|
||||
has "$A" "Report-only"
|
||||
has "$A" "grounded doubt" # uncertain findings → [MINOR], not self-censored (Opus 5 literalism)
|
||||
|
||||
# 2) reusable phase — the mechanism lives here (one canonical include)
|
||||
has "$L" 'subagent_type="plan-challenger"'
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
1.3.1
|
||||
1.4.0
|
||||
|
||||
Reference in New Issue
Block a user