From 1c69de2f40a0bc70f1eb9e1746931b8d0b2473a0 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sat, 4 Jul 2026 04:46:52 +0200 Subject: [PATCH] feat(skills): wire verify+secure into ship-feature/init-project; onboard no-loop + LRN-093 backstop (verify-loops lot 5) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ship-feature: STEP 0e CONTRACT (request verbatim) → ENRICHED at the STEP 3 validation gate (design criteria appended [gated ], the human micro-gate) → STEP 5 VERIFY+SECURE judges the branch against the ENRICHED contract via the shared include. Distinct axis from STEP 6 code review, both run (LRN-095). init-project: contract seeded from the PROJECT BRIEF (V1 features → criteria) → ENRICHED at VALIDATION GATE #1 → STEP 9 VERIFY+SECURE. Adds the security gate init-project previously lacked (was deferred to a later /onboard). onboard: explicit NO verify-loop — it produces an audit report, not a change to verify against a request; contract is scope-only, security-auditor runs MODE audit (report-only), never a gate. Documented to prevent a misplaced symmetry loop (BDR-050: dev pipeline != audit). lib/tests/no-vacuous-locks.test.sh: deterministic backstop for LRN-093 (2nd recurrence in this chantier → the advisory alone did not hold). Refuses a literal \n in any grep/tf/tr_/tn pattern across lib/tests/*.test.sh; flip-tested against a synthetic offender so the guard proves it bites. lib/tests/loops-heavy.test.sh: 18 structure locks green. Behavioral dogfood (both vigilance points, real): (1) enrichment — a fresh verifier reads and checks a [gated] design criterion (ECARTS naming it precisely); (2) escalation — 3 consecutive ECARTS on the same criterion → orchestrator STOPs at the max-3 bound + presents the CONTRACT-vs-REALIZED table, no 4th loop, no commit. First real exercise of the infinite-loop guard. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS --- lib/tests/loops-heavy.test.sh | 49 ++++++++++++++++++++++++++ lib/tests/no-vacuous-locks.test.sh | 55 ++++++++++++++++++++++++++++++ skills/init-project/SKILL.md | 30 ++++++++++++++-- skills/onboard/SKILL.md | 9 +++++ skills/ship-feature/SKILL.md | 36 +++++++++++++++++-- 5 files changed, 174 insertions(+), 5 deletions(-) create mode 100644 lib/tests/loops-heavy.test.sh create mode 100644 lib/tests/no-vacuous-locks.test.sh diff --git a/lib/tests/loops-heavy.test.sh b/lib/tests/loops-heavy.test.sh new file mode 100644 index 0000000..64a2847 --- /dev/null +++ b/lib/tests/loops-heavy.test.sh @@ -0,0 +1,49 @@ +#!/usr/bin/env bash +# ============================================================ +# Structure locks — heavy-flow wiring (verify-loops lot 5) +# ship-feature + init-project get contract + enrich-at-gate + +# verify-secure-loop; onboard is the explicit NO-LOOP audit case. +# ============================================================ +set -u + +REPO="$(cd "$(dirname "$0")/../.." && pwd)" +SHF="$REPO/skills/ship-feature/SKILL.md" +INI="$REPO/skills/init-project/SKILL.md" +ONB="$REPO/skills/onboard/SKILL.md" +PASS=0; FAIL=0 + +tf() { # tf