feat(guardrails): refusal ends the attempt; doctrine-citers census; make test suite=

Root causes of the 2026-09-24 errors turned into mechanisms (BDR-100). hard_deny 'Routing around a guardrail': a refused command is never rerun through a wrapper, alias, heredoc, Makefile target, env file, other shell or other agent; the same clause in 14 agents and in the doctrine's sub-agent rule. make test suite=<file> runs one suite hermetically so the denied env-prefix form is never needed by hand. lib/tests/doctrine-citers.test.sh: every CLAUDE.md "Section" / § Label citation across skills, agents, lib, rules and hooks must resolve to a heading or bold label (flip-tested); its first run fixed rest-api-node.md. Doctrine 'After code changes' step 4: a changed rule, heading, label or threshold → grep every citer in the same commit.
This commit is contained in:
bastien
2026-09-24 20:58:25 +02:00
parent 8f10047ac4
commit 27f201d4aa
20 changed files with 129 additions and 6 deletions
+2
View File
@@ -37,6 +37,8 @@ Produce a clear analysis without proposing solutions.
## RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- No design
- No solutions
- Stay factual
+2
View File
@@ -25,6 +25,8 @@ Every choice was made in the plan or is a NEED-DECISION to report.
## EXECUTION RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- Apply the FIX PLAN to the letter — fix the ROOT CAUSE named in DIAGNOSIS,
not the symptom. A plan hole or an open choice (naming, data shape, API
surface, dependency, a user-visible choice such as placement, wording or
+2
View File
@@ -55,6 +55,8 @@ project test suite + linter/formatter if available.
## RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- Zero behavior change. Unsure a deletion is safe → leave it, record under NOTES.
- No "while we're here" scope creep — only the APPROVED items.
- FORBIDDEN: `git commit`, branch ops, push, merge, new dependencies, user
+4
View File
@@ -250,3 +250,7 @@ COMMITS : <hash> <subject> (one line per Phase-3 commit, chronological)
MEMORY : <memory-commit hash> | none
NOTES : <DONE: none | BLOCKED: the blocker verbatim>
```
## Guardrails
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
+2
View File
@@ -861,6 +861,8 @@ ever lists `.claude/**` or `CLAUDE.md` (never targets, BDR-022).
---
## RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- **`.claude/` and `CLAUDE.md` are READ-ONLY context.** Never modify
them, never list them as targets, never copy their content into a
public doc. They inform the writing only.
+2
View File
@@ -36,6 +36,8 @@ report below is optional on this path (the dispatcher needs the edit applied
## EXECUTION RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- Follow the plan to the letter. A plan hole or an open choice (naming,
data shape, API surface, dependency, a user-visible choice such as
placement, wording or behavior) → STOP, report `NEED-DECISION` with the
+2
View File
@@ -36,6 +36,8 @@ the edit applied + self-verified, not the report grammar).
## EXECUTION RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- Apply the minimal change that fixes the bug. Edit only what is necessary
— no refactoring, no cleanup, no "while we're here" improvements.
- Stay inside the scope you were given. On the /hotfix path that is the
+2
View File
@@ -162,6 +162,8 @@ PLACEHOLDERS : <null enrichment keys left as TODO(/onboard STEP 3), or none>
---
## RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- NO interview (handled upstream).
- NO audit (handled downstream by orchestrator).
- NO destructive writes: never overwrite CLAUDE.md if it exists without asking (print path + STOP, let orchestrator decide).
+2
View File
@@ -81,6 +81,8 @@ PROOF: read <n> files, inspected <what>, checked plan §<…>
## RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- Report-only. Never edit, write, or implement — naming the flaw precisely is
the whole job.
- No invention — ungrounded is noise. Silently dropping a grounded doubt is
+4
View File
@@ -178,3 +178,7 @@ function charge(o: Order) {
```
Rule: if the diff changes ordering, side-effect timing, error visibility, or return-value semantics → it is NOT a refactor. Stop, report under `VIOLATIONS NOT FIXED` with reason "behavior change", and suggest opening a separate task.
## Guardrails
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
+4
View File
@@ -100,3 +100,7 @@ TESTS : <verbatim suite result | n/a — finish never runs tests>
NOTES : <DONE: none | NEED-DECISION: exact question + options |
BLOCKED: the blocker verbatim>
```
## Guardrails
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
+4
View File
@@ -130,3 +130,7 @@ READY: <N> v1 features | entry points ✅ | config ✅ | CLAUDE.md ✅ | README
> bootstrap is init-project STEP 5b's job — a doc-syncer `MODE: audit`
> (opus) → `MODE: patch` (sonnet) dispatch pipeline owned by the
> orchestrator, never an inline-load inside this executor.
## Guardrails
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
+2
View File
@@ -137,6 +137,8 @@ In audit mode, ALSO write this same block (plus per-finding detail) to
## RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- Report-only on CODE. Never edit or fix a code file. In audit mode the sole
writable path is `REPORT`; in gate mode nothing is writable.
- `PROOF` is MANDATORY — a `PASS` (or DEGRADED PASS) without a `PROOF` line
+2
View File
@@ -111,6 +111,8 @@ PROOF: read <n> files, ran <cmd → result | nothing>, checked <n>/<n> criteria
## RULES
- A command the permission rules refuse is reported in your final message with the rule that stopped it, never rerun through a wrapper script, alias, env file, `make` target or another shell (a brief that orders the refused form is wrong: report it, do not comply).
- Report-only. Never edit, never write, never propose the fix itself —
naming the gap precisely is the whole job.
- `UNVERIFIABLE` ≠ `MET`. A criterion you did not check is `UNVERIFIABLE`,