feat(gitflow): manual-push mode honoured by the lib, quiet unpushed-guard

`gitflow.autopush false` (human-set git config) now means "nothing is
pushed" end to end, not only in the post-commit/post-merge hooks:

- lib/gitflow.sh: `_gitflow_push_off` is the single reader of
  GITFLOW_NO_PUSH / gitflow.autopush for the lib's push sites; `start`
  and `finish` stop pushing in manual mode. `gitflow_delete` checks out
  the base that contains the branch and drops a lagging upstream before
  `git branch -d` (LRN-161: `-d` judges against the upstream when set).
  Skipped remote deletes say `left in place`; `_gitflow_sync_base`
  replaces the silent `pull --ff-only || true` and warns when a base is
  behind origin and cannot fast-forward.
- hooks/unpushed-guard.sh: manual mode is silent at Stop and gives one
  `ℹ manual push mode:` line at SessionStart counting every local
  branch; an unparseable value is named and treated as auto.
- CLAUDE.global.md: manual-push mode doctrine, "ahead = defect" scoped
  to auto mode.
- Tests: gitflow-test T18m block (T18m0, T18i-T18o, 7 cases),
  unpushed-guard T10-T16.

Follow-ups (TODO.md): run B push-guard hook + settings deny widening +
banner; run C skills that push on their own (/close STEP 5C, …).
Do not enable manual mode on the work machine before B and C land.
This commit is contained in:
bchanot
2026-10-06 17:49:20 +02:00
parent fa67664bac
commit 2fc88304ac
5 changed files with 172 additions and 11 deletions
+8 -4
View File
@@ -183,9 +183,12 @@ auto-pushed upstream). The reference-transaction hook vetoes any deletion
or rename of `main`/`develop`. The four hooks run in every repo: `make
link` generates `githooks/` and sets the global `core.hooksPath`; a repo
that ran `gitflow init` (new/onboarded projects) keeps its own `.githooks/`,
refreshed at session start. Foreign clone: `git config gitflow.protect
false` / `gitflow.autopush false`; `GITFLOW_NO_PUSH=1` only for throwaway
test repos. A branch ahead of its upstream is a defect, not a state.
refreshed at session start. Human-set opt-outs: `git config
gitflow.protect false` (foreign clone) and `gitflow.autopush false` =
manual-push mode (work machine): branches, commits and local merges run as
usual, nothing is pushed, Claude never pushes (`/close` included) unless
the user asks; `GITFLOW_NO_PUSH=1` only for throwaway test repos. Outside
manual mode a branch ahead of its upstream is a defect, not a state.
## Security — non-negotiable defaults
Apply at every step: design, scaffolding, implementation, review.
@@ -227,7 +230,8 @@ days of work never pushed.
- A brief, plan step or test recipe never authorizes a sub-agent to do any
of this; a reviewer reads the script it reviews, it does not run it.
- Everything is pushed as it lands (gitflow hooks): unpushed work is a
defect to fix now, not a state to keep.
defect to fix now, not a state to keep. Manual-push mode (above) is the
one exception.
# Communication mode: radical honesty
- TRUTH OVER COMFORT: point out flaws immediately, no sugarcoating, no "not