chore(memory): BDR-114 + LRN-200..202 + journal — feat manual-push-mode run D

This commit is contained in:
bchanot
2026-10-07 17:24:31 +02:00
parent 1203a9a735
commit 3721cf522a
10 changed files with 260 additions and 2 deletions
@@ -0,0 +1,61 @@
# PLAN — manual-push-failclosed-d1 — REVISED r2 (3 lenses + correctness confirmation)
Contract: .claude/tasks/contracts/2026-10-07-manual-push-failclosed-d1-1522.md
## Context
Every lib/hook reader of `gitflow.autopush` uses `git config --bool --default true … = false`. `--default` only covers a MISSING key: an unparseable value makes git die with empty output, `[ "" = false ]` is false, and the push runs — a typo silently re-enables every push on a work machine. push-guard (run B) already fails closed; the lib verb `push-mode` (run C) already prints `invalid`. D1 makes the lib, the two emitted push hooks and unpushed-guard agree: unset/true → auto, false → manual, anything else → NO push AND one stderr line naming it (the terminal user keeps a signal: today git's own `fatal: bad boolean` is that signal, and D1 must not remove it silently). `~/.claude/lib` and `~/.claude/githooks` are symlinks into this checkout: lib edits are live machine-wide at once, so tests run against the SOURCED emitter before the installed copies are regenerated, and regeneration comes last.
## Checklist (in this order)
- [ ] lib/gitflow-test.sh FIRST — NEW isolated block after T18m (before T19): `echo "T18q — fail closed: unparseable gitflow.autopush → nothing pushes, named (BDR-114)"`; `newrepo badval; echo a>a; hookon; gitflow_init`; bare origin; `git push -q -u origin main develop`; `git config gitflow.autopush flase`.
T18q1 `gitflow_start feature bad >/dev/null 2>"$WORK/q1.err"` → local branch exists AND `! git ls-remote --exit-code --heads origin feature/bad` AND `grep -q 'not a boolean' "$WORK/q1.err"` (the verb's stderr passes through `_gitflow_push_off`).
T18q2 `echo b>b.txt; git add b.txt; git commit -q -m b 2>"$WORK/q2.err"` → `! git ls-remote --exit-code --heads origin feature/bad` AND `grep -q 'NOT pushed' "$WORK/q2.err"` (the hook names it; hooks ON via hookon — note: the installed `.githooks/` in the throwaway repo is written by `gitflow_init` from the SOURCED emitter, so this tests the new text before any regen).
T18q3 `dev_before=$(git -C "$bare" rev-parse develop)`; `gitflow_finish >/dev/null 2>&1; q_rc=$?` → `[ $q_rc -eq 0 ] && [ "$(git -C "$bare" rev-parse develop)" = "$dev_before" ] && ! git rev-parse --verify -q refs/heads/feature/bad`.
T18q4 positive control for the hook's `0:true` arm: `git config gitflow.autopush true; gitflow_start feature good; echo g>g.txt; git add g.txt; git commit -q -m g` → `[ "$(git rev-parse HEAD)" = "$(git -C "$bare" rev-parse feature/good)" ]` (tips equal: the post-commit hook pushed; `ls-remote` alone would pass from the start's push).
T18q5 POSIX-clean emitted hook: `_gitflow_emit_push_hook post-commit > "$WORK/pc.sh"` (SOURCED function, never a relative lib path from a fixture cwd); `[ -s "$WORK/pc.sh" ] && grep -qF 'case "$rc:$v"' "$WORK/pc.sh"`; then `if command -v shellcheck >/dev/null 2>&1; then chk "T18q5 emitted hook is POSIX-clean" 'shellcheck -s sh "$WORK/pc.sh"'; else ok "T18q5 skipped (no shellcheck)"; fi` (first shellcheck use in a hermetic suite → guarded).
Variables read in double-quoted assertions (no SC2034 suppression). Config writes live in the test FILE. No T18q0 (duplicate of T11b).
- [ ] lib/gitflow.sh — `_gitflow_push_off`:
```
# rc 0 when pushing is off: GITFLOW_NO_PUSH=1 (throwaway test repos), or
# gitflow.autopush not readable as `true`/unset — manual-push mode (false,
# human-set) AND fail closed on an unparseable value or a config read
# failure (BDR-114). The verb's stderr passes through: it names an invalid
# value and is silent for auto/manual. Single reader for the lib's push sites.
_gitflow_push_off() {
[ "${GITFLOW_NO_PUSH:-0}" = 1 ] && return 0
[ "$(gitflow_push_mode)" != auto ]
}
```
Comments: line ~195 ("manual mode never deletes origin/<br>") → "push off (manual mode or invalid value) never deletes origin/<br>"; line ~206 ("skipped under GITFLOW_NO_PUSH=1, gitflow.autopush=false or no origin") → "skipped when push is off (see _gitflow_push_off) or no origin". `_gitflow_note_remote_left`'s message UNCHANGED ("manual push mode" is the doctrine name for the off state; skills/gitflow/SKILL.md:114 quotes it).
- [ ] lib/gitflow.sh — `_gitflow_emit_push_hook` heredoc: replace the two opt-out lines (`# Per-repo opt-out (no push rights on a foreign clone): git config gitflow.autopush false` / `[ "$(git config --bool --default true gitflow.autopush)" = false ] && exit 0`) with:
```
# Manual-push mode (human-set): git config gitflow.autopush false. Fail closed:
# an unparseable value or a config read failure also means "no push", named.
# Mirrors gitflow_push_mode (lib/gitflow.sh); arms pinned by T18b/T18h/T18q2/T18q4.
v=$(git config --bool gitflow.autopush 2>/dev/null); rc=$?
case "$rc:$v" in
0:true|1:*) ;;
0:false) exit 0 ;;
*) echo "gitflow $hook: gitflow.autopush unreadable (git rc $rc) — NOT pushed, treated as manual push mode; fix the value by hand" >&2; exit 0 ;;
esac
```
POSIX sh only. pre-commit and reference-transaction emitters untouched (byte for byte).
- [ ] hooks/unpushed-guard.sh — at the TOP (before `payload=$(cat …)` and before `cd "$cwd"`): `_lib="$(cd "$(dirname "${BASH_SOURCE[0]}")/../lib" 2>/dev/null && pwd)/gitflow.sh"`. Replace lines 26-29 (the four lines `raw=`, `manual=0; invalid=0`, the `manual=` test, the `invalid=` test) AND lines 76-78 (the old invalid clause) — no `invalid` variable survives (SC2034 otherwise) — with:
```
out=$(bash "$_lib" push-mode 2>&1); mode=${out##*$'\n'}; mode_err=${out%"$mode"}
manual=0; [ "$mode" = auto ] || manual=1 # fail closed: anything but auto
```
(the verb writes its stderr line BEFORE its stdout word, so the last line is the mode; no temp file, no delete). Invalid/unreadable clause (SessionStart only): `case "$mode" in invalid) msg="${msg:+$msg; }${mode_err#gitflow.sh push-mode: } — treated as manual push mode (nothing pushes); fix the value by hand" ;; manual|auto) ;; *) msg="${msg:+$msg; }push mode unreadable (lib verb printed '${mode:-nothing}') — treated as manual push mode" ;; esac` (strip the trailing newline of `mode_err`). Stop + manual=1 → silent (unchanged early exit). Header comment: "+ an unparseable value is treated as manual (fail closed, BDR-114); the mode comes from the lib verb". Functions ≤25 logic lines.
- [ ] lib/tests/unpushed-guard.test.sh — T14 rewrite (same fixture, key `flase`, one unpushed commit): T14-invalid-named → SessionStart contains `not a boolean`; T14-invalid-prefix → contains `ℹ manual push mode:`; T14-invalid-treated → contains `treated as manual`; T14-invalid-no-warn → NOT `unpushed work`; T14-invalid-stop-silent → Stop → `silent`. T15 unchanged.
- [ ] regenerate in the SAME step as the emitter edit (a SessionStart `reconcile-hooks` between the two would run `install-hook` and write a local hooks-path entry), files only, with NO config read or write of any kind: `bash lib/gitflow.sh emit-hook post-commit > .githooks/post-commit`, `… emit-hook post-merge > .githooks/post-merge`, `… emit-hook post-commit > githooks/post-commit`, `… emit-hook post-merge > githooks/post-merge` (writing into the existing files keeps mode 755). NOT `install-hook` (local config write) and NOT `global-hooks` (writes the GLOBAL config when `~/.gitconfig` lacks the hooksPath — which is the case right now: the user's gitconfig was overwritten by a dotfiles installer at 15:39 and must be restored by the user first). Evidence: `md5 -q .git/config` identical before/after; `~/.gitconfig` untouched (the executor never reads it); `git diff --stat` shows only the four hook files. If a command is refused, STOP and report; never hand-edit generated hooks.
- [ ] then run `make test suite=lib/gitflow-test.sh` again: T19a–e green = installed == emitted.
## Edge cases
- `GITFLOW_NO_PUSH=1` still short-circuits before any mode read (T18o).
- Terminal user with a typo: every commit prints the hook's one-line stderr and pushes nothing; `gitflow start`/`finish` print the verb's line. Inside Claude: unpushed-guard names it at SessionStart; the banner shows the lock line after D2.
- Lib path for the guard resolved before any `cd` (relative invocation safe).
- Onboarded projects keep their committed fail-open `.githooks/` until a session-start `reconcile-hooks` runs there and the user commits the refresh: documented at doc-sync (CHANGELOG scope note), not solvable from this repo.
- Skills/docs still carrying "until run D" (capitalize :346/:379, CHANGELOG, SETTINGS) become stale the moment D1 lands: D3 + doc-sync follow on the same branch before merge.
- Hooks in throwaway test repos are written by `gitflow_init` from the sourced emitter → T18q runs against the NEW hook text before regeneration.
## Disposition
- honors BDR-111/BDR-112 (fail-closed semantics chosen by the user, now every reader), BDR-095 (push every commit — unchanged in auto mode; T18b/T18q4 positive controls; a stopped push is always NAMED on stderr), LRN-114 (edit the generator → regenerate installed copies through the lib → T19 drift gate), LRN-113 (grep `--default true gitflow.autopush` across lib/ hooks/ githooks/ .githooks/ ends at zero after D1+D2), LRN-191, LRN-194, LRN-196 (read git's rc), BDR-087 (Stop stays message-only), LRN-193 (fresh confirmation after this revision).
- New BDR-114 proposed at capitalize: "every autopush reader fails closed and names the value; unset/true auto, false manual, else no push".
@@ -0,0 +1,35 @@
# PLAN — manual-push-guard-residuals-d2 — REVISED r2 (3 lenses + correctness confirmation)
Contract: .claude/tasks/contracts/2026-10-07-manual-push-guard-residuals-d2-1526.md
## Context
push-guard (run B, hardened) is live on every Bash|Monitor call (`~/.claude/hooks` is a symlink into this tree: every edit above `is_push || exit 0` runs machine-wide at once → `bash -n` after each edit). Residuals: `arg_tokens`' unquoted alternative stops at the first quote, so `cd /m/'a b'` yields `/m/` and the wrong dir is checked (fail-open toward the parent); an unparseable payload allows silently; the mode `case` has no default; missing core tools allow silently; T42 is vacuous once committed; no literal-`true` test; the banner shows nothing on an invalid value. After D1 the lib verb is the single reader: push-guard sources the lib once and calls `gitflow_push_mode` per candidate; the banner calls the verb.
## Checklist (bash -n hooks/push-guard.sh after every edit)
- [ ] hooks/push-guard.sh
a. Top: `LIB="$(cd -P "$(dirname "${BASH_SOURCE[0]}")/../lib" 2>/dev/null && pwd)/gitflow.sh"` (absolute, before anything else). Tools: after the jq check, `for t in cat grep sed sort head; do command -v "$t" >/dev/null 2>&1 || { echo "push-guard: $t missing, guard inactive" >&2; exit 0; }; done` (jq policy; documented).
b. Payload fallback (no regex hoist, no early `static_deny` call): `unparsed=0; cmd=$(field '.tool_input.command') || { cmd=$payload; unparsed=1; }` (jq's rc is the rc of `field`; a parse failure → the raw payload becomes the text to scan). In the fold step, when `unparsed=1`, also replace the two-character JSON escapes `\n`, `\r`, `\t`, `\\` by spaces: `one=${one//\\n/ }; one=${one//\\r/ }; one=${one//\\t/ }; one=${one//\\\\/ }`. `is_push` runs unchanged on it. When `unparsed=1`, also set `bare=$one` (JSON quotes are syntax, not shell quoting: deleting every `"…"` span would blind the loose and alias regexes). Right after the EXIT trap is installed: `[ "$unparsed" = 1 ] && exit 0` → the trap emits the static deny (mode-blind, fail closed). Accepted limit (header): on a broken payload the whole JSON text is scanned, so a `description` mentioning a push also denies.
c. Source the lib once: after LIB: `# shellcheck source=/dev/null` then `if [ -r "$LIB" ]; then . "$LIB"; LIB_OK=1; else LIB_OK=0; fi` (the `source=/dev/null` directive is the only clean way to source a path variable; it is not a `disable`) (sourcing defines functions only; the CLI dispatcher runs only when executed). `mode_in <dir>`: `( cd -- "$1" 2>/dev/null || { echo "failed:cannot enter the directory"; exit 0; }; [ "$LIB_OK" = 1 ] || { echo "failed:gitflow lib missing"; exit 0; }; out=$(gitflow_push_mode 2>&1); m=${out##*$'\n'}; why=$(printf '%s\n' "$out" | grep -m1 '^gitflow.sh push-mode: ' | sed 's/^gitflow.sh push-mode: //'); case "$m" in manual|auto) echo "$m" ;; invalid) echo "invalid:${why:-unreadable}" ;; *) echo "$m" ;; esac )`. No temp file. Reason for `invalid:*`: `push-guard: ${mode#invalid:} in $dir — treated as manual push mode (fail closed). Fix the value by hand, or run it yourself: ! $cmd` (the verb's line already says "gitflow.autopush='x' is not a boolean (git rc N)" or "could not read …"). Reason for `failed:*`: `push-guard: push mode unreadable in $dir (${mode#failed:}) — push refused (fail closed). Run it yourself: ! $cmd`.
d. `case "$mode"` gains `*) deny "push-guard: unexpected push mode '$mode' in $dir — push refused (fail closed). Run it yourself: ! $cmd" ;;`.
e. Tokens: `arg_tokens`' argument alternative becomes a REPETITION of segments so adjacent quoted and unquoted parts form one shell word: `arg='(--[[:space:]]+)?((\\.|"[^"]*"|'"'"'[^'"'"']*'"'"'|[^[:space:];&|()"'"'"'`\\]+)+)'` — an escape alternative `\\.` and the backslash removed from the unquoted class, so `my\ dir` is one word (verified on BSD grep: `/W/manual/my\ dir`, `a\ b\ c`, `/a'/../b'`, `"Bob's"`). Keep the `--` optional prefix and the same `pre` class. Then a `classify_tok` step in the MAIN shell, before the 20-token cap: for each raw token — if it starts and ends with the same quote → strip that pair, then if the inner text still contains THAT same quote character → deny (mixed: `"/m"/x"/y"`, `'/u/Bob'\''s repo'`); inner quotes of the OTHER kind are fine (`"Bob's repo"`); a token not enclosed that contains any quote → deny: `push-guard: directory token $tok mixes quoted and unquoted parts — this guard refuses to interpolate it (fail closed). Quote the whole path, or run it yourself: ! $cmd`; else unescape backslashes in the unquoted token with ONE mechanism: `tok=$(printf '%s' "$tok" | sed -E 's/\\(.)/\1/g')` (BSD sed verified: `a\\b` → `a\b`, `my\ dir` → `my dir`; deterministic, no eval). Resolution and dedup unchanged after that. Drop the old `unquote` helper if `classify_tok` replaces it.
f. Header: DENIED now lists mixed-quote tokens and the case where a `cd` argument touches a closing quote followed by another quote on the line (`bash -c 'cd /x' && bash -c 'git push'` → one mixed token → denied; accepted, fail closed); MISSES drops inner-quote tokens, keeps `~`/`$VAR`/`$(…)`; add "payload jq cannot parse → raw text scanned (JSON escapes folded), static deny on a push match; grep/sed/sort/head/cat or jq missing → stderr warning, allow"; LIMITS unchanged (20 tokens).
- [ ] lib/tests/push-guard.test.sh
T51 `truerepo` fixture (key `true`) `git push` → allow.
T52 (cwd plain) `cd $WORK/auto'/../manual' && git push` (test writes the expanded `$WORK`) → deny, reason contains `mixes quoted and unquoted`. T52b (cwd plain) `cd "$WORK/manual/my dir" && git push` → deny, reason `manual push mode` (fully quoted, resolved). T52c (cwd auto) fixture dir `$WORK/auto/bob's` → `cd "$WORK/auto/bob's" && git status` → allow (no push) and `cd "$WORK/auto/bob's" && git push` → allow (auto; inner apostrophe inside a fully-quoted token is fine).
T53 (cwd plain) `cd $WORK/manual/my\ dir && git push` → deny, reason `manual push mode` (backslash unescaped, resolved). T53b (cwd plain) `cd "$WORK/manual"/sub"" && git push` → deny, reason `mixes quoted and unquoted`.
T54 unparseable payload: fixture written with `printf '%s'` holding the 6-char escape `\ud800` in `cwd`; precondition `! jq -e . <"$WORK/bad.json"` (FAIL the test if jq parses it); run from `$WORK/auto` with command `git push` → stdout contains `"permissionDecision":"deny"`, reason contains `internal error`, rc 0; T54b same broken payload with `git status` → empty stdout; T54c broken payload whose command is `git add -A\ngit push` (two-char escape) → deny. T54d broken payload whose command is `git subtree push --prefix=x origin main` → deny (loose regex must still see it: `bare=$one` when unparsed).
T55 missing core tool: shim with bash, cat, jq, git, sed, sort, head but NO grep → rc 0, empty stdout, stderr `grep missing`.
T56 lib missing: `mkdir -p "$WORK/alone/hooks" && cp "$ROOT/hooks/push-guard.sh" "$WORK/alone/hooks/"` (copy; no `$WORK/alone/lib`), run with a temporary `H="$WORK/alone/hooks/push-guard.sh"` then restore `H`, cwd manual → deny, reason `gitflow lib missing`.
T57 banner invalid: reuse the existing `banner` helper → `banner "$WORK/bad"` contains `push : manual (autopush bad)`.
T42 → base: whichever of `origin/main` / `main` resolves (`git -C "$ROOT" rev-parse -q --verify`); both → the fresher by ancestry (`merge-base --is-ancestor main origin/main` → origin/main, else main); neither → print `SKIP T42 (no main ref)` and count nothing; assert the base deny count > 0 (FAIL otherwise); print `T42 base: <ref>`.
- [ ] hooks/session-start.sh — replace the `--default true` test with: `_pm=$( [ -r "$_gf_lib" ] && bash "$_gf_lib" push-mode 2>/dev/null )` (reuse `_gf_lib`, computed at line ~52 — move its `unset` after this block); `case "$_pm" in manual) printf "│ 🔒 %-46s│\n" "push : manual (autopush=false) — ! git push" ;; invalid) printf "│ 🔒 %-46s│\n" "push : manual (autopush bad) — ! git push" ;; esac` (41 chars + 2 bytes for `—` → fits the box); `unset _pm`. Keep the byte-padding comment.
- [ ] skills/tour/SKILL.md — `git -C <abs project>` → `git -C "<abs project>"` at every placeholder site (~243, 245, 248, 285); the `~/proj/site` example row stays unquoted (a quoted `~` would not expand).
## Edge cases
- Sourcing `lib/gitflow.sh` inside the hook: functions only; `set -uo pipefail` is NOT set by sourcing (the lib sets it only in its CLI branch) — verify by reading the lib's last block; the hook keeps its own `set -u`.
- `gitflow_push_mode` inside `$(…)` in a subshell: one git call per candidate, no bash spawn (BASH_ENV irrelevant).
- Broken payload: the static deny is mode-blind by design (the mode cannot be read without a command); documented.
- Mixed-quote tokens are denied in auto mode too (user-gated fail-closed for pathological commands, run B); fully-quoted tokens with inner apostrophes and backslash-escaped spaces are resolved, not denied.
- D1 owns hooks/unpushed-guard.sh; D2 is verified after D1's commit, so AC3's `--default true` grep over hooks/ is run then (contract says so).
## Disposition
- honors BDR-112 (fail-closed guard; user-gated pathological cases), BDR-113/BDR-114 (single reader = the verb, sourced), LRN-196 (trap exit 0 unchanged; caps; read rc), LRN-198 (quoted paths; no eval, deterministic unescape), LRN-104 (every new string locked), LRN-191, LRN-194, LRN-193 (fresh confirmation after this revision), BDR-100 (`--default true gitflow.autopush` grep across hooks/ ends at zero after D1+D2).
@@ -0,0 +1,24 @@
# PLAN — manual-push-prose-d3 — REVISED r2 (3 lenses + correctness confirmation)
Contract: .claude/tasks/contracts/2026-10-07-manual-push-prose-d3-1530.md
## Context
After D1 and D2 every reader of `gitflow.autopush` in THIS checkout (lib, emitted hooks, unpushed-guard, push-guard, banner) treats an unparseable value as manual: nothing pushes, and the stop is named. Two caveats remain: (a) onboarded projects keep their committed `.githooks/` until a session-start reconcile refreshes them, so a stale per-repo hook can still push on an invalid value — the ahead count tells; (b) the soft_deny backstop names only `gitflow.autopush false` (settings.json is outside D3; TODO). The skill prose written during run C still says "the lib and hooks still push on an invalid value until run D". Two labels say "COMMIT + PUSH" although the step reads the push state. The release executor trusts the dispatcher's version regex alone.
## Checklist
- [ ] PRECONDITION (executor's first step): `grep -l -- '--default true gitflow.autopush' lib/gitflow.sh hooks/unpushed-guard.sh hooks/session-start.sh githooks/post-commit githooks/post-merge .githooks/post-commit .githooks/post-merge` must print nothing (D1 + D2 landed); any hit → STATUS: BLOCKED, nothing edited.
- [ ] skills/capitalize/SKILL.md — line ~346 (5C invalid outcome) becomes TWO lines, both single-line bullets, placed where the one line is (still evaluated first):
`- **push mode \`invalid\`, \`ahead\` > 0 or unknown** → \`merged to develop — <verb stderr line verbatim>: treated as manual push mode by every reader, nothing pushed (origin/develop is <ahead> commit(s) behind, or unknown). Fix the value by hand, then: ! git push origin develop\` (append \` once a remote exists\` when \`ahead\` is unknown).`
`- **push mode \`invalid\`, \`ahead\` = 0** → \`merged to develop — <verb stderr line verbatim>: pushed anyway, likely a stale fail-open hook (a session-start reconcile refreshes a stale .githooks/; commit the refresh) or a manual push. Fix the value by hand.\``
Line ~379 (STEP 6 invalid closing line) becomes two matching lines: `- **invalid (merged, ahead > 0 or unknown)** → \`⚠️ <mode> + merged to develop — <verb stderr line verbatim>: treated as manual push mode by every reader, nothing pushed (origin/develop <ahead> behind). Fix the value by hand, then: ! git push origin develop\` (+ \` once a remote exists\` when unknown)` and `- **invalid (merged, ahead = 0)** → \`⚠️ <mode> + merged to develop — <verb stderr line verbatim>: pushed anyway, likely a stale fail-open hook (refreshed by the next session-start reconcile; commit the refresh) or a manual push. Fix the value by hand.\``. STEP 6 is picked by the 5C result, not evaluated in order, so disambiguate the neighbours: line ~371 `**auto-persisted (5C: finish rc 0 AND \`ahead\` = 0)**` → `**auto-persisted (push mode \`auto\`, finish rc 0 AND \`ahead\` = 0)**`; line ~378 `**not on origin (merged, \`ahead\` unknown)**` → `**not on origin (push mode not \`invalid\`, merged, \`ahead\` unknown)**`. Recap line ~363: `merged, gitflow.autopush invalid (<ahead> behind)` → `merged, autopush invalid, nothing pushed (<ahead> behind) | merged, autopush invalid, pushed anyway (stale hook or manual push)`. Line ~375 (`--no-push`, `branch_ahead` = 0): add after the template, as an instruction like the :376 precedent: `With push mode \`invalid\`, replace \`(auto-push mode)\` with \`(<verb stderr line verbatim>: pushed anyway, likely a stale fail-open hook or a manual push; fix the value by hand, commit the .githooks refresh)\`.` Line ~376 (`--no-push`, `branch_ahead` > 0 or unknown): its existing `With push mode \`invalid\`, append \` gitflow.autopush=<value> is not a boolean: fix it by hand\`` → `With push mode \`invalid\`, append \` <verb stderr line verbatim>: treated as manual push mode, nothing pushed; fix the value by hand\``. No "until run D" text remains; no templated `<value>`: the verb's stderr line is quoted verbatim (it may say "could not read"). No period right after a `! git …` command.
- [ ] agents/client-handover-writer.md — heading `## STEP 5 — COMMIT + PUSH (only if files changed)` → `## STEP 5 — COMMIT + PUSH STATE READ (only if files changed)`. Residual push claims in the same step — the current text WRAPS across lines and carries bold markers; use the Read tool and multi-line old_strings: ~545-546 `Before any commit or push,⏎confirm this is a gitflow repo:` → `Before any commit, confirm this is a gitflow repo (the pipeline never pushes):`; ~553-554 `**do NOT commit,⏎do NOT push.**` → `**do NOT commit (and never push).**`; ~555-556 `Commit/push skipped — no gitflow model in this repo; publish the⏎listed changes manually before deploy.` → `Commit skipped — no gitflow model in this repo; publish the listed changes by hand before deploy.` (re-wrap as the file does). Line ~700 (C2-qualified "mini-commit; push state read, never assumed") stays. Verify with the Grep tool (pattern `push`), never a Bash grep carrying the push word.
- [ ] skills/client-handover/SKILL.md — step 4 label `**COMMIT + PUSH**` → `**COMMIT + PUSH STATE READ**`; in the same sentence `otherwise (manual push mode, or a hook push that failed)` → `otherwise (manual push mode, an invalid gitflow.autopush, or a hook push that failed)`.
- [ ] agents/release-executor.md — prep span, `### Input` paragraph: after "never bump it." add on its own line: `Format check only, by reading the string (never inside a Bash command): <X.Y.Z> must match ^[0-9]+\.[0-9]+\.[0-9]+$ (literal regex text, single backslashes); anything else → STATUS: BLOCKED, nothing created.` (prep only: finish's existing `### Preconditions` already requires the `release/<X.Y.Z>` branch that only prep creates). Lines ~80-83: `in manual push mode they stay local` → `in manual push mode, or with an invalid gitflow.autopush, they stay local` — keep `invalid gitflow.autopush` and `by reading the string` unbroken on one physical line each (line-based greps).
## Edge cases
- Label rename: repo-wide grep for "COMMIT + PUSH" (skills, agents, lib, hooks, rules, README, USAGE, templates, CLAUDE.global.md, CHANGELOG, docs) → only the two renamed lines; in-file references are by step number.
- "Pushed anyway" diagnosis: after D1, an invalid value with `ahead` = 0 can only come from a stale per-repo hook (or a human push); the line says so instead of asserting "nothing pushes".
- Doc-sync afterwards owns: CHANGELOG `[Unreleased]` three sites ("treated as auto", "for this hook a non-boolean value reads as manual", "still push on it as auto"), SETTINGS Push discipline "still push on it as auto; only push-guard fails closed", with the stale-`.githooks/` scope note.
- TODO (outside D3): settings.json soft_deny names only `gitflow.autopush false` — add "or an unparseable value" (restriction only) in a later settings run.
## Disposition
- honors BDR-114 (fail-closed everywhere → prose must stop saying otherwise, but never claims more than the facts: the ahead count decides), BDR-100/LRN-113 (label rename with citer grep; precondition grep for D1/D2 before any prose change), LRN-104, LRN-198 (version string checked by reading, never interpolated into a check command), BDR-042 (dispatcher decides the number; the executor only formats-checks).