chore(memory): BDR-112 + LRN-194..196 + journal — feat manual-push-guard run B

This commit is contained in:
bchanot
2026-10-07 12:41:46 +02:00
parent 6468eda495
commit 4630b625f7
6 changed files with 132 additions and 2 deletions
+3 -2
View File
@@ -2058,8 +2058,9 @@ dans un runner; capitalize reste main-loop.
## manual-push-mode (2026-10-06, /feat × 3)
- [x] run A — `gitflow.autopush=false` honoured by `_gitflow_push_branch`, quiet unpushed-guard, doctrine line; plan `.claude/tasks/plans/2026-10-06-manual-push-mode-1632.md` → commit 2fc8830 on feature/manual-push-mode; verifier ECARTS(1) = AC6 only (design-tool-gate env red, pre-existing on develop) → human waiver; merge human-gated
- [ ] run B — `hooks/push-guard.sh` PreToolUse (deny `git push` in manual mode) + test + settings.json (hook wiring, widen `gitflow.*` deny: `git config * gitflow.*`, `git -c gitflow.*`, `GIT_CONFIG_COUNT=*`; environment prose ~480/~499) + session-start banner push mode
- [ ] run C — skills that push on their own, gate on `gitflow.autopush`: capitalize STEP 5C (`git push origin develop`), client-handover SKILL:48 + agents/client-handover-writer.md:586, release-candidate:96 + tour:273 "already on origin" claims
- [x] run B — `hooks/push-guard.sh` PreToolUse (deny `git push` in manual mode) + 71-check test + settings.json (own hook group Bash|Monitor timeout 10; 18 write-form deny entries on the toggle; soft_deny on manual-mode pushes with no per-turn clearance; prose) + banner → a2ac018 + hardening commit; verifier CONFORME then ECARTS(1) closed by gated clarification (fail-closed cap/unenterable dir also in auto mode); security PASS ×2
- [ ] run D also (push-guard residuals, security gate 2026-10-07): tokens with inner quotes/backslashes (`cd /m/'a b'`) resolve to the wrong dir → treat as unresolvable + deny or document; unparseable payload (lone surrogate) → jq fails → silent allow → grep raw payload for `push` and deny; `case "$mode"` default `*) deny`; up-front `command -v grep sed sort head jq` check; header line > 80 cols; T42 compares against HEAD (vacuous once committed) → compare against a pinned base or drop; no test sets the key to literal `true`
- [ ] run C — skills that push on their own, gate on the mode through a NEW lib verb `bash ~/.claude/lib/gitflow.sh push-mode` (prints auto|manual|invalid; the bare `git config … gitflow.autopush` read is denied for Claude after run B — a trailing ` *` glob also matches end-of-string): capitalize STEP 5C (`git push origin develop`), client-handover SKILL:48 + agents/client-handover-writer.md:586, release-candidate:96 + tour:273 "already on origin" claims
- [ ] run B also: fail-CLOSED on an unparseable `gitflow.autopush` value in every reader at once (lib `_gitflow_push_off`, the two emitted push hooks, unpushed-guard) — run A keeps fail-open for consistency with the untouched emitters (security gate MEDIUM, 2026-10-06); `--end-of-options`/`--` on refname args and `printf %q` in copy-paste hints (LOW); `gitflow_delete`: check `_gitflow_checkout_containing_base` rc before `--unset-upstream` (LOW, 2nd gate)
- [ ] ORDER: do not set `gitflow.autopush false` on the work machine before B + C are merged (until then `/close` still pushes develop)