Commit Graph
129 Commits
Author SHA1 Message Date
Bastien Chanot 096418c3e7 feat(capitalize): auto-persist memory to develop on /close + /capitalize (STEP 5C, BDR-068) 2026-07-16 13:51:15 +02:00
Bastien Chanot c41aac6975 chore(memory): LRN-128 LRN-129 EVAL-023 — close ritual 2026-07-16 13:37:43 +02:00
Bastien Chanot fdbe168ad8 chore(memory): BDR-067 — v1.0.0 first public release (versioning reset) + journal + TODO 2026-07-16 13:29:54 +02:00
Bastien Chanot 890e55f789 fix(model-routing): ronde edge fixes — feater applier carve-out, /refactor→sonnet dispatch, /analyze gate, audit-pin guards (F1-F5) 2026-07-16 12:45:07 +02:00
Bastien Chanot c43f89cede docs(memory): LRN-126 (split severs implicit data paths) + LRN-127 (SDD implementer git-ops discipline) 2026-07-16 12:17:01 +02:00
Bastien Chanot 1947a21237 fix(model-routing): wave-4 review fixes — forward DEPLOY_HINTS + SKIP_SEO in PACKAGE, realign §7/§8 annex numbering (I1/I2/I3) 2026-07-16 12:12:53 +02:00
Bastien Chanot fe1d60fccb chore(model-routing): wave-4 census + docs + BDR-066 (client-handover doc-gen → sonnet) 2026-07-16 11:56:54 +02:00
Bastien Chanot 30f732c08f chore(memory): LRN-125 — no dual-use agent across model tiers (wave-3 lesson) 2026-07-16 11:02:32 +02:00
Bastien Chanot bed695a6c6 chore(model-routing): wave-3 census + docs + BDR-066 update (bugfix/code-clean split) 2026-07-16 10:34:12 +02:00
Bastien Chanot bc8eede090 chore(model-routing): wave-2 census + docs + BDR-066 update 2026-07-15 21:49:34 +02:00
Bastien Chanot 2ad712cfd4 chore(memory): BDR-066 model routing + journal + TODO follow-ups 2026-07-15 12:01:14 +02:00
Bastien Chanot 8d70fcb15c chore(memory): BDR-065 + LRN-124 — post-merge capitalize (transient artifacts, scan-report leak-map) 2026-07-14 18:46:43 +02:00
Bastien Chanot 30d6b031b4 chore(memory): BDR-064 + LRN-122 + LRN-123 — ship-feature claude-global-md-rename 2026-07-14 17:06:29 +02:00
Bastien Chanot 0cedbc7b3a chore(memory): LRN-121 shell allowlist validation (grep -Eq fragile → whole-string POSIX case) + seo-account-mgmt journal + contract 2026-07-10 12:48:54 +02:00
Bastien Chanot 504f6f2242 chore(memory): BDR-063 + LRN-119/120 — GSC+CrUX data layer (OAuth token store, fail-open engine contract, SDD merge-base gotcha) 2026-07-10 03:04:17 +02:00
Bastien Chanot 2533e10ccb chore(memory): LRN-118 — gitflow-conformity audit (commits-code vs applies-defers discriminator + phantom-ref/dry-run-both-sides discipline) 2026-07-09 11:33:51 +02:00
Bastien Chanot 8397354caa chore(memory): backmerge — LRN-117 fork orphans code + consolidated B journal + backlog 2026-07-08 17:22:52 +02:00
Bastien Chanot cc4f161df7 chore(memory): capitalize review remediation — LRN-113/114/115/116, EVAL-021/022, journal
LRN-113 partial-fix+guard (structural fil rouge), LRN-114 hook-generator drift,
LRN-115 analyzer report-grants not dead (FP1, don't re-flag), LRN-116 release fix
missing from develop. EVAL-021 the review, EVAL-022 M5 pins trace. Journal
2026-07-08 remediation line. (BDR-062 committed with A6.)
2026-07-08 16:05:49 +02:00
Bastien Chanot 1be90361ac chore(config): realign CLAUDE.md size guard to measured reality (280→320) + BDR-062
The session-start line-count guard warned 'density pass requis' every session since
job1 without the 275 target (BDR-031) or even the 280 threshold ever being met —
CLAUDE.md sits at 305 (319→305 at job1, never re-inflated). A gate that never goes
green is noise. BDR-062 supersedes BDR-031's 275 TARGET only (principle kept, append-
only): 305 assumed final, guard warns past a 320 margin so real regressions still
surface. Review A6 (verifier-amended MINEUR).
2026-07-08 16:01:12 +02:00
Bastien Chanot 8e9ff33cd7 chore(memory): backmerge BLK-016 from release/1.0.0 (resolved on develop)
BLK-016 (rtk PATH-dead) shipped resolved in 1.0.0 (2b4e7401) but neither the entry
NOR the fix reached develop — rtk was live-broken on develop. Fix ported in the
preceding commit (install-plugins.sh bridge), so this backfill marks it resolved
truthfully. Table row + section. Review A3.
2026-07-08 15:59:09 +02:00
Bastien Chanot 38cc821a35 chore(memory): backmerge EVAL-015 from release/1.0.0
EVAL-015 (/tour first real run, report-only bchanot-cv) shipped in 1.0.0 (74d3804),
never back-merged to develop (registry gap between EVAL-014 and EVAL-016). Section
backfill; links to now-present [[LRN-101]]. Review A3.
2026-07-08 15:55:53 +02:00
Bastien Chanot a01250ba59 chore(memory): backmerge LRN-101 from release/1.0.0
LRN-101 (nginx add_header inheritance trap — verify headers live, not in config)
shipped in 1.0.0 (74d3804), never back-merged to develop. Append-only backfill,
table row + section. Review A3.
2026-07-08 15:55:27 +02:00
Bastien Chanot 7cd82cf9c1 chore(memory): backmerge LRN-098 from release/1.0.0
LRN-098 (/model rewrites settings.json — read diff before settings commit) shipped
in 1.0.0 (a623514) but never back-merged to develop (registry gap). Append-only
backfill at numeric position, table row + section. Review A3.
2026-07-08 15:54:48 +02:00
Bastien Chanot aa73793b90 chore(memory): job9 — commit-changer trailer fix + J4-16 cross-check follow-up 2026-07-08 13:10:10 +02:00
Bastien Chanot f667780156 chore(memory): job9 — BDR-060 version floor, BDR-061 path-b, LRN-112 nesting, journal + TODO 2026-07-08 12:43:39 +02:00
Bastien Chanot 5822869056 chore(memory): job8 capitalize — journal + TODO follow-ups
Session log for job8 (A/B/C/D execution, 3 Bash permission denials
worked around mid-C, smoke gate confirmed by user). TODO tracks the
2 open residuals: C/D single-pass re-audit next cycle, MAGIC_API_KEY
rotation still pending (job7 residual, unrelated to job8's own scope).
2026-07-07 23:58:50 +02:00
Bastien Chanot 66e4c4d0f9 docs(mcp): job8 B — document component_builder callback-injection risk
BDR-059 + LRN-110 + LRN-111. Confirmed A's ask-gate covers component_builder
(mcp__ scope) — no code fix possible or attempted, it's third-party package
code (dist/utils/callback-server.js:36). README MCP section now documents
the risk and why the mitigation is ask-gating, not patching.
2026-07-07 23:48:52 +02:00
Bastien Chanot c34ac99882 chore(memory): job8 C — darwin-skill reinstalled full pinned tree, detached HEAD
BDR-058 + LRN-109. Root cause of the "referenced files absent" finding:
the skills CLI's skillPath only fetches SKILL.md, never sibling
references/scripts/templates dirs. Upstream HEAD matched the already-
recorded lockfile hash exactly (no drift, no tamper) — reinstalled the
full tree at that pinned SHA, detached HEAD so nothing can silently
advance. Reinstall happened outside this repo (~/.agents); this commit
is the only repo-side record. Backup of the old single-file dir kept.
2026-07-07 23:47:07 +02:00
Bastien Chanot eade4e603e job7 capitalize: BDR-057, BDR-026 update, LRN-108, journal
BDR-057: secrets by reference not by value; redact at capture, not just at
rest. Documents the two-part job7 posture (MCP ${VAR} expansion + rtk-rewrite
env-dump redaction) and flags the unreconciled contradiction with job6's
same-day (wrong) finding that ${VAR} expansion was unsupported at user scope.

BDR-026 updated: the backup-vector incident (2026-07-02) is closed at the
source rather than by repeated scrubbing — every native auto-backup taken
while the live file held the plaintext value was a fresh leak, so scrubbing
existing backups alone would have recurred forever.

LRN-108: `claude mcp add --env KEY=value` writes the value literally —
double- vs single-quoting around `${VAR}` is the entire difference between
a reference and a plaintext-forever config. The natural way to type the
flag (bash-expand it first) is exactly the trap.

Also refreshed .audit/scan-secrets-claude-home.json to the post-purge state
(15 residual hits, down from 18 pre-D).
2026-07-07 12:58:51 +02:00
Bastien Chanot 563fbd5422 job6: capitalize — BDR-056, LRN-107, EVAL-020, journal
BDR-056: deps policy reversal — latest gated by integration, not
KEEP-PINNED by default (job6-batch-3 override, gstack #1911 case).
LRN-107: read-only subagent mandates must ban copying secret VALUES,
not just mutations (job6's own MAGIC_API_KEY scratch-copy incident).
EVAL-020: job6 execution quality — 2 real STOP gates hit and resolved
live (graphifyy hook rewrite declined, gsd-pi format break patched).
2026-07-07 04:07:07 +02:00
Bastien Chanot 0e18116ae3 job5: BDR-055 — pending verbs removal, J4-17 closed MOOT 2026-07-07 00:57:07 +02:00
Bastien Chanot bb5fb0cf5c job4: capitalize execution — EVAL-019 + LRN-106 + journal
EVAL-019: job4 test-gap audit + execution summary (11 specs, 5 fixes/
seams, every mutation red-green verified, zero residual, /tmp-exhaustion
incident + recovery, SPEC-06 checkpoint honesty, J4-22 caller-census
flag).

LRN-106: fixing B1 in one file != closing the B1 pattern. job3-B1
froze a fixture + repointed run-reconcile.sh's T2 off the live
registry, declared unblocked, 20/20 green — job4's very next audit
pass found T3/T5 in the SAME FILE still reading the live registry,
same fragility, untouched siblings. Now actually closed (SPEC-10).

journal: 2026-07-06 (cont. 2) entry.
2026-07-06 21:59:58 +02:00
Bastien Chanot 64f2e59a36 job3: capitalize B1 resolution — journal follow-up (sentinel authorized, suite 20/20) 2026-07-06 17:36:33 +02:00
Bastien Chanot 2028023359 job3: capitalize execution — EVAL-018 + LRN-105 + journal close
EVAL-018: job3 shipped, 46/46 findings verified, 20/23 fixes applied
(B1 blocked on sentinel scope, D2-D5+B6 skipped by decision), zero
residual on final re-sweep. LRN-105: explorer subagents need an
explicit ban on executing the subject-under-test's own CLI, not just
"read-only" framing (caught mid-run: a subagent ran `graphify .`).
2026-07-06 17:19:53 +02:00
Bastien Chanot d43d8131e5 job3: D6+D7+D9 supersede BDR-038 (BDR-054) + banner historical deploy docs
BDR-038 recorded NEXT.sh file + AskUserQuestion hand-back as the /deploy
design; 52f6678 removed both (LRN-102: pre-tool-call text may never render)
with no superseding decision. BDR-054 regularizes it. One-line banners on
docs/plans/2026-06-27-deploy-skill.md and docs/specs/2026-06-27-deploy-skill-design.md
point to the shipped behavior; historical body left untouched.
2026-07-06 16:50:17 +02:00
Bastien Chanot e737f41355 job2 tail: capitalize BDR-053 (ctx7 single surface) + journal close 2026-07-06 12:40:46 +02:00
Bastien Chanot 2ea21c25ba job2: capitalize execution — LRN-104 (oracle contract + no-runner) + journal 2026-07-06 12:34:03 +02:00
Bastien Chanot 0e7f171405 job2: capitalize — journal 2026-07-06 + EVAL-017 (audit shipped, verify-pass anomalies) 2026-07-06 12:09:30 +02:00
Bastien Chanot 98761fc1d0 job1: capitalize LRN-103 — BLK-009 doc was stale, paths: works at both levels 2026-07-06 02:48:16 +02:00
Bastien Chanot d1e74238d3 job1: close BLK-009 2026-07-06 02:48:16 +02:00
Bastien Chanot adf64dfd9d chore(memory): LRN-102 — deliverable text before a tool call may never render + journal 2026-07-05 20:19:13 +02:00
Bastien Chanot 7d566da776 chore(memory): EVAL-016 /deploy first real run + journal — tour→prod closed, skill UX patch 2026-07-05 15:32:16 +02:00
Bastien Chanot 16037acefd chore(memory): BDR-052 branch-as-gate + LRN-099/100 + EVAL-014 + journal — /tour TDD capitalized 2026-07-05 12:53:08 +02:00
Bastien ChanotandClaude Opus 4.8 599d7ddadb chore(memory): LRN-097 blog-pattern-vs-real-feature + journal 2026-07-04
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
2026-07-04 13:48:46 +02:00
Bastien ChanotandClaude Opus 4.8 b99ace29c0 chore(memory): BDR-051 enrich-at-gate + LRN-096 flip-test-guards + journal lot 5 (chantier complete)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
2026-07-04 04:52:55 +02:00
Bastien ChanotandClaude Opus 4.8 65edf8c1ba chore(memory): BDR-050 universal pipeline + LRN-095 orthogonal gates + journal lot 4
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
2026-07-04 04:38:45 +02:00
Bastien Chanot 5aa4216409 Merge branch 'feature/security-auditor' into feature/verify-loops
# Conflicts:
#	.claude/memory/journal.md
2026-07-03 20:35:07 +02:00
Bastien Chanot 324bb7b4b1 Merge branch 'feature/contract-verifier' into feature/verify-loops
# Conflicts:
#	.claude/memory/decisions.md
#	.claude/memory/journal.md
#	.claude/memory/learnings.md
2026-07-03 20:34:00 +02:00
Bastien ChanotandClaude Opus 4.8 938a908857 chore(memory): journal lot 3 — security-auditor shipped; LRN-094/BDR-048-addendum deferred to integration
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
2026-07-03 19:52:47 +02:00
Bastien ChanotandClaude Opus 4.8 d682705f34 chore(memory): BDR-049 verifier doctrine + LRN-093 vacuous grep lock + journal 2026-07-03
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
2026-07-03 18:53:54 +02:00