Commit Graph
383 Commits
Author SHA1 Message Date
Bastien Chanot 8cade82edb Merge feature/audit-hardening into develop 2026-07-02 14:35:56 +02:00
Bastien Chanot c6660c1c5f Merge bugfix/audit-bugs into develop 2026-07-02 14:35:31 +02:00
Bastien Chanot 0c353d2102 Merge feature/audit-tokens into develop 2026-07-02 14:32:59 +02:00
Bastien ChanotandClaude Fable 5 1aa9afe669 feat(tokens): compress the 10 fattest personal skill descriptions
6,416 → 4,243 chars (≈ −540 tokens/session, catalog loaded every
session). Kept per BDR-014/LRN-043: 'Use when' pattern, discriminating
FR+EN triggers, all 'For X → /Y' disambiguation lines. Cut: redundant
trigger synonyms, header/engine enumerations, prose the model derives.
find-docs excluded (ctx7-owned, regen clobbers — LRN-086); doc + geo
taken instead. All ≤ ~505 chars body (BDR-014 aspirational ceiling).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:31:38 +02:00
Bastien ChanotandClaude Fable 5 a73dff4edf feat(settings): rtk-wrapped allowlist + .env deny mirrors (audit #11 companion)
The rtk hook no longer auto-allows (audit-bugs branch): rewritten
commands are evaluated natively. Allow rules match the original forms
(grep *, ls *) not the rewritten ones — without explicit rules every
rewrite would fall to the classifier. Added the read-only rtk-wrapped
family, bare + absolute-path forms (the hook emits absolute paths when
PATH lacks the cargo dir): grep, ls, cat, head, tail, wc, diff, git
status/log/diff/show/branch. NOT find (rtk find could carry -exec rm —
native find-deny rules would not match the rtk prefix).
Deny mirrors guard the bypass the allowlist would open on hand-written
'rtk cat .env'-class commands: cat/grep/head/tail × .env, both prefixes.
Residual: exotic quoting may evade the mirrors — second curtain stays
the auto-mode classifier (BDR-004).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:29:53 +02:00
Bastien ChanotandClaude Fable 5 731ed95c98 feat(rtk): drop auto-allow — permission control returns to settings.json
The exit-0 branch emitted permissionDecision:allow, making rtk's internal
Rust registry a PARALLEL permission authority: a rewritten command
bypassed settings.json deny/ask entirely (audit #11). Both rewrite paths
now emit updatedInput only; the rewritten command goes through native
evaluation. Companion allow rules for read-only 'rtk <tool>' forms land
in settings.json (audit-hardening branch) to keep the safe majority
frictionless. Re-pinned.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:28:31 +02:00
Bastien ChanotandClaude Fable 5 56bd5ff0c2 feat(tokens): pr-review-toolkit OFF by default — heaviest plugin, PR-only use
Measured: 6 agent descriptions = ~2.2k tokens injected EVERY session
(the single largest plugin contributor) for a toolkit useful only when
reviewing PRs. enabledPlugins → false; removed from full+backend
profiles (BDR-017 caveat already accepts full excluding rarely-used
items); audit.profile KEEPS it = profile reactivation channel.
Per-PR-session: claude plugin enable pr-review-toolkit@claude-code-plugins
(or bash lib/profile.sh apply audit); a later 'profile set full'
re-disables it via the MANAGED_PLUGINS lifecycle.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:17:55 +02:00
Bastien ChanotandClaude Fable 5 a0d092ca9f chore(make): declare onboard in .PHONY
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:16:36 +02:00
Bastien ChanotandClaude Fable 5 9e534241f9 feat(settings): deny-list hardening pass (audit #20)
- rm -r / rm -fr denied (only -rf was; flag-order variants passed).
- python3 -c / python -c ask → deny: aligned with node -e / perl -e /
  ruby -e (arbitrary-interpreter class was incoherently split).
- git push <remote> +<ref> denied (refspec force carried no flag).
- --force-with-lease un-over-blocked: --force* split into --force /
  --force *, so the safer variant now falls to the git push ASK gate.
Deny 99 → 105, ask 19 → 18. Second curtain unchanged (auto-mode
classifier, BDR-004). doctor's deny sentinel tracks HEAD (LOT 1).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:16:36 +02:00
Bastien ChanotandClaude Fable 5 45a387c1dd feat(update-all): bun self-upgrade + documented non-update exclusions
Step 6.5: bun upgrade (guarded). Deliberate exclusions documented in
place: magic MCP (npx @latest resolves at invocation), graphify claude
install (rewrites curated configs — BDR-028 territory, manual only),
gsd (lock-pinned: make update reinstalls the pin, note added to
plugins.lock.json so the no-op is explicit).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:16:36 +02:00
Bastien ChanotandClaude Fable 5 ed2408e742 fix(design-hook): tighten trigger regex — cut ultra-generic tokens
page/pages/form/menu/card/carte/style/look/screen/interface/color/shadow
fired on a large share of non-UI prompts (~200 tokens of reminder each;
measured 6 fires during a pure config audit, including on task
notifications). Specific compounds stay: formulaire, styling, stylesheet,
styliser, écran, couleur, palette… FR aesthetic words kept.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:16:16 +02:00
Bastien ChanotandClaude Fable 5 3a9b9e584d fix(install-plugins): gate success messages on real outcomes; drop plugin-dev
- gstack + graphify blocks printed unconditional ok after || warn —
  misleading-success (LRN-071 class). ok now gated on tracked outcome,
  loud warn otherwise.
- plugin-dev install dropped (audit #14): installed 2026-06-23, never
  enabled, pure disk weight; uninstalled from the machine, reinstall
  deliberately if plugin authoring becomes a need.
- Summary block truthfulness: header no longer claims 'start OFF' for
  plugins committed enabled; pr-review-toolkit token estimate ~300 →
  ~2.2k (measured, 6 agent descriptions); ui-ux ~400 → ~780 (measured);
  graphifyy row names the CLI (graphify).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:16:16 +02:00
Bastien ChanotandClaude Fable 5 6d72d0adc8 fix(session-start): truthful banner — derive ALWAYS_ON, label graphify, greedy split
- ALWAYS_ON derived from settings.json:enabledPlugins (true entries)
  minus toggle-owned names — the hardcoded pair under-reported newly
  enabled plugins (pr-review-toolkit enabled yet invisible). LRN-005.
- Display 'graphify' (the CLI/skill name); graphifyy stays the pipx
  package name everywhere it IS the package.
- Overflow split = greedy width-fill: the fixed 3-name cut overflowed
  line 1 and printed an empty line 2 with 3 long names.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:16:02 +02:00
Bastien ChanotandClaude Fable 5 cca43cbe5a chore(agents): remove stale tracked seo-analyzer.md.bak + ignore *.bak
Pre-split (SEO/GEO) backup, 1097 diff lines vs live agent — dead weight
committed by accident. *.bak now gitignored (Editors block).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:16:02 +02:00
Bastien ChanotandClaude Fable 5 ca8df16885 fix(doctor): kill 3 permanent false sentinels (LRN-047 class)
- EXPECTED_DENY hardcoded 100 vs 99 real → derive from committed
  settings.json (HEAD): auto-tracks legit deny edits, still flags
  live-vs-committed divergence.
- EXPECTED_SKILLS required gstack 'health' (OFF by default, profile-
  managed): false warn on a default install with a wrong remedy —
  link.sh cannot restore gstack skills. Dropped; 'status' kept (repo-
  owned personal skill, git ls-files proven).
- disable-model-invocation check required a key BDR-019 stripped
  repo-wide (2026-06-09) → warned on every owned skill since.
  Inverted into a BDR-019 regression watch.
- pass message derives the skill list from the array (LRN-005 class:
  no hardcoded display drift).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:07:40 +02:00
Bastien ChanotandClaude Fable 5 17fb6dda43 fix(tests): run-reconcile T6c — oracle pointed at the removed parasite dir
$MEM/../skills resolved to .claude/skills/ (the LRN-042 parasite, removed
2026-06-30 by make plugin Step 8.5), not the real skills/. Green at build
time only because the parasite still existed — green-for-wrong-reason
(LRN-077 class); red ever since. Suite back to 20/20.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:07:31 +02:00
Bastien ChanotandClaude Fable 5 8e61d03c43 fix(session-start): update-check reads origin/main — dead since master→main migration
git show origin/master:version.txt fatal-ed since the gitflow migration
(2026-06-29): the 'update available' banner could never fire while a
synchronous git fetch was still paid every session for a discarded result.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:07:29 +02:00
Bastien ChanotandClaude Fable 5 f0b7e89468 fix(rtk): rtk resolution + absolute-path rewrite — compression was silently dead
rtk lives at ~/.cargo/bin but the hand-managed .bashrc lost the cargo
line: command -v failed in hook AND tool shell, so the hook no-op'd with
a stderr warn on every Bash call — input compression silently OFF.

- Resolve RTK_BIN by probing known install dirs (LRN-036 class).
- Substitute the ABSOLUTE path at the rewrite head: a bare 'rtk …'
  exits 127 in the tool shell, whose PATH the hook cannot fix (proven).
- Compound rewrites carrying further bare rtk segments pass through
  unrewritten: quoted text (commit messages) makes a global substitution
  unsafe — lose compression, never emit a command that 127s (proven:
  a commit chain 127'd mid-flow).
- detect_rtk probes the same dirs so the banner reports capability.
- Re-pinned .rtk-hook.sha256: the rtk BINARY verifies the hook against
  it at execution time and refuses a modified hook — the pin is live
  machinery, not a vestige; coupling documented in the header.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
2026-07-02 14:07:22 +02:00
Bastien Chanot fe9fa86bb2 Merge chore/lrn-086-ctx7-provenance into develop 2026-07-02 13:23:08 +02:00
Bastien ChanotandClaude Opus 4.8 f5961cb8d6 chore(memory): LRN-086 — external-tool skill provenance + gitignore/regen rule
ctx7 setup --claude --cli materializes find-docs (skill, symlinked into repo)
+ rules/context7.md (global, user-editable). login != setup. Rule: prove
provenance by mtime not repo grep; gitignore tool-generated skill + regen via
install-step; guard regen on absence when tool co-writes editable config.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C8bmCXTHNccS7KRV4gWXEF
2026-07-02 13:22:59 +02:00
Bastien Chanot 41ee5c54bf Merge bugfix/ctx7-auth-guidance into develop 2026-07-02 13:11:00 +02:00
Bastien ChanotandClaude Opus 4.8 01d8b8f65c feat(install-plugins): interactive ctx7 login + auto-setup, ignore find-docs
STEP 6 ctx7 auth, when anonymous:
- interactive TTY -> prompt [y/N] then run `ctx7 login`; non-interactive
  (CI/headless/re-run) keeps text guidance, never opens a browser or blocks.
- run `ctx7 setup --claude --cli` when the find-docs skill is absent, to
  (re)install CLI+Skills mode. Guarded on absence so a re-run never clobbers
  a customized ~/.claude/rules/context7.md.

gitignore skills/find-docs/: it is a ctx7-managed skill materialized by
`ctx7 setup --claude --cli` into ~/.claude/skills (symlink to repo skills/),
re-created on demand by Step 6 — not vendored here.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C8bmCXTHNccS7KRV4gWXEF
2026-07-02 13:09:51 +02:00
Bastien ChanotandClaude Opus 4.8 9ee2e9407e fix(install-plugins): auth-aware ctx7 guidance + drop obsolete MCP nudge
Step 6 printed its ctx7 hints unconditionally — telling already-authed users
to log in, and pointing at `ctx7 setup --claude` (MCP-adjacent). Anonymous mode
is fully functional (docs + library work without auth); auth only buys rate
limits, so setup was never required for ctx7 to work.

- Detect auth via an offline oracle: credentials.json presence (XDG-aware),
  no subprocess / network / browser — mirrors the idempotent-claude fix.
- Authenticated -> "ctx7 authenticated"; anonymous -> non-blocking guidance
  (works anonymously; `ctx7 login`, `--no-browser` for headless). The installer
  guides, never launches login/setup.
- Drop `ctx7 setup --claude`: leftover reopening MCP path, aligns w/ TODO:48
  CLI-only decision.

Verified: bash -n, shellcheck (no new findings), + simulated both auth states
(credentials.json present/absent) — correct branch each, credentials restored.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
2026-07-01 23:36:21 +02:00
Bastien Chanot c816b11bc4 Merge chore/ecc-audit-bdr into develop 2026-07-01 22:55:08 +02:00
Bastien Chanot d2df514126 chore(memory): BDR-047 — ECC audit → zero import, config ahead of reference 2026-07-01 22:52:06 +02:00
Bastien Chanot d0ec54ee61 Merge chore/reconcile-todo-drift into develop 2026-07-01 21:18:23 +02:00
Bastien Chanot caf3d01487 Merge bugfix/install-plugins-npm-guard into develop 2026-07-01 21:18:22 +02:00
Bastien ChanotandClaude Opus 4.8 90dc7d854d chore(memory): capitalize reconcile session + (a) npm-guard fix
Session capture for the /reconcile pass + the BLK-013 fix-forward build:

- journal 2026-07-01: reconcile real-state (1 actionable / 3 upstream /
  3 deferred / release live), (c) TODO drift, (a) npm guard built.
- BLK-013: append Update — fix-forward now BUILT (1f2c1cc); was
  "script hardening NOT built". Now fully resolved (env + script).
- BLK-014 + BDR-046: append Update — MERGED 2393ca5, supersedes the
  stale "pending merge". Records that BDR-046 already settled the
  "canal d'install" question (native installer, no `elif npm` branch).

Append-only (Update blocks, last-block-wins) — no past entry rewritten;
verified reconcile_blk_open now returns only the true upstream trio.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
2026-07-01 21:18:16 +02:00
Bastien ChanotandClaude Opus 4.8 1f2c1cc6e7 fix(install-plugins): guarantee npm present, not just node>=22
BLK-013 fix-forward. Step 1 checked `node >=22` but never verified npm.
On a host where node was already recent, NODE_OK short-circuited the
installer and npm was never touched — yet GSD (gsd-pi) and ctx7 install
via `npm install -g`, so a missing npm made `make plugin` die Error 127
mid-run (distro `apt install nodejs` can ship npm as a separate package).

Add an unconditional npm guard right after the Node block:
corepack enable npm → distro package-manager install fallback → fatal
exit 1 with an actionable message if still absent. Happy path (npm
present) skips the whole block: zero behavior change on healthy machines.

shellcheck clean (only pre-existing SC1091 infos), bash -n OK. Fresh
npm-less apt host validation still pending. Closes TODO (a) 2026-06-30.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
2026-07-01 21:07:38 +02:00
Bastien ChanotandClaude Opus 4.8 9c024064bb chore(todo): reconcile --help chantier drift — 7 subtasks [ ]→[-]
/reconcile show-only surfaced 7 open [ ] boxes under the
`## Helper --help` section headed [WON'T-BUILD 2026-06-30]. The chantier
was killed (BDR-001 won't-build, measured non-rentable) but the build
subtasks stayed unchecked → naive `grep '[ ]'` counted them as open work.

Mark them [-] (cancelled) so declared state matches reality. The ⛔
WON'T-BUILD prose already frames them as "historique, non actionnables".
Naive open-count 10→3; survivors are genuine deferred-open (context-file
2e passage, zenquality cross-repo, install-plugins npm harden).

Registries left untouched (reconcile is read-only there; BLK-014/BDR-046
"pending merge" staleness is a /prune-memory concern, not this).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VeBXkDr74N9whdiJyjzyVN
2026-07-01 20:51:15 +02:00
Bastien Chanot 2393ca536c Merge bugfix/install-claude-idempotent into develop 2026-07-01 20:20:00 +02:00
Bastien ChanotandClaude 020737de57 chore(memory): BDR-046 — Claude Code via official native installer, drop npm
Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-01 20:14:56 +02:00
Bastien ChanotandClaude 6be627e246 fix(install): install Claude Code via official native installer, not npm
Uniformizes point 1: install.sh fresh-machine branch used npm, but npm
is no longer a documented Claude Code channel (official quickstart lists
Native/Homebrew/WinGet/apt only) and collides with the native symlink.
Switch the fresh-install path to the recommended native installer,
matching install-plugins.sh which already points to the native channel.

- install.sh: fresh install via `curl -fsSL https://claude.ai/install.sh
  | bash`; ensure ~/.local/bin on PATH for the auth/verify steps.
- skip-if-present guard unchanged.
- fix stale node/npm prerequisite comment (npm now serves the plugins
  step, not the Claude Code install).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-01 16:33:02 +02:00
Bastien ChanotandClaude 01f9ebb57b chore(memory): BLK-014 + LRN-085 — install.sh idempotent claude install/update
Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-01 16:10:59 +02:00
Bastien ChanotandClaude 8dc4027c4b fix(install): make Claude Code install/update idempotent across channels
install.sh aborted with npm EEXIST when claude was already present:
the binary is a native-installer symlink (~/.local/bin/claude ->
~/.local/share/claude/versions/*) that npm does not own, and the
npm prefix (~/.local, set for BLK-013) targets the same path. The
`else err` branch turned EEXIST into a fatal exit. No presence guard
existed, unlike the RTK/GSD steps.

- install.sh: skip-if-present guard (command -v claude), mirroring
  the RTK/GSD pattern; npm only runs on a truly fresh machine.
- update-all.sh: pick updater by channel — npm for npm-managed
  installs, `claude update` for native installs (npm would EEXIST).

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-01 16:07:13 +02:00
Bastien Chanot 2d76233b02 Merge feature/doc-sync into develop 2026-07-01 14:31:38 +02:00
Bastien ChanotandClaude Opus 4.8 8ca1bb7bab docs: +/gitflow /release-candidate /deploy /reconcile /pdf-translate
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RNaYKPEkjH1jbgoX1TwKMX
2026-07-01 14:31:38 +02:00
Bastien Chanot 0a2e832a66 Merge feature/gitflow-aiguillage-standalone into develop 2026-07-01 14:28:10 +02:00
Bastien ChanotandClaude Opus 4.8 8f001ec868 chore(memory): BDR-045 + LRN-084 + LRN-034 corrob — capitalize gitflow aiguillage-standalone
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RNaYKPEkjH1jbgoX1TwKMX
2026-07-01 14:04:15 +02:00
Bastien ChanotandClaude Opus 4.8 e8807a7333 feat(gitflow): chore branch type + aiguillage for standalone memory/doc skills
Standalone /capitalize /close /prune-memory /reconcile no longer lean on the .claude/** hook exemption when run on main/develop: the aiguillage branches them to chore/* off develop before writing. New chore type (base develop, finish->develop) added to the lib; hook unchanged (chore/* non-protected). Closes the leak where standalone memory work (memory IS the work, no code branch to follow) landed direct on a protected base. 64/64 gitflow-test green, shellcheck clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RNaYKPEkjH1jbgoX1TwKMX
2026-07-01 13:25:36 +02:00
Bastien ChanotandClaude Opus 4.8 53bd7beee8 chore(memory): BDR-044 + LRN-083 + auto-skill-dispatch won't-build — capitalize
BDR-044: auto-skill-dispatch chantier retired won't-build — 3rd measured moot
of the session (after --help, darwin re-baseline). Cartography showed L1
(superpowers "1%->MUST invoke") already over-determines routing -> reframed
from "does it route" (yes) to DISCERNMENT; risk inverted under->over. Measured
in real fresh sessions (8 prompts/3 classes): clear->route, ambiguous->ask,
trivial->abstain — model discriminates, no over-routing. Adding L2 prose =
phantom value + degradation risk. LRN-083: subagents are an invalid instrument
for measuring main-loop spontaneous routing (SUBAGENT-STOP + delegated framing
pin to the no-route floor) — retired the 0/6 subagent RED. LRN-080 corroborated
(3-in-a-row). TODO -> won't-build. Claude composed all -> trailers (4th
application of LRN-081).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017KWG7sXg94LXX1gddCGBvM
2026-06-30 20:04:30 +02:00
Bastien ChanotandClaude Opus 4.8 efe33b76c5 chore(memory): LRN-081 correction — helper is trailer-agnostic
Append-only correction bullet to LRN-081: memory-commit.sh does NOT append
trailers (git commit -m verbatim, memory-commit.sh:86, no hook/template);
trailers are model-composed message content; control point = the MESSAGE, not
the helper. Proven by 532ae69 (bare msg → no trailers) → c09f2b2 (amended).
Phrasing cleanup of the false wording (body + Index cell) deferred to
/prune-memory. Claude-composed → trailers (LRN-081 rule, 3rd application).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017KWG7sXg94LXX1gddCGBvM
2026-06-30 18:43:54 +02:00
Bastien ChanotandClaude Opus 4.8 c09f2b2630 chore(memory): LRN-082 + TODO(b) moot — capitalize
LRN-082: a trigger-cleared on a multi-motif exclusion lifts only the named
motif. BDR-043 cleared BDR-015's broken-symlink ground (a) but not its
external-ownership ground (b) → the darwin re-baseline is phantom value
(would edit the gstack submodule, LRN-070; results.tsv gone anyway). TODO (b)
resolved-MOOT (not done, not open). Trailers present: Claude composed LRN-082
+ the moot note — LRN-081's own rule, 2nd application.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017KWG7sXg94LXX1gddCGBvM
2026-06-30 18:38:50 +02:00
Bastien ChanotandClaude Opus 4.8 5d348a711f chore(memory): LRN-081 + TODO reconcile — close ritual
LRN-081: Claude commit trailers only on Claude-COMPOSED content; a commit merely staging user-authored text gets none (staging != authorship). TODO reconcile: checked L26 'Cleanup machine courante' DONE (make plugin EXIT=0 this session ran Step 8.5, fs-verified strays absent); added (a) harden install-plugins.sh Step 1 npm-via-corepack (BLK-013 fix-forward) + (b) darwin re-baseline of the 5 ex-broken skills (BDR-043). Trailers present here because Claude composed the LRN + TODO formulations (LRN-081's own rule) — unlike e591510 which staged raw user text.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C6bUdvHnajCNzgVQefZowj
2026-06-30 18:08:12 +02:00
Bastien ChanotandClaude Opus 4.8 437697e961 chore(memory): EVAL-013 — /reconcile real-usage value proven (usage vs build)
Capitalize the /reconcile dogfood on fresh live drift. Distinct from EVAL-011
(BUILD: fixture RED/GREEN + self-dogfood) — EVAL-013 = USAGE on real repo,
proving 2 things the build eval did not: (a) finds UNANTICIPATED gaps (3 stale
[branch …] headers = header-marker drift class beyond checkbox drift), (b) rejects
a FALSE POSITIVE off-fixture (--help candidate, both WON'T-BUILD → aligned).
'this run' wording kept — value proven, not zero-false-positive guaranteed
(consistent with the skill's engraved honest-limits). action keep.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017KWG7sXg94LXX1gddCGBvM
2026-06-30 17:49:01 +02:00
Bastien ChanotandClaude Opus 4.8 09200c5274 chore(memory): reconcile TODO — /release-candidate QUEUED→SHIPPED + 3 [branch] headers→DONE
/reconcile dogfood on a fresh declared↔real gap. Oracle-proven requalifications:
- /release-candidate: QUEUED→SHIPPED (SKILL.md d3d6ced, merged 0c0b748, released
  v4.0.0/tag v4.0.0); 4 subtasks [ ]→[x] (tag/SKILL.md/routing/test=real 4.0.0 fan-out).
- 3 stale [branch …] headers (minor-gate, blk-011-gsd, prune-memory-hardening)
  →[DONE]: all merged to develop + branches deleted (merge_done=YES).
Bodies left intact (historical 'why'). Registries untouched (read-only per skill).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017KWG7sXg94LXX1gddCGBvM
2026-06-30 17:43:22 +02:00
Bastien Chanot e591510160 chore(todo): queue auto-skill-dispatch chantier (NEXT, measure-first)
Append the "Auto-déclenchement des skills par intention" chantier to TODO.md as NEXT — measure-first (twin of BDR-001 --help): behavioral RED before any design, scope bounded to clear/unambiguous intent signals. Design opens only if the RED proves value.
2026-06-30 17:20:26 +02:00
Bastien ChanotandClaude Opus 4.8 5b03ac28a2 chore(memory): BLK-013 + BDR-043 — capitalize (make-plugin npm blocker + BDR-015 darwin re-baseline requalif)
Capitalized from 2 code vérifs (subagents, no-memory) + the make plugin fix:
- BLK-013: make plugin Error 127 — apt `nodejs` ships node WITHOUT npm; Step 1
  checks node>=22 but never npm. Fixed via corepack (npm 11.18.0 → ~/.local/bin,
  prefix ~/.local), EXIT=0, Step 4 ✓, Step 8.5 stray-dir residual cleanup
  (BDR-030/LRN-042) finally ran. Fix-forward: Step 1 should guarantee npm via
  corepack on apt-nodejs hosts.
- BDR-043: BDR-015 trigger cleared — its 5 broken gstack symlinks repaired
  (0 broken / 83 today, gstack now ships those skills); darwin re-baseline
  UNBLOCKED, NOT run. Kept distinct from BLK-007/f928a53 (iOS episode).
- ③ doc-commit branch-guard requalif DROPPED (already graved BDR-040/TODO:292);
  only the new whitelist-replication nuance logged in journal.

TODO.md planning note left uncommitted (user's WIP, separate scope).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C6bUdvHnajCNzgVQefZowj
2026-06-30 17:08:06 +02:00
Bastien ChanotandClaude Opus 4.8 c3ba540372 chore(memory): BDR-001 won't-build + LRN-080 + TODO requalify (--help measured non-rentable)
--help chantier ABANDONED after measurement (not built — nothing to build):
- BDR-001 append (won't-build 2026-06-30): behavioral RED, 6 reps (/web-validate
  + /harden, no instruction) → 6/6 already render help AND stop without dispatch;
  residual value = format consistency only → ROI insufficient on a solo repo.
  Original Decision/Why/Rejected intact (append-only); Index status cell updated.
- LRN-080: measure if the model already does X before adding an instruction to
  make it do X — the behavioral RED kills phantom-value additions. Links LRN-075.
- TODO: chantier requalified WON'T-BUILD (3rd state — not done, not open).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C6bUdvHnajCNzgVQefZowj
2026-06-30 16:27:04 +02:00
Bastien Chanot 4a00a60494 Merge release/4.0.0 into develop 2026-06-30 15:33:23 +02:00