From 3e8ebeb96c59d9c01f82633a2ecdfbb5465c9f0d Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Tue, 6 Oct 2026 13:43:57 +0200 Subject: [PATCH] =?UTF-8?q?Instruction=20files=20kept=20true=20(09=20?= =?UTF-8?q?=C2=A73=20decision=20150):=20stale=20gate=20lists,=20paths=20an?= =?UTF-8?q?d=20facts=20corrected;=20no=20code=20change?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- .claude/rules/health-checks.md | 5 +++-- CHANGELOG.md | 6 ++++++ CLAUDE.md | 14 +++++++------- REPORT.md | 19 ++++++++----------- 4 files changed, 24 insertions(+), 20 deletions(-) diff --git a/.claude/rules/health-checks.md b/.claude/rules/health-checks.md index 45df350..180f9d7 100644 --- a/.claude/rules/health-checks.md +++ b/.claude/rules/health-checks.md @@ -21,6 +21,7 @@ fast, and wrong. This rule used to be duplicated verbatim in felhom-agent/CLAUDE.md with a note explaining that felhom.eu/CLAUDE.md "does not load in an agent-only session". That reasoning was correct before -path-scoped rules existed. The single source is now felhom.eu/CLAUDE.md "Code quality rules"; this -file is the scoped copy that loads exactly where health checks are written. (2026-08-06) +path-scoped rules existed. Deliberate scoped copies now live in felhom.eu/.claude/rules/hub.md and +felhom-controller/.claude/rules/gates.md (hub.md's comment names them); none is the single source. This +file is the copy that loads exactly where agent health checks are written. (2026-08-06; corrected 2026-10-06) --> diff --git a/CHANGELOG.md b/CHANGELOG.md index 9ce9eec..cda105d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,9 @@ +## Unreleased (2026-10-06 afternoon) — instruction files kept true (`09` §3 decision 150); no code change + +- `CLAUDE.md` „Gates — ONE entry point": the runner runs every gate in its `GATES` table (five: three shared, `published`, `release-complete`); `--fast` skips `published` (network). It said two gates and „all of them". +- `CLAUDE.md`: the decoy gate and its audit are named with their `felhom.eu/` prefix (they do not exist in this repo). +- `.claude/rules/health-checks.md` (comment): the health-check rule's copies live in felhom.eu `hub.md` and the controller's `gates.md`; it named felhom.eu `CLAUDE.md` „Code quality rules", which holds no such rule. + ## v0.149.0 — a weekly disk trim of each customer guest, the crash-boot fact for the controller, the phantom WARN names its runbook (R-444, R-856, R-99; operator rulings `09` §3 139, 143, 140) (2026-10-06) Released by `scripts/release-agent.sh`: binary sha256 `6bcae9c2eb5d97e8285316583870059835793893299e291891a53a4ce505585f` diff --git a/CLAUDE.md b/CLAUDE.md index 742f90d..adca3fe 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -52,11 +52,11 @@ This is in the core because breaching it is how this component stops being audit ## Gates — ONE entry point -**Run `python3 scripts/agent_gates.py` from the repo root after ANY change here.** It runs this -repo's gates — `reuse_refs_check` and `instructions_gate`, both the **shared** copies in -`felhom.eu/scripts/`, never copied into this repo (a copy recreates the drift they detect; an absent -sibling clone FAILS). `--fast` selects the gates touching no network and no container runtime; today -that is all of them. **A missing gate is a FAILURE, never a skip.** +**Run `python3 scripts/agent_gates.py` from the repo root after ANY change here.** It runs every +gate in its `GATES` table (that table is the list); the shared ones — `reuse_refs_check`, +`instructions_gate`, `observations_gate` — are the copies in `felhom.eu/scripts/`, never copied into +this repo (a copy recreates the drift they detect; an absent sibling clone FAILS). `--fast` selects the +gates touching no network and no container runtime, and skips `published` (network), naming it. **A missing gate is a FAILURE, never a skip.** **The pre-push hook** (`.githooks/pre-push`) runs it with `--fast` and refuses a failing push. It is **per-clone** — switch it on once with `git config core.hooksPath .githooks`, and a manual run WARNS @@ -104,8 +104,8 @@ the mechanism are exempt. **A gate ships with a decoy test that has been seen to fail (R-421).** A decoy is the LABEL without the FACT — a directory with the right name and no bake log, a note whose prose mentions the marker it -lacks. `scripts/decoy_coverage_gate.py` refuses a new gate that has neither a decoy nor a named +lacks. `felhom.eu/scripts/decoy_coverage_gate.py` (run by felhom.eu's `repo_gates.py`, for all four repos) refuses a new gate that has neither a decoy nor a named exemption carrying its row. The four shapes, the 2026-09-01 sweep that fooled 16 of 29 gates, and the -decoys withdrawn as illegitimate: `documentation/audits/AUDIT-gate-decoys-2026-09-01.md` and +decoys withdrawn as illegitimate: `felhom.eu/documentation/audits/AUDIT-gate-decoys-2026-09-01.md` and `felhom-controller/.claude/rules/gates.md`. **Scope is a fact too** — prefer `os.walk` over `os.listdir`, and a glob over a hand-maintained list. diff --git a/REPORT.md b/REPORT.md index 15176d5..98cb2aa 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,13 +1,10 @@ -# REPORT — agent v0.149.0 (2026-10-06, the operator's ten answers) +# REPORT — instruction files kept true (2026-10-06 afternoon) -Full session report: `felhom.eu/REPORT.md`. Baseline `37e98f4` (v0.148.0). +Operator ruling 2026-10-06 13:25 (`09` §3 decision 150): a session corrects a stale fact in an instruction file +itself and names the edit; it may not loosen a rule. No code changed in this repo. The full session report, with every +instruction-file edit (file, before, after, why), is `felhom.eu/REPORT.md`. -- **R-444** (`09` §3 decision 139): a weekly `pct fstrim` of each running customer guest, daytime only (due Wednesday from - 10:00; never 01:00–06:59), under the one-heavy-op gate, logged, persisted, reported as `guest_disk_trim`; ONE exact sudo - rule `FELHOM_FSTRIM` in the bundle. Measured by hand on demo-hp first: 24 s, thin pool 65.5 % → 33.4 %, app probes all 200. -- **R-856** (decision 143): `GET /host/crash-guard` for the controller. -- **R-99** (decision 140): the phantom WARN names `runbooks/pbs-phantom-cleanup.md`. - -Released v0.149.0 (tag = `f277e61`, sha `6bcae9c2…`, bundle `e182c82d…`), vouched, signed `agent_update` + `agent_config_update` -to demo-hp, demo-felhom, Tester 1. Read back: all three on 0.149.0; the bundle installed on demo-hp (self-check 68/68) and -demo-felhom; `sudo -l` on both: `pct fstrim 9201` allowed, every decoy refused. Tester 2: nothing sent. +Edits here: +- `CLAUDE.md` „Gates — ONE entry point": before „It runs this repo's gates — `reuse_refs_check` and `instructions_gate` … today that is all of them"; after: every gate in `GATES` (five), `--fast` skips `published`. Why: `scripts/agent_gates.py` registers five, `published` is not fast. +- `CLAUDE.md` decoy paragraph: `scripts/decoy_coverage_gate.py` and `documentation/audits/AUDIT-gate-decoys-2026-09-01.md` gained the `felhom.eu/` prefix. Why: neither exists in this repo. +- `.claude/rules/health-checks.md` (HTML comment): „The single source is now felhom.eu/CLAUDE.md 'Code quality rules'" → the copies are felhom.eu `hub.md` and the controller's `gates.md`. Why: that section holds no health-check rule.