Instruction files kept true (09 §3 decision 150): stale gate lists, paths and facts corrected; no code change
gates / gates (push) Successful in 52s
gates / gates (push) Successful in 52s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
+10
-10
@@ -6,17 +6,17 @@ paths: ["controller/**/*.go", "controller/**/*.html", "controller/**/*.css", "co
|
||||
|
||||
## The ONE entry point
|
||||
|
||||
**Run `python3 controller/scripts/controller_gates.py` (from `controller/`) after ANY change in this
|
||||
repo.** It runs the local gates — `template_id_gate`, `emoji_gate`, `native_confirm_gate`,
|
||||
`offbox_rename_gate`, `app_row_dedup_gate`, `mojibake_gate`, `docker_run_volume_path_gate`,
|
||||
`secret_in_markup_gate`, `retrieval_promise_gate`, `debug_route_gate` — plus `reuse_refs_check`,
|
||||
`instructions_gate` and `observations_gate` on the repo root, streaming each gate's own output and
|
||||
exiting non-zero if any fails. **The runner's `GATES` table is the list; this sentence is a pointer to
|
||||
it, not a second copy** — it has already drifted once (it said "seven" while nine were registered).
|
||||
**Run `python3 scripts/controller_gates.py` from `controller/` (or `python3
|
||||
controller/scripts/controller_gates.py` from the repo root) after ANY change in this repo.** It runs
|
||||
every gate in the runner's `GATES` table, the shared `reuse_refs_check`, `instructions_gate` and
|
||||
`observations_gate` among them, streaming each gate's own output and exiting non-zero if any fails;
|
||||
one, `golden-notice`, is ADVISORY and never refuses. **The `GATES` table is the list; this sentence is a
|
||||
pointer to it, not a second copy** — it drifted twice (it said "seven" while nine were registered, then
|
||||
named ten local gates while fourteen were).
|
||||
|
||||
- `--fast` selects the gates that touch no network and no container runtime; today that is all of them.
|
||||
- **A missing gate script is a FAILURE, never a skip.**
|
||||
- **The shared `reuse_refs_check.py` and `instructions_gate.py` live in `felhom.eu/scripts/` and are
|
||||
- **The shared `reuse_refs_check.py`, `instructions_gate.py` and `observations_gate.py` live in `felhom.eu/scripts/` and are
|
||||
never copied here** — a copy would recreate the drift they detect; an absent sibling clone FAILS.
|
||||
- **The pre-push hook** (`.githooks/pre-push`) runs it with `--fast` and refuses a failing push. It is
|
||||
per-clone — switch it on once with `git config core.hooksPath .githooks`, and a manual run WARNS
|
||||
@@ -59,7 +59,7 @@ fast, and wrong.
|
||||
|
||||
**A decoy is the LABEL without the FACT** — a directory with the right name and no bake log, a
|
||||
handler case that exists only in a comment, a note whose prose mentions the marker it lacks. Write
|
||||
one for every new gate, run it, and watch it convict. `scripts/decoy_coverage_gate.py` refuses a gate
|
||||
one for every new gate, run it, and watch it convict. `felhom.eu/scripts/decoy_coverage_gate.py` (run by felhom.eu's `repo_gates.py`, for all four repos) refuses a gate
|
||||
registered without one, or without a named exemption carrying its row.
|
||||
|
||||
**Earned by five instances, every one found by accident:** R-410, R-400, R-378, R-419, R-94. The
|
||||
@@ -75,4 +75,4 @@ green and correct today, blind the moment anyone adds a subdirectory. Prefer `os
|
||||
glob over a hand-maintained list of files.
|
||||
|
||||
**A decoy nobody would write proves nothing** — say the gate is sound and move on. Five of mine were
|
||||
withdrawn as illegitimate and are named in `documentation/audits/AUDIT-gate-decoys-2026-09-01.md`.
|
||||
withdrawn as illegitimate and are named in `felhom.eu/documentation/audits/AUDIT-gate-decoys-2026-09-01.md`.
|
||||
|
||||
@@ -6,7 +6,8 @@ unconditional: true
|
||||
> Goal sessions, nightly sessions, "work the register" sessions. **A session that starts from
|
||||
> `/goal` or a standing brief inherits these rules exactly as it inherits the gates.** They are the
|
||||
> part of `PROMPT-TEMPLATE.md` that a task file used to carry and a goal does not. Same wording lives
|
||||
> in all three repos' `.claude/rules/`; change it in all three or in none.
|
||||
> in `felhom.eu`, `felhom-controller` and `app-catalog-felhom.eu` `.claude/rules/`, and in the workspace root's
|
||||
> unversioned `.claude/rules/`; change all four or none.
|
||||
|
||||
## 1. What you may pick up on your own
|
||||
|
||||
@@ -56,3 +57,13 @@ One screen, plain language, in this order: **decisions you took** (§2) first; w
|
||||
what broke and whether you fixed it; rows opened and closed with the register size before and after;
|
||||
what needs the operator, each with what happens if they do nothing. No file paths, no function
|
||||
names, no row numbers as the subject of a sentence.
|
||||
|
||||
## 5. Instruction files
|
||||
|
||||
**Instruction files (`CLAUDE.md`, `.claude/rules/*`) are kept true by the session that finds them wrong**
|
||||
(operator ruling 2026-10-06, `09` §3 decision 150). A session MAY, without asking: correct a stale fact (a command, a
|
||||
count, a version, a path, a description of what a gate does), add a fact it proved, and remove a reference to something
|
||||
that no longer exists. Each edit is named in the report (file, line, before, after, why). A session MAY NOT, without the
|
||||
operator's word: loosen a safety rule, a fence, a „never", a protected machine, a secret rule, or a review step; or
|
||||
remove a rule. When in doubt, it is a rule change, and it goes to the operator. If Claude Code's own permission check
|
||||
asks before such an edit, wait for the operator's click; if it refuses, record that and file the exact line.
|
||||
|
||||
Reference in New Issue
Block a user