From a29ee9dd3318103fe58403c78bdad96df0173f0f Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Tue, 6 Oct 2026 13:52:28 +0200 Subject: [PATCH] Decisions 149-150 recorded; instruction files kept true; R-890, R-891, R-644 closed, R-469 narrowed (142 -> 139) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Decision 150 (operator 13:25): sessions correct stale facts in instruction files themselves, naming each edit; never loosen a rule. Added to unprompted-work.md §5 (all copies) and PROMPT-TEMPLATE.md §9. CLAUDE.md gates paragraph (R-891), architecture pointer, docs/website rules, the doubled R-286 sentence in the workspace CLAUDE.md. Decision 149: vaultwarden's step proven on bench 9401 and box 9202 (evidence here). Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- .claude/rules/docs.md | 2 +- .claude/rules/unprompted-work.md | 13 +- .claude/rules/website.md | 4 +- CLAUDE.md | 14 +- CONTEXT.md | 9 + documentation/PROMPT-TEMPLATE.md | 7 + .../architecture/09-update-architecture.md | 14 + .../C/R-644-9202-live.txt | 11 + .../r890-instructions-2026-10-06/README.md | 23 + .../bench/R890-vw.log | 115 +++ .../evidence/MV-vaultwarden/abort-states.json | 8 + .../evidence/MV-vaultwarden/compose-final.log | 26 + .../evidence/MV-vaultwarden/engine-state.json | 1 + .../MV-vaultwarden/files-after-detail.json | 1 + .../evidence/MV-vaultwarden/files-after.json | 1 + .../MV-vaultwarden/files-before-detail.json | 1 + .../evidence/MV-vaultwarden/files-before.json | 1 + .../MV-vaultwarden/memory-samples.json | 682 ++++++++++++++++++ .../MV-vaultwarden/migration-lines.txt | 0 .../bench/evidence/MV-vaultwarden/run.log | 61 ++ .../bench/evidence/MV-vaultwarden/to-full.log | 18 + .../evidence/MV-vaultwarden/to-states.json | 8 + .../evidence/MV-vaultwarden/verdict.json | 54 ++ .../box/C1-repoint-drill.txt | 2 + .../vaultwarden/box-verdict-vaultwarden.json | 18 + .../box/vaultwarden/step.txt | 37 + .../tools/repoint.py | 37 + .../tools/vwstep.py | 76 ++ documentation/backlog/CLOSED-ITEMS.md | 10 + documentation/backlog/OPEN-ITEMS.md | 5 +- documentation/runbooks/workspace-CLAUDE.md | 3 - 31 files changed, 1244 insertions(+), 18 deletions(-) create mode 100644 documentation/audits/r890-instructions-2026-10-06/C/R-644-9202-live.txt create mode 100644 documentation/audits/r890-instructions-2026-10-06/README.md create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/R890-vw.log create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/abort-states.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/compose-final.log create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/engine-state.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/files-after-detail.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/files-after.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/files-before-detail.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/files-before.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/memory-samples.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/migration-lines.txt create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/run.log create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/to-full.log create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/to-states.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/bench/evidence/MV-vaultwarden/verdict.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/box/C1-repoint-drill.txt create mode 100644 documentation/audits/r890-instructions-2026-10-06/box/vaultwarden/box-verdict-vaultwarden.json create mode 100644 documentation/audits/r890-instructions-2026-10-06/box/vaultwarden/step.txt create mode 100644 documentation/audits/r890-instructions-2026-10-06/tools/repoint.py create mode 100644 documentation/audits/r890-instructions-2026-10-06/tools/vwstep.py diff --git a/.claude/rules/docs.md b/.claude/rules/docs.md index a3bdb7cc..a555ec08 100644 --- a/.claude/rules/docs.md +++ b/.claude/rules/docs.md @@ -11,7 +11,7 @@ repo. Sibling repos point here; this is where the pointed-at thing must actually | Fact | Home | |---|---| -| the locked design | `architecture/01..05-*.md` | +| the locked design | `architecture/01..11-*.md` | | capability status + its evidence | `architecture/00-capability-map.md` | | host addresses, routes, node names, break-glass, what is provisioned | `operations/nodes.md` | | Tailscale topology, accept-dns/accept-routes | `operations/tailscale.md` | diff --git a/.claude/rules/unprompted-work.md b/.claude/rules/unprompted-work.md index d7a83c5b..49df8ff8 100644 --- a/.claude/rules/unprompted-work.md +++ b/.claude/rules/unprompted-work.md @@ -6,7 +6,8 @@ unconditional: true > Goal sessions, nightly sessions, "work the register" sessions. **A session that starts from > `/goal` or a standing brief inherits these rules exactly as it inherits the gates.** They are the > part of `PROMPT-TEMPLATE.md` that a task file used to carry and a goal does not. Same wording lives -> in all three repos' `.claude/rules/`; change it in all three or in none. +> in `felhom.eu`, `felhom-controller` and `app-catalog-felhom.eu` `.claude/rules/`, and in the workspace root's +> unversioned `.claude/rules/`; change all four or none. ## 1. What you may pick up on your own @@ -56,3 +57,13 @@ One screen, plain language, in this order: **decisions you took** (§2) first; w what broke and whether you fixed it; rows opened and closed with the register size before and after; what needs the operator, each with what happens if they do nothing. No file paths, no function names, no row numbers as the subject of a sentence. + +## 5. Instruction files + +**Instruction files (`CLAUDE.md`, `.claude/rules/*`) are kept true by the session that finds them wrong** +(operator ruling 2026-10-06, `09` §3 decision 150). A session MAY, without asking: correct a stale fact (a command, a +count, a version, a path, a description of what a gate does), add a fact it proved, and remove a reference to something +that no longer exists. Each edit is named in the report (file, line, before, after, why). A session MAY NOT, without the +operator's word: loosen a safety rule, a fence, a „never", a protected machine, a secret rule, or a review step; or +remove a rule. When in doubt, it is a rule change, and it goes to the operator. If Claude Code's own permission check +asks before such an edit, wait for the operator's click; if it refuses, record that and file the exact line. diff --git a/.claude/rules/website.md b/.claude/rules/website.md index 789fa39c..9664e233 100644 --- a/.claude/rules/website.md +++ b/.claude/rules/website.md @@ -18,8 +18,8 @@ tag-based publishing is a separate mechanism — see the R-110 fence in the repo Website changes go through `python3 scripts/repo_gates.py`, which runs `site_gates.py`. **A new page must be added to that gate's `PAGES` list** or it is unchecked. -`site_gates.py` asserts: BOM, emoji, nav/footer consistency, analytics, CDN, design tokens, and -cache-busting. +`site_gates.py` asserts: BOM, emoji, nav/footer consistency, analytics, CDN, design tokens, no +embedded `