Skip to content

fix(toolkit): one Git policy, build-loop laws, read-only reviewer, anchored merge guard (gh-#753, #754, #755) - #762

Merged
genwave-radio merged 1 commit into
mainfrom
fix/toolkit-git-policy-loop-laws-753-755
Sep 13, 2026
Merged

genwave-radio merged 1 commit into
mainfrom
fix/toolkit-git-policy-loop-laws-753-755

Conversation

@genwave-radio

Copy link
Copy Markdown
Collaborator

🔧 What

gh-#753 Git policy — git-workflow/SKILL.md rewritten as the single policy: GitHub + gh, gh-#N refs, branches only (no trunk lane), explicit git add, no Co-Authored-By/session trailers, merge/tag/release/push-main reserved for Dean. git-commit, quick-fix, build-loop, README now defer to it. Gitea, genwave-2.0 tag, -am, hardcoded co-author all gone.

gh-#754 build-loop laws — preflight green baseline on the full solution (MaxParallelThreads=3 note); brief laws (quote don't paraphrase, verify every citation, name the full test command); three-FAIL circuit breaker that stops and reports to Dean; PASS-WITH-NOTES handled by the orchestrator without a build round; smoke teardown by port + next build restore + If-Match; pending: T<n> grep and no Assert.Fail stubs before ticking; explicit staging; scratch excludes; git worktree prune at finish.

gh-#755 reviewer — disallowedTools: Write, Edit, NotebookEdit; honest wording (Bash is read-only by rule, tree writes are a self-FAIL); verdict scale PASS | PASS-WITH-NOTES | FAIL; full-solution rule; cite-and-quote rule.

gh-#751 follow-up — merge guard moved to .claude/hooks/merge-guard.sh; matches the leading verb of each ; && || | segment. Blocks gh pr merge, gh release create, git tag <name>, git push --tags, push to main/:main/refs/heads/main, --delete. Allows git tag -l/--list/--contains, pushes to other branches, and any grep/echo/sed that merely mentions those strings. 22 cases tested.

🧪 How to verify

  • echo '{"tool_input":{"command":"gh pr merge 1"}}' | .claude/hooks/merge-guard.sh; echo $? → 2
  • echo '{"tool_input":{"command":"grep -rn \"git tag\" docs/"}}' | .claude/hooks/merge-guard.sh; echo $? → 0
  • Read build-loop.md steps 1, 3, 5, 6

⚠️ Risk / rollback

Prompt + hook text only; no product code. Low, git revert.

Closes #753
Closes #754
Closes #755

…chored merge guard (gh-#753, gh-#754, gh-#755)

gh-#753: git-workflow is now the single Git policy (GitHub + gh, branches
only, explicit staging, no trailers, merge/tag/release = Dean). git-commit,
quick-fix, build-loop and the README reference it instead of restating a
Gitea-era trunk lane with -am and a hardcoded co-author.

gh-#754: build-loop carries the laws learned across fifteen epics: green
full-solution baseline in preflight, quote-don't-paraphrase briefs with
verified citations, a three-FAIL circuit breaker that stops and reports,
PASS-WITH-NOTES so comment-only findings never cost a build round, smoke
teardown by port, next-build file restore, pending-spec grep before
ticking, explicit git add, scratch excludes, worktree prune at finish.

gh-#755: reviewer disallows Write/Edit/NotebookEdit and says honestly
that Bash is read-only by rule, with tree-writing commands a self-FAIL.
Verdict scale gains PASS-WITH-NOTES; full-solution test rule added.

gh-#751 follow-up: the merge guard moves to .claude/hooks/merge-guard.sh
and matches the leading verb of each command segment, so grep/echo/sed
that mention "git tag" or a `git pull origin main` after a branch push
no longer trip it. 22 cases tested.

Refs gh-#753, gh-#754, gh-#755, gh-#751
@genwave-radio
genwave-radio merged commit b165b78 into main Sep 13, 2026
11 checks passed
@genwave-radio
genwave-radio deleted the fix/toolkit-git-policy-loop-laws-753-755 branch September 13, 2026 17:43
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 13, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

1 participant