Merge pull request #376 from AIOSAI/system/devpulse-docs-drill-main-only-git-rule-into-global-prompt-c

feat(system): docs: drill main-only git rule into global prompt, CLAUDE.md, devpulse local prompt (S101 fix)
This commit is contained in:
AIPass
2026-04-21 08:41:05 -07:00
committed by GitHub
5 changed files with 56 additions and 2 deletions
+33
View File
@@ -46,6 +46,39 @@ Secrets live outside the repo at `~/.secrets/aipass/` — API keys, tokens, cred
- `drone systems` — list all registered branches
- `drone --help` — full drone reference
# Git — Always on Main
**ONE rule: every agent works on `main`. No exceptions.**
You do not create branches. You do not `git checkout -b`. You do not tell another agent to "create a branch first." Branches only exist during the atomic window inside `drone @git system-pr` which: commits → creates branch → pushes → opens PR → **returns HEAD to main**. That command owns the branch lifecycle end to end. You own nothing about branches.
Workflow:
1. You're on main. Always.
2. Make edits directly on main.
3. When the work is ready to ship: `drone @git system-pr "description"`.
4. That command commits + branches + pushes + PRs + returns you to main. One action.
5. Devpulse reviews + merges with `drone @git merge <PR#>`.
Why this matters: the AIPass repo has ONE shared HEAD across all branches. If any agent lingers on a non-main HEAD, every other agent's next edit lands on the wrong branch. Files get stranded. Work gets lost. Conflicts pile up. We've lived this pain — don't repeat it.
Rules exist to help, not to control. These rules came from fixing actual bugs. Trust them.
Allowed:
- `drone @git status` — what changed?
- `drone @git sync` — pull latest main
- `drone @git system-pr "msg"` — ship your work (devpulse only)
- `drone @git merge <PR#>` — squash-merge a reviewed PR (devpulse only)
- `drone @git smart-sync` — fetch + rebase (devpulse only)
- `drone @git fix` — repair broken git states (devpulse only)
- `git status`, `git diff`, `git log` — read-only, always fine
Forbidden (denied system-wide in `.claude/settings.json`):
- `git checkout*` — any form, including `-b`, `-`, branch names
- `git add -f*` / `--force*`
- Culturally avoid `git commit`, `git push`, `gh pr create` directly — go through drone
If `drone @git system-pr` fails to return HEAD to main, that's a drone bug — report it, don't work around it by staying on a branch.
# aipass init
`aipass init` bootstraps an AIPass project in any directory, inside or outside the repo. One command creates the registry, identity, memory, and local prompt so any folder becomes an AI-powered workspace with persistent memory and structure. Spawn can then add full agent scaffolding on top.
+16
View File
@@ -28,6 +28,22 @@ user builds WITH AI, not just using AI as a tool. Every module, every system, ev
---
## Git — Always on Main
**One rule, no exceptions: every agent works on `main`.**
You do not create branches. You do not checkout other branches. You do not instruct another agent to "create a branch first." The AIPass repo has ONE shared HEAD across all branches — if any agent lingers on a non-main HEAD, every other agent's edits land on the wrong branch. Work gets stranded. Files get lost. Conflicts cascade.
Branches only exist inside the atomic `drone @git system-pr` command which commits → creates branch → pushes → opens PR → **returns HEAD to main**. That one command owns the entire branch lifecycle. Agents own nothing about branches.
Workflow: edit on main → `drone @git system-pr "msg"` → back on main. Devpulse merges reviewed PRs with `drone @git merge <PR#>`.
`git checkout*` and `git add -f*` are denied system-wide in `.claude/settings.json`. These aren't arbitrary rules — they came from fixing actual bugs caused by agents staying on branches. Trust them.
If `system-pr` fails to return HEAD to main, that's a drone bug — report it, don't work around.
---
## Identity & Citizenship
AIPass means **AI Passport**. The name wasn't accidental - the architecture wasn't accidental. Everything converged.
@@ -32,9 +32,13 @@ When a task belongs to a specialist's DOMAIN, ask them. You can still investigat
| Command routing | @drone | @branch resolution, subprocess |
| Memory, vectors | @memory | ChromaDB, search, archival |
## Git Workflow — Drone Only
## Git Workflow — Always on Main, Drone Only
Never use raw git commands (git commit, git push, git checkout anything, gh pr create). `Bash(git checkout*)` and `Bash(git add -f*)` are denied system-wide in `.claude/settings.json`. Every time raw git is used, it causes divergence, rebase conflicts, and wasted time fixing the mess. Drone handles everything correctly.
**One rule: always on main. No exceptions.** You don't create branches. You don't tell other agents to create branches. You don't stay on someone else's branch while they're mid-work. Branches exist ONLY inside the atomic `drone @git system-pr` window which commits → creates branch → pushes → PRs → returns HEAD to main. Every other moment: you're on main.
Why: AIPass repo has ONE shared HEAD. Linger on a non-main HEAD and every agent's next edit lands on the wrong branch. Work gets stranded. Dispatch briefs must NEVER say "create a branch as step 1" — that's what caused the S101 merge mess.
Never use raw git commands (git commit, git push, git checkout anything, gh pr create). `Bash(git checkout*)` and `Bash(git add -f*)` are denied system-wide in `.claude/settings.json`. Drone handles everything correctly.
```
drone @git system-pr "description" # System-wide PR (devpulse only) — commit, branch, push, PR, back to main
@@ -0,0 +1 @@
{"sessionId":"72a81f36-752b-4924-9123-d640e9726345","pid":12928,"acquiredAt":1776753271581}