From d1a0be6630c6b84f11ca0c11757b6a8166945a87 Mon Sep 17 00:00:00 2001 From: AIOSAI Date: Tue, 21 Apr 2026 08:40:34 -0700 Subject: [PATCH] feat(system): docs: drill main-only git rule into global prompt, CLAUDE.md, devpulse local prompt (S101 fix) Co-Authored-By: @devpulse --- .aipass/aipass_global_prompt.md | 33 ++++++++++++++++++ .claude/CLAUDE.md | 16 +++++++++ .../devpulse/.aipass/aipass_local_prompt.md | 8 +++-- .../devpulse/.claude/scheduled_tasks.lock | 1 + .../__pycache__/auth.cpython-312.pyc | Bin 3332 -> 3433 bytes 5 files changed, 56 insertions(+), 2 deletions(-) create mode 100644 src/aipass/devpulse/.claude/scheduled_tasks.lock diff --git a/.aipass/aipass_global_prompt.md b/.aipass/aipass_global_prompt.md index af24b3f9..a3a20dca 100644 --- a/.aipass/aipass_global_prompt.md +++ b/.aipass/aipass_global_prompt.md @@ -46,6 +46,39 @@ Secrets live outside the repo at `~/.secrets/aipass/` — API keys, tokens, cred - `drone systems` — list all registered branches - `drone --help` — full drone reference +# Git — Always on Main + +**ONE rule: every agent works on `main`. No exceptions.** + +You do not create branches. You do not `git checkout -b`. You do not tell another agent to "create a branch first." Branches only exist during the atomic window inside `drone @git system-pr` which: commits → creates branch → pushes → opens PR → **returns HEAD to main**. That command owns the branch lifecycle end to end. You own nothing about branches. + +Workflow: +1. You're on main. Always. +2. Make edits directly on main. +3. When the work is ready to ship: `drone @git system-pr "description"`. +4. That command commits + branches + pushes + PRs + returns you to main. One action. +5. Devpulse reviews + merges with `drone @git merge `. + +Why this matters: the AIPass repo has ONE shared HEAD across all branches. If any agent lingers on a non-main HEAD, every other agent's next edit lands on the wrong branch. Files get stranded. Work gets lost. Conflicts pile up. We've lived this pain — don't repeat it. + +Rules exist to help, not to control. These rules came from fixing actual bugs. Trust them. + +Allowed: + - `drone @git status` — what changed? + - `drone @git sync` — pull latest main + - `drone @git system-pr "msg"` — ship your work (devpulse only) + - `drone @git merge ` — squash-merge a reviewed PR (devpulse only) + - `drone @git smart-sync` — fetch + rebase (devpulse only) + - `drone @git fix` — repair broken git states (devpulse only) + - `git status`, `git diff`, `git log` — read-only, always fine + +Forbidden (denied system-wide in `.claude/settings.json`): + - `git checkout*` — any form, including `-b`, `-`, branch names + - `git add -f*` / `--force*` + - Culturally avoid `git commit`, `git push`, `gh pr create` directly — go through drone + +If `drone @git system-pr` fails to return HEAD to main, that's a drone bug — report it, don't work around it by staying on a branch. + # aipass init `aipass init` bootstraps an AIPass project in any directory, inside or outside the repo. One command creates the registry, identity, memory, and local prompt so any folder becomes an AI-powered workspace with persistent memory and structure. Spawn can then add full agent scaffolding on top. diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index 97e6d001..d6a6c679 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -28,6 +28,22 @@ user builds WITH AI, not just using AI as a tool. Every module, every system, ev --- +## Git — Always on Main + +**One rule, no exceptions: every agent works on `main`.** + +You do not create branches. You do not checkout other branches. You do not instruct another agent to "create a branch first." The AIPass repo has ONE shared HEAD across all branches — if any agent lingers on a non-main HEAD, every other agent's edits land on the wrong branch. Work gets stranded. Files get lost. Conflicts cascade. + +Branches only exist inside the atomic `drone @git system-pr` command which commits → creates branch → pushes → opens PR → **returns HEAD to main**. That one command owns the entire branch lifecycle. Agents own nothing about branches. + +Workflow: edit on main → `drone @git system-pr "msg"` → back on main. Devpulse merges reviewed PRs with `drone @git merge `. + +`git checkout*` and `git add -f*` are denied system-wide in `.claude/settings.json`. These aren't arbitrary rules — they came from fixing actual bugs caused by agents staying on branches. Trust them. + +If `system-pr` fails to return HEAD to main, that's a drone bug — report it, don't work around. + +--- + ## Identity & Citizenship AIPass means **AI Passport**. The name wasn't accidental - the architecture wasn't accidental. Everything converged. diff --git a/src/aipass/devpulse/.aipass/aipass_local_prompt.md b/src/aipass/devpulse/.aipass/aipass_local_prompt.md index 8cbd0bfd..380ae7d3 100644 --- a/src/aipass/devpulse/.aipass/aipass_local_prompt.md +++ b/src/aipass/devpulse/.aipass/aipass_local_prompt.md @@ -32,9 +32,13 @@ When a task belongs to a specialist's DOMAIN, ask them. You can still investigat | Command routing | @drone | @branch resolution, subprocess | | Memory, vectors | @memory | ChromaDB, search, archival | -## Git Workflow — Drone Only +## Git Workflow — Always on Main, Drone Only -Never use raw git commands (git commit, git push, git checkout anything, gh pr create). `Bash(git checkout*)` and `Bash(git add -f*)` are denied system-wide in `.claude/settings.json`. Every time raw git is used, it causes divergence, rebase conflicts, and wasted time fixing the mess. Drone handles everything correctly. +**One rule: always on main. No exceptions.** You don't create branches. You don't tell other agents to create branches. You don't stay on someone else's branch while they're mid-work. Branches exist ONLY inside the atomic `drone @git system-pr` window which commits → creates branch → pushes → PRs → returns HEAD to main. Every other moment: you're on main. + +Why: AIPass repo has ONE shared HEAD. Linger on a non-main HEAD and every agent's next edit lands on the wrong branch. Work gets stranded. Dispatch briefs must NEVER say "create a branch as step 1" — that's what caused the S101 merge mess. + +Never use raw git commands (git commit, git push, git checkout anything, gh pr create). `Bash(git checkout*)` and `Bash(git add -f*)` are denied system-wide in `.claude/settings.json`. Drone handles everything correctly. ``` drone @git system-pr "description" # System-wide PR (devpulse only) — commit, branch, push, PR, back to main diff --git a/src/aipass/devpulse/.claude/scheduled_tasks.lock b/src/aipass/devpulse/.claude/scheduled_tasks.lock new file mode 100644 index 00000000..d8b191a9 --- /dev/null +++ b/src/aipass/devpulse/.claude/scheduled_tasks.lock @@ -0,0 +1 @@ +{"sessionId":"72a81f36-752b-4924-9123-d640e9726345","pid":12928,"acquiredAt":1776753271581} \ No newline at end of file diff --git a/src/aipass/drone/apps/plugins/devpulse_ops/__pycache__/auth.cpython-312.pyc b/src/aipass/drone/apps/plugins/devpulse_ops/__pycache__/auth.cpython-312.pyc index b5fbdb6a8a3bd49263bfc3b60d137f334c217b1e..7b7741bd82aea959634409e4c35f8fb43e8e0671 100644 GIT binary patch delta 267 zcmZpXdMU+snwOW00SGFmJA%ETx$S%B*~SIU*tk_#!N7o^HI zGji)PG73!A=SelbrIwgkkXT%-SDc!flAf=ZSWr-`mz$qbnv+_rSCCqin^|0(nV(l& z#13@QEtZ_j;*!Zzc#OErfn1QIi;X8=;E|KP%i!@)R`G(8`DIy)2L1_>ml-U+uo*JS J7nuRo008x{O$-14 delta 165 zcmaDU)gr}rnwOW00SLVPA7=jGn#d=?7&TGdMVvjIF^VgNBb7Ua(*`J;!kxm^!V<-^ zafS#Z*Da2e)UtxooZ{5YM;W=;7)>T$U{~gG%*n|wPfbxsPRz;K%*tWP#3()4n(H}N z+?Dve3vu}uqzX3caO*NM@=lK8NuB(O$B4@mXfPuX7wb&c