diff --git a/.aipass/aipass_global_prompt.md b/.aipass/aipass_global_prompt.md index a3a20dca..7cadb78d 100644 --- a/.aipass/aipass_global_prompt.md +++ b/.aipass/aipass_global_prompt.md @@ -57,7 +57,11 @@ Workflow: 2. Make edits directly on main. 3. When the work is ready to ship: `drone @git system-pr "description"`. 4. That command commits + branches + pushes + PRs + returns you to main. One action. -5. Devpulse reviews + merges with `drone @git merge `. +5. STOP. The user merges. Do not run `drone @git merge` unless the user explicitly tells you to merge a specific PR number in this session. + +Never merge. Ever. User-merges-only. Past PRs, your own PRs, closed PRs — none of them auto-qualify. You fix, you PR, you stop. + +Local files are source of truth. When you edit a file, the state on disk IS reality — you don't wait for a merge to act on what you see locally. This also means: if the truth is wrong, fix it locally, then PR. Why this matters: the AIPass repo has ONE shared HEAD across all branches. If any agent lingers on a non-main HEAD, every other agent's next edit lands on the wrong branch. Files get stranded. Work gets lost. Conflicts pile up. We've lived this pain — don't repeat it. diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index d6a6c679..5fb0d56f 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -36,7 +36,9 @@ You do not create branches. You do not checkout other branches. You do not instr Branches only exist inside the atomic `drone @git system-pr` command which commits → creates branch → pushes → opens PR → **returns HEAD to main**. That one command owns the entire branch lifecycle. Agents own nothing about branches. -Workflow: edit on main → `drone @git system-pr "msg"` → back on main. Devpulse merges reviewed PRs with `drone @git merge `. +Workflow: edit on main → `drone @git system-pr "msg"` → back on main → STOP. The user merges. Never run `drone @git merge` without an explicit user instruction for that specific PR number — not even for your own PRs, not even for PRs that look ready. User-merges-only. + +Local files are source of truth. A file edit IS reality on disk; you don't wait for a merge to act on it. If the truth is wrong, fix locally first, then PR. `git checkout*` and `git add -f*` are denied system-wide in `.claude/settings.json`. These aren't arbitrary rules — they came from fixing actual bugs caused by agents staying on branches. Trust them. diff --git a/.claude/settings.json b/.claude/settings.json index c109cf9b..f666cb82 100644 --- a/.claude/settings.json +++ b/.claude/settings.json @@ -13,6 +13,12 @@ "Bash(git add -f*)", "Bash(git add --force*)", "Bash(git checkout*)", + "Bash(git switch -c*)", + "Bash(git switch --create*)", + "Bash(git branch -c*)", + "Bash(git branch --copy*)", + "Bash(git branch -m*)", + "Bash(git branch --move*)", "Read(/home/patrick/Patrick-Personal/**)", "Edit(/home/patrick/Patrick-Personal/**)", "Write(/home/patrick/Patrick-Personal/**)", diff --git a/src/aipass/devpulse/.aipass/aipass_local_prompt.md b/src/aipass/devpulse/.aipass/aipass_local_prompt.md index 380ae7d3..c3a35fda 100644 --- a/src/aipass/devpulse/.aipass/aipass_local_prompt.md +++ b/src/aipass/devpulse/.aipass/aipass_local_prompt.md @@ -32,11 +32,17 @@ When a task belongs to a specialist's DOMAIN, ask them. You can still investigat | Command routing | @drone | @branch resolution, subprocess | | Memory, vectors | @memory | ChromaDB, search, archival | -## Git Workflow — Always on Main, Drone Only +## Git Workflow — Always on Main, Drone Only, Never Merge -**One rule: always on main. No exceptions.** You don't create branches. You don't tell other agents to create branches. You don't stay on someone else's branch while they're mid-work. Branches exist ONLY inside the atomic `drone @git system-pr` window which commits → creates branch → pushes → PRs → returns HEAD to main. Every other moment: you're on main. +**Three rules, in order:** -Why: AIPass repo has ONE shared HEAD. Linger on a non-main HEAD and every agent's next edit lands on the wrong branch. Work gets stranded. Dispatch briefs must NEVER say "create a branch as step 1" — that's what caused the S101 merge mess. +1. **Always on main. No exceptions.** You don't create branches. You don't tell other agents to create branches. Branches exist ONLY inside the atomic `drone @git system-pr` window which commits → creates branch → pushes → PRs → returns HEAD to main. Every other moment: you're on main. + +2. **Never merge PRs.** That's the user's role. You fix, you PR, you stop. The user says "merge X" or merges themselves. Do not run `drone @git merge` without an explicit user instruction for that specific PR number. Past PRs, closed PRs, your own PRs — none of them auto-qualify. User-merges-only is the rule. + +3. **Local files are source of truth.** When you make an edit, the file on disk IS reality — you don't need to wait for a merge to act on the state you see. But that also means: if the truth is wrong, fix it locally first, then PR. Don't assume remote state matches. + +Why main-only: AIPass repo has ONE shared HEAD. Linger on a non-main HEAD and every agent's next edit lands on the wrong branch. Work gets stranded. Dispatch briefs must NEVER say "create a branch as step 1" — that's what caused the S101 merge mess. Never use raw git commands (git commit, git push, git checkout anything, gh pr create). `Bash(git checkout*)` and `Bash(git add -f*)` are denied system-wide in `.claude/settings.json`. Drone handles everything correctly.