Skip to content

Commit 5337f43

Browse files
committed
Backfill the day's repository work into TODOS.md
An audit of every commit since the branch split found the CHANGELOG complete: all seventeen carry both trailers, every trailer resolves to an entry, and the only entry without a commit is CL-20260802-018, drafted for the blocked fixed-port change and correctly absent from the committed file. TODOS.md was the gap. The day's work cites no task at all, where AGENTS.md requires a governing ID and says to add the task first when none exists. A dated section, matching the Completion Audit and Pipeline Refinement convention, records sixteen completed items against their Change-IDs and commits, and eight open items for the gaps the review found. REPO-016 records the GitHub server-side configuration: rulesets and their IDs, required checks, security toggles, Actions restrictions, labels, milestone, and the deliberate disabling of auto-merge. None of it exists in Git, so this is the only place it is written down. Change-Log: CL-20260802-025 Dev-Log: DL-20260802-035 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 1ef9949 commit 5337f43

3 files changed

Lines changed: 124 additions & 2 deletions

File tree

CHANGELOG

Lines changed: 27 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,35 @@ Dev-Log:
4242

4343
Entries
4444
-------
45-
Change-ID: CL-20260802-024
45+
Change-ID: CL-20260802-025
4646
Commit: pending
4747
Date: 2026-08-02
48+
Type: The day's repository work is backfilled into TODOS.md, including the
49+
server-side configuration no commit can carry
50+
Request-or-TODO: User: "review the latest commits against the todo list and
51+
changelog and backfill todos and changes that werent documented"
52+
Outcome: An audit of every commit since the branch split found the CHANGELOG
53+
complete: all seventeen commits carry both trailers, every trailer resolves to
54+
an entry, and the only entry without a commit is CL-20260802-018, which is
55+
drafted for the blocked fixed-port change and correctly absent from the
56+
committed file. TODOS.md was the gap -- the day's work cites no task at all,
57+
where AGENTS.md requires a governing ID and says to add the task first when
58+
none exists. A dated section, matching the convention of the Completion Audit
59+
and Pipeline Refinement sections, records sixteen completed items against
60+
their Change-IDs and commits, and eight open ones for the gaps found in the
61+
review. REPO-016 records the GitHub server-side configuration -- rulesets and
62+
their IDs, required checks, security toggles, Actions restrictions, labels,
63+
milestone, and the deliberate disabling of auto-merge -- because none of it
64+
exists in Git and this is the only place it is written down
65+
Affected-behavior: None. Records only
66+
Compatibility-or-migration: None
67+
Verification: Each completed item was checked against its commit by trailer
68+
before being written. No Go source touched
69+
Dev-Log: DL-20260802-035
70+
71+
Change-ID: CL-20260802-024
72+
Commit: 1ef9949
73+
Date: 2026-08-02
4874
Type: The user guide stops instructing people to verify a release that does not
4975
exist, and the issue tracker's role is stated
5076
Request-or-TODO: User: "use the gaps to refine the repo handling"

DEVLOG

Lines changed: 37 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,47 @@ Next-safe-step:
2525

2626
Entries
2727
-------
28+
Dev-Log: DL-20260802-035
29+
Date: 2026-08-02
30+
Status: TODOS backfilled; CHANGELOG audited and found complete
31+
Change-ID: CL-20260802-025
32+
Commit: pending
33+
Request-or-TODO: User: "review the latest commits against the todo list and
34+
changelog and backfill todos and changes that werent documented"
35+
Goal: Make the completion ledger match what was actually done today
36+
Assumptions: Backfilling means recording the work honestly after the fact, not
37+
pretending a task existed beforehand. The section says so in its first
38+
paragraph rather than implying the tasks predated the work
39+
Decisions: The audit ran both directions -- commit to entry and entry to commit
40+
-- rather than only checking that entries exist. That is what found
41+
CL-20260802-018 as the single entry with no commit, and confirmed it is
42+
correctly absent from the committed CHANGELOG rather than orphaned. The
43+
server-side configuration was written into TODOS rather than left as chat
44+
history: rulesets, security toggles, and Actions restrictions are real changes
45+
to how this repository behaves, they are invisible to git log, and without
46+
REPO-016 the only record of them would be a conversation. Open gaps were
47+
written as unchecked items with the same identifiers rather than as prose, so
48+
they are picked up by the same reading that picks up any other work
49+
Files-or-schemas: TODOS.md. No schema change
50+
Validation: Every completed item's Change-ID was resolved to its commit through
51+
its trailer before being recorded. The staged blob was built from HEAD plus
52+
the appended section, so a concurrent lane's 80 uncommitted lines elsewhere in
53+
the file stayed unstaged and intact
54+
Failures-or-discarded-approaches: A first attempt to build the staged blob read
55+
git output under the Windows default codepage and failed on a byte in the
56+
file; nothing was written. Retried with explicit UTF-8
57+
Known-limitations: The completed items are recorded after the fact, so they
58+
document rather than authorise the work. REPO-016 has to be maintained by
59+
hand: nothing reconciles it against the repository's actual settings, so it
60+
will drift the first time a setting is changed without editing it
61+
Next-safe-step: REPO-018, the 44 findings and the failing package, which blocks
62+
REPO-017 and REPO-019
63+
2864
Dev-Log: DL-20260802-034
2965
Date: 2026-08-02
3066
Status: Install guide and tracker roles corrected
3167
Change-ID: CL-20260802-024
32-
Commit: pending
68+
Commit: 1ef9949
3369
Request-or-TODO: User: "use the gaps to refine the repo handling"
3470
Goal: Remove two places where the documentation claimed more than the project
3571
can currently do

TODOS.md

Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4413,3 +4413,63 @@ Depends on: `MEM-022` for the key, then `PIPE-084` for the records. The key come
44134413
- [ ] `MEM-G07 GATE` No prior seeds into an approval rung and no prior removes a stage, proven by a fixture whose routing evidence recommends both.
44144414
- [ ] `MEM-G08 GATE` The exploration floor is observable in the record: of the runs seeded above the cheapest rung, the report states how many the cheapest rung would have handled, drawn from exploring runs of the same key.
44154415
- [ ] `MEM-G09 GATE` A quarantined artifact never regains authority, and its independently derived successor carries a new identity, no inherited confidence, and the original counterexample, proven end to end through the extraction path rather than only in the domain layer.
4416+
4417+
# Repository and Agent Operations (2026-08-02)
4418+
4419+
This work was requested directly by the user and carried no governing task at
4420+
the time, which `AGENTS.md` requires. It is recorded here after the fact so the
4421+
completion ledger matches what was actually done. Every completed item names its
4422+
`Change-ID` and the commit that carries it.
4423+
4424+
Server-side GitHub configuration is included because it exists nowhere in Git:
4425+
`REPO-016` is the only record that it was changed, and to what.
4426+
4427+
- [x] `REPO-001` Relicense the project MIT and publish the repository metadata a public project needs.
4428+
- `CL-20260802-007`, commit `f49f0da`. `LICENSE` replaced (Apache 2.0 to MIT), root `README.md`, `.github/SECURITY.md`, `CONTRIBUTING.md`, `CODE_OF_CONDUCT.md`, `CODEOWNERS`, `PULL_REQUEST_TEMPLATE.md`, three issue forms, `FUNDING.yml`, `.editorconfig`, `.env.example`, and the CodeQL and dependency-review workflows.
4429+
- Supersedes the `M01-003` and `M01-004` bootstrap evidence, which recorded the README as intentionally absent and the licence as Apache 2.0.
4430+
- [x] `REPO-002` Track the interface design references as source rather than leaving them untracked.
4431+
- `CL-20260802-008`, commit `ae4afe7`. Six renderings under `design/references/ui/`, 11.2 MB, already covered by the `*.png binary` attribute.
4432+
- [x] `REPO-003` Stop the redaction suite's synthetic credentials from blocking pushes.
4433+
- `CL-20260802-010`, commit `0a460b5`. Two Slack fixtures assembled at runtime instead of written as contiguous literals, matching how the Google and GitHub fixtures were already built.
4434+
- GitHub push protection had refused the push; the literals lived in commits `73f801d` and `6c2393c`, so 25 unpushed commits were rewritten by blob substitution, with the resulting tree verified byte-identical to its backup.
4435+
- [x] `REPO-004` Adopt a two-branch model and set the compiled version to 0.0.1.
4436+
- `CL-20260802-011`, commit `204c76a`. `dev` is the default and integration branch; `main` takes only `dev` through a pull request with every check green.
4437+
- [x] `REPO-005` Track the Claude Code configuration and vendor the Karpathy guidelines.
4438+
- `CL-20260802-012`, commit `b614fc5`. `.claude/settings.json`, three subagents, and `skills/karpathy-guidelines/`, pinned at `2c60614` and relying on that file's own `license: MIT` frontmatter, the upstream repository having no `LICENSE`.
4439+
- [x] `REPO-006` Split CI into a non-gating dev pass and the gated main pass.
4440+
- `CL-20260802-013`, commit `90685d7`. `ci.yml` narrowed to `main`; `dev-pass.yml` added, one runner, every step running even after an earlier failure.
4441+
- [x] `REPO-007` Require feature-atomic commits and carry the real commit hash in both ledgers.
4442+
- `CL-20260802-014`, commit `fc05c3f`. `Commit:` is written as `pending`, filled in after the commit exists, and swept up by the next feature commit.
4443+
- [x] `REPO-008` Require a driven browser check for any frontend change.
4444+
- `CL-20260802-015`, commit `bce52d0`. Real clicks and keystrokes; assert the event, the state, and the render; walk the keyboard path; open the screenshot.
4445+
- [x] `REPO-009` Restructure `AGENTS.md` for focus without removing a rule.
4446+
- `CL-20260802-016`, commit `5c0dda8`. Three overlapping checklists merged into one Task Lifecycle; every removed line checked for survival elsewhere.
4447+
- [x] `REPO-010` Vendor Anthropic's frontend-design skill and require it before surface work.
4448+
- `CL-20260802-017`, commit `13392a7`. Apache-2.0, copied verbatim with its `LICENSE.txt`, plus the rule that its CSS vocabulary does not override this repository's Go design tokens.
4449+
- [x] `REPO-011` Repair the two instruction-file lint regressions introduced while restructuring.
4450+
- `CL-20260802-019` commit `ece2c03`, and `CL-20260802-020` commit `246c480`. `CLAUDE.md` returned under its thirty-line limit and the pinned reference restored to both files.
4451+
- `ece2c03` also carried the `Stop What You Start` section because the whole file was staged rather than the intended hunk: two features in one commit, recorded as a `Correction` in `CL-20260802-021`.
4452+
- [x] `REPO-012` Make the pre-commit hook format, lint, and test before allowing a commit.
4453+
- `CL-20260802-021`, commit `e3d72fe`. `core.hooksPath` was also set; the hook had existed since `M01-050` and had never run, which is why two lint regressions reached the remote.
4454+
- [x] `REPO-013` Require a separate worktree per concurrent agent lane.
4455+
- `CL-20260802-022`, commit `a476144`. Repository-wide lint means any lane's unfinished file blocks every other lane's commit.
4456+
- [x] `REPO-014` Report drift between the vendored skills and upstream without updating them.
4457+
- `CL-20260802-023`, commit `8a1886c`. Weekly, report-only; a failed fetch is reported as unknown rather than passed as a match.
4458+
- [x] `REPO-015` Stop the user guide instructing readers to verify a release that does not exist, and state the tracker roles.
4459+
- `CL-20260802-024`, commit `1ef9949`. `TODOS.md` is authoritative; GitHub issues are the inbox.
4460+
- [x] `REPO-016` Record the server-side GitHub configuration, which no commit can capture.
4461+
- Description set, homepage left unset, 15 topics; wiki and projects off, discussions on; delete-branch-on-merge on; merge commits off, squash and rebase on.
4462+
- Rulesets. `20243842` "main is released code": no bypass, pull request required, seven required checks (`Quality (Windows 11 ARM64)`, `Build and test` on four platforms, `Race tests (Ubuntu 24.04 AMD64)`, `Analyze Go`), strict up-to-date policy, deletion and force-push blocked. `20243850` "dev is the integration branch": repository-admin bypass, pull request required, no status checks, deletion and force-push blocked.
4463+
- Security: private vulnerability reporting, secret scanning, push protection, Dependabot alerts and security updates all enabled. Non-provider patterns and validity checks were refused by the API and remain disabled.
4464+
- Actions: GitHub-owned and verified actions only; default workflow token read-only and unable to approve pull requests; fork pull requests from all external contributors require approval.
4465+
- Auto-merge was enabled and then deliberately disabled: `dev` requires no status checks, so an auto-merged pull request would have landed there unchecked.
4466+
- 22 labels, and milestone 1, `M24 - End-to-End Vertical Slice and Prototype Exit`.
4467+
- `backup/pre-secret-rewrite-20260802` exists locally only; pushing it is refused by push protection because it contains the fixture credentials the rewrite removed.
4468+
- [ ] `REPO-017 BLOCKER` Land the first `dev` to `main` pull request. The gate has never passed once, so the branch model is unproven and `main` is frozen behind a red tree.
4469+
- [ ] `REPO-018 BLOCKER` Clear the 44 `staticcheck` findings — 35 `U1000`, 5 `SA1019`, 2 `ST1018`, 1 `S1002`, 1 `S1011` — and the failing `test-fast` package. These block `REPO-017` and every Go commit.
4470+
- [ ] `REPO-019` Land the fixed dev-server port `127.0.0.1:47311`. Written and passing its own checks; `CL-20260802-018` is drafted and uncommitted because the pre-commit hook refuses the tree for other lanes' failures.
4471+
- [ ] `REPO-020` Enforce in `lint` that a commit carries both ledger trailers and that the referenced entries exist. The most-violated rules in this repository are the unenforced ones.
4472+
- [ ] `REPO-021` Prevent ledger identifier collisions between lanes. Sequential `CL-` and `DL-` numbers on a shared branch collided once on 2026-08-02; either derive them collision-free or make `lint` reject a duplicate.
4473+
- [ ] `REPO-022` Add `test-browser` to the main gate once its CI runtime is measured, and add its context to ruleset `20243842` in the same change. Until then `REPO-008` cannot be verified in CI.
4474+
- [ ] `REPO-023` Publish the first release, then remove the note added by `REPO-015`. Requires a tag, artifacts, `SHA256SUMS`, and a signing key, none of which exist.
4475+
- [ ] `REPO-024` Re-check the vendored `frontend-design` skill by hand periodically; the Anthropic marketplace publishes no per-skill version, so `REPO-014` cannot cover it.

0 commit comments

Comments
 (0)