diff --git a/.claude/wurk/commit.md b/.claude/wurk/commit.md index 526c0cc..8f4a467 100644 --- a/.claude/wurk/commit.md +++ b/.claude/wurk/commit.md @@ -43,8 +43,8 @@ release bead moves it. The manifest does carry a `release` recipe - `kind: "hex"`, `version_file` `mix.exs`, `readme_pin` true - so `/wurk:release` runs here, driven by that block together with the required steps in `.claude/wurk/release.md`. None of -that is a commit-time concern: the recipe runs on an operator-authorized -release bead, and it still stops short of tagging, pushing and publishing. +that is a commit-time concern: the recipe runs on a release bead the +operator has named, and it still stops short of tagging, pushing and publishing. Those follow `CLAUDE.md`'s authority table: once the prep is merged to `origin/main`, the conductor or the session that owns the release bead tags that merged commit, and only the publish (`mix hex.publish`, a GitHub diff --git a/.claude/wurk/release.md b/.claude/wurk/release.md index c0d5a81..8008529 100644 --- a/.claude/wurk/release.md +++ b/.claude/wurk/release.md @@ -221,9 +221,9 @@ The skill does not tag, push, open a request or publish, and this extension does not either. The one thing a release-prep request contains is the version bump and the fragment promotion above. What happens around it is `CLAUDE.md`'s authority table, not this recipe. A version bump on a release -bead's branch is authorized only on "an operator-authorized release bead, -inside a campaign carrying the operator's explicit consent"; the push and the -request follow the table's push row. Once the prep is merged to +bead's branch is authorized on "a release bead the operator has named (in +the campaign plan or their own words)", with no campaign consent to name it; +the push and the request follow the table's push row. Once the prep is merged to `origin/main`, the conductor or the session that owns the release bead tags that merged commit with the new version and pushes the tag: the table's tagging row fires when "the release bead's version bump is merged to diff --git a/CLAUDE.md b/CLAUDE.md index c04e6f6..c0bef6c 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -57,11 +57,11 @@ irreversible step, and report. | `bd` task tracking (`create`, `claim`, `update`, `note`) | any time | never - this is the default profile too | | `mix quality` in any profile | any time | never - running the gate costs nothing but time | | `git commit` | the claimed bead's work is complete **and** full `mix quality` is green; a change touching no Elixir code has no gate to run and may commit on review of the diff alone | on a red gate, on a `--profile loop` or otherwise scoped run, or with unrelated changes in the tree | -| `git push`, `gh pr create` | the user asks for it in their own words | inferred from "the work is done"; finishing a bead is not a request to publish it | +| `git push`, `gh pr create` | the user asks for it in their own words - a human invoking `/wurk:mr` satisfies this, so the skill does not stop to ask again; a conductor, an orchestrator or a parent session invoking it on the user's behalf does not, and needs the campaign's consent | inferred from "the work is done"; finishing a bead is not a request to publish it | | merging a campaign PR | a campaign consent the operator adopted verbatim that names automatic merges, with every named condition met (full gate green, CI green, firewall scan clean with a positive control, any named review gate passed) | outside such a consent; any named condition unmet; any PR the consent's carve-outs hold for the operator | | `bd close ` | never for a mirrored bead whose other half is not merged to its own repo's `origin/main`; a mirrored bead whose other half has ALSO landed may be closed by the campaign conductor under a consent naming this exception, both halves together, each verified against its remote; otherwise the work is on `origin/main`, verified against the remote | for a bead whose description carries a `mirrors:` line while its other half is unlanded, campaign consent included; and otherwise at commit time, or on a local commit that has not been pushed | | `bd dolt push` | bead state changed locally **and** the git side of the same change has already reached `origin` | as a way to publish beads for work that is not on `origin/main` yet; and inside a campaign that spans mirrored trackers - the conductor pushes those atomically | -| a version bump on a release bead's branch | an operator-authorized release bead, inside a campaign carrying the operator's explicit consent | on any other bead, on main, or when the operator has not named this repo's release bead | +| a version bump on a release bead's branch | a release bead the operator has named (in the campaign plan or their own words); the bump is the family norm, not a grant a campaign consent has to name - its tag follows the tagging row once the prep is merged to `origin/main`, and the publish stays the operator's | on any other bead, on main, or when the operator has not named this repo's release bead | | tagging a release prep | the release bead's version bump is merged to `origin/main`; the tag names that version at the merged commit | before the bump is on `origin/main`; a tag naming any other version or commit | | a release (`mix hex.publish`, GitHub release) | never | always - publishing is the operator's, in every campaign |