From e02539e0aec0a695b712af5bf40b6b9feafb1752 Mon Sep 17 00:00:00 2001 From: JohnnyT Date: Tue, 29 Sep 2026 06:33:26 -0600 Subject: [PATCH] Authority rows: the release-prep bump follows the family norm The version-bump row's trigger now reads a release bead the operator has named (in the campaign plan or their own words), restating the Release preps paragraph; the version bump and the tag of a release prep are the family norm, ruled by the operator, 2026-09-27. The publish stays the operator's. release.md and commit.md say the same in their own voice. The tracker-push row now reads: bead state changed locally and the git side of the same change has already reached origin; inside a campaign the conductor pushes, atomically across the campaign's trackers; never as a way to publish beads for work not yet on origin/main (ruled by the operator, 2026-09-29). Every other row is byte-identical. No Elixir code changes, so there is no gate to run. --- .claude/wurk/commit.md | 7 ++++--- .claude/wurk/release.md | 17 +++++++++-------- CLAUDE.md | 4 ++-- 3 files changed, 15 insertions(+), 13 deletions(-) diff --git a/.claude/wurk/commit.md b/.claude/wurk/commit.md index e7c69fb..90db141 100644 --- a/.claude/wurk/commit.md +++ b/.claude/wurk/commit.md @@ -68,9 +68,10 @@ happens and this section does not restate it: a release (`mix hex.publish`, GitHub release) is never an agent's; the tag of a release prep is made after the prep is merged to `origin/main`, by the conductor or the session that owns the release bead (the tagging row and the "Release preps" paragraph), never -in a commit here; and the version-bump row allows the bump only on an -operator-authorized release bead's branch, inside a campaign carrying the -operator's explicit consent. Read the row +in a commit here; and the version-bump row allows the bump only on the +branch of a release bead the operator has named (in the campaign plan or +their own words), the family norm rather than a grant a campaign consent has +to name. Read the row rather than a version quoted here, which goes stale at every release. Never edit the version field as part of an ordinary commit. diff --git a/.claude/wurk/release.md b/.claude/wurk/release.md index f7fc907..aad2d1b 100644 --- a/.claude/wurk/release.md +++ b/.claude/wurk/release.md @@ -223,10 +223,11 @@ does not either: the recipe ends at the release commit on the release bead's branch. What follows that commit is `CLAUDE.md`'s to say, and its authority table and "Release preps" paragraph say it: -- *a version bump on a release bead's branch* - allowed only on "an - operator-authorized release bead, inside a campaign carrying the operator's - explicit consent", and still unauthorized "on any other bead, on main, or - when the operator has not named this repo's release bead". The prep then +- *a version bump on a release bead's branch* - allowed on "a release bead + the operator has named (in the campaign plan or their own words) - the + family norm, not a grant a campaign consent has to name", and still + unauthorized "on any other bead, on main, or when the operator has not + named this repo's release bead". The prep then lands through the commit, push and merge rows like any other bead's work. - *tagging a release prep* - trigger: "the release bead's version bump is merged to `origin/main`; the tag names that version at the merged commit"; @@ -241,10 +242,10 @@ table and "Release preps" paragraph say it: and no consent or relay delegates it. So the one thing this recipe performs - the bump plus the step B promotion, on -a named release bead's branch, under a campaign consent that names it - is -release *prep*. `.claude/wurk/commit.md`'s "Version bump: never" section -records the same boundary from the commit side: the version field moves only -through a release bead, never as a convenience. +the branch of a release bead the operator has named - is release *prep*. +`.claude/wurk/commit.md`'s "Version bump: never" section records the same +boundary from the commit side: the version field moves only through a +release bead, never as a convenience. `changelog.d/README.md` ends its "At release" paragraph with "and tag it". That clause is the tag in the list above: made on the merged prep commit, by diff --git a/CLAUDE.md b/CLAUDE.md index 91efa5e..44fe16e 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -55,8 +55,8 @@ irreversible step, and report. | `git push`, `gh pr create` | the same consent, **and** the terminology scan in the umbrella's `docs/terminology-firewall.md` clean over the full outbound content | any scan hit - that is a hard stop, not something to rephrase past | | merging a campaign PR | a campaign consent the operator adopted verbatim that names automatic merges, with every named condition met (full gate green, CI green, firewall scan clean with a positive control, any named review gate passed) | outside such a consent; any named condition unmet; any PR the consent's carve-outs hold for the operator | | `bd close ` | never for a mirrored bead whose other half is not merged to its own repo's origin/main; a mirrored bead whose other half has ALSO landed may be closed by the campaign conductor under a consent naming this exception, both halves together, each verified against its remote; otherwise the operator's call | for a bead whose description carries a `mirrors:` line while its other half is unlanded, campaign consent included | -| `bd dolt push` | the operator's call | inside a campaign that spans mirrored trackers - the conductor pushes those atomically | -| a version bump on a release bead's branch | an operator-authorized release bead, inside a campaign carrying the operator's explicit consent | on any other bead, on main, or when the operator has not named this repo's release bead | +| `bd dolt push` | bead state changed locally **and** the git side of the same change has already reached `origin`; inside a campaign, the conductor pushes (atomically across the campaign's trackers) | as a way to publish beads for work that is not on `origin/main` yet | +| a version bump on a release bead's branch | a release bead the operator has named (in the campaign plan or their own words) - the family norm, not a grant a campaign consent has to name | on any other bead, on main, or when the operator has not named this repo's release bead | | tagging a release prep | the release bead's version bump is merged to `origin/main`; the tag names that version at the merged commit | before the bump is on `origin/main`; a tag naming any other version or commit | | a release (`mix hex.publish`, GitHub release) | never | always - publishing is the operator's, in every campaign |