Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions .claude/wurk/commit.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,9 +68,10 @@ happens and this section does not restate it: a release (`mix hex.publish`,
GitHub release) is never an agent's; the tag of a release prep is made after
the prep is merged to `origin/main`, by the conductor or the session that owns
the release bead (the tagging row and the "Release preps" paragraph), never
in a commit here; and the version-bump row allows the bump only on an
operator-authorized release bead's branch, inside a campaign carrying the
operator's explicit consent. Read the row
in a commit here; and the version-bump row allows the bump only on the
branch of a release bead the operator has named (in the campaign plan or
their own words), the family norm rather than a grant a campaign consent has
to name. Read the row
rather than a version quoted here, which goes stale at every release. Never
edit the version field as part of an ordinary commit.

Expand Down
17 changes: 9 additions & 8 deletions .claude/wurk/release.md
Original file line number Diff line number Diff line change
Expand Up @@ -223,10 +223,11 @@ does not either: the recipe ends at the release commit on the release bead's
branch. What follows that commit is `CLAUDE.md`'s to say, and its authority
table and "Release preps" paragraph say it:

- *a version bump on a release bead's branch* - allowed only on "an
operator-authorized release bead, inside a campaign carrying the operator's
explicit consent", and still unauthorized "on any other bead, on main, or
when the operator has not named this repo's release bead". The prep then
- *a version bump on a release bead's branch* - allowed on "a release bead
the operator has named (in the campaign plan or their own words) - the
family norm, not a grant a campaign consent has to name", and still
unauthorized "on any other bead, on main, or when the operator has not
named this repo's release bead". The prep then
lands through the commit, push and merge rows like any other bead's work.
- *tagging a release prep* - trigger: "the release bead's version bump is
merged to `origin/main`; the tag names that version at the merged commit";
Expand All @@ -241,10 +242,10 @@ table and "Release preps" paragraph say it:
and no consent or relay delegates it.

So the one thing this recipe performs - the bump plus the step B promotion, on
a named release bead's branch, under a campaign consent that names it - is
release *prep*. `.claude/wurk/commit.md`'s "Version bump: never" section
records the same boundary from the commit side: the version field moves only
through a release bead, never as a convenience.
the branch of a release bead the operator has named - is release *prep*.
`.claude/wurk/commit.md`'s "Version bump: never" section records the same
boundary from the commit side: the version field moves only through a
release bead, never as a convenience.

`changelog.d/README.md` ends its "At release" paragraph with "and tag it".
That clause is the tag in the list above: made on the merged prep commit, by
Expand Down
4 changes: 2 additions & 2 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,8 +55,8 @@ irreversible step, and report.
| `git push`, `gh pr create` | the same consent, **and** the terminology scan in the umbrella's `docs/terminology-firewall.md` clean over the full outbound content | any scan hit - that is a hard stop, not something to rephrase past |
| merging a campaign PR | a campaign consent the operator adopted verbatim that names automatic merges, with every named condition met (full gate green, CI green, firewall scan clean with a positive control, any named review gate passed) | outside such a consent; any named condition unmet; any PR the consent's carve-outs hold for the operator |
| `bd close <id>` | never for a mirrored bead whose other half is not merged to its own repo's origin/main; a mirrored bead whose other half has ALSO landed may be closed by the campaign conductor under a consent naming this exception, both halves together, each verified against its remote; otherwise the operator's call | for a bead whose description carries a `mirrors:` line while its other half is unlanded, campaign consent included |
| `bd dolt push` | the operator's call | inside a campaign that spans mirrored trackers - the conductor pushes those atomically |
| a version bump on a release bead's branch | an operator-authorized release bead, inside a campaign carrying the operator's explicit consent | on any other bead, on main, or when the operator has not named this repo's release bead |
| `bd dolt push` | bead state changed locally **and** the git side of the same change has already reached `origin`; inside a campaign, the conductor pushes (atomically across the campaign's trackers) | as a way to publish beads for work that is not on `origin/main` yet |
| a version bump on a release bead's branch | a release bead the operator has named (in the campaign plan or their own words) - the family norm, not a grant a campaign consent has to name | on any other bead, on main, or when the operator has not named this repo's release bead |
| tagging a release prep | the release bead's version bump is merged to `origin/main`; the tag names that version at the merged commit | before the bump is on `origin/main`; a tag naming any other version or commit |
| a release (`mix hex.publish`, GitHub release) | never | always - publishing is the operator's, in every campaign |

Expand Down
Loading