diff --git a/.claude/settings.json b/.claude/settings.json new file mode 100644 index 0000000..481478f --- /dev/null +++ b/.claude/settings.json @@ -0,0 +1,24 @@ +{ + "//": "Project-scoped Claude Code settings. See CLAUDE.md and docs/WORK_CYCLE.md.", + "permissions": { + "//deny": [ + "Deny wins over allow. Paths use the DOUBLE-SLASH absolute form -- a", + "tilde-style rule looks right in review and silently matches nothing,", + "which is indistinguishable from a rule that works until it matters.", + "", + "This closes the Read TOOL only. A shell can read a file a hundred ways,", + "so this catches the accidental read, not the determined one. The real", + "protection is having a sanctioned reader that answers the question", + "without returning the value -- see CLAUDE.md." + ], + "deny": [ + "Read(//**/.env)", + "Read(//**/.env.*)", + "Read(//**/*.token)", + "Read(//**/*.pem)", + "Read(//**/id_rsa*)", + "Read(//**/credentials/**)", + "Read(//**/secrets/**)" + ] + } +} diff --git a/.claudeignore b/.claudeignore new file mode 100644 index 0000000..1bc8d11 --- /dev/null +++ b/.claudeignore @@ -0,0 +1,45 @@ +# What Claude should not spend context on. +# +# EXCLUDE ARTIFACTS, NEVER THE RECORD. `docs/` is load-bearing: the Command +# Center reads this repository's documents at a commit, `DOC_TRUST_MAP.md` says +# which document owns which answer, and `docs/qa/ClaudeReport.md` is parsed for +# the sentence shown on the project screen. A generic ignore file that sweeps +# "documentation" or "data" starves both the agent and the reconcile, and the +# failure is silent -- everything still runs, it is just working blind. +# +# Same for the tracker: nothing here is a substitute for it. + +node_modules/ +.venv/ +__pycache__/ +*.pyc + +# Build output +dist/ +build/ +.next/ +*.tsbuildinfo + +# Databases and captures — large, binary, and derived +var/*.db +var/*.db-wal +var/*.db-shm +var/archive/ +*.sqlite +*.sqlite3 + +# Logs and rotations +*.log +*.log.* + +# Media that costs context and answers nothing +*.png +*.jpg +*.jpeg +*.webp +*.mp4 +*.pdf + +# Local editor state +.idea/ +.vscode/ diff --git a/CLAUDE.md b/CLAUDE.md new file mode 100644 index 0000000..a1f1d8e --- /dev/null +++ b/CLAUDE.md @@ -0,0 +1,70 @@ +# + + + +**Read `docs/DOC_TRUST_MAP.md` before trusting anything else in `docs/`.** It +says which document owns which answer. This file is deliberately short and +points at it rather than repeating it — a second copy of the map is the failure +that map exists to prevent. + +## What this file is for + +Only what an agent needs **before** it can read anything else, and that is not +already owned by a document. If you are about to add current state, a task list, +or a summary of `docs/`, it goes in the tracker or in `docs/` respectively. + +## Exit codes are an API + + + +| Code | Means | +| --- | --- | +| `0` | did its work | +| `1` | refused for a normal, designed reason | +| `2` | **did not run** — a precondition failed. Never a pass | +| `3` | ran and the work failed | +| `99` | a lock was held; another copy is running | + +Three states, never two: `ok` / `skipped` / `failed`. An exit code alone cannot +tell "nothing to do" from "I did nothing". + +## Before you finish + +`docs/WORK_CYCLE.md` owns this and outranks anything here. In short: + +- Run this project's own guards, not just its tests: +- **Never `git add -A`.** Stage by explicit path — <`bash scripts/commit-mine.sh` + if adopted>. A shared checkout means someone else's work is one careless + `add` away from your commit. +- Update the documents this change triggered, **in the same commit as the + code**. Check each document's `Review trigger:` line. +- Close issues with the evidence that proves them: a path, a symbol, a test + name, or the command that shows it. "Done" is not a close. + +## Before you plan + +`docs/WORK_CYCLE.md` lists six sections **every plan must name**: unified code, +error handling, logging, blind spots, rolled-in landmine fixes, and +hardcode-as-little-as-possible. Read them there. + +## Two standing instructions + +**Flag anything that looks wrong, even if it is not what you were asked about.** +Most real defects are found while looking at something else. Say so, then fix it +or ask — a known bug that ships is a decision, and it is never yours to make +silently. + +**Never print a credential.** Not from a file, not from a command's output, not +from a config subtree "with the secrets filtered out" — that filter has failed +before, because it matched key *names* and the secret sat inside an object whose +name was innocent. Name the variable or the path; never the value. To compare +two secrets, compare hashes. + +## Conventions + + + +- +- +- diff --git a/START-HERE-Existing-Project.md b/START-HERE-Existing-Project.md index c87082d..14331f8 100644 --- a/START-HERE-Existing-Project.md +++ b/START-HERE-Existing-Project.md @@ -53,6 +53,11 @@ Your plan must name, separately: - anything you will DELETE, and a migrated backlog above all - which scripts this project will adopt, and which it will not - what you will deliberately leave undone, by name, and why + - the six mandatory sections from