You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Decision gates: classify every side-effecting action by reversibility × impact. Reversible/local work (edits, tests, local commits, work-branch push) runs autonomously — never re-confirmed; only irreversible or high-impact actions stop on a human gate. Doctrine in the loop-engineering skill + references/decision-gates.md.
decision_gate.sh (new PreToolUse Bash hook) mechanically blocks the T2 class inside a loop project: package publish, release/submit (gh release, eas submit), gh pr merge, push to a protected branch, force-push, tag push, catastrophic rm -rf. Scoped to loop projects only (fail-open everywhere else).
loop.config.md gains protected_branches (default main master), gate_push (default false — set true for direct-to-main repos), and extra_gates (optional project regex). Absent keys fall back to defaults, so existing loops need no change.
One-shot approval marker .claude/loop/.gate-approved (action class + session + 15-min TTL, gitignored): the main agent writes it only after explicit human approval, retries the gated command, then removes it.
loop-audit (new command) + auditor (new read-only subagent): audit the loop process — maker/checker separation, machine-verifiable stops, disk-memory discipline, and gate adherence (over-/under-confirmation) — and write a scored report to audit.md. Complements the product-grading verifier.
verifier_guard.sh now also guards the auditor agent (both are read-only checkers).
loop-ci (new command) + gen_ci.sh: scaffold a GitHub Actions CI workflow from the loop's detected test/lint/build (a pure, golden-tested generator; node stacks for now).
CI/CD for this repo: ci.yml (shellcheck + bash -n + jq manifest validation + tests/run.sh) on push/PR; release.yml cuts a GitHub Release from the matching CHANGELOG section when a v* tag is pushed.
.gitignore for OS/editor files and loop runtime artifacts (.run-marker, .gate-approved, codex logs, …).