|
D-137: repo-carried build spec for the fresh-session handoff
Operator directed the build to a fresh session. The design and committee review lived in a plan file under ~/.claude/plans/ -- outside the repo -- so a session bootstrapping via the GA-R4 path (CURRENT-STATE -> session-ledger -> ledger-scan) would never have surfaced it. That is a real durability gap given repo-is-authoritative, so the spec now lives at docs/D-137-implementation-plan.md (precedent: docs/D-068-vault-migration-plan-draft.md). Carries the five ruled decisions and their consequences, the matrix schema (logical keys only per the SEC-004 ruling), the checker model with file:line precedents (provider-bundle-check for structure, sandbox-fidelity-check:131-143 for both-bounds), the three tiers, inherited constraints (metadata-only source-grep guard, gauntlet excerpt regex, preflight 0/1/2, L1/L10), the file list, and the acceptance test. Explicitly instructs the next session NOT to make the first run green: the acceptance test is that the checker REPRODUCES SEC-021/-022/-023 and the predicted admin-openrc case as NAMED failures. A checker that passes on today's tree is wrong. Going green is a separate remediation project. CURRENT-STATE item 9 + the ledger addendum point at it. Auto-memory pointer updated: policy authority is D-137 per sub-ruling 4, with a verify-first caveat that creds-audit CLEAN is not evidence of completeness. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/D-137-implementation-plan.md 0 → 100644 |
|---|
| docs/changelog-20260725-maas-admin-recovery.md |
|---|
| docs/session-ledger.md |
|---|