HOLD — do not ready: docs(rules) change refuted on home, gate and budget; see CLOUD-1533's repair note - #885
HOLD — do not ready: docs(rules) change refuted on home, gate and budget; see CLOUD-1533's repair note#885wenzowski wants to merge 2 commits into
Conversation
…d row four's write direction `.claude/rules/scanning.md` routed four question classes to four instruments and left two failures unnamed, both measured on one session (CLOUD-1533). Row five: a pointer confirmed in code is not a behaviour confirmed in the store. A row was filed on a correctly cited mechanism and stated the store behaviour it implied; a census over the store found zero entries of that origin in 9,674. The instrument is a count over the live instance, taken before the sentence is written, and the row names a capability rather than a product for row one's reason. Row four's write direction: a finding leaves the session in the turn it is found, filed or fixed, before it reaches a sentence to a human. Six defects and a root-cause analysis were carried in chat until a human asked what would survive the archive. `scanner_taxonomy.rs` pins the new row and iterates it as a capability row; the declared mutation rewrites the question so the prose assertion goes red. Refs: CLOUD-1533
|
Warning Review limit reachedNext included review available in 33 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe scanner taxonomy adds a fifth question to determine whether pointer behavior is live or only present in code. The question uses a census over the store or session before the sentence is written. Capability-row validation now includes this question. The scanning guidance documents the row-five rule and clarifies the write direction for row four findings. Merge Risk: ⚪ Minimal · up to This change adds guidance and taxonomy coverage requiring a live store or session census before claiming pointer behavior is active. No merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 unsupported.) ✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…s self-heals and an out-of-band client cannot `mem:connector-allowlist-recovery` carried four states and a recovery whose step 2 (a user-level allow entry) is the wrong layer for the one measured 2026-09-08: the CCR proxy answering `-32003 needs_approval` on the harness's own calls, healed by a retroactive approval card keyed on the `_meta["claudecode/toolUseId"]` the harness sends, while `batten mcp call` sends no id and is refused on every call. The discriminating read is the CLI's own MCP log, which names the state in its own words; the memory now routes a reader there before the settings surface. Series on CLOUD-178. Refs: CLOUD-178 Admits: 3a8de44aa692e537bafbe37ff585bb424c352a0999c7a7b0c0c19cf0f77f8590 Admits-rule: protected-mutation Admits-verdict: path write refused Admits-subject: .serena/memories/connector-allowlist-recovery.md Admits-anchor: call:a003aa3e88000073ad0bbfabea628e496afa232e Admits-epoch: 718625aad61944a4dac21416f2cdc7fae14da565cbe39a4f9855f59e7ac0df63 Admits-author: alec@wenzowski.com Admits-prev: - Admits-answer-lost: Without the edit the memory sends the next session to its step 2 (a user-level permissions.allow entry), which this session measured as the wrong layer for this state, and to arguing the connector is broken when the harness self-heals it and the user sees nothing. That cost ~5 hours and ~30 refused calls on 2026-09-08 and is recorded on CLOUD-178; the memory is the only surface a fresh container reads before repeating it. Admits-answer-precondition: protected-mutation's override route declares that the surface this class names cannot express the change and the write is one a reviewer sees in the diff it lands in. The change is a new section in mem:connector-allowlist-recovery recording the fifth connector state (the CCR proxy's per-call approval, keyed on the harness's _meta claudecode/toolUseId, which an out-of-band client cannot satisfy). It was written through Serena's edit_memory, the exact route the .serena/memories/** redirect names, and it lands as a reviewed diff in a draft PR; the commit gate refuses the commit until this block travels with it. Admits-answer-rejected-route: config read first (document, batten.toml) is a read of the authority and the work is a write to a memory it protects; reading it again tells me the path is protected, which is already known. patch run first (command, git restore) undoes the edit rather than landing it, and was already run once this session by mistake at the cost of redoing the work.
|
❌ The last analysis has failed. |
DO-NOT-CLOSE
Hold, 2026-09-06. This PR is not to be readied. CLOUD-1533's repair note records why: the change writes doctrine into a one-harness directory (CLOUD-1152), its test asserts presence rather than behaviour (rule 2), and the surface it grows has no token budget (CLOUD-50 counts
AGENTS.mdonly).mise run landwas stopped by hand before readying, so no CI ran on it.The two findings the change carries stand and are recorded on CLOUD-1533; what is withdrawn is the delivery. The PR stays a draft as the record of what was built, until CLOUD-1152 decides where doctrine lives and CLOUD-1470 supplies the gate-fired delivery.
Original description follows.
.claude/rules/scanning.mdgains a fifth taxonomy row and a section under row four.crates/batten/tests/it/scanner_taxonomy.rspins the new row inINSTRUMENTS, iterates it as a capability row, and declares the mutationrow-five-question-dropped.🤖 Generated with Claude Code
https://claude.ai/code/session_01Goor5aNugW4qgMassn32TG