Skip to content

epic: make the workflow rules enforceable, not just documented #286

Description

@xenodeve

Deferred by decision on 2026-07-28: CI/CD (#275) lands first. Filed so the analysis is not lost, not to be started yet.

EN

CLAUDE.md's enforcement-status table currently reads "discipline only" in every row — and that is the honest reading, verified against this checkout:

Control Reality today
A PR must reference an issue no PreToolUse hook, no .claude/t4.json — nothing checks
code-review + scrutinize before merge nothing verifies the evidence exists
verify / tests before merge no merge hook in this checkout
Dangerous git (reset --hard, force-push, branch -D) no command-denial hook
Production DB write stop stated in the file; no mechanism

This is not a theoretical gap. On 2026-07-26 the pre-merge gate was skipped on four PRs in one day, using an invented heuristic that appears in no document. On 2026-07-27 a PR was merged while both CI contexts were red, because a polling loop returned success on failure and nothing downstream re-checked. In both cases the rule existed, was documented, and was believed — and nothing enforced it.

CI/CD (#275) fixes a different half: it makes the code verifiable. This issue is about making the process verifiable. They are complementary and the ordering is deliberate — a gate that blocks a merge is worth more once there is a check worth blocking on.

What this would cover, when it starts

  • A PreToolUse gate that denies gh pr create with no referenced issue, and denies the dangerous-git commands CLAUDE.md already forbids.
  • A merge-time check that the repository's own verify passed, rather than trusting that someone ran it.
  • Machine-checkable pre-merge review evidence — feat(ci): run the pre-merge gate audit on a schedule #283 automates detection after the fact; this would be prevention.
  • .claude/t4.json or the equivalent configuration those hooks read, checked in so a fresh clone inherits them.
  • Every row it implements updates the enforcement table in the same PR, with the artifact named. nestjs/test/enforcement-claims-are-backed.spec.ts already fails if a claim names no artifact.

Why it is not started now

Client-side hooks bind only the agent that loads them; branch protection and CI bind everyone and everything, including a merge from the GitHub web UI. Building the weaker layer first would create exactly the false confidence the enforcement table was written to remove — the table would gain rows that a fresh clone or a different agent does not honour.

Prerequisite: #275's pipeline is landed and trusted, and #279's branch protection is on. Then this issue becomes its own PRD.

TH

เลื่อนโดยการตัดสินเมื่อ 2026-07-28: CI/CD (#275) ลงก่อน · ยื่นไว้เพื่อไม่ให้บทวิเคราะห์หาย ไม่ใช่เพื่อเริ่มตอนนี้

ตารางสถานะการบังคับใช้ใน CLAUDE.md ตอนนี้อ่านว่า "discipline only" ทุกแถว — และนั่นคือการอ่านที่ซื่อสัตย์ ยืนยันกับ checkout นี้แล้ว:

การควบคุม ความจริงวันนี้
PR ต้องอ้าง issue ไม่มี PreToolUse hook ไม่มี .claude/t4.json — ไม่มีอะไรตรวจ
code-review + scrutinize ก่อน merge ไม่มีอะไรยืนยันว่าหลักฐานมีอยู่
verify / เทสต์ ก่อน merge ไม่มี merge hook ใน checkout นี้
git อันตราย (reset --hard, force-push, branch -D) ไม่มี hook ปฏิเสธคำสั่ง
การหยุดก่อนเขียน prod DB ระบุในไฟล์ · ไม่มีกลไก

นี่ไม่ใช่ช่องว่างเชิงทฤษฎี · เมื่อ 2026-07-26 เกตก่อน merge ถูกข้ามใน PR สี่อันในวันเดียว ด้วย heuristic ที่ประดิษฐ์ขึ้นเองซึ่งไม่ปรากฏในเอกสารใด · เมื่อ 2026-07-27 มี PR ถูก merge ขณะที่ CI แดงทั้งสอง context เพราะ loop ที่ poll คืนค่าสำเร็จตอนล้มเหลว และไม่มีอะไรถัดจากนั้นตรวจซ้ำ · ทั้งสองกรณีกฎมีอยู่ · ถูกบันทึกไว้ · และถูกเชื่อ — แต่ไม่มีอะไรบังคับ

CI/CD (#275) แก้อีกครึ่งหนึ่ง: มันทำให้ โค้ด ตรวจสอบได้ · อิชชูนี้ว่าด้วยการทำให้ กระบวนการ ตรวจสอบได้ · ทั้งสองเสริมกันและลำดับเป็นไปโดยเจตนา — เกตที่กั้นการ merge มีค่ามากขึ้นเมื่อมี check ที่คุ้มค่าจะกั้นด้วยแล้ว

สิ่งที่มันจะครอบเมื่อเริ่ม

  • เกต PreToolUse ที่ปฏิเสธ gh pr create ที่ไม่อ้าง issue และปฏิเสธคำสั่ง git อันตรายที่ CLAUDE.md ห้ามอยู่แล้ว
  • การตรวจตอน merge ว่า verify ของรีโปผ่านแล้วจริง แทนที่จะเชื่อว่ามีคนรัน
  • หลักฐานการรีวิวก่อน merge ที่เครื่องตรวจได้ — feat(ci): run the pre-merge gate audit on a schedule #283 ทำให้การ ตรวจจับ ย้อนหลังเป็นอัตโนมัติ · อันนี้คือการ ป้องกัน
  • .claude/t4.json หรือคอนฟิกเทียบเท่าที่ hook เหล่านั้นอ่าน commit ไว้เพื่อให้ clone ใหม่ได้รับไปด้วย
  • ทุกแถวที่มันทำสำเร็จ อัปเดตตารางการบังคับใช้ใน PR เดียวกันพร้อมระบุ artifact · nestjs/test/enforcement-claims-are-backed.spec.ts ล้มอยู่แล้วถ้าคำอ้างไม่ระบุ artifact

เหตุที่ยังไม่เริ่มตอนนี้

hook ฝั่ง client ผูกเฉพาะ agent ที่โหลดมัน · ส่วน branch protection กับ CI ผูกทุกคนและทุกอย่าง รวมถึงการ merge จากหน้าเว็บ GitHub · การสร้างชั้นที่อ่อนกว่าก่อนจะสร้างความมั่นใจเทียมแบบเดียวกับที่ตารางการบังคับใช้ถูกเขียนมาเพื่อกำจัด — ตารางจะได้แถวที่ clone ใหม่หรือ agent ตัวอื่นไม่ทำตาม

เงื่อนไขก่อนหน้า: ไปป์ไลน์ของ #275 ลงและได้รับความเชื่อถือ และ branch protection ของ #279 เปิดแล้ว · จากนั้นอิชชูนี้จึงกลายเป็น PRD ของตัวเอง

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-humanRequires human implementation (secrets/dashboard)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions