Require default execution rails for all harness agents.

Codify authorize → plan → build → review → check → local-only save so
Grok Build stays on process without the user naming every slash command.
This commit is contained in:
Ty
2026-07-27 10:13:30 -07:00
parent 47327d90d8
commit ce087533fa
5 changed files with 116 additions and 9 deletions
+81 -3
View File
@@ -12,8 +12,11 @@ Remote: Gitea **Ty_Tech/Salon_Assistant** (via **gitea_vps** MCP only for this p
3. [`design/scenarios.md`](design/scenarios.md)
4. [`design/DECISIONS.md`](design/DECISIONS.md)
5. [`docs/README.md`](docs/README.md) (operator manuals)
6. **This files [Git hygiene](#git-hygiene-mandatory)**binding for every agent session
7. [`CONTRIBUTING.md`](CONTRIBUTING.md) for PR/branch detail
6. **[Execution loop](#execution-loop-mandatory)** — default harness rails (plan → build → review → check → commit)
7. **[Git hygiene](#git-hygiene-mandatory)** — binding for every agent session
8. [`CONTRIBUTING.md`](CONTRIBUTING.md) for PR/branch detail
Also auto-loaded under `.grok/rules/`: `execution-loop.md`, `git-hygiene.md`.
## Hard rules
@@ -23,7 +26,8 @@ Remote: Gitea **Ty_Tech/Salon_Assistant** (via **gitea_vps** MCP only for this p
- Owner never gets terminal/nano/docker instructions.
- No agent pay; no silent send/publish.
- **`design/`** = product POR SSOT; **`docs/`** = operator runbooks.
- **Git hygiene below is mandatory** for every agent (Grok, Claude, Cursor, subagents, scripts).
- **Execution loop + Git hygiene below are mandatory** for every agent (Grok, Claude, Cursor, subagents, workflows, scripts).
- **Do not require the user to restate process.** If they authorize work without naming every step, still run the rails. Only the user may *narrow* scope or *skip* a gate (e.g. “docs-only, skip check-work”).
## Git MCP
@@ -34,6 +38,80 @@ Remote: Gitea **Ty_Tech/Salon_Assistant** (via **gitea_vps** MCP only for this p
---
## Execution loop (mandatory)
Default path for **any** non-trivial change. The user does **not** need to type each slash command; the agent **must still execute the gates**. Slash commands (`/plan`, `/review`, `/check-work`, `/execute-plan`, …) are preferred when available; equivalent manual steps (plan in chat, independent reviewer subagent, verifier subagent) are required if skills are not invoked by name.
```text
Authorize → Plan (if needed) → Build → Review → Check → Local commit (if asked) → User pushes
```
### Authorize (hard stop)
| User said… | Agent may… |
|------------|------------|
| **build** / **implement** (with or without slice) | Product implementation within stated or agreed slice |
| Design / docs / hygiene / scaffolding structure only | Edit design, docs, agent rules, README scaffolds — **not** product runtime code until **build** |
| Vague “continue” / “do it” **after** an approved plan or build slice | Continue **that** slice only; do not expand scope |
| Nothing authorizing build | **No** product implementation |
If scope is unclear after **build**, ask **one** clarifying question or propose a minimal slice and wait — do **not** invent a multi-package rewrite.
### Default gates (do these without being asked)
1. **Plan** — If approach is ambiguous or multi-file architecture is involved: enter plan mode / write a short plan and get approval **or** follow an existing approved plan/design section. Skip plan only for trivial single-concern edits (typo, one obvious fix).
2. **Build** — Implement only the authorized slice. Prefer main session for one sequential change.
3. **Review** — Independent review of the diff (prefer `/review --local`, else a **read-only** reviewer subagent). Address **bugs** before claiming done; suggestions/nits: fix or note wontfix with reason.
4. **Check** — Verify work (prefer `/check-work`, else a verifier subagent / `make verify` when implementation exists). Do not mark complete on green review alone.
5. **Save** — Commit **only** when the user asks (commit / checkpoint / prepare local commit). **Never push, open/merge PR, or tag** unless the user explicitly asks. User owns `git push` by default.
### Subagents & orchestration (rails, not free-for-all)
| Rule | Requirement |
|------|-------------|
| Roles | **Implementers** edit; **reviewers/explorers/verifiers** are read-only (no source edits). |
| Isolation | Parallel writers → `isolation: "worktree"`. Do not parallel-edit the main tree. |
| Scope | One concern per implementer. No “implement half the product” prompts. |
| Product rules | Every implementer/reviewer prompt **must** include or inherit: this files hard rules, authorized slice, no secrets, platform-first, owner-safe messaging. |
| Resume | Fix cycles: `resume_from` same implementer/reviewer. After ~4 review-fix rounds, escalate disagreement to the user or refresh reviewer — do not thrash forever silently. |
| Orchestrator | Main agent (or `/execute-plan` orchestrator) owns sequencing, git policy, and user-facing status. Subagents do not push/merge. |
| Multi-PR | Only with an explicit PR Plan DAG (`## PR Plan` / `### PR N:`). Prefer `/execute-plan --dry-run` first. This repo: **`--no-graphite`**, **no auto-PR**, **no push/merge** unless user overrides in writing. |
| Workflows | Allowed for repeatable gates; must not bypass authorize/review/check/git hygiene. Effectful git still needs user-gated commit/push rules above. |
| best-of-n | Only when user asks or two architectures must be compared with a clear eval. |
### Stop conditions (do not “push through”)
Stop and report to the user when:
- Authorized slice is done (review + check clean, or issues listed).
- Build was never authorized.
- Plan is blocked on a product decision only the user can make.
- Review/check finds **bugs** you cannot fix without expanding scope.
- Secrets, destructive git, or forge mismatch (GitHub/`gh` assumptions on this Gitea product) would be required.
- Subagent wants to rewrite `design/` SSOT or add a parallel control API.
### Anti-rails (forbidden defaults)
- Implementing product code because “were in execution mode” without **build** / **implement**.
- Skipping review **and** check on a multi-file change.
- Self-only review (same agent edits and declares “LGTM” with no independent pass).
- Push/PR/merge/tag as a surprise side effect of “finishing.”
- Expanding into neighboring packages/skills “while here.”
- Using GitHub/`gh`/Graphite flows as defaults on this Gitea product.
- Weakening these rules in a subdirectory `AGENTS.md` or subagent prompt.
### Tiny-change exception
Single-file or pure typo/docs nit: plan optional; still **no push**; still no secrets; still no build without authorize. Prefer a quick diff self-check; full `/review` + `/check-work` strongly recommended once tests/scripts exist.
### Related
- Git details: [Git hygiene](#git-hygiene-mandatory)
- Human/agent PR conventions: [`CONTRIBUTING.md`](CONTRIBUTING.md)
- Short Grok rule mirror: [`.grok/rules/execution-loop.md`](.grok/rules/execution-loop.md)
---
## Git hygiene (mandatory)
Every agent that opens or works in this workspace **must** follow these practices. Deeper dirs inherit this file; do not weaken these rules in subdirectory `AGENTS.md` files.