From 29e7a06c49f4923f5186da3a9987d0f2c3ef2676 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Thu, 10 Sep 2026 18:50:41 +0700 Subject: [PATCH] fleetd #458: restate invariant 5 by purpose, not mechanism Invariant 5 banned 'driving the terminal multiplexer directly', naming herdr CLI and socket as the banned tool. That bans a mechanism. What it protects is the control plane: nobody may move a fleet session, pane or peer by a route that skips the bridge's policy checks. In this repo herdr is itself the subject under test, so four contract tests must open its socket on purpose (see the addendum's 'Herdr socket tests' note). Under the old wording, a worker assigned to that code reads invariant 5 and finds its only path to finish the task banned. Restate the invariant by purpose: never move fleet state except through the bridge. herdr's CLI and socket stay as the named example of the banned route, not the definition of it. --- CLAUDE.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 09fd3fe..1e99cbc 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -58,8 +58,9 @@ and the sender silently receives nothing. Fail toward the recoverable error. re-send because a call looks slow — the bridge delivers when the peer is `idle`, `blocked` or `done`. A spawned member must **also** have mounted the bridge MCP: until it has, it is not deliverable, and a send waits on that gate for ~60s and then fails without ever reaching its pane. -5. **Never drive the terminal multiplexer directly** (no `herdr` CLI, no socket). The bridge owns - policy; the multiplexer owns PTYs. Going around the bridge bypasses every rule above. +5. **Never move a fleet session, pane or peer except through the bridge.** The bridge owns policy; + the multiplexer owns PTYs. Any route that changes fleet state without the bridge's checks + bypasses every rule above — the `herdr` CLI and its socket are the usual example. ### Primary (lead) — run this on every task, in order