Verified by me on a local merge of29e7a06ontof5e02fe: - One file, one hunk. 5 changed lines inside the canonical block, all of them invariant 5; a line-by-line diff of the block against origin/main shows nothing else moved. - The addendum is untouched: both 'Herdr socket tests (measured 2026-09-10)' and 'Only the lead can run that check' appear once on each side. - Block size: origin/main 17467 chars / 17626 bytes, the merge 17557 chars / 17718 bytes. The worker's numbers were bytes and were right; I am naming both units because len(str) in python is characters and this block is full of em dashes, which is a mistake I have made before. - mvn -B clean test: Tests run: 1583, Failures: 0, Errors: 0, Skipped: 0. BUILD SUCCESS, rc=0. The three things I reserved from the worker, because a provisioned worktree cannot do them: - wiki/7-Use-Cases.md updated to match, in the wiki repo's own commit. - The sync script run in this clone: in sync: True. - Other projects carrying the block: NONE. 29 CLAUDE.md files under the operator's project roots, 18 of them carry the block and 17 of those are this repo's own worktrees, which inherit it from git. Only LTMS/claude-bridge/CLAUDE.md is a real second copy, and it is this file. On the worker's criterion-4 question: the addendum note stays. The restated invariant removes the unsatisfiability, which was the sharp problem, but the note still names the exact four files the carve-out covers and records why (fleetd #449, where a fake and the real herdr disagreed for weeks under a green suite). A rule that is merely satisfiable is not the same as a rule a worker can apply without re-deriving it.
This commit is contained in:
@@ -58,8 +58,9 @@ and the sender silently receives nothing. Fail toward the recoverable error.
|
||||
re-send because a call looks slow — the bridge delivers when the peer is `idle`, `blocked` or
|
||||
`done`. A spawned member must **also** have mounted the bridge MCP: until it has, it is not
|
||||
deliverable, and a send waits on that gate for ~60s and then fails without ever reaching its pane.
|
||||
5. **Never drive the terminal multiplexer directly** (no `herdr` CLI, no socket). The bridge owns
|
||||
policy; the multiplexer owns PTYs. Going around the bridge bypasses every rule above.
|
||||
5. **Never move a fleet session, pane or peer except through the bridge.** The bridge owns policy;
|
||||
the multiplexer owns PTYs. Any route that changes fleet state without the bridge's checks
|
||||
bypasses every rule above — the `herdr` CLI and its socket are the usual example.
|
||||
|
||||
### Primary (lead) — run this on every task, in order
|
||||
|
||||
|
||||
Reference in New Issue
Block a user