From ae72a5214e2344761e845c9b9d765a0784269c88 Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Mon, 28 Sep 2026 19:03:59 +0200 Subject: [PATCH 1/3] docs: add the final-HEAD review gate to CLAUDE.md Moves the CUDly review gate here from the global dotclaude pr-lifecycle skill, refreshed to the current policy: Opus 5.5 adversarial review, CodeRabbit optional under exact-revision verification, green CI, macOS local plus Linux CI, merge only at the reviewed SHA. Closes #2108 --- CLAUDE.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/CLAUDE.md b/CLAUDE.md index ef1c69e4d..09473d0dd 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -145,6 +145,23 @@ justification reply on the thread", not "PR opened and CR pinged". When in doubt, copy the iteration loop above (steps 2–6) into the fork prompt verbatim. +## Review gate + +Merge only at the reviewed SHA, and only when all of these cover it: + +- An independent adversarial review of the full PR diff on Opus 5.5 + (exact model `claude-opus-5-5`; never Fable, a floating alias, or a + cross-provider substitute) names the SHA and has no open actionable + findings. +- CodeRabbit is optional when exact-revision local verification plus a + thorough independent review cover the SHA; otherwise run the loop above. +- CI is green on the SHA. +- Local verification exercises the real affected scenario on macOS; + Linux is covered by CI. Windows is out of scope. + +Any new commit or rebase restarts the gate. A missing reviewer or +verification blocks the PR; it is never clean by assumption. + ## PR labeling — mirror closing-issue labels (MANDATORY) Every PR opened in this repo must carry the **same** triage labels as From a5c39cbb48f21bdf25ca2c362c28c6c09f9711d7 Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Mon, 28 Sep 2026 19:07:47 +0200 Subject: [PATCH 2/3] docs(claude-md): make the CodeRabbit loop consistent with the review gate --- CLAUDE.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 09473d0dd..f99b14852 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -106,11 +106,12 @@ Forgetting this rule has been a recurring failure mode in this project. Before declaring a "pushed and done" turn complete, confirm at least one `ci-watch-*` background task is armed. -## CodeRabbit loop — iterate to silence (MANDATORY) +## CodeRabbit loop: iterate to silence (when required by the review gate) -CodeRabbit reviews this repo on every push to a PR branch. The full +Run this loop when CodeRabbit is the chosen review path, or when the +independent-review condition in "Review gate" below is not met. The full rules live in `~/.claude/git-workflow.md` §"Post-PR review loop" -(§§3, 3a) — read them. The minimum-viable loop for this project: +(§§3, 3a); read them. The minimum-viable loop for this project: 1. After every push, ping `@coderabbitai review` on the PR (CR doesn't always re-review automatically; the explicit ping makes it From 68850998988c7c50557cbab243659f66ba787c82 Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Mon, 28 Sep 2026 19:16:07 +0200 Subject: [PATCH 3/3] docs(claude-md): complete the review gate --- CLAUDE.md | 32 +++++++++++++++++++------------- 1 file changed, 19 insertions(+), 13 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index f99b14852..26fd82182 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -136,7 +136,8 @@ rules live in `~/.claude/git-workflow.md` §"Post-PR review loop" Forgetting this rule leaves CR threads silently unresolved and pushes the triage burden onto the human reviewer. -**When delegating PR work to a subagent**: the prompt MUST include the +When the CodeRabbit loop applies (see Review gate) and you are +**delegating PR work to a subagent**, the prompt MUST include the full CR loop, not stop at the first `@coderabbitai review` ping. A fork that pushes the PR, pings CR, then exits leaves the CR threads unresolved — same failure mode as forgetting the post-push CI watcher. @@ -152,16 +153,21 @@ Merge only at the reviewed SHA, and only when all of these cover it: - An independent adversarial review of the full PR diff on Opus 5.5 (exact model `claude-opus-5-5`; never Fable, a floating alias, or a - cross-provider substitute) names the SHA and has no open actionable - findings. -- CodeRabbit is optional when exact-revision local verification plus a - thorough independent review cover the SHA; otherwise run the loop above. -- CI is green on the SHA. -- Local verification exercises the real affected scenario on macOS; - Linux is covered by CI. Windows is out of scope. - -Any new commit or rebase restarts the gate. A missing reviewer or -verification blocks the PR; it is never clean by assumption. + cross-provider substitute) names the SHA. +- All actionable findings from any reviewer (independent review, + CodeRabbit, CI) are resolved. CodeRabbit is optional when + exact-revision local verification plus a thorough independent review + cover the SHA; otherwise run the loop above. CI is green on the SHA. +- Local verification exercises the real affected scenario on macOS + (Linux via CI; Windows out of scope). Label fixture- or mock-based + evidence as such; it does not count as real-scenario verification. +- The verdict, the reviewed SHA and the local verification evidence are + recorded on the PR itself. + +Merge normally; never bypass failing or required checks (no +`gh pr merge --admin`, no `--no-verify`). Verification never authorizes +real purchases, deploys or the CLI's `--yes`. Any new commit or rebase +restarts the gate; a missing reviewer or verification blocks the PR. ## PR labeling — mirror closing-issue labels (MANDATORY) @@ -172,8 +178,8 @@ it. Skipping this leaves PRs invisible to the same priority queries that surface the issues, so an unlabeled PR is effectively unreviewable in priority order. -Mechanics — fold into the **same `gh pr create` round**, before pinging -CodeRabbit: +Mechanics: apply the labels right after `gh pr create`, in the same +round: ```bash # Right after `gh pr create ...` returns the PR URL: