Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

# Contributing

Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/3c770b5db125ad5f28515380c59c4d1718e3a020/labs/12-product-engineering-loop).
Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/9a3cafb4f5040ed787390607b7cd6ced843588ea/labs/12-product-engineering-loop).

The Boatstack repository receives product/runtime changes through a generated pull request. Review the PR's `UPSTREAM.json`, tests, adapter diff, and context-size change; do not hand-edit generated output on `main`. `.github/workflows` is the exception: it is Boatstack's executable control plane, excluded from scheduled projection and changed only through a separate manually reviewed Boatstack PR.

Expand Down
15 changes: 8 additions & 7 deletions UPSTREAM.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
},
"files": {
".gitignore": "a7079e923a776f14f1bb3a6aa0a11a133a8e1dfb35af020f327623357b7e3957",
"CONTRIBUTING.md": "57832885d79ec4dc777699fd52028e297bf787041a927299b38cbf3d51bb5a21",
"CONTRIBUTING.md": "c0ea4700fd74f0930812adde111a8719f13697963d027905f71a6251a68a548f",
"README.md": "3ce3e95e511089b44e946a44b8d5f4f81d019ece5336db65b2cab1f9dc4d4dad",
"assets/boatstack-journey.svg": "e465befc50c8ce30f3e07e8fd97012931beeb053392c8fbf38ad645023b3cc63",
"assets/boatstack-mark.svg": "be1f984da1bfa69fa5d1f986d8343d21f7e20921b71db888c928b4d2e54b09b5",
Expand Down Expand Up @@ -160,8 +160,8 @@
"boatstack/runtime_cache.go": "e026ffc1906f7e1e98b768bae63e6658164d2826c07169c9121ce0f23c73faf8",
"boatstack/runtime_cache_test.go": "b981467ddc9f0f562da6bff5de7a80a9fe5a433a0317541d1e48df268546ac85",
"boatstack/runtime_provenance_test.go": "1d52f1e6b0691cf4667729cc9b9f3c55c128f0aa3321f3a2843a9aa6fd0e73dc",
"boatstack/safety.go": "31dbeb58ff22359812fee8e4113d47ebb563733908d17eddb264fe9e92fe2ca7",
"boatstack/safety_test.go": "c5c5413e66266a5159e56e6f9681fc5fdce4c4e53174f207c1605b639bd9d686",
"boatstack/safety.go": "e21cc46048e51ed973096a4c4f1c32908aff79cfba8f2f75a301c5f6521656c8",
"boatstack/safety_test.go": "500ad53cd5e3a700553eb781d9eaf4028ae27478796759a76bfd57321fff5a7c",
"boatstack/safety_update_publisher_test.go": "ed3f8187036623694dfe7c395cdae00fdae14609bab6124d1fdfc6fe73fa2196",
"boatstack/skill_frontmatter.go": "73364df463ce828c2d005aab55f72bb92f7a34d99cf3f53d4e0cd5a4da9dbd0e",
"boatstack/skill_frontmatter_test.go": "a3ec52e7df357a72265c95dd66db15d9c0effc7e5f90f14ce69c27792ce394eb",
Expand All @@ -187,10 +187,10 @@
"docs/benchmark-corpus-audit.md": "f2d206fe8579a514f9da82b2c96c19b343ac004be67617e1bd34f0f8e0e5e6c6",
"docs/benchmark-submission-audit.md": "9518abdd17690729c6423f87cab20418ed47b0915b5faa44b9ef975e9e9c3b79",
"docs/configuration.md": "060775c73431f28bd16066bdf9e0f89034d2855c7ca0f5544f660d24b91211d0",
"docs/evidence-engineered-coding.md": "0c0e344f5eae535c5b406ed1bff51c807fd31aa7768668491888d3f9f84df293",
"docs/evidence-engineered-coding.md": "1e76e625f5e891abdc08384ef3fc91559232c9e8a43f2c64a61798990f122337",
"docs/generated-files.md": "437791765b0a4015032ae21d1a6618563cad92b7402819e4f963bf5ae16284a3",
"docs/getting-started.md": "51c2823f21e35140d31e6d5083dc4b89fddd24721ac6acc474154a4da53ee9f8",
"docs/public-claims.json": "1cf62f1ffa0d5fadd49c7c4843143a09ffa38a1d78309de590378542a5a8ea78",
"docs/public-claims.json": "cfa12bb1b55a8d1a7a5e70565298caaae19151e972d31bb16820128dac92cb7f",
"docs/public-surface.md": "713f7a050b5f339cf948299103ef3800417dccfecf2cc1a4166397ea6f978907",
"docs/research-and-design.md": "8d78678108f0a6c924e1ff9b32c0f81aae9d1f779e0082843b6f99ad993ae2b6",
"docs/safety.md": "7b9b5c515d36e683767ec8d3d9d6d119ac93650b2f629d351deadd4c600ed6a6",
Expand All @@ -204,7 +204,7 @@
"labs/diagram-json/compiled/evidence.md": "1ba1c989ade070a8ef9a508fbd788d100d7292f2dbacbb2bce895468019f619d",
"labs/diagram-json/compiled/tasks.json": "88f60851abf79d851e9fccc754ff3040034ae595306bc87d64784c19eb403e71",
"labs/diagram-json/compiled/test-matrix.json": "424657ff505768e50fa113801fd8363364a18269d5297480907a993d44063a39",
"labs/diagram-json/plan.lock.json": "dc95b0ece06634bae69a6f010a0d1fb49c6b2c43659031a29b78c891466deade",
"labs/diagram-json/plan.lock.json": "96fd7a684a7324c8443881e4defc991e25846f83f41eac6a027f3129337fb188",
"labs/diagram-json/plan.md": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
"labs/diagram-json/questions.md": "74733b015002c8a6777c558e7e997fa48c94850b9bd39054fe9366c97ecf728d",
"labs/diagram-json/request.md": "0808fc41c36779c404f4a3a121167da6e76cac56df526e70f9ed6d3e0d4c02ed",
Expand Down Expand Up @@ -318,6 +318,7 @@
"release-notes/2026-07-26-guard-hydrate-double-check.md": "83a5591aba6bf30c9f4008ba8d26bf1994ef3fd61145f46fcdd1678912b9990b",
"release-notes/2026-07-26-hidden-jflow-design-note.md": "f60ed9dbbfb46a172ac9d33dd758a3166f820007b1673029f29f0fbefa0e5c0a",
"release-notes/2026-07-26-workspace-reap.md": "e691d6a1c232cf218157880655413005fcb2c4f3113ededffdb80899a5054bb8",
"release-notes/2026-07-27-constitutional-boundary-floor.md": "41514cbea53867c264e354f149638444ab0d80f64896b9cf720f3979ae78b3de",
"release-notes/2026-07-27-coreachable-recovery.md": "6ffc6b0e9a7d46c0f99a64112813c33d19571c73d02e98ac5573924f1663fd54",
"release-notes/2026-07-27-discoverable-planning-errors.md": "d8099d1a6cd1805c3fcd446d9fa95739dec93e57ff421ecf4f99562b143c9966",
"release-notes/2026-07-27-invalid-delivery-block-actionable.md": "8fac8e3921e2285291703efa46e624b72cb5bac1b8492beca4c4b633abb5ba16",
Expand All @@ -326,7 +327,7 @@
"generator": "operatorstack/intelligence-flow:boatstack-distribution",
"schema_version": 1,
"source": {
"commit": "3c770b5db125ad5f28515380c59c4d1718e3a020",
"commit": "9a3cafb4f5040ed787390607b7cd6ced843588ea",
"path": "labs/12-product-engineering-loop",
"repository": "operatorstack/intelligence-flow"
}
Expand Down
10 changes: 10 additions & 0 deletions boatstack/safety.go
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,16 @@ func malformedHookInput(code string) error {
// still banned in isPureReadOnlyCommand, so no filter can be turned into a writer.
var readOnlyStage = regexp.MustCompile(`(?i)^\s*(?:env\s+[^ ]+\s+)*(?:rg|grep|git\s+(?:grep|diff|status|show|log)|cat|sed|head|tail|less|wc|awk|sort|uniq|cut|tr|jq|column|nl|comm|rev|fold|find\s+[^\n]*-(?:print|ls)|psql\s+[^\n]*\s-c\s+["']?\s*select\b|(?:[^\s]*/)?boatstack-helper(?:[_.-][a-z0-9._-]+)?\s+(?:recovery-status|mutation-status|operation-status|delivery-status|next-status|workspace-status|repair-status|check-plan|check-source-plan|check-safety|diagnose-hook|doctor|version)\b)`)

// Constitutional/Optimization split. These destruction rules are CONSTITUTIONAL:
// they define the real boundary (destroying a live resource) and are never traded
// for convenience — no project config knob disables them; config may only ADD
// scope (HighRiskPaths). The executor-gating around them (the scanSQL argument to
// classifySafetyText; the executed-vs-data file distinction; the artifact exemption
// on committed diffs) is the OPTIMIZATION surface: it narrows WHEN a rule is
// observed to cut false positives, but it may never disable the boundary — when the
// executor is live, a constitutional rule must still fire. That floor is enforced by
// TestExecutorGatingNeverDisablesTheBoundary.
//
// irreversiblePatterns classify destruction by text. Rules whose regex names its
// own EXECUTOR (rm, git, terraform, supabase db reset, …) are self-executing:
// matching the text is sound because the text IS the command. Rules marked
Expand Down
37 changes: 37 additions & 0 deletions boatstack/safety_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -198,6 +198,43 @@ func TestReadOnlyInspectionPipelinesAllowed(t *testing.T) {
}
}

// Constitutional/Optimization split: the executor-gating optimization narrows WHEN
// a destruction rule is observed (to cut false positives) but must NEVER disable the
// boundary. When the executor is live the constitutional rule still fires; the
// optimization's benefit (data operations pass) does not become a leak; and no
// project config can trade the boundary away.
func TestExecutorGatingNeverDisablesTheBoundary(t *testing.T) {
repo := safetyTestRepo(t)
if err := os.WriteFile(filepath.Join(repo, "migrate.sql"), []byte("DROP TABLE accounts;\n"), 0o644); err != nil {
t.Fatal(err)
}
// Optimization FLOOR: a live executor still blocks (the gating did not disable it).
mustBlock := []string{
`psql -c "DROP TABLE accounts"`, // executor-gated SQL, live client
`psql -f migrate.sql`, // live client runs a DDL file it executes
`rm -rf /`, // self-executing constitutional
`terraform destroy -auto-approve`, // self-executing constitutional
`supabase db reset`, // self-executing constitutional
`git push --force origin main`, // self-executing constitutional
}
for _, command := range mustBlock {
if findings := ClassifyCommand(repo, command); len(findings) == 0 {
t.Errorf("optimization disabled the boundary — live destruction allowed: %q", command)
}
}
// Optimization BENEFIT (not a leak): the same DDL as inert data passes, because
// no live executor observes it.
mustPass := []string{
"git add migrate.sql",
`git commit -m "add migration with DROP TABLE accounts"`,
}
for _, command := range mustPass {
if findings := ClassifyCommand(repo, command); len(findings) != 0 {
t.Errorf("data operation wrongly blocked: %q -> %#v", command, findings)
}
}
}

func TestSafeDiagnosticsAndFixForwardCommandsRemainAllowed(t *testing.T) {
repo := safetyTestRepo(t)
safeScript := filepath.Join(repo, "scripts", "apply_schema.py")
Expand Down
2 changes: 1 addition & 1 deletion docs/evidence-engineered-coding.md
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,6 @@ Delivery and system improvement also remain separate. A failed task may suggest

## What is evidence-backed

The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`3c770b5db125ad5f28515380c59c4d1718e3a020`](https://github.com/operatorstack/intelligence-flow/tree/3c770b5db125ad5f28515380c59c4d1718e3a020/labs/12-product-engineering-loop).
The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`9a3cafb4f5040ed787390607b7cd6ced843588ea`](https://github.com/operatorstack/intelligence-flow/tree/9a3cafb4f5040ed787390607b7cd6ced843588ea/labs/12-product-engineering-loop).

The evidence supports specific failure mechanisms and guardrails. It does not establish that Boatstack is optimal, that control-theory notation proves software quality, or that one workflow dominates every team. Those are evaluation questions, so the distribution preserves measurements, provenance, gaps, and negative results.
24 changes: 12 additions & 12 deletions docs/public-claims.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schema_version": 1,
"source_commit": "3c770b5db125ad5f28515380c59c4d1718e3a020",
"source_commit": "9a3cafb4f5040ed787390607b7cd6ced843588ea",
"statuses": ["verified", "observed", "still_being_evaluated"],
"claims": [
{
Expand All @@ -12,7 +12,7 @@
"readable_evidence": "why-these-steps.md#portable-workflow-and-state",
"implementation": ["../boatstack/export.go", "../boatstack/references/artifacts.md", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/export_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "human-decisions",
Expand All @@ -23,7 +23,7 @@
"readable_evidence": "why-these-steps.md#human-decisions",
"implementation": ["../boatstack/references/workflow.md", "../boatstack/plan.go"],
"verification": ["../boatstack/plan_test.go", "../boatstack/planning_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "validation-provenance",
Expand All @@ -34,7 +34,7 @@
"readable_evidence": "why-these-steps.md#validation-provenance",
"implementation": ["validation-and-evidence.md", "../boatstack/plan.go"],
"verification": ["../boatstack/plan_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "irreversible-operations",
Expand All @@ -46,7 +46,7 @@
"readable_evidence": "why-these-steps.md#irreversible-operations",
"implementation": ["safety.md", "../boatstack/safety.go", "../boatstack/hooks.go"],
"verification": ["../boatstack/safety_test.go", "../boatstack/hooks_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "reviewer-ready-pr",
Expand All @@ -57,7 +57,7 @@
"readable_evidence": "why-these-steps.md#reviewer-ready-pr",
"implementation": ["../boatstack/pr.go", "getting-started.md"],
"verification": ["../boatstack/pr_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "phase-scoped-delivery",
Expand All @@ -68,7 +68,7 @@
"readable_evidence": "why-these-steps.md#phase-scoped-delivery",
"implementation": ["../boatstack/delivery.go", "../boatstack/safety.go", "../boatstack/hooks.go", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/delivery_test.go", "../boatstack/pr_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "model-neutral-contract",
Expand All @@ -79,7 +79,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/export_test.go", "../boatstack/planning_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "cross-model-failures",
Expand All @@ -90,7 +90,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md"],
"verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "lower-cost-outcomes",
Expand All @@ -101,7 +101,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md"],
"verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "git-worktree-activation",
Expand All @@ -112,7 +112,7 @@
"readable_evidence": "why-these-steps.md#git-worktree-activation",
"implementation": ["../boatstack/runtime_cache.go", "../boatstack/hooks.go"],
"verification": ["../boatstack/runtime_cache_test.go", "../boatstack/hooks_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
},
{
"id": "visible-updates",
Expand All @@ -123,7 +123,7 @@
"readable_evidence": "why-these-steps.md#visible-updates",
"implementation": ["../boatstack/update.go", "../boatstack/init.go"],
"verification": ["../boatstack/update_test.go", "../boatstack/init_test.go", "../boatstack/export_test.go"],
"last_verified_version": "source:3c770b5db125ad5f28515380c59c4d1718e3a020"
"last_verified_version": "source:9a3cafb4f5040ed787390607b7cd6ced843588ea"
}
]
}
2 changes: 1 addition & 1 deletion labs/diagram-json/plan.lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"plan_path": "labs/diagram-json/plan.md",
"plan_sha256": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
"schema_version": 1,
"source_commit": "3c770b5db125ad5f28515380c59c4d1718e3a020",
"source_commit": "9a3cafb4f5040ed787390607b7cd6ced843588ea",
"source_plan_path": "labs/diagram-json/source-plan.md",
"source_plan_sha256": "e10593ddaa7522ab80cc991d0a09399257139799e37f737794cd49d68a39985b",
"spec_path": "labs/diagram-json/spec.md",
Expand Down
16 changes: 16 additions & 0 deletions release-notes/2026-07-27-constitutional-boundary-floor.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
### The destruction boundary is guaranteed to survive its own optimization

The guard now decides destruction by effect: it asks which executor runs a command, not whether a file
or a message spells a keyword. That change removed false positives — committing a migration, staging a
schema file, editing a note. This release records and enforces the limit of that optimization.

The rule that decides destruction is constitutional. It defines the real boundary — destroying a live
resource — and is never traded for convenience. No project setting disables it; a setting can only add
scope. The executor check that narrows when the rule is observed is an optimization: it exists to cut
false positives, and it may never let a live destructive command through. When the executor is live, the
rule still fires.

A conformance test now holds this floor. A live database client running a drop, a client running a
migration file, a recursive delete, an infrastructure destroy, a database reset, and a force push are
all still denied, while the same SQL sitting inert in a staged or committed file passes. The benefit of
the optimization does not become a leak, and the boundary cannot be optimized away.
Loading