Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

# Contributing

Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/7214b6013406e37567c5ebd6c46a23c78f2446a0/labs/12-product-engineering-loop).
Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/e18c8a4e2a77a63476b28f56c84c29289f2b4a47/labs/12-product-engineering-loop).

The Boatstack repository receives product/runtime changes through a generated pull request. Review the PR's `UPSTREAM.json`, tests, adapter diff, and context-size change; do not hand-edit generated output on `main`. `.github/workflows` is the exception: it is Boatstack's executable control plane, excluded from scheduled projection and changed only through a separate manually reviewed Boatstack PR.

Expand Down
15 changes: 8 additions & 7 deletions UPSTREAM.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
},
"files": {
".gitignore": "a7079e923a776f14f1bb3a6aa0a11a133a8e1dfb35af020f327623357b7e3957",
"CONTRIBUTING.md": "cb692f2ba4ccccb546100be7734f3c94602b8c29c8b6f63b8b058dcdc80ef4ec",
"CONTRIBUTING.md": "47d3f95927671ac039764c55029d9522eb094611145605b22c235cea719752dc",
"README.md": "8d481f8e395346400726d02f760f831a8b11062de18b7a76fe4cf00e5e12ca08",
"assets/boatstack-journey.svg": "e465befc50c8ce30f3e07e8fd97012931beeb053392c8fbf38ad645023b3cc63",
"assets/boatstack-mark.svg": "be1f984da1bfa69fa5d1f986d8343d21f7e20921b71db888c928b4d2e54b09b5",
Expand Down Expand Up @@ -41,13 +41,13 @@
"boatstack/delivery.go": "6ff71b6f4ae4f85a184edaf453b5933a79366e36137802fda056e58f83fe319c",
"boatstack/delivery_test.go": "e0323d4e2ef9c74a07c799cf42df91c90a43d61a0fdfddd8b10c5e3e27d5e492",
"boatstack/evidence.go": "497a31e6ff632cb1d7c3adfc9f269af3f6aa84e948dd5d417c162767542a27df",
"boatstack/export.go": "308a6f454b297a9ca068802072afdb039505a2b3fdba5dfb8cc985875a49a008",
"boatstack/export.go": "eab2b510bdb2730d0edeb691fba63a6092e2eefcd06adb4b28b946ae1a235209",
"boatstack/export_test.go": "27f9895f39d0958b5b4824193865a8a30333db709e5b91788aff3d49304457ed",
"boatstack/go.mod": "6086ef1b2a83f5696190dca692c653925f27b61f652f659fd3fca43ed54a1641",
"boatstack/go.sum": "26c315c867b11b886f3c9402fce7f341f6a9115a5d61f54afbb5e1b1fb5f6017",
"boatstack/hooks.go": "2b7d899f92efef8a68a160c423a46bcd6fd37daa0eba2ac8ad44ffa3dc5f88c9",
"boatstack/hooks_test.go": "d71271c0b9ea59b907cc0407a7173d3542281fb2984e6e3c3062ac39b131ec59",
"boatstack/init.go": "018252a3112818191d69ee78dbf8816664e6ef7affde2cb576dbca7a67459c9e",
"boatstack/init.go": "bc484058959202a832c9b6a76c121fcc5a666b5bcfc52ab7a7e9e3f9b37c0887",
"boatstack/init_test.go": "fa48be69d07691fa7842224ec831e5f290504d8b6565263c9735d2dabd9b43b8",
"boatstack/init_transaction.go": "112456c4e1c4db54c4137bcf4f7a9a9e63399a6f5971e9b3dc952d0c4b2aa4b6",
"boatstack/integrations.go": "75b39ce2e662fccd66bf4b9bff0e097a4db558f23b3aa1d9bc83a5fc6373444c",
Expand Down Expand Up @@ -91,10 +91,10 @@
"docs/account-recovery-walkthrough.md": "676034974594a7d1a559b24dbed31d7ccc429eb81404b203ca07bbdaa19ec3d3",
"docs/benchmark-corpus-audit.md": "f2d206fe8579a514f9da82b2c96c19b343ac004be67617e1bd34f0f8e0e5e6c6",
"docs/benchmark-submission-audit.md": "9518abdd17690729c6423f87cab20418ed47b0915b5faa44b9ef975e9e9c3b79",
"docs/evidence-engineered-coding.md": "699203766af7a93584caad922656422a90c1c309ea814da1c7126d4574468229",
"docs/evidence-engineered-coding.md": "b689ca599996074d394a3167a77990fff98d0bd61b686f3485f4803888fac8ed",
"docs/generated-files.md": "136422baf0c7fc2bd5100cfe0ebdb3d9d0705dfd7e7d54bf745dd1037e63492c",
"docs/getting-started.md": "eacc814fdffdfa3c7d8052b7cd99a79c04da5c75d88d8b44f3fb68d9afec0316",
"docs/public-claims.json": "8371581f75f7eff19840137322476e7a58b507093b8fda1c177abf30b85d2e69",
"docs/public-claims.json": "822a677480a83525e736bb6c7d978148586efe60e5ea8c045d1077c616cd5d83",
"docs/public-surface.md": "713f7a050b5f339cf948299103ef3800417dccfecf2cc1a4166397ea6f978907",
"docs/research-and-design.md": "d65c66e323037bda5d45aacef5d48afa6bf93da55901378891d235aca3a5684f",
"docs/safety.md": "7b9b5c515d36e683767ec8d3d9d6d119ac93650b2f629d351deadd4c600ed6a6",
Expand All @@ -108,7 +108,7 @@
"labs/diagram-json/compiled/evidence.md": "1ba1c989ade070a8ef9a508fbd788d100d7292f2dbacbb2bce895468019f619d",
"labs/diagram-json/compiled/tasks.json": "88f60851abf79d851e9fccc754ff3040034ae595306bc87d64784c19eb403e71",
"labs/diagram-json/compiled/test-matrix.json": "424657ff505768e50fa113801fd8363364a18269d5297480907a993d44063a39",
"labs/diagram-json/plan.lock.json": "632437055949355b724b581da4171a928fe95aeec57f7eebc18f1f6e23bef49b",
"labs/diagram-json/plan.lock.json": "9d264ba6ab8b7a47bd234e39863861b5fe78e89961b521b9aad3aea379364118",
"labs/diagram-json/plan.md": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
"labs/diagram-json/questions.md": "74733b015002c8a6777c558e7e997fa48c94850b9bd39054fe9366c97ecf728d",
"labs/diagram-json/request.md": "0808fc41c36779c404f4a3a121167da6e76cac56df526e70f9ed6d3e0d4c02ed",
Expand Down Expand Up @@ -150,6 +150,7 @@
"release-notes/2026-07-20-speak-software-standards.md": "a8890ed7eb38868bdf3035572d71785ca89abd3ffc3a314a5dc5315150afe397",
"release-notes/2026-07-21-blueprint-diagrams-value-first-readme.md": "11eb70cb814a99606b4f7761401d3670074fe6bd1af8557f95f573b04a3195af",
"release-notes/2026-07-21-e2e-architecture-grounding.md": "7fa7e99fc6fd4e0688009bb736e6506830bf0216f3fa19757cbd9f5679c7ac3b",
"release-notes/2026-07-21-execution-interceptor.md": "32dc077ff069d2b685efae2438e3ead619936bc39a6fc967416d50465c2dd640",
"release-notes/2026-07-21-multi-feature-avoidance-dx.md": "a1196a3e1a19466c5c4c86782b3db1ca9a078b0146b9199466bff8a2c263ed0c",
"release-notes/2026-07-21-plan-decision-operator.md": "c2a7416ef17a6042583dd60f1f4e847cb1e0f06b28dbde885479efd566bb5cae",
"release-notes/2026-07-21-prevent-hallucinated-approver-names.md": "a5fd08bc3d8b983340a2ddd67b71c78b2b34a915fdfe6eb7cdffd0f1d52e3427",
Expand All @@ -159,7 +160,7 @@
"generator": "operatorstack/intelligence-flow:boatstack-distribution",
"schema_version": 1,
"source": {
"commit": "7214b6013406e37567c5ebd6c46a23c78f2446a0",
"commit": "e18c8a4e2a77a63476b28f56c84c29289f2b4a47",
"path": "labs/12-product-engineering-loop",
"repository": "operatorstack/intelligence-flow"
}
Expand Down
2 changes: 1 addition & 1 deletion boatstack/export.go
Original file line number Diff line number Diff line change
Expand Up @@ -298,7 +298,7 @@ When the user asks to update Boatstack itself, use /boatstack-update. Release di
Do not branch behavior on model name, provider, or price; branch on observed work state and evidence.
Boatstack's repository hooks deny high-confidence irreversible operations across every agent call. There is no in-session bypass. Preserve failed external state, use read-only diagnosis and fix-forward recovery, and leave intentional destructive recovery to an operator-owned surface outside Boatstack.
`
files[fmt.Sprintf(".cursor/rules/%s.mdc", adapterName)], err = GeneratedFrontmatter(rule + executionModeDX)
files[fmt.Sprintf(".cursor/rules/%s.mdc", adapterName)], err = GeneratedFrontmatter(rule + executionModeDX + "\n" + ExecutionBoundaryDX)
if err != nil {
return ExportBundle{}, err
}
Expand Down
59 changes: 59 additions & 0 deletions boatstack/init.go
Original file line number Diff line number Diff line change
Expand Up @@ -494,6 +494,12 @@ func RunInit(options InitOptions) (returnErr error) {
if err := initCheckpoint("hooks-written"); err != nil {
return fmt.Errorf("initialization checkpoint hooks-written: %w", err)
}
if err := InstallExecutionInterceptors(repo, config.Adapters); err != nil {
return err
}
if err := initCheckpoint("interceptors-written"); err != nil {
return fmt.Errorf("initialization checkpoint interceptors-written: %w", err)
}
binaryPath, binaryHash, err := copyHelper(helperSource, repo)
if err != nil {
return err
Expand Down Expand Up @@ -597,6 +603,59 @@ func RunInit(options InitOptions) (returnErr error) {
return nil
}

const ExecutionBoundaryDX = `
**Boatstack Execution Boundary:**
When the user approves a plan within your native Plan Mode, **do not immediately transition to Auto-Edit or begin mutating product files.** Because this repository is managed by Boatstack, execution must pass through verifiable gates. Instead of executing the code:
1. Save your proposed plan to ` + "`.product-loop/intake/source-plan.md`" + `.
2. Pause and ask the user: *"I have saved the plan. Should we execute this through Boatstack (` + "`/boatstack run`" + `), or do you want me to write the code directly?"*
`

const interceptorHeader = "<!-- BEGIN BOATSTACK EXECUTION INTERCEPTOR -->\n"
const interceptorFooter = "\n<!-- END BOATSTACK EXECUTION INTERCEPTOR -->\n"

func injectExecutionInterceptor(repo, file string) error {
path := filepath.Join(repo, file)
content, err := os.ReadFile(path)
if err != nil {
if os.IsNotExist(err) {
content = []byte{}
} else {
return err
}
}
text := string(content)
start := strings.Index(text, interceptorHeader)
end := strings.Index(text, interceptorFooter)
injection := interceptorHeader + strings.TrimSpace(ExecutionBoundaryDX) + interceptorFooter

if start >= 0 && end > start {
text = text[:start] + injection + text[end+len(interceptorFooter):]
} else {
text = strings.TrimSpace(text) + "\n\n" + injection
}
return os.WriteFile(path, []byte(strings.TrimSpace(text)+"\n"), 0o644)
}

func InstallExecutionInterceptors(repo string, adapters []string) error {
for _, adapter := range adapters {
if adapter == "gemini" {
if err := injectExecutionInterceptor(repo, "GEMINI.md"); err != nil {
return err
}
} else if adapter == "claude" {
if err := injectExecutionInterceptor(repo, "CLAUDE.md"); err != nil {
return err
}
} else if adapter == "cursor" {
if err := injectExecutionInterceptor(repo, ".cursorrules"); err != nil {
return err
}
}
}
return nil
}


func RunUpdate(options InitOptions) error {
options.Update = true
return RunInit(options)
Expand Down
2 changes: 1 addition & 1 deletion docs/evidence-engineered-coding.md
Original file line number Diff line number Diff line change
Expand Up @@ -146,6 +146,6 @@ Delivery and system improvement also remain separate. A failed task may suggest

## What is evidence-backed

The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`7214b6013406e37567c5ebd6c46a23c78f2446a0`](https://github.com/operatorstack/intelligence-flow/tree/7214b6013406e37567c5ebd6c46a23c78f2446a0/labs/12-product-engineering-loop).
The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`e18c8a4e2a77a63476b28f56c84c29289f2b4a47`](https://github.com/operatorstack/intelligence-flow/tree/e18c8a4e2a77a63476b28f56c84c29289f2b4a47/labs/12-product-engineering-loop).

The evidence supports specific failure mechanisms and guardrails. It does not establish that Boatstack is optimal, that control-theory notation proves software quality, or that one workflow dominates every team. Those are evaluation questions, so the distribution preserves measurements, provenance, gaps, and negative results.
24 changes: 12 additions & 12 deletions docs/public-claims.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schema_version": 1,
"source_commit": "7214b6013406e37567c5ebd6c46a23c78f2446a0",
"source_commit": "e18c8a4e2a77a63476b28f56c84c29289f2b4a47",
"statuses": ["verified", "observed", "still_being_evaluated"],
"claims": [
{
Expand All @@ -12,7 +12,7 @@
"readable_evidence": "why-these-steps.md#portable-workflow-and-state",
"implementation": ["../boatstack/export.go", "../boatstack/references/artifacts.md", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/export_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "human-decisions",
Expand All @@ -23,7 +23,7 @@
"readable_evidence": "why-these-steps.md#human-decisions",
"implementation": ["../boatstack/references/workflow.md", "../boatstack/plan.go"],
"verification": ["../boatstack/plan_test.go", "../boatstack/planning_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "validation-provenance",
Expand All @@ -34,7 +34,7 @@
"readable_evidence": "why-these-steps.md#validation-provenance",
"implementation": ["validation-and-evidence.md", "../boatstack/plan.go"],
"verification": ["../boatstack/plan_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "irreversible-operations",
Expand All @@ -46,7 +46,7 @@
"readable_evidence": "why-these-steps.md#irreversible-operations",
"implementation": ["safety.md", "../boatstack/safety.go", "../boatstack/hooks.go"],
"verification": ["../boatstack/safety_test.go", "../boatstack/hooks_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "reviewer-ready-pr",
Expand All @@ -57,7 +57,7 @@
"readable_evidence": "why-these-steps.md#reviewer-ready-pr",
"implementation": ["../boatstack/pr.go", "getting-started.md"],
"verification": ["../boatstack/pr_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "phase-scoped-delivery",
Expand All @@ -68,7 +68,7 @@
"readable_evidence": "why-these-steps.md#phase-scoped-delivery",
"implementation": ["../boatstack/delivery.go", "../boatstack/safety.go", "../boatstack/hooks.go", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/delivery_test.go", "../boatstack/pr_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "model-neutral-contract",
Expand All @@ -79,7 +79,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md", "../boatstack/references/workflow.md"],
"verification": ["../boatstack/export_test.go", "../boatstack/planning_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "cross-model-failures",
Expand All @@ -90,7 +90,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md"],
"verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "lower-cost-outcomes",
Expand All @@ -101,7 +101,7 @@
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
"implementation": ["research-and-design.md"],
"verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "git-worktree-activation",
Expand All @@ -112,7 +112,7 @@
"readable_evidence": "why-these-steps.md#git-worktree-activation",
"implementation": ["../boatstack/runtime_cache.go", "../boatstack/hooks.go"],
"verification": ["../boatstack/runtime_cache_test.go", "../boatstack/hooks_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
},
{
"id": "visible-updates",
Expand All @@ -123,7 +123,7 @@
"readable_evidence": "why-these-steps.md#visible-updates",
"implementation": ["../boatstack/update.go", "../boatstack/init.go"],
"verification": ["../boatstack/update_test.go", "../boatstack/init_test.go", "../boatstack/export_test.go"],
"last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0"
"last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47"
}
]
}
2 changes: 1 addition & 1 deletion labs/diagram-json/plan.lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"plan_path": "labs/diagram-json/plan.md",
"plan_sha256": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
"schema_version": 1,
"source_commit": "7214b6013406e37567c5ebd6c46a23c78f2446a0",
"source_commit": "e18c8a4e2a77a63476b28f56c84c29289f2b4a47",
"source_plan_path": "labs/diagram-json/source-plan.md",
"source_plan_sha256": "e10593ddaa7522ab80cc991d0a09399257139799e37f737794cd49d68a39985b",
"spec_path": "labs/diagram-json/spec.md",
Expand Down
3 changes: 3 additions & 0 deletions release-notes/2026-07-21-execution-interceptor.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
### Intercept eager AI execution from native plan mode

Added a new "Execution Interceptor" boundary rule that is injected into repository global instructions (`GEMINI.md`, `CLAUDE.md`, `.cursorrules`, and `.cursor/rules/boatstack.mdc`) during Boatstack initialization and export. This instructs AI agents (like Gemini, Claude, and Cursor) to pause after the user approves a native plan, save it to `source-plan.md`, and suggest executing it through `/boatstack run` rather than blindly proceeding into Auto-Edit mode to mutate product files.
Loading