diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index cffbf18..037f196 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -2,7 +2,7 @@ # Contributing -Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/7214b6013406e37567c5ebd6c46a23c78f2446a0/labs/12-product-engineering-loop). +Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/e18c8a4e2a77a63476b28f56c84c29289f2b4a47/labs/12-product-engineering-loop). The Boatstack repository receives product/runtime changes through a generated pull request. Review the PR's `UPSTREAM.json`, tests, adapter diff, and context-size change; do not hand-edit generated output on `main`. `.github/workflows` is the exception: it is Boatstack's executable control plane, excluded from scheduled projection and changed only through a separate manually reviewed Boatstack PR. diff --git a/UPSTREAM.json b/UPSTREAM.json index 019af31..8d3677f 100644 --- a/UPSTREAM.json +++ b/UPSTREAM.json @@ -12,7 +12,7 @@ }, "files": { ".gitignore": "a7079e923a776f14f1bb3a6aa0a11a133a8e1dfb35af020f327623357b7e3957", - "CONTRIBUTING.md": "cb692f2ba4ccccb546100be7734f3c94602b8c29c8b6f63b8b058dcdc80ef4ec", + "CONTRIBUTING.md": "47d3f95927671ac039764c55029d9522eb094611145605b22c235cea719752dc", "README.md": "8d481f8e395346400726d02f760f831a8b11062de18b7a76fe4cf00e5e12ca08", "assets/boatstack-journey.svg": "e465befc50c8ce30f3e07e8fd97012931beeb053392c8fbf38ad645023b3cc63", "assets/boatstack-mark.svg": "be1f984da1bfa69fa5d1f986d8343d21f7e20921b71db888c928b4d2e54b09b5", @@ -41,13 +41,13 @@ "boatstack/delivery.go": "6ff71b6f4ae4f85a184edaf453b5933a79366e36137802fda056e58f83fe319c", "boatstack/delivery_test.go": "e0323d4e2ef9c74a07c799cf42df91c90a43d61a0fdfddd8b10c5e3e27d5e492", "boatstack/evidence.go": "497a31e6ff632cb1d7c3adfc9f269af3f6aa84e948dd5d417c162767542a27df", - "boatstack/export.go": "308a6f454b297a9ca068802072afdb039505a2b3fdba5dfb8cc985875a49a008", + "boatstack/export.go": "eab2b510bdb2730d0edeb691fba63a6092e2eefcd06adb4b28b946ae1a235209", "boatstack/export_test.go": "27f9895f39d0958b5b4824193865a8a30333db709e5b91788aff3d49304457ed", "boatstack/go.mod": "6086ef1b2a83f5696190dca692c653925f27b61f652f659fd3fca43ed54a1641", "boatstack/go.sum": "26c315c867b11b886f3c9402fce7f341f6a9115a5d61f54afbb5e1b1fb5f6017", "boatstack/hooks.go": "2b7d899f92efef8a68a160c423a46bcd6fd37daa0eba2ac8ad44ffa3dc5f88c9", "boatstack/hooks_test.go": "d71271c0b9ea59b907cc0407a7173d3542281fb2984e6e3c3062ac39b131ec59", - "boatstack/init.go": "018252a3112818191d69ee78dbf8816664e6ef7affde2cb576dbca7a67459c9e", + "boatstack/init.go": "bc484058959202a832c9b6a76c121fcc5a666b5bcfc52ab7a7e9e3f9b37c0887", "boatstack/init_test.go": "fa48be69d07691fa7842224ec831e5f290504d8b6565263c9735d2dabd9b43b8", "boatstack/init_transaction.go": "112456c4e1c4db54c4137bcf4f7a9a9e63399a6f5971e9b3dc952d0c4b2aa4b6", "boatstack/integrations.go": "75b39ce2e662fccd66bf4b9bff0e097a4db558f23b3aa1d9bc83a5fc6373444c", @@ -91,10 +91,10 @@ "docs/account-recovery-walkthrough.md": "676034974594a7d1a559b24dbed31d7ccc429eb81404b203ca07bbdaa19ec3d3", "docs/benchmark-corpus-audit.md": "f2d206fe8579a514f9da82b2c96c19b343ac004be67617e1bd34f0f8e0e5e6c6", "docs/benchmark-submission-audit.md": "9518abdd17690729c6423f87cab20418ed47b0915b5faa44b9ef975e9e9c3b79", - "docs/evidence-engineered-coding.md": "699203766af7a93584caad922656422a90c1c309ea814da1c7126d4574468229", + "docs/evidence-engineered-coding.md": "b689ca599996074d394a3167a77990fff98d0bd61b686f3485f4803888fac8ed", "docs/generated-files.md": "136422baf0c7fc2bd5100cfe0ebdb3d9d0705dfd7e7d54bf745dd1037e63492c", "docs/getting-started.md": "eacc814fdffdfa3c7d8052b7cd99a79c04da5c75d88d8b44f3fb68d9afec0316", - "docs/public-claims.json": "8371581f75f7eff19840137322476e7a58b507093b8fda1c177abf30b85d2e69", + "docs/public-claims.json": "822a677480a83525e736bb6c7d978148586efe60e5ea8c045d1077c616cd5d83", "docs/public-surface.md": "713f7a050b5f339cf948299103ef3800417dccfecf2cc1a4166397ea6f978907", "docs/research-and-design.md": "d65c66e323037bda5d45aacef5d48afa6bf93da55901378891d235aca3a5684f", "docs/safety.md": "7b9b5c515d36e683767ec8d3d9d6d119ac93650b2f629d351deadd4c600ed6a6", @@ -108,7 +108,7 @@ "labs/diagram-json/compiled/evidence.md": "1ba1c989ade070a8ef9a508fbd788d100d7292f2dbacbb2bce895468019f619d", "labs/diagram-json/compiled/tasks.json": "88f60851abf79d851e9fccc754ff3040034ae595306bc87d64784c19eb403e71", "labs/diagram-json/compiled/test-matrix.json": "424657ff505768e50fa113801fd8363364a18269d5297480907a993d44063a39", - "labs/diagram-json/plan.lock.json": "632437055949355b724b581da4171a928fe95aeec57f7eebc18f1f6e23bef49b", + "labs/diagram-json/plan.lock.json": "9d264ba6ab8b7a47bd234e39863861b5fe78e89961b521b9aad3aea379364118", "labs/diagram-json/plan.md": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51", "labs/diagram-json/questions.md": "74733b015002c8a6777c558e7e997fa48c94850b9bd39054fe9366c97ecf728d", "labs/diagram-json/request.md": "0808fc41c36779c404f4a3a121167da6e76cac56df526e70f9ed6d3e0d4c02ed", @@ -150,6 +150,7 @@ "release-notes/2026-07-20-speak-software-standards.md": "a8890ed7eb38868bdf3035572d71785ca89abd3ffc3a314a5dc5315150afe397", "release-notes/2026-07-21-blueprint-diagrams-value-first-readme.md": "11eb70cb814a99606b4f7761401d3670074fe6bd1af8557f95f573b04a3195af", "release-notes/2026-07-21-e2e-architecture-grounding.md": "7fa7e99fc6fd4e0688009bb736e6506830bf0216f3fa19757cbd9f5679c7ac3b", + "release-notes/2026-07-21-execution-interceptor.md": "32dc077ff069d2b685efae2438e3ead619936bc39a6fc967416d50465c2dd640", "release-notes/2026-07-21-multi-feature-avoidance-dx.md": "a1196a3e1a19466c5c4c86782b3db1ca9a078b0146b9199466bff8a2c263ed0c", "release-notes/2026-07-21-plan-decision-operator.md": "c2a7416ef17a6042583dd60f1f4e847cb1e0f06b28dbde885479efd566bb5cae", "release-notes/2026-07-21-prevent-hallucinated-approver-names.md": "a5fd08bc3d8b983340a2ddd67b71c78b2b34a915fdfe6eb7cdffd0f1d52e3427", @@ -159,7 +160,7 @@ "generator": "operatorstack/intelligence-flow:boatstack-distribution", "schema_version": 1, "source": { - "commit": "7214b6013406e37567c5ebd6c46a23c78f2446a0", + "commit": "e18c8a4e2a77a63476b28f56c84c29289f2b4a47", "path": "labs/12-product-engineering-loop", "repository": "operatorstack/intelligence-flow" } diff --git a/boatstack/export.go b/boatstack/export.go index 7c3b54a..c01852b 100644 --- a/boatstack/export.go +++ b/boatstack/export.go @@ -298,7 +298,7 @@ When the user asks to update Boatstack itself, use /boatstack-update. Release di Do not branch behavior on model name, provider, or price; branch on observed work state and evidence. Boatstack's repository hooks deny high-confidence irreversible operations across every agent call. There is no in-session bypass. Preserve failed external state, use read-only diagnosis and fix-forward recovery, and leave intentional destructive recovery to an operator-owned surface outside Boatstack. ` - files[fmt.Sprintf(".cursor/rules/%s.mdc", adapterName)], err = GeneratedFrontmatter(rule + executionModeDX) + files[fmt.Sprintf(".cursor/rules/%s.mdc", adapterName)], err = GeneratedFrontmatter(rule + executionModeDX + "\n" + ExecutionBoundaryDX) if err != nil { return ExportBundle{}, err } diff --git a/boatstack/init.go b/boatstack/init.go index 48cfb29..d951194 100644 --- a/boatstack/init.go +++ b/boatstack/init.go @@ -494,6 +494,12 @@ func RunInit(options InitOptions) (returnErr error) { if err := initCheckpoint("hooks-written"); err != nil { return fmt.Errorf("initialization checkpoint hooks-written: %w", err) } + if err := InstallExecutionInterceptors(repo, config.Adapters); err != nil { + return err + } + if err := initCheckpoint("interceptors-written"); err != nil { + return fmt.Errorf("initialization checkpoint interceptors-written: %w", err) + } binaryPath, binaryHash, err := copyHelper(helperSource, repo) if err != nil { return err @@ -597,6 +603,59 @@ func RunInit(options InitOptions) (returnErr error) { return nil } +const ExecutionBoundaryDX = ` +**Boatstack Execution Boundary:** +When the user approves a plan within your native Plan Mode, **do not immediately transition to Auto-Edit or begin mutating product files.** Because this repository is managed by Boatstack, execution must pass through verifiable gates. Instead of executing the code: +1. Save your proposed plan to ` + "`.product-loop/intake/source-plan.md`" + `. +2. Pause and ask the user: *"I have saved the plan. Should we execute this through Boatstack (` + "`/boatstack run`" + `), or do you want me to write the code directly?"* +` + +const interceptorHeader = "\n" +const interceptorFooter = "\n\n" + +func injectExecutionInterceptor(repo, file string) error { + path := filepath.Join(repo, file) + content, err := os.ReadFile(path) + if err != nil { + if os.IsNotExist(err) { + content = []byte{} + } else { + return err + } + } + text := string(content) + start := strings.Index(text, interceptorHeader) + end := strings.Index(text, interceptorFooter) + injection := interceptorHeader + strings.TrimSpace(ExecutionBoundaryDX) + interceptorFooter + + if start >= 0 && end > start { + text = text[:start] + injection + text[end+len(interceptorFooter):] + } else { + text = strings.TrimSpace(text) + "\n\n" + injection + } + return os.WriteFile(path, []byte(strings.TrimSpace(text)+"\n"), 0o644) +} + +func InstallExecutionInterceptors(repo string, adapters []string) error { + for _, adapter := range adapters { + if adapter == "gemini" { + if err := injectExecutionInterceptor(repo, "GEMINI.md"); err != nil { + return err + } + } else if adapter == "claude" { + if err := injectExecutionInterceptor(repo, "CLAUDE.md"); err != nil { + return err + } + } else if adapter == "cursor" { + if err := injectExecutionInterceptor(repo, ".cursorrules"); err != nil { + return err + } + } + } + return nil +} + + func RunUpdate(options InitOptions) error { options.Update = true return RunInit(options) diff --git a/docs/evidence-engineered-coding.md b/docs/evidence-engineered-coding.md index dc619d3..c1d0957 100644 --- a/docs/evidence-engineered-coding.md +++ b/docs/evidence-engineered-coding.md @@ -146,6 +146,6 @@ Delivery and system improvement also remain separate. A failed task may suggest ## What is evidence-backed -The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`7214b6013406e37567c5ebd6c46a23c78f2446a0`](https://github.com/operatorstack/intelligence-flow/tree/7214b6013406e37567c5ebd6c46a23c78f2446a0/labs/12-product-engineering-loop). +The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`e18c8a4e2a77a63476b28f56c84c29289f2b4a47`](https://github.com/operatorstack/intelligence-flow/tree/e18c8a4e2a77a63476b28f56c84c29289f2b4a47/labs/12-product-engineering-loop). The evidence supports specific failure mechanisms and guardrails. It does not establish that Boatstack is optimal, that control-theory notation proves software quality, or that one workflow dominates every team. Those are evaluation questions, so the distribution preserves measurements, provenance, gaps, and negative results. diff --git a/docs/public-claims.json b/docs/public-claims.json index c8ab53f..a2a2659 100644 --- a/docs/public-claims.json +++ b/docs/public-claims.json @@ -1,6 +1,6 @@ { "schema_version": 1, - "source_commit": "7214b6013406e37567c5ebd6c46a23c78f2446a0", + "source_commit": "e18c8a4e2a77a63476b28f56c84c29289f2b4a47", "statuses": ["verified", "observed", "still_being_evaluated"], "claims": [ { @@ -12,7 +12,7 @@ "readable_evidence": "why-these-steps.md#portable-workflow-and-state", "implementation": ["../boatstack/export.go", "../boatstack/references/artifacts.md", "../boatstack/references/workflow.md"], "verification": ["../boatstack/export_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "human-decisions", @@ -23,7 +23,7 @@ "readable_evidence": "why-these-steps.md#human-decisions", "implementation": ["../boatstack/references/workflow.md", "../boatstack/plan.go"], "verification": ["../boatstack/plan_test.go", "../boatstack/planning_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "validation-provenance", @@ -34,7 +34,7 @@ "readable_evidence": "why-these-steps.md#validation-provenance", "implementation": ["validation-and-evidence.md", "../boatstack/plan.go"], "verification": ["../boatstack/plan_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "irreversible-operations", @@ -46,7 +46,7 @@ "readable_evidence": "why-these-steps.md#irreversible-operations", "implementation": ["safety.md", "../boatstack/safety.go", "../boatstack/hooks.go"], "verification": ["../boatstack/safety_test.go", "../boatstack/hooks_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "reviewer-ready-pr", @@ -57,7 +57,7 @@ "readable_evidence": "why-these-steps.md#reviewer-ready-pr", "implementation": ["../boatstack/pr.go", "getting-started.md"], "verification": ["../boatstack/pr_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "phase-scoped-delivery", @@ -68,7 +68,7 @@ "readable_evidence": "why-these-steps.md#phase-scoped-delivery", "implementation": ["../boatstack/delivery.go", "../boatstack/safety.go", "../boatstack/hooks.go", "../boatstack/references/workflow.md"], "verification": ["../boatstack/delivery_test.go", "../boatstack/pr_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "model-neutral-contract", @@ -79,7 +79,7 @@ "readable_evidence": "why-these-steps.md#model-choice-and-budget", "implementation": ["research-and-design.md", "../boatstack/references/workflow.md"], "verification": ["../boatstack/export_test.go", "../boatstack/planning_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "cross-model-failures", @@ -90,7 +90,7 @@ "readable_evidence": "why-these-steps.md#model-choice-and-budget", "implementation": ["research-and-design.md"], "verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "lower-cost-outcomes", @@ -101,7 +101,7 @@ "readable_evidence": "why-these-steps.md#model-choice-and-budget", "implementation": ["research-and-design.md"], "verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "git-worktree-activation", @@ -112,7 +112,7 @@ "readable_evidence": "why-these-steps.md#git-worktree-activation", "implementation": ["../boatstack/runtime_cache.go", "../boatstack/hooks.go"], "verification": ["../boatstack/runtime_cache_test.go", "../boatstack/hooks_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" }, { "id": "visible-updates", @@ -123,7 +123,7 @@ "readable_evidence": "why-these-steps.md#visible-updates", "implementation": ["../boatstack/update.go", "../boatstack/init.go"], "verification": ["../boatstack/update_test.go", "../boatstack/init_test.go", "../boatstack/export_test.go"], - "last_verified_version": "source:7214b6013406e37567c5ebd6c46a23c78f2446a0" + "last_verified_version": "source:e18c8a4e2a77a63476b28f56c84c29289f2b4a47" } ] } diff --git a/labs/diagram-json/plan.lock.json b/labs/diagram-json/plan.lock.json index 68a6629..7a8e68f 100644 --- a/labs/diagram-json/plan.lock.json +++ b/labs/diagram-json/plan.lock.json @@ -6,7 +6,7 @@ "plan_path": "labs/diagram-json/plan.md", "plan_sha256": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51", "schema_version": 1, - "source_commit": "7214b6013406e37567c5ebd6c46a23c78f2446a0", + "source_commit": "e18c8a4e2a77a63476b28f56c84c29289f2b4a47", "source_plan_path": "labs/diagram-json/source-plan.md", "source_plan_sha256": "e10593ddaa7522ab80cc991d0a09399257139799e37f737794cd49d68a39985b", "spec_path": "labs/diagram-json/spec.md", diff --git a/release-notes/2026-07-21-execution-interceptor.md b/release-notes/2026-07-21-execution-interceptor.md new file mode 100644 index 0000000..5fcd678 --- /dev/null +++ b/release-notes/2026-07-21-execution-interceptor.md @@ -0,0 +1,3 @@ +### Intercept eager AI execution from native plan mode + +Added a new "Execution Interceptor" boundary rule that is injected into repository global instructions (`GEMINI.md`, `CLAUDE.md`, `.cursorrules`, and `.cursor/rules/boatstack.mdc`) during Boatstack initialization and export. This instructs AI agents (like Gemini, Claude, and Cursor) to pause after the user approves a native plan, save it to `source-plan.md`, and suggest executing it through `/boatstack run` rather than blindly proceeding into Auto-Edit mode to mutate product files.