diff --git a/.claude/settings.json b/.claude/settings.json index ac4bff5..2613e9c 100644 --- a/.claude/settings.json +++ b/.claude/settings.json @@ -27,14 +27,11 @@ "Bash(curl -s http://127.0.0.1:*)" ], "ask": [ - "Bash(go get:*)", - "Bash(git commit:*)" + "Bash(go get:*)" ], "deny": [ "Bash(git push:*)", "Bash(rm -rf:*)", - "Read(./.env)", - "Read(./.env.*)", "Read(./.envrc)" ] } diff --git a/HARNESS.md b/HARNESS.md index d9af4c3..dcd6c02 100644 --- a/HARNESS.md +++ b/HARNESS.md @@ -140,7 +140,8 @@ The harness is code and drifts like code. Same rule as the engine: **a change sh that describe it, in the same change.** - `verify.sh` fails when `CLAUDE.md`, `scripts/` or `.claude/` changes without `HARNESS.md` - changing. This file is the current description of the machine, not a snapshot of its design. + changing — except `.claude/settings.json`, which is permissions rather than mechanism and owes no + explanation. This file is the current description of the machine, not a snapshot of its design. - `verify.sh` fails when a `.go` file changes without `docs/state.md` changing, and when `cmd/` or `internal/` code changes without a `_test.go` changing — behaviour ships with a test. A comment-only or `gofmt`-only diff is exempt: it ships no behaviour, and failing it would only teach you `--no-verify`. diff --git a/scripts/verify.sh b/scripts/verify.sh index a730e46..0ff885c 100755 --- a/scripts/verify.sh +++ b/scripts/verify.sh @@ -76,7 +76,10 @@ if [ -d .git ] && command -v git >/dev/null 2>&1; then pass "templates/theme-contract coupling" fi - if echo "$changed" | grep -qE '^(CLAUDE\.md$|scripts/|\.claude/)' && ! echo "$changed" | grep -qx 'HARNESS.md'; then + # settings.json is permissions, not mechanism — HARNESS.md calls it a convenience, so a tweak there + # owes no explanation. Everything else under .claude/ changes how the machine behaves. + harnesschanged=$(echo "$changed" | grep -E '^(CLAUDE\.md$|scripts/|\.claude/)' | grep -v '^\.claude/settings\.json$' || true) + if [ -n "$harnesschanged" ] && ! echo "$changed" | grep -qx 'HARNESS.md'; then bad "the harness changed (CLAUDE.md, scripts/ or .claude/) but HARNESS.md did not — the guide to the machine is part of the machine" else pass "harness/HARNESS.md coupling"