From c6d5b4abb79db0c476d44de09ac95c8311d671ea Mon Sep 17 00:00:00 2001 From: bdeshi Date: Thu, 30 Jul 2026 01:39:28 +0600 Subject: [PATCH] harness: say which settings file the exemption means The exemption is Claude Code's permission list, not "settings files". khosra will have its own configuration and none of it is exempt: the engine's settings live in the site root and the engine validates them, while scripts/budgets.env and everything else under scripts/ and .claude/ stays gated. Verified by touching budgets.env and watching the coupling gate fail. --- HARNESS.md | 5 +++-- scripts/verify.sh | 7 +++++-- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/HARNESS.md b/HARNESS.md index ce48c2c..a0d5cfc 100644 --- a/HARNESS.md +++ b/HARNESS.md @@ -142,8 +142,9 @@ The harness is code and drifts like code. Same rule as the engine: **a change sh that describe it, in the same change.** - `verify.sh` fails when `CLAUDE.md`, `scripts/` or `.claude/` changes without `HARNESS.md` - changing — except `.claude/settings.json`, which is permissions rather than mechanism and owes no - explanation. This file is the current description of the machine, not a snapshot of its design. + changing — except `.claude/settings.json`, which is Claude Code's permission list rather than anything + about khosra. That exemption is one path: `scripts/budgets.env` and every other file under `scripts/` + and `.claude/` stays gated, and khosra's own settings are not exempt from anything. This file is the current description of the machine, not a snapshot of its design. - `verify.sh` fails when a `.go` file changes without `docs/state.md` changing, and when `cmd/` or `internal/` code changes without a `_test.go` changing — behaviour ships with a test. A comment-only or `gofmt`-only diff is exempt: it ships no behaviour, and failing it would only teach you `--no-verify`. diff --git a/scripts/verify.sh b/scripts/verify.sh index b8a56dc..0f4ce65 100755 --- a/scripts/verify.sh +++ b/scripts/verify.sh @@ -76,8 +76,11 @@ if [ -d .git ] && command -v git >/dev/null 2>&1; then pass "templates/theme-contract coupling" fi - # settings.json is permissions, not mechanism — HARNESS.md calls it a convenience, so a tweak there - # owes no explanation. Everything else under .claude/ changes how the machine behaves. + # One exemption, and it is about the agent tooling rather than this project: .claude/settings.json is + # Claude Code's own permission list, which HARNESS.md calls a convenience, so editing it explains + # nothing about khosra. khosra's own configuration is not exempt from anything — the engine's settings + # live in the site root (content-model.md) and the engine validates them itself. Everything else under + # .claude/, and all of scripts/ including budgets.env, changes how the machine behaves and is gated. harnesschanged=$(echo "$changed" | grep -E '^(CLAUDE\.md$|scripts/|\.claude/)' | grep -v '^\.claude/settings\.json$' || true) if [ -n "$harnesschanged" ] && ! echo "$changed" | grep -qx 'HARNESS.md'; then bad "the harness changed (CLAUDE.md, scripts/ or .claude/) but HARNESS.md did not — the guide to the machine is part of the machine"