From 152575b73dd8ac81df7cb6799f707c468368a0c6 Mon Sep 17 00:00:00 2001 From: japabu Date: Sat, 3 Oct 2026 23:36:16 +0200 Subject: [PATCH 1/5] A branch other than main belongs to its implementer, who may amend, rebase and force-push it The owner ruled on 2026-10-03 that an agent may do what it wants with its local copy, including remaking a commit it has not pushed, and that a remote branch other than main may be force-pushed: its implementer owns it. Root CLAUDE.md's "Working here" forbade --amend, rebase and --force on every branch, so that bullet now states the rulings. `git commit -F ` stays. main stays as the next bullet already holds it: it moves only through a merged pull request and is protected against push and force-push. The grant names this repository's branches. A fork branch is named by main's lockfiles and gitlinks, no single implementer owns it, and implementer.md's "A fork" keeps a fix a commit appended to it. No role prompt forbade a rewrite. The rules that read a pushed head hold without new words: a reviewer reads the head its brief names and diffs a later head against the last reviewed one, both of which stay in the object store every worktree shares after a force-push; a pull request body is kept true of the branch as it stands; an issue that cites a hash is a record kept true of what it describes (root CLAUDE.md, "Prose"). Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8 --- CLAUDE.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CLAUDE.md b/CLAUDE.md index 5e480bcea0b..99063970e22 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -84,7 +84,7 @@ The root `Cargo.toml`'s `[workspace]` `members` and `exclude` lists account for - **Always be empirical.** Read actual output; run the code; investigate root causes instead of guessing. Every written number comes from a command that was run; an estimate or datasheet bound says so. - **Never put the owner's email or any other personal data in a network request or its headers**; any `User-Agent` is `toyos-build (https://github.com/ToyOSOrg/ToyOS)`. Nothing that identifies his machines or network goes into the tree, a commit message or anything posted on GitHub, and one that has to be referred to there is named by where it stands and its kind, with no character of it; `src/sourcegate.rs` names the shapes. - **One agent, one worktree, one branch.** The primary checkout owns `rust/`, the rustup link and `main`, and is no workspace; `.claude/agents/implementer.md` makes a worktree and `orchestrator.md` removes it. Never make one with `git clone`, and never run `git submodule` in one: either fetches the fork's history again, a clone builds a toolchain that takes the rustup link, and `git submodule` writes `core.worktree` into the fork's shared config, which breaks git in the primary's `rust/`. -- **Commit freely on your branch; never rewrite history.** `git commit -F `, never `-m`. No `--amend`, no `rebase`, no `--force` — merge `origin/main` instead: a pushed hash may already be cited. +- **Commit freely on your branch.** `git commit -F `, never `-m`. A branch of this repository other than `main`, local or remote, belongs to its implementer, who may amend, rebase and force-push it. - **Never touch `main`.** It moves only through a merged pull request, by its required merge queue, and is protected — no push, force-push, deletion or bypass. A pull request's title and body become the merge commit's: write them as `main`'s record. A branch lands after a review against `.claude/agents/reviewer.md`. A modify/delete conflict is resolved by accounting for every hunk of the modified side, never by checking its headings survived. A merge that deletes a document also deletes every citation to it in the same merge, found by searching the bare name as well as the path. An ABI change lands with the work that needs it: every worktree builds the toolchain its own sources name, so branches that change the ABI run side by side. Every merge leaves `main`'s tip compiling. ## Prose From f5b4203d8f3faad1326c9b6e58c5325b54edb7c4 Mon Sep 17 00:00:00 2001 From: japabu Date: Sun, 4 Oct 2026 00:05:17 +0200 Subject: [PATCH 2/5] Answer review round 1: the local grant covers an agent's unpushed commits in a fork clone too, and only the remote grant stops at this repository The owner's local ruling, "yes agents can do with their local copy what they want", names no repository. It was given when he was asked whether an agent may remake a commit it has not pushed. No lockfile or gitlink can name such a commit, and only that agent made it. The bullet now grants it as he gave it: an agent does what it wants with the commits it made and has not pushed, in a fork clone too. His remote ruling, "remote non main branches can be force pushed i dont care what happens to them the implementers own them", names no repository either. Its scope comes from "the implementers own them". No implementer owns a fork's branch: implementer.md's "A fork" keeps one branch per upstream base, and every worktree appends its fixes to it. So the bullet keeps "of this repository" on the remote grant. It also says that a commit pushed to a fork's branch is never rewritten. That was the removed "never rewrite history" clause's job there. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8 --- CLAUDE.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CLAUDE.md b/CLAUDE.md index 99063970e22..36352c1bc95 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -84,7 +84,7 @@ The root `Cargo.toml`'s `[workspace]` `members` and `exclude` lists account for - **Always be empirical.** Read actual output; run the code; investigate root causes instead of guessing. Every written number comes from a command that was run; an estimate or datasheet bound says so. - **Never put the owner's email or any other personal data in a network request or its headers**; any `User-Agent` is `toyos-build (https://github.com/ToyOSOrg/ToyOS)`. Nothing that identifies his machines or network goes into the tree, a commit message or anything posted on GitHub, and one that has to be referred to there is named by where it stands and its kind, with no character of it; `src/sourcegate.rs` names the shapes. - **One agent, one worktree, one branch.** The primary checkout owns `rust/`, the rustup link and `main`, and is no workspace; `.claude/agents/implementer.md` makes a worktree and `orchestrator.md` removes it. Never make one with `git clone`, and never run `git submodule` in one: either fetches the fork's history again, a clone builds a toolchain that takes the rustup link, and `git submodule` writes `core.worktree` into the fork's shared config, which breaks git in the primary's `rust/`. -- **Commit freely on your branch.** `git commit -F `, never `-m`. A branch of this repository other than `main`, local or remote, belongs to its implementer, who may amend, rebase and force-push it. +- **Commit freely on your branch.** `git commit -F `, never `-m`. An agent does what it wants with the commits it made and has not pushed, in a fork clone too. A remote branch of this repository other than `main` belongs to its implementer, who may amend, rebase and force-push it; a fork's branch belongs to no implementer, and what is pushed to it is never rewritten. - **Never touch `main`.** It moves only through a merged pull request, by its required merge queue, and is protected — no push, force-push, deletion or bypass. A pull request's title and body become the merge commit's: write them as `main`'s record. A branch lands after a review against `.claude/agents/reviewer.md`. A modify/delete conflict is resolved by accounting for every hunk of the modified side, never by checking its headings survived. A merge that deletes a document also deletes every citation to it in the same merge, found by searching the bare name as well as the path. An ABI change lands with the work that needs it: every worktree builds the toolchain its own sources name, so branches that change the ABI run side by side. Every merge leaves `main`'s tip compiling. ## Prose From 9e9bc5eae872e3d70b6cd7d8896d40c4f684589d Mon Sep 17 00:00:00 2001 From: japabu Date: Sun, 4 Oct 2026 00:27:04 +0200 Subject: [PATCH 3/5] Answer review round 2: the remote grant reaches the branches one implementer owns, a fork's per-agent branch included, and a fork's shared branch is append-only Round 2 found the remote grant scoped by repository, which his words do not do: "remote non main branches can be force pushed i dont care what happens to them the implementers own them" covers a per-agent branch of the rust fork, such as wt-toyos-launchonce, which one implementer pushes from its worktree's own rust/ checkout. The grant is now scoped by ownership, as his words are. Asked whether the shared fork branches stay append-only while per-agent fork branches may be force-pushed like any other, the owner answered "Shared ones append-only". The clause says that, and replaces "a fork's branch belongs to no implementer, and what is pushed to it is never rewritten", which round 2 found false of the rust fork. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8 --- CLAUDE.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CLAUDE.md b/CLAUDE.md index 36352c1bc95..68eea089157 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -84,7 +84,7 @@ The root `Cargo.toml`'s `[workspace]` `members` and `exclude` lists account for - **Always be empirical.** Read actual output; run the code; investigate root causes instead of guessing. Every written number comes from a command that was run; an estimate or datasheet bound says so. - **Never put the owner's email or any other personal data in a network request or its headers**; any `User-Agent` is `toyos-build (https://github.com/ToyOSOrg/ToyOS)`. Nothing that identifies his machines or network goes into the tree, a commit message or anything posted on GitHub, and one that has to be referred to there is named by where it stands and its kind, with no character of it; `src/sourcegate.rs` names the shapes. - **One agent, one worktree, one branch.** The primary checkout owns `rust/`, the rustup link and `main`, and is no workspace; `.claude/agents/implementer.md` makes a worktree and `orchestrator.md` removes it. Never make one with `git clone`, and never run `git submodule` in one: either fetches the fork's history again, a clone builds a toolchain that takes the rustup link, and `git submodule` writes `core.worktree` into the fork's shared config, which breaks git in the primary's `rust/`. -- **Commit freely on your branch.** `git commit -F `, never `-m`. An agent does what it wants with the commits it made and has not pushed, in a fork clone too. A remote branch of this repository other than `main` belongs to its implementer, who may amend, rebase and force-push it; a fork's branch belongs to no implementer, and what is pushed to it is never rewritten. +- **Commit freely on your branch.** `git commit -F `, never `-m`. An agent does what it wants with the commits it made and has not pushed, in a fork clone too. A remote branch other than `main` that one implementer owns, a fork's per-agent branch included, is that implementer's to amend, rebase and force-push; a fork's shared branch is append-only. - **Never touch `main`.** It moves only through a merged pull request, by its required merge queue, and is protected — no push, force-push, deletion or bypass. A pull request's title and body become the merge commit's: write them as `main`'s record. A branch lands after a review against `.claude/agents/reviewer.md`. A modify/delete conflict is resolved by accounting for every hunk of the modified side, never by checking its headings survived. A merge that deletes a document also deletes every citation to it in the same merge, found by searching the bare name as well as the path. An ABI change lands with the work that needs it: every worktree builds the toolchain its own sources name, so branches that change the ABI run side by side. Every merge leaves `main`'s tip compiling. ## Prose From 2a243d3be60e9faff51776c322433db9c2463719 Mon Sep 17 00:00:00 2001 From: japabu Date: Sun, 4 Oct 2026 00:39:24 +0200 Subject: [PATCH 4/5] Answer review round 3: a fork's branches are append-only, and the force-push grant stops at this repository Round 3 found that the bullet granted a force-push of "a fork's per-agent branch" in the window after `main` pins its commit, a case the owner did not rule on. The orchestrator's ruling settles it from implementer.md's "A fork": a fork keeps one branch per upstream base and a fix is a commit appended to it, never a new branch, so every fork branch is shared, and the owner's "Shared ones append-only" covers all of them. The remote grant now names this repository's branches other than `main` that one implementer owns. Files the pin `96441690a` set, `0e27504731a5f6a2f7c9d43e9e40e6b28b56a0e5`, which seven commits of main's history carry and which no repository holds. It was never pushed: a short-hash collision with the fork head of the time, as `4670353eb`'s message records. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8 --- CLAUDE.md | 2 +- ...y-pin-a-rust-commit-no-repository-holds.md | 50 +++++++++++++++++++ 2 files changed, 51 insertions(+), 1 deletion(-) create mode 100644 issues/build/seven-commits-of-mains-history-pin-a-rust-commit-no-repository-holds.md diff --git a/CLAUDE.md b/CLAUDE.md index 68eea089157..329af0f0cf2 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -84,7 +84,7 @@ The root `Cargo.toml`'s `[workspace]` `members` and `exclude` lists account for - **Always be empirical.** Read actual output; run the code; investigate root causes instead of guessing. Every written number comes from a command that was run; an estimate or datasheet bound says so. - **Never put the owner's email or any other personal data in a network request or its headers**; any `User-Agent` is `toyos-build (https://github.com/ToyOSOrg/ToyOS)`. Nothing that identifies his machines or network goes into the tree, a commit message or anything posted on GitHub, and one that has to be referred to there is named by where it stands and its kind, with no character of it; `src/sourcegate.rs` names the shapes. - **One agent, one worktree, one branch.** The primary checkout owns `rust/`, the rustup link and `main`, and is no workspace; `.claude/agents/implementer.md` makes a worktree and `orchestrator.md` removes it. Never make one with `git clone`, and never run `git submodule` in one: either fetches the fork's history again, a clone builds a toolchain that takes the rustup link, and `git submodule` writes `core.worktree` into the fork's shared config, which breaks git in the primary's `rust/`. -- **Commit freely on your branch.** `git commit -F `, never `-m`. An agent does what it wants with the commits it made and has not pushed, in a fork clone too. A remote branch other than `main` that one implementer owns, a fork's per-agent branch included, is that implementer's to amend, rebase and force-push; a fork's shared branch is append-only. +- **Commit freely on your branch.** `git commit -F `, never `-m`. An agent does what it wants with the commits it made and has not pushed, in a fork clone too. A remote branch of this repository other than `main` that one implementer owns is that implementer's to amend, rebase and force-push; a fork's branches are append-only. - **Never touch `main`.** It moves only through a merged pull request, by its required merge queue, and is protected — no push, force-push, deletion or bypass. A pull request's title and body become the merge commit's: write them as `main`'s record. A branch lands after a review against `.claude/agents/reviewer.md`. A modify/delete conflict is resolved by accounting for every hunk of the modified side, never by checking its headings survived. A merge that deletes a document also deletes every citation to it in the same merge, found by searching the bare name as well as the path. An ABI change lands with the work that needs it: every worktree builds the toolchain its own sources name, so branches that change the ABI run side by side. Every merge leaves `main`'s tip compiling. ## Prose diff --git a/issues/build/seven-commits-of-mains-history-pin-a-rust-commit-no-repository-holds.md b/issues/build/seven-commits-of-mains-history-pin-a-rust-commit-no-repository-holds.md new file mode 100644 index 00000000000..c9e89fceb26 --- /dev/null +++ b/issues/build/seven-commits-of-mains-history-pin-a-rust-commit-no-repository-holds.md @@ -0,0 +1,50 @@ +--- +status: open +kind: defect +opened: 2026-10-04 +--- + +# Seven commits of `main`'s history pin a `rust` commit no repository holds + +`96441690a` set the `rust` gitlink to `0e27504731a5f6a2f7c9d43e9e40e6b28b56a0e5`, +and seven commits of `main`'s history carry it, from `96441690a` to `7810c9f66` +on `wt/toyos-endow`'s side of its merge `44bc5acce`. `4670353eb` moved the pin +to `d91d5a423`. Those seven commits cannot be built: the toolchain their tree +names is not on the fork. + +The pin was never pushed. `4670353eb`'s message says the fork head then was +`0e27504731a51efe`, which shares twelve hex characters with the pin, so every +short-hash check that branch ran took the one for the other. No force-push lost +it. + +## Measured + +At `42e5fca73`: + +- `git ls-tree 96441690a rust` prints + `0e27504731a5f6a2f7c9d43e9e40e6b28b56a0e5`. +- `git rev-parse "$c:rust"` for every `c` in `git rev-list origin/main` prints + that commit for seven: `96441690a`, `4fc34a222`, `904353fb3`, `f34bf3460`, + `1efa027cd`, `bc2a814cd`, `7810c9f66`. None is on `main`'s first-parent line. +- `gh api repos/ToyOSOrg/rust/commits/0e27504731a5f6a2f7c9d43e9e40e6b28b56a0e5` + answers HTTP 422, `No commit found for SHA`. +- In the primary checkout's `rust/`, after `git fetch origin`, + `git cat-file -t 0e27504731a5f6a2f7c9d43e9e40e6b28b56a0e5` exits 128, and + `git rev-parse 0e2750473` prints `0e27504731a51efe39976648db289afadfdb2fbe`: + a nine-character short hash names the other commit. + +## Read, not measured + +No check sees whether a commit a branch carries pins a `rust` commit the fork +holds. A worktree's build fetches its pin from the primary checkout's `rust/` +(`sysroot::fork_checkout`), never from the fork, so a commit made there and +never pushed builds green. + +## Owner + +Unassigned: the orchestrator, which lands every pull request that moves the +`rust` gitlink, assigns it. + +**Exit**: a pull request any of whose commits pins a `rust` commit no fork +branch holds is refused before it lands. The seven commits above stay +unbuildable; the closing commit records them. From b8ab31974709c0d28728e0180f3c0b9cce88ffbb Mon Sep 17 00:00:00 2001 From: japabu Date: Sun, 4 Oct 2026 01:03:45 +0200 Subject: [PATCH 5/5] Answer review round 4: the unreachable-rust-commit issue is kind tooling It describes the build machine and main's history, not a ToyOS behaviour. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WcU2Dsw6mDYtwYfzVHPzM8 --- ...ts-of-mains-history-pin-a-rust-commit-no-repository-holds.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/issues/build/seven-commits-of-mains-history-pin-a-rust-commit-no-repository-holds.md b/issues/build/seven-commits-of-mains-history-pin-a-rust-commit-no-repository-holds.md index c9e89fceb26..2f52d8cb545 100644 --- a/issues/build/seven-commits-of-mains-history-pin-a-rust-commit-no-repository-holds.md +++ b/issues/build/seven-commits-of-mains-history-pin-a-rust-commit-no-repository-holds.md @@ -1,6 +1,6 @@ --- status: open -kind: defect +kind: tooling opened: 2026-10-04 ---