WI-7: T-C server-side branch-protection line + R1 honesty doc amendment #834
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Deliverable 7 (BUILD-BRIEF §3.7). The T-C server-side line = branch protection is the irreducible guarantee; the client gate is window-narrowing ONLY. If this is ops-config rather than code, DOCUMENT the required posture explicitly (push/merge to
mainprotected regardless of client-gate state).R1 doc amendment: state honestly that the receipt detects ABSENT/PREFIX-TRUNCATED terminal token, but a MIDDLE-DROP preserving the tail is a T-C contract violation (server-side covers, receipt does not). No over-claim. Fold as a doc amendment.
Functional/doc surface — may take GPT review (NOT a peercred/gate/receipt security surface).
Authority (build AGAINST these, do not re-derive): BUILD-BRIEF
89fdbc27, SPEC-v5a6d07ade, RATIFICATIONbac58319, sol red-team3da326a4. Coder MUST re-verify sha256 before build. Target: framework-nativepackages/mosaic/inmosaicstack/stack(NOT jarvis-brain, NOT~/.config/mosaic/directly). M1 = Claude + Pi only.Review discipline: red-first TDD; author≠reviewer; no self-merge; exact-head RoR (reviewed-SHA=merged-SHA);
closes #<this>; full 40-char head; never edit tests to pass / never force-merge red / never--no-verify. Mos merges after review + green suite + (for security surfaces) Opus-SECREV.Mos tripwire (ratification): GPT-OK holds ONLY while this WI stays DOCUMENTATION of the required branch-protection POSTURE + R1 honesty doc amendment (ops-config/prose). IF it grows any ENFORCEMENT CODE (a gate/hook/policy that server-side blocks a mutation), it FLIPS to a security surface = Opus-SECREV, no GPT sub. Scope-check at build; report which it turned out to be.