The Harness
The Rings

Ring 1 · Branch Rules

Brief validation

ci

Ever seen a PR title that told you nothing about what changed?

Re-checks in CI that a pull request’s title and brief sections are properly formed.

PR-report density

ci

Ever read a PR body whose Summary quietly grew into three paragraphs nobody actually reads?

Re-checks that a pull request's `## Summary` and `## Scope` sections are each exactly one paragraph, per the canonical PR-body form.

Closes linkage

ci

Ever had a PR merge and it wasn't clear which ticket it actually closed?

Re-checks that a pull request names the Issue it closes.

Writing to pull requests or Issues through the raw API

event

Ever had a bot silently edit a PR or issue behind your back?

Re-checks, in CI, that whatever landed on a pull request or Issue satisfies the CLI's validated-write shape rules — the actual backstop against a raw write, since no ring-0 hook can refuse one at the point it happens.

Single-plan-PR guard

ci

Ever had two people plan the same work at the same time, unknowingly?

Re-checks that no two open pull requests are planning the same work at once.

Coherence check

ci

Ever found a task marked "done" that was never actually merged?

Re-checks every task’s recorded state against what actually merged.

Documentation gate

ci

Ever shipped a change and forgot to update the doc explaining it?

Re-checks that a change carrying real code also updates the docs explaining it.

Test-plan state

ci

Ever merged a PR with an unchecked "did you test this" box?

Re-checks that the pull request's `[principal]` test-plan boxes are genuinely ticked.

Principal Test Plan wait

ci

Ever ticked a "verified" box and watched nothing re-check it?

Owns the merge condition an unticked `[principal]` Test Plan item represents, as its own independent check — the Principal wants every merge condition to be its own check, so that all green means mergeable, rather than a reviewer having to notice this reason buried among `review-gate`'s own several possible failures.

Typecheck + unit tests

ci

Ever had a change silently break something it wasn't even touching?

Re-runs the type checker and the unit tests for every package this change can reach.

Conventions

ci

Ever opened a PR full of inconsistent formatting and naming?

States where formatting/naming conventions stand in this repo: currently unenforced.

AI review

ci

Ever wished every PR got a second pair of eyes, even at 2am?

Requires independent review verdicts to exist on every pull request before merge.

Review gate

ci

Ever had a PR merge with nobody actually approving it?

Holds the merge until the required review verdicts actually exist.

Implementation exists

ci

Ever read about a safeguard that turned out not to actually exist?

Re-checks that every gate the doctrine describes has real code behind it.

No orphan hook/CLI

ci

Ever found a script nobody remembers the purpose of?

Re-checks that every hook and CLI in the repo is one the doctrine claims, and that a row scaffolded to fix that stays visibly incomplete until a human finishes it.

No seventh way into GitHub

ci

Ever discovered a backdoor that skipped all your checks?

Re-checks that no route into GitHub exists beyond the ones the doctrine gates.

Cited forge numbers resolve

ci

Ever read a doc that cited a ticket number that didn't exist?

Re-checks that every Issue and PR number cited in the docs resolves to a real one.

Role/contract integrity

ci

Ever had a process doc reference a role that was never actually defined?

Re-checks that every role and contract the doctrine references is really defined.

Doctrine-registry parity

ci

Ever read a doc that claimed a check ran, when nothing in the registry actually ran it?

Re-checks that every row this page marks `product` actually ships as a real, adopter-runnable check, not just a documented claim.

reader-resolvable-prose

ci

Ever read a doc that assumed you already worked here?

Re-checks reader-facing doctrine, durable specs and configured source comments for unresolvable citations and coined vocabulary.

retired-vocabulary

ci

Ever read a doc that described a mechanism as live after it was retired?

Re-checks that no doctrine page claims a retired mechanism is still live.

doctrine-portability

ci

Ever shipped doctrine that named a file only you could see?

Re-checks that shipped doctrine doesn't cite a path that exists only in the authoring repository.

doctrine-no-procedures

ci

Ever pasted a copy-paste runbook into doctrine, and it rotted the moment the real command changed?

Re-checks that doctrine (`roles/*.md`, `contracts/*.md`, …) describes commands rather than scripting them (task 9/task 10's rule).

No new on-disk state

ci

Ever had a file and the forge disagree about the same fact?

Blocks a diff that creates a new on-disk state file duplicating what the forge already derives.

workspace-escape

ci

Ever deleted a package only to break a sibling's tests through a path nobody's dependency graph saw?

Re-checks that no source file's constructed filesystem reference reaches outside its own workspace package, or points at a path that does not exist.

changeset-coverage

ci

Ever shipped a change to a published package and the release train never picked it up?

Re-checks that a diff touching a published package's own shipped files also carries a changeset in the same diff.

quoted-command

ci

Ever read a doc that quoted a command as "what runs today", and the command changed underneath it?

Re-checks that a doc's explicitly marked quote of a command or config line still matches, verbatim, the file it names as its source.

Bare code-fact digits in a PR body

ci

Ever had a PR body cite a line number that drifted the moment the file changed?

Re-checks that a pull request's narrative prose carries no bare `<path>.<ext>:<digits>` code-fact pointer outside a fenced code span or a `Premise:` pin.

Evidence-block freshness

ci

Ever seen a PR's own "tests pass" claim go stale the moment someone pushed again?

Re-checks that a PR's Evidence block still matches a fresh recompute at the PR's current head.

Documentation gate (PR open/edit)

ci

Ever opened a PR, watched the doc-coverage gate pass, then pushed a second commit that broke it?

Re-checks C5 doc-coverage — the SAME code→doc binding the push-time row above enforces — again at PR create/edit time, not only on push.

Surface-scope (out-of-boundary file)

ci

Ever had a "small" task quietly touch a file its own plan said it wouldn't?

Re-checks that a task branch's changed files stay inside its own Issue's declared `## Surface` — never inside a declared `out:` glob.

PR-body premise reassertion

ci

Ever had a brief's pinned fact quietly go stale, and the merge never noticed?

Re-checks, in CI, that a pull request body's `Premise:` pins still hold against the PR's own current tree — not only at Step 0, authoring time.