Files
BFM-decomp/decomp-architect/templates/run-README.md
T
Drew T 9235800fb7 tools+docs(phase-33.5): task 11 — kit part 2: the firewall pack (templates/gitignore.decomp extracted byte-for-byte from the wiki fence — gitignore_template_check now runs in tools-health; firewall.txt with purge:/glob:/required:/pending:/fixture: rules; audit_public.template.py generalised from the repo's audit with its sources in the config, refusing zero sources; firewall-fixture/ = 16 synthetic bytes + sha1, the planted negative control), no-rom.template.yml, the docs/.run READMEs, ops-setup.decomp.md, bootstrap.template.sh (skeleton), CLAUDE.decomp-overlay.md (the four fail-safes + session-start extras), pa-overlays.md (7 fenced blocks: DIGEST, the 🛑 checkpoint block, the PhaseEnd narrative axis, effort rows, cookbook entry shape + triage table, wave-playbook skeleton, settings/mcp), the LICENSE/NOTICE/README/CONTRIBUTING skeletons, .clang-format + make-format.snippet.mk; tools/MANIFEST.md (325 tool files by ladder phase from one read-only survey, coverage 325/325, as Phase-N tasks); tools/kit_lint.py (fence-aware leak grep, the PLACEHOLDERS set-diff, in-memory compile / bash -n / JSON+YAML, the gitignore diff, TODO counts, coverage; --selftest = the R39 control) wired into tools-health; decomp-architect/README.md in doc_links DEFAULT; SETUP row; PLACEHOLDERS Used-in cells reconciled; make tools-health OK on this tree (detached run, .run/P33.5/tools_health_t11.log); story-timeline regenerated by the report step; log + checkpoint (NEXT = task 12, Max)
2026-09-07 19:22:51 -06:00

2.4 KiB

.run/ — scratch, with dated exceptions

Installed by decomp-architect (Step 4) on {{INSTALL_DATE}} for {{PROJECT_NAME}}. This folder is the project-local replacement for the system temp directory: no project data lives outside the repository, ever. Build and extract logs, signature dumps, permuter and compile scratch, agent work directories, per-session probes — everything a rerun can reproduce lives here and is never committed. make clean never touches it; pruning it is a hand decision.

It is ignored by contents, not as a directory. The .gitignore rule is /.run/* rather than /.run/, because git will not look inside an excluded directory and no ! re-include could then work. That form lets the irreplaceable part be tracked by exception. Each exception is a three-line idiom under a dated comment naming the phase, the session and the rule that justified it:

# P<N> <task> (<session>, <date>): the recorded contract run's per-step logs. Evidence, tracked.
!/.run/P<N>/
/.run/P<N>/*
!/.run/P<N>/verify/
/.run/P<N>/verify/*
!/.run/P<N>/verify/*.log

The test for an exception: commit what a rerun CANNOT reproduce — hand or frontier-model analysis, the harness that produced a verdict, a ledger, the recorded contract run — and leave what a script regenerates (compiler dumps, build logs, drafts, compile directories) ignored. Work that turns out to be irreplaceable gets its dated ! block the day it is recognised as such, not at the phase close.

Per-session layout. A session or wave gets one directory, .run/<session>/; each agent works in its own work/<binary>-<address>/ under it and may clean only that; deliverables (drafts, verdict lines, reports) go to a drafts/, verdicts/ or reports/ directory no agent owns; an agent never runs find, rm or mv outside its own work directory; an agent's final message is one JSON line, with the prose in reports/<function>.md.

Two fail-safes. Never git clean -x or git clean -fdx in this tree: the game-derived data (the dump, memory images, the reverse-engineering database, the vendor SDK) is ignored-but-present on the maintainer's disk, and a -x clean deletes it. And a tracked .run/ file is PUBLISHED: it is subject to the ROM firewall like anything else — a listing of the target's instructions is game-derived even inside a notes file, and the audit's content check looks for exactly that.