Skip to content

docs(plugin-quality): settle write-once as an agent discipline (#3866) - #4968

Merged
cursor[bot] merged 1 commit into
mainfrom
cursor/3866-write-once-discipline-37e9
Sep 28, 2026
Merged

cursor[bot] merged 1 commit into
mainfrom
cursor/3866-write-once-discipline-37e9

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Closes #3866

Summary

Write-once on the plugin-quality evidence packet is a documented agent discipline with after-the-fact verify, not a filesystem lock. Mechanical seal is unpaid (Option A).

Decision

Claim: The producing agent holds Write (and the main thread can Edit). Nothing makes a sealed file physically unwritable. packet-seal.sh verify reports CHANGED after the fact; record then refuses to reseal, so later files in that packet stay UNSEALED. That loss is terminal for the packet. A sealed packet asserts bytes at seal time, not current world state (unblocks the snapshot question on #3867 without closing it).

Basis: packet-seal.sh record/verify (reseal refuses over a CHANGED entry); the three write-once rules in skills/audit/reference/evidence-packet.md; agents/auditor.md Write grant. Option B (chmod / write proxy that refuses sealed files) is unpaid: it must not break the documented re-seal of packet.sha256, and it is a cross-platform lock the plugin does not currently own.

As of: 2026-09-28.

Recheck: a paid slice that makes sealed packet files physically unwritable on the platforms this plugin supports without breaking the documented re-seal of packet.sha256, or packet-seal.sh gaining an --acknowledge-divergence path.

Docs + checklist only. packet-seal.sh error text unchanged. plugin-quality 0.7.27.

Test plan

  • Four-part record in skills/audit/reference/evidence-packet.md
  • Auditor prompt, skill body, and recurring-concerns §3 name the weaker reading
  • changelog parity + em-dash gate
Open in Web Open in Cursor 

Record Option A: write-once is a documented discipline with after-the-fact
verify, not a filesystem lock. Mechanical seal is unpaid. A sealed packet
asserts bytes at seal time, which unblocks #3867.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body does not yet satisfy the issue-linkage contract:

  • Missing a "## Fix" section. State the concrete change and how it addresses the problem.
  • Missing a "## Verification" section. Record concrete evidence the change works (commands, gates, output).
  • Missing a "## Related" section. List related PRs, ADRs, or decision-log entries this PR does not close.

Edit the body and this comment updates itself on the next run.

@cursor
cursor Bot marked this pull request as ready for review September 28, 2026 04:49
@cursor
cursor Bot merged commit 76c0485 into main Sep 28, 2026
32 checks passed
@cursor
cursor Bot deleted the cursor/3866-write-once-discipline-37e9 branch September 28, 2026 04:55
kyle-sexton added a commit that referenced this pull request Sep 28, 2026
…pshot section

The branch was built from a copy that predated #4968 and dropped its
write-once paragraph and claim table; restore them and point the snapshot
sentence at the new section.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PT4esxbdC7eQiwQxy35Mie
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

plugin-quality: decide how write-once is guaranteed when the agent bound by it is the party able to break it

2 participants