Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions .context/TASKS.md
Original file line number Diff line number Diff line change
Expand Up @@ -313,6 +313,32 @@ These have priority because other knowledge ingestion projects depend on them.

Important things that agent (or human) yeeted to the future.

- [ ] Private mode: let `ctx` run in a project without committing anything
to it. Open-source projects cannot make `ctx` a contributor dependency,
and today using `ctx` there leaks into tracked files or breaks for
others. Observed in spike-sdk-go (session 28b10323, 2026-09-23):
- `ctx init` edits tracked files: appends to `.gitignore` and adds
`-include Makefile.ctx` to `Makefile`; writes `CLAUDE.md`.
- If `CLAUDE.md` is committed but `.context/` is not, a contributor
who has `ctx` installed hits `Error: no .context here` from
`ctx system bootstrap`, and CLAUDE.md's "installed but returns an
error -> relay and STOP" rule blocks their agent. (Reproduced in a
fresh clone with only CLAUDE.md.)
- Ignoring `.context/` drops the undo layer the constitution relies on
("persistent memory is dishonest without git reflog"); the
LEARNINGS clobber recovery (`git show <sha>:.context/LEARNINGS.md`)
would be impossible.
Scope: (1) `ctx init --private` (or equivalent) writes ignore rules
to `.git/info/exclude` instead of `.gitignore`, and never touches
tracked files (no Makefile include; e.g. an untracked `GNUmakefile`
or no make targets); (2) the agent instructions live in an untracked
file (e.g. `CLAUDE.local.md`) or the CLAUDE.md template treats a
missing `.context/` as "not a ctx project", not an error to STOP on;
(3) a versioning story for an untracked `.context/` (e.g. its own
nested git repo or snapshot) so undo still exists; (4) `ctx drift` /
`ctx doctor` flag private-mode leaks into tracked files.
Spec (stub): specs/private-mode.md. #priority:high #session:28b10323 #branch:build/go-version-sync #commit:7094924a #added:2026-09-23-111723

- [x] Nav gap: doc pages absent from zensical.toml's nav are silently
unreachable from the site sidebar. Discovered + fully fixed 2026-07-06
(session 7f6de29d, UNCOMMITTED). Swept EVERY docs/ tree, not just
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,9 @@ jobs:
- name: Check Go toolchain version sync
run: make check-go-version

- name: Check go.work.sum completeness
run: make check-go-work-sum

- name: Check steering outputs freshness
run: make check-steering

Expand Down
8 changes: 6 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -97,15 +97,19 @@ outbox
# ideas/'s privacy class; the don't-leak guard double-checks at write
# time. Must stay gitignored (see specs/ctx-dream.md).
dreams

# Encryption keys and the encrypted scratchpad. Never commit these
# (TestGitignoreProtectsSensitiveFiles guards the scratchpad key).
.context/.ctx.key
.context/.scratchpad.key
.context/scratchpad.enc

# macOS Finder metadata
.DS_Store
.gitnexus

# Generated skills
.claude/skills/generated
.claude/skills/gitnexus

# GitNexus code-graph index (local, do not commit)
.gitnexus/
.gitnexus
10 changes: 9 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
clean all release build-all help \
test-coverage smoke site site-guard site-feed site-serve site-serve-lan site-setup audit check plugin-reload \
journal journal-serve journal-serve-lan gpg-fix gpg-test register-mcp reinstall check-tools \
sync-version check-version-sync check-go-version sync-why check-why sync-copilot-skills check-copilot-skills sync-codex-skills check-codex-skills codex-plugin-install sync-opencode-skills check-opencode-skills sync-steering check-steering gemini-search \
sync-version check-version-sync check-go-version check-go-work-sum sync-why check-why sync-copilot-skills check-copilot-skills sync-codex-skills check-codex-skills codex-plugin-install sync-opencode-skills check-opencode-skills sync-steering check-steering gemini-search \
gitnexus-version gitnexus-update gitnexus-index gitnexus-mcp strip-gitnexus install-ctxctl reinstall-ctxctl

# Default binary name and output
Expand Down Expand Up @@ -177,6 +177,8 @@ audit:
@$(MAKE) --no-print-directory check-version-sync
@echo "==> Checking Go toolchain version sync..."
@$(MAKE) --no-print-directory check-go-version
@echo "==> Checking go.work.sum completeness..."
@$(MAKE) --no-print-directory check-go-work-sum
@echo "==> Checking why docs freshness..."
@$(MAKE) --no-print-directory check-why
@echo "==> Checking Copilot skills freshness..."
Expand Down Expand Up @@ -404,6 +406,12 @@ check-version-sync:
check-go-version:
@./hack/check-go-version.sh

## check-go-work-sum: Verify go.work.sum already holds every workspace checksum
# Unlike the skill checks, a failure leaves the refreshed file in place:
# the regenerated go.work.sum is exactly what needs committing.
check-go-work-sum:
@./hack/check-go-work-sum.sh

## sync-copilot-skills: Sync Copilot CLI skills from canonical ctx skills
sync-copilot-skills:
@./hack/sync-copilot-skills.sh
Expand Down
Loading
Loading