Verified Memory
One lesson,
from mistake to signed pack.
A real RepoOps lesson walked stage by stage, every stage naming the file you can open to check it. The panels quote those files where the file is the artifact, and show the shape where it is not.
01The mistake
On 2026-05-29 a session shipped the Accountability Loop program: six pull requests merged to origin/main. But the agent worked in isolated worktrees, and the shared checkout the IDE had open never pulled. The user opened TODO.md, saw the pre-merge content with every checkbox unflipped, and asked where the updates were. From their seat, a whole day's work looked like it never happened.
What the user saw
## ⏳ Accountability Loop
- [ ] A0a ...
- [ ] A0b ... <- all merged remotely,
- [ ] A0c ... invisible locally
02The mistake is written down
The failure went into .claude/brain/errors.md the same day: the symptom, the two-layer root cause (local main never advances on its own; the completion ritual stopped before touching the shared checkout), the fix, and a rule with a concrete test. A file every future session can read and cite, rather than a postmortem that gets filed away.
From .claude/brain/errors.md (condensed)
## 2026-05-29 - Shared canonical checkout went 8 commits
stale because the build-phase ritual never pulled
Prevention rule: "Done" is defined as: the user can see it
in their IDE without doing anything. Not: the remote has it.
Test: git -C <shared-checkout> rev-parse HEAD must equal
rev-parse origin/main. If they diverge, the ritual
didn't finish.
03The lesson is minted
The error record became a structured lesson row in .claude/brain/lessons/lessons.jsonl: a trigger, what went wrong, the fix, and a source_defect back-pointer to the errors.md entry it came from. The row also carries outcome counters (times_recurred, prevented_count), so the store records what happened after the lesson was written.
The lesson row (condensed)
{
"id": "lesson-36894f7c5ddc7f38",
"trigger": "End of build-phase ritual without
fast-forwarding the shared canonical checkout",
"fix": "Add step 10b to the completion ritual:
fast-forward the shared checkout to origin/main;
stash user edits first; on conflict, stop.",
"source_defect": { "file": ".claude/brain/errors.md" },
"times_recurred": 0,
"created_at": "2026-05-29T15:20:15.646Z"
} 04The lesson is placed where sessions read it
The fix went into CLAUDE.md, the operating manual every agent session reads before it works: the completion ritual gained step 10b, fast-forward the shared checkout, verify HEAD equals origin/main, stop on conflict. The same file ends with a managed block that lib/agent-md-blocks.mjs regenerates from the active lessons, ranked by their outcome counters and held to a byte budget, so only the top rows are pinned. This lesson's counters read zero, so it sits in the store rather than in that window. Step 10b still sits in the path of every future run.
The block format lib/agent-md-blocks.mjs writes into CLAUDE.md (the shape, not the current block)
Active lessons from RepoOps. Do not hand-edit;
managed by lib/agent-md-blocks.mjs.
### Lesson <id>: <trigger, first line>
**Trigger.** ...
**What went wrong.** ...
**Fix.** ...
05The claim earns a receipt
The Brain Wiki page that documents the lessons store cites .claude/brain/lessons/lessons.jsonl as a backticked source reference. The strict citation gate (scripts/brain-drift/check-wiki-citations.mjs, part of the required brain-drift CI job) resolves that citation against HEAD on every commit and fails the build if it breaks. So the claim carries a receipt: source file, claim line, resolution status, and the commit the check resolved against, with its timestamp. Below is the receipt from the current audit, the same data /verified renders.
The live receipt (from the committed audit)
page: architecture/brain-and-mcp.md
source: .claude/brain/lessons/lessons.jsonl
line: L14
status: verified
commit: a1a244034
CI: 2026-09-28T13:22:35-05:00
06The signed pack
A brain pack (lib/brain-pack/export.mjs) passes every lesson through the transfer redaction profile first, emits only allowlisted distilled fields, and stamps each item with a sha256 content hash plus a pack-level manifest hash. Marketplace bundles carry an ed25519 signature (lib/federation/sign-node.mjs), and the pack installer (lib/federation/pack-installer.mjs) verifies it or rejects the pack: an unsigned response, a tampered bundle, or an untrusted signer writes nothing. A verified install lands held for human review, never active on its own.
What an install verifies
signature: VERIFIED ed25519 - signer a1b2c3d4...
items: each carries kind + sha256 content_hash
redaction: transfer profile (stricter than strict)
landing: HELD for review. Nothing activates silently.
This audit runs on us firstCommitted snapshot
Lessonlesson-36894f7c5ddc7f38
Cited store.claude/brain/lessons/lessons.jsonl
Receipt statusverified
The receipt above comes from RepoOps auditing its own brain at commit a1a244034. The full checker output, red rows included, is on /verified.