# === Python ===
__pycache__/
*.pyc
*.pyo
.venv/
.pytest_cache/
.ruff_cache/

# === Obsidian (local UI only; not part of three-zone layout) ===
.trash/
.obsidian/

# === Runtime dirs inside the vault (gitignored, regenerated on demand) ===
# Three-zone layout: code + knowledge are tracked; runtime churn is local.
# cache/    — FTS5 / vector / graph indexes
# logs/     — lint reports, compile logs, SessionStart debug dumps
# run/      — state.json, compile.pid, queue/, locks
# Override root via LLM_WIKI_STATE_ROOT (tests use a temp dir).
cache/
logs/
run/
# The operator's own limits (scripts/settings.py); absent by default, never published.
/llm-wiki.toml
state/
.ci-lint-state/

# === The knowledge zone is denied by default ===
# Anything new directly under knowledge/ used to be allowed: the runtime writes
# knowledge/guardrails.md (rules learned from private sessions) and `git add -A`
# would have staged it. Entries are denied, then published one literal line at a
# time; the subdirectories are re-included and keep their own rules below.
# See docs/research/2026-09-17-the-knowledge-zone-is-denied-by-default.md.
knowledge/*
!knowledge/README.md
!knowledge/index.md
!knowledge/log.md
# Directories stay open so the literal `!` lines below can publish a file inside
# one (git cannot re-include a file whose directory is excluded), and everything
# inside them is denied until such a line names it.
!knowledge/*/
knowledge/*/**

# === Personal session data (private, NOT in git) ===
knowledge/daily/*
# A writer that died mid-write leaves its atomic-write temp beside the
# page, holding the page's private bytes under a name the rule above
# does not match. Seen 2026-09-07: `.2026-09-07.md.<hex>.tmp`, 91 KB.
knowledge/**/.*.tmp
# Public Evidence fixtures (synthetic; no personal content)
!knowledge/daily/README.md
# Empty local scratch dailies stay ignored (no un-ignore for 2026-07-*)
# Compile receipts bind a private daily to the pages it produced, so they
# name private slugs. `knowledge/daily/*.md` does not reach this directory.
knowledge/daily/receipts/

# === Knowledge allowlist ===
# Every page under knowledge/notes is somebody's memory and stays private.
# The repository ships no memory (2026-09-10, issue #19): only the README is
# tracked. A page is published only by an explicit literal `!` line here —
# never a broad !*.md — and only when the owner decides so.
knowledge/notes/*
!knowledge/notes/README.md
# Nested personal categories stay ignored unless explicitly published:
knowledge/notes/*/**

# === Per-project state ===
knowledge/projects/*
!knowledge/projects/_template/
!knowledge/projects/_template/**
!knowledge/projects/README.md

# === Retired feedback candidates (2026-09-25): old files stay private ===
knowledge/feedback/*
knowledge/inbox/**
!knowledge/inbox/README.md
knowledge/raw/**
!knowledge/raw/README.md
# The vault's editorial log. The tracked knowledge/log.md is the shipped template and
# nothing writes it; see docs/research/2026-09-14-the-vault-log-is-private.md.
knowledge/log.local.md
knowledge/log-archive/
# `build_guardrails.py --apply` writes summaries of private pages here; see
# docs/research/2026-09-17-the-guard-rails-say-how-many-rules-they-left-out.md.
knowledge/guardrails.md

# === Skills allowlist ===
# Only the 9 public memory-system skills ship in this repo.
skills/*
!skills/bridge-promote-insight/
!skills/contradict-check/
!skills/crystallize-playbook/
!skills/knowledge-compile/
!skills/knowledge-lookup/
!skills/knowledge-qa-file-back/
!skills/knowledge-review/
!skills/session-memory-compile/
!skills/session-memory-review/

# === Gitleaks / audit artifacts ===
gitleaks-report.json
gitleaks-report.sarif

# === Secrets ===
*.env
*.env.local
secrets/

# === OS / IDE junk ===
.DS_Store
Thumbs.db
Desktop.ini
.playwright-mcp/
.vscode/
.idea/
*.swp
*.swo

# === Runtime lock files ===
*.pid
state.json.lock

# === Backups ===
*.bak-*

# Corpora built from this machine's real sessions: real transcript text, never
# published. Only the aggregate numbers they produce are.
benchmark/flush-classification-live*.json

# Agent worktrees are throwaway checkouts, never repository content.
.claude/worktrees/

# Third-party code-intelligence tools measured by benchmark/code-parity.
# Their indexes and configuration are theirs, not ours, and never ship.
.trace-mcp/
.serena/
