A plain `docker build .` from a checkout whose `.git` is a file (a linked worktree, or a repository checked out as a submodule) stops at the version check of the canonical `Dockerfile`: that file points to a git directory outside the build context, so `git describe` prints nothing. The policy said a plain build must succeed and did not name this case.
`prompts/REPO_POLICIES.md` and both checklists now say, right after that rule, that such a checkout is the exception and is given its version with `--build-arg VERSION=...`, as `script/docker` and `script/cibuild` already do. The check is unchanged.
Model: opus-5-5