Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 8 additions & 4 deletions BACKLOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ CC-001/CC-002 were consumed by PR #24 fix bundle inline, with no standalone entr
| CC-516 | ⏸ deferred | evidence-gated thin delivery wrapper 評估;只組合既有 primitives,不建立 workflow engine/FSM | ux/process | 2026-07-23 | — | P3 | spike |
| CC-517 | 🔵 active | maintainer `/ship`:primary review、structured remediation closure 與 conditional targeted confirmation | process/gate | 2026-07-23 | — | P1 | design |
| CC-518 | ✅ closed 2026-07-29 | gate scope manifest v1:immutable subject、changed paths、paired tests、signals 與 bounded expansion | ops/gate | 2026-07-23 | pr:#455 | P1 | design |
| CC-519 | 🔵 active | selected-reviewer coverage/finding contract:declared coverage、stable IDs 與 actionable fix boundary | ops/gate | 2026-07-23 | | P1 | design |
| CC-519 | ✅ closed 2026-07-30 | selected-reviewer coverage/finding contract:declared coverage、stable IDs 與 actionable fix boundary | ops/gate | 2026-07-23 | pr:#456 | P1 | design |
| CC-520 | 🔵 active | synthesis parity 與 remediation seed:findings union、root-cause grouping、coverage matrix 與 no-silent-drop | ops/gate | 2026-07-23 | — | P1 | design |
| CC-521 | 🔵 active | test-gap matrix、protocol recovery 與 live recall evaluation 分層 | ops/test | 2026-07-23 | — | P2 | design |
| CC-522 | 🔵 active | 任意 `--test-cmd` 的 opaque/structured capability negotiation、執行失敗分類與外部 evidence recovery | ops/test | 2026-07-27 | feedback:2026-07-27 | P1 | design |
Expand All @@ -47,7 +47,7 @@ CC-001/CC-002 were consumed by PR #24 fix bundle inline, with no standalone entr
| CC-525 | 🔵 active | copy-mode verifier fallback 的 generated provenance 必須指向實際 generator,並由 parity ratchet 防止再次漂移 | ops/test | 2026-07-28 | feedback:2026-07-28 | P3 | hygiene |
| CC-526 | 🔵 active | reviewer override file 的 symlink trust-boundary hardening 與相容性契約 | security/gate | 2026-07-28 | feedback:2026-07-28 | P2 | hygiene |
| CC-527 | 🔵 active | targeted gate CLI 拆分 pass、reviewer coverage 與 tier,避免 full targeted 語意重疊 | ux/gate | 2026-07-28 | feedback:2026-07-28 | P2 | design |
| CC-528 | 🔵 active | publish policy compatibility:generic 為可接受 baseline、maintainer 為 preferred,並允許 ship 驗證既有 current-tree Gate artifact | release/gate | 2026-07-30 | feedback:2026-07-30 | P1 | design |
| CC-528 | ✅ closed 2026-07-30 | publish policy compatibility:generic 為可接受 baseline、maintainer 為 preferred,並允許 ship 驗證既有 current-tree Gate artifact | release/gate | 2026-07-30 | pr:#457 | P1 | design |
| CC-529 | 🔵 active | publish assurance observability:在 ship 成功輸出、PR body 與 finish marker 保留 embedded policy 與 baseline/preferred satisfaction | release/gate | 2026-07-30 | feedback:2026-07-30 | P2 | hygiene |
| CC-530 | 🔵 active | source-safe runtime library contract + centralized domain identifier policy | arch/reuse | 2026-07-30 | feedback:2026-07-30 | P1 | hygiene |
| CC-531 | 🔵 active | Adapter manifest contract closure:dispatch entrypoint 成為唯一 runtime authority | arch/schema | 2026-07-30 | feedback:2026-07-30 | P1 | design |
Expand Down Expand Up @@ -2076,7 +2076,9 @@ expansion 與 truncation 有 deterministic fixtures。

---

## CC-519 — selected-reviewer coverage/finding contract 🔵 active
## CC-519 — selected-reviewer coverage/finding contract ✅ 2026-07-30

**See**: pr:#456

**Problem**: reviewer prose 沒有一致的 coverage declaration;找到 blocker 後可能
early stop,finding 也常缺少受影響 behavior、fix boundary 與 verification expectation。
Expand Down Expand Up @@ -2549,7 +2551,9 @@ inheritance 依賴 [[CC-515]];maintainer consumer 接線由 [[CC-517]] 使用

---

## CC-528 — publish policy compatibility:generic baseline + maintainer preferred 🔵 active
## CC-528 — publish policy compatibility:generic baseline + maintainer preferred ✅ 2026-07-30

**See**: pr:#457

**Problem**: `generic` 與 `maintainer` 是 Gate consumer policy,不是權限或身分;
但 shared verifier 目前以 policy 名稱完全相等判斷 applicability,並把 `publish`
Expand Down
42 changes: 40 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,38 @@ Versions follow [Semantic Versioning](https://semver.org/).

### Added

- **Deterministic synthesis parity and remediation seed (CC-520).** Completed
selected-reviewer routes now emit `pr_gate_result_v4` with exactly one
`gate_synthesis_result_v1` block. The verifier mechanically reconciles the
selected/not-reviewed dimensions, reviewer-by-surface coverage matrix,
complete stable-ID inventory and findings union, uncertainty/caution sets,
root-cause membership, and a pending `remediation_closure_v1` seed against
the authoritative reviewer JSON. Silent drops, duplicate IDs, coverage
drift, missing verification expectations, malformed uncertainty objects, or
malformed seeds stop as synthesis protocol `INCOMPLETE`. Sequential and
parallel modes share the same contract and fixed human sections for must-fix
order, advisories/cautions, coverage gaps, and recommended verification;
executor-authored frontmatter is normalized to an unbound v1 staging result,
so a model that anticipates v4 cannot race the shell-owned assurance sidecar
publication. Multiple model-authored assurance pointers fail closed, while
the shell alone binds the final bounded pointer and result version.
Legacy v1-v3 results remain readable under their historical contracts.

- **Fail-closed gate artifact handoff hardening.** Model staging accepts an exact
`+---` patch-marker variant only long enough to canonicalize it back to a real
YAML fence; malformed or ambiguous staging still fails closed. Protocol
failures now emit `failure-result: <path>` so detached supervisors preserve
and surface the inspectable artifact without treating it as a verdict.

- **Reviewer command guard false-positive hardening.** Quoted operands of
`rg`/`grep`/`egrep`/`fgrep` are treated as search data during denylist
matching, so reviewing source text containing destructive spellings no
longer blocks a reviewer; executable `sed`/`awk` programs remain subject to
denylist inspection. Command substitutions remain conservative and denied.
Actual destructive command forms remain denied. Supervisor EXIT handling also
publishes a failed terminal claim when normal dispatch exits before result
handoff, while parent reconciliation defers until the producer stops.

- **Selected-reviewer coverage and finding contract (CC-519).** Every selected
reviewer now emits a scope-bound `gate_reviewer_result_v1` JSON report with
an explicit eleven-surface checklist, evidence/reasons, stable finding IDs,
Expand All @@ -36,8 +68,14 @@ Versions follow [Semantic Versioning](https://semver.org/).
Sequential and parallel reviewers receive the same manifest digest.
Budget omissions stop as `INCOMPLETE` unless explicitly accepted with
`--accept-scope-truncation`; accepted truncation remains recorded with exact
omitted counts and reasons. Named v3 consumers now require verified linked
scope evidence; historical v3 envelopes with unavailable scope remain
omitted counts and reasons. Symbol expansion is language-aware, and shell
call-site hints are limited to direct source-path consumers, preventing
embedded foreign-language snippets and unrelated local functions with common
names from exhausting the search-match budget. Consumer scans read through
the full immutable snapshot so `pipefail` cannot turn an early grep match
into a nondeterministic omission. A compatible-language query that truly
exceeds the limit still fails closed. Named v3 consumers now require verified
linked scope evidence; historical v3 envelopes with unavailable scope remain
readable only through non-authorizing artifact inspection.

- **Immutable gate subject and shared three-axis verification (CC-515).**
Expand Down
117 changes: 117 additions & 0 deletions DECISIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,123 @@ H2 標題格式:## YYYY-MM-DD: <短描述>
與 BACKLOG closure 對應的 entry,內文首行寫:Closes: BACKLOG.md#<PREFIX>-NNN
-->

## 2026-07-31: reviewer-search-commands-and-supervisor-failures-remain-observable

**Context**: Reviewer dispatch can legitimately search source text containing
destructive command spellings. Matching the raw command string caused the PM
Bash guard to block such a search, while an early supervisor exit could leave
the operation apparently running with readiness evidence but no terminal claim.

**Decision**: For known search tools, quoted operands without command
substitution are masked before the denylist is evaluated; `$()` and backtick
substitutions retain conservative denylist matching. Actual destructive command
syntax outside quoted search data remains covered by the existing denylist. The
gate supervisor installs an EXIT fallback that publishes a failed terminal
claim whenever ordinary shell exit occurs before the normal result handoff, and
parent reconciliation defers while the producer is still active.

**Alternatives considered**: (a) Remove the destructive patterns—rejected
because that weakens the security boundary. (b) Allow all reviewer commands—
rejected because reviewers still execute in a protected PM context. (c) Infer a
verdict from readiness or child disappearance—rejected because protocol
failure must remain distinct from GO/NO-GO.

**Constraints introduced**: Search-tool masking is intentionally limited to
quoted operands without executable substitution and does not become a shell
interpreter. Parent child claims cannot terminalize an operation while its
producer is pending/running/stopping. SIGKILL or host loss can still prevent an
EXIT trap; those cases remain indeterminate and require reconciliation rather
than synthetic verdict publication.

## 2026-07-31: scope-search-budgets-follow-language-and-consumer-selection

Relates: CC-518, CC-520

**Context**: A real CC-520 gate stopped before reviewer dispatch with 379 of
512 expansion entries but 142 omitted raw matches. The shell producer had
parsed an embedded jq `def flag(...)` as though it were a Python definition,
and treated the file-local `usage()` function like one repository-wide symbol.
The per-query limit therefore measured unrelated lexical collisions rather
than bounded adjacent review scope, forcing explicit truncation acceptance for
routine shell changes.

**Decision**: Scope symbol extraction follows the changed source's language,
and symbol searches only retain compatible-language paths. Shell functions are
treated as file-local; a shell call-site hint is emitted only when another
shell file directly references the defining script and also uses the symbol.
Direct shared-helper consumer evidence remains independent. The existing
per-symbol budget is applied after this deterministic language/consumer
selection, so a real compatible-language overflow remains a truthful
`search-match-budget` omission and fails closed.

**Alternatives considered**: (a) Increase the 64-match limit—rejected because
common names would hit the next fixed threshold and add noisy references.
(b) Automatically accept `search-match-budget` truncation—rejected because a
widely used exported symbol can represent real omitted review scope. (c) Treat
all raw matches as complete after global deduplication—rejected because omitted
provenance can still identify unique relevant paths.

**Constraints introduced**: Embedded languages must not leak symbols into the
host file's query set. Shell call-site expansion must not search unrelated
same-name scripts. Snapshot-content predicates in a `pipefail` producer must
consume the complete input rather than use an early-exiting pipeline whose
upstream SIGPIPE can nondeterministically suppress a match. Language-compatible
overflow, diff-hunk/source/symbol overflow, and global expansion-entry overflow
keep the existing explicit acceptance contract; this refinement does not claim
a complete call graph or change immutable-subject, reviewer, synthesis, or
publication authorization semantics.

---

## 2026-07-31: synthesis-preserves-reviewer-evidence-without-claiming-defect-completeness

Relates: CC-517, CC-519, CC-520, CC-521

**Context**: Reviewer JSON 已能提供 declared coverage、stable finding IDs 與
verification expectation,但 consolidated synthesis 仍由模型自由摘要。只檢查最高
verdict 與 cross-reviewer overlap,無法證明 lower-severity finding、caution、
uncertainty、disagreement 或 test expectation 沒有在 dedup 時消失;也無法直接產生
後續 remediation 可沿用的完整 seed。把 synthesis prose 當 authority 會重新引入
已由 reviewer protocol 排除的格式與遺漏風險。

**Decision**: Completed selected-reviewer routes emit one
`gate_synthesis_result_v1` and publish `pr_gate_result_v4`. Raw
`gate_reviewer_result_v1` documents remain authoritative inputs. The synthesis
copies a deterministic reviewer finding inventory, findings union and
reviewer-by-surface coverage matrix; root-cause grouping and disagreement
summaries remain synthesis judgments, but every original finding ID must appear
in exactly one group and one pending `remediation_closure_v1` seed entry.
Uncertainty and caution collections are mechanically derived from reviewer
origins and coverage statuses. The shell verifies all parity before binding the
result to assurance. Executor frontmatter is untrusted staging input: the shell
accepts a supported result version, rejects duplicate assurance pointer fields,
normalizes the document to unbound v1 for intermediate verification, then alone
publishes the sidecar and upgrades the final bounded result to v4. Human output
固定呈現 must-fix、advisory/caution、coverage gap/uncertainty 與 recommended
verification sections。

**Alternatives considered**: (a) 只加強 synthesis prompt——否決,prompt 不能證明
沒有 silent drop。(b) 由 shell 自動合併所有 human prose——否決,root-cause 與
disagreement 仍需要語意判斷,且會產生另一套摘要器。(c) 直接把 seed 宣告為
remediation closure——否決,seed 只保存待處理 finding 與驗證期待,不證明修正、
final-tree freshness 或 targeted confirmation。

**Constraints introduced**: `uncertainties` 必須是單一
`{finding_ids,coverage_cells}` object,不得多包 array。Finding/coverage parity、
stable-ID uniqueness、group membership、caution/uncertainty derivation與 seed parity
任一失敗都使 protocol `INCOMPLETE`,不能產生 authorization。Result v1-v3 保持歷史
可讀;v4 證明 union/parity,不宣稱 reviewer recall 或 defect completeness,也不
實作 CC-521 recovery/test-gap matrix 或 CC-517 closure lifecycle。模型不得決定
assurance publication 時序;即使模型預先輸出 v4,intermediate verification 也只
消費 shell-normalized v1 staging,避免在 sidecar 發佈前錯誤 dereference。
Protocol failure 仍不得轉化為 GO/NO-GO;若結果檔已產生,producer 只透過
`failure-result` 傳遞可供 post-mortem 的路徑,detached wait 仍以 terminal
sentinel 與完整 verifier 結果為準。模型意外留下的精確 `+---` patch marker
只可被 staging normalization canonicalize,其他 frontmatter 變形維持
fail-closed。

---

## 2026-07-30: pre-v1-roadmap-is-contiguous-and-preserves-milestone-history

Relates: CC-032, CC-033, CC-358, CC-446, CC-447, CC-511, CC-514, CC-517,
Expand Down
4 changes: 2 additions & 2 deletions MILESTONES.md
Original file line number Diff line number Diff line change
Expand Up @@ -130,7 +130,7 @@ Gate correctness 與 release evidence 仍必須先在 v0.11.0 關閉。
| 票 | 摘要 | 狀態 |
|----|------|------|
| CC-518 | `gate_scope_manifest_v1`:immutable subject、changed/renamed/untracked、paired tests、signals、bounded expansion/truncation | ✅ pr:#455 |
| CC-519 | selected-reviewer coverage/finding contract;sequential logical sections 與 parallel session isolation 分開 | 🔵 |
| CC-519 | selected-reviewer coverage/finding contract;sequential logical sections 與 parallel session isolation 分開 | ✅ pr:#456 |
| CC-520 | synthesis findings-union parity、root-cause grouping、coverage matrix、remediation seed、no silent drop | 🔵 |
| CC-521 | actionable test-gap matrix + bounded protocol recovery;seeded live recall 僅作 quality evaluation | 🔵 |
| CC-522 | arbitrary `--test-cmd` opaque/structured negotiation;test failure 與 timeout/environment INCOMPLETE 分流 | 🔵 |
Expand All @@ -139,7 +139,7 @@ Gate correctness 與 release evidence 仍必須先在 v0.11.0 關閉。

| 票 | 摘要 | 狀態 |
|----|------|------|
| CC-528 | publish policy compatibility:generic current-tree initial GO 為 baseline、maintainer 為 preferred;ship 可驗證明確 supplied result | 🔵 |
| CC-528 | publish policy compatibility:generic current-tree initial GO 為 baseline、maintainer 為 preferred;ship 可驗證明確 supplied result | ✅ pr:#457 |
| CC-529 | publish assurance observability:ship stdout、PR body、finish marker 保留 producer policy 與 baseline/preferred satisfaction | 🔵 |
| CC-517 | `/ship` primary review→local/targeted/split remediation closure→final affected/full tests;不虛稱 final-tree GO | 🔵 |
| CC-511 Phase B | final-tree review或 primary-review closure authorization + current-tree full PASS → publish | 🔵 |
Expand Down
Loading