Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
"plugins": [
{
"name": "issue-driven-dev",
"version": "2.100.0",
"version": "2.101.0",
"description": "v2.99.1: staleness sweep + guard-net expansion (#267). README carried three stale gpt-5.5 pins and a stale vendored-codex-call claim — all outside the drift-guard scan net; fixed and the net widened: model-generation-sync now refutes pins in README + both catalog docs (31 assertions), and a new docs-catalog-sync suite requires every skills/* directory to appear in the catalog docs (the #122 no-forcing-function root cause is now test-detectable; it caught idd-ask and idd-config on its first RED). docs/workflows.md + skill-dimensions.md backfilled to v2.99 reality (P-find-lookup / P-ask-history / P-report-rollup / P-config-maintain / P-verify-file-profile paths, matrix rows, D12 4th member). 38 suites 0 fail. v2.99.0: /idd-ask — grounded QA over the issue corpus (#72), the surfacing family's 4th member mirroring /spectra-ask. Natural-language question -> decide-to-search gate (greetings/meta skip; bug-shaped questions never trigger diagnose) -> retrieval delegating idd-find's search backend (family rule: never rebuild a read-only query) -> full-text read of top-N hits (default 5, capped 10) -> grounded synthesis: first line blockquotes the question, every claim carries an issue/comment citation, source priority closed-with-PR > open > orphaned comment with conflicts surfaced, ending with Referenced Issues; corpus silence reported honestly, never filled from training memory. Read-only allowed-tools locked. First live run of the #140 fourth-member procedure (Q3 weak-hit judgment recorded in the family canonical). New capability spec idd-ask (+2 requirements); new drift-guard suite; 37 suites 0 fail. v2.98.0: codex channel goes full-dependency (#264, user ruling 'like superpowers'). The vendored bin/codex-call is DELETED — it trailed pai 2.18.0 by four security/correctness fixes (token-exp NSNumber parse, OAuth-file umask 0o077, form-encoding escape, post-flock re-read). Executable now resolves from the parallel-ai-agents plugin cache (MIN_PAI 2.19.0 — the codexModel/codexEffort contract floor, pai issue 22); model/effort/max-time governance resolves from codex-pro's EXTERNAL-CONSUMER CONTRACT (MIN_CODEX_PRO 0.7.0: machine-readable references/defaults.json base + global/project profile.yaml overlay, codex-pro issue 7) and is passed explicitly on all three call paths (canonical Workflow args + manual fan-out + legacy direct). IDD's tree contains ZERO model pins — generation bumps touch codex-pro's defaults.json only. Dependency wiring mirrors the superpowers shape: install-time dependencies entry (codex-pro@codex-pro), allowCrossMarketplaceDependenciesOn, check-plugin-presence pre-flight, fail-fast with a one-step install instruction, no soft fallback. model-generation-sync drift-guard reshaped to the v2 contract (a re-vendored codex-call fails the suite). 36 suites 0 fail. v2.97.0: 9-issue drain via 5 cluster PRs (#259-#263). Composable verification profiles (#258): idd-verify --profile code|prose|academic (+ config-registered custom via verify_profiles) switches the (lens set, DA focus, input source, freshness) four-tuple; new --file/--dir input sources make the git worktree optional; file-mode SHA-256 freshness gate mirrors the #228 diff gate (never silently exempted); code default byte-identical. New /idd-find skill (#139): surfacing-only semantic lookup over the open+closed corpus with GitHub relevance + phase/PR overlay; read-only, filter flags redirect to idd-list, embedding honestly deferred. Dashboard comment contract (#133) + idd-report --rollup (#134): one human-facing narrative snapshot per issue (marker-located, updates bound to phase transitions only, anti-#116) and a pull-only four-group attention view (need-attention / in-progress / stalled>14d / recently-closed). sdd_bias config switch (#252): hard-gate hits escalate to Spectra when high; default routing byte-identical. Layer V unattended deferred-record (#120): registry literal + structured catch-up record aggregated by idd-all Phase 6. Surfacing-primitives family doc, D12 axis (#140). Model-generation sync (#251): codex-call default gpt-5.6-sol is the tree's single generation pin (live-probed); prose generation-neutral; idd-route candidate renamed codex-xhigh. Docs path catalog completed (#122). 5 new drift-guard suites; 36 suites 0 fail. v2.96.0: gh-egress hardening cluster + idd-edit batch semantics. Exit-code band >=10 (#227: 10=privacy/11=mention/12=unscannable/13=attestation/14=usage; wrapper never exits <10 on its own — rc<10 is always gh's, so unattended callers can split gate-refusal from gh-failure on $? alone). Unified python3 content-net scan (#225: kills the jq/no-jq divergence; taxonomy = projects keys + path-shaped values under sensitive key names; fail-closed wide net when python3 absent). Phase 2 rollout (#226: all 6 skills' comment/edit egress now dispatch through gh-egress with attestation — the #117 mention net is mechanically enforced on the comment channel). idd-edit batch x R5 (#158: per-comment refuse + continue, batch outcome report, exit 4 iff any refused). v2.95.0: Discussions intake bridge (#221) — opt-in `idd-list --discussions` (GraphQL surface: Q&A/Ideas + unanswered + deduped vs issue refs; graceful no-op) + `idd-issue --from-discussion` (Provenance seed + draft-and-confirm reply, unattended never posts); cardinal rule: never auto-file. Plus idd-verify diff-freshness gate (#228: FROZEN_SHA vs HEAD before aggregate — refuse stale-snapshot verdicts) and the IDD_CALLER registry (#161: dynamic tree-sweep drift-guard). v2.94.0: selective git auto-tag (#85) — idd-issue tags idd-{N}-baseline at main HEAD (rollback anchor); idd-verify tags idd-{N}-verified on Aggregate PASS (review snapshot). Only these two milestones (no diagnose/plan/implement tags) so the tag namespace stays clean. Config `auto_tag` (default-ON, opt-out via enabled:false); idempotent (existing tag skipped) + graceful-skip on push failure (never aborts the workflow). v2.93.1: collaborator identity registry in idd-config (#86) — optional `collaborators[]` config field mapping a person's alias / email / display-name → GitHub @login WITHOUT guessing (github_login required; email is PII, private/gitignored only). tagging-collaborators.md Step 2.5 consults the registry first as an accelerator (a hit is still existence-verified via `gh api users/<login>`; a miss falls through to the API fuzzy-match); idd-config validate checks login charset + globally-unique aliases + PII reminder. v2.93.0: reshape Plan / pre-implementation tier (Cluster C, #129/#57/#111, via reshape-plan-preimpl-tier Spectra change) — first-class `meeting` issue type (meeting-first routing + Phase A/B/C deliberation + self-contained close gate), complexity hard gate (>=5-file interdependent-concept OR shared-abstraction MUST-trigger Plan, escalate-only), and superpowers pre-implementation hand-off (README stage-mapping table + non-binding brainstorming pointer, no self-built staging skill). v2.92.1: hotfix — parallel-ai-agents install-time dependency pointed at the wrong marketplace (psychquant-claude-plugins), making v2.92.0 fail to load and silently dropping all /idd-* skills; corrected to the parallel-ai-agents marketplace. v2.92.0: /idd-all batch-drain release — 23 issues verified+closed via 16 PRs (#223, #229-#243), the plugin's largest self-dogfood. Added: unattended-contract (state-file signal + TTL, TTY heuristic removed, idd-all/chain dependency early gates #123/#222/#211); gh-egress unconditional @-mention net with --mention-attested escape-or-attest contract (#117) atop 6-item mechanical-net precision hardening (#203); idd-close Step 6.3 doc-sync sweep (#220); test aggregator + GitHub Actions CI, 21 suites (#217); idd-list blocked-state grouping + all-blocked banner (#84); config Mechanism 3.5 submodule routing (#162); check-plugin-presence enabled-state detection exit 3 (#212); monorepo host plugin disambiguation (#68); assert-helpers eval-content ban + safe output-grep pair (#188); diagnosis-detection contract fixtures (#61). Changed: parallel-ai-agents promoted to install-time dependency, vendored ensemble fork DELETED, idd-verify two-tier chain (#219); DA sequenced-spawn eliminates the #119 socket-crash polling window (#130); spectra-archive-post-ic --force-linked-issue vs --linked-issue intent separation (#172); worktree conventions unified on the managed helper (#169); bridge state migrated to .claude/.idd/state/bridge.json (#199); .gitattributes LF policy (#216); merge-completeness fixtures default-branch self-sufficiency (#224). Audits: dependency bindings vs deep-integration rule (#210), rules layering 12/12 (#215). Follow-ups filed: #225-#228.",
"author": {
"name": "Che Cheng"
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
schema: spec-driven
created: 2026-07-19
created_by: che cheng <kiki830621@gmail.com>
created_with: claude
32 changes: 32 additions & 0 deletions openspec/changes/add-reply-thirdparty-tier-floor/design.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
## Context

privacy-scrubbing 契約(v2.87–2.96 已 ship)的 tier 由 repo visibility 決定;gh-egress.sh 的 mechanical net 限 3 個 zero-tolerance items 且 rules 檔明文「不得長成 semantic pattern set、增長需 separate change」。reply 型(v2.100.0)逐字重製第三方原文,marker `<!-- idd:comment type=reply ... points-from={comment-url|issue-body|user-pasted} calibrated={yes|no} -->` 是 IDD 自產結構化 token。#269 verify DA-3:own-repo 情境永不 ENFORCE,layer-3 只有 prose 自審,必要不充分。in-flight change `add-privacy-scrubbing-gate` 尚有 11 open tasks、標的同兩檔。

## Goals / Non-Goals

**Goals:**

- layer-3(user-pasted)reply payload 的 tier floor:機械可執行、不論 repo visibility
- net 邊界紀律不破:新 item 僅 token matching(自產 marker),零 semantic
- 與 in-flight change 疊層不衝突(rules 檔 append-only)

**Non-Goals:**

- layer 1/2 tier 變更、unattended draft 持久化、semantic 偵測、其他 human-facing 輸出面

## Decisions

**D1 — floor 只綁 layer 3,不綁整個 reply。** layer 1/2 的內容本已在同 repo remote(issue body / comment),重引零新增暴露;全 reply 拉 tier 會把日常 advisor 回覆全部拖進 confirm 流程(比例原則違反、user 明示要評估的軸)。替代案「全 reply enforce」被否。

**D2 — 機械 backstop 檢測『自產 marker token』,不是內容。** gh-egress 新 item 4 的判準:SCAN 同時含字串 `type=reply` 與 `points-from=user-pasted`(兩 token 同在 metadata marker 慣例內)且 `$ATTESTED = light` → exit 13(attestation band:這是「attested level 對此 payload 無效」,不是 content leak 的 exit 10)。為何 13 不是 10:net_refuse(10) 語意是 zero-tolerance content leak;本案是 tier-floor violation——attested level 不足,重派時帶 `warn`+完成確認即可,body 本身不必改。marker 可被不寫 marker 繞過 → backstop 定位是 belt-and-suspenders(與既有 net 哲學一致),主 gate 在 SKILL 端手續。

**D3 — SKILL 端主 gate:attended 顯式確認、unattended refuse。** layer-3 時 attended → AskUserQuestion「此段第三方逐字內容確認可進 remote?」(帶 redact 選項);unattended(`is_unattended` / directive)→ 不 post、印 refuse 說明+改跑 attended 的指示。理由:reply 本質是 correspondence(人在場的工作),unattended 貼第三方逐字內容無人把關 = CLAUDE.md「raw 第三方逐字內容不進 remote」鐵律的直接風險面。

**D4 — rules 檔以 append 為主。** 「Reply layer-3 payload tier floor」段落 append 在 Related rules 之前;既有段落僅允許兩處最小 in-place 校正(net count 句 3→4、growth 歷史句補 3→4),其餘段落(tier 表、ENFORCE 語意、division of labor、implementation contract)零改動——與 in-flight change 的疊層紀律(C_shared_module_coord)以此為界。

## Implementation Contract

- **gh-egress.sh net item 4**:`printf '%s' "$SCAN" | grep -q 'type=reply'` 且 `grep -q 'points-from=user-pasted'` 且 `[ "$ATTESTED" = "light" ]` → stderr 訊息(指示以 `--scrub-attested warn` 重派並先完成使用者確認)+ `exit 13`。attested=warn/enforce 或 marker 不全 → 不觸發、行為不變。位置:既有 3-item net 之後、mention net 之前或之後皆可(獨立判斷)。
- **SKILL R1 增訂**(R4 僅在 R1 的 floor 條目中被引用、不改動):layer-3 手續字句(attended confirm / unattended refuse)、marker `points-from=user-pasted` 值與 tier floor 的對應、引用 rules 段名。
- **rules 新段**:normative 三句——LIGHT 不適用於 user-pasted reply payload;最低 WARN+顯式確認;unattended 不 post。net item 4 的邊界聲明(token-only)。
- **驗證目標**:gh-egress suite 斷言(light+雙 token → exit 13+stderr 含 warn 重派指示;warn+雙 token → 照派;light+單 token(各向)→ 照派;fenced 討論體 → refuse 的 accepted-friction 鎖定;template↔wrapper token binding);idd-comment-reply suite 斷言 SKILL 新字句與 rules 段名;`run-all-tests.sh` 40 suites 全綠;版本 2.100.0 → 2.101.0 三處同步。
37 changes: 37 additions & 0 deletions openspec/changes/add-reply-thirdparty-tier-floor/proposal.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
## Why

reply 型(v2.100.0,#269)是唯一逐字重製第三方原文的 comment 型別,但 `SCRUB_LEVEL` 是 repo-visibility-keyed——reply 的典型情境(第三方逐字內容貼到使用者自己的 repo)落在 WARN / LIGHT、永不 ENFORCE;layer-3(使用者貼上的外部原文)是新第三方內容首次進 remote 的唯一通道,目前只靠 prose「heightened 自審」(#269 verify DA-3 判為必要不充分)。

## What Changes

- `rules/privacy-scrubbing.md` 新增 normative 段「Reply layer-3 payload tier floor」:`points-from=user-pasted` 的 reply egress 不適用 LIGHT——最低 WARN+顯式使用者確認(不論 repo visibility);unattended context 下不 post(refuse+說明,留待 attended)
- `skills/idd-comment/SKILL.md` R1/R4:layer-3 source 時 attended → AskUserQuestion 顯式確認第三方逐字內容可進 remote;unattended → refuse post。取代 v2.100.0 的「heightened 自審」prose
- `scripts/gh-egress.sh` 機械 net item 4(3→4,本案即 rules 要求的 separate change):SCAN 含 `type=reply` 且 `points-from=user-pasted` 且 attested=`light` → exit 13 band refuse。僅偵測 IDD 自產 metadata marker token,零 semantic matching——net 邊界紀律不變
- 測試:gh-egress suite 新斷言(refuse / pass 兩向)+ idd-comment-reply suite 新斷言(SKILL 手續字句)
- **比例原則邊界**:layer 1(comment URL)/ layer 2(issue-body)內容本已在 repo remote、無新增暴露 → 維持 repo-tier 預設,不受本案影響

## Non-Goals

- 不把 reply 全部 payload(layer 1/2)拉 tier——過度(無新增暴露)
- 不做 unattended draft 持久化檔案(YAGNI;refuse+說明即可)
- 不擴 mechanical net 為 semantic 偵測(rules 檔明文禁止;item 4 限自產 marker token)
- 不動 in-flight `add-privacy-scrubbing-gate` 的未完成 tasks(rules 檔僅 append 新段)
- 不涵蓋 PR body / Discussions 等其他 human-facing 輸出面的同類問題(horizon 另案)

## Capabilities

### New Capabilities

(none)

### Modified Capabilities

- `idd-comment-reply`: MODIFIED Points-source resolution(layer-3 綁 tier floor)+ ADDED requirement「Layer-3 third-party payload tier floor」(rules 段、SKILL 手續、gh-egress 機械 backstop 三件套的 normative 契約)

## Impact

- Affected specs: `idd-comment-reply`(delta:1 MODIFIED + 1 ADDED requirement)
- Affected code:
- New: (none)
- Modified: plugins/issue-driven-dev/rules/privacy-scrubbing.md, plugins/issue-driven-dev/scripts/gh-egress.sh, plugins/issue-driven-dev/skills/idd-comment/SKILL.md, plugins/issue-driven-dev/scripts/tests/gh-egress/test.sh, plugins/issue-driven-dev/scripts/tests/idd-comment-reply/test.sh, plugins/issue-driven-dev/CHANGELOG.md, plugins/issue-driven-dev/.claude-plugin/plugin.json, .claude-plugin/marketplace.json
- Removed: (none)
Loading
Loading