Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
"plugins": [
{
"name": "issue-driven-dev",
"version": "2.103.3",
"version": "2.109.0",
"description": "v2.102.2: Deep Research light integration (#277, ruling b). idd-diagnose gains a non-binding pointer (the #111 superpowers hand-off shape: pure suggestion, no presence check, no dependency) fired when the diagnosis's quality depends on facts OUTSIDE the repo — with trigger examples AND counter-examples (the overly-broad-signal risk). Output flows back via '/idd-comment --type note' as summary + link, never full text (#116) — that is what keeps external research inside the audit trail. Both real-user misconceptions get canonical answers where they lived: research attaches AT diagnose (not after plan), and research vs implement are different phases' work, not substitutes. usecase-routing scenario 32 + a three-row internal-corpus vs external-world boundary table (idd-find / idd-ask / Deep Research). Deep integration stays a recorded residue until a plugin-dependable primitive exists. v2.102.1: reopen / resume path (#278) — the legal return trip from closed. idd-close gains a 'Reopen / resume path' section (close's dual operation): reopen-vs-new-issue criteria (same Expected -> reopen for trail continuity; morphed need -> new issue Refs old; broken upstream artifact -> #200's re-baseline, out of this path), resume point decided by the closing summary's WHY (premise changed -> re-diagnose; pure deferral -> implement), and the old summary stays untouched (append-only; reopen = note comment + idd-update phase rollback + optional prepend-note). Cross-referenced against auto-close-trap recovery. usecase-routing scenario 31. From a real user exchange; verify on substitute basis (disclosed). v2.102.0: three-front release. Skill-description contract + Path Map (#276, two-phase): idd-plan's frontmatter description — the ONLY surface read at skill-selection time — now names its diagnosis precondition; 5 skills gain the house pattern (drift-guard skill-description-contract, RED 8 first); docs/workflows.md gains a mermaid Path Flowchart mirroring the decision tree with all 36 catalog paths, rendered deterministically to the wiki Path-Map page by scripts/generate-path-map.py (drift-guard path-map-sync: freshness / coverage / discovery). Egress data-safety cluster (#275 + #273): empty-body guard — a provided-but-empty body now refuses (exit 15, band discipline; edit floors at 10 stripped chars because overwrite semantics turn empty dispatch into data loss — live incident 2026-07-22; explicit-intent escape --allow-empty-body); and the comment-PATCH surgery channel enters the nets via the new edit-comment verb (the #226 rollout's tracked-separately whitelist debt retired — it had bypassed EVERY net), with idd-edit's batch loop consuming the refusal band into a second outcome bucket (final exit stays 4). Dogfood: the #163 contract layer caught this release's own SCRUB_LEVEL provenance gap on first sweep. 42 suites, 0 fail. v2.99.1: staleness sweep + guard-net expansion (#267). README carried three stale gpt-5.5 pins and a stale vendored-codex-call claim — all outside the drift-guard scan net; fixed and the net widened: model-generation-sync now refutes pins in README + both catalog docs (31 assertions), and a new docs-catalog-sync suite requires every skills/* directory to appear in the catalog docs (the #122 no-forcing-function root cause is now test-detectable; it caught idd-ask and idd-config on its first RED). docs/workflows.md + skill-dimensions.md backfilled to v2.99 reality (P-find-lookup / P-ask-history / P-report-rollup / P-config-maintain / P-verify-file-profile paths, matrix rows, D12 4th member). 38 suites 0 fail. v2.99.0: /idd-ask — grounded QA over the issue corpus (#72), the surfacing family's 4th member mirroring /spectra-ask. Natural-language question -> decide-to-search gate (greetings/meta skip; bug-shaped questions never trigger diagnose) -> retrieval delegating idd-find's search backend (family rule: never rebuild a read-only query) -> full-text read of top-N hits (default 5, capped 10) -> grounded synthesis: first line blockquotes the question, every claim carries an issue/comment citation, source priority closed-with-PR > open > orphaned comment with conflicts surfaced, ending with Referenced Issues; corpus silence reported honestly, never filled from training memory. Read-only allowed-tools locked. First live run of the #140 fourth-member procedure (Q3 weak-hit judgment recorded in the family canonical). New capability spec idd-ask (+2 requirements); new drift-guard suite; 37 suites 0 fail. v2.98.0: codex channel goes full-dependency (#264, user ruling 'like superpowers'). The vendored bin/codex-call is DELETED — it trailed pai 2.18.0 by four security/correctness fixes (token-exp NSNumber parse, OAuth-file umask 0o077, form-encoding escape, post-flock re-read). Executable now resolves from the parallel-ai-agents plugin cache (MIN_PAI 2.19.0 — the codexModel/codexEffort contract floor, pai issue 22); model/effort/max-time governance resolves from codex-pro's EXTERNAL-CONSUMER CONTRACT (MIN_CODEX_PRO 0.7.0: machine-readable references/defaults.json base + global/project profile.yaml overlay, codex-pro issue 7) and is passed explicitly on all three call paths (canonical Workflow args + manual fan-out + legacy direct). IDD's tree contains ZERO model pins — generation bumps touch codex-pro's defaults.json only. Dependency wiring mirrors the superpowers shape: install-time dependencies entry (codex-pro@codex-pro), allowCrossMarketplaceDependenciesOn, check-plugin-presence pre-flight, fail-fast with a one-step install instruction, no soft fallback. model-generation-sync drift-guard reshaped to the v2 contract (a re-vendored codex-call fails the suite). 36 suites 0 fail. v2.97.0: 9-issue drain via 5 cluster PRs (#259-#263). Composable verification profiles (#258): idd-verify --profile code|prose|academic (+ config-registered custom via verify_profiles) switches the (lens set, DA focus, input source, freshness) four-tuple; new --file/--dir input sources make the git worktree optional; file-mode SHA-256 freshness gate mirrors the #228 diff gate (never silently exempted); code default byte-identical. New /idd-find skill (#139): surfacing-only semantic lookup over the open+closed corpus with GitHub relevance + phase/PR overlay; read-only, filter flags redirect to idd-list, embedding honestly deferred. Dashboard comment contract (#133) + idd-report --rollup (#134): one human-facing narrative snapshot per issue (marker-located, updates bound to phase transitions only, anti-#116) and a pull-only four-group attention view (need-attention / in-progress / stalled>14d / recently-closed). sdd_bias config switch (#252): hard-gate hits escalate to Spectra when high; default routing byte-identical. Layer V unattended deferred-record (#120): registry literal + structured catch-up record aggregated by idd-all Phase 6. Surfacing-primitives family doc, D12 axis (#140). Model-generation sync (#251): codex-call default gpt-5.6-sol is the tree's single generation pin (live-probed); prose generation-neutral; idd-route candidate renamed codex-xhigh. Docs path catalog completed (#122). 5 new drift-guard suites; 36 suites 0 fail. v2.96.0: gh-egress hardening cluster + idd-edit batch semantics. Exit-code band >=10 (#227: 10=privacy/11=mention/12=unscannable/13=attestation/14=usage; wrapper never exits <10 on its own — rc<10 is always gh's, so unattended callers can split gate-refusal from gh-failure on $? alone). Unified python3 content-net scan (#225: kills the jq/no-jq divergence; taxonomy = projects keys + path-shaped values under sensitive key names; fail-closed wide net when python3 absent). Phase 2 rollout (#226: all 6 skills' comment/edit egress now dispatch through gh-egress with attestation — the #117 mention net is mechanically enforced on the comment channel). idd-edit batch x R5 (#158: per-comment refuse + continue, batch outcome report, exit 4 iff any refused). v2.95.0: Discussions intake bridge (#221) — opt-in `idd-list --discussions` (GraphQL surface: Q&A/Ideas + unanswered + deduped vs issue refs; graceful no-op) + `idd-issue --from-discussion` (Provenance seed + draft-and-confirm reply, unattended never posts); cardinal rule: never auto-file. Plus idd-verify diff-freshness gate (#228: FROZEN_SHA vs HEAD before aggregate — refuse stale-snapshot verdicts) and the IDD_CALLER registry (#161: dynamic tree-sweep drift-guard). v2.94.0: selective git auto-tag (#85) — idd-issue tags idd-{N}-baseline at main HEAD (rollback anchor); idd-verify tags idd-{N}-verified on Aggregate PASS (review snapshot). Only these two milestones (no diagnose/plan/implement tags) so the tag namespace stays clean. Config `auto_tag` (default-ON, opt-out via enabled:false); idempotent (existing tag skipped) + graceful-skip on push failure (never aborts the workflow). v2.93.1: collaborator identity registry in idd-config (#86) — optional `collaborators[]` config field mapping a person's alias / email / display-name → GitHub @login WITHOUT guessing (github_login required; email is PII, private/gitignored only). tagging-collaborators.md Step 2.5 consults the registry first as an accelerator (a hit is still existence-verified via `gh api users/<login>`; a miss falls through to the API fuzzy-match); idd-config validate checks login charset + globally-unique aliases + PII reminder. v2.93.0: reshape Plan / pre-implementation tier (Cluster C, #129/#57/#111, via reshape-plan-preimpl-tier Spectra change) — first-class `meeting` issue type (meeting-first routing + Phase A/B/C deliberation + self-contained close gate), complexity hard gate (>=5-file interdependent-concept OR shared-abstraction MUST-trigger Plan, escalate-only), and superpowers pre-implementation hand-off (README stage-mapping table + non-binding brainstorming pointer, no self-built staging skill). v2.92.1: hotfix — parallel-ai-agents install-time dependency pointed at the wrong marketplace (psychquant-claude-plugins), making v2.92.0 fail to load and silently dropping all /idd-* skills; corrected to the parallel-ai-agents marketplace. v2.92.0: /idd-all batch-drain release — 23 issues verified+closed via 16 PRs (#223, #229-#243), the plugin's largest self-dogfood. Added: unattended-contract (state-file signal + TTL, TTY heuristic removed, idd-all/chain dependency early gates #123/#222/#211); gh-egress unconditional @-mention net with --mention-attested escape-or-attest contract (#117) atop 6-item mechanical-net precision hardening (#203); idd-close Step 6.3 doc-sync sweep (#220); test aggregator + GitHub Actions CI, 21 suites (#217); idd-list blocked-state grouping + all-blocked banner (#84); config Mechanism 3.5 submodule routing (#162); check-plugin-presence enabled-state detection exit 3 (#212); monorepo host plugin disambiguation (#68); assert-helpers eval-content ban + safe output-grep pair (#188); diagnosis-detection contract fixtures (#61). Changed: parallel-ai-agents promoted to install-time dependency, vendored ensemble fork DELETED, idd-verify two-tier chain (#219); DA sequenced-spawn eliminates the #119 socket-crash polling window (#130); spectra-archive-post-ic --force-linked-issue vs --linked-issue intent separation (#172); worktree conventions unified on the managed helper (#169); bridge state migrated to .claude/.idd/state/bridge.json (#199); .gitattributes LF policy (#216); merge-completeness fixtures default-branch self-sufficiency (#224). Audits: dependency bindings vs deep-integration rule (#210), rules layering 12/12 (#215). Follow-ups filed: #225-#228.",
"author": {
"name": "Che Cheng"
Expand Down
2 changes: 1 addition & 1 deletion plugins/issue-driven-dev/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "issue-driven-dev",
"description": "v2.102.2: Deep Research light integration (#277, ruling b). idd-diagnose gains a non-binding pointer (the #111 superpowers hand-off shape: pure suggestion, no presence check, no dependency) fired when the diagnosis's quality depends on facts OUTSIDE the repo — with trigger examples AND counter-examples (the overly-broad-signal risk). Output flows back via '/idd-comment --type note' as summary + link, never full text (#116) — that is what keeps external research inside the audit trail. Both real-user misconceptions get canonical answers where they lived: research attaches AT diagnose (not after plan), and research vs implement are different phases' work, not substitutes. usecase-routing scenario 32 + a three-row internal-corpus vs external-world boundary table (idd-find / idd-ask / Deep Research). Deep integration stays a recorded residue until a plugin-dependable primitive exists.",
"version": "2.108.0",
"version": "2.109.0",
"author": {
"name": "Che Cheng"
},
Expand Down
71 changes: 71 additions & 0 deletions plugins/issue-driven-dev/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,77 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [2.109.0] - 2026-08-15

### Fixed — post-merge audit of the 2026-08-13/14 session

The `#295` line reached `main` at round 7 without any independent review, and the twenty-one issues in PRs #306–#314
had none at all. An ensemble audit of `8d0ec33..737dbe0` returned 4 CRITICAL and 17 HIGH. The pattern it found in the
unreviewed half is worth stating plainly: **documentation was shipped and recorded as implementation.** Three "fixes"
did not execute. Each of them passed the author's tests, because those tests exercised the code that was written and
never the seam where it meets `gh`, the filesystem, or a reader.

- **`migrate-idd-config.sh` moved files outside the tree it was told to scan, and reported success** — `find -print`
with `while read -r` splits a path containing a NEWLINE into two entries, and the second fragment is a **relative**
path that `dirname`/`mv` then resolve against the caller's cwd. Reproduced: with a victim at
`caller/.claude/.claude/…` and a newline-named repo inside the scan root, `--apply ../scan` relocated the victim —
entirely outside the scan — and printed `✓ migrated: .claude`. Now `-print0`/`read -d ''`, plus a guard that refuses
any path not under the scan root, `archive/` and `.claude/worktrees/` pruning, and a breadcrumb that will not truncate
an existing file. This is the first script here that moves user data; it was moving the wrong files.

- **The round-7 truncation repair never worked, and never reached the surface users invoke** — `gh api --paginate --jq`
emits **one JSON array per page**, so `--argjson` rejected the concatenation, jq died, and the empty-payload guard
silently disabled the entire audit on any repo containing a >100-comment issue (verified against
`microsoft/vscode#301011`). Folded with `jq -s add`, plus a refusal to swap in a re-fetch that *shrinks* the comment
set and integer validation on `.number` before it reaches an API path. Separately, the repair had only ever been
applied to `scripts/check-closed-without-summary.sh`; **`/idd-list --audit-closes` — the surface that actually prints
the `--retroactive` invitation — still had the truncated fetch**, and now documents the same repair.

- **`bare_re`'s trailing anchor sent emphasised headings to `missing`** — `**Closing Summary** - fixed the parser` has a
tail, so the phrase-only form rejected it and no hash form matched. `emph_re` covers it; the anchor stays, because it
is what keeps ordinary prose out of the presence test (5 of 9 genuinely-missing issues in a real repo mention the
phrase in prose and must stay flagged).

- **`#286` was inert** — `gh release upload FILE#TEXT` sets a **display label, not the asset name**; the asset always
takes the on-disk basename. An earlier revision computed `upload_name` and never used it at all, so the documented
naming convention had **never** been applied. Attachments are now staged under the target basename before upload, and
`--clobber` is restored (removing it broke legitimate re-uploads).

- **`#293`/`#305` was documentation only** — a contract file plus a prose ⚠ near each site, while all seven call sites
still ran `.[0]` on a coarse search. The client-side filter and the `createdAt` ordering check are now in the code at
the gate, the branch resolution and verify's auto-detect, and the reference examples are correct rather than merely
annotated.

- **`#302`'s global layer had no reader** — the claim that the path was "already on the walk-up route, just recognise
one more filename" described a change that had not been made; the walk-up only ever checked `local.json` and the
legacy name. The reader exists now, as a last resort that announces itself; the remaining consumers are recorded as
residue rather than implied to be done.

- **`idd-repo-map.sh` reproduced the row-forging channel from scratch** — a `github_repo` containing a newline emitted a
standalone forged row and corrupted the footer counts; ESC reached the terminal raw; tabs shifted columns. The sibling
script spent seven rounds closing exactly this. The shape of that script was copied without its safety; both now
sanitise every field that reaches stdout.

- **Two prose callouts had been inserted inside fenced bash blocks** (`pr-flow.md`, `idd-close`), breaking the very
commands the contract says get copied.

- **`marketplace.json` was five releases behind `plugin.json`** (2.103.3 vs 2.108.0) — the version-conflict resolution
had forced the maximum onto only one of the two files.

### Fixed — tests that could not fail

- **The prose-drift scan was case-sensitive against a canonically-capitalised marker**, so it could not fire on the
realistic literal — **and its positive control planted the lowercase form**, so the control passed while the check was
blind. A positive control that certifies a capability the check does not have is worse than no control at all. The
scan is case-insensitive and the canary now plants the canonical case.

- **New suite `acquisition-truncation`** — the truncation repair lives in the live-`gh` branch, which every existing
suite skips because `--json-file` short-circuits it; the audit deleted all nineteen lines with 46/46 still green. The
new suite stubs `gh` on PATH so the real code runs, and acid confirms **5/5** of its mechanisms turn assertions red on
their own. Reaching that took three attempts, each recorded in the file: the first assertion could not tell "recovered"
from "failed safely", the second could not tell either from "the audit aborted before printing anything" (hence a
canary), and the shrink guard needed its own stub.

## [2.108.0] - 2026-08-14

### Added
Expand Down
2 changes: 1 addition & 1 deletion plugins/issue-driven-dev/references/config-protocol.md
Original file line number Diff line number Diff line change
Expand Up @@ -751,7 +751,7 @@ User runs `/idd-issue`, attaches label `cross-package`. Re-resolve picks the gro

**位置的四個理由**(考慮過 `~/.idd/`,不採用):

1. walk-up **已經**會經過 `$HOME/.claude/.idd/` —— 終止條件的檢查在 break 之前,所以這條路徑本來就在讀取路徑上,只需要多認一個檔名,零新增掃描邏輯
1. walk-up 的終止條件檢查在 break 之前,所以 `$HOME/.claude/.idd/` 在**目錄層級**上就在讀取路徑上 —— 但**檔名不是自動就認的**。這一點原本寫成「只需要多認一個檔名」,而那個改動當時並沒有做,於是 global 層有了規格卻沒有任何 reader(post-merge audit 2026-08-15 指出)。現已在 `scripts/check-closed-without-summary.sh` 的 walk-up 之後補上讀取(repo-local 皆未命中時才用,並印一行說明來源)。**其餘 consumer 尚未接上 —— 那是 residue,不是已完成的事**
2. 與 project 層的 `.claude/.idd/local.json` 完全對稱,只差 `local` / `global`。
3. IDD 是 Claude Code plugin,`~/.claude/` 是它的生態家(`settings.json`、`rules/`、`plugins/` 都在此);另開 `~/.idd/` 等於在 home 再放一個 dotdir。
4. 檔名**必須**是 `global.json` 而非 `local.json` —— 後者會讓 `$HOME` 被誤讀成「一個 repo」,汙染既有的 repo-boundary 判定。
Expand Down
Loading
Loading