feat(agents): wire contract + verify + security into feat/bugfix/hotfix (verify-loops lot 4)
lib/verify-secure-loop.md: shared main-loop include. GATE 1 fresh verifier (blind, contract from disk) → CONFORME straight to GATE 2, ECARTS loop max 3; GATE 2 fresh security-auditor (MODE gate) → PASS to commit, BLOCK loop max 3 with re-verify-request-FIRST order invariant. Mute agent never a PASS. feater.md: STEP 0.7 CONTRACT (proportional, silent on a clear feature) + STEP 3 VERIFY+SECURE via the include. Nominal = one verifier + one security dispatch; the loop only costs when it loops. bugfixer.md: STEP 3.5 CONTRACT fed by the DIAGNOSIS (bug report verbatim + reproduced-then-gone + regression test criteria) + STEP 5 fresh gates via the include. Renumbered STEP 5 sub-steps (gates before the commit gate). hotfixer.md: STEP 1.7 CONTRACT (silent autofill, zero questions) + STEP 3 security gate whose FAILURE REVERTS (git restore to pre-flight SHA + escalate to /bugfix), never loops — the 1-attempt model preserved. No fresh verifier at hotfix weight (the smoke-check verifies the trivial contract). Adds the Agent tool to hotfixer.md + hotfix/SKILL.md for the security dispatch. lib/tests/loops-light.test.sh: 27 structure locks green, shellcheck clean. Behavioral pipeline dogfood on a fixture (feat adding a feature WITH a SQLi): GATE1 CONFORME (feature present, SQLi not a conformity gap — orthogonal gates) → GATE2 BLOCK(1) (checklist caught the %-interp SQLi semgrep's taint rules missed) → [fix to parameterized] → re-verify CONFORME (order invariant, feature intact) → re-scan PASS. Loop converges to green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
5aa4216409
commit
0f0162dcae
+25
-3
@@ -100,6 +100,16 @@ RISK: <low/medium — what could go wrong>
|
||||
- If the fix is significant (>10 lines, multiple files,
|
||||
behavior change): wait for user approval.
|
||||
|
||||
## STEP 3.5 — CONTRACT
|
||||
|
||||
Run `$HOME/.claude/lib/contract-interview.md` (main loop). The DIAGNOSIS
|
||||
feeds it: REQUEST verbatim = the bug report as received; ACCEPTANCE CRITERIA
|
||||
= the symptom reproduced-then-gone + a regression test present and passing;
|
||||
FILE SCOPE = the FIX PLAN files. Questions stay proportional (a clear,
|
||||
reproduced bug → zero). It writes the contract to
|
||||
`.claude/tasks/contracts/<date>-<slug>-<HHMM>.md`; keep the path for GATE 1
|
||||
(STEP 5).
|
||||
|
||||
## STEP 4 — FIX
|
||||
|
||||
**Gitflow aiguillage (before editing):** follow `$HOME/.claude/lib/gitflow-aiguillage.md`
|
||||
@@ -131,7 +141,19 @@ Apply the fix following the plan:
|
||||
```
|
||||
2. If a build step exists, verify it passes (`npm run build`, `tsc --noEmit`, `cargo build`, etc.).
|
||||
3. Check for regressions in related functionality.
|
||||
4. **Pre-commit confirmation gate.** Before running `git commit`, present the diff
|
||||
4. **Fresh gates (verify + secure), bounded loops.** Steps 1-3 are your
|
||||
dev-side smoke test, NOT the gate. Run the two fresh gates per
|
||||
`$HOME/.claude/lib/verify-secure-loop.md` with `CONTRACT` = the STEP 3.5
|
||||
path, `DIFF` = the fix diff, `TEST` = the suite from step 1:
|
||||
- GATE 1 — a FRESH verifier judges the fix against the contract (bug gone
|
||||
+ regression test present). CONFORME → GATE 2. ECARTS → fix, re-verify,
|
||||
max 3 → escalate.
|
||||
- GATE 2 — a FRESH security-auditor (`MODE: gate`) scans the fix diff
|
||||
(a bug fix can introduce a vuln). PASS → commit gate. BLOCK → fix,
|
||||
re-verify request THEN re-scan, max 3 → escalate.
|
||||
|
||||
Nominal = one verifier + one security dispatch. Only then the commit gate.
|
||||
5. **Pre-commit confirmation gate.** Before running `git commit`, present the diff
|
||||
summary and the proposed message, then wait for approval:
|
||||
|
||||
```
|
||||
@@ -152,7 +174,7 @@ Apply the fix following the plan:
|
||||
- `skip` → leave changes uncommitted, exit cleanly.
|
||||
- `amend last` → the fix should fold into the previous commit (use only when prior commit is unpushed).
|
||||
|
||||
5. Commit using conventional format (after approval):
|
||||
6. Commit using conventional format (after approval):
|
||||
```
|
||||
fix(<scope>): <root cause description>
|
||||
|
||||
@@ -161,7 +183,7 @@ Apply the fix following the plan:
|
||||
|
||||
Co-Authored-By: Claude <noreply@anthropic.com>
|
||||
```
|
||||
6. Print summary:
|
||||
7. Print summary:
|
||||
```
|
||||
BUGFIX COMPLETE
|
||||
BUG : <symptom>
|
||||
|
||||
Reference in New Issue
Block a user