diff --git a/lib/tests/plan-challenger.test.sh b/lib/tests/plan-challenger.test.sh index ca3916e..fa70adc 100644 --- a/lib/tests/plan-challenger.test.sh +++ b/lib/tests/plan-challenger.test.sh @@ -38,7 +38,8 @@ has "$L" "proposals" has "$L" "fix-bundle" # 3) every reflection orchestrator wires the phase + carries a challenge summary -for s in ship-feature init-project feat bugfix onboard audit-delta code-clean seo geo harden web-validate; do +# (hotfix wires it under a logic-only guard — STEP 1.8) +for s in ship-feature init-project feat bugfix hotfix onboard audit-delta code-clean seo geo harden web-validate; do has "skills/$s/SKILL.md" "lib/challenge-plan.md" has "skills/$s/SKILL.md" "CHALLENGE SUMMARY" done diff --git a/skills/hotfix/SKILL.md b/skills/hotfix/SKILL.md index 21f8ec2..6e5255a 100644 --- a/skills/hotfix/SKILL.md +++ b/skills/hotfix/SKILL.md @@ -76,6 +76,26 @@ security gate and the escalation report if a gate fails. No verifier is dispatched at hotfix weight — STEP 4's smoke result already verifies these trivial criteria; the gate hotfix adds is security (STEP 4). +## STEP 1.8 — CHALLENGE THE FIX (logic fixes only) +GUARD — this is the one place the plan-challenge phase is kept proportionate to +hotfix's speed. SKIP entirely for a purely cosmetic fix (CSS value, copy/typo, a +broken link): there is nothing for three lenses to bite on, and speed is the +point. Run it ONLY when the settled fix touches control flow or behaviour — an +off-by-one, a wrong operator/variable, a behaviour-changing config value, or a +missing import that alters execution. In doubt → it is probably a `/bugfix`. + +For a logic fix: persist the STEP 1 located fix (root cause + the exact edit) to +`.claude/tasks/plans/--.md`, then run +`$HOME/.claude/lib/challenge-plan.md` with `PLAN` = that file, `KIND` = +`build-plan`, `SCOPE` = the 1-2 target files, `CONSTRAINTS` = the STEP 1.7 +contract's acceptance criteria. Three blind challengers attack the fix; the main +loop RE-THINKS any aspect a BLOCKER lands (a named change to the fix, or +`[deferred]`) and re-challenges once if it materially changed. Print a +CHALLENGE SUMMARY (BLOCKERs addressed / deferred / lenses returned). A BLOCKER +that shows the fix is wrong or incomplete means this was never +a hotfix — escalate to `/bugfix` (its STEP 3b runs the same phase under the full +verify+secure loop). + ## STEP 2 — PRE-FLIGHT **Gitflow aiguillage (before dispatch):** follow `$HOME/.claude/lib/gitflow-aiguillage.md`