Files
claude_mac/lib/tests/loops-light.test.sh
T
Bastien ChanotandClaude Opus 4.8 0f0162dcae feat(agents): wire contract + verify + security into feat/bugfix/hotfix (verify-loops lot 4)
lib/verify-secure-loop.md: shared main-loop include. GATE 1 fresh verifier
(blind, contract from disk) → CONFORME straight to GATE 2, ECARTS loop max
3; GATE 2 fresh security-auditor (MODE gate) → PASS to commit, BLOCK loop
max 3 with re-verify-request-FIRST order invariant. Mute agent never a PASS.

feater.md: STEP 0.7 CONTRACT (proportional, silent on a clear feature) +
STEP 3 VERIFY+SECURE via the include. Nominal = one verifier + one security
dispatch; the loop only costs when it loops.

bugfixer.md: STEP 3.5 CONTRACT fed by the DIAGNOSIS (bug report verbatim +
reproduced-then-gone + regression test criteria) + STEP 5 fresh gates via
the include. Renumbered STEP 5 sub-steps (gates before the commit gate).

hotfixer.md: STEP 1.7 CONTRACT (silent autofill, zero questions) + STEP 3
security gate whose FAILURE REVERTS (git restore to pre-flight SHA + escalate
to /bugfix), never loops — the 1-attempt model preserved. No fresh verifier
at hotfix weight (the smoke-check verifies the trivial contract). Adds the
Agent tool to hotfixer.md + hotfix/SKILL.md for the security dispatch.

lib/tests/loops-light.test.sh: 27 structure locks green, shellcheck clean.
Behavioral pipeline dogfood on a fixture (feat adding a feature WITH a SQLi):
GATE1 CONFORME (feature present, SQLi not a conformity gap — orthogonal
gates) → GATE2 BLOCK(1) (checklist caught the %-interp SQLi semgrep's taint
rules missed) → [fix to parameterized] → re-verify CONFORME (order invariant,
feature intact) → re-scan PASS. Loop converges to green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
2026-07-03 20:47:07 +02:00

71 lines
3.2 KiB
Bash

#!/usr/bin/env bash
# ============================================================
# Structure locks — light-flow wiring (verify-loops lot 4)
# feat/bugfix get contract + fresh verifier + security gate
# (bounded 3x); hotfix gets contract + security gate whose
# FAILURE REVERTS (never loops). Locks the load-bearing clauses.
# ============================================================
set -u
REPO="$(cd "$(dirname "$0")/../.." && pwd)"
INC="$REPO/lib/verify-secure-loop.md"
FEA="$REPO/agents/feater.md"
BUG="$REPO/agents/bugfixer.md"
HOT="$REPO/agents/hotfixer.md"
HSK="$REPO/skills/hotfix/SKILL.md"
PASS=0; FAIL=0
tf() { # tf <label> <file> <fixed-string>
if grep -qF -- "$3" "$2" 2>/dev/null; then
echo " PASS $1"; PASS=$((PASS+1))
else
echo " FAIL $1 — missing: $3"; FAIL=$((FAIL+1))
fi
}
tr_() { # tr_ <label> <file> <ERE>
if grep -qE -- "$3" "$2" 2>/dev/null; then
echo " PASS $1"; PASS=$((PASS+1))
else
echo " FAIL $1 — no match: $3"; FAIL=$((FAIL+1))
fi
}
echo "── verify-secure-loop.md (shared include) ──"
if [ -f "$INC" ]; then echo " PASS include exists"; PASS=$((PASS+1)); else echo " FAIL include missing"; FAIL=$((FAIL+1)); fi
tf "gate1 fresh verifier" "$INC" "GATE 1 — REQUEST CONFORMITY (fresh verifier)"
tf "gate2 fresh auditor" "$INC" "GATE 2 — SECURITY (fresh security-auditor)"
tf "blind — no dev summary" "$INC" "Never pass the dev's summary"
tf "conforme first pass no loop" "$INC" "First-pass conforme = no loop"
tf "conformity max 3" "$INC" "Max 3 conformity iterations"
tf "security max 3" "$INC" "Max 3 security iterations"
tf "reverify request first" "$INC" "re-verify the REQUEST first"
tf "order invariant" "$INC" "always re-checked BEFORE security"
tf "mute never a pass (verify)" "$INC" "NEVER a PASS"
tf "nominal cheap stated" "$INC" "one verifier dispatch + one security dispatch"
echo "── feater.md (feat wiring) ──"
tf "feat contract step" "$FEA" "STEP 0.7 — CONTRACT"
tf "feat contract-interview" "$FEA" "lib/contract-interview.md"
tf "feat verify+secure step" "$FEA" "STEP 3 — VERIFY + SECURE"
tf "feat uses shared include" "$FEA" "lib/verify-secure-loop.md"
tf "feat nominal 1+1 dispatch" "$FEA" "verifier + one security dispatch"
echo "── bugfixer.md (bugfix wiring) ──"
tf "bug contract step" "$BUG" "STEP 3.5 — CONTRACT"
tf "bug diagnosis feeds it" "$BUG" "feeds it: REQUEST verbatim"
tf "bug fresh gates" "$BUG" "Fresh gates (verify + secure)"
tf "bug uses shared include" "$BUG" "lib/verify-secure-loop.md"
echo "── hotfixer.md (hotfix wiring — revert, not loop) ──"
tr_ "hotfix has Agent tool" "$HOT" "^tools:.*Agent"
tf "hotfix silent contract" "$HOT" "STEP 1.7 — CONTRACT (silent autofill)"
tf "hotfix zero questions" "$HOT" "questions ever"
tf "hotfix security gate" "$HOT" "Security gate (fresh auditor)"
tf "hotfix block reverts" "$HOT" "failure REVERTS, never loops"
tf "hotfix no verifier" "$HOT" "No verifier is dispatched at hotfix weight"
tf "hotfix skill has Agent" "$HSK" " - Agent"
echo ""
echo "loops-light structure locks: $PASS pass, $FAIL fail"
[ "$FAIL" -eq 0 ]