docs: adjudicate the twelve citations the encapsulation sweep created, and flag a fired security re-trigger - #3477
Conversation
…, and close the dometrain staleness #3468 closed the ADR 0018 encapsulation floor by writing a convention CHANGELOG entry for each fix, and every entry quotes the path it removed. That manufactured twelve new instances of the shape the pass was sweeping. The sweep record listed them and stated they were fine; nothing ruled on them one at a time, so the arithmetic (16 fixed and 35 kept, not 16 and 23) rested on an assumption. Ruled individually against the test #3475 wrote into ADR 0018's amendment. All twelve are keep-correct and none is edited. Each sits in a dated entry whose claim is what a named file contained on that date, quoted as the string the entry removed, with the replacing invocation named in the same sentence, so no reader is sent to any of them for a rule. Three sub-rulings the class needed are recorded, because a bare "all twelve are evidence" is the assumption this was meant to replace. The three config-cascade rows quote plugin-relative forms that resolve against nothing, and the entry says so: clause 3 does not fire where the entry asserts non-resolution, since making them resolve would delete the finding. The other nine resolve on disk from their own implied base, checked one at a time. None carries a line or step pin, the part the amendment says rots first. Re-derived with a second expression over the fix commit's added lines rather than a scan of the files at rest. Same twelve, plus one the roster excludes on purpose: plugins/review/reference/topic-docs.md, a plugin-level non-skill tree that belongs to the pass the amendment routes it to, and a declared keep rather than a quoted removal. Separately, MIGRATION-PLAYBOOK's dometrain record was reviewed at 0.1.0 and the manifest reads 0.2.7, eleven releases later. Whether any of them added a trust surface is what the re-trigger clause turns on and no record answers it, which takes a review rather than a reading. The staleness is now stated in place with the re-review logged as owed. The review itself is deliberately not performed here. Refs #3468, refs #3475, refs #3460. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UmrZGdp1dgbZuPCy7tcRJo
51c8fa4 to
79ab186
Compare
|
Claude finished @kyle-sexton's task in 4m 32s —— View job Code review —
|
|
Claude has reviewed this PR 1 time. The lane skips further automatic reviews after 5; deleting this comment resets the count. |
…reopened it three times (#3478) The L4 roster's Group 2, eight intra-plugin path-form citations, was the last block anyone believed open. All eight were already closed, by 6c7a103 (#3380) on 2026-08-26 -- the same commit that wrote the roster. Its own message names what it did: eight citations written with an implied base of the plugin root while the real base was reference/, none of which resolved for any reader. Verified one at a time against the roster's own text test. All eight now read ${CLAUDE_PLUGIN_ROOT}/skills/<skill>/<path> and all seven distinct targets exist on disk. Zero plugins/** files edited, so no bump and no plugin changelog entry: nothing needed changing. The reason four separate passes each re-derived this roster from scratch is one sentence. #3380 fixed 32 of 34 rows and left its summary asserting that all 34 path:line citations were re-verified on 2026-08-26 and every one resolves -- standing over citations it had just deleted. A fifth-round audit caught that for Group 1, where 22 of 32 were already closed and twelve of those by #3380 itself. This closes the same hole for Group 2. The generalizable rule is now in the sweep spec: a record that fixes findings and updates its own summary in the same commit must update the summary, or the summary outranks the fix for every later reader. The roster's inventory rows are left verbatim, per its own decay rule that the inventory is the part that cannot be re-derived, and per the precedent that #3474 and #3475 both closed rows without touching the file. Only an additive closure stamp is appended. On whether ADR 0018 reaches this class, the honest answer is that its encapsulation half does not. Clause 1 legalises intra-plugin citations and names this exact citing surface. Clause 2 cannot apply, because both files ship inside one plugin so the runtime absence motivating it cannot occur, and the 2026-08-28 amendment's fix-an-address / keep-evidence test divides clause 2 applications only. Only clause 3 reaches Group 2, and clause 3 is a resolvability rule rather than an encapsulation one: had these been open, the remedy would have been path form and nothing else. The clause that earned its keep is the ADR's own observation that proximity did not prevent them. A second derivation making no reference to the roster resolved every citation token in every plugin-level reference/, context/ and agents/ tree plus every plugin README against the base its own form implies: 52 tokens, 0 clause-3 failures. Group 3's two anchors were also closed by #3380. 34 closed, 0 open. No fresh-context verifier reviewed this diff. Nested spawning is unavailable at this depth: the Agent tool is withheld pre-launch, so there is no call to refuse and no refusal string. A second mechanical derivation was substituted and every line reference re-checked against the live tree, which is weaker than a fresh context and is recorded as such. Refs #3477, refs #3476, refs #3475, refs #3474, refs #3469, refs #3468.
No linked issue
Summary
Adjudicates the twelve cross-plugin path citations that #3468 created in convention CHANGELOGs and never ruled on, and records a security-review record whose own re-trigger has fired unnoticed.
The population at
mainis 16 fixed + 35 kept, not 16 + 23: every one of #3468's citation fixes wrote a CHANGELOG entry quoting the path it removed, creating twelve new instances of the shape it was closing. #3475 wrote the governing test into ADR 0018; this applies it to those twelve so a later re-derivation does not re-open them.Fix
The twelve are all keep-correct, and now say why
A dated changelog entry quoting a citation it removed is the evidence case exactly. That was the expectation going in — it was established rather than assumed, one row at a time, anchored on text rather than line numbers. No CHANGELOG was edited, so no convention version bump or entry is owed.
Three sub-rulings the class needed, now written into the spec rather than left implicit:
config-cascade's three rows are the only clause-3 question in the set. They are plugin-relative and resolve against nothing — and the entry says so in the same sentence. Clause 3 governs addresses a doc offers, not strings it quotes in order to report them broken. Forcing resolution would delete the finding.One excluded on purpose and recorded so it is not re-opened:
plugins/review/reference/topic-docs.md, added by the same commit. It is a plugin-level non-skill tree, which the amendment routes to its own pass, and the entry declares it a keep rather than quoting it as removed.A security review whose re-trigger fired
docs/MIGRATION-PLAYBOOK.mdrecords adometrainreview performed at 0.1.0 and states that "a version bump adding a new trust surface re-triggers this review". The manifest now reads 0.2.7 — eleven releases later.The note added states the reviewed version, the shipping version, that the ACCEPT below it describes
0.1.0only, and that the re-review is owed and deliberately not performed here. It stops short of asserting a trust surface was added: that is the condition the clause turns on and it cannot be settled by reading the page. Two checks were run to avoid claiming otherwise —sync/SKILL.mdstill carriesdisable-model-invocation: true(the premise two of the original surfaces rest on), and thesetupskill the record never enumerates shipped in the plugin's first commit, so it is not new-surface evidence. Neither settles the trigger, and the note says so rather than guessing.Verification
Independently re-checked before merge rather than taken on the worker's report: no
docs/conventions/**file appears in the diff (consistent with all-twelve-correct), three sampled citation targets resolve on disk, anddometrain's manifest is0.2.7.Roster delta, second derivation. The first pass scanned the six files at rest; the second matched path-shaped tokens in the added lines of
c66f26ceonly. Same twelve, no addition, no subtraction.A decay-rule repair worth naming: the spec's dometrain entry pinned
MIGRATION-PLAYBOOK.md:943— a line this change's own edit would have invalidated. Re-anchored on the record's heading text. That rule ("the check is the text, never the status and never the line number") has been violated three times across this sweep; this is the first time it was caught before landing rather than after.An empirical finding about the harness, recorded because two earlier claims about it were wrong in opposite directions. This worker's definition declares the
Agenttool, and the harness withheld it at spawn: the callable set contained noAgent/Taskat all. So nesting is gated by depth, realized as pre-launch tool omission — there is no refusal string because there is no call to refuse. An earlier conclusion that "subagents have no Agent tool" was right in effect and wrong in mechanism; the follow-up guess that the gate is definition-specific was wrong outright.Related
Refs #3476, refs #3475, refs #3474, refs #3469, refs #3468, refs #3460. Closes the unadjudicated-citation half of the sweep's recorded open remainder.
Generated by Claude Code