Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .context/codex-reviews/gate-b-quality-hpg0kyk2nz-pass-1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:818-831 | The WIP matcher accepts arbitrary flags before -m and an unchecked suffix after its WIP prefix, including message-changing options: real sh and dash runs of git commit --allow-empty -m 'WIP: snapshot' --fixup=HEAD emit the WIP exemption but create subject 'fixup! real baseline'; -e can likewise let an editor replace the subject. The generic prefix also accepts git commit --allow-empty -m -m -m WIP, whose actual subject is '-m'. | These successful non-WIP commits suppress the ordinary Gate-B reminder, violating the requested conservative PreToolUse behavior and AGENTS.md invariant 2; the later PostToolUse reset cannot restore the missed reminder. | Match a complete bounded command shape with explicitly supported flags and an unambiguous first message argument; reject editor and subject-changing options anywhere, and add real-run regression cases under sh and dash.
MINOR | high | plugins/dev-workflow/hooks/codex-gate.sh:982 | The existing WIP note still promises 'your pass counters are preserved' and 'Codex cycle preserved', although the new PostToolUse check may clear them. Reproduced under sh and dash with a non-WIP HEAD, count 2, index.lock, and plain git commit -m 'WIP: snapshot': PreToolUse prints the promise, Git exits 128, and PostToolUse deletes the counters. | The shipped prompt now falsely assures the agent of counter preservation, contrary to prompt-standard 11 and the requested audit of existing WIP descriptions. | Describe an attempted WIP snapshot and make preservation conditional on the subsequent HEAD check; cover this failed-commit lifecycle in the note assertions.
END OF FINDINGS (2 total)
3 changes: 3 additions & 0 deletions .context/codex-reviews/gate-b-quality-hpg0kyk2nz-pass-2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:839 | PostToolUse treats final WIP HEAD as sufficient attribution even when repository hooks create additional commits. Reproduced under sh and dash: an executable post-commit hook creates an empty 'real boundary' commit followed by an empty 'WIP: hook snapshot' commit, using git -c core.hooksPath=/dev/null to prevent recursion; the outer command is the allowed git commit -q --allow-empty -m 'WIP: requested'. | All three Gate-B state files survive despite crossing a real boundary; this leaves the requested reset-on-undecidable-history behavior incomplete and violates invariant 2. | Conservatively reset when active hooks make the resulting history unattributable, or establish sufficient attribution before preserving counters; add this real-hook lifecycle regression under both shells without changing the no-edit rules.
MINOR | high | CLAUDE.md:1327-1329; plugins/dev-workflow/commands/workflow-init.md:1516-1518; plugins/dev-workflow/CHANGELOG.md:34-35; plugins/dev-workflow/hooks/codex-gate.sh:776 | The new prose says commits made any other way reset after prescribing single quotes and short flags, but the matcher also preserves bare messages, double-quoted messages with jq, --all and --quiet. The changelog and hook comment also incorrectly say only single-quoted messages qualify without jq; bare -m WIP qualifies too. | Readers receive incorrect counter-reset expectations, contrary to the task's documentation requirement and prompt-standards item 11; identical prompt copies propagate the same error downstream. | Label the single-quoted command as the recommended portable form, describe resets using the actual allow-list boundary, and acknowledge bare messages in the jq-free description while keeping both Mechanics copies identical.
END OF FINDINGS (2 total)
6 changes: 6 additions & 0 deletions .context/codex-reviews/gate-b-quality-hpg0kyk2nz-pass-3.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:853-855 | Final parent equality does not detect an intervening real commit followed by an amendment. Reproduced under sh and dash: prepare-commit-msg rewrites git commit --allow-empty -m 'WIP: next' to 'real boundary'; post-commit runs git -c core.hooksPath=/dev/null commit -q --allow-empty --amend -m 'WIP: amended by hook'. The reflog records both commits, but final HEAD is still a direct child of the saved HEAD | All Gate-B state survives a real boundary, violating the required conservative reset and invariant 2 | Record enough history to detect intervening ref updates, or reset when hook execution leaves the result unattributable; add this real-run regression under both shells
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:856 | The --amend search includes the quoted message. Reproduced under sh and dash with git commit --allow-empty -m 'WIP: --amend is documentation' and a post-commit hook that runs git reset --soft HEAD~2 followed by a hook-disabled WIP commit: the resulting sibling passes the amendment exception even though the command contains no amendment option | Counters survive an otherwise rejected, unattributable history because message text is treated as a command option | Determine amendment from the allow-listed option positions outside the message, record that classification before execution, and add a quoted-message regression
MINOR | high | plugins/dev-workflow/hooks/codex-gate.sh:1013 | The new WIP note and its title still promise counters are kept if the result is WIP, omitting the required readable record and ancestry checks. Under both sh and dash, an initial WIP commit gets this note but resets because the unborn HEAD could not be recorded | The shipped prompt predicts preservation when the implemented attribution rule requires a reset; CHANGELOG.md:43 repeats the incomplete condition | Use neutral wording about the pending decision or qualify preservation by successful attribution and record availability, updating the title and changelog consistently
MINOR | high | CLAUDE.md:1320-1323; plugins/dev-workflow/commands/workflow-init.md:1509-1512 | The purported accepted command grammar omits the blanket shell-metacharacter and backslash veto, including inside quotes. git commit --allow-empty -m 'WIP: fix(api)' satisfies the documented form but is rejected and resets after a successful WIP commit, reproduced under sh and dash | Users following the scaffolded instructions can unexpectedly lose counters for ordinary snapshot messages | State the character restriction in both identical Mechanics copies, or describe only a known accepted example without claiming the complete grammar
MINOR | high | docs/architecture.md:94-98; todos.md:512-514 | The updated summaries describe direct descent from recorded HEAD as the preservation condition and say other detected commits reset, omitting the implemented shared-parent --amend -m path and unchanged-HEAD failed-command path | These summaries contradict Mechanics and the m10/m4 regression cases, leaving the requested behavior documentation inaccurate | Include both alternatives or reference the authoritative Mechanics description instead of restating the decision procedure
END OF FINDINGS (5 total)
5 changes: 5 additions & 0 deletions .context/codex-reviews/gate-b-quality-hpg0kyk2nz-pass-4.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:864 | An absent HEAD reflog becomes length 0, and unchanged final HEAD with recorded/current lengths 0 passes as a failed commit. Reproduced under sh and dash with core.logAllRefUpdates=false, no reflog, a prepare-commit-msg hook rewriting the commit to a real subject, and a post-commit hook resetting to the original WIP HEAD. | Counters survive a real boundary whose intermediate history is unavailable, violating invariant 2 and the documented no-reflog reset rule. | Require an available, nonempty HEAD reflog before either preservation branch; reset on unavailable history and add this real lifecycle regression under both shells.
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:861-865 | The digit-only record validation accepts 08 or 09, but arithmetic expansion interprets a leading zero as octal. With recorded length 08 and an advanced WIP HEAD, PostToolUse exits 1 under sh and 2 under dash. | A corrupt attribution record aborts the advisory hook before the counter reset, violating invariant 1 and leaving stale Gate-B state. | Reject noncanonical or out-of-range numeric records before arithmetic, or safely normalize and bound them; test malformed lengths through PostToolUse under sh and dash.
MINOR | high | plugins/dev-workflow/hooks/codex-gate.sh:1024 | The shared WIP note says preservation uses how HEAD moved and clears counters when the result cannot be attributed to the command, but it also serves --amend --no-edit. That unchanged path records no base and checks only command shape, repository rewrite conditions, and the current WIP subject. | The shipped prompt claims attribution protection that the no-edit path does not implement, contrary to prompt-standards item 11. | Keep the requested no-edit behavior unchanged and shorten the shared note to reference the applicable policy conditions, or distinguish the two paths in the message.
MINOR | high | docs/getting-started.md:55-56 | The revised example still says the hook knows the plain git commit -m 'WIP: …' command does not end the cycle, without qualifying preservation by the resulting subject and attribution checks. The exact command resets if a repository hook rewrites its subject or attribution fails. | The getting-started guide retains the unconditional WIP-preservation claim that the original task explicitly required correcting. | Replace the parenthetical promise with a reference to the implemented WIP conditions in CLAUDE.md section 5 or the 0.13.3 CHANGELOG.
END OF FINDINGS (4 total)
2 changes: 2 additions & 0 deletions .context/codex-reviews/gate-b-quality-hpg0kyk2nz-pass-5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:869 | Unchanged HEAD and reflog are treated as a failed completed commit without checking whether Bash returned while the command is still running. Reproduced under sh and dash: start on a WIP HEAD with two passes, run the accepted git commit --allow-empty -m 'WIP: next' with run_in_background=true and a waiting prepare-commit-msg hook, deliver PostToolUse with backgroundTaskId, then release the hook to rewrite the subject to real subject. | PostToolUse preserves both passes and removes the attribution record; the real commit subsequently lands with the count still 2, missing the required reset at a real boundary. Background Bash returns immediately while execution continues, so this is not evidence of a failed commit. | Reject backgrounded or incomplete Bash results before granting the new -m WIP exemption, covering explicit background input and automatic/manual background response signals; reset conservatively and add the delayed real-commit regression under sh and dash.
END OF FINDINGS (1 total)
2 changes: 2 additions & 0 deletions .context/codex-reviews/gate-b-quality-hpg0kyk2nz-pass-6.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
NO FINDINGS
END OF FINDINGS (0 total)
3 changes: 3 additions & 0 deletions .context/codex-reviews/gate-b-quality-p0nhw0wb2d-pass-1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:853-855 | Validate the original JSON string before shell normalization: with jq, tool_use_id="toolu_b\n" becomes toolu_b because command substitution strips trailing newlines; numeric and boolean IDs are also converted to accepted text. | An invalid-ID call can select a valid call's record instead of resetting. Reproduced under sh and dash: the malformed-ID PostToolUse preserved the counter and deleted toolu_b's record. | Require a string and validate its exact decoded characters and length before command substitution; add malformed-ID collision regressions asserting reset and preservation of the foreign record.
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:853 | The jq-free field() fallback searches all nesting levels, so wip_record_path accepts tool_response.tool_use_id when the top-level ID is missing, or selects a nested ID appearing before the actual top-level ID. | Call A can consume call B's record despite lacking B's top-level ID. Reproduced under sh and dash with A's real commit followed by B's WIP commit: A's PostToolUse retained the counters and deleted B's record, violating conservative reset and call isolation. | Use extraction that establishes top-level string scope, refusing attribution when it cannot do so; add jq-free missing-top-level and nested-before-top-level regressions asserting reset and that foreign records remain.
END OF FINDINGS (2 total)
2 changes: 2 additions & 0 deletions .context/codex-reviews/gate-b-quality-p0nhw0wb2d-pass-2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:861 | Using the raw mixed-case tool_use_id as the filename makes distinct valid ids such as toolu_a and toolu_A share a record on case-insensitive filesystems; reproduced with the actual hook on Darwin under both sh and dash | Both original failures recur: the m16 interleaving loses valid counters, while m17 preserves count 2 after A was rewritten into a real commit; A's PostToolUse deletes B's record in both cases | Derive a bounded case-fold-safe filename that preserves id identity, or conservatively reject ids that cannot be isolated; add both interleavings with case-variant ids and verify that neither call reads or deletes the other's record
END OF FINDINGS (1 total)
2 changes: 2 additions & 0 deletions .context/codex-reviews/gate-b-quality-p0nhw0wb2d-pass-3.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
NO FINDINGS
END OF FINDINGS (0 total)
5 changes: 5 additions & 0 deletions .context/codex-reviews/gate-b-spec-hpg0kyk2nz-pass-1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:818 | The supposed value-less flag group accepts operand-taking flags, including -m and -F. With an edited tracked file named WIP, git commit -m -m WIP matches the exemption although Git uses the second -m as its message; git commit -F -m WIP similarly reads the message from a file named -m. These are successful real commits, not attributable WIP commands. | PreToolUse emits the WIP note and suppresses the ordinary Gate-B reminder before a real boundary, violating the requested conservative recognition and invariant 2. | Allow only explicitly known value-less options before the message option; reject ambiguous argument forms and add real-command regressions under sh and dash.
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:831 | The pre-commit decision checks repository hooks/settings but accepts message-changing command options. The matcher permits --edit/-e and ignores everything after the WIP prefix: git commit --allow-empty -m WIP --fixup=HEAD creates a fixup! subject; adding --edit lets the configured editor replace WIP with a real subject. Both received the WIP note in real runs under sh and dash. | The ordinary Gate-B reminder is suppressed even when the command itself can rewrite the message; resetting afterward does not satisfy the separate before-commit requirement. | Validate the complete supported command form and make editor or message-transforming options take the ordinary reminder path; add real-run coverage for --edit and --fixup.
MINOR | high | docs/architecture.md:97; CLAUDE.md:1325; plugins/dev-workflow/commands/workflow-init.md:1514 | The new claims that any other spelling resets and a snapshot made any other way discards counters imply recognition of arbitrary Bash commit forms. The detector still requires literal commit text: git com""mit --allow-empty -m real succeeds while both hook phases are silent and the counters remain, reproduced under sh and dash. | The documentation promises a reset the implementation does not perform, contrary to the explicit requirement to bound command-attribution claims. | Qualify these statements to commit attempts recognized by the hook and avoid promising coverage for arbitrary Bash spellings; keep the Mechanics copies identical.
MINOR | high | CLAUDE.md:1319; plugins/dev-workflow/commands/workflow-init.md:1508; docs/architecture.md:93; docs/getting-started.md:55 | The recommended double-quoted git commit -m "WIP: …" is described as preserving the cycle, but without optional jq the fallback reader truncates at the escaped opening quote and the new matcher rejects the remaining backslash. A successful WIP commit then loses its counters, reproduced under sh and dash. | The documented WIP workaround does not preserve the review cycle in a supported jq-free environment; the new real-run tests use single quotes and miss this discrepancy. | Recommend a supported single-quoted WIP command consistently, or explicitly document the conservative jq-free reset for double-quoted messages; cover the documented spelling without jq.
END OF FINDINGS (4 total)
4 changes: 4 additions & 0 deletions .context/codex-reviews/gate-b-spec-hpg0kyk2nz-pass-2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
MAJOR | high | plugins/dev-workflow/hooks/codex-gate.sh:839 | PostToolUse treats a WIP HEAD as sufficiently attributable even when repository hooks create additional history. Reproduced under sh and dash: run the accepted git commit --allow-empty -m 'WIP: requested' with prepare-commit-msg rewriting the subject to 'real boundary' and post-commit running git -c core.hooksPath=/dev/null commit --allow-empty -m 'WIP: follow-up'; the command succeeds and history becomes WIP follow-up -> real boundary -> initial, but passCount remains 2 | Counters survive a real boundary, violating the requested reset on real boundaries or undecidable history and invariant 2; checking the final subject does not identify the requested commit | Preserve counters only when the result can be attributed without intervening real commits; otherwise reset conservatively, including hook environments where that attribution cannot be established. Add this real lifecycle regression under both shells without changing the amend/no-edit rules
MINOR | high | CLAUDE.md:1327; plugins/dev-workflow/commands/workflow-init.md:1516 | The Mechanics text prescribes single quotes and a flag subset, then says any detected commit made any other way resets; the matcher also preserves --all, --quiet, bare WIP messages and double-quoted WIP messages with jq | Both synchronized prompt copies still misdescribe implemented WIP recognition, contrary to the documentation task and prompt-standards item 11 | Identify the shown command as a recommended subset and qualify the reset claim using the actual supported forms; keep both copies identical
MINOR | high | plugins/dev-workflow/CHANGELOG.md:34; plugins/dev-workflow/hooks/codex-gate.sh:782 | The new text says only the single-quoted form qualifies without jq, but the fallback reads git commit -m WIP intact and the matcher accepts that bare form under both sh and dash | The release notes and implementation comment incorrectly state the jq-free recognition boundary | Say single-quoted and bare forms qualify without jq, while double-quoted messages fail the fallback reader
END OF FINDINGS (3 total)
Loading