Skip to content

feat(instruction-placement): add detect.sh identity subcommand - #5486

Open
kyle-sexton wants to merge 6 commits into
mainfrom
feat/5166-detect-identity-subcommand
Open

kyle-sexton wants to merge 6 commits into
mainfrom
feat/5166-detect-identity-subcommand

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Closes #5166

Summary

audit and delta derived anchor/v1 and finding_id by hand, so the values could drift between runs and silently stop suppressing declined findings. detect.sh identity now computes both deterministically.

Fix

  • detect.sh identity --file <repo-relative path> --start <n> --lane <demote|promote> --destination <rung> walks the SECTION chain to the enclosing heading path and prints anchor/v1 and finding_id. An absolute --file is rejected, since it would hash to a different id.
  • The formula is implemented locally in the plugin and pinned to the claude-config finding-identity vectors, because plugins may not import a sibling plugin's files.
  • audit, delta, context/findings-artifact.md and reference/consumer-config.md call the subcommand instead of describing a hand derivation.
  • Plugin version 0.15.22 to 0.16.0 with a CHANGELOG entry.

Verification

  • bash plugins/instruction-placement/scripts/detect.test.sh: 55 cases, 0 failures (includes golden vectors 4b322d9c/6e9976d9d2e2c5a4 and f2146d4b/3f63ad6cc4466c0a).
  • scripts/check-changelog-parity.sh --check --check-order: pass.
  • scripts/validate-plugins.sh: all manifests and the catalog validated.

Related

Issue #5166. Formula source: claude-config audit-pass finding-identity.sh.

🤖 Generated with Claude Code

kyle-sexton and others added 6 commits September 29, 2026 18:15
Emits one IDENTITY record (check, claim, anchor/v1, finding_id, heading path)
for a single section, built from the sweep's own per-file awk pass, so audit
and delta stop deriving identity by hand.

Refs #5166

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ect.sh identity

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tity-subcommand

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…en docs

An absolute --file hashed to a different finding_id than the repo-relative
path for the same section. detect.sh identity now exits 2 on an absolute
--file, with a test. Also restores the "That file" antecedent in the audit
skill, rewraps the findings-artifact paragraph, and corrects the golden-vector
comment.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review September 29, 2026 22:52
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T22:55:02.715700Z bc14f19 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude encountered an error after 0s —— View job


I'll analyze this and get back to you.

@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Claude encountered an error after 0s —— View job


I'll analyze this and get back to you.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bc14f195b6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +454 to +459
sha256_hex() {
if command -v sha256sum >/dev/null 2>&1; then
sha256sum | cut -d' ' -f1
else
shasum -a 256 | cut -d' ' -f1
fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Fail when no SHA-256 utility is available

On a host with neither sha256sum nor shasum, this fallback fails inside command substitutions, but the script lacks set -e and still exits 0 after emitting an IDENTITY record with empty anchor and finding_id fields. In that environment, audit and delta silently fail to match existing suppressions and may write malformed finding records; explicitly check for either utility and return a nonzero error before emitting.

Useful? React with 👍 / 👎.

Comment on lines +128 to +140
[[ -n "$ID_FILE" ]] || id_die "--file is required"
[[ "$ID_FILE" != /* ]] || id_die "--file must be a path relative to --root: $ID_FILE"
[[ "$ID_START" =~ ^[0-9]+$ ]] || id_die "--start must be an integer"
case "$ID_LANE" in
demote | promote) ;;
*) id_die "--lane must be demote or promote" ;;
esac
case "$ID_RUNG" in
path-scoped-rule | nested-agents-md | skill | linter | deletion) ;;
*) id_die "--destination must be path-scoped-rule, nested-agents-md, skill, linter, or deletion" ;;
esac
ID_FILE="${ID_FILE#./}"
EXPLICIT=("$ID_FILE")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject noncanonical paths before hashing

The absolute-path check only rejects POSIX /... spellings and the subsequent normalization removes only one leading ./, so aliases such as ././CLAUDE.md, docs/../CLAUDE.md, and Git Bash drive paths like C:/repo/CLAUDE.md can identify the same file with different finding_id values; ../... can also escape --root. Because the path bytes are part of the hash, these accepted spellings defeat deterministic suppression matching, so require a canonical path contained beneath the root before hashing it.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

instruction-placement:audit: script the anchor/v1 and finding_id derivation

1 participant