feat(instruction-placement): add detect.sh identity subcommand - #5486
kyle-sexton wants to merge 6 commits into
Conversation
Emits one IDENTITY record (check, claim, anchor/v1, finding_id, heading path) for a single section, built from the sweep's own per-file awk pass, so audit and delta stop deriving identity by hand. Refs #5166 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ect.sh identity Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tity-subcommand Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…en docs An absolute --file hashed to a different finding_id than the repo-relative path for the same section. detect.sh identity now exits 2 on an absolute --file, with a test. Also restores the "That file" antecedent in the audit skill, rewraps the findings-artifact paragraph, and corrects the golden-vector comment. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude encountered an error after 0s —— View job I'll analyze this and get back to you. |
|
Claude encountered an error after 0s —— View job I'll analyze this and get back to you. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bc14f195b6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| sha256_hex() { | ||
| if command -v sha256sum >/dev/null 2>&1; then | ||
| sha256sum | cut -d' ' -f1 | ||
| else | ||
| shasum -a 256 | cut -d' ' -f1 | ||
| fi |
There was a problem hiding this comment.
Fail when no SHA-256 utility is available
On a host with neither sha256sum nor shasum, this fallback fails inside command substitutions, but the script lacks set -e and still exits 0 after emitting an IDENTITY record with empty anchor and finding_id fields. In that environment, audit and delta silently fail to match existing suppressions and may write malformed finding records; explicitly check for either utility and return a nonzero error before emitting.
Useful? React with 👍 / 👎.
| [[ -n "$ID_FILE" ]] || id_die "--file is required" | ||
| [[ "$ID_FILE" != /* ]] || id_die "--file must be a path relative to --root: $ID_FILE" | ||
| [[ "$ID_START" =~ ^[0-9]+$ ]] || id_die "--start must be an integer" | ||
| case "$ID_LANE" in | ||
| demote | promote) ;; | ||
| *) id_die "--lane must be demote or promote" ;; | ||
| esac | ||
| case "$ID_RUNG" in | ||
| path-scoped-rule | nested-agents-md | skill | linter | deletion) ;; | ||
| *) id_die "--destination must be path-scoped-rule, nested-agents-md, skill, linter, or deletion" ;; | ||
| esac | ||
| ID_FILE="${ID_FILE#./}" | ||
| EXPLICIT=("$ID_FILE") |
There was a problem hiding this comment.
Reject noncanonical paths before hashing
The absolute-path check only rejects POSIX /... spellings and the subsequent normalization removes only one leading ./, so aliases such as ././CLAUDE.md, docs/../CLAUDE.md, and Git Bash drive paths like C:/repo/CLAUDE.md can identify the same file with different finding_id values; ../... can also escape --root. Because the path bytes are part of the hash, these accepted spellings defeat deterministic suppression matching, so require a canonical path contained beneath the root before hashing it.
Useful? React with 👍 / 👎.
Closes #5166
Summary
auditanddeltaderivedanchor/v1andfinding_idby hand, so the values could drift between runs and silently stop suppressing declined findings.detect.sh identitynow computes both deterministically.Fix
detect.sh identity --file <repo-relative path> --start <n> --lane <demote|promote> --destination <rung>walks the SECTION chain to the enclosing heading path and printsanchor/v1andfinding_id. An absolute--fileis rejected, since it would hash to a different id.claude-configfinding-identity vectors, because plugins may not import a sibling plugin's files.audit,delta,context/findings-artifact.mdandreference/consumer-config.mdcall the subcommand instead of describing a hand derivation.Verification
bash plugins/instruction-placement/scripts/detect.test.sh: 55 cases, 0 failures (includes golden vectors 4b322d9c/6e9976d9d2e2c5a4 and f2146d4b/3f63ad6cc4466c0a).scripts/check-changelog-parity.sh --check --check-order: pass.scripts/validate-plugins.sh: all manifests and the catalog validated.Related
Issue #5166. Formula source:
claude-configaudit-passfinding-identity.sh.🤖 Generated with Claude Code