Skip to content

Commit 51b302d

Browse files
committed
chore: 2.111.0 — CHANGELOG + plugin.json/marketplace.json 同步
1 parent 15c0837 commit 51b302d

3 files changed

Lines changed: 78 additions & 2 deletions

File tree

.claude-plugin/marketplace.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
"plugins": [
1616
{
1717
"name": "issue-driven-dev",
18-
"version": "2.110.0",
18+
"version": "2.111.0",
1919
"description": "v2.102.2: Deep Research light integration (#277, ruling b). idd-diagnose gains a non-binding pointer (the #111 superpowers hand-off shape: pure suggestion, no presence check, no dependency) fired when the diagnosis's quality depends on facts OUTSIDE the repo — with trigger examples AND counter-examples (the overly-broad-signal risk). Output flows back via '/idd-comment --type note' as summary + link, never full text (#116) — that is what keeps external research inside the audit trail. Both real-user misconceptions get canonical answers where they lived: research attaches AT diagnose (not after plan), and research vs implement are different phases' work, not substitutes. usecase-routing scenario 32 + a three-row internal-corpus vs external-world boundary table (idd-find / idd-ask / Deep Research). Deep integration stays a recorded residue until a plugin-dependable primitive exists. v2.102.1: reopen / resume path (#278) — the legal return trip from closed. idd-close gains a 'Reopen / resume path' section (close's dual operation): reopen-vs-new-issue criteria (same Expected -> reopen for trail continuity; morphed need -> new issue Refs old; broken upstream artifact -> #200's re-baseline, out of this path), resume point decided by the closing summary's WHY (premise changed -> re-diagnose; pure deferral -> implement), and the old summary stays untouched (append-only; reopen = note comment + idd-update phase rollback + optional prepend-note). Cross-referenced against auto-close-trap recovery. usecase-routing scenario 31. From a real user exchange; verify on substitute basis (disclosed). v2.102.0: three-front release. Skill-description contract + Path Map (#276, two-phase): idd-plan's frontmatter description — the ONLY surface read at skill-selection time — now names its diagnosis precondition; 5 skills gain the house pattern (drift-guard skill-description-contract, RED 8 first); docs/workflows.md gains a mermaid Path Flowchart mirroring the decision tree with all 36 catalog paths, rendered deterministically to the wiki Path-Map page by scripts/generate-path-map.py (drift-guard path-map-sync: freshness / coverage / discovery). Egress data-safety cluster (#275 + #273): empty-body guard — a provided-but-empty body now refuses (exit 15, band discipline; edit floors at 10 stripped chars because overwrite semantics turn empty dispatch into data loss — live incident 2026-07-22; explicit-intent escape --allow-empty-body); and the comment-PATCH surgery channel enters the nets via the new edit-comment verb (the #226 rollout's tracked-separately whitelist debt retired — it had bypassed EVERY net), with idd-edit's batch loop consuming the refusal band into a second outcome bucket (final exit stays 4). Dogfood: the #163 contract layer caught this release's own SCRUB_LEVEL provenance gap on first sweep. 42 suites, 0 fail. v2.99.1: staleness sweep + guard-net expansion (#267). README carried three stale gpt-5.5 pins and a stale vendored-codex-call claim — all outside the drift-guard scan net; fixed and the net widened: model-generation-sync now refutes pins in README + both catalog docs (31 assertions), and a new docs-catalog-sync suite requires every skills/* directory to appear in the catalog docs (the #122 no-forcing-function root cause is now test-detectable; it caught idd-ask and idd-config on its first RED). docs/workflows.md + skill-dimensions.md backfilled to v2.99 reality (P-find-lookup / P-ask-history / P-report-rollup / P-config-maintain / P-verify-file-profile paths, matrix rows, D12 4th member). 38 suites 0 fail. v2.99.0: /idd-ask — grounded QA over the issue corpus (#72), the surfacing family's 4th member mirroring /spectra-ask. Natural-language question -> decide-to-search gate (greetings/meta skip; bug-shaped questions never trigger diagnose) -> retrieval delegating idd-find's search backend (family rule: never rebuild a read-only query) -> full-text read of top-N hits (default 5, capped 10) -> grounded synthesis: first line blockquotes the question, every claim carries an issue/comment citation, source priority closed-with-PR > open > orphaned comment with conflicts surfaced, ending with Referenced Issues; corpus silence reported honestly, never filled from training memory. Read-only allowed-tools locked. First live run of the #140 fourth-member procedure (Q3 weak-hit judgment recorded in the family canonical). New capability spec idd-ask (+2 requirements); new drift-guard suite; 37 suites 0 fail. v2.98.0: codex channel goes full-dependency (#264, user ruling 'like superpowers'). The vendored bin/codex-call is DELETED — it trailed pai 2.18.0 by four security/correctness fixes (token-exp NSNumber parse, OAuth-file umask 0o077, form-encoding escape, post-flock re-read). Executable now resolves from the parallel-ai-agents plugin cache (MIN_PAI 2.19.0 — the codexModel/codexEffort contract floor, pai issue 22); model/effort/max-time governance resolves from codex-pro's EXTERNAL-CONSUMER CONTRACT (MIN_CODEX_PRO 0.7.0: machine-readable references/defaults.json base + global/project profile.yaml overlay, codex-pro issue 7) and is passed explicitly on all three call paths (canonical Workflow args + manual fan-out + legacy direct). IDD's tree contains ZERO model pins — generation bumps touch codex-pro's defaults.json only. Dependency wiring mirrors the superpowers shape: install-time dependencies entry (codex-pro@codex-pro), allowCrossMarketplaceDependenciesOn, check-plugin-presence pre-flight, fail-fast with a one-step install instruction, no soft fallback. model-generation-sync drift-guard reshaped to the v2 contract (a re-vendored codex-call fails the suite). 36 suites 0 fail. v2.97.0: 9-issue drain via 5 cluster PRs (#259-#263). Composable verification profiles (#258): idd-verify --profile code|prose|academic (+ config-registered custom via verify_profiles) switches the (lens set, DA focus, input source, freshness) four-tuple; new --file/--dir input sources make the git worktree optional; file-mode SHA-256 freshness gate mirrors the #228 diff gate (never silently exempted); code default byte-identical. New /idd-find skill (#139): surfacing-only semantic lookup over the open+closed corpus with GitHub relevance + phase/PR overlay; read-only, filter flags redirect to idd-list, embedding honestly deferred. Dashboard comment contract (#133) + idd-report --rollup (#134): one human-facing narrative snapshot per issue (marker-located, updates bound to phase transitions only, anti-#116) and a pull-only four-group attention view (need-attention / in-progress / stalled>14d / recently-closed). sdd_bias config switch (#252): hard-gate hits escalate to Spectra when high; default routing byte-identical. Layer V unattended deferred-record (#120): registry literal + structured catch-up record aggregated by idd-all Phase 6. Surfacing-primitives family doc, D12 axis (#140). Model-generation sync (#251): codex-call default gpt-5.6-sol is the tree's single generation pin (live-probed); prose generation-neutral; idd-route candidate renamed codex-xhigh. Docs path catalog completed (#122). 5 new drift-guard suites; 36 suites 0 fail. v2.96.0: gh-egress hardening cluster + idd-edit batch semantics. Exit-code band >=10 (#227: 10=privacy/11=mention/12=unscannable/13=attestation/14=usage; wrapper never exits <10 on its own — rc<10 is always gh's, so unattended callers can split gate-refusal from gh-failure on $? alone). Unified python3 content-net scan (#225: kills the jq/no-jq divergence; taxonomy = projects keys + path-shaped values under sensitive key names; fail-closed wide net when python3 absent). Phase 2 rollout (#226: all 6 skills' comment/edit egress now dispatch through gh-egress with attestation — the #117 mention net is mechanically enforced on the comment channel). idd-edit batch x R5 (#158: per-comment refuse + continue, batch outcome report, exit 4 iff any refused). v2.95.0: Discussions intake bridge (#221) — opt-in `idd-list --discussions` (GraphQL surface: Q&A/Ideas + unanswered + deduped vs issue refs; graceful no-op) + `idd-issue --from-discussion` (Provenance seed + draft-and-confirm reply, unattended never posts); cardinal rule: never auto-file. Plus idd-verify diff-freshness gate (#228: FROZEN_SHA vs HEAD before aggregate — refuse stale-snapshot verdicts) and the IDD_CALLER registry (#161: dynamic tree-sweep drift-guard). v2.94.0: selective git auto-tag (#85) — idd-issue tags idd-{N}-baseline at main HEAD (rollback anchor); idd-verify tags idd-{N}-verified on Aggregate PASS (review snapshot). Only these two milestones (no diagnose/plan/implement tags) so the tag namespace stays clean. Config `auto_tag` (default-ON, opt-out via enabled:false); idempotent (existing tag skipped) + graceful-skip on push failure (never aborts the workflow). v2.93.1: collaborator identity registry in idd-config (#86) — optional `collaborators[]` config field mapping a person's alias / email / display-name → GitHub @login WITHOUT guessing (github_login required; email is PII, private/gitignored only). tagging-collaborators.md Step 2.5 consults the registry first as an accelerator (a hit is still existence-verified via `gh api users/<login>`; a miss falls through to the API fuzzy-match); idd-config validate checks login charset + globally-unique aliases + PII reminder. v2.93.0: reshape Plan / pre-implementation tier (Cluster C, #129/#57/#111, via reshape-plan-preimpl-tier Spectra change) — first-class `meeting` issue type (meeting-first routing + Phase A/B/C deliberation + self-contained close gate), complexity hard gate (>=5-file interdependent-concept OR shared-abstraction MUST-trigger Plan, escalate-only), and superpowers pre-implementation hand-off (README stage-mapping table + non-binding brainstorming pointer, no self-built staging skill). v2.92.1: hotfix — parallel-ai-agents install-time dependency pointed at the wrong marketplace (psychquant-claude-plugins), making v2.92.0 fail to load and silently dropping all /idd-* skills; corrected to the parallel-ai-agents marketplace. v2.92.0: /idd-all batch-drain release — 23 issues verified+closed via 16 PRs (#223, #229-#243), the plugin's largest self-dogfood. Added: unattended-contract (state-file signal + TTL, TTY heuristic removed, idd-all/chain dependency early gates #123/#222/#211); gh-egress unconditional @-mention net with --mention-attested escape-or-attest contract (#117) atop 6-item mechanical-net precision hardening (#203); idd-close Step 6.3 doc-sync sweep (#220); test aggregator + GitHub Actions CI, 21 suites (#217); idd-list blocked-state grouping + all-blocked banner (#84); config Mechanism 3.5 submodule routing (#162); check-plugin-presence enabled-state detection exit 3 (#212); monorepo host plugin disambiguation (#68); assert-helpers eval-content ban + safe output-grep pair (#188); diagnosis-detection contract fixtures (#61). Changed: parallel-ai-agents promoted to install-time dependency, vendored ensemble fork DELETED, idd-verify two-tier chain (#219); DA sequenced-spawn eliminates the #119 socket-crash polling window (#130); spectra-archive-post-ic --force-linked-issue vs --linked-issue intent separation (#172); worktree conventions unified on the managed helper (#169); bridge state migrated to .claude/.idd/state/bridge.json (#199); .gitattributes LF policy (#216); merge-completeness fixtures default-branch self-sufficiency (#224). Audits: dependency bindings vs deep-integration rule (#210), rules layering 12/12 (#215). Follow-ups filed: #225-#228.",
2020
"author": {
2121
"name": "Che Cheng"

plugins/issue-driven-dev/.claude-plugin/plugin.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"name": "issue-driven-dev",
33
"description": "v2.102.2: Deep Research light integration (#277, ruling b). idd-diagnose gains a non-binding pointer (the #111 superpowers hand-off shape: pure suggestion, no presence check, no dependency) fired when the diagnosis's quality depends on facts OUTSIDE the repo — with trigger examples AND counter-examples (the overly-broad-signal risk). Output flows back via '/idd-comment --type note' as summary + link, never full text (#116) — that is what keeps external research inside the audit trail. Both real-user misconceptions get canonical answers where they lived: research attaches AT diagnose (not after plan), and research vs implement are different phases' work, not substitutes. usecase-routing scenario 32 + a three-row internal-corpus vs external-world boundary table (idd-find / idd-ask / Deep Research). Deep integration stays a recorded residue until a plugin-dependable primitive exists.",
4-
"version": "2.110.0",
4+
"version": "2.111.0",
55
"author": {
66
"name": "Che Cheng"
77
},

plugins/issue-driven-dev/CHANGELOG.md

Lines changed: 76 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,82 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
66
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
77

8+
## [2.111.0] - 2026-08-28
9+
10+
### Fixed — the post-merge ensemble on 2.110.0 (first complete cross-model pass) returned FAIL
11+
12+
Six of six legs reported; Codex had been rate-limited for four consecutive rounds on the `#295` line and its DA leg
13+
died on a weekly limit the round before. 69 findings, 4 CRITICAL, 15 HIGH. Every fix below was reproduced before it
14+
was accepted.
15+
16+
- **CRITICAL — the gate fails open on a failed fetch.** Four lenses (codex, logic, security, regression) independently
17+
reproduced it. `gh api ... --paginate | jq -s 'add // []'` in one pipeline, with `set -u` and no `pipefail`: `if !`
18+
observed **jq's** status, and `jq -s 'add // []'` exits 0 on empty stdin printing `[]`. A 403, a 5xx, or a
19+
`--paginate` leg dying halfway was indistinguishable from "this issue has no comments", so the classifier answered
20+
`missing` — the sole authorisation for an irreversible duplicate post. The partial case is worse and unexotic:
21+
`--paginate` streams **oldest first**, so a mid-pagination failure keeps the old comments and drops the newest,
22+
which is by construction where a closing summary lives. Two syscalls, two checks now.
23+
**This is the seven-round failure shape, restored at the acquisition layer** — the header claim that "the gate
24+
simply never takes the broken road" was inverted: it took a different one, with no repair at all.
25+
26+
- **CRITICAL — `--issue ""` bypassed the gate entirely.** That is what `--issue "$NUMBER"` expands to when `NUMBER`
27+
is unset. `[ -n "$GATE_ISSUE" ]` was false, so the run fell through to **audit mode**, whose contract is to always
28+
exit 0 — read by the caller as "confirmed missing, go ahead". The validator's own `''` arm was unreachable for the
29+
same reason. Gate mode now keys on whether the FLAG was passed, not on whether it has a value.
30+
31+
- **`scripts/tests/gate-live-path/` (new, 52nd suite, 22 assertions) — the coverage that was missing.** The gate
32+
shipped with every assertion going through `--json-file`, which skips acquisition entirely. Repo resolution, the
33+
`gh issue view` fetch and the paginated REST fetch had none, and the suite was 51/51 green throughout. Every case
34+
here stubs `gh` on PATH and goes through the live branch.
35+
36+
- **The gate resolved its own executable from `$PWD`.** A shell default-value expansion whose default was a relative
37+
path, in a skill that runs inside the user's repo: a cloned repo shipping that path got arbitrary code execution
38+
plus an unconditional pass. Closing the "helper absent" hole had opened the "helper substituted" one.
39+
40+
- **Four HTML shapes a reader sees and the recogniser did not** — a marker or anchor tag before the heading on the
41+
same line, a raw `<h2>`, a `<details><summary>`. The first is the sharp one: the fixtures already had the marker
42+
*after* the heading and on its *own line*; marker *before*, same line, is the **third arrangement of the same three
43+
tokens**, and it is the one that authorises the duplicate post.
44+
45+
- **`#317` criterion (c) was not met**, and the closing summary said it was. `docs/workflows.md` is the third place
46+
and stated the OPPOSITE. The grep searched for `Phase 3p` — the implementation *label* — while that file states the
47+
*claim* without ever using the token. The test now scans the claim's vocabulary, not the label.
48+
49+
- **`#315` was broken seven ways**, including a use of the oldest-100 connection this same release routes the gate
50+
away from, and an undefined `$N`. The assertion meant to prove backend parity **locked the gap in**: adding the
51+
context to the codex leg would have made it fail. Reviewers are now enumerated by name; the pai devil's-advocate is
52+
recorded as a real upstream gap (`ensemble-workflow.js` `daPrompt` takes no `contextBlock`) rather than covered by
53+
a "both backends" claim.
54+
55+
- **`idd-update`'s previous fix was an over-correction I introduced**, and it regressed `#295`'s own measured case
56+
(a summary merged into the Implementation Complete comment). `phase = closed` now gates on GitHub's `state` — an
57+
authoritative field that comment text cannot forge — instead of on a stricter regex.
58+
59+
- **Attachment filenames were URL-decoded *after* `basename`**, so `%2e%2e%2f%2e%2e%2f…` escaped the attachments
60+
directory into `.claude/.idd/`. Reproduced. Decode first, then `basename`, then refuse anything that is not a
61+
plain filename.
62+
63+
- **`#288`'s rule and its two largest violations shipped together**: `references/external-agent-delegation.md` (the
64+
egress-body copy — the surface `#288`'s own rationale calls the worst) and `rules/tagging-collaborators.md` (a
65+
protocol `idd-verify` mandates, whose fixed files are the mention gate's decision source) were outside the scan's
66+
declared scope. The scan also exempted the whole `${TMPDIR:-/tmp}` idiom and did not even match that shape.
67+
68+
- Breadcrumb writing in `migrate-idd-config.sh` was still check-then-write; it now uses the same atomic `ln` primitive
69+
as the move itself.
70+
71+
### Honest residue
72+
73+
- **Nine broken probes were found and fixed during this round, by me, in my own tests.** An unquoted heredoc that made
74+
a case return the right exit code for the wrong reason; `$(...)` running assertions in a subshell so four counter
75+
increments vanished; `--include` after `--`; `bash -c` spawning a shell without the sourced function so two
76+
assertions passed having tested nothing; a backtick needle executing as command substitution; a fixture *title*
77+
containing `#121` which broke an unrelated assertion; an apostrophe in a comment closing the single-quoted jq
78+
program and turning 44 assertions red at once — the file header warns about that exact thing three hundred lines
79+
above. The count is the point: this is the failure mode of the work, not an incident in it.
80+
- `html_pfx` individually has no test weight in `present_re` (the safety property survives via `lead_re`); two
81+
narrower assertions were added so the strict half does. Disclosed rather than claimed.
82+
- The pai devil's-advocate still cannot receive the external-writes record. Upstream.
83+
884
## [2.110.0] - 2026-08-15
985

1086
### Added — the closing-summary gate is now executed, not read

0 commit comments

Comments
 (0)