Commit Graph
16 Commits
Author SHA1 Message Date
ddadmin bbf4499b71 fix(skill): findings from round-4 adversarial review
- Зачем:
  - round-4 self-review на ветке нашёл HIGH-bug (пропущен плейсхолдер в Step 2, буквальный Opus мог не подставить литерал) и три MEDIUM (лишний abort на APPROVED при пустом `~/.codex/sessions/`, ложное обещание детекции wrong-session, same-epoch race при быстром codex). Исправляю до PR, чтобы не оставлять известных дефектов.
- Что:
  - SKILL.md Step 2: `${CODEX_SESSIONS_BEFORE}` добавлен в список placeholders с явным пояснением роли.
  - SKILL.md Step 4/7 + Rules: timestamp capture через `$(($(date +%s) - 1))` — сдвиг на секунду защищает от same-epoch race против `-newermt` strict-greater.
  - SKILL.md Step 4: перестановка проверок — review-sanity (check 3) раньше session-id capture (check 4); на APPROVED session-id не нужен → skip entirely. Убирает лишний abort валидной APPROVED round.
  - SKILL.md Step 4 check 4: parallel-codex caveat переписан честно — wrong-session resume НЕ детектируется автоматически, риск silent corruption зафиксирован.
  - SKILL.md Step 4 check 4: при zero-lines перед abort выводятся диагностические артефакты (jsonl, stderr, 3 недавних rollout).
  - DESIGN.md §4.8: обновлён с 4-check порядком и объяснением почему review раньше session-id.
  - DESIGN.md §4.1: alternative-considered про filesystem-only-primary переписан — убрано ложное обещание §4.8-детекции; trade-offs расширены `-1` shift и skip-on-APPROVED.
  - README.md: добавлены permissions `Bash(ls -t ~/.codex/sessions*)` для диагностики.
- Проверка:
  - Заново прогнать §7.1 smoke-test: EXIT=0, rollout-UUID извлекается даже при пустом JSONL.
  - Edge case: codex exec с cached response <1s + `CODEX_SESSIONS_BEFORE=T` → `find -newermt "@$((T-1))"` всё равно находит rollout.
2026-04-17 17:31:24 +03:00
ddadmin af0ad8ab11 docs: macOS/BSD find — template+понимание вместо ветвления
- Зачем:
  - `-newermt "@<epoch>"` и `-printf` в secondary session-id capture — GNU-специфичные; на macOS BSD find они не работают, а тестировать на маке негде.
- Что:
  - SKILL.md: добавлена one-paragraph platform note рядом с `find` — формулирует цель шага ("найти свежие rollout-файлы, выбрать последний, извлечь UUID") и приглашает Opus/пользователя подставить BSD-эквивалент.
  - docs/DESIGN.md §9.5: новое known-limitation с обоснованием template+understanding подхода вместо platform-detection.
  - README.md Known limitations: user-facing note, что end-to-end на macOS не тестировался.
- Проверка:
  - Ничего не ломается на Linux (команды без изменений).
  - На macOS оператор читает note и адаптирует.
2026-04-17 17:21:27 +03:00
ddadmin b213678ff0 refactor(skill): template+understanding вместо шелл-пайплайна в secondary session-id
- Зачем:
  - Opus последней версии выполняет инструкции буквально; длинный пайплайн `find | sort | tail -1 | xargs basename | grep -oE UUID` создаёт permission-матчинг проблему (Claude Code матчит всю команду с пайпами) и не оставляет модели свободы адаптироваться к среде.
- Что:
  - SKILL.md Step 4 check 3 secondary: один `find -printf '%T@ %f\n'`, парсинг отдан ведущему (Claude выбирает max-mtime и извлекает UUID из filename).
  - SKILL.md Step 7 check 4: компактная ссылка на ту же логику Step 4, без дублирования пайплайна.
  - README.md permission упрощён до `Bash(find ~/.codex/sessions*)` — матчит любой find в правильном поддереве.
- Проверка:
  - `find ~/.codex/sessions -name 'rollout-*.jsonl' -newermt "@$(date -d '-1 minute' +%s)" -printf '%T@ %f\n'` на живой среде возвращает 0+ строк, парсятся корректно.
2026-04-17 17:18:31 +03:00
ddadmin 390d912739 docs(design): подтянуть §3.2, §7.2, §7.3, §2.5 под новую pipe-форму
- Зачем:
  - остатки документации ссылались на `- < file` и старый одноуровневый session-id, расходились с SKILL.md после основной правки.
- Что:
  - §3.2 теперь рекомендует `cat file | cmd -` со ссылкой на §4.13.
  - §7.2 smoke-test resume переведён на pipe-форму и включает secondary filesystem session-id capture.
  - §7.3 (bad-UUID) тоже на pipe-форме для изоляции от §6.6.
  - §2.5 разделяет success-row на reference и affected окружения, добавлен row для `- < file` exit-1-empty-stderr.
- Проверка:
  - `grep -n '\- < ' docs/DESIGN.md` остаются только контекстные упоминания (§2.1 описание обеих форм, §4.13 decision, §6.6 lesson, §8 log).
2026-04-17 17:11:32 +03:00
ddadmin fa61ae03ac fix(skill): pipe-форма и rollout-UUID fallback для переносимости
- Зачем:
  - форма `codex exec ... - < file` exit=1 с пустым stderr, а `--json` stdout оказывается пустым в части Claude Code песочниц; без обхода скилл не может захватить session ID и теряет resume на раундах 2-5.
- Что:
  - SKILL.md Step 4/7 переведены на `cat file | codex exec ... -` как canonical; добавлен two-tier захват session ID (primary = first JSONL line, secondary = UUID из имени `~/.codex/sessions/**/rollout-*.jsonl` с mtime > CODEX_SESSIONS_BEFORE).
  - README.md обновлены permissions (pipe-форма, `find rollout-*`, `date +%s`) и добавлен troubleshooting про env-specific пустой JSONL.
  - docs/DESIGN.md: §2.1 описывает обе формы, §2.2 фиксирует env-specific suppression, §2.3 добавляет filesystem-recovery путь, §4.1 переделан на two-tier decision, добавлены §4.13 (canonical pipe) и §6.6 (lesson от 2026-04-17), в §8 новая строка с окружением yantar-k8s.
- Проверка:
  - DESIGN.md §7.1 smoke test (обновлён на pipe-форму + проверка filesystem secondary path).
  - Оба окружения (reference WSL2 + containerized sandbox) должны давать валидный session ID и успешный resume.
2026-04-17 17:09:29 +03:00
ddadminandClaude Opus 4.7 3f0d1321ff docs: add DESIGN.md explaining why the skill is built this way
1082-line design note covering:
- Empirical facts about Codex CLI 0.121.0 (invocation, streams,
  resume semantics, known failure modes) with copy-pasteable
  verification commands.
- Claude Code harness facts (Bash truncation, cwd drift, Opus
  literal-interpretation tendencies).
- 12 design decisions in a uniform format: what, where in SKILL.md,
  alternatives considered, why chosen, trade-offs accepted.
- Rejected ideas (marker files, per-round naming, $(pwd), etc.) with
  reasons, so future contributors don't re-propose them.
- Prior diagnostic errors from a previous agent-auditor's dump that
  turned out to be wrong when verified, kept as a methodological
  lesson.
- Smoke-test protocol (§7) with concrete commands and expected
  outputs so any maintainer can verify the Codex contract still holds
  in minutes.
- Update protocol: when and how to revise this file, with a pointer
  that future Opus generations interpret instructions more literally
  and SKILL.md hardening must track that.
- Mermaid flow diagram of the round-trip.

Intended audiences: future Claude sessions resuming work on the skill,
human developers, and new contributors. The file is self-contained —
does not rely on conversation history that produced the current design.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-17 14:29:16 +03:00
ddadminandClaude Opus 4.7 6cf42ad130 refactor: switch to --json for session capture, harden fallbacks
Address 10+ findings from two rounds of adversarial review of the
previous Step 4/5/7 design. Major changes:

- Use `codex exec --json` so `thread_id` can be parsed deterministically
  from the first JSONL line on stdout (bypasses the ~30KB Bash-tool
  truncation that could drop stderr metadata in the old flow).
- Capture REPO_ROOT via `git rev-parse --show-toplevel` at Step 2 and
  substitute the absolute path literally. Pin the initial exec with
  `-C "${REPO_ROOT}"` and prefix every resume with `cd '${REPO_ROOT}' &&`
  because `codex exec resume` has no `-C` flag and inherits cwd from
  the invoking shell.
- Drop `resume --last` from the fallback chain (cwd filtering is not
  enough to distinguish our session from unrelated parallel codex runs).
- Update CODEX_SESSION_ID only on full success (exit 0, no stderr error
  line, review file contains VERDICT and findings on REVISE); rotate
  to the resumed session's new thread_id each round.
- Harden the "show review" gate (Step 5 "YOUR NEXT MESSAGE" instruction
  and Step 6 precondition check) now that --json stdout no longer leaks
  review text into the Bash tool result.
- Add strict check order for launch and resume (exit → stderr → review
  file) so we never commit a broken session-id on a half-failed run.
- Replace silent fresh-exec fallback with interactive ask / headless
  severity-based decision. Fresh-exec prompt rebuilds prior rounds from
  conversation history.
- Bare repo / submodule / shell-hostile paths abort at Step 2 with a
  clear message rather than failing silently later.
- Conditional cleanup: keep temp files on abort paths for diagnostics.
- Expand REVIEW_ID random to 8 digits.

README: update permissions (add stdout JSONL read, resume-prompt write,
narrower `cd * && ... codex exec resume *` pattern) and troubleshooting
(NOT VERIFIED outcome, bare repo, submodule).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-17 14:07:42 +03:00
ddadminandClaude Opus 4.6 5966e2a388 docs: rewrite README for agent-friendly setup, expand permissions
- Restructure installation as step-by-step Quick Start with verification commands
- Expand permissions list: add Read(/tmp/codex-review-*), Read(/tmp/codex-stderr-*),
  Bash(rm -f /tmp/codex-*), Bash(tee *)
- Add guidance on global vs project config for permissions
- Add Troubleshooting section (model errors, timeouts, resume, Plan Mode)
- Add authentication docs (ChatGPT login vs CODEX_API_KEY)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 17:56:28 +03:00
ddadminandClaude Opus 4.6 899591ebf0 docs: add platform note to prevent recursive Codex invocation
When the skill is available in shared ~/.agents/skills/, Codex CLI
picks it up and tries to follow its instructions — launching itself
recursively. The blockquote explains the architectural constraint
and tells Codex to review directly instead.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-07 11:53:31 +03:00
ddadminandClaude Opus 4.6 05fe11a4df fix: permissions, temp file prefix, session ID extraction
- Fix recommended permissions: add missing Write(/tmp/codex-prompt-*),
  remove overbroad rm rule (cleanup is best-effort)
- Rename claude-plan-* → codex-plan-* so all temp files share codex-* prefix
- Extract session ID via Read tool instead of grep (no extra permission needed)
- Add UUID format spec for session ID validation

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 23:23:07 +03:00
ddadminandClaude Opus 4.6 834a74c798 docs: document Plan Mode and resume sandbox limitations
- Add Plan Mode /tmp write limitation to SKILL.md (Step 4) and README
- Document that `codex exec resume` inherits sandbox from original session
- Remove none/low reasoning effort options (minimum is now medium)
- Add .claude to .gitignore (plan files from testing)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 22:50:26 +03:00
ddadminandClaude Opus 4.6 0b8891e19e fix: prompt delivery через stdin и захват session ID
- Зачем:
  - длинные XML-промпты (60+ строк) ломали shell quoting при inline-передаче в codex exec.
  - session ID терялся из-за 2>/dev/null на stderr, делая resume невозможным.
- Что:
  - промпт записывается в temp-файл, передаётся через stdin: `codex exec ... - < file`.
  - stderr перенаправлен в temp-файл, session ID извлекается через grep.
  - resume унифицирован: тот же stdin-механизм вместо inline-аргумента.
  - fallback fresh exec явно обновляет CODEX_SESSION_ID.
  - cleanup дополнен новыми temp-файлами (prompt, stderr).
- Проверка:
  - smoke test: plan review → 2 раунда с resume через session ID — OK.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 21:16:06 +03:00
ddadminandClaude Opus 4.6 649256517e feat: translate SKILL.md to English, add permissions guide
- Why:
  - English makes the skill accessible to a wider audience
  - Permission prompts on every git/codex call hurt UX
- What:
  - Translated all SKILL.md instructions and rules to English
  - Added recommended permissions section to README
  - Removed literal ## from output_format to avoid Claude Code
    security warning about # in quoted arguments
  - Removed overly broad Bash(codex *) permission rule
  - Added explicit note about codex exec scope limitations
- Verify:
  - /adversarial-review produces structured output with markdown headers
  - No "Newline followed by #" security warning on codex exec

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 20:06:22 +03:00
ddadminandClaude Opus 4.6 515820abed fix: verdict parsing, README claims, example consistency
Fixes from adversarial code-vs-plan review (3 rounds):
- Verdict format in prompts now matches parser (bare tokens)
- Missing verdict treated as parse failure, not approval
- README: softened backend swappability to "designed for extensibility"
- Example: replaced incorrect FK scenario with valid transaction bug
- Example: aligned fixes and round-2 summary with round-1 finding

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 19:24:56 +03:00
ddadminandClaude Opus 4.6 b86a1778e6 feat: adversarial prompt rewrite + README + example
- Rewrite all review prompts with XML-structured adversarial stance
  (role, operating_stance, attack_surface, finding_bar, calibration)
- Rename skill from codex-review to adversarial-review
- Add verbatim output rule for reviewer findings
- Improve resume prompt with adversarial re-review focus
- Add README with installation, usage, architecture, roadmap
- Add synthetic example of review output
- Inspired by openai/codex-plugin-cc (Apache-2.0) prompt structure

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 18:29:15 +03:00
ddadminandClaude Opus 4.6 7c130253b1 chore: initial import of codex-review skill
Baseline copy of the working codex-review SKILL.md from dotfiles
before adversarial prompt rewrite and rebranding.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 18:25:46 +03:00