-
Notifications
You must be signed in to change notification settings - Fork 3k
feat(review): transfer per-file content verdicts across rebases #9191
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
wenshao
wants to merge
41
commits into
review-incremental/2-local-anchor
from
review-incremental/3-blob-verdicts
Closed
Changes from all commits
Commits
Show all changes
41 commits
Select commit
Hold shift + click to select a range
4dda9ee
feat(review): transfer per-file content verdicts across rebases
wenshao 58ffea9
fix(review): resolve merge-conflict blocks committed into SKILL.md
wenshao 7a95f44
fix(review): round-2 findings — narrow the candidate, consult verdict…
wenshao 485011a
fix(review): round-3 findings — certify only what was reviewed, one e…
wenshao 6c98cb5
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao ffed4fe
fix(review): round-4 findings — police every persisted string, test t…
wenshao 31f36b1
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao 0f7127d
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao 8b29078
fix(review): round-5 Criticals — unusable beats wrong, and no write f…
wenshao 272f6e8
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao 393994c
fix(review): round-7 Criticals — certify only what was read, guard th…
wenshao 33d0565
test(review): realpath the cache-commit fixture's temp dir
wenshao 9bc29f2
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao 75386a5
fix(review): keep both report fields the merge collided on
wenshao f4c32a3
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao ed7145e
Merge branch 'tmp-9190' into tmp-9191
wenshao c0f8b7b
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao 8306841
Merge remote-tracking branch 'origin/review-incremental/2-local-ancho…
wenshao 95d3e68
Merge remote-tracking branch 'origin/review-incremental/2-local-ancho…
wenshao 797b3e0
Merge branch 'tmp2' into tmp3
wenshao 629b8f2
fix(review): repair the build, close the attributes hole, stop overcl…
wenshao 7f86508
Merge remote-tracking branch 'origin/review-incremental/2-local-ancho…
wenshao 31858f5
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao 24ce961
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao 192434f
Merge branch 'tmp2' into tmp3
wenshao d3634a8
Merge branch 'tmp2' into tmp3
wenshao b8f0c7c
fix(review): keep the attribute digest through promotion, guard both …
wenshao aa59c7a
Merge branch 'review-incremental/2-local-anchor' into review-incremen…
wenshao 1c7760f
Merge branch 'tmp2' into tmp3
wenshao 91879cc
fix(review): a refused candidate write costs the anchor, not the round
wenshao 621dc74
Merge branch 'tmp2' into tmp3
wenshao b037b44
Merge remote-tracking branch 'origin/review-incremental/2-local-ancho…
wenshao d560012
merge: take the shared safeTarget, keep this branch's parent guard
wenshao 563971d
Merge branch 'review-incremental/2-local-anchor' of github.com:QwenLM…
wenshao e5765e1
merge: union the subcommand list and the path-helper tests
wenshao c4f652a
merge: keep this branch's guard import, and its own DESIGN paragraph
wenshao 8295083
Merge branch 'review-incremental/2-local-anchor' of github.com:QwenLM…
wenshao a4467d4
Merge branch 'review-incremental/2-local-anchor' of github.com:QwenLM…
wenshao 6e67308
Merge branch 'review-incremental/2-local-anchor' of github.com:QwenLM…
wenshao 54785b0
merge: let the candidate's identity win cache-commit's merge
wenshao 53817ae
merge: union the fs imports and the plan's new stop field
wenshao File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[Suggestion] R4-6: The removed
.slice(0, 12)incidentally bounded the interpolated anchor;displayAnchoronly truncates 40–64-hex labels,inertPathsubstitutes characters but has no length cap, andincrementalScopeOfvalidates the anchor only as a non-empty string — so an arbitrary-size non-hex anchor now reaches every chunk brief (this site) and role brief (the twin at ~999). — Failure scenario: the plan file is parsed off disk with field-by-field re-validation precisely because it is untrusted input; a tampered plan with a multi-megabyteincremental.anchorinjects it into every agent brief, blowing the brief size budget this file otherwise enforces withSCOPE_LIST_CAP/SCOPE_EDGE_CAP. Legitimate producers are bounded (rescope's 7–64-hex gate or the literalcontent-verdicts), so only a tampered plan triggers this — the old code bounded that case at 12 chars. Suggested fix: inincrementalScopeOf, reject or truncate over-length anchors (e.g.raw.anchor.length > 64 → return null, matching the degrade-to-full-scope policy), or clampdisplayAnchor's output to a fixed display length.中文说明
建议:被移除的
.slice(0, 12)附带地限制了被内插锚点的长度;displayAnchor只截断 40–64 位十六进制标签,inertPath替换字符但不限长,incrementalScopeOf只校验锚点为非空字符串——于是任意长度的非十六进制锚点现在会进入每个分块 brief(本处)与角色 brief(~999 处的孪生点)。失败场景:plan 文件之所以逐字段重新校验,正因为它是不可信输入;篡改的 plan 用数 MB 的
incremental.anchor把该字符串注入每个代理 brief,击穿本文件用SCOPE_LIST_CAP/SCOPE_EDGE_CAP维护的 brief 体积预算。合法生产者是有界的(rescope 的 7–64 hex 门或字面量 `content-verdicts``),因此只有篡改的 plan 能触发——旧代码把该情形限制在 12 字符。建议修复:在
incrementalScopeOf中拒绝或截断超长锚点(如raw.anchor.length > 64 → return null,与降级到全量范围的策略一致),或给displayAnchor的输出加上固定显示长度上限。— qwen3.8-max via Qwen Code /review (v0.21.12)