Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
67 commits
Select commit Hold shift + click to select a range
a02b69a
feat(review): audit the applied --fix for unpinned new assumptions
wenshao Aug 26, 2026
ca8f8a8
fix(review): close round-1 fix-audit holes (#10169)
Aug 26, 2026
254739e
fix(review): close round-2 fix-delta holes (#10169)
Aug 26, 2026
9289572
fix(review): close round-3 fix-delta holes (#10169)
Aug 27, 2026
de17ab8
fix(review): close round-4 fix-delta holes (#10169)
Aug 27, 2026
a5fb370
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
Aug 27, 2026
5eecc55
fix(review): close round-5 fix-delta holes (#10169)
Aug 27, 2026
bbdcf58
fix(review): fail closed on fix-delta blind spots and capture notes (…
Aug 28, 2026
739f57a
Merge branch 'main' into feat/review-fix-audit
wenshao Aug 28, 2026
315f006
Merge branch 'main' into feat/review-fix-audit
qwen-code-dev-bot Aug 28, 2026
545f87d
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
qwen-code-dev-bot Aug 28, 2026
3732d02
fix(review): close round-7 and round-8 fix-delta holes (#10169)
qwen-code-dev-bot Aug 28, 2026
8ce6ca0
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
qwen-code-dev-bot Aug 29, 2026
078cf47
fix(review): close round-9 and round-10 fix-delta holes (#10169)
qwen-code-dev-bot Aug 29, 2026
88ef528
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
qwen-code-dev-bot Aug 29, 2026
8bfd83c
fix(review): refuse side-path symlink writes, close blind-spot entran…
qwen-code-dev-bot Aug 29, 2026
db39815
fix(review): close round-11 fix-delta holes (#10169)
qwen-code-dev-bot Aug 29, 2026
e6d1519
Merge branch 'main' into feat/review-fix-audit
qwen-code-dev-bot Aug 30, 2026
ae00d71
Merge branch 'main' into feat/review-fix-audit
wenshao Aug 30, 2026
177ffa1
Merge branch 'main' into feat/review-fix-audit
qwen-code-dev-bot Aug 30, 2026
683db0d
Merge branch 'main' into feat/review-fix-audit
qwen-code-dev-bot Aug 30, 2026
20dcde6
Merge branch 'main' into feat/review-fix-audit
qwen-code-dev-bot Aug 31, 2026
d26da50
Merge remote-tracking branch 'origin/main' into pr-10169
wenshao Aug 31, 2026
964936f
fix(review): close the fix-audit's blind spots and its claim-vs-edit …
wenshao Aug 31, 2026
1751c45
fix(review): ask the attribute probe about the raw name bytes
wenshao Aug 31, 2026
4c42ffe
chore(review): smooth the claim-vs-edit refusal wording
wenshao Aug 31, 2026
30d8b6b
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 3, 2026
cff8ac3
fix(review): derive the fix-delta prune from git's registry and pin t…
wenshao Sep 3, 2026
9b17eb5
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 3, 2026
a8edda3
Merge branch 'main' into feat/review-fix-audit
wenshao Sep 3, 2026
8e7b14a
Merge branch 'main' into feat/review-fix-audit
wenshao Sep 4, 2026
973a7ce
fix(review): anchor the fix-delta baseline and close the round-17 bli…
wenshao Sep 4, 2026
d58c3ea
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 5, 2026
1a47982
fix(review): classify review worktrees by the orchestrator's naming a…
wenshao Sep 5, 2026
163c7cb
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 5, 2026
6e1e3e3
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 5, 2026
e2351cc
Merge branch 'main' into feat/review-fix-audit
wenshao Sep 5, 2026
ae256ce
fix(review): close the round-20 fix-delta and fix-audit entrances
wenshao Sep 5, 2026
8364ea6
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 7, 2026
042874f
fix(review): close the round-19/20 fix-audit findings with a state ma…
Sep 8, 2026
6d9eeea
Merge remote-tracking branch 'origin/feat/review-fix-audit' into feat…
Sep 8, 2026
c1ad69f
fix(review): close the round-21/22 fix-audit findings — hooks, discov…
Sep 8, 2026
743e759
fix(review): close the round-23 fix-audit findings
wenshao Sep 9, 2026
d9637ee
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 9, 2026
0640b48
fix(review): carry the capture's pathspec as bytes through stdin
wenshao Sep 9, 2026
bb540bf
fix(review): stop excluding the in-tree git dir by its decoded name i…
wenshao Sep 9, 2026
596a138
fix(review): close the round-24/25 blind-spot and capture-invention e…
wenshao Sep 9, 2026
c68b029
test(review): skip the unreadable-interior witness where permissions …
wenshao Sep 9, 2026
372aca5
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 10, 2026
01894d2
docs(review): name the channel the fix-delta snapshot fingerprint pri…
wenshao Sep 10, 2026
f67ba01
Merge branch 'main' into feat/review-fix-audit
wenshao Sep 10, 2026
32af418
fix(review): close round 26's capture, probe and protocol entrances
wenshao Sep 12, 2026
6aa0361
Merge remote-tracking branch 'origin/feat/review-fix-audit' into feat…
wenshao Sep 12, 2026
cc21db3
fix(review): narrow the file-target family's own records out of the r…
wenshao Sep 12, 2026
b2e3945
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 12, 2026
a351e7b
test(review): pin the fix-audit wave emit-workflow builds for Step 6B
wenshao Sep 12, 2026
03795d5
fix(review): close the round-10 capture entrances and anchor the hunk…
wenshao Sep 14, 2026
7fda80e
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 15, 2026
5340ea2
fix(review): seed the second fix-delta capture from the snapshot tree…
wenshao Sep 17, 2026
9db1286
fix(review): close the round-29 fix-delta findings and the audit-foun…
wenshao Sep 17, 2026
1f52690
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 18, 2026
bf1380f
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
wenshao Sep 21, 2026
322e9c4
docs(review): tell the fix-audit agent apart from the fix-audit round
wenshao Sep 21, 2026
8a43737
Merge remote-tracking branch 'origin/main' into feat/review-fix-audit
Sep 23, 2026
2f1bf30
refactor(review): state the fix-delta scope instead of certifying it
Sep 23, 2026
6c3eb96
fix(review): keep fix-delta working under .qwen/ ignore rules
Sep 23, 2026
aac172e
fix(review): make the fix-delta scope line say what the capture does
Sep 24, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
refactor(review): state the fix-delta scope instead of certifying it
Thirty review rounds went into making `fix-delta` certify that its hunks
were the whole edit: nested-repository digests, ignored-path and symlink
classification, sparse/skip-worktree bits, redirected excludes, filter
screening, record fingerprints. fix-delta.ts grew from 222 to 5,680
lines and held 142 of the loop's 185 Criticals, each round's fixes
opening the next round's entrances — for a check whose output is a
disclosure that changes no verdict.

Replace the certification with a fixed scope printed on every `--since`
run: the hunks hold what `git add -A` records in this repository, and an
edit inside a submodule or nested repository, or to a gitignored file,
is named as outside it. What stays is what the audit needs: the
throwaway-index capture, the review's own side files excluded (both the
name and the directory form, at any depth, plus the command's own
--out/--since), the second capture seeded from the snapshot tree, and a
moved-HEAD disclosure. HEAD is now read once and the capture is seeded
from that sha, so the record and the tree describe one moment (R30-1).

agent-prompt drops --hunks-fingerprint and the C-quoted patch-path
parser; whether a fixed finding's edit is among the hunks is now the
auditor's check, which has both in front of it. SKILL.md Step 6B,
DESIGN.md and the user docs follow; lib/worktree.ts is back to main and
lib/git.ts keeps only gitWithEnv.
  • Loading branch information
wenshao
wenshao committed Sep 23, 2026
commit 2f1bf302d46f285ef95d334cdbc3e7243cba84a1
2 changes: 1 addition & 1 deletion docs/users/features/code-review.md
Original file line number Diff line number Diff line change
Expand Up @@ -234,7 +234,7 @@ A finding is skipped when its fix would change intended behavior, would need cha

**Every finding gets an outcome, and this is enforced rather than requested.** The ledger goes through `qwen review findings --outcomes`, which refuses a set that does not cover all of them — a fixer that applies six of nine findings and reports six has not lied about any one of them, it has silently shortened the list, and you would have no way to see the three that fell off.

**The applied fix is then audited — by one agent, and not by re-reviewing your tree.** The review does not re-run itself over code it just edited (that would be a new review of different code, wearing this one's verdict). Instead it records your working tree before the first edit (`qwen review fix-delta --snapshot`, through a throwaway index — your own index and stash are never touched), diffs the tree against that record afterwards (`fix-delta --since`), and hands exactly those hunks, together with the `fixed` findings each claims to close, to a single `fix-audit` agent. That agent never sees the reviewed diff and files no findings. It answers one question per hunk: what does this edit newly assume — a bound, a key, a lifetime, a shared resource, an ordering — and does anything in the tree pin it (a test that goes red, a type, a single source the value derives from)? Only the unpinned ones come back, each with what would pin it. They are reported in a **Fix audit** block in the terminal and as the affected finding's outcome note; they are not findings, change no verdict, and are left for you to act on — the measured reason this exists is that a third of a multi-round review's later findings were introduced by the fix immediately before them, and the two Criticals a real fix round shipped were exactly assumptions of this kind that a mutation probe of the intended fix sites could not reach (that round was a PR review whose author applied the posted comments — the path this audit does not run on; it runs where `--fix` is effective, on local and file targets). If nothing was `fixed` and nothing was applied, the audit is skipped and says so; if the ledger and the tree disagree — no `fixed` outcome beside hunks that landed — you are told, because that is a bookkeeping problem rather than an audit question; a `fixed` finding no hunk touches is annotated in the auditor's input rather than refused, since a fix can legitimately land entirely in files the finding does not name. And because the hunks are the audit's whole input, the snapshot command also reports what it cannot see: uncommitted content inside a submodule or a nested repository (an edit there moves no gitlink, so no tree records it), paths its probe could not resolve, a HEAD that moved between the two moments (a change that landed by commit alone — an ignored path force-added, a tracked path untracked — leaves no hunk, because the second capture is measured against the snapshot's own tree rather than against the new commit), and repo-local git configuration that shapes what is captured or how it renders — a content filter, a `.git/info/exclude` rule, or a `diff` attribute that turns a text edit into an opaque binary patch. The capture itself never runs inside a submodule or nested repository, so nothing configured there is executed on your behalf.
**The applied fix is then audited — by one agent, and not by re-reviewing your tree.** The review does not re-run itself over code it just edited (that would be a new review of different code, wearing this one's verdict). Instead it records your working tree before the first edit (`qwen review fix-delta --snapshot`, through a throwaway index — your own index and stash are never touched), diffs the tree against that record afterwards (`fix-delta --since`), and hands exactly those hunks, together with the `fixed` findings each claims to close, to a single `fix-audit` agent. That agent never sees the reviewed diff and files no findings. It answers one question per hunk: what does this edit newly assume — a bound, a key, a lifetime, a shared resource, an ordering — and does anything in the tree pin it (a test that goes red, a type, a single source the value derives from)? Only the unpinned ones come back, each with what would pin it. They are reported in a **Fix audit** block in the terminal and as the affected finding's outcome note; they are not findings, change no verdict, and are left for you to act on — the measured reason this exists is that a third of a multi-round review's later findings were introduced by the fix immediately before them, and the two Criticals a real fix round shipped were exactly assumptions of this kind that a mutation probe of the intended fix sites could not reach (that round was a PR review whose author applied the posted comments — the path this audit does not run on; it runs where `--fix` is effective, on local and file targets). If nothing was `fixed` and nothing was applied, the audit is skipped and says so; if the ledger and the tree disagree — no `fixed` outcome beside hunks that landed, or a `fixed` outcome beside no hunk at all — you are told, because that is a bookkeeping problem rather than an audit question. A `fixed` finding whose file no hunk touches is reported by the auditor as unattested rather than refused, since a fix can legitimately land entirely in files the finding does not name. The hunks have a fixed scope, printed beside the audit: what `git add -A` records in your repository — tracked files, and untracked files no ignore rule hides. An edit inside a submodule or a nested repository, or to a gitignored file, is not in them, and a commit made between the snapshot and the diff is reported, since a change that landed by commit alone leaves no hunk.

## Resuming an interrupted review (`--resume`)

Expand Down
Loading