Skip to content

Tie reviews to the exact reviewed version with a fingerprint - #42

Merged
taspinar merged 1 commit into
mainfrom
feature/38-review-fingerprint
Oct 2, 2026
Merged

taspinar merged 1 commit into
mainfrom
feature/38-review-fingerprint

Conversation

@taspinar

@taspinar taspinar commented Oct 2, 2026

Copy link
Copy Markdown
Owner

What changed

  • New scripts/lib/fingerprint.sh: the Git tree hash of the current file contents, for the whole working tree or an explicit set of paths (files, directories, symlinks). Uncommitted and untracked changes count; ignored files count only when Git tracks them; review and triage artifacts never count. It depends on content, not commits.
  • review-feature.sh records the fingerprint as reviewed_tree, and reviewed_paths (null for a whole-tree review). Review artifacts accept reviewed_paths.
  • triage-review.sh and apply-triage.sh refuse a stale review before starting an agent.
  • New scripts/check-review.sh <review-json>: exit 0 when current, 1 when stale, 2 on an error. Ready for finish-planning.sh in wave 4.
  • Review and triage runs also detect an agent changing the artifacts that fingerprints leave out.
  • docs/development.md explains when a review becomes stale.
  • New tests/fingerprint-test.sh; test fixtures now carry real fingerprints, and the triage and apply-triage suites cover stale reviews.

Issue / acceptance criteria

Closes #38

Risk

  • Low
  • Medium
  • High

Verification evidence

  • ./scripts/verify.sh passed (10 checks)
  • Tests added/updated where appropriate (also passing under macOS system bash 3.2)
  • Independent review completed when required
  • Architecture/docs/ADR updated when required

Independent review: Codex (gpt-6-astra) through the isolated read-only profile. CHANGES REQUIRED:

  • M1 (replacing the full snapshot with the fingerprint dropped detection of a reviewer changing review or triage artifacts): fixed with a separate artifact hash, with a regression test.
  • MIN1 (explicit file sets did not exclude artifacts): fixed, with a test.
  • MIN2 (dangling symlinks were treated as absent in file sets): fixed, with a test.

check-review.sh reported the new review as current right after it was written. Not re-reviewed after the fixes.

Agent involvement

Planner: —
Implementer: Claude (Opus 5.5)
Reviewer: Codex (gpt-6-astra)

Production impact

None.

🤖 Generated with Claude Code

scripts/lib/fingerprint.sh computes a content fingerprint of the working
tree or of an explicit set of paths, including uncommitted and untracked
changes and excluding review and triage artifacts. Committing unchanged
content keeps it; changing a covered file changes it.

review-feature.sh records it as reviewed_tree (and reviewed_paths for a
file-set review). triage-review.sh and apply-triage.sh refuse a stale
review before starting an agent, and check-review.sh reports whether a
review is current. Agent runs also detect changes to the artifacts that
fingerprints leave out.

Closes #38

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@taspinar
taspinar merged commit 2a67d26 into main Oct 2, 2026
1 check passed
@taspinar
taspinar deleted the feature/38-review-fingerprint branch October 2, 2026 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tie reviews to the exact reviewed version with a fingerprint

1 participant