Skip to content

feat(policy): merge driver refuses an author-written verdict (review-on-done 1b.3) - #111

Merged
androidand merged 1 commit into
devfrom
feat/review-authenticity-driver
Oct 3, 2026
Merged

androidand merged 1 commit into
devfrom
feat/review-authenticity-driver

Conversation

@androidand

Copy link
Copy Markdown
Owner

mayMerge gains authorSessionID: the verdict must name a reviewer session and it must differ from the author's. Also requireIndependent, which refuses a same-model or unrecorded-independence review. toMergeEvidence now carries reviewer.sessionID; merge-run passes both options through.

Evidence: 5 new tests in drivers.test.ts; mutating the equality check turns the author-self-approval test red (1 fail). policy suite 157 pass. Not covered: no caller passes authorSessionID yet (the merge CLI is unwritten), merge-run passthrough has no test, 1b.1/1b.2/1b.4 remain.

🤖 Generated with Claude Code

…d can require an independent review

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown

This PR doesn't fully meet our contributing guidelines and PR template.

What needs to be fixed:

  • PR description is missing required template sections. Please use the PR template.

Please edit this PR description to address the above within 2 hours, or it will be automatically closed.

If you believe this was flagged incorrectly, please let a maintainer know.

@androidand
androidand merged commit 3bdfbf0 into dev Oct 3, 2026
3 of 9 checks passed
androidand added a commit that referenced this pull request Oct 4, 2026
The reader shipped in abadec9 and enforces nothing: the record is a plain
file in the author's working tree, and a model can write a file. This adds the two
pieces that make it mean something, and is explicit about the piece it cannot fix.

write() stamps the reviewer from the caller's own session identity, never from a
model-supplied argument, so a model can record a verdict but cannot record one *as*
somebody else. It validates against the reader's own closed schema before writing —
a record rejected here would be rejected on read too, and the round trip would
look like a review that never happened rather than a refused write — and renames
into place so a reader never sees a truncated file.

gate() supplies the authorSessionID that mayMerge was already asking for but that
no caller passed, so #111 stops being inert. It carries the record's own base as
mergeBase, letting the driver apply its own unrelated-histories rule rather than
second-guessing it.

Does NOT close the hole, and this is pinned as a test rather than left in a
comment: a record forged by shell naming a real reviewer is still accepted. The
gate compares two ids; it cannot tell a real review from a fabricated one.
Deny the path to models is task 1b.2 and does not change this for bash. Only OS
separation would, and nothing here claims it. That is why the surrounding controls
are bounded claims rather than proof of authorship.

Identity comes from ctx.sessionID — in-process, not parsed from a message — so
this does not wait on callback confirmation, which is not merged.

Mutation-checked, each failing only the test that owns it: dropping the author
comparison, and having the writer skip validation. test/policy 166 pass / 8 skip /
0 fail, typecheck clean, fork:verify clean.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant