feat: review_diff v2 — source plus plugin-generation semantic risk #34
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Depends on
Reference
h-dv/code-index#34
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Current state
review_diff v1 shipped in v0.6.0 and subsequent hardening:
This issue tracks review_diff v2 only.
V2 outcome
Explain semantic risk across source changes and plugin-generation changes without pretending static evidence proves behavior.
Scope
Active-generation discipline
Every diff result declares the active plugin generation used for current-tree analysis.
Base/current plugin identity
A commit range may change requested package digests or grants. Report:
Do not claim an exact historical semantic diff when the base package artifact is unavailable.
Per-seed and edge deltas
Target comparisons use stable semantic identities, never raw ids across generations.
Optional analyzers
Compose, independently:
Each analyzer reports skipped/unavailable separately.
Validation suggestions
Suggest evidence-backed checks:
Never claim semantic correctness or runtime coverage.
Findings added for #75
Reason-code values and old/new daemon normalization are wire contracts.
Tests
Acceptance
Minimal v1 shipped in v0.6.0 (I030 Track C) as
review_diff— the narrow scope this issue's roadmap called for.changed_symbols' classification core extracted (collect_changed, zero behavior change, 19 existing tests green) and composed with onechange_impactcall: risk-ranked findings with stable reason codes (api_break_deletedwith live-breakage evidence,untested_changeas a disclosed static proxy,wide_blastwith witness chain,low_confidence_areaself-disclosure,seed_overflow), severity-sorted, capped at 50, confidence +graph_semanticsriding along. Deferred to a future round per the spec's larger vision: rename-pair inference, cycle/clone analyzers (#27/#28 not yet shipped), per-seed blast granularity. Bench: review + test-selection = 2 calls / 4.3KB on this repo (21 findings, 21-file test selection).Triage: P1 — keep open as
review_diffv2v1 shipped in v0.6.0, and the production-hardening follow-up changed two details from the existing shipment comment:
seed_overflowwas removeduntested_changeRecommended v2 scope:
Prefer evolving this tool over adding a separate
validate_changetool.feat: semantic_diff / review_diff — explain structural risk, not changed linesto feat: review_diff v2 — source plus plugin-generation semantic risk