Skip to main content

Independent Review Remediation

Use when remediating an independently reviewed candidate. Repair an independently reviewed candidate without mistaking helper tests or an agent summary for closure.

Procedure​

  1. Bind the review and candidate

    • Read the complete review report and the candidate’s manifest/evidence packet.
    • Enumerate every finding into an acceptance matrix: severity, public boundary, failure mechanism, required negative probe, files, focused test, and final gate.
    • If structural code discovery is graph-backed, index the exact working directory first and check coverage for every relied-on file. Read any missed ranges directly.
    • Establish a baseline with the candidate’s documented full suite and opt-in drills. Record pre-existing failures separately; do not silently fold them into remediation.
  2. Repair one mechanism at a time

    • Add a regression that reproduces the finding at the exact public authority boundary named by the reviewer. Run it RED for the expected reason before production edits.
    • Make the smallest end-to-end correction, run the focused test GREEN, then continue to the next finding.
    • Re-read the original finding after GREEN. A nearby helper test is insufficient when the public CLI/API, durable store, process telemetry, OS sandbox, service entrypoint, or restart path can still bypass it.
    • When the defect is two components disagreeing about a shared decision, "smallest" means factoring ONE authority that both derive from, not aligning the two named predicates: the same defect class hides in the sibling judgments the two components still make independently. After unifying, sweep the sibling decisions differentially before committing. Regression fixtures must use the tracked input's exact spelling/quoting, not a simplified shape, or the fix is unproven against the real tree.
    • When remediation pivots architecture, remove or isolate the superseded executable authority before adding the replacement. A disabled flag, parser fence, early exception followed by dead code, or new engine beside an old callable runner is not consolidation because source and internal callers can still reactivate the bypass.
    • Keep the default test-discovery command green after intentional retirement. Update or remove obsolete tests under the approved scope and preserve their historical evidence separately; never call a red default suite acceptable merely because a smaller frozen suite passes.
  3. Preserve authority across durable execution

    • Persist binding and attempt identity before launch; bind telemetry to exact PID, start time, boot ID, CWD, unit, attempt, route contract, registry contract, and policy revision.
    • For controller-issued review receipts, derive session, workspace, report bytes, and evidence identity from controller-custodied completed execution. Capture output through the controller-owned unit/session and expose only stored receipt IDs to public decisions. Never seal caller-authored verdict text or evidence references merely because a process is active.
    • When stable roles share provider/model argv, treat model classification as legacy discovery only. Attribute execution through the immutable binding and the controller’s pre-registered process identity.
    • A continuation handoff is consumed only when the replacement worker reads and acknowledges the exact canonical record. Do not let the coordinator mark it consumed merely because launch returned or a unit is loaded; gate route verification on worker-recorded consumption.
  4. Exercise interruption and conflict boundaries

    • Inject crashes before and after each durable transition and external effect.
    • Persist the exact blocked action and predecessor state; retry that same idempotent action after readback.
    • Make competing compare-and-swap outcomes terminal with observed/expected evidence so stale intents cannot block later fenced work.
    • Serialize launch, adopt, role-policy mutation, and rebind preparation under one documented lock order.
  5. Run an independent adversarial re-audit

    • After focused and full tests pass, launch a fresh read-only audit against the original findings.
    • Reproduce every reported residual blocker before editing. Repair it, rerun focused tests, then rerun the audit.
    • Do not claim “all findings remediated” while the re-audit is pending or reports actionable gaps.
  6. Freeze and seal the final candidate

    • Rerun the full suite, compilation/type/lint gates, configuration parsing, service validation, and every opt-in acceptance drill after the last code change.
    • Verify disposable services/processes are absent after drills.
    • Generate the file-hash map and aggregate manifest digest only after the tree is frozen. Programmatically require exact file count, no missing/extra files, no hash mismatches, and equal recomputed digest.
    • If multiple workers share the directory, detect late mutations and rerun final gates after the last observed write. Never publish a seal assembled from mixed generations.
    • Keep deployment authorization separate from implementation verification.

Completion report​

Report only:

  • changed artifacts and candidate root;
  • each finding’s disposition in one line;
  • exact verification commands and observed counts;
  • final manifest digest and file count;
  • remaining external gates or explicit blockers.

Pitfalls​

  • Do not inherit a reviewer's scope label. A finding tagged "pre-existing at base / out of scope" is a claim, not evidence: check the base commit for the finding's mechanism before classifying it. A finding whose mechanism does not exist at the base was introduced by this branch and sits under its file ceiling — treat it as in-scope and fix it in the same remediation chain rather than deferring it.
  • Do not trust coding-agent completion summaries. Inspect source and rerun every claimed gate because agents can stop on quota or leave partially integrated alternatives.
  • Do not keep two competing production implementations. Consolidate the authoritative store/runner path; an unused alternate can preserve the original bypass and mislead reviewers.
  • Do not update evidence before the last edit. Self-excluded evidence files avoid recursion, but every other byte must be hashed from the final generation.
  • Do not normalize malformed identifiers or historical records while repairing new writes. Keep explicit legacy reads and make only new writes use stable vocabulary.

Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/engineering/independent-review-remediation/ · view source · Imported 2026-10-03. Supporting files (references, scripts) remain in the source repository.

Published by Muse · 2026-10-03.