rdd-advisory-transport
GitHub定义 Go 语言 RDD 审查传输协议,规范运行时与适配器交互。限制适配器职责,确保提示词、证据和结果模式统一由 Go 合约管理,保障审查流程的完整性与安全性。
Trigger Scenarios
Install
npx skills add Gentleman-Programming/gentle-ai --skill rdd-advisory-transport -g -y
SKILL.md
Frontmatter
{
"name": "rdd-advisory-transport",
"license": "Apache-2.0",
"metadata": {
"author": "gentleman-programming",
"version": "1.0"
},
"description": "Trigger: reviewer transport, advisory transport, review adapter, lens prompt\/schema, OpenCode reviewer plugin, Codex reviewer, ReviewProviderContract. Enforce the shared Go advisory reviewer transport contract."
}
Activation Contract
Load when changing how any runtime (Claude Code, OpenCode, Codex, future) invokes an RDD reviewer, refuter, or fix validator, or when touching reviewer prompts, lens evidence, result schemas, adapters, or transport capability policy.
Hard Rules
- One Go provider contract owns binding, frozen evidence, lens mandate, prompt, result schema, byte budget, JSON extraction, and admission. Start from existing native sources (
reviewLensContextBlock,ReviewerResultSchema,RunReviewCaptureResult,CaptureAdmittedReviewerResult); never build a parallel system. - Adapters only invoke the reviewer and return raw bytes plus a transport error. An adapter must never parse bindings, rebuild prompts, copy schemas, apply local budgets, parse JSON, capture or preserve results, hold retry state, or decide blocking.
- Runtime output is advisory: it cannot create authority, mutate review state, mint a receipt, or open a gate. Only Go admission does.
- Byte budget refuses before invocation; never truncate. Malformed, truncated, or incomplete input never becomes PASS, complete, or a clean receipt.
- No OpenCode restart, child isolation, special session, or
OPENCODE_DISABLE_*variables. An ordinary running session is sufficient. - The RDD semantic pipeline is untouchable: lens selection, severity meanings, candidate causality, refuter adjudication, bounded correction, verification, terminal receipt, delivery gates.
- Refuter and fix validator consume the same provider contract. A validator that could not inspect produced no verdict — surface a blocked decision; never record it as failed (that irreversibly consumes the single correction).
- Capability advertisement requires shared-contract conformance plus organic runtime proof. Codex stays unadvertised until both positive and fail-closed proofs pass.
- Transport failures never consume a correction budget, duplicate a capture, or strand a lineage.
- Historical receipts stay readable; never rewrite
provider_commandorruntime_interceptiondescriptors.
Decision Gates
| Condition | Action |
|---|---|
| Logic fits "prompt/evidence/schema/validation" | It belongs in the Go contract, never an adapter. |
| Adapter cannot expose raw final output | Runtime stays typed unavailable; no artifact-parser workaround. |
| Cutover slice exceeds 1000 lines/PR | Chained PRs on the tracker; advertisement flip lands last. |
| Shared prompt changes any semantic outcome | STOP; regression against baseline blocks the slice. |
Slice touches negotiated START / repository_context |
Coordinate with the deferred Wave 7 switch-removal finding first. |
Execution Steps
- Freeze the boundary: contract-level tests around current native prompt/evidence/schema/admission.
- Extract the Go provider contract; differential-test against current admission.
- Add adapter-minimality static guards (no binding types, prompt text, schema copies, budgets, parsers, capture, retry in adapters) — from the first adapter slice, not last.
- Cut Claude + OpenCode over without an advertised intermediate path; delete the OpenCode plugin and isolation machinery in the same release slice.
- Prove Codex organically before advertising; retire historical transport code last.
- Gate every slice on the bench journey corpus diff: all journeys unchanged.
Output Contract
Report per slice: contract surface touched, adapter minimality guard status, bench corpus diff result, semantic regression result, capability advertisement state, and any unresolved maintainer decision (e.g. receipt provider_contract descriptor).
References
references/shared-advisory-transport-proposal.md— full proposal: architecture, deletion candidates, test plan, risks.references/issue-impact-matrix.md— per-issue dispositions under the shared contract; a maintainer condition in an issue's own thread always outranks its row.
Version History
- 35deba3 Current 2026-08-20 00:49


