Skip to content

[spdd] Daily spec work plan - 2026-07-06 #43838

Description

@github-actions

Summary

SPDD batch for rotation indices 25–26 + 0–2 (wrapped). Covers specs/security-architecture-spec.md (+ validation + summary), ai-credits-specification.md, bash-command-parser-specification.md, copilot-sdk-driver-specification.md.

Key findings:

  1. specs/test-vectors/bash-command-parser/ — required by §9 of bash-command-parser spec — does not exist.
  2. specs/security-architecture-spec-summary.md has 4 ⏳ Pending maintenance tasks needing resolution in the main spec.
  3. ai-credits-specification.md §5.4 lacks a normative CI gate for models.json mirror consistency.
  4. copilot-sdk-driver-specification.md is missing a Sync Notes section and has a SHOULD/MUST inconsistency in §4.5.

Priority Work Queue

P0 — Missing required artifact

  • specs/test-vectors/bash-command-parser/ directory and seed JSON files are absent (spec §9).

P1 — Open spec maintenance (tracked in summary)

  • 4 ⏳ Pending tasks: pre_activation role-validation linkage, Appendix D detection job example, conclusion job documentation, trusted-users audit.

P2 — Weak Safeguards / missing Sync Notes

  • AI Credits spec §5.4: no normative CI gate requirement.
  • SDK driver spec: no Sync Notes section, SHOULD/MUST split in §4.5.

SPDD Checklist

Bash-Command-Parser Spec

  • [Generate] Create specs/test-vectors/bash-command-parser/v1.1.0-model-based.json and v1.1.0-verification.json with the ≥15 required test vectors from §6.1. Done when: both files exist and cover all S-CORE/E-CORE/P-CORE/R-CORE categories.
  • [Sync] Add ### Sync Notes section to docs/src/content/docs/specs/bash-command-parser-specification.md naming the canonical vector path and revalidation trigger (spec version bump or parser behavioral change). Done when: section present with revalidation trigger.

Security Architecture Spec

  • [Generate] Add normative note to specs/security-architecture-spec.md §7.6 linking pre_activation job to role-validation requirement. Done when: pre_activation-to-role-validation linkage is explicit.
  • [Generate] Add Appendix D example in specs/security-architecture-spec.md naming the detection job as the runtime threat-detection layer. Done when: example present.
  • [Generate] Document optional conclusion job (non-normative) in specs/security-architecture-spec.md. Done when: job documented with non-normative marker.
  • [Generate] Audit trusted-users enforcement in specs/security-architecture-spec.md §§8–9; add a note or forward reference to the companion MCP access-control spec. Done when: §9 or footnote references trusted-users scope.

AI Credits Spec

  • [Safeguards] Add a MUST-level CI gate requirement to docs/src/content/docs/specs/ai-credits-specification.md §5.4 specifying that a CI check MUST fail when pkg/cli/data/models.json and actions/setup/js/models.json diverge. Done when: MUST-level requirement stated.
  • [Sync] Add ### Sync Notes section to docs/src/content/docs/specs/ai-credits-specification.md with at least one revalidation trigger (new model, pricing change, or spec minor bump). Done when: section present.

Copilot SDK Driver Spec

  • [Structure] Add ### Sync Notes section to docs/src/content/docs/specs/copilot-sdk-driver-specification.md referencing at least one harness implementation file and when revalidation is required. Done when: section present.
  • [Norms] Resolve SHOULD/MUST split in docs/src/content/docs/specs/copilot-sdk-driver-specification.md §4.5: either strengthen counting to MUST or add a rationale note. Done when: inconsistency resolved with commentary.

Per-Spec Findings

specs/security-architecture-spec.md (v1.0.0)

REASONS canvas gaps:

REASONS Gap
Entities conclusion job undocumented
Structure Appendix D missing detection job example
Operations pre_activation↔role-validation linkage implicit
Safeguards No revalidation trigger for companion MCP spec changes

Pending tasks from summary:

  1. pre_activation role-validation linkage in §7.6
  2. Appendix D detection job named example
  3. conclusion job non-normative documentation
  4. trusted-users runtime enforcement audit (§§8–9 or companion spec ref)
docs/src/content/docs/specs/ai-credits-specification.md (v1.4.0)

REASONS canvas gaps:

REASONS Gap
Safeguards §5.4 lacks normative CI gate for models.json mirror check
Sync Notes Missing — no revalidation trigger documented

Ambiguous: §9.8 bypass condition interaction with GH_AW_HAS_SLASH_COMMAND / GH_AW_HAS_LABEL_COMMAND compiler-set variables is not traced to a compiler output test.

docs/src/content/docs/specs/bash-command-parser-specification.md (v1.1.0)

REASONS canvas gaps:

REASONS Gap
Structure Canonical vector path specs/test-vectors/bash-command-parser/ absent in repo
Norms "space" in §5 Driver Integration Semantics (exact-match fallback) undefined (ASCII vs Unicode)
Safeguards No CI gate for vector file presence
Sync Notes Missing
docs/src/content/docs/specs/copilot-sdk-driver-specification.md (v1.0.2)

REASONS canvas gaps:

REASONS Gap
Norms §4.5: SHOULD for counting denials, MUST for stopping — allows non-counting conforming impl
Operations §5.2 points 2+3 both approve-all; normative distinction unclear
Sync Notes Missing

Sync Follow-ups

  1. After completing the 4 security spec pending tasks, mark them ✅ in specs/security-architecture-spec-summary.md.
  2. After seeding test vectors, update the change log in the bash-command-parser spec.
  3. After spec updates, trigger a security-spec revalidation pass and update specs/security-architecture-spec-validation.md.
  4. After adding the AI Credits CI gate requirement, create/update the Make target and reference it from §5.4.

Context

Item Value
Files reviewed specs/security-architecture-spec-validation.md, specs/security-architecture-spec.md, docs/src/content/docs/specs/ai-credits-specification.md, docs/src/content/docs/specs/bash-command-parser-specification.md, docs/src/content/docs/specs/copilot-sdk-driver-specification.md
Rotation index 24 → 2 (wrapped, 27 total files)
Run §28808118583

References:

Generated by 📋 Daily SPDD Spec Planner · 77.1 AIC · ⌖ 6.92 AIC · ⊞ 4.9K ·

  • expires on Jul 9, 2026, 9:00 AM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions