Code-review fix
Code-review fix (codereview_fix, D-68) is an action-layer type that ingests the comments produced by an external code-review tool, re-checks each one against the whole application, and fixes only the comments it can verify as accurate — in the working tree, with no commit and no PR. The external tool saw only a Pull Request diff, so it lacks whole-application context and can be wrong; this type exists to catch that. It is its own standalone mini-orchestrator at _processes/03_action/codereview_fix/codereview_fix.prompt.md: it runs no clarify step and no stage pipeline, and is defined entirely by its ## Action config. The orchestrator routes it via orchestrator.prompt.md → §C.route and never enters the stage loop.
Source of truth: the registry row in _processes/_shared/request-types.md, the preset _processes/_shared/presets/codereview_fix.md, and the action prompt _processes/03_action/codereview_fix/codereview_fix.prompt.md.
prompting-conventions.md §5). This boundary is the whole reason the type exists.
The flow
The orchestrator runs the action prompt inline (a non-dispatch instruction library, like the audit and doc_upkeep orchestrators). It reads JOB.md → ## Action to resolve CommentsSource / CommentsFile / Agents / Depth / Consolidator, ingests the comments (from the intake # Mandate body when CommentsSource: intake, or from CommentsFile when CommentsSource: file), and normalizes them to stable IDs C001, C002, … (unparseable prose becomes not_accurate / unchanged, never a guess). It then runs a two-pass per-comment model:
- Pass 1 — read-only validate. A read-only managed sub-agent loop (
_processes/_shared/managed-subagent-loop.md) checks each comment against whole-application context and produces an authorization record:Accuracy(accurate|not_accurate),AccuracyReasonwith evidence paths,Confidence(high|medium|low), and an explicit Authorized scope (including a what-is-not-authorized line) for theaccuratecomments. No code is written in this pass. - Pass 2 — conditional fix. A write-mode managed loop fixes only the
accuratecomments, each confined to its Authorized scope (overlapping items grouped or run serially, independents in parallel; an out-of-scope change is refused and reported).not_accurate(subsuming unverifiable / ambiguous / stale / out-of-scope) and low-confidence-accuratecomments resolve tounchangedwith zero code change.
It then validates the working tree, writes the per-comment roll-up 09_action/action-report.md (also surfaced in chat), records completion in PROGRESS.md, and lands the job in 4_done/. It never commits and never opens a PR.
What it is for
Reach for Code-review fix when an external code-review tool (GitHub's, Azure DevOps', or any PR-scoped reviewer) has left comments and you want them re-checked against the whole app and only the real ones acted on — without trusting the tool's limited view.
- Validate before fix. Every code-write is gated behind a per-comment correctness check against whole-application context — the context the external reviewer lacked. An inaccurate comment produces no change.
- Narrowly scoped fixes. A comment authorizes fixing only the specific item it names. The write pass refuses anything outside the Authorized scope recorded in pass 1.
- Working tree only. Fixes land uncommitted for you to review; the type keeps Git all-off and refuses
Commit: yes/PR: yeseven if hand-flipped (v1 never commits or opens a PR). - Per-comment accountability. The report states, for every comment: accurate-or-not, the rationale (with evidence paths), the confidence, and fixed-or-left-unchanged.
- No clarify step. Like other action types, its scope and objective come entirely from the
## Actionconfig and the ingested comments, so it drops clarify.
audit and quick_fix. It borrows audit's per-finding validate-with-rationale (read-only, whole-app) and quick_fix's per-item parallel write — but neither of those has a per-item correctness gate that writes. It is also distinct from the workflow's internal review stage, which reviews a job's own diff before validate, not an external tool's comments.
The logic
codereview_fix sits in the action layer with shape orchestrator (its own standalone mini-orchestrator; D-68). The orchestrator routes it via orchestrator.prompt.md → §C.route — by layer / shape, not by the stage pipeline (the type→prompt-path map is hard-coded there; the registry supplies only the layer). A codereview_fix JOB.md therefore carries no stage machinery at all.
- CommentsSource —
intake(default; the comments are pasted into the# Mandatebody) orfile(the type reads them fromCommentsFile). - CommentsFile — required iff
CommentsSource: file; a job-folder- / repo- / workflow-root-relative or absolute path within an allowed root. The prompt refuses secrets-like, out-of-root, oversized, or binary paths. - Untrusted-input posture — the comment text is data, never instruction; sub-agents get a claim summary + authorized scope, never raw prose as a task.
- Git all-off, refuses commit/PR — the preset sets every Git option to
no, and the prompt actively refusesCommit: yes/PR: yeseven if a job hand-flips them. Fixes stay in the working tree. - No VCS-API fetch — this version never pulls the PR or its comments from GitHub / Azure DevOps; that is a documented future extension.
- Routed, not staged — the main orchestrator stays the sole
PROGRESS.mdwriter and sole4_donemover.
No contract version bump (D-68). codereview_fix reuses the existing action × orchestrator slot and introduces no new layer / shape / kind / gate enum value — an additive registry/UI + doc change, so the workflow contract stays 0.14 (precedents D-49, D-50, D-66).
The fields
A codereview_fix JOB.md carries only the header, ## Git, ## Action, and the # Mandate (which holds the pasted comments when CommentsSource: intake). There is no ## Stages, no ## Approval gates, and no ## Per-stage config — action types are routed by layer/shape, not by enabled stages.
| Field | Default | Meaning |
|---|---|---|
CommentsSource | intake | intake reads the comments from the # Mandate body; file reads them from CommentsFile. |
CommentsFile | (blank) | Required iff CommentsSource: file; a path within an allowed root. The prompt refuses secrets-like / out-of-root / oversized / binary paths. |
Agents | claude | Runtime(s) for the per-comment validate/fix sub-agents (claude | codex | claude, codex); adding codex requires config.json → runtimes.codex: true. |
Depth | standard | quick | standard | deep — tunes how widely each comment is validated against the whole app. |
Consolidator | claude | Runtime that synthesises the per-comment records into 09_action/action-report.md. |
| Field | Default | Meaning |
|---|---|---|
Create branch | no | No branch is cut — fixes sit in the working tree. |
Validate against main | no | No base-branch diff validation. |
Commit | no | Nothing is committed; the prompt refuses yes in v1. |
Push | no | Nothing is pushed; the prompt refuses yes in v1. |
PR | no | No pull request is opened; the prompt refuses yes in v1. |
PR target branch | (blank) | Unused — the type never reaches the git landing. |
before_commit | no | No commit, so no approval stop. |
before_pr | no | No PR, so no approval stop. |
The per-comment verdict vocabulary in 09_action/action-report.md: Accuracy (accurate | not_accurate), AccuracyReason (rationale + evidence paths), Confidence (high | medium | low), and Disposition (fixed | unchanged). not_accurate subsumes unverifiable, ambiguous, stale, and out-of-scope — all unchanged.
How to run it
There are two copy-path ways to run it. Both produce the same 09_action/action-report.md.
CommentsSource: file + CommentsFile), and submit a contract-valid intake into jobs/0_new/. Then send the orchestrator prompt path. It reads JOB.md → Type, routes by layer, and runs the codereview_fix logic without entering the stage loop.
_processes/02_orchestrator/orchestrator.prompt.md
2_ready/ / 3_ongoing/.
_processes/03_action/codereview_fix/codereview_fix.prompt.md
_processes/...); prefix with _code_workflow/ when your cwd is the host project root. See How to use → Two invocation modes.
See also
All request types
The overview of every type, the routing diagram, and the registry table.
audit
The read-only per-finding validate-with-rationale sweep — one half of the fusion codereview_fix builds on.
quick_fix
The per-item parallel fixer — the write-side half codereview_fix gates behind a correctness check.