feat(process): risk by changed hunks decides ship and informs show (#707)

The ship limits count lines and files but not what was touched: a
12-line pointerdown handler passed them like a typo and merged unread.
The track rule also lived twice - the guard computed the cycle limit in
bash while process-track.mjs computed the track, and the two disagreed
on multiple track labels. The packet still told authors to rebase
show/ship branches that merge cleanly.

- scripts/change-risk.mjs: one pure classifier over `git diff -U0` from
  the merge base. Class A lines only; comments, blank lines and pure
  renames give no risk; deletions do. Area and token rules per class
  (geometry, touch, migration, devices, perf, ux, visual render/ui),
  evidence as path:line, five per class.
- process-track.mjs: owner confirmation is a comment line
  "Трек: <x> — решение владельца" by the repo owner (latest wins, only
  for the current track); several track labels read as the strictest
  with a warning; cycleLimit, guardLimit and rebaseBeforeReview are the
  single source. `stage` makes the whole S7 track decision in one call:
  ship with risk and no confirmation is raised to show with evidence,
  a confirmed ship keeps merging without the model and records the risk
  for the batch review; show/ask get a risk note for the reviewer.
- _process.yml: the guard asks process-track.mjs for the limit and keeps
  no track logic; the track step calls the script once and only
  executes its raise flag and comment file; risk_note reaches the
  Review prompt, ship_risk reaches the hp:ship-merge comment (marker
  line unchanged).
- task-packet.mjs: track basis, limit and rebase policy; next step
  without the stale rebase line; risk with its consequence per track;
  required checks with reasons (ci:golden only on render risk);
  changelog and visual evidence - from the same exports.
- ship-review.mjs: the batch brief prints the risk line of a ship merge.
- Canon: PROCESS.md §5, §5.1, §10.4, §11.7, both digests, AGENTS.md.
- Registry anchors that watched the moved code are moved, not dropped.

Issue: #707
User-Visible: no
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018qZfe7YS4rqEMKoVeS3GKd
This commit is contained in:
Claude
2026-10-01 00:03:35 +00:00
committed by claude[bot]
parent a49f7095ce
commit 1d51beade1
15 changed files with 1750 additions and 161 deletions
+12
View File
@@ -145,6 +145,15 @@
- Ветка `show` с чистым слиянием к `dev` до ревью не приводится: материал —
ветка как есть, кандидат проверит Validate при слиянии
([§10.4](../../PROCESS.md#104-событийный-конвейер-метка-как-триггер)).
- Промпт несёт риск по изменённым участкам: по каждому классу назови документ
или AC, где поведение уже зафиксировано; не нашёл — Medium «решать есть что —
нужен `track:ask`» с названным критерием. `show`, подтверждённый владельцем,
не повышать — вопрос владельцу, вариант по умолчанию «повысить до `ask`»; на
`ask` — сверить, что каждый класс покрыт AC ТЗ
([§5](../../PROCESS.md#5-треки-ship-show-ask--метка-владельца)).
- Визуальный риск в пути отрисовки плана без `ci:golden`: если задача меняет
вид, нужен `ci:golden`; иначе — запись в «чего не проверял»
([§5.1](../../PROCESS.md#51-метки-тяжёлых-проверок-и-прежние-метки)).
## Пакетное ревью ship
@@ -155,6 +164,9 @@
соседнее, не вышла ли правка из ship по смыслу
([§11.7](../../PROCESS.md#117-пакетное-ревью-ship-перед-бетой),
[§5](../../PROCESS.md#5-треки-ship-show-ask--метка-владельца)).
- Строка «Риск по участкам» под задачей — рискованные участки ship,
подтверждённого владельцем: конвейер их не повышал, пакетное ревью читает их
первыми ([§11.7](../../PROCESS.md#117-пакетное-ревью-ship-перед-бетой)).
- Документ `docs/reviews/SHIP-REVIEW-<тег>.md` публикует детерминированный
шаг; High не пускает бету, Medium и Low решает владелец
([§11.7](../../PROCESS.md#117-пакетное-ревью-ship-перед-бетой)).