name: review-fix-backend
description: Backend-focused review + fix loop (structure, modularization, hexagonal architecture, security, coding)
all_steps:
  rules:
    - ref: findings-handling
      position: before_instruction
    - ref: plain-terminology
      position: before_instruction

max_steps: 30
facet_pools:
  security-review-facets:
    uses: security-review-facets
initial_step: gather
loop_monitors:
  - cycle:
      - reviewers
      - final-gate
      - remediation
    threshold: 3
    judge:
      persona: supervisor
      instruction: loop-monitor-reviewers-fix
      rules:
        - condition: Healthy (fixes progressing and report content converging)
          next: reviewers
        - condition: Implementation incomplete or report not converged, but the next review or fix can be performed
          next: reviewers
        - condition: The current loop cannot converge and requires a final-gate decision
          next: final-gate

steps:
  - name: gather
    uses: review-gather-to-reviewers
    rules:
      - condition: Review target information gathered
        next: reviewers
      - condition: Unable to identify review target, insufficient information
        next: ABORT

  - name: reviewers
    tags:
      - review
    parallel:
      fixed:
        - name: arch-review
          capabilities: readonly
          tags:
            - review
          edit: false
          persona: architecture-reviewer
          policy:
            - contract-change
            - review
            - architecture
            - backend
          knowledge:
            - architecture
            - backend
          instruction: review-arch
          output_contracts:
            report:
              - name: architect-review.md
                format: architecture-review
          rules:
            - condition: approved
            - condition: needs_fix

        - name: coding-review
          capabilities: readonly
          tags:
            - review
          edit: false
          persona: coding-reviewer
          policy:
            - contract-change
            - review
            - coding
          instruction: review-coding
          output_contracts:
            report:
              - name: coding-review.md
                format: coding-review
          rules:
            - condition: approved
            - condition: needs_fix

      pool:
        - name: security-review
          description: Do not select by default. Select only when (a) the change may affect secret or credential handling, external-input handling, process execution, filesystem operations, network or terminal boundaries, sandboxing, or permissions, or (b) the change is large enough that security impact cannot be confidently ruled out. Do not select for documentation-only, comment-only, or test-only changes, or small localized fixes.
          capabilities: readonly
          tags:
            - review
          edit: false
          persona: security-reviewer
          policy:
            - contract-change
            - security-review
          knowledge:
            - security
            - security-data
            - security-dependencies
          dynamic_facets:
            pool: security-review-facets
            selector:
              instruction: select-applicable-candidates
          instruction: review-security
          output_contracts:
            report:
              - name: security-review.md
                format: security-review
          rules:
            - condition: approved
            - condition: needs_fix
      selection:
        selector:
          instruction: select-applicable-candidates

    rules:
      - condition: any("error")
        next: reviewers
      - condition: all("approved")
        next: final-gate
      - condition: any("needs_fix")
        next: remediation

  - name: final-gate
    kind: workflow_call
    call: final-gate
    args:
      supervise_knowledge:
        - backend
        - security
        - architecture
      supervise_policy:
        - contract-change
        - backend
        - architecture
    rules:
      - condition: COMPLETE
        next: COMPLETE
      - condition: needs_fix
        next: remediation
      - condition: need_replan
        next: ABORT
      - condition: ABORT
        next: ABORT
  - name: remediation
    uses: review-remediation
    with:
      plan_policy:
        - coding
        - testing
        - review
      fix_policy:
        - coding
        - testing
        - architecture
        - backend
      verification_policy:
        - coding
        - testing
        - review
      fix_knowledge:
        - backend
        - security
        - architecture
    rules:
      - condition: COMPLETE
        next: reviewers
      - condition: need_replan
        next: final-gate
      - condition: ABORT
        next: ABORT
