Conversation
…erical field authority
…nal comparison provenance
…ed physical acceptance
…hetic fixture copy
…hetic fixture copy
…f and immutable provenance
…a and narrowed exclusions
…a and narrowed exclusions
…l tracked surfaces
…tive fixtures run
|
Superseded by PR #384, rebuilt from the actual current |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: df32669679
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| Assert.Contains("externalReferenceCapture", workflow, StringComparison.Ordinal); | ||
| Assert.Contains("evidence/interoperability-reference-target.json", workflow, StringComparison.Ordinal); | ||
| Assert.Contains("evidence/interoperability-reference-target.json", documentation, StringComparison.Ordinal); | ||
| Assert.Contains("ApprovedConvergenceIdentifierPaths", sourceClean, StringComparison.Ordinal); |
There was a problem hiding this comment.
Assert the removed exemption is absent
When the standard build runs the complete ARSAS.Tests project, this assertion always fails: the same commit deliberately removes ApprovedConvergenceIdentifierPaths from verify-source-clean.ps1, and the updated SourceClean_GuardsEveryTrackedFileWithoutWholeFileExceptions test already asserts its absence. Change this stale assertion to DoesNotContain (or remove it) so the unit and negative-path validation gates can pass.
AGENTS.md reference: AGENTS.md:L215-L221
Useful? React with 👍 / 👎.
Root cause
The source-clean checker exempted complete convergence documents/workflows/tests from prohibited external-identifier scanning. Any new restricted identifier placed in one of those paths could silently bypass the gate.
Fix
-RepositoryRootand-ScanOnlyfixture mode, leaving default production validation unchanged.Based on the neutral reference contract from #381, already merged. No app/engine/runtime/release changes. All CI and post-merge source-clean gates must pass; a failed fixture cannot be bypassed via an allowlist.