Skip to content

fix(source-clean): remove whole-file exclusions and test rejection end-to-end - #383

Closed
masarray wants to merge 19 commits into
mainfrom
hardening/source-clean-no-whole-file-exemptions
Closed

masarray wants to merge 19 commits into
mainfrom
hardening/source-clean-no-whole-file-exemptions

Conversation

@masarray

Copy link
Copy Markdown
Owner

Root cause

The source-clean checker exempted complete convergence documents/workflows/tests from prohibited external-identifier scanning. Any new restricted identifier placed in one of those paths could silently bypass the gate.

Fix

  • Scan every tracked text path/content without entire-file exceptions; retain the checker's self-file skip only for its embedded one-way fingerprints.
  • Add optional -RepositoryRoot and -ScanOnly fixture mode, leaving default production validation unchanged.
  • Add real temporary Git fixture tests for source, Markdown, JSON, workflow (including previously exempt workflow path), test, filename, and a neutral positive control.
  • Run those negative fixtures in the canonical Windows build after the full source check.
  • Update contract assertions to require zero whole-file exemptions.

Based on the neutral reference contract from #381, already merged. No app/engine/runtime/release changes. All CI and post-merge source-clean gates must pass; a failed fixture cannot be bypassed via an allowlist.

Copy link
Copy Markdown
Owner Author

Superseded by PR #384, rebuilt from the actual current main after #381 was squash-merged. This stacked branch's three-dot diff replayed reference-contract migration files despite the content already being on main. #384 contains exactly four source-clean/CI/test files and is the sole active review target. No code from this obsolete stack is merged.

@masarray masarray closed this Sep 24, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: df32669679

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Assert.Contains("externalReferenceCapture", workflow, StringComparison.Ordinal);
Assert.Contains("evidence/interoperability-reference-target.json", workflow, StringComparison.Ordinal);
Assert.Contains("evidence/interoperability-reference-target.json", documentation, StringComparison.Ordinal);
Assert.Contains("ApprovedConvergenceIdentifierPaths", sourceClean, StringComparison.Ordinal);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Assert the removed exemption is absent

When the standard build runs the complete ARSAS.Tests project, this assertion always fails: the same commit deliberately removes ApprovedConvergenceIdentifierPaths from verify-source-clean.ps1, and the updated SourceClean_GuardsEveryTrackedFileWithoutWholeFileExceptions test already asserts its absence. Change this stale assertion to DoesNotContain (or remove it) so the unit and negative-path validation gates can pass.

AGENTS.md reference: AGENTS.md:L215-L221

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant