Skip to content

fix(source-clean): scan every tracked file and test rejection fixtures - #384

Merged
masarray merged 10 commits into
mainfrom
hardening/source-clean-fully-scoped
Sep 25, 2026
Merged

masarray merged 10 commits into
mainfrom
hardening/source-clean-fully-scoped

Conversation

@masarray

@masarray masarray commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Rebuilt on current main after the interoperability-reference migration. Scope remains source-clean hardening only.

Changes:

  • remove whole-file external-identifier exclusions from the actual source-clean gate;
  • scan tracked paths and text content, including identifiers embedded in class/fixture/file tokens;
  • add optional temporary-repository scan mode while preserving full production checks by default;
  • add end-to-end negative Git fixture cases across source, test, Markdown, JSON, workflow and tracked filename, plus a neutral positive fixture;
  • invoke expected-failure scanner cases through System.Diagnostics.Process so Windows PowerShell stderr does not abort the test harness;
  • cache identifier fingerprint decisions and reuse the SHA-256 instance to keep full-tree validation bounded;
  • run source-clean rejection cases on every canonical Windows build.

No runtime, engine, Discovery, reporting, SCL, version or stable-release changes. Merge only after exact-head CI passes.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6229e275d8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +66 to +67
# No tracked path receives a whole-file external-identifier exemption. Historical
# comparison evidence is linked by immutable commit rather than copied into active files.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Scan the guard script before skipping its policy literals

When scripts/verify-source-clean.ps1 itself contains a prohibited plain-text identifier, the gate still accepts it because the loop reaches if ($relative -eq "scripts/verify-source-clean.ps1") { continue } before reading its content. This contradicts the newly stated no-whole-file-exemption invariant, and the fixture suite does not expose it because the scanner executable lives outside each temporary repository. Move the self-skip after the external-identifier check (skipping only the embedded policy-pattern checks) and add a fixture using this reserved path.

AGENTS.md reference: AGENTS.md:L172-L176

Useful? React with 👍 / 👎.

@masarray
masarray merged commit 5445637 into main Sep 25, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant