guards: Grant-owned findings never block (compute-guard + ci-hygiene)
status_for(lane, whole_tree, grant=...): only lane-owned findings fail in MODE=block; Grant-owned (ci/grant-owned.yml) post WARN. The bridge splits via guards_report.split_grant; if the split cannot run it WARNs (never blocks). Orchestrator 09-23: block compute-guard for lane-owned paths only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -220,3 +220,12 @@ def test_scoped_allow_in_a_real_diff():
|
||||
"""
|
||||
fs = cg.parse_added("windy-pro", diff, ALLOW)
|
||||
assert [(f.line, f.match) for f in fs] == [(3, "openrouter.ai")]
|
||||
|
||||
|
||||
def test_block_mode_never_blocks_grant_owned(monkeypatch):
|
||||
monkeypatch.setattr(cg, "MODE", "block")
|
||||
g = cg.Finding("src/client/desktop/x.js", 9, "provider host", "api.openai.com")
|
||||
state, desc, f = cg.status_for([], whole_tree=True, grant=[g])
|
||||
assert state == "success" and desc.startswith("⚠ WARN (Grant-owned, not blocking): 1") and f is g
|
||||
lane = cg.Finding("a.py", 3, "provider host", "x")
|
||||
assert cg.status_for([lane], whole_tree=True, grant=[g])[0] == "failure"
|
||||
|
||||
Reference in New Issue
Block a user