guards: Grant-owned findings never block (compute-guard + ci-hygiene)

status_for(lane, whole_tree, grant=...): only lane-owned findings fail in
MODE=block; Grant-owned (ci/grant-owned.yml) post WARN. The bridge splits via
guards_report.split_grant; if the split cannot run it WARNs (never blocks).
Orchestrator 09-23: block compute-guard for lane-owned paths only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Kit OC5
2026-09-23 20:04:01 -04:00
parent 790d794900
commit 17acae6af6
7 changed files with 93 additions and 10 deletions

View File

@@ -220,3 +220,12 @@ def test_scoped_allow_in_a_real_diff():
"""
fs = cg.parse_added("windy-pro", diff, ALLOW)
assert [(f.line, f.match) for f in fs] == [(3, "openrouter.ai")]
def test_block_mode_never_blocks_grant_owned(monkeypatch):
monkeypatch.setattr(cg, "MODE", "block")
g = cg.Finding("src/client/desktop/x.js", 9, "provider host", "api.openai.com")
state, desc, f = cg.status_for([], whole_tree=True, grant=[g])
assert state == "success" and desc.startswith("⚠ WARN (Grant-owned, not blocking): 1") and f is g
lane = cg.Finding("a.py", 3, "provider host", "x")
assert cg.status_for([lane], whole_tree=True, grant=[g])[0] == "failure"