guards: Grant-owned findings never block (compute-guard + ci-hygiene)

status_for(lane, whole_tree, grant=...): only lane-owned findings fail in
MODE=block; Grant-owned (ci/grant-owned.yml) post WARN. The bridge splits via
guards_report.split_grant; if the split cannot run it WARNs (never blocks).
Orchestrator 09-23: block compute-guard for lane-owned paths only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Kit OC5
2026-09-23 20:04:01 -04:00
parent 790d794900
commit 17acae6af6
7 changed files with 93 additions and 10 deletions

View File

@@ -65,3 +65,13 @@ def test_render_splits_lane_and_grant_counts():
def test_windy_pro_root_env_example_is_grant_owned_but_not_the_account_servers():
assert gr.grant_owned("windy-pro", ".env.example", None, OWNED)
assert not gr.grant_owned("windy-pro", "account-server/.env.example", None, OWNED)
def test_split_grant_sends_desktop_code_to_grant(monkeypatch):
F = gr.cg.Finding
fs = [F("src/client/desktop/main.js", 3, "provider host", "x"),
F("account-server/src/llm.ts", 5, "provider host", "y")]
lane, grant = gr.split_grant("windy-pro", "a" * 40, fs)
assert [f.path for f in grant] == ["src/client/desktop/main.js"]
assert [f.path for f in lane] == ["account-server/src/llm.ts"]
assert gr.split_grant("windy-chat", "a" * 40, fs) == (fs, [])