guards: Grant-owned findings never block (compute-guard + ci-hygiene)

status_for(lane, whole_tree, grant=...): only lane-owned findings fail in
MODE=block; Grant-owned (ci/grant-owned.yml) post WARN. The bridge splits via
guards_report.split_grant; if the split cannot run it WARNs (never blocks).
Orchestrator 09-23: block compute-guard for lane-owned paths only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Kit OC5
2026-09-23 20:04:01 -04:00
parent 790d794900
commit 17acae6af6
7 changed files with 93 additions and 10 deletions

View File

@@ -215,8 +215,13 @@ def _check(repo: str, sha: str, default_branch: str, is_default_head: bool):
lambda: cg.scan_added(repo, bare, f"refs/heads/{default_branch}", sha, allow, **kw))
def status_for(findings, whole_tree: bool):
def status_for(findings, whole_tree: bool, grant=()):
"""Same contract as compute_guard.status_for: `grant` findings never block."""
scope = "in CI/Dockerfiles" if whole_tree else "added"
if not findings and grant:
g, n = grant[0], len(grant)
desc = f"⚠ WARN (Grant-owned, not blocking): {n} CI hygiene issue{'s' if n > 1 else ''} {scope}, e.g. {g.path}:{g.line} {g.match}"
return "success", desc[:140], g
if not findings:
return "success", f"OK: no floating install or host-port service {scope}", None
f = findings[0]

View File

@@ -260,9 +260,19 @@ def check(repo: str, sha: str, default_branch: str, is_default_head: bool) -> li
)
def status_for(findings: list[Finding], whole_tree: bool) -> tuple[str, str, Finding | None]:
"""(state, description, first finding) for the GitHub commit status."""
def status_for(findings: list[Finding], whole_tree: bool,
grant: list[Finding] = ()) -> tuple[str, str, Finding | None]:
"""(state, description, first finding) for the GitHub commit status.
`findings` = lane-owned (these block in MODE=block); `grant` = findings in
Grant-owned code (ci/grant-owned.yml): always WARN, never red (orchestrator
09-23: his desktop work is never blocked by us)."""
scope = "in tree" if whole_tree else "added"
if not findings and grant:
g, n = grant[0], len(grant)
desc = (f"⚠ WARN (Grant-owned, not blocking): {n} direct AI-provider use{'s' if n > 1 else ''} "
f"{scope}, e.g. {g.path}:{g.line} {g.match}")
return "success", desc[:140], g
if not findings:
what = "no direct AI-provider use in tree" if whole_tree else "no direct AI-provider use added"
return "success", f"OK: {what} (Windy Mind is the only door)", None

View File

@@ -75,6 +75,25 @@ def grant_owned(repo: str, path: str, job: str | None, owned: list[dict]) -> boo
return False
def split_grant(repo: str, sha: str, findings: list) -> tuple[list, list]:
"""(lane-owned, Grant-owned) findings at `sha`, by ci/grant-owned.yml, with
workflow lines attributed to their job exactly as the status page does."""
owned = (yaml.safe_load(OWNED.read_text()) or {}).get("grant_owned") or []
if not any(e["repo"] == repo for e in owned):
return list(findings), []
bare = cg.WORK / f"{repo}.git"
texts: dict[str, str] = {}
lane, grant = [], []
for f in findings:
job = None
if "/workflows/" in f.path:
if f.path not in texts:
texts[f.path] = cg._git(bare, "show", f"{sha}:{f.path}")
job = job_of(texts[f.path], f.line)
(grant if grant_owned(repo, f.path, job, owned) else lane).append(f)
return lane, grant
def scan(repo: str, owned: list[dict]):
bare = cg.WORK / f"{repo}.git"
if not bare.is_dir():

View File

@@ -395,7 +395,14 @@ def _post_guard(modname: str, ctx: str, repo: str, sha: str, default_branch: str
return
if findings is None:
return
state, desc, first = g.status_for(findings, whole_tree=is_default_head)
try: # Grant-owned code never blocks (orchestrator 09-23); lazy like the guards
import importlib
lane, grant = importlib.import_module("guards_report").split_grant(repo, sha, findings)
except Exception as e: # noqa: BLE001 — can't tell whose code: warn, never block
print(f" {repo}@{sha[:7]} {ctx}: Grant-owned split failed ({type(e).__name__}); WARN only")
lane, grant = [], list(findings)
state, desc, first = g.status_for(lane, whole_tree=is_default_head, grant=grant)
st, existing = github("GET", f"/repos/{GH_OWNER}/{repo}/commits/{sha}/statuses?per_page=100")
for s in existing or []: # newest first: compare the latest guard status only
if s["context"] == ctx: