guards: Grant-owned findings never block (compute-guard + ci-hygiene)

status_for(lane, whole_tree, grant=...): only lane-owned findings fail in
MODE=block; Grant-owned (ci/grant-owned.yml) post WARN. The bridge splits via
guards_report.split_grant; if the split cannot run it WARNs (never blocks).
Orchestrator 09-23: block compute-guard for lane-owned paths only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Kit OC5
2026-09-23 20:04:01 -04:00
parent 790d794900
commit 17acae6af6
7 changed files with 93 additions and 10 deletions

View File

@@ -215,8 +215,13 @@ def _check(repo: str, sha: str, default_branch: str, is_default_head: bool):
lambda: cg.scan_added(repo, bare, f"refs/heads/{default_branch}", sha, allow, **kw))
def status_for(findings, whole_tree: bool):
def status_for(findings, whole_tree: bool, grant=()):
"""Same contract as compute_guard.status_for: `grant` findings never block."""
scope = "in CI/Dockerfiles" if whole_tree else "added"
if not findings and grant:
g, n = grant[0], len(grant)
desc = f"⚠ WARN (Grant-owned, not blocking): {n} CI hygiene issue{'s' if n > 1 else ''} {scope}, e.g. {g.path}:{g.line} {g.match}"
return "success", desc[:140], g
if not findings:
return "success", f"OK: no floating install or host-port service {scope}", None
f = findings[0]