guards: Grant-owned findings never block (compute-guard + ci-hygiene)
status_for(lane, whole_tree, grant=...): only lane-owned findings fail in MODE=block; Grant-owned (ci/grant-owned.yml) post WARN. The bridge splits via guards_report.split_grant; if the split cannot run it WARNs (never blocks). Orchestrator 09-23: block compute-guard for lane-owned paths only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -260,9 +260,19 @@ def check(repo: str, sha: str, default_branch: str, is_default_head: bool) -> li
|
||||
)
|
||||
|
||||
|
||||
def status_for(findings: list[Finding], whole_tree: bool) -> tuple[str, str, Finding | None]:
|
||||
"""(state, description, first finding) for the GitHub commit status."""
|
||||
def status_for(findings: list[Finding], whole_tree: bool,
|
||||
grant: list[Finding] = ()) -> tuple[str, str, Finding | None]:
|
||||
"""(state, description, first finding) for the GitHub commit status.
|
||||
|
||||
`findings` = lane-owned (these block in MODE=block); `grant` = findings in
|
||||
Grant-owned code (ci/grant-owned.yml): always WARN, never red (orchestrator
|
||||
09-23: his desktop work is never blocked by us)."""
|
||||
scope = "in tree" if whole_tree else "added"
|
||||
if not findings and grant:
|
||||
g, n = grant[0], len(grant)
|
||||
desc = (f"⚠ WARN (Grant-owned, not blocking): {n} direct AI-provider use{'s' if n > 1 else ''} "
|
||||
f"{scope}, e.g. {g.path}:{g.line} {g.match}")
|
||||
return "success", desc[:140], g
|
||||
if not findings:
|
||||
what = "no direct AI-provider use in tree" if whole_tree else "no direct AI-provider use added"
|
||||
return "success", f"OK: {what} (Windy Mind is the only door)", None
|
||||
|
||||
Reference in New Issue
Block a user