guards: Grant-owned findings never block (compute-guard + ci-hygiene)
status_for(lane, whole_tree, grant=...): only lane-owned findings fail in MODE=block; Grant-owned (ci/grant-owned.yml) post WARN. The bridge splits via guards_report.split_grant; if the split cannot run it WARNs (never blocks). Orchestrator 09-23: block compute-guard for lane-owned paths only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -395,7 +395,14 @@ def _post_guard(modname: str, ctx: str, repo: str, sha: str, default_branch: str
|
||||
return
|
||||
if findings is None:
|
||||
return
|
||||
state, desc, first = g.status_for(findings, whole_tree=is_default_head)
|
||||
try: # Grant-owned code never blocks (orchestrator 09-23); lazy like the guards
|
||||
import importlib
|
||||
|
||||
lane, grant = importlib.import_module("guards_report").split_grant(repo, sha, findings)
|
||||
except Exception as e: # noqa: BLE001 — can't tell whose code: warn, never block
|
||||
print(f" {repo}@{sha[:7]} {ctx}: Grant-owned split failed ({type(e).__name__}); WARN only")
|
||||
lane, grant = [], list(findings)
|
||||
state, desc, first = g.status_for(lane, whole_tree=is_default_head, grant=grant)
|
||||
st, existing = github("GET", f"/repos/{GH_OWNER}/{repo}/commits/{sha}/statuses?per_page=100")
|
||||
for s in existing or []: # newest first: compare the latest guard status only
|
||||
if s["context"] == ctx:
|
||||
|
||||
Reference in New Issue
Block a user