feat(verifier): floor-guard waivers outside test files need a CLARIFICATIONS ack
Security-gate MEDIUM: a self-service floor-guard: allow <reason> neutralised the detector in the same commit. User chose strict: the tool prints WAIVED, the contract authorizes, the verifier counts the rest as gaps. BDR-102 amendment.
This commit is contained in:
+4
-1
@@ -24,7 +24,10 @@ Format follows [Keep a Changelog](https://keepachangelog.com/).
|
|||||||
`floor-guard: allow <reason>` waiver, rc 0/2/3. Mandatory verifier
|
`floor-guard: allow <reason>` waiver, rc 0/2/3. Mandatory verifier
|
||||||
STEP 3 (`agents/verifier.md`), documented under GATE 1 of
|
STEP 3 (`agents/verifier.md`), documented under GATE 1 of
|
||||||
`lib/verify-secure-loop.md`. Suite `lib/tests/floor-guard.test.sh`: 6
|
`lib/verify-secure-loop.md`. Suite `lib/tests/floor-guard.test.sh`: 6
|
||||||
kinds plus a WAIVED and a CLEAN fixture, each flip-tested. Adapted from agent-skills `constraint-driven-development`.
|
kinds plus a WAIVED and a CLEAN fixture, each flip-tested. Waivers
|
||||||
|
outside test files count as gaps unless the contract's CLARIFICATIONS
|
||||||
|
names them (security-gate MEDIUM, user chose strict). Adapted from
|
||||||
|
agent-skills `constraint-driven-development`.
|
||||||
- **`lib/tests/skill-routing-census.test.sh`** (+ `lib/skill-routing-census.py`)
|
- **`lib/tests/skill-routing-census.test.sh`** (+ `lib/skill-routing-census.py`)
|
||||||
— TF-IDF cosine census of skill-description collisions across the live
|
— TF-IDF cosine census of skill-description collisions across the live
|
||||||
catalog (routing ambiguity, not naming): top 10 pairs, WARN ≥ 0.50,
|
catalog (routing ambiguity, not naming): top 10 pairs, WARN ≥ 0.50,
|
||||||
|
|||||||
+7
-2
@@ -83,12 +83,17 @@ bash ~/.claude/lib/floor-guard.sh <base> -- <pathspec>...
|
|||||||
`<base>` = the branch's gitflow base (develop; main for a hotfix/release).
|
`<base>` = the branch's gitflow base (develop; main for a hotfix/release).
|
||||||
Parse the single `FLOOR GUARD:` line:
|
Parse the single `FLOOR GUARD:` line:
|
||||||
|
|
||||||
- `clean` (rc 0) → no finding, continue to STEP 4.
|
- `clean` (rc 0) → no unwaived finding; still apply the WAIVED rule below.
|
||||||
- `<n> finding(s), <m> waived` (rc 2) → each `FLOOR <KIND> <file>:<line>
|
- `<n> finding(s), <m> waived` (rc 2) → each `FLOOR <KIND> <file>:<line>
|
||||||
<snippet>` line is a gap for STEP 5's `ECARTS` count, UNLESS the
|
<snippet>` line is a gap for STEP 5's `ECARTS` count, UNLESS the
|
||||||
contract's `CLARIFICATIONS` explicitly authorizes that exact weakening —
|
contract's `CLARIFICATIONS` explicitly authorizes that exact weakening —
|
||||||
quote the authorizing sentence in the verdict instead of counting it as a
|
quote the authorizing sentence in the verdict instead of counting it as a
|
||||||
gap. `WAIVED` lines are informational only, never a gap.
|
gap.
|
||||||
|
- `WAIVED <KIND> <file>:<line>` lines (either rc): on a test file (path
|
||||||
|
holds `test`, `spec` or `__tests__`) they are informational. Anywhere
|
||||||
|
else the waiver is self-service by construction, so it is a gap UNLESS
|
||||||
|
the contract's `CLARIFICATIONS` names that file and the reason — quote
|
||||||
|
it. The tool prints, the contract authorizes, the verifier counts.
|
||||||
- rc 3 (usage error) → a structural failure like a missing contract: retry
|
- rc 3 (usage error) → a structural failure like a missing contract: retry
|
||||||
once (base ref or pathspec likely wrong), a second failure escalates.
|
once (base ref or pathspec likely wrong), a second failure escalates.
|
||||||
|
|
||||||
|
|||||||
@@ -63,7 +63,9 @@ coverage threshold) that an LLM verdict alone can miss or be talked past
|
|||||||
one line at a time. Its findings fold straight into that same verifier's
|
one line at a time. Its findings fold straight into that same verifier's
|
||||||
`ECARTS` count unless the contract's `CLARIFICATIONS` explicitly authorizes
|
`ECARTS` count unless the contract's `CLARIFICATIONS` explicitly authorizes
|
||||||
the exact weakening; there is no separate gate and no extra dispatch, it
|
the exact weakening; there is no separate gate and no extra dispatch, it
|
||||||
rides this GATE 1 call.
|
rides this GATE 1 call. A `floor-guard: allow` waiver outside a test file
|
||||||
|
is a finding too unless the contract's `CLARIFICATIONS` names it: the
|
||||||
|
waiver is self-service, the contract is human-gated (BDR-102 amendment).
|
||||||
|
|
||||||
Parse its single `VERIFY — VERDICT:` line:
|
Parse its single `VERIFY — VERDICT:` line:
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user