feat(verifier): floor-guard waivers outside test files need a CLARIFICATIONS ack

Security-gate MEDIUM: a self-service floor-guard: allow <reason> neutralised
the detector in the same commit. User chose strict: the tool prints WAIVED,
the contract authorizes, the verifier counts the rest as gaps. BDR-102
amendment.
This commit is contained in:
bastien
2026-09-27 21:20:36 +02:00
parent 740138337c
commit 6617889b77
3 changed files with 14 additions and 4 deletions
+3 -1
View File
@@ -63,7 +63,9 @@ coverage threshold) that an LLM verdict alone can miss or be talked past
one line at a time. Its findings fold straight into that same verifier's
`ECARTS` count unless the contract's `CLARIFICATIONS` explicitly authorizes
the exact weakening; there is no separate gate and no extra dispatch, it
rides this GATE 1 call.
rides this GATE 1 call. A `floor-guard: allow` waiver outside a test file
is a finding too unless the contract's `CLARIFICATIONS` names it: the
waiver is self-service, the contract is human-gated (BDR-102 amendment).
Parse its single `VERIFY — VERDICT:` line: