MAJOR
- 9e97cd5 40-validate-standalone.sh: route a target's sc2_gate to its dedicated
gate (config-audit → 50-config-audit-sc2.sh), mirroring 99-dryrun.sh, so --all
no longer falsely FAILs config-audit on the machine-locked v5.0.0 tests.
- 1708e90 99-dryrun.sh: assert EXACTLY one tag survives (F5); a partial tag-strip
no longer silently reports the wrong tag via head -1.
- 4e494c8 99-dryrun.sh: capture the SC2 standalone failing set from the dry-run's
own prepped extract ($dest), not the 40-validate side-effect clean room.
- aeb6292 00-preflight.sh: assert every map path is whitespace/glob-free, making
the word-split path handling in 99-dryrun.sh sound.
- 5d112cb extract the SC6 DROP + SC2 regression detectors into sc6-check.sh /
sc2-regression.sh and add sc-checks.test.mjs — a negative test proving each
detector FIRES (force-fresh re-extraction would undo a planted file-drop).
- 9e588ca 10-extract.sh re-asserts git filter-repo before use (self-heal runs
preflight only on a missing mirror); RUNBOOK lists git-filter-repo + python3>=3.6.
MINOR
- bc0f8a7 plugin-map.json: reset ms-ai-architect blob_strip_safe to null
(00-preflight.sh populates it per run).
- 8d649e9 99-dryrun.sh: gate SC6 behind extract success; a failed extract is
labelled (extract failed), not a content DROP.
- 4044c49 99-dryrun.sh: guard mktemp — an empty capture is an error, not a
false zero-regression PASS.
Also: 00-preflight.test.mjs asserted all 3 'renamed' plugins carry >=2 paths, but
llm-security became single-path in 836b8e9 (copilot was a coexisting plugin, not a
rename) — a stale pre-existing failure. Aligned the test to the ratified map and
added a positive single-path lock against re-introducing the 87-file-drop defect.
Verified: full dry-run 11/11, 0 pushes; sc-checks/99-dryrun/40-validate/00-preflight/
60-rewrite suites green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
23 lines
1.1 KiB
Bash
Executable file
23 lines
1.1 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# SC6 content-retention decision — extracted from 99-dryrun.sh so the DROP detector (the deterministic
|
|
# guard against the llm-security 87-file-drop class, commit 836b8e9) is independently unit-testable
|
|
# (5d112cb). Given the extract's git-tracked file count, the live monorepo's count for the same paths, and
|
|
# whether an intentional >1MB blob-strip applies to this target, it prints the SC6 report-cell label and
|
|
# EXITS NON-ZERO on a real DROP — a shortfall NOT explained by a blob-strip. A blob-strip target may
|
|
# legitimately shed >1MB blobs, so a shortfall there is reported (exit 0), never failed.
|
|
#
|
|
# Usage: sc6-check.sh <ext_files> <live_files> <blob_strip>
|
|
# blob_strip: True/true → intentional >1MB strip (shortfall allowed); anything else → shortfall = DROP.
|
|
set -u
|
|
ext="${1:?ext_files}"
|
|
live="${2:?live_files}"
|
|
blob="${3:-false}"
|
|
|
|
if [ "$ext" -lt "$live" ]; then
|
|
case "$blob" in
|
|
True|true) echo "${ext}/${live} (blob-strip)"; exit 0 ;;
|
|
*) echo "${ext}/${live} DROP"; exit 1 ;;
|
|
esac
|
|
fi
|
|
echo "${ext}/${live}"
|
|
exit 0
|