Skip to content

fix(governance): cover scripts/lib modules in the Windows deploy tier - #570

Merged
monkey1sai merged 3 commits into
mainfrom
fix/windows-tier-covers-lib-modules
Aug 17, 2026
Merged

monkey1sai merged 3 commits into
mainfrom
fix/windows-tier-covers-lib-modules

Conversation

@monkey1sai

@monkey1sai monkey1sai commented Aug 17, 2026 •

Copy link
Copy Markdown
Owner

為什麼

scripts/lib/windows-verification-scope.ps1 的 tier-2(deploy_dryrun)pattern 只比對 .ps1:

'^scripts/lib/(?!platform/)[^/]+\.ps1$'

後果(以 origin/main 的 checker 原件實測,非改後版本):

路徑 Tier Required
scripts/lib/rebuild-test-deploy.ps1 2 deploy_dryrun True
scripts/lib/StructLog.psm1(被前者 import) 0 none False

一個 tier-2 deploy 函式庫的直接依賴,自己不欠任何 Windows 證據——依賴逃出了依賴者所在的層級。

判定為疏漏,非刻意排除,三條獨立證據:

  1. StructLog.psm1 於 2026-05-27(feat(structured-log): cross-service structured log baseline #126)就存在;pattern 是 2026-08-05(feat(deploy): migrate the persistent test deploy area to remote Linux (PR-B) #467)才寫——撰寫當下 .psm1 已在該目錄。
  2. test-windows-verification-scope.ps1 自述涵蓋「the deliberate exclusions」(docs/tests/前端/README),全檔未出現 psm1 或 module。
  3. 該 pattern 本來就把 scripts/lib/ 底下每個非 platform 的 .ps1 都當 deploy 函式庫(design-system-gate.ps1、pr-review-agent.ps1、openspec-lifecycle.ps1 皆命中而皆非 deploy 檔)——設計接受過度涵蓋,唯一逃掉的偏偏是 module 型別。

變更

-'^scripts/lib/(?!platform/)[^/]+\.ps1$',
+'^scripts/lib/(?!platform/)[^/]+\.psm?1$',

測試補三組邊界,證明擴充不多不少:

  • scripts/lib/StructLog.psm1 → 必須 deploy_dryrun(正向)
  • scripts/lib/platform/adapter.psm1 → 仍是 platform_unit,不被 tier-2 搶走(排除保留)
  • scripts/lib/SomeModule.psd1 與 scripts/lib/nested/helper.psm1 → 不得被收進來(防過度延伸;manifest 不是可執行 deploy 邏輯,巢狀路徑比照 .ps1 半邊的既有邊界)

驗證(全部在本分支實跑)

檢查 結果
pwsh -File scripts/tests/test-windows-verification-scope.ps1 passed,exit 0
pwsh -File scripts/tests/test-pr-body-evidence.ps1 passed,exit 0
pwsh -File scripts/tests/invoke-powershell-static.ps1(PSScriptAnalyzer 1.24.0) passed,exit 0
pwsh -File scripts/tests/test-deploy-dryrun.ps1 ALL PASSED,exit 0
pwsh -File scripts/tests/test-deploy-governance-static.ps1 passed,exit 0
pwsh -File scripts/tests/test-platform-adapter.ps1 passed on windows,exit 0
pwsh -File scripts/tests/test-verify-all.ps1 passed,exit 0

完整 before/after 分類表與疏漏證據:docs/evidence/windows-tier-lib-modules/self-referential-bootstrap/verification.txt。

已知後果(誠實揭露)

  • 合併後,scripts/lib/ 底下的 .psm1 變更一律欠 deploy_dryrun 證據——包含 feat(governance): add report-only Agent Governance Policy module #565 新增的 agent-governance-policy.psm1。這是修正的預期效果,不是回歸;成本已在 evidence 檔第 4 節載明。
  • 本 PR 自己就是第一個付這筆成本的 PR(見下方 Windows verification 欄位)。

AI Coding Governance

欄位 值
Linked issue 無既有 issue;在 #565(Agent Governance Policy module)落地過程中以 Get-WindowsVerificationScope 實測發現,刻意不混入該 PR
Requirement source existing contract: scripts/lib/windows-verification-scope.ps1 的 D-20 tier 契約(本 PR 修復其涵蓋面),佐以 scripts/verification-manifest.json 將 StructLog.psm1 列入 rebuild-test-deploy path class 的既有裁決
CODEOWNERS / owner review .github/CODEOWNERS 的 * @monkey1sai-blip 仍是唯一合格 approver;本 PR 未改 CODEOWNERS
GitNexus evidence 未執行 impact 分析:變更為一條 regex 字元類別(.ps1 → .psm?1)與其測試,無任何 symbol 簽名或呼叫關係改動
Browser E2E evidence 不適用:無前端變更
Agent workflow changed? no —— 未改 .github/workflows/ 或任何 gate 的派遣;改的是 tier 分類資料面
Required checks expected agent-governance、root-contracts、powershell-static
欄位 值
Change lane G
Behavior contract changed yes

Behavior contract changed: yes:本 PR 收緊了 Windows verification tier 的機器裁決面(.psm1 從不欠證據變成欠 deploy_dryrun)。這是治理契約的行為變更,故如實申報。

欄位 值
Self-referential bootstrap yes
Bootstrap ledger entry windows-tier-lib-modules
Bootstrap reason this PR changes the checker that decides how much Windows evidence every other PR owes, so no pre-merge run can prove the post-merge classification; a post-merge fixpoint from main is required
欄位 值
Windows verification tier deploy_dryrun
Windows verification evidence 於 exact reviewed head 8fe68fe 在 Windows 實跑 test-deploy-dryrun.ps1、test-deploy-governance-static.ps1、test-platform-adapter.ps1、test-verify-all.ps1 與 test-windows-verification-scope.ps1,全部 exit 0(PSScriptAnalyzer 1.24.0 亦 passed)。Exact-head CI run:https://github.com/monkey1sai/AI-BIM-governance/actions/runs/32015937849(最終狀態以 PR checks 為準)。

tier-2 (deploy_dryrun) 的 pattern 只比對 scripts/lib 底下的 .ps1,漏掉 .psm1:

    '^scripts/lib/(?!platform/)[^/]+\.ps1$'

後果是 scripts/lib/rebuild-test-deploy.ps1(tier 2)import 的
scripts/lib/StructLog.psm1 落在 tier 0——deploy 函式庫自己的依賴不欠任何
Windows 證據。以 origin/main 的 checker 原件實測確認(見 evidence)。

判定為疏漏而非刻意排除:
- StructLog.psm1 於 2026-05-27 (#126) 就存在,pattern 是 2026-08-05 (#467)
  才寫,撰寫時 .psm1 已在該目錄。
- test-windows-verification-scope.ps1 自述涵蓋 deliberate exclusions,
  但全檔未出現 psm1 或 module。
- 該 pattern 本來就把 scripts/lib 底下每個非 platform 的 .ps1 都當 deploy
  函式庫(含 design-system-gate、pr-review-agent 等非 deploy 檔),設計本身
  接受過度涵蓋;唯一逃掉的偏偏是 module 型別。

改為 '\.psm?1$',並補三組測試:StructLog.psm1 必須落 deploy_dryrun、
platform/ 底下的 .psm1 仍是 tier 1、.psd1 與巢狀路徑不得被收進來。

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
PR Body Evidence Test and others added 2 commits August 17, 2026 17:33
#570)

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@monkey1sai
monkey1sai enabled auto-merge (squash) August 17, 2026 09:37
@monkey1sai
monkey1sai merged commit 655f1f9 into main Aug 17, 2026
35 of 39 checks passed
@monkey1sai
monkey1sai deleted the fix/windows-tier-covers-lib-modules branch August 17, 2026 10:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants