fix(governance): cover scripts/lib modules in the Windows deploy tier - #570
Merged
Merged
Conversation
tier-2 (deploy_dryrun) 的 pattern 只比對 scripts/lib 底下的 .ps1,漏掉 .psm1:
'^scripts/lib/(?!platform/)[^/]+\.ps1$'
後果是 scripts/lib/rebuild-test-deploy.ps1(tier 2)import 的
scripts/lib/StructLog.psm1 落在 tier 0——deploy 函式庫自己的依賴不欠任何
Windows 證據。以 origin/main 的 checker 原件實測確認(見 evidence)。
判定為疏漏而非刻意排除:
- StructLog.psm1 於 2026-05-27 (#126) 就存在,pattern 是 2026-08-05 (#467)
才寫,撰寫時 .psm1 已在該目錄。
- test-windows-verification-scope.ps1 自述涵蓋 deliberate exclusions,
但全檔未出現 psm1 或 module。
- 該 pattern 本來就把 scripts/lib 底下每個非 platform 的 .ps1 都當 deploy
函式庫(含 design-system-gate、pr-review-agent 等非 deploy 檔),設計本身
接受過度涵蓋;唯一逃掉的偏偏是 module 型別。
改為 '\.psm?1$',並補三組測試:StructLog.psm1 必須落 deploy_dryrun、
platform/ 底下的 .psm1 仍是 tier 1、.psd1 與巢狀路徑不得被收進來。
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
#570) Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
monkey1sai
enabled auto-merge (squash)
August 17, 2026 09:37
monkey1sai-blip
approved these changes
Aug 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
為什麼
scripts/lib/windows-verification-scope.ps1的 tier-2(deploy_dryrun)pattern 只比對.ps1:後果(以
origin/main的 checker 原件實測,非改後版本):scripts/lib/rebuild-test-deploy.ps1deploy_dryrunscripts/lib/StructLog.psm1(被前者 import)none一個 tier-2 deploy 函式庫的直接依賴,自己不欠任何 Windows 證據——依賴逃出了依賴者所在的層級。
判定為疏漏,非刻意排除,三條獨立證據:
StructLog.psm1於 2026-05-27(feat(structured-log): cross-service structured log baseline #126)就存在;pattern 是 2026-08-05(feat(deploy): migrate the persistent test deploy area to remote Linux (PR-B) #467)才寫——撰寫當下.psm1已在該目錄。test-windows-verification-scope.ps1自述涵蓋「the deliberate exclusions」(docs/tests/前端/README),全檔未出現psm1或module。scripts/lib/底下每個非 platform 的.ps1都當 deploy 函式庫(design-system-gate.ps1、pr-review-agent.ps1、openspec-lifecycle.ps1皆命中而皆非 deploy 檔)——設計接受過度涵蓋,唯一逃掉的偏偏是 module 型別。變更
測試補三組邊界,證明擴充不多不少:
scripts/lib/StructLog.psm1→ 必須deploy_dryrun(正向)scripts/lib/platform/adapter.psm1→ 仍是platform_unit,不被 tier-2 搶走(排除保留)scripts/lib/SomeModule.psd1與scripts/lib/nested/helper.psm1→ 不得被收進來(防過度延伸;manifest 不是可執行 deploy 邏輯,巢狀路徑比照.ps1半邊的既有邊界)驗證(全部在本分支實跑)
pwsh -File scripts/tests/test-windows-verification-scope.ps1pwsh -File scripts/tests/test-pr-body-evidence.ps1pwsh -File scripts/tests/invoke-powershell-static.ps1(PSScriptAnalyzer 1.24.0)pwsh -File scripts/tests/test-deploy-dryrun.ps1pwsh -File scripts/tests/test-deploy-governance-static.ps1pwsh -File scripts/tests/test-platform-adapter.ps1pwsh -File scripts/tests/test-verify-all.ps1完整 before/after 分類表與疏漏證據:
docs/evidence/windows-tier-lib-modules/self-referential-bootstrap/verification.txt。已知後果(誠實揭露)
scripts/lib/底下的.psm1變更一律欠deploy_dryrun證據——包含 feat(governance): add report-only Agent Governance Policy module #565 新增的agent-governance-policy.psm1。這是修正的預期效果,不是回歸;成本已在 evidence 檔第 4 節載明。AI Coding Governance
Get-WindowsVerificationScope實測發現,刻意不混入該 PRscripts/lib/windows-verification-scope.ps1的 D-20 tier 契約(本 PR 修復其涵蓋面),佐以scripts/verification-manifest.json將StructLog.psm1列入rebuild-test-deploypath class 的既有裁決.github/CODEOWNERS的* @monkey1sai-blip仍是唯一合格 approver;本 PR 未改 CODEOWNERS.ps1→.psm?1)與其測試,無任何 symbol 簽名或呼叫關係改動.github/workflows/或任何 gate 的派遣;改的是 tier 分類資料面agent-governance、root-contracts、powershell-statictest-deploy-dryrun.ps1、test-deploy-governance-static.ps1、test-platform-adapter.ps1、test-verify-all.ps1與test-windows-verification-scope.ps1,全部 exit 0(PSScriptAnalyzer 1.24.0 亦 passed)。Exact-head CI run:https://github.com/monkey1sai/AI-BIM-governance/actions/runs/32015937849(最終狀態以 PR checks 為準)。