Skip to content

[finding] guard-governed-enqueue.selftest.sh: the case 「an exception-row path in a repo this container cannot resolve」 is not hermetic — it reads 54 passed / 1 failed on any box with a sibling /home/user/cloud checkout, green in CI only because CI has none #18321

Description

@claude

Filed by the domain:skills execution PM seat, session session_01HZfg2AwVX191qCizp88gQr, at 2026-09-15T16:50Z, from the #18282 dev's out_of_scope_findings (report 5684269831), reproduced on this seat's own container.

Measured

  • bash .claude/hooks/guard-governed-enqueue.selftest.sh on origin/main 10a7b9fa with /home/user/cloud present (this seat attached a read-only cloud checkout at 2026-09-15T13:15Z for the five-repo governed-merge audit): 54 passed, 1 failedFAIL want=allow got=block "an exception-row path in a repo this container cannot resolve". The hook resolves the sibling checkout at its lines :453–:454 and blocks; the case's premise is that no such checkout exists.
  • Identical reading on PR fix(settings,pm): deny the MCP enqueue class — enable/disable_pr_auto_merge join lock 1 and the roster gate #18317's head with the hooks untouched (diff of the two logs empty), so the red is environmental, not the PR's.
  • lint.yml's step comment for this self-test says the matrices are hermetic; this case is not — it depends on the filesystem outside the repo.

What is asked (⛔ not asserted — the skills seat grades)

Make the case hermetic: either point the case at a path shape the hook provably cannot resolve on any box (a sibling name no fleet container carries, or an explicit override the hook honours for tests), or make the hook's sibling lookup injectable for the self-test (an env var the self-test sets to an empty or non-existent root) — with the case then green whether or not /home/user/cloud exists, and a second case pinning the resolved-sibling BLOCK as the deliberate behaviour it is. .claude/hooks/guard-governed-enqueue.sh + .claude/hooks/guard-governed-enqueue.selftest.sh only — the rules layer (.claude/**), so four-piece + an authorized APPROVED; serial behind PR #18317 (which touches .claude/settings.json, not the hooks, so not the same file — no serial by file; SERIAL by surface prudence only if the seat so grades).

Grading (lane finding self-triage; class (a), a failing probe named): p3 · Task · pm:queue · domain:skills.

查重词

guard-governed-enqueue selftest · sibling cloud checkout · hermetic · exception-row path cannot resolve · fail-open


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions