feat(plan-01): Phase 4c — hard cutoff, remove .specify compat facade
Repoint every remaining literal `.specify/...` / `docs/input` reference to the real package/domain location and delete all compat symlinks. The harness now runs purely via packages/casan-harness/... with no .specify facade; .specify holds ONLY runtime state (logs/, agentops/alerts.log, level5/central-governance). Refs fixed (Phase 0.5 only caught `$VAR/.specify/` — these were bare/`__file__`/literal): - secrets-scan.sh: scan-target excludes -> packages/casan-harness/... (+ apps/okr/domain/corpus) - loop_common.py: loop-policy.yaml -> harness config (package-relative) - evidence-pack-build.py: judge-gate test + traceability-matrix.py -> harness/sibling - phase10-traceability: REQ -> $CASAN_DOMAIN_ROOT/input - run-casan-pipeline.mjs: model-fallback/drift-detect/rollback-manager -> HARNESS_BASH, golden -> GOLDEN_PLAN (apps/okr/domain), with .specify/logs state kept - casan-step.mjs: requirement fallback restored to docs/input for hermetic sandboxes - descriptive config (tool-registry/harness-package/drift-policy/hallucination/risk-registry/ loop-policy.schema + docstrings) repointed for accuracy - policy-bundle.yaml: 8 policy paths -> packages/casan-harness/...; manifest regenerated + re-signed (POLICY_HASHES_VALID files=8, POLICY_SIGNATURE_VALID) Removed 22 .specify code/config symlinks + docs/input symlink. Full gate via packages path, NO facade: PASS=64 FAIL=0 SKIP=3. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
e891981b59
commit
7101af9fd4
@@ -21,6 +21,9 @@ import os
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
# Plan-01: this script lives at <harness>/scripts/bash/; the harness root is two levels up.
|
||||
_HARNESS = os.path.abspath(os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", ".."))
|
||||
|
||||
|
||||
def read_jsonl(path):
|
||||
rows = []
|
||||
@@ -73,11 +76,11 @@ def main():
|
||||
# H3 eval scorecard (best effort — reference known evidence)
|
||||
reports["h3-eval-scorecard.json"] = {
|
||||
"harness": "H3-eval", "run_id": run_id,
|
||||
"judge_gate_tests": os.path.exists(os.path.join(root, ".specify/tests/phase3-judge-gate-tests.sh")),
|
||||
"judge_gate_tests": os.path.exists(os.path.join(_HARNESS, "tests/phase3-judge-gate-tests.sh")),
|
||||
"note": "judge-gate fail-before/fix cycle proven by phase3-judge-gate-tests.sh",
|
||||
}
|
||||
traceability_out = os.path.join(pack_dir, "traceability-matrix.json")
|
||||
traceability_script = os.path.join(root, ".specify/scripts/bash/traceability-matrix.py")
|
||||
traceability_script = os.path.join(os.path.dirname(os.path.abspath(__file__)), "traceability-matrix.py")
|
||||
traceability_rc = 1
|
||||
if os.path.isfile(traceability_script):
|
||||
traceability_rc = subprocess.run(
|
||||
|
||||
@@ -136,7 +136,9 @@ def policy_path() -> str:
|
||||
explicit = os.environ.get("CASAN_LOOP_POLICY_FILE")
|
||||
if explicit:
|
||||
return explicit
|
||||
return os.path.join(project_root(), ".specify/config/loop-policy.yaml")
|
||||
# Plan-01: loop-policy.yaml is harness config, not app state — resolve it inside the
|
||||
# package (this file lives at <harness>/scripts/bash/), independent of any .specify facade.
|
||||
return os.path.abspath(os.path.join(os.path.dirname(__file__), "..", "..", "config", "loop-policy.yaml"))
|
||||
|
||||
|
||||
def load_policy():
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
#!/usr/bin/env python3
|
||||
"""CASAN H4 PII masker driven by .specify/security/pii-rules.yaml.
|
||||
"""CASAN H4 PII masker driven by packages/casan-harness/security/pii-rules.yaml.
|
||||
|
||||
Reads content on stdin, applies every `action: mask` rule from the rules
|
||||
file, and writes the masked content to stdout. Type-specific replacement
|
||||
|
||||
@@ -39,14 +39,15 @@ fi
|
||||
# Exclude known test-fixture files and evidence directories that intentionally
|
||||
# contain the pattern as test data.
|
||||
FIXTURE_EXCLUDES=(
|
||||
".specify/tests/"
|
||||
"packages/casan-harness/tests/"
|
||||
"docs/output/casan/evidence/"
|
||||
".specify/security/"
|
||||
".specify/scripts/bash/security-check.sh"
|
||||
".specify/scripts/bash/verify-audit-chain.sh"
|
||||
".specify/scripts/bash/verify-tool-audit.sh"
|
||||
".specify/scripts/bash/tool-audit-lib.sh"
|
||||
".specify/scripts/bash/governance-check.sh"
|
||||
"packages/casan-harness/security/"
|
||||
"apps/okr/domain/corpus/"
|
||||
"packages/casan-harness/scripts/bash/security-check.sh"
|
||||
"packages/casan-harness/scripts/bash/verify-audit-chain.sh"
|
||||
"packages/casan-harness/scripts/bash/verify-tool-audit.sh"
|
||||
"packages/casan-harness/scripts/bash/tool-audit-lib.sh"
|
||||
"packages/casan-harness/scripts/bash/governance-check.sh"
|
||||
)
|
||||
build_exclude_args() {
|
||||
for ex in "${FIXTURE_EXCLUDES[@]}"; do printf -- "--exclude-dir=%s " "$ex"; done
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
#!/usr/bin/env python3
|
||||
"""CASAN Plan-10 traceability matrix generator/gate.
|
||||
|
||||
Parses FR-* requirements from docs/input/okr-requirement.md and checks each
|
||||
Parses FR-* requirements from apps/okr/domain/input/okr-requirement.md and checks each
|
||||
requirement has at least one existing code file and one existing test file.
|
||||
"""
|
||||
import argparse
|
||||
|
||||
Reference in New Issue
Block a user