Skip to content

firewall_gate: check PyAutoHands out now its leg has landed - #208

Merged
Jammy2211 merged 1 commit into
mainfrom
claude/mge-multi-start-lanes-2q7h70
Aug 18, 2026
Merged

firewall_gate: check PyAutoHands out now its leg has landed#208
Jammy2211 merged 1 commit into
mainfrom
claude/mge-multi-start-lanes-2q7h70

Conversation

@Jammy2211

Copy link
Copy Markdown
Collaborator

PyAutoLabs/PyAutoHands#237 cleared the last of issue #198's 9 tenant-firewall
findings and added the --only gate to Hands' own PR CI. The Mind-side gate
deliberately omitted the Hands checkout while Hands main still carried that
finding — including it earlier would have reddened this workflow on drift it
could not fix. That reason is now gone.

With this, the gate verifies the checker against all three organ mains, so an
allowlist over-grant or a check that stopped finding real drift fails the PR
that authors it — for every organ, not two of three.

Changes

  • add the PyAutoLabs/PyAutoHands checkout to firewall_gate.yml
  • replace the "deliberately NOT checked out yet" comment with the reason it
    joined

Verification

Run against a four-organ root (Mind + Brain + Heart + Hands) before merging
Hands' leg, the check reported the single Hands mismatch:

check tenant firewall (organ code): 1 mismatch(es)
  ✗ PyAutoHands/tests/test_pre_build_staging.py: new instance fact(s) in unlisted file
    — 'HowToFit' (204), 'PyAutoLabs' (61), 'autofit_workspace' (211),
      'autolens_assistant' (141), 'autolens_workspace' (176)

With the leg applied it reports OK, exit 0. Negative probe re-run on the
cleared tree: a bogus manifest name in the genericised file is still flagged,
so the check is not weakened.

Note on issue #198

Both remaining checklist items are now resolved or unblocked. They were not
independent: Heart's manifest_drift.py shells out to repos_sync.py --check,
so on a full local workspace the tenant-firewall YELLOW reason could not drop
while this Hands finding stood. It can now.


Generated by Claude Code

PyAutoHands#237 cleared the last of issue #198's 9 tenant-firewall
findings and added the `--only` gate to Hands' own PR CI. The Mind-side
gate deliberately omitted the Hands checkout while Hands main still
carried that finding — including it earlier would have reddened this
workflow on drift it could not fix. That reason is now gone.

With this, the gate verifies the checker against all three organ mains,
so an allowlist over-grant or a check that stopped finding real drift
fails the PR that authors it — for every organ, not two of three.

Verified against a four-organ root before merging Hands' leg: the check
reported the single Hands mismatch, and reported OK once the leg was
applied. Negative probe re-run on the cleared tree: a bogus manifest name
in the genericised file is still flagged.

Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_013xP1c7XRVQJzxoWAoH92GQ
@Jammy2211
Jammy2211 merged commit 84dac42 into main Aug 18, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants