Skip to content

Evidence and identity hygiene sweep with a repository hygiene CI guard - #943

Merged
drmoisan merged 40 commits into
mainfrom
bug/evidence-and-identity-hygiene-sweep-927
Sep 30, 2026
Merged

drmoisan merged 40 commits into
mainfrom
bug/evidence-and-identity-hygiene-sweep-927

Conversation

@drmoisan

Copy link
Copy Markdown
Owner

Suggested title

Evidence and identity hygiene sweep with a repository hygiene CI guard

Summary

  • Adds a repository hygiene guard (scripts/hygiene/Test-RepositoryHygiene.ps1 with its .Rules.ps1 and .Git.ps1 parts) that rejects tracked raw test-platform documents, raw coverage-collector documents and absolute user-profile paths, and wires it into CI as a new hygiene context (.github/workflows/_hygiene.yml, called from .github/workflows/ci.yml).
  • Removes the tracked raw TRX, Cobertura, dotnet-coverage and raw Pester JaCoCo documents from the feature evidence trees and the stray root-level test-output.txt, and adds .gitignore patterns so they cannot be re-added.
  • Redacts developer account, host and profile-path identifiers in about 1,052 committed evidence files to the placeholders <repo-root>, <user-profile>, <user> and <host>; a per-file line-multiset comparison shows 0 unmatched lines, with an in-memory negative control that reports 1.
  • Rewrites hard-coded host paths in thirteen C# test fixtures to placeholder literals; no production C# file changes.
  • Adds 31 Pester tests for the guard under tests/scripts/hygiene/ and extends the CI Pester run and coverage arrays to the new folders.

Why

The repository was out of compliance with its own Committed Test Evidence Format (CLAUDE.md): hundreds of raw test-platform and coverage documents and absolute host paths had been committed before the convention existed, and nothing rejected new ones at commit or CI time. Earlier tooling fixed prevention in the scripts/vscode test route but did not remove existing content or add an enforcement gate. This change removes the content, redacts the identifiers, and adds a CI gate so the cleanup does not regress. It consolidates the unresolved remainder of several earlier hygiene reports into one delivery.

What Changed

Guard (new PowerShell, T4 tooling)

  • scripts/hygiene/Test-RepositoryHygiene.ps1 (entry point), Test-RepositoryHygiene.Rules.ps1 (pure rule logic), Test-RepositoryHygiene.Git.ps1 (git I/O seam).
  • Exit code 0 with a HYGIENE Findings=0 summary on a clean tree; non-zero with per-finding lines otherwise.

CI and ignore rules

  • .github/workflows/_hygiene.yml (new callee, 10-minute timeout), ci.yml (seventh context), _pester.yml (Run.Path and CodeCoverage.Path arrays include the hygiene folders), .github/workflows/README.md.
  • .gitignore: *.trx and *cobertura*.xml patterns with a comment naming the guard.

Tests

  • tests/scripts/hygiene/ three new Pester files (31 tests); tests/scripts/vscode/Invoke-MSTestWithCoverage.Helpers.Tests.ps1 fixture literals.
  • Thirteen C# test files across QuickFiler.Test, TaskMaster.Test, ToDoModel.Test and UtilitiesCS.Test: fixture path literals only; no assertion removed.

Docs and evidence (mechanical, large)

  • About 1,052 evidence files redacted in place; raw documents deleted; this feature folder with spec, plan, evidence and review artifacts.

Architecture / How It Fits Together

The CI orchestrator ci.yml calls _hygiene.yml, which runs the guard entry point on the Ubuntu runner. The entry point dot-sources the Rules and Git parts: the Git part enumerates tracked files and reads blobs, the Rules part classifies each path and content as raw document, profile path or clean, and the entry point aggregates findings and sets the exit code. The Pester suite exercises the Rules part directly and the Git part through an injected invoker, so no test touches the real repository or a temporary file.

Verification

Completed (recorded under docs/features/active/2026-09-28-evidence-and-identity-hygiene-sweep-927/evidence/):

  • Guard over the pre-sweep tree: findings equal to the raw-document population plus the profile-path file population (AC1); over the final tree: exit 0, 0 findings, 39 seconds.
  • PoshQC format and analyze: pass (analyze reports no count; recorded as "PoshQC analyze: pass (0 findings); tool reports no count"). PoshQC test: 373 passed, 0 failed; hygiene tests 31 passed.
  • C#: dotnet tool run csharpier check . exit 0; analyzer and nullable /t:Rebuild exit 0 with 0 errors and 0 warnings; MSTest 7346 passed, 0 failed; first-party coverage 85.92% lines, 80.08% branches, equal to main's own CI figures at the merge base.
  • Redaction fidelity: 1052 files, 0 unmatched lines, negative control 1.
  • Scope: no path outside the plan's write set; nothing under the governance directory, no MCP configuration, no solution, project or package file, no production C# file; three ancestry checks exit 0 and their negative control exits 1.
  • Feature review: zero blocking findings (policy-audit, code-review and feature-audit artifacts in the feature folder).

Pending on this pull request's CI run (completed by the remaining plan tasks after CI reports):

  • The new hygiene context green on the head (AC16).
  • Pester per-file and aggregate coverage for the three new guard files from the CI Pester job and its pester-coverage artifact (AC4).
  • C# coverage comparison of this run's mstest-coverage job against main's CI at the merge base (AC13).

Backward Compatibility / Migration Notes

  • No production code or public API changes.
  • New CI context hygiene; commits that add raw test documents or absolute profile paths will fail it.
  • Deleted raw documents are recoverable from git history; the committed projections and summaries carry their figures.

Risks and Mitigations

  • False positives from the guard on legitimate content: the rules match only raw-document shapes and profile-path patterns, and placeholders are recognised; the 31 tests cover positive, negative and boundary cases.
  • Guard runtime against the CI timeout: 39 seconds on the final tree against a 600-second job limit.
  • Redaction altering evidence meaning: the line-multiset check shows every changed line only replaced an identifier or legacy token.

Review Guide

  1. scripts/hygiene/ and tests/scripts/hygiene/ (the guard and its tests).
  2. .github/workflows/_hygiene.yml, ci.yml, _pester.yml, .gitignore.
  3. The thirteen C# test fixture diffs (literal changes only).
  4. The feature folder's spec, plan and evidence/qa-gates/ artifacts.
  5. The evidence redaction sweep is mechanical and very large; spot-check rather than read in full.

Follow-ups

  • Maintainer step after a green run: add the hygiene context to the main branch ruleset's required status checks (manual; not done by this change).
  • The push-down-owned governance directory is out of scope here and is handled upstream.

GitHub Auto-close

🤖 Generated with Claude Code

drmoisan and others added 30 commits September 28, 2026 22:50
…giene sweep

Carries issue, spec, research, write-set inventory and plan round 4 from the prior preparation worktree, plus the promoted record.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…nced blocks

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…iene guard (P1-T1, P1-T2)

Preserves the two test files written by the previous run before the plan is re-batched for the PowerShell batch budget. Refs 927.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Claude-Session: https://claude.ai/code/session_01KNZiXntshsLY8vqqCHUvHm
…ision 1.9)

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

Claude-Session: https://claude.ai/code/session_01KNZiXntshsLY8vqqCHUvHm
…ision 1.10)

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

Claude-Session: https://claude.ai/code/session_01KNZiXntshsLY8vqqCHUvHm
…ion; batched revision 1.10 is retracted and pinned on local ref prep/927-batched-plan-r1.10

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
… evidence at STOP AC1 ARITHMETIC MISMATCH (P1-T12)

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…and the P1-T13 range check; preflight round 8 requires revisions pending a coordinator scope ruling

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Claude-Session: https://claude.ai/code/session_01KmPs3siUtjDrp1E1B9C9gS
…n R8-01 to R8-06 and the spec AC1 amendment; confirming preflight round 9 requires revisions F1 to F3, halted for a coordinator ruling

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… F1 to F4; confirming preflight pending

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…lan revision 1.13 cleared by confirming preflight round 10

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… Pester callee arrays

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ocuments and ignore their name patterns

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ile parent

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…the canonical placeholders

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… document the seventh context

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…QC analyze returns no diagnostic count

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…sourced Pester coverage, PoshQC analyze pass line, P4-T7 line-multiset check with in-memory negative control); confirming preflight pending

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…n revision 1.14; halted for coordinator ruling on F1 to F5, F7 and F8

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
… F1 to F8 (three-dot diff anchor, CI Pester baseline 342, AC19 ancestry checks with negative control); confirming preflight pending

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…eltas D1 to D3 under the extended standing authority; confirming preflight pending

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…y negative control

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…in consolidation

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…e artifacts

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
… main CI at the current merge base (new P6-T39 with negative control); confirming preflight pending

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
… (main-tip drift guard, PR mstest job conclusion, ledger counts, confirming guard run); feature review artifacts with zero blocking findings

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…and cross-reference fixes R15-1 to R15-4

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
…and AC13 check-off

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
@drmoisan
drmoisan merged commit 231e1c0 into main Sep 30, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: evidence-and-identity-hygiene-sweep

1 participant