feat(ci): export SPDX symbol table and reject dangling operators (#627 follow-up) - #630
Merged
Merged
Conversation
…follow-up) Differential fuzzing of traverse-cli's ai-rule port found SPDX divergence: license-expression 30.4.4's ScanCode db classifies 243 names as exceptions, its license list differs from the Rust spdx crate, it knows multi-word aliases, and it silently drops a trailing AND/OR. Export the pinned symbol table (with a staleness test), reject dangling operators, and add 13 corpus fixtures (corpus 1.1.0). Decision-log entry 130. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
5 of 7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #627 / #629, decision-log entry 130. I ran a differential fuzz of traverse-cli's port of the
airules (traverse-framework/traverse#1597) against this gate:airules: agreed on all 4,000 mutatedaiobjects.The SPDX disagreements have one main cause:
license-expression30.4.4 bundles ScanCode's licence database, and the Rust side has a different one.WITH. Examples:eCos-2.0,MPL-2.0-no-copyleft-exception,GPL-3.0-with-GCC-exception,LicenseRef-scancode-*-exception.spdxcrate's.GPL 2.0.Separately, it silently drops a trailing
AND/OR, soMIT AND Apache-2.0 ANDwas accepted.This PR exports the pinned symbol table so the CLI can resolve ids exactly as CI does, and fixes the trailing-operator bug here instead of having the CLI copy it.
Governing Spec
Project Item
What Changed
spdx_symbol_table()writesscripts/ci/fixtures/spdx_symbols.json: 2,451 licence names and 243 exception names, keys and aliases. A test fails if the file is stale against the pinnedlicense-expression.validate_spdx_expressionrejects a dangling trailingAND/OR/WITHwithcontract.invalid_licensing_spdx. No published contract is affected; I checked the whole tree before the change.WITHfollowed by a ScanCode, deprecated or lowercase exception;LicenseRefcase handling;docs/model-rights.md, and decision-log entry 130.Validation
test_ai_admission_corpus.py: 116 fixtures plus the symbol-table freshness testtest_capability_validation.py: 212 tests (with the connector fixture runner built, as in CI)capability_validation.pypassespre_pr_check.sh🤖 Generated with Claude Code