Fail the warning policy guard on response-file suppression (#132) - #133
Merged
Merged
Conversation
wallstop
force-pushed
the
t132/fail-closed-response-file
branch
from
October 2, 2026 17:58
57acdd6 to
dbf9781
Compare
The assembly warning policy lint named the argument forms it rejects and passed everything it did not name. `-nowarn:1701` and `-warnaserror-` in a `csc.rsp` matched neither the warning-level scan nor the analyzer scan, so the guard reported OK while the response file turned off the policy it claims to enforce. Each `csc.rsp` now has to hold exactly one argument, the maximum warning level, and the error names the file with every argument it found. The `-analyzer:` prefix scan is removed because the single-argument rule covers it and it cannot fail on its own. The response-file self-tests are one data-driven table of 16 rows. Validation: the #132 fixtures exit 1 and name the file. Each row kills a different regression: the pre-fix guard, a dropped count check, a skipped comment line, or a message without the offending argument. `npm run lint:llm:full` green (19 of 19 self-test files), the four committed assemblies pass, CSharpier clean, `npm pack` payload unchanged at 172 files. No C# or Unity change, so the Unity suites are not exercised. Refs #132.
wallstop
force-pushed
the
t132/fail-closed-response-file
branch
from
October 2, 2026 18:04
dbf9781 to
400604e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The assembly warning policy lint passed a
csc.rspthat suppressed warnings or disabled warnings-as-errors, so the guard reported OK while the response file turned off the policy it owns.Behavior
csc.rspmust hold exactly one argument, the maximum warning level; any other argument fails and the error names the file with every argument it found. The-analyzer:prefix scan is gone because the single-argument rule covers it.-nowarn:,-nowarn,/nowarn, any-warnaserrorform, comment lines, several arguments on one line, a repeated warning level, and an empty file.Validation
#132fixtures exit 1 and name the file; 16 data-driven self-test rows each kill a different regression (pre-fix guard, dropped count check, skipped comment, message without the offending argument).npm run lint:llm:fullgreen (19/19 self-test files), four committed assemblies pass, CSharpier clean,npm packunchanged at 172 files, pre-commit green. No C# or Unity change, so the Unity suites are not exercised.Risk / Rollback
Note
Low Risk
Developer tooling and lint policy only; stricter validation may fail CI if a legitimate second compiler argument exists in
csc.rsp.Overview
Tightens the assembly warning policy lint so
csc.rspcannot silently undermine warnings-as-errors. The guard no longer looks only for a-warn:5-style flag while ignoring other switches; it now requires exactly one argument matching the maximum warning level (-warn:5,-w:5, or slash forms). Any extra line—-nowarn,-warnaserror±,-analyzer:, comment lines treated as content, multiple args on one line, duplicates, or an empty file—fails and reports the path plus all arguments found.The separate
-analyzer:scan is folded into that single-argument rule. Forbidden patterns gains a row (#132) documenting that config guards must allow-list permitted args instead of block-listing a few bad ones.Tests replace a few one-off response-file cases with a 16-row data-driven matrix covering pass shapes and every regression the old guard missed.
Reviewed by Cursor Bugbot for commit 400604e. Bugbot is set up for automated code reviews on this repo. Configure here.