Skip to content

Fail the warning policy guard on response-file suppression (#132) - #133

Merged
wallstop merged 1 commit into
mainfrom
t132/fail-closed-response-file
Oct 2, 2026
Merged

wallstop merged 1 commit into
mainfrom
t132/fail-closed-response-file

Conversation

@wallstop

@wallstop wallstop commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

The assembly warning policy lint passed a csc.rsp that suppressed warnings or disabled warnings-as-errors, so the guard reported OK while the response file turned off the policy it owns.

Behavior

  • Each csc.rsp must hold exactly one argument, the maximum warning level; any other argument fails and the error names the file with every argument it found. The -analyzer: prefix scan is gone because the single-argument rule covers it.
  • Fail closed on content the guard does not model: -nowarn:, -nowarn, /nowarn, any -warnaserror form, comment lines, several arguments on one line, a repeated warning level, and an empty file.

Validation

  • The #132 fixtures exit 1 and name the file; 16 data-driven self-test rows each kill a different regression (pre-fix guard, dropped count check, skipped comment, message without the offending argument).
  • npm run lint:llm:full green (19/19 self-test files), four committed assemblies pass, CSharpier clean, npm pack unchanged at 172 files, pre-commit green. No C# or Unity change, so the Unity suites are not exercised.

Risk / Rollback

  • Risk: low. Developer tooling only; a legitimate second compiler argument now needs a reviewed guard change.
  • Rollback: revert this commit.

Note

Low Risk
Developer tooling and lint policy only; stricter validation may fail CI if a legitimate second compiler argument exists in csc.rsp.

Overview
Tightens the assembly warning policy lint so csc.rsp cannot silently undermine warnings-as-errors. The guard no longer looks only for a -warn:5-style flag while ignoring other switches; it now requires exactly one argument matching the maximum warning level (-warn:5, -w:5, or slash forms). Any extra line—-nowarn, -warnaserror±, -analyzer:, comment lines treated as content, multiple args on one line, duplicates, or an empty file—fails and reports the path plus all arguments found.

The separate -analyzer: scan is folded into that single-argument rule. Forbidden patterns gains a row (#132) documenting that config guards must allow-list permitted args instead of block-listing a few bad ones.

Tests replace a few one-off response-file cases with a 16-row data-driven matrix covering pass shapes and every regression the old guard missed.

Reviewed by Cursor Bugbot for commit 400604e. Bugbot is set up for automated code reviews on this repo. Configure here.

@wallstop
wallstop force-pushed the t132/fail-closed-response-file branch from 57acdd6 to dbf9781 Compare October 2, 2026 17:58
The assembly warning policy lint named the argument forms it rejects and
passed everything it did not name. `-nowarn:1701` and `-warnaserror-` in a
`csc.rsp` matched neither the warning-level scan nor the analyzer scan, so
the guard reported OK while the response file turned off the policy it
claims to enforce.

Each `csc.rsp` now has to hold exactly one argument, the maximum warning
level, and the error names the file with every argument it found. The
`-analyzer:` prefix scan is removed because the single-argument rule covers
it and it cannot fail on its own. The response-file self-tests are one
data-driven table of 16 rows.

Validation: the #132 fixtures exit 1 and name the file. Each row kills a
different regression: the pre-fix guard, a dropped count check, a skipped
comment line, or a message without the offending argument. `npm run
lint:llm:full` green (19 of 19 self-test files), the four committed
assemblies pass, CSharpier clean, `npm pack` payload unchanged at 172
files. No C# or Unity change, so the Unity suites are not exercised.

Refs #132.
@wallstop
wallstop force-pushed the t132/fail-closed-response-file branch from dbf9781 to 400604e Compare October 2, 2026 18:04
@wallstop
wallstop merged commit a3ccc08 into main Oct 2, 2026
3 checks passed
@wallstop
wallstop deleted the t132/fail-closed-response-file branch October 2, 2026 18:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant