From 14afe94d7644a4e4665a41a41148c9ebdb79c46e Mon Sep 17 00:00:00 2001 From: DongHyeonka Date: Thu, 10 Sep 2026 11:36:45 +0900 Subject: [PATCH] =?UTF-8?q?=EA=B2=80=EC=82=AC:=20=EA=B4=80=EB=AC=B8?= =?UTF-8?q?=EC=9D=B4=20=EC=96=B4=EB=8A=90=20=EB=8C=80=EC=83=81=EC=97=90=20?= =?UTF-8?q?=EB=8F=8C=EC=95=98=EB=8A=94=EC=A7=80=20=EB=B3=B4=EA=B3=A0,=20?= =?UTF-8?q?=ED=95=84=EC=88=98=20=EB=82=B4=EC=9A=A9=20=EA=B2=80=EC=82=AC?= =?UTF-8?q?=EB=A5=BC=20=EC=A0=84=EC=B2=B4=20=ED=9B=91=EA=B8=B0=EC=97=90=20?= =?UTF-8?q?=EB=84=A3=EB=8A=94=EB=8B=A4?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit R5 — 원장은 관문의 명령과 종료 코드를 적는데 **그 명령이 어느 대상에 돌았는지는 아무도 안 봤다.** 다른 프로젝트에 돌려 받은 exit 0 을 적어도 통과로 셌다. `_wrong_target()` 이 `docs/<이름>/` 경로와 명령 인자의 프로젝트 이름 둘 다 본다. 정상 원장 넷 새 error 0 (B 의 document-haness 원장 PASS · warn 3) 프로젝트 인자를 바꾼 원장 FAIL 「관문이 다른 대상에 돌았다」 기록 경로를 바꾼 원장 FAIL **유효 범위를 docstring 에 적었다** — 「다른 프로젝트」만 본다. 같은 프로젝트의 다른 기록에 돌린 관문은 안 잡는다. 기록 단위까지 보려면 관문마다 대상 단위를 계약이 먼저 정해야 한다. R12 — `check-required-content.py` 를 `OUTPUT_CHECKS` 에 더한다. B-003 이 병합돼 이제 된다. 세 상태 표를 지키는 것을 확인했다 — `ca-tmpl` exit 2 · `keycloak-session-store` exit 0 · 없는 프로젝트 exit 2. `OUTPUT CHECKS` 의 error 가 5 → 7 이 된다. **부채가 늘어난 것이 아니라 세는 자리가 늘었다** — `ca-tmpl` 에 계약이 없다는 한 사실이 `check_evidence` · `check-required-content` · `TECH LOG TREES` 세 곳에서 셈된다. 같은 사실을 세 번 세지 않는다. 회귀 `scripts/tests/test_run_target.py` 2건 (123 → 125). **「정상 원장은 그대로 통과한다」 대조를 함께 넣는다** — 무조건 거절로 성공률을 올리는 것이 R-003 이 든 실패다. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01Wp9jNbePAmWc5jQwCYhK9v --- scripts/tests/test_run_target.py | 79 ++++++++++++++++++++++++++++++++ scripts/verify-pipeline-run.py | 38 +++++++++++++++ scripts/verify-pipeline.py | 6 ++- 3 files changed, 121 insertions(+), 2 deletions(-) create mode 100644 scripts/tests/test_run_target.py diff --git a/scripts/tests/test_run_target.py b/scripts/tests/test_run_target.py new file mode 100644 index 0000000..6f43451 --- /dev/null +++ b/scripts/tests/test_run_target.py @@ -0,0 +1,79 @@ +"""원장에 적힌 관문이 **그 원장의 대상**에 돌았는지 (R5). + +원장은 명령 문자열과 종료 코드를 적는다. 그런데 그 명령이 어느 대상에 돌았는지는 아무도 +안 봤다 — 다른 프로젝트에 돌려 받은 exit 0 을 적어도 통과로 셌다. + +**정상 원장이 그대로 통과하는 대조를 함께 둔다.** 무조건 거절로 성공률을 올리는 것이 +R-003 이 든 실패다. +""" +from __future__ import annotations + +import copy +import glob +import importlib.util +import json +import os +import tempfile +import unittest + +ROOT = os.path.dirname(os.path.dirname(os.path.dirname(os.path.abspath(__file__)))) + + +def _module(): + path = os.path.join(ROOT, "scripts", "verify-pipeline-run.py") + spec = importlib.util.spec_from_file_location("verify_pipeline_run", path) + mod = importlib.util.module_from_spec(spec) + spec.loader.exec_module(mod) + return mod + + +def _a_ledger() -> dict | None: + for p in sorted(glob.glob(os.path.join(ROOT, "runs", "*", "*", "run.json"))): + d = json.load(open(p, encoding="utf-8")) + gates = [g for st in d.get("stages", []) for g in (st.get("gates") or [])] + if any("docs/" in str(g.get("cmd", "")) for g in gates): + return d + return None + + +def _verify(doc: dict) -> object: + with tempfile.NamedTemporaryFile("w", suffix=".json", delete=False, + dir=os.path.join(ROOT, "runs"), encoding="utf-8") as f: + json.dump(doc, f, ensure_ascii=False) + path = f.name + try: + return _module().verify(path) + finally: + os.unlink(path) + + +class GateRanAgainstTheLedgersTarget(unittest.TestCase): + def setUp(self) -> None: + self.doc = _a_ledger() + if self.doc is None: + self.skipTest("대상 경로가 있는 원장이 이 저장소에 없다") + + def test_untouched_ledger_still_passes(self) -> None: + """대조군 — 손대지 않은 원장은 이 규칙으로 새 error 를 얻지 않는다.""" + rep = _verify(self.doc) + self.assertNotIn("관문이 다른 대상에 돌았다", rep.errors) + + def test_gate_on_another_project_is_an_error(self) -> None: + other = "n+1liner" if self.doc["project"] != "n+1liner" else "keycloak" + if not os.path.isdir(os.path.join(ROOT, "docs", other)): + self.skipTest("대조에 쓸 다른 프로젝트가 없다") + bad = copy.deepcopy(self.doc) + swapped = False + for st in bad["stages"]: + for g in st.get("gates") or []: + cmd = str(g.get("cmd") or "") + if not swapped and f"docs/{bad['project']}/" in cmd: + g["cmd"] = cmd.replace(f"docs/{bad['project']}/", f"docs/{other}/") + swapped = True + self.assertTrue(swapped, "바꿀 관문을 못 찾았다") + rep = _verify(bad) + self.assertIn("관문이 다른 대상에 돌았다", rep.errors) + + +if __name__ == "__main__": + unittest.main() diff --git a/scripts/verify-pipeline-run.py b/scripts/verify-pipeline-run.py index 931b40e..da02068 100644 --- a/scripts/verify-pipeline-run.py +++ b/scripts/verify-pipeline-run.py @@ -70,6 +70,38 @@ MEASUREMENT_GATES = ("style_profile.mjs",) ORDER = ["S1", "S2", "S3", "S4", "S5", "S6", "S7"] +def _known_projects() -> set[str]: + docs = os.path.join(ROOT, "docs") + if not os.path.isdir(docs): + return set() + return {d for d in os.listdir(docs) + if os.path.isdir(os.path.join(docs, d)) and not d.startswith(("_", "."))} + + +def _wrong_target(cmd: str, project: str, known: set[str]) -> str | None: + """이 관문이 **다른 프로젝트**에 돌지 않았는지 본다 (R5). + + 원장은 관문의 명령 문자열과 종료 코드를 적는다. 그런데 그 명령이 어느 대상에 돌았는지는 + 아무도 안 봤다 — 다른 프로젝트에 돌려 exit 0 을 받아 적어도 통과로 셌다. + `docs/<이름>/` 경로와 명령 인자로 오는 프로젝트 이름 둘 다 본다. + + **유효 범위 — 「다른 프로젝트」만 본다.** 같은 프로젝트 안의 **다른 기록**에 돌린 관문은 + 안 잡는다. `docs/<프로젝트>/` 가 같으면 통과한다. 기록 단위까지 보려면 원장의 `record` 와 + 대조해야 하고, 그러면 프로젝트 단위로 도는 관문(`verify-tech-log-tree.py <프로젝트>`)이 + 전부 걸리므로 관문마다 대상 단위를 따로 적어야 한다. 그것은 이 검사기가 아니라 계약이 + 먼저 정할 일이다. + """ + for m in re.finditer(r"docs/([A-Za-z0-9_.+-]+)/", cmd): + if m.group(1) != project: + return f"docs/{m.group(1)}/" + for other in known: + if other == project: + continue + if re.search(rf"(? str: """공백을 하나로 접는다. 인용을 줄바꿈까지 똑같이 옮기라고 요구하지 않는다.""" return re.sub(r"\s+", " ", text).strip() @@ -168,6 +200,7 @@ def verify(path: str) -> Report: rep.error("원장에 칸이 없다", key) project = run.get("project") or "" rep.facts["project"] = project or "—" + known_projects = _known_projects() stages = {s.get("id"): s for s in run.get("stages") or []} missing = [sid for sid in ORDER if sid not in stages] @@ -228,6 +261,11 @@ def verify(path: str) -> Report: gates = st.get("gates") or [] cmds = " ; ".join(str(g.get("cmd") or "") for g in gates) + for g in gates: + other = _wrong_target(str(g.get("cmd") or ""), project, known_projects) + if other: + rep.error("관문이 다른 대상에 돌았다", + f"{where} — {str(g.get('cmd'))[:60]} → {other} (원장은 {project})") for token in spec["gates"]: if token not in cmds: rep.error("관문이 빠졌다", f"{where} — {token}") diff --git a/scripts/verify-pipeline.py b/scripts/verify-pipeline.py index 802eea6..02721d4 100755 --- a/scripts/verify-pipeline.py +++ b/scripts/verify-pipeline.py @@ -295,8 +295,7 @@ class _OutputReport: # CLAUDE.md 「검사」 절이 게시 전에 돌리라고 적은 것인데 verify-pipeline.py 가 부르지 않아, # 결함이 있는 채로 전체가 PASS 로 보고됐다 (V-001 verdict R3). # -# 셋째로 `check-required-content.py <프로젝트>` 가 들어갈 자리다. B-003 의 신규 파일이라 -# 그 작업이 accept 된 뒤에 아래 튜플에 한 줄 더한다 — 없는 스크립트를 부르면 전체가 깨진다. +# 셋째 `check-required-content.py` 는 B-003 이 들어온 뒤에 더했다 (R12). # 명령이 실재하지 않으면 건너뛰도록 아래 verify_outputs 가 파일 존재를 먼저 본다. OUTPUT_CHECKS = ( ("check-figure-text", @@ -305,6 +304,9 @@ OUTPUT_CHECKS = ( lambda root, proj: ["node", str(root / ".agents" / "skills" / "writing-tech-log-records" / "scripts" / "check_evidence.mjs"), proj, "--repo"]), + ("check-required-content", + lambda root, proj: [sys.executable, + str(root / "scripts" / "check-required-content.py"), proj]), )