test(contract): keep the private-address regression fixture public-safe - #5362
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
English verdict: APPROVE
Reviewed head: c558d83428850962b517e72676eace0dc282e0c0. No blocking finding.
动机
The full-source boundary preflight rejected its own synthetic scanner regression fixture. This patch closes that concrete validation defect; it does not claim that the broader App conversation journey is complete.
改动思路
Keep the existing scanner and assertions. Construct the address from numeric octets only inside the temporary test file, so repository source no longer carries the flagged literal. Adding exclusions or deleting the negative test would weaken the boundary and is unnecessary.
具体改动
Only the existing test changes: two added lines replace one literal write. At runtime the file still contains the same private address, and independent assertions still require both the missing-root diagnostic and private-address detection. The four focused tests pass, and the real full-tree CLI scan changes from one error to zero errors. No production helper, state or compatibility path is introduced.
对主干的风险
An octet typo is the strongest relevant failure: the private-address assertion would fail even if source scanning remained clean. Focused pytest, changed-file Ruff/Mypy, compile, diff hygiene and exact-scope premerge pass; quality receipt cqr_741d4f1581f7b4ba5db8 is verified. Full promotion qualification also passes with optional usage observation explicitly disabled. The earlier usage-on run hit a temporary-directory cleanup race; it is not erased or counted as passing. A broad Mypy experiment followed unchanged imports and failed outside the selected test scope; no full-repository typecheck claim is made. No required check was skipped and no paid model evaluation ran.
我的整体评价
The boundary is proportionate: it removes a repeated validation blocker and preserves the ordinary user journey because no product surface changes. The future-facing pass found no useful shared abstraction for this local fixture. This test-only PR is eligible for the repository's narrow self-merge policy after exact-head readiness; no scanner policy or authority exception is requested.
The full public-boundary preflight rejected the scanner regression test itself because its synthetic private address appeared literally in the tracked fixture. Build the same address from octets at test runtime, keeping both the missing-root diagnostic and the private-address detection assertions unchanged. Scanner policy and exclusions are unchanged.
Complete within this fixture-repair scope. This unblocks source-tree boundary validation; it does not claim completion of the App conversation journey.
Validation at
c558d83428850962b517e72676eace0dc282e0c0:--follow-imports=skip) pass.LOOPX_USAGE_PING=0switch to isolate that unrelated boundary; the original failed run remains recorded and no scanner-policy exception was introduced.UI impact: none. Only
tests/test_contract_scan_missing_roots.pychanges; no runtime, CLI, persistence, permission, or installed UI behavior changes. DCO signed. Synthetic inputs only; no private evidence is included.