Files
fips/.github/workflows
Johnathan Corgan 9b977f8359 Gate every source comment reference so the sweep cannot silently undo
A hand-run search closes the population that exists the day it runs. This
closes it for every commit after. Three checks over the committed tree: no
local item identifier anywhere in the repository, no source comment citing a
document that is not in the tree, and no refactor-stage vocabulary in the
source.

The identifier check is repository-wide rather than source-only, because the
packaging and workflow files are at least as public as the source, and one of
them installs to users' machines.

The vocabulary check shares its pattern verbatim with the sweep that produced
the clean tree, so the two cannot drift apart.

Three exit states, not two. Zero means every reference resolves, one means
some do not and every offender is printed, and two means the check could not
look at all: not in a work tree, wrong directory, or an empty pathspec. A
search that found nothing because it searched the wrong place returns the same
empty result as a healthy tree, so that case is an error rather than a pass.
The coverage gaps that remain are listed in the script itself.
2026-08-16 14:28:28 +00:00
..