mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
A hand-run search closes the population that exists the day it runs. This closes it for every commit after. Three checks over the committed tree: no local item identifier anywhere in the repository, no source comment citing a document that is not in the tree, and no refactor-stage vocabulary in the source. The identifier check is repository-wide rather than source-only, because the packaging and workflow files are at least as public as the source, and one of them installs to users' machines. The vocabulary check shares its pattern verbatim with the sweep that produced the clean tree, so the two cannot drift apart. Three exit states, not two. Zero means every reference resolves, one means some do not and every offender is printed, and two means the check could not look at all: not in a work tree, wrong directory, or an empty pathspec. A search that found nothing because it searched the wrong place returns the same empty result as a healthy tree, so that case is an error rather than a pass. The coverage gaps that remain are listed in the script itself.