R-422: reuse_refs_check checks .md citations too

PATH_RE gains .md. The false-positive walk across all four repos found one: an audit document cited
by app-catalog's REUSE.md, hidden by the evidence-copy exclusion — excluded trees are now walked for
.md documents only, so a .go evidence copy there still never satisfies a citation. The KNOWN HOLE
decoy now expects a conviction.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 21:37:22 +02:00
parent 7ee00d59a8
commit bf1798479d
3 changed files with 54 additions and 14 deletions
+25
View File
@@ -155,6 +155,31 @@ class ReuseRefsCheckTest(unittest.TestCase):
self.assertNotEqual(rc, 0, "an audits/ or documentation/tests/ copy must NOT resolve:\n" + out)
self.assertIn("FAILED 2", out)
# ── R-422: document citations are checked ───────────────────────────────────
def test_absent_md_citation_fails(self):
"""The measured hole: a rotted .md citation passed because .md was not a checked extension."""
self.reuse("see `documentation/architecture/99-does-not-exist.md`\n")
rc, out = self.run_check()
self.assertNotEqual(rc, 0, "a .md citation that exists nowhere must fail:\n" + out)
self.assertIn("99-does-not-exist.md", out)
def test_md_citation_resolves_including_under_audits(self):
"""An audit DOCUMENT is the cited thing, not an evidence copy — it must resolve (the one false
positive the 2026-10-05 walk found, in app-catalog's REUSE.md)."""
write(os.path.join(self.root, "documentation", "architecture", "05-hub.md"), "# x\n")
write(os.path.join(self.root, "documentation", "audits", "SPIKE-x.md"), "# y\n")
self.reuse("see `documentation/architecture/05-hub.md` and `documentation/audits/SPIKE-x.md`\n")
rc, out = self.run_check()
self.assertEqual(rc, 0, out)
def test_audits_still_hide_code_copies_when_docs_are_indexed(self):
"""Indexing .md under audits/ must not let a .go evidence copy there resolve."""
write(os.path.join(self.root, "documentation", "audits", "pkg", "x.go"), "package pkg\n")
write(os.path.join(self.root, "documentation", "audits", "pkg", "notes.md"), "# n\n")
self.reuse("see `pkg/x.go`\n")
rc, out = self.run_check()
self.assertNotEqual(rc, 0, out)
# ── a clone in isolation must still check itself ────────────────────────────
def test_no_siblings_is_not_a_failure(self):
write(os.path.join(self.root, "a", "b.go"), "package a\n")