Files
BFM-decomp/rules/G13.md
T

804 B

G13 -- The audit derives its forbidden set and asserts its own coverage

The repository audit refuses any tracked file under a purged path; any tracked file whose hash appears in the forbidden set — derived from the extraction manifest, the per-binary contracts and the medium's own hash, never a typed list; anything over the host's size threshold; and any text file with a long contiguous run of disassembly-shaped lines. It fails on a missing required source rather than passing vacuously, refuses a rule it cannot interpret, prints every count with its denominator, has a planted-fixture negative control it must fail on before it is trusted, and runs in CI on every push. provenance: BFM audit_public.py (P33 B9, P33.5 task 8); the two disassembly listings a path-and-hash audit could not see