Files
BFM-decomp/decomp-architect/templates/firewall-fixture
Drew T 9235800fb7 tools+docs(phase-33.5): task 11 — kit part 2: the firewall pack (templates/gitignore.decomp extracted byte-for-byte from the wiki fence — gitignore_template_check now runs in tools-health; firewall.txt with purge:/glob:/required:/pending:/fixture: rules; audit_public.template.py generalised from the repo's audit with its sources in the config, refusing zero sources; firewall-fixture/ = 16 synthetic bytes + sha1, the planted negative control), no-rom.template.yml, the docs/.run READMEs, ops-setup.decomp.md, bootstrap.template.sh (skeleton), CLAUDE.decomp-overlay.md (the four fail-safes + session-start extras), pa-overlays.md (7 fenced blocks: DIGEST, the 🛑 checkpoint block, the PhaseEnd narrative axis, effort rows, cookbook entry shape + triage table, wave-playbook skeleton, settings/mcp), the LICENSE/NOTICE/README/CONTRIBUTING skeletons, .clang-format + make-format.snippet.mk; tools/MANIFEST.md (325 tool files by ladder phase from one read-only survey, coverage 325/325, as Phase-N tasks); tools/kit_lint.py (fence-aware leak grep, the PLACEHOLDERS set-diff, in-memory compile / bash -n / JSON+YAML, the gitignore diff, TODO counts, coverage; --selftest = the R39 control) wired into tools-health; decomp-architect/README.md in doc_links DEFAULT; SETUP row; PLACEHOLDERS Used-in cells reconciled; make tools-health OK on this tree (detached run, .run/P33.5/tools_health_t11.log); story-timeline regenerated by the report step; log + checkpoint (NEXT = task 12, Max)
2026-09-07 19:22:51 -06:00
..
2026-09-07 19:22:51 -06:00
2026-09-07 19:22:51 -06:00
2026-09-07 19:22:51 -06:00

The firewall fixture — the audit's negative control

blob.bin is sixteen synthetic bytes (printf 'DECOMP-FIXTURE!!'), derived from no game; blob.sha1 is its SHA1 in sha1sum format. The kit's installer (Step 3) copies only the .sha1 file into the new repository as config/firewall-fixture.sha1 and lists it in config/firewall.txt as a fixture: hash source, so the audit has at least one resolvable source before the extraction manifest exists. The control then plants a copy of the blob under scratch (.run/firewall-control/planted.bin), runs the audit on that path alone, asserts it FAILS naming the planted file, removes the copy, and asserts the tree PASSES. An audit that has not failed on the fixture is not trusted to pass (the source project's negative-control rule). The blob itself is never tracked in the new repository — the kit's package folder is gitignored after install.