Files
BFM-decomp/decomp-architect/templates/firewall.txt
T
Drew T 9235800fb7 tools+docs(phase-33.5): task 11 — kit part 2: the firewall pack (templates/gitignore.decomp extracted byte-for-byte from the wiki fence — gitignore_template_check now runs in tools-health; firewall.txt with purge:/glob:/required:/pending:/fixture: rules; audit_public.template.py generalised from the repo's audit with its sources in the config, refusing zero sources; firewall-fixture/ = 16 synthetic bytes + sha1, the planted negative control), no-rom.template.yml, the docs/.run READMEs, ops-setup.decomp.md, bootstrap.template.sh (skeleton), CLAUDE.decomp-overlay.md (the four fail-safes + session-start extras), pa-overlays.md (7 fenced blocks: DIGEST, the 🛑 checkpoint block, the PhaseEnd narrative axis, effort rows, cookbook entry shape + triage table, wave-playbook skeleton, settings/mcp), the LICENSE/NOTICE/README/CONTRIBUTING skeletons, .clang-format + make-format.snippet.mk; tools/MANIFEST.md (325 tool files by ladder phase from one read-only survey, coverage 325/325, as Phase-N tasks); tools/kit_lint.py (fence-aware leak grep, the PLACEHOLDERS set-diff, in-memory compile / bash -n / JSON+YAML, the gitignore diff, TODO counts, coverage; --selftest = the R39 control) wired into tools-health; decomp-architect/README.md in doc_links DEFAULT; SETUP row; PLACEHOLDERS Used-in cells reconciled; make tools-health OK on this tree (detached run, .run/P33.5/tools_health_t11.log); story-timeline regenerated by the report step; log + checkpoint (NEXT = task 12, Max)
2026-09-07 19:22:51 -06:00

38 lines
2.0 KiB
Plaintext

# config/firewall.txt — the ROM audit's sources, in ONE file (installed by decomp-architect Step 3).
# The audit (tools/audit_public.py) derives everything it forbids from the lines below; it never carries a typed list.
#
# purge: <prefix-or-glob> a path that may never be tracked (the rewrite's purge set reads the same lines, so the
# audit and any future history rewrite can never disagree about what is forbidden)
# required: <path> a hash source that MUST exist: a `.jsonl` manifest (one object per line with a `sha1`
# key) or a checksum file (`<sha1> <name>` lines, sha1sum format). Missing = the audit FAILS.
# pending: <path> a hash source a later phase creates; missing = a loud warning, never a pass on its own.
# Promote it to `required:` in the phase that creates it (the phase ladder names which).
# fixture: <path> the planted-fixture control's sha1 (Step 3); counts as a required source.
#
# The audit refuses to run with zero resolvable hash sources or zero purge rules (a tool must refuse, never pass vacuously).
# ---- purge rules: the nine classes of the ROM firewall (mirror .gitignore's paths) ----
purge: disks/
purge: {{TARGET_BINARY}}
purge: extracted/
glob: extracted/**
purge: asm/
purge: assets/
purge: build/
purge: expected/
purge: dumps/
glob: dumps/**/*.bin
purge: ghidra/
purge: tools/psyq/
purge: session-archive/
purge: datasets/
purge: models/
glob: **/*.gguf
glob: **/*.safetensors
# ---- hash sources ----
fixture: config/firewall-fixture.sha1
pending: extracted/retail/manifest.jsonl # TODO(phase-1): the extraction manifest — promote to required:
pending: config/medium.sha1 # TODO(phase-1): the medium's own track/image hash — promote to required:
pending: config/check.*.sha # TODO(phase-3): the per-binary contracts (a glob) — promote to required: