Narrow development guidance to provisional contract

Keep plan enrichment internal and read-only pending consumer agreement and runtime pilot evidence. Move knowledge to its independent PR and remove the consumer-owned forensic evaluator.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 638b66d2-9f06-4f60-8781-808709e1485c
This commit is contained in:
Jesper Schulz-Wedde 2026-09-18 15:46:52 +02:00
parent 8f025ac679
commit fa7eb750c6
40 changed files with 294 additions and 2053 deletions

View file

@ -1,499 +0,0 @@
# Helpers for Test-DevelopmentGuidanceFixtures.ps1 and its deterministic regressions.
function Get-GuidanceDiagnostic {
param($ErrorRecord)
if ($ErrorRecord.Exception -is [Management.Automation.RuntimeException] -and
$ErrorRecord.FullyQualifiedErrorId -eq $ErrorRecord.Exception.Message) {
return $ErrorRecord.Exception.Message
}
return 'Evidence or report could not be read safely (missing, malformed, inaccessible or unsupported state).'
}
function Assert-GuidanceObject {
param($Value, [string] $Label, [string[]] $Fields = @())
if ($Value -isnot [Collections.IDictionary]) { throw "$Label must be a JSON object." }
foreach ($field in $Fields) {
if (-not $Value.Contains($field)) { throw "$Label is missing required field '$field'." }
}
}
function Assert-GuidanceString {
param($Value, [string] $Label)
if ($Value -isnot [string] -or [string]::IsNullOrWhiteSpace($Value)) { throw "$Label must be a non-empty string." }
}
function Assert-GuidanceArray {
param($Value, [string] $Label, [switch] $Strings, [switch] $NonEmpty)
if ($Value -isnot [array]) { throw "$Label must be a JSON array." }
if ($NonEmpty -and $Value.Count -eq 0) { throw "$Label must not be empty." }
if ($Strings) { foreach ($item in $Value) { Assert-GuidanceString $item "$Label entry" } }
}
function Assert-GuidanceInteger {
param($Value, [string] $Label)
if (($Value -isnot [long] -and $Value -isnot [int] -and $Value -isnot [bigint]) -or $Value -lt 0) {
throw "$Label must be a non-negative integer."
}
}
function Read-GuidanceJson {
param([string] $Path)
function Assert-JsonMembers($Element) {
if ($Element.ValueKind -eq [Text.Json.JsonValueKind]::Object) {
$names = [Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase)
foreach ($property in $Element.EnumerateObject()) {
if (-not $names.Add($property.Name)) { throw 'JSON contains duplicate or case-ambiguous members.' }
Assert-JsonMembers $property.Value
}
} elseif ($Element.ValueKind -eq [Text.Json.JsonValueKind]::Array) {
foreach ($item in $Element.EnumerateArray()) { Assert-JsonMembers $item }
}
}
try {
if ((Get-Item -LiteralPath $Path -Force).Length -gt 32MB) { throw 'Oversized JSON.' }
$text = [IO.File]::ReadAllText($Path)
$document = [Text.Json.JsonDocument]::Parse($text)
try { Assert-JsonMembers $document.RootElement } finally { $document.Dispose() }
return ConvertFrom-Json -InputObject $text -AsHashtable -Depth 64 -NoEnumerate
} catch { throw 'Input is not readable, strict JSON with unique members.' }
}
function Get-GuidanceHash {
param([string] $Path)
return (Get-FileHash -LiteralPath $Path -Algorithm SHA256).Hash
}
function Get-GuidanceCaseId {
param([string] $Id)
$bytes = [Security.Cryptography.SHA256]::HashData([Text.Encoding]::UTF8.GetBytes($Id))
return "case-$([Convert]::ToHexString($bytes).Substring(0, 8).ToLowerInvariant())"
}
function Test-GuidanceWithin {
param([string] $Path, [string] $Parent)
$comparison = if ($IsWindows) { [StringComparison]::OrdinalIgnoreCase } else { [StringComparison]::Ordinal }
$prefix = $Parent.TrimEnd([IO.Path]::DirectorySeparatorChar) + [IO.Path]::DirectorySeparatorChar
return $Path.Equals($Parent, $comparison) -or $Path.StartsWith($prefix, $comparison)
}
function Assert-GuidanceItem {
param($Item)
if (($Item.Attributes -band [IO.FileAttributes]::ReparsePoint) -or $Item.LinkType -or $Item.LinkTarget) {
throw 'Links, junctions, hard links and reparse points are not supported.'
}
if (-not $Item.PSIsContainer -and $IsWindows) {
$unsupportedStreams = @(
Get-Item -LiteralPath $Item.FullName -Stream '*' -Force -ErrorAction Stop |
Where-Object Stream -notin @(':$DATA', 'sec.endpointdlp')
)
if ($unsupportedStreams.Count) {
throw 'Alternate data streams are not supported.'
}
}
}
function Get-GuidanceSafePath {
param([string] $Path, [switch] $AllowMissing, [switch] $Directory, [switch] $File)
Assert-GuidanceString $Path 'Filesystem path'
$full = [IO.Path]::GetFullPath($Path)
$driveRoot = [IO.Path]::GetPathRoot($full)
if ($IsWindows -and ($driveRoot.StartsWith('\\') -or $full.Substring($driveRoot.Length).Contains(':'))) {
throw 'Network paths and alternate stream paths are not supported.'
}
$cursor = $driveRoot
$components = $full.Substring($driveRoot.Length).Split([IO.Path]::DirectorySeparatorChar, [StringSplitOptions]::RemoveEmptyEntries)
foreach ($component in $components) {
if ($component -match '[\. ]$') { throw 'Ambiguous filesystem path components are not supported.' }
$cursor = Join-Path $cursor $component
# Get-Item sees dangling links that Test-Path may treat as missing.
$item = Get-Item -LiteralPath $cursor -Force -ErrorAction SilentlyContinue
if ($null -ne $item) { Assert-GuidanceItem $item }
elseif (-not $AllowMissing) { throw 'Required filesystem path is missing.' }
}
if ($Directory -and -not (Test-Path -LiteralPath $full -PathType Container)) { throw 'Required directory is missing.' }
if ($File -and -not (Test-Path -LiteralPath $full -PathType Leaf)) { throw 'Required file is missing.' }
return $full.TrimEnd([IO.Path]::DirectorySeparatorChar)
}
function Assert-GuidanceTree {
param([string] $Root)
$pending = [Collections.Generic.Stack[string]]::new()
$pending.Push($Root)
while ($pending.Count) {
foreach ($item in Get-ChildItem -LiteralPath $pending.Pop() -Force) {
Assert-GuidanceItem $item
if ($item.PSIsContainer) { $pending.Push($item.FullName) }
}
}
}
function Invoke-GuidanceGit {
param([string] $Root, [string[]] $Arguments, [switch] $RawOutput)
$start = [Diagnostics.ProcessStartInfo]::new('git')
$start.UseShellExecute = $false
$start.RedirectStandardOutput = $true
$start.RedirectStandardError = $true
foreach ($variable in @('GIT_DIR', 'GIT_WORK_TREE', 'GIT_COMMON_DIR', 'GIT_INDEX_FILE',
'GIT_OBJECT_DIRECTORY', 'GIT_ALTERNATE_OBJECT_DIRECTORIES', 'GIT_CONFIG',
'GIT_CONFIG_COUNT', 'GIT_CONFIG_PARAMETERS', 'GIT_NAMESPACE')) {
$null = $start.Environment.Remove($variable)
}
$start.Environment['GIT_CONFIG_NOSYSTEM'] = '1'
$start.Environment['GIT_CONFIG_GLOBAL'] = ''
$start.Environment['GIT_TERMINAL_PROMPT'] = '0'
# In particular, do not execute a repository-supplied fsmonitor hook on reads.
foreach ($argument in (@('--no-optional-locks', '-c', 'core.fsmonitor=false', '-C', $Root) + $Arguments)) {
$start.ArgumentList.Add($argument)
}
$process = [Diagnostics.Process]::Start($start)
try {
$output = $process.StandardOutput.ReadToEndAsync()
$errors = $process.StandardError.ReadToEndAsync()
$process.WaitForExit()
$null = $errors.GetAwaiter().GetResult()
if ($process.ExitCode -ne 0) { throw 'Git evidence could not be read.' }
$text = $output.GetAwaiter().GetResult()
if ($RawOutput) { return $text }
return $text.TrimEnd("`r", "`n")
} finally { $process.Dispose() }
}
function Get-GuidanceSnapshot {
param([string] $Root, [switch] $Target)
$Root = Get-GuidanceSafePath $Root -Directory
$dotGit = Get-GuidanceSafePath (Join-Path $Root '.git')
if (Test-Path -LiteralPath $dotGit -PathType Container) {
$gitDir = $dotGit
} else {
if ($Target) { throw 'Target workspaces must be standalone repositories with internal Git storage.' }
$pointer = [IO.File]::ReadAllText($dotGit)
if ($pointer -notmatch '\Agitdir: ([^\r\n]+)\r?\n?\z') { throw 'Unsupported Git worktree pointer.' }
$gitPath = $Matches[1]
if (-not [IO.Path]::IsPathFullyQualified($gitPath)) { $gitPath = Join-Path $Root $gitPath }
$gitDir = Get-GuidanceSafePath $gitPath -Directory
}
$commonDir = $gitDir
$commonPointer = Get-GuidanceSafePath (Join-Path $gitDir 'commondir') -AllowMissing
if (Test-Path -LiteralPath $commonPointer) {
$commonPath = [IO.File]::ReadAllText($commonPointer).Trim()
if (-not [IO.Path]::IsPathFullyQualified($commonPath)) { $commonPath = Join-Path $gitDir $commonPath }
$commonDir = Get-GuidanceSafePath $commonPath -Directory
}
if ($Target -and ($gitDir -cne (Join-Path $Root '.git') -or $commonDir -cne $gitDir)) {
throw 'Target workspaces must be standalone repositories with internal Git storage.'
}
$files = [Collections.Generic.List[object]]::new()
$pending = [Collections.Generic.Stack[string]]::new()
$pending.Push($Root)
while ($pending.Count) {
foreach ($item in @(Get-ChildItem -LiteralPath $pending.Pop() -Force | Sort-Object Name -CaseSensitive)) {
Assert-GuidanceItem $item
$relative = [IO.Path]::GetRelativePath($Root, $item.FullName).Replace('\', '/')
$entry = [ordered]@{
path = $relative
kind = if ($item.PSIsContainer) { 'directory' } else { 'file' }
attributes = [int]$item.Attributes
unixMode = [int]$item.UnixFileMode
creationUtcTicks = $item.CreationTimeUtc.Ticks
}
if ($item.PSIsContainer) {
$pending.Push($item.FullName)
} else {
$entry.length = $item.Length
$entry.lastWriteUtcTicks = $item.LastWriteTimeUtc.Ticks
$entry.sha256 = Get-GuidanceHash $item.FullName
}
$files.Add($entry)
}
}
# Linked knowledge worktrees have explicitly identified Git metadata outside
# the content root. Record its meaningful configuration as well as HEAD/refs.
$gitMetadata = [ordered]@{}
foreach ($storage in @($gitDir, $commonDir) | Sort-Object -Unique) {
foreach ($name in @('HEAD', 'commondir', 'config', 'config.worktree', 'packed-refs', 'refs', 'objects', 'index', 'info\exclude', 'shallow')) {
$path = Get-GuidanceSafePath (Join-Path $storage $name) -AllowMissing
if ((Test-Path -LiteralPath $path -PathType Container) -and -not (Test-GuidanceWithin $path $Root)) {
Assert-GuidanceTree $path
}
if (Test-Path -LiteralPath $path -PathType Leaf) {
$gitMetadata[$path] = Get-GuidanceHash $path
}
if ($name -in @('config', 'config.worktree') -and (Test-Path -LiteralPath $path) -and
[IO.File]::ReadAllText($path) -match '(?im)^\s*\[include(?:If)?\b') {
throw 'External Git configuration includes are not supported.'
}
}
foreach ($name in @('objects\info\alternates', 'objects\info\http-alternates')) {
if (Test-Path -LiteralPath (Join-Path $storage $name)) { throw 'External Git object stores are not supported.' }
}
}
$top = Get-GuidanceSafePath (Invoke-GuidanceGit $Root @('rev-parse', '--show-toplevel')) -Directory
if ($top -cne $Root) { throw 'Evidence requires the exact Git worktree root, not a subdirectory.' }
$indexPath = Get-GuidanceSafePath (Join-Path $gitDir 'index') -AllowMissing
$tracked = Invoke-GuidanceGit $Root @('ls-files', '--stage')
if ($tracked -match '(?m)^160000 ') { throw 'Submodule workspaces are not supported.' }
if ((Invoke-GuidanceGit $Root @('ls-files', '-t')) -match '(?m)^S ') { throw 'Sparse workspaces are not supported.' }
$head = Invoke-GuidanceGit $Root @('rev-parse', '--verify', 'HEAD')
$headFile = Get-GuidanceSafePath (Join-Path $gitDir 'HEAD') -File
# Access times, Git status refreshes, and index-builder generatedAt are not evidence.
return [ordered]@{
version = 1
root = $Root
rootCreationUtcTicks = (Get-Item -LiteralPath $Root -Force).CreationTimeUtc.Ticks
gitDir = $gitDir
commonDir = $commonDir
gitMetadata = $gitMetadata
head = $head
headFileSha256 = Get-GuidanceHash $headFile
references = Invoke-GuidanceGit $Root @('for-each-ref', '--format=%(refname) %(objectname) %(symref)')
indexPath = $indexPath
indexSha256 = if (Test-Path -LiteralPath $indexPath) { Get-GuidanceHash $indexPath } else { $null }
files = @($files | Sort-Object { $_.path } -CaseSensitive)
}
}
function Test-GuidanceSnapshotEqual {
param($Before, $After)
return ($Before | ConvertTo-Json -Depth 64 -Compress) -ceq ($After | ConvertTo-Json -Depth 64 -Compress)
}
function Write-GuidanceNewJson {
param([string] $Path, $Value)
$parent = Split-Path -Parent $Path
[IO.Directory]::CreateDirectory($parent) | Out-Null
$bytes = [Text.Encoding]::UTF8.GetBytes(($Value | ConvertTo-Json -Depth 64))
$stream = [IO.File]::Open($Path, [IO.FileMode]::CreateNew, [IO.FileAccess]::Write, [IO.FileShare]::None)
try { $stream.Write($bytes, 0, $bytes.Length) } finally { $stream.Dispose() }
}
function Resolve-GuidanceReference {
param([string] $Root, $Reference, [switch] $Knowledge, [string] $Article)
Assert-GuidanceString $Reference 'Reference path'
if ($Reference -cnotmatch '^[a-zA-Z0-9_-]+(?:/[a-zA-Z0-9_.-]+)+$' -or
@($Reference.Split('/') | Where-Object { $_ -in @('.', '..') -or $_ -match '[\. ]$' }).Count) {
throw 'Reference must be an unambiguous forward-slash repository-relative path without traversal.'
}
if ($Knowledge -and $Reference -cnotmatch '^(microsoft|community|custom)/knowledge/[a-z0-9-]+/(?:[a-z0-9-]+/)*[a-z0-9-]+\.md$') {
throw 'Knowledge references must identify actual layered knowledge articles.'
}
if ($Article) {
$stem = $Article.Substring(0, $Article.Length - 3)
if ($Reference -cnotmatch ('^' + [regex]::Escape($stem) + '\.(good|bad)\.[a-zA-Z0-9]+$')) {
throw 'Sample references must be good/bad siblings of their knowledge article.'
}
}
$cursor = $Root
foreach ($component in $Reference.Split('/')) {
$cursor = Join-Path $cursor $component
$cursor = Get-GuidanceSafePath $cursor
if ((Get-Item -LiteralPath $cursor -Force).Name -cne $component) { throw 'Reference path casing must match the actual file.' }
}
if (-not (Test-GuidanceWithin $cursor $Root) -or -not (Test-Path -LiteralPath $cursor -PathType Leaf)) {
throw 'Reference must resolve to an existing file inside the knowledge checkout.'
}
if ($Knowledge) {
$text = [IO.File]::ReadAllText($cursor)
if ($text -notmatch '(?s)^---\r?\n.*?\r?\n---' -or
$text -notmatch '(?m)^domain:\s*\S+' -or $text -notmatch '(?m)^## (Best Practice|Anti Pattern)\s*$') {
throw 'Knowledge reference does not contain a normative knowledge article.'
}
}
return $cursor
}
function Get-GuidancePlanRequest {
param($Plan)
if ($Plan -is [string]) { Assert-GuidanceString $Plan 'development-plan'; return $Plan }
Assert-GuidanceObject $Plan 'development-plan' @('request')
Assert-GuidanceString $Plan.request 'development-plan.request'
return $Plan.request
}
function Assert-GuidanceContext {
param($Context)
Assert-GuidanceObject $Context 'context' @('bc-version', 'technologies', 'countries', 'application-area', 'unknown')
Assert-GuidanceString $Context.'bc-version' 'context.bc-version'
foreach ($key in @('technologies', 'countries', 'application-area', 'unknown')) {
Assert-GuidanceArray $Context[$key] "context.$key" -Strings
if (@($Context[$key] | Sort-Object -Unique).Count -ne $Context[$key].Count) { throw "context.$key contains duplicates." }
}
foreach ($key in $Context.unknown) {
if ($key -cnotin @('bc-version', 'technologies', 'countries', 'application-area')) { throw 'context.unknown contains an invalid dimension.' }
}
if ($Context.'bc-version' -eq 'unknown' -and 'bc-version' -cnotin $Context.unknown) {
throw 'Unknown BC version must be recorded in context.unknown.'
}
foreach ($key in @('technologies', 'countries', 'application-area')) {
if ((-not $Context[$key].Count -or 'unknown' -in $Context[$key]) -and $key -cnotin $Context.unknown) {
throw 'Unavailable applicability dimensions must be recorded in context.unknown.'
}
}
}
function Assert-GuidanceManifest {
param($Manifest, [string] $Root)
Assert-GuidanceObject $Manifest 'manifest' @('version', 'minimumKnowledgeRecall', 'minimumKnowledgePrecision', 'skill', 'cases')
if ($Manifest.version -ne 1) { throw 'Unsupported guidance fixture manifest version.' }
foreach ($name in @('minimumKnowledgeRecall', 'minimumKnowledgePrecision')) {
$value = $Manifest[$name]
if (($value -isnot [double] -and $value -isnot [long] -and $value -isnot [int] -and $value -isnot [decimal]) -or
$value -lt 0 -or $value -gt 1) { throw 'Manifest thresholds must be numbers between zero and one.' }
}
$null = Resolve-GuidanceReference $Root $Manifest.skill
Assert-GuidanceArray $Manifest.cases 'manifest.cases' -NonEmpty
$ids = [Collections.Generic.HashSet[string]]::new([StringComparer]::Ordinal)
$modelIds = [Collections.Generic.HashSet[string]]::new([StringComparer]::Ordinal)
foreach ($case in $Manifest.cases) {
Assert-GuidanceObject $case 'manifest case' @('id', 'expectedKind', 'expectedOutcome', 'development-plan', 'context', 'requiredKnowledge', 'optionalKnowledge', 'expectedUnknown', 'requiresUnresolved', 'requiresMaterialUnresolved')
if ($case.id -isnot [string] -or $case.id -cnotmatch '^[a-z0-9]+(?:-[a-z0-9]+)*$') { throw 'Fixture id must be kebab-case.' }
if (-not $ids.Add($case.id) -or -not $modelIds.Add((Get-GuidanceCaseId $case.id))) { throw 'Duplicate fixture or model case identity.' }
if ($case.expectedKind -cnotin @('feature', 'bug', 'refactor', 'upgrade', 'maintenance')) { throw 'Fixture expectedKind is invalid.' }
if ($case.expectedOutcome -cnotin @('completed', 'not-applicable', 'no-knowledge', 'partial', 'failed')) { throw 'Fixture expectedOutcome is invalid.' }
Assert-GuidanceString $case.expectedKind 'fixture.expectedKind'
Assert-GuidanceString $case.expectedOutcome 'fixture.expectedOutcome'
$null = Get-GuidancePlanRequest $case.'development-plan'
Assert-GuidanceContext $case.context
foreach ($name in @('requiredKnowledge', 'optionalKnowledge', 'expectedUnknown')) {
Assert-GuidanceArray $case[$name] "fixture.$name" -Strings
}
if ($case.requiresUnresolved -isnot [bool]) { throw 'Fixture requiresUnresolved must be boolean.' }
if ($case.requiresMaterialUnresolved -isnot [bool]) { throw 'Fixture requiresMaterialUnresolved must be boolean.' }
if ($case.requiresMaterialUnresolved -and ($case.expectedOutcome -ne 'partial' -or -not $case.requiresUnresolved)) {
throw 'Materially unresolved fixtures must expect partial and unresolved evidence.'
}
foreach ($key in $case.expectedUnknown) {
if ($key -cnotin @('bc-version', 'technologies', 'countries', 'application-area')) { throw 'Fixture expectedUnknown is invalid.' }
}
$references = @($case.requiredKnowledge) + @($case.optionalKnowledge)
if (@($references | Sort-Object -Unique).Count -ne $references.Count) { throw 'Fixture knowledge references contain duplicates.' }
foreach ($reference in $references) { $null = Resolve-GuidanceReference $Root $reference -Knowledge }
if ($case.expectedOutcome -in @('no-knowledge', 'not-applicable') -and $references.Count) {
throw 'Empty-knowledge outcomes cannot require or accept knowledge.'
}
}
}
function Assert-GuidanceResult {
param($Result, $Case, $Manifest, [string] $Root, [string] $Workspace)
Assert-GuidanceObject $Result 'result' @('caseId', 'guidanceReport')
Assert-GuidanceString $Result.caseId 'result.caseId'
if ($Result.caseId -cne (Get-GuidanceCaseId $Case.id)) { throw 'Result caseId mismatch.' }
if ($Result.Contains('workspaceRoot')) {
Assert-GuidanceString $Result.workspaceRoot 'result.workspaceRoot'
if (-not [IO.Path]::IsPathFullyQualified($Result.workspaceRoot) -or
(Get-GuidanceSafePath $Result.workspaceRoot -Directory) -cne $Workspace) {
throw 'Result workspaceRoot disagrees with the runner binding.'
}
}
$report = $Result.guidanceReport
Assert-GuidanceObject $report 'guidanceReport' @('skill', 'outcome', 'summary', 'context', 'knowledge', 'validation-considerations', 'suppressed', 'unresolved')
Assert-GuidanceObject $report.skill 'skill' @('id', 'version')
Assert-GuidanceString $report.skill.id 'skill.id'
if ($report.skill.id -cne 'al-development-plan' -or $report.skill.version -isnot [long] -or $report.skill.version -ne 1) {
throw 'Report skill identity/version is invalid.'
}
Assert-GuidanceString $report.outcome 'outcome'
if ($report.outcome -cnotin @('completed', 'not-applicable', 'no-knowledge', 'partial', 'failed')) { throw 'Report outcome enum is invalid.' }
if ($report.outcome -cne $Case.expectedOutcome) { throw 'Report outcome does not match fixture expectedOutcome.' }
if ($report.outcome -in @('partial', 'failed') -or $report.Contains('outcome-reason')) {
Assert-GuidanceString $report['outcome-reason'] 'outcome-reason'
}
Assert-GuidanceObject $report.summary 'summary' @('request', 'kind', 'candidates', 'selected')
Assert-GuidanceString $report.summary.request 'summary.request'
Assert-GuidanceString $report.summary.kind 'summary.kind'
if ($report.summary.kind -cne $Case.expectedKind) { throw 'summary.kind does not match the intended change.' }
Assert-GuidanceInteger $report.summary.candidates 'summary.candidates'
Assert-GuidanceInteger $report.summary.selected 'summary.selected'
Assert-GuidanceContext $report.context
foreach ($name in @('knowledge', 'validation-considerations', 'suppressed', 'unresolved')) {
Assert-GuidanceArray $report[$name] $name
}
Assert-GuidanceArray $report.unresolved 'unresolved' -Strings
if ($report.summary.selected -ne $report.knowledge.Count -or $report.summary.selected -gt $report.summary.candidates) {
throw 'Summary counts disagree with selected knowledge/candidates.'
}
if ($report.outcome -in @('no-knowledge', 'not-applicable') -and $report.knowledge.Count) { throw 'This outcome requires empty knowledge.' }
if ($report.outcome -eq 'completed' -and -not $report.knowledge.Count) { throw 'Completed requires selected knowledge; empty evaluation is no-knowledge.' }
if (($report.outcome -eq 'partial' -or $Case.requiresUnresolved) -and -not $report.unresolved.Count) {
throw 'Partial/incomplete evaluation must explain unresolved gaps.'
}
foreach ($dimension in $Case.expectedUnknown) {
if ($dimension -cnotin $report.context.unknown) { throw 'Expected unknown context was silently resolved.' }
}
foreach ($dimension in $report.context.unknown) {
if (-not @($report.unresolved | Where-Object { $_ -match [regex]::Escape($dimension) }).Count) {
throw 'Unknown dimensions require a corresponding unresolved explanation.'
}
}
# Free-form unresolved text has no machine-readable materiality field in DO.
# Known material fixture conditions are runner expectations, not model claims.
if ($Case.requiresMaterialUnresolved -and $report.outcome -ne 'partial') { throw 'Material unknown guidance must remain partial.' }
$used = [Collections.Generic.HashSet[string]]::new([StringComparer]::Ordinal)
foreach ($entry in $report.knowledge) {
Assert-GuidanceObject $entry 'knowledge entry' @('path', 'used-for', 'constraints', 'sample-paths')
$null = Resolve-GuidanceReference $Root $entry.path -Knowledge
if (-not $used.Add($entry.path)) { throw 'Duplicate knowledge reference.' }
Assert-GuidanceString $entry.'used-for' 'knowledge.used-for'
Assert-GuidanceArray $entry.constraints 'knowledge.constraints' -Strings -NonEmpty
Assert-GuidanceArray $entry.'sample-paths' 'knowledge.sample-paths' -Strings
if (@($entry.'sample-paths' | Sort-Object -Unique).Count -ne $entry.'sample-paths'.Count) { throw 'Duplicate sample reference.' }
foreach ($sample in $entry.'sample-paths') { $null = Resolve-GuidanceReference $Root $sample -Article $entry.path }
Assert-GuidanceReferenceSha $entry $Root
}
$validationIds = [Collections.Generic.HashSet[string]]::new([StringComparer]::Ordinal)
foreach ($entry in $report.'validation-considerations') {
Assert-GuidanceObject $entry 'validation consideration' @('id', 'reason', 'evidence')
foreach ($key in @('id', 'reason', 'evidence')) { Assert-GuidanceString $entry[$key] "validation-considerations.$key" }
if (-not $validationIds.Add($entry.id)) { throw 'Duplicate validation consideration id.' }
}
$suppressed = [Collections.Generic.HashSet[string]]::new([StringComparer]::Ordinal)
foreach ($entry in $report.suppressed) {
Assert-GuidanceObject $entry 'suppressed entry' @('reference', 'reason')
Assert-GuidanceObject $entry.reference 'suppressed.reference' @('path')
$null = Resolve-GuidanceReference $Root $entry.reference.path -Knowledge
Assert-GuidanceReferenceSha $entry.reference $Root
Assert-GuidanceString $entry.reason 'suppression reason'
if ($entry.reason -cnotin @('layer-precedence', 'configuration')) { throw 'Suppression reason is invalid.' }
if (-not $suppressed.Add($entry.reference.path) -or $used.Contains($entry.reference.path)) { throw 'Duplicate or selected suppressed reference.' }
}
$matched = @($Case.requiredKnowledge | Where-Object { $used.Contains($_) }).Count
$recall = if ($Case.requiredKnowledge.Count) { $matched / $Case.requiredKnowledge.Count } else { 1.0 }
$accepted = @($Case.requiredKnowledge) + @($Case.optionalKnowledge)
$acceptedCount = @($used | Where-Object { $_ -cin $accepted }).Count
$precision = if ($used.Count) { $acceptedCount / $used.Count } elseif (-not $Case.requiredKnowledge.Count) { 1.0 } else { 0.0 }
if ($recall -lt $Manifest.minimumKnowledgeRecall) { throw 'Knowledge recall is below the manifest threshold.' }
if ($precision -lt $Manifest.minimumKnowledgePrecision) { throw 'Knowledge precision is below the manifest threshold.' }
}
function Assert-GuidanceReferenceSha {
param($Entry, [string] $Root)
if ($Entry.Contains('sha')) {
if ($Entry.sha -isnot [string] -or $Entry.sha -cnotmatch '^([0-9a-fA-F]{40}|[0-9a-fA-F]{64})$') {
throw 'Reference SHA must be a full commit object id.'
}
$head = Invoke-GuidanceGit $Root @('rev-parse', '--verify', 'HEAD')
if ($Entry.sha -ne $head) { throw 'Reference SHA does not identify the recorded live checkout.' }
$committed = Invoke-GuidanceGit $Root @('cat-file', 'blob', "$head`:$($Entry.path)") -RawOutput
$live = [IO.File]::ReadAllText((Resolve-GuidanceReference $Root $Entry.path -Knowledge))
if ($committed.Replace("`r`n", "`n") -cne $live.Replace("`r`n", "`n")) {
throw 'Reference SHA content differs from the live knowledge article.'
}
}
}
function Get-GuidanceResultSchema {
param([string] $CaseId)
return [ordered]@{
caseId = $CaseId
guidanceReport = [ordered]@{
skill = [ordered]@{ id = 'al-development-plan'; version = 1 }
outcome = 'completed | not-applicable | no-knowledge | partial | failed'
'outcome-reason' = 'required for partial or failed'
summary = [ordered]@{ request = 'planned intent'; kind = 'feature | bug | refactor | upgrade | maintenance'; candidates = 0; selected = 0 }
context = [ordered]@{ 'bc-version' = 'resolved target or unknown'; technologies = @('al'); countries = @('w1'); 'application-area' = @('all'); unknown = @() }
knowledge = @([ordered]@{ path = 'repo-relative knowledge article'; sha = 'optional full checkout commit id'; 'used-for' = 'plan decision'; constraints = @('faithful normative constraint'); 'sample-paths' = @() })
'validation-considerations' = @([ordered]@{ id = 'stable id'; reason = 'why needed'; evidence = 'evidence implementation should obtain' })
suppressed = @([ordered]@{ reference = [ordered]@{ path = 'suppressed knowledge path' }; reason = 'layer-precedence | configuration' })
unresolved = @('Missing context/decision, affected candidate, and materiality; name unknown dimensions exactly.')
}
}
}

View file

@ -1,452 +0,0 @@
<#
.SYNOPSIS
Deterministic, offline regressions for the guidance evaluator (no model/AL run).
.DESCRIPTION
Creates only a uniquely named .guidance-evaluator-regression-* directory below
the current checkout, with standalone Git repositories and sibling runner
artifacts. Removes that exact directory in finally; never uses the OS temp
directory or cleans a caller-provided repository.
#>
[CmdletBinding()]
param()
Set-StrictMode -Version Latest
$ErrorActionPreference = 'Stop'
. (Join-Path $PSScriptRoot 'DevelopmentGuidance.Evidence.ps1')
$evaluator = Join-Path $PSScriptRoot 'Test-DevelopmentGuidanceFixtures.ps1'
$sourceRoot = (Get-Item -LiteralPath (Join-Path $PSScriptRoot '..')).FullName
$scratch = Join-Path $sourceRoot ".guidance-evaluator-regression-$([guid]::NewGuid().ToString('N'))"
$root = Join-Path $scratch 'knowledge-checkout'
$article = 'microsoft/knowledge/performance/pair-findset-with-next-loop.md'
$otherArticle = 'microsoft/knowledge/performance/findset-true-applies-updlock-on-read.md'
$sample = 'microsoft/knowledge/performance/pair-findset-with-next-loop.good.al'
$tests = [Collections.Generic.List[string]]::new()
$script:scenarioNumber = 0
$script:reportScenario = $null
function Set-TestJson($Path, $Value) {
[IO.File]::WriteAllText($Path, ($Value | ConvertTo-Json -Depth 64))
}
function Invoke-TestGit([string] $Directory, [string[]] $Arguments) {
$output = @(& git --no-optional-locks -C $Directory @Arguments 2>&1)
if ($LASTEXITCODE -ne 0) { throw 'Regression Git setup failed.' }
}
function Initialize-TestRepository([string] $Directory) {
[IO.Directory]::CreateDirectory($Directory) | Out-Null
Invoke-TestGit $Directory @('init', '--quiet')
Invoke-TestGit $Directory @('config', 'user.email', 'guidance-fixture@example.invalid')
Invoke-TestGit $Directory @('config', 'user.name', 'Guidance fixture')
Invoke-TestGit $Directory @('config', 'commit.gpgSign', 'false')
Invoke-TestGit $Directory @('config', 'core.autocrlf', 'false')
[IO.File]::WriteAllText((Join-Path $Directory 'app.json'), '{"name":"Synthetic AL fixture","application":"28.0.0.0"}')
[IO.File]::WriteAllText((Join-Path $Directory 'tracked.al'), 'codeunit 50100 Example {}')
[IO.File]::WriteAllText((Join-Path $Directory '.gitignore'), "ignored.txt`nignored-directory/`n")
Invoke-TestGit $Directory @('add', '.')
Invoke-TestGit $Directory @('commit', '--quiet', '-m', 'Synthetic fixture baseline')
}
function Invoke-EvaluatorTest([string] $Name, [string[]] $Arguments, [bool] $ShouldPass, [string] $Diagnostic = '') {
$output = @(& pwsh -NoProfile -File $evaluator @Arguments 2>&1) -join "`n"
$code = $LASTEXITCODE
if (($code -eq 0) -ne $ShouldPass -or $output -notmatch $(if ($ShouldPass) { 'PASSED|captured' } else { 'FAILED' })) {
throw "Regression '$Name' unexpected exit $code. $output"
}
if ($Diagnostic -and $output -notmatch [regex]::Escape($Diagnostic)) {
throw "Regression '$Name' missing diagnostic '$Diagnostic'. $output"
}
if ($output -match 'MODEL_SECRET_SENTINEL') { throw "Regression '$Name' leaked model content." }
$tests.Add($Name)
}
function New-TestScenario([string] $Outcome = 'completed', [switch] $Unknown, [switch] $SecondCase) {
$script:scenarioNumber++
$directory = Join-Path $scratch "scenario-$script:scenarioNumber"
[IO.Directory]::CreateDirectory($directory) | Out-Null
$workspace = Join-Path $directory 'target'
Initialize-TestRepository $workspace
[IO.File]::WriteAllText((Join-Path $workspace 'untracked.txt'), 'existing untracked content')
[IO.File]::WriteAllText((Join-Path $workspace 'ignored.txt'), 'existing ignored content')
[IO.Directory]::CreateDirectory((Join-Path $workspace 'ignored-directory')) | Out-Null
[IO.File]::WriteAllText((Join-Path $workspace 'ignored-directory\child.txt'), 'ignored child')
$results = Join-Path $directory 'results'
[IO.Directory]::CreateDirectory($results) | Out-Null
$hasKnowledge = $Outcome -in @('completed', 'partial')
$case = [ordered]@{
id = 'synthetic-case'
expectedKind = 'bug'
expectedOutcome = $Outcome
expectedUnknown = @($(if ($Unknown) { 'bc-version' }))
requiresUnresolved = ($Outcome -eq 'partial' -or $Unknown.IsPresent)
requiresMaterialUnresolved = ($Outcome -eq 'partial')
'development-plan' = [ordered]@{ kind = 'bug'; request = 'Iterate the supplied filtered record set.' }
context = [ordered]@{
'bc-version' = $(if ($Unknown) { 'unknown' } else { '28' })
technologies = @('al')
countries = @('w1')
'application-area' = @('all')
unknown = @($(if ($Unknown) { 'bc-version' }))
}
requiredKnowledge = @($(if ($hasKnowledge) { $article }))
optionalKnowledge = @()
}
$manifest = [ordered]@{
version = 1
skill = 'microsoft/skills/development/al-development-plan.md'
minimumKnowledgeRecall = 1.0
minimumKnowledgePrecision = 1.0
cases = @($case)
}
$result = [ordered]@{
caseId = Get-GuidanceCaseId $case.id
guidanceReport = [ordered]@{
skill = [ordered]@{ id = 'al-development-plan'; version = 1 }
outcome = $Outcome
summary = [ordered]@{ request = 'Iterate all selected records.'; kind = 'bug'; candidates = [int]$hasKnowledge; selected = [int]$hasKnowledge }
context = $case.context
knowledge = @($(if ($hasKnowledge) {
[ordered]@{ path = $article; 'used-for' = 'Choose the multi-record reader.'; constraints = @('Use FindSet when iterating with Next.'); 'sample-paths' = @($sample) }
}))
'validation-considerations' = @([ordered]@{ id = 'all-selected'; reason = 'Preserve selection.'; evidence = 'Test all selected records and an excluded record.' })
suppressed = @()
unresolved = @($(if ($Outcome -eq 'partial') {
if ($Unknown) { 'bc-version is unknown and materially affects the candidate; clarify before completing guidance.' }
else { 'The caller cardinality decision remains materially unresolved.' }
} elseif ($Unknown) { 'bc-version is unknown but immaterial: selected loop guidance applies to all versions.' }))
}
}
if ($Outcome -in @('partial', 'failed')) { $result.guidanceReport.'outcome-reason' = 'Fixture intentionally leaves evaluation incomplete.' }
$manifestPath = Join-Path $directory 'manifest.json'
$mapPath = Join-Path $directory 'workspace-map.json'
$map = [ordered]@{ 'synthetic-case' = $workspace }
if ($SecondCase) {
$second = $case | ConvertTo-Json -Depth 64 | ConvertFrom-Json -AsHashtable
$second.id = 'second-case'
$manifest.cases += $second
$secondWorkspace = Join-Path $directory 'second-target'
Initialize-TestRepository $secondWorkspace
$map[$second.id] = $secondWorkspace
$secondResult = $result | ConvertTo-Json -Depth 64 | ConvertFrom-Json -AsHashtable
$secondResult.caseId = Get-GuidanceCaseId $second.id
Set-TestJson (Join-Path $results "result-$($secondResult.caseId).json") $secondResult
}
Set-TestJson $manifestPath $manifest
Set-TestJson $mapPath $map
$resultPath = Join-Path $results "result-$($result.caseId).json"
Set-TestJson $resultPath $result
$baselinePath = Join-Path $directory 'baseline.json'
$captureArgs = @('-Root', $root, '-ManifestPath', $manifestPath, '-CaptureBaseline', '-WorkspaceMapPath', $mapPath, '-BaselinePath', $baselinePath)
$output = @(& pwsh -NoProfile -File $evaluator @captureArgs 2>&1) -join "`n"
if ($LASTEXITCODE -ne 0) { throw "Baseline setup failed. $output" }
return [ordered]@{
directory = $directory; workspace = $workspace; resultPath = $resultPath; result = $result
results = $results; manifest = $manifest; manifestPath = $manifestPath; mapPath = $mapPath
baselinePath = $baselinePath; captureArgs = $captureArgs
scoreArgs = @('-Root', $root, '-ManifestPath', $manifestPath, '-ResultsDirectory', $results, '-BaselinePath', $baselinePath, '-BaselineSha256', (Get-GuidanceHash $baselinePath))
}
}
function Test-ReportMutation([string] $Name, [scriptblock] $Change, [string] $Diagnostic) {
if ($null -eq $script:reportScenario) { $script:reportScenario = New-TestScenario }
$scenario = $script:reportScenario
$result = $scenario.result | ConvertTo-Json -Depth 64 | ConvertFrom-Json -AsHashtable
& $Change $result
Set-TestJson $scenario.resultPath $result
Invoke-EvaluatorTest $Name $scenario.scoreArgs $false $Diagnostic
}
try {
[IO.Directory]::CreateDirectory($root) | Out-Null
foreach ($reference in @($article, $otherArticle, $sample, $otherArticle.Replace('.md', '.good.al'),
'microsoft/skills/development/al-development-plan.md', 'tools/Build-KnowledgeIndex.ps1',
'tools/Knowledge-Retrieval.ps1')) {
$destination = Join-Path $root $reference.Replace('/', [IO.Path]::DirectorySeparatorChar)
[IO.Directory]::CreateDirectory((Split-Path $destination -Parent)) | Out-Null
[IO.File]::Copy((Join-Path $sourceRoot $reference.Replace('/', [IO.Path]::DirectorySeparatorChar)), $destination)
}
Initialize-TestRepository $root
$publicManifestPath = Join-Path $sourceRoot 'evaluation\development-guidance-fixtures.json'
$publicManifest = Read-GuidanceJson $publicManifestPath
$publicRoot = Join-Path $scratch 'public-fixture-checkout'
$publicKnowledgeReferences = @(
$publicManifest.cases |
ForEach-Object { $_.requiredKnowledge; $_.optionalKnowledge } |
Sort-Object -Unique
)
$publicSampleReferences = @(
foreach ($articleReference in $publicKnowledgeReferences) {
$articlePath = Join-Path $sourceRoot $articleReference.Replace('/', [IO.Path]::DirectorySeparatorChar)
$articleDirectory = Split-Path $articleReference -Parent
$articleText = [IO.File]::ReadAllText($articlePath)
foreach ($match in [regex]::Matches(
$articleText,
'\[[^\]]+\]\((?<sample>[a-z0-9-]+\.(?:good|bad)\.[a-zA-Z0-9]+)\)'
)) {
"$($articleDirectory.Replace('\', '/'))/$($match.Groups['sample'].Value)"
}
}
)
$publicReferences = @(
@(
$publicManifest.skill,
'tools/Build-KnowledgeIndex.ps1',
'tools/Knowledge-Retrieval.ps1',
'evaluation/development-guidance-fixtures.json'
) +
$publicKnowledgeReferences +
$publicSampleReferences |
Sort-Object -Unique
)
foreach ($reference in @($publicReferences | Sort-Object -Unique)) {
$destination = Join-Path $publicRoot $reference.Replace('/', [IO.Path]::DirectorySeparatorChar)
[IO.Directory]::CreateDirectory((Split-Path $destination -Parent)) | Out-Null
[IO.File]::Copy((Join-Path $sourceRoot $reference.Replace('/', [IO.Path]::DirectorySeparatorChar)), $destination)
}
$publicPrepared = Join-Path $scratch 'public-prepared'
Invoke-EvaluatorTest 'public five-case manifest validation' @('-Root', $publicRoot) $true
Invoke-EvaluatorTest 'public five-case manifest preparation' @('-Root', $publicRoot, '-PrepareDirectory', $publicPrepared) $true
$initialCase = $publicManifest.cases | Where-Object id -eq 'synthetic-normal-initial-plan'
$initialRequest = Read-GuidanceJson (Join-Path $publicPrepared "request-$(Get-GuidanceCaseId $initialCase.id).json")
if ($initialRequest.'development-plan' -cne $initialCase.'development-plan') { throw 'Preparation truncated the serialized initial plan.' }
$document = $initialRequest.'development-plan' | ConvertFrom-Json -AsHashtable
if ($document.metadata.kind -ne 'bug' -or
@('Root cause and design', 'Proposed fix', 'Affected files', 'Test strategy', 'Acceptance criteria' |
Where-Object { $document.body -notmatch [regex]::Escape($_) }).Count) {
throw 'Synthetic consumer boundary lost metadata or markdown plan sections.'
}
$tests.Add('serialized synthetic initial-plan boundary preserves full metadata and markdown body')
$scenario = New-TestScenario
Invoke-EvaluatorTest 'unchanged target with ignored and untracked files passes' $scenario.scoreArgs $true
Invoke-EvaluatorTest 'scoring itself leaves index and content unchanged' $scenario.scoreArgs $true
Invoke-EvaluatorTest 'existing baseline cannot silently recapture' $scenario.captureArgs $false 'Baseline already exists'
Invoke-EvaluatorTest 'scoring without baseline fails' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-ResultsDirectory', $scenario.results) $false 'require BaselinePath'
Invoke-EvaluatorTest 'scoring requires independently retained baseline digest' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-ResultsDirectory', $scenario.results, '-BaselinePath', $scenario.baselinePath) $false 'runner-retained pre-run BaselineSha256'
Invoke-EvaluatorTest 'tampered baseline digest fails' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-ResultsDirectory', $scenario.results, '-BaselinePath', $scenario.baselinePath, '-BaselineSha256', ('0' * 64)) $false 'digest mismatch'
$prepare = Join-Path $scenario.directory 'prepared'
Invoke-EvaluatorTest 'prepare outside roots with runner workspace binding' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-PrepareDirectory', $prepare, '-WorkspaceMapPath', $scenario.mapPath) $true
$prepared = Read-GuidanceJson (Join-Path $prepare "request-$($scenario.result.caseId).json")
if ($prepared.repository -cne $scenario.workspace -or $prepared.Contains('expectedOutcome') -or $prepared.Contains('requiredKnowledge')) {
throw 'Prepared request lost runner binding or exposed answers.'
}
Invoke-EvaluatorTest 'preparation never overwrites requests' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-PrepareDirectory', $prepare) $false 'new or empty'
foreach ($option in @('PrepareDirectory', 'BaselinePath', 'ResultsDirectory')) {
$inside = Join-Path $scenario.workspace 'unsafe-artifact'
$arguments = @('-Root', $root, '-ManifestPath', $scenario.manifestPath)
if ($option -eq 'PrepareDirectory') { $arguments += @('-PrepareDirectory', $inside, '-WorkspaceMapPath', $scenario.mapPath) }
elseif ($option -eq 'BaselinePath') { $arguments += @('-CaptureBaseline', '-BaselinePath', $inside, '-WorkspaceMapPath', $scenario.mapPath) }
else { $arguments += @('-BaselinePath', $scenario.baselinePath, '-BaselineSha256', (Get-GuidanceHash $scenario.baselinePath), '-ResultsDirectory', $inside) }
Invoke-EvaluatorTest "$option inside target rejected" $arguments $false 'outside target workspaces'
}
foreach ($mutation in @('uncommitted', 'committed', 'empty-commit', 'staged', 'index-only', 'untracked', 'ignored', 'ignored-child', 'added', 'deleted', 'directory', 'ref', 'metadata')) {
$scenario = New-TestScenario
switch ($mutation) {
'uncommitted' { [IO.File]::AppendAllText((Join-Path $scenario.workspace 'tracked.al'), "`n// changed") }
'committed' {
[IO.File]::AppendAllText((Join-Path $scenario.workspace 'tracked.al'), "`n// changed")
Invoke-TestGit $scenario.workspace @('add', 'tracked.al')
Invoke-TestGit $scenario.workspace @('commit', '--quiet', '-m', 'Committed forbidden edit')
}
'staged' {
[IO.File]::AppendAllText((Join-Path $scenario.workspace 'tracked.al'), "`n// changed")
Invoke-TestGit $scenario.workspace @('add', 'tracked.al')
}
'empty-commit' { Invoke-TestGit $scenario.workspace @('commit', '--quiet', '--allow-empty', '-m', 'Forbidden empty commit') }
'index-only' { Invoke-TestGit $scenario.workspace @('update-index', '--assume-unchanged', 'tracked.al') }
'untracked' { [IO.File]::AppendAllText((Join-Path $scenario.workspace 'untracked.txt'), 'changed') }
'ignored' { [IO.File]::AppendAllText((Join-Path $scenario.workspace 'ignored.txt'), 'changed') }
'ignored-child' { [IO.File]::AppendAllText((Join-Path $scenario.workspace 'ignored-directory\child.txt'), 'changed') }
'added' { [IO.File]::WriteAllText((Join-Path $scenario.workspace 'new.txt'), 'new ignored/untracked payload') }
'deleted' { [IO.File]::Delete((Join-Path $scenario.workspace 'untracked.txt')) }
'directory' { [IO.Directory]::CreateDirectory((Join-Path $scenario.workspace 'new-empty-directory')) | Out-Null }
'ref' { Invoke-TestGit $scenario.workspace @('branch', 'new-reference') }
'metadata' {
$path = Join-Path $scenario.workspace 'tracked.al'
[IO.File]::SetLastWriteTimeUtc($path, [IO.File]::GetLastWriteTimeUtc($path).AddSeconds(5))
}
}
Invoke-EvaluatorTest "$mutation mutation fails" $scenario.scoreArgs $false 'identity/content changed'
}
$scenario = New-TestScenario -SecondCase
Invoke-EvaluatorTest 'two independently bound workspaces pass' $scenario.scoreArgs $true
$map = Read-GuidanceJson $scenario.mapPath
[IO.File]::AppendAllText((Join-Path $scenario.workspace 'tracked.al'), "`n// changed")
$scenario.result.workspaceRoot = $map['second-case']
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'self-reported clean workspace cannot hide changed runner target' $scenario.scoreArgs $false 'identity/content changed'
$scenario = New-TestScenario -SecondCase
$scenario.result.workspaceRoot = (Read-GuidanceJson $scenario.mapPath)['second-case']
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'result workspace swapping rejected even when both are clean' $scenario.scoreArgs $false 'runner binding'
$scenario = New-TestScenario -SecondCase
$scenario.result.caseId = Get-GuidanceCaseId 'second-case'
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'result case swapping rejected' $scenario.scoreArgs $false 'caseId mismatch'
$scenario = New-TestScenario
$scenario.manifest.cases[0].expectedKind = 'feature'
Set-TestJson $scenario.manifestPath $scenario.manifest
Invoke-EvaluatorTest 'changed manifest rejected' $scenario.scoreArgs $false 'root or manifest'
$scenario = New-TestScenario
$baseline = Read-GuidanceJson $scenario.baselinePath
$baseline.workspaces['synthetic-case'].caseId = 'case-00000000'
Set-TestJson $scenario.baselinePath $baseline
Invoke-EvaluatorTest 'baseline case binding checked even with matching digest' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-ResultsDirectory', $scenario.results, '-BaselinePath', $scenario.baselinePath, '-BaselineSha256', (Get-GuidanceHash $scenario.baselinePath)) $false 'case identity mismatch'
foreach ($outcome in @('no-knowledge', 'partial', 'failed', 'not-applicable')) {
$scenario = New-TestScenario $outcome
Invoke-EvaluatorTest "honest $outcome is distinguishable and passes" $scenario.scoreArgs $true
}
$scenario = New-TestScenario 'partial' -Unknown
Invoke-EvaluatorTest 'material unknown stays partial' $scenario.scoreArgs $true
$scenario.result.guidanceReport.outcome = 'completed'
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'material unknown cannot silently complete' $scenario.scoreArgs $false 'expectedOutcome'
$scenario = New-TestScenario 'completed' -Unknown
Invoke-EvaluatorTest 'nonmaterial unknown can complete with explanation' $scenario.scoreArgs $true
$scenario.result.guidanceReport.unresolved = @()
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'unknown cannot disappear from unresolved evidence' $scenario.scoreArgs $false 'unresolved gaps'
$scenario = New-TestScenario 'no-knowledge' -Unknown
Invoke-EvaluatorTest 'immaterial unknown and no-knowledge are not failures' $scenario.scoreArgs $true
foreach ($outcome in @('partial', 'failed')) {
$scenario = New-TestScenario $outcome
$scenario.result.guidanceReport.Remove('outcome-reason')
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest "$outcome requires outcome-reason" $scenario.scoreArgs $false 'outcome-reason'
}
$scenario = New-TestScenario 'no-knowledge'
$scenario.result.guidanceReport.outcome = 'completed'
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'no-knowledge is not completed-empty' $scenario.scoreArgs $false 'expectedOutcome'
$scenario = New-TestScenario 'no-knowledge'
$scenario.result.guidanceReport.knowledge = @(@{ path = $article; 'used-for' = 'filler'; constraints = @('filler'); 'sample-paths' = @() })
$scenario.result.guidanceReport.summary.candidates = 1
$scenario.result.guidanceReport.summary.selected = 1
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'no-knowledge cannot contain filler knowledge' $scenario.scoreArgs $false 'requires empty knowledge'
Test-ReportMutation 'invalid outcome enum' { param($r) $r.guidanceReport.outcome = 'success' } 'outcome enum'
Test-ReportMutation 'missing report fields' { param($r) $r.guidanceReport.Remove('knowledge') } 'missing required field'
Test-ReportMutation 'null report object' { param($r) $r.guidanceReport = $null } 'JSON object'
Test-ReportMutation 'wrong skill version type' { param($r) $r.guidanceReport.skill.version = '1' } 'identity/version'
Test-ReportMutation 'wrong skill id type' { param($r) $r.guidanceReport.skill.id = @('al-development-plan') } 'non-empty string'
Test-ReportMutation 'wrong kind type' { param($r) $r.guidanceReport.summary.kind = @('bug') } 'non-empty string'
Test-ReportMutation 'wrong summary type' { param($r) $r.guidanceReport.summary = @() } 'JSON object'
Test-ReportMutation 'fractional count' { param($r) $r.guidanceReport.summary.candidates = 1.5 } 'non-negative integer'
Test-ReportMutation 'negative count' { param($r) $r.guidanceReport.summary.selected = -1 } 'non-negative integer'
Test-ReportMutation 'inconsistent selected count' { param($r) $r.guidanceReport.summary.selected = 0 } 'Summary counts'
Test-ReportMutation 'candidate count below selected' { param($r) $r.guidanceReport.summary.candidates = 0 } 'Summary counts'
Test-ReportMutation 'wrong context list type' { param($r) $r.guidanceReport.context.technologies = 'al' } 'JSON array'
Test-ReportMutation 'missing constraints' { param($r) $r.guidanceReport.knowledge[0].constraints = @() } 'must not be empty'
Test-ReportMutation 'non-string constraints' { param($r) $r.guidanceReport.knowledge[0].constraints = @(@{ body = 'MODEL_SECRET_SENTINEL' }) } 'non-empty string'
Test-ReportMutation 'missing sample array' { param($r) $r.guidanceReport.knowledge[0].Remove('sample-paths') } 'missing required field'
Test-ReportMutation 'duplicate knowledge' {
param($r)
$r.guidanceReport.knowledge += $r.guidanceReport.knowledge[0]
$r.guidanceReport.summary.selected = 2
$r.guidanceReport.summary.candidates = 2
} 'Duplicate knowledge'
Test-ReportMutation 'bad validation entry' { param($r) $r.guidanceReport.'validation-considerations'[0].evidence = $false } 'non-empty string'
Test-ReportMutation 'invalid suppression shape' { param($r) $r.guidanceReport.suppressed = @(@{ path = $article; reason = 'configuration' }) } 'missing required field'
Test-ReportMutation 'invalid unresolved shape' { param($r) $r.guidanceReport.unresolved = @(@{ candidate = $article }) } 'non-empty string'
Test-ReportMutation 'invalid SHA provenance' { param($r) $r.guidanceReport.knowledge[0].sha = '0' * 40 } 'recorded live checkout'
$scenario = New-TestScenario
$scenario.result.guidanceReport.knowledge[0].sha = Invoke-GuidanceGit $root @('rev-parse', 'HEAD')
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'actual pinned knowledge SHA accepted' $scenario.scoreArgs $true
foreach ($badPath in @('../outside.md', '/absolute.md', 'C:/external.md',
'microsoft\knowledge\performance\pair-findset-with-next-loop.md',
'microsoft/knowledge/performance/../performance/pair-findset-with-next-loop.md',
'https://example.invalid/article.md', 'microsoft/knowledge/performance/missing.md',
'microsoft/skills/development/al-development-plan.md')) {
$scenario = New-TestScenario
$scenario.result.guidanceReport.knowledge[0].path = $badPath
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'unsafe/nonexistent/non-knowledge citation rejected' $scenario.scoreArgs $false
}
foreach ($badSample in @('../outside.al', $article, $otherArticle.Replace('.md', '.good.al'), 'microsoft/knowledge/performance/other.good.al', 'microsoft\knowledge\performance\pair-findset-with-next-loop.good.al')) {
$scenario = New-TestScenario
$scenario.result.guidanceReport.knowledge[0].'sample-paths' = @($badSample)
Set-TestJson $scenario.resultPath $scenario.result
Invoke-EvaluatorTest 'unsafe/nonexistent/non-sibling sample rejected' $scenario.scoreArgs $false
}
foreach ($json in @('{', 'null', '[]', '{"caseId":"MODEL_SECRET_SENTINEL","caseId":"duplicate"}', '{"caseId":true,}', '// comment')) {
$scenario = New-TestScenario
[IO.File]::WriteAllText($scenario.resultPath, $json)
Invoke-EvaluatorTest 'malformed model result fails without runtime crash or content leakage' $scenario.scoreArgs $false
}
$scenario = New-TestScenario
$outside = Join-Path $scenario.directory 'outside'
[IO.Directory]::CreateDirectory($outside) | Out-Null
$link = Join-Path $scenario.workspace 'escape'
$linkKind = if ($IsWindows) { 'Junction' } else { 'SymbolicLink' }
New-Item -ItemType $linkKind -Path $link -Target $outside | Out-Null
try {
Invoke-EvaluatorTest 'target junction/symlink rejected instead of followed' $scenario.scoreArgs $false 'Links, junctions'
Invoke-EvaluatorTest 'baseline capture rejects junction/symlink target children' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-CaptureBaseline', '-WorkspaceMapPath', $scenario.mapPath, '-BaselinePath', (Join-Path $scenario.directory 'linked-baseline.json')) $false 'Links, junctions'
Invoke-EvaluatorTest 'prepared directory cannot escape through junction' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-PrepareDirectory', (Join-Path $link 'prepared'), '-WorkspaceMapPath', $scenario.mapPath) $false 'Links, junctions'
} finally { Remove-Item -LiteralPath $link -Force }
$scenario = New-TestScenario
$external = Join-Path $scenario.directory 'external.txt'
[IO.File]::WriteAllText($external, 'external hard-link target')
$hardLink = Join-Path $scenario.workspace 'hard-link.txt'
New-Item -ItemType HardLink -Path $hardLink -Target $external | Out-Null
try {
Invoke-EvaluatorTest 'hard-link escape rejected' $scenario.scoreArgs $false 'Links, junctions'
} finally { Remove-Item -LiteralPath $hardLink -Force }
$scenario = New-TestScenario
$externalArticle = Join-Path $scenario.directory 'outside.md'
[IO.File]::Copy((Join-Path $root $article.Replace('/', [IO.Path]::DirectorySeparatorChar)), $externalArticle)
$articleLink = Join-Path $root 'custom\knowledge\performance'
[IO.Directory]::CreateDirectory((Split-Path $articleLink -Parent)) | Out-Null
New-Item -ItemType $linkKind -Path $articleLink -Target $scenario.directory | Out-Null
try {
$rejected = $false
try { $null = Resolve-GuidanceReference $root 'custom/knowledge/performance/outside.md' -Knowledge }
catch { $rejected = $_.Exception.Message -match 'Links, junctions' }
if (-not $rejected) { throw 'Linked knowledge reference was followed.' }
$tests.Add('knowledge junction/symlink reference rejected')
$rejected = $false
try { $null = Resolve-GuidanceReference $root 'custom/knowledge/performance/pair-findset-with-next-loop.good.al' -Article 'custom/knowledge/performance/pair-findset-with-next-loop.md' }
catch { $rejected = $_.Exception.Message -match 'Links, junctions' }
if (-not $rejected) { throw 'Linked sample reference was followed.' }
$tests.Add('sample junction/symlink reference rejected')
} finally { Remove-Item -LiteralPath $articleLink -Force }
$normativePath = Join-Path $root 'microsoft\knowledge\performance\single-normative-section.md'
foreach ($heading in @('Best Practice', 'Anti Pattern')) {
[IO.File]::WriteAllText($normativePath, "---`ndomain: performance`n---`n## Description`nSynthetic contract fixture.`n## $heading`nSynthetic normative constraint.`n")
$null = Resolve-GuidanceReference $root 'microsoft/knowledge/performance/single-normative-section.md' -Knowledge
$tests.Add("Knowledge article with only $heading accepted")
}
[IO.File]::Delete($normativePath)
$scenario = New-TestScenario
$linkedRoot = Join-Path $scratch 'linked-knowledge-checkout'
Invoke-TestGit $root @('worktree', 'add', '--quiet', '--detach', $linkedRoot, 'HEAD')
$linkedBaseline = Join-Path $scenario.directory 'linked-root-baseline.json'
Invoke-EvaluatorTest 'linked knowledge checkout baseline capture' @('-Root', $linkedRoot, '-ManifestPath', $scenario.manifestPath, '-CaptureBaseline', '-WorkspaceMapPath', $scenario.mapPath, '-BaselinePath', $linkedBaseline) $true
Invoke-EvaluatorTest 'unchanged linked knowledge checkout scoring' @('-Root', $linkedRoot, '-ManifestPath', $scenario.manifestPath, '-ResultsDirectory', $scenario.results, '-BaselinePath', $linkedBaseline, '-BaselineSha256', (Get-GuidanceHash $linkedBaseline)) $true
$scenario = New-TestScenario
$map = Read-GuidanceJson $scenario.mapPath
$map['synthetic-case'] = $linkedRoot
Set-TestJson $scenario.mapPath $map
Invoke-EvaluatorTest 'linked target checkout rejected as external Git storage' @('-Root', $root, '-ManifestPath', $scenario.manifestPath, '-CaptureBaseline', '-WorkspaceMapPath', $scenario.mapPath, '-BaselinePath', (Join-Path $scenario.directory 'external-git-baseline.json')) $false 'standalone repositories'
$scenario = New-TestScenario
[IO.File]::AppendAllText((Join-Path $root $sample.Replace('/', [IO.Path]::DirectorySeparatorChar)), "`n// changed knowledge sample")
Invoke-EvaluatorTest 'knowledge checkout changes rejected' $scenario.scoreArgs $false 'Knowledge checkout identity/content changed'
Write-Host "Development guidance evaluator regressions PASSED: $($tests.Count) checks."
} finally {
if (Test-Path -LiteralPath $scratch) {
# Only our own uniquely named directory; links made by tests are removed above.
Remove-Item -LiteralPath $scratch -Recurse -Force
}
}
# Intentional negative native-command probes leave LASTEXITCODE nonzero.
exit 0

View file

@ -1,219 +0,0 @@
<#
.SYNOPSIS
Validates, prepares, and scores read-only AL development-guidance fixtures.
.DESCRIPTION
Capture runner-owned evidence BEFORE invoking an agent:
-CaptureBaseline -WorkspaceMapPath <json> -BaselinePath <new-json>
The workspace map is {"manifest-case-id":"absolute-standalone-git-root",...}.
Score AFTER the agent finishes:
-BaselinePath <json> -BaselineSha256 <runner-retained-digest> -ResultsDirectory <directory>
Preparation (-PrepareDirectory) is independent; supply -WorkspaceMapPath to
include runner-selected target paths. Never derive target paths from results.
Baseline, map, prepared requests, and results must be outside all targets and
the knowledge checkout. Keep the baseline runner-only; retain the printed
SHA256 and pass -BaselineSha256 when scoring to detect baseline tampering.
Capture never overwrites an existing baseline. The runner must protect this
script, the baseline/digest and its invocation from the agent.
This compares before/after evidence, NOT an OS sandbox or a write monitor.
It cannot detect reverted transient writes, prove that articles were opened,
or validate semantic faithfulness of prose. Files, directories, hashes,
stable metadata, Git HEAD/refs/index and ignored/untracked files are compared.
Links/reparse points, hard links, external Git storage in targets,
submodules and sparse checkouts are rejected rather than followed. Windows
alternate data streams are rejected except for the known endpoint-DLP
metadata stream `sec.endpointdlp`, which is ignored because endpoint
protection may add or refresh it asynchronously without changing file
content. Direct stream paths remain rejected. Run in quiescent repositories.
The knowledge checkout may itself be a linked Git worktree; its Git storage
identity is recorded explicitly.
#>
[CmdletBinding()]
param(
[string] $Root = (Join-Path $PSScriptRoot '..'),
[string] $ManifestPath,
[string] $PrepareDirectory,
[string] $ResultsDirectory,
[switch] $CaptureBaseline,
[string] $BaselinePath,
[string] $BaselineSha256,
[string] $WorkspaceMapPath
)
Set-StrictMode -Version Latest
$ErrorActionPreference = 'Stop'
. (Join-Path $PSScriptRoot 'DevelopmentGuidance.Evidence.ps1')
try {
if ($CaptureBaseline -and ($ResultsDirectory -or $PrepareDirectory)) {
throw 'CaptureBaseline is a separate pre-run operation.'
}
if (($CaptureBaseline -or $ResultsDirectory) -and -not $BaselinePath) {
throw 'Capture and scoring require BaselinePath.'
}
if ($ResultsDirectory -and -not $BaselineSha256) {
throw 'Scoring requires the runner-retained pre-run BaselineSha256.'
}
if ($CaptureBaseline -and -not $WorkspaceMapPath) {
throw 'Capture requires a runner-owned WorkspaceMapPath.'
}
if ($ResultsDirectory -and ($WorkspaceMapPath -or $PrepareDirectory)) {
throw 'Scoring uses only the recorded workspace map; run preparation separately.'
}
$Root = Get-GuidanceSafePath $Root -Directory
if (-not $ManifestPath) { $ManifestPath = Join-Path $Root 'evaluation\development-guidance-fixtures.json' }
$ManifestPath = Get-GuidanceSafePath $ManifestPath -File
$manifest = Read-GuidanceJson $ManifestPath
Assert-GuidanceManifest $manifest $Root
$caseIds = @($manifest.cases | ForEach-Object { $_.id })
$workspaces = [ordered]@{}
$baseline = $null
if ($WorkspaceMapPath) {
$WorkspaceMapPath = Get-GuidanceSafePath $WorkspaceMapPath -File
$map = Read-GuidanceJson $WorkspaceMapPath
Assert-GuidanceObject $map 'workspace map'
if ($map.Count -ne $caseIds.Count) { throw 'Workspace map must bind exactly every manifest case.' }
foreach ($id in $caseIds) {
Assert-GuidanceString $map[$id] 'workspace map value'
if (-not [IO.Path]::IsPathFullyQualified($map[$id])) { throw 'Workspace roots must be absolute.' }
$workspaces[$id] = Get-GuidanceSafePath $map[$id] -Directory
}
}
if ($ResultsDirectory) {
$BaselinePath = Get-GuidanceSafePath $BaselinePath -File
if ($BaselineSha256 -cnotmatch '^[0-9A-Fa-f]{64}$') {
throw 'BaselineSha256 must be a SHA256 digest.'
}
if ((Get-GuidanceHash $BaselinePath) -ne $BaselineSha256) {
throw 'Runner baseline digest mismatch.'
}
$baseline = Read-GuidanceJson $BaselinePath
Assert-GuidanceObject $baseline 'baseline' @('version', 'kind', 'root', 'manifestPath', 'manifestSha256', 'workspaces', 'rootSnapshot')
if ($baseline.version -ne 1 -or $baseline.kind -cne 'bcquality-guidance-runner-baseline') {
throw 'Unsupported runner baseline.'
}
if ($baseline.root -cne $Root -or $baseline.manifestPath -cne $ManifestPath -or
$baseline.manifestSha256 -ne (Get-GuidanceHash $ManifestPath)) {
throw 'Runner baseline does not match the knowledge root or manifest.'
}
Assert-GuidanceObject $baseline.workspaces 'baseline workspaces'
if ($baseline.workspaces.Count -ne $caseIds.Count) { throw 'Runner baseline case set mismatch.' }
foreach ($id in $caseIds) {
$entry = $baseline.workspaces[$id]
Assert-GuidanceObject $entry 'baseline workspace entry' @('caseId', 'root', 'snapshot')
if ($entry.caseId -cne (Get-GuidanceCaseId $id)) { throw 'Runner baseline case identity mismatch.' }
$workspaces[$id] = Get-GuidanceSafePath $entry.root -Directory
}
}
$protectedRoots = @($Root) + @($workspaces.Values)
for ($i = 0; $i -lt $protectedRoots.Count; $i++) {
for ($j = $i + 1; $j -lt $protectedRoots.Count; $j++) {
if ((Test-GuidanceWithin $protectedRoots[$i] $protectedRoots[$j]) -or
(Test-GuidanceWithin $protectedRoots[$j] $protectedRoots[$i])) {
throw 'Knowledge checkout and case workspaces must be distinct, non-overlapping roots.'
}
}
}
foreach ($artifact in @($BaselinePath, $WorkspaceMapPath, $PrepareDirectory, $ResultsDirectory)) {
if ($artifact) {
$safeArtifact = Get-GuidanceSafePath $artifact -AllowMissing
foreach ($protectedRoot in $protectedRoots) {
if (Test-GuidanceWithin $safeArtifact $protectedRoot) {
throw 'Runner artifacts must be outside target workspaces and the knowledge checkout.'
}
}
}
}
if ($CaptureBaseline) {
$BaselinePath = Get-GuidanceSafePath $BaselinePath -AllowMissing
if (Test-Path -LiteralPath $BaselinePath) { throw 'Baseline already exists; capture never overwrites evidence.' }
$snapshots = [ordered]@{}
foreach ($id in $caseIds) {
$snapshots[$id] = [ordered]@{
caseId = Get-GuidanceCaseId $id
root = $workspaces[$id]
snapshot = Get-GuidanceSnapshot $workspaces[$id] -Target
}
}
$record = [ordered]@{
kind = 'bcquality-guidance-runner-baseline'
version = 1
root = $Root
manifestPath = $ManifestPath
manifestSha256 = Get-GuidanceHash $ManifestPath
rootSnapshot = Get-GuidanceSnapshot $Root
workspaces = $snapshots
}
Write-GuidanceNewJson $BaselinePath $record
Write-Host "Guidance baseline captured. Runner SHA256: $(Get-GuidanceHash $BaselinePath)"
} elseif ($PrepareDirectory) {
$PrepareDirectory = Get-GuidanceSafePath $PrepareDirectory -AllowMissing
if ((Test-Path -LiteralPath $PrepareDirectory) -and
@(Get-ChildItem -LiteralPath $PrepareDirectory -Force).Count) {
throw 'PrepareDirectory must be new or empty; existing requests/evidence are never overwritten.'
}
[IO.Directory]::CreateDirectory($PrepareDirectory) | Out-Null
# The index builder walks recursively; reject linked corpus paths first.
Assert-GuidanceTree $Root
& (Join-Path $Root 'tools\Build-KnowledgeIndex.ps1') -BCQualityRoot $Root `
-IndexPath (Join-Path $PrepareDirectory 'knowledge-index.json') | Out-Null
$skillInstructions = [IO.File]::ReadAllText((Resolve-GuidanceReference $Root $manifest.skill))
foreach ($case in $manifest.cases) {
$modelId = Get-GuidanceCaseId $case.id
$request = [ordered]@{
protocol = 'Run the supplied read-only skill on the runner-assigned repository and existing plan. Return only caseId and guidanceReport. The runner captures evidence before invocation; do not capture or modify it. Do not create artifacts in the target or knowledge checkout.'
caseId = $modelId
skill = $manifest.skill
skillInstructions = $skillInstructions
knowledgeIndex = Join-Path $PrepareDirectory 'knowledge-index.json'
knowledgeRoot = $Root
'task-context' = [ordered]@{
goal = Get-GuidancePlanRequest $case.'development-plan'
'inputs-available' = @('development-plan', 'repository')
'bc-version' = $case.context.'bc-version'
technologies = $case.context.technologies
countries = $case.context.countries
'application-area' = $case.context.'application-area'
}
'development-plan' = $case.'development-plan'
resultSchema = Get-GuidanceResultSchema $modelId
}
if ($workspaces.Count) { $request.repository = $workspaces[$case.id] }
Write-GuidanceNewJson (Join-Path $PrepareDirectory "request-$modelId.json") $request
}
Write-Host "Development guidance preparation PASSED: $($caseIds.Count) case(s)."
} elseif ($ResultsDirectory) {
$ResultsDirectory = Get-GuidanceSafePath $ResultsDirectory -Directory
$failures = [Collections.Generic.List[string]]::new()
if (-not (Test-GuidanceSnapshotEqual $baseline.rootSnapshot (Get-GuidanceSnapshot $Root))) {
$failures.Add('Knowledge checkout identity/content changed after baseline capture.')
}
foreach ($case in $manifest.cases) {
$id = $case.id
try {
if (-not (Test-GuidanceSnapshotEqual $baseline.workspaces[$id].snapshot `
(Get-GuidanceSnapshot $workspaces[$id] -Target))) {
throw 'Target repository identity/content changed after baseline capture.'
}
$resultPath = Get-GuidanceSafePath (Join-Path $ResultsDirectory "result-$(Get-GuidanceCaseId $id).json") -File
$result = Read-GuidanceJson $resultPath
Assert-GuidanceResult $result $case $manifest $Root $workspaces[$id]
} catch {
# Only evaluator-authored diagnostics are printed, never model or file contents.
$failures.Add("${id}: $(Get-GuidanceDiagnostic $_)")
}
}
if ($failures.Count) {
Write-Host "Development guidance scoring FAILED ($($failures.Count) problem(s)):"
$failures | ForEach-Object { Write-Host " - $_" }
exit 1
}
Write-Host "Development guidance scoring PASSED: $($caseIds.Count) case(s)."
} else {
Write-Host "Development guidance fixture validation PASSED: $($caseIds.Count) case(s)."
}
} catch {
Write-Host "Development guidance FAILED: $(Get-GuidanceDiagnostic $_)"
exit 1
}