Live smoke exposed a self-pollution bug (pre-existing from PR #17): the post-build denied-path check wrote its own _build_diff_z.bin / _build_status_z.bin into the working tree, then its own `git status --untracked-files=all` flagged them as out-of-scope writes — failing any run with a narrow declared_scope (the smoke's docs/**). Write them to $RUNNER_TEMP instead (read via $_DIFF_Z/$_STATUS_Z), so the check no longer sees its own temp files. The agent-team pytest artifacts were already correctly gitignored; only the check's own files tripped it. Test harness updated to pass the env paths. 1044 tests, ruff clean. |
||
|---|---|---|
| .. | ||
| workflows | ||
| dependabot.yml | ||