diff --git a/docs/BRD_IMPLEMENTATION_AUDIT.md b/docs/BRD_IMPLEMENTATION_AUDIT.md index b4a277ef..ef14bf81 100644 --- a/docs/BRD_IMPLEMENTATION_AUDIT.md +++ b/docs/BRD_IMPLEMENTATION_AUDIT.md @@ -311,3 +311,4 @@ - 2026-07-14 BRD 生产迁移回归固化:新增 `scripts/tests/aihr-schema-migrations.test.sh`,在临时 MySQL 库验证 SOP 主体/版本字段和组织入职日期迁移面对旧表、缺前置表时可安全执行且重复执行幂等;不写入开发库业务数据。 - 2026-07-14 BRD 生产迁移回归扩展:同一临时 MySQL 回归测试同时连续执行 `aihr_20260714_practice_evidence_mysql8.sql`,确认 `aihr_practice_audio` 与 `aihr_practice_calibration` 两张证据表可重复创建;不写入开发库业务数据。 - 2026-07-14 BRD 当前开发库审查快照:生活顾问启用场景 `12`、校准记录 `20`、已评审 SOP `2`,但住宅 SOP 文档仅 `3/5`、已入库案例 `2/20`,在职组织快照 `3001` 条中手机号可映射仅 `1` 条;这些数据不能作为正式试点通过,下一步优先补内容负责人确认的核心流程素材和正式组织身份映射,不用烟测记录替代。 +- 2026-07-14 BRD 严格门禁绕过修复:`AIHR_DEMO_CHECK_LIBRARY_ONLY=true` 仅允许测试加载脚本函数,和 `AIHR_PILOT_STRICT=true` 同时使用时现在直接失败,避免调试开关把正式试点检查静默跳过;新增回归断言,未修改业务数据。 diff --git a/scripts/demo-check.sh b/scripts/demo-check.sh index 68f75471..1b1325fd 100755 --- a/scripts/demo-check.sh +++ b/scripts/demo-check.sh @@ -325,6 +325,7 @@ check_pilot_samples() { } if [[ "${AIHR_DEMO_CHECK_LIBRARY_ONLY:-false}" == "true" ]]; then + [[ "${AIHR_PILOT_STRICT:-false}" != "true" ]] || fail "AIHR_DEMO_CHECK_LIBRARY_ONLY cannot bypass strict pilot checks" return 0 2>/dev/null || exit 0 fi diff --git a/scripts/tests/demo-check-pilot-gates.test.sh b/scripts/tests/demo-check-pilot-gates.test.sh index bbf1691b..69055fd0 100755 --- a/scripts/tests/demo-check-pilot-gates.test.sh +++ b/scripts/tests/demo-check-pilot-gates.test.sh @@ -32,6 +32,15 @@ assert_contains 'reviewed_time >=' assert_not_contains 'p.identity_key = o.ext_party_id OR p.identity_key = o.person_phone' assert_not_contains 's.ext_party_id = o.ext_party_id OR s.ext_party_id = o.person_phone' +if (AIHR_DEMO_CHECK_LIBRARY_ONLY=true AIHR_PILOT_STRICT=true "$SCRIPT") >/tmp/wygj-pilot-library-strict.log 2>&1; then + echo "FAIL: library-only mode bypassed strict pilot checks" >&2 + exit 1 +fi +grep -Fq 'AIHR_DEMO_CHECK_LIBRARY_ONLY cannot bypass strict pilot checks' /tmp/wygj-pilot-library-strict.log || { + echo "FAIL: library-only strict guard is unclear" >&2 + exit 1 +} + if ! command -v docker >/dev/null || ! docker ps --format '{{.Names}}' | grep -qx 'wygj-mysql'; then echo "SKIP: behavioral pilot gate test requires wygj-mysql" exit 0