feat: convert --verify 對帳 + 修復 CRLF 使 hash 失準 + raw/** .gitattributes #1

Merged
yellowadmin merged 2 commits from feat/convert-verify-reconcile into main 2026-07-23 02:27:47 +00:00
2 changed files with 10 additions and 1 deletions
Showing only changes of commit d41cb49a45 - Show all commits

8
.gitattributes vendored Normal file
View File

@@ -0,0 +1,8 @@
# raw/ 是 hash 釘選的 provenance 帳本AGENTS.md §1.4 / §9 / §14
# git 一律不得正規化其換行,否則 checkout 後磁碟 bytes 會與 manifest 的
# SHA-256 不符,讓 --verify 對帳失準(本專案 core.autocrlf=true
# 轉換器已在寫入時以 write_bytes 固定為登記的那份 bytes此處把同樣的
# 保證延伸到 git 的 checkin/checkout。
raw/originals/** -text
raw/converted/** -text
raw/manifest.json -text

View File

@@ -28,7 +28,8 @@
SHA-256 至 `raw/manifest.json`(結構見 §9轉換檔條目必須回指原始檔 hash。 SHA-256 至 `raw/manifest.json`(結構見 §9轉換檔條目必須回指原始檔 hash。
wiki 頁面引用來源必須帶 `source_ref`(格式見 §3.3)。登記的 hash 必須等於檔案在 wiki 頁面引用來源必須帶 `source_ref`(格式見 §3.3)。登記的 hash 必須等於檔案在
磁碟上的實際 bytesUTF-8換行不轉換——轉換器一律以 write_bytes 寫入所登記的 磁碟上的實際 bytesUTF-8換行不轉換——轉換器一律以 write_bytes 寫入所登記的
那份 bytes不受平台 CRLF 影響);完整性以 §14 `--verify` 稽核。 那份 bytes不受平台 CRLF 影響git 亦以 `.gitattributes``raw/**` 關閉換行
正規化,避免 checkout 重新引入 CRLF完整性以 §14 `--verify` 稽核。
5. **HITL 閘門**:所有 wiki 層的變更以 git branch + PR 形式提交,經人工審核後才 5. **HITL 閘門**:所有 wiki 層的變更以 git branch + PR 形式提交,經人工審核後才
合併至 main。攝入腳本永遠不直接 commit 到 main。lint 絕不擅自刪檔,一律標記 合併至 main。攝入腳本永遠不直接 commit 到 main。lint 絕不擅自刪檔,一律標記
待人工核准。 待人工核准。