The Auditor Uses the Same Ruler as the Gate
An audit report accused eight documentation commits of missing trailers; all eight were false positives. One filter line aligned the auditor with the gate.
TL;DR
The audit flagged nineteen commits missing Security-review trailers, but eight were false positives on QA and doc paths the commit gate has always exempt. Root cause: the auditor didn't share the gate's exemption list, so two versions of one policy drifted apart. Fix is a one-line filter reusing the gate's constant, proven red-first by a selftest.
The audit run finished and printed nineteen findings: code commits missing a Security-review: trailer since the adoption date. Eight of them accused commits that only touched QA reports and screenshots. Technically the report was right, the trailers are absent. Policy-wise the report was wrong, because those paths have been exempt from the commit gate since day one. A trailer means a key-value pair with a colon separator at the tail of a commit message [2]; on documentation commits, the gate never asked for one in the first place.
This mismatch has a name: policy drift between the gate and its own auditor. The KotaPortal commit gate inspects a message only when at least one staged path falls outside its exemption list. Commits whose every changed file sits in documentation folders, project-management notes, or QA reports were never required to carry a trailer. The retroactive auditor had no such filter: it swept every commit on the code paths and flagged each missing trailer, including commits the gate itself does not classify as code. Eight of the nineteen findings were false positives, and the hidden cost goes further: every line still had to be opened one by one, compared against the policy, and dismissed. That is review labor paid for an empty conclusion. A report that is three-quarters wrong will not be read a second time, and the next sweep starts being treated as a routine that may be skipped.
Diagnosis: two rules for one policy
The root cause is not a parsing bug. It is two implementations running without a shared definition. The gate evaluates paths at commit time; the audit re-evaluates months of history later. Both speak a different language about who must be inspected. As long as the auditor does not read the same exemption list, it applies a stricter standard to non-code artifacts without anyone deciding so.
The one-line fix
The fix is a single line, inserted just before the trailer check inside the audit loop. Upstream of the loop, git log selects candidates since the adoption date and git log -1 --format=%B fetches each raw message body [3]. The new filter reads the paths each commit changed:
git show --name-only --format="" "$sha" | grep -qvE "$EXEMPT_RE" || continuegit show --name-only prints the list of files a commit touched, and an empty format string keeps metadata out of the output. The grep -qvE test succeeds only when at least one path falls outside the exemption pattern. If every path matches, the skip pattern at the end of the line moves on without checking the trailer. The exemption pattern is consumed straight from the same constant the gate uses, covering documentation folders, management notes, agent configuration, QA reports, and screenshots. One constant, two consumers; there is no room left for a second version of the policy.
Red first, then green
The change is proven by selftest case 18. The case plants a commit containing only a QA report, with no trailer, runs the audit, and asserts the commit does not appear in the findings. Before the filter landed, the suite ran red: seventeen passing, one failing. With the filter in, it runs fully green: eighteen passing, zero failing. The order matters. The test existed first and demonstrably failed before the fix, so the green that followed is evidence the filter works, not an assumption.
Detector precision is a feature
The general lesson is plain: an auditor must use the same exemption policy as the gate it audits. A preventive control stops violations before they happen; a detective control discovers and corrects events that already slipped through [4]. The detective side holds value on one condition only: every line it prints deserves action. False positives train readers to ignore the report, and trust that has gone is expensive to win back. When the auditor mirrors the gate's rules exactly, its reports stay short, rare, and always mean something needs fixing.