refactor(df): tidy policy fake and add verdict.Allowed constant

Follow-up review-feedback fix for the Dependency Firewall policy fake checker (code already merged to main).

Tidies internal/dependencyfirewall/policy/fake.go:

  • Rename deflt to defaultVerdict for clarity.
  • Read only the three GLAB_DF_FAKE_* keys the fake checker needs via a small lookupEnv helper, instead of copying the whole environment into a map. lookupEnv scans with slices.Backward so a duplicate key resolves to its last occurrence, preserving the old map's last-occurrence-wins semantics (matching os.Environ).
  • Use the verdict.Allowed constant instead of a bare empty string.
  • Add a test pinning the duplicate-key last-occurrence behavior.

Scope note: the original review batch also included adding the verdict.Allowed constant and marking the cilog tests parallel. Both of those already landed on main independently, so after rebasing this MR onto current main only the fake-checker tidy-up remains.

Testing

  • go build ./...
  • go test ./internal/dependencyfirewall/...
Edited by Michael Eddington

Merge request reports

Loading
Loading