linux observer

close the spl pin guard gaps the audit found master

The root workspace entry now rejects a path route, so a local override is caught in every manifest rather than only in members. The exact-version coverage the old policy test carried is restored as a derived property: each workspace declaration must carry a version and it must equal the resolved lockfile version, with no literal version in guard or test code. The inherited-exactly-once requirement is now stated over the workspace instead of a hardcoded consumer manifest path. Source-replacement and TOML-parse diagnostics now name what the guard actually checks: the Cargo configuration route and the specific file, rather than claiming a package-specific effect the guard does not establish. The wrong-query and wrong-fragment fixtures now derive a different revision dynamically instead of assuming the pin is never forty a characters. The suite now has 29 fixture cases. make ci is green, and the pinned revision and lockfile are unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>


+174 -44
2 changed files