Payload/scripts/kaden/harness/harness-prove-copilot-hook-coverage.ps1

#Requires -Version 5.1
<#
.SYNOPSIS
    Prove which Copilot gate-file edit envelopes reach preToolUse and are denied.

.DESCRIPTION
    Replays fixture envelopes through harness-pretooluse-guard.ps1 (same port Copilot hooks use).
    Supported edit envelopes must return deny. Unsupported families are marked fallback_required
    so the harness does not claim hook coverage it cannot prove.

    Optional -DogfoodChecklistPath writes an operator checklist for live wsl-sandbox Copilot dogfood.
    Live dogfood evidence is operator-owned; this script never invents a live PASS.

.EXAMPLE
    pwsh -File scripts/kaden/harness-invoke.ps1 harness-prove-copilot-hook-coverage.ps1 -OutPath docs\harness\features\harness-event-journal\quality\copilot-hook-coverage-proof.json
#>

[CmdletBinding()]
param(
    [string]$RepoRoot = '',
    [string]$FixturePath = '',
    [string]$OutPath = '',
    [string]$DogfoodChecklistPath = '',
    [switch]$RequireHooksTemplate
)

Set-StrictMode -Version Latest
$ErrorActionPreference = 'Stop'

Import-Module (Join-Path $PSScriptRoot 'lib\HarnessContract.psm1') -Force

if ([string]::IsNullOrWhiteSpace($RepoRoot)) {
    $RepoRoot = Get-HarnessRepoRoot -StartPath $PSScriptRoot
}

$result = Invoke-HarnessCopilotHookCoverageProof `
    -RepoRoot $RepoRoot `
    -FixturePath $FixturePath `
    -RequireHooksTemplate:$RequireHooksTemplate

$json = ($result | ConvertTo-Json -Depth 12) + [Environment]::NewLine
if (-not [string]::IsNullOrWhiteSpace($OutPath)) {
    $fullOut = if ([System.IO.Path]::IsPathRooted($OutPath)) { $OutPath } else { Join-Path $RepoRoot $OutPath }
    $fullDir = Split-Path -Parent $fullOut
    if (-not (Test-Path -LiteralPath $fullDir)) {
        New-Item -ItemType Directory -Path $fullDir -Force | Out-Null
    }
    [System.IO.File]::WriteAllText($fullOut, $json)
    Write-Output "Wrote coverage proof: $fullOut"
}
else {
    Write-Output $json.TrimEnd()
}

if (-not [string]::IsNullOrWhiteSpace($DogfoodChecklistPath)) {
    $checklistFull = if ([System.IO.Path]::IsPathRooted($DogfoodChecklistPath)) {
        $DogfoodChecklistPath
    }
    else {
        Join-Path $RepoRoot $DogfoodChecklistPath
    }
    $checkDir = Split-Path -Parent $checklistFull
    if (-not (Test-Path -LiteralPath $checkDir)) {
        New-Item -ItemType Directory -Path $checkDir -Force | Out-Null
    }
    $checklist = @'
# Copilot hook coverage dogfood - wsl-sandbox

**Status:** LIVE_DOGFOOD_PENDING (operator-owned)
**Fixture proof:** automated envelopes in this repo (see coverage proof JSON)
**Target host:** GitHub Copilot with templates/copilot-hooks.json installed via setup-harness-hooks.ps1

## Checklist

1. Fresh feature/slice under the product dogfood slug (wsl-sandbox preferred).
2. With an open ownership turn, attempt a direct Copilot edit to .review-loop.json.
3. Expect preToolUse deny or later DIRECT_GATE_FILE_MUTATION / closeout block.
4. Attempt a direct edit to journal/events.jsonl - same expectation.
5. Paste outcomes into a dated evidence note under the feature quality/ folder.
6. Retro must not show dark projection clerking.

Do not mark this checklist PASS until a live Copilot session records deny or fallback catch.
'@

    [System.IO.File]::WriteAllText($checklistFull, $checklist + [Environment]::NewLine)
    Write-Output "Wrote dogfood checklist: $checklistFull"
}

if (-not [bool]$result.ok) {
    exit 1
}
exit 0