SIGN IN SIGN UP

fix(policy): report misspelled keys inside workflow.gates (GH #515 follow-up)

The unknown-key walker treated workflow.gates as a leaf, on the assumption that
the typed GateRule/GateSpec deserialisers reject bad shapes. GateSpec does, but
GateRule and ConditionalGate are serde(default) without deny_unknown_fields, so
a typo such as `require_al:` or `gat:` parsed fine and silently dropped the
gate, and neither the new stderr warning nor br doctor's policy.unknown_keys
named it. Descend into the free-form "from -> to" map, each rule, and each
require_if entry, reporting paths like
workflow.gates."in_review -> closed".require_if[1].gat.

Also refresh two doc comments that still said the notice is a tracing::warn!.

Test: detect_unknown_policy_fields_walks_workflow_gates (fails on the old
walker, which reported nothing for this document).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
J
Jeff Emanuel committed
565b43c8fd681031ab8ffd43c18d468170cdf8e8
Parent: c1b9343