fix(ci): reject non-integer teardown exit codes

This commit is contained in:
2026-08-01 09:18:21 -05:00
parent 033b2ffb46
commit 6e7a336deb
4 changed files with 17 additions and 2 deletions
@@ -102,6 +102,7 @@ The nine-case contract harness was written before the verifier. First execution
- Blocker: the verifier echoed the pipeline commit but did not bind it to the current PR head; mutating only #2188's commit still returned terminal-green.
- Remediation: require `--expect-commit <full-40>`, add a pipeline anomaly on missing/mismatched record commits, emit expected and observed values, wire both CI documentation and the merge-gate baseline to pass provider PR head, and add match/missing/mismatch tests.
- This binding is not prohibited head-based clustering policy: it proves the evidence belongs to the commit under verdict. Runner/node/time/head correlation remains excluded from the teardown signature itself.
- Review 69 later approved the commit-binding remediation at exact head `033b2ffb46674b2c0bcc5197273c109b461f62d9`; pipeline #2193 was 9/9 success. Before merge-gate, an independent adjudicator found that Python treats JSON `false == 0`, allowing a non-integer exit value to match. The prior gate-ready state was withdrawn. A four-case red-first control (`false`, `0.0`, `"0"`, `null`) reproduced the over-match before implementation; remediation requires the decoded type to be exactly `int`.
## Documentation checklist