feat(869-c4): activation version-coupling assertion (Part of #869)
All checks were successful
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was successful

Part of #869

Mos (id-11) Gate-16 merge: independent APPROVE @90eb48fa (fail-closed identity locks byte-unchanged verified), author id2 != approver id11, clean mosaic-coder author, CI green wp1992. #869 Point-1 CODE COMPLETE (C1/C3/C5/C2/C4).

Co-authored-by: jason.woltje <jason@diversecanvas.com>
Co-committed-by: jason.woltje <jason@diversecanvas.com>
This commit was merged in pull request #881.
This commit is contained in:
2026-07-23 19:07:27 +00:00
committed by Mos
parent d351caad36
commit a32ce4c8f9
6 changed files with 543 additions and 1 deletions

View File

@@ -47,6 +47,22 @@ const piLifecyclePath = join(frameworkRoot, 'runtime/pi/lease-lifecycle.ts');
const prdyInitPath = join(frameworkRoot, 'tools/prdy/prdy-init.sh');
const prdyUpdatePath = join(frameworkRoot, 'tools/prdy/prdy-update.sh');
const remediationHandlerPath = join(frameworkRoot, 'tools/qa/remediation-hook-handler.sh');
// C4 (#869 Point-1): launch-runtime.py now asserts, before anything else,
// that the CLI's advertised lease-activation capability (normally read via
// the hidden `mosaic __lease-capability` subcommand) matches what
// enforcement expects — see framework/tools/lease-broker/
// activation_version_gate.py. This suite drives launch-runtime.py directly
// as a subprocess (never through the real `mosaic` CLI), so — exactly like
// the fake broker (daemon.py) and fake `claude` binaries already used
// below — it must supply a fake activation-capability probe rather than
// depend on a real `mosaic` binary being on PATH. `MOSAIC_LEASE_VERSION_PROBE_COMMAND`
// is launch-runtime.py's injection point for that fake; this literal
// {name, version} pair must be kept in sync with
// `EXPECTED_ACTIVATION_CAPABILITY` (activation_version_gate.py) and
// `LEASE_ACTIVATION_CAPABILITY` (lease-activation-probe.ts) — all three
// currently agree on v1.
const leaseCapabilityProbeStub = `python3 -c "import json; print(json.dumps({'name': 'lease-runtime-activation', 'version': 1}))"`;
const children: ChildProcess[] = [];
const temporaryRoots: string[] = [];
@@ -184,6 +200,7 @@ raise SystemExit(0 if len(session_id) == 64 and denied else 1)
MOSAIC_PRDY_RUNTIME: 'claude',
MOSAIC_LEASE_BROKER_SOCKET: socket,
MOSAIC_RUNTIME_GENERATION: '1',
MOSAIC_LEASE_VERSION_PROBE_COMMAND: leaseCapabilityProbeStub,
},
});
}
@@ -743,6 +760,7 @@ describe('whole mutator-class lease gate', () => {
...process.env,
MOSAIC_LEASE_BROKER_SOCKET: socket,
MOSAIC_RUNTIME_GENERATION: '1',
MOSAIC_LEASE_VERSION_PROBE_COMMAND: leaseCapabilityProbeStub,
},
},
);
@@ -761,6 +779,7 @@ describe('whole mutator-class lease gate', () => {
...process.env,
MOSAIC_LEASE_BROKER_SOCKET: join(tmpdir(), 'missing-mosaic-broker.sock'),
MOSAIC_RUNTIME_GENERATION: '1',
MOSAIC_LEASE_VERSION_PROBE_COMMAND: leaseCapabilityProbeStub,
},
},
);
@@ -878,6 +897,7 @@ raise SystemExit(0 if len(session_id) == 64 and hook_present and observers_prese
PATH: `${binDir}:${process.env.PATH ?? ''}`,
MOSAIC_LEASE_BROKER_SOCKET: socket,
MOSAIC_RUNTIME_GENERATION: '1',
MOSAIC_LEASE_VERSION_PROBE_COMMAND: leaseCapabilityProbeStub,
},
proxyGate: () =>
Promise.resolve({