feat(869-c1): activation-capability probe (Part of #869)
Some checks failed
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/ci Pipeline was canceled

Part of #869

Mos (id-11) Gate-16 merge: independent 3-round APPROVE @c5a2bcc5, author id2 != approver id11, CI green wp1973.

Co-authored-by: jason.woltje <jason@diversecanvas.com>
Co-committed-by: jason.woltje <jason@diversecanvas.com>
This commit was merged in pull request #870.
This commit is contained in:
2026-07-23 17:14:57 +00:00
committed by Mos
parent 48fd1df28a
commit db90da347e
5 changed files with 535 additions and 2 deletions

View File

@@ -0,0 +1,41 @@
import { spawnSync } from 'node:child_process';
import { join } from 'node:path';
import { describe, expect, it } from 'vitest';
/**
* C-REGRESS (issue #869, Point-1) — proves the fail-closed gate is untouched
* by the C1 activation probe added alongside this test.
*
* `mutator-gate.py`'s fail-closed-on-absent-identity behavior is INTENTIONAL
* and TEST-LOCKED: #869 C1 gates the WIRING decision for enforcement (via
* `leaseEnforcementActivatable()`), it does not — and must not — touch the
* gate's own runtime denial behavior. This spec runs the two test-locked
* cases from `runtime_tools_unittest.py` directly (rather than merely
* re-asserting the same logic in TypeScript) so a regression in the actual
* Python gate is caught here too, not just documented in prose.
*/
const MUTATOR_GATE_DIR = new URL('.', import.meta.url).pathname;
const UNITTEST_FILE = join(MUTATOR_GATE_DIR, 'runtime_tools_unittest.py');
const LOCKED_TEST_CASES = [
'ExecutableEntrypointTest.test_gate_entrypoint_denies_when_identity_environment_is_absent',
'MutatorGateTest.test_environment_generation_and_request_failures_deny',
] as const;
describe('mutator-gate fail-closed behavior (C-REGRESS, unchanged by #869 C1)', () => {
it.each(LOCKED_TEST_CASES)('%s still passes', (testCase) => {
const result = spawnSync('python3', ['-m', 'unittest', `${moduleName()}.${testCase}`, '-v'], {
cwd: MUTATOR_GATE_DIR,
encoding: 'utf-8',
});
expect(result.status, `stderr:\n${result.stderr}`).toBe(0);
});
});
function moduleName(): string {
// runtime_tools_unittest.py, addressed as a bare module name for `python3 -m unittest`.
return UNITTEST_FILE.split('/').pop()!.replace(/\.py$/, '');
}