Compare commits

..

3 Commits

Author SHA1 Message Date
ms-lead-reviewer
69092718d3 chore: prettier --write on tools/orchestrator/README.md (pre-existing drift)
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
Unrelated to the per-agent-identity feature in this branch. The repo's
format:check gate (which the pre-push hook runs across the whole tree) was
already failing against origin/main on this file before this branch existed;
fixing it here only because it otherwise blocks pushing this PR. No content
change — table alignment/spacing only.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 11:47:12 -05:00
ms-lead-reviewer
597b06e10d fix(tools/git): restore executable bit on new per-agent-identity scripts
core.filemode=false in this worktree meant the initial commit recorded
git-credential-mosaic, test-git-credential-mosaic.sh, and
test-gitea-token-identity.sh as 100644. git invokes a path-configured
credential.helper directly (exec, not `sh <path>`), so git-credential-mosaic
must carry the executable bit; the two test scripts match the 100755
convention already used by the other test-*.sh harnesses in this directory.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 11:44:43 -05:00
ms-lead-reviewer
9d2b12ca71 feat(tools/git): per-agent Gitea identity (git-credential-mosaic + get_gitea_token)
Adds an opt-in per-agent Gitea identity so a fleet agent can push/commit/open
PRs under its own token instead of the single shared account, giving
cryptographic author-!=-reviewer separation (Gate-16).

Resolution priority (both tools): MOSAIC_GIT_IDENTITY env > git config
mosaic.gitIdentity (per-worktree, persists on disk) > git-supplied username
(git-credential-mosaic only). If the resolved identity has a token file at
~/.config/mosaic/secrets/gitea-tokens/gitea-{usc,mosaicstack}-<id>.token, that
identity is used; otherwise both tools fall through to the existing
shared-account path unchanged, so this is a no-op on any host without
per-slot tokens configured.

- tools/git/git-credential-mosaic: new git credential helper (get verb).
- tools/git/detect-platform.sh: get_gitea_token() gains the same identity
  resolution, prepended ahead of the existing shared-token logic, so API
  tooling (pr-create.sh, issue-create.sh, ...) authors under the same
  identity as git push/fetch.
- install.sh: explicit chmod +x for git-credential-mosaic (it ships without
  a .sh suffix, so the existing *.sh glob does not cover it); tools/** is
  already framework-owned so the file syncs automatically.
- tools/git/README.md: documents the feature, the one-time
  `git config credential.helper` registration step (deliberately not
  auto-wired — see README for why), and the PowerShell-parity decision
  (detect-platform.ps1 authenticates via tea logins, not a raw-token
  function, so there is nothing to port there).
- tools/git/test-git-credential-mosaic.sh,
  tools/git/test-gitea-token-identity.sh: new regression harnesses (red
  verified against the pre-patch code) covering identity-resolution
  priority, per-host token path selection, and shared-account fallback.
  Wired into package.json's test:framework-shell.

Upstreams Mos host-local tooling-patch kit (2026-07-23), Patches 1+2.

Closes #873

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 11:43:11 -05:00
12 changed files with 442 additions and 536 deletions

View File

@@ -639,6 +639,10 @@ reconcile_framework_files
# Ensure tool scripts are executable
find "$TARGET_DIR/tools" -name "*.sh" -exec chmod +x {} + 2>/dev/null || true
find "$TARGET_DIR/tools/_scripts" -type f -exec chmod +x {} + 2>/dev/null || true
# git-credential-mosaic (per-agent Gitea identity helper) ships without a .sh
# suffix — git resolves credential helpers by exact name/path, not extension —
# so the *.sh glob above does not cover it; chmod it explicitly.
[[ -f "$TARGET_DIR/tools/git/git-credential-mosaic" ]] && chmod +x "$TARGET_DIR/tools/git/git-credential-mosaic" 2>/dev/null || true
ok "Framework synced to $TARGET_DIR"

View File

@@ -7,3 +7,64 @@ These scripts provide host-aware GitHub and Gitea issue, pull-request, milestone
A successful provider write command—or a wrapper message based only on that command's exit code—is **not** durable review provenance. Review comments count as durable provenance only after the wrapper reads the created provider record back and verifies that it belongs to the intended repository and pull request and contains the exact submitted body (or verifies the provider-returned record ID).
`pr-review.sh` therefore fails closed when a Gitea comment cannot be written, its created comment ID cannot be identified, or provider read-back does not match. It reports comment success only after that read-back verification passes.
## Per-agent Gitea identity (Gate-16 author≠reviewer)
By default, git push/fetch (via `git-credential-mosaic`) and the API wrappers above (via
`detect-platform.sh`'s `get_gitea_token`) all authenticate as the single shared Gitea
account/token configured through `tools/_lib/credentials.sh`. That means every agent in a
fleet commits, pushes, and opens PRs under one identity — with no cryptographic
separation between an author and a reviewer.
Both `git-credential-mosaic` and `get_gitea_token()` resolve an optional **per-agent
identity** before falling back to the shared account:
1. `MOSAIC_GIT_IDENTITY` environment variable, or
2. `git config --get mosaic.gitIdentity` (set per-worktree; persists on disk across
non-persistent shells — `git config mosaic.gitIdentity <agent-id>`), or
3. (git-credential-mosaic only) the username git itself supplies for the credential
request.
If the resolved identity has a token file at
`~/.config/mosaic/secrets/gitea-tokens/gitea-{usc,mosaicstack}-<agent-id>.token`, that
identity + token is used. **Nothing configured → nothing changes**: with no per-slot
token file present, both tools fall through to the existing shared-account path
unchanged, so this feature is a no-op on any host that hasn't provisioned per-slot
tokens.
### Enabling it for a clone
The framework installer syncs `git-credential-mosaic` to
`~/.config/mosaic/tools/git/git-credential-mosaic` (executable) on every install/update,
but does **not** register it as git's credential helper automatically. Registration is a
one-time, explicit step:
```bash
# Per-repo (recommended — scopes the helper to this clone only):
git config credential.helper "$HOME/.config/mosaic/tools/git/git-credential-mosaic"
# Per-worktree identity pin (Gate-16 separation):
git config mosaic.gitIdentity <agent-id>
```
This is deliberately **not** auto-registered on install/update: `credential.helper` is
global, order-sensitive git config (`~/.gitconfig`) that can already hold an
operator-chosen credential manager (keychain, `store`, `manager-core`, …) for
repositories unrelated to Mosaic. Silently inserting an entry on every framework
install/upgrade risks reordering or shadowing that operator-owned surface across the
whole host — the same operator-owned config the installer's manifest system is
otherwise careful never to touch. Because identity is already resolved per-worktree
(`mosaic.gitIdentity`), the correct granularity for registering the helper is per-clone
too, so a documented manual step is the right shape here, not a global auto-write.
### PowerShell parity
`detect-platform.ps1`'s Gitea wrappers authenticate through `tea` CLI logins
(`Get-GiteaLoginForHost`), not a raw-token `get_gitea_token`-equivalent function — there
is nothing to prepend the identity-resolution block to on the PowerShell side. A native
PowerShell git-credential helper is also unnecessary: `git-credential-mosaic` is invoked
by git's credential-helper protocol (stdin/stdout), which works identically under Git for
Windows' bundled `bash`/`sh` when configured via `credential.helper`, without a `.ps1`
counterpart. A `tea`-login-based per-agent identity for the PowerShell wrappers is a
separate, larger design (mapping identities to `tea login` profiles) and is out of scope
here.

View File

@@ -505,6 +505,28 @@ get_gitea_token() {
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
local cred_loader="$script_dir/../_lib/credentials.sh"
# 0. Per-agent identity (Gate-16 author≠reviewer). If MOSAIC_GIT_IDENTITY, or the
# per-worktree `git config mosaic.gitIdentity`, resolves to an agent that has a
# stored per-slot token for this host, act AS that agent so API tooling
# (pr-create, issue-create, …) authors under the right identity — matching the
# git credential helper. Backward-compatible: nothing resolvable → shared logic below.
local _ident="${MOSAIC_GIT_IDENTITY:-}"
[[ -z "$_ident" ]] && _ident="$(git config --get mosaic.gitIdentity 2>/dev/null || true)"
if [[ -n "$_ident" ]]; then
local _idpfx=""
case "$host" in
git.uscllc.com) _idpfx=gitea-usc ;;
git.mosaicstack.dev) _idpfx=gitea-mosaicstack ;;
esac
if [[ -n "$_idpfx" ]]; then
local _idtok="$HOME/.config/mosaic/secrets/gitea-tokens/${_idpfx}-${_ident}.token"
if [[ -r "$_idtok" ]]; then
cat "$_idtok"
return 0
fi
fi
fi
# 1. Mosaic credential loader (host → service mapping, run in subshell to avoid polluting env)
if [[ -f "$cred_loader" ]]; then
local token

View File

@@ -0,0 +1,69 @@
#!/bin/bash
# git-credential-mosaic — git credential helper — resolves Gitea tokens from
# the Mosaic credential store at runtime so remote URLs never embed secrets.
#
# Install (one-time, per clone or globally):
# git config credential.helper "$HOME/.config/mosaic/tools/git/git-credential-mosaic"
# # or, fleet-wide: git config --global credential.helper "$HOME/.config/mosaic/tools/git/git-credential-mosaic"
#
# Per-agent Gate-16 identity (author != reviewer separation):
# git config mosaic.gitIdentity <agent-id> # per-worktree, persists on disk
# # or: export MOSAIC_GIT_IDENTITY=<agent-id>
#
# Resolution priority: MOSAIC_GIT_IDENTITY env > git config mosaic.gitIdentity
# (per-worktree, survives across non-persistent shells) > git-supplied username
# (credential.username / URL). When the resolved identity has a matching
# per-agent token file, use it instead of the shared account. Backward
# compatible: nothing resolvable -> shared token (unchanged behavior).
[ "$1" = "get" ] || exit 0
host=""; username_in=""
while IFS= read -r line; do
[ -z "$line" ] && break
case "$line" in
host=*) host=${line#host=};;
username=*) username_in=${line#username=};;
esac
done
# Per-agent identity resolution (Gate-16 author≠reviewer separation).
# Priority: MOSAIC_GIT_IDENTITY env > git config mosaic.gitIdentity (per-worktree,
# survives across non-persistent shells) > git-supplied username (credential.username
# / URL). When the resolved identity has a matching per-agent token, use it instead of
# the shared account. Backward-compatible: nothing resolvable → shared token.
ident="$MOSAIC_GIT_IDENTITY"
[ -z "$ident" ] && ident=$(git config --get mosaic.gitIdentity 2>/dev/null)
[ -z "$ident" ] && ident="$username_in"
if [ -n "$ident" ]; then
case "$host" in
git.uscllc.com) idpfx=gitea-usc;;
git.mosaicstack.dev) idpfx=gitea-mosaicstack;;
*) idpfx="";;
esac
if [ -n "$idpfx" ]; then
idtok="$HOME/.config/mosaic/secrets/gitea-tokens/${idpfx}-${ident}.token"
if [ -r "$idtok" ]; then
echo "username=${ident}"
echo "password=$(cat "$idtok")"
exit 0
fi
fi
fi
case "$host" in
git.uscllc.com) svc=gitea-usc;;
git.mosaicstack.dev) svc=gitea-mosaicstack;;
*) exit 0;;
esac
# Script-relative (not $HOME-absolute) so this resolves correctly regardless
# of where the framework installer places tools/ under $HOME — mirrors
# detect-platform.sh's own cred_loader resolution in this same directory.
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# shellcheck source=../_lib/credentials.sh
source "$script_dir/../_lib/credentials.sh"
load_credentials "$svc" >/dev/null 2>&1 || exit 0
# GITEA_USER is not populated by load_credentials (it only exports
# GITEA_URL/GITEA_TOKEN for gitea-*), so this fallback is normally taken. Gitea's
# git-over-HTTP auth authenticates from the token itself (the password field),
# not from the username string, so any non-empty placeholder works here — this
# is deliberately NOT a real account name (framework files must stay
# operator-agnostic; see tools/quality/scripts/verify-sanitized.sh).
echo "username=${GITEA_USER:-git}"
echo "password=$GITEA_TOKEN"

View File

@@ -0,0 +1,161 @@
#!/usr/bin/env bash
# Regression harness for `git-credential-mosaic` — per-agent Gitea identity
# resolution (Gate-16 author≠reviewer separation).
#
# Covers:
# 1. Identity resolution priority: MOSAIC_GIT_IDENTITY env > git config
# mosaic.gitIdentity (per-worktree) > git-supplied username.
# 2. Correct per-slot token file path chosen per host
# (gitea-usc-<id>.token vs gitea-mosaicstack-<id>.token).
# 3. Per-slot token present -> emits that identity + token.
# 4. Per-slot token absent -> falls back to the shared account
# (backward-compat / no-op for hosts without per-slot tokens).
# 5. Unknown/unrelated host -> exits 0 with no output (passthrough).
#
# Uses stubbed token files under a fake HOME + a real (throwaway) git repo.
# NEVER reads real secrets or touches the real ~/.config/mosaic/secrets.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/git-credential-mosaic}"
FAKE_HOME="$WORK_DIR/home"
REPO_DIR="$WORK_DIR/repo"
# Mirror the real deployed layout (~/.config/mosaic/tools/{git,_lib}/) under the
# fake HOME: git-credential-mosaic resolves its credentials.sh sibling via a
# script-relative path (BASH_SOURCE), so the copy must live next to a stubbed
# _lib/credentials.sh, not the real one, to keep this test hermetic.
HELPER="$FAKE_HOME/.config/mosaic/tools/git/git-credential-mosaic"
rm -rf "$WORK_DIR"
mkdir -p "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens" \
"$FAKE_HOME/.config/mosaic/tools/git" \
"$FAKE_HOME/.config/mosaic/tools/_lib" \
"$REPO_DIR"
cp "$SCRIPT_DIR/git-credential-mosaic" "$HELPER"
chmod +x "$HELPER"
git -C "$REPO_DIR" init -q
git -C "$REPO_DIR" config user.email "test@example.invalid"
git -C "$REPO_DIR" config user.name "Test"
# Fake shared-account credential loader — stands in for
# tools/_lib/credentials.sh's load_credentials(), scoped to this test only.
cat > "$FAKE_HOME/.config/mosaic/tools/_lib/credentials.sh" <<'SH'
load_credentials() {
case "$1" in
gitea-mosaicstack) GITEA_URL="https://git.mosaicstack.dev"; GITEA_TOKEN="shared-mosaicstack-token"; export GITEA_URL GITEA_TOKEN; return 0 ;;
gitea-usc) GITEA_URL="https://git.uscllc.com"; GITEA_TOKEN="shared-usc-token"; export GITEA_URL GITEA_TOKEN; return 0 ;;
*) return 1 ;;
esac
}
SH
fail=0
assert_eq() {
local desc="$1" expected="$2" actual="$3"
if [[ "$expected" != "$actual" ]]; then
echo "FAIL: $desc — expected '$expected', got '$actual'" >&2
fail=1
fi
}
# Feed "host=<h>\nusername=<u>\n\n" on stdin (mirrors git's credential protocol)
# and run the helper with the fake HOME, inside REPO_DIR (so `git config
# mosaic.gitIdentity` resolves per-worktree), plus any extra env passed in $@.
run_helper() {
local host="$1" username_in="$2"; shift 2
(
cd "$REPO_DIR"
env -i HOME="$FAKE_HOME" PATH="$PATH" "$@" bash "$HELPER" get <<EOF
host=$host
username=$username_in
EOF
)
}
# ---------------------------------------------------------------------------
# 1. No identity resolvable anywhere, no per-slot token -> shared fallback
# (backward-compat: unchanged behavior when nothing is configured).
# ---------------------------------------------------------------------------
git -C "$REPO_DIR" config --unset mosaic.gitIdentity 2>/dev/null || true
out=$(run_helper "git.mosaicstack.dev" "")
assert_eq "shared fallback: username" "username=git" "$(echo "$out" | grep '^username=')"
assert_eq "shared fallback: password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
# ---------------------------------------------------------------------------
# 2. git-supplied username resolves to an identity WITH a per-slot token ->
# that identity + token wins over the shared account.
# ---------------------------------------------------------------------------
echo -n "agentA-mosaicstack-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentA.token"
out=$(run_helper "git.mosaicstack.dev" "agentA")
assert_eq "username-resolved identity: username" "username=agentA" "$(echo "$out" | grep '^username=')"
assert_eq "username-resolved identity: password" "password=agentA-mosaicstack-token" "$(echo "$out" | grep '^password=')"
# ---------------------------------------------------------------------------
# 3. git config mosaic.gitIdentity (per-worktree) beats git-supplied username.
# ---------------------------------------------------------------------------
echo -n "agentB-mosaicstack-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentB.token"
git -C "$REPO_DIR" config mosaic.gitIdentity agentB
out=$(run_helper "git.mosaicstack.dev" "agentA")
assert_eq "git-config beats username: username" "username=agentB" "$(echo "$out" | grep '^username=')"
assert_eq "git-config beats username: password" "password=agentB-mosaicstack-token" "$(echo "$out" | grep '^password=')"
# ---------------------------------------------------------------------------
# 4. MOSAIC_GIT_IDENTITY env beats git config mosaic.gitIdentity.
# ---------------------------------------------------------------------------
echo -n "agentC-mosaicstack-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentC.token"
out=$(run_helper "git.mosaicstack.dev" "agentA" MOSAIC_GIT_IDENTITY=agentC)
assert_eq "env beats git-config: username" "username=agentC" "$(echo "$out" | grep '^username=')"
assert_eq "env beats git-config: password" "password=agentC-mosaicstack-token" "$(echo "$out" | grep '^password=')"
git -C "$REPO_DIR" config --unset mosaic.gitIdentity
# ---------------------------------------------------------------------------
# 5. Identity resolves, but no matching per-slot token file -> falls back to
# the shared account (per-agent identity is opt-in, not a hard requirement).
# ---------------------------------------------------------------------------
out=$(run_helper "git.mosaicstack.dev" "no-such-agent")
assert_eq "no per-slot token: username" "username=git" "$(echo "$out" | grep '^username=')"
assert_eq "no per-slot token: password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
# ---------------------------------------------------------------------------
# 6. Correct per-slot token PATH is chosen per host: same agent id, different
# host prefix (gitea-usc- vs gitea-mosaicstack-).
# ---------------------------------------------------------------------------
echo -n "agentD-usc-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-usc-agentD.token"
out=$(run_helper "git.uscllc.com" "agentD")
assert_eq "host-scoped token path (usc): username" "username=agentD" "$(echo "$out" | grep '^username=')"
assert_eq "host-scoped token path (usc): password" "password=agentD-usc-token" "$(echo "$out" | grep '^password=')"
# agentD has NO mosaicstack token -> must fall back to shared mosaicstack, not
# leak the usc token across hosts.
out=$(run_helper "git.mosaicstack.dev" "agentD")
assert_eq "host-scoped token path (cross-host must not leak): username" "username=git" "$(echo "$out" | grep '^username=')"
assert_eq "host-scoped token path (cross-host must not leak): password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
# ---------------------------------------------------------------------------
# 7. Unrelated/unknown host -> exit 0, no output (passthrough for non-Gitea
# remotes, e.g. github.com via a different credential helper).
# ---------------------------------------------------------------------------
out=$(run_helper "github.com" "agentA")
assert_eq "unknown host: no output" "" "$out"
# ---------------------------------------------------------------------------
# 8. Non-"get" verb (store/erase) -> exit 0, no output (git-credential
# protocol: this helper only implements get).
# ---------------------------------------------------------------------------
store_out=$(cd "$REPO_DIR" && env -i HOME="$FAKE_HOME" PATH="$PATH" bash "$HELPER" store <<EOF
host=git.mosaicstack.dev
username=agentA
password=whatever
EOF
)
assert_eq "store verb: no output" "" "$store_out"
if [[ "$fail" -eq 0 ]]; then
echo "git-credential-mosaic identity resolution regression passed"
fi
exit "$fail"

View File

@@ -0,0 +1,122 @@
#!/usr/bin/env bash
# Regression harness for detect-platform.sh's get_gitea_token() per-agent
# identity resolution (Gate-16 author≠reviewer separation) — the API-tooling
# counterpart to git-credential-mosaic, so pr-create.sh/issue-create.sh/etc.
# open records under the resolved agent identity, not the shared account.
#
# Covers:
# 1. Identity resolution priority: MOSAIC_GIT_IDENTITY env > git config
# mosaic.gitIdentity (per-worktree).
# 2. Correct per-slot token file path chosen per host
# (gitea-usc-<id>.token vs gitea-mosaicstack-<id>.token).
# 3. Per-slot token present -> that token is returned (agent-authored calls).
# 4. Per-slot token absent -> falls back to the shared credential-loader
# token (backward-compat / no-op for hosts without per-slot tokens).
# 5. Unrelated host with no shared credentials configured -> failure
# (unchanged, existing behavior).
#
# Uses a stubbed credentials.json + stubbed per-slot token files under a fake
# HOME. NEVER reads real secrets or touches the real ~/.config/mosaic/secrets.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/gitea-token-identity}"
FAKE_HOME="$WORK_DIR/home"
REPO_DIR="$WORK_DIR/repo"
CREDENTIALS_FILE="$FAKE_HOME/.config/mosaic/credentials.json"
rm -rf "$WORK_DIR"
mkdir -p "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens" "$REPO_DIR"
git -C "$REPO_DIR" init -q
git -C "$REPO_DIR" remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git
cat > "$CREDENTIALS_FILE" <<'JSON'
{
"gitea": {
"mosaicstack": {
"url": "https://git.mosaicstack.dev",
"token": "shared-mosaicstack-token"
},
"usc": {
"url": "https://git.uscllc.com",
"token": "shared-usc-token"
}
}
}
JSON
fail=0
assert_eq() {
local desc="$1" expected="$2" actual="$3"
if [[ "$expected" != "$actual" ]]; then
echo "FAIL: $desc — expected '$expected', got '$actual'" >&2
fail=1
fi
}
# Runs get_gitea_token for $1=host inside REPO_DIR (per-worktree git config
# resolves there) with a fake HOME + the stub credentials.json, plus any
# extra env passed in $@.
call_get_gitea_token() {
local host="$1"; shift
(
cd "$REPO_DIR"
# shellcheck disable=SC2016 # deliberately deferred: $DETECT_PLATFORM_SH is
# expanded by the INNER bash -c (via the exported env var below), not here.
env -i HOME="$FAKE_HOME" PATH="$PATH" MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" \
DETECT_PLATFORM_SH="$SCRIPT_DIR/detect-platform.sh" "$@" \
bash -c 'source "$DETECT_PLATFORM_SH"; get_gitea_token "$1"' _ "$host"
)
}
# ---------------------------------------------------------------------------
# 1. No identity resolvable -> shared credential-loader token (unchanged).
# ---------------------------------------------------------------------------
git -C "$REPO_DIR" config --unset mosaic.gitIdentity 2>/dev/null || true
out=$(call_get_gitea_token "git.mosaicstack.dev")
assert_eq "shared fallback (no identity)" "shared-mosaicstack-token" "$out"
# ---------------------------------------------------------------------------
# 2. git config mosaic.gitIdentity resolves to an agent WITH a per-slot
# token -> that token wins over the shared account.
# ---------------------------------------------------------------------------
echo -n "agentA-mosaicstack-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentA.token"
git -C "$REPO_DIR" config mosaic.gitIdentity agentA
out=$(call_get_gitea_token "git.mosaicstack.dev")
assert_eq "git-config identity token" "agentA-mosaicstack-token" "$out"
# ---------------------------------------------------------------------------
# 3. MOSAIC_GIT_IDENTITY env beats git config mosaic.gitIdentity.
# ---------------------------------------------------------------------------
echo -n "agentB-mosaicstack-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentB.token"
out=$(call_get_gitea_token "git.mosaicstack.dev" MOSAIC_GIT_IDENTITY=agentB)
assert_eq "env beats git-config identity token" "agentB-mosaicstack-token" "$out"
# ---------------------------------------------------------------------------
# 4. Identity resolves but has no per-slot token for THIS host -> falls back
# to the shared token (per-agent identity is opt-in per host).
# ---------------------------------------------------------------------------
git -C "$REPO_DIR" config mosaic.gitIdentity no-such-agent
out=$(call_get_gitea_token "git.mosaicstack.dev")
assert_eq "no per-slot token falls back to shared" "shared-mosaicstack-token" "$out"
# ---------------------------------------------------------------------------
# 5. Correct per-slot token PATH per host: same agent id, only a usc token
# exists -> usc host returns it, mosaicstack host must NOT leak it and
# instead falls back to the shared mosaicstack token.
# ---------------------------------------------------------------------------
echo -n "agentD-usc-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-usc-agentD.token"
git -C "$REPO_DIR" config mosaic.gitIdentity agentD
out=$(call_get_gitea_token "git.uscllc.com")
assert_eq "host-scoped token path (usc)" "agentD-usc-token" "$out"
out=$(call_get_gitea_token "git.mosaicstack.dev")
assert_eq "host-scoped token path (no cross-host leak)" "shared-mosaicstack-token" "$out"
git -C "$REPO_DIR" config --unset mosaic.gitIdentity
if [[ "$fail" -eq 0 ]]; then
echo "get_gitea_token identity resolution regression passed"
fi
exit "$fail"

View File

@@ -25,7 +25,7 @@
"lint": "eslint src",
"typecheck": "tsc --noEmit",
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
"test:framework-shell": "python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh"
"test:framework-shell": "python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh"
},
"dependencies": {
"@mosaicstack/brain": "workspace:*",

View File

@@ -21,7 +21,6 @@ import { registerRestoreCommand } from './commands/restore.js';
import { registerSkillCommand } from './commands/skill.js';
// prdy is registered via launch.ts
import { registerLaunchCommands } from './commands/launch.js';
import { registerLeaseCapabilityProbe } from './commands/lease-activation-probe.js';
import { registerAuthCommand } from './commands/auth.js';
import { registerFederationCommand } from './commands/federation.js';
import { registerGatewayCommand } from './commands/gateway.js';
@@ -79,10 +78,6 @@ Command Groups:
registerLaunchCommands(program);
// ─── lease activation capability probe (hidden; #869 Point-1 C1) ────────
registerLeaseCapabilityProbe(program);
// ─── login ──────────────────────────────────────────────────────────────
program

View File

@@ -806,14 +806,7 @@ function launchRuntime(runtime: RuntimeName, args: string[], yolo: boolean): nev
process.exit(0); // Unreachable but satisfies never
}
/**
* Resolve the lease broker's control socket path. Exported (in addition to
* being used internally by execLeaseGatedRuntime) so the C1 activation probe
* (lease-activation-probe.ts) can perform the same resolution when checking
* whether the broker supervisor is reachable — detection only, this never
* connects to the socket itself.
*/
export function defaultLeaseBrokerSocket(env: NodeJS.ProcessEnv = process.env): string {
function defaultLeaseBrokerSocket(env: NodeJS.ProcessEnv = process.env): string {
if (env['MOSAIC_LEASE_BROKER_SOCKET']) return env['MOSAIC_LEASE_BROKER_SOCKET'];
const runtimeDir = env['XDG_RUNTIME_DIR'];
if (runtimeDir) return join(runtimeDir, 'mosaic-lease', 'broker.sock');
@@ -902,12 +895,7 @@ function delegateToScript(scriptPath: string, args: string[], env?: Record<strin
* bundled in the @mosaicstack/mosaic npm package (always matches the installed
* CLI version) over the deployed copy in ~/.config/mosaic/ (may be stale).
*/
/**
* Exported so the C1 activation probe (lease-activation-probe.ts) can resolve
* the same lease-broker launcher/daemon artifacts execLeaseGatedRuntime()
* uses, for detection-only supervisor presence checks.
*/
export function resolveTool(...segments: string[]): string {
function resolveTool(...segments: string[]): string {
try {
const req = createRequire(import.meta.url);
const mosaicPkg = dirname(req.resolve('@mosaicstack/mosaic/package.json'));

View File

@@ -1,243 +0,0 @@
import { describe, it, expect } from 'vitest';
import { Command } from 'commander';
import { existsSync, mkdtempSync, rmSync, writeFileSync } from 'node:fs';
import { dirname, join } from 'node:path';
import { tmpdir } from 'node:os';
import { fileURLToPath } from 'node:url';
import {
LEASE_ACTIVATION_CAPABILITY,
LEASE_CAPABILITY_PROBE_COMMAND,
defaultCapabilityProbe,
defaultResolveCliEntry,
defaultSupervisorProbe,
leaseEnforcementActivatable,
registerLeaseCapabilityProbe,
type LeaseActivationCapability,
type SupervisorProbeResult,
} from './lease-activation-probe.js';
/**
* Red-first tests for issue #869 Point-1 C1 — leaseEnforcementActivatable().
*
* Root cause under test: #828 shipped the lease broker's ENFORCEMENT half
* (hooks) and ACTIVATION half (execLeaseGatedRuntime + a running daemon.py
* broker) on different channels, and they drifted — the published CLI
* tarball lacked the activation half even though it existed in source. The
* predicate here must say NO when either half of activation is unavailable,
* and only YES when both are genuinely present — never based on "does the
* source file exist", but on a real capability signal + real supervisor
* detection.
*/
const compatibleCapability: LeaseActivationCapability = { ...LEASE_ACTIVATION_CAPABILITY };
const presentSupervisor: SupervisorProbeResult = {
supervisorPresent: true,
socketPath: '/run/user/1000/mosaic-lease/broker.sock',
};
describe('leaseEnforcementActivatable', () => {
it('is false when the activation capability is absent (null)', () => {
const result = leaseEnforcementActivatable({
getCapability: () => null,
probeSupervisor: () => presentSupervisor,
});
expect(result).toBe(false);
});
it('is false when the activation capability name does not match', () => {
const result = leaseEnforcementActivatable({
getCapability: () => ({
name: 'some-other-capability',
version: LEASE_ACTIVATION_CAPABILITY.version,
}),
probeSupervisor: () => presentSupervisor,
});
expect(result).toBe(false);
});
it('is false when the activation capability version is incompatible (stale/newer build)', () => {
const result = leaseEnforcementActivatable({
getCapability: () => ({
name: LEASE_ACTIVATION_CAPABILITY.name,
version: LEASE_ACTIVATION_CAPABILITY.version + 1,
}),
probeSupervisor: () => presentSupervisor,
});
expect(result).toBe(false);
});
it('is false when the supervisor artifacts (launcher/daemon) are not present', () => {
const result = leaseEnforcementActivatable({
getCapability: () => compatibleCapability,
probeSupervisor: () => ({
supervisorPresent: false,
socketPath: presentSupervisor.socketPath,
}),
});
expect(result).toBe(false);
});
it('is false when the supervisor socket path is not resolvable', () => {
const result = leaseEnforcementActivatable({
getCapability: () => compatibleCapability,
probeSupervisor: () => ({ supervisorPresent: true, socketPath: null }),
});
expect(result).toBe(false);
});
it('is false when BOTH capability and supervisor are absent', () => {
const result = leaseEnforcementActivatable({
getCapability: () => null,
probeSupervisor: () => ({ supervisorPresent: false, socketPath: null }),
});
expect(result).toBe(false);
});
it('is true when a compatible capability AND a resolvable supervisor are both present', () => {
const result = leaseEnforcementActivatable({
getCapability: () => compatibleCapability,
probeSupervisor: () => presentSupervisor,
});
expect(result).toBe(true);
});
it('uses the real default probes when no deps are injected (does not throw)', () => {
// No live broker / built CLI is guaranteed in a test environment, so this
// only asserts the predicate degrades to a safe boolean rather than
// throwing — the fail-closed behavior itself is covered by the injected
// cases above.
expect(() => leaseEnforcementActivatable()).not.toThrow();
expect(typeof leaseEnforcementActivatable()).toBe('boolean');
});
});
describe('defaultCapabilityProbe', () => {
it('returns null (fail-closed) when no built CLI artifact is resolvable', () => {
// Deterministic regardless of ambient host state (e.g. a host that has
// already run `pnpm build`, which would otherwise make this pass or fail
// depending on whether dist/cli.js happens to exist) — inject a resolver
// pointing at a path that cannot exist, rather than relying on this
// checkout being unbuilt. The probe must report "no capability" rather
// than fabricate one from source-tree presence — this is the exact
// distinction #828's version skew needed: source existing is not the
// same as the published artifact advertising the capability.
const result = defaultCapabilityProbe({
resolveCliEntry: () => '/nonexistent/mosaic-lease-activation-probe-test/cli.js',
});
expect(result).toBeNull();
});
describe('positive path — injected resolver, isolated scratch dir (never the real dist/)', () => {
// A prior version of this test staged the stub cli.js at the package's
// REAL resolved dist/ path and relied on afterEach to clean up "only
// what it created" — which meant a host with a real pre-built
// dist/cli.js (ordinary `pnpm build && pnpm test`) would have its real
// ~26KB compiled CLI silently overwritten by an 87-byte stub, with no
// restoration of the original content. That is exactly the kind of
// build-artifact corruption #869 exists to prevent. This version uses
// dependency injection exclusively: defaultCapabilityProbe() is never
// called with its default resolver here, so it can never touch the real
// package dist/ at all — proven below by asserting that path's
// existence is unchanged by the test.
it('returns the real {name, version} capability from a stub cli.js in a temp dir, and leaves the real dist/ untouched', () => {
const packageRoot = join(dirname(fileURLToPath(import.meta.url)), '..', '..');
const realDistDir = join(packageRoot, 'dist');
const realDistPreexisted = existsSync(realDistDir);
const scratchDir = mkdtempSync(join(tmpdir(), 'mosaic-lease-capability-probe-'));
try {
const scratchCliPath = join(scratchDir, 'cli.js');
// Minimal stand-in for the built CLI's hidden __lease-capability
// subcommand — prints exactly what registerLeaseCapabilityProbe()
// wires the real `mosaic __lease-capability` command to print.
writeFileSync(
scratchCliPath,
`process.stdout.write(JSON.stringify(${JSON.stringify(LEASE_ACTIVATION_CAPABILITY)}));\n`,
);
const result = defaultCapabilityProbe({ resolveCliEntry: () => scratchCliPath });
expect(result).toEqual(LEASE_ACTIVATION_CAPABILITY);
// The real package dist/ must be byte-for-byte untouched: this test
// never invokes the default resolver, so the path's mere existence
// (created or not) must be unchanged by having run this test.
expect(existsSync(realDistDir)).toBe(realDistPreexisted);
} finally {
rmSync(scratchDir, { recursive: true, force: true });
}
});
});
});
describe('defaultResolveCliEntry', () => {
it('resolves the bare "@mosaicstack/mosaic" specifier (the exported "." entry), never the non-exported "./package.json" subpath', () => {
// Fully isolated from the real filesystem/package state (no dependency
// on whether @mosaicstack/mosaic has been built on this host) via an
// injected fake resolver that mirrors Node's real behavior: the "."
// export resolves fine, but "./package.json" is NOT in package.json's
// `exports` map, so real `require.resolve` throws
// ERR_PACKAGE_PATH_NOT_EXPORTED for it. This is genuinely red-first
// against the reviewer-found bug: the old implementation resolved the
// "./package.json" subpath here, which this fake throws on — the new
// implementation must resolve only the bare specifier.
const requestedSpecifiers: string[] = [];
const fakeResolve = (specifier: string): string => {
requestedSpecifiers.push(specifier);
if (specifier === '@mosaicstack/mosaic') return '/fake/pkg/dist/index.js';
throw new Error(`ERR_PACKAGE_PATH_NOT_EXPORTED: ${specifier}`);
};
const result = defaultResolveCliEntry(fakeResolve);
expect(result).toBe(join('/fake/pkg/dist', 'cli.js'));
expect(requestedSpecifiers).toEqual(['@mosaicstack/mosaic']);
});
});
describe('defaultSupervisorProbe', () => {
it('returns a well-shaped result without starting or connecting to anything', () => {
const result = defaultSupervisorProbe({});
expect(typeof result.supervisorPresent).toBe('boolean');
expect(result.socketPath === null || typeof result.socketPath === 'string').toBe(true);
});
it('resolves a socket path from an explicit MOSAIC_LEASE_BROKER_SOCKET override', () => {
const result = defaultSupervisorProbe({ MOSAIC_LEASE_BROKER_SOCKET: '/tmp/explicit.sock' });
expect(result.socketPath).toBe('/tmp/explicit.sock');
});
});
describe('registerLeaseCapabilityProbe', () => {
it('registers a hidden subcommand named __lease-capability', () => {
const program = new Command();
program.exitOverride();
registerLeaseCapabilityProbe(program);
const registered = program.commands.find((c) => c.name() === LEASE_CAPABILITY_PROBE_COMMAND);
expect(registered).toBeDefined();
// Commander exposes "hidden" only as help-output suppression (no public
// getter) — assert the observable behavior instead of a private field.
expect(program.helpInformation()).not.toContain(LEASE_CAPABILITY_PROBE_COMMAND);
});
it('prints the capability constant as JSON when invoked', () => {
const program = new Command();
program.exitOverride();
registerLeaseCapabilityProbe(program);
let written = '';
const originalWrite = process.stdout.write.bind(process.stdout);
process.stdout.write = ((chunk: string) => {
written += chunk;
return true;
}) as typeof process.stdout.write;
try {
program.parse(['node', 'mosaic', LEASE_CAPABILITY_PROBE_COMMAND]);
} finally {
process.stdout.write = originalWrite;
}
expect(JSON.parse(written)).toEqual(LEASE_ACTIVATION_CAPABILITY);
});
});

View File

@@ -1,232 +0,0 @@
/**
* Lease-enforcement activation probe (issue #869, Point-1 card C1).
*
* Root cause this exists to guard against (#828 version skew): the
* ENFORCEMENT half of the lease broker (PreToolUse/Stop hooks —
* `mutator-gate.py`, `receipt-observer-client.py` — wired via the framework
* reseed) and the ACTIVATION half (`execLeaseGatedRuntime()` in `launch.ts`,
* which chains the runtime through `launch-runtime.py`, injects
* `MOSAIC_LEASE_*`, and requires a running `daemon.py` broker) ship on
* different channels. When the published CLI tarball lags behind an
* enforcement reseed, the gate correctly fails CLOSED on absent identity —
* but every tool call then denies with GATE_UNAVAILABLE. That fail-closed
* behavior is intentional and must not change (see the C-REGRESS note in
* `runtime_tools_unittest.py`); this module exists so a downstream
* install-ordering guard (C2, out of scope here) can refuse to WIRE
* enforcement in the first place on a host that cannot ACTIVATE it.
*
* `leaseEnforcementActivatable()` answers one narrow question: "if
* enforcement were wired right now, could activation actually satisfy it?"
* It is a real capability probe — not a "does the source file exist" check
* — and both of its inputs are injectable so tests can drive every branch
* without a live broker or an installed CLI on PATH.
*/
import { execFileSync } from 'node:child_process';
import { existsSync } from 'node:fs';
import { createRequire } from 'node:module';
import { dirname, join } from 'node:path';
import type { Command } from 'commander';
import { defaultLeaseBrokerSocket, resolveTool } from './launch.js';
// ─── Capability signal (owned by the activation half) ──────────────────────
/**
* Versioned identity for the activation contract `execLeaseGatedRuntime()`
* implements. OWNED by the activation half of the lease broker. Bump
* `version` only when the activation contract itself changes (env vars
* injected, chaining behavior, socket protocol, etc.) — deliberately
* independent of the package's npm semver, because #828 happened precisely
* because the npm version was NOT bumped even though the shipped artifact
* fell out of sync. A build that cannot advertise this exact
* `{ name, version }` pair does not implement the contract a caller is
* relying on, whatever its package.json claims.
*/
export interface LeaseActivationCapability {
readonly name: string;
readonly version: number;
}
export const LEASE_ACTIVATION_CAPABILITY: LeaseActivationCapability = {
name: 'lease-runtime-activation',
version: 1,
};
/** Hidden CLI probe subcommand name — wired via {@link registerLeaseCapabilityProbe}. */
export const LEASE_CAPABILITY_PROBE_COMMAND = '__lease-capability';
function capabilityMatches(candidate: LeaseActivationCapability | null): boolean {
return (
candidate !== null &&
candidate.name === LEASE_ACTIVATION_CAPABILITY.name &&
candidate.version === LEASE_ACTIVATION_CAPABILITY.version
);
}
/**
* Register the hidden `__lease-capability` probe subcommand. Prints the
* capability this BUILD advertises as compact JSON to stdout and exits 0.
* Deliberately undocumented (hidden from `--help`): it is an internal signal
* for {@link defaultCapabilityProbe}, not a user-facing command.
*/
export function registerLeaseCapabilityProbe(program: Command): void {
program
.command(LEASE_CAPABILITY_PROBE_COMMAND, { hidden: true })
.description('Internal: print the lease-activation capability this build advertises')
.action(() => {
process.stdout.write(JSON.stringify(LEASE_ACTIVATION_CAPABILITY));
});
}
/** Injectable Node module resolver — matches `require.resolve`'s signature
* narrowly (specifier in, absolute path out, or throws). Defaults to the
* real `createRequire(import.meta.url).resolve`. Injectable so tests can
* exercise WHICH specifier {@link defaultResolveCliEntry} resolves (the
* reviewer-found bug was resolving the wrong one) without depending on
* whether `@mosaicstack/mosaic` has actually been built on the test host —
* and without ever touching the real package's `dist/` to find out. */
export type ModuleResolver = (specifier: string) => string;
/**
* Resolve the CLI's built entrypoint (`dist/cli.js`). Resolves via the
* package's "." export (already present in package.json's `exports` map)
* rather than a "./package.json" subpath — the latter is NOT exported, so
* `require.resolve('@mosaicstack/mosaic/package.json')` throws
* ERR_PACKAGE_PATH_NOT_EXPORTED on every real install. The "." export
* resolves to `dist/index.js`; `cli.js` is its sibling in the same built
* `dist/` directory (see package.json's `bin.mosaic`).
*
* Exported standalone (and injectable via {@link CapabilityProbeDeps}) so
* tests can exercise this resolution logic in isolation, or point
* {@link defaultCapabilityProbe} at a scratch directory instead of ever
* touching the real installed package's `dist/` — a test corrupting a real
* build artifact is exactly the artifact-integrity failure class this card
* exists to prevent (#828).
*/
export function defaultResolveCliEntry(
resolve: ModuleResolver = createRequire(import.meta.url).resolve,
): string {
const mainEntry = resolve('@mosaicstack/mosaic');
return join(dirname(mainEntry), 'cli.js');
}
/** Injectable inputs for {@link defaultCapabilityProbe}. */
export interface CapabilityProbeDeps {
/** Resolve the CLI entrypoint (`cli.js`) to probe. Defaults to
* {@link defaultResolveCliEntry}. Inject to point at an isolated scratch
* location in tests — never at the real package's `dist/`. */
resolveCliEntry?: () => string;
}
/**
* Real capability lookup. Resolves the installed `@mosaicstack/mosaic`
* package's BUILT entrypoint (`dist/cli.js` — the published artifact a user
* actually runs, not this TypeScript source file) and executes its hidden
* `__lease-capability` probe subcommand out-of-process. A build that lacks
* the subcommand, fails to execute, or reports an incompatible
* `{ name, version }` is treated as having NO activation capability.
*
* This is the check that would have caught #828's version skew: the
* source-tree activation half existed, but the published tarball's `dist/`
* did not carry it, so this probe — reading the actually-resolvable built
* artifact rather than trusting source-tree presence — would report null.
*/
export function defaultCapabilityProbe(
deps: CapabilityProbeDeps = {},
): LeaseActivationCapability | null {
try {
const resolveCliEntry = deps.resolveCliEntry ?? defaultResolveCliEntry;
const cliEntry = resolveCliEntry();
if (!existsSync(cliEntry)) return null;
const output = execFileSync(process.execPath, [cliEntry, LEASE_CAPABILITY_PROBE_COMMAND], {
encoding: 'utf-8',
timeout: 2000,
stdio: ['ignore', 'pipe', 'ignore'],
});
const parsed: unknown = JSON.parse(output);
if (
typeof parsed !== 'object' ||
parsed === null ||
typeof (parsed as Record<string, unknown>)['name'] !== 'string' ||
typeof (parsed as Record<string, unknown>)['version'] !== 'number'
) {
return null;
}
const candidate = parsed as { name: string; version: number };
return { name: candidate.name, version: candidate.version };
} catch {
return null;
}
}
// ─── Supervisor / socket resolution (detection only) ───────────────────────
/** Detection-only supervisor/socket probe result. Never starts the broker
* and never connects to the socket — presence and path resolution only. */
export interface SupervisorProbeResult {
/** The lease-broker supervisor artifacts (launcher + daemon) are present. */
readonly supervisorPresent: boolean;
/** Resolved broker socket path, or null if it could not be resolved. */
readonly socketPath: string | null;
}
/**
* Real supervisor/socket resolution: checks that the lease-broker's launcher
* (`launch-runtime.py`) and supervisor (`daemon.py`) artifacts resolve on
* disk via the same tool-resolution `execLeaseGatedRuntime()` uses, and that
* a broker socket path resolves via the same logic as
* `defaultLeaseBrokerSocket()`. Detection only — this never starts the
* daemon and never connects to the socket.
*/
export function defaultSupervisorProbe(
env: NodeJS.ProcessEnv = process.env,
): SupervisorProbeResult {
const launcherPath = resolveTool('lease-broker', 'launch-runtime.py');
const daemonPath = resolveTool('lease-broker', 'daemon.py');
const supervisorPresent = existsSync(launcherPath) && existsSync(daemonPath);
let socketPath: string | null = null;
try {
const resolved = defaultLeaseBrokerSocket(env);
socketPath = resolved.trim().length > 0 ? resolved : null;
} catch {
socketPath = null;
}
return { supervisorPresent, socketPath };
}
// ─── Predicate ───────────────────────────────────────────────────────────
/** Injectable inputs for {@link leaseEnforcementActivatable}, so tests (and
* downstream callers such as the C2 install-ordering guard) can drive every
* branch without a live broker or an installed CLI on PATH. */
export interface ActivationProbeDeps {
getCapability?: () => LeaseActivationCapability | null;
probeSupervisor?: () => SupervisorProbeResult;
}
/**
* True IFF lease enforcement can actually be ACTIVATED on this host:
*
* (a) the resolvable CLI advertises a {@link LeaseActivationCapability}
* compatible with {@link LEASE_ACTIVATION_CAPABILITY}, AND
* (b) the broker supervisor is resolvable — launcher + `daemon.py`
* artifacts present AND a broker socket path resolves.
*
* Pure/testable: both probes default to the real, side-effect-free lookups
* above but can be injected, so this predicate never itself starts a broker
* or performs enforcement — it only reports whether activation *could*
* satisfy enforcement if wired.
*/
export function leaseEnforcementActivatable(deps: ActivationProbeDeps = {}): boolean {
const getCapability = deps.getCapability ?? defaultCapabilityProbe;
const probeSupervisor = deps.probeSupervisor ?? defaultSupervisorProbe;
if (!capabilityMatches(getCapability())) return false;
const supervisor = probeSupervisor();
return supervisor.supervisorPresent && supervisor.socketPath !== null;
}

View File

@@ -1,41 +0,0 @@
import { spawnSync } from 'node:child_process';
import { join } from 'node:path';
import { describe, expect, it } from 'vitest';
/**
* C-REGRESS (issue #869, Point-1) — proves the fail-closed gate is untouched
* by the C1 activation probe added alongside this test.
*
* `mutator-gate.py`'s fail-closed-on-absent-identity behavior is INTENTIONAL
* and TEST-LOCKED: #869 C1 gates the WIRING decision for enforcement (via
* `leaseEnforcementActivatable()`), it does not — and must not — touch the
* gate's own runtime denial behavior. This spec runs the two test-locked
* cases from `runtime_tools_unittest.py` directly (rather than merely
* re-asserting the same logic in TypeScript) so a regression in the actual
* Python gate is caught here too, not just documented in prose.
*/
const MUTATOR_GATE_DIR = new URL('.', import.meta.url).pathname;
const UNITTEST_FILE = join(MUTATOR_GATE_DIR, 'runtime_tools_unittest.py');
const LOCKED_TEST_CASES = [
'ExecutableEntrypointTest.test_gate_entrypoint_denies_when_identity_environment_is_absent',
'MutatorGateTest.test_environment_generation_and_request_failures_deny',
] as const;
describe('mutator-gate fail-closed behavior (C-REGRESS, unchanged by #869 C1)', () => {
it.each(LOCKED_TEST_CASES)('%s still passes', (testCase) => {
const result = spawnSync('python3', ['-m', 'unittest', `${moduleName()}.${testCase}`, '-v'], {
cwd: MUTATOR_GATE_DIR,
encoding: 'utf-8',
});
expect(result.status, `stderr:\n${result.stderr}`).toBe(0);
});
});
function moduleName(): string {
// runtime_tools_unittest.py, addressed as a bare module name for `python3 -m unittest`.
return UNITTEST_FILE.split('/').pop()!.replace(/\.py$/, '');
}