4.5 KiB
#1182 — fail closed when a wrong answer is read as no answer
Objective
Implement FL-07 through FL-10 as one narrow fail-closed change: explicit invalid runtime/storage enum values and launcher failures must never be interpreted as absence or success.
Tracking
- Issue: #1182 (child of #1156; W-F1 prerequisite)
- Branch:
fix/1182-fail-closed-launch - Verified base:
origin/nextat216cd72226cd9ee17eea461cfe7cd0e010a22f02
Scope and fence
- Gateway chat runtime enum resolution and focused tests.
- Config storage-tier enum resolution and focused tests.
- Mosaic launcher spawn/provenance failure handling and focused integration/anti-drift tests.
- Narrow operator documentation in
packages/mosaic/README.mdif required by the behavior change. - Preserve the #1109 lease broker without refactor; do not implement W-F1 composition.
- Do not touch #1178, #1179, #1072, #1080, #1054,
docs/TASKS.md, or unrelated source/docs.
Plan
- RED: add one independent negative control per FL finding plus exact anti-drift checks.
- Pause and report BASE / BRANCH / FENCE / SPLIT / RED to the coordinator.
- After coordinator confirmation, implement each minimal fail-closed fix and verify each negative control independently.
- Run affected package and repository test/typecheck/lint/build/format gates, focused security review, then commit/push/PR for independent exact-head verification.
Split assessment
One PR remains reviewable: three narrowly bounded decision boundaries, no shared abstraction, no lease-broker refactor, and four independent tests naming the single defect class. Splitting would separate the same fail-closed invariant without reducing implementation coupling. If RED reveals material launcher harness expansion, split before production edits; the Gateway config half is the direct W-F1 selection prerequisite and would gate first.
Budget
No explicit token or monetary cap supplied. Keep scope to the three production files, focused tests, this scratchpad, and one existing README.
Progress
- Issue #1182 and parent #1156 read directly through Mosaic wrappers.
- Base derived from issue dependency plus repository topology: FL-07 exists on
origin/next(introduced by #1172) and is absent fromorigin/main; branch reset before edits to the exactorigin/nexthead above.
Verification evidence
- RED observed independently for FL-07 through FL-10 before implementation.
- Focused GREEN: Gateway runtime 4/4, config 5/5, launcher 6/6.
- Four final per-finding production reverts discriminated: FL-07 made only FL-07 red; FL-08 made its unit and real Gateway boundary controls red after rebuilding config; FL-09 made only its abnormal-spawn controls red; FL-10 made all three provenance controls (
opencode,claudex, andyolo claudex) red while sibling findings stayed green. - Public config export negative control: removing only the
packages/config/src/index.tsexport caused TS2305 andMosaicConfigEnvironmentError is not a constructor; restoring it passed 5/5. - Gateway full package: 74 files passed, 7 skipped; 829 tests passed, 17 skipped.
- Config full test/typecheck/lint/build: green.
- Mosaic typecheck/lint/build: green. Vitest is qualified-red only on the exact three update-notice stderr assertions tracked by #1190 — bare
--source, bare--decisions, and bare--observations; 1528 other tests pass. - The separate
test:framework-shellcommand is red and is not attributed to #1190:invariant_r_unittest.pyreports the host Pi runtime changed from measured 0.84.1 to 0.80.7. A clean archive oforigin/next@216cd722reproduces the same single failure. The base test hardcodes the W-B measurement asPI_VERSION = "0.84.1", then resolvespiviashutil.whichand executes--version; on this host that is/home/hermes/.npm-global/bin/pi, whose global package reports 0.80.7. Issue #1191 tracks the immediate host drift and hardcoded-version design defect; #1184 tracks pinning/approving native Pi 0.84.1. No related source or test is changed here. - Repository typecheck/lint/format/build: green.
- Codex security review: no findings. Initial code-review blocker (claudex provenance bypass) remediated with normal/yolo claudex coverage; subsequent public-export finding remediated.
Risks / blockers
- Coordinated branch: no merge authority; coordinator routes independent exact-head verification.
- #1179 currently owns
apps/gateway/src/__tests__/required-security-wiring.test.ts; this change does not touch it. - #1190 independently tracks the pre-existing CLI smoke/update-notice stderr collision; no #1190 source or test is included here.