All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
Part of #869 (Point-1 C4). Locks the lease broker's ENFORCEMENT half (launch-runtime.py) and ACTIVATION half (execLeaseGatedRuntime, C1's LEASE_ACTIVATION_CAPABILITY) as one versioned unit, closing the #828 version-skew gap C1 only made observable. - New packages/mosaic/framework/tools/lease-broker/activation_version_gate.py: EXPECTED_ACTIVATION_CAPABILITY (enforcement-owned, mirrors but is independent from C1's LEASE_ACTIVATION_CAPABILITY), a fail-closed subprocess probe of the CLI's hidden `mosaic __lease-capability` command, and an assertion that FAILS LOUD (VersionCouplingError with an actionable #869 remediation message) on mismatch OR absence — never a silent pass, never a dead gate. - launch-runtime.py now runs this assertion first, before any broker registration, and denies with a dedicated exit code (65) distinct from its existing usage (64) and registration-failure (1) codes. - Red-first tests: src/mutator-gate/version_coupling_unittest.py (module-level match/mismatch/name-mismatch/absent-capability cases, and seam-level LAUNCHER.main() cases proving the gate runs before broker registration and never silently passes). - Existing fail-closed-on-absent-identity lock (runtime_tools_unittest.py) stays green: matching-capability fakes were injected into its pre-existing LAUNCHER.main() calls so the new gate runs alongside, not in place of, identity enforcement. - mutator-gate.acceptance.spec.ts updated to supply a fake CLI-capability probe (matching the existing fake-broker/fake-runtime-binary test doubles already in that suite) everywhere it drives launch-runtime.py as a real subprocess. launch.ts and lease-activation-probe.ts are untouched (C2/C5 avoidance, C1 read-only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2.9 KiB
2.9 KiB