R-502: the ISO first-boot harness is a gate, full runs only, "not checked" without docker

iso_bootstrap_gate.py runs scripts/iso/test/bootstrap-modes.sh in felhom-iso-assistant:trixie
(staged copy, read-only mount, --network none), registered fast=False in repo_gates.py so the
pre-push hook and CI (both --fast) never run it (decision 147). No docker / no image / docker
error -> exit 2 NOT CHECKED. Every green run is followed by a built-in decoy: the harness must
FAIL a bootstrap whose pairing banner never paints (R-496 shape), or the gate convicts the
instrument as blind. Docker-free decoys in test_iso_bootstrap_gate.py (fake docker on a
one-directory PATH), run from test_gate_decoys.py (COVERS).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-06 11:20:51 +02:00
parent 6b5804c63c
commit 9d39faabf8
4 changed files with 329 additions and 0 deletions
+7
View File
@@ -27,6 +27,8 @@ Gates, in order (all must pass; **non-zero exit on any failure**):
14b. stands where-felhom-stands.yaml: every claim cites a source that resolves, and every
'walked' cites a walk (R-819; it was red and ran in no runner)
15. script-tests every Python test suite under scripts/ (found by a walk), by exit code (R-885)
15b. iso-bootstrap the ISO first-boot harness in felhom-iso-assistant:trixie, with a built-in
decoy — FULL RUNS ONLY, "not checked" (exit 2) without docker (R-502, decision 147)
16. decoy-coverage every registered gate in all four repos has a decoy, or a named exemption (R-421)
**THE `GATES` TABLE BELOW IS THE LIST; THIS IS A POINTER TO IT.** It drifted once already —
@@ -162,6 +164,11 @@ GATES = [
# R-885 — the Python test suites under scripts/ (found by a walk) ran only by hand; a change that broke the
# 15 tests of the DooPlex hub-DB scripts, or the 73 of the instructions gate, reached main green. ~20 s.
("script-tests", os.path.join(SCRIPTS, "script_tests_gate.py"), [ROOT], True, False),
# R-502 — the ISO first-boot harness (scripts/iso/test/bootstrap-modes.sh) was run by no gate and was RED
# for two days unseen (R-586). It needs docker and an image, so it is fast=False: FULL RUNS ONLY, never
# the pre-push hook, never CI (operator ruling 2026-10-06, `09` §3 decision 147). Without docker or the
# image it says "not checked" and exits 2 — never a pass. Pinned by test_iso_bootstrap_gate.py.
("iso-bootstrap", os.path.join(SCRIPTS, "iso_bootstrap_gate.py"), [], False, False),
# R-421 — every registered gate across all four repos ships with a decoy test, or is
# named in the exemption list with its row. Registered LAST, after every runner was green:
# a failing gate refuses every push, which is what instructions_gate learned the hard way.