R-502: the ISO first-boot harness is a gate, full runs only, "not checked" without docker
iso_bootstrap_gate.py runs scripts/iso/test/bootstrap-modes.sh in felhom-iso-assistant:trixie (staged copy, read-only mount, --network none), registered fast=False in repo_gates.py so the pre-push hook and CI (both --fast) never run it (decision 147). No docker / no image / docker error -> exit 2 NOT CHECKED. Every green run is followed by a built-in decoy: the harness must FAIL a bootstrap whose pairing banner never paints (R-496 shape), or the gate convicts the instrument as blind. Docker-free decoys in test_iso_bootstrap_gate.py (fake docker on a one-directory PATH), run from test_gate_decoys.py (COVERS). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -53,6 +53,11 @@ COVERS = {
|
||||
"(2026-10-03) an old-shape row under the new header, a near-miss category, an "
|
||||
"old rank tag as Sev, an undefined state word, and a pipe outside backticks"),
|
||||
"decoy-coverage": "a gate registered in a runner with no decoy and no exemption (its red-proof)",
|
||||
"iso-bootstrap": ("R-502: SIX decoys + the genuine article in scripts/test_iso_bootstrap_gate.py, run from here, docker-free (a "
|
||||
"fake docker on a one-directory PATH): a BLIND harness that passes a bootstrap whose "
|
||||
"pairing banner never paints (the R-496 shape), a failing harness, the pass line with no "
|
||||
"checks behind it, and no docker / no image / a docker error, each 'not checked' (exit 2); "
|
||||
"the gate also plants that broken banner itself in the real container on every full run"),
|
||||
"instructions": "R-426: a version literal in a CLAUDE.md's effective text; the same in an HTML comment must pass",
|
||||
"wire-contract": ("R-555: an emitted tag whose name the receiver carries ONLY in a // and a /* */ comment "
|
||||
"must convict (it passed for months as `language` did); the genuine article — the same "
|
||||
@@ -455,6 +460,19 @@ else:
|
||||
_n = _gq.stdout.strip().splitlines()[-1] if _gq.stdout.strip() else "?"
|
||||
print(" ok %-20s %s" % ("guide-quote", _n))
|
||||
|
||||
# ── iso-bootstrap (R-502) ────────────────────────────────────────────────────────────────────────
|
||||
#
|
||||
# Its decoys need a fake docker on a one-directory PATH, so they live in their own file and are RUN from
|
||||
# here (guide-quote's shape). The suite never reaches the real docker, so this stays CI-safe.
|
||||
ran += 1
|
||||
_ib = subprocess.run([sys.executable, os.path.join("scripts", "test_iso_bootstrap_gate.py")],
|
||||
cwd=ROOT, capture_output=True, text=True)
|
||||
if _ib.returncode != 0:
|
||||
fails.append("iso-bootstrap: its decoy suite FAILED — a decoy did not convict\n%s"
|
||||
% (_ib.stdout + _ib.stderr)[-800:])
|
||||
else:
|
||||
print(" ok %-20s %s" % ("iso-bootstrap", (_ib.stderr.strip().splitlines() or ["?"])[-1]))
|
||||
|
||||
# ── site (R-423) ─────────────────────────────────────────────────────────────────────────────────
|
||||
# A page that exists but is not in PAGES. The content is a perfectly valid page, so only the scope rule can convict.
|
||||
decoy("site/unlisted-page", "site_gates.py",
|
||||
|
||||
Reference in New Issue
Block a user