* fix(doctor): explain update lint supervisor refusals
* test(gateway): complete placement read policy fixture
Supply the policyConfig required by SessionRowReadView after scoped session authorization was introduced. This restores the gateway-root type check without weakening the production contract or changing lifecycle assertions.
(cherry picked from commit 0901260323)
* test(agents): join owned cleanup before fixture assertions
Completion now crosses asynchronous SQLite work, but two steer-restart
fixture cases still polled callbacks every millisecond with a one-second
deadline. The assertion could expire while valid completion work remained
admitted; the existing teardown join then observed the missing announcement.
Join the existing lifecycle and cleanup roots before the unchanged assertions,
restore observers in finally, and remove the timed-poll helper.
The original CI failure and two local failures reproduced the race; a local
diagnostic observed zero announcements before owner settlement and one after.
Natural isolated and loaded Linux baselines passed, so no natural Linux
before-failure is claimed. After the repair, the full file passed 20 times
and its exact 86-file Linux child shard passed three times. Changed checks
and P2 review passed. The existing 22-test file measured 27.99 seconds wall
with one worker; no new tests, retries, or timeouts were added.
(cherry picked from commit 1f067fa03d)
* test(update): arm Doctor refusal at the worker entry
Use the existing survivor preload path so inspection budget admission cannot skip the diagnostic refusal fixture. Preserve refused update and process evidence separately from the healthy retry through the maintained diagnostics publisher.
Retain the original successful-update fixture failure as evidence; production Doctor semantics remain unchanged.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* test(e2e): reap orphaned upgrade survivor fixture children
Start both survivor containers with Docker init so orphaned worker children
are reaped by the namespace owner. Retain process parentage and PID 1 identity
in the refusal witnesses, and include HostConfig.Init in failure diagnostics.
Keep the supervisor refusal and completed-cleanup assertions unchanged.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* fix(ci): accept plugin fixture capabilities
* fix(ci): detect fixture capability consent support
Probe candidate command help through the existing bounded E2E runners so
positive fixtures accept capabilities only when that command supports it.
Preserve historical packages, probe failures, argv, and child exit status;
keep negative, no-op, and integrity-bound update coverage unapproved.
Replace duplicated probes and source-string checks with executable
compatibility regressions. Synchronize the RPC timeout test with real
process readiness before advancing its unchanged 100 ms deadline, while
retaining real process-group termination and cleanup.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* fix(ci): run Docker lanes from trusted harness
Resolve package scripts and packaging tools from the trusted harness while
keeping candidate source, artifacts, registry identity, and preflight on
the frozen target. Remove candidate-script lane filtering and the duplicate
live command wrapper; preserve source inputs in source-built Docker lanes.
Prove the public scheduler boundary with distinct harness/target roots and
poisoned candidate scripts. Synchronize scheduler timeout fixtures with real
child readiness, retain real signals and kill grace, and handle empty QR
build arguments on Bash 3.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* test(ci): retire superseded harness source assertions
Keep the workflow trust and pnpm PATH guards, but remove checks for the
old inline replacement and deleted duplicate live-script wrapper. The
public scheduler regressions now prove those behaviors through distinct
candidate/harness roots and quoted pinned pnpm commands.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* test(ci): cover multi-build source roots
* fix(ci): select the harness toolchain before Docker lanes
Start prepared pnpm commands in the trusted harness before Corepack resolves
its package-manager pin. Preserve frozen candidate source and artifact
identity, and resolve relative executable and cache paths before changing cwd.
Keep quoted rerun environment values out of executable substitution. Cover
different toolchain pins, shell-sensitive paths, and generated reruns through
the public scheduler boundary.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>