fix(ci): restore cross-platform release gates
Some checks are pending
CI / quick-test (push) Waiting to run
CI / build (zip, windows-latest, windows-x64, syft_1.50.0_windows_amd64.zip, syft.exe, 815ee6973ec5dff6a671d7f41b0e78835a8c45b91d5a39f4743ea1cee833d3be) (push) Blocked by required conditions
CI / full-test (macos-latest) (push) Waiting to run
CI / full-test (ubuntu-latest) (push) Waiting to run
CI / full-test (windows-latest) (push) Waiting to run
CI / betterleaks-platform-smoke (macos-latest) (push) Waiting to run
CI / betterleaks-platform-smoke (ubuntu-latest) (push) Waiting to run
CI / betterleaks-platform-smoke (windows-latest) (push) Waiting to run
CI / integration-test (push) Waiting to run
CI / skill-smoke (macos-latest) (push) Waiting to run
CI / skill-smoke (ubuntu-latest) (push) Waiting to run
CI / skill-smoke (windows-latest) (push) Waiting to run
CI / marker-guards (push) Waiting to run
CI / ui-smoke (push) Waiting to run
CI / docker-ui-smoke (push) Waiting to run
CI / docker-portable-test (push) Waiting to run
CI / release-preflight (push) Blocked by required conditions
CI / build (dmg, macos-latest, macos-arm64, syft_1.50.0_darwin_arm64.tar.gz, syft, e32fdb9d47823fa633748a1efca2528fd77c37469ea93c9e40ab835da44e4cce) (push) Blocked by required conditions
CI / build (tar.gz, ubuntu-latest, linux-x86_64, syft_1.50.0_linux_amd64.tar.gz, syft, bf7b29ff57f06da30918266a0e1c2885a8f99784798d1bdb1628886aa015d788) (push) Blocked by required conditions
CI / vendor-package-smoke (push) Blocked by required conditions
CI / release (push) Blocked by required conditions
Claudexor platform gate (API keys — subscription auth NOT covered) / fixture · ubuntu-latest · exact managed runtime, fake harness, no model (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / live · macos-latest · claude · API key only, subscription NOT covered (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / live · ubuntu-latest · claude · API key only, subscription NOT covered (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / live · windows-latest · claude · API key only, subscription NOT covered (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / live · macos-latest · codex · API key only, subscription NOT covered (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / fixture · macos-latest · exact managed runtime, fake harness, no model (push) Waiting to run
Claudexor platform gate (API keys — subscription auth NOT covered) / fixture · windows-latest · exact managed runtime, fake harness, no model (push) Waiting to run
Submit Claudexor dependency / Submit managed runtime snapshot (push) Waiting to run

Normalize the CSS contract test across CRLF checkouts and bind the delegated live platform smoke to its caller-owned execution workspace.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
This commit is contained in:
Anton Razzhigaev 2026-08-30 08:44:29 +03:00
parent 5c09224a81
commit 7b9d0ffe71
3 changed files with 16 additions and 3 deletions

View file

@ -252,6 +252,10 @@ def build_request(lane: str, harness: str, model: str, effort: str,
"maxSeconds": int(max_seconds),
}
if lane == "live":
# Production binds a fresh delegated mutating run to the caller-owned
# execution tree. The smoke owns ``root`` too, so exercise that same
# admission contract instead of relying on the project scope as a shim.
request["execution"]["workspaceRoot"] = str(root)
# Production sends "subscription". CI cannot authenticate one, so it asks
# for the substrate it actually has. This is THE difference between what
# this gate exercises and what production does.

View file

@ -414,7 +414,11 @@ def test_the_request_uses_the_seams_own_authority_shape(tmp_path):
# The delegated marker rides the live lane only: a fake maps no
# `external_sandbox_full`, so the engine refuses the delegated mutating shape
# on a pinned fake lane wherever the host has a kernel boundary.
assert live["execution"] == {"isolation": shape.isolation, "delegated": shape.delegated}
assert live["execution"] == {
"isolation": shape.isolation,
"delegated": shape.delegated,
"workspaceRoot": str(tmp_path),
}
assert fixture["execution"] == {"isolation": shape.isolation, "delegated": False}
# Both lanes pin the pool: `primaryHarness` alone only reorders the auto-pool,
# and the auto-pool excludes `fake-*` routes entirely.
@ -467,7 +471,11 @@ def test_the_live_request_pins_the_pool_and_keeps_the_delegated_marker(
request = smoke.build_request("live", "claude", "m", "low", tmp_path, "p", 300)
assert request["harnesses"] == ["claude"]
assert request["primaryHarness"] == "claude"
assert request["execution"] == {"isolation": "live", "delegated": True}
assert request["execution"] == {
"isolation": "live",
"delegated": True,
"workspaceRoot": str(tmp_path),
}
assert request["authPreference"] == "api_key"

View file

@ -55,7 +55,8 @@ import {
} from '../modules/harness_login_cards.js';
test('account actions stack at the app shell compact breakpoint', () => {
const css = readFileSync(new URL('../style.css', import.meta.url), 'utf8');
const css = readFileSync(new URL('../style.css', import.meta.url), 'utf8')
.replace(/\r\n?/g, '\n');
assert.ok(css.includes(`@media (max-width: 980px) {
.harness-account-row {
grid-template-columns: minmax(0, 1fr);