Commit graph

5 commits

Author SHA1 Message Date
Anton Razzhigaev
55af051ec5 Resolve node/npm launches through an execution-probed runtime ladder
On macOS the generic process surfaces (run_command, run_script,
start_service, verify_and_record) resolved bare node/npm through the
host PATH, which can point at a Homebrew node the kernel SIGKILLs on
launch (CODESIGNING, ~9ms) while a working signed bundled node ships
inside the application. shutil.which proves existence, not runnability.

process_interpreters.py (renamed from python_interpreter.py; one generic
InterpreterResolutionTrace with a family field, python event payloads
byte-identical) gains the node branch of the resolver: POST-GATES - the
health probe EXECUTES a candidate, so it must sit below the light fence,
shell guards and safety refusals
(test_light_fence_refuses_before_the_node_probe_can_execute pins that a
planted PATH shim's payload cannot run off a refused call); guards
inspect the original argv and the substitution reaches the handler
through a scoped attestation. Ladder: bootstrap_process_path first;
non-local executor backends are skipped; a healthy PATH node is a
byte-identical no-op in argv, child env, rendered prose and receipts
(the typed resolution trace event is deliberate observability, symmetric
with python's); a missing or probe-dead PATH node falls back to the
bundled runtime (argv rewrite only for bare node/nodejs; an attested
child-env PATH prepend for npm-family launches and for sh/bash/zsh/dash
bodies found via shell_parse.shell_tokens, wrappers matched by
basename); no usable node runs as written with the probe facts
disclosed - never a pre-block.

ouroboros/node_runtime.py owns the execution-probed health memo
((path, mtime, size)-keyed; missing never cached so a mid-session
install is noticed; a timeout verdict is cached with its probe budget
and re-probed only by a larger one; a relative which() result is never
trusted) and the skill-family policy select_skill_node_runtime
(bundled-first with health rollback), used by skill_exec, companions,
isolated deps, workspace preflight and the world profiler;
platform_layer lazily re-exports the public names (PEP 562, both import
orders pinned).

Handlers publish typed process facts (exit_code, POSIX signal name,
duration_ms, resolved_runtime) through the thread-local seam in
tools/process_facts.py; loop_tool_execution consumes them for the same
call, and the regex harvest over rendered text remains the read
fallback. Verify receipts disclose duration/signal/runtime while the
ORIGINAL check text stays the receipt identity. A signal death (rc < 0)
leaves the cosmetic bucket (POSIX; Windows is a disclosed residual), the
web log renders it as an error, and an executed serial pin proves our
own cancel custody never surfaces as tool_failure. Durations are
monotonic; the filesystem freshness audit keeps its own epoch stamp.

Three adversarial rounds, a triad+scope review round (12 runs) and a
delta + full-scope verification round (4 runs) are dispositioned in the
sprint plan; the accepted findings are folded in (Windows-only token
normalization, padded-head declassification, relative-which no-op on
both resolver lanes, basename-matched shell wrappers, case-aware env
overlay merge shared with the companion manifest lane, budget-scoped
timeout memo, size-gate surgery).
2026-08-30 19:53:59 +00:00
Ouroboros
26e50c34e5 fix: preserve light and direct-call semantics
Keep generic runtime data and cross-target system writes guarded in light mode, retain actionable cwd/not-found errors, and align private-binding test handlers with the frozen dispatch contract.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-08-11 09:37:42 +03:00
Ouroboros
5570ffd59b Bind process consumers to workspace authority
Resolve command, script, service, and run-kind verification targets once and carry the selected binding through interpreter choice, guards, execution, and receipts while preserving task custody.

Co-authored-by: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com>
2026-08-11 09:37:42 +03:00
Anton Razzhigaev
543cc8376c fix(test): 3-OS portability for the v6.67.0 suites
Windows: the python-resolver tests built fake venvs in POSIX layout
(bin/python) while project_venv_python correctly looks for
Scripts\python.exe — the fixture is now platform-aware; the isolated-checkout
test repos pin core.autocrlf=false so the LF staged patch applies in the
detached worktree on autocrlf=true runners. ui-smoke: the desktop chat scroll
probe re-injects its bubbles after the viewport resize dance — a resize can
re-render the chat from the (empty) real history and silently drop injected
nodes, which made the post-resize assertion an environment-dependent flake.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 23:52:36 +00:00
Anton Razzhigaev
a776639fcb feat(v6.66.0): honest mutation attribution, attributed staging, environment-correct Python, auditable Skill Review history, and a drift-proof operator review wrapper
Operator phase 2 of the owner-approved 6.65-6.67 release cycle. The physical
mutation lease/holder subsystem was deliberately descoped by the owner:
attribution is evidence-only (root-task baseline, terminal candidate snapshot,
attributed commit staging, projection into acceptance/review evidence, no
structural outcome veto). Ships the surface-aware Python interpreter resolver,
auditable Skill Review rounds/history, the single task-tree disposition
authority with cancel-wins, the SSOT operator review wrapper with typed exit
codes, the parallel hermetic pytest preflight, and the chronic red-CI
light-model test fix.

Review: advisory=skipped (prompt-size cap, non-blocking), triad
fable-5/gpt-5.6-sol/gemini-3.5-flash all responded, scope fable-5 responded,
aggregate PASSED (run 20260716T221730Z, $16.38). Full non-serial+serial pytest
green; ruff -F clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 22:25:04 +00:00