feat(runtime): enforce governed mutation boundaries

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a06ba0-10aa-7ea0-b20a-4f3fac39efe9
This commit is contained in:
tegwick 2026-09-04 11:25:07 +02:00
parent e3c6124e22
commit 20e6f381f6
28 changed files with 1068 additions and 154 deletions

View file

@ -12,7 +12,9 @@ How to add a row:
from __future__ import annotations
import os
from dataclasses import dataclass, field
from datetime import date
from pathlib import Path
from typing import Any
@ -35,6 +37,21 @@ APPROACH_MAIL_TRIAGE = "mail-triage"
APPROACH_MAIL_PIPELINE = "mail-scan+triage"
APPROACH_AGENT_SESSION = "agent-session"
APPROACH_UNMATCHED = "unmatched"
LEGACY_APPROACHES_UNTIL_ENV = "AGENT_HARNESS_LEGACY_APPROACHES_UNTIL"
def legacy_approaches_enabled(
value: str | None = None,
*,
today: date | None = None,
) -> bool:
"""Require an explicit, non-expired ISO date for profile-absent routing."""
raw = os.environ.get(LEGACY_APPROACHES_UNTIL_ENV, "") if value is None else value
try:
expires = date.fromisoformat(raw.strip())
except (AttributeError, ValueError):
return False
return (today or date.today()) <= expires
@dataclass(frozen=True)
@ -185,6 +202,19 @@ def execute_approach(
reopen=False,
)
if not legacy_approaches_enabled():
configured = os.environ.get(LEGACY_APPROACHES_UNTIL_ENV, "").strip()
state = f"expired at {configured}" if configured else "not configured"
return ApproachResult(
ok=False,
approach=name,
reason=(
"refused: profile-absent compatibility routing is disabled "
f"({LEGACY_APPROACHES_UNTIL_ENV} {state})"
),
reopen=False,
)
try:
target = resolve_ops_target(run, cfg)
except TaskSpecError as exc:
@ -266,6 +296,7 @@ def execute_approach(
reopen=True,
)
def _run_fi(target: Path, *, report_to_hub: bool, commit: bool) -> ApproachResult:
from rein_aharness.fi_research_brief import run_fi_research_brief