fix: reject broken runtime launchers and preserve failed proof evidence
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Some checks failed
Governed runtime contract / contract (push) Failing after 16s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
parent
4e666d6fa3
commit
43e621439a
26 changed files with 1367 additions and 3 deletions
|
|
@ -230,6 +230,8 @@ except OSError: readonly=True
|
|||
else: readonly=False
|
||||
print(json.dumps({'runtime_readonly':readonly,'python_prefix':sys.prefix,
|
||||
'cli_version':subprocess.check_output(['claude','--version'],text=True).strip(),
|
||||
'entrypoints':{name:subprocess.run([name,'--help'],capture_output=True,timeout=15).returncode
|
||||
for name in ('rein-aharness','glas-harness')},
|
||||
'private_absent':not Path(sys.argv[1]).exists(),'source_absent':not Path(sys.argv[2]).exists(),
|
||||
'proxy_absent':not any('proxy' in k.lower() for k in os.environ),
|
||||
'interfaces':[x.split(':')[0].strip() for x in Path('/proc/net/dev').read_text().splitlines()[2:]]}))
|
||||
|
|
@ -239,6 +241,7 @@ print(json.dumps({'runtime_readonly':readonly,'python_prefix':sys.prefix,
|
|||
assert facts["runtime_readonly"] and facts["private_absent"] and facts["source_absent"]
|
||||
assert facts["proxy_absent"] and facts["interfaces"] == ["lo"]
|
||||
assert facts["cli_version"] == "2.1.266 (Claude Code)"
|
||||
assert all(code == 0 for code in facts["entrypoints"].values()), json.dumps({"entrypoint_check_failed": facts["entrypoints"], "provider_requests": server.provider_calls-before})
|
||||
adapter = AgenticClaudeCodeAdapter(workdir=Path(status.inputs["workspace_dir"]),
|
||||
cli_path="/opt/sandboxer/runtime/bin/claude",
|
||||
model=profile.model.model)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue