fix(#4794): decision-coverage answers an unmeasured shape on could-not-parse; a non-file context path fails closed (#4889)

* test(#4794): failing-first — could-not-parse must answer an unmeasured shape; a directory context path fails closed

* fix(#4794): could-not-parse answers an unmeasured shape (null counts, unreadable ids, no uncovered); a non-file context path fails closed

* chore(#4794): backfill changeset PR number (4889)

* test(#4794): skip the directory-identity probe when the platform cannot discriminate (windows runner volume collapse, measured)

Two consecutive windows conformance runs failed the probe with measured identical
(dev, ino) for two distinct mkdtemp directories (dev=3606225537, ino=9007199255243448
for both) — a runner-volume property, not a regression in the guard. On such a
platform the guard's identity containment degrades to refuse-everything (fail-closed,
documented); the probe asserts capability, so the honest response is an explicit
t.skip carrying the measurement (ADR-2719 §6), not a red lane for every PR.

---------

Co-authored-by: sim <sim@local>
This commit is contained in:
Tom Boucher
2026-09-20 02:53:58 -04:00
committed by GitHub
parent 3d2cb1fb01
commit 822934c901
5 changed files with 181 additions and 15 deletions

View File

@@ -3636,6 +3636,21 @@ describe('#3712 in-process home confinement', () => {
t.after(() => { cleanup(a); cleanup(b); });
const sa = fs.statSync(a);
const sb = fs.statSync(b);
// #4794 fold-in (windows conformance lane, 2 consecutive runs): a runner
// image whose temp volume reports an identical synthesized (dev, ino) for
// two distinct directories cannot discriminate at all. On such a platform
// the guard's identity containment degrades to refuse-everything (fail-
// closed, documented) — there is no behavior this probe can assert, only
// capability to report. Measured evidence rides in the skip reason (the
// ADR-2719 §6 explicit-skip discipline: reported as skipped, never a bare
// return that scores a PASS). When the platform CAN discriminate, the
// original assertions run unchanged.
if (sa.dev === sb.dev && sa.ino === sb.ino) {
t.skip(`this platform reports an identical identity for two distinct directories ` +
`(dev=${sa.dev}, ino=${sa.ino}) — identity-based containment would refuse ` +
'everything here; the guard remains fail-closed but this probe has nothing to assert');
return;
}
assert.ok(sa.dev !== sb.dev || sa.ino !== sb.ino,
`two distinct directories share an identity (dev=${sa.dev}/${sb.dev}, ino=${sa.ino}/${sb.ino}) — ` +
'isInside() would then match its first ancestor and refuse everything');