Add tests/issue-57-runtime-install-no-drift.test.cjs protecting the Runtime Install Policy Module boundary (ADR-58) and the explicit Runtime Config Adapter Registry (#60), now that #58/#60/#56 have landed and the seam exists. The guards fail when: - (AC1) supported-runtime metadata is added to an installer/query call site (allRuntimes, the interactive runtimeMap menu) without a matching registry adapter entry — enforced by three-way set equality across allRuntimes, runtimeMap values, and ALLOWED_CONFIG_RUNTIMES. - (AC2) config-mutation dispatch escapes the registry: every intent uses a registry-declared install surface, every permission writer is null or a registry-known runtime, unknown/prototype-key runtimes fail loudly, and a new inline 'runtime === "..."' branch against an unregistered runtime is rejected. Assertions are behavioral (require + reflect on live exports) where behavior can cover the contract (AC3); two annotated structural guards cover what it cannot. Existing installer/runtime-policy/runtime-global-skills suites stay green (AC4). Gates: eslint, lint-test-file-count, full Mac suite (12715 pass / 0 fail) and Linux Docker (14709 pass / 0 fail) all green; Codex adversarial-review, /code-review, and /security-review run with findings addressed. Closes #57 Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
697 B
697 B
type, pr
| type | pr |
|---|---|
| Changed | 867 |
Added no-drift guard tests (tests/issue-57-runtime-install-no-drift.test.cjs) that protect the Runtime Install Policy Module boundary (ADR-58) and the explicit Runtime Config Adapter Registry (#60). They fail loudly when supported-runtime metadata is added to an installer call site (allRuntimes, the interactive runtimeMap menu) without a matching registry adapter entry, or when config-mutation dispatch escapes the registry's declared install surfaces — catching reintroduction of the scattered per-runtime branching those seams removed.