Skip to content

fix: wire live verifier through state volume - #113

Merged
sanjey99 merged 1 commit into
mainfrom
fix/111-live-verifier-state-volume
Sep 1, 2026
Merged

sanjey99 merged 1 commit into
mainfrom
fix/111-live-verifier-state-volume

Conversation

@sanjey99

@sanjey99 sanjey99 commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Problem

The authorized exact-main Shepherd live gate authenticated and completed real Agent execution, then failed closed with ContractVerificationInfrastructureError before an independent verifier container could be created.

Closes #111.

Root cause

live-runtime.integration.test.ts constructed ContainerVerifier without stateRoot and stateVolume. Inside the nested live controller, ContainerVerifier therefore fell back to a bind mount for a controller-private /app/state/... snapshot. The host Docker daemon cannot resolve that private path, so verifier creation failed. Production composition already passes both coordinates.

Fix

  • Pass config.containerStateRoot and config.containerStateVolume into the live verifier.
  • Add a non-model composition regression that requires both coordinates at the live construction site.

Test plan

  • Observed the new regression fail before the wiring fix.
  • Targeted composition test: 1/1 passed.
  • Server test-source typecheck passed.
  • Credential-free live preflight built the exact-tree images and discovered exactly one test.
  • After merge: run the explicitly authorized exact-main live Shepherd gate.
  • If the primary gate passes: run the approved legacy Playground continuity gate.

Out of scope

Provider configuration, production verifier policy, group-chat issue #110, teardown race #112, UI changes, and documentation.

## Summary
Make the containerized live Runtime gate address independent verification snapshots through its wrapper-provided Docker state volume.

## Root cause
The live gate omitted containerStateRoot and containerStateVolume when constructing ContainerVerifier. That forced a host bind mount for a controller-private path, so Docker could not create the verifier container.

## Fix
- Pass the resolved state root and volume to the live verifier.
- Add a causal composition regression for both coordinates.

## Testing
- Observed the new regression fail before the fix and pass after it.
- Targeted composition tests: 5 passed.
- Server test typecheck passed.
- Live test list and credential-free container preflight passed.

Refs #111
@sanjey99
sanjey99 marked this pull request as ready for review September 1, 2026 03:32
Copilot AI lite review requested due to automatic review settings September 1, 2026 03:32
@sanjey99
sanjey99 merged commit 412609c into main Sep 1, 2026
1 check passed
@sanjey99
sanjey99 deleted the fix/111-live-verifier-state-volume branch September 1, 2026 03:34

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new composition regression test is brittle to different Vitest invocation roots and potential formatting changes in the constructor call, which can cause false failures.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR fixes the live Shepherd runtime gate’s independent verifier creation by wiring the controller state volume coordinates into the ContainerVerifier options, matching the production composition. It also adds a regression test to ensure the live construction site continues to pass both stateRoot and stateVolume.

Changes:

  • Pass config.containerStateRoot and config.containerStateVolume into the live gate’s ContainerVerifier construction.
  • Add a composition regression test that asserts those two options are present at the live verifier construction site.
File summaries
File Description
apps/server/src/shepherd/live-runtime.integration.test.ts Wires state volume coordinates into the live verifier options to prevent bind-mount fallback.
apps/server/src/shepherd/live-runtime.composition.test.ts Adds a composition assertion to prevent regressions in live verifier state-volume wiring.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +1 to +22
import { readFile } from "node:fs/promises";
import path from "node:path";
import { describe, expect, it } from "vitest";

function liveVerifierArguments(source: string): string {
const expression = "new ContainerVerifier(registry(), {";
const start = source.indexOf(expression);
if (start < 0) throw new Error("live verifier composition site was not found");
const close = /^\s*\}\);/mu.exec(source.slice(start));
if (!close) throw new Error("live verifier composition site was not terminated");
return source
.slice(start, start + close.index)
.replace(/\/\/[^\n]*/gu, "")
.replace(/\/\*[\s\S]*?\*\//gu, "");
}

describe("live Runtime verifier composition", () => {
it("addresses independent verification snapshots through the controller state volume", async () => {
const source = await readFile(
path.resolve(process.cwd(), "src/shepherd/live-runtime.integration.test.ts"),
"utf8",
);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix live verifier state-volume wiring

2 participants