Repository navigation
fix: wire live verifier through state volume - #113
Merged
Merged
Conversation
## Summary Make the containerized live Runtime gate address independent verification snapshots through its wrapper-provided Docker state volume. ## Root cause The live gate omitted containerStateRoot and containerStateVolume when constructing ContainerVerifier. That forced a host bind mount for a controller-private path, so Docker could not create the verifier container. ## Fix - Pass the resolved state root and volume to the live verifier. - Add a causal composition regression for both coordinates. ## Testing - Observed the new regression fail before the fix and pass after it. - Targeted composition tests: 5 passed. - Server test typecheck passed. - Live test list and credential-free container preflight passed. Refs #111
There was a problem hiding this comment.
🟡 Changes recommended
The new composition regression test is brittle to different Vitest invocation roots and potential formatting changes in the constructor call, which can cause false failures.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR fixes the live Shepherd runtime gate’s independent verifier creation by wiring the controller state volume coordinates into the ContainerVerifier options, matching the production composition. It also adds a regression test to ensure the live construction site continues to pass both stateRoot and stateVolume.
Changes:
- Pass
config.containerStateRootandconfig.containerStateVolumeinto the live gate’sContainerVerifierconstruction. - Add a composition regression test that asserts those two options are present at the live verifier construction site.
File summaries
| File | Description |
|---|---|
| apps/server/src/shepherd/live-runtime.integration.test.ts | Wires state volume coordinates into the live verifier options to prevent bind-mount fallback. |
| apps/server/src/shepherd/live-runtime.composition.test.ts | Adds a composition assertion to prevent regressions in live verifier state-volume wiring. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+1
to
+22
| import { readFile } from "node:fs/promises"; | ||
| import path from "node:path"; | ||
| import { describe, expect, it } from "vitest"; | ||
|
|
||
| function liveVerifierArguments(source: string): string { | ||
| const expression = "new ContainerVerifier(registry(), {"; | ||
| const start = source.indexOf(expression); | ||
| if (start < 0) throw new Error("live verifier composition site was not found"); | ||
| const close = /^\s*\}\);/mu.exec(source.slice(start)); | ||
| if (!close) throw new Error("live verifier composition site was not terminated"); | ||
| return source | ||
| .slice(start, start + close.index) | ||
| .replace(/\/\/[^\n]*/gu, "") | ||
| .replace(/\/\*[\s\S]*?\*\//gu, ""); | ||
| } | ||
|
|
||
| describe("live Runtime verifier composition", () => { | ||
| it("addresses independent verification snapshots through the controller state volume", async () => { | ||
| const source = await readFile( | ||
| path.resolve(process.cwd(), "src/shepherd/live-runtime.integration.test.ts"), | ||
| "utf8", | ||
| ); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The authorized exact-main Shepherd live gate authenticated and completed real Agent execution, then failed closed with
ContractVerificationInfrastructureErrorbefore an independent verifier container could be created.Closes #111.
Root cause
live-runtime.integration.test.tsconstructedContainerVerifierwithoutstateRootandstateVolume. Inside the nested live controller,ContainerVerifiertherefore fell back to a bind mount for a controller-private/app/state/...snapshot. The host Docker daemon cannot resolve that private path, so verifier creation failed. Production composition already passes both coordinates.Fix
config.containerStateRootandconfig.containerStateVolumeinto the live verifier.Test plan
Out of scope
Provider configuration, production verifier policy, group-chat issue #110, teardown race #112, UI changes, and documentation.