affaan-m/ECC · error · GateError

gate.isolation_required

gate.isolation_required

Error message

Candidate execution is disabled: no verified OS containment backend is implemented.

What it means

requireSupportedIsolation is an unconditional refusal: the eval-harness currently implements no verified OS containment backend, so any code path that would execute candidate code (runVariant, runGate) throws GateError('gate.isolation_required'). No flag, option, or caller-supplied executor can bypass this by design — candidate execution is disabled.

Solutions

  1. Do not attempt execution; inspect and verify candidates offline instead (source digests, inspection, receipt verification via `node scripts/eval-harness.js`).
  2. Restructure the workflow to use replay/inspection modes that do not execute candidate code.
  3. Wait for/track an upstream release that ships a verified OS containment backend.
  4. Remove or gate off call sites that assume runVariant/runGate execute code; treat isolation_required as a permanent refusal, not a transient error.

Example fix

// before
runVariant(variant, taskset) // throws gate.isolation_required
// after
// inspect offline instead of executing
const info = inspectSource(variant.dir); // digest + syntactic inspection, no execution
Defensive patterns

Strategy: try-catch

Validate before calling

// Detection: this refusal is unconditional; there is no pre-check that makes execution legal.
// Guard call sites instead:
if (typeof gate.runVariant === 'function') {
  console.warn('gate.runVariant is unavailable: candidate execution is disabled');
}

Type guard

function executionIsAvailable(gateModule) {
  // No flag enables execution; treat as never available.
  return false;
}

Try / catch

try {
  runGate(args);
} catch (e) {
  if (e.code === 'gate.isolation_required') {
    console.error('Candidate execution is disabled; use offline inspection/replay instead of executing variants');
    // fall back to inspection workflow
  } else throw e;
}

Prevention

When it happens

Trigger: Calling runGate or runVariant (or the CLI equivalents, e.g. `gate run`) in any environment; attempting to pass a custom executor or trust flag hoping to enable execution.

Common situations: Trying to replay or score candidate variants locally; migrating from a legacy direct-runner workflow to the current gate; automation scripts that still call runVariant; reading docs/examples that predate the execution lockout.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/6d58d3d7c0a2638a. Report an issue: GitHub.

Appendix: source

Thrown at scripts/lib/eval-harness/gate.js:176

  for (const relative of listFiles(variant.dir)) {
    if (!/\.(?:js|cjs|mjs|json|sh)$/.test(relative)) {
      continue;
    }
    const lines = readRegularFile(path.join(variant.dir, relative), 'utf8').split(/\r?\n/);
    lines.forEach((text, index) => {
      for (const rule of rules) {
        if (rule.pattern.test(text)) {
          hits.push({ variant: variant.name, rule: rule.rule, file: relative, line: index + 1 });
        }
      }
    });
  }
  return hits;
}

/** No verified OS backend is implemented; caller-supplied flags cannot bypass this. */
function requireSupportedIsolation() {
  throw new GateError('gate.isolation_required', 'Candidate execution is disabled: no verified OS containment backend is implemented.');
}

/** Reject every legacy direct-runner invocation before copying or executing code. */
function runVariant() {
  requireSupportedIsolation();
}

/** Validate bounded child protocol data. This does not attest to isolation. */
function parseChildResult(child, tasks) {
  const outputs = new Map();
  let fatal = null;
  if (!child || typeof child !== 'object') return { outputs, fatal: 'missing child result' };
  if (child.error) return { outputs, fatal: child.error.code === 'ETIMEDOUT' ? 'timeout' : 'child process error' };
  if (child.status !== 0 || child.signal) return { outputs, fatal: 'child exited unsuccessfully' };
  try {
    const raw = String(child.stdout || '');
    if (Buffer.byteLength(raw) > 1024 * 1024) throw new Error('oversized child output');
    const lastLine = raw.trim().split('\n').filter(Boolean).pop() || '';

View on GitHub (pinned to 8321021c54)