affaan-m/ECC · error · GateError
gate.isolation_required
gate.isolation_required
Error message
Candidate execution is disabled: no verified OS containment backend is implemented.
What it means
requireSupportedIsolation is an unconditional refusal: the eval-harness currently implements no verified OS containment backend, so any code path that would execute candidate code (runVariant, runGate) throws GateError('gate.isolation_required'). No flag, option, or caller-supplied executor can bypass this by design — candidate execution is disabled.
Solutions
- Do not attempt execution; inspect and verify candidates offline instead (source digests, inspection, receipt verification via `node scripts/eval-harness.js`).
- Restructure the workflow to use replay/inspection modes that do not execute candidate code.
- Wait for/track an upstream release that ships a verified OS containment backend.
- Remove or gate off call sites that assume runVariant/runGate execute code; treat isolation_required as a permanent refusal, not a transient error.
Example fix
// before runVariant(variant, taskset) // throws gate.isolation_required // after // inspect offline instead of executing const info = inspectSource(variant.dir); // digest + syntactic inspection, no execution
Defensive patterns
Strategy: try-catch
Validate before calling
// Detection: this refusal is unconditional; there is no pre-check that makes execution legal.
// Guard call sites instead:
if (typeof gate.runVariant === 'function') {
console.warn('gate.runVariant is unavailable: candidate execution is disabled');
} Type guard
function executionIsAvailable(gateModule) {
// No flag enables execution; treat as never available.
return false;
} Try / catch
try {
runGate(args);
} catch (e) {
if (e.code === 'gate.isolation_required') {
console.error('Candidate execution is disabled; use offline inspection/replay instead of executing variants');
// fall back to inspection workflow
} else throw e;
} Prevention
- Never build automation that assumes runVariant/runGate will execute code.
- Design pipelines around offline inspection, digests, and receipt verification.
- Do not attempt bypass flags — the refusal is deliberate and unconditional.
- Track upstream releases for a verified OS containment backend before enabling execution paths.
When it happens
Trigger: Calling runGate or runVariant (or the CLI equivalents, e.g. `gate run`) in any environment; attempting to pass a custom executor or trust flag hoping to enable execution.
Common situations: Trying to replay or score candidate variants locally; migrating from a legacy direct-runner workflow to the current gate; automation scripts that still call runVariant; reading docs/examples that predate the execution lockout.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- artifact must be a resident regular file
- artifact path escapes output directory
- artifact path must be canonical and absolute
- artifact permits provider execution
- cannot reset hunks for untracked files
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/6d58d3d7c0a2638a.
Report an issue: GitHub.
Appendix: source
Thrown at scripts/lib/eval-harness/gate.js:176
for (const relative of listFiles(variant.dir)) {
if (!/\.(?:js|cjs|mjs|json|sh)$/.test(relative)) {
continue;
}
const lines = readRegularFile(path.join(variant.dir, relative), 'utf8').split(/\r?\n/);
lines.forEach((text, index) => {
for (const rule of rules) {
if (rule.pattern.test(text)) {
hits.push({ variant: variant.name, rule: rule.rule, file: relative, line: index + 1 });
}
}
});
}
return hits;
}
/** No verified OS backend is implemented; caller-supplied flags cannot bypass this. */
function requireSupportedIsolation() {
throw new GateError('gate.isolation_required', 'Candidate execution is disabled: no verified OS containment backend is implemented.');
}
/** Reject every legacy direct-runner invocation before copying or executing code. */
function runVariant() {
requireSupportedIsolation();
}
/** Validate bounded child protocol data. This does not attest to isolation. */
function parseChildResult(child, tasks) {
const outputs = new Map();
let fatal = null;
if (!child || typeof child !== 'object') return { outputs, fatal: 'missing child result' };
if (child.error) return { outputs, fatal: child.error.code === 'ETIMEDOUT' ? 'timeout' : 'child process error' };
if (child.status !== 0 || child.signal) return { outputs, fatal: 'child exited unsuccessfully' };
try {
const raw = String(child.stdout || '');
if (Buffer.byteLength(raw) > 1024 * 1024) throw new Error('oversized child output');
const lastLine = raw.trim().split('\n').filter(Boolean).pop() || '';View on GitHub (pinned to 8321021c54)