{"record":{"id":"6d58d3d7c0a2638a","repo":"affaan-m/ECC","slug":"gate-isolation-required","errorCode":"gate.isolation_required","errorMessage":"Candidate execution is disabled: no verified OS containment backend is implemented.","messagePattern":"Candidate execution is disabled: no verified OS containment backend is implemented\\.","errorType":"exception","errorClass":"GateError","httpStatus":null,"severity":"error","filePath":"scripts/lib/eval-harness/gate.js","lineNumber":176,"sourceCode":"  for (const relative of listFiles(variant.dir)) {\n    if (!/\\.(?:js|cjs|mjs|json|sh)$/.test(relative)) {\n      continue;\n    }\n    const lines = readRegularFile(path.join(variant.dir, relative), 'utf8').split(/\\r?\\n/);\n    lines.forEach((text, index) => {\n      for (const rule of rules) {\n        if (rule.pattern.test(text)) {\n          hits.push({ variant: variant.name, rule: rule.rule, file: relative, line: index + 1 });\n        }\n      }\n    });\n  }\n  return hits;\n}\n\n/** No verified OS backend is implemented; caller-supplied flags cannot bypass this. */\nfunction requireSupportedIsolation() {\n  throw new GateError('gate.isolation_required', 'Candidate execution is disabled: no verified OS containment backend is implemented.');\n}\n\n/** Reject every legacy direct-runner invocation before copying or executing code. */\nfunction runVariant() {\n  requireSupportedIsolation();\n}\n\n/** Validate bounded child protocol data. This does not attest to isolation. */\nfunction parseChildResult(child, tasks) {\n  const outputs = new Map();\n  let fatal = null;\n  if (!child || typeof child !== 'object') return { outputs, fatal: 'missing child result' };\n  if (child.error) return { outputs, fatal: child.error.code === 'ETIMEDOUT' ? 'timeout' : 'child process error' };\n  if (child.status !== 0 || child.signal) return { outputs, fatal: 'child exited unsuccessfully' };\n  try {\n    const raw = String(child.stdout || '');\n    if (Buffer.byteLength(raw) > 1024 * 1024) throw new Error('oversized child output');\n    const lastLine = raw.trim().split('\\n').filter(Boolean).pop() || '';","sourceCodeStart":158,"sourceCodeEnd":194,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/lib/eval-harness/gate.js#L158-L194","documentation":"requireSupportedIsolation is an unconditional refusal: the eval-harness currently implements no verified OS containment backend, so any code path that would execute candidate code (runVariant, runGate) throws GateError('gate.isolation_required'). No flag, option, or caller-supplied executor can bypass this by design — candidate execution is disabled.","triggerScenarios":"Calling runGate or runVariant (or the CLI equivalents, e.g. `gate run`) in any environment; attempting to pass a custom executor or trust flag hoping to enable execution.","commonSituations":"Trying to replay or score candidate variants locally; migrating from a legacy direct-runner workflow to the current gate; automation scripts that still call runVariant; reading docs/examples that predate the execution lockout.","solutions":["Do not attempt execution; inspect and verify candidates offline instead (source digests, inspection, receipt verification via `node scripts/eval-harness.js`).","Restructure the workflow to use replay/inspection modes that do not execute candidate code.","Wait for/track an upstream release that ships a verified OS containment backend.","Remove or gate off call sites that assume runVariant/runGate execute code; treat isolation_required as a permanent refusal, not a transient error."],"exampleFix":"// before\nrunVariant(variant, taskset) // throws gate.isolation_required\n// after\n// inspect offline instead of executing\nconst info = inspectSource(variant.dir); // digest + syntactic inspection, no execution","handlingStrategy":"try-catch","validationCode":"// Detection: this refusal is unconditional; there is no pre-check that makes execution legal.\n// Guard call sites instead:\nif (typeof gate.runVariant === 'function') {\n  console.warn('gate.runVariant is unavailable: candidate execution is disabled');\n}","typeGuard":"function executionIsAvailable(gateModule) {\n  // No flag enables execution; treat as never available.\n  return false;\n}","tryCatchPattern":"try {\n  runGate(args);\n} catch (e) {\n  if (e.code === 'gate.isolation_required') {\n    console.error('Candidate execution is disabled; use offline inspection/replay instead of executing variants');\n    // fall back to inspection workflow\n  } else throw e;\n}","preventionTips":["Never build automation that assumes runVariant/runGate will execute code.","Design pipelines around offline inspection, digests, and receipt verification.","Do not attempt bypass flags — the refusal is deliberate and unconditional.","Track upstream releases for a verified OS containment backend before enabling execution paths."],"tags":["security","isolation","unsupported-operation","eval-harness"],"backgroundTag":"unsupported-operation","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}