Skip to content

Bind supplemental probes to an explicit ready contract - #276

Merged
DavidBakerEffendi merged 1 commit into
mainfrom
dave/v090-ready-contract-220
Sep 29, 2026
Merged

DavidBakerEffendi merged 1 commit into
mainfrom
dave/v090-ready-contract-220

Conversation

@DavidBakerEffendi

Copy link
Copy Markdown
Collaborator

The release preparer and launchers accept an explicit versioned contract, but the Python supplemental probe expects its script to be the last command argument and the OpenTaint probe requires a fixed two-argument command and canonical inventory path. Those checks prevent a reviewed ready contract from being used without changing the disabled preparation contract.

Accept an explicit --contract only when it names the exact consumed contract inside the versioned execution-plan directory. OpenTaint follows the hash-bound inventory reference there. Preserve the default canonical invocation for the preparation workflow. No arbitrary file overlay or external preparation driver is introduced.

Validation: 17 focused probe tests and 11 planning-contract tests pass. New tests execute mocked controls from a final-01 contract/inventory, prove disabled canonical bytes remain unchanged, and reject a mismatched contract argument before output creation. Execution remains disabled; no native analyzer was run.

@DavidBakerEffendi
DavidBakerEffendi merged commit 94ff0ad into main Sep 29, 2026
4 checks passed
@DavidBakerEffendi
DavidBakerEffendi deleted the dave/v090-ready-contract-220 branch September 29, 2026 15:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant