Commit 657658b
M30a: a slow host could move the provenance digest
`test · windows-latest` failed on M30 with two calls to detect() inside one
process disagreeing. Not a flake in the test: `docker --version` can take
longer than the ten-second timeout on a loaded runner, the TimeoutExpired is
caught, and the probe then reports exactly what it reports for a host with no
docker at all -- so the isolation tier fell from docker to subprocess between
one call and the next, and the digest of what the host could enforce moved
with it.
The probe now answers once per process. Failing to probe still reads as
absent, which under-claims the host's isolation, and that is the safe
direction to be wrong in here -- so the fix is to stop the answer changing
rather than to make a timeout mean something new.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>1 parent 3062e8e commit 657658b
2 files changed
Lines changed: 37 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| 24 | + | |
24 | 25 | | |
25 | 26 | | |
26 | 27 | | |
| |||
92 | 93 | | |
93 | 94 | | |
94 | 95 | | |
| 96 | + | |
95 | 97 | | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
96 | 114 | | |
97 | 115 | | |
98 | 116 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
6 | 7 | | |
7 | 8 | | |
8 | 9 | | |
| |||
31 | 32 | | |
32 | 33 | | |
33 | 34 | | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
34 | 53 | | |
35 | 54 | | |
36 | 55 | | |
| |||
0 commit comments