Merge nucleic/lucid-river-toad-6efj into dev

This commit is contained in:
2026-07-29 18:57:59 -07:00
parent e41bafdb7c
commit 6777223e3d
3 changed files with 173 additions and 12 deletions
+8 -1
View File
@@ -194,7 +194,7 @@ Options: `--image` (default `ghcr.io/abkslm/naros-agent:26.07`), `--container`,
`--iterations` (timing runs, default 5), `--broker <path>` if autodiscovery fails,
`--no-recovery` to skip the crash test.
It answers three open questions:
It answers four open questions:
1. **Does the happy path work?** session → GHCR pull → container with an NTFS `ContainerVolume` →
exec → stdio round-trip → signal → teardown. Also prints the §5 host gateway, which no wslc
@@ -210,6 +210,13 @@ It answers three open questions:
crash — starts a fresh one, and reports whether the orphan was cleared or whether it still
fails `session_exists`. It distinguishes "Tier 1 never bound" from "Tier 1 bound and did not
work", because those are different bugs.
4. **Can the guest reach the host at the gateway? (M1 b)** The last thing M2 waits on. It binds a
listener on the WSL-facing address only — never `0.0.0.0`, which is the posture §5 requires —
and has the container open a TCP round trip to it. Every agent session rides this: approvals,
the git/gh interceptors, nash's shell reports. On failure it prints the `New-NetFirewallRule`
remediation §5 step 5 calls for, and notes that the AF_HYPERV fallback needs a VM GUID that
§13.2 found no client route to — so gateway TCP is not merely preferred, it is the only path
currently available.
Every step prints what happened rather than asserting: a spike's product is evidence. It exits
non-zero only when a step that should have worked threw. The `[brokerd]` lines interleaved in the