fix(check): fail when the server withholds runtime rules for entitlement - #406
Merged
Merged
Conversation
…untime rule fails check
This was referenced Sep 27, 2026
thecodedrift
marked this pull request as ready for review
September 27, 2026 20:02
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Under every CLI through 0.11.2, a runtime rule the server withholds because the organization's plan lacks runtime signatures is skipped with a generic "unsafe / unknown / drift" notice, and
checkexits 0. A customer whose paid plan lapses gets a greentaskless checkwhile their runtime rules have stopped running.What changes
checkexits 1 when reconcile'sentitlement.withheldis non-empty, in human and--jsonmodes. Each withheld rule is skipped withnot included in your Taskless plan(never "drift"), one notice names the rules, reason, and upgrade URL (printed once), and--jsongains an optionalentitlementobject. A withheld file matching no local rule still fails the run, named by its path; a withheld file is never sent to restore.checkblesses them.rule create/rule improvewarn innoticeswhen they write a runtime rule the plan will not run. Static rules never warn.checkandciagent recipes (topics v3 / v2) document the exit and tell an agent not to reach for--anonymousor--dangerously-run-scriptsto get green.Unauthenticated,
--anonymous, degrade paths, andsg/valerules are unchanged. A response with noentitlement, orruntimeSignatures: true, is behavior-identical to today (tested).Review notes
__schemahas noentitlement(measured 2026-09-27). Restore and retrieval type it asMayCarryEntitlement<T>, an optionalunknownnormalized byparseEntitlement. Tightening once it is always sent is Tighten entitlement and file-set signature typing once the service always returns them #409.signaturefrom thesg/valefile-set variants (runtime keeps it) pending a cloud change, and also carries an unrelatedsuccessCasesshape change. Both in Tighten entitlement and file-set signature typing once the service always returns them #409.cli-check's exit-code requirement is MODIFIED under its unchanged title and restates all three standing scenarios. Before/after title sets across the three touched specs: 0 lost, 19 gained.--dangerously-run-scriptson a TTY orCI=1is Require a TTY or CI=1 for --dangerously-run-scripts #408.Fixes #403