Skip to content

fix(check): fail when the server withholds runtime rules for entitlement - #406

Merged
thecodedrift merged 6 commits into
mainfrom
fix/check-fails-on-withheld-runtime-rules
Sep 27, 2026
Merged

thecodedrift merged 6 commits into
mainfrom
fix/check-fails-on-withheld-runtime-rules

Conversation

@thecodedrift

@thecodedrift thecodedrift commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Under every CLI through 0.11.2, a runtime rule the server withholds because the organization's plan lacks runtime signatures is skipped with a generic "unsafe / unknown / drift" notice, and check exits 0. A customer whose paid plan lapses gets a green taskless check while their runtime rules have stopped running.

What changes

  • check exits 1 when reconcile's entitlement.withheld is non-empty, in human and --json modes. Each withheld rule is skipped with not included in your Taskless plan (never "drift"), one notice names the rules, reason, and upgrade URL (printed once), and --json gains an optional entitlement object. A withheld file matching no local rule still fails the run, named by its path; a withheld file is never sent to restore.
  • Restore under a lapsed plan still writes the blessed bytes but stops promising the next check blesses them.
  • rule create / rule improve warn in notices when they write a runtime rule the plan will not run. Static rules never warn.
  • check and ci agent recipes (topics v3 / v2) document the exit and tell an agent not to reach for --anonymous or --dangerously-run-scripts to get green.

Unauthenticated, --anonymous, degrade paths, and sg/vale rules are unchanged. A response with no entitlement, or runtimeSignatures: true, is behavior-identical to today (tested).

Review notes

Fixes #403

@github-actions github-actions Bot added the Open OpenSpec Contains unresolved OpenSpec changes. All openspec changes must eventually reach an archive state. label Sep 27, 2026
@github-actions github-actions Bot removed the Open OpenSpec Contains unresolved OpenSpec changes. All openspec changes must eventually reach an archive state. label Sep 27, 2026
@thecodedrift
thecodedrift marked this pull request as ready for review September 27, 2026 20:02
@thecodedrift
thecodedrift merged commit 86799ef into main Sep 27, 2026
16 checks passed
@thecodedrift
thecodedrift deleted the fix/check-fails-on-withheld-runtime-rules branch September 27, 2026 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fail check when the server withholds runtime rules (paid Taskless accounts only)

1 participant