#!/usr/bin/env bash # ============================================================ # lib/gates.sh — behavioural tests + structure locks for the # deterministic floor (GATE 0, lib/verify-secure-loop.md). # # Fail-closed is the entire point of this runner, so every # "looks green but must not pass" case is asserted explicitly: # nonzero exit carrying the marker, marker absent, timeout, # unindented attribute silently demoting a gate to manual. # Non-execution is proved with a sentinel file, and the # sentinel's own positive control is asserted first — an # absence check that was never able to fire proves nothing. # ============================================================ set -uo pipefail REPO="$(cd "$(dirname "$0")/../.." && pwd)" GATES="$REPO/lib/gates.sh" WORK="$(mktemp -d)" trap 'rm -rf "$WORK"' EXIT PASS=0; FAIL=0; N=0 LAST="" ok() { echo " PASS $1"; PASS=$((PASS + 1)); } bad() { echo " FAIL $1 — $2"; FAIL=$((FAIL + 1)); } # gate