SIGN IN SIGN UP

fix(test): the worker-scope script sends the policy a supervisor sends

main fails scripts/test.sh at Step 5f on every platform:

    === Step 5f: worker request-scope regression ===
    worker did not index the admitted repository
    {"content":[{"type":"text","text":"missing or incomplete trusted
    worker policy"}], ... "isError":true}

Second collision from the #1723 merge (92abefa3), and the same kind as
the first. #1723 made an index worker refuse any request that does not
carry `_cbm_index_policy`: a worker never resolves the resource policy
from config or environment, the supervisor does and sends it along.
tests/test_worker_session_scope.sh, added on 2026-09-06 by a08b9ecb,
plays the supervisor by hand -- it runs `cli --index-worker
index_repository '{"repo_path":...,"mode":"fast"}'` directly -- and
#1723's branch never contained that script, so its CI never ran the two
together. The merge was textually clean and the result was wrong. It
stayed hidden behind the lint failure the previous commit fixes, because
the test stage only runs once lint is green.

The worker is right and the script was incomplete: it now sends what the
supervisor sends, both limits off, which is the default
(`"index_max_files":"off","index_max_source_mb":"off"`, the same object
tests/test_index_policy.c uses). The fail-closed case carries it too, so
that a request without repo_path is still refused for its missing scope
("request workspace scope invalid") and not, by accident, for a missing
policy. No assertion changed.

RED, production binary built from this branch, script unmodified:
    worker did not index the admitted repository
    ... "missing or incomplete trusted worker policy" ...      rc=1
GREEN:
    ok: index worker is scoped to the admitted request, not the daemon
    environment                                                  rc=0

On the failed CI run of this PR, 12 of the 13 red test jobs carry exactly
that signature and nothing else. The 13th, test-windows-guards, is
test_daemon_stability.py section_cold_storm ("secure CLI coordination
could not be created (endpoint)", a racing cold start) -- a known
nondeterministic guard, unrelated to either commit here. Step 6, which
Step 5f's failure kept CI from reaching, passes locally:
security-strings allow-list 4 passed, destructive-ordering contract PASS.

Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com>
M
Martin Vogel committed
c1128db8187db2dac27a7ad14120fc09802c8018
Parent: af3e003