What happens
project-bin/test-stack-up.sh proves that a serving port is this project's only one way: through a Docker container under <project>/.docker (owned_app_port, ~l.131; find_app_port, ~l.161-177). An app started by mxcli run --local is the documented local loop, and it has no such container. The port is found by scan and recorded as APP_OWNERSHIP=unverified in stack.env. The harness then refuses it unless the port is asserted by hand (ALLOW_UNVERIFIED_APP=1 / APP_PORT=…), on every run.
Evidence (card-disbursement requirements-driven build, 2026-09-25)
- Every journey run in the project needed
APP_PORT=8080 asserted by hand. There is a register ruling for it.
- The proof of ownership was available all along. The runtime's java process runs
runtimelauncher.jar <project>/app/deployment (read from /proc/<pid>/cmdline), which names this project's own deployment directory.
Suggested fix
In find_app_port (or owned_app_port), after the container check, accept a second proof:
- Find the PID listening on the candidate port:
- Linux:
ss -ltnp or /proc/net/tcp → inode → /proc/*/fd;
- macOS:
lsof -nP -iTCP:<port> -sTCP:LISTEN.
- Read its command line:
- Linux:
/proc/<pid>/cmdline;
- macOS/Git Bash:
ps -o args= -p <pid>.
- Record
APP_OWNERSHIP=verified only when the command line runs runtimelauncher.jar and its argument resolves (realpath) to this project's deployment directory. Check both layouts: <root>/deployment and <root>/app/deployment on a two-tree checkout.
- Otherwise it stays unverified, as today.
Filed rather than fixed because the field-proof bar needs a run against a live run --local app on each platform. test-stack-up.sh also probes the port over HTTP, which could not be done against the field app from this session.
Files
project-bin/test-stack-up.sh: owned_app_port, find_app_port, publish_stack_env
project-bin/_common.sh: platform helpers
skills/testing-shape.md: stack ownership
What happens
project-bin/test-stack-up.shproves that a serving port is this project's only one way: through a Docker container under<project>/.docker(owned_app_port, ~l.131;find_app_port, ~l.161-177). An app started bymxcli run --localis the documented local loop, and it has no such container. The port is found by scan and recorded asAPP_OWNERSHIP=unverifiedinstack.env. The harness then refuses it unless the port is asserted by hand (ALLOW_UNVERIFIED_APP=1/APP_PORT=…), on every run.Evidence (card-disbursement requirements-driven build, 2026-09-25)
APP_PORT=8080asserted by hand. There is a register ruling for it.runtimelauncher.jar <project>/app/deployment(read from/proc/<pid>/cmdline), which names this project's own deployment directory.Suggested fix
In
find_app_port(orowned_app_port), after the container check, accept a second proof:ss -ltnpor/proc/net/tcp→ inode →/proc/*/fd;lsof -nP -iTCP:<port> -sTCP:LISTEN./proc/<pid>/cmdline;ps -o args= -p <pid>.APP_OWNERSHIP=verifiedonly when the command line runsruntimelauncher.jarand its argument resolves (realpath) to this project'sdeploymentdirectory. Check both layouts:<root>/deploymentand<root>/app/deploymenton a two-tree checkout.Filed rather than fixed because the field-proof bar needs a run against a live
run --localapp on each platform.test-stack-up.shalso probes the port over HTTP, which could not be done against the field app from this session.Files
project-bin/test-stack-up.sh:owned_app_port,find_app_port,publish_stack_envproject-bin/_common.sh: platform helpersskills/testing-shape.md: stack ownership