feat(wake): W7 A10 idempotent installer + mosaic-wake.service (component-manifest, Gate-A, blank-reset retire, snapshot-guard, fail-closed install-validate) (#911)
Co-authored-by: jason.woltje <jason@diversecanvas.com> Co-committed-by: jason.woltje <jason@diversecanvas.com>
This commit was merged in pull request #911.
This commit is contained in:
@@ -39,10 +39,19 @@ INSTALL_MODE="${MOSAIC_INSTALL_MODE:-prompt}"
|
||||
# never an environment variable — so this opt-out can never sit silently
|
||||
# inherited in a shell profile. See #869 Point-1 C2.
|
||||
ALLOW_INACTIVE_ENFORCEMENT=0
|
||||
# Component-scoped install (#892 W7): `install.sh --component <name>` runs an
|
||||
# additive, self-contained component installer and EXITS — it never enters the
|
||||
# full-framework sync below and never modifies framework-manifest ownership
|
||||
# behavior (#869: the diff is ADDITIVE). Parsed as a two-token flag here.
|
||||
COMPONENT=""
|
||||
_prev_arg=""
|
||||
for _arg in "$@"; do
|
||||
case "$_arg" in
|
||||
--allow-inactive-enforcement) ALLOW_INACTIVE_ENFORCEMENT=1 ;;
|
||||
--component=*) COMPONENT="${_arg#--component=}" ;;
|
||||
esac
|
||||
[[ "$_prev_arg" == "--component" ]] && COMPONENT="$_arg"
|
||||
_prev_arg="$_arg"
|
||||
done
|
||||
|
||||
# Shared framework path-ownership manifest reader (#791). Parity with
|
||||
@@ -605,6 +614,46 @@ run_migrations() {
|
||||
fi
|
||||
}
|
||||
|
||||
# ═══════════════════════════════════════════════════════════════════════════════
|
||||
# Component-scoped install (#892 W7) — additive early dispatch.
|
||||
# ═══════════════════════════════════════════════════════════════════════════════
|
||||
# `install.sh --component <name>` delegates to the component's own idempotent,
|
||||
# fail-closed installer and EXITS. This path is ADDITIVE (#869): it does NOT run
|
||||
# the full-framework sync, does NOT alter framework-manifest ownership behavior,
|
||||
# and touches NOTHING the #869 install-ordering-guard covers (no runtime-asset
|
||||
# linking, no lease-enforcement hook wiring). Each component installer is
|
||||
# INTERSECTED-AND-VALIDATED against the single SSOT framework-manifest.txt, so a
|
||||
# component manifest can never authorize a write outside framework ownership.
|
||||
run_component_install() {
|
||||
local name="$1"
|
||||
case "$name" in
|
||||
wake)
|
||||
local wi="$SOURCE_DIR/tools/wake/wake-install.sh"
|
||||
if [[ ! -x "$wi" && ! -f "$wi" ]]; then
|
||||
fail "Component 'wake' installer not found at $wi"
|
||||
exit 1
|
||||
fi
|
||||
step "Installing Mosaic component: wake"
|
||||
WAKE_INSTALL_SOURCE="$SOURCE_DIR" WAKE_INSTALL_TARGET="$TARGET_DIR" \
|
||||
bash "$wi" install
|
||||
;;
|
||||
"")
|
||||
fail "--component requires a name (e.g. --component wake)."
|
||||
exit 1
|
||||
;;
|
||||
*)
|
||||
fail "Unknown component '$name'. Supported: wake."
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
if [[ -n "$COMPONENT" ]]; then
|
||||
mkdir -p "$TARGET_DIR"
|
||||
run_component_install "$COMPONENT"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# ═══════════════════════════════════════════════════════════════════════════════
|
||||
# Main
|
||||
# ═══════════════════════════════════════════════════════════════════════════════
|
||||
|
||||
Reference in New Issue
Block a user