feat(fleet): brain-home split — fleet state under ~/.mosaic, templates stay config-home (#1298)
ci/woodpecker/push/publish Pipeline failed
ci/woodpecker/push/publish Pipeline failed
Co-authored-by: Jason Woltje <[email protected]>
This commit was merged in pull request #1298.
This commit is contained in:
@@ -0,0 +1,114 @@
|
||||
import { mkdir, mkdtemp, rm } from 'node:fs/promises';
|
||||
import { homedir, tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
|
||||
import {
|
||||
brainHomeIsActive,
|
||||
fleetAgentEnvDir,
|
||||
fleetProfilesDir,
|
||||
fleetRolesLocalDir,
|
||||
fleetStateDir,
|
||||
resolveBrainHome,
|
||||
type BrainHomeOptions,
|
||||
} from './brain-home.js';
|
||||
|
||||
describe('fleet brain-home resolution', (): void => {
|
||||
let cleanup: string | undefined;
|
||||
|
||||
const savedBrainEnv = process.env['MOSAIC_BRAIN_HOME'];
|
||||
|
||||
beforeEach((): void => {
|
||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||
});
|
||||
|
||||
afterEach(async (): Promise<void> => {
|
||||
if (savedBrainEnv === undefined) {
|
||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||
} else {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = savedBrainEnv;
|
||||
}
|
||||
if (cleanup !== undefined) {
|
||||
await rm(cleanup, { recursive: true, force: true });
|
||||
cleanup = undefined;
|
||||
}
|
||||
});
|
||||
|
||||
async function makeTmp(): Promise<string> {
|
||||
const root = await mkdtemp(join(tmpdir(), 'mosaic-brain-home-'));
|
||||
cleanup = root;
|
||||
return root;
|
||||
}
|
||||
|
||||
it('MOSAIC_BRAIN_HOME env wins over every other signal', (): void => {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = '/explicit/brain';
|
||||
expect(resolveBrainHome('/any/mosaic-home')).toBe('/explicit/brain');
|
||||
expect(fleetAgentEnvDir('/any/mosaic-home')).toBe('/explicit/brain/fleet/agents');
|
||||
expect(brainHomeIsActive('/any/mosaic-home')).toBe(true);
|
||||
});
|
||||
|
||||
it('injected envBrainHome wins identically (test seam)', (): void => {
|
||||
const opts: BrainHomeOptions = { envBrainHome: '/injected/brain' };
|
||||
expect(resolveBrainHome('/any/mosaic-home', opts)).toBe('/injected/brain');
|
||||
expect(fleetAgentEnvDir('/any/mosaic-home', opts)).toBe('/injected/brain/fleet/agents');
|
||||
});
|
||||
|
||||
it('a non-default mosaicHome never adopts the canonical brain (hermetic legacy)', (): void => {
|
||||
const mosaicHome = '/tmp/not-the-default-config-home';
|
||||
expect(resolveBrainHome(mosaicHome)).toBe(mosaicHome);
|
||||
expect(brainHomeIsActive(mosaicHome)).toBe(false);
|
||||
expect(fleetAgentEnvDir(mosaicHome)).toBe(join(mosaicHome, 'fleet', 'agents'));
|
||||
});
|
||||
|
||||
it('the default config home adopts the brain when it carries fleet/agents', async (): Promise<void> => {
|
||||
const root = await makeTmp();
|
||||
const brain = join(root, 'brain');
|
||||
await mkdir(join(brain, 'fleet', 'agents'), { recursive: true });
|
||||
const configHome = join(root, 'config', 'mosaic');
|
||||
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
|
||||
|
||||
expect(resolveBrainHome(configHome, opts)).toBe(brain);
|
||||
expect(fleetAgentEnvDir(configHome, opts)).toBe(join(brain, 'fleet', 'agents'));
|
||||
expect(fleetRolesLocalDir(configHome, opts)).toBe(join(brain, 'fleet', 'roles.local'));
|
||||
expect(fleetProfilesDir(configHome, opts)).toBe(join(brain, 'fleet', 'profiles'));
|
||||
expect(fleetStateDir(configHome, opts)).toBe(join(brain, 'fleet'));
|
||||
expect(brainHomeIsActive(configHome, opts)).toBe(true);
|
||||
});
|
||||
|
||||
it('the default config home stays legacy when no brain exists', async (): Promise<void> => {
|
||||
const root = await makeTmp();
|
||||
const configHome = join(root, 'config', 'mosaic');
|
||||
const opts: BrainHomeOptions = {
|
||||
homes: { brain: join(root, 'brain'), configDefault: configHome },
|
||||
};
|
||||
|
||||
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
|
||||
expect(brainHomeIsActive(configHome, opts)).toBe(false);
|
||||
});
|
||||
|
||||
it('an empty MOSAIC_BRAIN_HOME is ignored, not treated as set', (): void => {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = ' ';
|
||||
expect(resolveBrainHome('/tmp/legacy-home')).toBe('/tmp/legacy-home');
|
||||
});
|
||||
|
||||
it('adoption requires fleet/agents specifically, not any brain content', async (): Promise<void> => {
|
||||
const root = await makeTmp();
|
||||
const brain = join(root, 'brain');
|
||||
await mkdir(join(brain, 'fleet'), { recursive: true }); // fleet without agents
|
||||
const configHome = join(root, 'config', 'mosaic');
|
||||
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
|
||||
|
||||
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
|
||||
});
|
||||
|
||||
it('real-home control: a host brain is adopted only through the default home', (): void => {
|
||||
// Control on the un-injected path: this host carries ~/.mosaic/fleet/agents,
|
||||
// so the default config home resolves to the brain or legacy — both valid
|
||||
// canonical endpoints — while a non-default home never adopts.
|
||||
const defaultHome = join(homedir(), '.config', 'mosaic');
|
||||
const resolved = resolveBrainHome(defaultHome);
|
||||
expect([defaultHome, join(homedir(), '.mosaic')]).toContain(resolved);
|
||||
expect(resolveBrainHome(join(homedir(), 'elsewhere', 'mosaic'))).toBe(
|
||||
join(homedir(), 'elsewhere', 'mosaic'),
|
||||
);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,76 @@
|
||||
import { existsSync } from 'node:fs';
|
||||
import { homedir } from 'node:os';
|
||||
import { join, resolve } from 'node:path';
|
||||
|
||||
/**
|
||||
* Overridable resolution inputs (tests inject tmp homes; production reads
|
||||
* the environment and the real home directory).
|
||||
*/
|
||||
export interface BrainHomeOptions {
|
||||
/** Explicit brain home; defaults to `MOSAIC_BRAIN_HOME`. */
|
||||
readonly envBrainHome?: string;
|
||||
/**
|
||||
* Canonical homes used for adoption. Defaults derive from the real
|
||||
* `homedir()`: `{ brain: ~/.mosaic, configDefault: ~/.config/mosaic }`.
|
||||
*/
|
||||
readonly homes?: { readonly brain: string; readonly configDefault: string };
|
||||
}
|
||||
|
||||
/**
|
||||
* Brain-home resolution — the three-tree fleet split (stack canon
|
||||
* `docs/STRUCTURE-CANON.md` §2, first carried by the USC estate brain):
|
||||
*
|
||||
* config home (~/.config/mosaic) framework templates + dispatch state:
|
||||
* fleet/roles (baseline), fleet/roster.yaml,
|
||||
* fleet/run (heartbeats), fleet/services
|
||||
* brain home (~/.mosaic) user-owned fleet state, committed:
|
||||
* fleet/agents/<seat>.env.*, fleet/roles.local,
|
||||
* fleet/profiles working copies
|
||||
*
|
||||
* Resolution order:
|
||||
* 1. `MOSAIC_BRAIN_HOME` env (explicit, always wins)
|
||||
* 2. canonical `~/.mosaic` — adopted ONLY when mosaicHome is the real
|
||||
* default config home AND `~/.mosaic/fleet/agents` exists. Custom
|
||||
* `--mosaic-home` values (tests, sandboxes, canaries) never trigger
|
||||
* adoption, keeping them hermetic and deterministic.
|
||||
* 3. mosaicHome itself (legacy single-tree behavior).
|
||||
*/
|
||||
export function resolveBrainHome(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
const explicit = options.envBrainHome ?? process.env['MOSAIC_BRAIN_HOME'];
|
||||
if (explicit !== undefined && explicit.trim() !== '') {
|
||||
return explicit;
|
||||
}
|
||||
const homes = options.homes ?? {
|
||||
brain: join(homedir(), '.mosaic'),
|
||||
configDefault: join(homedir(), '.config', 'mosaic'),
|
||||
};
|
||||
if (resolve(mosaicHome) !== resolve(homes.configDefault)) {
|
||||
return mosaicHome;
|
||||
}
|
||||
return existsSync(join(homes.brain, 'fleet', 'agents')) ? homes.brain : mosaicHome;
|
||||
}
|
||||
|
||||
/** True when fleet state resolves somewhere other than the config home. */
|
||||
export function brainHomeIsActive(mosaicHome: string, options: BrainHomeOptions = {}): boolean {
|
||||
return resolve(resolveBrainHome(mosaicHome, options)) !== resolve(mosaicHome);
|
||||
}
|
||||
|
||||
/** Fleet state root (brain home when active, else the config home). */
|
||||
export function fleetStateDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
return join(resolveBrainHome(mosaicHome, options), 'fleet');
|
||||
}
|
||||
|
||||
/** Seat launch envs — `<brainHome>/fleet/agents` when a brain is active. */
|
||||
export function fleetAgentEnvDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
return join(fleetStateDir(mosaicHome, options), 'agents');
|
||||
}
|
||||
|
||||
/** PRESERVE-protected persona override layer — `<brainHome>/fleet/roles.local`. */
|
||||
export function fleetRolesLocalDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
return join(fleetStateDir(mosaicHome, options), 'roles.local');
|
||||
}
|
||||
|
||||
/** System-type profiles (user working copies) — `<brainHome>/fleet/profiles`. */
|
||||
export function fleetProfilesDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
return join(fleetStateDir(mosaicHome, options), 'profiles');
|
||||
}
|
||||
@@ -3,6 +3,7 @@ import { lstat, open, readFile, unlink, type FileHandle } from 'node:fs/promises
|
||||
import { randomUUID } from 'node:crypto';
|
||||
import { homedir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { fleetAgentEnvDir } from './brain-home.js';
|
||||
import {
|
||||
applyPreparedAgentEnvironmentProjection,
|
||||
prepareAgentEnvironmentProjection,
|
||||
@@ -617,7 +618,7 @@ function defaultPrepareProjections(
|
||||
(agent: FleetRosterV2Agent): Promise<PreparedAgentEnvironmentProjection> =>
|
||||
prepareAgentEnvironmentProjection({
|
||||
mosaicHome,
|
||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||
agentName: agent.name,
|
||||
generated: projectRosterV2AgentGeneratedEnv(roster, agent),
|
||||
}),
|
||||
|
||||
@@ -176,6 +176,52 @@ describe('generated fleet agent environment boundary', (): void => {
|
||||
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
||||
});
|
||||
|
||||
it('brain home: accepts and writes projections under MOSAIC_BRAIN_HOME/fleet/agents', async (): Promise<void> => {
|
||||
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
|
||||
try {
|
||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
||||
const mosaicHome = join(cleanup, 'config-home');
|
||||
const brainHome = join(cleanup, 'brain');
|
||||
const agentEnvDir = join(brainHome, 'fleet', 'agents');
|
||||
process.env['MOSAIC_BRAIN_HOME'] = brainHome;
|
||||
|
||||
const result = await writeAgentEnvironmentProjection({
|
||||
mosaicHome,
|
||||
agentEnvDir,
|
||||
agentName: 'coder0',
|
||||
generated: generatedValues,
|
||||
});
|
||||
|
||||
// Projection landed in the brain tree, not under the config home.
|
||||
expect(result.generatedPath).toBe(join(agentEnvDir, 'coder0.env.generated'));
|
||||
expect((await stat(join(brainHome, 'fleet'))).mode & 0o777).toBe(0o700);
|
||||
expect((await stat(agentEnvDir)).mode & 0o777).toBe(0o700);
|
||||
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
||||
await expect(stat(join(mosaicHome, 'fleet'))).rejects.toThrow();
|
||||
|
||||
// A config-home agentEnvDir is now REJECTED while the brain is active —
|
||||
// the boundary must not silently split state across two trees.
|
||||
let rejected: unknown;
|
||||
try {
|
||||
await writeAgentEnvironmentProjection({
|
||||
mosaicHome,
|
||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||
agentName: 'coder1',
|
||||
generated: { ...generatedValues, MOSAIC_AGENT_NAME: 'coder1' },
|
||||
});
|
||||
} catch (caught: unknown) {
|
||||
rejected = caught;
|
||||
}
|
||||
expect(rejected).toBeInstanceOf(AgentEnvBoundaryError);
|
||||
} finally {
|
||||
if (savedBrainHome === undefined) {
|
||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||
} else {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
it('regenerates desired keys, relocates safe legacy local data, and quarantines forbidden legacy input', async (): Promise<void> => {
|
||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
||||
const mosaicHome = join(cleanup, 'mosaic');
|
||||
|
||||
@@ -2,6 +2,7 @@ import { createHash, randomUUID } from 'node:crypto';
|
||||
import { chmod, lstat, mkdir, readFile, rename, unlink, writeFile } from 'node:fs/promises';
|
||||
import { homedir } from 'node:os';
|
||||
import { dirname, join, resolve } from 'node:path';
|
||||
import { fleetAgentEnvDir, resolveBrainHome } from './brain-home.js';
|
||||
import { compareCodePoints } from './deterministic-order.js';
|
||||
|
||||
export type AgentEnvironmentKind = 'generated' | 'local';
|
||||
@@ -528,12 +529,15 @@ async function validatePrivateProjectionDirectory(
|
||||
mosaicHome: string,
|
||||
agentEnvDir: string,
|
||||
): Promise<void> {
|
||||
const fleetDir = join(mosaicHome, 'fleet');
|
||||
const expectedAgentEnvDir = join(fleetDir, 'agents');
|
||||
// Brain-home split (canon §2): seat envs live under the brain home's
|
||||
// fleet/agents when a brain is active; roster + templates stay config-home.
|
||||
const expectedAgentEnvDir = fleetAgentEnvDir(mosaicHome);
|
||||
if (resolve(agentEnvDir) !== resolve(expectedAgentEnvDir)) {
|
||||
throw new AgentEnvBoundaryError('unsafe-directory', '(directory)', agentEnvDir);
|
||||
}
|
||||
await assertManagedDirectoryIfPresent(mosaicHome, false);
|
||||
const stateHome = resolveBrainHome(mosaicHome);
|
||||
const fleetDir = join(stateHome, 'fleet');
|
||||
await assertManagedDirectoryIfPresent(stateHome, false);
|
||||
await assertManagedDirectoryIfPresent(fleetDir, false);
|
||||
await assertManagedDirectoryIfPresent(agentEnvDir, true);
|
||||
}
|
||||
@@ -543,8 +547,9 @@ async function ensurePrivateProjectionDirectory(
|
||||
agentEnvDir: string,
|
||||
): Promise<void> {
|
||||
await validatePrivateProjectionDirectory(mosaicHome, agentEnvDir);
|
||||
const fleetDir = join(mosaicHome, 'fleet');
|
||||
await ensureManagedDirectory(mosaicHome, false);
|
||||
const stateHome = resolveBrainHome(mosaicHome);
|
||||
const fleetDir = join(stateHome, 'fleet');
|
||||
await ensureManagedDirectory(stateHome, false);
|
||||
await ensureManagedDirectory(fleetDir, false);
|
||||
await ensureManagedDirectory(agentEnvDir, true);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user