feat(mosaic): install-ordering guard for lease-enforcement hook wiring (#869 Point-1 C2)
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
mosaic-link-runtime-assets wired the PreToolUse mutator-gate.py and Stop
receipt-observer-client.py hooks into ~/.claude/settings.json unconditionally.
If the activation half (C1's leaseEnforcementActivatable()) can't be
confirmed on the host, the fail-closed gate then denies every tool call —
bricking it.
Add a TS install-ordering guard (guardClaudeSettingsWiring /
runInstallOrderingGuard, hidden CLI bridge `mosaic __link-claude-settings`)
that imports leaseEnforcementActivatable() directly and decides whether the
enforcement hooks get wired:
- activatable -> wire as-is.
- NOT activatable, no opt-out -> strip the enforcement hooks, exit
non-zero with an actionable message
(default, fail-loud).
- NOT activatable + explicit
--allow-inactive-enforcement -> wire anyway, loud warning logged.
--allow-inactive-enforcement is a real CLI flag threaded through
install.sh -> mosaic-link-runtime-assets -> the hidden subcommand —
deliberately never an environment variable, so it can't sit as a
silently-inherited default. Wire mosaic-link-runtime-assets's guarded
settings.json copy to call out to the CLI (with a python3 fallback if
`mosaic` isn't resolvable at all), and stop swallowing stderr in
install.sh/finalize.ts so the guard's message actually reaches the operator.
mutator-gate.py's own fail-closed-on-absent-identity runtime behavior is
untouched (this only gates the WIRING); runtime_tools_unittest.py and
fail-closed-regression.spec.ts remain green.
Part of #869 (Point-1 C2)
This commit is contained in:
@@ -22,6 +22,7 @@ import { registerSkillCommand } from './commands/skill.js';
|
||||
// prdy is registered via launch.ts
|
||||
import { registerLaunchCommands } from './commands/launch.js';
|
||||
import { registerLeaseCapabilityProbe } from './commands/lease-activation-probe.js';
|
||||
import { registerInstallOrderingGuardCommand } from './commands/install-ordering-guard.js';
|
||||
import { registerAuthCommand } from './commands/auth.js';
|
||||
import { registerFederationCommand } from './commands/federation.js';
|
||||
import { registerGatewayCommand } from './commands/gateway.js';
|
||||
@@ -83,6 +84,10 @@ registerLaunchCommands(program);
|
||||
|
||||
registerLeaseCapabilityProbe(program);
|
||||
|
||||
// ─── install-ordering guard (hidden; #869 Point-1 C2) ───────────────────
|
||||
|
||||
registerInstallOrderingGuardCommand(program);
|
||||
|
||||
// ─── login ──────────────────────────────────────────────────────────────
|
||||
|
||||
program
|
||||
|
||||
301
packages/mosaic/src/commands/install-ordering-guard.spec.ts
Normal file
301
packages/mosaic/src/commands/install-ordering-guard.spec.ts
Normal file
@@ -0,0 +1,301 @@
|
||||
import { describe, it, expect, afterEach } from 'vitest';
|
||||
import { mkdtempSync, rmSync, writeFileSync, readFileSync, existsSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { leaseEnforcementActivatable } from './lease-activation-probe.js';
|
||||
import {
|
||||
ENFORCEMENT_HOOK_MARKERS,
|
||||
FAIL_LOUD_MESSAGE,
|
||||
guardClaudeSettingsWiring,
|
||||
loudOptOutMessage,
|
||||
runInstallOrderingGuard,
|
||||
settingsHasEnforcementHooks,
|
||||
stripEnforcementHooks,
|
||||
} from './install-ordering-guard.js';
|
||||
|
||||
/**
|
||||
* Red-first tests for issue #869 Point-1 C2 — the install-ordering guard.
|
||||
*
|
||||
* Root cause under test: `mosaic-link-runtime-assets` copies
|
||||
* `runtime/claude/settings.json` (which embeds the PreToolUse
|
||||
* `mutator-gate.py` hook and the Stop `receipt-observer-client.py` hook)
|
||||
* straight into `~/.claude/settings.json`, unconditionally. If the
|
||||
* activation half (C1: `leaseEnforcementActivatable()`) cannot be confirmed,
|
||||
* wiring those hooks bricks the host with a fail-closed gate that can never
|
||||
* be satisfied. This guard must refuse to wire in that case by default, and
|
||||
* only wire anyway on an explicit, loud opt-out.
|
||||
*
|
||||
* All fixtures use temp directories — this suite never reads or writes the
|
||||
* real `~/.claude/settings.json`.
|
||||
*/
|
||||
|
||||
const FIXTURE_SETTINGS = {
|
||||
model: 'opus',
|
||||
hooks: {
|
||||
PreCompact: [
|
||||
{
|
||||
matcher: '.*',
|
||||
hooks: [{ type: 'command', command: 'python3 revoke-lease.py --reason pre-compact' }],
|
||||
},
|
||||
],
|
||||
PreToolUse: [
|
||||
{
|
||||
matcher: '.*',
|
||||
hooks: [
|
||||
{
|
||||
type: 'command',
|
||||
command: 'python3 ~/.config/mosaic/tools/lease-broker/mutator-gate.py --runtime claude',
|
||||
timeout: 3,
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
matcher: 'Write|Edit|MultiEdit',
|
||||
hooks: [{ type: 'command', command: '~/.config/mosaic/tools/qa/prevent-memory-write.sh' }],
|
||||
},
|
||||
],
|
||||
PostToolUse: [
|
||||
{
|
||||
matcher: 'Edit|MultiEdit|Write',
|
||||
hooks: [{ type: 'command', command: '~/.config/mosaic/tools/qa/qa-hook-stdin.sh' }],
|
||||
},
|
||||
],
|
||||
Stop: [
|
||||
{
|
||||
hooks: [
|
||||
{
|
||||
type: 'command',
|
||||
command:
|
||||
'python3 ~/.config/mosaic/tools/lease-broker/receipt-observer-client.py --runtime claude',
|
||||
timeout: 3,
|
||||
},
|
||||
{ type: 'command', command: '~/.config/mosaic/tools/qa/reflect-stop-hook.sh' },
|
||||
],
|
||||
},
|
||||
],
|
||||
},
|
||||
enabledPlugins: { 'feature-dev@claude-plugins-official': true },
|
||||
};
|
||||
|
||||
function fixtureJson(): string {
|
||||
return JSON.stringify(FIXTURE_SETTINGS, null, 2) + '\n';
|
||||
}
|
||||
|
||||
describe('stripEnforcementHooks', () => {
|
||||
it('removes the PreToolUse mutator-gate trigger entirely', () => {
|
||||
const { settings } = stripEnforcementHooks(FIXTURE_SETTINGS);
|
||||
const hooks = settings['hooks'] as Record<string, unknown[]>;
|
||||
const preToolUse = hooks['PreToolUse'] as Array<{ hooks: Array<{ command: string }> }>;
|
||||
expect(preToolUse.some((t) => t.hooks.some((h) => h.command.includes('mutator-gate.py')))).toBe(
|
||||
false,
|
||||
);
|
||||
});
|
||||
|
||||
it('preserves the sibling prevent-memory-write.sh PreToolUse trigger', () => {
|
||||
const { settings } = stripEnforcementHooks(FIXTURE_SETTINGS);
|
||||
const hooks = settings['hooks'] as Record<string, unknown[]>;
|
||||
const preToolUse = hooks['PreToolUse'] as Array<{ hooks: Array<{ command: string }> }>;
|
||||
expect(
|
||||
preToolUse.some((t) => t.hooks.some((h) => h.command.includes('prevent-memory-write.sh'))),
|
||||
).toBe(true);
|
||||
});
|
||||
|
||||
it('removes only the receipt-observer-client.py hook from Stop, keeping reflect-stop-hook.sh', () => {
|
||||
const { settings } = stripEnforcementHooks(FIXTURE_SETTINGS);
|
||||
const hooks = settings['hooks'] as Record<string, unknown[]>;
|
||||
const stop = hooks['Stop'] as Array<{ hooks: Array<{ command: string }> }>;
|
||||
const commands = stop.flatMap((t) => t.hooks.map((h) => h.command));
|
||||
expect(commands.some((c) => c.includes('receipt-observer-client.py'))).toBe(false);
|
||||
expect(commands.some((c) => c.includes('reflect-stop-hook.sh'))).toBe(true);
|
||||
});
|
||||
|
||||
it('leaves PreCompact/PostToolUse hooks byte-identical', () => {
|
||||
const { settings } = stripEnforcementHooks(FIXTURE_SETTINGS);
|
||||
const hooks = settings['hooks'] as Record<string, unknown>;
|
||||
expect(hooks['PreCompact']).toEqual(FIXTURE_SETTINGS.hooks.PreCompact);
|
||||
expect(hooks['PostToolUse']).toEqual(FIXTURE_SETTINGS.hooks.PostToolUse);
|
||||
});
|
||||
|
||||
it('reports what it removed', () => {
|
||||
const { removed } = stripEnforcementHooks(FIXTURE_SETTINGS);
|
||||
expect(removed).toContain(`PreToolUse:${ENFORCEMENT_HOOK_MARKERS.preToolUse}`);
|
||||
expect(removed).toContain(`Stop:${ENFORCEMENT_HOOK_MARKERS.stop}`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('settingsHasEnforcementHooks', () => {
|
||||
it('is true for the unmodified fixture', () => {
|
||||
expect(settingsHasEnforcementHooks(FIXTURE_SETTINGS)).toBe(true);
|
||||
});
|
||||
|
||||
it('is false after stripping', () => {
|
||||
const { settings } = stripEnforcementHooks(FIXTURE_SETTINGS);
|
||||
expect(settingsHasEnforcementHooks(settings)).toBe(false);
|
||||
});
|
||||
|
||||
it('is false for settings with no hooks key at all', () => {
|
||||
expect(settingsHasEnforcementHooks({ model: 'opus' })).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe('guardClaudeSettingsWiring', () => {
|
||||
it('probe=false (default, no opt-out): strips enforcement hooks and reports non-zero with a loud, actionable message', () => {
|
||||
const outcome = guardClaudeSettingsWiring(fixtureJson(), {}, { activatable: () => false });
|
||||
|
||||
expect(outcome.exitCode).toBe(1);
|
||||
expect(outcome.wired).toBe(false);
|
||||
expect(settingsHasEnforcementHooks(JSON.parse(outcome.json) as Record<string, unknown>)).toBe(
|
||||
false,
|
||||
);
|
||||
expect(outcome.logs).toHaveLength(1);
|
||||
expect(outcome.logs[0]?.level).toBe('error');
|
||||
expect(outcome.logs[0]?.message).toBe(FAIL_LOUD_MESSAGE);
|
||||
expect(outcome.logs[0]?.message).toMatch(/refusing to wire a dead gate/i);
|
||||
expect(outcome.logs[0]?.message).toMatch(/#869/);
|
||||
expect(outcome.logs[0]?.message).toMatch(/--allow-inactive-enforcement/);
|
||||
});
|
||||
|
||||
it('probe=false + explicit opt-out flag: wires hooks as-is and emits a loud warning', () => {
|
||||
const outcome = guardClaudeSettingsWiring(
|
||||
fixtureJson(),
|
||||
{ allowInactiveEnforcement: true },
|
||||
{ activatable: () => false },
|
||||
);
|
||||
|
||||
expect(outcome.exitCode).toBe(0);
|
||||
expect(outcome.wired).toBe(true);
|
||||
expect(settingsHasEnforcementHooks(JSON.parse(outcome.json) as Record<string, unknown>)).toBe(
|
||||
true,
|
||||
);
|
||||
expect(outcome.logs).toHaveLength(1);
|
||||
expect(outcome.logs[0]?.level).toBe('warn');
|
||||
expect(outcome.logs[0]?.message).toBe(loudOptOutMessage());
|
||||
expect(outcome.logs[0]?.message).toMatch(/WITHOUT confirmed activation/);
|
||||
});
|
||||
|
||||
it('probe=true: wires hooks normally with no logs, regardless of opt-out', () => {
|
||||
const outcome = guardClaudeSettingsWiring(fixtureJson(), {}, { activatable: () => true });
|
||||
|
||||
expect(outcome.exitCode).toBe(0);
|
||||
expect(outcome.wired).toBe(true);
|
||||
expect(outcome.logs).toHaveLength(0);
|
||||
expect(JSON.parse(outcome.json)).toEqual(FIXTURE_SETTINGS);
|
||||
});
|
||||
|
||||
it('probe=true + opt-out flag set anyway: still wires normally, no spurious warning', () => {
|
||||
const outcome = guardClaudeSettingsWiring(
|
||||
fixtureJson(),
|
||||
{ allowInactiveEnforcement: true },
|
||||
{ activatable: () => true },
|
||||
);
|
||||
|
||||
expect(outcome.exitCode).toBe(0);
|
||||
expect(outcome.wired).toBe(true);
|
||||
expect(outcome.logs).toHaveLength(0);
|
||||
});
|
||||
|
||||
it('defaults to the real leaseEnforcementActivatable() when no activatable dep is injected', () => {
|
||||
// Deliberately does not assume a fixed true/false value for the real
|
||||
// probe (whether dist/cli.js happens to be built varies by environment —
|
||||
// asserting a hardcoded expectation here would make the test flaky, not
|
||||
// red-first). Instead it proves the wiring is genuinely delegated: the
|
||||
// no-deps call must agree with an explicit call to the same real
|
||||
// predicate, not some other hardcoded value.
|
||||
const reallyActivatable = leaseEnforcementActivatable();
|
||||
const outcome = guardClaudeSettingsWiring(fixtureJson());
|
||||
|
||||
if (reallyActivatable) {
|
||||
expect(outcome.exitCode).toBe(0);
|
||||
expect(outcome.wired).toBe(true);
|
||||
} else {
|
||||
expect(outcome.exitCode).toBe(1);
|
||||
expect(outcome.wired).toBe(false);
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe('runInstallOrderingGuard (file-level, temp dirs only)', () => {
|
||||
let dir: string;
|
||||
|
||||
afterEach(() => {
|
||||
if (dir) rmSync(dir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
function makeSrc(): string {
|
||||
dir = mkdtempSync(join(tmpdir(), 'mosaic-install-ordering-guard-'));
|
||||
const src = join(dir, 'settings.json');
|
||||
writeFileSync(src, fixtureJson());
|
||||
return src;
|
||||
}
|
||||
|
||||
it('probe=false: writes a dest settings.json with hooks stripped and returns exitCode 1', () => {
|
||||
const src = makeSrc();
|
||||
const dest = join(dir, 'claude-settings.json');
|
||||
|
||||
const result = runInstallOrderingGuard(src, dest, {}, { activatable: () => false });
|
||||
|
||||
expect(result.exitCode).toBe(1);
|
||||
expect(result.destWritten).toBe(true);
|
||||
expect(existsSync(dest)).toBe(true);
|
||||
const written = JSON.parse(readFileSync(dest, 'utf-8')) as Record<string, unknown>;
|
||||
expect(settingsHasEnforcementHooks(written)).toBe(false);
|
||||
});
|
||||
|
||||
it('probe=false + opt-out: writes dest with hooks intact and returns exitCode 0', () => {
|
||||
const src = makeSrc();
|
||||
const dest = join(dir, 'claude-settings.json');
|
||||
|
||||
const result = runInstallOrderingGuard(
|
||||
src,
|
||||
dest,
|
||||
{ allowInactiveEnforcement: true },
|
||||
{ activatable: () => false },
|
||||
);
|
||||
|
||||
expect(result.exitCode).toBe(0);
|
||||
const written = JSON.parse(readFileSync(dest, 'utf-8')) as Record<string, unknown>;
|
||||
expect(settingsHasEnforcementHooks(written)).toBe(true);
|
||||
});
|
||||
|
||||
it('probe=true: writes dest with hooks intact and returns exitCode 0', () => {
|
||||
const src = makeSrc();
|
||||
const dest = join(dir, 'claude-settings.json');
|
||||
|
||||
const result = runInstallOrderingGuard(src, dest, {}, { activatable: () => true });
|
||||
|
||||
expect(result.exitCode).toBe(0);
|
||||
const written = JSON.parse(readFileSync(dest, 'utf-8')) as Record<string, unknown>;
|
||||
expect(settingsHasEnforcementHooks(written)).toBe(true);
|
||||
});
|
||||
|
||||
it('backs up a pre-existing divergent dest before overwriting (copy_file_managed parity)', () => {
|
||||
const src = makeSrc();
|
||||
const dest = join(dir, 'claude-settings.json');
|
||||
writeFileSync(dest, JSON.stringify({ preexisting: true }));
|
||||
|
||||
const result = runInstallOrderingGuard(src, dest, {}, { activatable: () => true });
|
||||
|
||||
expect(result.destWritten).toBe(true);
|
||||
expect(result.backupPath).toBeDefined();
|
||||
expect(existsSync(result.backupPath!)).toBe(true);
|
||||
expect(JSON.parse(readFileSync(result.backupPath!, 'utf-8'))).toEqual({ preexisting: true });
|
||||
});
|
||||
|
||||
it('is a no-op write when dest already matches the guarded content (idempotent)', () => {
|
||||
const src = makeSrc();
|
||||
const dest = join(dir, 'claude-settings.json');
|
||||
|
||||
const first = runInstallOrderingGuard(src, dest, {}, { activatable: () => true });
|
||||
expect(first.destWritten).toBe(true);
|
||||
|
||||
const second = runInstallOrderingGuard(src, dest, {}, { activatable: () => true });
|
||||
expect(second.destWritten).toBe(false);
|
||||
expect(second.backupPath).toBeUndefined();
|
||||
});
|
||||
|
||||
it('never touches the real home directory settings path used by this test file', () => {
|
||||
// Sanity guard for the suite itself: every dest path used above lives
|
||||
// under the mkdtemp() scratch dir, never under homedir()/.claude.
|
||||
expect(dir).toContain('mosaic-install-ordering-guard-');
|
||||
});
|
||||
});
|
||||
327
packages/mosaic/src/commands/install-ordering-guard.ts
Normal file
327
packages/mosaic/src/commands/install-ordering-guard.ts
Normal file
@@ -0,0 +1,327 @@
|
||||
/**
|
||||
* Install-ordering guard (issue #869, Point-1 card C2).
|
||||
*
|
||||
* Root cause this exists to guard against (#828 version skew, restated): the
|
||||
* framework reseed / install path (`framework/install.sh` →
|
||||
* `mosaic-link-runtime-assets` → copies `runtime/claude/settings.json` to
|
||||
* `~/.claude/settings.json`) wires the ENFORCEMENT half of the lease broker —
|
||||
* the `PreToolUse` `mutator-gate.py` hook and the `Stop`
|
||||
* `receipt-observer-client.py` hook — unconditionally. If the ACTIVATION half
|
||||
* (a CLI build advertising launch-runtime activation + a running broker
|
||||
* supervisor — see `lease-activation-probe.ts`, C1) is absent, the fail-closed
|
||||
* gate then denies every tool call with GATE_UNAVAILABLE: a bricked host.
|
||||
*
|
||||
* This module is the WIRING gate, not the enforcement gate: it decides
|
||||
* whether the enforcement hook entries are written into the settings.json
|
||||
* that ships to `~/.claude/`. It never touches `mutator-gate.py`'s own
|
||||
* fail-closed-on-absent-identity runtime behavior (test-locked in
|
||||
* `runtime_tools_unittest.py` / `fail-closed-regression.spec.ts`).
|
||||
*
|
||||
* Default (no opt-out): NOT activatable → strip the enforcement hook entries
|
||||
* from the written settings.json and report a non-zero outcome with a loud,
|
||||
* actionable message (see FAIL_LOUD_MESSAGE below).
|
||||
*
|
||||
* Opt-out: `--allow-inactive-enforcement` (an explicit, per-invocation CLI
|
||||
* flag — deliberately NOT an environment variable, so it can never sit as a
|
||||
* silently-inherited default in a shell profile). When set on a NOT
|
||||
* activatable host, the hooks ARE wired but a loud warning is emitted saying
|
||||
* so, and the outcome is reported ok (this is a conscious, informed choice).
|
||||
*/
|
||||
|
||||
import { existsSync, mkdirSync, readFileSync, writeFileSync } from 'node:fs';
|
||||
import { dirname } from 'node:path';
|
||||
import type { Command } from 'commander';
|
||||
import { leaseEnforcementActivatable } from './lease-activation-probe.js';
|
||||
|
||||
// ─── Enforcement hook identification ────────────────────────────────────────
|
||||
|
||||
/** Substrings that identify the two enforcement hook commands #828 wired
|
||||
* unconditionally. Matches the marker strings documented in
|
||||
* `lease-activation-probe.ts`. */
|
||||
export const ENFORCEMENT_HOOK_MARKERS = {
|
||||
preToolUse: 'mutator-gate.py',
|
||||
stop: 'receipt-observer-client.py',
|
||||
} as const;
|
||||
|
||||
interface HookEntry {
|
||||
command?: string;
|
||||
[key: string]: unknown;
|
||||
}
|
||||
|
||||
interface HookTrigger {
|
||||
matcher?: string;
|
||||
hooks?: HookEntry[];
|
||||
[key: string]: unknown;
|
||||
}
|
||||
|
||||
type HooksMap = Record<string, HookTrigger[]>;
|
||||
|
||||
function cloneJson<T>(value: T): T {
|
||||
return JSON.parse(JSON.stringify(value)) as T;
|
||||
}
|
||||
|
||||
function commandIncludes(hook: HookEntry, marker: string): boolean {
|
||||
return String(hook.command ?? '').includes(marker);
|
||||
}
|
||||
|
||||
/**
|
||||
* Return a deep clone of `settings` with the enforcement hook entries removed:
|
||||
* - Any `PreToolUse` trigger group containing a `mutator-gate.py` command is
|
||||
* dropped in full (that trigger exists solely to run the gate).
|
||||
* - Within `Stop` trigger groups, only the individual `receipt-observer-client.py`
|
||||
* hook entry is dropped; sibling hooks in the same trigger (e.g.
|
||||
* `reflect-stop-hook.sh`) are preserved.
|
||||
* Every other hook (PreCompact/SessionStart revoke-lease, the
|
||||
* `prevent-memory-write.sh` PreToolUse trigger, PostToolUse qa/typecheck
|
||||
* hooks) is left byte-identical — this function only ever removes the two
|
||||
* markers above.
|
||||
*/
|
||||
export function stripEnforcementHooks(settings: Record<string, unknown>): {
|
||||
settings: Record<string, unknown>;
|
||||
removed: string[];
|
||||
} {
|
||||
const cloned = cloneJson(settings);
|
||||
const removed: string[] = [];
|
||||
const hooks = cloned['hooks'] as HooksMap | undefined;
|
||||
if (!hooks || typeof hooks !== 'object') {
|
||||
return { settings: cloned, removed };
|
||||
}
|
||||
|
||||
const preToolUse = hooks['PreToolUse'];
|
||||
if (Array.isArray(preToolUse)) {
|
||||
const kept = preToolUse.filter((trigger) => {
|
||||
const hasGate = (trigger.hooks ?? []).some((h) =>
|
||||
commandIncludes(h, ENFORCEMENT_HOOK_MARKERS.preToolUse),
|
||||
);
|
||||
if (hasGate) removed.push('PreToolUse:mutator-gate.py');
|
||||
return !hasGate;
|
||||
});
|
||||
if (kept.length > 0) hooks['PreToolUse'] = kept;
|
||||
else delete hooks['PreToolUse'];
|
||||
}
|
||||
|
||||
const stop = hooks['Stop'];
|
||||
if (Array.isArray(stop)) {
|
||||
const rebuilt: HookTrigger[] = [];
|
||||
for (const trigger of stop) {
|
||||
const innerHooks = trigger.hooks ?? [];
|
||||
const keptHooks = innerHooks.filter((h) => {
|
||||
const isReceiptObserver = commandIncludes(h, ENFORCEMENT_HOOK_MARKERS.stop);
|
||||
if (isReceiptObserver) removed.push('Stop:receipt-observer-client.py');
|
||||
return !isReceiptObserver;
|
||||
});
|
||||
if (keptHooks.length > 0) {
|
||||
rebuilt.push({ ...trigger, hooks: keptHooks });
|
||||
}
|
||||
}
|
||||
if (rebuilt.length > 0) hooks['Stop'] = rebuilt;
|
||||
else delete hooks['Stop'];
|
||||
}
|
||||
|
||||
if (Object.keys(hooks).length === 0) {
|
||||
delete cloned['hooks'];
|
||||
} else {
|
||||
cloned['hooks'] = hooks;
|
||||
}
|
||||
|
||||
return { settings: cloned, removed };
|
||||
}
|
||||
|
||||
/** True iff `settings` currently wires either enforcement hook. */
|
||||
export function settingsHasEnforcementHooks(settings: Record<string, unknown>): boolean {
|
||||
const hooks = settings['hooks'] as HooksMap | undefined;
|
||||
if (!hooks || typeof hooks !== 'object') return false;
|
||||
|
||||
const preToolUse = hooks['PreToolUse'] ?? [];
|
||||
const preHit = preToolUse.some((trigger) =>
|
||||
(trigger.hooks ?? []).some((h) => commandIncludes(h, ENFORCEMENT_HOOK_MARKERS.preToolUse)),
|
||||
);
|
||||
if (preHit) return true;
|
||||
|
||||
const stop = hooks['Stop'] ?? [];
|
||||
return stop.some((trigger) =>
|
||||
(trigger.hooks ?? []).some((h) => commandIncludes(h, ENFORCEMENT_HOOK_MARKERS.stop)),
|
||||
);
|
||||
}
|
||||
|
||||
// ─── Guard predicate ────────────────────────────────────────────────────────
|
||||
|
||||
export const FAIL_LOUD_MESSAGE =
|
||||
'[mosaic] ERROR: enforcement requested but activation half absent — needs a published CLI ' +
|
||||
'carrying launch-runtime activation + a broker supervisor; refusing to wire a dead gate (see #869). ' +
|
||||
'The PreToolUse mutator-gate.py hook and Stop receipt-observer-client.py hook were NOT written to ' +
|
||||
'settings.json. Fix by installing/updating the CLI and broker, then re-run the framework reseed. ' +
|
||||
'To wire anyway (NOT recommended — the fail-closed gate will deny every tool call with ' +
|
||||
'GATE_UNAVAILABLE until activation is restored), re-run with --allow-inactive-enforcement.';
|
||||
|
||||
export function loudOptOutMessage(): string {
|
||||
return (
|
||||
'[mosaic] WARNING: wiring lease-enforcement hooks (mutator-gate.py / receipt-observer-client.py) ' +
|
||||
'WITHOUT confirmed activation — --allow-inactive-enforcement was set explicitly. The fail-closed ' +
|
||||
'gate will deny every tool call (GATE_UNAVAILABLE) until the activation half (launch-runtime ' +
|
||||
'activation capability + a running broker supervisor) is present on this host (see #869).'
|
||||
);
|
||||
}
|
||||
|
||||
export type GuardLogLevel = 'error' | 'warn';
|
||||
|
||||
export interface GuardLogLine {
|
||||
level: GuardLogLevel;
|
||||
message: string;
|
||||
}
|
||||
|
||||
export interface InstallOrderingGuardOptions {
|
||||
/** Explicit, per-invocation opt-out. Never source this from an environment
|
||||
* variable — see module doc. */
|
||||
allowInactiveEnforcement?: boolean;
|
||||
}
|
||||
|
||||
export interface InstallOrderingGuardDeps {
|
||||
/** Defaults to {@link leaseEnforcementActivatable}. Injectable for tests. */
|
||||
activatable?: () => boolean;
|
||||
}
|
||||
|
||||
export interface InstallOrderingGuardOutcome {
|
||||
/** The settings.json content to write (pretty-printed, trailing newline). */
|
||||
json: string;
|
||||
/** Whether the enforcement hooks are present in `json`. */
|
||||
wired: boolean;
|
||||
/** 0 = proceed normally; 1 = enforcement was refused (fail-loud default path). */
|
||||
exitCode: 0 | 1;
|
||||
logs: GuardLogLine[];
|
||||
}
|
||||
|
||||
/**
|
||||
* The install-ordering guard: decide whether the enforcement hooks embedded
|
||||
* in the Claude settings.json template may be wired into the settings.json
|
||||
* actually shipped to `~/.claude/`.
|
||||
*
|
||||
* - activatable → wire as-is. exitCode 0, no logs.
|
||||
* - NOT activatable, no opt-out → strip enforcement hooks. exitCode 1,
|
||||
* one 'error' log with the actionable FAIL_LOUD_MESSAGE.
|
||||
* - NOT activatable, opt-out set → wire as-is anyway. exitCode 0, one
|
||||
* 'warn' log making the risk explicit and loud.
|
||||
*
|
||||
* Pure function: takes the raw settings.json text, returns the text to write
|
||||
* plus metadata. No filesystem access — callers (the hidden CLI subcommand
|
||||
* below, or a test) own reading/writing so this stays trivially testable with
|
||||
* fakes/temp files and never risks touching a real `~/.claude/settings.json`.
|
||||
*/
|
||||
export function guardClaudeSettingsWiring(
|
||||
rawSettingsJson: string,
|
||||
options: InstallOrderingGuardOptions = {},
|
||||
deps: InstallOrderingGuardDeps = {},
|
||||
): InstallOrderingGuardOutcome {
|
||||
const parsed = JSON.parse(rawSettingsJson) as Record<string, unknown>;
|
||||
const activatable = deps.activatable ?? leaseEnforcementActivatable;
|
||||
const isActivatable = activatable();
|
||||
|
||||
const serialize = (settings: Record<string, unknown>): string =>
|
||||
JSON.stringify(settings, null, 2) + '\n';
|
||||
|
||||
if (isActivatable) {
|
||||
return {
|
||||
json: serialize(parsed),
|
||||
wired: settingsHasEnforcementHooks(parsed),
|
||||
exitCode: 0,
|
||||
logs: [],
|
||||
};
|
||||
}
|
||||
|
||||
if (options.allowInactiveEnforcement === true) {
|
||||
return {
|
||||
json: serialize(parsed),
|
||||
wired: settingsHasEnforcementHooks(parsed),
|
||||
exitCode: 0,
|
||||
logs: [{ level: 'warn', message: loudOptOutMessage() }],
|
||||
};
|
||||
}
|
||||
|
||||
const { settings: stripped } = stripEnforcementHooks(parsed);
|
||||
return {
|
||||
json: serialize(stripped),
|
||||
wired: settingsHasEnforcementHooks(stripped),
|
||||
exitCode: 1,
|
||||
logs: [{ level: 'error', message: FAIL_LOUD_MESSAGE }],
|
||||
};
|
||||
}
|
||||
|
||||
// ─── File-level runner (shared by the CLI action + tests) ──────────────────
|
||||
|
||||
export interface RunInstallOrderingGuardResult extends InstallOrderingGuardOutcome {
|
||||
destWritten: boolean;
|
||||
backupPath?: string;
|
||||
}
|
||||
|
||||
/**
|
||||
* Read `src`, guard it, and write the result to `dest` — mirroring
|
||||
* `copy_file_managed`'s backup-on-change semantics from
|
||||
* `mosaic-link-runtime-assets` (skip the write if content is unchanged;
|
||||
* back up an existing divergent file once, timestamped). Exported standalone
|
||||
* (not only reachable via the CLI action closure) so tests can exercise real
|
||||
* file I/O against temp directories without ever touching `~/.claude/`.
|
||||
*/
|
||||
export function runInstallOrderingGuard(
|
||||
src: string,
|
||||
dest: string,
|
||||
options: InstallOrderingGuardOptions = {},
|
||||
deps: InstallOrderingGuardDeps = {},
|
||||
): RunInstallOrderingGuardResult {
|
||||
const raw = readFileSync(src, 'utf-8');
|
||||
const outcome = guardClaudeSettingsWiring(raw, options, deps);
|
||||
|
||||
mkdirSync(dirname(dest), { recursive: true });
|
||||
|
||||
const existing = existsSync(dest) ? readFileSync(dest, 'utf-8') : null;
|
||||
let destWritten = false;
|
||||
let backupPath: string | undefined;
|
||||
|
||||
if (existing !== outcome.json) {
|
||||
if (existing !== null) {
|
||||
const stamp = new Date()
|
||||
.toISOString()
|
||||
.replace(/[-:]/g, '')
|
||||
.replace(/\..+$/, '')
|
||||
.replace('T', '');
|
||||
backupPath = `${dest}.mosaic-bak-${stamp}`;
|
||||
writeFileSync(backupPath, existing);
|
||||
}
|
||||
writeFileSync(dest, outcome.json);
|
||||
destWritten = true;
|
||||
}
|
||||
|
||||
return { ...outcome, destWritten, backupPath };
|
||||
}
|
||||
|
||||
// ─── Hidden CLI bridge (bash → TS) ──────────────────────────────────────────
|
||||
|
||||
/** Hidden CLI subcommand name. `mosaic-link-runtime-assets` (bash) invokes
|
||||
* this instead of its generic `copy_file_managed` for the settings.json
|
||||
* runtime file specifically, so the guard's decision is made by importing
|
||||
* `leaseEnforcementActivatable()` directly rather than re-implementing the
|
||||
* capability/supervisor probes in shell. Deliberately undocumented (hidden
|
||||
* from `--help`) — internal wiring, not a user-facing command. */
|
||||
export const INSTALL_ORDERING_GUARD_COMMAND = '__link-claude-settings';
|
||||
|
||||
export function registerInstallOrderingGuardCommand(program: Command): void {
|
||||
program
|
||||
.command(`${INSTALL_ORDERING_GUARD_COMMAND} <src> <dest>`, { hidden: true })
|
||||
.description(
|
||||
'Internal: copy the Claude settings.json template, gating enforcement-hook ' +
|
||||
'wiring on lease-activation capability (#869 Point-1 C2)',
|
||||
)
|
||||
.option(
|
||||
'--allow-inactive-enforcement',
|
||||
'Wire enforcement hooks even when activation cannot be confirmed on this host ' +
|
||||
'(explicit, loud, non-default opt-out — see #869)',
|
||||
)
|
||||
.action((src: string, dest: string, opts: { allowInactiveEnforcement?: boolean }) => {
|
||||
const result = runInstallOrderingGuard(src, dest, {
|
||||
allowInactiveEnforcement: opts.allowInactiveEnforcement === true,
|
||||
});
|
||||
for (const line of result.logs) {
|
||||
(line.level === 'error' ? console.error : console.warn)(line.message);
|
||||
}
|
||||
process.exit(result.exitCode);
|
||||
});
|
||||
}
|
||||
@@ -13,22 +13,37 @@ import {
|
||||
type SkillSyncResult as ClaudeSkillSyncResult,
|
||||
} from '../commands/skill.js';
|
||||
|
||||
function linkRuntimeAssets(mosaicHome: string, skipClaudeHooks: boolean): void {
|
||||
/**
|
||||
* Link runtime assets. Returns a warning string when the install-ordering
|
||||
* guard (#869 Point-1 C2) reported a degraded outcome — i.e. the
|
||||
* lease-enforcement hooks were NOT wired into ~/.claude/settings.json because
|
||||
* this host could not confirm it can activate them — so the caller can
|
||||
* surface it via `p.warn(...)` instead of it being swallowed by `stdio:
|
||||
* 'pipe'`. Non-fatal either way: the wizard always continues.
|
||||
*/
|
||||
function linkRuntimeAssets(mosaicHome: string, skipClaudeHooks: boolean): string | undefined {
|
||||
const script = join(mosaicHome, 'bin', 'mosaic-link-runtime-assets');
|
||||
if (existsSync(script)) {
|
||||
try {
|
||||
spawnSync('bash', [script], {
|
||||
timeout: 30000,
|
||||
stdio: 'pipe',
|
||||
env: {
|
||||
...process.env,
|
||||
...(skipClaudeHooks ? { MOSAIC_SKIP_CLAUDE_HOOKS: '1' } : {}),
|
||||
},
|
||||
});
|
||||
} catch {
|
||||
// Non-fatal: wizard continues
|
||||
if (!existsSync(script)) return undefined;
|
||||
try {
|
||||
const result = spawnSync('bash', [script], {
|
||||
timeout: 30000,
|
||||
stdio: 'pipe',
|
||||
encoding: 'utf-8',
|
||||
env: {
|
||||
...process.env,
|
||||
...(skipClaudeHooks ? { MOSAIC_SKIP_CLAUDE_HOOKS: '1' } : {}),
|
||||
},
|
||||
});
|
||||
if (result.status !== 0) {
|
||||
const stderr = (result.stderr ?? '').trim();
|
||||
return (
|
||||
stderr || 'Runtime asset linking reported a non-zero exit (see mosaic doctor for details).'
|
||||
);
|
||||
}
|
||||
} catch {
|
||||
// Non-fatal: wizard continues
|
||||
}
|
||||
return undefined;
|
||||
}
|
||||
|
||||
interface SyncSkillsResult {
|
||||
@@ -201,7 +216,7 @@ export async function finalizeStage(
|
||||
// copied into ~/.claude/ while still linking the other runtime files.
|
||||
spin.update('Linking runtime assets...');
|
||||
const skipClaudeHooks = state.hooks?.accepted === false;
|
||||
linkRuntimeAssets(state.mosaicHome, skipClaudeHooks);
|
||||
const linkWarning = linkRuntimeAssets(state.mosaicHome, skipClaudeHooks);
|
||||
|
||||
// 4. Sync skills (only installs the user-selected subset)
|
||||
let skillsResult: SyncSkillsResult = { success: true, installedCount: 0 };
|
||||
@@ -236,6 +251,10 @@ export async function finalizeStage(
|
||||
|
||||
spin.stop('Installation complete');
|
||||
|
||||
// Surface the install-ordering guard's outcome (#869 Point-1 C2) — never
|
||||
// silent, even though the wizard continues either way.
|
||||
if (linkWarning) p.warn(linkWarning);
|
||||
|
||||
// Report skill install failure clearly (non-fatal but user should know)
|
||||
if (!skillsResult.success && skillsResult.failureReason) {
|
||||
p.warn(skillsResult.failureReason);
|
||||
|
||||
Reference in New Issue
Block a user