Commit Graph
27 Commits
Author SHA1 Message Date
fred 1e069946ff contract(onboarding-wizard): revision 15 — bootstrap-status envelope split (NEW-20 residual), active-window mutant attribution (NEW-22)
ci/woodpecker/pr/ci Pipeline was successful
Sol r14 re-review left two findings. NEW-20 residual (BLOCKER): §2.3
closed the bootstrap-status response to epoch/mode with no other field,
conflicting with contract 5 §4.3's mandatory correlation echo on mapped
operations (§§1.1, 7 item 8). Rev 14's state-derived/envelope split is
now applied to bootstrap-status: §2.3 bounds state-derived content only
and carries the contract 5 §4 envelope; §6 item 2's closed-field
assertion and §7 item 2's description follow. Contract 5 not amended.

NEW-22 (MAJOR): the active-window witness claimed its seed-workspace-
scoped mutant fails branches (b) and (c); it passes (c). The witness now
attributes (b) to that mutant, names the separate all-workspace mutant
branch (c) catches, and states branches (a)/(b)/(c) start from isolated
copies of the same incomplete pre-state.

Preamble: Revision 15 paragraph; Revision 14 superseding note.
2026-08-27 05:19:30 -05:00
fred f97d7220e3 contract(onboarding-wizard): revision 14 — query/originate loop, RBAC §1 exception ratified, contract 5 envelope reconciled, one refusal order
ci/woodpecker/pr/ci Pipeline was successful
Addresses sol re-review 13 (NEW-18/NEW-19 residuals, NEW-20, NEW-21):

- NEW-18: seed-progress query response is a closed discriminated union
  (next index | typed complete variant); normative query/originate loop
  — stop on complete, re-query on canonical refusal, continue only on a
  strictly-later result, surface a fault on an unchanged index. New
  witnesses: same-designation race (with unchanged-index fault variant)
  and completed-world stop run of the actual fresh client; cross-surface
  refusal-shape control added to the two-world query witness.
- NEW-19: RBAC §1 expressly named among amended surfaces — narrow
  ratified exception making the designation a fourth authority source
  inside the mechanical origination scope only (§1.2, §4.3, §7 item
  12). New active-window boundary witness: canonical tuple succeeds
  while non-canonical and non-seed-workspace commands refuse in the
  SAME incomplete state; predecessor- and successor-created content
  reads refused post-origination.
- NEW-20: state-derived disclosure split from mandatory envelope
  metadata everywhere — origination and query responses remain ordinary
  contract 5 §4 result DTOs carrying the correlation envelope; contract
  5 not amended. §6.1 closed-schema assertion covers both halves.
- NEW-21: result-disclosure paragraph restates the operative order —
  fresh-mutation authorization first (owning family's refusal), then
  seed-boundary gate before fence presence and canonical-reference
  resolution, constant shape scoped to callers that reached the gate;
  child-race control asserts the refusal class, pinning the order.
2026-08-27 04:44:57 -05:00
fred 552650a69b contract(onboarding-wizard): revision 13 — seed-progress query, generalized designation-derived authority
ci/woodpecker/pr/ci Pipeline was successful
Addresses sol r12 verdict (NEW-18, NEW-19):

- NEW-18: new mapped, designation-only seed-progress query returning
  exactly the next unrecorded canonical position index (or completion
  marker); screening evaluated before any fence state, non-designated
  submitters refused byte-shape-identically across recorded and
  unrecorded worlds; closed read set (position-committed existence
  flags + designation, §6.1); origin fresh-client resume and successor
  completion both query first and originate from the returned index.
- NEW-19: designation-derived authority generalized to the
  actor-authorization component of every canonical position's owning
  family, each surface named expressly (contract 2 §4; RBAC §§2-3
  workspace-content authorization; native-kanban SOT REQ-TEN-001 /
  A1 §8.1.3) as coupled severable-together amendments under one
  mechanically decidable scope, with a defined result-disclosure
  boundary (canonical outcome fields only).
- §6.7: seed-progress two-world refusal, entitlement witness with the
  actual fresh client run against both worlds, content-position
  completion in both recovery variants, non-canonical content
  refusal, result-disclosure witness.
- §7 item 12 now three coupled amendments; §1.1/§1.2/§5.3-5.4/§6.1
  disclosures updated; preamble Revision 13 paragraph.
2026-08-27 04:12:05 -05:00
fred 10e82d05c0 contract 7 rev 12: pure designation transfer, epoch-derived account-free seed tuples, designation-derived origination authority
ci/woodpecker/pr/ci Pipeline was successful
Answers sol re-review 10 (NEW-12/NEW-13/NEW-14 residuals, NEW-16, NEW-17):

- Canonical seed tuples fully epoch-derived and account-free: no
  generated id or account identifier in any canonical payload or
  scope; child positions reference parents by epoch-scoped canonical
  seed role, resolved server-side at execution (canonical-reference
  resolution); position 1 carries no initial-owner field — the
  contract 2 §4.3 default binds owner to the acting designation as a
  recorded outcome. Byte-stability absolute; post-succession replay
  compares equal by construction (NEW-13).
- Succession reduced to a pure designation transfer: condition (a) =
  identity §7.1 unavailability alone (unable disjunct removed), no
  grant conferred, reads identity/platform/epoch state only, closed
  write set = designation update + one audit event. World-independent
  unconditionally, self-revocation pair included (NEW-12); post-
  completion succession confers nothing (NEW-16).
- Designation-derived origination authority: scoped contract 2 §4
  amendment (§7 item 12) — the current designation satisfies the
  hierarchy-authority component for fresh origination of unoriginated
  canonical positions only; no read/replay/standing authority.
- §6.1 succession-write inventory closed in both directions; no-seed-
  input static assertion (NEW-17).
- Revision-10 preamble vocabulary corrected to the banned state
  identity defines (NEW-14).
- §6.7 reworked: strengthened two-world control (event content, grant-
  table delta, full-command timing), new self-revocation two-world
  refusal, designation-derived completion, post-completion
  harmlessness, post-succession replay digest-equality, empty-prefix
  digest-equality witnesses; out-of-order origination witness.
2026-08-27 03:38:06 -05:00
fred 83142e1b79 docs: onboarding-wizard contract revision 11 (sol r10 NEW-12/13/14/15: world-independent succession with conferred position-1 authority, unavailable-or-unable re-succession, §7.1 predicate collapse with forward constraint, dual identity-surface disclosure)
ci/woodpecker/pr/ci Pipeline was successful
2026-08-27 02:50:32 -05:00
fred 3824fc6a37 docs: onboarding-wizard contract revision 10 (sol r9 NEW-11: seed-origin becomes a designation with a disclosed succession command — origin loss recoverable without factory reset, no-oracle shape preserved)
ci/woodpecker/pr/ci Pipeline failed
2026-08-26 23:21:33 -05:00
fred 535ac2d860 docs: onboarding-wizard contract revision 9 (sol r8 NEW-9 residual: prefix-derived seed tuples + seed-origin gate; NEW-10: target-result authorization on every replay mode)
ci/woodpecker/pr/ci Pipeline failed
2026-08-26 22:56:59 -05:00
fred eff3b91478 docs: onboarding-wizard contract revision 8 (sol r7 NEW-9: shared replay target-result authorization, seed-only boundary, replay access event)
ci/woodpecker/pr/ci Pipeline was canceled
2026-08-26 22:30:22 -05:00
fred 84fe8b6ef1 docs: onboarding-wizard contract revision 7 (sol r6 F6 residual + NEW-8)
ci/woodpecker/pr/ci Pipeline was successful
2026-08-26 21:43:57 -05:00
fred b8b257e1ec docs: onboarding-wizard contract revision 6 (sol r5 residual F7 + N7 seed immutability)
ci/woodpecker/pr/ci Pipeline was successful
2026-08-26 21:08:33 -05:00
fred 0162443a38 docs: onboarding-wizard contract revision 5 (sol re-review 3 residuals + N5/N6)
ci/woodpecker/pr/ci Pipeline was successful
2026-08-26 20:40:14 -05:00
fred e58d0a5447 docs: onboarding-wizard contract revision 4 (sol re-review 2 residuals + N3/N4)
ci/woodpecker/pr/ci Pipeline was canceled
- F2: bootstrap-status closed two-field schema (epoch enum + pre-epoch-only
  mode), post-epoch mode-field absence witnessed, contract 6 \u00a72.2 amendment
  disclosed (\u00a77.9)
- F5/N4: contract 5 \u00a73.1 rank-6 mapping expansion disclosed naming the rows
  to amend (\u00a77.8); \u00a71.1 states which families are live vs amended
- F7: complete idempotency envelope \u2014 fence records operation/actor/scope/
  payload digest, re-authorized replay, collision refusal, no error replay,
  concurrent loser receives winner's recorded outcome; witnesses added
- N1/N3: post-epoch application phase replaced by a single bootstrap finalize
  command (one transaction: admin + epoch close + carried settings/registration/
  JIT/seed-parameter writes under the new admin); password-only v1 first admin
  (\u00a77.10); seed sequence derived from canonical state; \u00a76.11 uses the
  authentication-failure class
2026-08-26 20:21:55 -05:00
fred eb48d72f67 docs(wizard): revision 3 — client-side composition, collect-first settings, idempotency fence, bound name sources (sol r2 residuals + N1/N2)
ci/woodpecker/pr/ci Pipeline was canceled
2026-08-26 19:55:45 -05:00
fred 666e3dbf20 docs: onboarding wizard revision 2 — first-company authority, mode as input, choice/witness repairs (sol F1-F9)
ci/woodpecker/pr/ci Pipeline is running
2026-08-26 19:13:36 -05:00
fred 1c9a3ddefb docs: onboarding wizard contract (S2 contract 3)
ci/woodpecker/pr/ci Pipeline was canceled
2026-08-26 18:46:14 -05:00
fred 4b448109dd docs/prd: address independent review findings 1-10 (fidelity, A1 record class + carve-out, roadmap completeness)
ci/woodpecker/pr/ci Pipeline was successful
2026-08-25 23:20:40 -05:00
fred bc1149c15e docs: north-star PRD rewrite (D1-D14), ROADMAP.md, kanban SOT Amendment A1
ci/woodpecker/pr/ci Pipeline was successful
- docs/PRD.md: Part I product north star authored from ratified decisions
  D1-D14; Part II preserves all active workstream contracts verbatim
  (KBN-101, FCM #758, FCOM #766, TESS, #756, MOS-PORT, #1150, #1174, #1194,
  RI #1275, M1). Referenced anchors unchanged.
- docs/archive/PRD-v0.1.md: v0.1.0 beta PRD body archived verbatim with
  supersession header.
- docs/ROADMAP.md: all phases P0-P5 present from day one per D11
  (P2-P5 as explicit placeholders).
- docs/requirements/native-kanban-sot.md: Amendment A1 (D13) - hierarchy
  parentage + RBAC chain above workspaces; sections 1-7 untouched.
2026-08-25 22:23:07 -05:00
fred 5e93ef70bd guides: fix the cross-reference direction in SEAT-IDENTITY
ci/woodpecker/pr/ci Pipeline was successful
rev-code-01's non-blocking nit on #1313 round 2. The no-linking-step paragraph
pointed at the bridge explanation as 'described below'; it is above. Now names the
section, which survives further reordering better than a direction word does.

Text-only. Verified with the repo's PINNED prettier (3.8.1 via pnpm-lock.yaml) and
the sanitization gate, both clean.
2026-08-18 19:10:09 -05:00
fred 3884f2de4d guides: address rev-code-01's review of #1313 (B1, B2, S1, S2)
ci/woodpecker/pr/ci Pipeline was successful
All four findings reproduced before fixing. rev-code-01 was right on each.

B2 (blocker, mine). SEAT-IDENTITY provisioning step 4 said to symlink the
framework store entry to the seat slot, while the same file says those bridges
must not be recreated. The same bridge, told both ways, in one document. I
rewrote the resolution and token-location sections when the deploy made them
stale and did not carry the change into the numbered steps. Step 4 is gone and
the file now says explicitly that no provisioning step links the store to the
slot, so the omission cannot read as an oversight.

S1 (mine). The guide claimed the helper "attempts a fleet notification" on
refusal. The shipped helper does no such thing — its only reference to
notification is a comment saying an alert built on the record is best-effort, and
there is no send or wake call anywhere in the file. Now: it writes a durable
record, the record is what exists, and nobody should wait for a notification that
nothing sends. A guide that promises an alert is worse than one that promises
nothing.

S2. Estate-local content removed from files that ship to every estate: the
~/.mosaic/fleet/bin script paths (dead paths elsewhere) and the 2026-08-18 dates,
which dated a specific host's migration rather than describing behavior. The
bridge-removal passage now states the ORDERING that matters — remove bridges only
after a seat-aware helper can reach the slot, never before — which is the part
that transfers.

B1. prettier reformatted all three files. Reproduced the pipeline 2515 failure
locally before and confirmed clean after; the other three guides prettier flags
are untouched by this branch (0 changes vs origin/next) and are pre-existing.

Sanitization gate re-run and passing.

Verified for the record, since I could not verify my own work: rev-code-01
confirmed the no-fallback claim TRUE against helper content on origin/next, and
judged the evidence rules actionable on the grounds that each names an executable
replacement.
2026-08-18 18:51:15 -05:00
fred a3c50d91ca guides: genericize the operator name in SEAT-IDENTITY provisioning
ci/woodpecker/pr/ci Pipeline failed
Pipeline 2514 failed the sanitization gate on 'Jason mints the token into the
seat slot'. The denylist is jarvis|jason|woltje|... and a shipped framework file
must not carry operator identity. My mistake: I generalized the estate paths and
seat names when promoting this guide and did not check the operator name.

Now reads 'the estate operator', with the accompanying rule that an agent does
not ask another agent to mint one either.

Verified by running tools/quality/scripts/verify-sanitized.sh locally rather than
guessing at the pattern: gate passes.
2026-08-18 18:28:37 -05:00
fred 2fd102e6af guides: state the decree, drop the mechanism
ci/woodpecker/pr/ci Pipeline failed
The #1280 prohibition carried an explanation of how the tools misattribute and
why the failure is invisible from inside them. A reader who is not going to use
the tool cannot act on any of it. Same for rule 2's closing clause about what
reviews commonly miss. Both cut to the decree and the corrective action.

Rules 1 and 3-12 keep their trailing sentences: those are corrective actions or
the detail that makes the case recognizable, not justification.
2026-08-18 18:25:47 -05:00
fred efb3c3a10c guides: add SEAT-IDENTITY and FLEET-COMMS; harden CODE-REVIEW evidence rules
ci/woodpecker/pr/ci Pipeline failed
Three guides that existed only as one host's working copy, promoted to framework
templates so every estate gets them. A working copy under ~/.mosaic binds one
host; only a template here binds all of them.

SEAT-IDENTITY.md (new) documents how a seat's git credential is actually
resolved after #1311: identity from MOSAIC_GIT_IDENTITY, then
mosaic.gitIdentity, then the stdin username; host mapped to a store prefix; then
ONE of two stores chosen by whether the seat directory exists, with no
precedence and no fallback between them. A seat with a directory and an empty
slot fails closed rather than reaching the service store, and that is the point.

It also corrects how to find the helper. credential.helper commonly names an
absolute path, so `command -v git-credential-mosaic` answers a different question
than the one git asks, and the two stop agreeing the moment the PATH copy is
removed. Git also tries EVERY configured helper in order, so a fail-closed helper
in front silently hands the request to whatever is configured behind it. The
guide says to read the whole list.

FLEET-COMMS.md (new) documents agent-send.sh: the class table, the addressing
preamble, and the exit codes — including that rc=2 means the text reached the
pane as an unsubmitted draft, so retrying double-sends it. Confirm with
capture-pane instead. It also says to measure the fleet rather than trust
roster.yaml, which on a live host was simultaneously naming a socket that did not
exist, listing seats that were not running, and omitting seats that were.

CODE-REVIEW.md gains an Evidence Discipline section: a green is not a result
until you have shown it could go red, measurement and explanation are separate
sentences, verify by content on the ref that ships rather than by ancestry of a
local sha, and confidence is part of a finding. Plus four shell-measurement rules
earned on #1311, each of which produced a wrong conclusion first — `cmd | tail;
echo rc=$?` reports tail's status, a missed glob under pipefail exits 2 and kills
the run under set -e, nonzero-with-no-output is an environment question before it
is a code question, and `git -C` in a non-repo directory answers from the
enclosing repo.

The estate-specific repository exception that lived in the working copy is not
carried here. The template says an estate may document one, scoped to a named
repository and never precedent for a second.

Both new guides are added to the two routing tables that agents read.
2026-08-18 18:15:50 -05:00
fred c703cc50eb git-credential-mosaic: escape the escalation record, and stop naming a record that was never written
ci/woodpecker/pr/ci Pipeline was successful
Both defects found in review by rev-code-01 on #1311.

F3 — the JSONL record interpolated every field with a bare %s. An identity comes
from git config or the environment and a cwd is whatever directory git ran in, so
either can contain a quote or a backslash. One such refusal turned the day's spool
into unparseable JSONL, and the operator would only discover it while reading the
record that explains an outage. Fields are now JSON-escaped.

F2 — the diagnostic printed "record: <spool>/<date>.jsonl" unconditionally, but
the record is only written inside the branch where mkdir -p succeeded. When the
spool cannot be created the helper named a file that does not exist, on exactly
the hosts where the escalation was lost. It now reports the real path or says
NOT WRITTEN.

Also: prettier on README.md, which was the format-step failure on pipeline 2508.
It reflowed only the two tables this branch added.

Tests: cases 14 and 15 cover both. Verified discriminating — against the previous
helper with these same tests, case 14 fails with the unparseable record printed
and case 15 fails on both assertions; against this one both pass.

The first draft of case 14 used `ls "$spool"/*.jsonl | head -1`, which under
`set -o pipefail` exits 2 on a missed glob and killed the suite with zero output
— the same silent-nonzero failure rev-code-01 hit from a partial tools/ extraction
and the reason this file exists. Replaced with a glob loop and a comment.
2026-08-18 17:04:55 -05:00
fred 3d2b712355 git credentials: fail closed, and read a seat's token from its own slot
ci/woodpecker/pr/ci Pipeline failed
Two changes to one rule: a credential is resolved from exactly one place,
and an identity that cannot be resolved is refused rather than substituted.

FAIL CLOSED. Both readers ended in an unconditional fall-through to the
shared Gitea account whenever an identity did not resolve. Every seat in a
fleet therefore pushed, opened PRs and filed reviews under one account, and
a record made that way cannot be traced to the agent that made it
afterwards. The fallback now applies only where there is no attribution to
lose: a host with no fleet. Where seats exist, an unresolvable request emits
nothing, exits nonzero, explains itself on stderr, and — in the git helper —
appends a record naming the identity, host, reason and cwd, and no token
value, to ${MOSAIC_CREDENTIAL_SPOOL:-~/.local/state/mosaic-credential-escalations}.

A host runs a fleet when <brain>/fleet/agents exists, which is the signal
packages/mosaic/src/fleet/brain-home.ts already uses to decide a brain is
active, resolved the same way (MOSAIC_BRAIN_HOME, else ~/.mosaic). This is
what keeps the change a no-op for an operator who has not provisioned
per-slot tokens: no fleet directory, shared account, unchanged. It is also
why there is no environment variable to restore the old behavior — one would
reintroduce the substitution being removed.

STORE SELECTION. Both readers hardcoded ~/.config/mosaic/secrets/gitea-tokens,
so a seat's own secrets/ slot was invisible to the framework: a seat could
hold a valid credential and still be served the shared account. The store is
now chosen by what the identity is. An identity with a directory under
<brain>/fleet/agents/ is a seat and is read only from
<brain>/fleet/agents/<id>/secrets/; any other identity is a service identity
and is read from the framework store. There is no precedence between them
and no fallback from one to the other, so a seat with an empty slot is
refused even when a same-named token sits in the framework store. Two copies
of one credential are drift rather than redundancy, and drift surfaces as
the stale copy returning 401, which reads as a revoked token and sends
whoever debugs it somewhere else.

detect-platform.sh is in scope alongside git-credential-mosaic because they
are the two readers of these tokens. Patching only the git helper would make
"one credential, one location" true for push and fetch and false for
pr-create.sh, issue-create.sh and pr-review.sh, which is the harder failure
to notice.

TESTS. The three assertions that pinned the shared-account fall-through are
now fail-closed assertions, and a refusal is checked four independent ways:
nonzero exit, empty stdout, a stderr diagnostic naming identity and host,
and no shared token value anywhere in the output. The exit code alone would
pass against a helper that emitted the credential and then failed. Added:
seat-slot resolution, the no-cross-store-fallback case with a control
proving the framework-store file it declines to read is readable, no-identity
on a fleet host, the fleet gate firing on the default ~/.mosaic and not only
on an injected MOSAIC_BRAIN_HOME, and a cross-host leak check. Both suites
were run against the pre-change code as a control and fail there on exactly
the shared-token emission.

shellcheck is not installed on the authoring host, so the rewritten helper
is unlinted locally and CI is the first lint of it.
2026-08-18 16:19:43 -05:00
fred 57a2f2b40e docs(ci): point the exclusion at tracking issue #1271, not the closed first filing
ci/woodpecker/pr/ci Pipeline was successful
The first PR for this change was filed under the retired mos-dt-0 principal
(pr-create.sh has no --login flag and find_tea_login_for_host returns the first
host match) and was closed and refiled as #1270. That left in-tree references
pointing at a closed duplicate PR rather than at the burn-down issue, which is
the wrong target for them anyway: the open design question belongs on #1271.
2026-08-16 18:03:02 -05:00
fred 93c1de51e1 fix(ci): unwire test-start-agent-session.sh, restore its signed exclusion (#1269)
ci/woodpecker/pr/ci Pipeline was canceled
The `test` step has failed on every `next` pipeline since #1017 on exactly one
assertion, and it is the same one on unrelated PRs:

    FAIL: host provides 'pi' in the system path; missing-binary cases are not
    measurable here            (framework/tools/fleet/test-start-agent-session.sh:103)

Measured 2026-08-16 across pipelines 2444 (#1256), 2438 (#1240) and 2441
(#1017-quality): exactly one FAIL line in each full log, identical, this line.
Control `zzz-not-present-zzz` -> 0 on all three.

Cause. #1241 (5c35a250) added the guard: the suite shims fake mosaic/pi/npm into
$FAKE_BIN, but the constructed PANE_PATH always ends in the real system path, so
on a host that installs those binaries the missing-binary cases cannot be
measured and a green run would mean nothing. The guard says so instead of
passing. Its own pipeline 2430 was green only because the suite was CI-excluded
at the time, so the guard had never run in CI. #1017 (c56483eb) then enumerated
it and dropped the exclusion. The CI image installs
@earendil-works/[email protected].1 on purpose, so the precondition is
unsatisfiable there. Both commits are mine.

The guard is correct and is not being softened. A check that cannot measure its
property and reports success is the failure mode this repo has been cataloguing
all week; the error was wiring the suite into an image that violates its
precondition, so the wiring is what gets reverted.

Second effect, which is the reason this cost a day rather than an hour:
test:framework-shell is one && chain and this sat at position 44 of 48, so
glpi/test-list-http-status.sh, orchestrator/test-board-roll.sh,
woodpecker/test-ci-wait-exit-matrix.sh and _scripts/test-fleet-transport-check.sh
have not run at all since the merge. The pipeline reported one failure, never
"one failure plus four unrun". All four are green when run directly on
sb-it-1-dt, so the mask hid nothing broken -- but that is a local result on one
host, not a CI-image result.

Verification, with controls:
- enumeration guard OK (population 52, enumerated 36, signed-excluded 16).
- control A, exclusion line removed while unwired -> FAIL UNENUMERATED.
- control B, exclusion line kept while rewired -> FAIL CONTRADICTORY EXCLUSION.
  The gate discriminates in both directions, so its OK is load-bearing.
- the four formerly-masked suites: rc=0 each, run directly.
- the full chain cannot be run to completion on sb-it-1-dt: it stops earlier, at
  the lease-broker Invariant R test, because this host carries the quarantined
  operator-global pi 0.84.2 against a measured 0.84.1. That is host-specific and
  out of scope here -- CI pins 0.84.1, and the single FAIL line in those three
  pipelines proves positions 1-43 passed there.

Burn-down is to control the tail of PANE_PATH inside the test, not to remove pi
from the image. Recorded in the exclusion reason and in #1269.
2026-08-16 17:58:49 -05:00
fred 07373ede4d docs(install): record the two trust/portability assumptions in install_node
ci/woodpecker/pr/ci Pipeline was successful
Comment-only, no behaviour change. Both raised by scooby in the #1229 review
as non-blocking findings worth writing down rather than fixing here.

F-A: the SHASUMS256.txt check gives integrity, not authenticity. TLS to
$NODE_DIST_BASE is the whole trust root, and MOSAIC_NODE_DIST_BASE widens it
to any mirror with no signature backstop. GPG-verifying SHASUMS256.txt.sig is
filed as its own follow-up so it gets its own review.

F-C: the uname map pulls the glibc build, so musl hosts fail — visibly, via
node_is_suitable, not silently.
2026-08-15 21:50:14 -05:00