Compare commits
13 Commits
docs/758-l
...
feat/869-c
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
75235ef823 | ||
|
|
b4d26abacd | ||
| b79336a8c1 | |||
| 4e5af23214 | |||
|
|
880c28b191 | ||
|
|
7bc2dfb6c8 | ||
| b0d78d8632 | |||
| 344d86a635 | |||
| acd7d380f6 | |||
| 3b70c66c07 | |||
| 11d2818453 | |||
| aa999daf1b | |||
| 77c9a82614 |
@@ -64,7 +64,7 @@ Active workstream is **W1 — Federation v1**. Workers should:
|
||||
| FCM-M3-002 | in-progress | Add isolated systemd/tmux lifecycle, drift, socket, unmanaged-session, crash, and rollback acceptance coverage | #758 | sonnet | mosaicstack/stack | `test/758-reconciler-lifecycle-gates` | FCM-M3-001 | 25K | Canonical v2 named-socket + legacy-v1 default-server boundaries; fake adapters/temp fixtures only |
|
||||
| FCM-M4-001 | done | Implement field-complete v1-to-v2 inventory/preview/migrator with alias, lifecycle, env-quarantine, and remote/connector disposition evidence | #758 | codex | mosaicstack/stack | `feat/758-v1-v2-migrator` | FCM-M1-003, FCM-M3-001 | 35K | PR #788; final head `d63bb0206a1d312ab8352ec1d3ca3631146b0baa`; tree `4da210da9a71b035130d4160a4a2e691bdfde2da`; squash `9745bc3f29c26b021a478b7ad03cfb494f6c9de3`; descendant-main pipeline 1855 terminal success |
|
||||
| FCM-M4-002 | not-started | Add reversible canary migration, rollback, stale-projection/orphan classification, and current-host 9-managed/3-unmanaged fixture coverage | #758 | sonnet | mosaicstack/stack | `test/758-migration-rollback-gates` | FCM-M4-001, FCM-M3-002 | 25K | HOLD: never starts a previously stopped agent or kills an unproven unmanaged session; not authorized by FCM-M5-001 |
|
||||
| FCM-M5-001 | in-progress | Deliver the accepted fleet documentation IA, how-to/operations/migration references, and link/example validation | #758 | haiku | mosaicstack/stack | `docs/758-fleet-config-operator-docs` | FCM-M1-003, FCM-M2-002, FCM-M3-001, FCM-M4-001 | 24K | Sole owner: this FCM-M5-001 delivery on the recorded branch; must close every checklist item or record an approved deferral |
|
||||
| FCM-M5-001 | done | Deliver the accepted fleet documentation IA, how-to/operations/migration references, and link/example validation | #758 | haiku | mosaicstack/stack | `docs/758-fleet-config-operator-docs` | FCM-M1-003, FCM-M2-002, FCM-M3-001, FCM-M4-001 | 24K | #789 content squash 627cf2bb; de-flake repair PR#851/#849 squash 77c9a826; completion proof wp1937 @aa999daf push/ci step 49632 recovery_runtime_unittest.py 3/3 OK (closes wp1932 step 49576 Errno111) |
|
||||
| FCM-M5-002 | not-started | Package/update asset-drift checks, rolling local canary, independent validation certificate, and release evidence | #758 | sonnet | mosaicstack/stack | `feat/758-fleet-config-release-gate` | FCM-M3-002, FCM-M4-002, FCM-M5-001 | 30K | HOLD: final #758 gate; quality, independent code/security review, validator certificate, merge-gate approval, and green CI remain out of M5-001 |
|
||||
|
||||
## Thin-core prompt diet (#528) — feat/contract-thin-core
|
||||
|
||||
58
docs/scratchpads/812-pr-review-comment.md
Normal file
58
docs/scratchpads/812-pr-review-comment.md
Normal file
@@ -0,0 +1,58 @@
|
||||
# Issue #812 — durable Gitea PR review comments
|
||||
|
||||
- **Lane:** ms-812
|
||||
- **Branch:** `fix/812-pr-review-comment`
|
||||
- **Issue:** mosaicstack/stack#812
|
||||
- **Budget:** 15K working estimate; single focused shell-wrapper/test/docs change.
|
||||
|
||||
## Objective
|
||||
|
||||
Make the Gitea `comment` action in `packages/mosaic/framework/tools/git/pr-review.sh` use the supported Gitea comments REST API and report success only after provider read-back verifies the created comment against the intended repository, PR, and exact body.
|
||||
|
||||
## Plan
|
||||
|
||||
1. Add and commit a failing shell regression harness before production changes.
|
||||
2. Verify RED against the nonexistent `tea pr comment` fallback false-positive.
|
||||
3. Implement the minimal supported write plus ID-based provider read-back.
|
||||
4. Document that wrapper write output is not durable provenance until read-back succeeds.
|
||||
5. Run focused regression tests, touched-package tests, and repository quality gates.
|
||||
6. Remediate review findings, queue-guard, and push for coordinator-owned independent review. Do not open or merge a PR.
|
||||
|
||||
## Progress checkpoints
|
||||
|
||||
- [x] RED regression committed and reported to mosaic-100 (rebased commit `770e3f57`)
|
||||
- [x] Initial minimal fix implemented (rebased commit `ea7f8c57`)
|
||||
- [x] Rebased cleanly onto main `627cf2bb387f7c84a532d88819903a7679ce0d72`
|
||||
- [x] Codex blocker remediated by replacing unsupported `tea api` with authenticated REST write/read-back
|
||||
- [x] Focused, package, and repository gates green
|
||||
- [ ] Coordinator-owned independent review pending after push
|
||||
- [x] No PR opened; no self-review or self-merge
|
||||
|
||||
## Tests run
|
||||
|
||||
- RED after rebase: the regression harness failed against `origin/main` with status 1 after reproducing the old `tea pr comment` zero-exit fallback and false success echo.
|
||||
- GREEN at resumed head: the same harness passed with REST POST 201 plus GET 200 read-back.
|
||||
- All `packages/mosaic/framework/tools/git/test-*.sh` harnesses passed.
|
||||
- `shellcheck -x` passed for the changed scripts; `bash -n` passed.
|
||||
- Manifest resolver returned `framework` for `tools/git/test-pr-review-gitea-comment.sh`.
|
||||
- `pnpm test` passed (43/43 Turbo tasks; Mosaic 75 files/1434 tests; Gateway 56 files/628 tests plus documented skips).
|
||||
- `pnpm typecheck` passed (42/42 tasks), `pnpm lint` passed (23/23), and `pnpm format:check` passed.
|
||||
- Firewall checks found no user-home paths or operator identities in changed shipped files; no token value is logged or echoed.
|
||||
|
||||
## Risks / blockers
|
||||
|
||||
- No active implementation blocker. #789 reached terminal merged state and the coordination hold was lifted.
|
||||
- Review round 1 found one portability blocker: the API base reconstructed `https://$host` and discarded configured schemes/path prefixes.
|
||||
- Review round 2 found a second subpath portability blocker: clone-derived `get_repo_slug` retained the deployment prefix, duplicating it under `/api/v1/repos/`.
|
||||
- Round 3 resolves owner/repo relative to the configured Gitea base path for HTTP(S) clones while preserving root-mounted and SSH clone forms. Host matching now compares non-default ports consistently.
|
||||
- REST transport failures, non-201 writes, malformed/missing created IDs, non-200 read-backs, and read-back mismatches all fail closed.
|
||||
- Existing approve/request-changes behavior remains covered.
|
||||
- Independent exact-head re-review remains coordinator-owned.
|
||||
|
||||
## Final verification evidence
|
||||
|
||||
- URL-portability regression was RED before remediation at the new `http://git.mosaicstack.dev` case and GREEN afterward.
|
||||
- Round-3 genuine subpath regression was RED against round-2 head `1b190201` and GREEN after the fix: `https://git.example/gitea/owner/repo.git` maps to API repository `owner/repo` under configured base `/gitea`.
|
||||
- Regression coverage verifies POST and read-back GET for root-mounted HTTP(S), path-prefixed HTTP(S), non-default HTTP port, scp-style SSH, and `ssh://` clone forms.
|
||||
- Focused shell checks, all git-wrapper harnesses, and full repository test/typecheck/lint/format gates passed after remediation.
|
||||
- Branch will be force-pushed with lease for coordinator re-verification; no PR opened.
|
||||
@@ -0,0 +1,22 @@
|
||||
[Unit]
|
||||
Description=Mosaic lease broker daemon (framework tools/lease-broker/daemon.py)
|
||||
Documentation=https://git.mosaicstack.dev/mosaicstack/stack
|
||||
After=default.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
# The broker socket lives under the runtime directory so it disappears with
|
||||
# the user session instead of surviving as stale state across logins.
|
||||
# daemon.py's secure_parent() fails closed unless this directory is exactly
|
||||
# 0700, so RuntimeDirectoryMode is not cosmetic.
|
||||
RuntimeDirectory=mosaic-lease
|
||||
RuntimeDirectoryMode=0700
|
||||
# Remove loader and noninteractive-shell controls before ExecStart loads env,
|
||||
# matching the tmux fleet units in this same directory.
|
||||
UnsetEnvironment=LD_PRELOAD BASH_ENV ENV
|
||||
ExecStart=/usr/bin/env -i HOME=%h PATH=/usr/bin:/bin XDG_RUNTIME_DIR=%t /bin/bash --noprofile --norc %h/.config/mosaic/tools/lease-broker/start-lease-broker.sh
|
||||
Restart=on-failure
|
||||
RestartSec=1
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
9
packages/mosaic/framework/tools/git/README.md
Normal file
9
packages/mosaic/framework/tools/git/README.md
Normal file
@@ -0,0 +1,9 @@
|
||||
# Git provider wrappers
|
||||
|
||||
These scripts provide host-aware GitHub and Gitea issue, pull-request, milestone, and CI operations.
|
||||
|
||||
## Durable review provenance
|
||||
|
||||
A successful provider write command—or a wrapper message based only on that command's exit code—is **not** durable review provenance. Review comments count as durable provenance only after the wrapper reads the created provider record back and verifies that it belongs to the intended repository and pull request and contains the exact submitted body (or verifies the provider-returned record ID).
|
||||
|
||||
`pr-review.sh` therefore fails closed when a Gitea comment cannot be written, its created comment ID cannot be identified, or provider read-back does not match. It reports comment success only after that read-back verification passes.
|
||||
@@ -81,7 +81,32 @@ get_repo_slug() {
|
||||
gitea_url_matches_host() {
|
||||
local url="${1:-}" host="${2:-}"
|
||||
[[ -n "$url" && -n "$host" ]] || return 1
|
||||
[[ "${url%/}" == "https://$host" || "${url%/}" == "http://$host" || "${url%/}" == *"//$host" ]]
|
||||
python3 - "$url" "$host" <<'PY'
|
||||
import sys
|
||||
from urllib.parse import urlparse
|
||||
|
||||
url, remote_host = sys.argv[1:]
|
||||
configured = urlparse(url)
|
||||
remote = urlparse(f"//{remote_host}")
|
||||
if configured.scheme not in {"http", "https"} or configured.hostname != remote.hostname:
|
||||
raise SystemExit(1)
|
||||
|
||||
# Normalize by scheme: an implicit (portless) HTTP(S) URL and its explicit
|
||||
# default-port form (":80" for http, ":443" for https) name the same
|
||||
# provider endpoint. Apply that equivalence symmetrically -- whichever side
|
||||
# omits the port is treated as carrying the scheme's default port -- so
|
||||
# "configured implicit vs. remote explicit" and "configured explicit vs.
|
||||
# remote implicit" both match. (The remote side here is always an HTTP(S)
|
||||
# authority; an SSH remote's transport port is stripped by get_remote_host
|
||||
# before reaching this comparison, since it identifies an unrelated
|
||||
# service on the same host, not the HTTP(S) provider port.)
|
||||
default_port = 80 if configured.scheme == "http" else 443
|
||||
normalized_configured = configured.port if configured.port is not None else default_port
|
||||
normalized_remote = remote.port if remote.port is not None else default_port
|
||||
if normalized_configured != normalized_remote:
|
||||
raise SystemExit(1)
|
||||
raise SystemExit(0)
|
||||
PY
|
||||
}
|
||||
|
||||
get_gitea_service_for_host() {
|
||||
@@ -347,6 +372,47 @@ get_gitea_api_host_for_repo_override() {
|
||||
get_host_from_url "${GITEA_URL:-}"
|
||||
}
|
||||
|
||||
# Resolve owner/repo relative to a configured Gitea base URL. HTTP(S) clone
|
||||
# URLs can include the deployment prefix (for example /gitea/owner/repo.git),
|
||||
# but Gitea's /repos API expects only owner/repo. Root-mounted and SSH clone
|
||||
# forms retain their existing owner/repo behavior.
|
||||
get_gitea_repo_slug_for_url() {
|
||||
local configured_url="$1" remote_url
|
||||
remote_url=$(git remote get-url origin 2>/dev/null) || return 1
|
||||
|
||||
if [[ "$remote_url" =~ ^https?:// ]]; then
|
||||
python3 - "$remote_url" "$configured_url" <<'PY'
|
||||
import sys
|
||||
from urllib.parse import urlparse
|
||||
|
||||
remote = urlparse(sys.argv[1])
|
||||
base = urlparse(sys.argv[2])
|
||||
remote_path = remote.path.strip("/")
|
||||
if remote_path.endswith(".git"):
|
||||
remote_path = remote_path[:-4]
|
||||
base_path = base.path.strip("/")
|
||||
remote_parts = [part for part in remote_path.split("/") if part]
|
||||
base_parts = [part for part in base_path.split("/") if part]
|
||||
|
||||
if base_parts and remote_parts[:len(base_parts)] == base_parts:
|
||||
repo_parts = remote_parts[len(base_parts):]
|
||||
elif len(remote_parts) == 2:
|
||||
# Preserve a root-shaped clone URL when provider API configuration carries
|
||||
# a reverse-proxy prefix separately.
|
||||
repo_parts = remote_parts
|
||||
else:
|
||||
raise SystemExit(1)
|
||||
|
||||
if len(repo_parts) != 2:
|
||||
raise SystemExit(1)
|
||||
print("/".join(repo_parts))
|
||||
PY
|
||||
return
|
||||
fi
|
||||
|
||||
get_repo_slug
|
||||
}
|
||||
|
||||
get_gitea_repo_args() {
|
||||
local repo host login
|
||||
repo=$(get_repo_slug) || return 1
|
||||
@@ -370,6 +436,15 @@ get_remote_host() {
|
||||
echo "${host##*@}"
|
||||
return 0
|
||||
fi
|
||||
if [[ "$remote_url" =~ ^ssh://([^/]+)/ ]]; then
|
||||
local host="${BASH_REMATCH[1]}"
|
||||
host="${host##*@}"
|
||||
# Strip an SSH transport port (e.g. "git.example:2222"): it names the
|
||||
# SSH daemon port, not the HTTP(S) provider API port, and must not
|
||||
# feed gitea_url_matches_host's port comparison (#850).
|
||||
echo "${host%%:*}"
|
||||
return 0
|
||||
fi
|
||||
if [[ "$remote_url" =~ ^git@([^:]+): ]]; then
|
||||
echo "${BASH_REMATCH[1]}"
|
||||
return 0
|
||||
@@ -377,6 +452,51 @@ get_remote_host() {
|
||||
return 1
|
||||
}
|
||||
|
||||
# Resolve the configured Gitea base URL for a host from the same credential
|
||||
# source used by get_gitea_token. The scheme and any deployment path prefix are
|
||||
# provider configuration and must not be reconstructed from the git remote.
|
||||
get_gitea_url_for_host() {
|
||||
local host="$1" script_dir cred_loader url
|
||||
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
cred_loader="$script_dir/../_lib/credentials.sh"
|
||||
|
||||
if [[ -f "$cred_loader" ]]; then
|
||||
url=$(
|
||||
# shellcheck source=/dev/null
|
||||
source "$cred_loader"
|
||||
unset GITEA_TOKEN GITEA_URL
|
||||
case "$host" in
|
||||
git.mosaicstack.dev) load_credentials gitea-mosaicstack 2>/dev/null ;;
|
||||
git.uscllc.com) load_credentials gitea-usc 2>/dev/null ;;
|
||||
*)
|
||||
for svc in gitea-mosaicstack gitea-usc; do
|
||||
unset GITEA_TOKEN GITEA_URL
|
||||
load_credentials "$svc" 2>/dev/null || continue
|
||||
if gitea_url_matches_host "${GITEA_URL:-}" "$host"; then
|
||||
break
|
||||
fi
|
||||
unset GITEA_TOKEN GITEA_URL
|
||||
done
|
||||
;;
|
||||
esac
|
||||
if gitea_url_matches_host "${GITEA_URL:-}" "$host"; then
|
||||
printf '%s' "${GITEA_URL%/}"
|
||||
fi
|
||||
)
|
||||
if [[ -n "$url" ]]; then
|
||||
printf '%s\n' "$url"
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
|
||||
if gitea_url_matches_host "${GITEA_URL:-}" "$host"; then
|
||||
printf '%s\n' "${GITEA_URL%/}"
|
||||
return 0
|
||||
fi
|
||||
|
||||
return 1
|
||||
}
|
||||
|
||||
# Resolve a Gitea API token for the given host.
|
||||
# Priority: Mosaic credential loader → GITEA_TOKEN env → ~/.git-credentials
|
||||
get_gitea_token() {
|
||||
@@ -403,7 +523,7 @@ get_gitea_token() {
|
||||
for svc in gitea-mosaicstack gitea-usc; do
|
||||
unset GITEA_TOKEN GITEA_URL
|
||||
load_credentials "$svc" 2>/dev/null || continue
|
||||
if [[ "${GITEA_URL:-}" == "https://$host" || "${GITEA_URL:-}" == "http://$host" || "${GITEA_URL:-}" == *"//$host" ]]; then
|
||||
if gitea_url_matches_host "${GITEA_URL:-}" "$host"; then
|
||||
matched=true
|
||||
break
|
||||
fi
|
||||
@@ -423,7 +543,7 @@ get_gitea_token() {
|
||||
|
||||
# 2. GITEA_TOKEN env var (only when GITEA_URL, if present, matches the remote host)
|
||||
if [[ -n "${GITEA_TOKEN:-}" ]]; then
|
||||
if [[ -z "${GITEA_URL:-}" || "${GITEA_URL:-}" == "https://$host" || "${GITEA_URL:-}" == "http://$host" || "${GITEA_URL:-}" == *"//$host" ]]; then
|
||||
if [[ -z "${GITEA_URL:-}" ]] || gitea_url_matches_host "$GITEA_URL" "$host"; then
|
||||
echo "$GITEA_TOKEN"
|
||||
return 0
|
||||
fi
|
||||
|
||||
@@ -5,6 +5,7 @@
|
||||
set -e
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
# shellcheck source=packages/mosaic/framework/tools/git/detect-platform.sh
|
||||
source "$SCRIPT_DIR/detect-platform.sh"
|
||||
|
||||
# Parse arguments
|
||||
@@ -55,6 +56,125 @@ fi
|
||||
|
||||
detect_platform >/dev/null
|
||||
|
||||
# Post a review comment body to a Gitea PR via the supported comments REST API
|
||||
# and verify it durably via provider read-back (see docs on durable review
|
||||
# provenance in README.md). Used by the `comment` action and, since `tea`
|
||||
# v0.11.1 defines no `--comment`/`-comment` flag on `pr approve`/`pr reject`,
|
||||
# also by the `approve` and `request-changes` actions to carry an optional
|
||||
# review body that `tea` itself cannot attach.
|
||||
#
|
||||
# Args: $1 = PR number, $2 = comment body
|
||||
# On success: prints only the created comment ID to stdout, returns 0.
|
||||
# On failure: prints an error to stderr, returns 1.
|
||||
gitea_post_verified_comment() {
|
||||
local pr_number="$1" comment_body="$2"
|
||||
local host token configured_url repo api_base payload
|
||||
local write_response_file readback_response_file comment_id
|
||||
|
||||
host=$(get_remote_host)
|
||||
token=$(get_gitea_token "$host") || {
|
||||
echo "Error: Gitea token not found for comment persistence" >&2
|
||||
return 1
|
||||
}
|
||||
configured_url=$(get_gitea_url_for_host "$host") || {
|
||||
echo "Error: Configured Gitea URL not found for comment persistence" >&2
|
||||
return 1
|
||||
}
|
||||
repo=$(get_gitea_repo_slug_for_url "$configured_url") || {
|
||||
echo "Error: Could not resolve Gitea owner/repository relative to configured URL" >&2
|
||||
return 1
|
||||
}
|
||||
api_base="${configured_url%/}/api/v1/repos/$repo"
|
||||
payload=$(COMMENT_BODY="$comment_body" python3 -c '
|
||||
import json
|
||||
import os
|
||||
|
||||
print(json.dumps({"body": os.environ["COMMENT_BODY"]}))
|
||||
')
|
||||
write_response_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-write.XXXXXX")
|
||||
readback_response_file=$(mktemp "${TMPDIR:-/tmp}/mosaic-pr-review-readback.XXXXXX")
|
||||
trap 'rm -f "$write_response_file" "$readback_response_file"' RETURN
|
||||
|
||||
if ! write_status=$(curl -sS -o "$write_response_file" -w '%{http_code}' \
|
||||
-X POST \
|
||||
-H "Authorization: token $token" \
|
||||
-H 'Content-Type: application/json' \
|
||||
-d "$payload" \
|
||||
"$api_base/issues/$pr_number/comments"); then
|
||||
echo "Error: Gitea comment write transport failed" >&2
|
||||
return 1
|
||||
fi
|
||||
if [[ "$write_status" != "201" ]]; then
|
||||
echo "Error: Gitea comment write failed with HTTP $write_status" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
comment_id=$(python3 - "$write_response_file" <<'PY'
|
||||
import json
|
||||
import sys
|
||||
|
||||
try:
|
||||
with open(sys.argv[1], encoding="utf-8") as response:
|
||||
comment = json.load(response)
|
||||
comment_id = comment.get("id") if isinstance(comment, dict) else None
|
||||
if not isinstance(comment_id, int) or comment_id <= 0:
|
||||
raise ValueError("missing positive comment id")
|
||||
except (OSError, json.JSONDecodeError, ValueError) as error:
|
||||
print(f"Error: could not identify created Gitea comment: {error}", file=sys.stderr)
|
||||
raise SystemExit(1)
|
||||
print(comment_id)
|
||||
PY
|
||||
) || return 1
|
||||
|
||||
if ! readback_status=$(curl -sS -o "$readback_response_file" -w '%{http_code}' \
|
||||
-H "Authorization: token $token" \
|
||||
"$api_base/issues/comments/$comment_id"); then
|
||||
echo "Error: Gitea comment read-back transport failed" >&2
|
||||
return 1
|
||||
fi
|
||||
if [[ "$readback_status" != "200" ]]; then
|
||||
echo "Error: Gitea comment read-back failed with HTTP $readback_status" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
if EXPECTED_COMMENT_ID="$comment_id" EXPECTED_COMMENT_BODY="$comment_body" EXPECTED_REPO="$repo" EXPECTED_PR_NUMBER="$pr_number" \
|
||||
python3 - "$readback_response_file" <<'PY'
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
from urllib.parse import urlparse
|
||||
|
||||
try:
|
||||
with open(sys.argv[1], encoding="utf-8") as response:
|
||||
comment = json.load(response)
|
||||
if not isinstance(comment, dict):
|
||||
raise ValueError("response is not a comment object")
|
||||
expected_id = int(os.environ["EXPECTED_COMMENT_ID"])
|
||||
expected_body = os.environ["EXPECTED_COMMENT_BODY"]
|
||||
expected_repo = os.environ["EXPECTED_REPO"]
|
||||
expected_pr = os.environ["EXPECTED_PR_NUMBER"]
|
||||
issue_path = urlparse(comment.get("issue_url", "")).path.rstrip("/")
|
||||
expected_suffix = f"/repos/{expected_repo}/issues/{expected_pr}"
|
||||
if comment.get("id") != expected_id:
|
||||
raise ValueError("comment id mismatch")
|
||||
if comment.get("body") != expected_body:
|
||||
raise ValueError("comment body mismatch")
|
||||
if not issue_path.endswith(expected_suffix):
|
||||
raise ValueError("repository or PR mismatch")
|
||||
except (OSError, json.JSONDecodeError, KeyError, TypeError, ValueError) as error:
|
||||
print(f"Error: Gitea comment persistence verification failed: {error}", file=sys.stderr)
|
||||
raise SystemExit(1)
|
||||
PY
|
||||
then
|
||||
true
|
||||
else
|
||||
return 1
|
||||
fi
|
||||
|
||||
echo "$comment_id"
|
||||
return 0
|
||||
}
|
||||
|
||||
if [[ "$PLATFORM" == "github" ]]; then
|
||||
case $ACTION in
|
||||
approve)
|
||||
@@ -85,24 +205,41 @@ if [[ "$PLATFORM" == "github" ]]; then
|
||||
elif [[ "$PLATFORM" == "gitea" ]]; then
|
||||
case $ACTION in
|
||||
approve)
|
||||
tea pr approve "$PR_NUMBER" $(get_gitea_repo_args) ${COMMENT:+--comment "$COMMENT"}
|
||||
repo=$(get_repo_slug)
|
||||
host=$(get_remote_host)
|
||||
login=$(get_gitea_login_for_host "$host")
|
||||
# tea v0.11.1 defines no --comment/-comment flag on `pr approve`;
|
||||
# route any review body via the durable comment API instead (#835).
|
||||
tea pr approve "$PR_NUMBER" --repo "$repo" --login "$login"
|
||||
echo "Approved Gitea PR #$PR_NUMBER"
|
||||
if [[ -n "$COMMENT" ]]; then
|
||||
comment_id=$(gitea_post_verified_comment "$PR_NUMBER" "$COMMENT") || exit 1
|
||||
echo "Added and verified review comment on Gitea PR #$PR_NUMBER (comment ID $comment_id)"
|
||||
fi
|
||||
;;
|
||||
request-changes)
|
||||
if [[ -z "$COMMENT" ]]; then
|
||||
echo "Error: Comment required for request-changes"
|
||||
exit 1
|
||||
fi
|
||||
tea pr reject "$PR_NUMBER" $(get_gitea_repo_args) --comment "$COMMENT"
|
||||
repo=$(get_repo_slug)
|
||||
host=$(get_remote_host)
|
||||
login=$(get_gitea_login_for_host "$host")
|
||||
# tea v0.11.1 defines no --comment/-comment flag on `pr reject`;
|
||||
# route the review body via the durable comment API instead (#835).
|
||||
tea pr reject "$PR_NUMBER" --repo "$repo" --login "$login"
|
||||
echo "Requested changes on Gitea PR #$PR_NUMBER"
|
||||
comment_id=$(gitea_post_verified_comment "$PR_NUMBER" "$COMMENT") || exit 1
|
||||
echo "Added and verified review comment on Gitea PR #$PR_NUMBER (comment ID $comment_id)"
|
||||
;;
|
||||
comment)
|
||||
if [[ -z "$COMMENT" ]]; then
|
||||
echo "Error: Comment required"
|
||||
exit 1
|
||||
fi
|
||||
tea pr comment "$PR_NUMBER" "$COMMENT" $(get_gitea_repo_args)
|
||||
echo "Added comment to Gitea PR #$PR_NUMBER"
|
||||
|
||||
comment_id=$(gitea_post_verified_comment "$PR_NUMBER" "$COMMENT") || exit 1
|
||||
echo "Added and verified comment on Gitea PR #$PR_NUMBER (comment ID $comment_id)"
|
||||
;;
|
||||
*)
|
||||
echo "Error: Unknown action: $ACTION"
|
||||
|
||||
@@ -0,0 +1,328 @@
|
||||
#!/usr/bin/env bash
|
||||
# Regression harness for durable Gitea PR review comments (#812) and for the
|
||||
# approve/reject `--comment` flag removal (#835). The `tea` stub below rejects
|
||||
# any `-comment`/`--comment` flag on `pr approve`/`pr reject` exactly like real
|
||||
# `tea` v0.11.1 does ("flag provided but not defined: -comment"), so this
|
||||
# harness fails RED against the pre-#835 wrapper (which passed that flag) and
|
||||
# only passes once the wrapper routes the review body through the durable
|
||||
# comment REST API instead.
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/pr-review-gitea-comment}"
|
||||
REPO_DIR="$WORK_DIR/repo"
|
||||
BIN_DIR="$WORK_DIR/bin"
|
||||
TEA_LOG="$WORK_DIR/tea.log"
|
||||
CURL_LOG="$WORK_DIR/curl.log"
|
||||
OUTPUT_FILE="$WORK_DIR/output.log"
|
||||
CREDENTIALS_FILE="$WORK_DIR/credentials.json"
|
||||
|
||||
cleanup() {
|
||||
rm -rf "$WORK_DIR"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
mkdir -p "$REPO_DIR" "$BIN_DIR"
|
||||
git -C "$REPO_DIR" init -q
|
||||
git -C "$REPO_DIR" remote add origin https://git.mosaicstack.dev/mosaicstack/stack.git
|
||||
|
||||
write_credentials() {
|
||||
local configured_url="$1"
|
||||
CONFIGURED_GITEA_URL="$configured_url" python3 - "$CREDENTIALS_FILE" <<'PY'
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
|
||||
with open(sys.argv[1], "w", encoding="utf-8") as credentials:
|
||||
json.dump({
|
||||
"gitea": {
|
||||
"mosaicstack": {
|
||||
"url": os.environ["CONFIGURED_GITEA_URL"],
|
||||
"token": "test-only-placeholder",
|
||||
}
|
||||
}
|
||||
}, credentials)
|
||||
PY
|
||||
}
|
||||
|
||||
cat > "$BIN_DIR/tea" <<'SH'
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
printf '%s\n' "$*" >> "$PR_REVIEW_TEA_LOG"
|
||||
|
||||
if [[ "$*" == "login list --output json" ]]; then
|
||||
printf '%s\n' '[{"name":"mosaicstack","url":"https://git.mosaicstack.dev"}]'
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# tea v0.11.1 defines no --comment/-comment flag on `pr approve` or `pr
|
||||
# reject`; it fails closed with this exact message and a nonzero exit. Any
|
||||
# regression that reintroduces the flag on those subcommands must hit this
|
||||
# branch and fail RED (#835).
|
||||
if [[ "$*" == *" -comment "* || "$*" == *" --comment "* || "$*" == *" -comment" || "$*" == *" --comment" ]]; then
|
||||
echo "flag provided but not defined: -comment" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
case "${PR_REVIEW_TEST_MODE:-}" in
|
||||
approve)
|
||||
[[ "$*" == "pr approve 123 --repo mosaicstack/stack --login mosaicstack" ]] || exit 90
|
||||
;;
|
||||
request-changes)
|
||||
[[ "$*" == "pr reject 123 --repo mosaicstack/stack --login mosaicstack" ]] || exit 91
|
||||
;;
|
||||
legacy-fallback|comment-success|http-success|prefix-success|subpath-success|port-success|scp-ssh-success|url-ssh-success|ssh-transport-port-success|explicit-default-port-success|write-transport-failure|write-http-failure|readback-failure)
|
||||
if [[ "$*" == pr\ comment* ]]; then
|
||||
# tea v0.11.1 treats the nonexistent subcommand as `tea pr list` and exits 0.
|
||||
printf '%s\n' 'INDEX TITLE STATE'
|
||||
exit 0
|
||||
fi
|
||||
echo "Unexpected tea command: $*" >&2
|
||||
exit 92
|
||||
;;
|
||||
*)
|
||||
exit 95
|
||||
;;
|
||||
esac
|
||||
SH
|
||||
chmod +x "$BIN_DIR/tea"
|
||||
|
||||
cat > "$BIN_DIR/curl" <<'SH'
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
output_file=""
|
||||
method="GET"
|
||||
payload=""
|
||||
url=""
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case "$1" in
|
||||
-o)
|
||||
output_file="$2"
|
||||
shift 2
|
||||
;;
|
||||
-w|-H)
|
||||
shift 2
|
||||
;;
|
||||
-X)
|
||||
method="$2"
|
||||
shift 2
|
||||
;;
|
||||
-d|--data)
|
||||
payload="$2"
|
||||
shift 2
|
||||
;;
|
||||
-s|-S|-sS)
|
||||
shift
|
||||
;;
|
||||
http://*|https://*)
|
||||
url="$1"
|
||||
shift
|
||||
;;
|
||||
*)
|
||||
shift
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
printf '%s %s\n' "$method" "$url" >> "$PR_REVIEW_CURL_LOG"
|
||||
|
||||
write_response() {
|
||||
local status="$1" body="$2"
|
||||
[[ -n "$output_file" ]] || exit 96
|
||||
printf '%s' "$body" > "$output_file"
|
||||
printf '%s' "$status"
|
||||
}
|
||||
|
||||
case "${PR_REVIEW_TEST_MODE:-}" in
|
||||
legacy-fallback|write-transport-failure)
|
||||
echo "simulated transport failure" >&2
|
||||
exit 7
|
||||
;;
|
||||
write-http-failure)
|
||||
write_response 500 '{"message":"simulated rejection"}'
|
||||
;;
|
||||
approve|request-changes|comment-success|http-success|prefix-success|subpath-success|port-success|scp-ssh-success|url-ssh-success|ssh-transport-port-success|explicit-default-port-success|readback-failure)
|
||||
if [[ "$method" == "POST" && "$url" == "$PR_REVIEW_EXPECTED_API_BASE/issues/123/comments" ]]; then
|
||||
PR_REVIEW_PAYLOAD="$payload" python3 - <<'PY'
|
||||
import json
|
||||
import os
|
||||
|
||||
assert json.loads(os.environ["PR_REVIEW_PAYLOAD"]) == {"body": os.environ["PR_REVIEW_EXPECTED_BODY"]}
|
||||
PY
|
||||
response=$(python3 - <<'PY'
|
||||
import json
|
||||
import os
|
||||
|
||||
print(json.dumps({"id": 456, "body": os.environ["PR_REVIEW_EXPECTED_BODY"]}))
|
||||
PY
|
||||
)
|
||||
write_response 201 "$response"
|
||||
elif [[ "$method" == "GET" && "$url" == "$PR_REVIEW_EXPECTED_API_BASE/issues/comments/456" ]]; then
|
||||
if [[ "$PR_REVIEW_TEST_MODE" == "readback-failure" ]]; then
|
||||
body="different-body"
|
||||
else
|
||||
body="$PR_REVIEW_EXPECTED_BODY"
|
||||
fi
|
||||
response=$(PR_REVIEW_BODY="$body" python3 - <<'PY'
|
||||
import json
|
||||
import os
|
||||
|
||||
print(json.dumps({
|
||||
"id": 456,
|
||||
"body": os.environ["PR_REVIEW_BODY"],
|
||||
"issue_url": os.environ["PR_REVIEW_EXPECTED_API_BASE"] + "/issues/123",
|
||||
}))
|
||||
PY
|
||||
)
|
||||
write_response 200 "$response"
|
||||
else
|
||||
echo "Unexpected curl request: $method $url" >&2
|
||||
exit 97
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
exit 98
|
||||
;;
|
||||
esac
|
||||
SH
|
||||
chmod +x "$BIN_DIR/curl"
|
||||
|
||||
run_review() {
|
||||
local mode="$1" action="$2" comment="${3:-}"
|
||||
local configured_url="${4:-https://git.mosaicstack.dev}"
|
||||
local remote_url="${5:-https://git.mosaicstack.dev/mosaicstack/stack.git}"
|
||||
local expected_repo="${6:-mosaicstack/stack}"
|
||||
local expected_api_base="${configured_url%/}/api/v1/repos/$expected_repo"
|
||||
git -C "$REPO_DIR" remote set-url origin "$remote_url"
|
||||
write_credentials "$configured_url"
|
||||
: > "$TEA_LOG"
|
||||
: > "$CURL_LOG"
|
||||
: > "$OUTPUT_FILE"
|
||||
(
|
||||
cd "$REPO_DIR"
|
||||
PATH="$BIN_DIR:$PATH" \
|
||||
MOSAIC_CREDENTIALS_FILE="$CREDENTIALS_FILE" \
|
||||
PR_REVIEW_TEA_LOG="$TEA_LOG" \
|
||||
PR_REVIEW_CURL_LOG="$CURL_LOG" \
|
||||
PR_REVIEW_TEST_MODE="$mode" \
|
||||
PR_REVIEW_EXPECTED_BODY="$comment" \
|
||||
PR_REVIEW_EXPECTED_API_BASE="$expected_api_base" \
|
||||
"$SCRIPT_DIR/pr-review.sh" -n 123 -a "$action" ${comment:+-c "$comment"}
|
||||
) > "$OUTPUT_FILE" 2>&1
|
||||
}
|
||||
|
||||
run_review approve approve
|
||||
grep -q '^pr approve 123 --repo mosaicstack/stack --login mosaicstack$' "$TEA_LOG"
|
||||
grep -q 'Approved Gitea PR #123' "$OUTPUT_FILE"
|
||||
if grep -q 'comment' "$TEA_LOG"; then
|
||||
echo "Plain approve (no review body) unexpectedly touched comment persistence" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# #835: tea v0.11.1 defines no --comment/-comment flag on `pr approve`. A
|
||||
# review body supplied alongside approve must be routed through the durable
|
||||
# comment REST API instead of being passed to `tea` directly.
|
||||
run_review approve approve approve-note
|
||||
grep -q '^pr approve 123 --repo mosaicstack/stack --login mosaicstack$' "$TEA_LOG"
|
||||
grep -q 'Approved Gitea PR #123' "$OUTPUT_FILE"
|
||||
grep -q '^POST https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
|
||||
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
|
||||
grep -q 'Added and verified review comment on Gitea PR #123 (comment ID 456)' "$OUTPUT_FILE"
|
||||
|
||||
# #835: same for `pr reject` (request-changes), where a comment is required.
|
||||
run_review request-changes request-changes changes-required
|
||||
grep -q '^pr reject 123 --repo mosaicstack/stack --login mosaicstack$' "$TEA_LOG"
|
||||
grep -q 'Requested changes on Gitea PR #123' "$OUTPUT_FILE"
|
||||
grep -q '^POST https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
|
||||
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
|
||||
grep -q 'Added and verified review comment on Gitea PR #123 (comment ID 456)' "$OUTPUT_FILE"
|
||||
|
||||
if run_review legacy-fallback comment durable-body; then
|
||||
echo "The old nonexistent tea pr comment fallback returned success" >&2
|
||||
cat "$OUTPUT_FILE" >&2
|
||||
exit 1
|
||||
fi
|
||||
if grep -q '^pr comment ' "$TEA_LOG"; then
|
||||
echo "Wrapper invoked unsupported tea pr comment" >&2
|
||||
exit 1
|
||||
fi
|
||||
if grep -q 'Added comment to Gitea PR' "$OUTPUT_FILE"; then
|
||||
echo "Wrapper reported success without durable persistence" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
complex_body=$'durable "body"\n-- marker'
|
||||
run_review comment-success comment "$complex_body"
|
||||
grep -q '^POST https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
|
||||
grep -q '^GET https://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
|
||||
grep -q 'Added and verified comment on Gitea PR #123' "$OUTPUT_FILE"
|
||||
if [[ -s "$TEA_LOG" ]]; then
|
||||
echo "REST comment path unexpectedly invoked tea" >&2
|
||||
cat "$TEA_LOG" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
run_review http-success comment durable-body http://git.mosaicstack.dev
|
||||
grep -q '^POST http://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
|
||||
grep -q '^GET http://git.mosaicstack.dev/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
|
||||
|
||||
run_review prefix-success comment durable-body https://git.mosaicstack.dev/gitea/
|
||||
grep -q '^POST https://git.mosaicstack.dev/gitea/api/v1/repos/mosaicstack/stack/issues/123/comments$' "$CURL_LOG"
|
||||
grep -q '^GET https://git.mosaicstack.dev/gitea/api/v1/repos/mosaicstack/stack/issues/comments/456$' "$CURL_LOG"
|
||||
|
||||
run_review subpath-success comment durable-body https://git.example/gitea https://git.example/gitea/owner/repo.git owner/repo
|
||||
grep -q '^POST https://git.example/gitea/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
|
||||
grep -q '^GET https://git.example/gitea/api/v1/repos/owner/repo/issues/comments/456$' "$CURL_LOG"
|
||||
if grep -q '/repos/gitea/owner/repo/' "$CURL_LOG"; then
|
||||
echo "Configured Gitea path prefix leaked into the repository slug" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
run_review port-success comment durable-body http://git.example:3000 http://git.example:3000/owner/repo.git owner/repo
|
||||
grep -q '^POST http://git.example:3000/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
|
||||
grep -q '^GET http://git.example:3000/api/v1/repos/owner/repo/issues/comments/456$' "$CURL_LOG"
|
||||
|
||||
run_review scp-ssh-success comment durable-body https://git.example git@git.example:owner/repo.git owner/repo
|
||||
grep -q '^POST https://git.example/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
|
||||
|
||||
run_review url-ssh-success comment durable-body https://git.example ssh://git@git.example/owner/repo.git owner/repo
|
||||
grep -q '^POST https://git.example/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
|
||||
|
||||
# #850 (follow-up to #812): an SSH remote's transport port (e.g. `ssh://
|
||||
# git@host:2222/...`) must NOT be compared against the configured HTTP(S) API
|
||||
# URL's port -- they identify unrelated properties (SSH daemon port vs. HTTP(S)
|
||||
# provider port) of the same Gitea host. Before the fix, host-match required
|
||||
# the configured URL to carry the identical port, so this failed closed even
|
||||
# though both remote and configured URL name the same host.
|
||||
run_review ssh-transport-port-success comment durable-body https://git.example ssh://git@git.example:2222/owner/repo.git owner/repo
|
||||
grep -q '^POST https://git.example/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
|
||||
|
||||
# #850 (follow-up to #812): an explicit default HTTP(S) port on the remote
|
||||
# (`https://host:443/...`) must be treated as equal to an implicit
|
||||
# (portless) configured URL on BOTH sides -- the pre-fix comparison only
|
||||
# normalized the default port when the REMOTE side was portless, so the
|
||||
# inverse (explicit remote, implicit configured) form failed closed.
|
||||
run_review explicit-default-port-success comment durable-body https://git.example https://git.example:443/owner/repo.git owner/repo
|
||||
grep -q '^POST https://git.example/api/v1/repos/owner/repo/issues/123/comments$' "$CURL_LOG"
|
||||
|
||||
if run_review write-transport-failure comment durable-body; then
|
||||
echo "Expected provider transport failure to return nonzero" >&2
|
||||
exit 1
|
||||
fi
|
||||
if run_review write-http-failure comment durable-body; then
|
||||
echo "Expected non-201 provider write to return nonzero" >&2
|
||||
exit 1
|
||||
fi
|
||||
if run_review readback-failure comment durable-body; then
|
||||
echo "Expected mismatched provider read-back to return nonzero" >&2
|
||||
exit 1
|
||||
fi
|
||||
if grep -q 'Added and verified comment' "$OUTPUT_FILE"; then
|
||||
echo "Read-back mismatch reported durable success" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "pr-review.sh durable Gitea comment regression passed"
|
||||
31
packages/mosaic/framework/tools/lease-broker/start-lease-broker.sh
Executable file
31
packages/mosaic/framework/tools/lease-broker/start-lease-broker.sh
Executable file
@@ -0,0 +1,31 @@
|
||||
#!/usr/bin/env bash
|
||||
# Supervisor entry point for the Mosaic lease broker daemon (issue #869, C3).
|
||||
#
|
||||
# Resolves the broker socket path with the SAME precedence as
|
||||
# `defaultLeaseBrokerSocket` in `packages/mosaic/src/commands/launch.ts`, so a
|
||||
# gated runtime launched through that client always finds the socket this
|
||||
# supervisor creates:
|
||||
# 1. an explicit MOSAIC_LEASE_BROKER_SOCKET
|
||||
# 2. "$XDG_RUNTIME_DIR/mosaic-lease/broker.sock"
|
||||
# 3. "/run/user/<uid>/mosaic-lease/broker.sock"
|
||||
#
|
||||
# The state file is colocated next to the socket (same directory,
|
||||
# "state.json"), mirroring how the broker already colocates its per-session
|
||||
# generation files beside the socket.
|
||||
#
|
||||
# This script never installs, enables, or starts the systemd unit that calls
|
||||
# it; it is only ever invoked BY that unit (or by a human/test harness that
|
||||
# passes its own HOME/XDG_RUNTIME_DIR).
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR=$(cd -- "$(dirname -- "$0")" && pwd)
|
||||
|
||||
if [ -n "${MOSAIC_LEASE_BROKER_SOCKET:-}" ]; then
|
||||
SOCKET="$MOSAIC_LEASE_BROKER_SOCKET"
|
||||
else
|
||||
RUNTIME_DIR="${XDG_RUNTIME_DIR:-/run/user/$(id -u)}"
|
||||
SOCKET="$RUNTIME_DIR/mosaic-lease/broker.sock"
|
||||
fi
|
||||
STATE="$(dirname -- "$SOCKET")/state.json"
|
||||
|
||||
exec python3 "$SCRIPT_DIR/daemon.py" --socket "$SOCKET" --state "$STATE"
|
||||
92
packages/mosaic/framework/tools/orchestrator/README.md
Normal file
92
packages/mosaic/framework/tools/orchestrator/README.md
Normal file
@@ -0,0 +1,92 @@
|
||||
# orchestrator/ tools
|
||||
|
||||
Helper scripts for r0 coordinator / orchestrator sessions — mission lifecycle,
|
||||
session health, continuation, and board maintenance. See
|
||||
`framework/guides/ORCHESTRATOR-PROTOCOL.md` for the surrounding process.
|
||||
|
||||
| Script | Purpose |
|
||||
| -------------------- | ----------------------------------------------------------------------------------------------- |
|
||||
| `mission-init.sh` | Initialize a new orchestration mission (manifest, scratchpad, TASKS.md). |
|
||||
| `mission-status.sh` | Show the mission progress dashboard. |
|
||||
| `session-run.sh` | Generate continuation context and launch the target runtime. |
|
||||
| `session-resume.sh` | Crash recovery for dead orchestrator sessions. |
|
||||
| `session-status.sh` | Check agent session health. |
|
||||
| `continue-prompt.sh` | Generate the continuation prompt for the next session. |
|
||||
| `board-roll.sh` | Keep a LIVE orchestration board under its byte cap by rolling the oldest entries to its LEDGER. |
|
||||
| `smoke-test.sh` | Behavior smoke checks for the coord continue/run workflows. |
|
||||
| `test-board-roll.sh` | Regression harness for `board-roll.sh`. |
|
||||
| `_lib.sh` | Shared functions sourced by the above (state files, TASKS.md parsing, locks). |
|
||||
|
||||
## board-roll.sh
|
||||
|
||||
Coordinator boards (`MOS-ORCHESTRATION-BOARD-LIVE.md`, `MS-LEAD-BOARD-LIVE.md`)
|
||||
follow a **"< 8 KB LIVE"** discipline: the LIVE board is the only file loaded on
|
||||
resume, so it must stay small, and history lives in an append-only LEDGER. When a
|
||||
board write would push LIVE over its cap, coordinators otherwise hand-trim and
|
||||
retry every time — an observed 38 ABORT-OVER-CAP cycles in one 24 h window.
|
||||
`board-roll.sh` automates that trim mechanically and reversibly: the audit trail
|
||||
is moved to the LEDGER instead of being hand-deleted.
|
||||
|
||||
### Contract (conservative — it never guesses what is safe to move)
|
||||
|
||||
The LIVE board opts in by wrapping its aging archival ticks in an explicit roll
|
||||
zone. Everything **outside** the markers (title, protocol blockquote, curated
|
||||
always-current `##` sections) is pinned and never touched:
|
||||
|
||||
```markdown
|
||||
# MOS ORCHESTRATION BOARD — LIVE state
|
||||
|
||||
> protocol blockquote … (pinned)
|
||||
|
||||
## 🟦 Curated always-current section (pinned)
|
||||
|
||||
…
|
||||
|
||||
<!-- BOARD-ROLL:START -->
|
||||
|
||||
### 2026-07-22 (mid²²) — newest tick, stays longest
|
||||
|
||||
…
|
||||
|
||||
### 2026-07-20 (dawn) — oldest tick, rolled first
|
||||
|
||||
…
|
||||
|
||||
<!-- BOARD-ROLL:END -->
|
||||
```
|
||||
|
||||
Inside the zone, entries are delimited by a heading marker (default `### `) and
|
||||
are assumed **newest-first (top) → oldest-last (bottom)**. `board-roll.sh` moves
|
||||
whole oldest (bottom-most) entry blocks out of the zone and appends them verbatim
|
||||
to the LEDGER, one at a time, until LIVE is back under the cap or the zone is
|
||||
empty. If the board has no markers, it exits `3` and changes nothing — adding the
|
||||
markers is a deliberate opt-in by the board owner.
|
||||
|
||||
### Usage
|
||||
|
||||
```bash
|
||||
board-roll.sh --live <LIVE.md> --ledger <LEDGER.md> [options]
|
||||
|
||||
--live <path> LIVE board file (required)
|
||||
--ledger <path> append-only LEDGER file (required; created if absent)
|
||||
--cap <bytes> size ceiling for LIVE (default 8192)
|
||||
--marker <prefix> entry-heading prefix inside the roll zone (default "### ")
|
||||
--dry-run report what would move; change nothing
|
||||
-h, --help show help and exit 0
|
||||
```
|
||||
|
||||
Only **one** roll zone is supported. If a board carries more than one
|
||||
`BOARD-ROLL:START`/`END` pair, `board-roll.sh` refuses (exit `3`, zero changes)
|
||||
rather than span first-START..last-END and relocate the curated content between
|
||||
the zones — consolidate the ticks into a single zone instead.
|
||||
|
||||
Exit codes: `0` LIVE under cap (already, or after rolling) — on `--dry-run`, a
|
||||
plan exists or nothing to do · `2` usage / argument / IO error · `3` cannot meet
|
||||
the cap (no markers, **more than one marker pair**, or the pinned sections alone
|
||||
exceed the cap and need a manual trim).
|
||||
|
||||
Writes are atomic (temp file + `mv`, LEDGER first) so a failure never leaves a
|
||||
board half-written; line endings are normalized to LF on rewrite. `--dry-run`
|
||||
first is recommended when wiring it into a board update protocol.
|
||||
|
||||
Run the regression suite with `bash test-board-roll.sh`.
|
||||
277
packages/mosaic/framework/tools/orchestrator/board-roll.sh
Normal file
277
packages/mosaic/framework/tools/orchestrator/board-roll.sh
Normal file
@@ -0,0 +1,277 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# board-roll.sh — keep a LIVE orchestration board under its byte cap by rolling
|
||||
# the oldest archival entries out to its append-only LEDGER.
|
||||
#
|
||||
# WHY: coordinator boards (MOS-ORCHESTRATION-BOARD-LIVE.md, MS-LEAD-BOARD-LIVE.md)
|
||||
# enforce a "< 8 KB LIVE" discipline via a self-guard that ABORTs the board write
|
||||
# when the file exceeds the cap. In practice the LIVE board keeps bumping the cap,
|
||||
# so coordinators hand-trim + retry every time (observed: 38 ABORT-OVER-CAP cycles
|
||||
# in a 24h window on one coordinator). This automates that trim, mechanically and
|
||||
# reversibly, so the audit trail is preserved in the LEDGER instead of hand-deleted.
|
||||
#
|
||||
# CONTRACT (conservative by design — it NEVER guesses what is safe to move):
|
||||
# The LIVE board must declare an explicit ROLL ZONE with HTML-comment markers:
|
||||
#
|
||||
# <!-- BOARD-ROLL:START -->
|
||||
# ### 2026-07-22 (newest tick — stays longest)
|
||||
# ...
|
||||
# ### 2026-07-19 (oldest tick — rolled first)
|
||||
# ...
|
||||
# <!-- BOARD-ROLL:END -->
|
||||
#
|
||||
# Everything OUTSIDE the markers (title, protocol blockquote, curated always-current
|
||||
# `##` sections) is PINNED and never touched. Inside the zone, entries are delimited
|
||||
# by a heading marker (default `### `) and are assumed newest-first (top) → oldest-last
|
||||
# (bottom), matching board convention. board-roll moves whole oldest (bottom-most)
|
||||
# entry blocks out of the zone and APPENDS them verbatim to the LEDGER, one block at a
|
||||
# time, until the LIVE file is back under the cap or the zone is empty.
|
||||
#
|
||||
# If no markers are present, it exits 3 without changing anything (safe default —
|
||||
# adding the markers is a deliberate opt-in by the board owner).
|
||||
#
|
||||
# USAGE:
|
||||
# board-roll.sh --live <LIVE.md> --ledger <LEDGER.md> [options]
|
||||
#
|
||||
# OPTIONS:
|
||||
# --live <path> LIVE board file (required)
|
||||
# --ledger <path> append-only LEDGER file (required; created if absent)
|
||||
# --cap <bytes> size ceiling for LIVE (default 8192)
|
||||
# --marker <prefix> entry-heading prefix inside the roll zone (default "### ")
|
||||
# --dry-run report what would move + resulting size; change nothing
|
||||
# -h, --help print usage and exit 0
|
||||
#
|
||||
# EXIT CODES:
|
||||
# 0 LIVE is under cap (already, or after rolling); on --dry-run, 0 = a plan exists
|
||||
# (or nothing to do)
|
||||
# 2 usage / argument / IO error (bad flag, missing file, unwritable target)
|
||||
# 3 cannot satisfy the cap: no roll markers present, MORE THAN ONE marker pair
|
||||
# (multiple zones are refused, not guessed), OR the zone was emptied and LIVE
|
||||
# is still over cap (curated pinned sections need a manual trim)
|
||||
#
|
||||
# NOTE: line endings are normalized to LF on rewrite (boards are LF markdown); a
|
||||
# trailing newline is always ensured. Writes are atomic (temp file + mv) so a
|
||||
# failure never leaves LIVE or LEDGER half-written.
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
START_MARK='<!-- BOARD-ROLL:START -->'
|
||||
END_MARK='<!-- BOARD-ROLL:END -->'
|
||||
|
||||
usage() {
|
||||
cat <<'EOF'
|
||||
Usage: board-roll.sh --live <LIVE.md> --ledger <LEDGER.md> [options]
|
||||
|
||||
Roll the oldest entries out of a LIVE orchestration board into its LEDGER
|
||||
until the LIVE file is under a byte cap. Conservative: only content inside
|
||||
explicit <!-- BOARD-ROLL:START -->/<!-- BOARD-ROLL:END --> markers is moved.
|
||||
|
||||
Options:
|
||||
--live <path> LIVE board file (required)
|
||||
--ledger <path> append-only LEDGER file (required; created if absent)
|
||||
--cap <bytes> size ceiling for LIVE (default 8192)
|
||||
--marker <prefix> entry-heading prefix inside the roll zone (default "### ")
|
||||
--dry-run report what would move; change nothing
|
||||
-h, --help show this help and exit 0
|
||||
|
||||
Exit: 0 under cap (or dry-run plan) · 2 usage/IO error · 3 cannot meet cap
|
||||
(no markers, or pinned sections alone exceed the cap).
|
||||
EOF
|
||||
}
|
||||
|
||||
die() { echo "board-roll: $*" >&2; exit 2; }
|
||||
|
||||
LIVE=""; LEDGER=""; CAP=8192; MARKER='### '; DRYRUN=0
|
||||
while [[ $# -gt 0 ]]; do
|
||||
case "$1" in
|
||||
--live) LIVE="${2:-}"; shift 2 || die "--live needs a value" ;;
|
||||
--ledger) LEDGER="${2:-}"; shift 2 || die "--ledger needs a value" ;;
|
||||
--cap) CAP="${2:-}"; shift 2 || die "--cap needs a value" ;;
|
||||
--marker) MARKER="${2:-}"; shift 2 || die "--marker needs a value" ;;
|
||||
--dry-run) DRYRUN=1; shift ;;
|
||||
-h|--help) usage; exit 0 ;;
|
||||
*) usage >&2; die "unknown option: $1" ;;
|
||||
esac
|
||||
done
|
||||
|
||||
[[ -n "$LIVE" ]] || { usage >&2; die "--live is required"; }
|
||||
[[ -n "$LEDGER" ]] || { usage >&2; die "--ledger is required"; }
|
||||
[[ -f "$LIVE" ]] || die "LIVE file not found: $LIVE"
|
||||
[[ "$CAP" =~ ^[0-9]+$ ]] || die "--cap must be a non-negative integer, got: $CAP"
|
||||
|
||||
# --- read LIVE into a line array (newlines stripped; re-added on write) ---------
|
||||
mapfile -t LINES < "$LIVE"
|
||||
|
||||
# byte size of an array rendered as LF-terminated text
|
||||
render_size() {
|
||||
if [[ $# -eq 0 ]]; then printf 0; return; fi
|
||||
printf '%s\n' "$@" | wc -c
|
||||
}
|
||||
|
||||
orig_size=$(render_size "${LINES[@]}")
|
||||
|
||||
# --- already under cap → nothing to do -----------------------------------------
|
||||
if (( orig_size < CAP )); then
|
||||
echo "board-roll: LIVE is ${orig_size}B (< cap ${CAP}B) — nothing to roll."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# --- locate the roll-zone markers ----------------------------------------------
|
||||
# Exactly ONE marker pair is supported. If a board carries more than one START or
|
||||
# END marker we REFUSE (exit 3, zero changes) rather than guess: a naive
|
||||
# first-START..last-END span would swallow the curated content and the intermediate
|
||||
# markers sitting between two intended zones and silently relocate that pinned text
|
||||
# to the LEDGER — the exact data-loss this tool exists to prevent. Refusing matches
|
||||
# the "no markers = exit 3" conservative posture.
|
||||
start_idx=-1; end_idx=-1; start_count=0; end_count=0
|
||||
for i in "${!LINES[@]}"; do
|
||||
if [[ "${LINES[$i]}" == "$START_MARK" ]]; then
|
||||
if (( start_count == 0 )); then start_idx=$i; fi
|
||||
start_count=$(( start_count + 1 ))
|
||||
fi
|
||||
if [[ "${LINES[$i]}" == "$END_MARK" ]]; then
|
||||
end_idx=$i
|
||||
end_count=$(( end_count + 1 ))
|
||||
fi
|
||||
done
|
||||
if (( start_count > 1 || end_count > 1 )); then
|
||||
echo "board-roll: LIVE is ${orig_size}B (>= cap ${CAP}B) but has ${start_count} START / ${end_count} END" >&2
|
||||
echo " markers — only a SINGLE '$START_MARK' … '$END_MARK' roll zone is supported." >&2
|
||||
echo " Multiple zones are refused (not guessed) so content between zones is never relocated." >&2
|
||||
echo " Consolidate the archival ticks into one zone, or trim manually." >&2
|
||||
exit 3
|
||||
fi
|
||||
if (( start_idx < 0 || end_idx < 0 || end_idx <= start_idx )); then
|
||||
echo "board-roll: LIVE is ${orig_size}B (>= cap ${CAP}B) but no usable roll zone" >&2
|
||||
echo " (need '$START_MARK' then '$END_MARK'). Add the markers around the" >&2
|
||||
echo " archival tick section to opt this board into automatic rolling." >&2
|
||||
exit 3
|
||||
fi
|
||||
|
||||
# preamble = lines [0 .. start_idx] (inclusive of START marker)
|
||||
# zone = lines (start_idx .. end_idx) (exclusive of both markers)
|
||||
# footer = lines [end_idx .. end] (inclusive of END marker)
|
||||
preamble=(); zone=(); footer=()
|
||||
for i in "${!LINES[@]}"; do
|
||||
if (( i <= start_idx )); then preamble+=("${LINES[$i]}")
|
||||
elif (( i < end_idx )); then zone+=("${LINES[$i]}")
|
||||
else footer+=("${LINES[$i]}")
|
||||
fi
|
||||
done
|
||||
|
||||
# --- split the zone into a fixed head + entry blocks ----------------------------
|
||||
# zone_head = any zone lines before the first entry marker (kept, never rolled).
|
||||
# blocks[k] = newline-joined text of entry k (marker line .. line before next marker).
|
||||
zone_head=(); declare -a block_start=()
|
||||
first_block=-1
|
||||
for i in "${!zone[@]}"; do
|
||||
if [[ "${zone[$i]}" == "$MARKER"* ]]; then
|
||||
[[ $first_block -eq -1 ]] && first_block=$i
|
||||
block_start+=("$i")
|
||||
fi
|
||||
done
|
||||
if (( first_block == -1 )); then
|
||||
echo "board-roll: LIVE is ${orig_size}B (>= cap ${CAP}B) but the roll zone has no" >&2
|
||||
echo " '${MARKER}' entries to move. Trim the pinned sections manually." >&2
|
||||
exit 3
|
||||
fi
|
||||
for (( i=0; i<first_block; i++ )); do zone_head+=("${zone[$i]}"); done
|
||||
|
||||
nblocks=${#block_start[@]}
|
||||
# block k spans zone[ block_start[k] .. (block_start[k+1]-1 or end-of-zone) ]
|
||||
block_text() { # $1 = block index → prints the block's lines, LF-joined (no trailing)
|
||||
local k=$1 s e
|
||||
s=${block_start[$k]}
|
||||
if (( k+1 < nblocks )); then e=$(( block_start[$((k+1))] - 1 )); else e=$(( ${#zone[@]} - 1 )); fi
|
||||
local out=()
|
||||
for (( j=s; j<=e; j++ )); do out+=("${zone[$j]}"); done
|
||||
printf '%s\n' "${out[@]}"
|
||||
}
|
||||
|
||||
# --- greedily roll oldest (bottom-most) blocks until under cap ------------------
|
||||
# keep = number of newest blocks retained; start with all, drop from the bottom.
|
||||
keep=$nblocks # blocks [keep .. nblocks-1] are the oldest set that gets moved
|
||||
current_size=$orig_size
|
||||
build_live_size() { # size of LIVE if we keep blocks [0 .. keep-1]
|
||||
local acc=("${preamble[@]}" "${zone_head[@]}")
|
||||
local k s e j
|
||||
for (( k=0; k<keep; k++ )); do
|
||||
s=${block_start[$k]}
|
||||
if (( k+1 < nblocks )); then e=$(( block_start[$((k+1))] - 1 )); else e=$(( ${#zone[@]} - 1 )); fi
|
||||
for (( j=s; j<=e; j++ )); do acc+=("${zone[$j]}"); done
|
||||
done
|
||||
acc+=("${footer[@]}")
|
||||
render_size "${acc[@]}"
|
||||
}
|
||||
while (( current_size >= CAP && keep > 0 )); do
|
||||
keep=$(( keep - 1 ))
|
||||
current_size=$(build_live_size)
|
||||
done
|
||||
|
||||
moved_count=$(( nblocks - keep ))
|
||||
if (( moved_count == 0 )); then
|
||||
# zone had entries but none movable brought us under (shouldn't happen: keep hits 0)
|
||||
echo "board-roll: could not reduce LIVE below cap (${current_size}B >= ${CAP}B)." >&2
|
||||
exit 3
|
||||
fi
|
||||
|
||||
# --- dry-run report -------------------------------------------------------------
|
||||
plan_headers() {
|
||||
local k
|
||||
for (( k=keep; k<nblocks; k++ )); do
|
||||
# first line of each moved block
|
||||
printf ' %s\n' "${zone[${block_start[$k]}]}"
|
||||
done
|
||||
}
|
||||
if (( DRYRUN )); then
|
||||
echo "board-roll: DRY RUN"
|
||||
echo " LIVE now: ${orig_size}B (cap ${CAP}B) — over by $(( orig_size - CAP ))B"
|
||||
echo " would roll: ${moved_count} of ${nblocks} entr$([[ $moved_count -eq 1 ]] && echo y || echo ies) (oldest first):"
|
||||
plan_headers
|
||||
echo " LIVE after: ${current_size}B"
|
||||
if (( current_size >= CAP )); then
|
||||
echo " WARNING: still >= cap after emptying the zone; pinned sections need a manual trim." >&2
|
||||
exit 3
|
||||
fi
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# --- commit the roll atomically -------------------------------------------------
|
||||
live_tmp="$(mktemp "${LIVE}.roll.XXXXXX")" || die "cannot create temp next to LIVE"
|
||||
ledger_tmp=""
|
||||
# shellcheck disable=SC2329 # invoked indirectly via `trap cleanup EXIT`
|
||||
cleanup() { rm -f "$live_tmp" "$ledger_tmp" 2>/dev/null || true; }
|
||||
trap cleanup EXIT
|
||||
|
||||
# new LIVE = preamble + zone_head + kept blocks + footer
|
||||
{
|
||||
printf '%s\n' "${preamble[@]}" "${zone_head[@]}"
|
||||
for (( k=0; k<keep; k++ )); do block_text "$k"; done
|
||||
printf '%s\n' "${footer[@]}"
|
||||
} > "$live_tmp"
|
||||
|
||||
# LEDGER gets the moved blocks appended verbatim, in original top→bottom order,
|
||||
# under a provenance separator. LEDGER is append-only, so we only ever add at EOF.
|
||||
ledger_tmp="$(mktemp "${LEDGER}.roll.XXXXXX")" || die "cannot create temp next to LEDGER"
|
||||
if [[ -f "$LEDGER" ]]; then cat "$LEDGER" > "$ledger_tmp"; fi
|
||||
# ensure a trailing newline on existing content before appending
|
||||
if [[ -s "$ledger_tmp" && -n "$(tail -c1 "$ledger_tmp")" ]]; then printf '\n' >> "$ledger_tmp"; fi
|
||||
{
|
||||
printf '\n<!-- board-roll: %d entr%s rolled from %s -->\n' \
|
||||
"$moved_count" "$([[ $moved_count -eq 1 ]] && echo y || echo ies)" "$(basename "$LIVE")"
|
||||
for (( k=keep; k<nblocks; k++ )); do block_text "$k"; done
|
||||
} >> "$ledger_tmp"
|
||||
|
||||
# atomic swap (both, LEDGER first so a crash never drops content that left LIVE)
|
||||
mv "$ledger_tmp" "$LEDGER"; ledger_tmp=""
|
||||
mv "$live_tmp" "$LIVE"; live_tmp=""
|
||||
trap - EXIT
|
||||
|
||||
# read the real on-disk size back (truthful, not the predicted value)
|
||||
final_size=$(wc -c < "$LIVE")
|
||||
echo "board-roll: rolled ${moved_count} entr$([[ $moved_count -eq 1 ]] && echo y || echo ies) to $(basename "$LEDGER"); LIVE ${orig_size}B → ${final_size}B (cap ${CAP}B)."
|
||||
if (( final_size >= CAP )); then
|
||||
echo "board-roll: still >= cap after rolling all zone entries; pinned sections need a manual trim." >&2
|
||||
exit 3
|
||||
fi
|
||||
exit 0
|
||||
156
packages/mosaic/framework/tools/orchestrator/test-board-roll.sh
Normal file
156
packages/mosaic/framework/tools/orchestrator/test-board-roll.sh
Normal file
@@ -0,0 +1,156 @@
|
||||
#!/usr/bin/env bash
|
||||
# Regression harness for board-roll.sh — rolling oldest LIVE-board entries to LEDGER.
|
||||
#
|
||||
# Asserts:
|
||||
# 1. Under cap → no-op, exit 0, files unchanged.
|
||||
# 2. Over cap, no roll markers → exit 3, LIVE unchanged (never guesses).
|
||||
# 3. Over cap, markers present → rolls the fewest oldest entries to get under cap,
|
||||
# LIVE ends under cap, pinned preamble/footer + newest entries preserved.
|
||||
# 4. Rolled blocks land in the LEDGER verbatim, oldest set in original order.
|
||||
# 5. --dry-run changes nothing and reports a plan.
|
||||
# 6. Zone emptied but pinned sections alone exceed cap → exit 3.
|
||||
# 7. --help exits 0 and prints usage; an unknown flag exits nonzero (#701 discipline).
|
||||
# 8. More than one marker pair → exit 3, unchanged; curated content between the two
|
||||
# zones is never relocated to the LEDGER (rev0 #868 regression).
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
SUT="$SCRIPT_DIR/board-roll.sh"
|
||||
|
||||
fail=0
|
||||
note() { echo "FAIL: $*" >&2; fail=1; }
|
||||
|
||||
WORK="$(mktemp -d)"
|
||||
trap 'rm -rf "$WORK"' EXIT
|
||||
|
||||
# builds a LIVE board: pinned preamble + roll zone with N dated entries (newest first),
|
||||
# each entry padded to be individually large so the cap math is predictable.
|
||||
make_board() { # $1 file $2 n_entries $3 with_markers(1/0) $4 pad_bytes
|
||||
local f=$1 n=$2 markers=$3 pad=$4 i padtxt
|
||||
padtxt=$(head -c "$pad" < /dev/zero | tr '\0' 'x')
|
||||
{
|
||||
echo "# BOARD — LIVE"
|
||||
echo "> pinned protocol blockquote, never rolled."
|
||||
echo
|
||||
echo "## Curated always-current section (pinned)"
|
||||
echo "- this stays no matter what"
|
||||
echo
|
||||
[[ "$markers" == 1 ]] && echo '<!-- BOARD-ROLL:START -->'
|
||||
# newest first (i=n .. 1); oldest (i=1) ends at the bottom
|
||||
for (( i=n; i>=1; i-- )); do
|
||||
echo "### 2026-07-$(printf '%02d' $i) tick number $i"
|
||||
echo "- detail $i $padtxt"
|
||||
echo
|
||||
done
|
||||
[[ "$markers" == 1 ]] && echo '<!-- BOARD-ROLL:END -->'
|
||||
} > "$f"
|
||||
return 0
|
||||
}
|
||||
|
||||
# ── 1. under cap → no-op ───────────────────────────────────────────────────────
|
||||
L="$WORK/live1.md"; G="$WORK/ledger1.md"; : > "$G"
|
||||
make_board "$L" 2 1 10
|
||||
before=$(cat "$L")
|
||||
if ! out=$(bash "$SUT" --live "$L" --ledger "$G" --cap 100000 2>&1); then
|
||||
note "under-cap should exit 0 (got nonzero): $out"
|
||||
fi
|
||||
[[ "$(cat "$L")" == "$before" ]] || note "under-cap modified LIVE"
|
||||
[[ -s "$G" ]] && note "under-cap wrote to LEDGER"
|
||||
|
||||
# ── 2. over cap, no markers → exit 3, unchanged ────────────────────────────────
|
||||
L="$WORK/live2.md"; G="$WORK/ledger2.md"; : > "$G"
|
||||
make_board "$L" 6 0 400
|
||||
before=$(cat "$L")
|
||||
set +e; bash "$SUT" --live "$L" --ledger "$G" --cap 800 >/dev/null 2>&1; rc=$?; set -e
|
||||
[[ "$rc" -eq 3 ]] || note "no-markers over-cap should exit 3 (got $rc)"
|
||||
[[ "$(cat "$L")" == "$before" ]] || note "no-markers run modified LIVE (must never guess)"
|
||||
|
||||
# ── 3+4. over cap with markers → rolls oldest, LIVE under cap, LEDGER gets them ─
|
||||
L="$WORK/live3.md"; G="$WORK/ledger3.md"; echo "# LEDGER" > "$G"
|
||||
make_board "$L" 6 1 400 # 6 entries, each ~>400B
|
||||
big=$(wc -c < "$L")
|
||||
[[ "$big" -ge 2000 ]] || note "fixture too small to test rolling ($big B)"
|
||||
if ! out=$(bash "$SUT" --live "$L" --ledger "$G" --cap 2000 2>&1); then
|
||||
note "marker roll should exit 0 when it can get under cap: $out"
|
||||
fi
|
||||
after=$(wc -c < "$L")
|
||||
[[ "$after" -lt 2000 ]] || note "LIVE still >= cap after roll ($after B)"
|
||||
# pinned content survives
|
||||
grep -q "Curated always-current section" "$L" || note "roll dropped pinned section"
|
||||
grep -q 'BOARD-ROLL:START' "$L" || note "roll dropped START marker"
|
||||
grep -q 'BOARD-ROLL:END' "$L" || note "roll dropped END marker"
|
||||
# newest entry (07-06) stays; oldest (07-01) is the first to leave
|
||||
grep -q "### 2026-07-06 tick number 6" "$L" || note "roll dropped the newest entry"
|
||||
grep -q "### 2026-07-01 tick number 1" "$L" && note "oldest entry not rolled out of LIVE"
|
||||
# oldest went to LEDGER
|
||||
grep -q "### 2026-07-01 tick number 1" "$G" || note "oldest entry not appended to LEDGER"
|
||||
grep -q "board-roll:.*rolled from live3.md" "$G" || note "LEDGER missing provenance separator"
|
||||
# a rolled entry must not be duplicated (present in exactly one of LIVE/LEDGER)
|
||||
if grep -q "### 2026-07-01 tick number 1" "$L"; then note "rolled entry duplicated in LIVE"; fi
|
||||
# LEDGER original content preserved
|
||||
grep -q "^# LEDGER" "$G" || note "roll clobbered existing LEDGER content"
|
||||
|
||||
# ── 5. --dry-run changes nothing ───────────────────────────────────────────────
|
||||
L="$WORK/live5.md"; G="$WORK/ledger5.md"; echo "# LEDGER" > "$G"
|
||||
make_board "$L" 6 1 400
|
||||
before_l=$(cat "$L"); before_g=$(cat "$G")
|
||||
out=$(bash "$SUT" --live "$L" --ledger "$G" --cap 2000 --dry-run 2>&1) || note "dry-run exited nonzero: $out"
|
||||
echo "$out" | grep -qi "dry run" || note "dry-run did not announce itself"
|
||||
echo "$out" | grep -q "would roll" || note "dry-run did not report a plan"
|
||||
[[ "$(cat "$L")" == "$before_l" ]] || note "dry-run modified LIVE"
|
||||
[[ "$(cat "$G")" == "$before_g" ]] || note "dry-run modified LEDGER"
|
||||
|
||||
# ── 6. zone emptied, pinned alone over cap → exit 3 ────────────────────────────
|
||||
# cap 120 is below the pinned preamble+footer size (~180B), so even after rolling
|
||||
# every zone entry the LIVE file stays over cap → must report the unsatisfiable case.
|
||||
L="$WORK/live6.md"; G="$WORK/ledger6.md"; echo "# LEDGER" > "$G"
|
||||
make_board "$L" 3 1 50
|
||||
set +e; bash "$SUT" --live "$L" --ledger "$G" --cap 120 >/dev/null 2>&1; rc=$?; set -e
|
||||
[[ "$rc" -eq 3 ]] || note "unsatisfiable cap should exit 3 (got $rc)"
|
||||
|
||||
# ── 7. help exits 0, unknown flag exits nonzero (#701) ─────────────────────────
|
||||
if ! out=$(bash "$SUT" --help 2>&1); then note "--help exited nonzero"; fi
|
||||
[[ "$out" == Usage:* ]] || note "--help did not print usage"
|
||||
bash "$SUT" -h >/dev/null 2>&1 || note "-h exited nonzero"
|
||||
if bash "$SUT" --not-a-real-flag >/dev/null 2>&1; then note "unknown flag was accepted"; fi
|
||||
if bash "$SUT" --live "$WORK/live3.md" >/dev/null 2>&1; then note "missing --ledger was accepted"; fi
|
||||
|
||||
# ── 8. multiple marker pairs → exit 3, unchanged (no cross-zone relocation) ─────
|
||||
# Two separately-marked zones with a curated pinned section BETWEEN them. A naive
|
||||
# first-START..last-END span would sweep that curated section (and the intermediate
|
||||
# markers) into the LEDGER. board-roll must refuse (exit 3) and touch nothing.
|
||||
L="$WORK/live8.md"; G="$WORK/ledger8.md"; echo "# LEDGER" > "$G"
|
||||
pad8=$(head -c 300 < /dev/zero | tr '\0' 'x')
|
||||
{
|
||||
echo "# BOARD — LIVE"
|
||||
echo "> pinned protocol blockquote"
|
||||
echo
|
||||
echo '<!-- BOARD-ROLL:START -->'
|
||||
echo "### 2026-07-10 zone-A newest"
|
||||
echo "- detail A2 $pad8"
|
||||
echo "### 2026-07-09 zone-A oldest"
|
||||
echo "- detail A1 $pad8"
|
||||
echo '<!-- BOARD-ROLL:END -->'
|
||||
echo
|
||||
echo "## Curated-between-zones (pinned — must never move)"
|
||||
echo "- CANARY-BETWEEN keep me"
|
||||
echo
|
||||
echo '<!-- BOARD-ROLL:START -->'
|
||||
echo "### 2026-07-08 zone-B newest"
|
||||
echo "- detail B2 $pad8"
|
||||
echo "### 2026-07-07 zone-B oldest"
|
||||
echo "- detail B1 $pad8"
|
||||
echo '<!-- BOARD-ROLL:END -->'
|
||||
} > "$L"
|
||||
before8=$(cat "$L")
|
||||
set +e; bash "$SUT" --live "$L" --ledger "$G" --cap 80 >/dev/null 2>&1; rc=$?; set -e
|
||||
[[ "$rc" -eq 3 ]] || note "multi-pair board should exit 3 (got $rc)"
|
||||
[[ "$(cat "$L")" == "$before8" ]] || note "multi-pair run modified LIVE (must never guess across zones)"
|
||||
grep -q "CANARY-BETWEEN keep me" "$L" || note "multi-pair run relocated curated between-zones content"
|
||||
grep -q "CANARY-BETWEEN" "$G" && note "curated between-zones content leaked into LEDGER"
|
||||
|
||||
if [[ "$fail" -eq 0 ]]; then
|
||||
echo "board-roll regression passed (8 groups)"
|
||||
fi
|
||||
exit "$fail"
|
||||
@@ -50,6 +50,21 @@ if ! [[ "$FILE_PATH" =~ \.(ts|tsx|js|jsx|mjs|cjs)$ ]]; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# Deps preflight (#856): this hook is the common gate-entry seam the delivery
|
||||
# cycle invokes on every Edit/Write/MultiEdit — it fires before any pnpm-based
|
||||
# gate (test/lint/typecheck/format:check) runs against the edited file. In a
|
||||
# freshly created git worktree (pnpm workspaces do NOT share node_modules
|
||||
# across worktrees), node_modules/.bin is empty until `pnpm install` has run,
|
||||
# so gate binaries (tsc/eslint/prettier/vitest) fail with a raw, illegible
|
||||
# `sh: 1: <tool>: not found` that is indistinguishable from a real failure.
|
||||
# Fail legibly here instead, before that raw error has a chance to surface.
|
||||
BIN_DIR="$PROJECT_ROOT/node_modules/.bin"
|
||||
if [ ! -d "$BIN_DIR" ] || [ -z "$(ls -A "$BIN_DIR" 2>/dev/null)" ]; then
|
||||
echo "deps not installed — run pnpm install" >&2
|
||||
echo "[$(date '+%Y-%m-%d %H:%M:%S')] [ERROR] deps not installed — run pnpm install ($BIN_DIR is missing or empty)" >> "$LOG_FILE"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Call the main QA handler with extracted parameters
|
||||
if [ -f ~/.config/mosaic/tools/qa/qa-hook-handler.sh ]; then
|
||||
echo "[$(date '+%Y-%m-%d %H:%M:%S')] Calling QA handler for $FILE_PATH" >> "$LOG_FILE"
|
||||
|
||||
116
packages/mosaic/framework/tools/qa/test-deps-preflight.sh
Executable file
116
packages/mosaic/framework/tools/qa/test-deps-preflight.sh
Executable file
@@ -0,0 +1,116 @@
|
||||
#!/usr/bin/env bash
|
||||
# Regression harness for #856: worker git-worktrees under a fresh `git worktree
|
||||
# add` have no node_modules until `pnpm install` runs (pnpm workspaces do NOT
|
||||
# share node_modules across worktrees). Before the fix, the gate-entry seam
|
||||
# (qa-hook-stdin.sh, registered as the PostToolUse hook for every Edit/Write/
|
||||
# MultiEdit in runtime/claude/settings.json) silently let a raw
|
||||
# `sh: 1: <tool>: not found` surface from any downstream gate invocation —
|
||||
# indistinguishable from a real test/lint failure (false-red).
|
||||
#
|
||||
# Asserts:
|
||||
# 1. RED (documented): a completely fresh worktree with no node_modules/.bin
|
||||
# at all produces the raw "not found" for a gate binary — this is the
|
||||
# defect the fix prevents from reaching the operator un-annotated.
|
||||
# 2. With node_modules/.bin missing entirely, the seam exits nonzero with
|
||||
# the legible sentinel "deps not installed — run pnpm install" instead
|
||||
# of silently proceeding (exit 0) into a would-be raw not-found.
|
||||
# 3. With node_modules/.bin present but empty, same legible-sentinel
|
||||
# behavior (covers `git worktree add` immediately followed by an
|
||||
# as-yet-incomplete/interrupted install).
|
||||
# 4. Once node_modules/.bin is populated (post `pnpm install`), the seam
|
||||
# proceeds normally (exit 0) — the preflight does not false-positive.
|
||||
# 5. Non-JS/TS files are unaffected (existing skip behavior preserved).
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
HOOK="$SCRIPT_DIR/qa-hook-stdin.sh"
|
||||
|
||||
TMP_DIR=$(mktemp -d)
|
||||
trap 'rm -rf "$TMP_DIR"' EXIT
|
||||
|
||||
fail=0
|
||||
|
||||
fail_msg() {
|
||||
echo "FAIL: $*" >&2
|
||||
fail=1
|
||||
}
|
||||
|
||||
run_hook() {
|
||||
local file_path="$1"
|
||||
printf '{"tool_name":"Edit","tool_input":{"file_path":"%s"}}' "$file_path" | "$HOOK"
|
||||
}
|
||||
|
||||
make_fixture_repo() {
|
||||
local dir="$1"
|
||||
mkdir -p "$dir"
|
||||
git -C "$dir" init -q .
|
||||
git -C "$dir" -c user.email=fixture@test -c user.name=fixture commit -q --allow-empty -m init
|
||||
}
|
||||
|
||||
# --- Scenario 1: RED — document the pre-fix raw not-found a gate hits when
|
||||
# node_modules/.bin is entirely absent (this is what the preflight now
|
||||
# intercepts before any gate command runs).
|
||||
RED_DIR="$TMP_DIR/red-fixture"
|
||||
make_fixture_repo "$RED_DIR"
|
||||
RED_OUTPUT=$(PATH="/usr/bin:/bin" sh -c 'tsc --noEmit' 2>&1) && RED_STATUS=0 || RED_STATUS=$?
|
||||
case "$RED_OUTPUT" in
|
||||
*"not found"*) ;;
|
||||
*) fail_msg "expected the raw un-preflighted invocation to demonstrate 'not found'; got: $RED_OUTPUT" ;;
|
||||
esac
|
||||
[[ "$RED_STATUS" -ne 0 ]] || fail_msg "expected raw invocation without deps installed to fail"
|
||||
|
||||
# --- Scenario 2: node_modules/.bin missing entirely -> legible sentinel, nonzero.
|
||||
MISSING_DIR="$TMP_DIR/missing-bin"
|
||||
make_fixture_repo "$MISSING_DIR"
|
||||
echo "console.log(1)" > "$MISSING_DIR/x.ts"
|
||||
OUTPUT=$(cd "$MISSING_DIR" && run_hook "$MISSING_DIR/x.ts" 2>&1) && STATUS=0 || STATUS=$?
|
||||
[[ "$STATUS" -ne 0 ]] || fail_msg "missing node_modules/.bin: expected nonzero exit, got 0"
|
||||
case "$OUTPUT" in
|
||||
*"deps not installed"*"pnpm install"*) ;;
|
||||
*) fail_msg "missing node_modules/.bin: expected legible sentinel, got: $OUTPUT" ;;
|
||||
esac
|
||||
|
||||
# --- Scenario 3: node_modules/.bin present but empty -> legible sentinel, nonzero.
|
||||
EMPTY_DIR="$TMP_DIR/empty-bin"
|
||||
make_fixture_repo "$EMPTY_DIR"
|
||||
mkdir -p "$EMPTY_DIR/node_modules/.bin"
|
||||
echo "console.log(1)" > "$EMPTY_DIR/x.ts"
|
||||
OUTPUT=$(cd "$EMPTY_DIR" && run_hook "$EMPTY_DIR/x.ts" 2>&1) && STATUS=0 || STATUS=$?
|
||||
[[ "$STATUS" -ne 0 ]] || fail_msg "empty node_modules/.bin: expected nonzero exit, got 0"
|
||||
case "$OUTPUT" in
|
||||
*"deps not installed"*"pnpm install"*) ;;
|
||||
*) fail_msg "empty node_modules/.bin: expected legible sentinel, got: $OUTPUT" ;;
|
||||
esac
|
||||
|
||||
# --- Scenario 4: node_modules/.bin populated (post `pnpm install`) -> proceeds normally.
|
||||
OK_DIR="$TMP_DIR/installed-bin"
|
||||
make_fixture_repo "$OK_DIR"
|
||||
mkdir -p "$OK_DIR/node_modules/.bin"
|
||||
printf '#!/bin/sh\necho ok\n' > "$OK_DIR/node_modules/.bin/tsc"
|
||||
chmod +x "$OK_DIR/node_modules/.bin/tsc"
|
||||
echo "console.log(1)" > "$OK_DIR/x.ts"
|
||||
OUTPUT=$(cd "$OK_DIR" && run_hook "$OK_DIR/x.ts" 2>&1) && STATUS=0 || STATUS=$?
|
||||
[[ "$STATUS" -eq 0 ]] || fail_msg "populated node_modules/.bin: expected exit 0, got $STATUS ($OUTPUT)"
|
||||
case "$OUTPUT" in
|
||||
*"deps not installed"*) fail_msg "populated node_modules/.bin: unexpected sentinel fired: $OUTPUT" ;;
|
||||
*) ;;
|
||||
esac
|
||||
|
||||
# --- Scenario 5: non-JS/TS files are unaffected by the preflight (still
|
||||
# skipped before the deps check, regardless of node_modules state).
|
||||
NONJS_DIR="$TMP_DIR/nonjs"
|
||||
make_fixture_repo "$NONJS_DIR"
|
||||
echo "# doc" > "$NONJS_DIR/README.md"
|
||||
OUTPUT=$(cd "$NONJS_DIR" && run_hook "$NONJS_DIR/README.md" 2>&1) && STATUS=0 || STATUS=$?
|
||||
[[ "$STATUS" -eq 0 ]] || fail_msg "non-JS/TS file: expected exit 0 (skip), got $STATUS ($OUTPUT)"
|
||||
case "$OUTPUT" in
|
||||
*"deps not installed"*) fail_msg "non-JS/TS file: preflight incorrectly fired: $OUTPUT" ;;
|
||||
*) ;;
|
||||
esac
|
||||
|
||||
if [[ "$fail" -eq 0 ]]; then
|
||||
echo "deps-preflight regression passed (5/5 scenarios)"
|
||||
fi
|
||||
|
||||
exit "$fail"
|
||||
@@ -25,7 +25,7 @@
|
||||
"lint": "eslint src",
|
||||
"typecheck": "tsc --noEmit",
|
||||
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
|
||||
"test:framework-shell": "python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh"
|
||||
"test:framework-shell": "python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh"
|
||||
},
|
||||
"dependencies": {
|
||||
"@mosaicstack/brain": "workspace:*",
|
||||
|
||||
237
packages/mosaic/src/lease-broker/broker-supervisor.spec.ts
Normal file
237
packages/mosaic/src/lease-broker/broker-supervisor.spec.ts
Normal file
@@ -0,0 +1,237 @@
|
||||
import { createServer, type Server } from 'node:net';
|
||||
import { mkdir, mkdtemp, readFile, rm, stat, writeFile } from 'node:fs/promises';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
|
||||
import { afterEach, describe, expect, it } from 'vitest';
|
||||
|
||||
import {
|
||||
applyBrokerSupervisor,
|
||||
checkBrokerSupervisorHealth,
|
||||
isBrokerSupervisorHealthy,
|
||||
resolveBrokerSupervisorPaths,
|
||||
resolveLeaseBrokerSocketPath,
|
||||
type BrokerSupervisorPaths,
|
||||
} from './broker-supervisor.js';
|
||||
|
||||
const REAL_FRAMEWORK_ROOT = new URL('../../framework/', import.meta.url).pathname;
|
||||
|
||||
const cleanupDirs: string[] = [];
|
||||
const cleanupServers: Server[] = [];
|
||||
|
||||
async function tempDir(prefix: string): Promise<string> {
|
||||
const dir = await mkdtemp(join(tmpdir(), prefix));
|
||||
cleanupDirs.push(dir);
|
||||
return dir;
|
||||
}
|
||||
|
||||
afterEach(async () => {
|
||||
for (const server of cleanupServers.splice(0)) {
|
||||
await new Promise<void>((resolve) => server.close(() => resolve()));
|
||||
}
|
||||
for (const dir of cleanupDirs.splice(0)) {
|
||||
await rm(dir, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
describe('resolveLeaseBrokerSocketPath', () => {
|
||||
it('honors an explicit MOSAIC_LEASE_BROKER_SOCKET override', () => {
|
||||
expect(resolveLeaseBrokerSocketPath({ MOSAIC_LEASE_BROKER_SOCKET: '/tmp/explicit.sock' })).toBe(
|
||||
'/tmp/explicit.sock',
|
||||
);
|
||||
});
|
||||
|
||||
it('falls back to $XDG_RUNTIME_DIR/mosaic-lease/broker.sock', () => {
|
||||
expect(resolveLeaseBrokerSocketPath({ XDG_RUNTIME_DIR: '/run/user/1000' })).toBe(
|
||||
join('/run/user/1000', 'mosaic-lease', 'broker.sock'),
|
||||
);
|
||||
});
|
||||
|
||||
it('falls back to /run/user/<uid>/mosaic-lease/broker.sock as a last resort', () => {
|
||||
expect(resolveLeaseBrokerSocketPath({}, 4242)).toBe(
|
||||
join('/run/user', '4242', 'mosaic-lease', 'broker.sock'),
|
||||
);
|
||||
});
|
||||
|
||||
it('prefers the explicit override over XDG_RUNTIME_DIR', () => {
|
||||
expect(
|
||||
resolveLeaseBrokerSocketPath({
|
||||
MOSAIC_LEASE_BROKER_SOCKET: '/explicit.sock',
|
||||
XDG_RUNTIME_DIR: '/run/user/1000',
|
||||
}),
|
||||
).toBe('/explicit.sock');
|
||||
});
|
||||
});
|
||||
|
||||
describe('resolveBrokerSupervisorPaths', () => {
|
||||
it('colocates the state file next to the resolved socket', () => {
|
||||
const paths = resolveBrokerSupervisorPaths({
|
||||
mosaicHome: '/home/x/.config/mosaic',
|
||||
frameworkRoot: '/repo/framework',
|
||||
env: { XDG_RUNTIME_DIR: '/run/user/1000' },
|
||||
});
|
||||
expect(paths.socketPath).toBe(join('/run/user/1000', 'mosaic-lease', 'broker.sock'));
|
||||
expect(paths.statePath).toBe(join('/run/user/1000', 'mosaic-lease', 'state.json'));
|
||||
});
|
||||
|
||||
it('targets the systemd --user dir under the given home, not mosaicHome', () => {
|
||||
const paths = resolveBrokerSupervisorPaths({
|
||||
mosaicHome: '/somewhere-else/.config/mosaic',
|
||||
frameworkRoot: '/repo/framework',
|
||||
homeDir: '/home/canary',
|
||||
env: {},
|
||||
uid: 0,
|
||||
});
|
||||
expect(paths.systemdUserDir).toBe(join('/home/canary', '.config', 'systemd', 'user'));
|
||||
expect(paths.unitTargetPath).toBe(
|
||||
join('/home/canary', '.config', 'systemd', 'user', 'mosaic-lease-broker.service'),
|
||||
);
|
||||
});
|
||||
|
||||
it('is a pure function: identical options resolve to identical paths', () => {
|
||||
const options = {
|
||||
mosaicHome: '/h/.config/mosaic',
|
||||
frameworkRoot: '/repo/framework',
|
||||
env: { XDG_RUNTIME_DIR: '/run/user/1000' },
|
||||
};
|
||||
expect(resolveBrokerSupervisorPaths(options)).toEqual(resolveBrokerSupervisorPaths(options));
|
||||
});
|
||||
});
|
||||
|
||||
describe('applyBrokerSupervisor', () => {
|
||||
async function fakePaths(): Promise<BrokerSupervisorPaths> {
|
||||
const home = await tempDir('mosaic-broker-supervisor-home-');
|
||||
const mosaicHome = join(home, '.config', 'mosaic');
|
||||
const runtimeDir = await tempDir('mosaic-broker-supervisor-runtime-');
|
||||
return resolveBrokerSupervisorPaths({
|
||||
mosaicHome,
|
||||
frameworkRoot: REAL_FRAMEWORK_ROOT,
|
||||
homeDir: home,
|
||||
env: { XDG_RUNTIME_DIR: runtimeDir },
|
||||
});
|
||||
}
|
||||
|
||||
it('renders a unit that references the installed wrapper script and hardens the runtime dir', async () => {
|
||||
const paths = await fakePaths();
|
||||
const unitSource = await readFile(paths.unitSourcePath, 'utf8');
|
||||
expect(unitSource).toContain('ExecStart=');
|
||||
expect(unitSource).toContain('%h/.config/mosaic/tools/lease-broker/start-lease-broker.sh');
|
||||
expect(unitSource).toContain('RuntimeDirectory=mosaic-lease');
|
||||
expect(unitSource).toContain('RuntimeDirectoryMode=0700');
|
||||
expect(unitSource).toContain('Restart=on-failure');
|
||||
expect(unitSource).toContain('WantedBy=default.target');
|
||||
// No ambient environment file preload, matching the other fleet units'
|
||||
// strict-parsing convention.
|
||||
expect(unitSource).not.toMatch(/^Environment(File)?=/m);
|
||||
});
|
||||
|
||||
it('materializes the unit, wrapper script, and daemon sources on first apply', async () => {
|
||||
const paths = await fakePaths();
|
||||
|
||||
const result = await applyBrokerSupervisor(paths);
|
||||
|
||||
expect(result.installedFiles).toContain(paths.unitTargetPath);
|
||||
expect(result.installedFiles).toContain(paths.wrapperTargetPath);
|
||||
for (const target of paths.daemonTargetPaths) {
|
||||
expect(result.installedFiles).toContain(target);
|
||||
}
|
||||
|
||||
const unitTargetContent = await readFile(paths.unitTargetPath, 'utf8');
|
||||
const unitSourceContent = await readFile(paths.unitSourcePath, 'utf8');
|
||||
expect(unitTargetContent).toBe(unitSourceContent);
|
||||
|
||||
const wrapperMode = (await stat(paths.wrapperTargetPath)).mode & 0o777;
|
||||
expect(wrapperMode).toBe(0o755);
|
||||
|
||||
for (const target of paths.daemonTargetPaths) {
|
||||
await expect(stat(target)).resolves.toBeDefined();
|
||||
}
|
||||
});
|
||||
|
||||
it('is idempotent: applying twice reproduces identical files with no error', async () => {
|
||||
const paths = await fakePaths();
|
||||
|
||||
await applyBrokerSupervisor(paths);
|
||||
const firstUnit = await readFile(paths.unitTargetPath, 'utf8');
|
||||
const firstWrapper = await readFile(paths.wrapperTargetPath, 'utf8');
|
||||
const firstWrapperMode = (await stat(paths.wrapperTargetPath)).mode & 0o777;
|
||||
|
||||
await expect(applyBrokerSupervisor(paths)).resolves.toBeDefined();
|
||||
|
||||
const secondUnit = await readFile(paths.unitTargetPath, 'utf8');
|
||||
const secondWrapper = await readFile(paths.wrapperTargetPath, 'utf8');
|
||||
const secondWrapperMode = (await stat(paths.wrapperTargetPath)).mode & 0o777;
|
||||
|
||||
expect(secondUnit).toBe(firstUnit);
|
||||
expect(secondWrapper).toBe(firstWrapper);
|
||||
expect(secondWrapperMode).toBe(firstWrapperMode);
|
||||
});
|
||||
|
||||
it('never touches the real host: only writes under the supplied temp dirs', async () => {
|
||||
const paths = await fakePaths();
|
||||
await applyBrokerSupervisor(paths);
|
||||
expect(paths.systemdUserDir.startsWith(tmpdir())).toBe(true);
|
||||
expect(paths.mosaicHome.startsWith(tmpdir())).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
describe('checkBrokerSupervisorHealth / isBrokerSupervisorHealthy', () => {
|
||||
async function fakeHealthPaths(): Promise<
|
||||
Pick<BrokerSupervisorPaths, 'unitTargetPath' | 'socketPath'>
|
||||
> {
|
||||
const runtimeDir = await tempDir('mosaic-broker-supervisor-health-');
|
||||
await mkdir(join(runtimeDir, 'systemd-user'), { recursive: true });
|
||||
return {
|
||||
unitTargetPath: join(runtimeDir, 'systemd-user', 'mosaic-lease-broker.service'),
|
||||
socketPath: join(runtimeDir, 'broker.sock'),
|
||||
};
|
||||
}
|
||||
|
||||
it('reports unhealthy when neither the unit nor the socket exist', async () => {
|
||||
const paths = await fakeHealthPaths();
|
||||
|
||||
const health = await checkBrokerSupervisorHealth(paths);
|
||||
|
||||
expect(health).toEqual({ unitInstalled: false, socketPresent: false, healthy: false });
|
||||
expect(await isBrokerSupervisorHealthy(paths)).toBe(false);
|
||||
});
|
||||
|
||||
it('reports unhealthy when the unit is installed but no socket is listening', async () => {
|
||||
const paths = await fakeHealthPaths();
|
||||
await writeFile(paths.unitTargetPath, '[Unit]\n');
|
||||
|
||||
const health = await checkBrokerSupervisorHealth(paths);
|
||||
|
||||
expect(health.unitInstalled).toBe(true);
|
||||
expect(health.socketPresent).toBe(false);
|
||||
expect(health.healthy).toBe(false);
|
||||
});
|
||||
|
||||
it('reports healthy=true once a real Unix socket exists at the resolved path, and false again once removed', async () => {
|
||||
const paths = await fakeHealthPaths();
|
||||
|
||||
const server = createServer();
|
||||
cleanupServers.push(server);
|
||||
await new Promise<void>((resolve, reject) => {
|
||||
server.once('error', reject);
|
||||
server.listen(paths.socketPath, resolve);
|
||||
});
|
||||
|
||||
expect(await isBrokerSupervisorHealthy(paths)).toBe(true);
|
||||
const health = await checkBrokerSupervisorHealth(paths);
|
||||
expect(health.socketPresent).toBe(true);
|
||||
expect(health.healthy).toBe(true);
|
||||
|
||||
await new Promise<void>((resolve) => server.close(() => resolve()));
|
||||
await rm(paths.socketPath, { force: true });
|
||||
|
||||
expect(await isBrokerSupervisorHealthy(paths)).toBe(false);
|
||||
});
|
||||
|
||||
it('does not confuse a stale regular file at the socket path with a live socket', async () => {
|
||||
const paths = await fakeHealthPaths();
|
||||
await writeFile(paths.socketPath, 'not actually a socket');
|
||||
|
||||
expect(await isBrokerSupervisorHealthy(paths)).toBe(false);
|
||||
});
|
||||
});
|
||||
223
packages/mosaic/src/lease-broker/broker-supervisor.ts
Normal file
223
packages/mosaic/src/lease-broker/broker-supervisor.ts
Normal file
@@ -0,0 +1,223 @@
|
||||
/**
|
||||
* Activation-side supervisor for the Mosaic lease broker (issue #869, Point-1
|
||||
* C3). #828 shipped fail-closed enforcement hooks (`mutator-gate.py`,
|
||||
* `receipt-observer-client.py`) with nothing that guaranteed `daemon.py` was
|
||||
* running or that its socket existed before a gated runtime started. This
|
||||
* module:
|
||||
*
|
||||
* - resolves the broker socket/state paths and the on-disk locations of the
|
||||
* supervisor artifacts, deterministically and consistently with
|
||||
* `defaultLeaseBrokerSocket` in `../commands/launch.ts`;
|
||||
* - idempotently applies (materializes) a systemd `--user` unit plus the
|
||||
* wrapper script and daemon sources it execs, mirroring the tmux fleet
|
||||
* unit convention in `framework/systemd/user/`;
|
||||
* - exposes a health predicate other cards (e.g. the C1 activation probe)
|
||||
* can call to learn whether a broker supervisor is present and healthy.
|
||||
*
|
||||
* `applyBrokerSupervisor` only writes files under the paths it is given. It
|
||||
* never runs `systemctl`, never starts `daemon.py`, and never touches a real
|
||||
* host's `~/.config` unless the caller explicitly resolves paths there.
|
||||
* Enabling/starting the unit is a separate, later, out-of-scope step.
|
||||
*/
|
||||
import { chmod, copyFile, mkdir, stat } from 'node:fs/promises';
|
||||
import { homedir } from 'node:os';
|
||||
import { dirname, join } from 'node:path';
|
||||
|
||||
const UNIT_NAME = 'mosaic-lease-broker.service';
|
||||
const WRAPPER_SCRIPT_NAME = 'start-lease-broker.sh';
|
||||
|
||||
/** Co-located modules `daemon.py` imports at runtime; kept alongside it. */
|
||||
const DAEMON_SOURCE_FILE_NAMES = [
|
||||
'daemon.py',
|
||||
'lease_generation.py',
|
||||
'normative_fragments.py',
|
||||
'receipt_challenge.py',
|
||||
'receipt_observer.py',
|
||||
] as const;
|
||||
|
||||
export interface ResolveBrokerSupervisorPathsOptions {
|
||||
/** `~/.config/mosaic` (or an override) — where installed tool copies live. */
|
||||
mosaicHome: string;
|
||||
/** Root of the checked-out `framework/` directory (canonical file source). */
|
||||
frameworkRoot: string;
|
||||
/** Defaults to `process.env`; pass a fake for tests. */
|
||||
env?: NodeJS.ProcessEnv;
|
||||
/** Defaults to `os.homedir()`; pass a temp dir in tests. */
|
||||
homeDir?: string;
|
||||
/** Defaults to `process.getuid()` (or 0); pass a fake for tests. */
|
||||
uid?: number;
|
||||
}
|
||||
|
||||
export interface BrokerSupervisorPaths {
|
||||
readonly mosaicHome: string;
|
||||
readonly frameworkRoot: string;
|
||||
readonly systemdUserDir: string;
|
||||
readonly leaseBrokerToolsDir: string;
|
||||
readonly unitSourcePath: string;
|
||||
readonly unitTargetPath: string;
|
||||
readonly wrapperSourcePath: string;
|
||||
readonly wrapperTargetPath: string;
|
||||
readonly daemonSourcePaths: readonly string[];
|
||||
readonly daemonTargetPaths: readonly string[];
|
||||
/**
|
||||
* Resolved with the same precedence as `defaultLeaseBrokerSocket` in
|
||||
* `../commands/launch.ts`: an explicit `MOSAIC_LEASE_BROKER_SOCKET`, else
|
||||
* `$XDG_RUNTIME_DIR/mosaic-lease/broker.sock`, else
|
||||
* `/run/user/<uid>/mosaic-lease/broker.sock`.
|
||||
*/
|
||||
readonly socketPath: string;
|
||||
/** Colocated next to the socket, matching the broker's own generation-file convention. */
|
||||
readonly statePath: string;
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve the lease broker socket path alone, with the same precedence as
|
||||
* `defaultLeaseBrokerSocket` in `../commands/launch.ts`. Exported so callers
|
||||
* (and tests) can assert the two stay in agreement without importing the CLI
|
||||
* command module.
|
||||
*/
|
||||
export function resolveLeaseBrokerSocketPath(
|
||||
env: NodeJS.ProcessEnv = process.env,
|
||||
uid: number = typeof process.getuid === 'function' ? process.getuid() : 0,
|
||||
): string {
|
||||
const explicit = env['MOSAIC_LEASE_BROKER_SOCKET'];
|
||||
if (explicit) return explicit;
|
||||
const runtimeDir = env['XDG_RUNTIME_DIR'];
|
||||
if (runtimeDir) return join(runtimeDir, 'mosaic-lease', 'broker.sock');
|
||||
return join('/run/user', String(uid), 'mosaic-lease', 'broker.sock');
|
||||
}
|
||||
|
||||
/** Resolve every path the supervisor apply/health functions need, deterministically. */
|
||||
export function resolveBrokerSupervisorPaths(
|
||||
options: ResolveBrokerSupervisorPathsOptions,
|
||||
): BrokerSupervisorPaths {
|
||||
const { mosaicHome, frameworkRoot } = options;
|
||||
const env = options.env ?? process.env;
|
||||
const homeDir = options.homeDir ?? homedir();
|
||||
const systemdUserDir = join(homeDir, '.config', 'systemd', 'user');
|
||||
const leaseBrokerToolsDir = join(mosaicHome, 'tools', 'lease-broker');
|
||||
const frameworkLeaseBrokerDir = join(frameworkRoot, 'tools', 'lease-broker');
|
||||
const socketPath = resolveLeaseBrokerSocketPath(env, options.uid);
|
||||
const statePath = join(dirname(socketPath), 'state.json');
|
||||
|
||||
return {
|
||||
mosaicHome,
|
||||
frameworkRoot,
|
||||
systemdUserDir,
|
||||
leaseBrokerToolsDir,
|
||||
unitSourcePath: join(frameworkRoot, 'systemd', 'user', UNIT_NAME),
|
||||
unitTargetPath: join(systemdUserDir, UNIT_NAME),
|
||||
wrapperSourcePath: join(frameworkLeaseBrokerDir, WRAPPER_SCRIPT_NAME),
|
||||
wrapperTargetPath: join(leaseBrokerToolsDir, WRAPPER_SCRIPT_NAME),
|
||||
daemonSourcePaths: DAEMON_SOURCE_FILE_NAMES.map((name) => join(frameworkLeaseBrokerDir, name)),
|
||||
daemonTargetPaths: DAEMON_SOURCE_FILE_NAMES.map((name) => join(leaseBrokerToolsDir, name)),
|
||||
socketPath,
|
||||
statePath,
|
||||
};
|
||||
}
|
||||
|
||||
export interface ApplyBrokerSupervisorResult {
|
||||
readonly installedFiles: readonly string[];
|
||||
}
|
||||
|
||||
/**
|
||||
* Idempotently materialize the supervisor unit, its wrapper script, and the
|
||||
* daemon sources it execs. Safe to call on every reseed: every write is a
|
||||
* deterministic overwrite of the same target path from the same source, so a
|
||||
* second call reproduces identical bytes/modes and never errors.
|
||||
*
|
||||
* Never runs `systemctl`; the caller decides separately whether/when to
|
||||
* `daemon-reload`/`enable`/`start` the installed unit.
|
||||
*/
|
||||
export async function applyBrokerSupervisor(
|
||||
paths: BrokerSupervisorPaths,
|
||||
): Promise<ApplyBrokerSupervisorResult> {
|
||||
await mkdir(paths.leaseBrokerToolsDir, { recursive: true });
|
||||
await mkdir(paths.systemdUserDir, { recursive: true });
|
||||
|
||||
const installedFiles: string[] = [];
|
||||
|
||||
for (let index = 0; index < paths.daemonSourcePaths.length; index += 1) {
|
||||
const source = paths.daemonSourcePaths[index];
|
||||
const target = paths.daemonTargetPaths[index];
|
||||
if (source === undefined || target === undefined) continue;
|
||||
await copyFile(source, target);
|
||||
await chmod(target, 0o644);
|
||||
installedFiles.push(target);
|
||||
}
|
||||
|
||||
await copyFile(paths.wrapperSourcePath, paths.wrapperTargetPath);
|
||||
await chmod(paths.wrapperTargetPath, 0o755);
|
||||
installedFiles.push(paths.wrapperTargetPath);
|
||||
|
||||
await copyFile(paths.unitSourcePath, paths.unitTargetPath);
|
||||
await chmod(paths.unitTargetPath, 0o644);
|
||||
installedFiles.push(paths.unitTargetPath);
|
||||
|
||||
return { installedFiles };
|
||||
}
|
||||
|
||||
export interface BrokerSupervisorHealth {
|
||||
/** Whether the systemd unit file has been materialized at its target path. */
|
||||
readonly unitInstalled: boolean;
|
||||
/** Whether a Unix domain socket currently exists at the resolved socket path. */
|
||||
readonly socketPresent: boolean;
|
||||
/**
|
||||
* The signal other cards (e.g. C1's activation probe) should treat as
|
||||
* "a broker supervisor is present and healthy". Presence of a live socket
|
||||
* is the authoritative signal: a gated runtime can only ever succeed by
|
||||
* connecting to it, so this is what fail-closed callers must check.
|
||||
*/
|
||||
readonly healthy: boolean;
|
||||
}
|
||||
|
||||
/**
|
||||
* Report the supervisor's on-disk/health signals. Never throws for an
|
||||
* absent unit or socket — both simply report `false`; unexpected filesystem
|
||||
* errors (permission issues, etc.) still propagate.
|
||||
*/
|
||||
export async function checkBrokerSupervisorHealth(
|
||||
paths: Pick<BrokerSupervisorPaths, 'unitTargetPath' | 'socketPath'>,
|
||||
): Promise<BrokerSupervisorHealth> {
|
||||
const [unitInstalled, socketPresent] = await Promise.all([
|
||||
pathExists(paths.unitTargetPath),
|
||||
isUnixSocket(paths.socketPath),
|
||||
]);
|
||||
return { unitInstalled, socketPresent, healthy: socketPresent };
|
||||
}
|
||||
|
||||
/** Convenience boolean form of {@link checkBrokerSupervisorHealth} for simple call sites. */
|
||||
export async function isBrokerSupervisorHealthy(
|
||||
paths: Pick<BrokerSupervisorPaths, 'unitTargetPath' | 'socketPath'>,
|
||||
): Promise<boolean> {
|
||||
return (await checkBrokerSupervisorHealth(paths)).healthy;
|
||||
}
|
||||
|
||||
async function pathExists(path: string): Promise<boolean> {
|
||||
try {
|
||||
await stat(path);
|
||||
return true;
|
||||
} catch (error) {
|
||||
if (isEnoent(error)) return false;
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
async function isUnixSocket(path: string): Promise<boolean> {
|
||||
try {
|
||||
const info = await stat(path);
|
||||
return info.isSocket();
|
||||
} catch (error) {
|
||||
if (isEnoent(error)) return false;
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
function isEnoent(error: unknown): boolean {
|
||||
return (
|
||||
typeof error === 'object' &&
|
||||
error !== null &&
|
||||
'code' in error &&
|
||||
(error as NodeJS.ErrnoException).code === 'ENOENT'
|
||||
);
|
||||
}
|
||||
@@ -31,17 +31,26 @@ PI_EXTENSION = FRAMEWORK / "runtime/pi/mosaic-extension.ts"
|
||||
|
||||
|
||||
def request(socket_path: Path, value: dict[str, object]) -> dict[str, object]:
|
||||
with socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) as connection:
|
||||
connection.settimeout(3.0)
|
||||
connection.connect(str(socket_path))
|
||||
connection.sendall((json.dumps(value, separators=(",", ":")) + "\n").encode())
|
||||
connection.shutdown(socket.SHUT_WR)
|
||||
response = bytearray()
|
||||
while True:
|
||||
chunk = connection.recv(4096)
|
||||
if not chunk:
|
||||
break
|
||||
response.extend(chunk)
|
||||
deadline = time.monotonic() + 5.0
|
||||
while True:
|
||||
with socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) as connection:
|
||||
connection.settimeout(3.0)
|
||||
try:
|
||||
connection.connect(str(socket_path))
|
||||
except ConnectionRefusedError:
|
||||
if time.monotonic() >= deadline:
|
||||
raise
|
||||
time.sleep(0.02)
|
||||
continue
|
||||
connection.sendall((json.dumps(value, separators=(",", ":")) + "\n").encode())
|
||||
connection.shutdown(socket.SHUT_WR)
|
||||
response = bytearray()
|
||||
while True:
|
||||
chunk = connection.recv(4096)
|
||||
if not chunk:
|
||||
break
|
||||
response.extend(chunk)
|
||||
break
|
||||
if not response.endswith(b"\n") or response.count(b"\n") != 1:
|
||||
raise AssertionError(f"unframed broker response: {bytes(response)!r}")
|
||||
reply = json.loads(response[:-1])
|
||||
|
||||
@@ -661,13 +661,27 @@ describe('whole mutator-class lease gate', () => {
|
||||
test('observer revocation and monotonic TTL expiry deny the next mutator', async () => {
|
||||
const { socket } = await startBroker();
|
||||
const sessionId = await register(socket);
|
||||
const pending = await beginVerification(socket, sessionId, 'claude', 1, 1);
|
||||
await promote(socket, sessionId, pending.receipt_challenge!);
|
||||
|
||||
// Establish the lease with a normal (non-racing) TTL first and prove it
|
||||
// authorizes. This "still valid" check is setup, not a TTL-expiry
|
||||
// assertion, so it must not share a lease with a 1-second TTL: on a
|
||||
// contended push-CI host, scheduling delay alone between promote() and
|
||||
// this authorize() call can consume that entire 1-second margin and
|
||||
// spuriously deny it (CI#1945). Using a generous TTL here removes that
|
||||
// real-time race without touching lease-gate security semantics.
|
||||
const pending = await beginVerification(socket, sessionId, 'claude');
|
||||
await promote(socket, sessionId, pending.receipt_challenge!);
|
||||
expect(await authorize(socket, sessionId, 'claude', 'Bash')).toMatchObject({
|
||||
ok: true,
|
||||
decision: 'allow',
|
||||
});
|
||||
|
||||
// A dedicated, isolated short-TTL lease drives the deliberate monotonic
|
||||
// expiry demonstration below. It is never used for anything but the
|
||||
// wait-then-expire assertion, so there is no setup work racing its
|
||||
// 1-second window.
|
||||
const shortLived = await beginVerification(socket, sessionId, 'claude', 1, 1, 2);
|
||||
await promote(socket, sessionId, shortLived.receipt_challenge!);
|
||||
await new Promise((resolve) => setTimeout(resolve, 1_100));
|
||||
expect(await authorize(socket, sessionId, 'claude', 'Bash')).toMatchObject({
|
||||
ok: false,
|
||||
@@ -675,7 +689,7 @@ describe('whole mutator-class lease gate', () => {
|
||||
decision: 'deny',
|
||||
});
|
||||
|
||||
const refreshed = await beginVerification(socket, sessionId, 'claude', 1, 300, 2);
|
||||
const refreshed = await beginVerification(socket, sessionId, 'claude', 1, 300, 3);
|
||||
await promote(socket, sessionId, refreshed.receipt_challenge!);
|
||||
expect(
|
||||
await request(socket, {
|
||||
|
||||
@@ -217,12 +217,22 @@ git fetch origin
|
||||
mkdir -p ~/src/${projectName}-worktrees
|
||||
git worktree add ~/src/${projectName}-worktrees/<task-slug> -b <branch-name> origin/main
|
||||
cd ~/src/${projectName}-worktrees/<task-slug>
|
||||
pnpm install --frozen-lockfile --prefer-offline
|
||||
# ... all work happens here ...
|
||||
git push origin <branch-name>
|
||||
cd ~/src/${projectName} && git worktree remove ~/src/${projectName}-worktrees/<task-slug>
|
||||
\`\`\`
|
||||
|
||||
Worktrees path: \`~/src/<repo>-worktrees/<task-slug>\` — NEVER use /tmp.`);
|
||||
Worktrees path: \`~/src/<repo>-worktrees/<task-slug>\` — NEVER use /tmp.
|
||||
|
||||
\`pnpm install --frozen-lockfile --prefer-offline\` MUST run immediately after
|
||||
\`git worktree add\`/\`cd\`, BEFORE any gate (\`pnpm test\`/\`lint\`/\`typecheck\`/\`format:check\`)
|
||||
is invoked. pnpm workspaces do NOT share \`node_modules\` across separate git
|
||||
worktrees — a fresh worktree has an empty \`node_modules/.bin\`, so every gate
|
||||
binary (\`tsc\`/\`eslint\`/\`prettier\`/\`vitest\`) fails \`sh: 1: <tool>: not found\`
|
||||
until deps are installed. That failure is indistinguishable from a real
|
||||
test/lint failure — a false-red gate. Never skip this step and never reorder
|
||||
it after the first gate invocation.`);
|
||||
|
||||
// 6. Completion gates
|
||||
sections.push(`# Completion Gates — ENFORCED
|
||||
|
||||
50
skills/glpi-create/SKILL.md
Normal file
50
skills/glpi-create/SKILL.md
Normal file
@@ -0,0 +1,50 @@
|
||||
# Skill: glpi-create — Open a New GLPI Ticket
|
||||
|
||||
> Create a new GLPI helpdesk ticket. Mutates GLPI — confirm the details before running.
|
||||
|
||||
## When to use
|
||||
|
||||
- Logging a new incident or request that should live in the helpdesk queue.
|
||||
|
||||
## Required information
|
||||
|
||||
- **title** — short subject line.
|
||||
- **content** — description of the issue / request.
|
||||
|
||||
## Optional
|
||||
|
||||
- **priority** — `1`=VeryLow, `2`=Low, `3`=Medium (default), `4`=High, `5`=VeryHigh, `6`=Major.
|
||||
- **type** — `1`=Incident (default), `2`=Request.
|
||||
|
||||
## Command
|
||||
|
||||
Wraps the existing tooling:
|
||||
|
||||
```bash
|
||||
~/.config/mosaic/tools/glpi/ticket-create.sh \
|
||||
-t "<title>" \
|
||||
-c "<content>" \
|
||||
[-p <priority>] \
|
||||
[-y <type>] \
|
||||
[-f json]
|
||||
```
|
||||
|
||||
Example:
|
||||
|
||||
```bash
|
||||
~/.config/mosaic/tools/glpi/ticket-create.sh \
|
||||
-t "Paint-area camera install" \
|
||||
-c "Ordered 2 cameras for Paint and stock; schedule mounting + NVR config." \
|
||||
-p 3 -y 2
|
||||
```
|
||||
|
||||
## After creating
|
||||
|
||||
- Note the returned **ticket ID** — you'll need it for **[[glpi-followup]]** and
|
||||
**[[glpi-solve]]**.
|
||||
- If it should also be tracked as brain work, add a matching task (see the `add-task` skill).
|
||||
|
||||
## Guardrails
|
||||
|
||||
- Confirm title/content/priority with the user before creating — a ticket is outward-facing.
|
||||
- Never echo GLPI tokens.
|
||||
56
skills/glpi-followup/SKILL.md
Normal file
56
skills/glpi-followup/SKILL.md
Normal file
@@ -0,0 +1,56 @@
|
||||
# Skill: glpi-followup — Add a Followup to a GLPI Ticket
|
||||
|
||||
> Post a followup (comment / progress note / resolution writeup) to a GLPI ticket.
|
||||
> This documents work but does **not** change the ticket status — to close a ticket
|
||||
> out, follow with **[[glpi-solve]]** to set status to Solved.
|
||||
|
||||
## When to use
|
||||
|
||||
- Recording progress, a decision, or a root-cause/resolution note on a ticket.
|
||||
- The documentation step that usually precedes closing a ticket out (`glpi-solve`).
|
||||
|
||||
## Critical quirk
|
||||
|
||||
Use the **top-level `/ITILFollowup` endpoint**, NOT `/Ticket/<id>/ITILFollowup`. The
|
||||
sub-resource path returns permission errors even with a Super-Admin profile.
|
||||
|
||||
## Procedure
|
||||
|
||||
### 1. Session + creds
|
||||
|
||||
```bash
|
||||
SESSION=$(~/.config/mosaic/tools/glpi/session-init.sh -q)
|
||||
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials glpi
|
||||
```
|
||||
|
||||
### 2. Post the followup
|
||||
|
||||
```bash
|
||||
TICKET_ID=<id>
|
||||
CONTENT="<the followup text>"
|
||||
curl -sk -X POST "${GLPI_URL}/ITILFollowup" \
|
||||
-H "App-Token: $GLPI_APP_TOKEN" \
|
||||
-H "Session-Token: $SESSION" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "$(jq -n --argjson id "$TICKET_ID" --arg c "$CONTENT" \
|
||||
'{input:{itemtype:"Ticket", items_id:$id, content:$c}}')"
|
||||
```
|
||||
|
||||
Expect HTTP 201. Building the payload with `jq` keeps quotes/newlines in the content safe.
|
||||
|
||||
### 3. Long or multi-paragraph content
|
||||
|
||||
Write the note to a file first, then read it into the payload:
|
||||
|
||||
```bash
|
||||
curl -sk -X POST "${GLPI_URL}/ITILFollowup" \
|
||||
-H "App-Token: $GLPI_APP_TOKEN" -H "Session-Token: $SESSION" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "$(jq -n --argjson id "$TICKET_ID" --rawfile c /path/to/note.md \
|
||||
'{input:{itemtype:"Ticket", items_id:$id, content:$c}}')"
|
||||
```
|
||||
|
||||
## Guardrails
|
||||
|
||||
- Never echo the GLPI app/user/session tokens.
|
||||
- A followup alone leaves the ticket open. If the work is done, run **[[glpi-solve]]** next.
|
||||
57
skills/glpi-list/SKILL.md
Normal file
57
skills/glpi-list/SKILL.md
Normal file
@@ -0,0 +1,57 @@
|
||||
# Skill: glpi-list — Query GLPI Tickets
|
||||
|
||||
> Quick lookups of GLPI helpdesk tickets by status or recency. Read-only.
|
||||
|
||||
## When to use
|
||||
|
||||
- "What tickets are open / pending?" · "Show recent tickets" · finding a ticket ID
|
||||
before running **[[glpi-followup]]** or **[[glpi-solve]]**.
|
||||
|
||||
## Command
|
||||
|
||||
Wraps the existing tooling:
|
||||
|
||||
```bash
|
||||
GLPI=~/.config/mosaic/tools/glpi
|
||||
|
||||
# Most recent tickets (default 50, newest first)
|
||||
"$GLPI/ticket-list.sh"
|
||||
|
||||
# Filter by status: new | processing | pending | solved | closed
|
||||
"$GLPI/ticket-list.sh" -s pending
|
||||
|
||||
# JSON output (for parsing / piping to jq) and a custom limit
|
||||
"$GLPI/ticket-list.sh" -s processing -f json -l 20
|
||||
```
|
||||
|
||||
Status IDs: 1 New · 2/3 Processing · 4 Pending · 5 Solved · 6 Closed.
|
||||
|
||||
## Details lookup for one ticket
|
||||
|
||||
When you have an ID and want the full record:
|
||||
|
||||
```bash
|
||||
SESSION=$(~/.config/mosaic/tools/glpi/session-init.sh -q)
|
||||
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials glpi
|
||||
curl -sk "${GLPI_URL}/Ticket/<id>?expand_dropdowns=true" \
|
||||
-H "App-Token: $GLPI_APP_TOKEN" -H "Session-Token: $SESSION" \
|
||||
| jq '{id, name, status, date, date_mod}'
|
||||
|
||||
# Followups on a ticket
|
||||
curl -sk "${GLPI_URL}/Ticket/<id>/ITILFollowup" \
|
||||
-H "App-Token: $GLPI_APP_TOKEN" -H "Session-Token: $SESSION" \
|
||||
| jq '.[] | {date, content}'
|
||||
```
|
||||
|
||||
(Reading followups via the sub-resource is fine — only _creating_ them requires the
|
||||
top-level `/ITILFollowup` endpoint. See **[[glpi-followup]]**.)
|
||||
|
||||
## Present to user
|
||||
|
||||
Group by status, one line per ticket: `#<id> · <title> · <status> · <last-modified>`.
|
||||
Use neutral phrasing — no "OVERDUE"/"URGENT".
|
||||
|
||||
## Guardrails
|
||||
|
||||
- Read-only. Never echo GLPI tokens.
|
||||
- To sync tickets into brain data instead, use `python tools/sync_glpi.py` (not this skill).
|
||||
96
skills/glpi-solve/SKILL.md
Normal file
96
skills/glpi-solve/SKILL.md
Normal file
@@ -0,0 +1,96 @@
|
||||
# Skill: glpi-solve — Close Out a GLPI Ticket
|
||||
|
||||
> Properly close out a completed GLPI helpdesk ticket. Completing the work is not
|
||||
> enough — the ticket **status must be set to "Solved"**, which is what triggers
|
||||
> GLPI's config-driven auto-close. Posting a resolution followup documents the work
|
||||
> but does **not** change status, so a ticket left at Solved-less status stays open.
|
||||
|
||||
## When to use
|
||||
|
||||
- Any time work on a GLPI ticket is finished and it should be closed out.
|
||||
- After posting a root-cause / resolution writeup as an `/ITILFollowup`.
|
||||
- During a cleanup sweep of tickets that are done in reality but still open in GLPI.
|
||||
|
||||
## The rule (from an operator, 2026-07-20)
|
||||
|
||||
**"Solved" is the correct terminal state to set — not "Closed."** GLPI is configured
|
||||
to auto-close Solved tickets after its delay. If you only post a followup and never set
|
||||
status, the ticket sits open (this bit us on a real incident where resolution followups
|
||||
were posted but status was never advanced, leaving tickets open, which the operator had
|
||||
to mark Solved by hand).
|
||||
|
||||
Close-out = **followup (optional but preferred) + set status to Solved.**
|
||||
|
||||
## GLPI status IDs
|
||||
|
||||
| ID | Status | |
|
||||
| ----- | --------------------- | -------------------------------------------- |
|
||||
| 1 | New | |
|
||||
| 2 | Processing (assigned) | |
|
||||
| 3 | Processing (planned) | |
|
||||
| 4 | Pending / Waiting | |
|
||||
| **5** | **Solved** | ← set this on close-out |
|
||||
| 6 | Closed | ← happens automatically; do not set manually |
|
||||
|
||||
## Procedure
|
||||
|
||||
### 1. Get a session token
|
||||
|
||||
```bash
|
||||
SESSION=$(~/.config/mosaic/tools/glpi/session-init.sh -q)
|
||||
source ~/.config/mosaic/tools/_lib/credentials.sh && load_credentials glpi
|
||||
```
|
||||
|
||||
### 2. (Preferred) Post the resolution followup
|
||||
|
||||
Use the **top-level `/ITILFollowup` endpoint** — the `/Ticket/<id>/ITILFollowup`
|
||||
sub-resource returns permission errors even as Super-Admin (known GLPI quirk).
|
||||
|
||||
```bash
|
||||
TICKET_ID=<id>
|
||||
curl -sk -X POST "${GLPI_URL}/ITILFollowup" \
|
||||
-H "App-Token: $GLPI_APP_TOKEN" \
|
||||
-H "Session-Token: $SESSION" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "{\"input\":{\"itemtype\":\"Ticket\",\"items_id\":${TICKET_ID},\"content\":\"<resolution summary>\"}}"
|
||||
```
|
||||
|
||||
### 3. Set status to Solved (the step that actually closes it out)
|
||||
|
||||
```bash
|
||||
curl -sk -X PUT "${GLPI_URL}/Ticket/${TICKET_ID}" \
|
||||
-H "App-Token: $GLPI_APP_TOKEN" \
|
||||
-H "Session-Token: $SESSION" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "{\"input\":{\"id\":${TICKET_ID},\"status\":5}}"
|
||||
```
|
||||
|
||||
Expect HTTP 200/201. GLPI will auto-close it later per its config — leave status at 5.
|
||||
|
||||
### 4. Verify
|
||||
|
||||
```bash
|
||||
curl -sk "${GLPI_URL}/Ticket/${TICKET_ID}?expand_dropdowns=true" \
|
||||
-H "App-Token: $GLPI_APP_TOKEN" -H "Session-Token: $SESSION" \
|
||||
| jq '{id, name, status}'
|
||||
```
|
||||
|
||||
`status` should read `Solved` (or `5`).
|
||||
|
||||
## Optional: sweep for done-but-open tickets
|
||||
|
||||
List tickets still open (New/Processing/Pending) to spot ones whose work is actually
|
||||
finished but were never marked Solved:
|
||||
|
||||
```bash
|
||||
~/.config/mosaic/tools/glpi/ticket-list.sh -s processing -f table
|
||||
~/.config/mosaic/tools/glpi/ticket-list.sh -s pending -f table
|
||||
```
|
||||
|
||||
Review each; for any that are genuinely resolved, run steps 2–3.
|
||||
|
||||
## Guardrails
|
||||
|
||||
- Read-only until you intend to close — confirm the ticket is actually done first.
|
||||
- Never echo the GLPI app/user/session tokens.
|
||||
- Set **Solved (5)**, never Closed (6) — auto-close owns that transition.
|
||||
62
skills/glpi-sweep/SKILL.md
Normal file
62
skills/glpi-sweep/SKILL.md
Normal file
@@ -0,0 +1,62 @@
|
||||
# Skill: glpi-sweep — Find Done-But-Open Tickets
|
||||
|
||||
> Read-only sweep for tickets that are finished in reality but still sitting open in
|
||||
> GLPI (never moved to Solved). Surfaces the exact miss an operator caught on 2026-07-20
|
||||
> (a real incident where an affected ticket had resolution followups posted but was left
|
||||
> open). For each one that's genuinely done, close it out with **[[glpi-solve]]**.
|
||||
|
||||
## When to use
|
||||
|
||||
- Periodic hygiene pass (e.g. before a weekly update or month-end).
|
||||
- After a burst of ticket work, to catch any you resolved-in-followup but never Solved.
|
||||
|
||||
## Why this exists
|
||||
|
||||
Posting an `/ITILFollowup` documents work but does **not** change status. Tickets only
|
||||
auto-close once set to **Solved (status 5)**. Anything left at New/Processing/Pending
|
||||
stays open indefinitely. This sweep finds those.
|
||||
|
||||
## Procedure
|
||||
|
||||
### 1. List still-open tickets by status
|
||||
|
||||
```bash
|
||||
GLPI=~/.config/mosaic/tools/glpi
|
||||
"$GLPI/ticket-list.sh" -s new -f table
|
||||
"$GLPI/ticket-list.sh" -s processing -f table
|
||||
"$GLPI/ticket-list.sh" -s pending -f table
|
||||
```
|
||||
|
||||
(GLPI status IDs: 1 New · 2/3 Processing · 4 Pending · 5 Solved · 6 Closed.)
|
||||
|
||||
### 2. Triage
|
||||
|
||||
For each open ticket, judge whether the underlying work is actually finished — check
|
||||
its latest followups and cross-reference brain tasks / recent work. Read-only here;
|
||||
change nothing yet.
|
||||
|
||||
Reasonable "probably done" signals:
|
||||
|
||||
- A resolution/root-cause followup already posted, but status never advanced.
|
||||
- The related brain task is `done`, or the fix shipped and was confirmed.
|
||||
- Requester confirmed resolution but the ticket was never Solved.
|
||||
|
||||
### 3. Present the candidates
|
||||
|
||||
List them for review before touching anything — never bulk-solve blindly:
|
||||
|
||||
```
|
||||
Open tickets that look resolved:
|
||||
- #<id> "<title>" — <why it looks done> → glpi-solve?
|
||||
```
|
||||
|
||||
### 4. Close out the confirmed ones
|
||||
|
||||
For each ticket the user (or clear evidence) confirms is done, run **[[glpi-solve]]**
|
||||
(optionally **[[glpi-followup]]** first if a closing note is warranted).
|
||||
|
||||
## Guardrails
|
||||
|
||||
- Read-only until a ticket is confirmed done — do not auto-solve on a guess.
|
||||
- Never echo GLPI tokens.
|
||||
- Set **Solved (5)**, never Closed (6) — GLPI auto-close owns that transition.
|
||||
Reference in New Issue
Block a user