Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
81f500bd29 | ||
|
|
d8e0aec950 | ||
|
|
49d6136b02 | ||
|
|
a80bae950d |
+24
-1
@@ -30,6 +30,19 @@ steps:
|
|||||||
# the baked pnpm store.
|
# the baked pnpm store.
|
||||||
- pnpm install --frozen-lockfile --prefer-offline
|
- pnpm install --frozen-lockfile --prefer-offline
|
||||||
|
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
# The steps below (sanitization, upgrade-guard, typecheck, lint, format,
|
||||||
|
# test) are the COMPLETE mandatory verification set. SDLC-D-034 mirrors them
|
||||||
|
# one-for-one in the canonical terminal verification command — root
|
||||||
|
# `pnpm verify:release` (scripts/verify-release.mjs) — which the publish
|
||||||
|
# pipeline (.woodpecker/publish.yml `verify` step) runs before ANY publish
|
||||||
|
# effect. These lines stay direct (not routed through the runner) because the
|
||||||
|
# #1017 test-enumeration guard audits framework tool paths through THIS
|
||||||
|
# surface; scripts/verify-release.test.mjs enforces that the runner's stage
|
||||||
|
# table keeps matching these commands exactly, so the two cannot drift.
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
# Canonical verify:release stage `sanitization`.
|
||||||
# Blocking gate: public framework package must contain no operator-specific
|
# Blocking gate: public framework package must contain no operator-specific
|
||||||
# personal data or private $HOME defaults. Runs early (no node_modules needed).
|
# personal data or private $HOME defaults. Runs early (no node_modules needed).
|
||||||
sanitization:
|
sanitization:
|
||||||
@@ -47,6 +60,7 @@ steps:
|
|||||||
# with everything it guards; this direct line keeps one instrument running.
|
# with everything it guards; this direct line keeps one instrument running.
|
||||||
- bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh
|
- bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh
|
||||||
|
|
||||||
|
# Canonical verify:release stage `upgrade-guard`.
|
||||||
# Blocking gate (#791): a framework upgrade must never write or delete an
|
# Blocking gate (#791): a framework upgrade must never write or delete an
|
||||||
# operator-owned path. The HARD GATE proves an unanticipated operator sentinel
|
# operator-owned path. The HARD GATE proves an unanticipated operator sentinel
|
||||||
# survives a keep-mode reseed byte-identical (with rsync present AND absent —
|
# survives a keep-mode reseed byte-identical (with rsync present AND absent —
|
||||||
@@ -68,6 +82,8 @@ steps:
|
|||||||
- bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh
|
- bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh
|
||||||
- bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh
|
- bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh
|
||||||
|
|
||||||
|
# Canonical verify:release stage `typecheck` — the same `pnpm typecheck`
|
||||||
|
# invocation (which runs the checkout preflight first, then turbo).
|
||||||
typecheck:
|
typecheck:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
commands:
|
commands:
|
||||||
@@ -78,7 +94,8 @@ steps:
|
|||||||
- sanitization
|
- sanitization
|
||||||
- upgrade-guard
|
- upgrade-guard
|
||||||
|
|
||||||
# lint, format, and test are independent — run in parallel after typecheck
|
# lint, format, and test are independent — run in parallel after typecheck.
|
||||||
|
# Each runs exactly its canonical verify:release stage command.
|
||||||
lint:
|
lint:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
commands:
|
commands:
|
||||||
@@ -95,6 +112,12 @@ steps:
|
|||||||
depends_on:
|
depends_on:
|
||||||
- typecheck
|
- typecheck
|
||||||
|
|
||||||
|
# Canonical verify:release stage `test` — the `pnpm test` line below is the
|
||||||
|
# shared command; everything else in this step is PIPELINE-LEVEL
|
||||||
|
# prerequisite the canonical command expects its caller to provide (SDLC-D-034):
|
||||||
|
# the ci-postgres service + pg_isready wait + db:migrate (postgres path),
|
||||||
|
# `apk add openssl`, and the pinned pi install. None of those can move into
|
||||||
|
# the runner (it must also work locally on the PGlite path with no database).
|
||||||
test:
|
test:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
@@ -1,5 +1,19 @@
|
|||||||
# Build, publish npm packages, and push Docker images
|
# Build, publish npm packages, and push Docker images
|
||||||
# Runs on main for stable publishes and on next for integration-line prereleases/images
|
# Runs on main for stable publishes and on next for integration-line prereleases/images
|
||||||
|
#
|
||||||
|
# SDLC-D-034 publish gate: every publish effect (publish-npm, publish-next-npm,
|
||||||
|
# and every image build/push step) depends DIRECTLY on the `verify` step below.
|
||||||
|
# `verify` (a) asserts the provider's commit identity matches the actual
|
||||||
|
# checkout (CI_COMMIT_SHA == git rev-parse HEAD, fail closed on mismatch or
|
||||||
|
# emptiness) and (b) runs the canonical terminal verification command
|
||||||
|
# (`pnpm verify:release`), which mirrors the PR CI pipeline's complete
|
||||||
|
# mandatory set (sanitization, upgrade-guard, preflight+typecheck, lint,
|
||||||
|
# format:check, test, build) — see scripts/verify-release.mjs. A missing,
|
||||||
|
# failed, skipped, cancelled, or inconclusive verification therefore skips the
|
||||||
|
# dependent publish effects (fail closed). Path-filtered short-circuits may
|
||||||
|
# skip publish EFFECTS (e.g. docs-only merges) but never bypass `verify` for a
|
||||||
|
# publish that does run: `verify` itself carries no path filter.
|
||||||
|
# scripts/verify-release.test.mjs enforces this DAG invariant at checkout time.
|
||||||
|
|
||||||
variables:
|
variables:
|
||||||
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
|
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
|
||||||
@@ -48,6 +62,45 @@ steps:
|
|||||||
# Resolve from the baked pnpm store instead of a cold network fetch.
|
# Resolve from the baked pnpm store instead of a cold network fetch.
|
||||||
- pnpm install --frozen-lockfile --prefer-offline
|
- pnpm install --frozen-lockfile --prefer-offline
|
||||||
|
|
||||||
|
# SDLC-D-034 exact-commit publish gate. No `when`/path filter on purpose: it
|
||||||
|
# runs for every event this pipeline serves so no publish effect can ever
|
||||||
|
# start without it. Fails closed on commit-identity mismatch (or either SHA
|
||||||
|
# being empty) and on any incomplete verification.
|
||||||
|
verify:
|
||||||
|
image: *node_image
|
||||||
|
commands:
|
||||||
|
- *enable_pnpm
|
||||||
|
# (a) Commit identity: the provider's claimed SHA must equal the actual
|
||||||
|
# checkout HEAD — verification of anything else must never authorize a
|
||||||
|
# publish of this commit.
|
||||||
|
- |
|
||||||
|
if [ -z "$CI_COMMIT_SHA" ]; then
|
||||||
|
echo "[verify] FATAL: CI_COMMIT_SHA is empty — cannot certify commit identity" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
CHECKOUT_SHA="$(git rev-parse HEAD 2>/dev/null || true)"
|
||||||
|
if [ -z "$CHECKOUT_SHA" ]; then
|
||||||
|
echo "[verify] FATAL: git rev-parse HEAD returned nothing — cannot certify commit identity" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if [ "$CI_COMMIT_SHA" != "$CHECKOUT_SHA" ]; then
|
||||||
|
echo "[verify] FATAL: provider commit ($CI_COMMIT_SHA) != checkout HEAD ($CHECKOUT_SHA)" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "[verify] commit identity confirmed: $CHECKOUT_SHA"
|
||||||
|
# (b) Canonical terminal verification. Caller-provided prerequisites the
|
||||||
|
# runner expects (see .woodpecker/ci.yml comments): bash/rsync for the
|
||||||
|
# guard stages, openssl + the pinned pi binary for the test stage. git is
|
||||||
|
# baked into ci-base but re-asserted here so the identity check above can
|
||||||
|
# never silently depend on a stale baked image. DATABASE_URL is
|
||||||
|
# deliberately NOT set: the canonical command must hold on the PGlite
|
||||||
|
# path too and never sets or requires a database itself.
|
||||||
|
- apk add --no-cache bash rsync openssl git
|
||||||
|
- npm install -g @earendil-works/[email protected]
|
||||||
|
- pnpm verify:release
|
||||||
|
depends_on:
|
||||||
|
- install
|
||||||
|
|
||||||
build:
|
build:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
commands:
|
commands:
|
||||||
@@ -55,6 +108,7 @@ steps:
|
|||||||
- pnpm build
|
- pnpm build
|
||||||
depends_on:
|
depends_on:
|
||||||
- install
|
- install
|
||||||
|
- verify
|
||||||
|
|
||||||
publish-npm:
|
publish-npm:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
@@ -114,6 +168,7 @@ steps:
|
|||||||
exit 1
|
exit 1
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
|
- verify
|
||||||
|
|
||||||
publish-next-npm:
|
publish-next-npm:
|
||||||
image: *node_image
|
image: *node_image
|
||||||
@@ -192,6 +247,7 @@ steps:
|
|||||||
echo "[publish-next] @mosaicstack/mosaic@next resolves to $RESOLVED_VERSION"
|
echo "[publish-next] @mosaicstack/mosaic@next resolves to $RESOLVED_VERSION"
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
|
- verify
|
||||||
|
|
||||||
# TODO: Uncomment when ready to publish to npmjs.org
|
# TODO: Uncomment when ready to publish to npmjs.org
|
||||||
# publish-npmjs:
|
# publish-npmjs:
|
||||||
@@ -205,6 +261,7 @@ steps:
|
|||||||
# - bash scripts/publish-npmjs.sh
|
# - bash scripts/publish-npmjs.sh
|
||||||
# depends_on:
|
# depends_on:
|
||||||
# - build
|
# - build
|
||||||
|
# - verify
|
||||||
# when:
|
# when:
|
||||||
# - event: [tag]
|
# - event: [tag]
|
||||||
|
|
||||||
@@ -242,6 +299,7 @@ steps:
|
|||||||
/kaniko/executor --context . --dockerfile docker/gateway.Dockerfile $DESTINATIONS
|
/kaniko/executor --context . --dockerfile docker/gateway.Dockerfile $DESTINATIONS
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
|
- verify
|
||||||
|
|
||||||
build-appservice:
|
build-appservice:
|
||||||
image: gcr.io/kaniko-project/executor:debug
|
image: gcr.io/kaniko-project/executor:debug
|
||||||
@@ -268,6 +326,7 @@ steps:
|
|||||||
/kaniko/executor --context . --dockerfile docker/appservice.Dockerfile $DESTINATIONS
|
/kaniko/executor --context . --dockerfile docker/appservice.Dockerfile $DESTINATIONS
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
|
- verify
|
||||||
|
|
||||||
build-web:
|
build-web:
|
||||||
image: gcr.io/kaniko-project/executor:debug
|
image: gcr.io/kaniko-project/executor:debug
|
||||||
@@ -294,3 +353,4 @@ steps:
|
|||||||
/kaniko/executor --context . --dockerfile docker/web.Dockerfile $DESTINATIONS
|
/kaniko/executor --context . --dockerfile docker/web.Dockerfile $DESTINATIONS
|
||||||
depends_on:
|
depends_on:
|
||||||
- build
|
- build
|
||||||
|
- verify
|
||||||
|
|||||||
@@ -190,7 +190,13 @@ beforeEach((ctx) => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
afterAll(async () => {
|
afterAll(async () => {
|
||||||
if (!handle) return;
|
// Cleanup only when the fixture actually installed rows. `handle` is set
|
||||||
|
// before the first query (createDb connects lazily), so on an unreachable
|
||||||
|
// database `handle` is truthy while nothing was inserted — cleanup must
|
||||||
|
// honor `dbAvailable` or the skip path fails the file with ECONNREFUSED in
|
||||||
|
// afterAll (caught live by the publish pipeline's no-DATABASE_URL verify
|
||||||
|
// step, pipeline 2486).
|
||||||
|
if (!handle || !dbAvailable) return;
|
||||||
const db = handle.db;
|
const db = handle.db;
|
||||||
|
|
||||||
// Delete in dependency order (FK constraints)
|
// Delete in dependency order (FK constraints)
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
"preflight": "node scripts/preflight.mjs",
|
"preflight": "node scripts/preflight.mjs",
|
||||||
"clean:generated": "node scripts/clean-generated.mjs",
|
"clean:generated": "node scripts/clean-generated.mjs",
|
||||||
"typecheck": "pnpm preflight && turbo run typecheck",
|
"typecheck": "pnpm preflight && turbo run typecheck",
|
||||||
|
"verify:release": "node scripts/verify-release.mjs",
|
||||||
"test:checkout": "node --test scripts/*.test.mjs",
|
"test:checkout": "node --test scripts/*.test.mjs",
|
||||||
"test": "pnpm test:checkout && turbo run test && pnpm run test:installer",
|
"test": "pnpm test:checkout && turbo run test && pnpm run test:installer",
|
||||||
"test:installer": "bash tools/install-next-lane.test.sh",
|
"test:installer": "bash tools/install-next-lane.test.sh",
|
||||||
|
|||||||
@@ -12,6 +12,33 @@ The default tmux socket is `mosaic-fleet` so fleet commands do not touch the
|
|||||||
default tmux server. The roster is the desired-state authority; generated environment files are
|
default tmux server. The roster is the desired-state authority; generated environment files are
|
||||||
rebuildable projections, never a second source of configuration.
|
rebuildable projections, never a second source of configuration.
|
||||||
|
|
||||||
|
## Brain-home split (fleet state vs framework templates)
|
||||||
|
|
||||||
|
When a mosaic-brain clone is present, fleet **state** resolves from the brain
|
||||||
|
home while framework templates and dispatch state stay in the config home
|
||||||
|
(three-tree model, canon `docs/STRUCTURE-CANON.md` §2):
|
||||||
|
|
||||||
|
| Path | Without brain (legacy) | With brain |
|
||||||
|
| ------------------------------------------------------------------------------- | ------------------------------------- | ------------------------------ |
|
||||||
|
| `fleet/agents/<seat>.env.*` | `~/.config/mosaic/fleet/agents/` | `~/.mosaic/fleet/agents/` |
|
||||||
|
| `fleet/roles.local/` (overrides) | `~/.config/mosaic/fleet/roles.local/` | `~/.mosaic/fleet/roles.local/` |
|
||||||
|
| `fleet/profiles/` (working copies) | `~/.config/mosaic/fleet/profiles/` | `~/.mosaic/fleet/profiles/` |
|
||||||
|
| `fleet/roster.yaml`, `fleet/roles/` (baseline), `fleet/run/`, `fleet/services/` | `~/.config/mosaic/fleet/…` | unchanged (config home) |
|
||||||
|
|
||||||
|
Activation (`packages/mosaic/src/fleet/brain-home.ts`, mirrored in
|
||||||
|
`tools/fleet/start-agent-session.sh`):
|
||||||
|
|
||||||
|
1. `MOSAIC_BRAIN_HOME` env var — explicit, always wins.
|
||||||
|
2. Canonical `~/.mosaic` — adopted only when `MOSAIC_HOME` is the default
|
||||||
|
`~/.config/mosaic` AND `~/.mosaic/fleet/agents` exists. Custom
|
||||||
|
`--mosaic-home` values (tests, sandboxes, canaries) never adopt, keeping
|
||||||
|
them hermetic.
|
||||||
|
3. Otherwise the config home (legacy single-tree behavior).
|
||||||
|
|
||||||
|
Seat env dirs under a brain are subject to the same privacy boundary (0700
|
||||||
|
dirs, 0600 files); `.env.generated` files are structure-valuable and tracked
|
||||||
|
in the brain repo, hand-maintained `.env`/`.env.local` stay ignored and private.
|
||||||
|
|
||||||
## Examples
|
## Examples
|
||||||
|
|
||||||
- `examples/minimal.yaml` starts one local canary slot.
|
- `examples/minimal.yaml` starts one local canary slot.
|
||||||
|
|||||||
@@ -80,6 +80,26 @@ safe_path "$MOSAIC_HOME" || fail_env unsafe-path MOSAIC_HOME "$MOSAIC_HOME"
|
|||||||
|
|
||||||
FLEET_DIR="$MOSAIC_HOME/fleet"
|
FLEET_DIR="$MOSAIC_HOME/fleet"
|
||||||
AGENT_ENV_DIR="$FLEET_DIR/agents"
|
AGENT_ENV_DIR="$FLEET_DIR/agents"
|
||||||
|
|
||||||
|
# Brain-home split (canon docs/STRUCTURE-CANON.md §2): seat launch envs live
|
||||||
|
# under the brain home's fleet/agents when a brain is active; roster, roles
|
||||||
|
# baseline, and runtime state (fleet/run) stay under MOSAIC_HOME.
|
||||||
|
# Resolution mirrors packages/mosaic/src/fleet/brain-home.ts:
|
||||||
|
# 1. MOSAIC_BRAIN_HOME env (explicit, always wins)
|
||||||
|
# 2. ~/.mosaic — adopted only when MOSAIC_HOME is the default config home AND
|
||||||
|
# ~/.mosaic/fleet/agents exists
|
||||||
|
# 3. MOSAIC_HOME (legacy single-tree)
|
||||||
|
BRAIN_HOME="${MOSAIC_BRAIN_HOME:-}"
|
||||||
|
if [ -z "$BRAIN_HOME" ]; then
|
||||||
|
BRAIN_HOME="$MOSAIC_HOME"
|
||||||
|
if [ "$(cd "$MOSAIC_HOME" 2>/dev/null && pwd -P)" = "$HOME/.config/mosaic" ] \
|
||||||
|
&& [ -d "$HOME/.mosaic/fleet/agents" ]; then
|
||||||
|
BRAIN_HOME="$HOME/.mosaic"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
if [ "$BRAIN_HOME" != "$MOSAIC_HOME" ]; then
|
||||||
|
AGENT_ENV_DIR="$BRAIN_HOME/fleet/agents"
|
||||||
|
fi
|
||||||
assert_managed_directory "$MOSAIC_HOME"
|
assert_managed_directory "$MOSAIC_HOME"
|
||||||
assert_managed_directory "$FLEET_DIR"
|
assert_managed_directory "$FLEET_DIR"
|
||||||
assert_private_directory "$AGENT_ENV_DIR"
|
assert_private_directory "$AGENT_ENV_DIR"
|
||||||
|
|||||||
@@ -167,6 +167,54 @@ if echo "$valid_args" | grep -qF 'bash -c'; then
|
|||||||
fail "launcher constructed a shell command payload"
|
fail "launcher constructed a shell command payload"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# ── Brain-home split (canon §2) ─────────────────────────────────────────
|
||||||
|
# When MOSAIC_HOME is the default config home under $HOME and the host carries
|
||||||
|
# $HOME/.mosaic/fleet/agents, seat envs resolve from the brain tree; the config
|
||||||
|
# home still owns fleet/run (holder-owner) and remains a managed boundary.
|
||||||
|
: > "$TMUX_CALLS"
|
||||||
|
HOME_BRAIN="$ROOT/brain-home"
|
||||||
|
CONFIG_HOME="$HOME_BRAIN/.config/mosaic"
|
||||||
|
BRAIN="$HOME_BRAIN/.mosaic"
|
||||||
|
mkdir -p "$CONFIG_HOME/fleet/run" "$BRAIN/fleet/agents" "$HOME_BRAIN/work"
|
||||||
|
chmod 700 "$CONFIG_HOME" "$CONFIG_HOME/fleet" "$CONFIG_HOME/fleet/run" \
|
||||||
|
"$BRAIN/fleet/agents" "$HOME_BRAIN/work"
|
||||||
|
printf '123e4567-e89b-12d3-a456-426614174000\n' > "$CONFIG_HOME/fleet/run/holder-owner"
|
||||||
|
chmod 600 "$CONFIG_HOME/fleet/run/holder-owner"
|
||||||
|
cat > "$BRAIN/fleet/agents/coder-brain.env.generated" <<EOF
|
||||||
|
MOSAIC_AGENT_NAME=coder-brain
|
||||||
|
MOSAIC_AGENT_CLASS=code
|
||||||
|
MOSAIC_AGENT_RUNTIME=pi
|
||||||
|
MOSAIC_AGENT_MODEL=openai-codex/gpt-5.6-sol
|
||||||
|
MOSAIC_AGENT_REASONING=high
|
||||||
|
MOSAIC_AGENT_TOOL_POLICY=code
|
||||||
|
MOSAIC_AGENT_WORKDIR=$HOME_BRAIN/work
|
||||||
|
MOSAIC_TMUX_SOCKET=mosaic-test
|
||||||
|
EOF
|
||||||
|
chmod 600 "$BRAIN/fleet/agents/coder-brain.env.generated"
|
||||||
|
install_pane_binaries "$HOME_BRAIN"
|
||||||
|
HOME="$HOME_BRAIN" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
||||||
|
MOSAIC_TEST_PANE_PID=$$ MOSAIC_TEST_HOME="$HOME_BRAIN" \
|
||||||
|
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
||||||
|
MOSAIC_HOME="$CONFIG_HOME" "$START" coder-brain
|
||||||
|
brain_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
||||||
|
echo "$brain_args" | grep -qF new-session || fail "brain-home generated projection did not reach tmux"
|
||||||
|
echo "$brain_args" | grep -qF 'coder-brain' || fail "brain-home agent env was not the launch source"
|
||||||
|
[ -f "$BRAIN/fleet/agents/coder-brain.env.generated" ] || fail "brain generated env vanished"
|
||||||
|
|
||||||
|
# Negative control: the SAME default-config-home shape but without
|
||||||
|
# ~/.mosaic/fleet/agents — the config-home env tree is used directly (legacy).
|
||||||
|
: > "$TMUX_CALLS"
|
||||||
|
HOME_NOBRAIN="$ROOT/brainless-home"
|
||||||
|
CONFIG_HOME_NOBRAIN="$HOME_NOBRAIN/.config/mosaic"
|
||||||
|
write_generated "$CONFIG_HOME_NOBRAIN" "coder-legacy"
|
||||||
|
install_pane_binaries "$HOME_NOBRAIN"
|
||||||
|
HOME="$HOME_NOBRAIN" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
||||||
|
MOSAIC_TEST_PANE_PID=$$ MOSAIC_TEST_HOME="$HOME_NOBRAIN" \
|
||||||
|
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
||||||
|
MOSAIC_HOME="$CONFIG_HOME_NOBRAIN" "$START" coder-legacy
|
||||||
|
legacy_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
||||||
|
echo "$legacy_args" | grep -qF new-session || fail "legacy single-tree launch regressed"
|
||||||
|
|
||||||
# The pane must start through an absolute clean-environment boundary. Its
|
# The pane must start through an absolute clean-environment boundary. Its
|
||||||
# runtime command remains an argv vector, but no holder/session environment
|
# runtime command remains an argv vector, but no holder/session environment
|
||||||
# control variable can pass through the pane command.
|
# control variable can pass through the pane command.
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import { readFile } from 'node:fs/promises';
|
import { readFile } from 'node:fs/promises';
|
||||||
import { join, resolve } from 'node:path';
|
import { join, resolve } from 'node:path';
|
||||||
|
import { fleetAgentEnvDir, fleetRolesLocalDir } from '../fleet/brain-home.js';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import {
|
import {
|
||||||
executeFleetAgentMutation,
|
executeFleetAgentMutation,
|
||||||
@@ -149,9 +150,9 @@ async function executeCommand(
|
|||||||
request,
|
request,
|
||||||
mosaicHome,
|
mosaicHome,
|
||||||
rosterPath,
|
rosterPath,
|
||||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||||
rolesDir: join(mosaicHome, 'fleet', 'roles'),
|
rolesDir: join(mosaicHome, 'fleet', 'roles'),
|
||||||
overrideDir: join(mosaicHome, 'fleet', 'roles.local'),
|
overrideDir: fleetRolesLocalDir(mosaicHome),
|
||||||
dryRun: forceDryRun || opts.dryRun === true,
|
dryRun: forceDryRun || opts.dryRun === true,
|
||||||
...(deps.projectionApplier === undefined ? {} : { projectionApplier: deps.projectionApplier }),
|
...(deps.projectionApplier === undefined ? {} : { projectionApplier: deps.projectionApplier }),
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import { readFile } from 'node:fs/promises';
|
import { readFile } from 'node:fs/promises';
|
||||||
import { join } from 'node:path';
|
import { join } from 'node:path';
|
||||||
|
import { fleetAgentEnvDir, fleetRolesLocalDir } from '../fleet/brain-home.js';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import {
|
import {
|
||||||
parseV1MigrationObservations,
|
parseV1MigrationObservations,
|
||||||
@@ -120,11 +121,11 @@ export function registerFleetMigrationCommand(
|
|||||||
observations,
|
observations,
|
||||||
personaDirs: {
|
personaDirs: {
|
||||||
rolesDir: deps.rolesDir ?? join(mosaicHome, 'fleet', 'roles'),
|
rolesDir: deps.rolesDir ?? join(mosaicHome, 'fleet', 'roles'),
|
||||||
overrideDir: deps.overrideDir ?? join(mosaicHome, 'fleet', 'roles.local'),
|
overrideDir: deps.overrideDir ?? fleetRolesLocalDir(mosaicHome),
|
||||||
},
|
},
|
||||||
environment: {
|
environment: {
|
||||||
mosaicHome,
|
mosaicHome,
|
||||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
printJson(preview);
|
printJson(preview);
|
||||||
|
|||||||
@@ -30,19 +30,21 @@ import { lstat, readFile, readdir, stat } from 'node:fs/promises';
|
|||||||
import { homedir } from 'node:os';
|
import { homedir } from 'node:os';
|
||||||
import { basename, isAbsolute, join, sep } from 'node:path';
|
import { basename, isAbsolute, join, sep } from 'node:path';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
|
import { fleetRolesLocalDir } from '../fleet/brain-home.js';
|
||||||
|
|
||||||
function defaultMosaicHome(): string {
|
function defaultMosaicHome(): string {
|
||||||
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Baseline persona role contracts (reseeded on update). */
|
/** Baseline persona role contracts (reseeded on update; config home — framework). */
|
||||||
export function defaultRolesDir(mosaicHome = defaultMosaicHome()): string {
|
export function defaultRolesDir(mosaicHome = defaultMosaicHome()): string {
|
||||||
return join(mosaicHome, 'fleet', 'roles');
|
return join(mosaicHome, 'fleet', 'roles');
|
||||||
}
|
}
|
||||||
|
|
||||||
/** PRESERVE-protected override layer (survives update; wins on merge). */
|
/** PRESERVE-protected override layer (survives update; wins on merge).
|
||||||
|
* Brain home (`~/.mosaic/fleet/roles.local`) when a brain is active. */
|
||||||
export function defaultOverrideDir(mosaicHome = defaultMosaicHome()): string {
|
export function defaultOverrideDir(mosaicHome = defaultMosaicHome()): string {
|
||||||
return join(mosaicHome, 'fleet', 'roles.local');
|
return fleetRolesLocalDir(mosaicHome);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -25,6 +25,7 @@ import { homedir } from 'node:os';
|
|||||||
import { basename, join } from 'node:path';
|
import { basename, join } from 'node:path';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import YAML from 'yaml';
|
import YAML from 'yaml';
|
||||||
|
import { fleetProfilesDir } from '../fleet/brain-home.js';
|
||||||
import {
|
import {
|
||||||
defaultOverrideDir,
|
defaultOverrideDir,
|
||||||
extractClassesFromDir,
|
extractClassesFromDir,
|
||||||
@@ -36,9 +37,10 @@ function defaultMosaicHome(): string {
|
|||||||
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Directory holding the seeded profile yaml files. */
|
/** Directory holding the seeded profile yaml files — brain home when active
|
||||||
|
* (user working copies, committed), else the config home seed. */
|
||||||
export function defaultProfilesDir(mosaicHome = defaultMosaicHome()): string {
|
export function defaultProfilesDir(mosaicHome = defaultMosaicHome()): string {
|
||||||
return join(mosaicHome, 'fleet', 'profiles');
|
return fleetProfilesDir(mosaicHome);
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Directory holding the persona role contracts. */
|
/** Directory holding the persona role contracts. */
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import { homedir } from 'node:os';
|
|||||||
import { join, relative, resolve } from 'node:path';
|
import { join, relative, resolve } from 'node:path';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import type { CommandRunner } from './fleet.js';
|
import type { CommandRunner } from './fleet.js';
|
||||||
|
import { fleetAgentEnvDir } from '../fleet/brain-home.js';
|
||||||
import {
|
import {
|
||||||
applyPreparedGeneratedAgentEnvironmentProjection,
|
applyPreparedGeneratedAgentEnvironmentProjection,
|
||||||
prepareGeneratedAgentEnvironmentProjection,
|
prepareGeneratedAgentEnvironmentProjection,
|
||||||
@@ -153,7 +154,7 @@ export async function executeFleetRegen(
|
|||||||
options: FleetRegenOptions,
|
options: FleetRegenOptions,
|
||||||
): Promise<FleetRegenResult> {
|
): Promise<FleetRegenResult> {
|
||||||
const mosaicHome = defaultMosaicHome(deps);
|
const mosaicHome = defaultMosaicHome(deps);
|
||||||
const agentEnvDir = join(mosaicHome, 'fleet', 'agents');
|
const agentEnvDir = fleetAgentEnvDir(mosaicHome);
|
||||||
const rosterPath = join(mosaicHome, 'fleet', 'roster.yaml');
|
const rosterPath = join(mosaicHome, 'fleet', 'roster.yaml');
|
||||||
const readRoster = deps.readRoster ?? defaultReadRoster(deps, mosaicHome);
|
const readRoster = deps.readRoster ?? defaultReadRoster(deps, mosaicHome);
|
||||||
const prepare = deps.prepareProjection ?? prepareGeneratedAgentEnvironmentProjection;
|
const prepare = deps.prepareProjection ?? prepareGeneratedAgentEnvironmentProjection;
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ import {
|
|||||||
import { randomUUID } from 'node:crypto';
|
import { randomUUID } from 'node:crypto';
|
||||||
import { homedir, hostname, userInfo } from 'node:os';
|
import { homedir, hostname, userInfo } from 'node:os';
|
||||||
import { dirname, join, resolve } from 'node:path';
|
import { dirname, join, resolve } from 'node:path';
|
||||||
|
import { fleetAgentEnvDir } from '../fleet/brain-home.js';
|
||||||
import { fileURLToPath } from 'node:url';
|
import { fileURLToPath } from 'node:url';
|
||||||
import { spawn } from 'node:child_process';
|
import { spawn } from 'node:child_process';
|
||||||
import * as readline from 'node:readline';
|
import * as readline from 'node:readline';
|
||||||
@@ -158,7 +159,7 @@ export function resolveFleetPaths(mosaicHome = defaultMosaicHome()): FleetPaths
|
|||||||
fleetToolsDir: join(mosaicHome, 'tools', 'fleet'),
|
fleetToolsDir: join(mosaicHome, 'tools', 'fleet'),
|
||||||
tmuxToolsDir: join(mosaicHome, 'tools', 'tmux'),
|
tmuxToolsDir: join(mosaicHome, 'tools', 'tmux'),
|
||||||
systemdUserDir: join(homedir(), '.config', 'systemd', 'user'),
|
systemdUserDir: join(homedir(), '.config', 'systemd', 'user'),
|
||||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -349,3 +349,90 @@ describe('registerRuntimeLaunchers — claudex (EXPERIMENTAL overlay)', () => {
|
|||||||
expect(mockExit).not.toHaveBeenCalled();
|
expect(mockExit).not.toHaveBeenCalled();
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// ─── Seat harness homes (MOSAIC-D-002, brain-home split) ────────────────────
|
||||||
|
|
||||||
|
import { activeSeatDir, seatPersonaOverlay } from './launch.js';
|
||||||
|
|
||||||
|
describe('activeSeatDir — per-agent harness home resolution', () => {
|
||||||
|
let root: string;
|
||||||
|
const savedAgentName = process.env['MOSAIC_AGENT_NAME'];
|
||||||
|
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
|
||||||
|
beforeEach(() => {
|
||||||
|
root = mkdtempSync(join(tmpdir(), 'mosaic-seat-home-'));
|
||||||
|
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(() => {
|
||||||
|
rmSync(root, { recursive: true, force: true });
|
||||||
|
if (savedAgentName === undefined) {
|
||||||
|
delete process.env['MOSAIC_AGENT_NAME'];
|
||||||
|
} else {
|
||||||
|
process.env['MOSAIC_AGENT_NAME'] = savedAgentName;
|
||||||
|
}
|
||||||
|
if (savedBrainHome !== undefined) {
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
|
||||||
|
} else {
|
||||||
|
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it('resolves the seat dir when MOSAIC_BRAIN_HOME carries the seat', () => {
|
||||||
|
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
||||||
|
mkdirSync(seat, { recursive: true });
|
||||||
|
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||||
|
|
||||||
|
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBe(seat);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns undefined without an agent name (bare launches stay shared)', () => {
|
||||||
|
delete process.env['MOSAIC_AGENT_NAME'];
|
||||||
|
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns undefined when the seat dir does not exist in the brain', () => {
|
||||||
|
process.env['MOSAIC_AGENT_NAME'] = 'ghost';
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||||
|
mkdirSync(join(root, 'brain', 'fleet', 'agents'), { recursive: true });
|
||||||
|
|
||||||
|
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
||||||
|
});
|
||||||
|
|
||||||
|
it.each(['../escape', 'a/b', '.hidden-start', '', 'spaced name'])(
|
||||||
|
'rejects unsafe agent name %j (path traversal cannot leave the seat store)',
|
||||||
|
(name: string) => {
|
||||||
|
process.env['MOSAIC_AGENT_NAME'] = name;
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||||
|
|
||||||
|
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
it('seatPersonaOverlay renders the seat SOUL.md as an overlay block', () => {
|
||||||
|
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
||||||
|
mkdirSync(seat, { recursive: true });
|
||||||
|
writeFileSync(join(seat, 'SOUL.md'), '# coder0 — code seat persona\n\nShips tested code.\n');
|
||||||
|
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||||
|
|
||||||
|
const overlay = seatPersonaOverlay(join(root, 'config', 'mosaic'));
|
||||||
|
expect(overlay).toContain('## Seat Persona');
|
||||||
|
expect(overlay).toContain('coder0 — code seat persona');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('seatPersonaOverlay is empty when the seat carries no SOUL.md', () => {
|
||||||
|
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
||||||
|
mkdirSync(seat, { recursive: true });
|
||||||
|
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||||
|
|
||||||
|
expect(seatPersonaOverlay(join(root, 'config', 'mosaic'))).toBe('');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('seatPersonaOverlay is empty when no agent name is set', () => {
|
||||||
|
delete process.env['MOSAIC_AGENT_NAME'];
|
||||||
|
expect(seatPersonaOverlay(join(root, 'config', 'mosaic'))).toBe('');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ import {
|
|||||||
import { createHash, randomBytes } from 'node:crypto';
|
import { createHash, randomBytes } from 'node:crypto';
|
||||||
import { createRequire } from 'node:module';
|
import { createRequire } from 'node:module';
|
||||||
import { homedir, hostname } from 'node:os';
|
import { homedir, hostname } from 'node:os';
|
||||||
import { join, dirname } from 'node:path';
|
import { join, dirname, resolve } from 'node:path';
|
||||||
import type { Command } from 'commander';
|
import type { Command } from 'commander';
|
||||||
import {
|
import {
|
||||||
buildResolvedFleetCommsBlock,
|
buildResolvedFleetCommsBlock,
|
||||||
@@ -29,6 +29,7 @@ import {
|
|||||||
import { readRegularFileSecure } from '../fleet/secure-file.js';
|
import { readRegularFileSecure } from '../fleet/secure-file.js';
|
||||||
import { readPersonaContractBlock } from '../fleet/persona-contract.js';
|
import { readPersonaContractBlock } from '../fleet/persona-contract.js';
|
||||||
import { canonicalizeRoleClass } from './fleet-personas.js';
|
import { canonicalizeRoleClass } from './fleet-personas.js';
|
||||||
|
import { resolveBrainHome } from '../fleet/brain-home.js';
|
||||||
import { launchClaudex, type ClaudexHarnessAdapter } from './claudex.js';
|
import { launchClaudex, type ClaudexHarnessAdapter } from './claudex.js';
|
||||||
import { runLeaseEnforcementDoctorCheck } from './lease-doctor-check.js';
|
import { runLeaseEnforcementDoctorCheck } from './lease-doctor-check.js';
|
||||||
|
|
||||||
@@ -64,9 +65,46 @@ const HARNESS_HOME_ENV: Record<RuntimeName, string> = {
|
|||||||
opencode: 'XDG_CONFIG_HOME',
|
opencode: 'XDG_CONFIG_HOME',
|
||||||
};
|
};
|
||||||
|
|
||||||
/** Dedicated mosaic-owned home for a runtime: ~/.config/mosaic/.<runtime> */
|
/** Dedicated mosaic-owned home for a runtime: ~/.config/mosaic/.<runtime>.
|
||||||
function harnessHome(runtime: RuntimeName): string {
|
* With an active brain seat (MOSAIC_AGENT_NAME + seat dir in the brain home)
|
||||||
return join(MOSAIC_HOME, `.${runtime}`);
|
* the home is per-agent instead: <brainHome>/fleet/agents/<seat>/.<runtime> —
|
||||||
|
* per-agent sessions, settings, and auth inside the seat dir (canon §2,
|
||||||
|
* MOSAIC-D-002). Seat runtime dirs are dot-named so the brain's ignore policy
|
||||||
|
* (per-seat .pi/.claude/.codex dirs) keeps credential material untracked. */
|
||||||
|
const SEAT_AGENT_NAME_RE = /^[a-zA-Z0-9][a-zA-Z0-9._-]*$/;
|
||||||
|
|
||||||
|
export function activeSeatDir(mosaicHome: string = MOSAIC_HOME): string | undefined {
|
||||||
|
const agent = process.env['MOSAIC_AGENT_NAME']?.trim();
|
||||||
|
if (
|
||||||
|
agent === undefined ||
|
||||||
|
agent === '' ||
|
||||||
|
!SEAT_AGENT_NAME_RE.test(agent) ||
|
||||||
|
agent.includes('..')
|
||||||
|
) {
|
||||||
|
return undefined;
|
||||||
|
}
|
||||||
|
const brain = resolveBrainHome(mosaicHome);
|
||||||
|
if (resolve(brain) === resolve(mosaicHome)) return undefined; // no brain
|
||||||
|
const seat = join(brain, 'fleet', 'agents', agent);
|
||||||
|
return existsSync(seat) ? seat : undefined;
|
||||||
|
}
|
||||||
|
|
||||||
|
function harnessHome(runtime: RuntimeName, mosaicHome: string = MOSAIC_HOME): string {
|
||||||
|
const seat = activeSeatDir(mosaicHome);
|
||||||
|
if (seat !== undefined) return join(seat, `.${runtime}`);
|
||||||
|
return join(mosaicHome, `.${runtime}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Seat persona block: with an active brain seat, <seat>/SOUL.md layers
|
||||||
|
* persona on the root generic base (canon invariant; MOSAIC-D-002). The base
|
||||||
|
* SOUL stays load-on-demand — only the seat delta is injected by value.
|
||||||
|
* Empty string when no seat is active or the seat carries no SOUL.md. */
|
||||||
|
export function seatPersonaOverlay(mosaicHome: string = MOSAIC_HOME): string {
|
||||||
|
const seatDir = activeSeatDir(mosaicHome);
|
||||||
|
if (seatDir === undefined) return '';
|
||||||
|
const seatSoul = readOptional(join(seatDir, 'SOUL.md'));
|
||||||
|
if (!seatSoul.trim()) return '';
|
||||||
|
return '## Seat Persona\n\n' + seatSoul.trim();
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -182,6 +220,8 @@ function recordLaunch(runtime: RuntimeName, cliArgs: string[], yolo: boolean): v
|
|||||||
cli_version: CLI_VERSION,
|
cli_version: CLI_VERSION,
|
||||||
config_home: harnessHome(runtime),
|
config_home: harnessHome(runtime),
|
||||||
config_home_isolated: true,
|
config_home_isolated: true,
|
||||||
|
config_home_kind: activeSeatDir() !== undefined ? 'seat' : 'runtime-shared',
|
||||||
|
agent_name: process.env['MOSAIC_AGENT_NAME']?.trim() || null,
|
||||||
config_home_env: HARNESS_HOME_ENV[runtime] ?? null,
|
config_home_env: HARNESS_HOME_ENV[runtime] ?? null,
|
||||||
argv: redactArgv(cliArgs),
|
argv: redactArgv(cliArgs),
|
||||||
normative_fragments: normativeFragmentDigests(runtime),
|
normative_fragments: normativeFragmentDigests(runtime),
|
||||||
@@ -569,6 +609,11 @@ For required push/merge/issue-close/release actions, execute without routine con
|
|||||||
if (soulLocal.trim()) {
|
if (soulLocal.trim()) {
|
||||||
overlayBlocks.push('## Persona Overlay (SOUL.local.md)\n\n' + soulLocal.trim());
|
overlayBlocks.push('## Persona Overlay (SOUL.local.md)\n\n' + soulLocal.trim());
|
||||||
}
|
}
|
||||||
|
// Seat persona (MOSAIC-D-002): per-seat SOUL.md layers on the generic base.
|
||||||
|
const seatPersona = seatPersonaOverlay(mosaicHome);
|
||||||
|
if (seatPersona !== '') {
|
||||||
|
overlayBlocks.push(seatPersona);
|
||||||
|
}
|
||||||
const standardsLocal = readOptional(join(mosaicHome, 'STANDARDS.local.md'));
|
const standardsLocal = readOptional(join(mosaicHome, 'STANDARDS.local.md'));
|
||||||
if (standardsLocal.trim()) {
|
if (standardsLocal.trim()) {
|
||||||
overlayBlocks.push('## Standards Overlay (STANDARDS.local.md)\n\n' + standardsLocal.trim());
|
overlayBlocks.push('## Standards Overlay (STANDARDS.local.md)\n\n' + standardsLocal.trim());
|
||||||
|
|||||||
@@ -0,0 +1,114 @@
|
|||||||
|
import { mkdir, mkdtemp, rm } from 'node:fs/promises';
|
||||||
|
import { homedir, tmpdir } from 'node:os';
|
||||||
|
import { join } from 'node:path';
|
||||||
|
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
|
||||||
|
import {
|
||||||
|
brainHomeIsActive,
|
||||||
|
fleetAgentEnvDir,
|
||||||
|
fleetProfilesDir,
|
||||||
|
fleetRolesLocalDir,
|
||||||
|
fleetStateDir,
|
||||||
|
resolveBrainHome,
|
||||||
|
type BrainHomeOptions,
|
||||||
|
} from './brain-home.js';
|
||||||
|
|
||||||
|
describe('fleet brain-home resolution', (): void => {
|
||||||
|
let cleanup: string | undefined;
|
||||||
|
|
||||||
|
const savedBrainEnv = process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
|
||||||
|
beforeEach((): void => {
|
||||||
|
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
});
|
||||||
|
|
||||||
|
afterEach(async (): Promise<void> => {
|
||||||
|
if (savedBrainEnv === undefined) {
|
||||||
|
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
} else {
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = savedBrainEnv;
|
||||||
|
}
|
||||||
|
if (cleanup !== undefined) {
|
||||||
|
await rm(cleanup, { recursive: true, force: true });
|
||||||
|
cleanup = undefined;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
async function makeTmp(): Promise<string> {
|
||||||
|
const root = await mkdtemp(join(tmpdir(), 'mosaic-brain-home-'));
|
||||||
|
cleanup = root;
|
||||||
|
return root;
|
||||||
|
}
|
||||||
|
|
||||||
|
it('MOSAIC_BRAIN_HOME env wins over every other signal', (): void => {
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = '/explicit/brain';
|
||||||
|
expect(resolveBrainHome('/any/mosaic-home')).toBe('/explicit/brain');
|
||||||
|
expect(fleetAgentEnvDir('/any/mosaic-home')).toBe('/explicit/brain/fleet/agents');
|
||||||
|
expect(brainHomeIsActive('/any/mosaic-home')).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('injected envBrainHome wins identically (test seam)', (): void => {
|
||||||
|
const opts: BrainHomeOptions = { envBrainHome: '/injected/brain' };
|
||||||
|
expect(resolveBrainHome('/any/mosaic-home', opts)).toBe('/injected/brain');
|
||||||
|
expect(fleetAgentEnvDir('/any/mosaic-home', opts)).toBe('/injected/brain/fleet/agents');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('a non-default mosaicHome never adopts the canonical brain (hermetic legacy)', (): void => {
|
||||||
|
const mosaicHome = '/tmp/not-the-default-config-home';
|
||||||
|
expect(resolveBrainHome(mosaicHome)).toBe(mosaicHome);
|
||||||
|
expect(brainHomeIsActive(mosaicHome)).toBe(false);
|
||||||
|
expect(fleetAgentEnvDir(mosaicHome)).toBe(join(mosaicHome, 'fleet', 'agents'));
|
||||||
|
});
|
||||||
|
|
||||||
|
it('the default config home adopts the brain when it carries fleet/agents', async (): Promise<void> => {
|
||||||
|
const root = await makeTmp();
|
||||||
|
const brain = join(root, 'brain');
|
||||||
|
await mkdir(join(brain, 'fleet', 'agents'), { recursive: true });
|
||||||
|
const configHome = join(root, 'config', 'mosaic');
|
||||||
|
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
|
||||||
|
|
||||||
|
expect(resolveBrainHome(configHome, opts)).toBe(brain);
|
||||||
|
expect(fleetAgentEnvDir(configHome, opts)).toBe(join(brain, 'fleet', 'agents'));
|
||||||
|
expect(fleetRolesLocalDir(configHome, opts)).toBe(join(brain, 'fleet', 'roles.local'));
|
||||||
|
expect(fleetProfilesDir(configHome, opts)).toBe(join(brain, 'fleet', 'profiles'));
|
||||||
|
expect(fleetStateDir(configHome, opts)).toBe(join(brain, 'fleet'));
|
||||||
|
expect(brainHomeIsActive(configHome, opts)).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('the default config home stays legacy when no brain exists', async (): Promise<void> => {
|
||||||
|
const root = await makeTmp();
|
||||||
|
const configHome = join(root, 'config', 'mosaic');
|
||||||
|
const opts: BrainHomeOptions = {
|
||||||
|
homes: { brain: join(root, 'brain'), configDefault: configHome },
|
||||||
|
};
|
||||||
|
|
||||||
|
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
|
||||||
|
expect(brainHomeIsActive(configHome, opts)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('an empty MOSAIC_BRAIN_HOME is ignored, not treated as set', (): void => {
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = ' ';
|
||||||
|
expect(resolveBrainHome('/tmp/legacy-home')).toBe('/tmp/legacy-home');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('adoption requires fleet/agents specifically, not any brain content', async (): Promise<void> => {
|
||||||
|
const root = await makeTmp();
|
||||||
|
const brain = join(root, 'brain');
|
||||||
|
await mkdir(join(brain, 'fleet'), { recursive: true }); // fleet without agents
|
||||||
|
const configHome = join(root, 'config', 'mosaic');
|
||||||
|
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
|
||||||
|
|
||||||
|
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('real-home control: a host brain is adopted only through the default home', (): void => {
|
||||||
|
// Control on the un-injected path: this host carries ~/.mosaic/fleet/agents,
|
||||||
|
// so the default config home resolves to the brain or legacy — both valid
|
||||||
|
// canonical endpoints — while a non-default home never adopts.
|
||||||
|
const defaultHome = join(homedir(), '.config', 'mosaic');
|
||||||
|
const resolved = resolveBrainHome(defaultHome);
|
||||||
|
expect([defaultHome, join(homedir(), '.mosaic')]).toContain(resolved);
|
||||||
|
expect(resolveBrainHome(join(homedir(), 'elsewhere', 'mosaic'))).toBe(
|
||||||
|
join(homedir(), 'elsewhere', 'mosaic'),
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,76 @@
|
|||||||
|
import { existsSync } from 'node:fs';
|
||||||
|
import { homedir } from 'node:os';
|
||||||
|
import { join, resolve } from 'node:path';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Overridable resolution inputs (tests inject tmp homes; production reads
|
||||||
|
* the environment and the real home directory).
|
||||||
|
*/
|
||||||
|
export interface BrainHomeOptions {
|
||||||
|
/** Explicit brain home; defaults to `MOSAIC_BRAIN_HOME`. */
|
||||||
|
readonly envBrainHome?: string;
|
||||||
|
/**
|
||||||
|
* Canonical homes used for adoption. Defaults derive from the real
|
||||||
|
* `homedir()`: `{ brain: ~/.mosaic, configDefault: ~/.config/mosaic }`.
|
||||||
|
*/
|
||||||
|
readonly homes?: { readonly brain: string; readonly configDefault: string };
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Brain-home resolution — the three-tree fleet split (stack canon
|
||||||
|
* `docs/STRUCTURE-CANON.md` §2, first carried by the USC estate brain):
|
||||||
|
*
|
||||||
|
* config home (~/.config/mosaic) framework templates + dispatch state:
|
||||||
|
* fleet/roles (baseline), fleet/roster.yaml,
|
||||||
|
* fleet/run (heartbeats), fleet/services
|
||||||
|
* brain home (~/.mosaic) user-owned fleet state, committed:
|
||||||
|
* fleet/agents/<seat>.env.*, fleet/roles.local,
|
||||||
|
* fleet/profiles working copies
|
||||||
|
*
|
||||||
|
* Resolution order:
|
||||||
|
* 1. `MOSAIC_BRAIN_HOME` env (explicit, always wins)
|
||||||
|
* 2. canonical `~/.mosaic` — adopted ONLY when mosaicHome is the real
|
||||||
|
* default config home AND `~/.mosaic/fleet/agents` exists. Custom
|
||||||
|
* `--mosaic-home` values (tests, sandboxes, canaries) never trigger
|
||||||
|
* adoption, keeping them hermetic and deterministic.
|
||||||
|
* 3. mosaicHome itself (legacy single-tree behavior).
|
||||||
|
*/
|
||||||
|
export function resolveBrainHome(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||||
|
const explicit = options.envBrainHome ?? process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
if (explicit !== undefined && explicit.trim() !== '') {
|
||||||
|
return explicit;
|
||||||
|
}
|
||||||
|
const homes = options.homes ?? {
|
||||||
|
brain: join(homedir(), '.mosaic'),
|
||||||
|
configDefault: join(homedir(), '.config', 'mosaic'),
|
||||||
|
};
|
||||||
|
if (resolve(mosaicHome) !== resolve(homes.configDefault)) {
|
||||||
|
return mosaicHome;
|
||||||
|
}
|
||||||
|
return existsSync(join(homes.brain, 'fleet', 'agents')) ? homes.brain : mosaicHome;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** True when fleet state resolves somewhere other than the config home. */
|
||||||
|
export function brainHomeIsActive(mosaicHome: string, options: BrainHomeOptions = {}): boolean {
|
||||||
|
return resolve(resolveBrainHome(mosaicHome, options)) !== resolve(mosaicHome);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Fleet state root (brain home when active, else the config home). */
|
||||||
|
export function fleetStateDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||||
|
return join(resolveBrainHome(mosaicHome, options), 'fleet');
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Seat launch envs — `<brainHome>/fleet/agents` when a brain is active. */
|
||||||
|
export function fleetAgentEnvDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||||
|
return join(fleetStateDir(mosaicHome, options), 'agents');
|
||||||
|
}
|
||||||
|
|
||||||
|
/** PRESERVE-protected persona override layer — `<brainHome>/fleet/roles.local`. */
|
||||||
|
export function fleetRolesLocalDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||||
|
return join(fleetStateDir(mosaicHome, options), 'roles.local');
|
||||||
|
}
|
||||||
|
|
||||||
|
/** System-type profiles (user working copies) — `<brainHome>/fleet/profiles`. */
|
||||||
|
export function fleetProfilesDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||||
|
return join(fleetStateDir(mosaicHome, options), 'profiles');
|
||||||
|
}
|
||||||
@@ -3,6 +3,7 @@ import { lstat, open, readFile, unlink, type FileHandle } from 'node:fs/promises
|
|||||||
import { randomUUID } from 'node:crypto';
|
import { randomUUID } from 'node:crypto';
|
||||||
import { homedir } from 'node:os';
|
import { homedir } from 'node:os';
|
||||||
import { join } from 'node:path';
|
import { join } from 'node:path';
|
||||||
|
import { fleetAgentEnvDir } from './brain-home.js';
|
||||||
import {
|
import {
|
||||||
applyPreparedAgentEnvironmentProjection,
|
applyPreparedAgentEnvironmentProjection,
|
||||||
prepareAgentEnvironmentProjection,
|
prepareAgentEnvironmentProjection,
|
||||||
@@ -617,7 +618,7 @@ function defaultPrepareProjections(
|
|||||||
(agent: FleetRosterV2Agent): Promise<PreparedAgentEnvironmentProjection> =>
|
(agent: FleetRosterV2Agent): Promise<PreparedAgentEnvironmentProjection> =>
|
||||||
prepareAgentEnvironmentProjection({
|
prepareAgentEnvironmentProjection({
|
||||||
mosaicHome,
|
mosaicHome,
|
||||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||||
agentName: agent.name,
|
agentName: agent.name,
|
||||||
generated: projectRosterV2AgentGeneratedEnv(roster, agent),
|
generated: projectRosterV2AgentGeneratedEnv(roster, agent),
|
||||||
}),
|
}),
|
||||||
|
|||||||
@@ -176,6 +176,52 @@ describe('generated fleet agent environment boundary', (): void => {
|
|||||||
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('brain home: accepts and writes projections under MOSAIC_BRAIN_HOME/fleet/agents', async (): Promise<void> => {
|
||||||
|
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
try {
|
||||||
|
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
||||||
|
const mosaicHome = join(cleanup, 'config-home');
|
||||||
|
const brainHome = join(cleanup, 'brain');
|
||||||
|
const agentEnvDir = join(brainHome, 'fleet', 'agents');
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = brainHome;
|
||||||
|
|
||||||
|
const result = await writeAgentEnvironmentProjection({
|
||||||
|
mosaicHome,
|
||||||
|
agentEnvDir,
|
||||||
|
agentName: 'coder0',
|
||||||
|
generated: generatedValues,
|
||||||
|
});
|
||||||
|
|
||||||
|
// Projection landed in the brain tree, not under the config home.
|
||||||
|
expect(result.generatedPath).toBe(join(agentEnvDir, 'coder0.env.generated'));
|
||||||
|
expect((await stat(join(brainHome, 'fleet'))).mode & 0o777).toBe(0o700);
|
||||||
|
expect((await stat(agentEnvDir)).mode & 0o777).toBe(0o700);
|
||||||
|
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
||||||
|
await expect(stat(join(mosaicHome, 'fleet'))).rejects.toThrow();
|
||||||
|
|
||||||
|
// A config-home agentEnvDir is now REJECTED while the brain is active —
|
||||||
|
// the boundary must not silently split state across two trees.
|
||||||
|
let rejected: unknown;
|
||||||
|
try {
|
||||||
|
await writeAgentEnvironmentProjection({
|
||||||
|
mosaicHome,
|
||||||
|
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||||
|
agentName: 'coder1',
|
||||||
|
generated: { ...generatedValues, MOSAIC_AGENT_NAME: 'coder1' },
|
||||||
|
});
|
||||||
|
} catch (caught: unknown) {
|
||||||
|
rejected = caught;
|
||||||
|
}
|
||||||
|
expect(rejected).toBeInstanceOf(AgentEnvBoundaryError);
|
||||||
|
} finally {
|
||||||
|
if (savedBrainHome === undefined) {
|
||||||
|
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||||
|
} else {
|
||||||
|
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
it('regenerates desired keys, relocates safe legacy local data, and quarantines forbidden legacy input', async (): Promise<void> => {
|
it('regenerates desired keys, relocates safe legacy local data, and quarantines forbidden legacy input', async (): Promise<void> => {
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
||||||
const mosaicHome = join(cleanup, 'mosaic');
|
const mosaicHome = join(cleanup, 'mosaic');
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ import { createHash, randomUUID } from 'node:crypto';
|
|||||||
import { chmod, lstat, mkdir, readFile, rename, unlink, writeFile } from 'node:fs/promises';
|
import { chmod, lstat, mkdir, readFile, rename, unlink, writeFile } from 'node:fs/promises';
|
||||||
import { homedir } from 'node:os';
|
import { homedir } from 'node:os';
|
||||||
import { dirname, join, resolve } from 'node:path';
|
import { dirname, join, resolve } from 'node:path';
|
||||||
|
import { fleetAgentEnvDir, resolveBrainHome } from './brain-home.js';
|
||||||
import { compareCodePoints } from './deterministic-order.js';
|
import { compareCodePoints } from './deterministic-order.js';
|
||||||
|
|
||||||
export type AgentEnvironmentKind = 'generated' | 'local';
|
export type AgentEnvironmentKind = 'generated' | 'local';
|
||||||
@@ -528,12 +529,15 @@ async function validatePrivateProjectionDirectory(
|
|||||||
mosaicHome: string,
|
mosaicHome: string,
|
||||||
agentEnvDir: string,
|
agentEnvDir: string,
|
||||||
): Promise<void> {
|
): Promise<void> {
|
||||||
const fleetDir = join(mosaicHome, 'fleet');
|
// Brain-home split (canon §2): seat envs live under the brain home's
|
||||||
const expectedAgentEnvDir = join(fleetDir, 'agents');
|
// fleet/agents when a brain is active; roster + templates stay config-home.
|
||||||
|
const expectedAgentEnvDir = fleetAgentEnvDir(mosaicHome);
|
||||||
if (resolve(agentEnvDir) !== resolve(expectedAgentEnvDir)) {
|
if (resolve(agentEnvDir) !== resolve(expectedAgentEnvDir)) {
|
||||||
throw new AgentEnvBoundaryError('unsafe-directory', '(directory)', agentEnvDir);
|
throw new AgentEnvBoundaryError('unsafe-directory', '(directory)', agentEnvDir);
|
||||||
}
|
}
|
||||||
await assertManagedDirectoryIfPresent(mosaicHome, false);
|
const stateHome = resolveBrainHome(mosaicHome);
|
||||||
|
const fleetDir = join(stateHome, 'fleet');
|
||||||
|
await assertManagedDirectoryIfPresent(stateHome, false);
|
||||||
await assertManagedDirectoryIfPresent(fleetDir, false);
|
await assertManagedDirectoryIfPresent(fleetDir, false);
|
||||||
await assertManagedDirectoryIfPresent(agentEnvDir, true);
|
await assertManagedDirectoryIfPresent(agentEnvDir, true);
|
||||||
}
|
}
|
||||||
@@ -543,8 +547,9 @@ async function ensurePrivateProjectionDirectory(
|
|||||||
agentEnvDir: string,
|
agentEnvDir: string,
|
||||||
): Promise<void> {
|
): Promise<void> {
|
||||||
await validatePrivateProjectionDirectory(mosaicHome, agentEnvDir);
|
await validatePrivateProjectionDirectory(mosaicHome, agentEnvDir);
|
||||||
const fleetDir = join(mosaicHome, 'fleet');
|
const stateHome = resolveBrainHome(mosaicHome);
|
||||||
await ensureManagedDirectory(mosaicHome, false);
|
const fleetDir = join(stateHome, 'fleet');
|
||||||
|
await ensureManagedDirectory(stateHome, false);
|
||||||
await ensureManagedDirectory(fleetDir, false);
|
await ensureManagedDirectory(fleetDir, false);
|
||||||
await ensureManagedDirectory(agentEnvDir, true);
|
await ensureManagedDirectory(agentEnvDir, true);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,166 @@
|
|||||||
|
#!/usr/bin/env node
|
||||||
|
// verify-release.mjs — the ONE canonical terminal verification command
|
||||||
|
// (SDLC-D-034, `pnpm verify:release`).
|
||||||
|
//
|
||||||
|
// Publication (.woodpecker/publish.yml `verify` step) is bound to terminal
|
||||||
|
// verification of the exact commit through this command, which is composed
|
||||||
|
// from the SAME commands the PR CI pipeline (.woodpecker/ci.yml) runs — CI and
|
||||||
|
// publish share one semantic checklist:
|
||||||
|
//
|
||||||
|
// stage | mirrors ci.yml step | commands
|
||||||
|
// --------------|---------------------|------------------------------------------
|
||||||
|
// sanitization | sanitization | verify-sanitized.sh, check-resident-
|
||||||
|
// | | budget.sh (--self-test + run),
|
||||||
|
// | | check-test-enumeration.sh
|
||||||
|
// upgrade-guard | upgrade-guard | test-upgrade-manifest-guard.sh,
|
||||||
|
// | | test-upgrade-rollback.sh,
|
||||||
|
// | | test-upgrade-durable-snapshot.sh,
|
||||||
|
// | | test-install-migration.sh
|
||||||
|
// typecheck | typecheck | pnpm typecheck (runs the checkout
|
||||||
|
// | | preflight, then turbo typecheck)
|
||||||
|
// lint | lint | pnpm lint
|
||||||
|
// format | format | pnpm format:check
|
||||||
|
// test | test | pnpm test
|
||||||
|
// build | publish.yml build | pnpm build
|
||||||
|
//
|
||||||
|
// Caller-provided prerequisites (kept at the pipeline level — see the comments
|
||||||
|
// in .woodpecker/ci.yml): `bash` + `rsync` for the guard stages, `openssl` and
|
||||||
|
// the pinned @earendil-works/pi-coding-agent for the test stage, and — on the
|
||||||
|
// postgres path only — the ci-postgres service plus
|
||||||
|
// `pnpm --filter @mosaicstack/db run db:migrate` before the test stage.
|
||||||
|
//
|
||||||
|
// This command works with DATABASE_URL set (CI postgres path) or unset (local
|
||||||
|
// PGlite path); it never sets, exports, or requires a database itself.
|
||||||
|
//
|
||||||
|
// scripts/verify-release.test.mjs enforces that this stage table keeps
|
||||||
|
// matching .woodpecker/ci.yml step-for-step, so the two surfaces cannot drift
|
||||||
|
// apart silently.
|
||||||
|
|
||||||
|
import { spawnSync } from 'node:child_process';
|
||||||
|
import path from 'node:path';
|
||||||
|
import { fileURLToPath } from 'node:url';
|
||||||
|
|
||||||
|
export const STAGES = [
|
||||||
|
{
|
||||||
|
name: 'sanitization',
|
||||||
|
// Mirror of the .woodpecker/ci.yml `sanitization` step (minus its
|
||||||
|
// `apk add` environment prep). Kept as direct command strings here: the
|
||||||
|
// #1017 test-enumeration guard audits these paths through the ci.yml
|
||||||
|
// surface, so indirection from ci.yml into this file is not possible.
|
||||||
|
commands: [
|
||||||
|
'bash packages/mosaic/framework/tools/quality/scripts/verify-sanitized.sh',
|
||||||
|
'bash packages/mosaic/framework/tools/quality/scripts/check-resident-budget.sh --self-test',
|
||||||
|
'bash packages/mosaic/framework/tools/quality/scripts/check-resident-budget.sh',
|
||||||
|
'bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh',
|
||||||
|
],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: 'upgrade-guard',
|
||||||
|
// Mirror of the .woodpecker/ci.yml `upgrade-guard` step (minus its
|
||||||
|
// `apk add` environment prep).
|
||||||
|
commands: [
|
||||||
|
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-manifest-guard.sh',
|
||||||
|
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-rollback.sh',
|
||||||
|
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh',
|
||||||
|
'bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh',
|
||||||
|
],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
// `pnpm typecheck` is `pnpm preflight && turbo run typecheck`, so the
|
||||||
|
// checkout preflight (scripts/preflight.mjs) is part of this stage exactly
|
||||||
|
// as it is part of the ci.yml `typecheck` step.
|
||||||
|
name: 'typecheck',
|
||||||
|
commands: ['pnpm typecheck'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: 'lint',
|
||||||
|
commands: ['pnpm lint'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: 'format',
|
||||||
|
commands: ['pnpm format:check'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
// Requires `openssl` and the pinned `pi` binary on the pipeline path; see
|
||||||
|
// the caller-provided prerequisites above.
|
||||||
|
name: 'test',
|
||||||
|
commands: ['pnpm test'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: 'build',
|
||||||
|
commands: ['pnpm build'],
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
export function stageByName(name) {
|
||||||
|
return STAGES.find((stage) => stage.name === name);
|
||||||
|
}
|
||||||
|
|
||||||
|
function missingBinaries(bins) {
|
||||||
|
return bins.filter(
|
||||||
|
(bin) => spawnSync('sh', ['-c', `command -v ${bin} >/dev/null 2>&1`]).status !== 0,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
function runCommand(command) {
|
||||||
|
const result = spawnSync(command, { shell: true, stdio: 'inherit' });
|
||||||
|
if (result.error) {
|
||||||
|
console.error(`[verify:release] failed to launch '${command}': ${result.error.message}`);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
if (result.status !== 0) {
|
||||||
|
const reason = result.signal ? `terminated by ${result.signal}` : `exited ${result.status}`;
|
||||||
|
console.error(`[verify:release] command '${command}' ${reason}`);
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Runs the complete mandatory verification set (or, with --stage <name>, the
|
||||||
|
// single named stage — used for wiring/smoke-testing, not for gating: only a
|
||||||
|
// run of every stage is a terminal verification). Fails fast: the first
|
||||||
|
// failing command aborts with a non-zero exit code. Returns the exit code.
|
||||||
|
export function verifyRelease({ stages = STAGES } = {}) {
|
||||||
|
const missing = missingBinaries(['bash', 'rsync']);
|
||||||
|
if (missing.length > 0) {
|
||||||
|
console.error(
|
||||||
|
`[verify:release] FATAL: required binaries missing from PATH: ${missing.join(', ')}. ` +
|
||||||
|
'The caller provides them (ci-base bakes bash; pipelines apk add rsync).',
|
||||||
|
);
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
|
for (const stage of stages) {
|
||||||
|
console.log(`\n[verify:release] === stage: ${stage.name} ===`);
|
||||||
|
for (const command of stage.commands) {
|
||||||
|
console.log(`[verify:release] $ ${command}`);
|
||||||
|
if (!runCommand(command)) {
|
||||||
|
console.error(
|
||||||
|
`[verify:release] FATAL: stage '${stage.name}' failed — verification inconclusive`,
|
||||||
|
);
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
console.log(`\n[verify:release] all ${stages.length} stage(s) passed`);
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
function main(argv) {
|
||||||
|
const stageFlagIndex = argv.indexOf('--stage');
|
||||||
|
if (stageFlagIndex !== -1) {
|
||||||
|
const name = argv[stageFlagIndex + 1];
|
||||||
|
const stage = stageByName(name);
|
||||||
|
if (!stage) {
|
||||||
|
console.error(
|
||||||
|
`[verify:release] unknown stage '${name ?? ''}' — expected one of: ${STAGES.map((entry) => entry.name).join(', ')}`,
|
||||||
|
);
|
||||||
|
process.exit(2);
|
||||||
|
}
|
||||||
|
process.exit(verifyRelease({ stages: [stage] }));
|
||||||
|
}
|
||||||
|
process.exit(verifyRelease());
|
||||||
|
}
|
||||||
|
|
||||||
|
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
|
||||||
|
main(process.argv.slice(2));
|
||||||
|
}
|
||||||
@@ -0,0 +1,277 @@
|
|||||||
|
import assert from 'node:assert/strict';
|
||||||
|
import { readFile } from 'node:fs/promises';
|
||||||
|
import { createRequire } from 'node:module';
|
||||||
|
import path from 'node:path';
|
||||||
|
import test from 'node:test';
|
||||||
|
|
||||||
|
import { STAGES } from './verify-release.mjs';
|
||||||
|
|
||||||
|
// SDLC-D-034 checkout invariant: publication in .woodpecker/publish.yml is
|
||||||
|
// bound to exact-commit terminal verification. This suite parses the real
|
||||||
|
// pipeline files and fails red when the gate is bypassed, weakened, or drifts
|
||||||
|
// out of sync with the canonical `pnpm verify:release` command.
|
||||||
|
|
||||||
|
// Reuse the monorepo's existing YAML parser (@mosaicstack/mosaic's direct
|
||||||
|
// dependency) instead of adding a root dependency or vendoring a parser.
|
||||||
|
const mosaicRequire = createRequire(
|
||||||
|
path.resolve(process.cwd(), 'packages', 'mosaic', 'package.json'),
|
||||||
|
);
|
||||||
|
const { parse: parseYaml } = mosaicRequire('yaml');
|
||||||
|
|
||||||
|
const publishYmlPath = path.join(process.cwd(), '.woodpecker', 'publish.yml');
|
||||||
|
const ciYmlPath = path.join(process.cwd(), '.woodpecker', 'ci.yml');
|
||||||
|
|
||||||
|
async function readPublishPipeline() {
|
||||||
|
return parseYaml(await readFile(publishYmlPath, 'utf8'));
|
||||||
|
}
|
||||||
|
|
||||||
|
// A step has an external publication effect when its name starts with
|
||||||
|
// `publish` or when any command pushes an image to a registry.
|
||||||
|
function pushesImage(step) {
|
||||||
|
return (step.commands ?? []).some((command) =>
|
||||||
|
/(^|\s)(\/kaniko\/executor|docker push)\b|--destination/.test(command),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
function publishEffectSteps(pipeline) {
|
||||||
|
return Object.entries(pipeline.steps ?? {})
|
||||||
|
.filter(([name, step]) => name.startsWith('publish') || pushesImage(step))
|
||||||
|
.map(([name]) => name);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Transitive closure of a step's depends_on graph.
|
||||||
|
function dependencyClosure(pipeline, stepName, seen = new Set()) {
|
||||||
|
const dependencies = pipeline.steps?.[stepName]?.depends_on ?? [];
|
||||||
|
for (const dependency of dependencies) {
|
||||||
|
if (seen.has(dependency)) continue;
|
||||||
|
seen.add(dependency);
|
||||||
|
dependencyClosure(pipeline, dependency, seen);
|
||||||
|
}
|
||||||
|
return seen;
|
||||||
|
}
|
||||||
|
|
||||||
|
function verifyCommands(pipeline) {
|
||||||
|
const verify = pipeline.steps?.verify;
|
||||||
|
assert.ok(verify, 'publish pipeline must define a `verify` step');
|
||||||
|
assert.ok(Array.isArray(verify.commands), '`verify` step must have commands');
|
||||||
|
return verify.commands;
|
||||||
|
}
|
||||||
|
|
||||||
|
function assertCommitIdentityAssertion(commands) {
|
||||||
|
const text = commands.join('\n');
|
||||||
|
assert.match(
|
||||||
|
text,
|
||||||
|
/CI_COMMIT_SHA/,
|
||||||
|
'`verify` must compare the provider commit identity (CI_COMMIT_SHA)',
|
||||||
|
);
|
||||||
|
assert.match(text, /git rev-parse HEAD/, '`verify` must compare against git rev-parse HEAD');
|
||||||
|
assert.match(
|
||||||
|
text,
|
||||||
|
/exit 1/,
|
||||||
|
'`verify` must fail closed (exit 1) on identity mismatch or emptiness',
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
function assertCanonicalCommand(commands) {
|
||||||
|
assert.ok(
|
||||||
|
commands.some((command) => /^pnpm verify:release\b/.test(command.trim())),
|
||||||
|
'`verify` must run the canonical terminal verification command `pnpm verify:release`',
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
function assertPublishGate(pipeline) {
|
||||||
|
assert.ok(pipeline.steps, 'publish pipeline must define steps');
|
||||||
|
|
||||||
|
const commands = verifyCommands(pipeline);
|
||||||
|
assertCommitIdentityAssertion(commands);
|
||||||
|
assertCanonicalCommand(commands);
|
||||||
|
|
||||||
|
const effects = publishEffectSteps(pipeline);
|
||||||
|
assert.ok(effects.length > 0, 'publish pipeline must contain publish effect steps to guard');
|
||||||
|
|
||||||
|
for (const stepName of effects) {
|
||||||
|
const step = pipeline.steps[stepName];
|
||||||
|
assert.ok(
|
||||||
|
Array.isArray(step.depends_on) && step.depends_on.includes('verify'),
|
||||||
|
`publish effect '${stepName}' must depend DIRECTLY on the verify step (SDLC-D-034: transitively through build is not enough)`,
|
||||||
|
);
|
||||||
|
assert.ok(
|
||||||
|
dependencyClosure(pipeline, stepName).has('verify'),
|
||||||
|
`publish effect '${stepName}' must depend on a chain that includes verify`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return effects;
|
||||||
|
}
|
||||||
|
|
||||||
|
test('the publish pipeline gates every publish effect behind exact-commit verification', async () => {
|
||||||
|
const pipeline = await readPublishPipeline();
|
||||||
|
const effects = assertPublishGate(pipeline);
|
||||||
|
assert.deepEqual(effects.sort(), [
|
||||||
|
'build-appservice',
|
||||||
|
'build-gateway',
|
||||||
|
'build-web',
|
||||||
|
'publish-next-npm',
|
||||||
|
'publish-npm',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the verify step carries no path/event short-circuit of its own', async () => {
|
||||||
|
const pipeline = await readPublishPipeline();
|
||||||
|
// A `when` filter on `verify` would let a publish effect fire on an event
|
||||||
|
// class that skipped verification — the gate must be unconditional.
|
||||||
|
assert.equal(pipeline.steps.verify.when, undefined);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a publish step that bypasses verify fails the gate checker', () => {
|
||||||
|
// Negative fixture: a plausible publish pipeline where `publish-npm` hangs
|
||||||
|
// off `build` only and `build` never chains to `verify` — the exact bypass
|
||||||
|
// class SDLC-D-034 closes. The checker must go red on it.
|
||||||
|
const bypassingPipeline = `
|
||||||
|
steps:
|
||||||
|
install:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- pnpm install --frozen-lockfile
|
||||||
|
verify:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- |
|
||||||
|
if [ -z "$CI_COMMIT_SHA" ] || [ "$CI_COMMIT_SHA" != "$(git rev-parse HEAD)" ]; then
|
||||||
|
echo "identity mismatch" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
- pnpm verify:release
|
||||||
|
depends_on:
|
||||||
|
- install
|
||||||
|
build:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- pnpm build
|
||||||
|
depends_on:
|
||||||
|
- install
|
||||||
|
publish-npm:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- pnpm publish
|
||||||
|
depends_on:
|
||||||
|
- build
|
||||||
|
`;
|
||||||
|
assert.throws(
|
||||||
|
() => assertPublishGate(parseYaml(bypassingPipeline)),
|
||||||
|
/publish-npm.*DIRECTLY.*verify/s,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a publish step chained to verify only transitively fails the gate checker', () => {
|
||||||
|
// Negative fixture: `build` depends on verify but `publish-npm` does not
|
||||||
|
// carry the direct edge — weaker than SDLC-D-034 requires of the real DAG.
|
||||||
|
const transitiveOnlyPipeline = `
|
||||||
|
steps:
|
||||||
|
install:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- pnpm install --frozen-lockfile
|
||||||
|
verify:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- |
|
||||||
|
if [ -z "$CI_COMMIT_SHA" ] || [ "$CI_COMMIT_SHA" != "$(git rev-parse HEAD)" ]; then
|
||||||
|
echo "identity mismatch" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
- pnpm verify:release
|
||||||
|
depends_on:
|
||||||
|
- install
|
||||||
|
build:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- pnpm build
|
||||||
|
depends_on:
|
||||||
|
- install
|
||||||
|
- verify
|
||||||
|
publish-npm:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- pnpm publish
|
||||||
|
depends_on:
|
||||||
|
- build
|
||||||
|
`;
|
||||||
|
assert.throws(
|
||||||
|
() => assertPublishGate(parseYaml(transitiveOnlyPipeline)),
|
||||||
|
/publish-npm.*DIRECTLY.*verify/s,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('a verify step without the commit-identity assertion fails the gate checker', () => {
|
||||||
|
const noIdentityPipeline = `
|
||||||
|
steps:
|
||||||
|
verify:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- pnpm verify:release
|
||||||
|
publish-npm:
|
||||||
|
image: node:24-alpine
|
||||||
|
commands:
|
||||||
|
- pnpm publish
|
||||||
|
depends_on:
|
||||||
|
- verify
|
||||||
|
`;
|
||||||
|
assert.throws(() => assertPublishGate(parseYaml(noIdentityPipeline)), /CI_COMMIT_SHA/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the canonical verify:release stages mirror the PR CI pipeline one-for-one', async () => {
|
||||||
|
const ci = parseYaml(await readFile(ciYmlPath, 'utf8'));
|
||||||
|
const canonical = Object.fromEntries(STAGES.map((stage) => [stage.name, stage.commands]));
|
||||||
|
|
||||||
|
// The complete mandatory set, in gate order.
|
||||||
|
assert.deepEqual(
|
||||||
|
STAGES.map((stage) => stage.name),
|
||||||
|
['sanitization', 'upgrade-guard', 'typecheck', 'lint', 'format', 'test', 'build'],
|
||||||
|
);
|
||||||
|
|
||||||
|
// Guard stages: ci.yml commands minus its `apk add` environment prep must be
|
||||||
|
// exactly the canonical stage commands (order included).
|
||||||
|
for (const stageName of ['sanitization', 'upgrade-guard']) {
|
||||||
|
assert.deepEqual(
|
||||||
|
ci.steps[stageName].commands.filter((command) => !command.startsWith('apk add')),
|
||||||
|
canonical[stageName],
|
||||||
|
`canonical '${stageName}' stage must match the ci.yml step`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// pnpm stages: ci.yml commands minus `corepack enable` must be exactly the
|
||||||
|
// canonical stage commands.
|
||||||
|
for (const stepName of ['typecheck', 'lint', 'format']) {
|
||||||
|
assert.deepEqual(
|
||||||
|
ci.steps[stepName].commands.filter((command) => command !== 'corepack enable'),
|
||||||
|
canonical[stepName],
|
||||||
|
`canonical '${stepName}' stage must match the ci.yml step`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
// The test stage is shared, but ci.yml wraps it in pipeline-level
|
||||||
|
// prerequisites the canonical command expects its caller to provide
|
||||||
|
// (SDLC-D-034): the postgres service + readiness wait + db:migrate, openssl,
|
||||||
|
// and the pinned pi runtime. None of those may be dropped silently.
|
||||||
|
for (const command of canonical.test) {
|
||||||
|
assert.ok(
|
||||||
|
ci.steps.test.commands.includes(command),
|
||||||
|
`ci.yml test step must run the canonical test stage command '${command}'`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
for (const fragment of [
|
||||||
|
'pg_isready -h ci-postgres',
|
||||||
|
'pnpm --filter @mosaicstack/db run db:migrate',
|
||||||
|
'npm install -g @earendil-works/[email protected]',
|
||||||
|
]) {
|
||||||
|
assert.ok(
|
||||||
|
ci.steps.test.commands.some((command) => command.includes(fragment)),
|
||||||
|
`ci.yml test step must keep its pipeline-level prerequisite '${fragment}'`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test('the root package.json exposes verify:release as the canonical command', async () => {
|
||||||
|
const packageJson = JSON.parse(await readFile(path.join(process.cwd(), 'package.json'), 'utf8'));
|
||||||
|
assert.match(packageJson.scripts['verify:release'], /scripts\/verify-release\.mjs/);
|
||||||
|
});
|
||||||
Reference in New Issue
Block a user