Compare commits

..
Author SHA1 Message Date
be-coder-08 379619d71f fix(ci): remove upgrade rollback signal race
ci/woodpecker/pr/ci Pipeline was successful
2026-08-05 16:52:35 -05:00
25 changed files with 287 additions and 4141 deletions
-68
View File
@@ -1,68 +0,0 @@
# C1 detector gate. The fixture itself is intentionally RED; CI is green only
# when its exact phase verdicts/reasons match the versioned expected-RED manifest.
when:
- event: [pull_request, manual]
- event: push
branch: [next, main]
steps:
greenfield-git-present:
image: node:22-bookworm-slim
commands:
- |
set +e
MOSAIC_GREENFIELD_CONTAINER=1 \
bash tools/e2e-install-test.sh --lane next --source checkout --git present \
> /tmp/greenfield-git-present.log 2>&1
fixture_status=$?
set -e
cat /tmp/greenfield-git-present.log
bash tools/verify-greenfield-expected-red.sh \
next-git-present /tmp/greenfield-git-present.log "$fixture_status"
greenfield-main-git-present:
image: node:22-bookworm-slim
commands:
- |
set +e
MOSAIC_GREENFIELD_CONTAINER=1 \
bash tools/e2e-install-test.sh --lane main --source checkout --git present \
> /tmp/greenfield-main-git-present.log 2>&1
fixture_status=$?
set -e
cat /tmp/greenfield-main-git-present.log
bash tools/verify-greenfield-expected-red.sh \
main-git-present /tmp/greenfield-main-git-present.log "$fixture_status"
greenfield-remote-installer-contract:
image: node:22-bookworm-slim
commands:
- |
expected="$(awk 'NF {print $1; exit}' tools/install.sh.sha256)"
actual="$(sha256sum tools/install.sh | awk '{print $1}')"
test "$actual" = "$expected"
set +e
MOSAIC_GREENFIELD_CONTAINER=1 \
MOSAIC_FIXTURE_INSTALLER_URL="https://git.mosaicstack.dev/mosaicstack/stack/raw/commit/${CI_COMMIT_SHA}/tools/install.sh" \
MOSAIC_FIXTURE_INSTALLER_SHA256="$expected" \
bash tools/e2e-install-test.sh --lane next --source remote --git present \
> /tmp/greenfield-remote.log 2>&1
fixture_status=$?
set -e
cat /tmp/greenfield-remote.log
bash tools/verify-greenfield-expected-red.sh \
next-git-present /tmp/greenfield-remote.log "$fixture_status"
greenfield-git-absent:
image: node:22-bookworm-slim
commands:
- |
set +e
MOSAIC_GREENFIELD_CONTAINER=1 \
bash tools/e2e-install-test.sh --lane next --source checkout --git absent \
> /tmp/greenfield-git-absent.log 2>&1
fixture_status=$?
set -e
cat /tmp/greenfield-git-absent.log
bash tools/verify-greenfield-expected-red.sh \
next-git-absent /tmp/greenfield-git-absent.log "$fixture_status"
+21 -32
View File
@@ -7,21 +7,20 @@ Mosaic gives you a unified launcher for Claude Code, Codex, OpenCode, and Pi —
## Quick Install
```bash
d="$(mktemp -d)" && trap 'rm -rf "$d"' EXIT && curl -fsSL -o "$d/install.sh" https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh -o "$d/install.sh.sha256" https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh.sha256 && (cd "$d" && test -s install.sh && sha256sum -c install.sh.sha256 && bash install.sh)
curl -fsSL https://mosaicstack.dev/install.sh | bash
```
The published installer body must be non-empty and match its versioned SHA-256
sidecar before it executes. A failed fetch, HTTP-200 empty body, or digest
mismatch is fatal. Because both files come from the same repository and trust
domain, this detects corruption or inconsistent publication—not repository or
server compromise. Independently signed release provenance is explicitly
deferred by the greenfield-install PRD.
Or use the direct URL:
```bash
bash <(curl -fsSL https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh)
```
The installer auto-launches the setup wizard, which walks you through gateway install and verification. Flags for non-interactive use:
```bash
(cd "$d" && bash install.sh --yes) # Accept all defaults
(cd "$d" && bash install.sh --yes --no-auto-launch) # Install only, skip wizard
bash <(curl -fsSL …) --yes # Accept all defaults
bash <(curl -fsSL …) --yes --no-auto-launch # Install only, skip wizard
```
This installs both components:
@@ -31,16 +30,6 @@ This installs both components:
| **Framework** | Bash launcher, guides, runtime configs, tools, skills | `~/.config/mosaic/` |
| **@mosaicstack/mosaic** | Unified `mosaic` CLI — TUI, gateway client, wizard, auto-updater | `~/.npm-global/bin/` |
### Install lanes
| Lane | Command | Use when | Source |
| ------------------------ | ------------------------------------- | ----------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| Stable | `bash tools/install.sh` | You want the released Mosaic CLI/framework | npm registry `@mosaicstack/mosaic@latest` + framework archive at `main` |
| Prerelease integration | `bash tools/install.sh --next` | You want the current `next` integration branch | Exact `@next` CLI/gateway versions + pinned `next` framework commit; pinned-source fallback |
| Contributor/source build | `bash tools/install.sh --dev --ref X` | You are testing a branch before release; `--ref` wins | Build-from-source at the requested ref |
`--next` selects the prerelease integration lane. It installs the exact CLI/gateway versions resolved from the aligned `@next` tags, and pins the framework archive to the resolved `next` commit. If the registry path fails, it builds from that pinned source. An explicit `--ref` or `MOSAIC_REF` wins and selects source mode.
After install, the wizard runs automatically or you can invoke it manually:
```bash
@@ -49,14 +38,10 @@ mosaic wizard # Full guided setup (gateway install → verify)
### Requirements
- Linux x86_64 with glibc (Debian is the greenfield CI platform; musl/Alpine, macOS, and ARM64 currently fail as unsupported)
- Node.js ≥ 20 and npm ≥ 9
- `bash`, `curl`, `git`, `python3`, `tar`, and standard core utilities (`awk`, `df`, `find`, `flock`, `grep`, `install`, `realpath`, `sed`, `sha256sum`, `stat`, `sync`)
- At least 256 MiB free disk and 1,000 free inodes at the npm prefix
- Node.js ≥ 20
- npm (for global @mosaicstack/mosaic install)
- One or more runtimes: [Claude Code](https://docs.anthropic.com/en/docs/claude-code), [Codex](https://github.com/openai/codex), [OpenCode](https://opencode.ai), or [Pi](https://github.com/mariozechner/pi-coding-agent)
The installer evaluates canonical phases P0P9 and does not print `Done.` unless every committed postcondition passes. A failed phase exits non-zero, names the phase, and points to its durable journal under `${XDG_STATE_HOME:-~/.local/state}/mosaic/install/`. See [Installer state machine and recovery](docs/guides/installer-state-machine.md).
## Usage
### Launching Agent Sessions
@@ -349,10 +334,16 @@ Each stage has a dispatch mode (`exec` for research/review, `yolo` for coding),
## Upgrading
Run the same verified installer flow again — it handles upgrades automatically:
Run the installer again — it handles upgrades automatically:
```bash
d="$(mktemp -d)" && trap 'rm -rf "$d"' EXIT && curl -fsSL -o "$d/install.sh" https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh -o "$d/install.sh.sha256" https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh.sha256 && (cd "$d" && test -s install.sh && sha256sum -c install.sh.sha256 && bash install.sh)
curl -fsSL https://mosaicstack.dev/install.sh | bash
```
Or use the direct URL:
```bash
bash <(curl -fsSL https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/main/tools/install.sh)
```
Or use the CLI:
@@ -367,17 +358,15 @@ The CLI also performs a background update check on every invocation (cached for
### Installer Flags
```bash
bash tools/install.sh --check # Side-effect-free P0-P8 postcondition check
bash tools/install.sh --check # Version check only
bash tools/install.sh --framework # Framework only (skip npm CLI)
bash tools/install.sh --cli # npm CLI only (skip framework)
bash tools/install.sh --next # Prerelease lane: exact @next versions + pinned-source fallback
bash tools/install.sh --dev # Contributor lane: source build at --ref/main
bash tools/install.sh --ref v1.0 # Install from a specific git ref (--ref wins over --next)
bash tools/install.sh --ref v1.0 # Install from a specific git ref
bash tools/install.sh --yes # Non-interactive, accept all defaults
bash tools/install.sh --no-auto-launch # Skip auto-launch of wizard
```
The installer rejects unrecognized flags or positional arguments before making changes and prints the supported-option usage. `--check` reports one PASS/FAIL row for each P0P8 predicate and exits non-zero if any row fails; it does not create the npm prefix, lock, journal, manifest, or runtime files.
The installer rejects unrecognized flags or positional arguments before making changes and prints the supported-option usage.
## Contributing
-39
View File
@@ -1368,42 +1368,3 @@ All work is **alpha** (< 0.1.0) until Jason approves 0.1.0 beta release.
10. ASSUMPTION: **Conversations and messages get their own PG tables** (not stored in brain's entity model). They follow a chat-specific schema with proper foreign keys to users and projects. Rationale: Chat has different access patterns (streaming, pagination, search) than brain entities.
11. RESOLVED: **Pi handles all target LLM providers natively.** Anthropic, OpenAI/Codex, Z.ai, Ollama, LM Studio, and llama.cpp are all supported via Pi's built-in providers or `models.json` configuration with `openai-completions` API type. No custom provider adapters needed in @mosaicstack/agent — only configuration management.
---
## Greenfield install correctness — C1 (#1050)
### Problem and objective
A from-zero install can report success while leaving the target host unusable because the installer has no transactional state machine capable of certifying its own postconditions. C1 supplies the structural spine and red-first fixture; later cards repair the individual failed postconditions.
### Normative requirements
1. The installer SHALL implement the canonical P0P9 numbering from the greenfield-install PRD v2: P0 Resolve context; P1 Preflight; P2 Acquire artifacts; P3 Install CLI; P4 Install framework + skills; P5 Identity; P6 Runtime linking / activation; P7 Services; P8 Shell discoverability; P9 Verify + commit. P2 is scoped to installer-distribution artifacts and SHALL NOT foreclose credentialed downstream acquisition. P5 owns validating any credential capability required by requested downstream work; P7 may provision credential-dependent resources only after that P5 postcondition commits.
2. Every phase SHALL declare preconditions, action, committed postconditions, and rollback. An unverifiable postcondition SHALL fail the install non-zero with the named phase and a remediation line; no best-effort failure may still certify success. P1's required-tool closure includes tools invoked by later phases, including `git`; a downstream prerequisite may not remain undeclared and degrade silently.
3. A durable mutation journal SHALL open before the first mutation and commit at P9. Fallible command output needed to diagnose a phase SHALL be journaled and surfaced, never discarded.
4. `--check` SHALL run exactly the P0P8 postcondition predicates without mutation, report each phase PASS/FAIL, and exit non-zero if any predicate fails.
5. P4 SHALL consume a checkout-free, lane/versioned shipped-set declaration published by the installer. C1 SHALL NOT select among the currently disagreeing framework-payload, repository-root, sync-source, and W-jarvis populations; while no declaration exists, P4 reports `NOT-MEASURED / UNDECLARED` and remains blocking rather than fabricating a count. C5 owns the declaration's contents and containment/loadability fulfillment.
6. The from-zero fixture SHALL be lane-parametric, use Debian/glibc, run the documented install command as a non-root target user with an isolated HOME, and inherit no host credentials, npm cache, home directory, or runtime configuration.
7. The fixture SHALL select `next` with `--next` or `MOSAIC_NEXT=1` and assert the resolved lane version. Internal predicates use P3's absolute CLI path; shell discoverability is tested only at P8.
8. Fault injection after each P2P8 phase SHALL prove either clean rollback or a durable, honestly reported resumable partial state, with no journal incorrectly left in progress.
9. Unsupported musl/Alpine and unavailable Docker SHALL fail loudly rather than skip as pass. The repository's installer tests SHALL nevertheless run in the canonical Alpine CI image by explicitly modeling a supported non-root/glibc target and using portable filesystem enumeration.
10. P0 SHALL bind the effective uid and username to the authoritative passwd HOME and shell and state/reject unsafe root or sudo-with-inherited-HOME privilege contexts.
11. Created paths SHALL satisfy phase-specific target owner/group and mode policy: P3 executables are not group/world writable, framework/runtime trees are not group/world writable, and identity/credential material is private.
12. The expected-RED comparator SHALL validate the complete manifest before selecting a case: exact case population, one exit and P0P9 disposition per case, pinned require/forbid classes, and no malformed, duplicate, or unknown rows.
13. The published installer contract SHALL reject failed fetches, HTTP-success empty bodies, and digest mismatch, then execute the exact digest-verified body. The remote CI arm SHALL bind that body to the immutable CI commit.
14. Phase diagnostics SHALL be redacted before terminal or durable-log output. A seeded positive-control canary SHALL remain absent from observed argv, output, command logs, npm configuration, generated files, and shell history.
### C1 acceptance criteria
1. The pre-C1 from-zero matrix records both discriminating controls: with `git` absent, the legacy installer still exits zero while P1 fails and skill sync degrades; with `git` present, P1 passes and the observed sync store/runtime links are 101/101. The C1 installer must fail at P1 before mutation when `git` is absent.
2. The discriminating P3 row passes: the binary exists at the expected absolute path and reports exactly the resolved `next` lane version, while P4, P5, and P8 fail.
3. The `--check` mutation negative control proves host fingerprints are byte-identical before and after observation.
4. Woodpecker executes and validates the expected RED fixture plus the immutable remote-installer contract; C1 does not repair P4/P5/P8 or activate #869.
5. Negative controls prove manifest shrink/duplicates/unknown rows fail, unsafe P0/P3/P4/P5 contexts fail, the P2P8 fault seam enters real actions rather than synthetic writes, empty/mismatched fetched bodies fail, and a deliberately emitted secret canary is redacted from every persisted/output population.
### Explicit exclusions and dependencies
- C2 owns P8/PATH, C3 owns P5/headless identity, C4 owns P6 activation policy, and C5 owns P4/skills.
- Main-lane execution is a promotion precondition owned by #1037; C1 only makes the fixture lane-parametric.
- RM-02 and #869 activation are out of scope.
-5
View File
@@ -9,11 +9,6 @@
- [Whole mutator-class gate](architecture/mutator-class-gate.md) — default-deny policy, revoke-first/promote-last state machine, TTL, runtime adapters, and T-B/T-C assurance boundary.
- [Compaction revocation lifecycle](architecture/compaction-revocation.md) — Claude/Pi observer matrix, same-PID generation rollover, failure fencing, and the named bounded residual stale window.
## Installation and upgrades
- [Installer state machine and recovery](guides/installer-state-machine.md) — canonical P0P9 phases, side-effect-free checks, durable journal states, rollback/remediation, and the Debian greenfield CI gate.
- [Upgrade safety and recovery](guides/upgrade-safety-and-recovery.md) — framework ownership, durable operator snapshots, verify net, and projection regeneration.
## CLI and skill management
- [Skill registration user guide](guides/user-guide.md#claude-code-skill-registration) — register, unregister, list statuses, automatic install/update reconciliation, and Claude reload behavior.
-99
View File
@@ -1,99 +0,0 @@
# Installer State Machine and Recovery
The unified installer uses a transactional P0P9 model. It may report success only after P9 reasserts every applicable committed postcondition. Internal phases invoke the CLI by P3's absolute path; shell discovery is checked only at P8.
## Canonical phases
| Phase | Responsibility | Failure disposition |
| ------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| P0 Resolve context | Bind uid/username to the authoritative passwd HOME/shell, state privilege mode, architecture, libc, Node, and npm | Fail before mutation |
| P1 Preflight | Validate downstream tool closure (including `git` and `python3`), writable prefix, registry lane, disk/inodes, and exclusive lock | Fail before target mutation |
| P2 Acquire artifacts | Resolve exact registry versions and an immutable framework commit; record lane and SHA-256 | Discard temporary work |
| P3 Install CLI | Install at the configured absolute prefix; require exact version plus target owner/group and non-writable executable mode | Restore the prior prefix/npmrc snapshot |
| P4 Install framework + skills | Sync framework and consume a checkout-free, lane/versioned shipped-skill declaration | Restore prior framework/runtime trees |
| P5 Identity | Validate SOUL/USER content and private modes; require private credential storage and target owner/group | Restore generated identity/credential binding |
| P6 Runtime linking / activation | Evaluate activation honestly; never treat dead enforcement hooks as active readiness | Restore runtime activation files |
| P7 Services | Provision only requested services/resources after any required P5 credential commits | Stop and restore requested services/resources |
| P8 Shell discoverability | Require fresh login and non-login shells of the actual target shell to resolve P3's path | Restore shell profiles |
| P9 Verify + commit | Re-run P0P8, commit the manifest, and seal the journal | Leave an honestly reported resumable failure or restore the pre-install snapshot |
The phase numbers are a cross-workstream contract and must not be renumbered.
## Side-effect-free check
```bash
bash tools/install.sh --check # stable/latest lane
bash tools/install.sh --check --next # prerelease lane
```
`--check`:
- emits exactly one `[P0]` through `[P8]` PASS/FAIL row;
- exits non-zero if any predicate fails;
- does not create the npm prefix, lock, journal, manifest, shell profile, or runtime file;
- uses temporary npm observation storage outside the target HOME and removes it before exit.
P4 currently fails as `NOT-MEASURED / UNDECLARED` until the installer publishes `~/.config/mosaic/.install-shipped-skills.json`. C1 deliberately does not select among the conflicting candidate populations; C5 owns publishing and fulfilling that declaration. Once present, the P4 predicate requires the declaration's lane/version to match the resolved install and every named skill to remain contained under `skills/<name>/SKILL.md` with matching loadable frontmatter.
## Durable journal
Each mutating run creates a private transaction directory:
```text
${XDG_STATE_HOME:-~/.local/state}/mosaic/install/
active.json
<UTC-run-id>/
journal.ndjson
journal.ndjson.sha256 # committed runs only
commands.log
snapshot/
```
Before each mutation scope is touched, `journal.ndjson` records:
- phase and path;
- whether prior state existed and where its snapshot lives;
- the reversal action;
- the captured command-output location and command status.
Journal, action-status, manifest, or command-log write/sync failure is fatal. An unrecorded mutation is not allowed. Command diagnostics are redacted before terminal output or durable logging; credential-shaped environment values, bearer values, auth tokens, and credentialed URLs are never deliberately persisted. Successful P9 runs append a seal event, write the SHA-256 sidecar, and make the journal and sidecar read-only. Required P4/P6 action failures are persisted in the manifest so a later `--check` cannot turn a failed action into a false pass.
Rollback roots must be non-overlapping, non-symlinked, target-user-owned strict descendants of canonical `HOME`; unsafe custom `MOSAIC_HOME`/`MOSAIC_PREFIX` values fail at P0. The same validation runs again immediately before recursive rollback. The OS lock is concurrency authority: if a process dies while `active.json` still says `in-progress`, a retry that acquires the free lock preserves the stale projection as `prior-active.json` and proceeds from the honestly retained partial state.
`active.json` is the current projection:
- `in-progress`: incomplete/open transaction;
- `rolled-back`: a fault restored the snapshot;
- `rollback-failed`: restoration failed or refused a replaced/unsafe target and requires manual recovery;
- `failed-resumable`: named postconditions failed and the recorded partial state remains for remediation;
- `committed`: P9 passed and the journal is sealed.
## Failure recovery
1. Read the named phase and remediation line from installer stderr.
2. Inspect `active.json`, then the referenced `journal.ndjson` and `commands.log`. Command output needed to diagnose a failure is preserved and surfaced; it is not redirected away.
3. For `rolled-back`, verify the target paths match their pre-install state before retrying.
4. For `failed-resumable`, repair the named phase owner requirement, then run `install.sh --check` before retrying the installer.
5. Do not activate the #869 enforcement hooks merely to turn P6 green. A broker-less host with those hooks is a failed P6 state.
## Greenfield CI gate
`.woodpecker/greenfield-install.yml` runs `tools/e2e-install-test.sh` from zero in Debian/glibc as a non-root uid with `env -i`. No host HOME, npm cache, credentials, or bind mount enters the target process. Checkout mode packages the complete current checkout into an archive, pins its SHA-256 through an internal fixture seam, and copies the self-contained fixture into the container; framework-installer changes in the PR are therefore exercised rather than fetched from an older remote branch.
The C1 fixture intentionally returns an attributable RED while C2C5 remain open. CI itself remains green only when the fixture's final P0P9 verdicts, required discriminator rows, seeded secret-canary scan, and non-zero exit match the versioned contract in `tools/fixtures/greenfield-expected-red.tsv`. The comparator validates the complete three-case schema before selecting a case: exactly one exit and P0P9 disposition per case, pinned require/forbid populations, and no duplicate or unknown rows. Any later remediation that changes an observed verdict makes CI red until the owning lane deliberately updates that manifest:
- `git` present: P1 and strict P3 pass; P4/P5/P6/P8 fail for their own reasons; P9 refuses success.
- `git` absent: P1 fails before target mutation and the installer emits no `Done.`.
The fixture is lane-parametric:
```bash
bash tools/e2e-install-test.sh --lane next --git present
bash tools/e2e-install-test.sh --lane main --git present
```
CI exercises both lane parameters as expected-RED structural checks. A separate remote-contract arm fetches the installer at the immutable CI commit, rejects failed or empty HTTP-success bodies, compares it to the reviewed `tools/install.sh.sha256`, and executes that exact fetched artifact. The P2P8 fault matrix runs the real phase actions (including the P3 npm path, P4 framework path, and wizard path) rather than synthetic representative writes, then compares the complete target tree to its pre-install fingerprint. Delivery targets `main` under the trunk-only merge rule; `next` remains a non-merging integration lane. The linked installer issue stays open after merge and closes only after Jarvis independently validates the greenfield behavior.
## Source trust boundary
Remote installer mode requires a non-empty body and an expected SHA-256 before execution. Remote source-archive mode separately pins the resolved commit, records the archive SHA-256, limits compressed/expanded size and entry count, and rejects traversal, links, devices, and special files before extraction. These controls provide immutable run provenance and archive safety, not an independent signing root. Signed artifact metadata/provenance is explicitly deferred by the canonical greenfield PRD; C1 does not invent a signing system. The checkout and remote CI seams verify reviewed digests before executing their artifacts.
@@ -12,20 +12,6 @@ with no snapshot to fall back to.
Protection is layered. Each layer is independent; a later layer catches what an
earlier one misses.
## Layer 0 — Transaction journal (install-wide recovery)
The unified installer opens a private journal under
`${XDG_STATE_HOME:-~/.local/state}/mosaic/install/` before the first target
mutation. Every mutation scope records its path, prior snapshot, and reversal
instructions before it is touched. Journal write/sync failure is fatal, and P9
seals successful journals with a SHA-256 sidecar. See
[Installer state machine and recovery](./installer-state-machine.md).
This transaction journal is distinct from the retained operator-only backup
below. The transaction journal is required for correctness and rollback;
Layer 2's durable backup remains a separately stated, fail-open recovery bonus
for a manifest bug that the normal transaction did not detect.
## Layer 1 — Manifest-owned sync (prevention)
The single source of truth for ownership is
@@ -1,14 +0,0 @@
subject_head=3edde464b3891ad439019fcc19aad7728e4c2fb8
source=git show HEAD:tools/install-next-lane.test.sh
477 echo 'credentialed URL userinfo leaked to terminal output' >&2; exit 1
478 fi
479 [[ "$(grep -oF '[REDACTED]@' <<<"$OUTPUT" | wc -l | tr -d ' ')" -ge 5 ]] \
480 || { echo 'credentialed URL redaction controls were not all exercised' >&2; exit 1; }
481 secret_active="$TMP/secret-state/active.json"
--
525 echo 'framework nested capture leaked credential diagnostics' >&2; exit 1
526 fi
527 [[ "$(grep -oF '[REDACTED]@' "$framework_log" | wc -l | tr -d ' ')" -ge 5 ]] \
528 || { echo 'framework URL redaction controls were not exercised' >&2; exit 1; }
529
@@ -1,16 +0,0 @@
source=/tmp/c1-ci-next-x.log (exact failing canonical-image xtrace)
credential material is already replaced by the redactor token [REDACTED]; no live secret is reproduced
urls=https://[REDACTED]@example.com/a https://[REDACTED]@example.net/b https://[REDACTED]@example.org/c https://[REDACTED]@example.dev/d https://[REDACTED]@example.io/e
urls=https://[REDACTED]@example.com/a https://[REDACTED]@example.net/b https://[REDACTED]@example.org/c https://[REDACTED]@example.dev/d https://[REDACTED]@example.io/e
line_count=2
occurrence_count=10
observed_assertion_value=2 (from xtrace: [[ 2 -ge 5 ]])
canonical-image discriminator (same locally cached digest as failing run):
image_id=sha256:d40fb1a218b72d3dcbf8a427a5076facf2a6d958b6854e6bbd057f7264540841 repo_digests=["git.mosaicstack.dev/mosaicstack/stack/ci-base@sha256:0f1d996a6cfcc09e6dcf979ee66c872a1b0be4f1bfde852b4790f520ddd0d776"]
busybox=BusyBox v1.37.0 (2026-01-10 15:38:28 UTC)
regex_-o_single_line=5
fixed_-oF_single_line=1
fixed_-oF_two_lines=2
@@ -1,14 +0,0 @@
positive_control_exit=1
seeded_line=https://[MASKED-USERINFO]@example.io/e (actual synthetic userinfo intentionally omitted here)
expected_failure=credentialed URL redaction control missing for example.io
transcript_tail:
[test] --next fast path pins resolved package versions
[test] fast path failure falls back to source build
[test] source-build failure is fatal and restores the pre-install prefix
[test] corrupt source archive is fatal and restores the pre-install prefix
[test] --dev source install does not require registry version resolution
[test] explicit --ref keeps source lane and avoids @next lookup
[test] --check --next rejects mismatched prerelease pipeline suffixes
[test] full framework path receives P3 absolute CLI without relying on PATH
[test] captured diagnostics redact seeded credential canary everywhere
credentialed URL redaction control missing for example.io
@@ -1,10 +0,0 @@
[test] --next fast path pins resolved package versions
[test] fast path failure falls back to source build
[test] source-build failure is fatal and restores the pre-install prefix
[test] corrupt source archive is fatal and restores the pre-install prefix
[test] --dev source install does not require registry version resolution
[test] explicit --ref keeps source lane and avoids @next lookup
[test] --check --next rejects mismatched prerelease pipeline suffixes
[test] full framework path receives P3 absolute CLI without relying on PATH
[test] captured diagnostics redact seeded credential canary everywhere
credentialed URL redaction control missing for example.io
@@ -1,578 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
ROOT="/work"
TMP="$(mktemp -d "${TMPDIR:-/tmp}/mosaic-next-install-test-XXXXXX")"
trap 'rm -rf "$TMP"' EXIT
export TMPDIR="$TMP/runtime-tmp"
mkdir -p "$TMPDIR"
FAKE_BIN="$TMP/bin"
HOME_DIR="$TMP/home"
PREFIX="$HOME_DIR/prefix"
MOSAIC_HOME="$HOME_DIR/mosaic"
STATE="$TMP/state"
LOG="$TMP/npm.log"
mkdir -p "$FAKE_BIN" "$HOME_DIR" "$STATE"
# Model the supported non-root/glibc target explicitly even when this harness
# itself runs as root in Alpine/BusyBox CI.
cat > "$FAKE_BIN/id" <<'FAKE_ID'
#!/usr/bin/env bash
case "${1:-}" in
-u) echo 1001 ;;
-g) echo 1001 ;;
-un) echo fixture-user ;;
*) exec /bin/id "$@" ;;
esac
FAKE_ID
cat > "$FAKE_BIN/getent" <<FAKE_GETENT
#!/usr/bin/env bash
printf 'fixture-user:x:1001:1001::%s:/bin/bash\n' '$HOME_DIR'
FAKE_GETENT
cat > "$FAKE_BIN/ldd" <<'FAKE_LDD'
#!/usr/bin/env bash
printf 'ldd (GNU libc) 2.36\n'
FAKE_LDD
cat > "$FAKE_BIN/stat" <<'FAKE_STAT'
#!/usr/bin/env bash
if [[ "${1:-} ${2:-}" == '-c %u' ]]; then
[[ "${3:-}" == "${MOSAIC_TEST_WRONG_OWNER_PATH:-__none__}" ]] && echo 9999 || echo 1001
exit 0
fi
if [[ "${1:-} ${2:-}" == '-c %g' ]]; then
[[ "${3:-}" == "${MOSAIC_TEST_WRONG_GROUP_PATH:-__none__}" ]] && echo 9999 || echo 1001
exit 0
fi
exec /bin/stat "$@"
FAKE_STAT
cat > "$FAKE_BIN/realpath" <<'FAKE_REALPATH'
#!/usr/bin/env python3
import os, sys
args=sys.argv[1:]
mode=args.pop(0) if args and args[0] in ('-e','-m') else '-m'
if args and args[0]=='--': args.pop(0)
if len(args)!=1 or (mode=='-e' and not os.path.exists(args[0])): raise SystemExit(1)
print(os.path.realpath(args[0]))
FAKE_REALPATH
chmod 0755 "$FAKE_BIN/id" "$FAKE_BIN/getent" "$FAKE_BIN/ldd" "$FAKE_BIN/stat" "$FAKE_BIN/realpath"
cat > "$FAKE_BIN/npm" <<'FAKE_NPM'
#!/usr/bin/env bash
set -euo pipefail
LOG="${MOSAIC_TEST_NPM_LOG:?}"
STATE="${MOSAIC_TEST_STATE:?}"
echo "$*" >> "$LOG"
if [[ "${1:-}" == "--version" ]]; then
echo "10.6.2"
exit 0
fi
install_cli() {
local version="$1"
echo "$version" > "$STATE/mosaic"
mkdir -p "${MOSAIC_PREFIX:?}/bin"
cat > "$MOSAIC_PREFIX/bin/mosaic" <<CLI
#!/usr/bin/env bash
set -euo pipefail
if [[ "\${1:-}" == "wizard" ]]; then
printf 'wizard\n' >> "\${MOSAIC_TEST_NPM_LOG:?}"
mkdir -p "\${MOSAIC_HOME:?}" "\${HOME:?}/.config/mosaic-gateway"
printf '# Soul\\n\\nConfigured.\\n' > "\$MOSAIC_HOME/SOUL.md"
printf '# User\\n\\nConfigured.\\n' > "\$MOSAIC_HOME/USER.md"
chmod 0600 "\$MOSAIC_HOME/SOUL.md" "\$MOSAIC_HOME/USER.md"
exit 0
fi
printf '%s\\n' '$version'
CLI
chmod +x "$MOSAIC_PREFIX/bin/mosaic"
}
if [[ "$1" == "view" ]]; then
if [[ "${MOSAIC_TEST_FAIL_NPM_VIEW:-0}" == "1" ]]; then
echo "forced registry metadata failure" >&2
exit 1
fi
case "$2 $3" in
"@mosaicstack/mosaic@next version") echo "0.0.49-next.999" ;;
"@mosaicstack/gateway@next version") echo "${MOSAIC_TEST_GATEWAY_NEXT_VERSION:-0.0.7-next.999}" ;;
"@mosaicstack/mosaic version") echo "0.0.48" ;;
*) echo "unexpected npm view: $*" >&2; exit 1 ;;
esac
exit 0
fi
if [[ "$1" == "install" ]]; then
if [[ -n "${MOSAIC_INSTALL_SECRET_CANARY:-}" ]]; then
printf 'registry diagnostic authToken=%s\n' "$MOSAIC_INSTALL_SECRET_CANARY"
printf 'urls=https://alice:p@[email protected]/a https://bob:pa:[email protected]/b https://carol:p%%[email protected]/c https://[email protected]/d https://public.example/e\n'
printf 'Authorization: Basic QWxhZGRpbjpvcGVu\n//registry/:_auth=Ym9iOnNlY3JldA==\nCookie: session=abc123\nSet-Cookie: sid=xyz789\n'
printf '%s\n' "$MOSAIC_INSTALL_SECRET_CANARY" > "${MOSAIC_TEST_CANARY_OBSERVATION:?}"
fi
case "$*" in
*"@mosaicstack/[email protected]"*)
install_cli "0.0.49-next.999"
;;
*"@mosaicstack/[email protected]"*)
if [[ "${MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL:-0}" == "1" ]]; then
echo "forced gateway install failure" >&2
exit 1
fi
echo "0.0.7-next.999" > "$STATE/gateway"
;;
*"mosaicstack-mosaic-0.0.0-source.tgz"*)
install_cli "0.0.0-source"
;;
*"mosaicstack-gateway-0.0.0-source.tgz"*)
echo "0.0.0-source" > "$STATE/gateway"
;;
*) echo "unexpected npm install: $*" >&2; exit 1 ;;
esac
exit 0
fi
if [[ "$1" == "ls" ]]; then
cli="$(cat "$STATE/mosaic" 2>/dev/null || true)"
gateway="$(cat "$STATE/gateway" 2>/dev/null || true)"
node -e '
const cli = process.argv[1];
const gateway = process.argv[2];
const dependencies = {};
if (cli) dependencies["@mosaicstack/mosaic"] = { version: cli };
if (gateway) dependencies["@mosaicstack/gateway"] = { version: gateway };
process.stdout.write(JSON.stringify({ dependencies }));
' "$cli" "$gateway"
exit 0
fi
echo "unexpected npm command: $*" >&2
exit 1
FAKE_NPM
chmod +x "$FAKE_BIN/npm"
cat > "$FAKE_BIN/curl" <<'FAKE_CURL'
#!/usr/bin/env bash
set -euo pipefail
headers=""; output=""; url=""
while [[ $# -gt 0 ]]; do
case "$1" in
-D) headers="$2"; shift 2 ;;
-o) output="$2"; shift 2 ;;
--max-filesize) shift 2 ;;
-*) shift ;;
*) url="$1"; shift ;;
esac
done
case "$url" in
*/api/v1/repos/mosaicstack/stack/commits?sha=*)
printf 'HTTP/1.1 200 OK\r\ncontent-type: application/json; charset=utf-8\r\n\r\n' > "$headers"
printf '[{"sha":"1111111111111111111111111111111111111111"}]\n' > "$output"
;;
*/archive/*.tar.gz)
if [[ "${MOSAIC_TEST_CORRUPT_ARCHIVE:-0}" == "1" ]]; then
printf 'not-a-tarball\n' > "$output"
else
archive_root="$(mktemp -d)"
mkdir -p "$archive_root/stack"
printf 'fixture\n' > "$archive_root/stack/.fixture"
/bin/tar czf "$output" -C "$archive_root" stack
rm -rf "$archive_root"
fi
;;
esac
FAKE_CURL
chmod +x "$FAKE_BIN/curl"
cat > "$FAKE_BIN/tar" <<'FAKE_TAR'
#!/usr/bin/env bash
set -euo pipefail
dest=""; list=false
while [[ $# -gt 0 ]]; do
case "$1" in
-C) dest="$2"; shift 2 ;;
-*t*|t*) list=true; shift ;;
*) shift ;;
esac
done
[[ "$list" == true ]] && exit 0
if [[ -z "$dest" ]]; then
echo "fake tar missing -C destination" >&2
exit 1
fi
mkdir -p "$dest/stack/packages/mosaic/framework" "$dest/stack/apps/gateway"
cat > "$dest/stack/packages/mosaic/framework/install.sh" <<'FRAMEWORK'
#!/usr/bin/env bash
set -euo pipefail
expected="${MOSAIC_PREFIX:?}/bin/mosaic"
[[ "${MOSAIC_CLI_PATH:-}" == "$expected" && -x "$MOSAIC_CLI_PATH" ]] || {
echo "framework did not receive P3 absolute CLI (got=${MOSAIC_CLI_PATH:-unset} expected=$expected)" >&2
exit 61
}
printf 'framework-cli=%s version=%s\n' "$MOSAIC_CLI_PATH" "$($MOSAIC_CLI_PATH --version)" >> "${MOSAIC_TEST_NPM_LOG:?}"
mkdir -p "${MOSAIC_HOME:?}/credentials"
chmod 0700 "$MOSAIC_HOME/credentials"
printf '# framework fixture\n' > "$MOSAIC_HOME/AGENTS.md"
FRAMEWORK
chmod 0755 "$dest/stack/packages/mosaic/framework/install.sh"
FAKE_TAR
chmod +x "$FAKE_BIN/tar"
cat > "$FAKE_BIN/pnpm" <<'FAKE_PNPM'
#!/usr/bin/env bash
set -euo pipefail
LOG="${MOSAIC_TEST_NPM_LOG:?}"
echo "pnpm $*" >> "$LOG"
if [[ "$1" == "pack" ]]; then
out=""
while [[ $# -gt 0 ]]; do
case "$1" in
--pack-destination) out="$2"; shift 2 ;;
*) shift ;;
esac
done
if [[ -z "$out" ]]; then
echo "fake pnpm pack missing destination" >&2
exit 1
fi
mkdir -p "$out"
case "$PWD" in
*/apps/gateway) touch "$out/mosaicstack-gateway-0.0.0-source.tgz" ;;
*/packages/mosaic) touch "$out/mosaicstack-mosaic-0.0.0-source.tgz" ;;
*) echo "unexpected pnpm pack cwd: $PWD" >&2; exit 1 ;;
esac
exit 0
fi
if [[ "${MOSAIC_TEST_FAIL_PNPM_INSTALL:-0}" == "1" && "$1" == "install" ]]; then
echo "forced pnpm install failure" >&2
exit 42
fi
# Other install/build commands are no-ops in this harness.
exit 0
FAKE_PNPM
chmod +x "$FAKE_BIN/pnpm"
reset_state() {
: > "$LOG"
rm -f "$STATE"/*
}
tree_fingerprint() {
local root="$1"
if [[ ! -d "$root" ]]; then printf 'ABSENT\n'; return; fi
python3 - "$root" <<'PY'
import hashlib, os, stat, sys
root=os.path.abspath(sys.argv[1]); rows=[]
for current, dirs, files in os.walk(root, topdown=True, followlinks=False):
for name in dirs + files:
path=os.path.join(current,name); meta=os.lstat(path)
rel=os.path.relpath(path,root)
target=os.readlink(path) if stat.S_ISLNK(meta.st_mode) else ''
digest=''
if stat.S_ISREG(meta.st_mode):
with open(path,'rb') as handle: digest=hashlib.sha256(handle.read()).hexdigest()
rows.append((rel,stat.S_IFMT(meta.st_mode),stat.S_IMODE(meta.st_mode),target,digest))
payload='\n'.join('|'.join(map(str,row)) for row in sorted(rows)).encode()
print(hashlib.sha256(payload).hexdigest())
PY
}
prefix_fingerprint() { tree_fingerprint "$PREFIX"; }
reset_state
echo "[test] --next fast path pins resolved package versions"
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch
)"
grep -qF 'Installed @next packages: CLI 0.0.49-next.999, gateway 0.0.7-next.999' <<<"$OUTPUT"
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
if grep -qE '^install -g .+@next( |$)' "$LOG"; then
echo "expected exact-version installs, found mutable @next install" >&2
exit 1
fi
if grep -qF 'Downloading source ref next at pinned commit' <<<"$OUTPUT"; then
echo "fast path unexpectedly fell back to source" >&2
exit 1
fi
ACTIVE="$HOME_DIR/.local/state/mosaic/install/active.json"
[[ "$(node -p "require('$ACTIVE').status")" == "committed" ]]
JOURNAL="$(node -p "require('$ACTIVE').journal")"
[[ "$(stat -c '%a' "$JOURNAL")" == "444" ]]
( cd "$(dirname "$JOURNAL")" && sha256sum -c "$(basename "$JOURNAL").sha256" >/dev/null )
grep -q '"event":"mutation".*"phase":"P3".*path=.*prior=.*reverse=' "$JOURNAL"
reset_state
echo "[test] fast path failure falls back to source build"
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch
)"
grep -qF 'Fast gateway @next install failed.' <<<"$OUTPUT"
grep -qF 'Falling back to source build at ref next; --next will not hard-fail on registry issues.' <<<"$OUTPUT"
grep -qF 'Downloading source ref next at pinned commit 1111111111111111111111111111111111111111' <<<"$OUTPUT"
grep -qF 'Installed from source: CLI 0.0.0-source' <<<"$OUTPUT"
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
grep -qE 'install -g .*/mosaicstack-gateway-0\.0\.0-source\.tgz' "$LOG"
grep -qE 'install -g .*/mosaicstack-mosaic-0\.0\.0-source\.tgz' "$LOG"
[[ "$(cat "$STATE/mosaic")" == "0.0.0-source" ]]
[[ "$(cat "$STATE/gateway")" == "0.0.0-source" ]]
reset_state
echo "[test] source-build failure is fatal and restores the pre-install prefix"
before_prefix="$(prefix_fingerprint)"
set +e
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
MOSAIC_TEST_FAIL_PNPM_INSTALL=1 \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch 2>&1
)"
FAIL_STATUS=$?
set -e
[[ "$FAIL_STATUS" -ne 0 ]]
[[ "$(prefix_fingerprint)" == "$before_prefix" ]]
grep -qF 'forced pnpm install failure' <<<"$OUTPUT"
[[ "$(node -p "require('$ACTIVE').status")" == "rolled-back" ]]
reset_state
echo "[test] corrupt source archive is fatal and restores the pre-install prefix"
before_prefix="$(prefix_fingerprint)"
set +e
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
MOSAIC_TEST_CORRUPT_ARCHIVE=1 \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch 2>&1
)"
FAIL_STATUS=$?
set -e
[[ "$FAIL_STATUS" -ne 0 ]]
[[ "$(prefix_fingerprint)" == "$before_prefix" ]]
grep -qF 'archive safety/integrity check failed' <<<"$OUTPUT"
[[ "$(node -p "require('$ACTIVE').status")" == "rolled-back" ]]
reset_state
echo "[test] --dev source install does not require registry version resolution"
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_FAIL_NPM_VIEW=1 \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --dev --ref feature-x --yes --no-auto-launch
)"
grep -qF 'Downloading source ref feature-x at pinned commit 1111111111111111111111111111111111111111' <<<"$OUTPUT"
grep -qF 'Installed from source: CLI 0.0.0-source' <<<"$OUTPUT"
grep -q '^\[P2\] PASS: source_ref=feature-x pinned_commit=1111111111111111111111111111111111111111 sha256=' <<<"$OUTPUT"
reset_state
echo "[test] explicit --ref keeps source lane and avoids @next lookup"
set +e
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --check --cli --next --ref feature-x
)"
CHECK_STATUS=$?
set -e
[[ "$CHECK_STATUS" -ne 0 ]]
grep -q '^\[P2\] PASS: source_ref=feature-x pinned_commit=1111111111111111111111111111111111111111 sha256=' <<<"$OUTPUT"
if grep -qF '@next version' "$LOG"; then
echo "explicit ref should not query @next dist-tags" >&2
exit 1
fi
reset_state
echo "[test] --check --next rejects mismatched prerelease pipeline suffixes"
set +e
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_GATEWAY_NEXT_VERSION="0.0.7-next.1000" \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --check --cli --next
)"
CHECK_STATUS=$?
set -e
[[ "$CHECK_STATUS" -ne 0 ]]
grep -q '^\[P2\] FAIL: resolved_version=unavailable' <<<"$OUTPUT"
printf '[test] full framework path receives P3 absolute CLI without relying on PATH\n'
rm -rf "$HOME_DIR" "$STATE"; mkdir -p "$HOME_DIR" "$STATE"; reset_state
set +e
OUTPUT="$(
HOME="$HOME_DIR" MOSAIC_HOME="$MOSAIC_HOME" MOSAIC_PREFIX="$PREFIX" \
MOSAIC_INSTALL_STATE_DIR="$TMP/full-state" MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --next --yes --no-auto-launch 2>&1
)"
FULL_STATUS=$?
set -e
[[ "$FULL_STATUS" -ne 0 ]] # P4 remains intentionally undeclared until C5.
grep -qF "framework-cli=$PREFIX/bin/mosaic version=0.0.49-next.999" "$LOG"
if grep -q "CLI not found on PATH\|did not receive P3 absolute CLI" <<<"$OUTPUT"; then
echo "internal framework phase depended on PATH instead of P3 absolute CLI" >&2
exit 1
fi
printf '[test] captured diagnostics redact seeded credential canary everywhere\n'
rm -rf "$HOME_DIR" "$STATE"; mkdir -p "$HOME_DIR" "$STATE"; reset_state
canary='C1_SECRET_CANARY_7df4c2'
OUTPUT="$(
HOME="$HOME_DIR" MOSAIC_HOME="$MOSAIC_HOME" MOSAIC_PREFIX="$PREFIX" \
MOSAIC_INSTALL_STATE_DIR="$TMP/secret-state" MOSAIC_NO_COLOR=1 \
MOSAIC_INSTALL_SECRET_CANARY="$canary" MOSAIC_TEST_CANARY_OBSERVATION="$TMP/canary-observed" \
MOSAIC_TEST_NPM_LOG="$LOG" MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch 2>&1
)"
# Positive control: replace the removed redacted example.io source with one deliberately unredacted userinfo URL.
OUTPUT+=$'\nhttps://[email protected]/e'
if grep -qF "$canary" <<<"$OUTPUT"; then echo 'credential canary leaked to terminal output' >&2; exit 1; fi
if grep -Eq 'alice:p@ss|bob:pa:ss|carol:p%40ss|token@example|user%3Apass|QWxhZGRpbjpvcGVu|Ym9iOnNlY3JldA|session=abc123|sid=xyz789' <<<"$OUTPUT"; then
echo 'credentialed URL userinfo leaked to terminal output' >&2; exit 1
fi
for host in example.com example.net example.org example.dev example.io; do
grep -qF "https://[REDACTED]@$host" <<<"$OUTPUT" \
|| { echo "credentialed URL redaction control missing for $host" >&2; exit 1; }
done
secret_active="$TMP/secret-state/active.json"
secret_journal="$(node -p "require('$secret_active').journal")"
secret_command_log="$(dirname "$secret_journal")/commands.log"
if grep -R -F "$canary" "$secret_command_log" "$HOME_DIR" 2>/dev/null; then
echo 'credential canary leaked to persistent installer output' >&2; exit 1
fi
if grep -E 'alice:p@ss|bob:pa:ss|carol:p%40ss|token@example|user%3Apass|QWxhZGRpbjpvcGVu|Ym9iOnNlY3JldA|session=abc123|sid=xyz789' "$secret_command_log" >/dev/null; then
echo 'credentialed URL userinfo leaked to persistent installer output' >&2; exit 1
fi
if [[ "$(cat "$TMP/canary-observed" 2>/dev/null || true)" != "$canary" ]]; then
echo 'credential canary positive control was not exercised' >&2; exit 1
fi
if find "$TMPDIR" -maxdepth 1 -type f \( -name 'mosaic-phase-redacted.*' -o -name 'mosaic-post-redacted.*' \) -print -quit | grep -q .; then
echo 'redacted diagnostic staging file survived normal completion' >&2; exit 1
fi
printf '[test] framework nested capture redacts the same canary and URL variants\n'
framework_test_home="$TMP/framework-redact-home"
framework_target="$framework_test_home/.config/mosaic"
framework_cli="$TMP/framework-redact-cli"
framework_log="$TMP/framework-redact-commands.log"
framework_status="$TMP/framework-redact-status.tsv"
mkdir -p "$framework_test_home"; : > "$framework_log"; : > "$framework_status"
cat > "$framework_cli" <<'FRAMEWORK_CLI'
#!/usr/bin/env bash
printf 'nested authToken=%s\n' "${MOSAIC_INSTALL_SECRET_CANARY:?}"
printf 'nested=https://alice:p@[email protected]/a https://bob:pa:[email protected]/b https://carol:p%%[email protected]/c https://[email protected]/d https://user%%[email protected]/e\n'
printf 'Authorization: Basic QWxhZGRpbjpvcGVu\n//registry/:_auth=Ym9iOnNlY3JldA==\nCookie: session=abc123\nSet-Cookie: sid=xyz789\n'
exit 1
FRAMEWORK_CLI
chmod 0755 "$framework_cli"
set +e
FRAMEWORK_OUTPUT="$(
HOME="$framework_test_home" MOSAIC_HOME="$framework_target" MOSAIC_INSTALL_MODE=overwrite \
MOSAIC_CLI_PATH="$framework_cli" MOSAIC_INSTALL_SECRET_CANARY="$canary" \
MOSAIC_INSTALL_COMMAND_LOG="$framework_log" MOSAIC_INSTALL_PHASE_STATUS_FILE="$framework_status" \
MOSAIC_ALLOW_MISSING_SEQUENTIAL_THINKING=1 MOSAIC_SKIP_SKILLS_SYNC=1 \
bash "$ROOT/packages/mosaic/framework/install.sh" 2>&1
)"
framework_install_status=$?
set -e
[[ "$framework_install_status" -eq 0 ]]
if grep -Eq "$canary|alice:p@ss|bob:pa:ss|carol:p%40ss|token@example|user%3Apass|QWxhZGRpbjpvcGVu|Ym9iOnNlY3JldA|session=abc123|sid=xyz789" <<<"$FRAMEWORK_OUTPUT" \
|| grep -Eq "$canary|alice:p@ss|bob:pa:ss|carol:p%40ss|token@example|user%3Apass|QWxhZGRpbjpvcGVu|Ym9iOnNlY3JldA|session=abc123|sid=xyz789" "$framework_log"; then
echo 'framework nested capture leaked credential diagnostics' >&2; exit 1
fi
for host in example.com example.net example.org example.dev example.io; do
grep -qF "https://[REDACTED]@$host" "$framework_log" \
|| { echo "framework URL redaction control missing for $host" >&2; exit 1; }
done
printf '[test] real P2-P8 actions run under fault injection and restore actual surfaces\n'
for phase in P2 P3 P4 P5 P6 P7 P8; do
rm -rf "$HOME_DIR" "$STATE" "$TMP/fault-$phase"; mkdir -p "$HOME_DIR" "$STATE" "$TMP/fault-$phase"
printf 'operator-sentinel\n' > "$HOME_DIR/operator.txt"
reset_state
before="$(tree_fingerprint "$HOME_DIR")"
set +e
HOME="$HOME_DIR" MOSAIC_HOME="$MOSAIC_HOME" MOSAIC_PREFIX="$PREFIX" \
MOSAIC_INSTALL_STATE_DIR="$TMP/fault-$phase" MOSAIC_INSTALL_FAULT_AFTER="$phase" \
MOSAIC_INSTALL_SELF_TEST_ALLOW=1 MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --state-machine-self-test --next --yes \
>"$TMP/fault-$phase.log" 2>&1
status=$?
set -e
[[ "$status" -eq 97 ]] || { echo "$phase real fault expected 97, got $status" >&2; exit 1; }
[[ -s "$LOG" ]] || { echo "$phase fault never entered the real action path" >&2; exit 1; }
[[ "$(tree_fingerprint "$HOME_DIR")" == "$before" ]] || { echo "$phase real rollback mismatch" >&2; exit 1; }
grep -q "phase=$phase" "$TMP/fault-$phase.log"
if find "$TMP/fault-$phase" -type f -exec grep -l '"status"[[:space:]]*:[[:space:]]*"in-progress"' {} + 2>/dev/null | grep -q .; then
echo "$phase left an in-progress transaction" >&2; exit 1
fi
done
printf '[test] stale projection is preserved while the real fault path acquires a free OS lock\n'
rm -rf "$HOME_DIR" "$STATE" "$TMP/stale-state"; mkdir -p "$HOME_DIR" "$STATE" "$TMP/stale-state"
printf '{"status":"in-progress","journal":"%s"}\n' "$TMP/stale-state/dead-run/journal.ndjson" > "$TMP/stale-state/active.json"
reset_state
set +e
HOME="$HOME_DIR" MOSAIC_HOME="$MOSAIC_HOME" MOSAIC_PREFIX="$PREFIX" \
MOSAIC_INSTALL_STATE_DIR="$TMP/stale-state" MOSAIC_INSTALL_FAULT_AFTER=P2 \
MOSAIC_INSTALL_SELF_TEST_ALLOW=1 MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --state-machine-self-test --next --yes >"$TMP/stale.log" 2>&1
stale_status=$?
set -e
[[ "$stale_status" -eq 97 ]]
find "$TMP/stale-state" -name prior-active.json -type f -print -quit | grep -q .
[[ "$(node -p "require('$TMP/stale-state/active.json').status")" == rolled-back ]]
echo "[test] installer next lane tests passed"
@@ -1,83 +0,0 @@
# #1050 — Installer P0P9 state machine and red-first fixture
## Objective
Implement C1 from the canonical greenfield-install PRD v2: a transactional P0P9 installer spine, a side-effect-free P0P8 `--check`, and a lane-parametric Debian/glibc non-root from-zero fixture. The acceptance milestone is an attributable RED on the pre-C1 installer while preserving P3 PASS.
## Authority and scope
- Canonical requirements: `jason.woltje/jarvis-brain` `docs/plans/2026-08-04-greenfield-install-blockers-PRD-v2.md`. Currency was re-derived after compaction: authenticated fetch resolved `origin/main` to `cb23e5fbc8a282fa967b93d7a134fa48d11b4bb1`; the PRD and charters are byte-identical to the previously read remote copies.
- Tracking: `mosaicstack/stack#1050` on `git.mosaicstack.dev` (author read back as `be-coder-05`).
- Historical implementation base: `origin/next` `4df478cdd150fdf8d52ea109f02ade5d85017acd`. Delivery PR #1054 targets `main` under L0's trunk-only rule; `next` remains a non-merging integration lane.
- Out of scope: PATH, skills, headless wizard/identity, activation remediation, #869 wiring, RM-02, main promotion.
- `docs/TASKS.md` is orchestrator-single-writer and is not modified by this worker.
## Plan
1. Pre-register the canonical phase/output/side-effect-free/fault-injection checks and observe RED against the base installer.
2. Commit the immutable red-first acceptance fixture before implementation.
3. Add the state-machine/journal/postcondition spine without repairing P4/P5/P8 symptoms.
4. Wire the expected-RED from-zero fixture into Woodpecker using Debian/glibc and a non-root target user.
5. Run shell/static baselines, situational container validation, code review, security review, then deliver through a PR to `next` under the coordinator-owned merge path.
## Budget
- Working estimate: 32K reasoning/output tokens.
- Hard external cap: none stated.
- Adaptation: keep implementation in shell surfaces already in scope; no package dependency install unless repository gates require it.
## Pre-registered acceptance checks
| ID | Exact case | Expected pre-fix result |
|---|---|---|
| C1-R1 | `tools/e2e-install-test.sh --lane next` in a clean Debian 12 container as uid 1001 | non-zero; P3 PASS; P4 `NOT-MEASURED / UNDECLARED`; P5/P6/P8 FAIL with own reasons |
| C1-R2 | `tools/install-state-machine.test.sh` phase table case | RED because base installer does not enumerate canonical P0P9 contracts |
| C1-R3 | side-effect-free `--check` case over a fingerprinted HOME | RED because base `--check` is version-only rather than P0P8 predicates |
| C1-R4 | fault injection after each P2…P8 | RED because base installer has no injectable durable journal/rollback state |
| C1-R5 | Docker unavailable | base harness incorrectly exits 0; replacement must fail non-zero |
| C1-R6 | lane resolution | bare checkout is forbidden; fixture must pass `--next` and assert the resolved prerelease version |
| C1-R7 | same Debian fixture with `git` absent vs present | absent: P1 FAIL while legacy installer exits 0 and sync degrades; present: P1 PASS and observed store/runtime containment 101/101 |
## Progress
- [x] Charter, doctrine, delivery/CI/QA/docs guides read and re-anchored after compaction.
- [x] Canonical PRD v2/v3 addenda and charters read from fetched `origin/main`; numbering reconciles with the TL spec. No numbering conflict found. INV-B/C/D are binding and implemented without renumbering.
- [x] Target base reachability verified with `merge-base --is-ancestor`.
- [x] Issue #1050 created and provider author read back.
- [x] Initial RED captured; TL rejected P4's repo-root count as a false RED. Four populations disagree (framework payload 1, repo root 13, sync store 101 in the fixture, W-jarvis observation 7), so C1 now requires a checkout-free declared shipped-set artifact and reports P4 `NOT-MEASURED / UNDECLARED` until C5 supplies it.
- [x] P6 strengthens #869: the two dead enforcement hooks reproduce from zero on a clean broker-less container. C1 asserts the breach but neither wires nor unwires it.
- [x] P1 false pass identified from the P4 evidence row: `git` is absent from the Debian base and was undeclared even though skill sync shells out to it. C1 adds `git` to P1; the fixture matrix preserves absent/present controls. The prior claim that web1's missing runtime skills reproduce this greenfield mechanism is withdrawn by the TL and is not carried here.
- [x] Corrected RED transcript captured and reported, including the git-present/absent controls and strict P3 PASS.
- [x] State-machine implementation complete: private pre-mutation journal/snapshot, P0P8 `--check`, P2P8 fault seam, rollback, durable manifest/journal seal, action-status persistence, safe rollback roots, and stale-projection recovery.
- [x] Debian/glibc checkout fixture now packages the complete current checkout, verifies its digest in-container, and reaches the expected attributable RED without host inheritance. CI compares its exact final phase map/reasons to `tools/fixtures/greenfield-expected-red.tsv`; the fixture remains red while the detector job is green only on an exact match.
- [ ] Reviews complete. Reviews 80 (`rev-security-02`) and 81 (`rev-974`) requested changes at `3934e03f`; their eight non-overlapping detector findings are being remediated red-first. Current remediation adds canonical-image portability, absolute P3 CLI propagation, exact expected-RED schema/cardinality, passwd-HOME binding, created-path owner/mode policy, real-action P2P8 fault injection, verified non-empty remote installer execution, and seeded secret-canary/redacted diagnostics. Both old verdicts become void when the remediation head moves and require fresh independent review.
## Risks / blockers
- The deployed create wrappers do not expose `--dry-run`; identity preflight was performed through `pr-merge.sh --dry-run` on the same HOMELAB repo, which resolved `git.mosaicstack.dev` + `be-coder-05`. The issue create then fell back from tea to the API but provider read-back confirmed author `be-coder-05`.
- `next` is a non-merging integration lane; PR #1054 targets `main`. The old “pending promotion to main” caution dissolved when the base moved. #1050 remains open after merge and closes only after Jarvis validates the greenfield behavior.
- #869 must remain staged and inactive.
- Late sequencing input MB-BRAIN-01 is accommodated without implementation or renumbering: P2 covers installer distribution only; P5 owns requested credential capability; P7 leaves an ordered seam for credential-dependent resource provisioning after P5.
## Remediation review controls
- B1 RED: the next-lane harness failed immediately under `ci-base:latest` as root/musl; it now models uid 1001/glibc explicitly and uses Python tree fingerprints instead of GNU `find -printf`.
- B2 RED: framework/runtime linking consumed bare `mosaic` from PATH after P3 had committed an absolute path. The unified installer now exports/passes `MOSAIC_CLI_PATH`; the linker invokes that absolute artifact, and wizard auto-launch has no stale-PATH fallback.
- B3 RED: a one-row manifest (`exit=1`) certified any exit-1 log. Full-manifest validation now requires the exact three cases, one exit and P0P9 row each, pinned require/forbid populations, and rejects malformed/duplicate/unknown rows; shrink is a negative control.
- B4 RED: uid 1001 with a passwd HOME different from ambient HOME produced P0 PASS. P0 now binds uid, username, passwd HOME and shell and explicitly rejects root and sudo-with-inherited-HOME controls.
- B5 RED: mode-0777 CLI, mode-0644 identity, and mode-0755 credential storage passed. P3/P4/P5 now apply target owner/group plus executable/shared/private policies; framework credential storage is created 0700.
- B6 RED: fault injection only wrote `.selftest-*` files. The synthetic path was removed; the P2P8 matrix enters the normal action flow, proves an action observation occurred, injects after each real phase, and fingerprints rollback.
- B7 RED: an HTTP-200 empty body exits zero when piped to Bash. The fetched installer must now be non-empty, digest-equal to `tools/install.sh.sha256`, and that exact file is executed; failed/empty/mismatch controls are blocking and CI has a remote immutable-commit arm.
- B8 RED: raw combined command output was duplicated to terminal and `commands.log`. Both capture layers now redact before output/persistence; a seeded canary is positively emitted by the fake credential-capable registry and must remain absent from terminal, command log, npmrc, generated files and observed argv. The real greenfield fixture also scans those populations.
- Advisory code review findings are fixed: URL userinfo redaction now handles raw `@`, token-only and percent-encoded forms, repeated `:`, multiple URLs, Authorization/Basic, npm `_auth`, and Cookie headers in both capture layers; the real greenfield path positively emits its canary through `state_run_captured`; verified-fetch removes its temporary body after successful execution; and plaintext diagnostics exist only in process-substitution pipes rather than interruptible temporary files.
- Advisory security review's independent trust-root finding is **DEFERRED by canonical PRD v2 §3**, which explicitly excludes signed provenance. README now states precisely that the same-origin sidecar detects empty/corrupt/inconsistent publication but cannot authenticate against repository/server compromise; no stronger claim remains.
- The web1 no-manifest representativeness observation is recorded but intentionally not acted on: it is explicitly outside these eight blockers. This remediation does not weaken or otherwise change P9's manifest-presence assertion.
## Verification log
- `bash -n` and ShellCheck pass for all changed shell surfaces; `git diff --check` passes.
- `bash tools/install-state-machine.test.sh` passes, including exact P0P8 rows, passwd-HOME/privilege discrimination, owner/group/mode attacks, persisted P4/P6 action failures, no synthetic fault implementation, unsafe/overlapping/symlink roots, and fatal journal initialization.
- `bash tools/install-next-lane.test.sh` passes inside `ci-base:latest`, including exact `@next` versions, immutable source fallback, source-build/archive-failure rollback, offline `--dev`, explicit refs, prerelease suffix mismatch, absolute P3 CLI propagation, secret redaction, real-action P2P8 rollback, and stale projection recovery.
- Comparator controls pass for verdict drift, unexpected exit, manifest shrink, missing phases, duplicate rows, unknown cases, and unknown kinds. Verified-fetch controls pass for successful execution and failed/empty/digest-mismatch rejection.
- `bash tools/e2e-install-test.sh --lane next --source checkout --git present` returns the required expected RED in clean Debian/glibc as uid 1001: installer P0/P1/P2/P3/P7 PASS; P4/P5/P6/P8 and P9 blocking; no `Done.` claim; checkout archive digest pinned and current framework installer exercised. `tools/verify-greenfield-expected-red.sh` converts that expected detector result into a green CI assertion and fails on any unreviewed verdict drift.
- Earlier repository gates passed: `pnpm typecheck`, `pnpm lint`, `pnpm format:check`, upgrade manifest/rollback/durable-snapshot/migration suites, and focused `@mosaicstack/mosaic` tests with an isolated npm prefix. Full exact-remediation rerun is required before push.
+1 -2
View File
@@ -10,8 +10,7 @@
"clean:generated": "node scripts/clean-generated.mjs",
"typecheck": "pnpm preflight && turbo run typecheck",
"test:checkout": "node --test scripts/*.test.mjs",
"test": "pnpm test:checkout && turbo run test && pnpm run test:installer",
"test:installer": "bash tools/install-state-machine.test.sh && bash tools/install-next-lane.test.sh && bash tools/verify-greenfield-expected-red.test.sh && bash tools/verified-installer-fetch.test.sh",
"test": "pnpm test:checkout && turbo run test",
"format": "prettier --write \"**/*.{ts,tsx,js,jsx,json,md}\"",
"format:check": "prettier --check \"**/*.{ts,tsx,js,jsx,json,md}\"",
"prepare": "node scripts/install-hooks.mjs"
+33 -176
View File
@@ -58,7 +58,6 @@ done
# packages/mosaic/src/framework/manifest.ts — both consume framework-manifest.txt.
# Sourcing does not run its CLI dispatch (guarded by BASH_SOURCE==$0).
# shellcheck source=tools/_lib/manifest.sh
# shellcheck disable=SC1091 # Dynamic SOURCE_DIR; the path is validated by set -e.
source "$SOURCE_DIR/tools/_lib/manifest.sh"
# Which paths a keep-mode upgrade may touch is no longer a hand-maintained
@@ -223,14 +222,12 @@ prune_durable_snapshots() {
[[ "$keep" =~ ^[0-9]+$ ]] && (( keep >= 1 )) || keep=5
list="$(mktemp)"
if ! find "$root" -maxdepth 1 -type d -name 'pre-update-*' > "$list"; then
warn "Backup pruning skipped; policy: retention cleanup is optional and a failed enumeration must preserve every existing recovery snapshot."
rm -f "$list"; return 0
fi
# Newest-first ordering needs `sort` (`-o` writes back in place — no `mv`
# dependency); if it is somehow unavailable, leave the backups untouched rather
# than risk pruning in an undefined order.
if ! LC_ALL=C sort -r -o "$list" "$list" 2>/dev/null; then
warn "Backup pruning skipped; policy: ordering failure preserves all snapshots rather than risking deletion in an undefined order."
rm -f "$list"; return 0
fi
while IFS= read -r d; do
@@ -269,11 +266,7 @@ make_durable_snapshot() {
warn "Durable snapshot skipped: cannot create backup dir $root (upgrade continues; operator files remain manifest-protected)."
return 0
fi
if ! chmod 700 "$root"; then
umask "$old_umask"
warn "Durable snapshot skipped: backup root permissions could not be made private; policy: never write operator data to an insufficiently protected location."
return 0
fi
chmod 700 "$root" 2>/dev/null || true
dir="$root/pre-update-$ts"
if [[ -e "$dir" ]]; then # same-second re-run: disambiguate
local n=1; while [[ -e "$dir-$n" ]]; do n=$((n + 1)); done; dir="$dir-$n"
@@ -288,10 +281,7 @@ make_durable_snapshot() {
if ! enumerate_operator_files "$list"; then
umask "$old_umask"
warn "Durable snapshot skipped: could not enumerate operator files (upgrade continues)."
rm -f "$list"
if ! rmdir "$dir"; then
warn "Durable snapshot cleanup left $dir in place; policy: preserve unexpected content rather than deleting it recursively."
fi
rm -f "$list"; rmdir "$dir" 2>/dev/null || true
return 0
fi
while IFS= read -r -d '' rel; do
@@ -302,18 +292,12 @@ make_durable_snapshot() {
warn "Durable snapshot: could not copy operator file '$rel' (skipped)."
continue
fi
if ! chmod 600 "$dst"; then
rm -f "$dst"
warn "Durable snapshot: copied '$rel' could not be made private and was removed; policy: do not retain an insecure recovery copy."
continue
fi
chmod 600 "$dst" 2>/dev/null || true
count=$((count + 1))
done < "$list"
rm -f "$list"
# Tighten every dir the copy created (mkdir -p already honored umask 077).
if ! find "$dir" -type d -exec chmod 700 {} +; then
warn "Durable snapshot directory permission recheck failed; policy: continue because every directory was created under umask 077, while retaining the diagnostic."
fi
# Tighten every dir the copy created (mkdir -p honors umask, but be explicit).
find "$dir" -type d -exec chmod 700 {} + 2>/dev/null || true
umask "$old_umask" # UMASK-RESTORE-NORMAL — restore before the upgrade proper resumes (see above)
DURABLE_SNAPSHOT_DIR="$dir"
ok "Durable pre-update snapshot: $count operator file(s) saved to $dir (recover with: mosaic restore --list)"
@@ -360,9 +344,7 @@ verify_operator_surface() {
continue
fi
if cp "$snap" "$cur"; then
if ! chmod 600 "$cur"; then
warn "Operator file '$rel' was restored but its mode could not be tightened to 0600; policy: preserve recovered content and require manual permission repair."
fi
chmod 600 "$cur" 2>/dev/null || true
warn "Operator file was modified by the upgrade and has been restored from the pre-update snapshot: $rel"
healed=$((healed + 1))
else
@@ -553,7 +535,7 @@ sync_framework_keep() {
# (unreadable dir) is surfaced as a warning rather than silently swallowed;
# the "directory not empty" races we tolerate are ignored via -delete's own
# rc, not by hiding stderr — so a real error is still visible to the operator.
if ! find "$dst/$root" -type d -empty -delete; then
if ! find "$dst/$root" -type d -empty -delete 2>/dev/null; then
warn "prune: could not fully sweep empty framework dirs under $root (left as-is)"
fi
done < <(manifest_subtree_roots)
@@ -599,7 +581,7 @@ run_migrations() {
MIGRATION_REMOVED_PATHS+=("bin" "rails")
if [[ -d "$TARGET_DIR/bin" ]]; then
ok "Removing legacy bin/ directory (executables now in npm CLI)"
rm -rf "${TARGET_DIR:?}/bin"
rm -rf "$TARGET_DIR/bin"
fi
# Remove old mosaic PATH entry from shell profiles
@@ -710,11 +692,9 @@ trap 'restore_snapshot; exit 1' ERR INT TERM
sync_framework
# Ensure persistent directories exist. Credentials are private material and
# must never inherit a permissive umask/default mode.
# Ensure persistent directories exist
mkdir -p "$TARGET_DIR/memory"
mkdir -p "$TARGET_DIR/credentials"
chmod 0700 "$TARGET_DIR/credentials"
# Reconcile contract files from defaults/ into the framework root: framework-owned
# files (CONSTITUTION/AGENTS/STANDARDS) are overwritten every upgrade (a divergent
@@ -726,23 +706,13 @@ chmod 0700 "$TARGET_DIR/credentials"
# by `mosaic init` from templates with user-supplied values.
reconcile_framework_files
# Ensure tool scripts are executable. These are P4 postconditions, not
# best-effort cleanup: a chmod failure leaves shipped tools unloadable.
if ! find "$TARGET_DIR/tools" -name "*.sh" -exec chmod +x {} +; then
fail "Could not mark shipped shell tools executable."
exit 1
fi
if ! find "$TARGET_DIR/tools/_scripts" -type f -exec chmod +x {} +; then
fail "Could not mark shipped runtime scripts executable."
exit 1
fi
# Ensure tool scripts are executable
find "$TARGET_DIR/tools" -name "*.sh" -exec chmod +x {} + 2>/dev/null || true
find "$TARGET_DIR/tools/_scripts" -type f -exec chmod +x {} + 2>/dev/null || true
# git-credential-mosaic (per-agent Gitea identity helper) ships without a .sh
# suffix — git resolves credential helpers by exact name/path, not extension.
if [[ -f "$TARGET_DIR/tools/git/git-credential-mosaic" ]] \
&& ! chmod +x "$TARGET_DIR/tools/git/git-credential-mosaic"; then
fail "Could not mark git-credential-mosaic executable."
exit 1
fi
# suffix — git resolves credential helpers by exact name/path, not extension
# so the *.sh glob above does not cover it; chmod it explicitly.
[[ -f "$TARGET_DIR/tools/git/git-credential-mosaic" ]] && chmod +x "$TARGET_DIR/tools/git/git-credential-mosaic" 2>/dev/null || true
ok "Framework synced to $TARGET_DIR"
@@ -769,162 +739,49 @@ step "Post-install tasks"
SCRIPTS="$TARGET_DIR/tools/_scripts"
# Capture every fallible post-install command. A failure's text is surfaced and
# also appended to the parent transaction's private command log. Failure to
# write that log is fatal: continuing would recreate the false-clean diagnosis
# INV-C forbids.
record_phase_outcome() {
local phase="$1" status="$2" reason="$3"
[[ -n "${MOSAIC_INSTALL_PHASE_STATUS_FILE:-}" ]] || return 0
if ! printf '%s\t%s\t%s\n' "$phase" "$status" "$reason" >> "$MOSAIC_INSTALL_PHASE_STATUS_FILE" \
|| ! sync "$MOSAIC_INSTALL_PHASE_STATUS_FILE"; then
fail "Could not durably record $phase action outcome for the parent transaction."
exit 1
fi
}
redact_install_stream() {
# Keep this bootstrap copy behaviorally identical to tools/install.sh's
# state_redact_stream; neither installer can assume the other is installed.
python3 /dev/fd/3 3<<'PY'
import os, re, sys
text = sys.stdin.read()
secret_name = re.compile(r"(?:TOKEN|PASSWORD|PASSWD|SECRET|API_KEY|AUTH|CREDENTIAL|CANARY)", re.I)
secrets = {value for name, value in os.environ.items() if secret_name.search(name) and len(value) >= 4}
for value in sorted(secrets, key=len, reverse=True):
text = text.replace(value, "[REDACTED]")
patterns = (
(re.compile(r"(?im)^(\s*(?:proxy-)?authorization\s*:\s*)[^\r\n]+"), r"\1[REDACTED]"),
(re.compile(r"(?im)^(\s*(?:set-)?cookie\s*:\s*)[^\r\n]+"), r"\1[REDACTED]"),
(re.compile(r"(?i)(Bearer\s+)[^\s'\"]+"), r"\1[REDACTED]"),
(re.compile(r"(?i)((?:[_-]?auth(?:Token)?|token|password|passwd|secret|api[_-]?key)\s*[=:]\s*)[^\s'\"]+"), r"\1[REDACTED]"),
)
for pattern, replacement in patterns:
text = pattern.sub(replacement, text)
url_pattern = re.compile(r"https?://[^\s'\"<>]+", re.I)
def redact_url(match):
url = match.group(0)
scheme_end = url.find("://") + 3
authority_end = len(url)
for separator in "/?#":
position = url.find(separator, scheme_end)
if position != -1:
authority_end = min(authority_end, position)
authority = url[scheme_end:authority_end]
at = authority.rfind("@")
if at != -1:
return url[:scheme_end] + "[REDACTED]@" + authority[at + 1:] + url[authority_end:]
return url
sys.stdout.write(url_pattern.sub(redact_url, text))
PY
}
run_captured() {
local label="$1" redacted redactor_pid capture_fd status=0 redact_status=0
shift
redacted="$(mktemp "${TMPDIR:-/tmp}/mosaic-post-redacted.XXXXXX")"
chmod 0600 "$redacted" || { rm -f "$redacted"; exit 1; }
# Preserve in-shell command behavior without ever staging plaintext output on
# disk. Process substitution carries raw bytes only through a pipe.
exec {capture_fd}> >(redact_install_stream > "$redacted")
redactor_pid=$!
set +e
"$@" >&"$capture_fd" 2>&1
status=$?
exec {capture_fd}>&-
wait "$redactor_pid"
redact_status=$?
set -e
if [[ "$redact_status" -ne 0 ]]; then
rm -f "$redacted"
fail "Could not redact '$label' diagnostics; refusing to expose or persist raw output."
exit 1
fi
if [[ -n "${MOSAIC_INSTALL_COMMAND_LOG:-}" ]]; then
if ! { printf '\n=== %s (exit=%s) ===\n' "$label" "$status"; cat "$redacted"; } >> "$MOSAIC_INSTALL_COMMAND_LOG" \
|| ! sync "$MOSAIC_INSTALL_COMMAND_LOG"; then
cat "$redacted" >&2
rm -f "$redacted"
fail "Could not durably append '$label' diagnostics to the install command log."
exit 1
fi
fi
if [[ "$status" -ne 0 ]]; then cat "$redacted" >&2; fi
rm -f "$redacted"
return "$status"
}
if [[ -x "$SCRIPTS/mosaic-link-runtime-assets" ]]; then
link_args=()
[[ "$ALLOW_INACTIVE_ENFORCEMENT" == "1" ]] && link_args+=(--allow-inactive-enforcement)
if run_captured "runtime asset linking" "$SCRIPTS/mosaic-link-runtime-assets" "${link_args[@]}"; then
record_phase_outcome P6 committed "runtime asset linker exited zero"
# stdout is suppressed as before, but stderr is left connected: the
# install-ordering guard's FAIL LOUD message (#869 Point-1 C2) must reach
# the operator, not be swallowed silently.
if "$SCRIPTS/mosaic-link-runtime-assets" "${link_args[@]}" >/dev/null; then
ok "Runtime assets linked"
else
record_phase_outcome P6 failed "runtime asset linker exited non-zero"
warn "Runtime asset linking did not commit; policy: continue only to enumerate all phase diagnostics, while P6/P9 remain blocking."
warn "Runtime asset linking failed (non-fatal) — see message above for details."
fi
else
record_phase_outcome P6 failed "required runtime asset linker is missing or not executable"
warn "Runtime asset linking was not attempted; policy: a missing required linker remains a blocking P6/P9 failure."
fi
if [[ -x "$SCRIPTS/mosaic-ensure-sequential-thinking" ]]; then
if run_captured "sequential-thinking setup" "$SCRIPTS/mosaic-ensure-sequential-thinking"; then
if "$SCRIPTS/mosaic-ensure-sequential-thinking" >/dev/null 2>&1; then
ok "sequential-thinking MCP configured"
elif [[ "${MOSAIC_ALLOW_MISSING_SEQUENTIAL_THINKING:-0}" == "1" ]]; then
record_phase_outcome P6 failed "sequential-thinking setup failed under diagnostic-continuation compatibility mode"
warn "sequential-thinking setup did not commit; policy: the unified installer compatibility flag allows diagnostic continuation, while P6/P9 remain blocking."
else
fail "sequential-thinking MCP setup failed (hard requirement)."
exit 1
if [[ "${MOSAIC_ALLOW_MISSING_SEQUENTIAL_THINKING:-0}" == "1" ]]; then
warn "sequential-thinking MCP setup bypassed (MOSAIC_ALLOW_MISSING_SEQUENTIAL_THINKING=1)"
else
fail "sequential-thinking MCP setup failed (hard requirement)."
exit 1
fi
fi
fi
if [[ -x "$SCRIPTS/mosaic-ensure-excalidraw" ]]; then
if run_captured "excalidraw setup" "$SCRIPTS/mosaic-ensure-excalidraw"; then
ok "excalidraw MCP configured"
else
warn "excalidraw setup did not commit; policy: optional integration failure is retained in the journal and does not define core install readiness."
fi
"$SCRIPTS/mosaic-ensure-excalidraw" >/dev/null 2>&1 && ok "excalidraw MCP configured" || warn "excalidraw MCP setup failed (non-fatal)"
fi
if [[ "${MOSAIC_SKIP_SKILLS_SYNC:-0}" == "1" ]]; then
record_phase_outcome P4 failed "required skills sync explicitly skipped"
warn "Skills sync was skipped; policy: diagnostic continuation is allowed, but P4/P9 cannot certify an incomplete requested framework install."
elif [[ -x "$SCRIPTS/mosaic-sync-skills" ]]; then
if run_captured "skills sync" "$SCRIPTS/mosaic-sync-skills"; then
record_phase_outcome P4 committed "skills sync exited zero"
ok "Skills synced"
else
record_phase_outcome P4 failed "skills sync exited non-zero"
warn "Skills sync did not commit; policy: continue to collect P4 diagnostics, but P4/P9 must not certify the install."
fi
else
record_phase_outcome P4 failed "required skills sync command is missing or not executable"
warn "Skills sync was not attempted; policy: a missing required sync command remains a blocking P4/P9 failure."
if [[ "${MOSAIC_SKIP_SKILLS_SYNC:-0}" != "1" ]] && [[ -x "$SCRIPTS/mosaic-sync-skills" ]]; then
"$SCRIPTS/mosaic-sync-skills" >/dev/null 2>&1 && ok "Skills synced" || warn "Skills sync failed (non-fatal)"
fi
if [[ -x "$SCRIPTS/mosaic-migrate-local-skills" ]]; then
if run_captured "local skills migration" "$SCRIPTS/mosaic-migrate-local-skills" --apply; then
ok "Local skills migrated"
else
record_phase_outcome P4 failed "local skills migration exited non-zero"
warn "Local skill migration did not commit; policy: preserve user content and continue diagnostics, while P4/P9 remain blocking."
fi
"$SCRIPTS/mosaic-migrate-local-skills" --apply >/dev/null 2>&1 && ok "Local skills migrated" || warn "Local skill migration failed (non-fatal)"
fi
if [[ -x "$SCRIPTS/mosaic-doctor" ]]; then
if run_captured "health audit" "$SCRIPTS/mosaic-doctor"; then
ok "Health audit passed"
else
warn "Health audit found unresolved state; policy: preserve its diagnostics and let P9 issue the authoritative failure."
fi
"$SCRIPTS/mosaic-doctor" >/dev/null 2>&1 && ok "Health audit passed" || warn "Health audit reported issues — run 'mosaic doctor' for details"
fi
# The version stamp records the successfully committed framework file sync.
# Post-install failures are carried separately into P4/P6 and cannot be erased
# by this stamp.
# Write version stamp AFTER everything succeeds
write_framework_version
# ── Summary ──────────────────────────────────────────────────
@@ -68,15 +68,8 @@ copy_claude_settings_guarded() {
guard_args+=(--allow-inactive-enforcement)
fi
local mosaic_cli="${MOSAIC_CLI_PATH:-}"
# Unified install passes P3's committed absolute artifact. Standalone
# framework installs may resolve PATH once, but still invoke the resulting
# absolute path rather than a bare command.
if [[ -z "$mosaic_cli" ]]; then
mosaic_cli="$(command -v mosaic 2>/dev/null || true)"
fi
if [[ "$mosaic_cli" == /* && -x "$mosaic_cli" ]]; then
if "$mosaic_cli" "${guard_args[@]}"; then
if command -v mosaic >/dev/null 2>&1; then
if mosaic "${guard_args[@]}"; then
return 0
fi
echo "[mosaic-link] Enforcement hooks were NOT wired into $dst (see message above)." >&2
@@ -84,7 +77,7 @@ copy_claude_settings_guarded() {
return 0
fi
echo "[mosaic-link] ERROR: P3 absolute mosaic CLI unavailable — cannot confirm lease-enforcement" >&2
echo "[mosaic-link] ERROR: 'mosaic' CLI not found on PATH — cannot confirm lease-enforcement" >&2
echo "[mosaic-link] activation capability. enforcement requested but activation half absent —" >&2
echo "[mosaic-link] needs a published CLI carrying launch-runtime activation + a broker" >&2
echo "[mosaic-link] supervisor; refusing to wire a dead gate (see #869)." >&2
+159 -378
View File
@@ -1,403 +1,184 @@
#!/usr/bin/env bash
# Greenfield installer acceptance fixture.
# ─── Mosaic Stack — End-to-End Install Test ────────────────────────────────────
#
# The fixture itself is intentionally RED until the C2-C5 phase owners repair
# their postconditions. C1's CI gate executes it and validates that the RED is
# attributable (including the discriminating P3 PASS); it does not turn the
# failed install into a false green.
# Runs a clean-container install test to verify the full first-run flow:
# tools/install.sh -> mosaic wizard (non-interactive)
# -> mosaic gateway install
# -> mosaic gateway verify
#
# Usage:
# bash tools/e2e-install-test.sh
#
# Requirements:
# - Docker (skips gracefully if not available)
# - Run from the repository root
#
# How it works:
# 1. Mounts the repository into a node:22-alpine container.
# 2. Installs prerequisites (bash, curl, jq, git) inside the container.
# 3. Runs `bash tools/install.sh --yes --no-auto-launch` to install the
# framework and CLI from the Gitea registry.
# 4. Runs `mosaic wizard --non-interactive` to set up SOUL/USER.
# 5. Runs `mosaic gateway install` with piped defaults (non-interactive).
# 6. Runs `mosaic gateway verify` and checks its exit code.
# NOTE: `mosaic gateway verify` is a new command added in the
# feat/mosaic-first-run-ux branch. If the installed CLI version
# pre-dates this branch (does not have `gateway verify`), the test
# marks this step as EXPECTED-SKIP and reports the installed version.
# 7. Reports PASS or FAIL with a summary.
#
# To run manually:
# cd /path/to/mosaic-stack
# bash tools/e2e-install-test.sh
#
# ──────────────────────────────────────────────────────────────────────────────
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
LANE="${MOSAIC_INSTALL_LANE:-next}"
SOURCE="${MOSAIC_INSTALL_SOURCE:-checkout}"
IMAGE="${MOSAIC_INSTALL_IMAGE:-node:22-bookworm-slim}"
GIT_MODE="${MOSAIC_INSTALL_GIT_MODE:-present}"
INSTALLER_FILE="${MOSAIC_FIXTURE_INSTALLER_FILE:-$ROOT/tools/install.sh}"
INSTALLER_URL="${MOSAIC_FIXTURE_INSTALLER_URL:-}"
INSTALLER_SHA256="${MOSAIC_FIXTURE_INSTALLER_SHA256:-}"
IN_CLEAN_CONTAINER="${MOSAIC_GREENFIELD_CONTAINER:-0}"
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
IMAGE="node:22-alpine"
CONTAINER_NAME="mosaic-e2e-install-$$"
usage() {
cat <<'EOF'
Usage: tools/e2e-install-test.sh [--lane next|main] [--source checkout|remote] [--git present|absent]
Runs the documented installer command from zero in Debian/glibc as a non-root
uid with an isolated HOME. The fixture exits non-zero when any P0-P8
postcondition fails. `next` is always selected with the --next installer flag.
EOF
}
while [[ $# -gt 0 ]]; do
case "$1" in
--lane) LANE="${2:-}"; shift 2 ;;
--source) SOURCE="${2:-}"; shift 2 ;;
--git) GIT_MODE="${2:-}"; shift 2 ;;
-h|--help) usage; exit 0 ;;
*) echo "[fixture] unknown argument: $1" >&2; usage >&2; exit 2 ;;
esac
done
case "$LANE" in next|main) ;; *) echo "[fixture] unsupported lane '$LANE' (expected next|main)" >&2; exit 2 ;; esac
case "$SOURCE" in checkout|remote) ;; *) echo "[fixture] unsupported source '$SOURCE' (expected checkout|remote)" >&2; exit 2 ;; esac
case "$GIT_MODE" in present|absent) ;; *) echo "[fixture] unsupported git mode '$GIT_MODE' (expected present|absent)" >&2; exit 2 ;; esac
if [[ "$SOURCE" == remote ]]; then
[[ -n "$INSTALLER_URL" ]] || INSTALLER_URL="https://git.mosaicstack.dev/mosaicstack/stack/raw/branch/${LANE}/tools/install.sh"
[[ "$INSTALLER_SHA256" =~ ^[0-9a-f]{64}$ ]] \
|| { echo '[fixture] remote source requires MOSAIC_FIXTURE_INSTALLER_SHA256=64hex' >&2; exit 2; }
# ─── Colour helpers ───────────────────────────────────────────────────────────
if [[ -t 1 ]]; then
R=$'\033[0;31m' G=$'\033[0;32m' Y=$'\033[0;33m' BOLD=$'\033[1m' RESET=$'\033[0m'
else
R="" G="" Y="" BOLD="" RESET=""
fi
if [[ "$IN_CLEAN_CONTAINER" != "1" ]]; then
if ! command -v docker >/dev/null 2>&1; then
echo "[fixture] FAIL: Docker is required; greenfield validation was NOT RUN." >&2
exit 2
fi
if ! docker info >/dev/null 2>&1; then
echo "[fixture] FAIL: Docker daemon is unavailable; greenfield validation was NOT RUN." >&2
exit 2
fi
info() { echo "${BOLD}[e2e]${RESET} $*"; }
ok() { echo "${G}[PASS]${RESET} $*"; }
fail() { echo "${R}[FAIL]${RESET} $*" >&2; }
warn() { echo "${Y}[WARN]${RESET} $*"; }
# ─── Docker availability check ────────────────────────────────────────────────
if ! command -v docker &>/dev/null; then
warn "Docker not found — skipping e2e install test."
warn "Install Docker and re-run this script to exercise the full install flow."
exit 0
fi
installer_b64=""
framework_payload_count="NOT-MEASURED"
repo_root_count="NOT-MEASURED"
checkout_archive=""
checkout_digest=""
checkout_content_id=""
if [[ "$SOURCE" == "checkout" ]]; then
installer_b64="$(base64 -w0 "$INSTALLER_FILE")"
[[ -d "$ROOT/packages/mosaic/framework/skills" ]] \
&& framework_payload_count="$(find "$ROOT/packages/mosaic/framework/skills" -mindepth 1 -maxdepth 1 -type d | wc -l | tr -d ' ')"
[[ -d "$ROOT/skills" ]] \
&& repo_root_count="$(find "$ROOT/skills" -mindepth 1 -maxdepth 1 -type d | wc -l | tr -d ' ')"
checkout_archive="$(mktemp "${TMPDIR:-/tmp}/mosaic-greenfield-checkout.XXXXXX")"
repo_parent="$(dirname "$ROOT")"
repo_name="$(basename "$ROOT")"
tar -C "$repo_parent" \
--exclude='*/.git' --exclude='*/node_modules' --exclude='*/dist' \
--exclude='*/coverage' --exclude='*/.turbo' --exclude='*/.mosaic-test-work' \
--exclude='*/.env' --exclude='*/.env.*' \
-czf "$checkout_archive" "$repo_name"
checkout_digest="$(sha256sum "$checkout_archive" | awk '{print $1}')"
checkout_content_id="${checkout_digest:0:40}"
if ! docker info &>/dev/null 2>&1; then
warn "Docker daemon is not running or not accessible — skipping e2e install test."
exit 0
fi
inner="$(mktemp "${TMPDIR:-/tmp}/mosaic-greenfield-inner.XXXXXX")"
trap 'rm -f "$inner" "$checkout_archive"' EXIT
cat > "$inner" <<'INNER'
#!/usr/bin/env bash
set -euo pipefail
info "Docker available — proceeding with e2e install test."
info "Repo root: ${REPO_ROOT}"
info "Container image: ${IMAGE}"
export DEBIAN_FRONTEND=noninteractive
apt-get update -qq
packages=(bash ca-certificates curl jq passwd python3 util-linux)
[[ "$FIXTURE_GIT_MODE" == "present" ]] && packages+=(git)
apt-get install -y -qq "${packages[@]}" >/dev/null
# ─── Inline script that runs INSIDE the container ────────────────────────────
INNER_SCRIPT="$(mktemp /tmp/mosaic-e2e-inner-XXXXXX.sh)"
trap 'rm -f "$INNER_SCRIPT"' EXIT
if [[ "$FIXTURE_SOURCE" == "checkout" ]]; then
awk 'found { print } /^__MOSAIC_CHECKOUT_ARCHIVE__$/ { found=1; next }' "$0" | base64 -d > /tmp/source-checkout.tar.gz
actual_checkout_digest="$(sha256sum /tmp/source-checkout.tar.gz | awk '{print $1}')"
if [[ "$actual_checkout_digest" != "$FIXTURE_CHECKOUT_SHA256" ]]; then
echo "[fixture] checkout archive transport digest mismatch" >&2
exit 1
fi
fi
useradd --create-home --uid 1001 --shell /bin/bash mosaic
install -d -o mosaic -g mosaic /home/mosaic/work
case "$FIXTURE_SOURCE" in
checkout)
printf '%s' "$FIXTURE_INSTALLER_B64" | base64 -d > /tmp/install.sh
;;
remote)
curl -fsSL "$FIXTURE_INSTALLER_URL" -o /tmp/install.sh
[[ -s /tmp/install.sh ]] || { echo '[fixture] remote installer returned an empty HTTP-success body' >&2; exit 1; }
actual_installer_sha256="$(sha256sum /tmp/install.sh | awk '{print $1}')"
[[ "$actual_installer_sha256" == "$FIXTURE_INSTALLER_SHA256" ]] || {
echo "[fixture] remote installer digest mismatch got=$actual_installer_sha256 expected=$FIXTURE_INSTALLER_SHA256" >&2
exit 1
}
;;
esac
chmod 0755 /tmp/install.sh
sha256sum /tmp/install.sh | sed 's/^/[fixture] installer sha256: /'
cat > /tmp/run-as-target.sh <<'TARGET'
#!/usr/bin/env bash
set -uo pipefail
lane="$FIXTURE_LANE"
home="$HOME"
prefix="$home/.npm-global"
mosaic_home="$home/.config/mosaic"
install_log="$home/install.log"
failures=0
phase_pass() { printf '[%s] PASS: %s\n' "$1" "$2"; }
phase_fail() { printf '[%s] FAIL: %s\n' "$1" "$2"; failures=$((failures + 1)); }
lane_args=()
resolved_spec='@mosaicstack/mosaic'
if [[ "$lane" == "next" ]]; then
lane_args+=(--next)
resolved_spec='@mosaicstack/mosaic@next'
fi
resolved_version="$(npm view "$resolved_spec" version --registry=https://git.mosaicstack.dev/api/packages/mosaicstack/npm/ 2>/dev/null || true)"
printf '[fixture] resolved lane=%s package=%s version=%s\n' "$lane" "$resolved_spec" "${resolved_version:-UNRESOLVED}"
secret_canary='MOSAIC_C1_CANARY_6f3c91e2'
argv_capture=/tmp/mosaic-installer-argv.log
: > "$argv_capture"
set +e
MOSAIC_NO_COLOR=1 MOSAIC_ASSUME_YES=1 MOSAIC_INSTALL_SECRET_CANARY="$secret_canary" \
MOSAIC_INSTALL_REDACTION_PROBE=1 \
bash /tmp/install.sh "${lane_args[@]}" --yes --no-auto-launch >"$install_log" 2>&1 &
installer_pid=$!
while kill -0 "$installer_pid" 2>/dev/null; do
for cmdline in /proc/[0-9]*/cmdline; do
[[ -r "$cmdline" ]] || continue
tr '\0' ' ' < "$cmdline" >> "$argv_capture" 2>/dev/null || true
printf '\n' >> "$argv_capture"
done
sleep 0.02
done
wait "$installer_pid"
install_status=$?
cat > "$INNER_SCRIPT" <<'INNER_SCRIPT_EOF'
#!/bin/sh
# Bootstrap: /bin/sh until bash is installed, then re-exec.
set -e
cat "$install_log"
probe_ok=true
if [[ "$FIXTURE_GIT_MODE" == present ]] \
&& ! grep -q '^\[REDACTION-PROBE\] emitted=\[REDACTED\]$' "$install_log"; then
probe_ok=false
fi
if [[ "$probe_ok" != true ]] \
|| grep -F "$secret_canary" "$argv_capture" >/dev/null \
|| grep -R -F "$secret_canary" "$home" >/dev/null 2>&1; then
phase_fail P0 'seeded credential probe missing or canary leaked to argv, output, command log, npmrc, generated files, or shell history'
else
printf '[SECRET-CONTROL] PASS: seeded captured-command canary was redacted and absent from argv/output/commands.log/npmrc/generated/history populations\n'
fi
printf '[fixture] installer_exit=%d done_claims=%s\n' \
"$install_status" "$(grep -cF 'Done.' "$install_log" || true)"
# P0 Resolve context
shell="$(getent passwd "$(id -u)" | cut -d: -f7)"
if [[ "$(id -u)" -ne 0 && "$home" == "/home/mosaic" && "$shell" == "/bin/bash" ]] \
&& ldd --version 2>&1 | grep -i 'glibc\|gnu libc' >/dev/null \
&& [[ "$(node -p 'Number(process.versions.node.split(".")[0])')" -ge 20 ]]; then
phase_pass P0 "target=mosaic uid=$(id -u) HOME=$home shell=$shell libc=glibc node=$(node --version)"
else
phase_fail P0 "context unresolved or unsupported (uid=$(id -u) HOME=$home shell=${shell:-unknown})"
echo "=== [inner] Installing system prerequisites ==="
apk add --no-cache bash curl jq git 2>/dev/null || \
apt-get install -y -q bash curl jq git 2>/dev/null || true
# Re-exec under bash.
if [ -z "${BASH_VERSION:-}" ] && command -v bash >/dev/null 2>&1; then
exec bash "$0" "$@"
fi
# P1 Preflight
missing_tools=()
for tool in bash curl git node npm python3 tar; do
command -v "$tool" >/dev/null 2>&1 || missing_tools+=("$tool")
done
if [[ "${#missing_tools[@]}" -eq 0 && -n "$resolved_version" && -w "$home" ]]; then
phase_pass P1 "required tools present (including downstream git); target HOME writable; registry lane resolved"
else
phase_fail P1 "undeclared/missing prerequisite(s)=${missing_tools[*]:-none}; target_writable=$([[ -w "$home" ]] && echo yes || echo no) registry_resolved=$([[ -n "$resolved_version" ]] && echo yes || echo no)"
fi
# ── bash from here ────────────────────────────────────────────────────────────
set -euo pipefail
# P2 Acquire artifacts
if [[ -n "$resolved_version" ]] && grep -qF "$resolved_version" "$install_log"; then
phase_pass P2 "lane=$lane pinned_version=$resolved_version recorded in installer transcript"
else
phase_fail P2 "lane=$lane did not resolve and record a pinned artifact version"
fi
echo "=== [inner] Node.js / npm versions ==="
node --version
npm --version
# P3 Install CLI — the discriminating row. Use the known absolute path only.
cli="$prefix/bin/mosaic"
cli_version=""
if [[ -x "$cli" ]]; then
cli_version="$($cli --version 2>/dev/null | tail -n 1 | tr -d '\r' || true)"
fi
if [[ -x "$cli" && "$cli_version" == "$resolved_version" ]]; then
phase_pass P3 "absolute_path=$cli version=$cli_version equals resolved lane version"
else
phase_fail P3 "absolute_path=$cli executable=$([[ -x "$cli" ]] && echo yes || echo no) got=${cli_version:-missing} expected=${resolved_version:-unresolved}"
fi
echo "=== [inner] Setting up npm global prefix ==="
export NPM_PREFIX="/root/.npm-global"
mkdir -p "$NPM_PREFIX/bin"
npm config set prefix "$NPM_PREFIX" 2>/dev/null || true
export PATH="$NPM_PREFIX/bin:$PATH"
# P4 Framework + skills. C1 does not choose among the four disagreeing
# candidate populations. It requires the installer to publish a lane/versioned
# shipped-set declaration that a checkout-free install can resolve; C5 owns its
# contents. Without that artifact P4 is NOT-MEASURED, never a fabricated count.
declared_set="$mosaic_home/.install-shipped-skills.json"
sync_store_count=0
runtime_link_count=0
[[ -d "$mosaic_home/skills" ]] \
&& sync_store_count="$(find "$mosaic_home/skills" -mindepth 1 -maxdepth 1 -type d | wc -l | tr -d ' ')"
[[ -d "$home/.pi/agent/skills" ]] \
&& runtime_link_count="$(find "$home/.pi/agent/skills" -mindepth 1 -maxdepth 1 \( -type d -o -type l \) | wc -l | tr -d ' ')"
printf '[P4-EVIDENCE] candidate_populations framework_payload=%s repo_root=%s sync_store=%s jarvis_W-jarvis_observation=7 runtime_links=%s\n' \
"$FIXTURE_FRAMEWORK_PAYLOAD_COUNT" "$FIXTURE_REPO_ROOT_COUNT" "$sync_store_count" "$runtime_link_count"
if [[ ! -s "$declared_set" ]]; then
phase_fail P4 "NOT-MEASURED / UNDECLARED: installer published no checkout-free, lane/versioned shipped-set artifact at $declared_set"
elif EXPECTED_LANE="$([[ "$lane" == next ]] && echo next || echo latest)" EXPECTED_VERSION="$resolved_version" \
MOSAIC_SKILLS_ROOT="$mosaic_home/skills" node - "$declared_set" <<'NODE'
const fs = require('fs');
const path = require('path');
const data = JSON.parse(fs.readFileSync(process.argv[2], 'utf8'));
const root = path.resolve(process.env.MOSAIC_SKILLS_ROOT);
if (!data || data.lane !== process.env.EXPECTED_LANE || data.version !== process.env.EXPECTED_VERSION ||
!Array.isArray(data.skills) || data.skills.length === 0) process.exit(1);
for (const name of data.skills) {
if (typeof name !== 'string' || !/^[A-Za-z0-9][A-Za-z0-9._-]*$/.test(name)) process.exit(1);
const skill = path.join(root, name, 'SKILL.md');
let real;
try { real = fs.realpathSync(skill); } catch { process.exit(1); }
const text = fs.readFileSync(real, 'utf8');
const declaredName = text.match(/^---\s*$[\s\S]*?^name:\s*([^\s]+)\s*$/m)?.[1];
if (!real.startsWith(root + path.sep) || !fs.statSync(real).isFile() || !text || declaredName !== name) process.exit(1);
echo "=== [inner] Running install.sh --yes --no-auto-launch ==="
# Install both framework and CLI from the Gitea registry.
MOSAIC_SKIP_SKILLS_SYNC=1 \
MOSAIC_ASSUME_YES=1 \
bash /repo/tools/install.sh --yes --no-auto-launch
INSTALLED_VERSION="$(mosaic --version 2>/dev/null || echo 'unknown')"
echo "[inner] mosaic CLI installed: ${INSTALLED_VERSION}"
echo "=== [inner] Running mosaic wizard (non-interactive) ==="
mosaic wizard \
--non-interactive \
--name "test-agent" \
--user-name "tester" \
--pronouns "they/them" \
--timezone "UTC" || {
echo "[WARN] mosaic wizard exited non-zero — continuing"
}
NODE
then
declared_count="$(node -p "require('$declared_set').skills.length")"
if [[ -s "$mosaic_home/.install-manifest.json" ]] \
&& [[ "$(node -p "require('$mosaic_home/.install-manifest.json').phaseOutcomes?.P4 || 'committed'")" == failed ]]; then
phase_fail P4 "declared skills are present but the required framework/skills action reported failure"
else
phase_pass P4 "declared shipped-set matches lane/version and all $declared_count skill(s) are contained and loadable"
fi
echo "=== [inner] Running mosaic gateway install ==="
# Feed non-interactive answers:
# "1" → storage tier: local
# "" → port: accept default (14242)
# "" → ANTHROPIC_API_KEY: skip
# "" → CORS origin: accept default
# Then admin bootstrap: name, email, password
printf '1\n\n\n\nTest Admin\[email protected]\ntestpassword123\n' \
| mosaic gateway install
INSTALL_EXIT="$?"
if [ "${INSTALL_EXIT}" -ne 0 ]; then
echo "[ERR] mosaic gateway install exited ${INSTALL_EXIT}"
mosaic gateway status 2>/dev/null || true
exit "${INSTALL_EXIT}"
fi
echo "=== [inner] Running mosaic gateway verify ==="
# `gateway verify` was added in feat/mosaic-first-run-ux.
# If the installed version pre-dates this, skip gracefully.
if ! mosaic gateway --help 2>&1 | grep -q 'verify'; then
echo "[SKIP] 'mosaic gateway verify' not available in installed version ${INSTALLED_VERSION}."
echo "[SKIP] This command was added in the feat/mosaic-first-run-ux release."
echo "[SKIP] Re-run after the new version is published to validate this step."
# Treat as pass — the install flow itself worked.
exit 0
fi
mosaic gateway verify
VERIFY_EXIT="$?"
echo "=== [inner] verify exit code: ${VERIFY_EXIT} ==="
exit "${VERIFY_EXIT}"
INNER_SCRIPT_EOF
chmod +x "$INNER_SCRIPT"
# ─── Pull image ───────────────────────────────────────────────────────────────
info "Pulling ${IMAGE}"
docker pull "${IMAGE}" --quiet
# ─── Run container ────────────────────────────────────────────────────────────
info "Starting container ${CONTAINER_NAME}"
EXIT_CODE=0
docker run --rm \
--name "${CONTAINER_NAME}" \
--volume "${REPO_ROOT}:/repo:ro" \
--volume "${INNER_SCRIPT}:/e2e-inner.sh:ro" \
--network host \
"${IMAGE}" \
/bin/sh /e2e-inner.sh \
|| EXIT_CODE=$?
# ─── Report ───────────────────────────────────────────────────────────────────
echo ""
if [[ "$EXIT_CODE" -eq 0 ]]; then
ok "End-to-end install test PASSED (exit ${EXIT_CODE})"
else
phase_fail P4 "shipped-set artifact is malformed, wrong-lane/version, or its declared skills are not contained and loadable"
fi
# P5 Identity
identity_ok=true
identity_reason=()
for f in SOUL.md USER.md; do
path="$mosaic_home/$f"
if [[ ! -s "$path" ]]; then
identity_ok=false; identity_reason+=("$f missing-or-empty"); continue
fi
owner="$(stat -c '%u' "$path")"; mode="$(stat -c '%a' "$path")"
if [[ "$owner" != "$(id -u)" || "$mode" =~ [2367]$ ]]; then
identity_ok=false; identity_reason+=("$f owner=$owner mode=$mode")
fi
done
if [[ "$identity_ok" == true ]]; then
phase_pass P5 "SOUL.md and USER.md are non-empty and target-user owned with non-world-writable modes"
else
phase_fail P5 "${identity_reason[*]}"
fi
# P6 Runtime linking / activation. #869 must remain unwired without its broker.
manifest="$mosaic_home/.install-manifest.json"
broker_present=false
[[ -S "${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/mosaic-lease/broker.sock" ]] && broker_present=true
dead_hooks=0
if [[ -f "$home/.claude/settings.json" ]]; then
dead_hooks="$(grep -Ec 'mutator-gate\.py|receipt-observer-client\.py' "$home/.claude/settings.json" || true)"
fi
p6_action_failed=false
if [[ -s "$manifest" ]]; then
p6_action_failed="$(node -p "require('$manifest').phaseOutcomes?.P6 === 'failed' ? 'true' : 'false'" 2>/dev/null || echo true)"
fi
if [[ "$p6_action_failed" == true ]]; then
phase_fail P6 "runtime linking/activation action reported a required failure"
elif [[ "$broker_present" == false && "$dead_hooks" -eq 0 ]]; then
phase_pass P6 "broker absent and #869 enforcement hooks remain inactive"
elif [[ "$broker_present" == true ]]; then
phase_pass P6 "activation broker present; hook state is evaluable"
else
phase_fail P6 "broker absent but dead enforcement hooks are active (count=$dead_hooks)"
fi
# P7 Services — none requested by --no-auto-launch.
phase_pass P7 "no services requested by this fixture"
# P8 Shell discoverability — actual target shell, fresh login and non-login.
base_env=(env -i HOME="$home" USER=mosaic LOGNAME=mosaic SHELL=/bin/bash PATH=/usr/local/bin:/usr/bin:/bin)
login_path="$("${base_env[@]}" /bin/bash -lc 'command -v mosaic' 2>/dev/null || true)"
nonlogin_path="$("${base_env[@]}" /bin/bash -c 'command -v mosaic' 2>/dev/null || true)"
if [[ "$login_path" == "$cli" && "$nonlogin_path" == "$cli" ]]; then
phase_pass P8 "login=$login_path nonlogin=$nonlogin_path equals P3 path"
else
phase_fail P8 "fresh bash login=${login_path:-missing} nonlogin=${nonlogin_path:-missing} expected=$cli"
fi
manifest="$mosaic_home/.install-manifest.json"
p0_p8_failures="$failures"
if [[ "$p0_p8_failures" -eq 0 && -s "$manifest" ]]; then
phase_pass P9 "P0-P8 reasserted; manifest present"
else
phase_fail P9 "P0-P8_failed_postconditions=$p0_p8_failures manifest=$([[ -s "$manifest" ]] && echo present || echo missing); install must not certify success"
fi
printf '[fixture] P0-P9_failed_rows=%d (includes P9 aggregate row)\n' "$failures"
if [[ "$failures" -ne 0 ]]; then
fail "End-to-end install test FAILED (exit ${EXIT_CODE})"
echo ""
echo " Troubleshooting:"
echo " - Review the output above for the failing step."
echo " - Re-run with bash -x tools/e2e-install-test.sh for verbose trace."
echo " - Run mosaic gateway logs inside a manual container for daemon output."
exit 1
fi
TARGET
chmod 0755 /tmp/run-as-target.sh
chown mosaic:mosaic /tmp/run-as-target.sh
exec runuser -u mosaic -- env -i \
HOME=/home/mosaic USER=mosaic LOGNAME=mosaic SHELL=/bin/bash \
PATH=/usr/local/bin:/usr/bin:/bin \
FIXTURE_LANE="$FIXTURE_LANE" \
FIXTURE_GIT_MODE="$FIXTURE_GIT_MODE" \
FIXTURE_FRAMEWORK_PAYLOAD_COUNT="$FIXTURE_FRAMEWORK_PAYLOAD_COUNT" \
FIXTURE_REPO_ROOT_COUNT="$FIXTURE_REPO_ROOT_COUNT" \
MOSAIC_INSTALL_LOCAL_SOURCE_ARCHIVE="$([[ "$FIXTURE_SOURCE" == "checkout" ]] && echo /tmp/source-checkout.tar.gz)" \
MOSAIC_INSTALL_LOCAL_SOURCE_COMMIT="$FIXTURE_CHECKOUT_CONTENT_ID" \
MOSAIC_INSTALL_LOCAL_SOURCE_SHA256="$FIXTURE_CHECKOUT_SHA256" \
/bin/bash /tmp/run-as-target.sh
INNER
if [[ "$SOURCE" == "checkout" ]]; then
{
printf '\n__MOSAIC_CHECKOUT_ARCHIVE__\n'
base64 "$checkout_archive"
} >> "$inner"
fi
chmod 0755 "$inner"
printf '[fixture] platform=Debian/glibc image=%s target_uid=1001 lane=%s source=%s git=%s\n' "$IMAGE" "$LANE" "$SOURCE" "$GIT_MODE"
printf '[fixture] host inheritance: no bind mounts, no host HOME, no npm cache, no credentials\n'
if [[ "$IN_CLEAN_CONTAINER" == "1" ]]; then
# Woodpecker already supplies the clean Debian container. The target install
# still runs through runuser + env -i, so CI variables/credentials do not
# enter the target user's process.
FIXTURE_LANE="$LANE" \
FIXTURE_SOURCE="$SOURCE" \
FIXTURE_GIT_MODE="$GIT_MODE" \
FIXTURE_INSTALLER_B64="$installer_b64" \
FIXTURE_INSTALLER_URL="$INSTALLER_URL" \
FIXTURE_INSTALLER_SHA256="$INSTALLER_SHA256" \
FIXTURE_CHECKOUT_SHA256="$checkout_digest" \
FIXTURE_CHECKOUT_CONTENT_ID="$checkout_content_id" \
FIXTURE_FRAMEWORK_PAYLOAD_COUNT="$framework_payload_count" \
FIXTURE_REPO_ROOT_COUNT="$repo_root_count" \
/bin/bash "$inner"
else
# Copy the self-contained script+archive into a stopped container instead of
# bind-mounting the checkout or passing host paths. The target runtime still
# inherits no host HOME/cache/credentials, and the multi-megabyte checkout
# payload avoids argv/environment size limits.
fixture_cid="$(docker create \
--network bridge \
--env FIXTURE_LANE="$LANE" \
--env FIXTURE_SOURCE="$SOURCE" \
--env FIXTURE_GIT_MODE="$GIT_MODE" \
--env FIXTURE_INSTALLER_B64="$installer_b64" \
--env FIXTURE_INSTALLER_URL="$INSTALLER_URL" \
--env FIXTURE_INSTALLER_SHA256="$INSTALLER_SHA256" \
--env FIXTURE_CHECKOUT_SHA256="$checkout_digest" \
--env FIXTURE_CHECKOUT_CONTENT_ID="$checkout_content_id" \
--env FIXTURE_FRAMEWORK_PAYLOAD_COUNT="$framework_payload_count" \
--env FIXTURE_REPO_ROOT_COUNT="$repo_root_count" \
"$IMAGE" /bin/bash /tmp/mosaic-greenfield-fixture.sh)"
docker cp "$inner" "$fixture_cid:/tmp/mosaic-greenfield-fixture.sh"
set +e
docker start -a "$fixture_cid"
fixture_status=$?
set -e
docker rm "$fixture_cid" >/dev/null
exit "$fixture_status"
fi
@@ -1,54 +0,0 @@
# Pinned C1 expected-RED contract. Updating a verdict/reason requires review by the owning remediation lane.
# case kind key/value
next-git-present exit 1
next-git-present phase P0=PASS
next-git-present phase P1=PASS
next-git-present phase P2=PASS
next-git-present phase P3=PASS
next-git-present phase P4=FAIL
next-git-present phase P5=FAIL
next-git-present phase P6=FAIL
next-git-present phase P7=PASS
next-git-present phase P8=FAIL
next-git-present phase P9=FAIL
next-git-present require ^\[fixture\] resolved lane=next .*version=[0-9]+\.[0-9]+\.[0-9]+-next\.
next-git-present require ^\[fixture\] installer_exit=1 done_claims=0$
next-git-present require ^\[SECRET-CONTROL\] PASS:
next-git-present require ^\[P3\] PASS: absolute_path=.* version=.* equals resolved lane version$
next-git-present require ^\[P4\] FAIL: NOT-MEASURED / UNDECLARED:
next-git-present require ^\[P6\] FAIL: broker absent but dead enforcement hooks are active
next-git-present forbid Done\.|MOSAIC_C1_CANARY_|CLI not found on PATH
main-git-present exit 1
main-git-present phase P0=PASS
main-git-present phase P1=PASS
main-git-present phase P2=PASS
main-git-present phase P3=PASS
main-git-present phase P4=FAIL
main-git-present phase P5=FAIL
main-git-present phase P6=FAIL
main-git-present phase P7=PASS
main-git-present phase P8=FAIL
main-git-present phase P9=FAIL
main-git-present require ^\[fixture\] resolved lane=main .*version=[0-9]+\.[0-9]+\.[0-9]+$
main-git-present require ^\[fixture\] installer_exit=1 done_claims=0$
main-git-present require ^\[SECRET-CONTROL\] PASS:
main-git-present require ^\[P3\] PASS: absolute_path=.* version=.* equals resolved lane version$
main-git-present require ^\[P4\] FAIL: NOT-MEASURED / UNDECLARED:
main-git-present require ^\[P6\] FAIL: runtime linking/activation action reported a required failure
main-git-present forbid Done\.|MOSAIC_C1_CANARY_|CLI not found on PATH
next-git-absent exit 1
next-git-absent phase P0=PASS
next-git-absent phase P1=FAIL
next-git-absent phase P2=FAIL
next-git-absent phase P3=FAIL
next-git-absent phase P4=FAIL
next-git-absent phase P5=FAIL
next-git-absent phase P6=PASS
next-git-absent phase P7=PASS
next-git-absent phase P8=FAIL
next-git-absent phase P9=FAIL
next-git-absent require ^\[fixture\] installer_exit=1 done_claims=0$
next-git-absent require ^\[SECRET-CONTROL\] PASS:
next-git-absent require ^\[P1\] FAIL: undeclared/missing prerequisite\(s\)=git;
next-git-absent require ^\[P3\] FAIL: .*executable=no
next-git-absent forbid Done\.|MOSAIC_C1_CANARY_
1 # Pinned C1 expected-RED contract. Updating a verdict/reason requires review by the owning remediation lane.
2 # case kind key/value
3 next-git-present exit 1
4 next-git-present phase P0=PASS
5 next-git-present phase P1=PASS
6 next-git-present phase P2=PASS
7 next-git-present phase P3=PASS
8 next-git-present phase P4=FAIL
9 next-git-present phase P5=FAIL
10 next-git-present phase P6=FAIL
11 next-git-present phase P7=PASS
12 next-git-present phase P8=FAIL
13 next-git-present phase P9=FAIL
14 next-git-present require ^\[fixture\] resolved lane=next .*version=[0-9]+\.[0-9]+\.[0-9]+-next\.
15 next-git-present require ^\[fixture\] installer_exit=1 done_claims=0$
16 next-git-present require ^\[SECRET-CONTROL\] PASS:
17 next-git-present require ^\[P3\] PASS: absolute_path=.* version=.* equals resolved lane version$
18 next-git-present require ^\[P4\] FAIL: NOT-MEASURED / UNDECLARED:
19 next-git-present require ^\[P6\] FAIL: broker absent but dead enforcement hooks are active
20 next-git-present forbid Done\.|MOSAIC_C1_CANARY_|CLI not found on PATH
21 main-git-present exit 1
22 main-git-present phase P0=PASS
23 main-git-present phase P1=PASS
24 main-git-present phase P2=PASS
25 main-git-present phase P3=PASS
26 main-git-present phase P4=FAIL
27 main-git-present phase P5=FAIL
28 main-git-present phase P6=FAIL
29 main-git-present phase P7=PASS
30 main-git-present phase P8=FAIL
31 main-git-present phase P9=FAIL
32 main-git-present require ^\[fixture\] resolved lane=main .*version=[0-9]+\.[0-9]+\.[0-9]+$
33 main-git-present require ^\[fixture\] installer_exit=1 done_claims=0$
34 main-git-present require ^\[SECRET-CONTROL\] PASS:
35 main-git-present require ^\[P3\] PASS: absolute_path=.* version=.* equals resolved lane version$
36 main-git-present require ^\[P4\] FAIL: NOT-MEASURED / UNDECLARED:
37 main-git-present require ^\[P6\] FAIL: runtime linking/activation action reported a required failure
38 main-git-present forbid Done\.|MOSAIC_C1_CANARY_|CLI not found on PATH
39 next-git-absent exit 1
40 next-git-absent phase P0=PASS
41 next-git-absent phase P1=FAIL
42 next-git-absent phase P2=FAIL
43 next-git-absent phase P3=FAIL
44 next-git-absent phase P4=FAIL
45 next-git-absent phase P5=FAIL
46 next-git-absent phase P6=PASS
47 next-git-absent phase P7=PASS
48 next-git-absent phase P8=FAIL
49 next-git-absent phase P9=FAIL
50 next-git-absent require ^\[fixture\] installer_exit=1 done_claims=0$
51 next-git-absent require ^\[SECRET-CONTROL\] PASS:
52 next-git-absent require ^\[P1\] FAIL: undeclared/missing prerequisite\(s\)=git;
53 next-git-absent require ^\[P3\] FAIL: .*executable=no
54 next-git-absent forbid Done\.|MOSAIC_C1_CANARY_
-576
View File
@@ -1,576 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
TMP="$(mktemp -d "${TMPDIR:-/tmp}/mosaic-next-install-test-XXXXXX")"
trap 'rm -rf "$TMP"' EXIT
export TMPDIR="$TMP/runtime-tmp"
mkdir -p "$TMPDIR"
FAKE_BIN="$TMP/bin"
HOME_DIR="$TMP/home"
PREFIX="$HOME_DIR/prefix"
MOSAIC_HOME="$HOME_DIR/mosaic"
STATE="$TMP/state"
LOG="$TMP/npm.log"
mkdir -p "$FAKE_BIN" "$HOME_DIR" "$STATE"
# Model the supported non-root/glibc target explicitly even when this harness
# itself runs as root in Alpine/BusyBox CI.
cat > "$FAKE_BIN/id" <<'FAKE_ID'
#!/usr/bin/env bash
case "${1:-}" in
-u) echo 1001 ;;
-g) echo 1001 ;;
-un) echo fixture-user ;;
*) exec /bin/id "$@" ;;
esac
FAKE_ID
cat > "$FAKE_BIN/getent" <<FAKE_GETENT
#!/usr/bin/env bash
printf 'fixture-user:x:1001:1001::%s:/bin/bash\n' '$HOME_DIR'
FAKE_GETENT
cat > "$FAKE_BIN/ldd" <<'FAKE_LDD'
#!/usr/bin/env bash
printf 'ldd (GNU libc) 2.36\n'
FAKE_LDD
cat > "$FAKE_BIN/stat" <<'FAKE_STAT'
#!/usr/bin/env bash
if [[ "${1:-} ${2:-}" == '-c %u' ]]; then
[[ "${3:-}" == "${MOSAIC_TEST_WRONG_OWNER_PATH:-__none__}" ]] && echo 9999 || echo 1001
exit 0
fi
if [[ "${1:-} ${2:-}" == '-c %g' ]]; then
[[ "${3:-}" == "${MOSAIC_TEST_WRONG_GROUP_PATH:-__none__}" ]] && echo 9999 || echo 1001
exit 0
fi
exec /bin/stat "$@"
FAKE_STAT
cat > "$FAKE_BIN/realpath" <<'FAKE_REALPATH'
#!/usr/bin/env python3
import os, sys
args=sys.argv[1:]
mode=args.pop(0) if args and args[0] in ('-e','-m') else '-m'
if args and args[0]=='--': args.pop(0)
if len(args)!=1 or (mode=='-e' and not os.path.exists(args[0])): raise SystemExit(1)
print(os.path.realpath(args[0]))
FAKE_REALPATH
chmod 0755 "$FAKE_BIN/id" "$FAKE_BIN/getent" "$FAKE_BIN/ldd" "$FAKE_BIN/stat" "$FAKE_BIN/realpath"
cat > "$FAKE_BIN/npm" <<'FAKE_NPM'
#!/usr/bin/env bash
set -euo pipefail
LOG="${MOSAIC_TEST_NPM_LOG:?}"
STATE="${MOSAIC_TEST_STATE:?}"
echo "$*" >> "$LOG"
if [[ "${1:-}" == "--version" ]]; then
echo "10.6.2"
exit 0
fi
install_cli() {
local version="$1"
echo "$version" > "$STATE/mosaic"
mkdir -p "${MOSAIC_PREFIX:?}/bin"
cat > "$MOSAIC_PREFIX/bin/mosaic" <<CLI
#!/usr/bin/env bash
set -euo pipefail
if [[ "\${1:-}" == "wizard" ]]; then
printf 'wizard\n' >> "\${MOSAIC_TEST_NPM_LOG:?}"
mkdir -p "\${MOSAIC_HOME:?}" "\${HOME:?}/.config/mosaic-gateway"
printf '# Soul\\n\\nConfigured.\\n' > "\$MOSAIC_HOME/SOUL.md"
printf '# User\\n\\nConfigured.\\n' > "\$MOSAIC_HOME/USER.md"
chmod 0600 "\$MOSAIC_HOME/SOUL.md" "\$MOSAIC_HOME/USER.md"
exit 0
fi
printf '%s\\n' '$version'
CLI
chmod +x "$MOSAIC_PREFIX/bin/mosaic"
}
if [[ "$1" == "view" ]]; then
if [[ "${MOSAIC_TEST_FAIL_NPM_VIEW:-0}" == "1" ]]; then
echo "forced registry metadata failure" >&2
exit 1
fi
case "$2 $3" in
"@mosaicstack/mosaic@next version") echo "0.0.49-next.999" ;;
"@mosaicstack/gateway@next version") echo "${MOSAIC_TEST_GATEWAY_NEXT_VERSION:-0.0.7-next.999}" ;;
"@mosaicstack/mosaic version") echo "0.0.48" ;;
*) echo "unexpected npm view: $*" >&2; exit 1 ;;
esac
exit 0
fi
if [[ "$1" == "install" ]]; then
if [[ -n "${MOSAIC_INSTALL_SECRET_CANARY:-}" ]]; then
printf 'registry diagnostic authToken=%s\n' "$MOSAIC_INSTALL_SECRET_CANARY"
printf 'urls=https://alice:p@[email protected]/a https://bob:pa:[email protected]/b https://carol:p%%[email protected]/c https://[email protected]/d https://user%%[email protected]/e\n'
printf 'Authorization: Basic QWxhZGRpbjpvcGVu\n//registry/:_auth=Ym9iOnNlY3JldA==\nCookie: session=abc123\nSet-Cookie: sid=xyz789\n'
printf '%s\n' "$MOSAIC_INSTALL_SECRET_CANARY" > "${MOSAIC_TEST_CANARY_OBSERVATION:?}"
fi
case "$*" in
*"@mosaicstack/[email protected]"*)
install_cli "0.0.49-next.999"
;;
*"@mosaicstack/[email protected]"*)
if [[ "${MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL:-0}" == "1" ]]; then
echo "forced gateway install failure" >&2
exit 1
fi
echo "0.0.7-next.999" > "$STATE/gateway"
;;
*"mosaicstack-mosaic-0.0.0-source.tgz"*)
install_cli "0.0.0-source"
;;
*"mosaicstack-gateway-0.0.0-source.tgz"*)
echo "0.0.0-source" > "$STATE/gateway"
;;
*) echo "unexpected npm install: $*" >&2; exit 1 ;;
esac
exit 0
fi
if [[ "$1" == "ls" ]]; then
cli="$(cat "$STATE/mosaic" 2>/dev/null || true)"
gateway="$(cat "$STATE/gateway" 2>/dev/null || true)"
node -e '
const cli = process.argv[1];
const gateway = process.argv[2];
const dependencies = {};
if (cli) dependencies["@mosaicstack/mosaic"] = { version: cli };
if (gateway) dependencies["@mosaicstack/gateway"] = { version: gateway };
process.stdout.write(JSON.stringify({ dependencies }));
' "$cli" "$gateway"
exit 0
fi
echo "unexpected npm command: $*" >&2
exit 1
FAKE_NPM
chmod +x "$FAKE_BIN/npm"
cat > "$FAKE_BIN/curl" <<'FAKE_CURL'
#!/usr/bin/env bash
set -euo pipefail
headers=""; output=""; url=""
while [[ $# -gt 0 ]]; do
case "$1" in
-D) headers="$2"; shift 2 ;;
-o) output="$2"; shift 2 ;;
--max-filesize) shift 2 ;;
-*) shift ;;
*) url="$1"; shift ;;
esac
done
case "$url" in
*/api/v1/repos/mosaicstack/stack/commits?sha=*)
printf 'HTTP/1.1 200 OK\r\ncontent-type: application/json; charset=utf-8\r\n\r\n' > "$headers"
printf '[{"sha":"1111111111111111111111111111111111111111"}]\n' > "$output"
;;
*/archive/*.tar.gz)
if [[ "${MOSAIC_TEST_CORRUPT_ARCHIVE:-0}" == "1" ]]; then
printf 'not-a-tarball\n' > "$output"
else
archive_root="$(mktemp -d)"
mkdir -p "$archive_root/stack"
printf 'fixture\n' > "$archive_root/stack/.fixture"
/bin/tar czf "$output" -C "$archive_root" stack
rm -rf "$archive_root"
fi
;;
esac
FAKE_CURL
chmod +x "$FAKE_BIN/curl"
cat > "$FAKE_BIN/tar" <<'FAKE_TAR'
#!/usr/bin/env bash
set -euo pipefail
dest=""; list=false
while [[ $# -gt 0 ]]; do
case "$1" in
-C) dest="$2"; shift 2 ;;
-*t*|t*) list=true; shift ;;
*) shift ;;
esac
done
[[ "$list" == true ]] && exit 0
if [[ -z "$dest" ]]; then
echo "fake tar missing -C destination" >&2
exit 1
fi
mkdir -p "$dest/stack/packages/mosaic/framework" "$dest/stack/apps/gateway"
cat > "$dest/stack/packages/mosaic/framework/install.sh" <<'FRAMEWORK'
#!/usr/bin/env bash
set -euo pipefail
expected="${MOSAIC_PREFIX:?}/bin/mosaic"
[[ "${MOSAIC_CLI_PATH:-}" == "$expected" && -x "$MOSAIC_CLI_PATH" ]] || {
echo "framework did not receive P3 absolute CLI (got=${MOSAIC_CLI_PATH:-unset} expected=$expected)" >&2
exit 61
}
printf 'framework-cli=%s version=%s\n' "$MOSAIC_CLI_PATH" "$($MOSAIC_CLI_PATH --version)" >> "${MOSAIC_TEST_NPM_LOG:?}"
mkdir -p "${MOSAIC_HOME:?}/credentials"
chmod 0700 "$MOSAIC_HOME/credentials"
printf '# framework fixture\n' > "$MOSAIC_HOME/AGENTS.md"
FRAMEWORK
chmod 0755 "$dest/stack/packages/mosaic/framework/install.sh"
FAKE_TAR
chmod +x "$FAKE_BIN/tar"
cat > "$FAKE_BIN/pnpm" <<'FAKE_PNPM'
#!/usr/bin/env bash
set -euo pipefail
LOG="${MOSAIC_TEST_NPM_LOG:?}"
echo "pnpm $*" >> "$LOG"
if [[ "$1" == "pack" ]]; then
out=""
while [[ $# -gt 0 ]]; do
case "$1" in
--pack-destination) out="$2"; shift 2 ;;
*) shift ;;
esac
done
if [[ -z "$out" ]]; then
echo "fake pnpm pack missing destination" >&2
exit 1
fi
mkdir -p "$out"
case "$PWD" in
*/apps/gateway) touch "$out/mosaicstack-gateway-0.0.0-source.tgz" ;;
*/packages/mosaic) touch "$out/mosaicstack-mosaic-0.0.0-source.tgz" ;;
*) echo "unexpected pnpm pack cwd: $PWD" >&2; exit 1 ;;
esac
exit 0
fi
if [[ "${MOSAIC_TEST_FAIL_PNPM_INSTALL:-0}" == "1" && "$1" == "install" ]]; then
echo "forced pnpm install failure" >&2
exit 42
fi
# Other install/build commands are no-ops in this harness.
exit 0
FAKE_PNPM
chmod +x "$FAKE_BIN/pnpm"
reset_state() {
: > "$LOG"
rm -f "$STATE"/*
}
tree_fingerprint() {
local root="$1"
if [[ ! -d "$root" ]]; then printf 'ABSENT\n'; return; fi
python3 - "$root" <<'PY'
import hashlib, os, stat, sys
root=os.path.abspath(sys.argv[1]); rows=[]
for current, dirs, files in os.walk(root, topdown=True, followlinks=False):
for name in dirs + files:
path=os.path.join(current,name); meta=os.lstat(path)
rel=os.path.relpath(path,root)
target=os.readlink(path) if stat.S_ISLNK(meta.st_mode) else ''
digest=''
if stat.S_ISREG(meta.st_mode):
with open(path,'rb') as handle: digest=hashlib.sha256(handle.read()).hexdigest()
rows.append((rel,stat.S_IFMT(meta.st_mode),stat.S_IMODE(meta.st_mode),target,digest))
payload='\n'.join('|'.join(map(str,row)) for row in sorted(rows)).encode()
print(hashlib.sha256(payload).hexdigest())
PY
}
prefix_fingerprint() { tree_fingerprint "$PREFIX"; }
reset_state
echo "[test] --next fast path pins resolved package versions"
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch
)"
grep -qF 'Installed @next packages: CLI 0.0.49-next.999, gateway 0.0.7-next.999' <<<"$OUTPUT"
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
if grep -qE '^install -g .+@next( |$)' "$LOG"; then
echo "expected exact-version installs, found mutable @next install" >&2
exit 1
fi
if grep -qF 'Downloading source ref next at pinned commit' <<<"$OUTPUT"; then
echo "fast path unexpectedly fell back to source" >&2
exit 1
fi
ACTIVE="$HOME_DIR/.local/state/mosaic/install/active.json"
[[ "$(node -p "require('$ACTIVE').status")" == "committed" ]]
JOURNAL="$(node -p "require('$ACTIVE').journal")"
[[ "$(stat -c '%a' "$JOURNAL")" == "444" ]]
( cd "$(dirname "$JOURNAL")" && sha256sum -c "$(basename "$JOURNAL").sha256" >/dev/null )
grep -q '"event":"mutation".*"phase":"P3".*path=.*prior=.*reverse=' "$JOURNAL"
reset_state
echo "[test] fast path failure falls back to source build"
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch
)"
grep -qF 'Fast gateway @next install failed.' <<<"$OUTPUT"
grep -qF 'Falling back to source build at ref next; --next will not hard-fail on registry issues.' <<<"$OUTPUT"
grep -qF 'Downloading source ref next at pinned commit 1111111111111111111111111111111111111111' <<<"$OUTPUT"
grep -qF 'Installed from source: CLI 0.0.0-source' <<<"$OUTPUT"
grep -qF 'install -g @mosaicstack/[email protected]' "$LOG"
grep -qE 'install -g .*/mosaicstack-gateway-0\.0\.0-source\.tgz' "$LOG"
grep -qE 'install -g .*/mosaicstack-mosaic-0\.0\.0-source\.tgz' "$LOG"
[[ "$(cat "$STATE/mosaic")" == "0.0.0-source" ]]
[[ "$(cat "$STATE/gateway")" == "0.0.0-source" ]]
reset_state
echo "[test] source-build failure is fatal and restores the pre-install prefix"
before_prefix="$(prefix_fingerprint)"
set +e
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
MOSAIC_TEST_FAIL_PNPM_INSTALL=1 \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch 2>&1
)"
FAIL_STATUS=$?
set -e
[[ "$FAIL_STATUS" -ne 0 ]]
[[ "$(prefix_fingerprint)" == "$before_prefix" ]]
grep -qF 'forced pnpm install failure' <<<"$OUTPUT"
[[ "$(node -p "require('$ACTIVE').status")" == "rolled-back" ]]
reset_state
echo "[test] corrupt source archive is fatal and restores the pre-install prefix"
before_prefix="$(prefix_fingerprint)"
set +e
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_FAIL_NEXT_GATEWAY_INSTALL=1 \
MOSAIC_TEST_CORRUPT_ARCHIVE=1 \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch 2>&1
)"
FAIL_STATUS=$?
set -e
[[ "$FAIL_STATUS" -ne 0 ]]
[[ "$(prefix_fingerprint)" == "$before_prefix" ]]
grep -qF 'archive safety/integrity check failed' <<<"$OUTPUT"
[[ "$(node -p "require('$ACTIVE').status")" == "rolled-back" ]]
reset_state
echo "[test] --dev source install does not require registry version resolution"
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_FAIL_NPM_VIEW=1 \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --cli --dev --ref feature-x --yes --no-auto-launch
)"
grep -qF 'Downloading source ref feature-x at pinned commit 1111111111111111111111111111111111111111' <<<"$OUTPUT"
grep -qF 'Installed from source: CLI 0.0.0-source' <<<"$OUTPUT"
grep -q '^\[P2\] PASS: source_ref=feature-x pinned_commit=1111111111111111111111111111111111111111 sha256=' <<<"$OUTPUT"
reset_state
echo "[test] explicit --ref keeps source lane and avoids @next lookup"
set +e
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --check --cli --next --ref feature-x
)"
CHECK_STATUS=$?
set -e
[[ "$CHECK_STATUS" -ne 0 ]]
grep -q '^\[P2\] PASS: source_ref=feature-x pinned_commit=1111111111111111111111111111111111111111 sha256=' <<<"$OUTPUT"
if grep -qF '@next version' "$LOG"; then
echo "explicit ref should not query @next dist-tags" >&2
exit 1
fi
reset_state
echo "[test] --check --next rejects mismatched prerelease pipeline suffixes"
set +e
OUTPUT="$(
HOME="$HOME_DIR" \
MOSAIC_HOME="$MOSAIC_HOME" \
MOSAIC_PREFIX="$PREFIX" \
MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" \
MOSAIC_TEST_STATE="$STATE" \
MOSAIC_TEST_GATEWAY_NEXT_VERSION="0.0.7-next.1000" \
PATH="$FAKE_BIN:$PATH" \
bash "$ROOT/tools/install.sh" --check --cli --next
)"
CHECK_STATUS=$?
set -e
[[ "$CHECK_STATUS" -ne 0 ]]
grep -q '^\[P2\] FAIL: resolved_version=unavailable' <<<"$OUTPUT"
printf '[test] full framework path receives P3 absolute CLI without relying on PATH\n'
rm -rf "$HOME_DIR" "$STATE"; mkdir -p "$HOME_DIR" "$STATE"; reset_state
set +e
OUTPUT="$(
HOME="$HOME_DIR" MOSAIC_HOME="$MOSAIC_HOME" MOSAIC_PREFIX="$PREFIX" \
MOSAIC_INSTALL_STATE_DIR="$TMP/full-state" MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --next --yes --no-auto-launch 2>&1
)"
FULL_STATUS=$?
set -e
[[ "$FULL_STATUS" -ne 0 ]] # P4 remains intentionally undeclared until C5.
grep -qF "framework-cli=$PREFIX/bin/mosaic version=0.0.49-next.999" "$LOG"
if grep -q "CLI not found on PATH\|did not receive P3 absolute CLI" <<<"$OUTPUT"; then
echo "internal framework phase depended on PATH instead of P3 absolute CLI" >&2
exit 1
fi
printf '[test] captured diagnostics redact seeded credential canary everywhere\n'
rm -rf "$HOME_DIR" "$STATE"; mkdir -p "$HOME_DIR" "$STATE"; reset_state
canary='C1_SECRET_CANARY_7df4c2'
OUTPUT="$(
HOME="$HOME_DIR" MOSAIC_HOME="$MOSAIC_HOME" MOSAIC_PREFIX="$PREFIX" \
MOSAIC_INSTALL_STATE_DIR="$TMP/secret-state" MOSAIC_NO_COLOR=1 \
MOSAIC_INSTALL_SECRET_CANARY="$canary" MOSAIC_TEST_CANARY_OBSERVATION="$TMP/canary-observed" \
MOSAIC_TEST_NPM_LOG="$LOG" MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch 2>&1
)"
if grep -qF "$canary" <<<"$OUTPUT"; then echo 'credential canary leaked to terminal output' >&2; exit 1; fi
if grep -Eq 'alice:p@ss|bob:pa:ss|carol:p%40ss|token@example|user%3Apass|QWxhZGRpbjpvcGVu|Ym9iOnNlY3JldA|session=abc123|sid=xyz789' <<<"$OUTPUT"; then
echo 'credentialed URL userinfo leaked to terminal output' >&2; exit 1
fi
for host in example.com example.net example.org example.dev example.io; do
grep -qF "https://[REDACTED]@$host" <<<"$OUTPUT" \
|| { echo "credentialed URL redaction control missing for $host" >&2; exit 1; }
done
secret_active="$TMP/secret-state/active.json"
secret_journal="$(node -p "require('$secret_active').journal")"
secret_command_log="$(dirname "$secret_journal")/commands.log"
if grep -R -F "$canary" "$secret_command_log" "$HOME_DIR" 2>/dev/null; then
echo 'credential canary leaked to persistent installer output' >&2; exit 1
fi
if grep -E 'alice:p@ss|bob:pa:ss|carol:p%40ss|token@example|user%3Apass|QWxhZGRpbjpvcGVu|Ym9iOnNlY3JldA|session=abc123|sid=xyz789' "$secret_command_log" >/dev/null; then
echo 'credentialed URL userinfo leaked to persistent installer output' >&2; exit 1
fi
if [[ "$(cat "$TMP/canary-observed" 2>/dev/null || true)" != "$canary" ]]; then
echo 'credential canary positive control was not exercised' >&2; exit 1
fi
if find "$TMPDIR" -maxdepth 1 -type f \( -name 'mosaic-phase-redacted.*' -o -name 'mosaic-post-redacted.*' \) -print -quit | grep -q .; then
echo 'redacted diagnostic staging file survived normal completion' >&2; exit 1
fi
printf '[test] framework nested capture redacts the same canary and URL variants\n'
framework_test_home="$TMP/framework-redact-home"
framework_target="$framework_test_home/.config/mosaic"
framework_cli="$TMP/framework-redact-cli"
framework_log="$TMP/framework-redact-commands.log"
framework_status="$TMP/framework-redact-status.tsv"
mkdir -p "$framework_test_home"; : > "$framework_log"; : > "$framework_status"
cat > "$framework_cli" <<'FRAMEWORK_CLI'
#!/usr/bin/env bash
printf 'nested authToken=%s\n' "${MOSAIC_INSTALL_SECRET_CANARY:?}"
printf 'nested=https://alice:p@[email protected]/a https://bob:pa:[email protected]/b https://carol:p%%[email protected]/c https://[email protected]/d https://user%%[email protected]/e\n'
printf 'Authorization: Basic QWxhZGRpbjpvcGVu\n//registry/:_auth=Ym9iOnNlY3JldA==\nCookie: session=abc123\nSet-Cookie: sid=xyz789\n'
exit 1
FRAMEWORK_CLI
chmod 0755 "$framework_cli"
set +e
FRAMEWORK_OUTPUT="$(
HOME="$framework_test_home" MOSAIC_HOME="$framework_target" MOSAIC_INSTALL_MODE=overwrite \
MOSAIC_CLI_PATH="$framework_cli" MOSAIC_INSTALL_SECRET_CANARY="$canary" \
MOSAIC_INSTALL_COMMAND_LOG="$framework_log" MOSAIC_INSTALL_PHASE_STATUS_FILE="$framework_status" \
MOSAIC_ALLOW_MISSING_SEQUENTIAL_THINKING=1 MOSAIC_SKIP_SKILLS_SYNC=1 \
bash "$ROOT/packages/mosaic/framework/install.sh" 2>&1
)"
framework_install_status=$?
set -e
[[ "$framework_install_status" -eq 0 ]]
if grep -Eq "$canary|alice:p@ss|bob:pa:ss|carol:p%40ss|token@example|user%3Apass|QWxhZGRpbjpvcGVu|Ym9iOnNlY3JldA|session=abc123|sid=xyz789" <<<"$FRAMEWORK_OUTPUT" \
|| grep -Eq "$canary|alice:p@ss|bob:pa:ss|carol:p%40ss|token@example|user%3Apass|QWxhZGRpbjpvcGVu|Ym9iOnNlY3JldA|session=abc123|sid=xyz789" "$framework_log"; then
echo 'framework nested capture leaked credential diagnostics' >&2; exit 1
fi
for host in example.com example.net example.org example.dev example.io; do
grep -qF "https://[REDACTED]@$host" "$framework_log" \
|| { echo "framework URL redaction control missing for $host" >&2; exit 1; }
done
printf '[test] real P2-P8 actions run under fault injection and restore actual surfaces\n'
for phase in P2 P3 P4 P5 P6 P7 P8; do
rm -rf "$HOME_DIR" "$STATE" "$TMP/fault-$phase"; mkdir -p "$HOME_DIR" "$STATE" "$TMP/fault-$phase"
printf 'operator-sentinel\n' > "$HOME_DIR/operator.txt"
reset_state
before="$(tree_fingerprint "$HOME_DIR")"
set +e
HOME="$HOME_DIR" MOSAIC_HOME="$MOSAIC_HOME" MOSAIC_PREFIX="$PREFIX" \
MOSAIC_INSTALL_STATE_DIR="$TMP/fault-$phase" MOSAIC_INSTALL_FAULT_AFTER="$phase" \
MOSAIC_INSTALL_SELF_TEST_ALLOW=1 MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --state-machine-self-test --next --yes \
>"$TMP/fault-$phase.log" 2>&1
status=$?
set -e
[[ "$status" -eq 97 ]] || { echo "$phase real fault expected 97, got $status" >&2; exit 1; }
[[ -s "$LOG" ]] || { echo "$phase fault never entered the real action path" >&2; exit 1; }
[[ "$(tree_fingerprint "$HOME_DIR")" == "$before" ]] || { echo "$phase real rollback mismatch" >&2; exit 1; }
grep -q "phase=$phase" "$TMP/fault-$phase.log"
if find "$TMP/fault-$phase" -type f -exec grep -l '"status"[[:space:]]*:[[:space:]]*"in-progress"' {} + 2>/dev/null | grep -q .; then
echo "$phase left an in-progress transaction" >&2; exit 1
fi
done
printf '[test] stale projection is preserved while the real fault path acquires a free OS lock\n'
rm -rf "$HOME_DIR" "$STATE" "$TMP/stale-state"; mkdir -p "$HOME_DIR" "$STATE" "$TMP/stale-state"
printf '{"status":"in-progress","journal":"%s"}\n' "$TMP/stale-state/dead-run/journal.ndjson" > "$TMP/stale-state/active.json"
reset_state
set +e
HOME="$HOME_DIR" MOSAIC_HOME="$MOSAIC_HOME" MOSAIC_PREFIX="$PREFIX" \
MOSAIC_INSTALL_STATE_DIR="$TMP/stale-state" MOSAIC_INSTALL_FAULT_AFTER=P2 \
MOSAIC_INSTALL_SELF_TEST_ALLOW=1 MOSAIC_NO_COLOR=1 \
MOSAIC_TEST_NPM_LOG="$LOG" MOSAIC_TEST_STATE="$STATE" \
PATH="$FAKE_BIN:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --state-machine-self-test --next --yes >"$TMP/stale.log" 2>&1
stale_status=$?
set -e
[[ "$stale_status" -eq 97 ]]
find "$TMP/stale-state" -name prior-active.json -type f -print -quit | grep -q .
[[ "$(node -p "require('$TMP/stale-state/active.json').status")" == rolled-back ]]
echo "[test] installer next lane tests passed"
-400
View File
@@ -1,400 +0,0 @@
#!/usr/bin/env bash
# Red-first acceptance checks for #1050. This file is committed before the
# installer implementation. Do not weaken these properties to make it green.
# pass_case always returns zero and fail_case records the aggregate failure;
# the compact A&&pass||fail assertions are intentional.
# shellcheck disable=SC2015
set -uo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
TMP="$(mktemp -d "${TMPDIR:-/tmp}/mosaic-install-state-test.XXXXXX")"
trap 'rm -rf "$TMP"' EXIT
failures=0
COMPAT_BIN="$TMP/compat-bin"
mkdir -p "$COMPAT_BIN"
cat > "$COMPAT_BIN/realpath" <<'REALPATH'
#!/usr/bin/env python3
import os
import sys
args = sys.argv[1:]
mode = args.pop(0) if args and args[0] in ("-e", "-m") else "-m"
if args and args[0] == "--":
args.pop(0)
if len(args) != 1 or (mode == "-e" and not os.path.exists(args[0])):
raise SystemExit(1)
print(os.path.realpath(args[0]))
REALPATH
chmod 0755 "$COMPAT_BIN/realpath"
fail_case() { printf '[test] FAIL: %s\n' "$*" >&2; failures=$((failures + 1)); }
pass_case() { printf '[test] PASS: %s\n' "$*"; }
fingerprint() {
local dir="$1"
if [[ ! -d "$dir" ]]; then printf 'ABSENT\n'; return; fi
python3 - "$dir" <<'PY'
import hashlib
import os
import stat
import sys
root = os.path.abspath(sys.argv[1])
rows = []
for current, dirs, files in os.walk(root, topdown=True, followlinks=False):
for name in dirs + files:
path = os.path.join(current, name)
rel = os.path.relpath(path, root)
meta = os.lstat(path)
target = os.readlink(path) if stat.S_ISLNK(meta.st_mode) else ""
digest = ""
if stat.S_ISREG(meta.st_mode):
with open(path, "rb") as handle:
digest = hashlib.sha256(handle.read()).hexdigest()
rows.append((rel, stat.S_IFMT(meta.st_mode), stat.S_IMODE(meta.st_mode), meta.st_uid, meta.st_gid, target, digest))
payload = "\n".join("|".join(map(str, row)) for row in sorted(rows)).encode()
print(hashlib.sha256(payload).hexdigest())
PY
}
make_fake_npm() {
local bin="$1"
mkdir -p "$bin"
cat > "$bin/npm" <<'FAKE'
#!/bin/bash
set -euo pipefail
if [[ "${1:-}" == "--version" ]]; then echo '10.6.2'; exit 0; fi
case "${1:-} ${2:-} ${3:-}" in
'view @mosaicstack/mosaic@next version') echo '0.0.50-next.999' ;;
'view @mosaicstack/gateway@next version') echo '0.0.7-next.999' ;;
'view @mosaicstack/mosaic version') echo '0.0.49' ;;
'ls -g --depth=0'|'ls -g --json') echo '{"dependencies":{"@mosaicstack/mosaic":{"version":"0.0.50-next.999"},"@mosaicstack/gateway":{"version":"0.0.7-next.999"}}}' ;;
ls*) echo '{"dependencies":{"@mosaicstack/mosaic":{"version":"0.0.50-next.999"},"@mosaicstack/gateway":{"version":"0.0.7-next.999"}}}' ;;
*) echo "unexpected fake npm command: $*" >&2; exit 1 ;;
esac
FAKE
chmod 0755 "$bin/npm"
}
printf '[test] case: --check enumerates exactly P0-P8, discriminates, and mutates nothing\n'
check_home="$TMP/check-home"
check_bin="$TMP/check-bin"
mkdir -p "$check_home/.config/mosaic/skills/alpha" "$check_home/.npm-global/bin" "$check_bin"
printf '# framework\n' > "$check_home/.config/mosaic/AGENTS.md"
printf '# skill\n' > "$check_home/.config/mosaic/skills/alpha/SKILL.md"
cat > "$check_home/.npm-global/bin/mosaic" <<'CLI'
#!/usr/bin/env bash
printf '0.0.50-next.999\n'
CLI
chmod 0755 "$check_home/.npm-global/bin/mosaic"
make_fake_npm "$check_bin"
before="$(fingerprint "$check_home")"
set +e
HOME="$check_home" MOSAIC_HOME="$check_home/.config/mosaic" MOSAIC_PREFIX="$check_home/.npm-global" \
MOSAIC_NO_COLOR=1 PATH="$check_bin:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --check --next >"$TMP/check.log" 2>&1
check_status=$?
set -e
after="$(fingerprint "$check_home")"
[[ "$before" == "$after" ]] && pass_case '--check left the complete HOME fingerprint unchanged' \
|| fail_case "--check mutated HOME (before=$before after=$after)"
[[ "$check_status" -ne 0 ]] && pass_case '--check exited non-zero for failed P4/P5/P8 predicates' \
|| fail_case '--check returned zero on the deliberately broken host'
phase_rows=0
for phase in P0 P1 P2 P3 P4 P5 P6 P7 P8; do
count="$(grep -Ec "^\[$phase\] (PASS|FAIL):" "$TMP/check.log" || true)"
[[ "$count" -eq 1 ]] || fail_case "$phase expected exactly one PASS/FAIL row, got $count"
phase_rows=$((phase_rows + count))
done
[[ "$phase_rows" -eq 9 ]] && pass_case '--check emitted exactly nine P0-P8 result rows' \
|| fail_case "--check emitted $phase_rows canonical rows instead of 9"
grep -q '^\[P3\] PASS:.*0\.0\.50-next\.999' "$TMP/check.log" \
&& pass_case 'P3 preserves the absolute-path exact-version discriminator' \
|| fail_case 'P3 did not PASS with the exact resolved next-lane version'
grep -q '^\[P4\] FAIL: NOT-MEASURED / UNDECLARED:' "$TMP/check.log" \
&& pass_case 'P4 refuses fabricated precision when no shipped-set declaration exists' \
|| fail_case 'P4 did not report the declared-set population as NOT-MEASURED / UNDECLARED'
for phase in P5 P8; do
grep -q "^\[$phase\] FAIL:" "$TMP/check.log" \
&& pass_case "$phase remains an attributable expected RED" \
|| fail_case "$phase did not report its own expected failure"
done
printf '[test] case: --check discriminates a constructed good host without mutation\n'
good_home="$TMP/good-home"
good_bin="$TMP/good-bin"
good_prefix="$good_home/.npm-global"
good_mosaic="$good_home/.config/mosaic"
mkdir -p "$good_bin" "$good_prefix/bin" "$good_mosaic/skills/declared-skill"
make_fake_npm "$good_bin"
cp "$COMPAT_BIN/realpath" "$good_bin/realpath"
cat > "$good_bin/id" <<'ID'
#!/bin/bash
uid="${MOSAIC_TEST_UID:-1001}"
gid="${MOSAIC_TEST_GID:-1001}"
user="${MOSAIC_TEST_USER:-fixture-user}"
case "${1:-}" in
-u) echo "$uid" ;;
-g) echo "$gid" ;;
-un) echo "$user" ;;
*) exec /bin/id "$@" ;;
esac
ID
cat > "$good_bin/stat" <<'STAT'
#!/bin/bash
if [[ "${1:-} ${2:-}" == '-c %u' ]]; then
[[ "${3:-}" == "${MOSAIC_TEST_WRONG_OWNER_PATH:-__none__}" ]] && echo 9999 || echo "${MOSAIC_TEST_UID:-1001}"
exit 0
fi
if [[ "${1:-} ${2:-}" == '-c %g' ]]; then
[[ "${3:-}" == "${MOSAIC_TEST_WRONG_GROUP_PATH:-__none__}" ]] && echo 9999 || echo "${MOSAIC_TEST_GID:-1001}"
exit 0
fi
exec /bin/stat "$@"
STAT
cat > "$good_bin/curl" <<'CURL'
#!/bin/bash
exit 0
CURL
cat > "$good_bin/ldd" <<'LDD'
#!/bin/bash
echo 'ldd (GNU libc) 2.36'
LDD
chmod 0755 "$good_bin/id" "$good_bin/stat" "$good_bin/curl" "$good_bin/ldd"
cat > "$good_prefix/bin/mosaic" <<'CLI'
#!/usr/bin/env bash
printf '0.0.50-next.999\n'
CLI
chmod 0755 "$good_prefix/bin/mosaic"
cat > "$good_bin/getent" <<GETENT
#!/bin/bash
printf '%s:x:%s:%s::%s:%s\\n' "\${MOSAIC_TEST_USER:-fixture-user}" "\${MOSAIC_TEST_UID:-1001}" "\${MOSAIC_TEST_GID:-1001}" "\${MOSAIC_TEST_PASSWD_HOME:-$good_home}" '$good_bin/bash'
GETENT
cat > "$good_bin/bash" <<SHELL
#!/bin/bash
if [[ "\${*: -1}" == 'command -v mosaic' ]]; then
printf '%s\\n' '$good_prefix/bin/mosaic'
exit 0
fi
exec /bin/bash "\$@"
SHELL
chmod 0755 "$good_bin/getent" "$good_bin/bash"
printf '# Soul\n\nConfigured.\n' > "$good_mosaic/SOUL.md"
printf '# User\n\nConfigured.\n' > "$good_mosaic/USER.md"
chmod 0600 "$good_mosaic/SOUL.md" "$good_mosaic/USER.md"
cat > "$good_mosaic/skills/declared-skill/SKILL.md" <<'SKILL'
---
name: declared-skill
description: Constructed loadable acceptance skill.
---
# Declared skill
SKILL
printf '{"lane":"next","version":"0.0.50-next.999","skills":["declared-skill"]}\n' > "$good_mosaic/.install-shipped-skills.json"
printf '{\n "lane": "next",\n "cliVersion": "0.0.50-next.999"\n}\n' > "$good_mosaic/.install-manifest.json"
before="$(fingerprint "$good_home")"
set +e
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" \
MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --check --next >"$TMP/good-check.log" 2>&1
status=$?
set -e
after="$(fingerprint "$good_home")"
[[ "$status" -eq 0 ]] && pass_case 'good-host --check exited zero' || fail_case "good-host --check exited $status"
[[ "$before" == "$after" ]] && pass_case 'good-host --check left HOME unchanged' || fail_case 'good-host --check mutated HOME'
good_rows="$(grep -Ec '^\[P[0-8]\] PASS:' "$TMP/good-check.log" || true)"
[[ "$good_rows" -eq 9 ]] && pass_case 'good-host --check emitted nine PASS rows' \
|| { cat "$TMP/good-check.log" >&2; fail_case "good-host --check emitted $good_rows PASS rows"; }
printf '[test] case: P0 binds uid, username, passwd HOME, shell, and privilege mode\n'
passwd_home="$TMP/passwd-authoritative-home"
mkdir -p "$passwd_home"
set +e
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" \
MOSAIC_TEST_PASSWD_HOME="$passwd_home" MOSAIC_NO_COLOR=1 \
PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --check --next >"$TMP/wrong-home.log" 2>&1
wrong_home_status=$?
set -e
[[ "$wrong_home_status" -ne 0 ]] || fail_case 'P0 accepted ambient HOME that disagrees with passwd HOME'
grep -q '^\[P0\] FAIL:.*HOME mismatch' "$TMP/wrong-home.log" \
&& pass_case 'P0 rejects ambient HOME that disagrees with passwd HOME' \
|| fail_case 'P0 did not attribute the passwd HOME mismatch'
for privilege_case in root-with-home sudo-with-inherited-home; do
extra_env=()
[[ "$privilege_case" == sudo-with-inherited-home ]] && extra_env+=(SUDO_USER=fixture-user SUDO_UID=1001)
set +e
env HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" \
MOSAIC_TEST_UID=0 MOSAIC_TEST_GID=0 MOSAIC_TEST_USER=root MOSAIC_TEST_PASSWD_HOME=/root \
MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" "${extra_env[@]}" \
bash "$ROOT/tools/install.sh" --check --next >"$TMP/$privilege_case.log" 2>&1
privilege_status=$?
set -e
[[ "$privilege_status" -ne 0 ]] || fail_case "P0 accepted unsafe $privilege_case context"
grep -q '^\[P0\] FAIL:.*privilege=' "$TMP/$privilege_case.log" \
&& pass_case "P0 states and rejects $privilege_case privilege context" \
|| fail_case "P0 did not state $privilege_case privilege mode"
done
printf '[test] case: P3/P5 reject unsafe owner, group, and mode\n'
chmod 0777 "$good_prefix/bin/mosaic"
set +e
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" MOSAIC_NO_COLOR=1 \
PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" bash "$ROOT/tools/install.sh" --check --next >"$TMP/p3-mode.log" 2>&1
p3_mode_status=$?
set -e
[[ "$p3_mode_status" -ne 0 ]] || fail_case 'P3 accepted mode-0777 CLI'
grep -q '^\[P3\] FAIL:.*unsafe owner/group/mode' "$TMP/p3-mode.log" \
&& pass_case 'P3 rejects group/world-writable CLI' || fail_case 'P3 did not attribute unsafe CLI mode'
chmod 0755 "$good_prefix/bin/mosaic"
for ownership_case in owner group; do
wrong_env=()
[[ "$ownership_case" == owner ]] && wrong_env+=(MOSAIC_TEST_WRONG_OWNER_PATH="$good_prefix/bin/mosaic")
[[ "$ownership_case" == group ]] && wrong_env+=(MOSAIC_TEST_WRONG_GROUP_PATH="$good_prefix/bin/mosaic")
set +e
env HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" MOSAIC_NO_COLOR=1 \
PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" "${wrong_env[@]}" \
bash "$ROOT/tools/install.sh" --check --next >"$TMP/p3-$ownership_case.log" 2>&1
owner_status=$?
set -e
[[ "$owner_status" -ne 0 ]] || fail_case "P3 accepted wrong CLI $ownership_case"
grep -q '^\[P3\] FAIL:.*unsafe owner/group/mode' "$TMP/p3-$ownership_case.log" \
&& pass_case "P3 rejects wrong CLI $ownership_case" || fail_case "P3 did not attribute wrong CLI $ownership_case"
done
chmod 0644 "$good_mosaic/SOUL.md" "$good_mosaic/USER.md"
set +e
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" MOSAIC_NO_COLOR=1 \
PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" bash "$ROOT/tools/install.sh" --check --next >"$TMP/p5-mode.log" 2>&1
p5_mode_status=$?
set -e
[[ "$p5_mode_status" -ne 0 ]] || fail_case 'P5 accepted world-readable identity files'
grep -q '^\[P5\] FAIL:' "$TMP/p5-mode.log" \
&& pass_case 'P5 rejects world-readable identity files' || fail_case 'P5 did not reject identity mode 0644'
chmod 0600 "$good_mosaic/SOUL.md" "$good_mosaic/USER.md"
mkdir -p "$good_mosaic/credentials"
chmod 0755 "$good_mosaic/credentials"
set +e
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" MOSAIC_NO_COLOR=1 \
PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" bash "$ROOT/tools/install.sh" --check --next >"$TMP/p5-credentials.log" 2>&1
credential_status=$?
set -e
[[ "$credential_status" -ne 0 ]] || fail_case 'P5 accepted mode-0755 credentials directory'
grep -q '^\[P5\] FAIL:.*credentials' "$TMP/p5-credentials.log" \
&& pass_case 'P5 rejects group/world-readable credential storage' \
|| fail_case 'P5 did not attribute unsafe credential directory mode'
chmod 0700 "$good_mosaic/credentials"
printf '# framework\n' > "$good_mosaic/AGENTS.md"
chmod 0666 "$good_mosaic/AGENTS.md"
set +e
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" MOSAIC_NO_COLOR=1 \
PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" bash "$ROOT/tools/install.sh" --check --next >"$TMP/p4-tree-mode.log" 2>&1
framework_mode_status=$?
set -e
[[ "$framework_mode_status" -ne 0 ]] || fail_case 'P4 accepted group/world-writable framework path'
grep -q '^\[P4\] FAIL:.*owner/mode policy' "$TMP/p4-tree-mode.log" \
&& pass_case 'P4 inventories and rejects unsafe created framework paths' \
|| fail_case 'P4 did not attribute unsafe created-path mode'
chmod 0644 "$good_mosaic/AGENTS.md"
printf '[test] case: persisted required-action failures remain blocking\n'
for blocked_phase in P4 P6; do
node -e '
const fs=require("fs"); const p=process.argv[1]; const phase=process.argv[2];
const m=JSON.parse(fs.readFileSync(p,"utf8")); m.phaseOutcomes={P4:"committed",P6:"committed"};
m.phaseOutcomes[phase]="failed"; fs.writeFileSync(p,JSON.stringify(m)+"\n");
' "$good_mosaic/.install-manifest.json" "$blocked_phase"
set +e
HOME="$good_home" MOSAIC_HOME="$good_mosaic" MOSAIC_PREFIX="$good_prefix" \
MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --check --next >"$TMP/action-$blocked_phase.log" 2>&1
status=$?
set -e
[[ "$status" -ne 0 ]] || fail_case "$blocked_phase action failure returned zero"
grep -q "^\[$blocked_phase\] FAIL:.*action reported a required $blocked_phase failure" "$TMP/action-$blocked_phase.log" \
&& pass_case "$blocked_phase action failure remained blocking in a later --check" \
|| fail_case "$blocked_phase persisted action failure was not attributed"
done
printf '{\n "lane": "next",\n "cliVersion": "0.0.50-next.999",\n "phaseOutcomes": {"P4":"committed","P6":"committed"}\n}\n' > "$good_mosaic/.install-manifest.json"
printf '[test] case: fault injection has no synthetic mutation implementation\n'
if grep -q '\.selftest-' "$ROOT/tools/install.sh"; then
fail_case 'synthetic .selftest mutation path remains in the production fault seam'
else
pass_case 'fault seam is attached only to real P2-P8 action flow (exercised by install-next-lane.test.sh)'
fi
printf '[test] case: unsafe and overlapping rollback roots fail before mutation\n'
unsafe_home="$TMP/unsafe-home"
mkdir -p "$unsafe_home"
for case_name in root-target home-target overlap-target; do
case "$case_name" in
root-target) unsafe_mosaic=/; unsafe_prefix="$unsafe_home/.npm-global" ;;
home-target) unsafe_mosaic="$unsafe_home"; unsafe_prefix="$unsafe_home/.npm-global" ;;
overlap-target) unsafe_mosaic="$unsafe_home/.config"; unsafe_prefix="$unsafe_home/.config/mosaic/prefix" ;;
esac
before="$(fingerprint "$unsafe_home")"
set +e
HOME="$unsafe_home" MOSAIC_HOME="$unsafe_mosaic" MOSAIC_PREFIX="$unsafe_prefix" \
MOSAIC_TEST_PASSWD_HOME="$unsafe_home" MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --check --next >"$TMP/$case_name.log" 2>&1
status=$?
set -e
after="$(fingerprint "$unsafe_home")"
[[ "$status" -ne 0 ]] || fail_case "$case_name unsafe path returned zero"
grep -q '^\[P0\] FAIL:.*unsafe context' "$TMP/$case_name.log" \
&& pass_case "$case_name was rejected by P0" || fail_case "$case_name lacked an attributable P0 failure"
[[ "$before" == "$after" ]] || fail_case "$case_name mutated HOME"
done
symlink_home="$TMP/symlink-home"
symlink_outside="$TMP/symlink-outside"
mkdir -p "$symlink_home" "$symlink_outside"
ln -s "$symlink_outside" "$symlink_home/.config"
set +e
HOME="$symlink_home" MOSAIC_HOME="$symlink_home/.config/mosaic" MOSAIC_PREFIX="$symlink_home/.npm-global" \
MOSAIC_TEST_PASSWD_HOME="$symlink_home" MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --check --next >"$TMP/symlink-target.log" 2>&1
status=$?
set -e
[[ "$status" -ne 0 ]] || fail_case 'symlink-parent unsafe path returned zero'
grep -q '^\[P0\] FAIL:.*unsafe context' "$TMP/symlink-target.log" \
&& pass_case 'symlinked rollback parent was rejected by P0' \
|| fail_case 'symlinked rollback parent lacked an attributable P0 failure'
[[ -z "$(find "$symlink_outside" -mindepth 1 -print -quit)" ]] || fail_case 'symlink target was mutated'
printf '[test] case: journal initialization failure is fatal before mutation\n'
journal_home="$TMP/journal-failure/home"
mkdir -p "$journal_home/.config/mosaic"
printf 'journal-sentinel\n' > "$journal_home/.config/mosaic/operator.txt"
before="$(fingerprint "$journal_home")"
set +e
HOME="$journal_home" MOSAIC_HOME="$journal_home/.config/mosaic" MOSAIC_PREFIX="$journal_home/.npm-global" \
MOSAIC_TEST_PASSWD_HOME="$journal_home" MOSAIC_INSTALL_STATE_DIR="/proc/mosaic-journal-denied-$$" \
MOSAIC_NO_COLOR=1 PATH="$good_bin:/usr/local/bin:/usr/bin:/bin" \
bash "$ROOT/tools/install.sh" --cli --next --yes --no-auto-launch \
>"$TMP/journal-failure.log" 2>&1
status=$?
set -e
after="$(fingerprint "$journal_home")"
[[ "$status" -ne 0 ]] && pass_case 'unwritable journal directory failed non-zero' \
|| fail_case 'unwritable journal directory returned zero'
grep -q 'cannot create private journal directory' "$TMP/journal-failure.log" \
&& pass_case 'journal initialization failure was named' \
|| fail_case 'journal initialization failure lacked a named diagnostic'
[[ "$before" == "$after" ]] && pass_case 'journal failure occurred before target mutation' \
|| fail_case "journal failure mutated target HOME (before=$before after=$after)"
if [[ "$failures" -ne 0 ]]; then
printf '[test] install state-machine acceptance RED: %d failed assertion(s)\n' "$failures" >&2
printf '[test] --check transcript: %s\n' "$TMP/check.log" >&2
exit 1
fi
printf '[test] installer state-machine acceptance passed\n'
+70 -1286
View File
File diff suppressed because it is too large Load Diff
-1
View File
@@ -1 +0,0 @@
4cd391b0974d3cce6c2a98455420d45bc2a04cb624e3c4bf43a813b8e28693e6 install.sh
-20
View File
@@ -1,20 +0,0 @@
#!/usr/bin/env bash
# Fetch, authenticate, and execute the exact downloaded installer body.
set -euo pipefail
url="${1:?usage: verified-installer-fetch.sh <url> <sha256> [-- installer-args...]}"
expected="${2:?usage: verified-installer-fetch.sh <url> <sha256> [-- installer-args...]}"
shift 2
[[ "${1:-}" != -- ]] || shift
[[ "$expected" =~ ^[0-9a-f]{64}$ ]] || { echo 'installer expected SHA-256 must be 64 lowercase hex characters' >&2; exit 2; }
tmp="$(mktemp "${TMPDIR:-/tmp}/mosaic-installer-body.XXXXXX")"
trap 'rm -f "$tmp"' EXIT
chmod 0600 "$tmp"
curl -fsSL "$url" -o "$tmp"
[[ -s "$tmp" ]] || { echo 'installer fetch returned an empty HTTP-success body' >&2; exit 1; }
actual="$(sha256sum "$tmp" | awk '{print $1}')"
[[ "$actual" == "$expected" ]] || { echo "installer SHA-256 mismatch (got=$actual expected=$expected)" >&2; exit 1; }
status=0
bash "$tmp" "$@" || status=$?
rm -f "$tmp"
trap - EXIT
exit "$status"
-64
View File
@@ -1,64 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
TMP="$(mktemp -d "${TMPDIR:-/tmp}/mosaic-fetch-contract.XXXXXX")"
trap 'rm -rf "$TMP"' EXIT
FAKE_BIN="$TMP/bin"; mkdir -p "$FAKE_BIN"
cat > "$FAKE_BIN/curl" <<'CURL'
#!/usr/bin/env bash
set -euo pipefail
url=""; output=""
while [[ $# -gt 0 ]]; do
case "$1" in
-o) output="$2"; shift 2 ;;
-*) shift ;;
*) url="$1"; shift ;;
esac
done
emit() { if [[ -n "$output" ]]; then cat > "$output"; else cat; fi; }
case "$url" in
fixture://ok)
emit <<'SCRIPT'
#!/usr/bin/env bash
set -euo pipefail
printf 'executed:%s\n' "${1:-missing}"
SCRIPT
;;
fixture://empty) : > "$output" ;;
fixture://failed) exit 22 ;;
*) exit 2 ;;
esac
CURL
chmod 0755 "$FAKE_BIN/curl"
cat > "$TMP/ok.sh" <<'SCRIPT'
#!/usr/bin/env bash
set -euo pipefail
printf 'executed:%s\n' "${1:-missing}"
SCRIPT
ok_sha="$(sha256sum "$TMP/ok.sh" | awk '{print $1}')"
empty_sha="$(printf '' | sha256sum | awk '{print $1}')"
mkdir -p "$TMP/downloads"
output="$(TMPDIR="$TMP/downloads" PATH="$FAKE_BIN:$PATH" bash "$ROOT/tools/verified-installer-fetch.sh" fixture://ok "$ok_sha" -- marker)"
[[ "$output" == 'executed:marker' ]]
[[ -z "$(find "$TMP/downloads" -mindepth 1 -print -quit)" ]]
printf '[test] PASS: digest-pinned fetched artifact executes and its temporary body is removed\n'
for row in 'fixture://empty empty-body' 'fixture://failed failed-fetch'; do
url="${row%% *}"; name="${row#* }"
set +e
PATH="$FAKE_BIN:$PATH" bash "$ROOT/tools/verified-installer-fetch.sh" "$url" "$empty_sha" -- marker \
>"$TMP/$name.log" 2>&1
status=$?
set -e
[[ "$status" -ne 0 ]] || { echo "[test] FAIL: $name certified success" >&2; exit 1; }
done
printf '[test] PASS: failed fetch and HTTP-200 empty body are both rejected\n'
set +e
PATH="$FAKE_BIN:$PATH" bash "$ROOT/tools/verified-installer-fetch.sh" fixture://ok "${ok_sha/0/1}" -- marker \
>"$TMP/mismatch.log" 2>&1
status=$?
set -e
[[ "$status" -ne 0 ]] || { echo '[test] FAIL: digest mismatch was accepted' >&2; exit 1; }
printf '[test] PASS: fetched installer digest mismatch is blocking\n'
-125
View File
@@ -1,125 +0,0 @@
#!/usr/bin/env bash
# Verify that the detector found exactly the pinned C1 phase verdicts. The
# fixture is expected to exit non-zero; this verifier is the green CI contract.
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
MANIFEST="${MOSAIC_EXPECTED_RED_MANIFEST:-$ROOT/tools/fixtures/greenfield-expected-red.tsv}"
CASE="${1:?usage: verify-greenfield-expected-red.sh <case> <log> <fixture-exit>}"
LOG="${2:?usage: verify-greenfield-expected-red.sh <case> <log> <fixture-exit>}"
FIXTURE_EXIT="${3:?usage: verify-greenfield-expected-red.sh <case> <log> <fixture-exit>}"
[[ -r "$MANIFEST" ]] || { echo "expected-RED manifest is unreadable: $MANIFEST" >&2; exit 2; }
[[ -r "$LOG" ]] || { echo "fixture log is unreadable: $LOG" >&2; exit 2; }
[[ "$FIXTURE_EXIT" =~ ^[0-9]+$ ]] || { echo "fixture exit is not numeric: $FIXTURE_EXIT" >&2; exit 2; }
# Validate the entire pinned contract before selecting one case. Otherwise a
# deleted case/phase silently disappears from the gate and a one-row manifest
# can certify any exit-1 transcript.
expected_cases=(next-git-present main-git-present next-git-absent)
declare -A allowed_case=(
[next-git-present]=1 [main-git-present]=1 [next-git-absent]=1
)
declare -A expected_requires=(
[next-git-present]=6 [main-git-present]=6 [next-git-absent]=4
)
declare -A row_count=() exit_count=() require_count=() forbid_count=() phase_count=() unique_rows=()
while IFS= read -r raw; do
[[ -n "$raw" && "${raw:0:1}" != "#" ]] || continue
field_count="$(awk -F '\t' '{print NF}' <<<"$raw")"
[[ "$field_count" -eq 3 ]] || { echo "invalid expected-RED manifest row (expected exactly 3 tab fields): $raw" >&2; exit 2; }
IFS=$'\t' read -r case_name kind expectation <<<"$raw"
[[ -n "${allowed_case[$case_name]:-}" ]] || { echo "invalid expected-RED manifest case: $case_name" >&2; exit 2; }
unique_key="$case_name|$kind|$expectation"
[[ -z "${unique_rows[$unique_key]:-}" ]] || { echo "duplicate expected-RED manifest row: $raw" >&2; exit 2; }
unique_rows[$unique_key]=1
row_count[$case_name]=$((${row_count[$case_name]:-0} + 1))
case "$kind" in
exit)
[[ "$expectation" == 1 ]] || { echo "invalid expected-RED exit contract: case=$case_name expected=$expectation" >&2; exit 2; }
exit_count[$case_name]=$((${exit_count[$case_name]:-0} + 1))
;;
phase)
[[ "$expectation" =~ ^(P[0-9])=(PASS|FAIL)$ ]] \
|| { echo "invalid expected-RED phase disposition: case=$case_name value=$expectation" >&2; exit 2; }
phase="${BASH_REMATCH[1]}"
phase_key="$case_name|$phase"
phase_count[$phase_key]=$((${phase_count[$phase_key]:-0} + 1))
;;
require)
[[ -n "$expectation" ]] || { echo "empty expected-RED require row: case=$case_name" >&2; exit 2; }
require_count[$case_name]=$((${require_count[$case_name]:-0} + 1))
;;
forbid)
[[ -n "$expectation" ]] || { echo "empty expected-RED forbid row: case=$case_name" >&2; exit 2; }
forbid_count[$case_name]=$((${forbid_count[$case_name]:-0} + 1))
;;
*) echo "invalid expected-RED manifest kind: case=$case_name kind=$kind" >&2; exit 2 ;;
esac
done < "$MANIFEST"
for case_name in "${expected_cases[@]}"; do
[[ "${exit_count[$case_name]:-0}" -eq 1 ]] \
|| { echo "expected-RED manifest requires exactly one exit row for case=$case_name" >&2; exit 2; }
for phase in P0 P1 P2 P3 P4 P5 P6 P7 P8 P9; do
[[ "${phase_count[$case_name|$phase]:-0}" -eq 1 ]] \
|| { echo "expected-RED manifest requires exactly one $phase disposition for case=$case_name" >&2; exit 2; }
done
[[ "${require_count[$case_name]:-0}" -eq "${expected_requires[$case_name]}" ]] \
|| { echo "expected-RED manifest require-row population changed for case=$case_name" >&2; exit 2; }
[[ "${forbid_count[$case_name]:-0}" -eq 1 ]] \
|| { echo "expected-RED manifest requires exactly one forbid row for case=$case_name" >&2; exit 2; }
expected_total=$((1 + 10 + expected_requires[$case_name] + 1))
[[ "${row_count[$case_name]:-0}" -eq "$expected_total" ]] \
|| { echo "expected-RED manifest row population changed for case=$case_name" >&2; exit 2; }
done
[[ -n "${allowed_case[$CASE]:-}" ]] || { echo "unknown expected-RED verification case: $CASE" >&2; exit 2; }
checks=0
failures=0
while IFS=$'\t' read -r case_name kind expectation; do
[[ -n "$case_name" && "${case_name:0:1}" != "#" ]] || continue
[[ "$case_name" == "$CASE" ]] || continue
checks=$((checks + 1))
case "$kind" in
exit)
if [[ "$FIXTURE_EXIT" != "$expectation" ]]; then
echo "expected-RED mismatch: case=$CASE fixture_exit=$FIXTURE_EXIT expected=$expectation" >&2
failures=$((failures + 1))
fi
;;
phase)
phase="${expectation%%=*}"
expected_verdict="${expectation#*=}"
last_row="$(grep -E "^\[$phase\] (PASS|FAIL):" "$LOG" | tail -n 1 || true)"
actual_verdict="$(printf '%s\n' "$last_row" | sed -n "s/^\[$phase\] \(PASS\|FAIL\):.*/\1/p")"
if [[ "$actual_verdict" != "$expected_verdict" ]]; then
echo "expected-RED mismatch: case=$CASE phase=$phase got=${actual_verdict:-missing} expected=$expected_verdict" >&2
failures=$((failures + 1))
fi
;;
require)
if ! grep -Eq -- "$expectation" "$LOG"; then
echo "expected-RED missing required evidence: case=$CASE regex=$expectation" >&2
failures=$((failures + 1))
fi
;;
forbid)
if grep -Eq -- "$expectation" "$LOG"; then
echo "expected-RED found forbidden evidence: case=$CASE regex=$expectation" >&2
failures=$((failures + 1))
fi
;;
*)
echo "invalid expected-RED manifest kind: case=$case_name kind=$kind" >&2
exit 2
;;
esac
done < "$MANIFEST"
[[ "$checks" -gt 0 ]] || { echo "expected-RED manifest has no checks for case=$CASE" >&2; exit 2; }
if [[ "$failures" -ne 0 ]]; then
echo "expected-RED verification failed: case=$CASE failures=$failures checks=$checks" >&2
exit 1
fi
printf 'expected-RED verification passed: case=%s checks=%d\n' "$CASE" "$checks"
@@ -1,77 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
TMP="$(mktemp -d "${TMPDIR:-/tmp}/mosaic-expected-red-test.XXXXXX")"
trap 'rm -rf "$TMP"' EXIT
cat > "$TMP/match.log" <<'LOG'
[fixture] resolved lane=next package=@mosaicstack/mosaic@next version=0.0.50-next.999
[fixture] installer_exit=1 done_claims=0
[SECRET-CONTROL] PASS: seeded canary absent from complete scan population
[P0] PASS: supported context
[P1] PASS: preflight complete
[P2] PASS: pinned artifact
[P3] PASS: absolute_path=/home/test/.npm-global/bin/mosaic version=0.0.50-next.999 equals resolved lane version
[P4] FAIL: NOT-MEASURED / UNDECLARED: declaration absent
[P5] FAIL: identity absent
[P6] FAIL: broker absent but dead enforcement hooks are active
[P7] PASS: no services requested
[P8] FAIL: shell path absent
[P9] FAIL: aggregate refusal
LOG
bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 1 >/dev/null
printf '[test] PASS: matching detector findings make the CI verifier green\n'
sed 's/^\[P4\] FAIL:/[P4] PASS:/' "$TMP/match.log" > "$TMP/drift.log"
if bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/drift.log" 1 >/dev/null 2>&1; then
echo '[test] FAIL: changed P4 verdict did not invalidate the pinned manifest' >&2
exit 1
fi
printf '[test] PASS: changed phase verdict requires a deliberate manifest update\n'
if bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 0 >/dev/null 2>&1; then
echo '[test] FAIL: unexpected fixture exit did not invalidate the pinned manifest' >&2
exit 1
fi
printf '[test] PASS: unexpected fixture exit remains blocking\n'
printf 'next-git-present\texit\t1\n' > "$TMP/shrunk.tsv"
if MOSAIC_EXPECTED_RED_MANIFEST="$TMP/shrunk.tsv" \
bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 1 >/dev/null 2>&1; then
echo '[test] FAIL: one-row manifest shrink still certified the detector' >&2
exit 1
fi
printf '[test] PASS: manifest shrink cannot delete the structural contract\n'
manifest="$ROOT/tools/fixtures/greenfield-expected-red.tsv"
grep -v $'^next-git-present\tphase\tP8=' "$manifest" > "$TMP/missing-phase.tsv"
if MOSAIC_EXPECTED_RED_MANIFEST="$TMP/missing-phase.tsv" \
bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 1 >/dev/null 2>&1; then
echo '[test] FAIL: missing P8 disposition was accepted' >&2; exit 1
fi
printf '[test] PASS: every case requires one P0-P9 disposition\n'
cp "$manifest" "$TMP/duplicate.tsv"
printf 'next-git-present\tphase\tP3=PASS\n' >> "$TMP/duplicate.tsv"
if MOSAIC_EXPECTED_RED_MANIFEST="$TMP/duplicate.tsv" \
bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 1 >/dev/null 2>&1; then
echo '[test] FAIL: duplicate phase key was accepted' >&2; exit 1
fi
printf '[test] PASS: duplicate structural keys are rejected\n'
cp "$manifest" "$TMP/unknown-case.tsv"
printf 'invented-case\texit\t1\n' >> "$TMP/unknown-case.tsv"
if MOSAIC_EXPECTED_RED_MANIFEST="$TMP/unknown-case.tsv" \
bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 1 >/dev/null 2>&1; then
echo '[test] FAIL: unknown case was accepted' >&2; exit 1
fi
printf '[test] PASS: unknown case rows are rejected\n'
cp "$manifest" "$TMP/unknown-kind.tsv"
printf 'next-git-present\toptional\tanything\n' >> "$TMP/unknown-kind.tsv"
if MOSAIC_EXPECTED_RED_MANIFEST="$TMP/unknown-kind.tsv" \
bash "$ROOT/tools/verify-greenfield-expected-red.sh" next-git-present "$TMP/match.log" 1 >/dev/null 2>&1; then
echo '[test] FAIL: unknown row kind was accepted' >&2; exit 1
fi
printf '[test] PASS: unknown manifest kinds are rejected\n'