Compare commits
5
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bf8510879f | ||
|
|
a80bae950d | ||
|
|
8199261caa | ||
|
|
57a2f2b40e | ||
|
|
93c1de51e1 |
+12
-14
@@ -115,19 +115,18 @@ gateway-backed agent catalog.
|
||||
|
||||
### Normative requirements
|
||||
|
||||
| ID | Requirement |
|
||||
| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `FCM-REQ-01` | The roster SHALL be the sole writable desired-state source for local fleet membership, launch policy, and persisted lifecycle target. Generated environment files, systemd enablement, tmux sessions, and heartbeat state SHALL be non-authoritative projections. |
|
||||
| `FCM-REQ-02` | The implementation SHALL provide one executable structural contract for YAML/JSON input and one shared semantic validator. Roster load, profile validation, provision, migration, and apply SHALL reuse the existing baseline-plus-`roles.local` profile/persona resolver; a parallel role resolver is forbidden. |
|
||||
| `FCM-REQ-03` | The local fleet CLI SHALL expose documented programmatic validate, show, plan, apply/reconcile, create, inspect, update, delete, start, stop, restart, status, verify, and doctor operations with stable JSON and exit-code behavior. Existing `fleet add/remove` compatibility aliases may remain during the stated deprecation window. |
|
||||
| `FCM-REQ-04` | A fresh create SHALL persist `enabled:true` and `desired_state:stopped` unless an explicit persisted start is requested. The model SHALL distinguish enabled state, persisted desired state, and observed state. Migration, apply, reboot, and rollback SHALL not start an agent that was observed stopped before cutover. |
|
||||
| `FCM-REQ-05` | The launch chain SHALL consume deterministic, digest-stamped generated input only. Optional local overrides SHALL be parsed as strict data, may not shadow authoritative generated keys, and may not contain arbitrary commands, credential values, channels, or unknown `MOSAIC_AGENT_*` keys. Forbidden legacy keys, including `MOSAIC_AGENT_COMMAND`, SHALL be privately quarantined before launch and reported only by key name and content hash. |
|
||||
| `FCM-REQ-06` | Mutations and apply SHALL validate before mutation, use an expected generation/lock, write projections atomically, produce a deterministic plan, and emit recovery information on partial failure. Reconciliation SHALL act only on local, enabled, roster-owned projections and SHALL not kill unmanaged tmux sessions by fuzzy name. |
|
||||
| `FCM-REQ-07` | Canonical required classes are `code`, `review`, `validator`, `orchestrator`, `team-leader`, `enhancer`, and `interaction`. `validator` issues an independent final certificate but has no merge authority; `merge-gate` remains sole approve-to-land/merge authority. Team-leader capacity is bounded by an orchestrator-issued lease, and interaction is request/status only. Tess and Ultron are configurable instance/display names, not required machine identities. |
|
||||
| `FCM-REQ-08` | v1 migration SHALL be field-complete, reversible, and explicit about aliases, unresolved classes, lifecycle inference, generated-file regeneration, local override quarantine, schema-only remote/connector fields, and rollback. Every shipped example, profile, and service preset SHALL be migrated and executable, retained as an explicitly versioned v1 fixture, or retired with a replacement and deprecation note. |
|
||||
| `FCM-REQ-09` | M1–M5 SHALL remain local tmux/systemd control-plane work. Remote/SSH reconciliation, connector mutation, secret references, arbitrary command/channel overrides, gateway/API convergence, and UI configuration storage are excluded and require a separate PRD/threat model. |
|
||||
| `FCM-REQ-10` | Documentation and examples are delivery gates. The M0 checklist at [docs/fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md](./fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md) and the baseline disposition inventory at [docs/fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md](./fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md) SHALL be maintained as acceptance evidence. |
|
||||
| `FCM-REQ-11` | Fleet provisioning SHALL validate the fleet CLI and distinct runtimes requested by the roster against the exact PATH construction used by the runtime pane, through one shared implementation rather than the operator PATH or a parallel PATH model. Name resolution alone is insufficient: a resolved script's shebang interpreter SHALL also be reachable, and Node SHALL execute a side-effect-free version probe when it is that interpreter. `fleet install` and `install-systemd` SHALL fail before installation effects when a required executable is absent or unreachable. `fleet doctor` SHALL emit the same named checks as non-green evidence. Every runtime failure SHALL name the runtime, all requesting roster rows, the pane PATH searched, and an exact install command. |
|
||||
| ID | Requirement |
|
||||
| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `FCM-REQ-01` | The roster SHALL be the sole writable desired-state source for local fleet membership, launch policy, and persisted lifecycle target. Generated environment files, systemd enablement, tmux sessions, and heartbeat state SHALL be non-authoritative projections. |
|
||||
| `FCM-REQ-02` | The implementation SHALL provide one executable structural contract for YAML/JSON input and one shared semantic validator. Roster load, profile validation, provision, migration, and apply SHALL reuse the existing baseline-plus-`roles.local` profile/persona resolver; a parallel role resolver is forbidden. |
|
||||
| `FCM-REQ-03` | The local fleet CLI SHALL expose documented programmatic validate, show, plan, apply/reconcile, create, inspect, update, delete, start, stop, restart, status, verify, and doctor operations with stable JSON and exit-code behavior. Existing `fleet add/remove` compatibility aliases may remain during the stated deprecation window. |
|
||||
| `FCM-REQ-04` | A fresh create SHALL persist `enabled:true` and `desired_state:stopped` unless an explicit persisted start is requested. The model SHALL distinguish enabled state, persisted desired state, and observed state. Migration, apply, reboot, and rollback SHALL not start an agent that was observed stopped before cutover. |
|
||||
| `FCM-REQ-05` | The launch chain SHALL consume deterministic, digest-stamped generated input only. Optional local overrides SHALL be parsed as strict data, may not shadow authoritative generated keys, and may not contain arbitrary commands, credential values, channels, or unknown `MOSAIC_AGENT_*` keys. Forbidden legacy keys, including `MOSAIC_AGENT_COMMAND`, SHALL be privately quarantined before launch and reported only by key name and content hash. |
|
||||
| `FCM-REQ-06` | Mutations and apply SHALL validate before mutation, use an expected generation/lock, write projections atomically, produce a deterministic plan, and emit recovery information on partial failure. Reconciliation SHALL act only on local, enabled, roster-owned projections and SHALL not kill unmanaged tmux sessions by fuzzy name. |
|
||||
| `FCM-REQ-07` | Canonical required classes are `code`, `review`, `validator`, `orchestrator`, `team-leader`, `enhancer`, and `interaction`. `validator` issues an independent final certificate but has no merge authority; `merge-gate` remains sole approve-to-land/merge authority. Team-leader capacity is bounded by an orchestrator-issued lease, and interaction is request/status only. Tess and Ultron are configurable instance/display names, not required machine identities. |
|
||||
| `FCM-REQ-08` | v1 migration SHALL be field-complete, reversible, and explicit about aliases, unresolved classes, lifecycle inference, generated-file regeneration, local override quarantine, schema-only remote/connector fields, and rollback. Every shipped example, profile, and service preset SHALL be migrated and executable, retained as an explicitly versioned v1 fixture, or retired with a replacement and deprecation note. |
|
||||
| `FCM-REQ-09` | M1–M5 SHALL remain local tmux/systemd control-plane work. Remote/SSH reconciliation, connector mutation, secret references, arbitrary command/channel overrides, gateway/API convergence, and UI configuration storage are excluded and require a separate PRD/threat model. |
|
||||
| `FCM-REQ-10` | Documentation and examples are delivery gates. The M0 checklist at [docs/fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md](./fleet/FLEET-CONFIG-DOCS-IA-CHECKLIST.md) and the baseline disposition inventory at [docs/fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md](./fleet/LEGACY-EXAMPLE-PROFILE-DISPOSITION-INVENTORY.md) SHALL be maintained as acceptance evidence. |
|
||||
|
||||
### Acceptance criteria
|
||||
|
||||
@@ -139,7 +138,6 @@ gateway-backed agent catalog.
|
||||
6. `AC-FCM-06`: A v1 roster migration previews field-by-field disposition, preserves observed stopped/running state, inventories rather than reconciles remote/schema-only entries, supports a canary and rollback, and classifies every shipped example, profile, and service preset according to the M0 inventory.
|
||||
7. `AC-FCM-07`: Required role authority is validated: validator certificate is consumed but does not merge, merge-gate is the sole merge authority, team-leader leases do not change roster/credentials/authority, and interaction/Tess cannot claim orchestration or merge powers.
|
||||
8. `AC-FCM-08`: Documentation, examples, migration, troubleshooting, operational recovery, package/update asset drift, schema/example/profile validation, independent code/security review, validator certificate, and terminal-green CI are complete before #758 closes.
|
||||
9. `AC-FCM-09`: Red-first isolated tests create (a) a roster whose runtime exists on the operator PATH but is absent from the constructed pane PATH and (b) a greenfield pane where `mosaic` and a runtime resolve as Node-shebang scripts while Node is absent. They prove `fleet install` fails before effects, the launcher creates no doomed session, and `fleet doctor` reports named non-green checks. Diagnostics include the executable or runtime, all requesting rows, searched pane PATH, shebang dependency when present, and exact runtime install command; repeated rows are checked once per distinct runtime/effective pane path. Tests use temporary `--mosaic-home` state and fixture binaries, never host runtime mutation.
|
||||
|
||||
### M0 implementation gate
|
||||
|
||||
|
||||
@@ -59,28 +59,6 @@ valid allowed local data can move to `.env.local`; invalid legacy input is priva
|
||||
Diagnostics expose only rule code, key name, and a SHA-256 content hash. They do not reveal command
|
||||
text, credentials, or other values.
|
||||
|
||||
## Pane executable preflight
|
||||
|
||||
The fleet install, install-systemd, and doctor commands plus the session launcher use
|
||||
**pane-runtime-path.sh** as the single pane-PATH implementation. Install inspects every distinct
|
||||
roster runtime and effective MOSAIC_RUNTIME_BIN pair before creating holder identity, tool,
|
||||
projection, or unit files. Doctor reports the same checks as JSON.
|
||||
|
||||
A resolved command is not automatically executable. The helper reads a script shebang, unwraps the
|
||||
common “/usr/bin/env node” and “/usr/bin/env -S node …” forms, then resolves the declared command
|
||||
against the pane PATH. When Node is the declared interpreter, the helper runs the side-effect-free
|
||||
“node --version” probe. It does not run “mosaic --version”, whose startup update check can write cache
|
||||
state. Native binaries have no PATH-resolved shebang dependency and retain their normal executable
|
||||
check. Failures name the executable or runtime, requesting roster rows, searched pane PATH,
|
||||
dependency, and runtime install command.
|
||||
|
||||
Supported runtime install commands are:
|
||||
|
||||
- **Claude:** curl -fsSL https://claude.ai/install.sh | bash
|
||||
- **Codex:** npm install -g @openai/codex
|
||||
- **OpenCode:** npm install -g opencode-ai
|
||||
- **Pi:** npm install -g @earendil-works/pi-coding-agent
|
||||
|
||||
## Launch and stop behavior
|
||||
|
||||
The launcher obtains the agent's socket only from the validated generated projection. It creates or
|
||||
|
||||
@@ -1,71 +0,0 @@
|
||||
# #1256 — Fleet runtime preflight
|
||||
|
||||
**Agent:** tiny
|
||||
|
||||
**Branch:** `fix/1256-fleet-runtime-preflight` from `origin/next@476db12b92971634b67fd2057b7577ee5894e449`
|
||||
|
||||
**Issue:** `mosaicstack/stack#1256` blocker 1
|
||||
|
||||
**Adjacent PR:** `#1258` (`fix/1256-fleet-pane-path-node`) owns the bootstrapped-Node candidate and must remain a separate change
|
||||
|
||||
**Budget:** 30K-token soft cap; one bounded implementation lane
|
||||
|
||||
## Objective
|
||||
|
||||
Make fleet provisioning fail before installation effects when the roster names a runtime binary absent from the exact PATH the tmux pane will receive. Make `mosaic fleet doctor` report the same named runtime check. Diagnostics must name the runtime, every requesting roster row, the pane PATH searched, and an exact install command.
|
||||
|
||||
For Pi the exact command is:
|
||||
|
||||
```text
|
||||
npm install -g @earendil-works/pi-coding-agent
|
||||
```
|
||||
|
||||
## Constraints
|
||||
|
||||
- TDD: add the failing behavior test and capture RED before implementation.
|
||||
- Runtime resolution uses the launcher's pane-PATH construction; a second PATH model is forbidden.
|
||||
- Operator PATH is non-authoritative and must not cause a false pass.
|
||||
- Tests use an isolated `--mosaic-home`/temporary HOME and never mutate host runtime binaries.
|
||||
- No install, removal, or binary-resolution changes on sb-it-1-dt.
|
||||
- PR targets `next` and requires a reviewer other than fred.
|
||||
- Commit identity is `tiny <[email protected]>`.
|
||||
- #1258's Node candidate is a dependency/adjacent change, never reimplemented here.
|
||||
|
||||
## Planned seam
|
||||
|
||||
1. Factor the shell pane-path builder/resolver into one sourceable and executable fleet helper.
|
||||
2. Have `start-agent-session.sh` source that helper, preserving one definition of the pane PATH.
|
||||
3. Have the TypeScript fleet command invoke the same helper under the unit-equivalent clean launcher environment.
|
||||
4. Group roster rows by distinct runtime and effective pane PATH, then report requesting row names.
|
||||
5. Run the preflight before `installFleet` performs any write.
|
||||
6. Add the named result to roster-v2 `fleet doctor` JSON and set a failing exit when a runtime is absent.
|
||||
7. Install/copy the helper alongside `start-agent-session.sh` and update framework manifest/docs as required.
|
||||
|
||||
This seam overlaps #1258 only at the location of the existing shell function. Development may use #1258 as a local dependency, but the final PR diff must exclude #1258's separately owned Node change after that PR lands or after an agreed rebase order.
|
||||
|
||||
## Acceptance evidence
|
||||
|
||||
| Requirement | Evidence |
|
||||
|---|---|
|
||||
| Missing Pi blocks install before effects | isolated CLI test: nonzero + no installed files/runner effects |
|
||||
| Operator PATH cannot create false green | test puts Pi only on operator PATH and omits it from constructed pane PATH |
|
||||
| Exact pane PATH reused | launcher and CLI call one shared shell helper; contract test exercises both |
|
||||
| Actionable diagnosis | runtime + roster rows + searched PATH + exact install command assertions |
|
||||
| Distinct runtimes | repeated rows produce one check with all row names |
|
||||
| Doctor reports named check | JSON assertion + nonzero exit for missing runtime |
|
||||
| Present runtime passes | isolated pane-path fixture with executable binary |
|
||||
| No host mutation | tests use temporary HOME/Mosaic home and fixture binaries only |
|
||||
| Baseline safety | focused tests, package typecheck/lint/format, full relevant suite, CI |
|
||||
|
||||
## Progress log
|
||||
|
||||
- 2026-08-16: Dispatch received from fred; issue #1256 and PR #1258 measured.
|
||||
- 2026-08-16: Fresh clone created under `~/agent-work/tiny-fleet-runtime-preflight`; local Git identity pinned to tiny so retired global `mos-dt-0` identity cannot win.
|
||||
- 2026-08-16: Design inspection found the pane PATH exists only inside `start-agent-session.sh`; the right seam is a shared shell helper rather than a parallel TypeScript reconstruction.
|
||||
- 2026-08-16: RED measured on `origin/next@476db12b`: focused `fleet-roster-v2-dispatch.spec.ts` ran 11 tests; the new case failed because install returned success, wrote units for two agents, and emitted no `runtime=pi` diagnosis while Pi existed only on operator PATH.
|
||||
- 2026-08-16: Factored pane home/PATH/resolution into sourceable and executable `pane-runtime-path.sh`; install invokes it before the first effect, doctor emits the same named checks, and the launcher sources it.
|
||||
- 2026-08-16: Fred/rhodey review exposed the #1241 name-resolution blind spot: `mosaic` can resolve while its `#!/usr/bin/env node` interpreter cannot. Measurement confirmed every supported current Mosaic package shape is a Node-shebang script, but executing `mosaic --version` is not observational because CLI startup runs the cache-writing/network update checker before Commander handles the flag.
|
||||
- 2026-08-16: Final executable check reads and unwraps direct and `/usr/bin/env` shebangs (including `env -S`), resolves the declared dependency against pane PATH, and runs only side-effect-free `node --version` when Node is declared. Native binaries do not inherit a permanent Node requirement. Install, doctor, and launcher share this implementation.
|
||||
- 2026-08-16: Isolated greenfield fixture places resolved Mosaic and Pi Node-shebang scripts in pane-visible npm-global bin while using an empty system suffix; both checks become `unexecutable` with `dependency=node`, and install leaves holder/tools/units absent. No host binary or HOME is changed.
|
||||
- 2026-08-16: GREEN evidence before #1258 rebase: focused install/doctor/preflight suites pass; `fleet.spec.ts` 209/209; full Vitest 87 files / 1,557 tests; launcher shell suite, typecheck, lint, build, and focused format check pass. Full framework-shell reaches an unrelated host-measurement drift in unchanged `invariant_r_unittest.py` (expected Pi 0.84.1, host resolves 0.84.2); no invariant was changed in this lane.
|
||||
- 2026-08-16: Merge-order gate remains: `origin/next` is still `476db12b`; #1258 is unmerged at `6dc35e5`. Rebase after it lands, relocate its Node candidate into the helper with explicit provenance, rerun gates, then open the PR to `next` for an independent non-fred review.
|
||||
@@ -12,6 +12,33 @@ The default tmux socket is `mosaic-fleet` so fleet commands do not touch the
|
||||
default tmux server. The roster is the desired-state authority; generated environment files are
|
||||
rebuildable projections, never a second source of configuration.
|
||||
|
||||
## Brain-home split (fleet state vs framework templates)
|
||||
|
||||
When a mosaic-brain clone is present, fleet **state** resolves from the brain
|
||||
home while framework templates and dispatch state stay in the config home
|
||||
(three-tree model, canon `docs/STRUCTURE-CANON.md` §2):
|
||||
|
||||
| Path | Without brain (legacy) | With brain |
|
||||
| ------------------------------------------------------------------------------- | ------------------------------------- | ------------------------------ |
|
||||
| `fleet/agents/<seat>.env.*` | `~/.config/mosaic/fleet/agents/` | `~/.mosaic/fleet/agents/` |
|
||||
| `fleet/roles.local/` (overrides) | `~/.config/mosaic/fleet/roles.local/` | `~/.mosaic/fleet/roles.local/` |
|
||||
| `fleet/profiles/` (working copies) | `~/.config/mosaic/fleet/profiles/` | `~/.mosaic/fleet/profiles/` |
|
||||
| `fleet/roster.yaml`, `fleet/roles/` (baseline), `fleet/run/`, `fleet/services/` | `~/.config/mosaic/fleet/…` | unchanged (config home) |
|
||||
|
||||
Activation (`packages/mosaic/src/fleet/brain-home.ts`, mirrored in
|
||||
`tools/fleet/start-agent-session.sh`):
|
||||
|
||||
1. `MOSAIC_BRAIN_HOME` env var — explicit, always wins.
|
||||
2. Canonical `~/.mosaic` — adopted only when `MOSAIC_HOME` is the default
|
||||
`~/.config/mosaic` AND `~/.mosaic/fleet/agents` exists. Custom
|
||||
`--mosaic-home` values (tests, sandboxes, canaries) never adopt, keeping
|
||||
them hermetic.
|
||||
3. Otherwise the config home (legacy single-tree behavior).
|
||||
|
||||
Seat env dirs under a brain are subject to the same privacy boundary (0700
|
||||
dirs, 0600 files); `.env.generated` files are structure-valuable and tracked
|
||||
in the brain repo, hand-maintained `.env`/`.env.local` stay ignored and private.
|
||||
|
||||
## Examples
|
||||
|
||||
- `examples/minimal.yaml` starts one local canary slot.
|
||||
|
||||
@@ -51,12 +51,8 @@ See `docs/fleet/reference/generated-env-boundary.md` for the full contract.
|
||||
## Manual canary sequence
|
||||
|
||||
Use the roster and the supported installer; do not pre-create the agent environment directory or
|
||||
edit a generated projection. Before it writes any holder identity, tool, projection, or unit file,
|
||||
`mosaic fleet install` validates the fleet CLI and every distinct roster runtime through the exact
|
||||
pane PATH. The shared helper also unwraps `/usr/bin/env` shebangs, so a resolved Node script with no
|
||||
pane-visible Node fails before effects. `mosaic fleet doctor` reports the same named executable
|
||||
checks without mutation. After that preflight, install places the units and helpers and writes private
|
||||
roster-derived projections before any service starts.
|
||||
edit a generated projection. `mosaic fleet install` validates the roster, installs the units and
|
||||
helpers, and writes private roster-derived projections before any service is started.
|
||||
|
||||
```bash
|
||||
# Create a site-owned canary roster. Inspect an existing roster before using --force.
|
||||
|
||||
@@ -255,6 +255,68 @@ fleet_declared_transport() {
|
||||
printf '%s\n' "${declared:-tmux}"
|
||||
}
|
||||
|
||||
# Brain-home fleet-state resolution (#1298; canon STRUCTURE-CANON §2).
|
||||
#
|
||||
# Seat launch envs, roles.local overrides, and profile working copies resolve
|
||||
# from the brain home when one is active; roster, baseline roles, run/, and
|
||||
# services stay under MOSAIC_HOME. This check surfaces which tree fleet state
|
||||
# resolves from and the drift a launch would otherwise hit at runtime:
|
||||
#
|
||||
# - a stale MOSAIC_BRAIN_HOME pointing at a directory with no fleet/agents is a
|
||||
# misconfiguration the resolver honors (explicit wins) — warn, don't pass;
|
||||
# - a symlinked brain or agents dir defeats the managed-directory boundary;
|
||||
# - a group/world-readable agents dir violates the 0700 projection boundary;
|
||||
# - env files left in the config-home tree while a brain is active are split
|
||||
# state — the write path rejects NEW split writes, but nothing would ever
|
||||
# tell the operator the old files are stranded.
|
||||
resolve_brain_home() {
|
||||
local explicit="${MOSAIC_BRAIN_HOME:-}"
|
||||
if [[ -n "$(printf '%s' "$explicit" | tr -d '[:space:]')" ]]; then
|
||||
printf '%s' "$explicit"
|
||||
return
|
||||
fi
|
||||
if [[ "$(cd "$MOSAIC_HOME" 2>/dev/null && pwd -P)" == "$HOME/.config/mosaic" \
|
||||
&& -d "$HOME/.mosaic/fleet/agents" ]]; then
|
||||
printf '%s' "$HOME/.mosaic"
|
||||
return
|
||||
fi
|
||||
printf '%s' "$MOSAIC_HOME"
|
||||
}
|
||||
|
||||
check_brain_home() {
|
||||
local brain agents mode
|
||||
brain="$(resolve_brain_home)"
|
||||
|
||||
if [[ "$brain" == "$MOSAIC_HOME" ]]; then
|
||||
pass "Fleet state home: $MOSAIC_HOME (legacy single-tree; no brain adopted)"
|
||||
return
|
||||
fi
|
||||
|
||||
agents="$brain/fleet/agents"
|
||||
if [[ ! -d "$agents" ]]; then
|
||||
warn "Brain home '$brain' has no fleet/agents — seat envs will not resolve from it. Point MOSAIC_BRAIN_HOME at a brain carrying fleet/agents, or unset it."
|
||||
return
|
||||
fi
|
||||
if [[ -L "$brain" || -L "$agents" ]]; then
|
||||
warn "Brain fleet-state path resolves through a symlink ($brain) — the managed-directory boundary requires regular directories."
|
||||
return
|
||||
fi
|
||||
|
||||
mode="$(stat -c '%a' -- "$agents" 2>/dev/null)" || mode=""
|
||||
if [[ -n "$mode" ]] && (( (8#$mode & 8#077) != 0 )); then
|
||||
warn "Brain agents dir '$agents' is group/world-accessible (mode $mode) — the projection boundary requires 0700."
|
||||
return
|
||||
fi
|
||||
|
||||
if [[ -d "$MOSAIC_HOME/fleet/agents" ]] \
|
||||
&& ls "$MOSAIC_HOME/fleet/agents/"*.env* >/dev/null 2>&1; then
|
||||
warn "Fleet env files exist in BOTH trees — brain '$brain' is active but '$MOSAIC_HOME/fleet/agents' still carries env files (split state). Migrate them (mosaic fleet regen) and remove the config-home copies."
|
||||
return
|
||||
fi
|
||||
|
||||
pass "Fleet state home: $brain (brain active); roster + templates: $MOSAIC_HOME"
|
||||
}
|
||||
|
||||
check_fleet_transport() {
|
||||
local transport
|
||||
transport="$(fleet_declared_transport)"
|
||||
@@ -273,6 +335,8 @@ check_fleet_transport() {
|
||||
|
||||
check_fleet_transport
|
||||
|
||||
check_brain_home
|
||||
|
||||
# Legacy migration surfaces should no longer contain symlink trees.
|
||||
legacy_paths=(
|
||||
"$HOME/.claude/agent-guides"
|
||||
|
||||
@@ -0,0 +1,108 @@
|
||||
#!/usr/bin/env bash
|
||||
# Covers the brain-home fleet-state check in `mosaic-doctor` (#1298 follow-up).
|
||||
#
|
||||
# The functions are extracted from the shipped script rather than copied here
|
||||
# (same discipline as test-fleet-transport-check.sh): a test that carries its
|
||||
# own copy of the logic keeps passing after the shipped copy changes.
|
||||
# Extraction is by exact function header and a closing brace in column one.
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR=$(cd -- "$(dirname "$0")" && pwd)
|
||||
DOCTOR="$SCRIPT_DIR/mosaic-doctor"
|
||||
|
||||
fail() {
|
||||
echo "FAIL: $*" >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
[ -f "$DOCTOR" ] || fail "missing mosaic-doctor at $DOCTOR"
|
||||
|
||||
extract_function() {
|
||||
local name="$1"
|
||||
local extracted
|
||||
extracted=$(sed -n "/^${name}() {/,/^}/p" "$DOCTOR")
|
||||
[ -n "$extracted" ] || fail "could not extract ${name}() from mosaic-doctor — script reshaped?"
|
||||
printf '%s\n' "$extracted"
|
||||
}
|
||||
|
||||
for fn in resolve_brain_home check_brain_home; do
|
||||
extract_function "$fn" >/dev/null
|
||||
done
|
||||
|
||||
warn_count=0
|
||||
warn() { warn_count=$((warn_count + 1)); echo "[WARN] $*"; }
|
||||
pass() { echo "[OK] $*"; return 0; }
|
||||
|
||||
eval "$(extract_function resolve_brain_home)"
|
||||
eval "$(extract_function check_brain_home)"
|
||||
|
||||
ROOT=$(mktemp -d)
|
||||
trap 'rm -rf "$ROOT"' EXIT
|
||||
|
||||
run_case() {
|
||||
# label, expect (ok|warn), then env assignments as arguments.
|
||||
# The check runs under `env` in a subshell, so its warn() also prints a
|
||||
# sentinel the parent counts — a subshell counter would never be visible.
|
||||
local label="$1" expect="$2"
|
||||
shift 2
|
||||
local out warns
|
||||
out=$(env "$@" bash -c "warn() { echo \"[WARN] \$*\"; }; pass() { echo \"[OK] \$*\"; return 0; }; $(extract_function resolve_brain_home); $(extract_function check_brain_home); check_brain_home" 2>&1)
|
||||
warns=$(printf '%s\n' "$out" | grep -c '^\[WARN\]' || true)
|
||||
if [[ "$expect" == ok && "$warns" -eq 0 ]]; then
|
||||
echo "ok - $label"
|
||||
elif [[ "$expect" == warn && "$warns" -gt 0 ]]; then
|
||||
echo "ok - $label (warned)"
|
||||
else
|
||||
echo "output: $out" >&2
|
||||
fail "$label: expected $expect (warns=$warns)"
|
||||
fi
|
||||
}
|
||||
|
||||
# ── legacy: no brain, custom home never adopts ─────────────────────────────
|
||||
mkdir -p "$ROOT/legacy-mosaic/fleet/agents"
|
||||
run_case "custom home without brain stays legacy" ok \
|
||||
MOSAIC_HOME="$ROOT/legacy-mosaic" HOME="$ROOT"
|
||||
|
||||
# ── healthy brain at the default config home ───────────────────────────────
|
||||
mkdir -p "$ROOT/home/.config/mosaic" "$ROOT/home/.mosaic/fleet/agents"
|
||||
chmod 700 "$ROOT/home/.mosaic/fleet/agents"
|
||||
run_case "default home adopts healthy brain" ok \
|
||||
MOSAIC_HOME="$ROOT/home/.config/mosaic" HOME="$ROOT/home"
|
||||
|
||||
# ── explicit MOSAIC_BRAIN_HOME to a brain without fleet/agents → warn ──────
|
||||
mkdir -p "$ROOT/brain-noagents/fleet" "$ROOT/config"
|
||||
run_case "explicit brain without agents warns" warn \
|
||||
MOSAIC_HOME="$ROOT/config" HOME="$ROOT" MOSAIC_BRAIN_HOME="$ROOT/brain-noagents"
|
||||
|
||||
# ── explicit MOSAIC_BRAIN_HOME to a healthy brain → ok ─────────────────────
|
||||
mkdir -p "$ROOT/brain-ok/fleet/agents" "$ROOT/config2"
|
||||
chmod 700 "$ROOT/brain-ok/fleet/agents"
|
||||
run_case "explicit healthy brain passes" ok \
|
||||
MOSAIC_HOME="$ROOT/config2" HOME="$ROOT" MOSAIC_BRAIN_HOME="$ROOT/brain-ok"
|
||||
|
||||
# ── group-readable agents dir → warn (0700 boundary) ───────────────────────
|
||||
mkdir -p "$ROOT/brain-loose/fleet/agents" "$ROOT/config3"
|
||||
chmod 750 "$ROOT/brain-loose/fleet/agents"
|
||||
run_case "group-readable brain agents warns" warn \
|
||||
MOSAIC_HOME="$ROOT/config3" HOME="$ROOT" MOSAIC_BRAIN_HOME="$ROOT/brain-loose"
|
||||
|
||||
# ── symlinked agents dir → warn (managed-directory boundary) ───────────────
|
||||
mkdir -p "$ROOT/brain-link/real-agents" "$ROOT/brain-link/fleet" "$ROOT/config4"
|
||||
ln -s "$ROOT/brain-link/real-agents" "$ROOT/brain-link/fleet/agents"
|
||||
run_case "symlinked brain agents warns" warn \
|
||||
MOSAIC_HOME="$ROOT/config4" HOME="$ROOT" MOSAIC_BRAIN_HOME="$ROOT/brain-link"
|
||||
|
||||
# ── split state: envs in BOTH trees → warn ─────────────────────────────────
|
||||
mkdir -p "$ROOT/brain-split/fleet/agents" "$ROOT/config5/fleet/agents"
|
||||
chmod 700 "$ROOT/brain-split/fleet/agents" "$ROOT/config5/fleet/agents"
|
||||
touch "$ROOT/config5/fleet/agents/coder0.env.generated"
|
||||
run_case "env files in both trees warns (split state)" warn \
|
||||
MOSAIC_HOME="$ROOT/config5" HOME="$ROOT" MOSAIC_BRAIN_HOME="$ROOT/brain-split"
|
||||
|
||||
# ── config-home agents dir WITHOUT env files alongside a brain → ok ────────
|
||||
mkdir -p "$ROOT/brain-clean/fleet/agents" "$ROOT/config6/fleet/agents"
|
||||
chmod 700 "$ROOT/brain-clean/fleet/agents" "$ROOT/config6/fleet/agents"
|
||||
run_case "empty config-home agents dir alongside brain passes" ok \
|
||||
MOSAIC_HOME="$ROOT/config6" HOME="$ROOT" MOSAIC_BRAIN_HOME="$ROOT/brain-clean"
|
||||
|
||||
echo "ok - mosaic-doctor brain-home check"
|
||||
@@ -1,199 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
# Canonical fleet-pane PATH construction and executable reachability checks.
|
||||
#
|
||||
# This file is both sourceable by start-agent-session.sh and executable by the
|
||||
# fleet CLI preflight. Keep the pane PATH in one implementation: provisioning
|
||||
# checks and the eventual pane must answer the same question.
|
||||
|
||||
mosaic_fleet_pane_home() {
|
||||
local mosaic_home="$1"
|
||||
local fallback_home="$2"
|
||||
case "$mosaic_home" in
|
||||
*/.config/mosaic) printf '%s' "${mosaic_home%/.config/mosaic}" ;;
|
||||
*) printf '%s' "$fallback_home" ;;
|
||||
esac
|
||||
}
|
||||
|
||||
mosaic_fleet_build_runtime_bin_prefix() {
|
||||
local pane_home="$1"
|
||||
local runtime_bin="${2:-}"
|
||||
local candidates=()
|
||||
if [ -n "$runtime_bin" ]; then candidates+=("$runtime_bin"); fi
|
||||
if command -v npm >/dev/null 2>&1; then
|
||||
local npm_prefix
|
||||
npm_prefix=$(npm config get prefix 2>/dev/null) || true
|
||||
if [ -n "$npm_prefix" ]; then candidates+=("${npm_prefix}/bin"); fi
|
||||
fi
|
||||
candidates+=("$pane_home/.npm-global/bin" "$pane_home/.local/bin")
|
||||
|
||||
local prefix="" dir
|
||||
for dir in "${candidates[@]}"; do
|
||||
[ -d "$dir" ] || continue
|
||||
case ":${prefix}:" in *":${dir}:"*) ;; *) prefix="${prefix:+$prefix:}$dir" ;; esac
|
||||
done
|
||||
printf '%s' "$prefix"
|
||||
}
|
||||
|
||||
mosaic_fleet_build_pane_path() {
|
||||
local pane_home="$1"
|
||||
local runtime_bin="${2:-}"
|
||||
local system_path="${3:-/usr/local/bin:/usr/bin:/bin}"
|
||||
local prefix
|
||||
prefix=$(mosaic_fleet_build_runtime_bin_prefix "$pane_home" "$runtime_bin")
|
||||
printf '%s' "${prefix:+${prefix}:}${system_path}"
|
||||
}
|
||||
|
||||
mosaic_fleet_resolve_in_pane_path() {
|
||||
local pane_path="$1"
|
||||
local binary="$2"
|
||||
PATH="$pane_path" command -v -- "$binary" 2>/dev/null
|
||||
}
|
||||
|
||||
# Sets executable evidence in MOSAIC_FLEET_EXECUTABLE_* and returns nonzero when
|
||||
# a resolved script's shebang interpreter cannot run in the pane. Native/ELF
|
||||
# binaries have no PATH-resolved interpreter dependency and pass the executable
|
||||
# bit check. Node receives an additional side-effect-free `node --version`
|
||||
# execution check; invoking `mosaic --version` itself is intentionally avoided
|
||||
# because Mosaic performs a cache-writing/network update check at CLI startup.
|
||||
mosaic_fleet_check_resolved_executable() {
|
||||
local pane_path="$1"
|
||||
local resolved="$2"
|
||||
MOSAIC_FLEET_EXECUTABLE_DEPENDENCY=""
|
||||
MOSAIC_FLEET_EXECUTABLE_PROBE=""
|
||||
MOSAIC_FLEET_EXECUTABLE_EXIT=""
|
||||
MOSAIC_FLEET_EXECUTABLE_OUTPUT=""
|
||||
|
||||
[ -x "$resolved" ] || {
|
||||
MOSAIC_FLEET_EXECUTABLE_OUTPUT="resolved path is not executable"
|
||||
return 70
|
||||
}
|
||||
|
||||
local magic=""
|
||||
IFS= read -r -n 2 magic < "$resolved" || true
|
||||
[ "$magic" = '#!' ] || return 0
|
||||
|
||||
local shebang
|
||||
IFS= read -r shebang < "$resolved" || true
|
||||
shebang=${shebang%$'\r'}
|
||||
shebang=${shebang#\#!}
|
||||
local parts=()
|
||||
read -r -a parts <<< "$shebang"
|
||||
local interpreter="${parts[0]:-}"
|
||||
[[ "$interpreter" = /* ]] && [ -x "$interpreter" ] || {
|
||||
MOSAIC_FLEET_EXECUTABLE_DEPENDENCY="$interpreter"
|
||||
MOSAIC_FLEET_EXECUTABLE_OUTPUT="shebang interpreter is absent or not executable"
|
||||
return 70
|
||||
}
|
||||
|
||||
local dependency="$interpreter"
|
||||
local dependency_path="$interpreter"
|
||||
if [ "${interpreter##*/}" = env ]; then
|
||||
local index=1
|
||||
if [ "${parts[$index]:-}" = -S ]; then index=$((index + 1)); fi
|
||||
dependency="${parts[$index]:-}"
|
||||
if [ -z "$dependency" ] || [[ "$dependency" = -* ]]; then
|
||||
MOSAIC_FLEET_EXECUTABLE_DEPENDENCY="$dependency"
|
||||
MOSAIC_FLEET_EXECUTABLE_OUTPUT="unsupported env shebang"
|
||||
return 70
|
||||
fi
|
||||
fi
|
||||
|
||||
MOSAIC_FLEET_EXECUTABLE_DEPENDENCY="$dependency"
|
||||
if [ "${dependency##*/}" = node ]; then
|
||||
MOSAIC_FLEET_EXECUTABLE_PROBE="node --version"
|
||||
fi
|
||||
if [ "${interpreter##*/}" = env ]; then
|
||||
if ! dependency_path=$(mosaic_fleet_resolve_in_pane_path "$pane_path" "$dependency"); then
|
||||
MOSAIC_FLEET_EXECUTABLE_OUTPUT="shebang command is not on the pane PATH"
|
||||
return 70
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ "${dependency##*/}" = node ]; then
|
||||
if MOSAIC_FLEET_EXECUTABLE_OUTPUT=$(PATH="$pane_path" "$dependency_path" --version 2>&1); then
|
||||
MOSAIC_FLEET_EXECUTABLE_EXIT=0
|
||||
else
|
||||
MOSAIC_FLEET_EXECUTABLE_EXIT=$?
|
||||
return 70
|
||||
fi
|
||||
fi
|
||||
return 0
|
||||
}
|
||||
|
||||
mosaic_fleet_runtime_path_main() {
|
||||
local mosaic_home=""
|
||||
local runtime_bin=""
|
||||
local system_path="/usr/local/bin:/usr/bin:/bin"
|
||||
local binary=""
|
||||
local check_executable=0
|
||||
|
||||
while [ "$#" -gt 0 ]; do
|
||||
case "$1" in
|
||||
--mosaic-home)
|
||||
[ "$#" -ge 2 ] || return 64
|
||||
mosaic_home="$2"
|
||||
shift 2
|
||||
;;
|
||||
--runtime-bin)
|
||||
[ "$#" -ge 2 ] || return 64
|
||||
runtime_bin="$2"
|
||||
shift 2
|
||||
;;
|
||||
--binary)
|
||||
[ "$#" -ge 2 ] || return 64
|
||||
binary="$2"
|
||||
shift 2
|
||||
;;
|
||||
--check-executable)
|
||||
check_executable=1
|
||||
shift
|
||||
;;
|
||||
# Test seam for measuring a greenfield host with no system Node. The
|
||||
# launcher and production CLI omit it and retain the fixed system suffix.
|
||||
--system-path)
|
||||
[ "$#" -ge 2 ] || return 64
|
||||
system_path="$2"
|
||||
shift 2
|
||||
;;
|
||||
*) return 64 ;;
|
||||
esac
|
||||
done
|
||||
|
||||
[ -n "$mosaic_home" ] && [ -n "$binary" ] || return 64
|
||||
local pane_home pane_path resolved
|
||||
pane_home=$(mosaic_fleet_pane_home "$mosaic_home" "${HOME:-}")
|
||||
# npm config is HOME-sensitive. Pin it to the derived pane home before asking
|
||||
# for its prefix so an operator's unrelated npmrc cannot influence preflight.
|
||||
HOME=$pane_home
|
||||
export HOME
|
||||
pane_path=$(mosaic_fleet_build_pane_path "$pane_home" "$runtime_bin" "$system_path")
|
||||
if ! resolved=$(mosaic_fleet_resolve_in_pane_path "$pane_path" "$binary"); then
|
||||
printf 'pane_path\0%s\0status\0missing\0binary_path\0\0dependency\0\0probe_command\0\0probe_exit\0\0probe_output\0\0' \
|
||||
"$pane_path"
|
||||
return 69
|
||||
fi
|
||||
|
||||
if [ "$check_executable" -eq 1 ]; then
|
||||
if mosaic_fleet_check_resolved_executable "$pane_path" "$resolved"; then
|
||||
printf 'pane_path\0%s\0status\0present\0binary_path\0%s\0dependency\0%s\0probe_command\0%s\0probe_exit\0%s\0probe_output\0%s\0' \
|
||||
"$pane_path" "$resolved" "$MOSAIC_FLEET_EXECUTABLE_DEPENDENCY" \
|
||||
"$MOSAIC_FLEET_EXECUTABLE_PROBE" "$MOSAIC_FLEET_EXECUTABLE_EXIT" \
|
||||
"$MOSAIC_FLEET_EXECUTABLE_OUTPUT"
|
||||
return 0
|
||||
fi
|
||||
printf 'pane_path\0%s\0status\0unexecutable\0binary_path\0%s\0dependency\0%s\0probe_command\0%s\0probe_exit\0%s\0probe_output\0%s\0' \
|
||||
"$pane_path" "$resolved" "$MOSAIC_FLEET_EXECUTABLE_DEPENDENCY" \
|
||||
"$MOSAIC_FLEET_EXECUTABLE_PROBE" "$MOSAIC_FLEET_EXECUTABLE_EXIT" \
|
||||
"$MOSAIC_FLEET_EXECUTABLE_OUTPUT"
|
||||
return 70
|
||||
fi
|
||||
|
||||
printf 'pane_path\0%s\0status\0present\0binary_path\0%s\0dependency\0\0probe_command\0\0probe_exit\0\0probe_output\0\0' \
|
||||
"$pane_path" "$resolved"
|
||||
return 0
|
||||
}
|
||||
|
||||
if [[ "${BASH_SOURCE[0]}" == "$0" ]]; then
|
||||
set -euo pipefail
|
||||
mosaic_fleet_runtime_path_main "$@"
|
||||
fi
|
||||
@@ -80,6 +80,26 @@ safe_path "$MOSAIC_HOME" || fail_env unsafe-path MOSAIC_HOME "$MOSAIC_HOME"
|
||||
|
||||
FLEET_DIR="$MOSAIC_HOME/fleet"
|
||||
AGENT_ENV_DIR="$FLEET_DIR/agents"
|
||||
|
||||
# Brain-home split (canon docs/STRUCTURE-CANON.md §2): seat launch envs live
|
||||
# under the brain home's fleet/agents when a brain is active; roster, roles
|
||||
# baseline, and runtime state (fleet/run) stay under MOSAIC_HOME.
|
||||
# Resolution mirrors packages/mosaic/src/fleet/brain-home.ts:
|
||||
# 1. MOSAIC_BRAIN_HOME env (explicit, always wins)
|
||||
# 2. ~/.mosaic — adopted only when MOSAIC_HOME is the default config home AND
|
||||
# ~/.mosaic/fleet/agents exists
|
||||
# 3. MOSAIC_HOME (legacy single-tree)
|
||||
BRAIN_HOME="${MOSAIC_BRAIN_HOME:-}"
|
||||
if [ -z "$BRAIN_HOME" ]; then
|
||||
BRAIN_HOME="$MOSAIC_HOME"
|
||||
if [ "$(cd "$MOSAIC_HOME" 2>/dev/null && pwd -P)" = "$HOME/.config/mosaic" ] \
|
||||
&& [ -d "$HOME/.mosaic/fleet/agents" ]; then
|
||||
BRAIN_HOME="$HOME/.mosaic"
|
||||
fi
|
||||
fi
|
||||
if [ "$BRAIN_HOME" != "$MOSAIC_HOME" ]; then
|
||||
AGENT_ENV_DIR="$BRAIN_HOME/fleet/agents"
|
||||
fi
|
||||
assert_managed_directory "$MOSAIC_HOME"
|
||||
assert_managed_directory "$FLEET_DIR"
|
||||
assert_private_directory "$AGENT_ENV_DIR"
|
||||
@@ -258,22 +278,46 @@ if _tmux has-session -t "=${AGENT_NAME}:0.0" 2>/dev/null; then
|
||||
fi
|
||||
|
||||
# Systemd passes HOME as %h, and the installed service fixes MOSAIC_HOME under
|
||||
# that home. The provisioning preflight executes this same helper under the
|
||||
# unit's clean launcher environment, so operator PATH cannot produce a false
|
||||
# green result for a binary the pane will never see.
|
||||
SCRIPT_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
|
||||
# shellcheck source=pane-runtime-path.sh
|
||||
. "$SCRIPT_DIR/pane-runtime-path.sh"
|
||||
PANE_HOME=$(mosaic_fleet_pane_home "$MOSAIC_HOME" "$HOME")
|
||||
PANE_PATH=$(mosaic_fleet_build_pane_path "$PANE_HOME" "$MOSAIC_RUNTIME_BIN")
|
||||
# that home. Derive the pane home from the canonical path when available so an
|
||||
# inherited pane/session HOME cannot become runtime authority.
|
||||
PANE_HOME=$HOME
|
||||
case "$MOSAIC_HOME" in
|
||||
*/.config/mosaic) PANE_HOME=${MOSAIC_HOME%/.config/mosaic} ;;
|
||||
esac
|
||||
|
||||
# #1241/#1256. The pane runs `mosaic yolo <runtime>` under PANE_PATH with a
|
||||
# cleared environment. Resolve both names and validate any shebang interpreter
|
||||
# here, before an effect, where the failure remains attributable. Name
|
||||
# resolution alone is insufficient: an `#!/usr/bin/env node` script resolves
|
||||
# even when the pane cannot execute it because Node is absent.
|
||||
_build_runtime_bin_prefix() {
|
||||
local candidates=()
|
||||
if [ -n "$MOSAIC_RUNTIME_BIN" ]; then candidates+=("$MOSAIC_RUNTIME_BIN"); fi
|
||||
if command -v npm >/dev/null 2>&1; then
|
||||
local npm_prefix
|
||||
npm_prefix=$(npm config get prefix 2>/dev/null) || true
|
||||
if [ -n "$npm_prefix" ]; then candidates+=("${npm_prefix}/bin"); fi
|
||||
fi
|
||||
candidates+=("$PANE_HOME/.npm-global/bin" "$PANE_HOME/.local/bin")
|
||||
|
||||
local prefix="" dir
|
||||
for dir in "${candidates[@]}"; do
|
||||
[ -d "$dir" ] || continue
|
||||
case ":${prefix}:" in *":${dir}:"*) ;; *) prefix="${prefix:+$prefix:}$dir" ;; esac
|
||||
done
|
||||
printf '%s' "$prefix"
|
||||
}
|
||||
|
||||
MOSAIC_RUNTIME_BIN_PREFIX=$(_build_runtime_bin_prefix)
|
||||
PANE_PATH=${MOSAIC_RUNTIME_BIN_PREFIX:+${MOSAIC_RUNTIME_BIN_PREFIX}:}/usr/local/bin:/usr/bin:/bin
|
||||
|
||||
# #1241. The pane runs `mosaic yolo <runtime>` under PANE_PATH with a cleared
|
||||
# environment. A binary missing from *that* path is a pane that dies in under a
|
||||
# second, inside a session nobody is attached to, with its diagnostic scrolled
|
||||
# into a pane tmux then destroys. Resolve both here, before any effect, where
|
||||
# the failure is still attributable to the thing that caused it.
|
||||
#
|
||||
# `mosaic yolo <runtime>` runs checkRuntime(runtime) and the binary it looks for
|
||||
# is named exactly like the runtime, so resolving the runtime name is the same
|
||||
# question the pane will ask a moment later — asked while an operator can still
|
||||
# see the answer.
|
||||
_resolve_in_pane_path() {
|
||||
mosaic_fleet_resolve_in_pane_path "$PANE_PATH" "$1"
|
||||
PATH="$PANE_PATH" command -v -- "$1" 2>/dev/null
|
||||
}
|
||||
|
||||
# Exit 69 (EX_UNAVAILABLE): the seat cannot be provided. Distinguished from the
|
||||
@@ -288,15 +332,8 @@ fail_launch() {
|
||||
}
|
||||
|
||||
for required_binary in mosaic "$MOSAIC_AGENT_RUNTIME"; do
|
||||
resolved_binary=$(_resolve_in_pane_path "$required_binary") ||
|
||||
_resolve_in_pane_path "$required_binary" >/dev/null ||
|
||||
fail_launch missing-binary "'${required_binary}' is not on the pane PATH (${PANE_PATH})"
|
||||
if mosaic_fleet_check_resolved_executable "$PANE_PATH" "$resolved_binary"; then
|
||||
continue
|
||||
else
|
||||
executable_exit=$?
|
||||
fi
|
||||
fail_launch unexecutable-binary \
|
||||
"'${required_binary}' resolves to '${resolved_binary}' but dependency '${MOSAIC_FLEET_EXECUTABLE_DEPENDENCY:-unknown}' is not executable on the pane PATH (${PANE_PATH}); check_exit=${executable_exit} detail=${MOSAIC_FLEET_EXECUTABLE_OUTPUT:-unavailable}"
|
||||
done
|
||||
|
||||
_ensure_claude_workdir_trusted() {
|
||||
|
||||
@@ -167,6 +167,54 @@ if echo "$valid_args" | grep -qF 'bash -c'; then
|
||||
fail "launcher constructed a shell command payload"
|
||||
fi
|
||||
|
||||
# ── Brain-home split (canon §2) ─────────────────────────────────────────
|
||||
# When MOSAIC_HOME is the default config home under $HOME and the host carries
|
||||
# $HOME/.mosaic/fleet/agents, seat envs resolve from the brain tree; the config
|
||||
# home still owns fleet/run (holder-owner) and remains a managed boundary.
|
||||
: > "$TMUX_CALLS"
|
||||
HOME_BRAIN="$ROOT/brain-home"
|
||||
CONFIG_HOME="$HOME_BRAIN/.config/mosaic"
|
||||
BRAIN="$HOME_BRAIN/.mosaic"
|
||||
mkdir -p "$CONFIG_HOME/fleet/run" "$BRAIN/fleet/agents" "$HOME_BRAIN/work"
|
||||
chmod 700 "$CONFIG_HOME" "$CONFIG_HOME/fleet" "$CONFIG_HOME/fleet/run" \
|
||||
"$BRAIN/fleet/agents" "$HOME_BRAIN/work"
|
||||
printf '123e4567-e89b-12d3-a456-426614174000\n' > "$CONFIG_HOME/fleet/run/holder-owner"
|
||||
chmod 600 "$CONFIG_HOME/fleet/run/holder-owner"
|
||||
cat > "$BRAIN/fleet/agents/coder-brain.env.generated" <<EOF
|
||||
MOSAIC_AGENT_NAME=coder-brain
|
||||
MOSAIC_AGENT_CLASS=code
|
||||
MOSAIC_AGENT_RUNTIME=pi
|
||||
MOSAIC_AGENT_MODEL=openai-codex/gpt-5.6-sol
|
||||
MOSAIC_AGENT_REASONING=high
|
||||
MOSAIC_AGENT_TOOL_POLICY=code
|
||||
MOSAIC_AGENT_WORKDIR=$HOME_BRAIN/work
|
||||
MOSAIC_TMUX_SOCKET=mosaic-test
|
||||
EOF
|
||||
chmod 600 "$BRAIN/fleet/agents/coder-brain.env.generated"
|
||||
install_pane_binaries "$HOME_BRAIN"
|
||||
HOME="$HOME_BRAIN" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
||||
MOSAIC_TEST_PANE_PID=$$ MOSAIC_TEST_HOME="$HOME_BRAIN" \
|
||||
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
||||
MOSAIC_HOME="$CONFIG_HOME" "$START" coder-brain
|
||||
brain_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
||||
echo "$brain_args" | grep -qF new-session || fail "brain-home generated projection did not reach tmux"
|
||||
echo "$brain_args" | grep -qF 'coder-brain' || fail "brain-home agent env was not the launch source"
|
||||
[ -f "$BRAIN/fleet/agents/coder-brain.env.generated" ] || fail "brain generated env vanished"
|
||||
|
||||
# Negative control: the SAME default-config-home shape but without
|
||||
# ~/.mosaic/fleet/agents — the config-home env tree is used directly (legacy).
|
||||
: > "$TMUX_CALLS"
|
||||
HOME_NOBRAIN="$ROOT/brainless-home"
|
||||
CONFIG_HOME_NOBRAIN="$HOME_NOBRAIN/.config/mosaic"
|
||||
write_generated "$CONFIG_HOME_NOBRAIN" "coder-legacy"
|
||||
install_pane_binaries "$HOME_NOBRAIN"
|
||||
HOME="$HOME_NOBRAIN" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
|
||||
MOSAIC_TEST_PANE_PID=$$ MOSAIC_TEST_HOME="$HOME_NOBRAIN" \
|
||||
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
|
||||
MOSAIC_HOME="$CONFIG_HOME_NOBRAIN" "$START" coder-legacy
|
||||
legacy_args=$(tr '\0' '\n' < "$TMUX_CALLS")
|
||||
echo "$legacy_args" | grep -qF new-session || fail "legacy single-tree launch regressed"
|
||||
|
||||
# The pane must start through an absolute clean-environment boundary. Its
|
||||
# runtime command remains an argv vector, but no holder/session environment
|
||||
# control variable can pass through the pane command.
|
||||
@@ -484,27 +532,6 @@ assert_missing_pane_binary_rejected() {
|
||||
assert_missing_pane_binary_rejected mosaic
|
||||
assert_missing_pane_binary_rejected pi
|
||||
|
||||
# #1256. Name resolution is not executable reachability. A script can resolve
|
||||
# while its /usr/bin/env shebang command is absent from PANE_PATH; reject that
|
||||
# before tmux creates the doomed session.
|
||||
: > "$TMUX_CALLS"
|
||||
HOME_UNEXECUTABLE="$ROOT/unexecutable-shebang"
|
||||
write_generated "$HOME_UNEXECUTABLE" "coder-unexecutable"
|
||||
rm -f "$HOME_UNEXECUTABLE/.npm-global/bin/mosaic"
|
||||
printf '#!/usr/bin/env mosaic-test-absent-interpreter\n' > \
|
||||
"$HOME_UNEXECUTABLE/.npm-global/bin/mosaic"
|
||||
chmod +x "$HOME_UNEXECUTABLE/.npm-global/bin/mosaic"
|
||||
if output=$(MOSAIC_TEST_PANE_PID=$$ run_start "$HOME_UNEXECUTABLE" coder-unexecutable 2>&1); then
|
||||
fail "launcher accepted a resolved mosaic script with an absent shebang command"
|
||||
fi
|
||||
echo "$output" | grep -qF 'code=unexecutable-binary' || \
|
||||
fail "unexecutable shebang diagnostic missing: $output"
|
||||
echo "$output" | grep -qF 'mosaic-test-absent-interpreter' || \
|
||||
fail "unexecutable shebang diagnostic did not name the missing dependency"
|
||||
if tr '\0' '\n' < "$TMUX_CALLS" | grep -qF new-session; then
|
||||
fail "launcher created a session after its shebang dependency check failed"
|
||||
fi
|
||||
|
||||
# #1241. tmux destroys a session when its pane command exits, so no pane PID a
|
||||
# second after new-session means the runtime died on startup. This used to be a
|
||||
# WARNING about the heartbeat sidecar followed by exit 0 — three layers above it
|
||||
|
||||
@@ -39,3 +39,20 @@ packages/mosaic/framework/tools/tmux/test-send-message-verdict.sh | requires rea
|
||||
# recorded judgement. These lines ARE that judgement, signed.)
|
||||
packages/mosaic/framework/tools/orchestrator/smoke-test.sh | behavior smoke checks for coord continue/run workflows, run manually by orchestrator seats; unmeasured in CI; #1017 burndown
|
||||
packages/mosaic/framework/tools/wake/validate-973/microtest-wake-assert.sh | #973 instrument self-test, run as a precondition of the validate-973 evidence procedure rather than as a standing CI suite; #1017 burndown candidate
|
||||
|
||||
# --- tools/fleet: precondition is unsatisfiable in the CI image (#1271) ---
|
||||
# Signed by fred (sb-it-1-dt, 2026-08-16) at origin/next 476db12.
|
||||
# This suite asserts the launcher's behaviour when `mosaic` and `pi` are MISSING.
|
||||
# It shims fakes into $FAKE_BIN, but the constructed PANE_PATH always ends in the
|
||||
# real system path, so on a host that installs those binaries the missing-binary
|
||||
# cases cannot be measured at all. The suite's own guard (line 103) says so and
|
||||
# fails rather than reporting a pass it cannot back. That guard is correct.
|
||||
# The error was wiring the suite into CI: #1017 (c56483eb) enumerated it and
|
||||
# dropped this exclusion, and the CI image provides `pi` in the system path, so
|
||||
# it has failed on every pipeline since. Measured 2026-08-16 across pipelines
|
||||
# 2444 (#1256), 2438 (#1240) and 2441 (#1017-quality): exactly one FAIL line in
|
||||
# each full log, identical, this assertion; control `zzz-not-present-zzz` -> 0.
|
||||
# Burn-down and the full measurement are tracked in #1271; unwired by PR #1270.
|
||||
# Because test:framework-shell is one && chain and this sat at position 44 of 48,
|
||||
# the four suites after it had not run at all since the merge.
|
||||
packages/mosaic/framework/tools/fleet/test-start-agent-session.sh | precondition unsatisfiable in the CI image: asserts missing-binary behaviour, but PANE_PATH always ends in the system path and the image provides `pi` there; guard at line 103 fails by design rather than passing unmeasured. Burn down by controlling the tail of PANE_PATH inside the test. NOT by removing `pi` from the image: the CI image installs @earendil-works/[email protected] deliberately (measured in pipeline 2444's test-step log), and other suites depend on that pin. Burn-down tracked in #1271
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
"lint": "eslint src",
|
||||
"typecheck": "tsc --noEmit",
|
||||
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
|
||||
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/promotion_binding_unittest.py && python3 src/lease-broker/promotion_trigger_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/receipt_observer_client_unittest.py && python3 src/lease-broker/invariant_r_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-ci-queue-wait-tristate.sh && bash framework/tools/git/test-ci-queue-wait-github-checks.sh && bash framework/tools/git/test-pr-merge-queue-branch.sh && bash framework/tools/git/test-pr-merge-head-pin.sh && bash framework/tools/git/test-pr-merge-message-field.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/woodpecker/test-terminal-green-contract.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/_scripts/test-mosaic-init-rce.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh && bash framework/tools/fleet/test-start-agent-session.sh && bash framework/tools/glpi/test-list-http-status.sh && bash framework/tools/orchestrator/test-board-roll.sh && bash framework/tools/woodpecker/test-ci-wait-exit-matrix.sh && bash framework/tools/_scripts/test-fleet-transport-check.sh"
|
||||
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/promotion_binding_unittest.py && python3 src/lease-broker/promotion_trigger_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/receipt_observer_client_unittest.py && python3 src/lease-broker/invariant_r_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-ci-queue-wait-tristate.sh && bash framework/tools/git/test-ci-queue-wait-github-checks.sh && bash framework/tools/git/test-pr-merge-queue-branch.sh && bash framework/tools/git/test-pr-merge-head-pin.sh && bash framework/tools/git/test-pr-merge-message-field.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/woodpecker/test-terminal-green-contract.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/_scripts/test-mosaic-init-rce.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh && bash framework/tools/glpi/test-list-http-status.sh && bash framework/tools/orchestrator/test-board-roll.sh && bash framework/tools/woodpecker/test-ci-wait-exit-matrix.sh && bash framework/tools/_scripts/test-fleet-transport-check.sh && bash framework/tools/_scripts/test-brain-home-check.sh"
|
||||
},
|
||||
"dependencies": {
|
||||
"@mosaicstack/brain": "workspace:*",
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
import { readFile } from 'node:fs/promises';
|
||||
import { join, resolve } from 'node:path';
|
||||
import { fleetAgentEnvDir, fleetRolesLocalDir } from '../fleet/brain-home.js';
|
||||
import type { Command } from 'commander';
|
||||
import {
|
||||
executeFleetAgentMutation,
|
||||
@@ -149,9 +150,9 @@ async function executeCommand(
|
||||
request,
|
||||
mosaicHome,
|
||||
rosterPath,
|
||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||
rolesDir: join(mosaicHome, 'fleet', 'roles'),
|
||||
overrideDir: join(mosaicHome, 'fleet', 'roles.local'),
|
||||
overrideDir: fleetRolesLocalDir(mosaicHome),
|
||||
dryRun: forceDryRun || opts.dryRun === true,
|
||||
...(deps.projectionApplier === undefined ? {} : { projectionApplier: deps.projectionApplier }),
|
||||
});
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
import { readFile } from 'node:fs/promises';
|
||||
import { join } from 'node:path';
|
||||
import { fleetAgentEnvDir, fleetRolesLocalDir } from '../fleet/brain-home.js';
|
||||
import type { Command } from 'commander';
|
||||
import {
|
||||
parseV1MigrationObservations,
|
||||
@@ -120,11 +121,11 @@ export function registerFleetMigrationCommand(
|
||||
observations,
|
||||
personaDirs: {
|
||||
rolesDir: deps.rolesDir ?? join(mosaicHome, 'fleet', 'roles'),
|
||||
overrideDir: deps.overrideDir ?? join(mosaicHome, 'fleet', 'roles.local'),
|
||||
overrideDir: deps.overrideDir ?? fleetRolesLocalDir(mosaicHome),
|
||||
},
|
||||
environment: {
|
||||
mosaicHome,
|
||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||
},
|
||||
});
|
||||
printJson(preview);
|
||||
|
||||
@@ -30,19 +30,21 @@ import { lstat, readFile, readdir, stat } from 'node:fs/promises';
|
||||
import { homedir } from 'node:os';
|
||||
import { basename, isAbsolute, join, sep } from 'node:path';
|
||||
import type { Command } from 'commander';
|
||||
import { fleetRolesLocalDir } from '../fleet/brain-home.js';
|
||||
|
||||
function defaultMosaicHome(): string {
|
||||
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
||||
}
|
||||
|
||||
/** Baseline persona role contracts (reseeded on update). */
|
||||
/** Baseline persona role contracts (reseeded on update; config home — framework). */
|
||||
export function defaultRolesDir(mosaicHome = defaultMosaicHome()): string {
|
||||
return join(mosaicHome, 'fleet', 'roles');
|
||||
}
|
||||
|
||||
/** PRESERVE-protected override layer (survives update; wins on merge). */
|
||||
/** PRESERVE-protected override layer (survives update; wins on merge).
|
||||
* Brain home (`~/.mosaic/fleet/roles.local`) when a brain is active. */
|
||||
export function defaultOverrideDir(mosaicHome = defaultMosaicHome()): string {
|
||||
return join(mosaicHome, 'fleet', 'roles.local');
|
||||
return fleetRolesLocalDir(mosaicHome);
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -25,6 +25,7 @@ import { homedir } from 'node:os';
|
||||
import { basename, join } from 'node:path';
|
||||
import type { Command } from 'commander';
|
||||
import YAML from 'yaml';
|
||||
import { fleetProfilesDir } from '../fleet/brain-home.js';
|
||||
import {
|
||||
defaultOverrideDir,
|
||||
extractClassesFromDir,
|
||||
@@ -36,9 +37,10 @@ function defaultMosaicHome(): string {
|
||||
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
|
||||
}
|
||||
|
||||
/** Directory holding the seeded profile yaml files. */
|
||||
/** Directory holding the seeded profile yaml files — brain home when active
|
||||
* (user working copies, committed), else the config home seed. */
|
||||
export function defaultProfilesDir(mosaicHome = defaultMosaicHome()): string {
|
||||
return join(mosaicHome, 'fleet', 'profiles');
|
||||
return fleetProfilesDir(mosaicHome);
|
||||
}
|
||||
|
||||
/** Directory holding the persona role contracts. */
|
||||
|
||||
@@ -1,13 +1,9 @@
|
||||
import { chmod, mkdir, mkdtemp, rm, writeFile } from 'node:fs/promises';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join, resolve } from 'node:path';
|
||||
import { join } from 'node:path';
|
||||
import { Command } from 'commander';
|
||||
import { afterEach, describe, expect, it, vi } from 'vitest';
|
||||
import { type FleetReconcileDeps } from '../fleet/fleet-reconciler.js';
|
||||
import {
|
||||
type FleetRuntimeProbeResult,
|
||||
type FleetRuntimeProbeRunner,
|
||||
} from '../fleet/fleet-runtime-preflight.js';
|
||||
import { registerFleetCommand, type CommandResult, type FleetCommandDeps } from './fleet.js';
|
||||
|
||||
const roster = `
|
||||
@@ -69,15 +65,12 @@ function program(
|
||||
mosaicHome: string,
|
||||
runner: FleetCommandDeps['runner'],
|
||||
reconcileOverrides: Partial<FleetReconcileDeps> = {},
|
||||
runtimeProbeRunner: FleetRuntimeProbeRunner = runtimeProbe('present'),
|
||||
): Command {
|
||||
const result = new Command();
|
||||
result.exitOverride();
|
||||
registerFleetCommand(result, {
|
||||
mosaicHome,
|
||||
runner,
|
||||
frameworkRoot: resolve(process.cwd(), 'framework'),
|
||||
runtimeProbeRunner,
|
||||
reconcileDeps: {
|
||||
homeDirectory: '/home/mosaic',
|
||||
readHolderIdentity: async () => '11111111-1111-4111-8111-111111111111',
|
||||
@@ -90,24 +83,6 @@ function program(
|
||||
return result;
|
||||
}
|
||||
|
||||
function runtimeProbe(status: 'present' | 'missing'): FleetRuntimeProbeRunner {
|
||||
return async (_command, args): Promise<FleetRuntimeProbeResult> => {
|
||||
const binaryFlag = args.indexOf('--binary');
|
||||
const binary = binaryFlag >= 0 ? args[binaryFlag + 1] : undefined;
|
||||
const effectiveStatus = binary === 'mosaic' ? 'present' : status;
|
||||
return {
|
||||
stdout:
|
||||
`pane_path\u0000/fixture/runtime-bin:/usr/bin:/bin\u0000status\u0000${effectiveStatus}\u0000` +
|
||||
`binary_path\u0000${effectiveStatus === 'present' ? `/fixture/runtime-bin/${binary ?? 'unknown'}` : ''}\u0000` +
|
||||
`dependency\u0000${effectiveStatus === 'present' ? 'node' : ''}\u0000` +
|
||||
`probe_command\u0000${effectiveStatus === 'present' ? 'node --version' : ''}\u0000` +
|
||||
`probe_exit\u0000${effectiveStatus === 'present' ? '0' : ''}\u0000probe_output\u0000\u0000`,
|
||||
stderr: '',
|
||||
exitCode: effectiveStatus === 'present' ? 0 : 69,
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
function capture(): string[] {
|
||||
const lines: string[] = [];
|
||||
vi.spyOn(console, 'log').mockImplementation((value: string): void => {
|
||||
@@ -177,64 +152,13 @@ describe('mosaic fleet reconciler commands', (): void => {
|
||||
|
||||
expect(lines.map((line: string): unknown => JSON.parse(line))).toMatchObject([
|
||||
{ applied: false, lifecycle: 'not-applied' },
|
||||
{
|
||||
applied: false,
|
||||
lifecycle: 'not-applied',
|
||||
checks: {
|
||||
fleetCliExecutable: [
|
||||
{
|
||||
check: 'fleet-cli-executable',
|
||||
status: 'ok',
|
||||
requestedBy: ['coder0'],
|
||||
dependency: 'node',
|
||||
probeCommand: 'node --version',
|
||||
},
|
||||
],
|
||||
fleetRuntimeAvailability: [
|
||||
{
|
||||
check: 'fleet-runtime-available',
|
||||
runtime: 'pi',
|
||||
status: 'ok',
|
||||
requestedBy: ['coder0'],
|
||||
},
|
||||
],
|
||||
},
|
||||
},
|
||||
{ applied: false, lifecycle: 'not-applied' },
|
||||
]);
|
||||
expect(
|
||||
calls.every((call: string[]): boolean => call[0] !== 'systemctl' || call[2] === 'show'),
|
||||
).toBe(true);
|
||||
});
|
||||
|
||||
it('reports a missing roster runtime as a named non-green doctor check', async (): Promise<void> => {
|
||||
const home = await fleetHome();
|
||||
const lines = capture();
|
||||
|
||||
await program(home, ownedRunner([]), {}, runtimeProbe('missing')).parseAsync([
|
||||
'node',
|
||||
'mosaic',
|
||||
'fleet',
|
||||
'doctor',
|
||||
]);
|
||||
|
||||
expect(JSON.parse(lines.pop() ?? '')).toMatchObject({
|
||||
applied: false,
|
||||
checks: {
|
||||
fleetRuntimeAvailability: [
|
||||
{
|
||||
check: 'fleet-runtime-available',
|
||||
runtime: 'pi',
|
||||
status: 'missing',
|
||||
requestedBy: ['coder0'],
|
||||
panePath: '/fixture/runtime-bin:/usr/bin:/bin',
|
||||
installCommand: 'npm install -g @earendil-works/pi-coding-agent',
|
||||
},
|
||||
],
|
||||
},
|
||||
});
|
||||
expect(process.exitCode).toBe(1);
|
||||
});
|
||||
|
||||
it.each(['start', 'stop', 'restart'] as const)(
|
||||
'uses exact roster-owned systemd targeting for %s',
|
||||
async (operation: 'start' | 'stop' | 'restart'): Promise<void> => {
|
||||
|
||||
@@ -8,18 +8,10 @@ import {
|
||||
type FleetReconcileCommand,
|
||||
type FleetReconcileDeps,
|
||||
} from '../fleet/fleet-reconciler.js';
|
||||
import {
|
||||
inspectFleetRuntimeAvailability,
|
||||
type FleetRuntimeInspection,
|
||||
type FleetRuntimePreflightCheck,
|
||||
type FleetRuntimeProbeRunner,
|
||||
} from '../fleet/fleet-runtime-preflight.js';
|
||||
import { parseRosterV2 } from '../fleet/roster-v2.js';
|
||||
|
||||
export interface FleetReconcilerCommandDeps {
|
||||
readonly runner: CommandRunner;
|
||||
readonly runtimeProbeRunner?: FleetRuntimeProbeRunner;
|
||||
readonly frameworkRoot?: string;
|
||||
readonly mosaicHome?: string;
|
||||
readonly reconcileDeps?: Omit<FleetReconcileDeps, 'runner' | 'mosaicHome'>;
|
||||
}
|
||||
@@ -79,10 +71,6 @@ export async function executeReconcilerCommand(
|
||||
const mosaicHome = resolveMosaicHome(fleetCommand, deps);
|
||||
const rosterPath = resolveRosterPath(fleetCommand, mosaicHome);
|
||||
const roster = parseRosterV2(await readFile(rosterPath, 'utf8'), 'yaml');
|
||||
const runtimeInspection =
|
||||
operation === 'doctor'
|
||||
? await inspectRuntimeAvailability(roster.agents, mosaicHome, deps)
|
||||
: undefined;
|
||||
const mutating = operation === 'apply' || operation === 'reconcile' || isLifecycle(operation);
|
||||
const expectedGeneration = mutating
|
||||
? parseExpectedGeneration(opts.expectedGeneration)
|
||||
@@ -102,31 +90,8 @@ export async function executeReconcilerCommand(
|
||||
...(deps.reconcileDeps ?? {}),
|
||||
},
|
||||
});
|
||||
printJson(operation === 'doctor' ? { ...result, checks: runtimeInspection } : result);
|
||||
const executableFailure =
|
||||
runtimeInspection !== undefined &&
|
||||
[...runtimeInspection.fleetCliExecutable, ...runtimeInspection.fleetRuntimeAvailability].some(
|
||||
(check: FleetRuntimePreflightCheck): boolean => check.status !== 'ok',
|
||||
);
|
||||
process.exitCode =
|
||||
result.recovery === undefined && result.cleanup === undefined && !executableFailure ? 0 : 1;
|
||||
}
|
||||
|
||||
async function inspectRuntimeAvailability(
|
||||
agents: readonly { readonly name: string; readonly runtime: string }[],
|
||||
mosaicHome: string,
|
||||
deps: FleetReconcilerCommandDeps,
|
||||
): Promise<FleetRuntimeInspection> {
|
||||
if (deps.frameworkRoot === undefined || deps.runtimeProbeRunner === undefined) {
|
||||
throw new Error('Fleet doctor runtime preflight dependencies are unavailable.');
|
||||
}
|
||||
return inspectFleetRuntimeAvailability({
|
||||
mosaicHome,
|
||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||
helperPath: join(deps.frameworkRoot, 'tools', 'fleet', 'pane-runtime-path.sh'),
|
||||
agents,
|
||||
runner: deps.runtimeProbeRunner,
|
||||
});
|
||||
printJson(result);
|
||||
process.exitCode = result.recovery === undefined && result.cleanup === undefined ? 0 : 1;
|
||||
}
|
||||
|
||||
function isLifecycle(operation: FleetReconcileCommand): boolean {
|
||||
|
||||
@@ -3,6 +3,7 @@ import { homedir } from 'node:os';
|
||||
import { join, relative, resolve } from 'node:path';
|
||||
import type { Command } from 'commander';
|
||||
import type { CommandRunner } from './fleet.js';
|
||||
import { fleetAgentEnvDir } from '../fleet/brain-home.js';
|
||||
import {
|
||||
applyPreparedGeneratedAgentEnvironmentProjection,
|
||||
prepareGeneratedAgentEnvironmentProjection,
|
||||
@@ -153,7 +154,7 @@ export async function executeFleetRegen(
|
||||
options: FleetRegenOptions,
|
||||
): Promise<FleetRegenResult> {
|
||||
const mosaicHome = defaultMosaicHome(deps);
|
||||
const agentEnvDir = join(mosaicHome, 'fleet', 'agents');
|
||||
const agentEnvDir = fleetAgentEnvDir(mosaicHome);
|
||||
const rosterPath = join(mosaicHome, 'fleet', 'roster.yaml');
|
||||
const readRoster = deps.readRoster ?? defaultReadRoster(deps, mosaicHome);
|
||||
const prepare = deps.prepareProjection ?? prepareGeneratedAgentEnvironmentProjection;
|
||||
|
||||
@@ -4,7 +4,6 @@ import { tmpdir } from 'node:os';
|
||||
import { join, resolve } from 'node:path';
|
||||
import { Command } from 'commander';
|
||||
import { afterEach, describe, expect, it, vi } from 'vitest';
|
||||
import type { FleetRuntimeProbeRunner } from '../fleet/fleet-runtime-preflight.js';
|
||||
import { registerFleetCommand, type CommandResult, type CommandRunner } from './fleet.js';
|
||||
|
||||
/**
|
||||
@@ -70,7 +69,6 @@ agents:
|
||||
let tempHome: string | undefined;
|
||||
const savedHome = process.env.HOME;
|
||||
const savedMosaicHome = process.env.MOSAIC_HOME;
|
||||
const savedPath = process.env.PATH;
|
||||
|
||||
afterEach(async (): Promise<void> => {
|
||||
vi.restoreAllMocks();
|
||||
@@ -79,8 +77,6 @@ afterEach(async (): Promise<void> => {
|
||||
else process.env.HOME = savedHome;
|
||||
if (savedMosaicHome === undefined) delete process.env.MOSAIC_HOME;
|
||||
else process.env.MOSAIC_HOME = savedMosaicHome;
|
||||
if (savedPath === undefined) delete process.env.PATH;
|
||||
else process.env.PATH = savedPath;
|
||||
if (tempHome) await rm(tempHome, { recursive: true, force: true });
|
||||
tempHome = undefined;
|
||||
});
|
||||
@@ -89,7 +85,7 @@ afterEach(async (): Promise<void> => {
|
||||
* A HOME with a roster-v2 fleet and nothing else — the greenfield shape, before
|
||||
* anything has been installed, applied or started.
|
||||
*/
|
||||
async function v2Home(options: { withPaneRuntime?: boolean } = {}): Promise<string> {
|
||||
async function v2Home(): Promise<string> {
|
||||
tempHome = await mkdtemp(join(tmpdir(), 'mosaic-fleet-v2-dispatch-'));
|
||||
process.env.HOME = tempHome;
|
||||
delete process.env.MOSAIC_HOME;
|
||||
@@ -101,12 +97,6 @@ async function v2Home(options: { withPaneRuntime?: boolean } = {}): Promise<stri
|
||||
await writeFile(join(mosaicHome, 'fleet', 'roles', 'code.md'), '`class: code`\n\n# code\n', {
|
||||
mode: 0o600,
|
||||
});
|
||||
const runtimeDir = join(tempHome, '.npm-global', 'bin');
|
||||
await mkdir(runtimeDir, { recursive: true });
|
||||
await writeFile(join(runtimeDir, 'mosaic'), '#!/bin/sh\nexit 0\n', { mode: 0o755 });
|
||||
if (options.withPaneRuntime !== false) {
|
||||
await writeFile(join(runtimeDir, 'pi'), '#!/bin/sh\nexit 0\n', { mode: 0o755 });
|
||||
}
|
||||
return mosaicHome;
|
||||
}
|
||||
|
||||
@@ -123,17 +113,10 @@ const greenfieldRunner: CommandRunner = async (command): Promise<CommandResult>
|
||||
return { stdout: '', stderr: '', exitCode: 1 };
|
||||
};
|
||||
|
||||
function program(
|
||||
runner: CommandRunner = greenfieldRunner,
|
||||
runtimeProbeRunner?: FleetRuntimeProbeRunner,
|
||||
): Command {
|
||||
function program(runner: CommandRunner = greenfieldRunner): Command {
|
||||
const result = new Command();
|
||||
result.exitOverride();
|
||||
registerFleetCommand(result, {
|
||||
runner,
|
||||
frameworkRoot: resolve(process.cwd(), 'framework'),
|
||||
...(runtimeProbeRunner === undefined ? {} : { runtimeProbeRunner }),
|
||||
});
|
||||
registerFleetCommand(result, { runner, frameworkRoot: resolve(process.cwd(), 'framework') });
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -183,93 +166,6 @@ describe('mosaic fleet ps — roster v2', (): void => {
|
||||
});
|
||||
|
||||
describe('mosaic fleet install — roster v2', (): void => {
|
||||
it('rejects a roster runtime missing from the pane PATH before installing any files', async (): Promise<void> => {
|
||||
const mosaicHome = await v2Home({ withPaneRuntime: false });
|
||||
const operatorBin = join(tempHome!, 'operator-bin');
|
||||
await mkdir(operatorBin, { recursive: true });
|
||||
await writeFile(join(operatorBin, 'pi'), '#!/bin/sh\nexit 0\n', { mode: 0o755 });
|
||||
process.env.PATH = `${operatorBin}:${savedPath ?? '/usr/bin:/bin'}`;
|
||||
|
||||
let message = '';
|
||||
try {
|
||||
await program().parseAsync([
|
||||
'node',
|
||||
'mosaic',
|
||||
'fleet',
|
||||
'--mosaic-home',
|
||||
mosaicHome,
|
||||
'install',
|
||||
'--no-enable',
|
||||
]);
|
||||
} catch (error: unknown) {
|
||||
message = error instanceof Error ? error.message : String(error);
|
||||
}
|
||||
|
||||
expect(message).toContain('runtime=pi');
|
||||
expect(message).toContain('requested_by=coder0,coder1');
|
||||
expect(message).toContain('pane_path=');
|
||||
expect(message).toContain('npm install -g @earendil-works/pi-coding-agent');
|
||||
expect(message).not.toContain(operatorBin);
|
||||
expect(
|
||||
await exists(join(tempHome!, '.config', 'systemd', 'user', '[email protected]')),
|
||||
).toBe(false);
|
||||
expect(await exists(join(mosaicHome, 'fleet', 'holder.id'))).toBe(false);
|
||||
expect(await exists(join(mosaicHome, 'tools'))).toBe(false);
|
||||
});
|
||||
|
||||
it('rejects resolved Node-shebang commands when Node is absent from the pane PATH', async (): Promise<void> => {
|
||||
const mosaicHome = await v2Home();
|
||||
const runtimeDir = join(tempHome!, '.npm-global', 'bin');
|
||||
const nodeScript = '#!/usr/bin/env node\nconsole.log("should-not-run");\n';
|
||||
await writeFile(join(runtimeDir, 'mosaic'), nodeScript, { mode: 0o755 });
|
||||
await writeFile(join(runtimeDir, 'pi'), nodeScript, { mode: 0o755 });
|
||||
await writeFile(join(tempHome!, '.npmrc'), `prefix=${join(tempHome!, 'absent-prefix')}\n`);
|
||||
const isolatedSystemPath = join(tempHome!, 'system-bin');
|
||||
await mkdir(isolatedSystemPath, { recursive: true });
|
||||
const isolatedProbeRunner: FleetRuntimeProbeRunner = async (
|
||||
command,
|
||||
args,
|
||||
): Promise<CommandResult> =>
|
||||
new Promise((settle) => {
|
||||
const child = execFile(
|
||||
command,
|
||||
[...args, '--system-path', isolatedSystemPath],
|
||||
{ encoding: 'utf8' },
|
||||
(error, stdout, stderr) => {
|
||||
settle({
|
||||
stdout,
|
||||
stderr,
|
||||
exitCode: child.exitCode ?? (error === null ? 0 : 1),
|
||||
});
|
||||
},
|
||||
);
|
||||
});
|
||||
|
||||
let message = '';
|
||||
try {
|
||||
await program(greenfieldRunner, isolatedProbeRunner).parseAsync([
|
||||
'node',
|
||||
'mosaic',
|
||||
'fleet',
|
||||
'--mosaic-home',
|
||||
mosaicHome,
|
||||
'install',
|
||||
'--no-enable',
|
||||
]);
|
||||
} catch (error: unknown) {
|
||||
message = error instanceof Error ? error.message : String(error);
|
||||
}
|
||||
|
||||
expect(message).toContain('check=fleet-cli-executable');
|
||||
expect(message).toContain('binary=mosaic');
|
||||
expect(message).toContain('dependency=node');
|
||||
expect(message).toContain('check=fleet-runtime-available');
|
||||
expect(message).toContain('runtime=pi');
|
||||
expect(message).not.toContain('/usr/bin');
|
||||
expect(await exists(join(mosaicHome, 'fleet', 'holder.id'))).toBe(false);
|
||||
expect(await exists(join(mosaicHome, 'tools'))).toBe(false);
|
||||
});
|
||||
|
||||
it('places the tool files and unit templates', async (): Promise<void> => {
|
||||
const mosaicHome = await v2Home();
|
||||
capture();
|
||||
@@ -287,11 +183,9 @@ describe('mosaic fleet install — roster v2', (): void => {
|
||||
]) {
|
||||
expect(await exists(join(systemdUserDir, unit))).toBe(true);
|
||||
}
|
||||
for (const tool of ['start-agent-session.sh', 'pane-runtime-path.sh']) {
|
||||
const toolPath = join(mosaicHome, 'tools', 'fleet', tool);
|
||||
expect(await exists(toolPath)).toBe(true);
|
||||
expect((await stat(toolPath)).mode & 0o777).toBe(0o755);
|
||||
}
|
||||
const launcher = join(mosaicHome, 'tools', 'fleet', 'start-agent-session.sh');
|
||||
expect(await exists(launcher)).toBe(true);
|
||||
expect((await stat(launcher)).mode & 0o777).toBe(0o755);
|
||||
});
|
||||
|
||||
it('writes NO generated env — that file belongs to the reconciler (#791)', async (): Promise<void> => {
|
||||
|
||||
@@ -1277,10 +1277,6 @@ describe('fleet command construction', () => {
|
||||
const home = await tempDir();
|
||||
process.env.HOME = home;
|
||||
delete process.env.MOSAIC_HOME;
|
||||
const runtimeDir = join(home, '.npm-global', 'bin');
|
||||
await mkdir(runtimeDir, { recursive: true });
|
||||
await writeFile(join(runtimeDir, 'pi'), '#!/bin/sh\nexit 0\n', { mode: 0o755 });
|
||||
await writeFile(join(runtimeDir, 'mosaic'), '#!/bin/sh\nexit 0\n', { mode: 0o755 });
|
||||
const mosaicHome = join(home, '.config', 'mosaic');
|
||||
const program = new Command();
|
||||
program.exitOverride();
|
||||
@@ -1319,10 +1315,6 @@ describe('fleet command construction', () => {
|
||||
const originalHome = process.env.HOME;
|
||||
const home = await tempDir();
|
||||
process.env.HOME = home;
|
||||
const runtimeDir = join(home, '.npm-global', 'bin');
|
||||
await mkdir(runtimeDir, { recursive: true });
|
||||
await writeFile(join(runtimeDir, 'pi'), '#!/bin/sh\nexit 0\n', { mode: 0o755 });
|
||||
await writeFile(join(runtimeDir, 'mosaic'), '#!/bin/sh\nexit 0\n', { mode: 0o755 });
|
||||
const mosaicHome = join(home, '.config', 'mosaic');
|
||||
const agentEnvDir = join(mosaicHome, 'fleet', 'agents');
|
||||
const fleetDir = join(mosaicHome, 'fleet');
|
||||
|
||||
@@ -13,6 +13,7 @@ import {
|
||||
import { randomUUID } from 'node:crypto';
|
||||
import { homedir, hostname, userInfo } from 'node:os';
|
||||
import { dirname, join, resolve } from 'node:path';
|
||||
import { fleetAgentEnvDir } from '../fleet/brain-home.js';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
import { spawn } from 'node:child_process';
|
||||
import * as readline from 'node:readline';
|
||||
@@ -60,12 +61,6 @@ import {
|
||||
writeAgentEnvironmentProjection,
|
||||
writeManagedFleetRoster,
|
||||
} from '../fleet/generated-env-boundary.js';
|
||||
import {
|
||||
assertFleetRuntimeAvailability,
|
||||
FleetRuntimePreflightError,
|
||||
inspectFleetRuntimeAvailability,
|
||||
type FleetRuntimeProbeRunner,
|
||||
} from '../fleet/fleet-runtime-preflight.js';
|
||||
import { registerFleetBacklogCommand } from './fleet-backlog.js';
|
||||
import { registerFleetPersonaCommand } from './fleet-personas.js';
|
||||
import { registerFleetProfileCommand } from './fleet-profiles.js';
|
||||
@@ -95,8 +90,6 @@ export type SleepFn = (ms: number) => Promise<void>;
|
||||
|
||||
export interface FleetCommandDeps {
|
||||
runner?: CommandRunner;
|
||||
/** Executes the pane-PATH helper under a clean launcher environment. */
|
||||
runtimeProbeRunner?: FleetRuntimeProbeRunner;
|
||||
/** Injectable interactive runner for commands needing inherited TTY (e.g., `tmux attach`). */
|
||||
interactiveRunner?: InteractiveRunner;
|
||||
/**
|
||||
@@ -166,7 +159,7 @@ export function resolveFleetPaths(mosaicHome = defaultMosaicHome()): FleetPaths
|
||||
fleetToolsDir: join(mosaicHome, 'tools', 'fleet'),
|
||||
tmuxToolsDir: join(mosaicHome, 'tools', 'tmux'),
|
||||
systemdUserDir: join(homedir(), '.config', 'systemd', 'user'),
|
||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||
};
|
||||
}
|
||||
|
||||
@@ -1437,10 +1430,6 @@ export function isSendAccepted(capturedOutput: string): SendVerifyResult {
|
||||
|
||||
export function registerFleetCommand(program: Command, deps: FleetCommandDeps = {}): Command {
|
||||
const runner = deps.runner ?? runCommand;
|
||||
const runtimeProbeRunner: FleetRuntimeProbeRunner =
|
||||
deps.runtimeProbeRunner ??
|
||||
(async (command: string, args: readonly string[]): Promise<CommandResult> =>
|
||||
runCommand(command, [...args]));
|
||||
const sleepFn = deps.sleepFn ?? defaultSleep;
|
||||
const paths = resolveFleetPaths(deps.mosaicHome);
|
||||
const frameworkRoot = deps.frameworkRoot ?? resolveFrameworkRoot();
|
||||
@@ -1539,7 +1528,7 @@ export function registerFleetCommand(program: Command, deps: FleetCommandDeps =
|
||||
.description('Install local fleet tools and user systemd units')
|
||||
.option('--no-enable', 'Skip enabling units for boot-survival')
|
||||
.action(async (opts: { enable?: boolean }) => {
|
||||
await installFleet(cmd, frameworkRoot, runtimeProbeRunner);
|
||||
await installFleet(cmd, frameworkRoot);
|
||||
// Unit enablement needs agent names only, so it reads either version.
|
||||
const roster = await loadRosterReadModel(cmd);
|
||||
await enableFleetUnits(runner, roster, opts);
|
||||
@@ -1550,7 +1539,7 @@ export function registerFleetCommand(program: Command, deps: FleetCommandDeps =
|
||||
.description('Install local fleet tools and user systemd units')
|
||||
.option('--no-enable', 'Skip enabling units for boot-survival')
|
||||
.action(async (opts: { enable?: boolean }) => {
|
||||
await installFleet(cmd, frameworkRoot, runtimeProbeRunner);
|
||||
await installFleet(cmd, frameworkRoot);
|
||||
// Unit enablement needs agent names only, so it reads either version.
|
||||
const roster = await loadRosterReadModel(cmd);
|
||||
await enableFleetUnits(runner, roster, opts);
|
||||
@@ -2096,8 +2085,6 @@ export function registerFleetCommand(program: Command, deps: FleetCommandDeps =
|
||||
});
|
||||
registerFleetReconcilerCommands(cmd, {
|
||||
runner,
|
||||
runtimeProbeRunner,
|
||||
frameworkRoot,
|
||||
mosaicHome: deps.mosaicHome,
|
||||
reconcileDeps: deps.reconcileDeps,
|
||||
});
|
||||
@@ -2363,68 +2350,18 @@ export function registerFleetAgentCommands(
|
||||
});
|
||||
}
|
||||
|
||||
async function installFleet(
|
||||
cmd: Command,
|
||||
frameworkRoot: string,
|
||||
runtimeProbeRunner: FleetRuntimeProbeRunner,
|
||||
): Promise<void> {
|
||||
async function installFleet(cmd: Command, frameworkRoot: string): Promise<void> {
|
||||
const activePaths = resolveFleetPaths(cmd.opts<{ mosaicHome: string }>().mosaicHome);
|
||||
assertDefaultMosaicHomeForSystemd(activePaths.mosaicHome);
|
||||
// Read and preflight before the first mkdir/copy/chmod/write. A successful
|
||||
// install must mean every roster runtime is executable in the eventual pane,
|
||||
// not merely visible to the operator who invoked this command.
|
||||
// Read model first: every file this function places is roster-independent, and
|
||||
// the v1 parser would reject a v2 roster before any of them were written.
|
||||
const roster = await loadRosterReadModel(cmd);
|
||||
const v1Roster = roster.version === 1 ? await loadRosterForCommand(cmd) : undefined;
|
||||
const preflightV1Projections =
|
||||
v1Roster === undefined
|
||||
? []
|
||||
: await Promise.all(
|
||||
v1Roster.agents.map((agent: FleetAgent) =>
|
||||
prepareAgentEnvironmentProjection({
|
||||
mosaicHome: activePaths.mosaicHome,
|
||||
agentEnvDir: activePaths.agentEnvDir,
|
||||
agentName: agent.name,
|
||||
generated: generateAgentEnvValues(v1Roster, agent),
|
||||
}),
|
||||
),
|
||||
);
|
||||
const preflightAgents =
|
||||
v1Roster === undefined
|
||||
? roster.agents
|
||||
: v1Roster.agents.map((agent: FleetAgent, index: number) => {
|
||||
const prepared = preflightV1Projections[index];
|
||||
if (prepared === undefined) {
|
||||
throw new Error(`Missing prepared environment projection for ${agent.name}.`);
|
||||
}
|
||||
const local = parseAgentEnvironment(prepared.local, 'local');
|
||||
return {
|
||||
name: agent.name,
|
||||
runtime: agent.runtime,
|
||||
runtimeBin: local['MOSAIC_RUNTIME_BIN'] ?? '',
|
||||
};
|
||||
});
|
||||
const runtimeInspection = await inspectFleetRuntimeAvailability({
|
||||
mosaicHome: activePaths.mosaicHome,
|
||||
agentEnvDir: activePaths.agentEnvDir,
|
||||
helperPath: join(frameworkRoot, 'tools', 'fleet', 'pane-runtime-path.sh'),
|
||||
agents: preflightAgents,
|
||||
runner: runtimeProbeRunner,
|
||||
});
|
||||
try {
|
||||
assertFleetRuntimeAvailability(runtimeInspection);
|
||||
} catch (error: unknown) {
|
||||
if (error instanceof FleetRuntimePreflightError) {
|
||||
cmd.error(error.message, { code: 'fleet.runtime-preflight', exitCode: 1 });
|
||||
}
|
||||
throw error;
|
||||
}
|
||||
await ensureFleetHolderIdentity(activePaths.mosaicHome);
|
||||
await mkdir(activePaths.fleetToolsDir, { recursive: true });
|
||||
await mkdir(activePaths.tmuxToolsDir, { recursive: true });
|
||||
await mkdir(activePaths.systemdUserDir, { recursive: true });
|
||||
|
||||
const startAgentSessionPath = join(activePaths.fleetToolsDir, 'start-agent-session.sh');
|
||||
const paneRuntimePath = join(activePaths.fleetToolsDir, 'pane-runtime-path.sh');
|
||||
const startInteractionServicePath = join(
|
||||
activePaths.fleetToolsDir,
|
||||
'start-interaction-service.sh',
|
||||
@@ -2438,7 +2375,6 @@ async function installFleet(
|
||||
const agentSendPath = join(activePaths.tmuxToolsDir, 'agent-send.sh');
|
||||
const executableToolPaths = [
|
||||
startAgentSessionPath,
|
||||
paneRuntimePath,
|
||||
startInteractionServicePath,
|
||||
startTmuxHolderPath,
|
||||
printInteractionPolicyPath,
|
||||
@@ -2449,7 +2385,6 @@ async function installFleet(
|
||||
join(frameworkRoot, 'tools', 'fleet', 'start-agent-session.sh'),
|
||||
startAgentSessionPath,
|
||||
);
|
||||
await copyFile(join(frameworkRoot, 'tools', 'fleet', 'pane-runtime-path.sh'), paneRuntimePath);
|
||||
await copyFile(
|
||||
join(frameworkRoot, 'tools', 'fleet', 'start-interaction-service.sh'),
|
||||
startInteractionServicePath,
|
||||
@@ -2493,9 +2428,7 @@ async function installFleet(
|
||||
return;
|
||||
}
|
||||
|
||||
if (v1Roster === undefined) {
|
||||
throw new Error('Roster version changed while installing fleet files.');
|
||||
}
|
||||
const v1Roster = await loadRosterForCommand(cmd);
|
||||
for (const agent of v1Roster.agents) {
|
||||
await writeAgentEnvironmentProjection({
|
||||
mosaicHome: activePaths.mosaicHome,
|
||||
|
||||
@@ -349,3 +349,90 @@ describe('registerRuntimeLaunchers — claudex (EXPERIMENTAL overlay)', () => {
|
||||
expect(mockExit).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
|
||||
// ─── Seat harness homes (MOSAIC-D-002, brain-home split) ────────────────────
|
||||
|
||||
import { activeSeatDir, seatPersonaOverlay } from './launch.js';
|
||||
|
||||
describe('activeSeatDir — per-agent harness home resolution', () => {
|
||||
let root: string;
|
||||
const savedAgentName = process.env['MOSAIC_AGENT_NAME'];
|
||||
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
|
||||
|
||||
beforeEach(() => {
|
||||
root = mkdtempSync(join(tmpdir(), 'mosaic-seat-home-'));
|
||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
rmSync(root, { recursive: true, force: true });
|
||||
if (savedAgentName === undefined) {
|
||||
delete process.env['MOSAIC_AGENT_NAME'];
|
||||
} else {
|
||||
process.env['MOSAIC_AGENT_NAME'] = savedAgentName;
|
||||
}
|
||||
if (savedBrainHome !== undefined) {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
|
||||
} else {
|
||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||
}
|
||||
});
|
||||
|
||||
it('resolves the seat dir when MOSAIC_BRAIN_HOME carries the seat', () => {
|
||||
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
||||
mkdirSync(seat, { recursive: true });
|
||||
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||
|
||||
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBe(seat);
|
||||
});
|
||||
|
||||
it('returns undefined without an agent name (bare launches stay shared)', () => {
|
||||
delete process.env['MOSAIC_AGENT_NAME'];
|
||||
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
||||
});
|
||||
|
||||
it('returns undefined when the seat dir does not exist in the brain', () => {
|
||||
process.env['MOSAIC_AGENT_NAME'] = 'ghost';
|
||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||
mkdirSync(join(root, 'brain', 'fleet', 'agents'), { recursive: true });
|
||||
|
||||
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
||||
});
|
||||
|
||||
it.each(['../escape', 'a/b', '.hidden-start', '', 'spaced name'])(
|
||||
'rejects unsafe agent name %j (path traversal cannot leave the seat store)',
|
||||
(name: string) => {
|
||||
process.env['MOSAIC_AGENT_NAME'] = name;
|
||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||
|
||||
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
|
||||
},
|
||||
);
|
||||
|
||||
it('seatPersonaOverlay renders the seat SOUL.md as an overlay block', () => {
|
||||
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
||||
mkdirSync(seat, { recursive: true });
|
||||
writeFileSync(join(seat, 'SOUL.md'), '# coder0 — code seat persona\n\nShips tested code.\n');
|
||||
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||
|
||||
const overlay = seatPersonaOverlay(join(root, 'config', 'mosaic'));
|
||||
expect(overlay).toContain('## Seat Persona');
|
||||
expect(overlay).toContain('coder0 — code seat persona');
|
||||
});
|
||||
|
||||
it('seatPersonaOverlay is empty when the seat carries no SOUL.md', () => {
|
||||
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
|
||||
mkdirSync(seat, { recursive: true });
|
||||
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
|
||||
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
|
||||
|
||||
expect(seatPersonaOverlay(join(root, 'config', 'mosaic'))).toBe('');
|
||||
});
|
||||
|
||||
it('seatPersonaOverlay is empty when no agent name is set', () => {
|
||||
delete process.env['MOSAIC_AGENT_NAME'];
|
||||
expect(seatPersonaOverlay(join(root, 'config', 'mosaic'))).toBe('');
|
||||
});
|
||||
});
|
||||
|
||||
@@ -19,7 +19,7 @@ import {
|
||||
import { createHash, randomBytes } from 'node:crypto';
|
||||
import { createRequire } from 'node:module';
|
||||
import { homedir, hostname } from 'node:os';
|
||||
import { join, dirname } from 'node:path';
|
||||
import { join, dirname, resolve } from 'node:path';
|
||||
import type { Command } from 'commander';
|
||||
import {
|
||||
buildResolvedFleetCommsBlock,
|
||||
@@ -29,6 +29,7 @@ import {
|
||||
import { readRegularFileSecure } from '../fleet/secure-file.js';
|
||||
import { readPersonaContractBlock } from '../fleet/persona-contract.js';
|
||||
import { canonicalizeRoleClass } from './fleet-personas.js';
|
||||
import { resolveBrainHome } from '../fleet/brain-home.js';
|
||||
import { launchClaudex, type ClaudexHarnessAdapter } from './claudex.js';
|
||||
import { runLeaseEnforcementDoctorCheck } from './lease-doctor-check.js';
|
||||
|
||||
@@ -64,9 +65,46 @@ const HARNESS_HOME_ENV: Record<RuntimeName, string> = {
|
||||
opencode: 'XDG_CONFIG_HOME',
|
||||
};
|
||||
|
||||
/** Dedicated mosaic-owned home for a runtime: ~/.config/mosaic/.<runtime> */
|
||||
function harnessHome(runtime: RuntimeName): string {
|
||||
return join(MOSAIC_HOME, `.${runtime}`);
|
||||
/** Dedicated mosaic-owned home for a runtime: ~/.config/mosaic/.<runtime>.
|
||||
* With an active brain seat (MOSAIC_AGENT_NAME + seat dir in the brain home)
|
||||
* the home is per-agent instead: <brainHome>/fleet/agents/<seat>/.<runtime> —
|
||||
* per-agent sessions, settings, and auth inside the seat dir (canon §2,
|
||||
* MOSAIC-D-002). Seat runtime dirs are dot-named so the brain's ignore policy
|
||||
* (per-seat .pi/.claude/.codex dirs) keeps credential material untracked. */
|
||||
const SEAT_AGENT_NAME_RE = /^[a-zA-Z0-9][a-zA-Z0-9._-]*$/;
|
||||
|
||||
export function activeSeatDir(mosaicHome: string = MOSAIC_HOME): string | undefined {
|
||||
const agent = process.env['MOSAIC_AGENT_NAME']?.trim();
|
||||
if (
|
||||
agent === undefined ||
|
||||
agent === '' ||
|
||||
!SEAT_AGENT_NAME_RE.test(agent) ||
|
||||
agent.includes('..')
|
||||
) {
|
||||
return undefined;
|
||||
}
|
||||
const brain = resolveBrainHome(mosaicHome);
|
||||
if (resolve(brain) === resolve(mosaicHome)) return undefined; // no brain
|
||||
const seat = join(brain, 'fleet', 'agents', agent);
|
||||
return existsSync(seat) ? seat : undefined;
|
||||
}
|
||||
|
||||
function harnessHome(runtime: RuntimeName, mosaicHome: string = MOSAIC_HOME): string {
|
||||
const seat = activeSeatDir(mosaicHome);
|
||||
if (seat !== undefined) return join(seat, `.${runtime}`);
|
||||
return join(mosaicHome, `.${runtime}`);
|
||||
}
|
||||
|
||||
/** Seat persona block: with an active brain seat, <seat>/SOUL.md layers
|
||||
* persona on the root generic base (canon invariant; MOSAIC-D-002). The base
|
||||
* SOUL stays load-on-demand — only the seat delta is injected by value.
|
||||
* Empty string when no seat is active or the seat carries no SOUL.md. */
|
||||
export function seatPersonaOverlay(mosaicHome: string = MOSAIC_HOME): string {
|
||||
const seatDir = activeSeatDir(mosaicHome);
|
||||
if (seatDir === undefined) return '';
|
||||
const seatSoul = readOptional(join(seatDir, 'SOUL.md'));
|
||||
if (!seatSoul.trim()) return '';
|
||||
return '## Seat Persona\n\n' + seatSoul.trim();
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -182,6 +220,8 @@ function recordLaunch(runtime: RuntimeName, cliArgs: string[], yolo: boolean): v
|
||||
cli_version: CLI_VERSION,
|
||||
config_home: harnessHome(runtime),
|
||||
config_home_isolated: true,
|
||||
config_home_kind: activeSeatDir() !== undefined ? 'seat' : 'runtime-shared',
|
||||
agent_name: process.env['MOSAIC_AGENT_NAME']?.trim() || null,
|
||||
config_home_env: HARNESS_HOME_ENV[runtime] ?? null,
|
||||
argv: redactArgv(cliArgs),
|
||||
normative_fragments: normativeFragmentDigests(runtime),
|
||||
@@ -569,6 +609,11 @@ For required push/merge/issue-close/release actions, execute without routine con
|
||||
if (soulLocal.trim()) {
|
||||
overlayBlocks.push('## Persona Overlay (SOUL.local.md)\n\n' + soulLocal.trim());
|
||||
}
|
||||
// Seat persona (MOSAIC-D-002): per-seat SOUL.md layers on the generic base.
|
||||
const seatPersona = seatPersonaOverlay(mosaicHome);
|
||||
if (seatPersona !== '') {
|
||||
overlayBlocks.push(seatPersona);
|
||||
}
|
||||
const standardsLocal = readOptional(join(mosaicHome, 'STANDARDS.local.md'));
|
||||
if (standardsLocal.trim()) {
|
||||
overlayBlocks.push('## Standards Overlay (STANDARDS.local.md)\n\n' + standardsLocal.trim());
|
||||
|
||||
@@ -0,0 +1,114 @@
|
||||
import { mkdir, mkdtemp, rm } from 'node:fs/promises';
|
||||
import { homedir, tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
|
||||
import {
|
||||
brainHomeIsActive,
|
||||
fleetAgentEnvDir,
|
||||
fleetProfilesDir,
|
||||
fleetRolesLocalDir,
|
||||
fleetStateDir,
|
||||
resolveBrainHome,
|
||||
type BrainHomeOptions,
|
||||
} from './brain-home.js';
|
||||
|
||||
describe('fleet brain-home resolution', (): void => {
|
||||
let cleanup: string | undefined;
|
||||
|
||||
const savedBrainEnv = process.env['MOSAIC_BRAIN_HOME'];
|
||||
|
||||
beforeEach((): void => {
|
||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||
});
|
||||
|
||||
afterEach(async (): Promise<void> => {
|
||||
if (savedBrainEnv === undefined) {
|
||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||
} else {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = savedBrainEnv;
|
||||
}
|
||||
if (cleanup !== undefined) {
|
||||
await rm(cleanup, { recursive: true, force: true });
|
||||
cleanup = undefined;
|
||||
}
|
||||
});
|
||||
|
||||
async function makeTmp(): Promise<string> {
|
||||
const root = await mkdtemp(join(tmpdir(), 'mosaic-brain-home-'));
|
||||
cleanup = root;
|
||||
return root;
|
||||
}
|
||||
|
||||
it('MOSAIC_BRAIN_HOME env wins over every other signal', (): void => {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = '/explicit/brain';
|
||||
expect(resolveBrainHome('/any/mosaic-home')).toBe('/explicit/brain');
|
||||
expect(fleetAgentEnvDir('/any/mosaic-home')).toBe('/explicit/brain/fleet/agents');
|
||||
expect(brainHomeIsActive('/any/mosaic-home')).toBe(true);
|
||||
});
|
||||
|
||||
it('injected envBrainHome wins identically (test seam)', (): void => {
|
||||
const opts: BrainHomeOptions = { envBrainHome: '/injected/brain' };
|
||||
expect(resolveBrainHome('/any/mosaic-home', opts)).toBe('/injected/brain');
|
||||
expect(fleetAgentEnvDir('/any/mosaic-home', opts)).toBe('/injected/brain/fleet/agents');
|
||||
});
|
||||
|
||||
it('a non-default mosaicHome never adopts the canonical brain (hermetic legacy)', (): void => {
|
||||
const mosaicHome = '/tmp/not-the-default-config-home';
|
||||
expect(resolveBrainHome(mosaicHome)).toBe(mosaicHome);
|
||||
expect(brainHomeIsActive(mosaicHome)).toBe(false);
|
||||
expect(fleetAgentEnvDir(mosaicHome)).toBe(join(mosaicHome, 'fleet', 'agents'));
|
||||
});
|
||||
|
||||
it('the default config home adopts the brain when it carries fleet/agents', async (): Promise<void> => {
|
||||
const root = await makeTmp();
|
||||
const brain = join(root, 'brain');
|
||||
await mkdir(join(brain, 'fleet', 'agents'), { recursive: true });
|
||||
const configHome = join(root, 'config', 'mosaic');
|
||||
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
|
||||
|
||||
expect(resolveBrainHome(configHome, opts)).toBe(brain);
|
||||
expect(fleetAgentEnvDir(configHome, opts)).toBe(join(brain, 'fleet', 'agents'));
|
||||
expect(fleetRolesLocalDir(configHome, opts)).toBe(join(brain, 'fleet', 'roles.local'));
|
||||
expect(fleetProfilesDir(configHome, opts)).toBe(join(brain, 'fleet', 'profiles'));
|
||||
expect(fleetStateDir(configHome, opts)).toBe(join(brain, 'fleet'));
|
||||
expect(brainHomeIsActive(configHome, opts)).toBe(true);
|
||||
});
|
||||
|
||||
it('the default config home stays legacy when no brain exists', async (): Promise<void> => {
|
||||
const root = await makeTmp();
|
||||
const configHome = join(root, 'config', 'mosaic');
|
||||
const opts: BrainHomeOptions = {
|
||||
homes: { brain: join(root, 'brain'), configDefault: configHome },
|
||||
};
|
||||
|
||||
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
|
||||
expect(brainHomeIsActive(configHome, opts)).toBe(false);
|
||||
});
|
||||
|
||||
it('an empty MOSAIC_BRAIN_HOME is ignored, not treated as set', (): void => {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = ' ';
|
||||
expect(resolveBrainHome('/tmp/legacy-home')).toBe('/tmp/legacy-home');
|
||||
});
|
||||
|
||||
it('adoption requires fleet/agents specifically, not any brain content', async (): Promise<void> => {
|
||||
const root = await makeTmp();
|
||||
const brain = join(root, 'brain');
|
||||
await mkdir(join(brain, 'fleet'), { recursive: true }); // fleet without agents
|
||||
const configHome = join(root, 'config', 'mosaic');
|
||||
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
|
||||
|
||||
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
|
||||
});
|
||||
|
||||
it('real-home control: a host brain is adopted only through the default home', (): void => {
|
||||
// Control on the un-injected path: this host carries ~/.mosaic/fleet/agents,
|
||||
// so the default config home resolves to the brain or legacy — both valid
|
||||
// canonical endpoints — while a non-default home never adopts.
|
||||
const defaultHome = join(homedir(), '.config', 'mosaic');
|
||||
const resolved = resolveBrainHome(defaultHome);
|
||||
expect([defaultHome, join(homedir(), '.mosaic')]).toContain(resolved);
|
||||
expect(resolveBrainHome(join(homedir(), 'elsewhere', 'mosaic'))).toBe(
|
||||
join(homedir(), 'elsewhere', 'mosaic'),
|
||||
);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,76 @@
|
||||
import { existsSync } from 'node:fs';
|
||||
import { homedir } from 'node:os';
|
||||
import { join, resolve } from 'node:path';
|
||||
|
||||
/**
|
||||
* Overridable resolution inputs (tests inject tmp homes; production reads
|
||||
* the environment and the real home directory).
|
||||
*/
|
||||
export interface BrainHomeOptions {
|
||||
/** Explicit brain home; defaults to `MOSAIC_BRAIN_HOME`. */
|
||||
readonly envBrainHome?: string;
|
||||
/**
|
||||
* Canonical homes used for adoption. Defaults derive from the real
|
||||
* `homedir()`: `{ brain: ~/.mosaic, configDefault: ~/.config/mosaic }`.
|
||||
*/
|
||||
readonly homes?: { readonly brain: string; readonly configDefault: string };
|
||||
}
|
||||
|
||||
/**
|
||||
* Brain-home resolution — the three-tree fleet split (stack canon
|
||||
* `docs/STRUCTURE-CANON.md` §2, first carried by the USC estate brain):
|
||||
*
|
||||
* config home (~/.config/mosaic) framework templates + dispatch state:
|
||||
* fleet/roles (baseline), fleet/roster.yaml,
|
||||
* fleet/run (heartbeats), fleet/services
|
||||
* brain home (~/.mosaic) user-owned fleet state, committed:
|
||||
* fleet/agents/<seat>.env.*, fleet/roles.local,
|
||||
* fleet/profiles working copies
|
||||
*
|
||||
* Resolution order:
|
||||
* 1. `MOSAIC_BRAIN_HOME` env (explicit, always wins)
|
||||
* 2. canonical `~/.mosaic` — adopted ONLY when mosaicHome is the real
|
||||
* default config home AND `~/.mosaic/fleet/agents` exists. Custom
|
||||
* `--mosaic-home` values (tests, sandboxes, canaries) never trigger
|
||||
* adoption, keeping them hermetic and deterministic.
|
||||
* 3. mosaicHome itself (legacy single-tree behavior).
|
||||
*/
|
||||
export function resolveBrainHome(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
const explicit = options.envBrainHome ?? process.env['MOSAIC_BRAIN_HOME'];
|
||||
if (explicit !== undefined && explicit.trim() !== '') {
|
||||
return explicit;
|
||||
}
|
||||
const homes = options.homes ?? {
|
||||
brain: join(homedir(), '.mosaic'),
|
||||
configDefault: join(homedir(), '.config', 'mosaic'),
|
||||
};
|
||||
if (resolve(mosaicHome) !== resolve(homes.configDefault)) {
|
||||
return mosaicHome;
|
||||
}
|
||||
return existsSync(join(homes.brain, 'fleet', 'agents')) ? homes.brain : mosaicHome;
|
||||
}
|
||||
|
||||
/** True when fleet state resolves somewhere other than the config home. */
|
||||
export function brainHomeIsActive(mosaicHome: string, options: BrainHomeOptions = {}): boolean {
|
||||
return resolve(resolveBrainHome(mosaicHome, options)) !== resolve(mosaicHome);
|
||||
}
|
||||
|
||||
/** Fleet state root (brain home when active, else the config home). */
|
||||
export function fleetStateDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
return join(resolveBrainHome(mosaicHome, options), 'fleet');
|
||||
}
|
||||
|
||||
/** Seat launch envs — `<brainHome>/fleet/agents` when a brain is active. */
|
||||
export function fleetAgentEnvDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
return join(fleetStateDir(mosaicHome, options), 'agents');
|
||||
}
|
||||
|
||||
/** PRESERVE-protected persona override layer — `<brainHome>/fleet/roles.local`. */
|
||||
export function fleetRolesLocalDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
return join(fleetStateDir(mosaicHome, options), 'roles.local');
|
||||
}
|
||||
|
||||
/** System-type profiles (user working copies) — `<brainHome>/fleet/profiles`. */
|
||||
export function fleetProfilesDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
|
||||
return join(fleetStateDir(mosaicHome, options), 'profiles');
|
||||
}
|
||||
@@ -3,6 +3,7 @@ import { lstat, open, readFile, unlink, type FileHandle } from 'node:fs/promises
|
||||
import { randomUUID } from 'node:crypto';
|
||||
import { homedir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { fleetAgentEnvDir } from './brain-home.js';
|
||||
import {
|
||||
applyPreparedAgentEnvironmentProjection,
|
||||
prepareAgentEnvironmentProjection,
|
||||
@@ -617,7 +618,7 @@ function defaultPrepareProjections(
|
||||
(agent: FleetRosterV2Agent): Promise<PreparedAgentEnvironmentProjection> =>
|
||||
prepareAgentEnvironmentProjection({
|
||||
mosaicHome,
|
||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||
agentEnvDir: fleetAgentEnvDir(mosaicHome),
|
||||
agentName: agent.name,
|
||||
generated: projectRosterV2AgentGeneratedEnv(roster, agent),
|
||||
}),
|
||||
|
||||
@@ -1,328 +0,0 @@
|
||||
import { spawn } from 'node:child_process';
|
||||
import { chmod, mkdir, mkdtemp, rm, writeFile } from 'node:fs/promises';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join, resolve } from 'node:path';
|
||||
import { afterEach, describe, expect, it } from 'vitest';
|
||||
import {
|
||||
inspectFleetRuntimeAvailability,
|
||||
type FleetRuntimeProbeResult,
|
||||
type FleetRuntimeProbeRunner,
|
||||
} from './fleet-runtime-preflight.js';
|
||||
|
||||
const helperPath = resolve(process.cwd(), 'framework', 'tools', 'fleet', 'pane-runtime-path.sh');
|
||||
let cleanup: string | undefined;
|
||||
|
||||
afterEach(async (): Promise<void> => {
|
||||
if (cleanup !== undefined) await rm(cleanup, { recursive: true, force: true });
|
||||
cleanup = undefined;
|
||||
});
|
||||
|
||||
interface FleetFixture {
|
||||
readonly root: string;
|
||||
readonly mosaicHome: string;
|
||||
readonly agentEnvDir: string;
|
||||
readonly runtimeDir: string;
|
||||
}
|
||||
|
||||
async function fleetHome(): Promise<FleetFixture> {
|
||||
const root = await mkdtemp(join(tmpdir(), 'mosaic-fleet-runtime-preflight-'));
|
||||
cleanup = root;
|
||||
const mosaicHome = join(root, '.config', 'mosaic');
|
||||
const agentEnvDir = join(mosaicHome, 'fleet', 'agents');
|
||||
const runtimeDir = join(root, '.npm-global', 'bin');
|
||||
await mkdir(agentEnvDir, { recursive: true, mode: 0o700 });
|
||||
await mkdir(runtimeDir, { recursive: true });
|
||||
for (const directory of [mosaicHome, join(mosaicHome, 'fleet'), agentEnvDir]) {
|
||||
await chmod(directory, 0o700);
|
||||
}
|
||||
await writeExecutable(runtimeDir, 'mosaic', '#!/bin/sh\nexit 0\n');
|
||||
return { root, mosaicHome, agentEnvDir, runtimeDir };
|
||||
}
|
||||
|
||||
async function writeExecutable(directory: string, name: string, content: string): Promise<void> {
|
||||
await mkdir(directory, { recursive: true });
|
||||
await writeFile(join(directory, name), content, { mode: 0o755 });
|
||||
}
|
||||
|
||||
const processRunner: FleetRuntimeProbeRunner = async (
|
||||
command: string,
|
||||
args: readonly string[],
|
||||
): Promise<FleetRuntimeProbeResult> =>
|
||||
new Promise((settle) => {
|
||||
const child = spawn(command, [...args], { stdio: ['ignore', 'pipe', 'pipe'] });
|
||||
let stdout = '';
|
||||
let stderr = '';
|
||||
child.stdout.setEncoding('utf8');
|
||||
child.stderr.setEncoding('utf8');
|
||||
child.stdout.on('data', (chunk: string): void => {
|
||||
stdout += chunk;
|
||||
});
|
||||
child.stderr.on('data', (chunk: string): void => {
|
||||
stderr += chunk;
|
||||
});
|
||||
child.on('error', (error: Error): void => {
|
||||
settle({ stdout, stderr: `${stderr}${error.message}`, exitCode: 127 });
|
||||
});
|
||||
child.on('close', (code: number | null): void => {
|
||||
settle({ stdout, stderr, exitCode: code ?? 1 });
|
||||
});
|
||||
});
|
||||
|
||||
describe('fleet runtime preflight', (): void => {
|
||||
it('executes one distinct pane runtime and aggregates every requesting roster row', async (): Promise<void> => {
|
||||
const fixture = await fleetHome();
|
||||
await writeExecutable(fixture.runtimeDir, 'pi', '#!/bin/sh\nexit 0\n');
|
||||
let probes = 0;
|
||||
|
||||
const inspection = await inspectFleetRuntimeAvailability({
|
||||
mosaicHome: fixture.mosaicHome,
|
||||
agentEnvDir: fixture.agentEnvDir,
|
||||
helperPath,
|
||||
agents: [
|
||||
{ name: 'coder1', runtime: 'pi' },
|
||||
{ name: 'coder0', runtime: 'pi' },
|
||||
],
|
||||
runner: async (command, args): Promise<FleetRuntimeProbeResult> => {
|
||||
probes += 1;
|
||||
return processRunner(command, args);
|
||||
},
|
||||
});
|
||||
|
||||
expect(probes).toBe(2);
|
||||
expect(inspection.fleetCliExecutable).toEqual([
|
||||
expect.objectContaining({
|
||||
check: 'fleet-cli-executable',
|
||||
status: 'ok',
|
||||
requestedBy: ['coder0', 'coder1'],
|
||||
binaryPath: join(fixture.runtimeDir, 'mosaic'),
|
||||
dependency: '/bin/sh',
|
||||
}),
|
||||
]);
|
||||
expect(inspection.fleetRuntimeAvailability).toEqual([
|
||||
expect.objectContaining({
|
||||
check: 'fleet-runtime-available',
|
||||
runtime: 'pi',
|
||||
status: 'ok',
|
||||
requestedBy: ['coder0', 'coder1'],
|
||||
binaryPath: join(fixture.runtimeDir, 'pi'),
|
||||
dependency: '/bin/sh',
|
||||
installCommand: 'npm install -g @earendil-works/pi-coding-agent',
|
||||
}),
|
||||
]);
|
||||
expect(inspection.fleetRuntimeAvailability[0]?.panePath).toContain(fixture.runtimeDir);
|
||||
});
|
||||
|
||||
it('returns an actionable non-green check when the pane PATH lacks the runtime', async (): Promise<void> => {
|
||||
const fixture = await fleetHome();
|
||||
|
||||
const inspection = await inspectFleetRuntimeAvailability({
|
||||
mosaicHome: fixture.mosaicHome,
|
||||
agentEnvDir: fixture.agentEnvDir,
|
||||
helperPath,
|
||||
agents: [{ name: 'coder0', runtime: 'pi' }],
|
||||
runner: processRunner,
|
||||
});
|
||||
|
||||
expect(inspection.fleetCliExecutable[0]?.status).toBe('ok');
|
||||
expect(inspection.fleetRuntimeAvailability).toEqual([
|
||||
expect.objectContaining({
|
||||
check: 'fleet-runtime-available',
|
||||
runtime: 'pi',
|
||||
status: 'missing',
|
||||
requestedBy: ['coder0'],
|
||||
installCommand: 'npm install -g @earendil-works/pi-coding-agent',
|
||||
}),
|
||||
]);
|
||||
expect(inspection.fleetRuntimeAvailability[0]?.panePath).not.toContain(
|
||||
process.env['PATH'] ?? 'operator-path-absent',
|
||||
);
|
||||
});
|
||||
|
||||
it('executes the side-effect-free Node version probe for Node-shebang commands', async (): Promise<void> => {
|
||||
const fixture = await fleetHome();
|
||||
const nodeScript = '#!/usr/bin/env node\nconsole.log("should-not-run");\n';
|
||||
await writeExecutable(fixture.runtimeDir, 'mosaic', nodeScript);
|
||||
await writeExecutable(fixture.runtimeDir, 'pi', nodeScript);
|
||||
await writeExecutable(
|
||||
fixture.runtimeDir,
|
||||
'node',
|
||||
'#!/bin/sh\n[ "$1" = --version ] || exit 9\nprintf "v-fixture-node\\n"\n',
|
||||
);
|
||||
|
||||
const inspection = await inspectFleetRuntimeAvailability({
|
||||
mosaicHome: fixture.mosaicHome,
|
||||
agentEnvDir: fixture.agentEnvDir,
|
||||
helperPath,
|
||||
agents: [{ name: 'coder0', runtime: 'pi' }],
|
||||
runner: processRunner,
|
||||
});
|
||||
|
||||
for (const check of [
|
||||
...inspection.fleetCliExecutable,
|
||||
...inspection.fleetRuntimeAvailability,
|
||||
]) {
|
||||
expect(check).toMatchObject({
|
||||
status: 'ok',
|
||||
dependency: 'node',
|
||||
probeCommand: 'node --version',
|
||||
probeExit: 0,
|
||||
probeOutput: 'v-fixture-node',
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
it('reddens when resolved Node-shebang commands cannot execute without pane Node', async (): Promise<void> => {
|
||||
const fixture = await fleetHome();
|
||||
const isolatedSystemPath = join(fixture.root, 'system-bin');
|
||||
await mkdir(isolatedSystemPath, { recursive: true });
|
||||
await writeFile(
|
||||
join(fixture.root, '.npmrc'),
|
||||
`prefix=${join(fixture.root, 'absent-prefix')}\n`,
|
||||
);
|
||||
const nodeScript = '#!/usr/bin/env node\nconsole.log("should-not-run");\n';
|
||||
await writeExecutable(fixture.runtimeDir, 'mosaic', nodeScript);
|
||||
await writeExecutable(fixture.runtimeDir, 'pi', nodeScript);
|
||||
|
||||
const inspection = await inspectFleetRuntimeAvailability({
|
||||
mosaicHome: fixture.mosaicHome,
|
||||
agentEnvDir: fixture.agentEnvDir,
|
||||
helperPath,
|
||||
agents: [{ name: 'coder0', runtime: 'pi' }],
|
||||
runner: processRunner,
|
||||
systemPath: isolatedSystemPath,
|
||||
});
|
||||
|
||||
expect(inspection.fleetCliExecutable).toEqual([
|
||||
expect.objectContaining({
|
||||
check: 'fleet-cli-executable',
|
||||
status: 'unexecutable',
|
||||
binaryPath: join(fixture.runtimeDir, 'mosaic'),
|
||||
dependency: 'node',
|
||||
probeCommand: 'node --version',
|
||||
}),
|
||||
]);
|
||||
expect(inspection.fleetRuntimeAvailability).toEqual([
|
||||
expect.objectContaining({
|
||||
check: 'fleet-runtime-available',
|
||||
runtime: 'pi',
|
||||
status: 'unexecutable',
|
||||
binaryPath: join(fixture.runtimeDir, 'pi'),
|
||||
dependency: 'node',
|
||||
probeCommand: 'node --version',
|
||||
}),
|
||||
]);
|
||||
expect(inspection.fleetCliExecutable[0]?.probeOutput).toBe(
|
||||
'shebang command is not on the pane PATH',
|
||||
);
|
||||
expect(inspection.fleetCliExecutable[0]?.panePath).not.toContain('/usr/bin');
|
||||
});
|
||||
|
||||
it('keeps distinct effective local runtime-bin paths as distinct checks', async (): Promise<void> => {
|
||||
const fixture = await fleetHome();
|
||||
const firstBin = join(fixture.root, 'first-bin');
|
||||
const secondBin = join(fixture.root, 'second-bin');
|
||||
for (const override of [
|
||||
{ agent: 'coder0', runtimeBin: firstBin },
|
||||
{ agent: 'coder1', runtimeBin: secondBin },
|
||||
]) {
|
||||
await writeExecutable(override.runtimeBin, 'pi', '#!/bin/sh\nexit 0\n');
|
||||
await writeFile(
|
||||
join(fixture.agentEnvDir, `${override.agent}.env.local`),
|
||||
`MOSAIC_RUNTIME_BIN=${override.runtimeBin}\n`,
|
||||
{ mode: 0o600 },
|
||||
);
|
||||
}
|
||||
|
||||
const inspection = await inspectFleetRuntimeAvailability({
|
||||
mosaicHome: fixture.mosaicHome,
|
||||
agentEnvDir: fixture.agentEnvDir,
|
||||
helperPath,
|
||||
agents: [
|
||||
{ name: 'coder0', runtime: 'pi' },
|
||||
{ name: 'coder1', runtime: 'pi' },
|
||||
],
|
||||
runner: processRunner,
|
||||
});
|
||||
|
||||
expect(inspection.fleetCliExecutable).toHaveLength(2);
|
||||
expect(inspection.fleetRuntimeAvailability).toHaveLength(2);
|
||||
expect(inspection.fleetRuntimeAvailability.map((check) => check.requestedBy)).toEqual([
|
||||
['coder0'],
|
||||
['coder1'],
|
||||
]);
|
||||
expect(inspection.fleetRuntimeAvailability.map((check) => check.binaryPath)).toEqual([
|
||||
join(firstBin, 'pi'),
|
||||
join(secondBin, 'pi'),
|
||||
]);
|
||||
});
|
||||
|
||||
it('reports each distinct roster runtime with its exact install command', async (): Promise<void> => {
|
||||
const fixture = await fleetHome();
|
||||
let probes = 0;
|
||||
|
||||
const inspection = await inspectFleetRuntimeAvailability({
|
||||
mosaicHome: fixture.mosaicHome,
|
||||
agentEnvDir: fixture.agentEnvDir,
|
||||
helperPath,
|
||||
agents: [
|
||||
{ name: 'pi-seat', runtime: 'pi' },
|
||||
{ name: 'claude-seat', runtime: 'claude' },
|
||||
{ name: 'codex-seat', runtime: 'codex' },
|
||||
{ name: 'opencode-seat', runtime: 'opencode' },
|
||||
],
|
||||
runner: async (): Promise<FleetRuntimeProbeResult> => {
|
||||
probes += 1;
|
||||
return {
|
||||
stdout:
|
||||
'pane_path\u0000/fixture/bin:/usr/bin:/bin\u0000status\u0000missing\u0000' +
|
||||
'binary_path\u0000\u0000probe_exit\u0000\u0000probe_output\u0000\u0000',
|
||||
stderr: '',
|
||||
exitCode: 69,
|
||||
};
|
||||
},
|
||||
});
|
||||
|
||||
expect(probes).toBe(5);
|
||||
expect(
|
||||
inspection.fleetRuntimeAvailability.map((check) => ({
|
||||
runtime: check.runtime,
|
||||
installCommand: check.installCommand,
|
||||
})),
|
||||
).toEqual([
|
||||
{
|
||||
runtime: 'claude',
|
||||
installCommand: 'curl -fsSL https://claude.ai/install.sh | bash',
|
||||
},
|
||||
{
|
||||
runtime: 'codex',
|
||||
installCommand: 'npm install -g @openai/codex',
|
||||
},
|
||||
{
|
||||
runtime: 'opencode',
|
||||
installCommand: 'npm install -g opencode-ai',
|
||||
},
|
||||
{
|
||||
runtime: 'pi',
|
||||
installCommand: 'npm install -g @earendil-works/pi-coding-agent',
|
||||
},
|
||||
]);
|
||||
});
|
||||
|
||||
it('fails closed when the shared helper returns malformed evidence', async (): Promise<void> => {
|
||||
const fixture = await fleetHome();
|
||||
|
||||
await expect(
|
||||
inspectFleetRuntimeAvailability({
|
||||
mosaicHome: fixture.mosaicHome,
|
||||
agentEnvDir: fixture.agentEnvDir,
|
||||
helperPath,
|
||||
agents: [{ name: 'coder0', runtime: 'pi' }],
|
||||
runner: async (): Promise<FleetRuntimeProbeResult> => ({
|
||||
stdout: 'not-a-field-protocol',
|
||||
stderr: '',
|
||||
exitCode: 0,
|
||||
}),
|
||||
}),
|
||||
).rejects.toThrow('malformed field output');
|
||||
});
|
||||
});
|
||||
@@ -1,362 +0,0 @@
|
||||
import { homedir } from 'node:os';
|
||||
import { getInstallInstructions } from '../runtime/detector.js';
|
||||
import type { RuntimeName } from '../types.js';
|
||||
import { compareCodePoints } from './deterministic-order.js';
|
||||
import {
|
||||
GENERATED_AGENT_ENV_SUPPORTED_RUNTIMES,
|
||||
readAgentLocalEnvironment,
|
||||
} from './generated-env-boundary.js';
|
||||
|
||||
const RUNTIME_SET = new Set<string>(GENERATED_AGENT_ENV_SUPPORTED_RUNTIMES);
|
||||
|
||||
export interface FleetRuntimeRequestedAgent {
|
||||
readonly name: string;
|
||||
readonly runtime: string;
|
||||
/** Planned effective local override, when provisioning has already prepared it. */
|
||||
readonly runtimeBin?: string;
|
||||
}
|
||||
|
||||
export interface FleetRuntimeProbeResult {
|
||||
readonly stdout: string;
|
||||
readonly stderr: string;
|
||||
readonly exitCode: number;
|
||||
}
|
||||
|
||||
export type FleetRuntimeProbeRunner = (
|
||||
command: string,
|
||||
args: readonly string[],
|
||||
) => Promise<FleetRuntimeProbeResult>;
|
||||
|
||||
export interface FleetRuntimePreflightOptions {
|
||||
readonly mosaicHome: string;
|
||||
readonly agentEnvDir: string;
|
||||
readonly helperPath: string;
|
||||
readonly agents: readonly FleetRuntimeRequestedAgent[];
|
||||
readonly runner: FleetRuntimeProbeRunner;
|
||||
/** Test-only system suffix; production and the launcher use the helper default. */
|
||||
readonly systemPath?: string;
|
||||
}
|
||||
|
||||
export type FleetExecutableStatus = 'ok' | 'missing' | 'unexecutable';
|
||||
|
||||
interface FleetExecutableEvidence {
|
||||
readonly status: FleetExecutableStatus;
|
||||
readonly panePath: string;
|
||||
readonly binaryPath?: string;
|
||||
readonly dependency?: string;
|
||||
readonly probeCommand?: string;
|
||||
readonly probeExit?: number;
|
||||
readonly probeOutput?: string;
|
||||
}
|
||||
|
||||
export interface FleetCliExecutableCheck extends FleetExecutableEvidence {
|
||||
readonly check: 'fleet-cli-executable';
|
||||
readonly binary: 'mosaic';
|
||||
readonly requestedBy: readonly string[];
|
||||
}
|
||||
|
||||
export interface FleetRuntimeCheck extends FleetExecutableEvidence {
|
||||
readonly check: 'fleet-runtime-available';
|
||||
readonly runtime: RuntimeName;
|
||||
readonly requestedBy: readonly string[];
|
||||
readonly installCommand: string;
|
||||
}
|
||||
|
||||
export type FleetRuntimePreflightCheck = FleetCliExecutableCheck | FleetRuntimeCheck;
|
||||
|
||||
export interface FleetRuntimeInspection {
|
||||
readonly fleetCliExecutable: readonly FleetCliExecutableCheck[];
|
||||
readonly fleetRuntimeAvailability: readonly FleetRuntimeCheck[];
|
||||
}
|
||||
|
||||
interface EffectiveAgent {
|
||||
readonly name: string;
|
||||
readonly runtime: RuntimeName;
|
||||
readonly runtimeBin: string;
|
||||
}
|
||||
|
||||
interface PaneProbeGroup {
|
||||
readonly runtimeBin: string;
|
||||
readonly requestedBy: string[];
|
||||
}
|
||||
|
||||
interface RuntimeProbeGroup extends PaneProbeGroup {
|
||||
readonly runtime: RuntimeName;
|
||||
}
|
||||
|
||||
interface BinaryProbeRequest {
|
||||
readonly binary: string;
|
||||
readonly runtimeBin: string;
|
||||
}
|
||||
|
||||
export class FleetRuntimePreflightError extends Error {
|
||||
readonly checks: readonly FleetRuntimePreflightCheck[];
|
||||
|
||||
constructor(checks: readonly FleetRuntimePreflightCheck[]) {
|
||||
super(formatFleetRuntimePreflightError(checks));
|
||||
this.name = FleetRuntimePreflightError.name;
|
||||
this.checks = checks;
|
||||
}
|
||||
}
|
||||
|
||||
export class FleetRuntimeProbeError extends Error {
|
||||
constructor(message: string) {
|
||||
super(message);
|
||||
this.name = FleetRuntimeProbeError.name;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Proves the fleet CLI and every distinct runtime/effective-bin pair resolve
|
||||
* with an executable shebang interpreter through the eventual pane PATH. The
|
||||
* helper runs under the unit's clean launcher environment, so operator PATH can
|
||||
* neither create a false green nor provide a hidden interpreter.
|
||||
*/
|
||||
export async function inspectFleetRuntimeAvailability(
|
||||
options: FleetRuntimePreflightOptions,
|
||||
): Promise<FleetRuntimeInspection> {
|
||||
const agents = await resolveEffectiveAgents(options);
|
||||
const paneGroups = groupPaneRequests(agents);
|
||||
const runtimeGroups = groupRuntimeRequests(agents);
|
||||
|
||||
const fleetCliExecutable: FleetCliExecutableCheck[] = [];
|
||||
for (const group of paneGroups) {
|
||||
const evidence = await probeBinary(options, {
|
||||
binary: 'mosaic',
|
||||
runtimeBin: group.runtimeBin,
|
||||
});
|
||||
fleetCliExecutable.push({
|
||||
check: 'fleet-cli-executable',
|
||||
binary: 'mosaic',
|
||||
requestedBy: sortedRequestedBy(group.requestedBy),
|
||||
...evidence,
|
||||
});
|
||||
}
|
||||
|
||||
const fleetRuntimeAvailability: FleetRuntimeCheck[] = [];
|
||||
for (const group of runtimeGroups) {
|
||||
const evidence = await probeBinary(options, {
|
||||
binary: group.runtime,
|
||||
runtimeBin: group.runtimeBin,
|
||||
});
|
||||
fleetRuntimeAvailability.push({
|
||||
check: 'fleet-runtime-available',
|
||||
runtime: group.runtime,
|
||||
requestedBy: sortedRequestedBy(group.requestedBy),
|
||||
installCommand: getInstallInstructions(group.runtime),
|
||||
...evidence,
|
||||
});
|
||||
}
|
||||
|
||||
return Object.freeze({
|
||||
fleetCliExecutable: Object.freeze(fleetCliExecutable),
|
||||
fleetRuntimeAvailability: Object.freeze(fleetRuntimeAvailability),
|
||||
});
|
||||
}
|
||||
|
||||
export function assertFleetRuntimeAvailability(inspection: FleetRuntimeInspection): void {
|
||||
const checks: FleetRuntimePreflightCheck[] = [
|
||||
...inspection.fleetCliExecutable,
|
||||
...inspection.fleetRuntimeAvailability,
|
||||
];
|
||||
const failures = checks.filter(
|
||||
(check: FleetRuntimePreflightCheck): boolean => check.status !== 'ok',
|
||||
);
|
||||
if (failures.length > 0) throw new FleetRuntimePreflightError(failures);
|
||||
}
|
||||
|
||||
export function formatFleetRuntimePreflightError(
|
||||
checks: readonly FleetRuntimePreflightCheck[],
|
||||
): string {
|
||||
const lines = ['Fleet runtime preflight failed:'];
|
||||
for (const check of checks) {
|
||||
const dependency = check.dependency === undefined ? '' : ` dependency=${check.dependency}`;
|
||||
const probe = check.probeCommand === undefined ? '' : ` dependency_probe=${check.probeCommand}`;
|
||||
const execution =
|
||||
check.status === 'unexecutable'
|
||||
? ` probe_exit=${check.probeExit?.toString() ?? 'not-run'} ` +
|
||||
`probe_output=${JSON.stringify(check.probeOutput ?? '')}`
|
||||
: '';
|
||||
if (check.check === 'fleet-cli-executable') {
|
||||
lines.push(
|
||||
`check=${check.check} binary=${check.binary} ` +
|
||||
`requested_by=${check.requestedBy.join(',')} pane_path=${check.panePath}` +
|
||||
`${dependency}${probe}${execution} ` +
|
||||
'action=repair the Mosaic installation until its pane dependencies resolve',
|
||||
);
|
||||
continue;
|
||||
}
|
||||
lines.push(
|
||||
`check=${check.check} runtime=${check.runtime} ` +
|
||||
`requested_by=${check.requestedBy.join(',')} pane_path=${check.panePath}` +
|
||||
`${dependency}${probe}${execution} install_command=${check.installCommand}`,
|
||||
);
|
||||
}
|
||||
return lines.join('\n');
|
||||
}
|
||||
|
||||
async function resolveEffectiveAgents(
|
||||
options: FleetRuntimePreflightOptions,
|
||||
): Promise<readonly EffectiveAgent[]> {
|
||||
const agents: EffectiveAgent[] = [];
|
||||
for (const agent of options.agents) {
|
||||
if (!isRuntimeName(agent.runtime)) {
|
||||
throw new FleetRuntimeProbeError(`Unsupported fleet runtime: ${agent.runtime}`);
|
||||
}
|
||||
const runtimeBin =
|
||||
agent.runtimeBin ??
|
||||
(
|
||||
await readAgentLocalEnvironment({
|
||||
mosaicHome: options.mosaicHome,
|
||||
agentEnvDir: options.agentEnvDir,
|
||||
agentName: agent.name,
|
||||
})
|
||||
)['MOSAIC_RUNTIME_BIN'] ??
|
||||
'';
|
||||
agents.push({ name: agent.name, runtime: agent.runtime, runtimeBin });
|
||||
}
|
||||
return agents;
|
||||
}
|
||||
|
||||
function groupPaneRequests(agents: readonly EffectiveAgent[]): readonly PaneProbeGroup[] {
|
||||
const groups = new Map<string, PaneProbeGroup>();
|
||||
for (const agent of agents) {
|
||||
const current = groups.get(agent.runtimeBin);
|
||||
if (current === undefined) {
|
||||
groups.set(agent.runtimeBin, { runtimeBin: agent.runtimeBin, requestedBy: [agent.name] });
|
||||
} else {
|
||||
current.requestedBy.push(agent.name);
|
||||
}
|
||||
}
|
||||
return [...groups.values()].sort((left, right): number =>
|
||||
compareCodePoints(left.runtimeBin, right.runtimeBin),
|
||||
);
|
||||
}
|
||||
|
||||
function groupRuntimeRequests(agents: readonly EffectiveAgent[]): readonly RuntimeProbeGroup[] {
|
||||
const groups = new Map<string, RuntimeProbeGroup>();
|
||||
for (const agent of agents) {
|
||||
const key = JSON.stringify([agent.runtime, agent.runtimeBin]);
|
||||
const current = groups.get(key);
|
||||
if (current === undefined) {
|
||||
groups.set(key, {
|
||||
runtime: agent.runtime,
|
||||
runtimeBin: agent.runtimeBin,
|
||||
requestedBy: [agent.name],
|
||||
});
|
||||
} else {
|
||||
current.requestedBy.push(agent.name);
|
||||
}
|
||||
}
|
||||
return [...groups.values()].sort((left, right): number =>
|
||||
compareCodePoints(
|
||||
`${left.runtime}\u0000${left.runtimeBin}`,
|
||||
`${right.runtime}\u0000${right.runtimeBin}`,
|
||||
),
|
||||
);
|
||||
}
|
||||
|
||||
async function probeBinary(
|
||||
options: FleetRuntimePreflightOptions,
|
||||
probe: BinaryProbeRequest,
|
||||
): Promise<FleetExecutableEvidence> {
|
||||
const args = [
|
||||
'-i',
|
||||
`HOME=${process.env['HOME'] ?? homedir()}`,
|
||||
'PATH=/usr/bin:/bin',
|
||||
`MOSAIC_HOME=${options.mosaicHome}`,
|
||||
'/bin/bash',
|
||||
'--noprofile',
|
||||
'--norc',
|
||||
options.helperPath,
|
||||
'--mosaic-home',
|
||||
options.mosaicHome,
|
||||
'--binary',
|
||||
probe.binary,
|
||||
'--check-executable',
|
||||
];
|
||||
if (probe.runtimeBin !== '') args.push('--runtime-bin', probe.runtimeBin);
|
||||
if (options.systemPath !== undefined) args.push('--system-path', options.systemPath);
|
||||
|
||||
const result = await options.runner('/usr/bin/env', args);
|
||||
const fields = parseNulFields(result.stdout);
|
||||
const panePath = requiredField(fields, 'pane_path');
|
||||
const status = requiredField(fields, 'status');
|
||||
if (result.exitCode === 0 && status === 'present') {
|
||||
return executableEvidence('ok', panePath, fields);
|
||||
}
|
||||
if (result.exitCode === 69 && status === 'missing') {
|
||||
return { status: 'missing', panePath };
|
||||
}
|
||||
if (result.exitCode === 70 && status === 'unexecutable') {
|
||||
return executableEvidence('unexecutable', panePath, fields);
|
||||
}
|
||||
throw new FleetRuntimeProbeError(
|
||||
`Fleet executable probe failed: binary=${probe.binary} exit=${result.exitCode.toString()} ` +
|
||||
`stderr=${JSON.stringify(result.stderr.trim())}`,
|
||||
);
|
||||
}
|
||||
|
||||
function executableEvidence(
|
||||
status: 'ok' | 'unexecutable',
|
||||
panePath: string,
|
||||
fields: ReadonlyMap<string, string>,
|
||||
): FleetExecutableEvidence {
|
||||
const dependency = requiredField(fields, 'dependency');
|
||||
const probeCommand = requiredField(fields, 'probe_command');
|
||||
const probeExit = requiredField(fields, 'probe_exit');
|
||||
const probeOutput = requiredField(fields, 'probe_output');
|
||||
return {
|
||||
status,
|
||||
panePath,
|
||||
binaryPath: requiredField(fields, 'binary_path'),
|
||||
...(dependency === '' ? {} : { dependency }),
|
||||
...(probeCommand === '' ? {} : { probeCommand }),
|
||||
...(probeExit === '' ? {} : { probeExit: parseProbeExit(probeExit) }),
|
||||
...(probeOutput === '' ? {} : { probeOutput }),
|
||||
};
|
||||
}
|
||||
|
||||
function sortedRequestedBy(requestedBy: readonly string[]): readonly string[] {
|
||||
return Object.freeze(
|
||||
[...requestedBy].sort((left: string, right: string): number => compareCodePoints(left, right)),
|
||||
);
|
||||
}
|
||||
|
||||
function parseNulFields(source: string): ReadonlyMap<string, string> {
|
||||
const parts = source.split('\u0000');
|
||||
if (parts.at(-1) === '') parts.pop();
|
||||
if (parts.length % 2 !== 0) {
|
||||
throw new FleetRuntimeProbeError('Fleet runtime probe returned malformed field output.');
|
||||
}
|
||||
const fields = new Map<string, string>();
|
||||
for (let index = 0; index < parts.length; index += 2) {
|
||||
const key = parts[index];
|
||||
const value = parts[index + 1];
|
||||
if (key === undefined || value === undefined || key === '' || fields.has(key)) {
|
||||
throw new FleetRuntimeProbeError('Fleet runtime probe returned malformed field output.');
|
||||
}
|
||||
fields.set(key, value);
|
||||
}
|
||||
return fields;
|
||||
}
|
||||
|
||||
function requiredField(fields: ReadonlyMap<string, string>, key: string): string {
|
||||
const value = fields.get(key);
|
||||
if (value === undefined) {
|
||||
throw new FleetRuntimeProbeError(`Fleet runtime probe omitted ${key}.`);
|
||||
}
|
||||
return value;
|
||||
}
|
||||
|
||||
function parseProbeExit(value: string): number {
|
||||
const exitCode = Number(value);
|
||||
if (!Number.isSafeInteger(exitCode) || exitCode < 0) {
|
||||
throw new FleetRuntimeProbeError('Fleet runtime probe returned an invalid execution status.');
|
||||
}
|
||||
return exitCode;
|
||||
}
|
||||
|
||||
function isRuntimeName(value: string): value is RuntimeName {
|
||||
return RUNTIME_SET.has(value);
|
||||
}
|
||||
@@ -176,6 +176,52 @@ describe('generated fleet agent environment boundary', (): void => {
|
||||
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
||||
});
|
||||
|
||||
it('brain home: accepts and writes projections under MOSAIC_BRAIN_HOME/fleet/agents', async (): Promise<void> => {
|
||||
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
|
||||
try {
|
||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
||||
const mosaicHome = join(cleanup, 'config-home');
|
||||
const brainHome = join(cleanup, 'brain');
|
||||
const agentEnvDir = join(brainHome, 'fleet', 'agents');
|
||||
process.env['MOSAIC_BRAIN_HOME'] = brainHome;
|
||||
|
||||
const result = await writeAgentEnvironmentProjection({
|
||||
mosaicHome,
|
||||
agentEnvDir,
|
||||
agentName: 'coder0',
|
||||
generated: generatedValues,
|
||||
});
|
||||
|
||||
// Projection landed in the brain tree, not under the config home.
|
||||
expect(result.generatedPath).toBe(join(agentEnvDir, 'coder0.env.generated'));
|
||||
expect((await stat(join(brainHome, 'fleet'))).mode & 0o777).toBe(0o700);
|
||||
expect((await stat(agentEnvDir)).mode & 0o777).toBe(0o700);
|
||||
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
|
||||
await expect(stat(join(mosaicHome, 'fleet'))).rejects.toThrow();
|
||||
|
||||
// A config-home agentEnvDir is now REJECTED while the brain is active —
|
||||
// the boundary must not silently split state across two trees.
|
||||
let rejected: unknown;
|
||||
try {
|
||||
await writeAgentEnvironmentProjection({
|
||||
mosaicHome,
|
||||
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
|
||||
agentName: 'coder1',
|
||||
generated: { ...generatedValues, MOSAIC_AGENT_NAME: 'coder1' },
|
||||
});
|
||||
} catch (caught: unknown) {
|
||||
rejected = caught;
|
||||
}
|
||||
expect(rejected).toBeInstanceOf(AgentEnvBoundaryError);
|
||||
} finally {
|
||||
if (savedBrainHome === undefined) {
|
||||
delete process.env['MOSAIC_BRAIN_HOME'];
|
||||
} else {
|
||||
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
it('regenerates desired keys, relocates safe legacy local data, and quarantines forbidden legacy input', async (): Promise<void> => {
|
||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
|
||||
const mosaicHome = join(cleanup, 'mosaic');
|
||||
|
||||
@@ -2,6 +2,7 @@ import { createHash, randomUUID } from 'node:crypto';
|
||||
import { chmod, lstat, mkdir, readFile, rename, unlink, writeFile } from 'node:fs/promises';
|
||||
import { homedir } from 'node:os';
|
||||
import { dirname, join, resolve } from 'node:path';
|
||||
import { fleetAgentEnvDir, resolveBrainHome } from './brain-home.js';
|
||||
import { compareCodePoints } from './deterministic-order.js';
|
||||
|
||||
export type AgentEnvironmentKind = 'generated' | 'local';
|
||||
@@ -25,12 +26,6 @@ export interface AgentGeneratedProjectionDeletionOptions {
|
||||
readonly agentName: string;
|
||||
}
|
||||
|
||||
export interface AgentLocalEnvironmentReadOptions {
|
||||
readonly mosaicHome: string;
|
||||
readonly agentEnvDir: string;
|
||||
readonly agentName: string;
|
||||
}
|
||||
|
||||
export interface AgentEnvironmentProjectionResult {
|
||||
readonly generatedPath: string;
|
||||
readonly localPath: string;
|
||||
@@ -151,23 +146,6 @@ export function parseAgentEnvironment(
|
||||
return Object.freeze(values);
|
||||
}
|
||||
|
||||
/**
|
||||
* Reads one agent's optional local overrides through the same path, file-type,
|
||||
* permission, key, and value boundary used by projection/launch handling.
|
||||
*/
|
||||
export async function readAgentLocalEnvironment(
|
||||
options: AgentLocalEnvironmentReadOptions,
|
||||
): Promise<Readonly<Record<string, string>>> {
|
||||
if (!AGENT_NAME.test(options.agentName)) {
|
||||
throw new AgentEnvBoundaryError('unsafe-agent-name', 'MOSAIC_AGENT_NAME', options.agentName);
|
||||
}
|
||||
await validatePrivateProjectionDirectory(options.mosaicHome, options.agentEnvDir);
|
||||
const source = await readOptionalPrivateFile(
|
||||
join(options.agentEnvDir, `${options.agentName}.env.local`),
|
||||
);
|
||||
return source === undefined ? Object.freeze({}) : parseAgentEnvironment(source, 'local');
|
||||
}
|
||||
|
||||
/** Renders the roster-derived generated projection in a stable, complete key order. */
|
||||
export function renderGeneratedAgentEnvironment(values: Readonly<Record<string, string>>): string {
|
||||
const normalized = normalizeGeneratedValues(values);
|
||||
@@ -551,12 +529,15 @@ async function validatePrivateProjectionDirectory(
|
||||
mosaicHome: string,
|
||||
agentEnvDir: string,
|
||||
): Promise<void> {
|
||||
const fleetDir = join(mosaicHome, 'fleet');
|
||||
const expectedAgentEnvDir = join(fleetDir, 'agents');
|
||||
// Brain-home split (canon §2): seat envs live under the brain home's
|
||||
// fleet/agents when a brain is active; roster + templates stay config-home.
|
||||
const expectedAgentEnvDir = fleetAgentEnvDir(mosaicHome);
|
||||
if (resolve(agentEnvDir) !== resolve(expectedAgentEnvDir)) {
|
||||
throw new AgentEnvBoundaryError('unsafe-directory', '(directory)', agentEnvDir);
|
||||
}
|
||||
await assertManagedDirectoryIfPresent(mosaicHome, false);
|
||||
const stateHome = resolveBrainHome(mosaicHome);
|
||||
const fleetDir = join(stateHome, 'fleet');
|
||||
await assertManagedDirectoryIfPresent(stateHome, false);
|
||||
await assertManagedDirectoryIfPresent(fleetDir, false);
|
||||
await assertManagedDirectoryIfPresent(agentEnvDir, true);
|
||||
}
|
||||
@@ -566,8 +547,9 @@ async function ensurePrivateProjectionDirectory(
|
||||
agentEnvDir: string,
|
||||
): Promise<void> {
|
||||
await validatePrivateProjectionDirectory(mosaicHome, agentEnvDir);
|
||||
const fleetDir = join(mosaicHome, 'fleet');
|
||||
await ensureManagedDirectory(mosaicHome, false);
|
||||
const stateHome = resolveBrainHome(mosaicHome);
|
||||
const fleetDir = join(stateHome, 'fleet');
|
||||
await ensureManagedDirectory(stateHome, false);
|
||||
await ensureManagedDirectory(fleetDir, false);
|
||||
await ensureManagedDirectory(agentEnvDir, true);
|
||||
}
|
||||
|
||||
@@ -19,7 +19,7 @@ const RUNTIME_DEFS: Record<
|
||||
label: 'Claude Code',
|
||||
command: 'claude',
|
||||
versionFlag: '--version',
|
||||
installHint: 'curl -fsSL https://claude.ai/install.sh | bash',
|
||||
installHint: 'npm install -g @anthropic-ai/claude-code',
|
||||
},
|
||||
codex: {
|
||||
label: 'Codex',
|
||||
@@ -31,13 +31,13 @@ const RUNTIME_DEFS: Record<
|
||||
label: 'OpenCode',
|
||||
command: 'opencode',
|
||||
versionFlag: 'version',
|
||||
installHint: 'npm install -g opencode-ai',
|
||||
installHint: 'See https://opencode.ai for install instructions',
|
||||
},
|
||||
pi: {
|
||||
label: 'Pi',
|
||||
command: 'pi',
|
||||
versionFlag: '--version',
|
||||
installHint: 'npm install -g @earendil-works/pi-coding-agent',
|
||||
installHint: 'curl -fsSL https://pi.dev/install.sh | sh',
|
||||
},
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user