Compare commits

..
Author SHA1 Message Date
jarvis 758659ddf9 docs(ri-050): session log — reviews 173/174, rebases, merge plan
ci/woodpecker/pr/ci Pipeline was successful
2026-08-17 20:19:49 -05:00
jarvisandjason.woltje 59e2c46076 docs(ri-050): resume under daily jarvis/fargo handoff protocol (#1275)
ci/woodpecker/pr/ci Pipeline was canceled
2026-08-17 20:12:20 -05:00
fargoandjason.woltje 9b4fb6b548 docs(ri-050): RI-2-001 independent review recorded — APPROVED (#1275)
Review 172 on PR #1278 (head 99b8f6ea): forge suite 116/116 executed at
head, workspace typecheck 45/45, consumer sweep clean, digest gate
before==after. CI red on the PR is the lane-wide fleet-test failure only
and carries no information about the change (fred, log-content analysis).
Continuation by fargo (sb-it-1-dt) per Jason; identity incident and fred's
ruling recorded in the scratchpad. Wave 2 (RI-2-002 + RI-4-001) next.
2026-08-17 20:12:20 -05:00
jarvisandjason.woltje 23204978e1 docs(ri-050): continuation handoff — state, blocker, mechanics, next actions (#1275) 2026-08-17 20:12:20 -05:00
jarvisandjason.woltje bee24fbdd6 docs(ri-050): mark RI-1-001/RI-2-001 in-progress 2026-08-17 20:12:20 -05:00
jarvisandjason.woltje 7d620ea288 docs(ri-050): wave 1 in-progress; lane-unblock dependency noted (#1275) 2026-08-17 20:12:20 -05:00
jarvisandjason.woltje e1e70a9966 style(ri-050): prettier-format TASKS.md 2026-08-17 20:12:20 -05:00
jarvisandjason.woltje e2a9b1ca59 docs(ri-050): bootstrap release-integrity workstream for 0.0.50 (#1275)
- PRD section: normative requirements RI-N1..RI-N5 (decisions SDLC-D-034..038)
- docs/release-integrity/TASKS.md: 10-card DAG, pi-glm-5.3 execution note
- scratchpad: mode, constraints, budget

Executed by jarvis (dragon-lin) with local pi workers per Jason's directive.
2026-08-17 20:12:20 -05:00
23 changed files with 22 additions and 1407 deletions
+1 -24
View File
@@ -30,19 +30,6 @@ steps:
# the baked pnpm store. # the baked pnpm store.
- pnpm install --frozen-lockfile --prefer-offline - pnpm install --frozen-lockfile --prefer-offline
# ---------------------------------------------------------------------------
# The steps below (sanitization, upgrade-guard, typecheck, lint, format,
# test) are the COMPLETE mandatory verification set. SDLC-D-034 mirrors them
# one-for-one in the canonical terminal verification command — root
# `pnpm verify:release` (scripts/verify-release.mjs) — which the publish
# pipeline (.woodpecker/publish.yml `verify` step) runs before ANY publish
# effect. These lines stay direct (not routed through the runner) because the
# #1017 test-enumeration guard audits framework tool paths through THIS
# surface; scripts/verify-release.test.mjs enforces that the runner's stage
# table keeps matching these commands exactly, so the two cannot drift.
# ---------------------------------------------------------------------------
# Canonical verify:release stage `sanitization`.
# Blocking gate: public framework package must contain no operator-specific # Blocking gate: public framework package must contain no operator-specific
# personal data or private $HOME defaults. Runs early (no node_modules needed). # personal data or private $HOME defaults. Runs early (no node_modules needed).
sanitization: sanitization:
@@ -60,7 +47,6 @@ steps:
# with everything it guards; this direct line keeps one instrument running. # with everything it guards; this direct line keeps one instrument running.
- bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh - bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh
# Canonical verify:release stage `upgrade-guard`.
# Blocking gate (#791): a framework upgrade must never write or delete an # Blocking gate (#791): a framework upgrade must never write or delete an
# operator-owned path. The HARD GATE proves an unanticipated operator sentinel # operator-owned path. The HARD GATE proves an unanticipated operator sentinel
# survives a keep-mode reseed byte-identical (with rsync present AND absent — # survives a keep-mode reseed byte-identical (with rsync present AND absent —
@@ -82,8 +68,6 @@ steps:
- bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh - bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh
- bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh - bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh
# Canonical verify:release stage `typecheck` — the same `pnpm typecheck`
# invocation (which runs the checkout preflight first, then turbo).
typecheck: typecheck:
image: *node_image image: *node_image
commands: commands:
@@ -94,8 +78,7 @@ steps:
- sanitization - sanitization
- upgrade-guard - upgrade-guard
# lint, format, and test are independent — run in parallel after typecheck. # lint, format, and test are independent — run in parallel after typecheck
# Each runs exactly its canonical verify:release stage command.
lint: lint:
image: *node_image image: *node_image
commands: commands:
@@ -112,12 +95,6 @@ steps:
depends_on: depends_on:
- typecheck - typecheck
# Canonical verify:release stage `test` — the `pnpm test` line below is the
# shared command; everything else in this step is PIPELINE-LEVEL
# prerequisite the canonical command expects its caller to provide (SDLC-D-034):
# the ci-postgres service + pg_isready wait + db:migrate (postgres path),
# `apk add openssl`, and the pinned pi install. None of those can move into
# the runner (it must also work locally on the PGlite path with no database).
test: test:
image: *node_image image: *node_image
environment: environment:
-60
View File
@@ -1,19 +1,5 @@
# Build, publish npm packages, and push Docker images # Build, publish npm packages, and push Docker images
# Runs on main for stable publishes and on next for integration-line prereleases/images # Runs on main for stable publishes and on next for integration-line prereleases/images
#
# SDLC-D-034 publish gate: every publish effect (publish-npm, publish-next-npm,
# and every image build/push step) depends DIRECTLY on the `verify` step below.
# `verify` (a) asserts the provider's commit identity matches the actual
# checkout (CI_COMMIT_SHA == git rev-parse HEAD, fail closed on mismatch or
# emptiness) and (b) runs the canonical terminal verification command
# (`pnpm verify:release`), which mirrors the PR CI pipeline's complete
# mandatory set (sanitization, upgrade-guard, preflight+typecheck, lint,
# format:check, test, build) — see scripts/verify-release.mjs. A missing,
# failed, skipped, cancelled, or inconclusive verification therefore skips the
# dependent publish effects (fail closed). Path-filtered short-circuits may
# skip publish EFFECTS (e.g. docs-only merges) but never bypass `verify` for a
# publish that does run: `verify` itself carries no path filter.
# scripts/verify-release.test.mjs enforces this DAG invariant at checkout time.
variables: variables:
# Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine + # Pre-baked CI base (see .woodpecker/ci-image.yml): node:24-alpine +
@@ -62,45 +48,6 @@ steps:
# Resolve from the baked pnpm store instead of a cold network fetch. # Resolve from the baked pnpm store instead of a cold network fetch.
- pnpm install --frozen-lockfile --prefer-offline - pnpm install --frozen-lockfile --prefer-offline
# SDLC-D-034 exact-commit publish gate. No `when`/path filter on purpose: it
# runs for every event this pipeline serves so no publish effect can ever
# start without it. Fails closed on commit-identity mismatch (or either SHA
# being empty) and on any incomplete verification.
verify:
image: *node_image
commands:
- *enable_pnpm
# (a) Commit identity: the provider's claimed SHA must equal the actual
# checkout HEAD — verification of anything else must never authorize a
# publish of this commit.
- |
if [ -z "$CI_COMMIT_SHA" ]; then
echo "[verify] FATAL: CI_COMMIT_SHA is empty — cannot certify commit identity" >&2
exit 1
fi
CHECKOUT_SHA="$(git rev-parse HEAD 2>/dev/null || true)"
if [ -z "$CHECKOUT_SHA" ]; then
echo "[verify] FATAL: git rev-parse HEAD returned nothing — cannot certify commit identity" >&2
exit 1
fi
if [ "$CI_COMMIT_SHA" != "$CHECKOUT_SHA" ]; then
echo "[verify] FATAL: provider commit ($CI_COMMIT_SHA) != checkout HEAD ($CHECKOUT_SHA)" >&2
exit 1
fi
echo "[verify] commit identity confirmed: $CHECKOUT_SHA"
# (b) Canonical terminal verification. Caller-provided prerequisites the
# runner expects (see .woodpecker/ci.yml comments): bash/rsync for the
# guard stages, openssl + the pinned pi binary for the test stage. git is
# baked into ci-base but re-asserted here so the identity check above can
# never silently depend on a stale baked image. DATABASE_URL is
# deliberately NOT set: the canonical command must hold on the PGlite
# path too and never sets or requires a database itself.
- apk add --no-cache bash rsync openssl git
- npm install -g @earendil-works/[email protected]
- pnpm verify:release
depends_on:
- install
build: build:
image: *node_image image: *node_image
commands: commands:
@@ -108,7 +55,6 @@ steps:
- pnpm build - pnpm build
depends_on: depends_on:
- install - install
- verify
publish-npm: publish-npm:
image: *node_image image: *node_image
@@ -168,7 +114,6 @@ steps:
exit 1 exit 1
depends_on: depends_on:
- build - build
- verify
publish-next-npm: publish-next-npm:
image: *node_image image: *node_image
@@ -247,7 +192,6 @@ steps:
echo "[publish-next] @mosaicstack/mosaic@next resolves to $RESOLVED_VERSION" echo "[publish-next] @mosaicstack/mosaic@next resolves to $RESOLVED_VERSION"
depends_on: depends_on:
- build - build
- verify
# TODO: Uncomment when ready to publish to npmjs.org # TODO: Uncomment when ready to publish to npmjs.org
# publish-npmjs: # publish-npmjs:
@@ -261,7 +205,6 @@ steps:
# - bash scripts/publish-npmjs.sh # - bash scripts/publish-npmjs.sh
# depends_on: # depends_on:
# - build # - build
# - verify
# when: # when:
# - event: [tag] # - event: [tag]
@@ -299,7 +242,6 @@ steps:
/kaniko/executor --context . --dockerfile docker/gateway.Dockerfile $DESTINATIONS /kaniko/executor --context . --dockerfile docker/gateway.Dockerfile $DESTINATIONS
depends_on: depends_on:
- build - build
- verify
build-appservice: build-appservice:
image: gcr.io/kaniko-project/executor:debug image: gcr.io/kaniko-project/executor:debug
@@ -326,7 +268,6 @@ steps:
/kaniko/executor --context . --dockerfile docker/appservice.Dockerfile $DESTINATIONS /kaniko/executor --context . --dockerfile docker/appservice.Dockerfile $DESTINATIONS
depends_on: depends_on:
- build - build
- verify
build-web: build-web:
image: gcr.io/kaniko-project/executor:debug image: gcr.io/kaniko-project/executor:debug
@@ -353,4 +294,3 @@ steps:
/kaniko/executor --context . --dockerfile docker/web.Dockerfile $DESTINATIONS /kaniko/executor --context . --dockerfile docker/web.Dockerfile $DESTINATIONS
depends_on: depends_on:
- build - build
- verify
-1
View File
@@ -9,7 +9,6 @@
"preflight": "node scripts/preflight.mjs", "preflight": "node scripts/preflight.mjs",
"clean:generated": "node scripts/clean-generated.mjs", "clean:generated": "node scripts/clean-generated.mjs",
"typecheck": "pnpm preflight && turbo run typecheck", "typecheck": "pnpm preflight && turbo run typecheck",
"verify:release": "node scripts/verify-release.mjs",
"test:checkout": "node --test scripts/*.test.mjs", "test:checkout": "node --test scripts/*.test.mjs",
"test": "pnpm test:checkout && turbo run test && pnpm run test:installer", "test": "pnpm test:checkout && turbo run test && pnpm run test:installer",
"test:installer": "bash tools/install-next-lane.test.sh", "test:installer": "bash tools/install-next-lane.test.sh",
-27
View File
@@ -12,33 +12,6 @@ The default tmux socket is `mosaic-fleet` so fleet commands do not touch the
default tmux server. The roster is the desired-state authority; generated environment files are default tmux server. The roster is the desired-state authority; generated environment files are
rebuildable projections, never a second source of configuration. rebuildable projections, never a second source of configuration.
## Brain-home split (fleet state vs framework templates)
When a mosaic-brain clone is present, fleet **state** resolves from the brain
home while framework templates and dispatch state stay in the config home
(three-tree model, canon `docs/STRUCTURE-CANON.md` §2):
| Path | Without brain (legacy) | With brain |
| ------------------------------------------------------------------------------- | ------------------------------------- | ------------------------------ |
| `fleet/agents/<seat>.env.*` | `~/.config/mosaic/fleet/agents/` | `~/.mosaic/fleet/agents/` |
| `fleet/roles.local/` (overrides) | `~/.config/mosaic/fleet/roles.local/` | `~/.mosaic/fleet/roles.local/` |
| `fleet/profiles/` (working copies) | `~/.config/mosaic/fleet/profiles/` | `~/.mosaic/fleet/profiles/` |
| `fleet/roster.yaml`, `fleet/roles/` (baseline), `fleet/run/`, `fleet/services/` | `~/.config/mosaic/fleet/…` | unchanged (config home) |
Activation (`packages/mosaic/src/fleet/brain-home.ts`, mirrored in
`tools/fleet/start-agent-session.sh`):
1. `MOSAIC_BRAIN_HOME` env var — explicit, always wins.
2. Canonical `~/.mosaic` — adopted only when `MOSAIC_HOME` is the default
`~/.config/mosaic` AND `~/.mosaic/fleet/agents` exists. Custom
`--mosaic-home` values (tests, sandboxes, canaries) never adopt, keeping
them hermetic.
3. Otherwise the config home (legacy single-tree behavior).
Seat env dirs under a brain are subject to the same privacy boundary (0700
dirs, 0600 files); `.env.generated` files are structure-valuable and tracked
in the brain repo, hand-maintained `.env`/`.env.local` stay ignored and private.
## Examples ## Examples
- `examples/minimal.yaml` starts one local canary slot. - `examples/minimal.yaml` starts one local canary slot.
@@ -80,26 +80,6 @@ safe_path "$MOSAIC_HOME" || fail_env unsafe-path MOSAIC_HOME "$MOSAIC_HOME"
FLEET_DIR="$MOSAIC_HOME/fleet" FLEET_DIR="$MOSAIC_HOME/fleet"
AGENT_ENV_DIR="$FLEET_DIR/agents" AGENT_ENV_DIR="$FLEET_DIR/agents"
# Brain-home split (canon docs/STRUCTURE-CANON.md §2): seat launch envs live
# under the brain home's fleet/agents when a brain is active; roster, roles
# baseline, and runtime state (fleet/run) stay under MOSAIC_HOME.
# Resolution mirrors packages/mosaic/src/fleet/brain-home.ts:
# 1. MOSAIC_BRAIN_HOME env (explicit, always wins)
# 2. ~/.mosaic — adopted only when MOSAIC_HOME is the default config home AND
# ~/.mosaic/fleet/agents exists
# 3. MOSAIC_HOME (legacy single-tree)
BRAIN_HOME="${MOSAIC_BRAIN_HOME:-}"
if [ -z "$BRAIN_HOME" ]; then
BRAIN_HOME="$MOSAIC_HOME"
if [ "$(cd "$MOSAIC_HOME" 2>/dev/null && pwd -P)" = "$HOME/.config/mosaic" ] \
&& [ -d "$HOME/.mosaic/fleet/agents" ]; then
BRAIN_HOME="$HOME/.mosaic"
fi
fi
if [ "$BRAIN_HOME" != "$MOSAIC_HOME" ]; then
AGENT_ENV_DIR="$BRAIN_HOME/fleet/agents"
fi
assert_managed_directory "$MOSAIC_HOME" assert_managed_directory "$MOSAIC_HOME"
assert_managed_directory "$FLEET_DIR" assert_managed_directory "$FLEET_DIR"
assert_private_directory "$AGENT_ENV_DIR" assert_private_directory "$AGENT_ENV_DIR"
@@ -167,54 +167,6 @@ if echo "$valid_args" | grep -qF 'bash -c'; then
fail "launcher constructed a shell command payload" fail "launcher constructed a shell command payload"
fi fi
# ── Brain-home split (canon §2) ─────────────────────────────────────────
# When MOSAIC_HOME is the default config home under $HOME and the host carries
# $HOME/.mosaic/fleet/agents, seat envs resolve from the brain tree; the config
# home still owns fleet/run (holder-owner) and remains a managed boundary.
: > "$TMUX_CALLS"
HOME_BRAIN="$ROOT/brain-home"
CONFIG_HOME="$HOME_BRAIN/.config/mosaic"
BRAIN="$HOME_BRAIN/.mosaic"
mkdir -p "$CONFIG_HOME/fleet/run" "$BRAIN/fleet/agents" "$HOME_BRAIN/work"
chmod 700 "$CONFIG_HOME" "$CONFIG_HOME/fleet" "$CONFIG_HOME/fleet/run" \
"$BRAIN/fleet/agents" "$HOME_BRAIN/work"
printf '123e4567-e89b-12d3-a456-426614174000\n' > "$CONFIG_HOME/fleet/run/holder-owner"
chmod 600 "$CONFIG_HOME/fleet/run/holder-owner"
cat > "$BRAIN/fleet/agents/coder-brain.env.generated" <<EOF
MOSAIC_AGENT_NAME=coder-brain
MOSAIC_AGENT_CLASS=code
MOSAIC_AGENT_RUNTIME=pi
MOSAIC_AGENT_MODEL=openai-codex/gpt-5.6-sol
MOSAIC_AGENT_REASONING=high
MOSAIC_AGENT_TOOL_POLICY=code
MOSAIC_AGENT_WORKDIR=$HOME_BRAIN/work
MOSAIC_TMUX_SOCKET=mosaic-test
EOF
chmod 600 "$BRAIN/fleet/agents/coder-brain.env.generated"
install_pane_binaries "$HOME_BRAIN"
HOME="$HOME_BRAIN" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
MOSAIC_TEST_PANE_PID=$$ MOSAIC_TEST_HOME="$HOME_BRAIN" \
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
MOSAIC_HOME="$CONFIG_HOME" "$START" coder-brain
brain_args=$(tr '\0' '\n' < "$TMUX_CALLS")
echo "$brain_args" | grep -qF new-session || fail "brain-home generated projection did not reach tmux"
echo "$brain_args" | grep -qF 'coder-brain' || fail "brain-home agent env was not the launch source"
[ -f "$BRAIN/fleet/agents/coder-brain.env.generated" ] || fail "brain generated env vanished"
# Negative control: the SAME default-config-home shape but without
# ~/.mosaic/fleet/agents — the config-home env tree is used directly (legacy).
: > "$TMUX_CALLS"
HOME_NOBRAIN="$ROOT/brainless-home"
CONFIG_HOME_NOBRAIN="$HOME_NOBRAIN/.config/mosaic"
write_generated "$CONFIG_HOME_NOBRAIN" "coder-legacy"
install_pane_binaries "$HOME_NOBRAIN"
HOME="$HOME_NOBRAIN" PATH="$FAKE_BIN:$PATH" MOSAIC_TEST_TMUX_CALLS="$TMUX_CALLS" \
MOSAIC_TEST_PANE_PID=$$ MOSAIC_TEST_HOME="$HOME_NOBRAIN" \
MOSAIC_TEST_FLEET_OWNER=123e4567-e89b-12d3-a456-426614174000 \
MOSAIC_HOME="$CONFIG_HOME_NOBRAIN" "$START" coder-legacy
legacy_args=$(tr '\0' '\n' < "$TMUX_CALLS")
echo "$legacy_args" | grep -qF new-session || fail "legacy single-tree launch regressed"
# The pane must start through an absolute clean-environment boundary. Its # The pane must start through an absolute clean-environment boundary. Its
# runtime command remains an argv vector, but no holder/session environment # runtime command remains an argv vector, but no holder/session environment
# control variable can pass through the pane command. # control variable can pass through the pane command.
@@ -1,6 +1,5 @@
import { readFile } from 'node:fs/promises'; import { readFile } from 'node:fs/promises';
import { join, resolve } from 'node:path'; import { join, resolve } from 'node:path';
import { fleetAgentEnvDir, fleetRolesLocalDir } from '../fleet/brain-home.js';
import type { Command } from 'commander'; import type { Command } from 'commander';
import { import {
executeFleetAgentMutation, executeFleetAgentMutation,
@@ -150,9 +149,9 @@ async function executeCommand(
request, request,
mosaicHome, mosaicHome,
rosterPath, rosterPath,
agentEnvDir: fleetAgentEnvDir(mosaicHome), agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
rolesDir: join(mosaicHome, 'fleet', 'roles'), rolesDir: join(mosaicHome, 'fleet', 'roles'),
overrideDir: fleetRolesLocalDir(mosaicHome), overrideDir: join(mosaicHome, 'fleet', 'roles.local'),
dryRun: forceDryRun || opts.dryRun === true, dryRun: forceDryRun || opts.dryRun === true,
...(deps.projectionApplier === undefined ? {} : { projectionApplier: deps.projectionApplier }), ...(deps.projectionApplier === undefined ? {} : { projectionApplier: deps.projectionApplier }),
}); });
@@ -1,6 +1,5 @@
import { readFile } from 'node:fs/promises'; import { readFile } from 'node:fs/promises';
import { join } from 'node:path'; import { join } from 'node:path';
import { fleetAgentEnvDir, fleetRolesLocalDir } from '../fleet/brain-home.js';
import type { Command } from 'commander'; import type { Command } from 'commander';
import { import {
parseV1MigrationObservations, parseV1MigrationObservations,
@@ -121,11 +120,11 @@ export function registerFleetMigrationCommand(
observations, observations,
personaDirs: { personaDirs: {
rolesDir: deps.rolesDir ?? join(mosaicHome, 'fleet', 'roles'), rolesDir: deps.rolesDir ?? join(mosaicHome, 'fleet', 'roles'),
overrideDir: deps.overrideDir ?? fleetRolesLocalDir(mosaicHome), overrideDir: deps.overrideDir ?? join(mosaicHome, 'fleet', 'roles.local'),
}, },
environment: { environment: {
mosaicHome, mosaicHome,
agentEnvDir: fleetAgentEnvDir(mosaicHome), agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
}, },
}); });
printJson(preview); printJson(preview);
@@ -30,21 +30,19 @@ import { lstat, readFile, readdir, stat } from 'node:fs/promises';
import { homedir } from 'node:os'; import { homedir } from 'node:os';
import { basename, isAbsolute, join, sep } from 'node:path'; import { basename, isAbsolute, join, sep } from 'node:path';
import type { Command } from 'commander'; import type { Command } from 'commander';
import { fleetRolesLocalDir } from '../fleet/brain-home.js';
function defaultMosaicHome(): string { function defaultMosaicHome(): string {
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic'); return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
} }
/** Baseline persona role contracts (reseeded on update; config home — framework). */ /** Baseline persona role contracts (reseeded on update). */
export function defaultRolesDir(mosaicHome = defaultMosaicHome()): string { export function defaultRolesDir(mosaicHome = defaultMosaicHome()): string {
return join(mosaicHome, 'fleet', 'roles'); return join(mosaicHome, 'fleet', 'roles');
} }
/** PRESERVE-protected override layer (survives update; wins on merge). /** PRESERVE-protected override layer (survives update; wins on merge). */
* Brain home (`~/.mosaic/fleet/roles.local`) when a brain is active. */
export function defaultOverrideDir(mosaicHome = defaultMosaicHome()): string { export function defaultOverrideDir(mosaicHome = defaultMosaicHome()): string {
return fleetRolesLocalDir(mosaicHome); return join(mosaicHome, 'fleet', 'roles.local');
} }
/** /**
@@ -25,7 +25,6 @@ import { homedir } from 'node:os';
import { basename, join } from 'node:path'; import { basename, join } from 'node:path';
import type { Command } from 'commander'; import type { Command } from 'commander';
import YAML from 'yaml'; import YAML from 'yaml';
import { fleetProfilesDir } from '../fleet/brain-home.js';
import { import {
defaultOverrideDir, defaultOverrideDir,
extractClassesFromDir, extractClassesFromDir,
@@ -37,10 +36,9 @@ function defaultMosaicHome(): string {
return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic'); return process.env['MOSAIC_HOME'] ?? join(homedir(), '.config', 'mosaic');
} }
/** Directory holding the seeded profile yaml files — brain home when active /** Directory holding the seeded profile yaml files. */
* (user working copies, committed), else the config home seed. */
export function defaultProfilesDir(mosaicHome = defaultMosaicHome()): string { export function defaultProfilesDir(mosaicHome = defaultMosaicHome()): string {
return fleetProfilesDir(mosaicHome); return join(mosaicHome, 'fleet', 'profiles');
} }
/** Directory holding the persona role contracts. */ /** Directory holding the persona role contracts. */
@@ -3,7 +3,6 @@ import { homedir } from 'node:os';
import { join, relative, resolve } from 'node:path'; import { join, relative, resolve } from 'node:path';
import type { Command } from 'commander'; import type { Command } from 'commander';
import type { CommandRunner } from './fleet.js'; import type { CommandRunner } from './fleet.js';
import { fleetAgentEnvDir } from '../fleet/brain-home.js';
import { import {
applyPreparedGeneratedAgentEnvironmentProjection, applyPreparedGeneratedAgentEnvironmentProjection,
prepareGeneratedAgentEnvironmentProjection, prepareGeneratedAgentEnvironmentProjection,
@@ -154,7 +153,7 @@ export async function executeFleetRegen(
options: FleetRegenOptions, options: FleetRegenOptions,
): Promise<FleetRegenResult> { ): Promise<FleetRegenResult> {
const mosaicHome = defaultMosaicHome(deps); const mosaicHome = defaultMosaicHome(deps);
const agentEnvDir = fleetAgentEnvDir(mosaicHome); const agentEnvDir = join(mosaicHome, 'fleet', 'agents');
const rosterPath = join(mosaicHome, 'fleet', 'roster.yaml'); const rosterPath = join(mosaicHome, 'fleet', 'roster.yaml');
const readRoster = deps.readRoster ?? defaultReadRoster(deps, mosaicHome); const readRoster = deps.readRoster ?? defaultReadRoster(deps, mosaicHome);
const prepare = deps.prepareProjection ?? prepareGeneratedAgentEnvironmentProjection; const prepare = deps.prepareProjection ?? prepareGeneratedAgentEnvironmentProjection;
+1 -2
View File
@@ -13,7 +13,6 @@ import {
import { randomUUID } from 'node:crypto'; import { randomUUID } from 'node:crypto';
import { homedir, hostname, userInfo } from 'node:os'; import { homedir, hostname, userInfo } from 'node:os';
import { dirname, join, resolve } from 'node:path'; import { dirname, join, resolve } from 'node:path';
import { fleetAgentEnvDir } from '../fleet/brain-home.js';
import { fileURLToPath } from 'node:url'; import { fileURLToPath } from 'node:url';
import { spawn } from 'node:child_process'; import { spawn } from 'node:child_process';
import * as readline from 'node:readline'; import * as readline from 'node:readline';
@@ -159,7 +158,7 @@ export function resolveFleetPaths(mosaicHome = defaultMosaicHome()): FleetPaths
fleetToolsDir: join(mosaicHome, 'tools', 'fleet'), fleetToolsDir: join(mosaicHome, 'tools', 'fleet'),
tmuxToolsDir: join(mosaicHome, 'tools', 'tmux'), tmuxToolsDir: join(mosaicHome, 'tools', 'tmux'),
systemdUserDir: join(homedir(), '.config', 'systemd', 'user'), systemdUserDir: join(homedir(), '.config', 'systemd', 'user'),
agentEnvDir: fleetAgentEnvDir(mosaicHome), agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
}; };
} }
@@ -349,90 +349,3 @@ describe('registerRuntimeLaunchers — claudex (EXPERIMENTAL overlay)', () => {
expect(mockExit).not.toHaveBeenCalled(); expect(mockExit).not.toHaveBeenCalled();
}); });
}); });
// ─── Seat harness homes (MOSAIC-D-002, brain-home split) ────────────────────
import { activeSeatDir, seatPersonaOverlay } from './launch.js';
describe('activeSeatDir — per-agent harness home resolution', () => {
let root: string;
const savedAgentName = process.env['MOSAIC_AGENT_NAME'];
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
beforeEach(() => {
root = mkdtempSync(join(tmpdir(), 'mosaic-seat-home-'));
delete process.env['MOSAIC_BRAIN_HOME'];
});
afterEach(() => {
rmSync(root, { recursive: true, force: true });
if (savedAgentName === undefined) {
delete process.env['MOSAIC_AGENT_NAME'];
} else {
process.env['MOSAIC_AGENT_NAME'] = savedAgentName;
}
if (savedBrainHome !== undefined) {
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
} else {
delete process.env['MOSAIC_BRAIN_HOME'];
}
});
it('resolves the seat dir when MOSAIC_BRAIN_HOME carries the seat', () => {
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
mkdirSync(seat, { recursive: true });
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBe(seat);
});
it('returns undefined without an agent name (bare launches stay shared)', () => {
delete process.env['MOSAIC_AGENT_NAME'];
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
});
it('returns undefined when the seat dir does not exist in the brain', () => {
process.env['MOSAIC_AGENT_NAME'] = 'ghost';
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
mkdirSync(join(root, 'brain', 'fleet', 'agents'), { recursive: true });
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
});
it.each(['../escape', 'a/b', '.hidden-start', '', 'spaced name'])(
'rejects unsafe agent name %j (path traversal cannot leave the seat store)',
(name: string) => {
process.env['MOSAIC_AGENT_NAME'] = name;
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
expect(activeSeatDir(join(root, 'config', 'mosaic'))).toBeUndefined();
},
);
it('seatPersonaOverlay renders the seat SOUL.md as an overlay block', () => {
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
mkdirSync(seat, { recursive: true });
writeFileSync(join(seat, 'SOUL.md'), '# coder0 — code seat persona\n\nShips tested code.\n');
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
const overlay = seatPersonaOverlay(join(root, 'config', 'mosaic'));
expect(overlay).toContain('## Seat Persona');
expect(overlay).toContain('coder0 — code seat persona');
});
it('seatPersonaOverlay is empty when the seat carries no SOUL.md', () => {
const seat = join(root, 'brain', 'fleet', 'agents', 'coder0');
mkdirSync(seat, { recursive: true });
process.env['MOSAIC_AGENT_NAME'] = 'coder0';
process.env['MOSAIC_BRAIN_HOME'] = join(root, 'brain');
expect(seatPersonaOverlay(join(root, 'config', 'mosaic'))).toBe('');
});
it('seatPersonaOverlay is empty when no agent name is set', () => {
delete process.env['MOSAIC_AGENT_NAME'];
expect(seatPersonaOverlay(join(root, 'config', 'mosaic'))).toBe('');
});
});
+4 -49
View File
@@ -19,7 +19,7 @@ import {
import { createHash, randomBytes } from 'node:crypto'; import { createHash, randomBytes } from 'node:crypto';
import { createRequire } from 'node:module'; import { createRequire } from 'node:module';
import { homedir, hostname } from 'node:os'; import { homedir, hostname } from 'node:os';
import { join, dirname, resolve } from 'node:path'; import { join, dirname } from 'node:path';
import type { Command } from 'commander'; import type { Command } from 'commander';
import { import {
buildResolvedFleetCommsBlock, buildResolvedFleetCommsBlock,
@@ -29,7 +29,6 @@ import {
import { readRegularFileSecure } from '../fleet/secure-file.js'; import { readRegularFileSecure } from '../fleet/secure-file.js';
import { readPersonaContractBlock } from '../fleet/persona-contract.js'; import { readPersonaContractBlock } from '../fleet/persona-contract.js';
import { canonicalizeRoleClass } from './fleet-personas.js'; import { canonicalizeRoleClass } from './fleet-personas.js';
import { resolveBrainHome } from '../fleet/brain-home.js';
import { launchClaudex, type ClaudexHarnessAdapter } from './claudex.js'; import { launchClaudex, type ClaudexHarnessAdapter } from './claudex.js';
import { runLeaseEnforcementDoctorCheck } from './lease-doctor-check.js'; import { runLeaseEnforcementDoctorCheck } from './lease-doctor-check.js';
@@ -65,46 +64,9 @@ const HARNESS_HOME_ENV: Record<RuntimeName, string> = {
opencode: 'XDG_CONFIG_HOME', opencode: 'XDG_CONFIG_HOME',
}; };
/** Dedicated mosaic-owned home for a runtime: ~/.config/mosaic/.<runtime>. /** Dedicated mosaic-owned home for a runtime: ~/.config/mosaic/.<runtime> */
* With an active brain seat (MOSAIC_AGENT_NAME + seat dir in the brain home) function harnessHome(runtime: RuntimeName): string {
* the home is per-agent instead: <brainHome>/fleet/agents/<seat>/.<runtime> — return join(MOSAIC_HOME, `.${runtime}`);
* per-agent sessions, settings, and auth inside the seat dir (canon §2,
* MOSAIC-D-002). Seat runtime dirs are dot-named so the brain's ignore policy
* (per-seat .pi/.claude/.codex dirs) keeps credential material untracked. */
const SEAT_AGENT_NAME_RE = /^[a-zA-Z0-9][a-zA-Z0-9._-]*$/;
export function activeSeatDir(mosaicHome: string = MOSAIC_HOME): string | undefined {
const agent = process.env['MOSAIC_AGENT_NAME']?.trim();
if (
agent === undefined ||
agent === '' ||
!SEAT_AGENT_NAME_RE.test(agent) ||
agent.includes('..')
) {
return undefined;
}
const brain = resolveBrainHome(mosaicHome);
if (resolve(brain) === resolve(mosaicHome)) return undefined; // no brain
const seat = join(brain, 'fleet', 'agents', agent);
return existsSync(seat) ? seat : undefined;
}
function harnessHome(runtime: RuntimeName, mosaicHome: string = MOSAIC_HOME): string {
const seat = activeSeatDir(mosaicHome);
if (seat !== undefined) return join(seat, `.${runtime}`);
return join(mosaicHome, `.${runtime}`);
}
/** Seat persona block: with an active brain seat, <seat>/SOUL.md layers
* persona on the root generic base (canon invariant; MOSAIC-D-002). The base
* SOUL stays load-on-demand — only the seat delta is injected by value.
* Empty string when no seat is active or the seat carries no SOUL.md. */
export function seatPersonaOverlay(mosaicHome: string = MOSAIC_HOME): string {
const seatDir = activeSeatDir(mosaicHome);
if (seatDir === undefined) return '';
const seatSoul = readOptional(join(seatDir, 'SOUL.md'));
if (!seatSoul.trim()) return '';
return '## Seat Persona\n\n' + seatSoul.trim();
} }
/** /**
@@ -220,8 +182,6 @@ function recordLaunch(runtime: RuntimeName, cliArgs: string[], yolo: boolean): v
cli_version: CLI_VERSION, cli_version: CLI_VERSION,
config_home: harnessHome(runtime), config_home: harnessHome(runtime),
config_home_isolated: true, config_home_isolated: true,
config_home_kind: activeSeatDir() !== undefined ? 'seat' : 'runtime-shared',
agent_name: process.env['MOSAIC_AGENT_NAME']?.trim() || null,
config_home_env: HARNESS_HOME_ENV[runtime] ?? null, config_home_env: HARNESS_HOME_ENV[runtime] ?? null,
argv: redactArgv(cliArgs), argv: redactArgv(cliArgs),
normative_fragments: normativeFragmentDigests(runtime), normative_fragments: normativeFragmentDigests(runtime),
@@ -609,11 +569,6 @@ For required push/merge/issue-close/release actions, execute without routine con
if (soulLocal.trim()) { if (soulLocal.trim()) {
overlayBlocks.push('## Persona Overlay (SOUL.local.md)\n\n' + soulLocal.trim()); overlayBlocks.push('## Persona Overlay (SOUL.local.md)\n\n' + soulLocal.trim());
} }
// Seat persona (MOSAIC-D-002): per-seat SOUL.md layers on the generic base.
const seatPersona = seatPersonaOverlay(mosaicHome);
if (seatPersona !== '') {
overlayBlocks.push(seatPersona);
}
const standardsLocal = readOptional(join(mosaicHome, 'STANDARDS.local.md')); const standardsLocal = readOptional(join(mosaicHome, 'STANDARDS.local.md'));
if (standardsLocal.trim()) { if (standardsLocal.trim()) {
overlayBlocks.push('## Standards Overlay (STANDARDS.local.md)\n\n' + standardsLocal.trim()); overlayBlocks.push('## Standards Overlay (STANDARDS.local.md)\n\n' + standardsLocal.trim());
@@ -1,114 +0,0 @@
import { mkdir, mkdtemp, rm } from 'node:fs/promises';
import { homedir, tmpdir } from 'node:os';
import { join } from 'node:path';
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
import {
brainHomeIsActive,
fleetAgentEnvDir,
fleetProfilesDir,
fleetRolesLocalDir,
fleetStateDir,
resolveBrainHome,
type BrainHomeOptions,
} from './brain-home.js';
describe('fleet brain-home resolution', (): void => {
let cleanup: string | undefined;
const savedBrainEnv = process.env['MOSAIC_BRAIN_HOME'];
beforeEach((): void => {
delete process.env['MOSAIC_BRAIN_HOME'];
});
afterEach(async (): Promise<void> => {
if (savedBrainEnv === undefined) {
delete process.env['MOSAIC_BRAIN_HOME'];
} else {
process.env['MOSAIC_BRAIN_HOME'] = savedBrainEnv;
}
if (cleanup !== undefined) {
await rm(cleanup, { recursive: true, force: true });
cleanup = undefined;
}
});
async function makeTmp(): Promise<string> {
const root = await mkdtemp(join(tmpdir(), 'mosaic-brain-home-'));
cleanup = root;
return root;
}
it('MOSAIC_BRAIN_HOME env wins over every other signal', (): void => {
process.env['MOSAIC_BRAIN_HOME'] = '/explicit/brain';
expect(resolveBrainHome('/any/mosaic-home')).toBe('/explicit/brain');
expect(fleetAgentEnvDir('/any/mosaic-home')).toBe('/explicit/brain/fleet/agents');
expect(brainHomeIsActive('/any/mosaic-home')).toBe(true);
});
it('injected envBrainHome wins identically (test seam)', (): void => {
const opts: BrainHomeOptions = { envBrainHome: '/injected/brain' };
expect(resolveBrainHome('/any/mosaic-home', opts)).toBe('/injected/brain');
expect(fleetAgentEnvDir('/any/mosaic-home', opts)).toBe('/injected/brain/fleet/agents');
});
it('a non-default mosaicHome never adopts the canonical brain (hermetic legacy)', (): void => {
const mosaicHome = '/tmp/not-the-default-config-home';
expect(resolveBrainHome(mosaicHome)).toBe(mosaicHome);
expect(brainHomeIsActive(mosaicHome)).toBe(false);
expect(fleetAgentEnvDir(mosaicHome)).toBe(join(mosaicHome, 'fleet', 'agents'));
});
it('the default config home adopts the brain when it carries fleet/agents', async (): Promise<void> => {
const root = await makeTmp();
const brain = join(root, 'brain');
await mkdir(join(brain, 'fleet', 'agents'), { recursive: true });
const configHome = join(root, 'config', 'mosaic');
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
expect(resolveBrainHome(configHome, opts)).toBe(brain);
expect(fleetAgentEnvDir(configHome, opts)).toBe(join(brain, 'fleet', 'agents'));
expect(fleetRolesLocalDir(configHome, opts)).toBe(join(brain, 'fleet', 'roles.local'));
expect(fleetProfilesDir(configHome, opts)).toBe(join(brain, 'fleet', 'profiles'));
expect(fleetStateDir(configHome, opts)).toBe(join(brain, 'fleet'));
expect(brainHomeIsActive(configHome, opts)).toBe(true);
});
it('the default config home stays legacy when no brain exists', async (): Promise<void> => {
const root = await makeTmp();
const configHome = join(root, 'config', 'mosaic');
const opts: BrainHomeOptions = {
homes: { brain: join(root, 'brain'), configDefault: configHome },
};
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
expect(brainHomeIsActive(configHome, opts)).toBe(false);
});
it('an empty MOSAIC_BRAIN_HOME is ignored, not treated as set', (): void => {
process.env['MOSAIC_BRAIN_HOME'] = ' ';
expect(resolveBrainHome('/tmp/legacy-home')).toBe('/tmp/legacy-home');
});
it('adoption requires fleet/agents specifically, not any brain content', async (): Promise<void> => {
const root = await makeTmp();
const brain = join(root, 'brain');
await mkdir(join(brain, 'fleet'), { recursive: true }); // fleet without agents
const configHome = join(root, 'config', 'mosaic');
const opts: BrainHomeOptions = { homes: { brain, configDefault: configHome } };
expect(resolveBrainHome(configHome, opts)).toBe(configHome);
});
it('real-home control: a host brain is adopted only through the default home', (): void => {
// Control on the un-injected path: this host carries ~/.mosaic/fleet/agents,
// so the default config home resolves to the brain or legacy — both valid
// canonical endpoints — while a non-default home never adopts.
const defaultHome = join(homedir(), '.config', 'mosaic');
const resolved = resolveBrainHome(defaultHome);
expect([defaultHome, join(homedir(), '.mosaic')]).toContain(resolved);
expect(resolveBrainHome(join(homedir(), 'elsewhere', 'mosaic'))).toBe(
join(homedir(), 'elsewhere', 'mosaic'),
);
});
});
-76
View File
@@ -1,76 +0,0 @@
import { existsSync } from 'node:fs';
import { homedir } from 'node:os';
import { join, resolve } from 'node:path';
/**
* Overridable resolution inputs (tests inject tmp homes; production reads
* the environment and the real home directory).
*/
export interface BrainHomeOptions {
/** Explicit brain home; defaults to `MOSAIC_BRAIN_HOME`. */
readonly envBrainHome?: string;
/**
* Canonical homes used for adoption. Defaults derive from the real
* `homedir()`: `{ brain: ~/.mosaic, configDefault: ~/.config/mosaic }`.
*/
readonly homes?: { readonly brain: string; readonly configDefault: string };
}
/**
* Brain-home resolution — the three-tree fleet split (stack canon
* `docs/STRUCTURE-CANON.md` §2, first carried by the USC estate brain):
*
* config home (~/.config/mosaic) framework templates + dispatch state:
* fleet/roles (baseline), fleet/roster.yaml,
* fleet/run (heartbeats), fleet/services
* brain home (~/.mosaic) user-owned fleet state, committed:
* fleet/agents/<seat>.env.*, fleet/roles.local,
* fleet/profiles working copies
*
* Resolution order:
* 1. `MOSAIC_BRAIN_HOME` env (explicit, always wins)
* 2. canonical `~/.mosaic` — adopted ONLY when mosaicHome is the real
* default config home AND `~/.mosaic/fleet/agents` exists. Custom
* `--mosaic-home` values (tests, sandboxes, canaries) never trigger
* adoption, keeping them hermetic and deterministic.
* 3. mosaicHome itself (legacy single-tree behavior).
*/
export function resolveBrainHome(mosaicHome: string, options: BrainHomeOptions = {}): string {
const explicit = options.envBrainHome ?? process.env['MOSAIC_BRAIN_HOME'];
if (explicit !== undefined && explicit.trim() !== '') {
return explicit;
}
const homes = options.homes ?? {
brain: join(homedir(), '.mosaic'),
configDefault: join(homedir(), '.config', 'mosaic'),
};
if (resolve(mosaicHome) !== resolve(homes.configDefault)) {
return mosaicHome;
}
return existsSync(join(homes.brain, 'fleet', 'agents')) ? homes.brain : mosaicHome;
}
/** True when fleet state resolves somewhere other than the config home. */
export function brainHomeIsActive(mosaicHome: string, options: BrainHomeOptions = {}): boolean {
return resolve(resolveBrainHome(mosaicHome, options)) !== resolve(mosaicHome);
}
/** Fleet state root (brain home when active, else the config home). */
export function fleetStateDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
return join(resolveBrainHome(mosaicHome, options), 'fleet');
}
/** Seat launch envs — `<brainHome>/fleet/agents` when a brain is active. */
export function fleetAgentEnvDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
return join(fleetStateDir(mosaicHome, options), 'agents');
}
/** PRESERVE-protected persona override layer — `<brainHome>/fleet/roles.local`. */
export function fleetRolesLocalDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
return join(fleetStateDir(mosaicHome, options), 'roles.local');
}
/** System-type profiles (user working copies) — `<brainHome>/fleet/profiles`. */
export function fleetProfilesDir(mosaicHome: string, options: BrainHomeOptions = {}): string {
return join(fleetStateDir(mosaicHome, options), 'profiles');
}
@@ -3,7 +3,6 @@ import { lstat, open, readFile, unlink, type FileHandle } from 'node:fs/promises
import { randomUUID } from 'node:crypto'; import { randomUUID } from 'node:crypto';
import { homedir } from 'node:os'; import { homedir } from 'node:os';
import { join } from 'node:path'; import { join } from 'node:path';
import { fleetAgentEnvDir } from './brain-home.js';
import { import {
applyPreparedAgentEnvironmentProjection, applyPreparedAgentEnvironmentProjection,
prepareAgentEnvironmentProjection, prepareAgentEnvironmentProjection,
@@ -618,7 +617,7 @@ function defaultPrepareProjections(
(agent: FleetRosterV2Agent): Promise<PreparedAgentEnvironmentProjection> => (agent: FleetRosterV2Agent): Promise<PreparedAgentEnvironmentProjection> =>
prepareAgentEnvironmentProjection({ prepareAgentEnvironmentProjection({
mosaicHome, mosaicHome,
agentEnvDir: fleetAgentEnvDir(mosaicHome), agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
agentName: agent.name, agentName: agent.name,
generated: projectRosterV2AgentGeneratedEnv(roster, agent), generated: projectRosterV2AgentGeneratedEnv(roster, agent),
}), }),
@@ -176,52 +176,6 @@ describe('generated fleet agent environment boundary', (): void => {
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600); expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
}); });
it('brain home: accepts and writes projections under MOSAIC_BRAIN_HOME/fleet/agents', async (): Promise<void> => {
const savedBrainHome = process.env['MOSAIC_BRAIN_HOME'];
try {
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
const mosaicHome = join(cleanup, 'config-home');
const brainHome = join(cleanup, 'brain');
const agentEnvDir = join(brainHome, 'fleet', 'agents');
process.env['MOSAIC_BRAIN_HOME'] = brainHome;
const result = await writeAgentEnvironmentProjection({
mosaicHome,
agentEnvDir,
agentName: 'coder0',
generated: generatedValues,
});
// Projection landed in the brain tree, not under the config home.
expect(result.generatedPath).toBe(join(agentEnvDir, 'coder0.env.generated'));
expect((await stat(join(brainHome, 'fleet'))).mode & 0o777).toBe(0o700);
expect((await stat(agentEnvDir)).mode & 0o777).toBe(0o700);
expect((await stat(result.generatedPath)).mode & 0o777).toBe(0o600);
await expect(stat(join(mosaicHome, 'fleet'))).rejects.toThrow();
// A config-home agentEnvDir is now REJECTED while the brain is active —
// the boundary must not silently split state across two trees.
let rejected: unknown;
try {
await writeAgentEnvironmentProjection({
mosaicHome,
agentEnvDir: join(mosaicHome, 'fleet', 'agents'),
agentName: 'coder1',
generated: { ...generatedValues, MOSAIC_AGENT_NAME: 'coder1' },
});
} catch (caught: unknown) {
rejected = caught;
}
expect(rejected).toBeInstanceOf(AgentEnvBoundaryError);
} finally {
if (savedBrainHome === undefined) {
delete process.env['MOSAIC_BRAIN_HOME'];
} else {
process.env['MOSAIC_BRAIN_HOME'] = savedBrainHome;
}
}
});
it('regenerates desired keys, relocates safe legacy local data, and quarantines forbidden legacy input', async (): Promise<void> => { it('regenerates desired keys, relocates safe legacy local data, and quarantines forbidden legacy input', async (): Promise<void> => {
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-')); cleanup = await mkdtemp(join(tmpdir(), 'mosaic-generated-env-'));
const mosaicHome = join(cleanup, 'mosaic'); const mosaicHome = join(cleanup, 'mosaic');
@@ -2,7 +2,6 @@ import { createHash, randomUUID } from 'node:crypto';
import { chmod, lstat, mkdir, readFile, rename, unlink, writeFile } from 'node:fs/promises'; import { chmod, lstat, mkdir, readFile, rename, unlink, writeFile } from 'node:fs/promises';
import { homedir } from 'node:os'; import { homedir } from 'node:os';
import { dirname, join, resolve } from 'node:path'; import { dirname, join, resolve } from 'node:path';
import { fleetAgentEnvDir, resolveBrainHome } from './brain-home.js';
import { compareCodePoints } from './deterministic-order.js'; import { compareCodePoints } from './deterministic-order.js';
export type AgentEnvironmentKind = 'generated' | 'local'; export type AgentEnvironmentKind = 'generated' | 'local';
@@ -529,15 +528,12 @@ async function validatePrivateProjectionDirectory(
mosaicHome: string, mosaicHome: string,
agentEnvDir: string, agentEnvDir: string,
): Promise<void> { ): Promise<void> {
// Brain-home split (canon §2): seat envs live under the brain home's const fleetDir = join(mosaicHome, 'fleet');
// fleet/agents when a brain is active; roster + templates stay config-home. const expectedAgentEnvDir = join(fleetDir, 'agents');
const expectedAgentEnvDir = fleetAgentEnvDir(mosaicHome);
if (resolve(agentEnvDir) !== resolve(expectedAgentEnvDir)) { if (resolve(agentEnvDir) !== resolve(expectedAgentEnvDir)) {
throw new AgentEnvBoundaryError('unsafe-directory', '(directory)', agentEnvDir); throw new AgentEnvBoundaryError('unsafe-directory', '(directory)', agentEnvDir);
} }
const stateHome = resolveBrainHome(mosaicHome); await assertManagedDirectoryIfPresent(mosaicHome, false);
const fleetDir = join(stateHome, 'fleet');
await assertManagedDirectoryIfPresent(stateHome, false);
await assertManagedDirectoryIfPresent(fleetDir, false); await assertManagedDirectoryIfPresent(fleetDir, false);
await assertManagedDirectoryIfPresent(agentEnvDir, true); await assertManagedDirectoryIfPresent(agentEnvDir, true);
} }
@@ -547,9 +543,8 @@ async function ensurePrivateProjectionDirectory(
agentEnvDir: string, agentEnvDir: string,
): Promise<void> { ): Promise<void> {
await validatePrivateProjectionDirectory(mosaicHome, agentEnvDir); await validatePrivateProjectionDirectory(mosaicHome, agentEnvDir);
const stateHome = resolveBrainHome(mosaicHome); const fleetDir = join(mosaicHome, 'fleet');
const fleetDir = join(stateHome, 'fleet'); await ensureManagedDirectory(mosaicHome, false);
await ensureManagedDirectory(stateHome, false);
await ensureManagedDirectory(fleetDir, false); await ensureManagedDirectory(fleetDir, false);
await ensureManagedDirectory(agentEnvDir, true); await ensureManagedDirectory(agentEnvDir, true);
} }
@@ -1,45 +0,0 @@
# RI-1-002 — Publish-gate negative controls (SDLC-D-034 second half)
- Task: RI-1-002 (docs/release-integrity workstream, PRD item RI-N1), issue ref #1275
- Branch: `test/ri-050-publish-gate-negative` (base `origin/next` @ d8e0aec9 = PR #1277, RI-1-001)
- Budget: worker estimate ~45K tokens; keep scoped to the two test files + scratchpad.
## Objective
Checked-in negative-control tests that PROVE the publish gate fails when it must:
1. Broken mandatory check blocks every publish step (structural DAG proof from `.woodpecker/publish.yml`).
2. Bypass shapes fail the checker: missing edge, hidden effect (non-`publish` name), detached verify, always-pass verify (`failure: ignore` / `success` override), conditional verify (`when`).
3. Exact-commit identity: no HEAD-moving step between verify and publish effects; legitimate re-checkout requires verify to re-run after it.
4. `verify-release.mjs` composition control: a SUBSET stage list fails the composition check.
## Plan
- NEW `scripts/publish-gate-structure.test.mjs` — self-contained structural checker (`assertPublishGateBlocksOnVerify`) + positive control on the real pipeline + one negative-control test per bypass shape (S1S6, documented in file header) + positive control for the legitimate re-checkout shape.
- EXTEND `scripts/verify-release.test.mjs` — refactor the stage-mirror test body into `assertStagesMirrorCi(stages, ci)`; add negative control dropping each stage one at a time (subset must throw).
## Conventions confirmed
- Root `test:checkout` = `node --test scripts/*.test.mjs` → new file auto-joins `pnpm test`.
- Test-enumeration guard population is `*test*.sh` under `packages/mosaic/framework/tools/` only → unaffected.
- Root eslint covers only `**/*.{ts,tsx}` → .mjs files need Prettier style only (printWidth 100, singleQuote, semi, trailingComma all).
- Do NOT touch docs/TASKS.md, docs/release-integrity/TASKS.md, docs/scratchpads/.
## Progress log
- [x] Base verified: publish.yml `verify` step + verify-release.mjs present; HEAD contains origin/next.
- [x] Wrote scripts/publish-gate-structure.test.mjs
- [x] Extended scripts/verify-release.test.mjs (mirror fn + subset negative control)
- [x] Gates: node --test scripts (31 tests pass), prettier clean on touched files, pnpm typecheck PASS, pnpm lint PASS, pnpm format:check PASS
- [x] Committed ff585b88 + pushed, PR #1305 → next (no conflicts). Stopped before merge per task instruction.
## Evidence
- `node --test scripts/verify-release.test.mjs scripts/publish-gate-structure.test.mjs` → 31 tests, 0 fail.
- Mutation sanity: temporarily removing the `verify` edge from build-gateway in publish.yml → structure test goes red (verified manually during dev, then reverted).
- Gates run from repo root on this worktree; results in Progress log.
## Risks / notes
- Effect detection (`isPublishCommand`) is deliberately over-broad (any npm/pnpm/yarn command mentioning `publish`, any kaniko/docker-push/`--destination`) — fail-closed: a false positive forces justification, a false negative is the actual hazard.
- `git fetch` flagged as HEAD-moving even though fetch alone doesn't move HEAD — fail-closed on the classic `fetch && reset` pair.
-310
View File
@@ -1,310 +0,0 @@
import assert from 'node:assert/strict';
import { readFile } from 'node:fs/promises';
import { createRequire } from 'node:module';
import path from 'node:path';
import test from 'node:test';
// RI-1-002 / RI-N1 publish-gate NEGATIVE CONTROLS (SDLC-D-034).
//
// scripts/verify-release.test.mjs pins the POSITIVE structure of the publish
// gate: every publish effect declares a direct `depends_on: verify` edge and
// the verify step asserts commit identity + runs the canonical command. This
// suite is the negative-control set: each test feeds a structural gate
// checker a pipeline in which the gate is bypassed by ONE specific shape and
// asserts the checker goes RED. The controls prove from the pipeline FILE —
// never by executing Woodpecker — that a verify step that FAILS (nonzero
// exit) blocks every publish effect.
//
// Woodpecker semantics these controls rely on:
// - A step that exits nonzero FAILS, and every step that transitively
// depends on a failed step is SKIPPED — never run. That skip is the only
// thing standing between a failed mandatory check and a publish effect.
// - `detach: true` removes the step from the wait graph: the pipeline does
// not wait for detached steps, so their failure can never block anything.
// - `failure: ignore` reports a failed step as success to the DAG.
// - `success: [codes...]` overrides which exit codes count as success;
// admitting any nonzero code launders a failed verification into green.
// - `when` on the verify step would skip verification entirely on some
// event/path classes while publish effects still run.
//
// Bypass shapes covered (one negative-control test each):
// S1 Missing edge — a publish effect whose dependency closure does not
// contain `verify` (a refactor drops the depends_on entry).
// S2 Hidden effect — a step whose NAME does not start with `publish` but
// whose COMMANDS publish npm packages or push images. Effects are
// classified by commands, so renaming a step cannot un-gate it.
// S3 Detached verify — `verify: { detach: true }`: publish steps no longer
// wait for verify, so the depends_on edge is decorative.
// S4 Always-pass verify — `failure: ignore`, or a `success` override
// admitting nonzero exit codes: verify fails, the DAG sees success.
// S5 Conditional verify — a `when`/path filter on verify itself.
// S6 Exact-commit drift — a HEAD-moving step (git checkout/switch/reset/
// clean/pull/clone/fetch) ordered between `verify` and a publish
// effect: the verified commit would not be the published commit. A
// LEGITIMATE re-checkout is allowed only when `verify` itself runs
// after it — positive control included.
// S7 Gate removal — the verify step deleted or renamed away entirely.
// Reuse the monorepo's existing YAML parser (@mosaicstack/mosaic's direct
// dependency) instead of adding a root dependency or vendoring a parser.
const mosaicRequire = createRequire(
path.resolve(process.cwd(), 'packages', 'mosaic', 'package.json'),
);
const { parse: parseYaml } = mosaicRequire('yaml');
const publishYmlPath = path.join(process.cwd(), '.woodpecker', 'publish.yml');
async function readPublishPipeline() {
return parseYaml(await readFile(publishYmlPath, 'utf8'));
}
// A command has a publish EFFECT when it publishes npm packages (`publish`
// anywhere after a package-manager token — `pnpm --filter "@x/*" publish`
// puts flags and quoted filters between the binary and the subcommand) or
// pushes an image (kaniko, docker push, or a registry --destination).
// Deliberately over-broad: a false positive forces justification, a false
// negative is the actual hazard.
function isPublishCommand(command) {
return (
/(^|\s)\/kaniko\/executor\b/.test(command) ||
/(^|\s)docker\s+push\b/.test(command) ||
/(^|\s)--destination(\s|=)/.test(command) ||
(/\bpublish\b/.test(command) && /(^|\s)(npm|pnpm|yarn)(\s|$)/.test(command))
);
}
function hasPublishEffect(step) {
return (step.commands ?? []).some(isPublishCommand);
}
// A step is a publish effect when its name says so OR (S2) when any of its
// commands does — classification must not depend on the name alone.
function publishEffectSteps(pipeline) {
return Object.entries(pipeline.steps ?? {})
.filter(([name, step]) => name.startsWith('publish') || hasPublishEffect(step))
.map(([name]) => name);
}
// Transitive closure of a step's depends_on graph.
function dependencyClosure(pipeline, stepName, seen = new Set()) {
const dependencies = pipeline.steps?.[stepName]?.depends_on ?? [];
for (const dependency of dependencies) {
if (seen.has(dependency)) continue;
seen.add(dependency);
dependencyClosure(pipeline, dependency, seen);
}
return seen;
}
// Deliberately over-broad: `git fetch` alone does not move HEAD, but the
// classic re-checkout pair is `git fetch && git reset --hard <remote>`; a
// fetch step sitting between verify and a publish effect deserves scrutiny,
// so the gate fails closed on it.
function movesHead(step) {
return (step.commands ?? []).some((command) =>
/(^|\s)git\s+(checkout|switch|reset|clean|pull|clone|fetch)\b/.test(command),
);
}
// The structural gate checker: green only when a failed (nonzero-exit)
// verify provably blocks every publish effect on the same commit.
function assertPublishGateBlocksOnVerify(pipeline) {
assert.ok(pipeline.steps, 'publish pipeline must define steps');
const verify = pipeline.steps.verify;
assert.ok(verify, 'publish pipeline must define a `verify` step (S7)');
// S5: a skipped verification authorizes publishes exactly as much as a
// failed one — verify must be unconditional.
assert.equal(verify.when, undefined, '`verify` must not carry a when/path filter (S5)');
// S3/S4: the depends_on edges are only meaningful if verify's own failure
// is both awaited and terminal for the DAG.
assert.equal(verify.detach, undefined, '`verify` must not be detached (S3)');
assert.equal(
verify.failure,
undefined,
'`verify` must not tolerate its own failure (S4: failure: ignore launders a failed gate into success)',
);
assert.equal(
verify.success,
undefined,
'`verify` must not override success exit codes (S4: nonzero codes would make failed verification pass)',
);
const effects = publishEffectSteps(pipeline);
assert.ok(effects.length > 0, 'publish pipeline must contain publish effect steps to guard');
const verifyClosure = dependencyClosure(pipeline, 'verify');
for (const stepName of effects) {
// S1: only the failure-skip semantics of the DAG stand between a failed
// verify and this effect — the verify edge in its closure is the proof.
const closure = dependencyClosure(pipeline, stepName);
assert.ok(
closure.has('verify'),
`publish effect '${stepName}' must transitively depend on verify (S1) — a failed verify must skip it`,
);
// S6: any step ordered after verify (outside its closure) but inside the
// effect's chain must not be able to move HEAD. If the pipeline
// legitimately re-checks-out, verify must run after the re-checkout.
for (const chainStep of closure) {
if (chainStep === 'verify' || verifyClosure.has(chainStep)) continue;
assert.ok(
!movesHead(pipeline.steps[chainStep]),
`step '${chainStep}' sits between verify and publish effect '${stepName}' and can move HEAD (S6)` +
' — verify must re-run after any re-checkout',
);
}
}
return effects;
}
// A minimal but healthy gate used as the base for every negative-control
// mutation: verify (identity + canonical command) → build → publish-npm,
// with the publish effect blocked by verify both directly and through build.
const HEALTHY_GATE_YAML = `
steps:
verify:
image: node:24-alpine
commands:
- |
if [ -z "$CI_COMMIT_SHA" ] || [ "$CI_COMMIT_SHA" != "$(git rev-parse HEAD)" ]; then
echo "identity mismatch" >&2
exit 1
fi
- pnpm verify:release
build:
image: node:24-alpine
commands:
- pnpm build
depends_on:
- verify
publish-npm:
image: node:24-alpine
commands:
- npm publish
depends_on:
- build
- verify
`;
// Fresh parse per call so every negative control mutates its own object.
function healthyPipeline() {
return parseYaml(HEALTHY_GATE_YAML);
}
test('the real publish pipeline: a failed verify provably blocks every publish effect', async () => {
const pipeline = await readPublishPipeline();
const effects = assertPublishGateBlocksOnVerify(pipeline);
assert.deepEqual(effects.sort(), [
'build-appservice',
'build-gateway',
'build-web',
'publish-next-npm',
'publish-npm',
]);
});
test('fixture sanity: the healthy gate base passes the checker unmutated', () => {
assertPublishGateBlocksOnVerify(healthyPipeline());
});
test('S1 negative control: a publish effect with no verify edge fails the checker', () => {
const pipeline = healthyPipeline();
pipeline.steps['publish-npm'].depends_on = ['build'];
pipeline.steps.build.depends_on = [];
assert.throws(
() => assertPublishGateBlocksOnVerify(pipeline),
/publish-npm.*must transitively depend on verify/s,
);
});
test('S2 negative control: an npm publish hidden behind a non-publish step name fails the checker', () => {
const pipeline = healthyPipeline();
delete pipeline.steps['publish-npm'];
pipeline.steps.build.depends_on = [];
pipeline.steps.deploy = {
image: 'node:24-alpine',
commands: ['npm publish'],
depends_on: ['build'],
};
// Detection must be by COMMAND: the name says "deploy", the commands say
// publish — an un-gated effect under either reading.
assert.throws(
() => assertPublishGateBlocksOnVerify(pipeline),
/deploy.*must transitively depend on verify/s,
);
});
test('S2 negative control: a kaniko image push under a build-* name fails the checker when ungated', () => {
const pipeline = healthyPipeline();
delete pipeline.steps['publish-npm'];
pipeline.steps.build.depends_on = [];
pipeline.steps['push-platform-image'] = {
image: 'gcr.io/kaniko-project/executor:debug',
commands: ['/kaniko/executor --context . --destination reg.example/img:latest'],
depends_on: ['build'],
};
assert.throws(
() => assertPublishGateBlocksOnVerify(pipeline),
/push-platform-image.*must transitively depend on verify/s,
);
});
test('S3 negative control: a detached verify fails the checker', () => {
const pipeline = healthyPipeline();
pipeline.steps.verify.detach = true;
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /detached \(S3\)/);
});
test('S4 negative control: failure: ignore on verify fails the checker', () => {
const pipeline = healthyPipeline();
pipeline.steps.verify.failure = 'ignore';
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /tolerate its own failure/);
});
test('S4 negative control: a success override admitting nonzero exit codes fails the checker', () => {
const pipeline = healthyPipeline();
pipeline.steps.verify.success = [0, 1];
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /success exit codes/);
});
test('S5 negative control: a when filter on verify fails the checker', () => {
const pipeline = healthyPipeline();
pipeline.steps.verify.when = [{ event: 'push' }];
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /when\/path filter \(S5\)/);
});
test('S6 negative control: a HEAD-moving step between verify and publish fails the checker', () => {
const pipeline = healthyPipeline();
pipeline.steps.resync = {
image: 'node:24-alpine',
commands: ['git fetch origin', 'git reset --hard origin/main'],
depends_on: [],
};
pipeline.steps.build.depends_on = ['verify', 'resync'];
// resync sits AFTER verify in the publish chain (verify does not depend on
// it), so the verified commit could be replaced before publishing.
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /resync.*can move HEAD/s);
});
test('S6 positive control: a legitimate re-checkout passes when verify re-runs after it', () => {
const pipeline = healthyPipeline();
pipeline.steps.resync = {
image: 'node:24-alpine',
commands: ['git fetch origin', 'git reset --hard origin/main'],
depends_on: [],
};
pipeline.steps.verify.depends_on = ['resync'];
pipeline.steps.build.depends_on = ['verify'];
// resync precedes verify in the chain, so verification covers the
// re-checked-out HEAD — the exact-commit contract holds.
assertPublishGateBlocksOnVerify(pipeline);
});
test('S7 negative control: deleting the verify step entirely fails the checker', () => {
const pipeline = healthyPipeline();
delete pipeline.steps.verify;
pipeline.steps['publish-npm'].depends_on = ['build'];
assert.throws(() => assertPublishGateBlocksOnVerify(pipeline), /`verify` step/);
});
-166
View File
@@ -1,166 +0,0 @@
#!/usr/bin/env node
// verify-release.mjs — the ONE canonical terminal verification command
// (SDLC-D-034, `pnpm verify:release`).
//
// Publication (.woodpecker/publish.yml `verify` step) is bound to terminal
// verification of the exact commit through this command, which is composed
// from the SAME commands the PR CI pipeline (.woodpecker/ci.yml) runs — CI and
// publish share one semantic checklist:
//
// stage | mirrors ci.yml step | commands
// --------------|---------------------|------------------------------------------
// sanitization | sanitization | verify-sanitized.sh, check-resident-
// | | budget.sh (--self-test + run),
// | | check-test-enumeration.sh
// upgrade-guard | upgrade-guard | test-upgrade-manifest-guard.sh,
// | | test-upgrade-rollback.sh,
// | | test-upgrade-durable-snapshot.sh,
// | | test-install-migration.sh
// typecheck | typecheck | pnpm typecheck (runs the checkout
// | | preflight, then turbo typecheck)
// lint | lint | pnpm lint
// format | format | pnpm format:check
// test | test | pnpm test
// build | publish.yml build | pnpm build
//
// Caller-provided prerequisites (kept at the pipeline level — see the comments
// in .woodpecker/ci.yml): `bash` + `rsync` for the guard stages, `openssl` and
// the pinned @earendil-works/pi-coding-agent for the test stage, and — on the
// postgres path only — the ci-postgres service plus
// `pnpm --filter @mosaicstack/db run db:migrate` before the test stage.
//
// This command works with DATABASE_URL set (CI postgres path) or unset (local
// PGlite path); it never sets, exports, or requires a database itself.
//
// scripts/verify-release.test.mjs enforces that this stage table keeps
// matching .woodpecker/ci.yml step-for-step, so the two surfaces cannot drift
// apart silently.
import { spawnSync } from 'node:child_process';
import path from 'node:path';
import { fileURLToPath } from 'node:url';
export const STAGES = [
{
name: 'sanitization',
// Mirror of the .woodpecker/ci.yml `sanitization` step (minus its
// `apk add` environment prep). Kept as direct command strings here: the
// #1017 test-enumeration guard audits these paths through the ci.yml
// surface, so indirection from ci.yml into this file is not possible.
commands: [
'bash packages/mosaic/framework/tools/quality/scripts/verify-sanitized.sh',
'bash packages/mosaic/framework/tools/quality/scripts/check-resident-budget.sh --self-test',
'bash packages/mosaic/framework/tools/quality/scripts/check-resident-budget.sh',
'bash packages/mosaic/framework/tools/quality/scripts/check-test-enumeration.sh',
],
},
{
name: 'upgrade-guard',
// Mirror of the .woodpecker/ci.yml `upgrade-guard` step (minus its
// `apk add` environment prep).
commands: [
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-manifest-guard.sh',
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-rollback.sh',
'bash packages/mosaic/framework/tools/quality/scripts/test-upgrade-durable-snapshot.sh',
'bash packages/mosaic/framework/tools/quality/scripts/test-install-migration.sh',
],
},
{
// `pnpm typecheck` is `pnpm preflight && turbo run typecheck`, so the
// checkout preflight (scripts/preflight.mjs) is part of this stage exactly
// as it is part of the ci.yml `typecheck` step.
name: 'typecheck',
commands: ['pnpm typecheck'],
},
{
name: 'lint',
commands: ['pnpm lint'],
},
{
name: 'format',
commands: ['pnpm format:check'],
},
{
// Requires `openssl` and the pinned `pi` binary on the pipeline path; see
// the caller-provided prerequisites above.
name: 'test',
commands: ['pnpm test'],
},
{
name: 'build',
commands: ['pnpm build'],
},
];
export function stageByName(name) {
return STAGES.find((stage) => stage.name === name);
}
function missingBinaries(bins) {
return bins.filter(
(bin) => spawnSync('sh', ['-c', `command -v ${bin} >/dev/null 2>&1`]).status !== 0,
);
}
function runCommand(command) {
const result = spawnSync(command, { shell: true, stdio: 'inherit' });
if (result.error) {
console.error(`[verify:release] failed to launch '${command}': ${result.error.message}`);
return false;
}
if (result.status !== 0) {
const reason = result.signal ? `terminated by ${result.signal}` : `exited ${result.status}`;
console.error(`[verify:release] command '${command}' ${reason}`);
return false;
}
return true;
}
// Runs the complete mandatory verification set (or, with --stage <name>, the
// single named stage — used for wiring/smoke-testing, not for gating: only a
// run of every stage is a terminal verification). Fails fast: the first
// failing command aborts with a non-zero exit code. Returns the exit code.
export function verifyRelease({ stages = STAGES } = {}) {
const missing = missingBinaries(['bash', 'rsync']);
if (missing.length > 0) {
console.error(
`[verify:release] FATAL: required binaries missing from PATH: ${missing.join(', ')}. ` +
'The caller provides them (ci-base bakes bash; pipelines apk add rsync).',
);
return 1;
}
for (const stage of stages) {
console.log(`\n[verify:release] === stage: ${stage.name} ===`);
for (const command of stage.commands) {
console.log(`[verify:release] $ ${command}`);
if (!runCommand(command)) {
console.error(
`[verify:release] FATAL: stage '${stage.name}' failed — verification inconclusive`,
);
return 1;
}
}
}
console.log(`\n[verify:release] all ${stages.length} stage(s) passed`);
return 0;
}
function main(argv) {
const stageFlagIndex = argv.indexOf('--stage');
if (stageFlagIndex !== -1) {
const name = argv[stageFlagIndex + 1];
const stage = stageByName(name);
if (!stage) {
console.error(
`[verify:release] unknown stage '${name ?? ''}' — expected one of: ${STAGES.map((entry) => entry.name).join(', ')}`,
);
process.exit(2);
}
process.exit(verifyRelease({ stages: [stage] }));
}
process.exit(verifyRelease());
}
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
main(process.argv.slice(2));
}
-303
View File
@@ -1,303 +0,0 @@
import assert from 'node:assert/strict';
import { readFile } from 'node:fs/promises';
import { createRequire } from 'node:module';
import path from 'node:path';
import test from 'node:test';
import { STAGES } from './verify-release.mjs';
// SDLC-D-034 checkout invariant: publication in .woodpecker/publish.yml is
// bound to exact-commit terminal verification. This suite parses the real
// pipeline files and fails red when the gate is bypassed, weakened, or drifts
// out of sync with the canonical `pnpm verify:release` command. The negative
// controls for pipeline DAG/bypass shapes live in
// scripts/publish-gate-structure.test.mjs (RI-1-002); this file owns the
// canonical-command composition controls.
// Reuse the monorepo's existing YAML parser (@mosaicstack/mosaic's direct
// dependency) instead of adding a root dependency or vendoring a parser.
const mosaicRequire = createRequire(
path.resolve(process.cwd(), 'packages', 'mosaic', 'package.json'),
);
const { parse: parseYaml } = mosaicRequire('yaml');
const publishYmlPath = path.join(process.cwd(), '.woodpecker', 'publish.yml');
const ciYmlPath = path.join(process.cwd(), '.woodpecker', 'ci.yml');
async function readPublishPipeline() {
return parseYaml(await readFile(publishYmlPath, 'utf8'));
}
// A step has an external publication effect when its name starts with
// `publish` or when any command pushes an image to a registry.
function pushesImage(step) {
return (step.commands ?? []).some((command) =>
/(^|\s)(\/kaniko\/executor|docker push)\b|--destination/.test(command),
);
}
function publishEffectSteps(pipeline) {
return Object.entries(pipeline.steps ?? {})
.filter(([name, step]) => name.startsWith('publish') || pushesImage(step))
.map(([name]) => name);
}
// Transitive closure of a step's depends_on graph.
function dependencyClosure(pipeline, stepName, seen = new Set()) {
const dependencies = pipeline.steps?.[stepName]?.depends_on ?? [];
for (const dependency of dependencies) {
if (seen.has(dependency)) continue;
seen.add(dependency);
dependencyClosure(pipeline, dependency, seen);
}
return seen;
}
function verifyCommands(pipeline) {
const verify = pipeline.steps?.verify;
assert.ok(verify, 'publish pipeline must define a `verify` step');
assert.ok(Array.isArray(verify.commands), '`verify` step must have commands');
return verify.commands;
}
function assertCommitIdentityAssertion(commands) {
const text = commands.join('\n');
assert.match(
text,
/CI_COMMIT_SHA/,
'`verify` must compare the provider commit identity (CI_COMMIT_SHA)',
);
assert.match(text, /git rev-parse HEAD/, '`verify` must compare against git rev-parse HEAD');
assert.match(
text,
/exit 1/,
'`verify` must fail closed (exit 1) on identity mismatch or emptiness',
);
}
function assertCanonicalCommand(commands) {
assert.ok(
commands.some((command) => /^pnpm verify:release\b/.test(command.trim())),
'`verify` must run the canonical terminal verification command `pnpm verify:release`',
);
}
function assertPublishGate(pipeline) {
assert.ok(pipeline.steps, 'publish pipeline must define steps');
const commands = verifyCommands(pipeline);
assertCommitIdentityAssertion(commands);
assertCanonicalCommand(commands);
const effects = publishEffectSteps(pipeline);
assert.ok(effects.length > 0, 'publish pipeline must contain publish effect steps to guard');
for (const stepName of effects) {
const step = pipeline.steps[stepName];
assert.ok(
Array.isArray(step.depends_on) && step.depends_on.includes('verify'),
`publish effect '${stepName}' must depend DIRECTLY on the verify step (SDLC-D-034: transitively through build is not enough)`,
);
assert.ok(
dependencyClosure(pipeline, stepName).has('verify'),
`publish effect '${stepName}' must depend on a chain that includes verify`,
);
}
return effects;
}
test('the publish pipeline gates every publish effect behind exact-commit verification', async () => {
const pipeline = await readPublishPipeline();
const effects = assertPublishGate(pipeline);
assert.deepEqual(effects.sort(), [
'build-appservice',
'build-gateway',
'build-web',
'publish-next-npm',
'publish-npm',
]);
});
test('the verify step carries no path/event short-circuit of its own', async () => {
const pipeline = await readPublishPipeline();
// A `when` filter on `verify` would let a publish effect fire on an event
// class that skipped verification — the gate must be unconditional.
assert.equal(pipeline.steps.verify.when, undefined);
});
test('a publish step that bypasses verify fails the gate checker', () => {
// Negative fixture: a plausible publish pipeline where `publish-npm` hangs
// off `build` only and `build` never chains to `verify` — the exact bypass
// class SDLC-D-034 closes. The checker must go red on it.
const bypassingPipeline = `
steps:
install:
image: node:24-alpine
commands:
- pnpm install --frozen-lockfile
verify:
image: node:24-alpine
commands:
- |
if [ -z "$CI_COMMIT_SHA" ] || [ "$CI_COMMIT_SHA" != "$(git rev-parse HEAD)" ]; then
echo "identity mismatch" >&2
exit 1
fi
- pnpm verify:release
depends_on:
- install
build:
image: node:24-alpine
commands:
- pnpm build
depends_on:
- install
publish-npm:
image: node:24-alpine
commands:
- pnpm publish
depends_on:
- build
`;
assert.throws(
() => assertPublishGate(parseYaml(bypassingPipeline)),
/publish-npm.*DIRECTLY.*verify/s,
);
});
test('a publish step chained to verify only transitively fails the gate checker', () => {
// Negative fixture: `build` depends on verify but `publish-npm` does not
// carry the direct edge — weaker than SDLC-D-034 requires of the real DAG.
const transitiveOnlyPipeline = `
steps:
install:
image: node:24-alpine
commands:
- pnpm install --frozen-lockfile
verify:
image: node:24-alpine
commands:
- |
if [ -z "$CI_COMMIT_SHA" ] || [ "$CI_COMMIT_SHA" != "$(git rev-parse HEAD)" ]; then
echo "identity mismatch" >&2
exit 1
fi
- pnpm verify:release
depends_on:
- install
build:
image: node:24-alpine
commands:
- pnpm build
depends_on:
- install
- verify
publish-npm:
image: node:24-alpine
commands:
- pnpm publish
depends_on:
- build
`;
assert.throws(
() => assertPublishGate(parseYaml(transitiveOnlyPipeline)),
/publish-npm.*DIRECTLY.*verify/s,
);
});
test('a verify step without the commit-identity assertion fails the gate checker', () => {
const noIdentityPipeline = `
steps:
verify:
image: node:24-alpine
commands:
- pnpm verify:release
publish-npm:
image: node:24-alpine
commands:
- pnpm publish
depends_on:
- verify
`;
assert.throws(() => assertPublishGate(parseYaml(noIdentityPipeline)), /CI_COMMIT_SHA/);
});
// The composition check: the canonical stage table must mirror the PR CI
// pipeline's complete mandatory set. Parameterized by the stage list so the
// subset negative control below can prove a dropped stage goes red (RI-1-002:
// the canonical command cannot silently lose a check).
function assertStagesMirrorCi(stages, ci) {
const canonical = Object.fromEntries(stages.map((stage) => [stage.name, stage.commands]));
// The complete mandatory set, in gate order.
assert.deepEqual(
stages.map((stage) => stage.name),
['sanitization', 'upgrade-guard', 'typecheck', 'lint', 'format', 'test', 'build'],
);
// Guard stages: ci.yml commands minus its `apk add` environment prep must be
// exactly the canonical stage commands (order included).
for (const stageName of ['sanitization', 'upgrade-guard']) {
assert.deepEqual(
ci.steps[stageName].commands.filter((command) => !command.startsWith('apk add')),
canonical[stageName],
`canonical '${stageName}' stage must match the ci.yml step`,
);
}
// pnpm stages: ci.yml commands minus `corepack enable` must be exactly the
// canonical stage commands.
for (const stepName of ['typecheck', 'lint', 'format']) {
assert.deepEqual(
ci.steps[stepName].commands.filter((command) => command !== 'corepack enable'),
canonical[stepName],
`canonical '${stepName}' stage must match the ci.yml step`,
);
}
// The test stage is shared, but ci.yml wraps it in pipeline-level
// prerequisites the canonical command expects its caller to provide
// (SDLC-D-034): the postgres service + readiness wait + db:migrate, openssl,
// and the pinned pi runtime. None of those may be dropped silently.
for (const command of canonical.test) {
assert.ok(
ci.steps.test.commands.includes(command),
`ci.yml test step must run the canonical test stage command '${command}'`,
);
}
for (const fragment of [
'pg_isready -h ci-postgres',
'pnpm --filter @mosaicstack/db run db:migrate',
'npm install -g @earendil-works/[email protected]',
]) {
assert.ok(
ci.steps.test.commands.some((command) => command.includes(fragment)),
`ci.yml test step must keep its pipeline-level prerequisite '${fragment}'`,
);
}
}
test('the canonical verify:release stages mirror the PR CI pipeline one-for-one', async () => {
const ci = parseYaml(await readFile(ciYmlPath, 'utf8'));
assertStagesMirrorCi(STAGES, ci);
});
test('a subset stage list fails the composition check — a dropped stage cannot pass silently', async () => {
const ci = parseYaml(await readFile(ciYmlPath, 'utf8'));
// Drop each stage one at a time: every stage is load-bearing, so every drop
// must go red. If any drop went green, a refactor could silently delete a
// mandatory check from the canonical command.
for (const stage of STAGES) {
const subset = STAGES.filter((entry) => entry.name !== stage.name);
assert.throws(
() => assertStagesMirrorCi(subset, ci),
Error,
`composition check must fail when the '${stage.name}' stage is dropped from the table`,
);
}
});
test('the root package.json exposes verify:release as the canonical command', async () => {
const packageJson = JSON.parse(await readFile(path.join(process.cwd(), 'package.json'), 'utf8'));
assert.match(packageJson.scripts['verify:release'], /scripts\/verify-release\.mjs/);
});