4.8 KiB
4.8 KiB
#1050 — Installer P0–P9 state machine and red-first fixture
Objective
Implement C1 from the canonical greenfield-install PRD v2: a transactional P0–P9 installer spine, a side-effect-free P0–P8 --check, and a lane-parametric Debian/glibc non-root from-zero fixture. The acceptance milestone is an attributable RED on the pre-C1 installer while preserving P3 PASS.
Authority and scope
- Canonical requirements:
jason.woltje/jarvis-braindocs/plans/2026-08-04-greenfield-install-blockers-PRD-v2.md, read from localorigin/mainobjectb2b6ed41f5aff5ea964e69b7c701cb45718742fa; remote currency is unestablished because authenticated fetch returned repository-not-found. - Tracking:
mosaicstack/stack#1050ongit.mosaicstack.dev(author read back asbe-coder-05). - Base:
origin/next4df478cdd150fdf8d52ea109f02ade5d85017acd. - Out of scope: PATH, skills, headless wizard/identity, activation remediation, #869 wiring, RM-02, main promotion.
docs/TASKS.mdis orchestrator-single-writer and is not modified by this worker.
Plan
- Pre-register the canonical phase/output/side-effect-free/fault-injection checks and observe RED against the base installer.
- Commit the immutable red-first acceptance fixture before implementation.
- Add the state-machine/journal/postcondition spine without repairing P4/P5/P8 symptoms.
- Wire the expected-RED from-zero fixture into Woodpecker using Debian/glibc and a non-root target user.
- Run shell/static baselines, situational container validation, code review, security review, then deliver through a PR to
nextunder the coordinator-owned merge path.
Budget
- Working estimate: 32K reasoning/output tokens.
- Hard external cap: none stated.
- Adaptation: keep implementation in shell surfaces already in scope; no package dependency install unless repository gates require it.
Pre-registered acceptance checks
| ID | Exact case | Expected pre-fix result |
|---|---|---|
| C1-R1 | tools/e2e-install-test.sh --lane next in a clean Debian 12 container as uid 1001 |
non-zero; P3 PASS; P4 NOT-MEASURED / UNDECLARED; P5/P6/P8 FAIL with own reasons |
| C1-R2 | tools/install-state-machine.test.sh phase table case |
RED because base installer does not enumerate canonical P0–P9 contracts |
| C1-R3 | side-effect-free --check case over a fingerprinted HOME |
RED because base --check is version-only rather than P0–P8 predicates |
| C1-R4 | fault injection after each P2…P8 | RED because base installer has no injectable durable journal/rollback state |
| C1-R5 | Docker unavailable | base harness incorrectly exits 0; replacement must fail non-zero |
| C1-R6 | lane resolution | bare checkout is forbidden; fixture must pass --next and assert the resolved prerelease version |
| C1-R7 | same Debian fixture with git absent vs present |
absent: P1 FAIL while legacy installer exits 0 and sync degrades; present: P1 PASS and observed store/runtime containment 101/101 |
Progress
- Charter, doctrine, delivery/CI/QA/docs guides read.
- Canonical PRD v2 and charters read from local origin object; numbering reconciles with the TL spec. No numbering conflict found. TL additions (early durable journal and INV-C) are additive, not contradictory.
- Target base reachability verified with
merge-base --is-ancestor. - Issue #1050 created and provider author read back.
- Initial RED captured; TL rejected P4's repo-root count as a false RED. Four populations disagree (framework payload 1, repo root 13, sync store 101 in the fixture, W-jarvis observation 7), so C1 now requires a checkout-free declared shipped-set artifact and reports P4
NOT-MEASURED / UNDECLAREDuntil C5 supplies it. - P6 strengthens #869: the two dead enforcement hooks reproduce from zero on a clean broker-less container. C1 asserts the breach but neither wires nor unwires it.
- P1 false pass identified from the P4 evidence row:
gitis absent from the Debian base and was undeclared even though skill sync shells out to it. C1 addsgitto P1; the fixture matrix preserves absent/present controls. The prior claim that web1's missing runtime skills reproduce this greenfield mechanism is withdrawn by the TL and is not carried here. - Corrected RED transcript captured and reported.
- State machine implemented.
- Reviews complete.
Risks / blockers
- The deployed create wrappers do not expose
--dry-run; identity preflight was performed throughpr-merge.sh --dry-runon the same HOMELAB repo, which resolvedgit.mosaicstack.dev+be-coder-05. The issue create then fell back from tea to the API but provider read-back confirmed authorbe-coder-05. nextis an integration lane;mainpromotion remains #1037-owned.- #869 must remain staged and inactive.
Verification log
(To be updated with exact commands and resulting objects.)