Framework install machinery for the wake component (EPIC #892 W7, the last build slice). ADDITIVE per #869: adds an `install.sh --component wake` early dispatch that never enters the full-framework sync, never alters framework-manifest ownership behavior, and touches nothing the #869 install-ordering-guard covers (no runtime-asset linking, no lease-enforcement hook wiring). (i) Idempotent component-manifest install + Gate A (wake-install.sh install): the wake manifest.txt is VERSION METADATA ONLY; the component file set is INTERSECTED-AND-VALIDATED against the single SSOT framework-manifest.txt. A candidate the SSOT does not own is REFUSED fail-closed with no partial write. Re-running writes zero files (no diff). (ii) systemd/user/mosaic-wake.service — the long-lived detector daemon (detector.sh run). Per-class SLO lives inside the daemon, not a systemd interval; it is a SERVICE not a timer, so blank-reset does not apply. (iii) blank-reset idiom on the legacy mosaic-heartbeat@<agent>.timer cadence drop-in during the §5 overlap->retire lifecycle (empty OnUnitActiveSec= reset before the new value => exactly one OnUnitActiveUSec), with a reset->verify->retire acceptance path (retire LAST, only on §4-vector pass). (iv) snapshot-guard — a reap/clean-checkout of a deployed unit is REFUSED without a prior snapshot (the deployed-from-uncommitted failure class). (v) fail-closed alarm-target + HMAC-key install-validation (G1/G2a): the operator W6 alarm sink must be configured + reachable and the W3/W7 HMAC key must resolve BY NAME; missing/unreachable => FAIL LOUD. The installer ships/writes NO endpoint value and NO secret, and echoes neither. Red-first harness test-wake-install.sh (6 groups) wired into test:framework-shell; Gate-A parity extended to prove bash+TS both resolve the wake component paths framework-owned. wake component manifest bumped 0.5.0 -> 0.6.0. Part of #892 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0158NZqN2n2ymKFeJAZ4GUCb
80 lines
5.1 KiB
Plaintext
80 lines
5.1 KiB
Plaintext
# Mosaic wake component — VERSION metadata manifest (Gate B).
|
|
#
|
|
# EPIC #892, W2 + W3 of the wake/heartbeat canon.
|
|
#
|
|
# SCOPE — THIS FILE IS VERSION METADATA ONLY. It declares the wake component's
|
|
# semantic version and the RANGE of watch-list schema versions it supports. It
|
|
# does NOT authorize file/path ownership: path-ownership remains the sole domain
|
|
# of packages/mosaic/framework/framework-manifest.txt (Gate A). Do not read any
|
|
# ownership meaning into this file.
|
|
#
|
|
# Format: KEY=VALUE, one per line. '#' and blank lines ignored.
|
|
|
|
# Component identity + semantic version.
|
|
# 0.1.0 W2 — store+drain lib + ack-wrapper.
|
|
# 0.2.0 W3 — cumulative-state digest renderer + non-circular HMAC signer.
|
|
# 0.3.0 W4 — per-host single-instance delta-gated detector daemon.
|
|
# 0.4.0 W5 — synthetic-canary FN-oracle + source-parity reconciler.
|
|
# 0.5.0 W6 — off-host dead-man beacon emitter + pluggable alarm-sink adapter
|
|
# + beacon-absence alarm (fail-loud on unconfigured/unreachable).
|
|
# 0.6.0 W7 — A10 idempotent, fail-closed component installer (Gate-A
|
|
# intersect+validate against the framework-manifest SSOT), the
|
|
# mosaic-wake.service detector daemon, the blank-reset retire idiom
|
|
# for the legacy heartbeat timer + snapshot-guard, and fail-closed
|
|
# alarm-target/HMAC-key install-validation. Also folds in the two W6
|
|
# monitor-integration observations (monitor-side ingested_ts
|
|
# staleness + beacon HMAC-verify at record).
|
|
component=wake
|
|
version=0.6.0
|
|
|
|
# Watch-list schema this component consumes, and the INCLUSIVE range of
|
|
# schema_version values it supports. A wake-watch-list.json whose schema_version
|
|
# falls outside [schema_min, schema_max] is rejected by the component (fail-loud),
|
|
# never silently coerced.
|
|
schema=wake-watch-list
|
|
schema_min=1
|
|
schema_max=1
|
|
|
|
# Pieces shipped by this component version (informational):
|
|
# store.sh A2 — three-cursor durable store + drain lib. (W2)
|
|
# ack.sh A4 — RECEIVED/CONSUMED ack-wrapper (local-write + ship). (W2)
|
|
# digest.sh A3 — cumulative-state digest renderer (hard locators,
|
|
# two-tier trust, injection/secret scrub). (W3)
|
|
# sign.sh A5 — non-circular HMAC signer (independent wake_id,
|
|
# load_credentials by-name; fills the hmac placeholder). (W3)
|
|
# detector.sh A1 — per-host single-instance delta-gated detector daemon
|
|
# (flock, anchor-scoped hashing, detector-local observed_seq,
|
|
# fail-loud source semantics; enqueues deltas to store.sh). (W4)
|
|
# fn-oracle.sh A6 — synthetic-canary FN-oracle: injects a KNOWN delta at the
|
|
# source boundary, drives the pipeline through the detector's
|
|
# public poll-once, asserts CONSUMED within the per-class SLO
|
|
# (off-domain verdict from the terminal store cursor). §4
|
|
# requires FN-rate=0; a dropping/disabled detector FAILS. (W5)
|
|
# reconcile.sh A7 — source-parity reconciler: (i) source-coverage parity
|
|
# inventory (an omitted source cannot pass the vector
|
|
# vacuously) + (ii) periodic full reconcile to 0-unaccounted,
|
|
# enumerating pre-existing/startup state into the store. (W5)
|
|
# beacon.sh A8 — off-host DEAD-MAN liveness beacon: a monotonic beacon
|
|
# EMITTER (emit — the primitive the detector run-loop calls
|
|
# each cycle), the off-host monitor's RECEIVER + beacon-ABSENCE
|
|
# alarm (record, check), and a pluggable alarm-sink/beacon-sink
|
|
# ADAPTER INTERFACE. Liveness is SPLIT from work-triggering;
|
|
# the alarm fires on ABSENCE, routing to a human/other-host
|
|
# within its SLO (§4/G1). FAIL-CLOSED: an unconfigured OR
|
|
# unreachable target FAILS LOUD (no silent no-alarm host).
|
|
# A same-host sibling is REJECTED as non-independent; an
|
|
# isolated host degrades to a FLAGGED different-supervision-root
|
|
# beacon; capture-pane is a liveness HINT only. (W6)
|
|
# wake-install.sh A10 — idempotent, fail-closed COMPONENT installer. Selects the
|
|
# component file set and INTERSECTS-AND-VALIDATES it against the
|
|
# single SSOT framework-manifest.txt (Gate A) — this VERSION
|
|
# manifest authorizes no path. Ships the blank-reset retire
|
|
# idiom (exactly-one OnUnitActiveUSec) for the legacy heartbeat
|
|
# timer, the snapshot-guard (no reap without a snapshot), and
|
|
# fail-closed alarm-target + HMAC-key install-validation (the
|
|
# installer wires + install-validates the beacon target that
|
|
# beacon.sh's fail-loud primitive is designed for). (W7)
|
|
# Companion (framework subtree, not under tools/wake/): systemd/user/mosaic-wake.service
|
|
# — the long-lived detector daemon unit (per-class SLO lives in
|
|
# the daemon, NOT a systemd interval). (W7)
|