Skip to content

The consumers' switch: extension + installer + guard (+ the plugin) read the projection, never the raw file (#1106) - #1109

Merged
aarontrowbridge merged 5 commits into
mainfrom
1106-consumer-switch
Sep 14, 2026
Merged

aarontrowbridge merged 5 commits into
mainfrom
1106-consumer-switch

Conversation

@aarontrowbridge

Copy link
Copy Markdown
Member

P3b-2 of the approved fleet rearchitect (spec-20260913-114814 row 1, D1, §8 F1) — the three-parser hazard is dead on the amicode side. The recon found four raw parsers (the three the issue named + the opencode-plugin's fleet-role read); all now read the fleet authority's projection through the ONE reader / the ONE CLI door. n_fleet_topology_parsers == 1 — the one is amicissimo's, behind python3 -m fleet_authority — asserted by a source-scan across src/plugin/both script copies plus the pinned CLI door.

The cache convention: ~/.amico/ops/fleet/projection.json (path defined ONCE in @amicode/schema), refreshed atomically by the verb on every successful amico fleet status --projection, and transitively by the installer, the extension's Go-Standalone flow (the coherence rule: every raw-config writer is followed by a cache refresh), and the guard (refresh-on-absent). Only a reader-VALIDATED projection lands there; exit-75 bootstrap never touches it.

The switch, by consumer:

  • Extension: a new fleet_topology.ts consumes @amicode/schema verbatim (readProjection/freshnessBetween/renderFleetStatus); all eight call sites switched (activation guard, tunnel port, status bar + freshness badge/advisory, Go-Standalone, restart-hub, server restart, terminal hint, health checks); fleet_fallback.ts is now WRITER-only (the readers stayed; the raw parse is gone — grep-guard-tested)
  • Installer (both copies, byte-identical): shells the verb, parses additive machine fields (role/canonical/cache_path — no JSON parsing in bash), exit-75 and CLI-absent are the IDENTICAL stated base-standalone branch; other failures die honestly
  • Guard (both copies): cache-first (contract-v1-pinned role read) + verb-refresh-on-absent — fast spawns, warm-cache CLI-less operation — and it FAILS CLOSED on verb failure (a client never silently forks on an unreadable topology)
  • Plugin: stack_state.ts's fleet-role read goes to the projection cache's topology section (AMICO_FLEET_PROJECTION replaces AMICO_FLEET_CONFIG); silent-on-optional per plugin discipline; its health read is F6's, untouched
  • CI gate: assert_fleet_guard.sh rewritten to assert the NEW convention (projection reference, verb door, contract pin, packaged copies in sync)

F1 green: the triple-consumer replay feeds the SAME absent/broken/stale fixtures through the extension seam + the REAL bash installer + guard (fabricated HOME/PATH, a faithful fake amico, a frozen binary proving exec-vs-refusal) — every consumer renders honestly; base-standalone byte-identical for the solo floor.

Gate evidence (director re-run, from commands): the five new/extended suites 66/66; typecheck clean; extension suite 3566 passed with the known environmental family (one FEWER failure than baseline — the fresh build produced the app dist; none outside the family); amico-run 1625 passed with 2 stash-verified pre-existing profile_verb failures (the known deploy-lag issue); boot smoke PASS. Scope: 87 files +2295/−778 (the −778 = the removed raw-parse paths + the rewritten gate; every file maps to the recon list).

Merge is per the standing green directive.

… machine fields (P3b-2 commit 1)

- @amicode/schema: fleetProjectionCachePath() + FLEET_PROJECTION_CACHE_RELPATH — the
  ONE definition of the consumers' cache convention (<home>/.amico/ops/fleet/projection.json)
- amico fleet status --projection: after the reader VALIDATES the published projection,
  it refreshes the stable cache (atomic tmp+rename; a rejected contract never clobbers
  it; the bootstrap exception (75) leaves it untouched) and the success JSON carries
  additive machine fields (role, canonical, cache_path) for script consumers
- tests hermetic: grantedWorld defaults the cache into the tmp dir
… through the ONE reader (P3b-2 commit 2)

- readFleetTopology: the cached projection (~/.amico/ops/fleet/projection.json) read
  through @amicode/schema's reader verbatim — contract validation + base defaults +
  D1 epoch-bound freshness; absent/broken are NAMED rendered states (refresh pointer /
  the reader's loud rejection), never silent fallthrough to raw files
- readFleetTopologyWithRefresh: the verb seam (amico fleet status --projection — the
  CLI is the only door); refresh on absent/broken/unknown-freshness; exit 75 and
  CLI-absent produce the IDENTICAL stated base-standalone bootstrap; a verb failure
  is surfaced as the honest non-bootstrap state it is
…itch, freshness surfaces (P3b-2 commit 3)

- fleet_fallback.ts is now a WRITER only (the raw readers are GONE — the read path
  is fleet_topology's alone); migrateLegacyFallback/goStandalone paths injectable
- fleet_health.ts: the four checks consume the FleetTopologyState — absent renders
  base-default standalone WITH the refresh pointer, broken is a rendered FAIL
  carrying the reader's rejection + the fix, the D1 verdict surfaces in the detail
- extension.ts: isFleetClientGuard routes through readFleetTopologyWithRefresh
  (verb runner PATH-augmented with the launcher dir, the same resolution the server
  spawn uses); the status bar renders role + freshness badge + advisory;
  Go Standalone refreshes the projection cache through the verb after the write
  (the coherence rule); restart-hub + restart-server read the projection topology
- terminal.ts: the AMICO_FLEET_STANDALONE hint flows through fleet_topology —
  the inline raw parse is gone; the legacy marker stays an existence probe
- fleet_topology gains fleetConfigOf (hub flows) + verbRunnerWithPaths
- new source-scan guard test: the extension module set parses no raw fleet config
…ep reads are gone (P3b-2 commit 4)

- guard: reads the verb-refreshed projection cache (~/.amico/ops/fleet/projection.json),
  pinned to contract v1 (an artifact speaking another contract is unusable, never guessed
  from); absent/unusable cache refreshes ONCE through the verb (CLI ladder: PATH → the
  known dev-checkout launchers); exit 75 and CLI-absent are the IDENTICAL stated
  base-standalone bootstrap (grant pointer, mode untouched); a verb FAILURE fails closed
  with the repair path — a client never silently forks on an unreadable topology
- installer: shells the verb (machine-parseable JSON — the additive role/canonical
  fields); exit 75 + CLI-absent → the identical base-standalone bootstrap branch (exit 0,
  the solo floor untouched); non-75 verb failure or unparseable output dies honestly;
  the verb run keeps the projection cache warm for the other consumers
- assert_fleet_guard.sh (CI gate) now enforces the #1106 convention: projection cache
  reference + verb door + contract pin in the guard; verb + no-FLEET_CONFIG-grep in the
  installer; fleet_topology consumer import in fleet_health
- both copies (tools/fleet + the VSIX's packaged copy) byte-identical; script behavior
  driven through real bash execs with fabricated HOME/PATH + a fake amico (18 cases)
…F1 triple-consumer replay + n_fleet_topology_parsers==1 (P3b-2 commit 5)

- opencode-plugin/stack_state.ts: readFleetRole reads the projection cache's topology
  section (AMICO_FLEET_PROJECTION override replaces AMICO_FLEET_CONFIG) — the plugin
  is a projection consumer, dependency-free, silent-on-optional (absent/broken → no
  fleet section, byte-identical to the standalone base; never a raw-file fallback);
  the health read (fleet-status.json) is untouched — row 6's slice owns that
- stack_state tests: projection fixtures (server/client/absent/mode-only/corrupt)
- new fleet_f1_triple_consumer_replay.test.ts — spec §8 F1: the SAME absent/
  broken/stale topology cases through all THREE consumers (extension unit seam +
  real bash guard/installer execs with fabricated HOME/PATH + a fake amico), and
  the counter: ZERO raw fleet-config parsers on the amicode side (source-scanned
  across src, the plugin, and both script copies) + the ONE parser pinned behind
  the CLI door (the verb's python3 -m fleet_authority invocation + @amicode/schema
  reader) == n_fleet_topology_parsers == 1
@aarontrowbridge aarontrowbridge added the hitl Needs human review before merge label Sep 13, 2026
@coderabbitai

coderabbitai Bot commented Sep 13, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 4d564e1a-ef85-49e6-85e8-7250558c6c4a


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@aarontrowbridge
aarontrowbridge merged commit 9be7ba5 into main Sep 14, 2026
9 of 10 checks passed
aarontrowbridge added a commit that referenced this pull request Sep 14, 2026
fix: restore main CI — platform-aware installer test + the F28 doctrine obeys its own rule (#1109 follow-up)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hitl Needs human review before merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant