Skip to content

feat(schema): nix.installer.expected_sha256 + NIX_INSTALLER_REQUIRED contract#55

Merged
UnbreakableMJ merged 1 commit into
mainfrom
feat/schema-nix-installer
Apr 28, 2026
Merged

feat(schema): nix.installer.expected_sha256 + NIX_INSTALLER_REQUIRED contract#55
UnbreakableMJ merged 1 commit into
mainfrom
feat/schema-nix-installer

Conversation

@UnbreakableMJ

Copy link
Copy Markdown
Contributor

Summary

First M4 W1 code chunk: lays the foundation for ADR-0012's pearlite bootstrap subcommand by adding the per-host nix declaration to the schema.

  • New pearlite_schema::NixDecl and NixInstallerDecl types in nix.rs. Wired through lib.rs and as DeclaredState::nix: Option<NixDecl>.
  • New cross-field contract NIX_INSTALLER_REQUIRED: when any user has home_manager.enabled = true, the host's nix.installer.expected_sha256 must be present and well-formed (64 lowercase hex chars). HM-disabled hosts may omit the block.
  • host_full.toml fixture extended with a [nix.installer] table so the existing validate_clean_full_fixture test keeps passing.
  • Four new validator tests covering: missing block when HM is on, malformed sha, uppercase hex (rejected per ADR pin convention), and HM-disabled-everywhere (block becomes optional).

Per ADR-0012: the SHA pin lives next to the consumer (host file) — operators bump it per-host when Determinate ships a new installer version. No repo-wide bootstrap.toml, no Pearlite-baked release constant.

Test plan

  • cargo test --workspace --all-features — 307 passing (+4 new)
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — clean
  • cargo fmt --all -- --check — clean
  • scripts/ci/check-spdx.sh — clean
  • pearlite-audit check . — 1 check, 0 violations
  • CI green on T1 / T2 / T3

🤖 Generated with Claude Code

…contract

Adds the per-host Nix bootstrap declaration that ADR-0012 routes
through `pearlite bootstrap`: the Determinate installer's SHA-256
pin lives next to the consumer (the host that needs it), not in a
repo-wide bootstrap file.

- New `pearlite_schema::NixDecl` and `NixInstallerDecl` types in
  `nix.rs`. Wired through `lib.rs` and as `DeclaredState::nix:
  Option<NixDecl>` (default None).
- New cross-field contract `NIX_INSTALLER_REQUIRED`: when any user
  has `home_manager.enabled = true`, the host's
  `nix.installer.expected_sha256` must be present and well-formed
  (64 lowercase hex chars). HM-disabled hosts may omit the block.
- `host_full.toml` fixture grows a `[nix.installer]` table so the
  pre-existing `validate_clean_full_fixture` keeps passing under
  the new contract.
- Four new validator tests covering the four cases (missing block
  with HM, malformed sha, uppercase hex, HM-disabled-everywhere).

Tests: 307 passing (was 303, +4). Clippy clean. fmt clean. audit clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@UnbreakableMJ
UnbreakableMJ merged commit 2f875d0 into main Apr 28, 2026
3 checks passed
@UnbreakableMJ
UnbreakableMJ deleted the feat/schema-nix-installer branch April 28, 2026 22:10
UnbreakableMJ added a commit that referenced this pull request May 5, 2026
* docs(todo): refresh post-#65 reconcile + bootstrap status

TODO.md was 8 days stale. Marks the M4 W1 reconcile read-side
(Engine::reconcile, #65) as done; resolves the M3 W1 runuser /
per-user nix.conf line as the bootstrap stack (#55-#58) plus
ADR-0013 (Home Manager owns per-user nix.conf); updates the
M3 W2 vm-09 prose to reflect that vm-09-nix-bootstrap.sh
shipped in M4 W1 (#59) rather than remaining deferred.

Bumps Last updated to 2026-05-04.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cli): pearlite reconcile subcommand wires Engine::reconcile

Read-only CLI surface for the M4 W1 reconcile read-side that
landed in #65. Adds Command::Reconcile (no flags), dispatch_reconcile,
reconcile_outcome_view, and reconcile_error_payload mapping every
pearlite_engine::ReconcileError variant to a typed error code:

  RECONCILE_PROBE_FAILED       — probe adapter failure
  RECONCILE_EMPTY_HOSTNAME     — /etc/hostname is blank
  RECONCILE_INVALID_HOSTNAME   — `/`, `\`, or NUL in hostname
  RECONCILE_ALREADY_EXISTS     — refuses to clobber operator review
  RECONCILE_IO_FAILED          — mkdir or atomic-write failure

All five are class=preflight, exit_code=2 — reconcile is read-only
with respect to state.toml; the only system-side effect is the
atomic write of <config_dir>/hosts/<hostname>.imported.ncl, and a
failed write leaves the operator's config repo untouched (tempfile
is dropped before rename).

Three dispatch tests cover the happy path (writes the imported.ncl
to disk and returns hostname + path in the envelope), the
already-exists guard (pre-seeded file is preserved verbatim), and
the metadata.command label.

Out of scope for this chunk:
- `--commit` and `--adopt-all` flags (need Engine::reconcile_commit)
- vm-10-reconcile-fresh-install.sh

Refs: PRD §11, Plan §7.5

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* style(cli): rustfmt reconcile dispatch tests

Two mechanical wrappings flagged by `cargo fmt --all --check`:
- assert! is_file() chain breaks across lines
- let preserved = ... fits on a single line at 100 cols

No behavior change.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(cli): extract dispatch_plan_or_status to fit too_many_lines

Adding `Command::Reconcile` pushed `dispatch()` to 101 lines (clippy
limit is 100). Pulled the inline Plan/Status arm into
`dispatch_plan_or_status`, mirroring the existing extraction pattern
for Apply, Bootstrap, Reconcile, etc. Behavior is identical;
read-only test run via cargo test -p pearlite-cli passes 42 tests
under WSL Arch.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(vm): vm-10 reconcile-fresh-install scenario

Verifies the read-side reconcile pipeline end-to-end against the
`pearlite reconcile` CLI shipped earlier in this branch.

Phase A (happy path):
- exit 0
- envelope: command=pearlite reconcile, hostname non-empty,
  imported_path resolves to <sandbox>/repo/hosts/<hostname>.imported.ncl
- on-disk file contains the Nickel record markers emit_host produces
  (meta = {, kernel = {, packages = {, services = {)

Phase B (clobber refusal):
- re-running with the same --config-dir exits 2 with
  RECONCILE_ALREADY_EXISTS, class=preflight
- the original .imported.ncl is byte-identical to the Phase A
  capture (cmp -s)

Whitelisted alongside vm-01 in scripts/ci/run-vm-tests.sh -- vm-10 is
read-only with respect to system state (only mutation is a single
Nickel file inside a tempdir), so it runs unconditionally without
PEARLITE_VM_TEST=1.

Verified locally via WSL Arch:
  bash tests/vm/vm-10-reconcile-fresh-install.sh -> PASS

Refs: PRD §11, Plan §7.5

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(todo): mark vm-10 reconcile-fresh-install done

Shipped earlier in this branch (commit 3d22c36) and verified locally
via WSL Arch.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(agents): document pearlite reconcile flow + error codes

Adds a Reconcile-flow section enumerating the five RECONCILE_*
error codes and the read-only / interactive split, so future agents
can discover the surface without re-deriving it from dispatch.rs.

Notes the users / config empty-array placeholders as intentional
per PRD §11, references vm-10 for end-to-end coverage, and points at
the M4 W1 remainder (reconcile --commit).

Bumps Last updated to 2026-05-04.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant