Skip to content

test(vm): vm-09 pearlite bootstrap idempotency#59

Merged
UnbreakableMJ merged 1 commit into
mainfrom
test/vm-09-bootstrap
Apr 28, 2026
Merged

test(vm): vm-09 pearlite bootstrap idempotency#59
UnbreakableMJ merged 1 commit into
mainfrom
test/vm-09-bootstrap

Conversation

@UnbreakableMJ

Copy link
Copy Markdown
Contributor

Summary

Closes the M3-rolled-forward vm-09-nix-bootstrap task per ADR-0012.

Two-step scenario:

  1. With nix already on PATH, run pearlite bootstrapinstall: "already" (nix --version short-circuits), nix_conf_written: true (sandbox starts without a nix.conf; the experimental-features line gets written).
  2. Re-run the same command → nix_conf_written: false (the line is already there, idempotent skip per ADR-0013).

The actual Determinate-installer execution path is intentionally NOT exercised here — doing that on the runner would mutate /nix and is unsafe outside a disposable image. ADR-004 SHA verification is unit-tested in pearlite-userenv. vm-09 covers the operational path operators hit on healthy (already-bootstrapped) hosts.

Gated behind PEARLITE_VM_TEST=1; expects nix and nickel-lang on PATH (VM-runner toolchain). README index updated.

This closes the M4 W1 carry-over from the M3 retrospective and rounds out ADR-0012's implementation surface (PRs #55#58 covered schema, engine, CLI subcommand, and apply preflight).

Test plan

  • sh -n vm-09-nix-bootstrap.sh — POSIX syntax clean
  • scripts/ci/check-spdx.sh — clean (script carries SPDX header)
  • pearlite-audit check . — 1 check, 0 violations
  • Local exec without nix runtime fails as expected (BOOTSTRAP_NICKEL_FAILED) — same precondition as vm-07 / vm-08; full run requires the CachyOS-VM runner per ADR-0009
  • CI green on T1 / T2 / T3 (vm tier runs separately on the self-hosted runner)

🤖 Generated with Claude Code

Closes the M3-rolled-forward `vm-09-nix-bootstrap` task per ADR-0012.
Two-step scenario:

1. With nix already on PATH, run `pearlite bootstrap` → install:
   "already" (nix --version short-circuits), nix_conf_written: true
   (sandbox starts with no nix.conf; the experimental-features line
   gets written).
2. Re-run the same command → nix_conf_written: false (the line is
   already in the file from step 1, idempotent skip per ADR-0013).

The Determinate-installer execution path is intentionally NOT
exercised here: doing that on the runner would mutate /nix and is
unsafe outside a disposable image. ADR-004 SHA verification is
unit-tested in pearlite-userenv. vm-09 covers the operational path
operators hit on healthy hosts.

Gated behind PEARLITE_VM_TEST=1; expects nix and nickel-lang on PATH
(VM-runner toolchain). README index updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@UnbreakableMJ
UnbreakableMJ merged commit 28cb66d into main Apr 28, 2026
3 checks passed
@UnbreakableMJ
UnbreakableMJ deleted the test/vm-09-bootstrap branch April 28, 2026 23:04
UnbreakableMJ added a commit that referenced this pull request May 5, 2026
* docs(todo): refresh post-#65 reconcile + bootstrap status

TODO.md was 8 days stale. Marks the M4 W1 reconcile read-side
(Engine::reconcile, #65) as done; resolves the M3 W1 runuser /
per-user nix.conf line as the bootstrap stack (#55-#58) plus
ADR-0013 (Home Manager owns per-user nix.conf); updates the
M3 W2 vm-09 prose to reflect that vm-09-nix-bootstrap.sh
shipped in M4 W1 (#59) rather than remaining deferred.

Bumps Last updated to 2026-05-04.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cli): pearlite reconcile subcommand wires Engine::reconcile

Read-only CLI surface for the M4 W1 reconcile read-side that
landed in #65. Adds Command::Reconcile (no flags), dispatch_reconcile,
reconcile_outcome_view, and reconcile_error_payload mapping every
pearlite_engine::ReconcileError variant to a typed error code:

  RECONCILE_PROBE_FAILED       — probe adapter failure
  RECONCILE_EMPTY_HOSTNAME     — /etc/hostname is blank
  RECONCILE_INVALID_HOSTNAME   — `/`, `\`, or NUL in hostname
  RECONCILE_ALREADY_EXISTS     — refuses to clobber operator review
  RECONCILE_IO_FAILED          — mkdir or atomic-write failure

All five are class=preflight, exit_code=2 — reconcile is read-only
with respect to state.toml; the only system-side effect is the
atomic write of <config_dir>/hosts/<hostname>.imported.ncl, and a
failed write leaves the operator's config repo untouched (tempfile
is dropped before rename).

Three dispatch tests cover the happy path (writes the imported.ncl
to disk and returns hostname + path in the envelope), the
already-exists guard (pre-seeded file is preserved verbatim), and
the metadata.command label.

Out of scope for this chunk:
- `--commit` and `--adopt-all` flags (need Engine::reconcile_commit)
- vm-10-reconcile-fresh-install.sh

Refs: PRD §11, Plan §7.5

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* style(cli): rustfmt reconcile dispatch tests

Two mechanical wrappings flagged by `cargo fmt --all --check`:
- assert! is_file() chain breaks across lines
- let preserved = ... fits on a single line at 100 cols

No behavior change.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(cli): extract dispatch_plan_or_status to fit too_many_lines

Adding `Command::Reconcile` pushed `dispatch()` to 101 lines (clippy
limit is 100). Pulled the inline Plan/Status arm into
`dispatch_plan_or_status`, mirroring the existing extraction pattern
for Apply, Bootstrap, Reconcile, etc. Behavior is identical;
read-only test run via cargo test -p pearlite-cli passes 42 tests
under WSL Arch.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(vm): vm-10 reconcile-fresh-install scenario

Verifies the read-side reconcile pipeline end-to-end against the
`pearlite reconcile` CLI shipped earlier in this branch.

Phase A (happy path):
- exit 0
- envelope: command=pearlite reconcile, hostname non-empty,
  imported_path resolves to <sandbox>/repo/hosts/<hostname>.imported.ncl
- on-disk file contains the Nickel record markers emit_host produces
  (meta = {, kernel = {, packages = {, services = {)

Phase B (clobber refusal):
- re-running with the same --config-dir exits 2 with
  RECONCILE_ALREADY_EXISTS, class=preflight
- the original .imported.ncl is byte-identical to the Phase A
  capture (cmp -s)

Whitelisted alongside vm-01 in scripts/ci/run-vm-tests.sh -- vm-10 is
read-only with respect to system state (only mutation is a single
Nickel file inside a tempdir), so it runs unconditionally without
PEARLITE_VM_TEST=1.

Verified locally via WSL Arch:
  bash tests/vm/vm-10-reconcile-fresh-install.sh -> PASS

Refs: PRD §11, Plan §7.5

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(todo): mark vm-10 reconcile-fresh-install done

Shipped earlier in this branch (commit 3d22c36) and verified locally
via WSL Arch.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(agents): document pearlite reconcile flow + error codes

Adds a Reconcile-flow section enumerating the five RECONCILE_*
error codes and the read-only / interactive split, so future agents
can discover the surface without re-deriving it from dispatch.rs.

Notes the users / config empty-array placeholders as intentional
per PRD §11, references vm-10 for end-to-end coverage, and points at
the M4 W1 remainder (reconcile --commit).

Bumps Last updated to 2026-05-04.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant