From c05e69a3eb67f521ac1c5ed78d168f8fad1ab4f8 Mon Sep 17 00:00:00 2001 From: Michael Pursifull Date: Thu, 1 Oct 2026 23:03:52 -0500 Subject: [PATCH] =?UTF-8?q?finding(sideshow):=20question-five-layer-doctor?= =?UTF-8?q?=20=E2=80=94=20findings=20006=20and=20007=20from=20the=20xorml?= =?UTF-8?q?=20harvest?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Refs: aae-orc-xorml, aae-orc-mobz8, aae-orc-wk92 --- ...ed-a-manifest-that-travels-with-content.md | 30 +++++++++++++++++++ .../finding-007-install-never-deletes.md | 27 +++++++++++++++++ .../frontier/question-five-layer-doctor.yaml | 7 +++++ 3 files changed, 64 insertions(+) create mode 100644 _kos/findings/finding-006-doctor-census-trusted-a-manifest-that-travels-with-content.md create mode 100644 _kos/findings/finding-007-install-never-deletes.md diff --git a/_kos/findings/finding-006-doctor-census-trusted-a-manifest-that-travels-with-content.md b/_kos/findings/finding-006-doctor-census-trusted-a-manifest-that-travels-with-content.md new file mode 100644 index 0000000..586340f --- /dev/null +++ b/_kos/findings/finding-006-doctor-census-trusted-a-manifest-that-travels-with-content.md @@ -0,0 +1,30 @@ +# finding-006: doctor's content census trusted a manifest that travels with the content it checks + +**Date:** 2026-10-02 +**Subject:** how `sideshow doctor` decides an installed store version is intact +**Occasion:** aae-orc-xorml half 2 (sideshow#138, #139) and aae-orc-mobz8 +**Evidence:** `internal/doctor/layer1.go` `checkContentCensus` at `c33fdd2`; an end-to-end run in a fresh +store with a bmad 6.12.0 pack built after sideshow-packs#40; the operator ruling relayed on 2026-09-30. + +## Why this is worth writing down + +An integrity check is only as good as the reference it compares against. If the reference arrives with the +content, replacing the content replaces the reference too, and the check passes. + +## What was observed + +- `store-content-census` reads bmad's own `_config/files-manifest.csv`. That file is part of the pack + content, so an `install --from` over an installed version (mobz8's case) brings or keeps a census that + agrees with whatever was copied. mobz8 recorded `store-content-census [ok]` after such an overwrite. +- #139 added `store-file-manifest`, which recomputes every store file against the pipeline's + `file-manifest.csv` (inside the tarball since sideshow-packs#40). In a fresh store: a clean install reports + `2023 files match`; an overwrite from a copy with one edited `SKILL.md` and no manifest reports + `1 differ (first: .claude/skills/bmad-agent-architect/SKILL.md)` while `store-freeze` still reports ok; + the published r2 reports unavailable. + +## The remaining gap, and the ruling + +The pipeline manifest is still only as trustworthy as the install source: an overwrite from a tree that +ships its own consistent `file-manifest.csv` is not detected. sideshow does not see the release signature +or `install.meta` until install fetches and verifies signed tarballs (aae-orc-wk92). The operator ruled +"yes default" on 2026-09-30: ship #139 as is, and anchoring to the signed copy waits on wk92. diff --git a/_kos/findings/finding-007-install-never-deletes.md b/_kos/findings/finding-007-install-never-deletes.md new file mode 100644 index 0000000..b8d5be2 --- /dev/null +++ b/_kos/findings/finding-007-install-never-deletes.md @@ -0,0 +1,27 @@ +# finding-007: install copies over an existing store version and never deletes + +**Date:** 2026-10-02 +**Subject:** `InstallFromLocal` over an already-installed version +**Occasion:** the same end-to-end run as finding-006 +**Evidence:** `internal/pack/pack.go` `InstallFromLocal` at `1b5d716` (a WalkDir copy with no removal step); +the overwrite run in finding-006, where a manifest from the first install survived an overwrite from a tree +that had none. + +## Why this is worth writing down + +A reinstall reads as "the store now holds this source". It does not: the store holds the union of every +source installed at that version. That changes what a doctor finding means and what a reinstall can fix. + +## What was observed + +- The copy walks the source and writes each file; nothing removes store files the source does not have. +- In finding-006's overwrite, the source had no `file-manifest.csv`, and doctor still read one: the file + from the earlier install had survived. That is why `store-file-manifest` caught the edit. +- The same property means a file dropped between two builds of one version stays in the store after a + reinstall, and binding sync may keep serving it. + +## Open + +Whether a reinstall should replace the version directory (stage, then swap) rather than copy over it. That +is install-path design, close to mobz8's refuse-or-force question, and is not decided here. doctor's +`unlisted` count in `store-file-manifest` is the current way to see leftovers. diff --git a/_kos/nodes/frontier/question-five-layer-doctor.yaml b/_kos/nodes/frontier/question-five-layer-doctor.yaml index e610901..384509f 100644 --- a/_kos/nodes/frontier/question-five-layer-doctor.yaml +++ b/_kos/nodes/frontier/question-five-layer-doctor.yaml @@ -31,6 +31,13 @@ content: | `aae-orc-e1jj` (the known-defects feed format) + `aae-orc-ztg5` (the registry itself). + Layer 1 progress (2026-10-02): finding-006 found the content census + trusted bmad's own manifest, which an overwrite replaces; #139 added + store-file-manifest against the pipeline manifest, and anchoring it to + the signed release waits on aae-orc-wk92 (operator ruling). finding-007: + install never deletes, so a store version holds the union of every + source installed at that version. + Open sub-questions: - Layer 2 spec separately or fold into the weaving engine? - When should layer 3 escalate from warn to error?