Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# finding-006: doctor's content census trusted a manifest that travels with the content it checks

**Date:** 2026-10-02
**Subject:** how `sideshow doctor` decides an installed store version is intact
**Occasion:** aae-orc-xorml half 2 (sideshow#138, #139) and aae-orc-mobz8
**Evidence:** `internal/doctor/layer1.go` `checkContentCensus` at `c33fdd2`; an end-to-end run in a fresh
store with a bmad 6.12.0 pack built after sideshow-packs#40; the operator ruling relayed on 2026-09-30.

## Why this is worth writing down

An integrity check is only as good as the reference it compares against. If the reference arrives with the
content, replacing the content replaces the reference too, and the check passes.

## What was observed

- `store-content-census` reads bmad's own `_config/files-manifest.csv`. That file is part of the pack
content, so an `install --from` over an installed version (mobz8's case) brings or keeps a census that
agrees with whatever was copied. mobz8 recorded `store-content-census [ok]` after such an overwrite.
- #139 added `store-file-manifest`, which recomputes every store file against the pipeline's
`file-manifest.csv` (inside the tarball since sideshow-packs#40). In a fresh store: a clean install reports
`2023 files match`; an overwrite from a copy with one edited `SKILL.md` and no manifest reports
`1 differ (first: .claude/skills/bmad-agent-architect/SKILL.md)` while `store-freeze` still reports ok;
the published r2 reports unavailable.

## The remaining gap, and the ruling

The pipeline manifest is still only as trustworthy as the install source: an overwrite from a tree that
ships its own consistent `file-manifest.csv` is not detected. sideshow does not see the release signature
or `install.meta` until install fetches and verifies signed tarballs (aae-orc-wk92). The operator ruled
"yes default" on 2026-09-30: ship #139 as is, and anchoring to the signed copy waits on wk92.
27 changes: 27 additions & 0 deletions _kos/findings/finding-007-install-never-deletes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# finding-007: install copies over an existing store version and never deletes

**Date:** 2026-10-02
**Subject:** `InstallFromLocal` over an already-installed version
**Occasion:** the same end-to-end run as finding-006
**Evidence:** `internal/pack/pack.go` `InstallFromLocal` at `1b5d716` (a WalkDir copy with no removal step);
the overwrite run in finding-006, where a manifest from the first install survived an overwrite from a tree
that had none.

## Why this is worth writing down

A reinstall reads as "the store now holds this source". It does not: the store holds the union of every
source installed at that version. That changes what a doctor finding means and what a reinstall can fix.

## What was observed

- The copy walks the source and writes each file; nothing removes store files the source does not have.
- In finding-006's overwrite, the source had no `file-manifest.csv`, and doctor still read one: the file
from the earlier install had survived. That is why `store-file-manifest` caught the edit.
- The same property means a file dropped between two builds of one version stays in the store after a
reinstall, and binding sync may keep serving it.

## Open

Whether a reinstall should replace the version directory (stage, then swap) rather than copy over it. That
is install-path design, close to mobz8's refuse-or-force question, and is not decided here. doctor's
`unlisted` count in `store-file-manifest` is the current way to see leftovers.
7 changes: 7 additions & 0 deletions _kos/nodes/frontier/question-five-layer-doctor.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,13 @@ content: |
`aae-orc-e1jj` (the known-defects feed format) + `aae-orc-ztg5`
(the registry itself).

Layer 1 progress (2026-10-02): finding-006 found the content census
trusted bmad's own manifest, which an overwrite replaces; #139 added
store-file-manifest against the pipeline manifest, and anchoring it to
the signed release waits on aae-orc-wk92 (operator ruling). finding-007:
install never deletes, so a store version holds the union of every
source installed at that version.

Open sub-questions:
- Layer 2 spec separately or fold into the weaving engine?
- When should layer 3 escalate from warn to error?
Expand Down
Loading