fix: keep installer internals out of human errors - #23
Merged
Merged
Conversation
iynewz
force-pushed
the
wug/humanize-installer-errors
branch
from
September 29, 2026 15:25
33c72fa to
52230ef
Compare
Signed-off-by: Wug <wug@mail.build>
iynewz
force-pushed
the
wug/humanize-installer-errors
branch
from
September 29, 2026 15:44
52230ef to
a1a5cab
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requirement Challenge
The product requirement is not to hide failures or weaken rollback. The k-carrier Voice contract requires every non-success result to keep two separate values: a human
reasonand a stable machinecode; the human output line contains no code, while raw causes stay internal. The smallest sufficient change is a central receipt/reply contract plus truthful, state-aware rendering and bounded private diagnostics. It does not change upgrade, rollback, lifecycle, release, or publication behavior.What changed
FailureCodeenum and make every current non-successReceiptand structuredReplycarry paired humanreasonand stablecodefields. Old on-disk receipts remain readable through a boundedlegacy_failurefallback.detail.diagnostic; current code no longer emits rawdetail.reason,detail.error, ordetail.upgradeErrorfields.Reply.diagnostic, visible only through JSON. Preserve top-level launcher errors in atomic mode-0600cli-*.jsonrecords, retaining at most 16; configuration failures that make the state root unknowable fail closed instead of guessing a directory.untouchedevidence proves it.Validation
python3 scripts/build.py --output dist --fixtures: darwin-arm64 production binary and fixtures built.python3 scripts/verify.py --no-build: Rust 17/17; native/Python 86 passed, 3 platform skips; format and clippy-D warningsclean.Reply.diagnosticmakes the real worker-execute failure test fail with the missing diagnostic.0 != 16.detail.diagnosticinto humanreason, changing a fixed code to an unknown value, reintroducing a raw rollback cause, and reintroducing top-level{error}each make their dedicated contract fail.git diff --checkclean; final worktree clean.Automate-readiness
The permanent checks exercise built processes, separate human output from structured/private diagnostics, verify the stable code set, verify bounded 0600 persistence, and prove internal detail cannot satisfy the human-reason contract. They bind the exact state branches that decide whether “Nothing was changed”, a manager update, or a
raft-computer startstep is truthful.Source-only change. No merge, release, publish, or channel/CDN mutation is included.