Skip to content

fix: keep installer internals out of human errors - #23

Merged
xxchan merged 1 commit into
mainfrom
wug/humanize-installer-errors
Sep 29, 2026
Merged

xxchan merged 1 commit into
mainfrom
wug/humanize-installer-errors

Conversation

@iynewz

@iynewz iynewz commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Requirement Challenge

The product requirement is not to hide failures or weaken rollback. The k-carrier Voice contract requires every non-success result to keep two separate values: a human reason and a stable machine code; the human output line contains no code, while raw causes stay internal. The smallest sufficient change is a central receipt/reply contract plus truthful, state-aware rendering and bounded private diagnostics. It does not change upgrade, rollback, lifecycle, release, or publication behavior.

What changed

  • Add a fixed FailureCode enum and make every current non-success Receipt and structured Reply carry paired human reason and stable code fields. Old on-disk receipts remain readable through a bounded legacy_failure fallback.
  • Move raw K/host/source causes to internal detail.diagnostic; current code no longer emits raw detail.reason, detail.error, or detail.upgradeError fields.
  • Preserve worker errors that have no receipt in a private structured Reply.diagnostic, visible only through JSON. Preserve top-level launcher errors in atomic mode-0600 cli-*.json records, retaining at most 16; configuration failures that make the state root unknowable fail closed instead of guessing a directory.
  • Keep output lines code-free and state-aware. Rollback copy distinguishes pre-running/post-running, pre-running/post-stopped, and pre-stopped/post-stopped outcomes; generic copy says “Nothing was changed” only when the existing untouched evidence proves it.
  • Keep human output to at most one runnable next step. Direct-caller, worker stderr, recovery, generic fallback, and foreign-manager paths no longer expose internal errors, process terms, or the support-file path. Manager-owned installs direct users back to that manager rather than telling them to remove files.
  • Add real-process and structured-output contracts for rollback, recovery, generic errors, top-level errors, caller rejection, and foreign-manager/link states. Human reasons use the same runtime forbidden-term checker as stdout/stderr; codes must belong to the fixed enum; raw detail may exist only on internal diagnostic surfaces.

Validation

  • python3 scripts/build.py --output dist --fixtures: darwin-arm64 production binary and fixtures built.
  • python3 scripts/verify.py --no-build: Rust 17/17; native/Python 86 passed, 3 platform skips; format and clippy -D warnings clean.
  • Controlled mutation: removing Reply.diagnostic makes the real worker-execute failure test fail with the missing diagnostic.
  • Controlled mutation: removing the top-level diagnostic write makes the bounded mode-0600 record test fail 0 != 16.
  • Controlled mutation: restoring the support-file name/path to the held line makes the real foreign-manager/link test fail on the exact unsafe line.
  • Earlier controls: feeding detail.diagnostic into human reason, changing a fixed code to an unknown value, reintroducing a raw rollback cause, and reintroducing top-level {error} each make their dedicated contract fail.
  • git diff --check clean; final worktree clean.

Automate-readiness

The permanent checks exercise built processes, separate human output from structured/private diagnostics, verify the stable code set, verify bounded 0600 persistence, and prove internal detail cannot satisfy the human-reason contract. They bind the exact state branches that decide whether “Nothing was changed”, a manager update, or a raft-computer start step is truthful.

Source-only change. No merge, release, publish, or channel/CDN mutation is included.

@iynewz
iynewz force-pushed the wug/humanize-installer-errors branch from 33c72fa to 52230ef Compare September 29, 2026 15:25
Signed-off-by: Wug <wug@mail.build>
@iynewz
iynewz force-pushed the wug/humanize-installer-errors branch from 52230ef to a1a5cab Compare September 29, 2026 15:44
@xxchan
xxchan merged commit f7cfe3a into main Sep 29, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants