80 lines
3.8 KiB
Markdown
80 lines
3.8 KiB
Markdown
# Worker Cheatsheet Validation - 2026-09-30
|
|
|
|
## Scope
|
|
|
|
Validation used isolated fake device tokens, private local state roots, a local
|
|
TLS no-work fixture, unique Docker names/volumes, and fresh artifacts. It did not
|
|
contact production, issue assignments, or use production credentials.
|
|
|
|
## Initial audit
|
|
|
|
- Windows package exposed install, start, stop, status, attach, logs, history,
|
|
and doctor; `watch` was rejected as an invalid command.
|
|
- The Linux image exposed the same command set, but an assembled native Linux
|
|
package had no package-root launcher or preparation workflow.
|
|
- First installation required token-bearing process arguments. Later lifecycle
|
|
commands already read the private installed JSON configuration.
|
|
- Active quickstart and operations instructions recommended server cap zero for
|
|
routine local maintenance.
|
|
- An unreachable-server negative check made `stop --timeout 120` return a
|
|
non-drained receipt with exit code 2 instead of reporting false success.
|
|
|
|
## Fresh artifact identities
|
|
|
|
| Artifact | Identity |
|
|
| --- | --- |
|
|
| Final Windows ZIP SHA-256 | `210eb61e8d6c35b014b39b18b4dd7e28e1e057a11d57790188f7904487bac004` |
|
|
| Windows package manifest | `4572e349cead890c4efdc113e4d41285981086db7c0783fb67493fdeb6bac04c` |
|
|
| Linux/Docker image | `sha256:8bc99d9e7e5f5f364de9b7d2b30100942b5ce3d9170a64e5abf0068ffc3d02c4` |
|
|
| Linux package manifest | `19907f29382bd2b5a1de13fd53a829e97a5626fbacbed8f4286071ba4d5a9bec` |
|
|
|
|
The final Windows ZIP was rebuilt after the last documentation correction. Its
|
|
full lifecycle run used the same package-manifest identity; the rebuild changed
|
|
only packaged operator-document bytes outside worker code authority.
|
|
|
|
## Checked command matrix
|
|
|
|
| Environment | YAML install | Doctor | Start | Status | Attach | Watch | Stop |
|
|
| --- | --- | --- | --- | --- | --- | --- | --- |
|
|
| Windows package | pass | pass | pass | pass | pass | pass | `drained=true`, `exit_code=0` |
|
|
| Native Linux package under `/opt` | pass | pass | pass | pass | pass | pass | `drained=true`, `exit_code=0` |
|
|
| Docker image with persistent volume | stdin pass | pass | pass | pass | pass | pass | `drained=true`, `exit_code=0` |
|
|
|
|
The stopped Docker container reported `status=exited`, `exit=0`, and
|
|
`oom=false`. `attach` and `watch` detached without stopping the verified worker
|
|
on every environment.
|
|
|
|
## Documentation result
|
|
|
|
The active general guide and operations runbook contain no cap-zero routine and
|
|
no token-bearing install command. Separate Windows, native Linux, and Docker
|
|
cheatsheets contain copy-paste install, start, stop, attach, status, and watch
|
|
commands. Historical dated validation reports retain factual records of earlier
|
|
cap-zero experiments and are not active instructions.
|
|
|
|
## Final gates
|
|
|
|
- Focused worker/package/documentation matrix: `157 passed, 3 skipped`.
|
|
- Windows packaged `watch --help`: pass.
|
|
- Linux image launcher, preparation script, packaged cheatsheets, and shell
|
|
syntax smoke: pass.
|
|
- Worker Compose rendering: pass.
|
|
- Python compilation: pass.
|
|
- Strict OpenSpec validation: pass.
|
|
|
|
## Release build
|
|
|
|
The final `dist/release-20260930-linux` release includes both native Linux and
|
|
Docker Linux artifacts plus all platform sheets under `cheatsheets/`. All
|
|
entries in `SHA256SUMS.txt` passed verification. The Docker bundle also contains
|
|
the sheets and both `workerctl` helpers, and all eight internal checksums passed.
|
|
The native archive contained no absolute paths, parent traversal, or links; its
|
|
launchers retained mode 0755 and passed an extracted `/opt` preparation and CLI
|
|
smoke test.
|
|
|
|
| Release artifact | SHA-256 |
|
|
| --- | --- |
|
|
| Native Linux package | `e44717c9e84fc73d1d0734189da5b809c1c2271648868c05caea954bf46f6ebc` |
|
|
| Docker Linux image archive | `80a59f180e7c1e4e5861427d94b44605a54ba08ed12198c63c3ae98c35678f63` |
|
|
| Trusted Linux package manifest | `a3e8b73855d3b0854c5891cb5a10ff892aa0929e24046d2ce6fd28a245317e82` |
|