test(installtest): 3-OS daemon-path setup-executor engine install leg (waired#835 §9/§11) - #127
Merged
Merged
Conversation
… (waired#835 §9/§11) The waired#835 §9/§11 setup executor engine install — the resident `sudo waired init` attaching a management-API lease and installing the engine the daemon-path first-run needs — was covered only by unit tests. No installtest leg exercised it end to end, because the two hands-free enrol modes the harness uses (`--google-sa-login`, `--bypass-mode`) both FORCE the standalone enrol path (cmd/waired/main.go gates the daemon path on `!bypassMode && !googleSALogin && !renewing && daemonReachable`). Since #119 the installer starts the daemon before `waired init`, so a real fresh first-run now takes the DAEMON path — the exact path the harness never drove. New `--daemon-engine` / `-DaemonEngine` leg (its own mode; Tier 2) on all three drivers, run nightly as a 3-OS job in installtest-inference.yml: - Leaves the service RUNNING and installs with the engine ABSENT (install.sh/.ps1 keep --skip-ollama), so only the daemon-path executor can put an engine on the host. - Runs `waired init` WITHOUT --google-sa-login (→ daemon path) and with --non-interactive (→ awaitBrowserSetup returns at once → the resident executor runs ensureDaemonPathEngine), inference on + a tiny pinned model so the trailing pull stays cheap. - Completes the login hands-free by SCRAPING the login-session id from the init transcript (the login URL's last path segment) and POSTing the host-minted SA id_token to the CP's /v1/login/oidc-grant — which flips any waiting session, whatever created it. Scrape, not POST /login/start: the #838 writeGuard refuses mgmt writes on the TCP port (they must use the local IPC socket / named pipe), and reads dodge it. - Asserts (via GET /waired/v1/setup/state — a read): the enrol took the daemon path, the OIDC completion succeeded, the executor lease went live (executor_attached) and claimed the ollama install (install_claimed), an engine is present afterward (the regression bar — pre-N3 it stayed engine-less forever), the subsystem left no_engine, and no install claim is stuck after init (§9-4). Not asserting setup-progress engine_install=done / setup_state.engine_installed here: those require a CP-served desired_engine (a browser-wizard / management write the hands-free harness has no auth for), so that path stays unit-tested; this leg proves the resident executor installs the engine on the real daemon-path first-run. Linux logic lives in the new scripts/dev/lib/installtest-daemon-engine.sh (kept out of installtest-enroll.sh to avoid churn); macOS/Windows mirror it inline. Cannot be validated locally (real-CP OIDC + a real engine install + self-hosted Windows/macOS runners) — needs a nightly workflow_dispatch run. shellcheck / pwsh-parse / actionlint all clean. Refs waired-ai/waired#835 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: gen16k <gen16k@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The waired#835 §9/§11 setup executor engine install — the resident
sudo waired initattaching a management-API lease and installing the engine on the daemon-path first-run (ensureDaemonPathEngine/runSetupEngineInstall,internal/management/setup_handlers.go+cmd/waired/{login_client,setup_install,init_daemon_inference}.go) — was covered only by unit tests. No installtest leg exercised it end to end.The reason: the two hands-free enrol modes the harness uses —
--google-sa-login(oidc) and--bypass-mode— both force the standalone enrol path (cmd/waired/main.gogates the daemon path on!bypassMode && !googleSALogin && !renewing && daemonReachable). On the standalone path the engine, when installed at all, comes frominstall.sh/configureInference, never the executor. And since #119 the installer starts the daemon beforewaired init, so a real fresh first-run now takes the daemon path — the exact path the harness never drove.This is PR-P of the N3 plan.
What this adds
A new
--daemon-engine(bash) /-DaemonEngine(PowerShell) leg — its own mode, Tier 2 — on all three drivers, run nightly as a 3-OS job ininstalltest-inference.yml(a real engine install + tiny model pull is minutes-scale + external-state, exactly the nightly cost profile).Per OS leg:
install.sh/install.ps1keep--skip-ollama, so only the daemon-path executor can put an engine on the host.waired initWITHOUT--google-sa-login(→ daemon path) +--non-interactive(→awaitBrowserSetupreturns at once → the resident executor runsensureDaemonPathEngine), inference on + a tiny pinned model so the trailing pull is cheap.POST /login/start: the id is the login URL's last path segment (lastPathSegment) read from the init transcript, and the host-minted SA id_token is POSTed to the CP's/v1/login/oidc-grant, which completes any waiting session regardless of what created it (internal/controlplane/api/oidc_grant.go).GET /waired/v1/setup/state— a read): the enrol took the daemon path; the OIDC completion succeeded; the executor lease went live (executor_attached) and claimed the ollama install (install_claimed); an engine is present afterward (the regression bar — pre-N3 an engine-less daemon-path host stayed engine-less andengine_installwas red forever); the subsystem leftno_engine; and no install claim is stuck after init (§9-4).Two design points worth calling out
POST /login/start. The coding-agent TTFT: every turn pays full-context prefill before the first token — measure and design prompt/KV reuse #838writeGuardrefuses mgmt writes on the TCP port (they must use the local IPC socket / named pipe — which plaincurl/Invoke-RestMethodcan't reach, especially the Windows named pipe). Scraping the transcript and reading/setup/statestay on the allowed read path; the only writes go to the CP (oidc-grant), which has no such guard.setup-progress engine_install=done/setup_state.engine_installedwould require a CP-serveddesired_engine— a browser-wizard / management-API write the hands-free harness has no auth for. That path stays unit-tested (setup_desired_test.go,setup_handlers_test.go,init_daemon_inference_test.go); this leg proves the resident executor installs the engine on the real daemon-path first-run, observed throughexecutor_attached/install_claimed(lease-derived, nodesired_engineneeded) + engine presence.Files
scripts/dev/lib/installtest-daemon-engine.sh(new) — Linuxit_enroll_daemon_path+assert_daemon_engine. Kept separate frominstalltest-enroll.sh(which has concurrent in-flight edits) to avoid churn/conflict.scripts/dev/installtest-run.sh—--daemon-engineflag, validation, memory cap, Tier-2 dispatch.scripts/dev/installtest-macos.sh/installtest-windows.ps1— the same flow mirrored inline (macOS bash / Windows PowerShellStart-Jobwatcher)..github/workflows/installtest-inference.yml— new 3-OSdaemon-enginejob on the existinglegsmatrix.No product code changed; no new
internal/packages (no testnet-gate impact); no user-facing CLI flags (nodocs-sitechange).Verification
shellcheck -x(lib clean; run.sh/macos only pre-existingSC2015info),bash -n,pwshAST parse (clean),actionlint(only pre-existing findings) — all green locally.app.dev.waired.net, a real engine install, and the self-hosted Windows/macOS runners. Requires a nightlyworkflow_dispatchrun ofinstalltest-inferenceto shake out. I'll fix any leg that fails there on this same branch before it's merge-ready.Refs
🤖 Generated with Claude Code