Skip to content

docs(design): record D58-D60 and sharpen the install-route rows - #528

Merged
wstein merged 12 commits into
mainfrom
docs/399-design-lane-batch
Oct 9, 2026
Merged

wstein merged 12 commits into
mainfrom
docs/399-design-lane-batch

Conversation

@wstein

@wstein wstein commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Design-lane batch from #399: D58 (alpha install policy, #493/#504), D59 (Homebrew bootstrap, option C, #505), D60 (OKF observed, not adopted, approved by Werner 2026-10-09), D30 CheckBoard options, darwin/arm64-only release host binary, CWE-78 row naming os.StartProcess, D24/T19 wording for the archive and checksums.txt binding (#524), and the open entry on the administrator's workspace roots now records the decided direction (the administrator's setup initializes the workharbor account; implementation pending on its own branch).

Opus review: CLEAR at 5ef0e0c (full review at f98ad455, narrowed review after the rebase and two fix commits). Docs build with panicOnWarning and docscheck passed in review.

Refs: #399

🤖 Generated with Claude Code

wstein and others added 12 commits October 9, 2026 13:51
CheckBoard checks Needs you, In progress and Done; a cancelled task
writes Todo and reports ErrBoard on a board without that option. Use
the narrower wording "which the development board no longer uses".

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Warn instead of refuse in the alpha, revisit at beta (#493, #504): whr
is refused only when it is not an executable file, and the --dev and
--managed flags and the development_prefix key are gone. D24, D34 and
D46, the setup wizard and launchd job text, and the threat model's
T18, T19 and accepted risk now say so; D24 names the release archive
as the first-install route. The known weaker point is recorded: the
supervisor may run a binary an agent could rewrite.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Werner chose option C of the bootstrap note (#505): setup downloads
Homebrew's install.sh, shows its path, URL and SHA-256 and runs it only
after the administrator confirms. The note's status now says decided
and built.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
The OKF v0.2 review on #399 by the design, docs and security lanes
found no reason to adopt the format. D60 records their proposal,
pending Werner's confirmation: never run executor or attester
resources or follow their path fields, treat the text as untrusted
(T1) that reaches an agent only through the D52 path, run no reference
agent and copy no code; revisit at OKF 1.0. The threat model and the
skill-set page get the matching line, and the design index lists D60
as proposed.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Since the one-archive change the host binary is built for darwin/arm64
only and the guest binaries for linux/arm64, in one archive with
install.sh; the dogfood install goes through that archive.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
whr ws shell starts the runtime's interactive exec with os.StartProcess
and an argument vector from apple.InteractiveCommand, never a shell
string; the row now lists it with its files.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
The PR-owning author's later pushes move into parentheses, so the desk
stays the one that opens the draft PR, posts the status and marks it
ready.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
The user checks run as another account say "this check describes the
account workharbor runs as: check it as workharbor", as the CLI prints.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
With a separate standard account nothing the administrator runs writes
/etc/whr/config.json, so workspace-folders, workspace-volume and
spotlight stay not verified in the administrator's run. The options
and a recommendation are recorded for Werner, not decided.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Werner approved "OKF: observed, not adopted" on 2026-10-09, on the
design, docs and security lanes' review on #399. The row, the design
index and the threat-model and skill-set lines no longer say proposed.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
install.sh ties the tag to the archive and installs the checked
archive's files only when checksums.txt is next to it; without it, it
installs the loose files with a stderr notice (install-release.sh).
D24 and T19 now say so.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Werner decided on 2026-10-09 that whr setup host, run by the
administrator, fully initializes the workharbor account's base
configuration; the implementation is pending on its own branch. The
entry now names the real cause of today's gap: config-first is
deliberately unreachable when --user differs, and the roots steps
become reachable once /etc/whr/config.json names the roots.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
@wstein

wstein commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

Opus review CLEAR at 5ef0e0c: full review at f98ad455 (no High/Medium; Lows L1 wording of D24/T19, L2 interfaces.md entry, L3 number reservation fixed or recorded on #399), narrowed review after rebase onto e704388 and two fix commits: range-diff identical, docs build with panicOnWarning and docscheck pass.

Co-Authored-By: Claude Sonnet 5.5 [email protected]

@wstein
wstein marked this pull request as ready for review October 9, 2026 11:55
@wstein
wstein enabled auto-merge (rebase) October 9, 2026 11:56
@wstein
wstein merged commit fe77afd into main Oct 9, 2026
20 of 21 checks passed
@wstein
wstein deleted the docs/399-design-lane-batch branch October 9, 2026 11:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant