Full-depth rename per the approved plan; the 'claw' product vocabulary (claws, /claws routes, clawId, Claw Chat) stays — it is now the brand. - Display brand: Clawmates (manifest, titles, hero, login/rail logo 'clawmates'); default host app.clawmates.work; registry ghcr.io/clawmates - Crates tc-* -> cm-* (16 crates + all imports); binaries clawmates-server/broker/bundler; images clawmates/*; env prefix CLAWMATES_* (+ CM_TEST_DATABASE_URL / CM_LIVE_LLM); config clawmates.toml; helm chart deploy/helm/clawmates with clawmates-* resources; db names clawmates*; sockets /run/clawmates; cookie cm_session; kind cluster clawmates-test; seccomp node profile clawmates-agent-profile.json - All 9 Playwright brand assertions updated in lockstep; historical spec document left untouched as the only remaining 'TeamClaw' - Local env migrated: dev pg clawmates-dev-pg/clawmates_dev, shared test server clawmates-test-pg, kind cluster recreated with image + profile, compose images rebuilt under clawmates/* Verified end to end: 161 Rust + 68 frontend tests, 29 Playwright journeys, 4 live kind tests, helm/install/LOC/placeholder gates, and the clean-room install rehearsal serving the clawmates login page from a signed bundle of the rebuilt images. Co-Authored-By: Claude Fable 5 <[email protected]>
49 lines
1.8 KiB
Bash
Executable File
49 lines
1.8 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Rehearses the air-gapped delivery loop without docker: assemble a signed
|
|
# bundle with the real bundler, run install.sh --verify-only against it,
|
|
# then tamper and prove the installer refuses before touching anything.
|
|
set -euo pipefail
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
|
WORK="$(mktemp -d)"
|
|
trap 'rm -rf "$WORK"' EXIT
|
|
|
|
cargo build -q -p clawmates-bundler
|
|
BUNDLER="$ROOT/target/debug/clawmates-bundler"
|
|
|
|
"$BUNDLER" keygen "$WORK/release.key" "$WORK/release.pub"
|
|
|
|
# Fixture artifacts standing in for image tarballs and compose files.
|
|
echo "pretend image bytes" > "$WORK/server.tar"
|
|
mkdir -p "$WORK/compose-src"
|
|
cp "$ROOT/deploy/compose/docker-compose.yml" "$WORK/compose-src/"
|
|
cp "$ROOT/deploy/compose/clawmates.toml" "$WORK/compose-src/"
|
|
cp "$ROOT/deploy/compose/.env.example" "$WORK/compose-src/"
|
|
|
|
"$BUNDLER" assemble "$WORK/bundle" "0.0.0-test" "$WORK/release.key" \
|
|
"$WORK/server.tar=images/server.tar" \
|
|
"$WORK/compose-src/docker-compose.yml=compose/docker-compose.yml" \
|
|
"$WORK/compose-src/clawmates.toml=compose/clawmates.toml" \
|
|
"$WORK/compose-src/.env.example=compose/.env.example" \
|
|
"$BUNDLER=bin/clawmates-bundler"
|
|
chmod +x "$WORK/bundle/bin/clawmates-bundler"
|
|
|
|
# 1. A clean bundle verifies.
|
|
"$ROOT/deploy/airgapped/install.sh" "$WORK/bundle" "$WORK/release.pub" --verify-only
|
|
|
|
# 2. A tampered image is refused.
|
|
echo "EVIL" >> "$WORK/bundle/images/server.tar"
|
|
if "$ROOT/deploy/airgapped/install.sh" "$WORK/bundle" "$WORK/release.pub" --verify-only 2>/dev/null; then
|
|
echo "FAIL: tampered bundle was accepted"
|
|
exit 1
|
|
fi
|
|
|
|
# 3. The wrong public key is refused.
|
|
"$BUNDLER" keygen "$WORK/other.key" "$WORK/other.pub"
|
|
if "$ROOT/deploy/airgapped/install.sh" "$WORK/bundle" "$WORK/other.pub" --verify-only 2>/dev/null; then
|
|
echo "FAIL: wrong key was accepted"
|
|
exit 1
|
|
fi
|
|
|
|
echo "install.sh verify path OK"
|