# Worker Cheatsheet Validation - 2026-09-30 ## Scope Validation used isolated fake device tokens, private local state roots, a local TLS no-work fixture, unique Docker names/volumes, and fresh artifacts. It did not contact production, issue assignments, or use production credentials. ## Initial audit - Windows package exposed install, start, stop, status, attach, logs, history, and doctor; `watch` was rejected as an invalid command. - The Linux image exposed the same command set, but an assembled native Linux package had no package-root launcher or preparation workflow. - First installation required token-bearing process arguments. Later lifecycle commands already read the private installed JSON configuration. - Active quickstart and operations instructions recommended server cap zero for routine local maintenance. - An unreachable-server negative check made `stop --timeout 120` return a non-drained receipt with exit code 2 instead of reporting false success. ## Fresh artifact identities | Artifact | Identity | | --- | --- | | Final Windows ZIP SHA-256 | `210eb61e8d6c35b014b39b18b4dd7e28e1e057a11d57790188f7904487bac004` | | Windows package manifest | `4572e349cead890c4efdc113e4d41285981086db7c0783fb67493fdeb6bac04c` | | Linux/Docker image | `sha256:8bc99d9e7e5f5f364de9b7d2b30100942b5ce3d9170a64e5abf0068ffc3d02c4` | | Linux package manifest | `19907f29382bd2b5a1de13fd53a829e97a5626fbacbed8f4286071ba4d5a9bec` | The final Windows ZIP was rebuilt after the last documentation correction. Its full lifecycle run used the same package-manifest identity; the rebuild changed only packaged operator-document bytes outside worker code authority. ## Checked command matrix | Environment | YAML install | Doctor | Start | Status | Attach | Watch | Stop | | --- | --- | --- | --- | --- | --- | --- | --- | | Windows package | pass | pass | pass | pass | pass | pass | `drained=true`, `exit_code=0` | | Native Linux package under `/opt` | pass | pass | pass | pass | pass | pass | `drained=true`, `exit_code=0` | | Docker image with persistent volume | stdin pass | pass | pass | pass | pass | pass | `drained=true`, `exit_code=0` | The stopped Docker container reported `status=exited`, `exit=0`, and `oom=false`. `attach` and `watch` detached without stopping the verified worker on every environment. ## Documentation result The active general guide and operations runbook contain no cap-zero routine and no token-bearing install command. Separate Windows, native Linux, and Docker cheatsheets contain copy-paste install, start, stop, attach, status, and watch commands. Historical dated validation reports retain factual records of earlier cap-zero experiments and are not active instructions. ## Final gates - Focused worker/package/documentation matrix: `157 passed, 3 skipped`. - Windows packaged `watch --help`: pass. - Linux image launcher, preparation script, packaged cheatsheets, and shell syntax smoke: pass. - Worker Compose rendering: pass. - Python compilation: pass. - Strict OpenSpec validation: pass. ## Release build The final `dist/release-20260930-linux` release includes both native Linux and Docker Linux artifacts plus all platform sheets under `cheatsheets/`. All entries in `SHA256SUMS.txt` passed verification. The Docker bundle also contains the sheets and both `workerctl` helpers, and all eight internal checksums passed. The native archive contained no absolute paths, parent traversal, or links; its launchers retained mode 0755 and passed an extracted `/opt` preparation and CLI smoke test. | Release artifact | SHA-256 | | --- | --- | | Native Linux package | `e44717c9e84fc73d1d0734189da5b809c1c2271648868c05caea954bf46f6ebc` | | Docker Linux image archive | `80a59f180e7c1e4e5861427d94b44605a54ba08ed12198c63c3ae98c35678f63` | | Trusted Linux package manifest | `a3e8b73855d3b0854c5891cb5a10ff892aa0929e24046d2ce6fd28a245317e82` |