3.8 KiB
Worker Cheatsheet Validation - 2026-09-30
Scope
Validation used isolated fake device tokens, private local state roots, a local TLS no-work fixture, unique Docker names/volumes, and fresh artifacts. It did not contact production, issue assignments, or use production credentials.
Initial audit
- Windows package exposed install, start, stop, status, attach, logs, history,
and doctor;
watchwas rejected as an invalid command. - The Linux image exposed the same command set, but an assembled native Linux package had no package-root launcher or preparation workflow.
- First installation required token-bearing process arguments. Later lifecycle commands already read the private installed JSON configuration.
- Active quickstart and operations instructions recommended server cap zero for routine local maintenance.
- An unreachable-server negative check made
stop --timeout 120return a non-drained receipt with exit code 2 instead of reporting false success.
Fresh artifact identities
| Artifact | Identity |
|---|---|
| Final Windows ZIP SHA-256 | 210eb61e8d6c35b014b39b18b4dd7e28e1e057a11d57790188f7904487bac004 |
| Windows package manifest | 4572e349cead890c4efdc113e4d41285981086db7c0783fb67493fdeb6bac04c |
| Linux/Docker image | sha256:8bc99d9e7e5f5f364de9b7d2b30100942b5ce3d9170a64e5abf0068ffc3d02c4 |
| Linux package manifest | 19907f29382bd2b5a1de13fd53a829e97a5626fbacbed8f4286071ba4d5a9bec |
The final Windows ZIP was rebuilt after the last documentation correction. Its full lifecycle run used the same package-manifest identity; the rebuild changed only packaged operator-document bytes outside worker code authority.
Checked command matrix
| Environment | YAML install | Doctor | Start | Status | Attach | Watch | Stop |
|---|---|---|---|---|---|---|---|
| Windows package | pass | pass | pass | pass | pass | pass | drained=true, exit_code=0 |
Native Linux package under /opt |
pass | pass | pass | pass | pass | pass | drained=true, exit_code=0 |
| Docker image with persistent volume | stdin pass | pass | pass | pass | pass | pass | drained=true, exit_code=0 |
The stopped Docker container reported status=exited, exit=0, and
oom=false. attach and watch detached without stopping the verified worker
on every environment.
Documentation result
The active general guide and operations runbook contain no cap-zero routine and no token-bearing install command. Separate Windows, native Linux, and Docker cheatsheets contain copy-paste install, start, stop, attach, status, and watch commands. Historical dated validation reports retain factual records of earlier cap-zero experiments and are not active instructions.
Final gates
- Focused worker/package/documentation matrix:
157 passed, 3 skipped. - Windows packaged
watch --help: pass. - Linux image launcher, preparation script, packaged cheatsheets, and shell syntax smoke: pass.
- Worker Compose rendering: pass.
- Python compilation: pass.
- Strict OpenSpec validation: pass.
Release build
The final dist/release-20260930-linux release includes both native Linux and
Docker Linux artifacts plus all platform sheets under cheatsheets/. All
entries in SHA256SUMS.txt passed verification. The Docker bundle also contains
the sheets and both workerctl helpers, and all eight internal checksums passed.
The native archive contained no absolute paths, parent traversal, or links; its
launchers retained mode 0755 and passed an extracted /opt preparation and CLI
smoke test.
| Release artifact | SHA-256 |
|---|---|
| Native Linux package | e44717c9e84fc73d1d0734189da5b809c1c2271648868c05caea954bf46f6ebc |
| Docker Linux image archive | 80a59f180e7c1e4e5861427d94b44605a54ba08ed12198c63c3ae98c35678f63 |
| Trusted Linux package manifest | a3e8b73855d3b0854c5891cb5a10ff892aa0929e24046d2ce6fd28a245317e82 |