Skip to content

R6.5: migration tool + VM pilot fixture (close overall R6 when exit gate met) #249

Description

@PLN

Goal

MILESTONES R6.5 Migration tool, from main tip 4223ac97 (after R6.4 finish #248 / evidence 7d21de2-r64-finish).

Implements discovery, backup, dry-run, conflict reporting, owner handoff, health verification, and inverse/rollback using a VM pilot fixture. Overall R6 closes only when R6.5 checks and the R6 exit gate is honestly met. Do not start R7 (live Hermes / soak). A3 / R4.4 stay deferred.

Sources of truth

  • docs/MILESTONES.md — R6.5 + R6 exit gate; R7 stays separate
  • docs/MSI-INSTALLER-PLAN.md — Migrating the Hermes pilot and manual installs
  • docs/INSTALLATION.md — conflicts / custom --base-dir / migration later work
  • docs/R6-EVIDENCE.md — extend with redacted R6.5 section; no private inventory
  • Existing tools/maintenance/* is operator Hermes update tooling under a pilot, not R6.5. Reuse ideas only; do not fold Hermes credentials, SIDs, or host paths into the product migration tool.

In scope

1) Migration tool (product tree)

Operator-facing migration entry (tools/migrate/ or documented CLI — no host-specific config in git) supporting at least:

  1. Discover (machine-wide + optional user-context): existing winunitd SCM service; unmanaged binary / non-LocalSystem; custom --base-dir; machine scheduled tasks / machine Run values launching winunitd.exe; per-user Task Scheduler pilot tasks and unit/enable trees in user context. Report MSI-preflight rejects vs user-context-only moves.
  2. Backup: export task XML/definitions and snapshot unit + enable configuration into an operator-chosen private directory (placeholders only in product docs).
  3. Dry-run: planned disable/stop/copy/enable/install sequence and conflicts; no mutation.
  4. Conflict reporting: fail closed on unmanaged service, beta UpgradeCode still present, unsafe/reparse data dirs, destination collisions, duplicate launchers; never overwrite an unrelated winunitd service.
  5. Owner handoff (apply): disable pilot manager task and old triggers; stop owned processes; copy pilot unit/enable into standard user data tree (%LOCALAPPDATA%\winunitd) with conflict detection; journals stay or archive without overwrite; install/start product MSI system service when absent (caller supplies MSI path — do not embed a package).
  6. Health verification: system service identity; user manager profile/environment; control ownership (named pipe / winctl); fixture workload checks. Success only after ownership + health pass.
  7. Inverse / rollback: on failure, stop new ownership path and restore former tasks/configuration from backup; retain backups; document inverse command.

Locks: no passwords in plaintext/env/files; no collecting account passwords; linger stays explicit opt-in; do not silently adopt custom --base-dir; fixtures alice / bob / carol only; public artifacts PLN only (no personal names, machine names, IPs, private lab paths, inventory, Hermes credentials, Python/Hermes home paths, or SIDs).

2) VM pilot fixture (not live Hermes)

Disposable VM stand-in mimicking Task Scheduler–launched interactive pilot + unit/enable tree (optional custom base-dir conflict). alice/bob/carol only. No real Hermes install, agent auth, or private Hermes layout in the product tree.

Native qualification: discover → dry-run → apply → health pass; plus at least one injected failure proving inverse restore. Redact into docs/R6-EVIDENCE.md (new R6.5 section + evidence id). Raw logs private.

3) Docs in the same PR

  • Check R6.5 in docs/MILESTONES.md only with tool + fixture evidence; record limitations.
  • Close overall R6 only when R6.5 is checked and the R6 exit gate text is honestly met; else leave unchecked with an explicit remaining list.
  • Update INSTALLATION.md + MSI plan: R6.5 = tool + VM fixture; R7 = live Hermes handoff + soak.
  • Drop stale “R6.4: acceptance matrix (+ close R6.1 install/repair/uninstall evidence) #245 stays open…” wording; point deferred-media / deferred-older-msi reopen to evidence deferral lists.

Out of scope

  • R7 live Hermes preflight/handoff/exercise/soak
  • Inventing claimed-SKU media or OlderMsi / ProductVersion; running deferred-media / deferred-older-msi
  • A3 / R4.4 / rejected active security instrumentation
  • Signing, SignPath, R8
  • Embedding Hermes/Python/WebUI into MSI; collecting passwords; enabling linger by default
  • Changing UpgradeCode / ProductCode without recorded need
  • Calling winunitd install/uninstall from MSI; purge; rewriting mutable formats without an explicit migration transaction
  • Replacing/expanding tools/maintenance/hermes-*.ps1 Hermes updater

Acceptance / merge bar

Merge bar

CoS merges after Reviewer ship + exact-source CI green + native qualification as required by the Brief.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions