kcode-k1-loom-bootstrap 0.1.1

First-run Loom administrator, public group, root, and Rust source bootstrap
Documentation
1
2
3
4
5
6
7
# Loom first-run bootstrap

`ensure` is the one synchronous first-run gate used before the daemon listener or readiness output. A completed canonical bootstrap returns immediately without reading the ZIP or prompting. Otherwise it requires `<loom-root>/bootstrap/k1-rust-code.zip`, validates the complete exporter archive, prompts for username, full name, and a hidden password plus confirmation, derives the browser-identical identity, and records canonical Begin state before any account or source effect. There is no Terms prompt; the required current Terms signature is generated automatically for the existing Account schema.

The operation creates or exactly reconciles the Account through a normal locally issued Invite and `K1Users`, the ordinary `loom-devs` group with the first user as Owner and typed All Models membership, one amber public saved Profile, one public group Kmap root, its `KmapLaunchNode` binding, and every authority-rewritten archived Rust package. The Profile authority is the group, editors are empty, and viewers are All Users and All Models. There is no private Profile.

All authority-rewritten packages are validated before the first Rust source effect. Existing package versions are accepted only when complete canonical source matches. Completion records the exact user, group, Profile, root, archive digest, and imported source inventory. Conflicting or ambiguous Account, group, Profile, root, package, or Begin state fails without destructive repair, rollback, retry, deployment, executable publication, or listener work.