# Loom first-run bootstrap
`ensure_with_topology(root, access, web_importer, services)` owns the supported blank-state Loom bootstrap.
Before prompting for credentials or creating canonical state, it opens the trusted same-machine Rust archive through the Rust importer and reads the Web archive. It then creates the first Account, the public first-user root, the public `loom-devs` and `kennedy-devs` groups and Profiles, and the six fixed authority-scoped Kmap roots. The first user owns both groups and each group includes typed All Models membership.
The Rust importer validates the exact three-file package shape, authority-rewrites the actual manifests, compiles the complete rewritten workspace once without executing tests, logs errors and skips to `bootstrap/k1-rust-import.log`, and publishes under `loom-devs` only after compilation succeeds. Web packages retain their existing authority rewrite, Chromium check, and immutable publication flow. Bootstrap Complete is recorded only after both imports finish. Neither the Rust archive nor imported package source is hashed or stored by digest.
A canonical Begin without Complete is deliberately not resumed: startup fails with an instruction to delete the disposable blank-state data and restart. `BootstrapResult` retains the five shared launch-node AccessIds in memory for daemon composition. No launch-node JSON file is created. Completed startup reconciles topology against the canonical Complete record and returns the same five IDs without requiring either bootstrap archive.
Conflicting Accounts, groups, Profiles, roots, bindings, completion state, worktrees, or published package bytes fail closed. There is no rollback, destructive repair, migration, compatibility reader, background work, listener management, deployment, or executable publication.