kcode-k1-loom-bootstrap 0.3.1

First-run Loom administrator, public topology, Rust source, and Web UI bootstrap
Documentation
# Loom first-run bootstrap

`ensure_with_topology(root, access, web_importer, services)` owns the supported blank-state Loom bootstrap.

When bootstrap state is Empty, it opens the trusted same-machine Rust archive, reads the Web archive, and replaces `bootstrap/k1-web-import.log` with a complete warning-only Web preflight before prompting for credentials or creating canonical state. Every preflight finding is flushed to the log. Unresolved dependencies, unusual declarations, cycles, and other uncertainty are diagnostic warnings only and never stop bootstrap.

It then creates the first Account, the public first-user root, the public `loom-devs` and `kennedy-devs` groups and Profiles, and the six fixed authority-scoped Kmap roots. The first user owns both groups and each group includes typed All Models membership. No Model launch node or binding is created.

The Rust importer validates the exact three-file package shape, authority-rewrites the actual manifests, compiles the complete rewritten workspace once without executing tests, logs errors and skips to `bootstrap/k1-rust-import.log`, and publishes under `loom-devs` only after compilation succeeds.

The Web importer appends every package attempt, warning, success, concrete error, and retry to `bootstrap/k1-web-import.log`, flushing every result. It proceeds optimistically despite uncertainty, attempts independent packages after concrete failures, and retries deferred packages in bounded progress rounds. It fails only when a required operation concretely cannot complete and one or more packages remain unimported after no further progress is possible. The Web log ends in `SUCCESS` only when every package was actually imported.

Bootstrap Complete is recorded only after both imports finish successfully. Neither the Rust archive nor imported package source is hashed or stored by digest.

A canonical Begin without Complete is deliberately not resumed: startup fails with an instruction to delete the disposable blank-state data and restart. Once Complete exists, bootstrap is finished: startup does not open either archive, inspect the imported-package inventory, reconcile topology, or inspect Profiles, policies, colors, roots, nodes, or bindings. It reads the first-user and `loom-devs` IDs from the Complete record and performs only the required read-only Groups lookup of the persisted `kennedy-devs` ID needed for daemon configuration. It performs no bootstrap write or repair.

`BootstrapResult` retains only the `loom-devs` and `kennedy-devs` group authority IDs in memory for daemon composition. It does not expose concrete launch-node IDs, and no launch-node JSON file is created. Completed startup costs one bootstrap-state read plus a scan of the first user's persisted Groups; blank startup is dominated by archive validation and import.

During the one-time Empty-state bootstrap, conflicting Accounts, groups, Profiles, roots, bindings, completion state, worktrees, or published package bytes fail closed. There is no rollback, destructive repair, migration, compatibility reader, background work, listener management, deployment, or executable publication.