Expand description
§Loom first-run bootstrap
ensure_with_topology(root, access, web_importer, services) owns the supported blank-state Loom bootstrap.
Before prompting for credentials or creating canonical state, it strictly validates both bootstrap/k1-rust-code.zip and bootstrap/k1-web-ui.zip. It then creates the first Account, the public first-user root, the public loom-devs and kennedy-devs groups and Profiles, and the six fixed authority-scoped Kmap roots. The first user owns both groups and each group includes typed All Models membership.
Rust packages are authority-rewritten and imported under loom-devs. Web packages are authority-rewritten, checked in real Chromium dependency-first, and immutably published under the same group. Bootstrap Complete is recorded only after both imports finish. A canonical Begin without Complete is deliberately not resumed: startup fails with an instruction to delete the disposable blank-state data and restart.
BootstrapResult retains the five shared launch-node AccessIds in memory for daemon composition. No launch-node JSON file is created. Completed startup reconciles topology against the canonical Complete record and returns the same five IDs without requiring either bootstrap archive.
Conflicting Accounts, groups, Profiles, roots, bindings, completion state, archive source, or published package bytes fail closed. There is no rollback, destructive repair, migration, compatibility reader, background work, listener management, deployment, or executable publication.