Expand description
§Loom first-run bootstrap
ensure_with_topology(root, access, web_importer, services) owns the supported blank-state Loom bootstrap.
Before prompting for credentials or creating canonical state, it opens the trusted same-machine Rust archive, reads the Web archive, and replaces bootstrap/k1-web-import.log with a complete warning-only Web preflight. Every preflight finding is flushed to the log. Unresolved dependencies, unusual declarations, cycles, and other uncertainty are diagnostic warnings only and never stop bootstrap.
It then creates the first Account, the public first-user root, the public loom-devs and kennedy-devs groups and Profiles, and the six fixed authority-scoped Kmap roots. The first user owns both groups and each group includes typed All Models membership. No Model launch node or binding is created.
The Rust importer validates the exact three-file package shape, authority-rewrites the actual manifests, compiles the complete rewritten workspace once without executing tests, logs errors and skips to bootstrap/k1-rust-import.log, and publishes under loom-devs only after compilation succeeds.
The Web importer appends every package attempt, warning, success, concrete error, and retry to bootstrap/k1-web-import.log, flushing every result. It proceeds optimistically despite uncertainty, attempts independent packages after concrete failures, and retries deferred packages in bounded progress rounds. It fails only when a required operation concretely cannot complete and one or more packages remain unimported after no further progress is possible. The Web log ends in SUCCESS only when every package was actually imported.
Bootstrap Complete is recorded only after both imports finish successfully. Neither the Rust archive nor imported package source is hashed or stored by digest.
A canonical Begin without Complete is deliberately not resumed: startup fails with an instruction to delete the disposable blank-state data and restart. BootstrapResult retains only the loom-devs and kennedy-devs group authority IDs in memory for daemon composition. It does not expose concrete launch-node IDs, and no launch-node JSON file is created. Completed startup reconciles topology against the canonical Complete record and returns the same two group IDs without requiring either bootstrap archive.
Conflicting Accounts, groups, Profiles, roots, bindings, completion state, worktrees, or published package bytes fail closed. There is no rollback, destructive repair, migration, compatibility reader, background work, listener management, deployment, or executable publication.