2.4 KiB
2.4 KiB
MODIFIED Requirements
Requirement: Dependency checks and installs are typed
Run SHALL check dependencies through plugin-declared probes and SHALL install missing dependencies only through approved, typed, reviewable, immutable plans executed by fixed adapters.
Scenario: Dependency check reports missing runtime
- WHEN Run evaluates a declared probe for a required runtime, service, package, toolchain, Steam app, Java runtime, Docker runtime, or file and finds it missing
- THEN Platform MUST persist and show the safe dependency status and a reviewable platform-matched install plan when the installed plugin declares one
Scenario: Dependency install is approved
- WHEN an authorized operator approves the current immutable plan digest
- THEN Platform MUST queue a fenced job and Run MUST execute only the typed package, verified-download, or SteamCMD steps, persist resumable evidence, and reject arbitrary shell or stale plan input
Scenario: Dependency result is synthetic
- WHEN Run has not executed and verified the declared probe or install steps
- THEN it MUST NOT report the dependency present, installed, or successfully completed
Requirement: Online run endpoints self-update through platform jobs
The platform SHALL update online Run endpoints through a bounded job that reads an approved same-server target-matched distribution, and Run SHALL durably download, verify, stage, activate, health-check, and roll back the update without receiving raw shell commands.
Scenario: Online Run accepts update
- WHEN the assigned endpoint is online, advertises real self-update capability, and the artifact matches its server and OS/architecture
- THEN Platform MUST queue a fenced update job and Run MUST download by bounded ranges, verify checksum, stage safely, report the result, and activate only after Platform accepts that result
Scenario: Update verification fails
- WHEN Run cannot verify or stage the artifact
- THEN Run MUST keep the current executable and configuration, report a bounded failure, preserve heartbeat/status, and never launch the update helper
Scenario: Updated Run fails health confirmation
- WHEN the replacement cannot start or authenticate/reconcile with the same identity before timeout
- THEN Run MUST restore and restart the previous executable and Platform MUST project a rolled-back/failed outcome rather than success