Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Running Installed-Package Conformance

This runbook starts after Secret preparation declares HOST READY. It covers the Linux server, backup, restore, rollback, fresh installed-client recovery checks, final WSL2 and macOS checks, cleanup, and finalization. Package files are installed only by the conformance harness.

Use this exact candidate for every phase:

archive: ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz
SHA-256: 8c4664cd7fb48c040869c09172cf15cba2bb324c2958b0d97407c424ce20fcea

The fixed predecessor is:

archive: ahri-tre-test-datastore-deployment-kit-0.3.12.tar.gz
SHA-256: 6f5555c25d96274d7772d1b46d4409bd36a42205f21c4c715de8df5179ab18ed

The admitted ORCID Sandbox iD is 0009-0005-0445-6675. The intentionally unadmitted iD is 0009-0007-0768-5937. Never admit the second iD.

Do not reboot until recovery is complete. The root identity and other verified inputs beneath /run/secrets are ephemeral.

The accepted v0.3.22 recovery followed by its dataset.metadata.assertion no-go is retained evidence and must be retired before this runbook starts. None of the earlier reset wizards accepts that boundary. Issue 19 — Preserve numeric Dataset Variable order over OAuth owns its checksum-bound exact-state reset; do not substitute a broader manual cleanup.

After that reset stops at RESET READY, run ./scripts/minisforum-conformance-preparation-wizard.sh, stop at HOST READY, and then begin section 1.

1. Set the server paths

On the MinisForum as sysadmin:

INPUT_ROOT=/home/sysadmin/ahri-tre-conformance/input
CANDIDATE_ROOT="$INPUT_ROOT/extracted/ahri-tre-test-datastore-deployment-kit-0.3.23"
EVIDENCE_ROOT=/var/backups/ahri-tre/conformance-evidence
DEPLOYMENT_ID=f2ef37c5-7430-468a-a439-b3ba1b0527c1
SAFE_IDENTITY=0009-0005-0445-6675

Verify the exact inputs without splitting grep from its filename:

cd "$INPUT_ROOT"
grep -qxF '8c4664cd7fb48c040869c09172cf15cba2bb324c2958b0d97407c424ce20fcea  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz' \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256
sha256sum --check --strict \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256
grep -qxF '6f5555c25d96274d7772d1b46d4409bd36a42205f21c4c715de8df5179ab18ed  ahri-tre-test-datastore-deployment-kit-0.3.12.tar.gz' \
  ahri-tre-test-datastore-deployment-kit-0.3.12.tar.gz.sha256
sha256sum --check --strict \
  ahri-tre-test-datastore-deployment-kit-0.3.12.tar.gz.sha256

Both checks must report OK.

2. Run the Linux server phase

sudo install -d -o root -g root -m 0700 "$EVIDENCE_ROOT"
sudo test -z "$(sudo find "$EVIDENCE_ROOT" -mindepth 1 -maxdepth 1 -print -quit)"

sudo "$CANDIDATE_ROOT/conformance/run.sh" server \
  --kit-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --predecessor-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.12.tar.gz" \
  --predecessor-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.12.tar.gz.sha256" \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-clean-host svrltreapcc02 \
  --confirm-host svrltreapcc02 \
  --confirm-address 192.168.31.75 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --safe-identity "$SAFE_IDENTITY" \
  --backup-name conformance-0.3.23

Positive output is Linux server installed-package evidence outcome=go. This phase admits SAFE_IDENTITY through the packaged site operation before any backup can be taken.

3. Back up the installed deployment

sudo "$CANDIDATE_ROOT/conformance/run.sh" recovery-backup \
  --kit-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-host svrltreapcc02 \
  --confirm-address 192.168.31.75 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --safe-identity "$SAFE_IDENTITY" \
  --backup-name conformance-0.3.23

Positive output is Linux server conformance phase=recovery-backup outcome=go. Verify the backup:

sudo bash -c 'cd /var/backups/ahri-tre/recovery/conformance-0.3.23 && sha256sum --check --strict SHA256SUMS'

Select one genuine recovery client

Before section 4, select either macos or wsl2 for both fresh recovery qualifications. The examples below select native Apple Silicon macOS. The first restore and rollback invocation persists this choice with the exact target and candidate digest; every resume must repeat the same choice. Never rename or edit one platform’s output to represent the other.

If neither client is currently available, stop here. The installed server, exact candidate, checksummed recovery backup, and server evidence form the safe pre-recovery checkpoint. Do not empty the restore targets until the selected client can complete both fresh qualifications.

4. Prepare the exact empty restore targets

This is the destructive preparation step. It deletes only the current ahri-tre-test database objects, active Managed-secret ciphertext, and active Lake content. The verified backup remains under /var/backups/ahri-tre/recovery/conformance-0.3.23.

First verify the exact directories and stop writers:

sudo test "$(sudo stat -c '%U:%G:%a' /var/lib/ahri-tre/secrets)" = 'ahri-tre-runtime:ahri-tre-runtime:700'
sudo test "$(sudo stat -c '%U:%G:%a' /data/ahri-tre/lake)" = 'ahri-tre-runtime:ahri-tre-runtime:700'
sudo test -f /run/secrets/ahri-tre/root-identity/value
sudo test ! -L /run/secrets/ahri-tre/root-identity/value
sudo systemctl stop ahri-tre-web.service ahri-tre-runtime.service

Render the packaged administrator connection and empty the public schema:

CONTRACT="$CANDIDATE_ROOT/site/postgresql/deployment-contract.json"
OPERATOR="$CANDIDATE_ROOT/site/postgresql/contract/operator.sh"
PSQL="$CANDIDATE_ROOT/site/postgresql/bin/psql"
DB_CONNINFO="$(sudo env PATH="$CANDIDATE_ROOT/site/postgresql/bin:/usr/bin:/bin" \
  "$OPERATOR" "$CONTRACT" render-conninfo ahri_tre_test)"
sudo "$PSQL" -X --no-psqlrc --set=ON_ERROR_STOP=1 \
  --dbname="$DB_CONNINFO" \
  --command='DROP SCHEMA public CASCADE; CREATE SCHEMA public AUTHORIZATION pg_database_owner;'

Empty the two exact filesystem targets and verify all three targets:

sudo find /var/lib/ahri-tre/secrets -mindepth 1 -maxdepth 1 -exec rm -rf -- {} +
sudo find /data/ahri-tre/lake -mindepth 1 -maxdepth 1 -exec rm -rf -- {} +
sudo test -z "$(sudo find /var/lib/ahri-tre/secrets -mindepth 1 -maxdepth 1 -print -quit)"
sudo test -z "$(sudo find /data/ahri-tre/lake -mindepth 1 -maxdepth 1 -print -quit)"
sudo test ! -e /var/backups/ahri-tre/restore-staging
sudo "$PSQL" -X --no-psqlrc --tuples-only --no-align \
  --dbname="$DB_CONNINFO" \
  --command="SELECT EXISTS (
    SELECT 1 FROM pg_class c JOIN pg_namespace n ON n.oid = c.relnamespace
    WHERE n.nspname NOT IN ('pg_catalog','information_schema')
      AND c.relkind IN ('r','p','v','m','S','f'));"

The last command must print f. If it does not, stop; do not broaden the SQL or filesystem deletion commands.

5. Restore and stop at the selected-client boundary

sudo "$CANDIDATE_ROOT/conformance/run.sh" recovery-restore \
  --kit-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-host svrltreapcc02 \
  --confirm-address 192.168.31.75 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --safe-identity "$SAFE_IDENTITY" \
  --backup-name conformance-0.3.23 \
  --recovery-platform macos

Positive output is Linux server conformance phase=recovery-restore outcome=pending-macos. The restore has completed; acceptance is intentionally waiting for a fresh native macOS qualification. This exact site is the closed CLI-only deployment: its site contract disables Web ingress and its Application configuration does not select services.web. Leave ahri-tre-web.service stopped.

6. Prepare the exact candidate on native macOS

On native Apple Silicon macOS 26:

MAC_INPUT_ROOT="$HOME/ahri-tre-conformance/input"
MAC_CANDIDATE_PARENT="$HOME/ahri-tre-conformance/macos-candidate-0.3.23"
MAC_CANDIDATE_ROOT="$MAC_CANDIDATE_PARENT/ahri-tre-test-datastore-deployment-kit-0.3.23"
MAC_RECOVERY_OUTPUT="$HOME/ahri-tre-conformance/recovery-qualification"
DEPLOYMENT_ID=f2ef37c5-7430-468a-a439-b3ba1b0527c1

cd "$MAC_INPUT_ROOT"
grep -qxF '8c4664cd7fb48c040869c09172cf15cba2bb324c2958b0d97407c424ce20fcea  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz' \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256
shasum --algorithm 256 --check \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256
test ! -e "$MAC_CANDIDATE_PARENT"
test ! -e "$MAC_RECOVERY_OUTPUT"
install -d -m 0700 "$MAC_CANDIDATE_PARENT" "$MAC_RECOVERY_OUTPUT"
tar --extract --gzip \
  --file ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz \
  --directory "$MAC_CANDIDATE_PARENT" --no-same-owner --no-same-permissions
(cd "$MAC_CANDIDATE_ROOT" && shasum --algorithm 256 --check SHA256SUMS)

The macOS client must be absent before each recovery qualification. The harness installs it, runs the installed qualifier, uninstalls it, then publishes only the validated redacted result.

Each qualification output is immutable. A completed invocation may return the shell prompt after writing its go result, so never rerun merely because the final console line was missed. Before reusing an existing restore or rollback output, verify its exact candidate binding:

verify_macos_recovery_output() {
  jq -e \
    --arg deployment "$DEPLOYMENT_ID" \
    --arg digest '8c4664cd7fb48c040869c09172cf15cba2bb324c2958b0d97407c424ce20fcea' '
    .ok == true and .outcome == "go" and
    .gate == "installed_remote_cli_capability.v1" and
    .platform == "macos" and .target == "aarch64-apple-darwin" and
    .kit_version == "0.3.23" and .client_version == "0.10.12" and
    .protocol_version == "1.0.0" and
    .source_revision == "1ae413547dae23b7fcbb659d064c704cce34cfa7" and
    .deployment_id == $deployment and .datastore == "ahri-tre-test" and
    .candidate_archive_sha256 == $digest and
    (.stages | length == 34 and all(.status == "pass"))
  ' "$1" >/dev/null
}

If --qualification-output must name an absent absolute path appears, do not delete the existing file. Run this verifier against it. A zero exit means the earlier invocation completed and the procedure resumes at the corresponding scp; any other result is preserved as a no-go and requires diagnosis.

For a genuine WSL2 recovery path, use the same sequence with --recovery-platform wsl2, the wsl2-recovery action, --confirm-clean-host wsl2, sha256sum --check --strict, and distinct restore-wsl2.json and rollback-wsl2.json paths beneath a WSL2-owned mode 0700 directory. Resume the server with --client-qualification naming the matching transferred file. Do not mix the two platform choices within a pending operation.

7. Qualify and accept the restore

On the Mac, sign out of other ORCID Sandbox browser sessions, then run:

RESTORE_QUALIFICATION="$MAC_RECOVERY_OUTPUT/restore-macos.json"
test ! -e "$RESTORE_QUALIFICATION"

If that test exits nonzero, do not execute the qualification command below; verify the existing file and resume at scp when it passes. If it exits zero, run:

"$MAC_CANDIDATE_ROOT/conformance/run.sh" macos-recovery \
  --kit-archive "$MAC_INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$MAC_INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --qualification-output "$RESTORE_QUALIFICATION" \
  --user "$(id -un)" \
  --confirm-clean-host macos \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --admitted-identity 0009-0005-0445-6675

verify_macos_recovery_output "$RESTORE_QUALIFICATION"

Authenticate as 0009-0005-0445-6675. Positive output ends with macos recovery installed-package qualification outcome=go. Transfer that single file:

scp "$RESTORE_QUALIFICATION" \
  sysadmin@192.168.31.75:/home/sysadmin/ahri-tre-conformance/input/restore-macos.json

On the MinisForum, resume the same server phase:

sudo "$CANDIDATE_ROOT/conformance/run.sh" recovery-restore \
  --kit-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-host svrltreapcc02 \
  --confirm-address 192.168.31.75 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --safe-identity "$SAFE_IDENTITY" \
  --backup-name conformance-0.3.23 \
  --recovery-platform macos \
  --client-qualification /home/sysadmin/ahri-tre-conformance/input/restore-macos.json

It must print Linux server conformance phase=recovery-restore outcome=go.

8. Roll back and stop at the selected-client boundary

On the MinisForum:

sudo "$CANDIDATE_ROOT/conformance/run.sh" recovery-rollback \
  --kit-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-host svrltreapcc02 \
  --confirm-address 192.168.31.75 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --safe-identity "$SAFE_IDENTITY" \
  --backup-name conformance-0.3.23 \
  --recovery-platform macos

It must print Linux server conformance phase=recovery-rollback outcome=pending-macos.

9. Qualify and accept the rollback

On the Mac, run a fresh harness-owned qualification with a different absent output path:

ROLLBACK_QUALIFICATION="$MAC_RECOVERY_OUTPUT/rollback-macos.json"
test ! -e "$ROLLBACK_QUALIFICATION"

Again, a nonzero result means verify and reuse an exact existing go result; it does not authorize overwriting it. Only when the path is absent, run:

"$MAC_CANDIDATE_ROOT/conformance/run.sh" macos-recovery \
  --kit-archive "$MAC_INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$MAC_INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --qualification-output "$ROLLBACK_QUALIFICATION" \
  --user "$(id -un)" \
  --confirm-clean-host macos \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --admitted-identity 0009-0005-0445-6675

verify_macos_recovery_output "$ROLLBACK_QUALIFICATION"

scp "$ROLLBACK_QUALIFICATION" \
  sysadmin@192.168.31.75:/home/sysadmin/ahri-tre-conformance/input/rollback-macos.json

On the MinisForum, accept the result, dispose only the accepted 0.3.12 rollback unit, and let the harness return the server to 0.3.23:

sudo "$CANDIDATE_ROOT/conformance/run.sh" recovery-rollback \
  --kit-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-host svrltreapcc02 \
  --confirm-address 192.168.31.75 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --safe-identity "$SAFE_IDENTITY" \
  --backup-name conformance-0.3.23 \
  --recovery-platform macos \
  --client-qualification /home/sysadmin/ahri-tre-conformance/input/rollback-macos.json \
  --confirm-dispose-rollback 0.3.12

It must print Linux server conformance phase=recovery-rollback outcome=go.

10. Aggregate recovery evidence

On the MinisForum:

sudo "$CANDIDATE_ROOT/conformance/run.sh" recovery \
  --kit-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-host svrltreapcc02 \
  --confirm-address 192.168.31.75 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --safe-identity "$SAFE_IDENTITY" \
  --backup-name conformance-0.3.23

Positive output is Linux server conformance phase=recovery outcome=go.

11. Run the final WSL2 platform phase

In WSL2, transfer the exact candidate archive and checksum into the private input directory, verify or extract it, create an empty evidence directory, and run the full platform action:

If WSL2 is temporarily unavailable, skip this section, complete section 12, run the deferred checkpoint immediately after it, and stop before cleanup. Return to this section later with the same immutable candidate.

WSL_INPUT_ROOT="$HOME/ahri-tre-conformance/input"
WSL_CANDIDATE_PARENT="$HOME/ahri-tre-conformance/wsl2-candidate-0.3.23"
WSL_CANDIDATE_ROOT="$WSL_CANDIDATE_PARENT/ahri-tre-test-datastore-deployment-kit-0.3.23"
WSL_EVIDENCE="$HOME/ahri-tre-conformance/wsl2-final-evidence"
DEPLOYMENT_ID=f2ef37c5-7430-468a-a439-b3ba1b0527c1

cd "$WSL_INPUT_ROOT"
grep -qxF '8c4664cd7fb48c040869c09172cf15cba2bb324c2958b0d97407c424ce20fcea  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz' \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256
sha256sum --check --strict \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256
if [[ ! -e "$WSL_CANDIDATE_ROOT" ]]; then
  install -d -m 0700 "$WSL_CANDIDATE_PARENT"
  tar --extract --gzip \
    --file ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz \
    --directory "$WSL_CANDIDATE_PARENT" --no-same-owner --no-same-permissions
fi
test -d "$WSL_CANDIDATE_ROOT"
test ! -L "$WSL_CANDIDATE_ROOT"
(cd "$WSL_CANDIDATE_ROOT" && sha256sum --check --strict SHA256SUMS)
test ! -e "$WSL_EVIDENCE"
install -d -m 0700 "$WSL_EVIDENCE"

"$WSL_CANDIDATE_ROOT/conformance/run.sh" wsl2 \
  --kit-archive "$WSL_INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$WSL_INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$WSL_EVIDENCE" \
  --user "$USER" \
  --confirm-clean-host wsl2 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --admitted-identity 0009-0005-0445-6675 \
  --unadmitted-identity 0009-0007-0768-5937

Use the admitted account for the first browser step. Sign it out at https://sandbox.orcid.org, then use the unadmitted account only when prompted. Positive output is wsl2 installed-package evidence outcome=go.

Transfer the result:

scp "$WSL_EVIDENCE/wsl2-client.json" \
  sysadmin@192.168.31.75:/home/sysadmin/ahri-tre-conformance/input/wsl2-client.json

On the MinisForum:

sudo install -o root -g root -m 0600 \
  /home/sysadmin/ahri-tre-conformance/input/wsl2-client.json \
  "$EVIDENCE_ROOT/wsl2-client.json"

12. Run the native Apple Silicon macOS phase

Transfer the same candidate archive and checksum to a private macOS directory. Do not transfer an unpacked client package. On the Mac:

MAC_INPUT_ROOT="$HOME/ahri-tre-conformance/input"
MAC_CANDIDATE_PARENT="$HOME/ahri-tre-conformance/macos-candidate-0.3.23"
MAC_CANDIDATE_ROOT="$MAC_CANDIDATE_PARENT/ahri-tre-test-datastore-deployment-kit-0.3.23"
MAC_EVIDENCE="$HOME/ahri-tre-conformance/macos-evidence"
DEPLOYMENT_ID=f2ef37c5-7430-468a-a439-b3ba1b0527c1

cd "$MAC_INPUT_ROOT"
grep -qxF '8c4664cd7fb48c040869c09172cf15cba2bb324c2958b0d97407c424ce20fcea  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz' \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256
shasum --algorithm 256 --check \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256
test -d "$MAC_CANDIDATE_ROOT"
test ! -L "$MAC_CANDIDATE_ROOT"
test ! -e "$MAC_EVIDENCE"
install -d -m 0700 "$MAC_EVIDENCE"
(cd "$MAC_CANDIDATE_ROOT" && shasum --algorithm 256 --check SHA256SUMS)

"$MAC_CANDIDATE_ROOT/conformance/run.sh" macos \
  --kit-archive "$MAC_INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$MAC_INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$MAC_EVIDENCE" \
  --user "$(id -un)" \
  --confirm-clean-host macos \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --admitted-identity 0009-0005-0445-6675 \
  --unadmitted-identity 0009-0007-0768-5937

If the first installation requests the one-time credential-adapter activation reboot, the harness exits safely with a platform.install no-go and uninstalls the client. Reboot the Mac, restore the shell variables above, and preserve the exact resumable record before retrying:

PLATFORM_REBOOT_RECORD="$HOME/ahri-tre-conformance/macos-platform-install-reboot-0.3.23.json"
test ! -e "$PLATFORM_REBOOT_RECORD"
jq -e '
  .schema_version == "ahri-tre.test-datastore-kit.evidence.v1" and
  .role == "macos-client" and .target == "aarch64-apple-darwin" and
  .outcome == "no-go" and .platform == {name:"macos",clean_host:true} and
  .failed_stage == "platform.install" and
  .failure_code == "installed_stage_failed"
' "$MAC_EVIDENCE/macos-client.json" >/dev/null
mv "$MAC_EVIDENCE/macos-client.json" "$PLATFORM_REBOOT_RECORD"
test -z "$(find "$MAC_EVIDENCE" -mindepth 1 -maxdepth 1 -print -quit)"

Then rerun the same macos command once against the now-empty evidence directory. Do not recreate the directory and do not reboot the MinisForum.

This requires native Apple Silicon macOS 26. Follow the same admitted then unadmitted browser-account sequence. Positive output is macos installed-package evidence outcome=go.

Transfer macos-client.json to the MinisForum and install it into the evidence directory:

scp "$MAC_EVIDENCE/macos-client.json" \
  sysadmin@192.168.31.75:/home/sysadmin/ahri-tre-conformance/input/macos-client.json

On the MinisForum:

sudo install -o root -g root -m 0600 \
  /home/sysadmin/ahri-tre-conformance/input/macos-client.json \
  "$EVIDENCE_ROOT/macos-client.json"

Deferred-finalization checkpoint

When the final WSL2 record is not yet available, verify the complete recovery and native macOS state on the still-installed server:

sudo "$CANDIDATE_ROOT/conformance/run.sh" recovery-checkpoint \
  --kit-archive "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz" \
  --kit-sha256 "$INPUT_ROOT/ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256" \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-host svrltreapcc02 \
  --confirm-address 192.168.31.75 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test \
  --safe-identity "$SAFE_IDENTITY" \
  --backup-name conformance-0.3.23

Positive output is Linux server conformance phase=recovery-checkpoint outcome=go. Stop here and preserve the installed server, candidate archive and checksum, backup, and evidence directory. When WSL2 becomes available, rerun this checkpoint first, complete section 11, install wsl2-client.json into the evidence directory, then continue to cleanup. Finalization still fails closed without that genuine WSL2 record.

13. Run final cleanup

Reverify the candidate checksum on the MinisForum, then invoke cleanup through the harness embedded in those exact bytes:

cd "$INPUT_ROOT"
sha256sum --check --strict \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256

sudo "$CANDIDATE_ROOT/conformance/run.sh" cleanup \
  --platform server \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-host svrltreapcc02 \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test

Cleanup removes package-owned server files and retains the recoverable Datastore, Lake, PostgreSQL container, logs, configuration, and backups. Positive output is server cleanup outcome=go.

14. Finalize and verify the evidence bundle

cd "$INPUT_ROOT"
sha256sum --check --strict \
  ahri-tre-test-datastore-deployment-kit-0.3.23.tar.gz.sha256

sudo "$CANDIDATE_ROOT/conformance/run.sh" finalize \
  --evidence-dir "$EVIDENCE_ROOT" \
  --confirm-deployment "$DEPLOYMENT_ID" \
  --confirm-datastore ahri-tre-test

sudo bash -c 'cd /var/backups/ahri-tre/conformance-evidence && sha256sum --check --strict SHA256SUMS'
sudo jq -e '.outcome == "go"' \
  /var/backups/ahri-tre/conformance-evidence/final-acceptance.json >/dev/null

Finalization succeeds only when the evidence directory contains exactly the declared server, WSL2, macOS, recovery, and recovery-operation records. Never copy raw browser output, credentials, Secret material, root identities, or any transient recovery qualification file into that directory.