Skip to content

Pin diagnostic command contracts (D1h: show-thumbprint round-trip + D2h: list-instances)

Placeholder ppxd requested to merge phase12.M.L.D.1-diagnostic-commands into main

Summary

Section D opens with the two operator-tailed verification commands operators rely on for ship-confidence:

  • D1h — show-thumbprint after register MUST return the SAME thumbprint the binary just sent in its register payload (round-trip pin via stub-recorded body). Catches TentacleCertificateManager.LoadOrCreateCertificate generating different certs across calls (cert-path resolution drift, file recreation races). Without this pin, the documented operator debug recipe ("run show-thumbprint, look it up in the server's trust list") silently lies and operators fix the wrong end of the mismatch.

  • D2h — list-instances after creating Alpha + Beta MUST show BOTH, with the documented NAME / CONFIG table headers. Reverse-pins the empty-state message ("No instances registered") doesn't appear when state IS on disk — catches InstanceRegistry.List reading from a different file than create-instance writes to.

Both tests live in a new file TentacleLinuxDiagnosticCommandE2ETests.cs, use a slim DiagnosticTestContext for cleanup, and join the existing host-state collection.

Why these tests matter to ship-confidence

When an agent fails to poll, the operator's first move is one of these two commands. If either lies, the operator burns hours debugging the wrong layer. These are higher-leverage than they look — they're the operator UX for the entire registration trust contract.

Test plan

  • dotnet build green (0 errors)
  • CI passes D1h_ShowThumbprintAfterRegister_MatchesStubReceivedThumbprint and D2h_ListInstancesAfterCreateAlphaAndBeta_ShowsBothEntries
  • D1h asserts: stub received exactly 1 register + body has 40-char hex tentacleThumbprint + show-thumbprint stdout equals that thumbprint
  • D2h asserts: both instance names in stdout + NAME/CONFIG headers present + 'No instances registered' NOT present
  • Existing 43 Linux E2E tests still pass

🤖 Generated with Claude Code

Merge request reports

Loading