feat(install): level-aware casan init + merge-safe adoption + hub guardrail

Answers the 3 adoption questions (Plan-21 follow-up):

1) LEVEL SELECTION (4 packaging levels, packaging/levels.json):
   - install.sh --level core|devkit; platform refused (preview service),
     enterprise refused (future). Level recorded in .casan-level.
   - casan init --level 1..4: L1=gate+Plan-20 hooks only; L2=+CI+domain-pack;
     L3=L2 base+preview note; L4=refused. New `casan level show|set`.
   - levels.json core now includes adapters/ + schemas/ + install scripts.

2) EXISTING SHELLS (agents/skills): init MERGES Plan-20 hooks into an existing
   .claude/settings.json and .codex/{hooks.json,config.toml} idempotently
   instead of clobbering — preserves the project's own hooks/agents/skills and
   unrelated keys. Re-running never duplicates the CASAN hook.

3) NO RE-INDEX / NO SHELL REWRITE: init only adds config; it does not parse or
   index code and does not rewrite the project shell.

Safety fixes after a test accidentally ran init in the real repo:
   - launcher shim now SELF-LOCATES its install from its own path (no ambient
     CASAN_HOME cross-talk).
   - casan init REFUSES to adopt a CASAN source hub into itself (--force to
     override), so the Plan-20 hooks can't block the developing agent.
   - test always runs init inside throwaway dirs; +source-hub guard test.

hybrid-install-tests.sh: 41/41 PASS.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
thanhnv
2026-07-23 22:00:46 +07:00
co-authored by Claude Opus 4.8
parent 8450f8ca1a
commit ff4e9d5a53
8 changed files with 430 additions and 22 deletions
+32 -4
View File
@@ -21,12 +21,26 @@ sh install.sh # macOS/Linux
pwsh .\install.ps1 # Windows
```
Chọn **level đóng gói** để cài (theo `packaging/levels.json`):
```bash
sh install.sh --level core # L1: harness + gates + CLI (casan run/gate/verify)
sh install.sh --level devkit # L2 (mặc định): + adoption tooling (casan init, CI, domain-pack)
sh install.sh --level platform # L3 preview: từ chối — là service, deploy riêng
sh install.sh --level enterprise# L4 future: từ chối (chưa ship)
```
Levels là cumulative (devkit ⊃ core). `casan init` là tính năng của **L2 (devkit)**;
cài `--level core` sẽ không có `casan init` (báo rõ ràng).
Installer sẽ:
- Copy harness vào `$CASAN_HOME/versions/<version>` (mặc định `~/.casan`,
Windows: `%LOCALAPPDATA%\casan`) và trỏ `current` vào version đó.
- Ghi **hash toàn vẹn** của gate-code (`.harness-hash`) — mỏ neo cho pin+verify.
- Tạo launcher `casan` và đưa lên PATH (`~/.local/bin` hoặc `$CASAN_HOME/bin`).
- Ghi level đã cài vào `.casan-level`.
- Tạo launcher `casan` (tự định vị install của chính nó) và đưa lên PATH
(`~/.local/bin` hoặc `$CASAN_HOME/bin`).
> Windows cần **Git for Windows (Git Bash)** để *chạy* harness (xem
> [CASAN_AGENTIC_CLIENTS_WINDOWS.md](CASAN_AGENTIC_CLIENTS_WINDOWS.md)) — không
@@ -39,11 +53,25 @@ cục bộ), `CASAN_DIST_URL` (tải tarball), `CASAN_NO_PATH_LINK=1` (không t
```bash
cd <dự-án-của-bạn>
casan init # project id lấy theo tên thư mục
# hoặc:
casan init --project my-app --client all --mode observe
casan init # project id lấy theo tên thư mục, level=devkit
# hoặc chọn level áp dụng cho project:
casan init --level 1 --project my-app # L1: chỉ gate + hook Plan-20
casan init --level 2 --project my-app # L2 (mặc định): + CI workflow + domain-pack
casan level show # xem level đã cài + level project
casan level set 2 # đổi level project (không cần init lại)
```
**Áp dụng cho dự án ĐÃ có vỏ (agents/skills/hook sẵn):** an toàn.
- `init` **KHÔNG index/parse code, KHÔNG sửa source, KHÔNG dựng lại vỏ** — chỉ thêm config.
- Hook được **MERGE** idempotent vào `.claude/settings.json` / `.codex/hooks.json`
hiện có (giữ nguyên hook/agents/skills/khóa khác của bạn), không ghi đè. Chạy
`init` nhiều lần không nhân đôi hook.
- **Guardrail:** `init` **từ chối** khi target chính là một CASAN source hub (để
không tự chặn agent đang phát triển CASAN); dùng `--force` nếu thực sự cần.
`--level 3` (platform) chỉ áp base L2 + nhắc rằng platform là service deploy riêng;
`--level 4` (enterprise) bị từ chối (chưa ship).
`casan init` chỉ ghi **config per-project** (không copy harness):
| File | Vai trò |
+16 -2
View File
@@ -1,7 +1,7 @@
# CASAN Plan-21 — Hybrid Global Install + `casan init`
> Ngày lập: 2026-07-23
> Trạng thái: **IMPLEMENTED (MVP) — global install + `casan init` + pin/verify xanh (21/21 test)**
> Trạng thái: **IMPLEMENTED — global install + `casan init` + pin/verify + level-aware + merge-safe (41/41 test)**
> Liên quan: [Plan-20](CASAN_PLAN_20_AGENTIC_CLIENT_INTEGRATION.md) (adapter/hook là base phổ quát), [CASAN_INSTALL_HYBRID.md](../casan/CASAN_INSTALL_HYBRID.md)
## 1. Mục tiêu
@@ -42,9 +42,23 @@ harness global thao tác đúng trên state của dự án hiện tại.
| Integrity hash primitive | `packages/casan-harness/scripts/python/harness_hash.py` |
| `casan init` / `verify` | `packages/casan-devkit/casan-init.py` |
| CLI wiring | `bin/casan` (`init`, `verify-harness`) |
| Acceptance suite | `packages/casan-devkit/tests/hybrid-install-tests.sh` — **21/21 PASS** |
| Acceptance suite | `packages/casan-devkit/tests/hybrid-install-tests.sh` — **41/41 PASS** |
| Adoption doc | `docs/casan/CASAN_INSTALL_HYBRID.md` |
### Level selection (4 packaging levels) & safe adoption
- `install.sh --level core|devkit` (driven by `packaging/levels.json`); `platform`
refused as a preview SERVICE, `enterprise` refused (future). Level recorded in
`.casan-level`; launcher self-locates its own install (no cross-home talk).
- `casan init --level 1..4`: L1 = gate + Plan-20 hooks only; L2 = + CI workflow +
domain-pack; L3 = L2 base + preview note; L4 = refused. `casan level show`/`set`.
- **Merge, not clobber:** `init` merges Plan-20 hooks into an existing
`.claude/settings.json` / `.codex/{hooks.json,config.toml}` idempotently,
preserving the project's own hooks/agents/skills. Never re-indexes or rewrites
the project shell.
- **Source-hub guardrail:** `init` refuses to adopt a CASAN source hub into itself
(would block the developing agent); `--force` overrides.
## 5. Definition of Done
- ✅ `install.sh` cài harness + launcher + integrity hash từ checkout cục bộ.