fenris status as the read-only CLI twin. It composes from the observation store and allow-listed system facts: the projection facts, the four separate service facts (boot enablement, runtime activity, last collect outcome, freshness), and a journalctl hint on failure or staleness — never auto-sampling, never prompting. The freshness constants are defined once and shared with the TUI: fresh within 2 × cadence + AccuracySec + 60 s of the newest sample, missed between that and 48 h, stale at ≥ 48 h, empty store reading "no observations yet" with an enable hint; the grade derives from the newest sample timestamp, never a stored flag. A store fault surfaces "observation store unreadable" with a journal hint and suppresses everything store-dependent; a newer-schema store renders "observation store written by a newer Fenris — upgrade Fenris" with no partial interpretation; a configuration error renders as a fact; drive-reported anomalies (critical warnings, media errors, unsafe shutdowns) render as ordinary facts that never affect the projection. Retired commands (start, stop, run) and --device are rejected with one-line migration pointers. The required wording and six disclosures render as adopted.
Acceptance criteria
Freshness grading with shared constants, derived from the newest sample timestamp; empty-store greeting with enable hint (LC-10)
Configuration error surfaced as configuration error: <reason> from direct reads of the world-readable config (LC-4)
status is a pure read-only composition — never auto-samples, never prompts — with the journal hint on failure or staleness (LC-9)
Store fault and newer-schema states render their exact fixed phrases with dependent content suppressed / no partial interpretation (FL-4, FL-5)
Drive anomalies render as ordinary facts, never affecting the projection (FL-7)
Retired commands and --device rejected with one-line pointers; the status fact set matches the TUI's four separate facts (LC-9, CI-2)
Required wording and six disclosures render as adopted; zero-rate and unavailable phrasing exact (CI-4)
## Parent
[Implement the Fenris persistent TUI monitoring redesign](https://git.bongbetic.com/xavierk/Fenris/issues/20)
Canonical contracts: [fenris-redesign spec](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/spec/fenris-redesign.md) · [acceptance criteria](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/spec/acceptance-criteria.md) — criterion IDs cited below live in the register.
## What to build
`fenris status` as the read-only CLI twin. It composes from the observation store and allow-listed system facts: the projection facts, the four separate service facts (boot enablement, runtime activity, last collect outcome, freshness), and a `journalctl` hint on failure or staleness — never auto-sampling, never prompting. The freshness constants are defined once and shared with the TUI: fresh within 2 × cadence + AccuracySec + 60 s of the newest sample, missed between that and 48 h, stale at ≥ 48 h, empty store reading "no observations yet" with an enable hint; the grade derives from the newest sample timestamp, never a stored flag. A store fault surfaces "observation store unreadable" with a journal hint and suppresses everything store-dependent; a newer-schema store renders "observation store written by a newer Fenris — upgrade Fenris" with no partial interpretation; a configuration error renders as a fact; drive-reported anomalies (critical warnings, media errors, unsafe shutdowns) render as ordinary facts that never affect the projection. Retired commands (`start`, `stop`, `run`) and `--device` are rejected with one-line migration pointers. The required wording and six disclosures render as adopted.
## Acceptance criteria
- [ ] Freshness grading with shared constants, derived from the newest sample timestamp; empty-store greeting with enable hint (LC-10)
- [ ] Configuration error surfaced as `configuration error: <reason>` from direct reads of the world-readable config (LC-4)
- [ ] `status` is a pure read-only composition — never auto-samples, never prompts — with the journal hint on failure or staleness (LC-9)
- [ ] Store fault and newer-schema states render their exact fixed phrases with dependent content suppressed / no partial interpretation (FL-4, FL-5)
- [ ] Drive anomalies render as ordinary facts, never affecting the projection (FL-7)
- [ ] Retired commands and `--device` rejected with one-line pointers; the status fact set matches the TUI's four separate facts (LC-9, CI-2)
- [ ] Required wording and six disclosures render as adopted; zero-rate and unavailable phrasing exact (CI-4)
## Blocked by
- [Project from the sustained regime: habit change, scenario range, and evidence gates](https://git.bongbetic.com/xavierk/Fenris/issues/26)
xavierk
changed title from Render as the read-only CLI twin to Render fenris status as the read-only CLI twin2026-08-31 18:25:07 +00:00
Created — the read-only CLI twin of the TUI (§8.8, LC-9, CI-2).
What was built
Freshness grading (§8.9, LC-10): shared constants — fresh within 2×cadence+AccuracySec+60s, missed between that and 48h, stale ≥48h, empty store greeting with enable hint. Derived from newest sample timestamp, never a stored flag.
Configuration error (§8.3, LC-4): reads directly, surfaces when device selector is missing or invalid.
Store fault and newer-schema (§9.4, §9.5, FL-4, FL-5): exact fixed phrases — with journal hint, — with dependent content suppressed, no partial interpretation.
Drive anomalies (§9.7, FL-7): critical_warning, media_errors, unsafe_shutdowns render as ordinary facts, never affecting the projection.
Four separate service facts (§7.3, LC-9, CI-2): boot enablement, timer activity, last collect outcome, freshness — never merged into one status.
Projection recomputed on read (§6.10): uses existing , never stores derived state.
Retired command rejection (§8.8): , , rejected with one-line migration pointers; rejected with pointer to config file.
Six disclosures (§6.11, CI-4): always available via flag, verbatim from spec.
Updated files
— new module (550+ lines)
— 43 tests covering all acceptance criteria
— replaced old , added retired command handlers
Test results
182 tests passing, zero regressions. All acceptance criteria verified:
LC-9: status is pure read-only, never auto-samples, never prompts
CI-2: four separate service facts match TUI contract
CI-4: required wording and six disclosures render as adopted
FL-4: store fault exact phrase with journal hint
FL-5: newer-schema exact phrase, no partial interpretation
FL-7: drive anomalies as ordinary facts, not affecting projection
LC-10: freshness constants defined once, shared with TUI
Resolved in this session.
## Implementation
Created — the read-only CLI twin of the TUI (§8.8, LC-9, CI-2).
### What was built
1. **Freshness grading** (§8.9, LC-10): shared constants — fresh within 2×cadence+AccuracySec+60s, missed between that and 48h, stale ≥48h, empty store greeting with enable hint. Derived from newest sample timestamp, never a stored flag.
2. **Configuration error** (§8.3, LC-4): reads directly, surfaces when device selector is missing or invalid.
3. **Store fault and newer-schema** (§9.4, §9.5, FL-4, FL-5): exact fixed phrases — with journal hint, — with dependent content suppressed, no partial interpretation.
4. **Drive anomalies** (§9.7, FL-7): critical_warning, media_errors, unsafe_shutdowns render as ordinary facts, never affecting the projection.
5. **Four separate service facts** (§7.3, LC-9, CI-2): boot enablement, timer activity, last collect outcome, freshness — never merged into one status.
6. **Projection recomputed on read** (§6.10): uses existing , never stores derived state.
7. **Retired command rejection** (§8.8): , , rejected with one-line migration pointers; rejected with pointer to config file.
8. **Six disclosures** (§6.11, CI-4): always available via flag, verbatim from spec.
### Updated files
- — new module (550+ lines)
- — 43 tests covering all acceptance criteria
- — replaced old , added retired command handlers
### Test results
182 tests passing, zero regressions. All acceptance criteria verified:
- LC-9: status is pure read-only, never auto-samples, never prompts
- CI-2: four separate service facts match TUI contract
- CI-4: required wording and six disclosures render as adopted
- FL-4: store fault exact phrase with journal hint
- FL-5: newer-schema exact phrase, no partial interpretation
- FL-7: drive anomalies as ordinary facts, not affecting projection
- LC-10: freshness constants defined once, shared with TUI
src/fenris/status.py — new module (550+ lines): read-only CLI status composition
tests/test_status.py — 43 new tests covering all acceptance criteria
fenris.py — replaced old cmd_status, added retired command handlers
Acceptance criteria verified
LC-10: Freshness grading with shared constants (fresh/missed/stale/empty)
LC-4: Configuration error surfaced from direct config reads
LC-9: Pure read-only composition, never auto-samples, never prompts
FL-4: Store fault exact phrase with journal hint
FL-5: Newer-schema exact phrase, no partial interpretation
FL-7: Drive anomalies as ordinary facts, not affecting projection
CI-2: Four separate service facts match TUI contract
CI-4: Required wording and six disclosures render as adopted
Retired commands (start/stop/run) and --device rejected with pointers
Test results
182 tests passing (139 existing + 43 new), zero regressions.
## Files changed
- src/fenris/status.py — new module (550+ lines): read-only CLI status composition
- tests/test_status.py — 43 new tests covering all acceptance criteria
- fenris.py — replaced old cmd_status, added retired command handlers
## Acceptance criteria verified
- LC-10: Freshness grading with shared constants (fresh/missed/stale/empty)
- LC-4: Configuration error surfaced from direct config reads
- LC-9: Pure read-only composition, never auto-samples, never prompts
- FL-4: Store fault exact phrase with journal hint
- FL-5: Newer-schema exact phrase, no partial interpretation
- FL-7: Drive anomalies as ordinary facts, not affecting projection
- CI-2: Four separate service facts match TUI contract
- CI-4: Required wording and six disclosures render as adopted
- Retired commands (start/stop/run) and --device rejected with pointers
## Test results
182 tests passing (139 existing + 43 new), zero regressions.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Parent
Implement the Fenris persistent TUI monitoring redesign
Canonical contracts: fenris-redesign spec · acceptance criteria — criterion IDs cited below live in the register.
What to build
fenris statusas the read-only CLI twin. It composes from the observation store and allow-listed system facts: the projection facts, the four separate service facts (boot enablement, runtime activity, last collect outcome, freshness), and ajournalctlhint on failure or staleness — never auto-sampling, never prompting. The freshness constants are defined once and shared with the TUI: fresh within 2 × cadence + AccuracySec + 60 s of the newest sample, missed between that and 48 h, stale at ≥ 48 h, empty store reading "no observations yet" with an enable hint; the grade derives from the newest sample timestamp, never a stored flag. A store fault surfaces "observation store unreadable" with a journal hint and suppresses everything store-dependent; a newer-schema store renders "observation store written by a newer Fenris — upgrade Fenris" with no partial interpretation; a configuration error renders as a fact; drive-reported anomalies (critical warnings, media errors, unsafe shutdowns) render as ordinary facts that never affect the projection. Retired commands (start,stop,run) and--deviceare rejected with one-line migration pointers. The required wording and six disclosures render as adopted.Acceptance criteria
configuration error: <reason>from direct reads of the world-readable config (LC-4)statusis a pure read-only composition — never auto-samples, never prompts — with the journal hint on failure or staleness (LC-9)--devicerejected with one-line pointers; the status fact set matches the TUI's four separate facts (LC-9, CI-2)Blocked by
Render as the read-only CLI twinto Render fenris status as the read-only CLI twinResolved in this session.
Implementation
Created — the read-only CLI twin of the TUI (§8.8, LC-9, CI-2).
What was built
Freshness grading (§8.9, LC-10): shared constants — fresh within 2×cadence+AccuracySec+60s, missed between that and 48h, stale ≥48h, empty store greeting with enable hint. Derived from newest sample timestamp, never a stored flag.
Configuration error (§8.3, LC-4): reads directly, surfaces when device selector is missing or invalid.
Store fault and newer-schema (§9.4, §9.5, FL-4, FL-5): exact fixed phrases — with journal hint, — with dependent content suppressed, no partial interpretation.
Drive anomalies (§9.7, FL-7): critical_warning, media_errors, unsafe_shutdowns render as ordinary facts, never affecting the projection.
Four separate service facts (§7.3, LC-9, CI-2): boot enablement, timer activity, last collect outcome, freshness — never merged into one status.
Projection recomputed on read (§6.10): uses existing , never stores derived state.
Retired command rejection (§8.8): , , rejected with one-line migration pointers; rejected with pointer to config file.
Six disclosures (§6.11, CI-4): always available via flag, verbatim from spec.
Updated files
Test results
182 tests passing, zero regressions. All acceptance criteria verified:
Files changed
Acceptance criteria verified
Test results
182 tests passing (139 existing + 43 new), zero regressions.