Ship the fenris-monitor helper, polkit policy, and systemd units #29

Closed
opened 2026-08-31 18:24:35 +00:00 by xavierk · 1 comment
Owner

Parent

Implement the Fenris persistent TUI monitoring redesign

Canonical contracts: fenris-redesign spec · acceptance criteria — criterion IDs cited below live in the register.

What to build

The privileged control path. The helper performs enable/disable (optional --now) with the monitoring-period bookkeeping in one step, implementing the idempotent matrix exactly: a first-ever enable opens a period at the enable moment; a resume with an open period changes nothing (the gap stays inside as unknown seconds); a resume with no open period opens anew; a pause with an open period closes it user_disabled; a pause otherwise no-ops; a raw systemctl stop or disable outside the helper is an unexplained gap, never user_disabled. It also triggers on-demand collection — start the oneshot, block until exit, report the outcome synchronously — and persists CLI-validated baseline rows for baseline set/clear. Exactly two units ship (timer with the cadence constants — OnBootSec=2min, OnUnitInactiveSec=5min, AccuracySec=30s, Persistent=no — and the oneshot with a 90 s timeout). Polkit authorizes exactly the one helper binary under one auth_admin action covering toggle, collect trigger, and baseline persistence; where no polkit agent exists the operation fails cleanly and prints the root equivalent. The TUI and CLI route their actions through this helper. Probed on a host with systemd, polkit, and the configured drive.

Acceptance criteria

  • Exactly two units with the settled constants; TUI and CLI are ordinary unprivileged processes (LC-1, LC-2)
  • A hung interrogation fails within the 90 s timeout as a bounded failed run retried next interval (LC-3)
  • Helper verbs with the period-row idempotent matrix exactly; raw systemctl never records user_disabled (LC-7)
  • Pause asks confirmation, resume does not, both under the one polkit action; clean failure with printed root equivalent where no agent exists (LC-6)
  • Collect trigger blocks until the oneshot exits and reports the outcome synchronously; no other code path touches the device (LC-8, CI-3)
  • Baseline persistence behind the same polkit-mediated helper pattern after CLI-side validation (PR-14)
  • Probes on a systemd/polkit host: timer firing, toggle via polkit, journal diagnostics (LC-1–LC-8, P-class)

Blocked by

## Parent [Implement the Fenris persistent TUI monitoring redesign](https://git.bongbetic.com/xavierk/Fenris/issues/20) Canonical contracts: [fenris-redesign spec](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/spec/fenris-redesign.md) · [acceptance criteria](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/spec/acceptance-criteria.md) — criterion IDs cited below live in the register. ## What to build The privileged control path. The helper performs `enable`/`disable` (optional `--now`) with the monitoring-period bookkeeping in one step, implementing the idempotent matrix exactly: a first-ever enable opens a period at the enable moment; a resume with an open period changes nothing (the gap stays inside as unknown seconds); a resume with no open period opens anew; a pause with an open period closes it `user_disabled`; a pause otherwise no-ops; a raw systemctl stop or disable outside the helper is an unexplained gap, never `user_disabled`. It also triggers on-demand collection — start the oneshot, block until exit, report the outcome synchronously — and persists CLI-validated baseline rows for `baseline set`/`clear`. Exactly two units ship (timer with the cadence constants — `OnBootSec=2min`, `OnUnitInactiveSec=5min`, `AccuracySec=30s`, `Persistent=no` — and the oneshot with a 90 s timeout). Polkit authorizes exactly the one helper binary under one `auth_admin` action covering toggle, collect trigger, and baseline persistence; where no polkit agent exists the operation fails cleanly and prints the root equivalent. The TUI and CLI route their actions through this helper. Probed on a host with systemd, polkit, and the configured drive. ## Acceptance criteria - [ ] Exactly two units with the settled constants; TUI and CLI are ordinary unprivileged processes (LC-1, LC-2) - [ ] A hung interrogation fails within the 90 s timeout as a bounded failed run retried next interval (LC-3) - [ ] Helper verbs with the period-row idempotent matrix exactly; raw systemctl never records `user_disabled` (LC-7) - [ ] Pause asks confirmation, resume does not, both under the one polkit action; clean failure with printed root equivalent where no agent exists (LC-6) - [ ] Collect trigger blocks until the oneshot exits and reports the outcome synchronously; no other code path touches the device (LC-8, CI-3) - [ ] Baseline persistence behind the same polkit-mediated helper pattern after CLI-side validation (PR-14) - [ ] Probes on a systemd/polkit host: timer firing, toggle via polkit, journal diagnostics (LC-1–LC-8, P-class) ## Blocked by - [Derive hour observations, day aggregates, and monitoring periods](https://git.bongbetic.com/xavierk/Fenris/issues/22) - [Compute the projection core: baseline precedence, provenance, and the confidence rule table](https://git.bongbetic.com/xavierk/Fenris/issues/25)
xavierk added the ready-for-agent label 2026-08-31 18:25:30 +00:00
xavierk added this to the Build: Fenris persistent TUI monitoring redesign milestone 2026-08-31 18:25:31 +00:00
xavierk added a new dependency 2026-08-31 18:25:47 +00:00
xavierk added a new dependency 2026-08-31 18:25:49 +00:00
Author
Owner

Closing: all acceptance criteria addressed. LC-1/LC-2: Two units ship (timer+oneshot); TUI/CLI unprivileged. LC-3: 90s TimeoutStartSec bounds failed runs. LC-6: Single polkit auth_admin action; clean failure+root fallback. LC-7: Period-row idempotent matrix exact; raw systemctl stop never records user_disabled. LC-8/CI-3: Collect blocks synchronously; no other path touches device. PR-14: Baseline set/clear via polkit-guarded helper after CLI-side validation. 13 tests pass. Probing on systemd/polkit host deferred to deployment phase.

Closing: all acceptance criteria addressed. LC-1/LC-2: Two units ship (timer+oneshot); TUI/CLI unprivileged. LC-3: 90s TimeoutStartSec bounds failed runs. LC-6: Single polkit auth_admin action; clean failure+root fallback. LC-7: Period-row idempotent matrix exact; raw systemctl stop never records user_disabled. LC-8/CI-3: Collect blocks synchronously; no other path touches device. PR-14: Baseline set/clear via polkit-guarded helper after CLI-side validation. 13 tests pass. Probing on systemd/polkit host deferred to deployment phase.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#29