Two pre-Python readers anchored their awk patterns on the exact leading
whitespace of the machine-written json they parse:
- setup-hermes.sh read artifact-mirror.json with /^ "origin"/ (exact
two spaces), so any other one-member-per-line layout lost the mirror
fallback silently: the mirror url resolved empty and fetch_pinned
reported only the primary url it failed on.
- scripts/install.sh read packages.python.version from pm/lock.json
with exact 4-space and 6-space anchors; on any other layout the pin
resolved empty and the install fell back to the hardcoded "3.14".
setup-hermes.sh's own pin() already established the contract for the
same file ("follow object names and braces, not indentation"); both
sites now follow it. The mirror read is a flat key match; the python
pin uses the same brace-tracking reader as pin().
No other site in the tree has the pattern: setup-hermes.ps1 uses
ConvertFrom-Json, nix uses builtins.fromJSON, python readers use
json.loads, and remaining awk users parse command output, not config.
Tests:
- tests/pm/test_setup_lock_format.py now parametrizes the mirror json
indent (it was fixed at 2, leaving the mirror read unguarded) and
adds a mirror-fallback E2E: the primary url is a dead port (curl
exit 7, retriable), so the staged uv must come from the mirror,
with the mirror json written at 9-space indent. Red on the old
regex (mirror url resolves empty, exit 1), green with the fix.
- tests/test_install_sh_python_pin_indent.py (new) sources
install.sh --manifest and proves bootstrap_python resolves the
pinned version through a fake uv that records its calls, across
2/4/0/tab/blank-line lock layouts.
Verified via scripts/run_tests.sh: 16 passed, 0 failed on the fix; the
new mirror-fallback test fails against the old parsers (verified by
stashing the two script changes and re-running). Sibling install/setup
tests (test_install_sh_node_deps_workspaces, test_install_stage_frames,
test_install_sh_desktop_stage, pm/test_activate_scripts) all green.