# Task 6 — Version, aggregate doctor, and build-aware start Status: complete. Implemented the host-side `tht version`, aggregate `tht doctor [--json]`, and `tht start [--build]` contracts. - `version` is descriptor-free and reports semantic version, commit, build time, OS, and architecture. - `doctor` emits typed, redacted checks for descriptor state, Docker/Compose, rendered volumes, file permissions, service health, workspace registry, the container-local workflow doctor, and Pi doctor. Its JSON mode writes exactly one JSON document to stdout. - The Python workflow doctor is invoked only as `docker compose exec -T core tht doctor --json` after core is running. - `start` uses the shared lifecycle service: default `up → health`; `--build` is `build → up → health`. - `setup` now reuses the shared lifecycle and aggregate diagnostics rather than keeping parallel health/volume implementations. Verification performed without live Docker/container commands: ```bash cd tools/tht go test ./internal/version ./internal/doctor ./internal/service ./cmd/tht \ -run 'TestVersion|TestDoctor|TestStart|TestCurrent|TestRun' -count=1 go test ./internal/setup -count=1 -run 'TestRun' -v go test ./... -count=1 git diff --check ``` All completed successfully. The intentionally fake runner coverage includes unavailable Docker, stopped/running core, workflow failure redaction, pristine JSON output, and start ordering. Concerns: no live Docker validation or host installation was run, by explicit task constraint. ## Fix round 1 Completed the independent-review follow-up without live Docker operations. - `workspace-registry` now executes a container-local, read-only Node validation of `/data/workspace-registry/state/active.json` and every declared snapshot descriptor. It no longer passes merely because Compose declares a volume. - Host file permissions are checked before Docker/Compose availability and therefore remain visible as failures when Docker is unavailable. - Separate typed, bounded HTTP probes verify core (`curl --max-time 5`) and frontend (`wget -T 5`) reachability, independently of Compose health. The probe is injectable in tests. - The successful report tests assert the stable full checklist: `descriptor`, `files`, `docker`, `compose`, `configuration`, `services`, `core-http`, `frontend-http`, `workspace-registry`, `workflow`, `pi`. Additional verification: ```bash cd tools/tht go test ./internal/doctor -run 'TestRun(ChecksUnsafeFilesEvenWhenDockerIsUnavailable|FailsAnInvalidContainerLocalRegistryState|ReportsEachHTTPReachabilityProbeFailure|UsesOnlyContainerLocalWorkflowAndPiDiagnosticsWhenCoreRuns)' -count=1 -v go test ./internal/doctor ./internal/setup ./internal/service ./cmd/tht -count=1 go test ./... -count=1 git diff --check ``` All passed with fake runners/probes only. No live container, HTTP endpoint, or host installation was touched.