# AIM 3.3.0rc8 controller acceptance Run on disposable/approved targets under the actual execution UID, groups, HOME and service sandbox, using native ansible-core 2.19.11 and declared collections. Do not use an ordinary root shell as evidence for another worker. Do not send raw Vaults/config secrets in test feedback. Keep the staging exceptions from the accepted deployment. ## Installation and unchanged controls Verify checksum, preview the deployer, confirm only named obsolete Core docs are removed, quiesce jobs/writers and apply. Verify `aim --version`, `aimctl --version`, capabilities, independent terminal startup, Vault wrong-then-correct retry and cancellation. Confirm operator aim.yml/inventory/keys/add-on state are unchanged. `aimctl staging-check` must pass inside the executor, including differing process and passwd homes when relevant. ## Discover the new contract without credentials ```bash aimctl capabilities printf '%s\n' '{"api_version":"1.0","operation":"list_playbooks","customer":"CUSTOMER"}' | aimctl request printf '%s\n' '{"api_version":"1.0","operation":"prepare","request":{"customer":"CUSTOMER","playbook":"debug_detect_host_roles","hosts":["HOST"]}}' | aimctl request ``` Replace identifiers. Request JSON is one line. Expect operation_results capability and prepared result_contract with host_capabilities_v1; unchanged explicit targets/revision. Nonreporting `debug_test_connection` must advertise result:null. Unknown options/hosts must still fail before launch. Schema changes must stale an earlier preparation. ## Fresh approved execution matrix Supply credentials through the established one-run provider/private FD. Use summary and detail on separate newly approved runs; compare reports rather than event ordering. Do not cache the password or reuse a provider/revision after source changes. | Operation | Evidence required | |---|---| | Detect roles | Eight booleans agree with authorized native report; no inventory mutation | | Disk usage | Compare Windows/Linux observed byte counts; handle unavailable/empty mounts | | Export event logs | Paths exist after apply; existing logs not cleared; check creates no export | | Start services | Disposable services: one recoverable, one failing dependency/disabled/race case, one excluded; compare before/after states and fixed reasons | | Patch OS | Disposable snapshots: verify Linux net package/version changes; Windows uses one native win_updates wave per approved patch stage; IDs/KBs/HRESULTs; user-visible reboot message/delay; default stops after reboot with continuation_required; explicit post-reboot continuation starts another wave | | Checkmk cleanup | Preview removes nothing; approved deletion lists only managed files actually changed | | Read Checkmk user config | Plugins/local/unknown sections preserved in report; dummy passphrase and MRPE command data redacted; reject other basenames; no timestamp/content write | | Checkmk install | Installed version agrees with registry/package DB; services observed; idempotent rerun shows no package/config changes | | Checkmk config update | One approved rule/file change reported; second run no change; unrelated local/MRPE/unknown files untouched | New reporting tasks change task counts. Compare effects, failure states and payloads, not historical exact ok/skipped totals. For patching, protect against concurrent package management and record starting snapshot/selected categories. A partial update still requires explicit recovery decisions; never repeat automatically. ### Windows patch-wave acceptance Use a disposable Windows target with several applicable updates. Confirm the normal apply path contains one `win_updates state=installed` task for the selected categories rather than one task per update. Windows/collection-native sequencing inside that wave is expected; AIM should not emit `accept_list` selectors for individual discovered updates. Record the structured result and compare it to Windows Update history. Installed and failed updates should retain bounded IDs/titles/KBs/HRESULT classifications. A mixed native result must not lose successful updates merely because another update failed. Raw failure messages or exception text must not enter the operation result. With `os_patching_rescan_after_reboot: false` (catalog default), allow the current wave to finish and require reboot. The user should receive the reviewed message/delay. After reconnect the run must end without another install/search wave. Expect `continuation_required: true` and `remaining_updates_known: false`; a new approved run owns the next patch state. Also test a host that begins with an already-pending reboot. With automatic reboot enabled and post-reboot continuation false, AIM should reboot and stop before patch installation. With continuation true, it may begin the first native update wave after reboot. With automatic reboot disabled, it must fail preflight before new installs. Repeat with `os_patching_rescan_after_reboot: true`. After a patch-triggered reboot AIM may start another native update wave. Do not infer this opt-in from the reboot flag. Explicit continuation remains bounded to 12 waves. A failed wave must stop and must never be replayed automatically. For a failed update, confirm `failed_updates` contains only bounded title/ID, unsigned/hex HRESULT, reason and fixed message. If `0x80240016` can be reproduced, expect `install_not_allowed`; do not expect `preexisting_reboot_required` unless the separate preflight actually observed a pending reboot. ## Fail-closed fixtures (disposable catalog/playbook only) After each fixture edit, prepare/review anew. Test missing required publisher; wrong schema/type/extra fields; publisher under no_log; duplicate publication; >limit data; and a supplied secret canary in an output string. Expect no rejected payload in public JSON/logs. Native exit 0 with invalid/missing required data must fail at result_validation, retain exit_code 0/native target facts and never replay. No declaration must export nothing even if unrelated debug/custom stats contain a secret. Test two targets with one unreachable and one completed report. Overall native failure remains; one available report does not imply all-target success. Test Ctrl+C mid-run: report must not claim earlier observations are completed output. Ensure no residual credential/helper process and a subsequent fresh operation works. Test chunked output beyond a single private frame; a torn stream must fail, never silently truncate. ## Sign-off Record version, execution UID/group context, runtime/collection versions, platform and which cases were tested, separately for native terminal and service. Do not mark global transport, another OS, Server 2012 R2 or another service identity accepted from one Windows 11 test. Report final status/exit/target facts/report availability with credentials removed.