Public/Update-KadenRepo.ps1

function Update-KadenRepo {
    <#
    .SYNOPSIS
        Apply the installed Kaden managed payload to an initialized child repository.
    .DESCRIPTION
        Validates the installed package, refuses to proceed when another update holds
        the lock or an incomplete transaction remains, then applies allowlisted managed
        files under a child-root journal. Child-owned overlays outside the managed-file
        manifest are preserved. Unknown keys already present in `.kaden.json` survive
        the version-state write. Invalid JSON in the shared manifest is refused
        before any managed file changes, with instructions to repair or restore it.
        A failure to read the file is left as that read error.
        Delimited Kaden blocks in AGENTS.md and .github/copilot-instructions.md are refreshed.
        The markers are <!-- KADEN:START --> and <!-- KADEN:END -->.
        Project text outside those markers stays. A missing AGENTS.md is left alone.
        A missing .github/copilot-instructions.md is created with a short project header and the delimited Kaden block.
        A malformed marker pair is left unchanged and reported on InstructionFindings.
        Project instruction overlays under .github/instructions/ are not modified.
    .EXAMPLE
        Update-KadenRepo -Path .
    #>

    [CmdletBinding(SupportsShouldProcess = $true)]
    param(
        [Parameter(Mandatory = $true)]
        [string]$Path
    )

    $childRoot = Resolve-KadenChildRoot -Path $Path
    if (-not (Test-Path -LiteralPath $childRoot)) {
        throw "KDN-TXN-PREFLIGHT-FAILED: Child repository path does not exist: $childRoot"
    }

    if (-not $PSCmdlet.ShouldProcess($childRoot, 'Update-KadenRepo')) {
        return
    }

    $sharedPath = Join-Path $childRoot '.kaden.json'
    if (-not (Test-Path -LiteralPath $sharedPath)) {
        throw 'KDN-TXN-PREFLIGHT-FAILED: Child repository is not initialized (.kaden.json missing). Run Initialize-KadenRepo first.'
    }

    if (Test-KadenIncompleteTransaction -ChildRoot $childRoot) {
        throw 'KDN-TXN-REPAIR-REQUIRED: An incomplete Kaden transaction remains. Run Repair-KadenRepo -Action Resume or -Action Restore before updating again.'
    }

    $payload = Test-KadenPackagePayload
    if (-not $payload.Valid) {
        throw $payload.Message
    }

    $sharedRaw = Get-Content -LiteralPath $sharedPath -Raw
    try {
        $shared = $sharedRaw | ConvertFrom-Json
    }
    catch {
        throw 'KDN-TXN-PREFLIGHT-FAILED: Shared configuration is corrupt. Repair .kaden.json or restore it from version control, then retry.'
    }
    $projectId = [string]$shared.projectId
    if ([string]::IsNullOrWhiteSpace($projectId)) {
        throw 'KDN-TXN-PREFLIGHT-FAILED: Shared manifest is missing projectId.'
    }

    $moduleVersion = Get-KadenRunningModuleVersion

    $instructionFindings = @(Invoke-KadenManagedInstructionUpdate -ChildRoot $childRoot -ProjectId $projectId `
            -Manifest $payload.Manifest -PayloadRoot (Get-KadenPayloadRoot) -ModuleVersion $moduleVersion)

    return [pscustomobject]@{
        Succeeded           = $true
        Path                = $childRoot
        ProjectId           = $projectId
        AppliedVersion      = $moduleVersion
        InstructionFindings = $instructionFindings
    }
}