Skip to content

fix(runtime): recover retained graphs after lost reboot publications - #103

Closed
roodboi wants to merge 9 commits into
nextfrom
codex/recover-absent-publications
Closed

roodboi wants to merge 9 commits into
nextfrom
codex/recover-absent-publications

Conversation

@roodboi

@roodboi roodboi commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

When a host reboot removes a retained graph’s temporary publisher and startup-control directories, ordinary cleanup cannot establish their ownership and refuses recovery. This change adds explicit, selection-bound cleanup for that verified absence while preserving named data and original graph history. Ordinary startup and cleanup remain strict.

The selected original Owner and host inspection are bounded, private inputs. Recovery reserves the foreground lock before acquiring the Engine lease, rechecks exact Owner/boot/share/volume identities, and records durable intent before any startup or bridge effect. Cleanup confirmation and publisher retirement remain separately recorded and verified. Foreign, stale, replaced or pending evidence refuses without adoption. Legacy receipts still cannot establish original physical-volume continuity across a host reboot; the acknowledgement and output state that limitation.

Recovery also explicitly unlocks the VM flock on scope exit, including failure, so inherited descriptors cannot retain it after completion. The regression holds a duplicate descriptor across success and error. Test fixtures now use exclusive directory creation and atomic sequences after a same-timestamp collision was reproduced under parallel execution.

Validation at 571862cc:

  • Default Rust: 944 passed, 62 ignored; all features: 1,030 passed, 83 ignored. Strict default and all-feature all-target Clippy and privacy check passed.
  • Required hosted CI: all eight checks passed on this exact head.
  • Signed native fixture: passed in 38.45 s, including selected/sibling data markers, a forced crash after an owned bridge effect, retry, separate retirement, stale/path replacement refusals, 0644 inspection refusal and exact 0600 copy reselection. Its VM, home and alias were independently confirmed disposed.
  • Maintained TLA controls passed (50 controls); the new positive model explored 247 states, and four guard-removal controls violated their named invariants.
  • CLI/root TypeScript gates passed on the unchanged TypeScript source; CLI: 1,697 passed, 67 skipped.

The native fixture uses synthetic prior-host-boot metadata and no shared source. A real retained post-host-reboot graph also completed this cleanup with stopped-data-retained and unchanged provider Owner bytes. Shared-source translation, normal application restart, retained app-marker readback and signed-in browser acceptance are separate remaining gates. No Event Agent source/config changes or release publication.

Base: protected next. Includes the pending provider/host-identity recovery prerequisites; coordinate their merge before narrowing this diff. Release intent: fix, explicit recovery only.

@roodboi

roodboi commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by merged #122. This PR’s source was incorporated through #122, squash commit cf4b6e9. Independent acceptance remains in Linear. Closing as superseded; branches and worktrees are retained.

@roodboi roodboi closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant