Skip to content

fix(runtime): restore retained source after host device migration - #104

Closed
roodboi wants to merge 14 commits into
nextfrom
codex/recover-source-device
Closed

roodboi wants to merge 14 commits into
nextfrom
codex/recover-source-device

Conversation

@roodboi

@roodboi roodboi commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

A retained shared-source graph still names its prior host filesystem device after explicit post-reboot cleanup. Ordinary restore refuses that mismatch. This adds a selection-bound source-device witness so the same run can restore while preserving its original stopped receipt, cleanup proofs and named volumes.

The witness requires exact completed absent-publication cleanup and retirement, current Owner/guest/share identity, and verified retained volumes. It projects only the device in memory and remains pinned through the first new-attempt write. Later ordinary generations use current source ownership; historical witnesses grant no authority. Pending or changed inputs refuse and are preserved. Exact-current cleanup now takes precedence over older enrollment records only after committed historical live/dead cleanup, bridge selection and unresolved-effect checks pass. Legacy physical volume continuity remains explicitly unproven.

Validation at 9da7305: default Rust suites 951 passed / 62 ignored; all-feature suites 1,037 passed / 84 ignored; default and all-feature/all-target strict Clippy, formatting and privacy passed. All eight exact-head CI checks pass. The signed native fixture passed: same-run marker preservation, two ordinary restart cycles, live host source edits reaching the guest, immutable history and verified owned VM/home/alias disposal. The prior device in that fixture is synthetic.

A real retained application accepted the source witness without changing its stopped receipt, Owner bytes or VM boot. Whole-application restart remains a separate gate: its legacy unbranched namespace differs from current named-branch review. No application source/config edits, merge or release publication.

Base: protected next. Depends on #103 and its identity-recovery prerequisites; coordinate those merges before narrowing this diff. Release intent: fix, explicit opt-in recovery only.

@roodboi

roodboi commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by merged #122. This PR’s source was incorporated through #122, squash commit cf4b6e9. Independent acceptance remains in Linear. Closing as superseded; branches and worktrees are retained.

@roodboi roodboi closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant