Repository navigation
Conversation
added 19 commits
September 29, 2026 21:41
roodboi
marked this pull request as ready for review
September 30, 2026 15:11
This was referenced Sep 30, 2026
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Legacy dependency socket paths can exhaust a retained pool after its foreground publications are lost, even when every graph has been cleaned and its data retained. Stopped-pool recovery requires another VM boot, which invalidates the exact boot selected by a retained source-rebind witness.
Add explicit
quiescent-dependency-socket-recoveryinspection and hash-selected recovery for a running, idle pool. A temporary pool publication gate closes the race in which a new foreground owner publishes before acquiring the Engine lease. Recovery holds that gate, each selected run lock and the Engine lease, pins provider/host/guest/graph/volume identity, requires empty dependency and bridge reservations and absent guest compute, and rechecks the proof before each selected socket unlink. Its separate immutable journal supports exact partial retry. Owner bytes, data, source witnesses and VM boot remain unchanged.Validation: pinned Rust formatting and Clippy with warnings denied, default and all-feature suites (964/1,050 passed; 62/84 opt-in tests ignored), regression controls for publication concurrency, live listeners, replacement paths, proof drift, pending/malformed receipts and partial retry, CLI argument rejection, staged privacy scan and diff checks passed. All eight exact-head CI checks passed. The signed M3 native fixture passed live-listener, wrong-selection, replacement-path, held-publication-gate, exact removal and idempotent retry controls, then confirmed managed fixture cleanup. Actual Event Agent recovery removed six selected stale sockets while retaining byte-identical Owner and both graph receipts, the VM process, guest boot and data.
Application startup now proceeds past socket capacity but encounters a separate retained cache-scope mismatch after a host filesystem device change. That follow-up and Event Agent retained marker/browser acceptance remain open; this recovery component does not claim full application acceptance.
This is explicit cooperative legacy migration, not adoption of an unknown live relay or proof of its original creator. It conservatively refuses remaining guest container objects and foreground roots with content beyond the lock-only recovery reservation.
Depends on the retained recovery chain through #105. Base:
next. Release signal:fix, opt-in native candidate recovery; no publishing change.