Skip to content

fix(runtime): recover selected dependency sockets in a quiescent live pool - #110

Closed
roodboi wants to merge 19 commits into
nextfrom
codex/recover-quiescent-dependency-sockets
Closed

roodboi wants to merge 19 commits into
nextfrom
codex/recover-quiescent-dependency-sockets

Conversation

@roodboi

@roodboi roodboi commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Legacy dependency socket paths can exhaust a retained pool after its foreground publications are lost, even when every graph has been cleaned and its data retained. Stopped-pool recovery requires another VM boot, which invalidates the exact boot selected by a retained source-rebind witness.

Add explicit quiescent-dependency-socket-recovery inspection and hash-selected recovery for a running, idle pool. A temporary pool publication gate closes the race in which a new foreground owner publishes before acquiring the Engine lease. Recovery holds that gate, each selected run lock and the Engine lease, pins provider/host/guest/graph/volume identity, requires empty dependency and bridge reservations and absent guest compute, and rechecks the proof before each selected socket unlink. Its separate immutable journal supports exact partial retry. Owner bytes, data, source witnesses and VM boot remain unchanged.

Validation: pinned Rust formatting and Clippy with warnings denied, default and all-feature suites (964/1,050 passed; 62/84 opt-in tests ignored), regression controls for publication concurrency, live listeners, replacement paths, proof drift, pending/malformed receipts and partial retry, CLI argument rejection, staged privacy scan and diff checks passed. All eight exact-head CI checks passed. The signed M3 native fixture passed live-listener, wrong-selection, replacement-path, held-publication-gate, exact removal and idempotent retry controls, then confirmed managed fixture cleanup. Actual Event Agent recovery removed six selected stale sockets while retaining byte-identical Owner and both graph receipts, the VM process, guest boot and data.

Application startup now proceeds past socket capacity but encounters a separate retained cache-scope mismatch after a host filesystem device change. That follow-up and Event Agent retained marker/browser acceptance remain open; this recovery component does not claim full application acceptance.

This is explicit cooperative legacy migration, not adoption of an unknown live relay or proof of its original creator. It conservatively refuses remaining guest container objects and foreground roots with content beyond the lock-only recovery reservation.

Depends on the retained recovery chain through #105. Base: next. Release signal: fix, opt-in native candidate recovery; no publishing change.

@roodboi

roodboi commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by merged #122. This PR’s source was incorporated through #122, squash commit cf4b6e9. Independent acceptance remains in Linear. Closing as superseded; branches and worktrees are retained.

@roodboi roodboi closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant