Skip to content

fix(runtime): release acknowledged dead dependency claims without losing evidence - #117

Closed
roodboi wants to merge 26 commits into
nextfrom
codex/release-acknowledged-dependencies
Closed

roodboi wants to merge 26 commits into
nextfrom
codex/release-acknowledged-dependencies

Conversation

@roodboi

@roodboi roodboi commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

A failed retained startup can complete current-boot graph cleanup and close its dependency sockets, then fail during journal archival before releasing its dependency reservation. After publisher retirement, normal up refuses the surviving same-run claim.

Add private release-acknowledged-dependencies recovery with exact run, Owner, stopped receipt, retired publisher and inspected reservation selectors. It requires the current cleanup ACK and independently verified resource/inventory effect, the exact completed retirement, and a dead reservation process matching that publisher, run, Owner, boot and receipt slots. Every selected socket must already be absent. The claim moves exclusively into graph history with original bytes/inode preserved; exact post-move retry is supported. Current proof and canonical HOME/alias, parent, source and destination identities are checked at effect boundaries. No socket, VM, graph receipt, dependency journal, retained data or sibling is changed.

Validation: focused selector, live/foreign/pending socket, stale process/boot/slot, source/HOME/parent/history replacement, interrupted fence, exact retry and sibling controls pass. Full Rust tests at the implementation revision passed 987 default and 1,075 all-feature tests (62/84 explicit ignores). Independent source review found no remaining blocker. Strict Clippy default and all-target/all-feature, format/privacy/diff, final bundle signatures and six checksums pass. Fresh CLI typecheck/lint and 1,724 Bun tests pass (67 explicit skips); the DB Turbo task was cached, CLI tasks were fresh. On M3, stale selector rejection, actual retained Event Agent claim release, exact repeat recovery and unchanged Owner/receipt/sibling/journal/witness were verified. All eight hosted CI checks pass at exact head b49fbda. Normal retained up passed reservation allocation and archived the old completed journal with original bytes preserved, then refused a separate dependency-connected listener exit before readiness. Ordinary cleanup now finishes, retains the four named volumes and releases the new claim. Full retained app readiness/data/browser acceptance remains open. The PR stays draft until those integration gates are recorded.

Release signal: fix, private v5 cleanup/recovery correction. Based on next; includes the pending stack through #115. New implementation commits df82fde and b49fbda. HACK-1210/HACK-1159 track current application acceptance. No release publication is included.

hack-cli-tests added 26 commits September 29, 2026 21:41
Stand-in invocations ran concurrently (a foreground `up` while the driver
polls `ps`) and each did an unlocked read-modify-write of state.json. A
`ps` that loaded the state before the second `up` saved its foreground
token then saved its stale copy over it, so `up` saw its token gone and
exited 0 before readiness; lost call records failed the acceptance test
as well. That failed 26 of 40 local runs, and Runtime state models on CI.

Each invocation now holds an exclusive flock across its read-modify-write
and releases it only before its long waits (the foreground loop and the
ps-hang fault). 40 of 40 local runs pass.
@roodboi

roodboi commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by merged #122. This PR’s source was incorporated through #122, squash commit cf4b6e9. Independent acceptance remains in Linear. Closing as superseded; branches and worktrees are retained.

@roodboi roodboi closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant