Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
10697ae
fix: recover missing native provider HOME aliases
Sep 30, 2026
8f99174
fix: explicitly recover legacy host filesystem device identities
Sep 30, 2026
4b5bdff
fix: fence replaced lock paths before filesystem recovery
Sep 30, 2026
cb0302a
fix: explicitly repair native project mapping device identities
Sep 30, 2026
3266931
fix: explicitly recover retained graph host pins after reboot
Sep 30, 2026
2404e43
test(runtime): model absent publication recovery safety
Sep 30, 2026
b3a9246
fix(runtime): recover retained graphs after lost reboot publications
Sep 30, 2026
18fc123
fix(runtime): release recovery VM locks with inherited descriptors
Sep 30, 2026
54f5541
test(runtime): preserve private recovery inspection selection
Sep 30, 2026
8e76aa5
test(runtime): isolate concurrent recovery fixture roots
Sep 30, 2026
318b39c
fix(runtime): restore retained source after host device migration
Sep 30, 2026
b843857
test(runtime): isolate publisher acknowledgement transport
Sep 30, 2026
015e00d
test(runtime): qualify bind-only source recovery invocation
Sep 30, 2026
0f3b971
fix(runtime): prefer verified current cleanup over historical enrollment
Sep 30, 2026
9da7305
test(runtime): stabilize source recovery lifecycle fixtures
Sep 30, 2026
dddebc8
fix(cli): preserve legacy namespaces during retained branch startup
Sep 30, 2026
46fe63e
fix(cli): select retained routing before branch normalization
Sep 30, 2026
87f1239
fix(cli): verify active legacy branch restart identity
Sep 30, 2026
5535152
fix(cli): retain content IDs when restoring unchanged image declarations
Sep 30, 2026
f90bdd8
fix(runtime): recover selected dependency sockets in a quiescent live…
Sep 30, 2026
7dc0811
fix(runtime): preserve witnessed dependency cache scope on restore
Sep 30, 2026
ee4bf3a
fix(runtime): archive retired dependency rebind before restore
Sep 30, 2026
ffdabaf
chore: reconcile retained recovery with latest next
Sep 30, 2026
2320bf9
test(native): cover retired dependency journal across restored genera…
Sep 30, 2026
0b80466
fix: retire acknowledged stopped graph publishers explicitly
Sep 30, 2026
9c78243
test(native): refresh only the live dependency service
Sep 30, 2026
ff48ed7
test: serialize the frontend acceptance stand-in's shared state
Sep 30, 2026
65a7cc8
test(native): use pinned Bun HTTP fixture for endpoint proof
Sep 30, 2026
df82fde
fix(runtime): release acknowledged dead dependency claims without los…
Sep 30, 2026
b49fbda
refactor(runtime): name the observed dependency record tuple
Sep 30, 2026
e372326
fix: keep a published Unix socket's identity through startup failure
Sep 30, 2026
01424a9
test: observe the MCP socket's private mode where it is now set
Sep 30, 2026
45fb8f3
fix: never remove or chmod an unproven staging entry when publishing …
Sep 30, 2026
fba8691
fix: move an unproven staging entry aside without overwriting a holdi…
Sep 30, 2026
2fe54aa
fix(runtime): archive exact quiescent HTTPS owner evidence
Sep 30, 2026
7718f2a
fix(runtime): select legacy HTTPS device migration explicitly
Sep 30, 2026
b34fba3
fix(runtime): budget retained live pools without duplicate disk alloc…
Sep 30, 2026
de2017c
fix(native): preflight explicit recovery of stopped retained graphs
Sep 30, 2026
f88c422
fix(native): retain admitted images in stopped restart preflight
Sep 30, 2026
4a9ac29
fix(runtime): confirm acknowledged publisher retirement during restart
Sep 30, 2026
1b9b896
fix(runtime): recover same-boot owners after completed dependency ref…
Oct 1, 2026
a330a73
fix(runtime): admit restore with current completed retention proof
Oct 1, 2026
fd284a4
chore: reconcile retained recovery candidate with next
Oct 1, 2026
9367020
chore: reconcile selected project mapping repair with recovery candidate
Oct 1, 2026
b357e03
chore: reconcile retired rebind qualification with current candidate
Oct 1, 2026
a593885
test: reconcile retained rebind fixture with mapping recovery
Oct 1, 2026
90ecf2a
test: make foreign socket replacement mode independent of umask
Oct 1, 2026
efdcdf6
test(native): align synthetic prior-boot reservation evidence
Oct 1, 2026
894ae2f
Merge commit 'efdcdf6ed9c8c0af067541e927367714a491aafe' into codex/sa…
Oct 1, 2026
bf8c7f2
test(native): preserve retired journal qualification failures
Oct 1, 2026
c76ed1e
Merge retired journal failure-preservation fixture
Oct 1, 2026
a6a9cee
fix(native): preserve bounded foreground cleanup cause codes
Oct 1, 2026
f029887
fix(runtime): align graph cleanup with environment admission capacity
Oct 1, 2026
67b41f8
fix(runtime): keep superseded recovery history inert after eviction
Oct 1, 2026
37bcfdb
fix(runtime): keep completed dependency archives inert during restore
Oct 1, 2026
f9d20fc
fix(runtime): retain unexpected startup listener exit evidence
Oct 1, 2026
a056624
fix(runtime): serialize HTTPS owner recovery and frontend finalization
Oct 2, 2026
bc35d11
test(runtime): retire legacy fixture dependency ownership explicitly
Oct 2, 2026
daa0350
fix(runtime): retire verified exited helpers before graph cleanup
Oct 2, 2026
0ca852e
fix(runtime): archive verified evicted cleanup history
Oct 2, 2026
4fc8b1d
fix(runtime): prefer current completed recovery authority
Oct 2, 2026
fc99bfa
test(runtime): model interrupted shared HTTPS archival
Oct 2, 2026
50969e5
fix(runtime): archive verified prior-boot shared HTTPS owners
Oct 2, 2026
f9f32c9
fix(runtime): recover selected interrupted startup cleanup
Oct 2, 2026
dd67e2e
fix(runtime): recover cleanup after normal relay exit
Oct 3, 2026
a774b8f
fix(runtime): retain verified caches during interrupted cleanup
Oct 3, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion .ai/skills/hack-repo-verify/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ untracked candidate additions. Keep private artifacts excluded from the index.
| Rust state/recovery | `packages/runtime-core/tests/` plus module tests; malformed/stale ownership, crash window, resume and data preservation |
| TLA models | `test:models`, [model mappings](../../../tests/models/tla/README.md), [runner](../../../scripts/check-tla-models.ts) and expected positive/negative controls |
| Consumer instructions | [ownership](../../../docs/agent-guidance.md), `bun run generate:agent-plugins`, affected examples and source/render tests |
| Native VM/routing/reclamation | candidate guide (local `_docs/docs/plans/v5/development.md`), relevant ledger gate and isolated host fixture; Linux checks cannot qualify macOS effects |
| Native VM/routing/reclamation | [candidate guide](../../../docs/guides/native-candidate.md), relevant acceptance gate and isolated host fixture; Linux checks cannot qualify macOS effects |
| Resource/performance claims | [performance skill](../hack-repo-performance/SKILL.md), matched workload and measured boundaries |

Read [CI](../../../.github/workflows/ci.yml) for current hosted gates. A local pass
Expand All @@ -63,6 +63,14 @@ not default local-product requirements; use them only for explicitly scoped work
## Verify the verifier

Treat unavailable prerequisites, ignored tests, cached results and timeouts explicitly.
Before an ignored native graph fixture, read its prerequisites in the
[runtime README](../../../packages/runtime-core/README.md). Some fixtures require
a caller-prepared pool: use the managed provider, engine and network-tool setup,
start the required socket capacity, load the pinned image, and verify runtime
status before invoking the test. Record the current-source test executable and
candidate bundle separately. An unprepared-pool failure does not exercise the
scenario; preserve its evidence and fix setup before rerunning.

TLC must explore the intended states; its negative control must fail the named
invariant with the expected trace, not merely return nonzero. A small abstract model
needs source mapping and implementation regression evidence; use
Expand Down
336 changes: 326 additions & 10 deletions docs/guides/native-candidate.md

Large diffs are not rendered by default.

4 changes: 4 additions & 0 deletions docs/reference/cli.md
Original file line number Diff line number Diff line change
Expand Up @@ -1263,6 +1263,10 @@ hack doctor [options]
| `--json` | Output JSON (machine-readable) |
| `--browser-url https://app.hack` | HTTPS origin manually tested in the browser (no path or credentials) |
| `--browser-result unknown|works|fails|permission-denied` | Your manual browser observation for --browser-url (default: unknown) |
| `--branch <name>` | Run against a branch-specific instance (compose name + hostnames) |
| `--native-run-mapping inspect|repair` | Inspect or explicitly repair a native run mapping after filesystem device renumbering |
| `--expect-selection <64-hex>` | Require the exact run-mapping recovery inspection selection |
| `--accept-legacy-device-rebind` | Explicitly accept legacy migration without proof of original filesystem volume continuity |
| `--no-interactive` | Never prompt: apply documented defaults or fail with E_INTERACTIVE_REQUIRED (also via HACK_NO_INTERACTIVE=1) |
| `--help, -h` | Show help |
| `--version, -v` | Show version |
Expand Down
205 changes: 205 additions & 0 deletions packages/runtime-core/README.md

Large diffs are not rendered by default.

304 changes: 304 additions & 0 deletions packages/runtime-core/src/graph_cli.rs
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,310 @@ pub fn command(candidate: &Candidate, args: &[&str]) -> Result<Value, CandidateE
let Some((action, args)) = args.split_first() else {
return Err(invalid());
};
if *action == "inspect-interrupted-start-cleanup" {
let run = match *args {
["--run-id", run] | ["--run-id", run, "--json"] => run,
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::inspect_interrupted_start_cleanup(candidate, run);
}
#[cfg(not(target_os = "macos"))]
{
let _ = run;
return Err(invalid());
}
}
if *action == "recover-interrupted-start-cleanup" {
let (run, expected) = match *args {
[
"--run-id",
run,
"--expect-selection",
expected,
"--retain-data",
]
| [
"--run-id",
run,
"--expect-selection",
expected,
"--retain-data",
"--json",
] => (run, expected),
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::recover_interrupted_start_cleanup(candidate, run, expected);
}
#[cfg(not(target_os = "macos"))]
{
let _ = (run, expected);
return Err(invalid());
}
}
if *action == "release-acknowledged-dependencies" {
let (run, owner, receipt, publisher, reservation) = match *args {
[
"--run-id",
run,
"--expect-owner",
owner,
"--expect-receipt",
receipt,
"--expect-publisher",
publisher,
"--expect-reservation",
reservation,
]
| [
"--run-id",
run,
"--expect-owner",
owner,
"--expect-receipt",
receipt,
"--expect-publisher",
publisher,
"--expect-reservation",
reservation,
"--json",
] => (run, owner, receipt, publisher, reservation),
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::release_acknowledged_dependencies(
candidate,
graph::AcknowledgedPublisherSelection {
run,
owner,
receipt_sha256: receipt,
publisher_sha256: publisher,
},
reservation,
);
}
#[cfg(not(target_os = "macos"))]
{
let _ = (run, owner, receipt, publisher, reservation);
return Err(invalid());
}
}
if *action == "retire-acknowledged-publisher" {
let (run, owner, receipt, publisher) = match *args {
[
"--run-id",
run,
"--expect-owner",
owner,
"--expect-receipt",
receipt,
"--expect-publisher",
publisher,
]
| [
"--run-id",
run,
"--expect-owner",
owner,
"--expect-receipt",
receipt,
"--expect-publisher",
publisher,
"--json",
] => (run, owner, receipt, publisher),
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::retire_acknowledged_publisher(
candidate,
graph::AcknowledgedPublisherSelection {
run,
owner,
receipt_sha256: receipt,
publisher_sha256: publisher,
},
);
}
#[cfg(not(target_os = "macos"))]
{
let _ = (run, owner, receipt, publisher);
return Err(invalid());
}
}
if *action == "inspect-host-pin-recovery" {
let run = match *args {
["--run-id", run] | ["--run-id", run, "--json"] => run,
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::inspect_host_pin_recovery(candidate, run);
}
#[cfg(not(target_os = "macos"))]
{
let _ = run;
return Err(invalid());
}
}
if *action == "recover-host-pins" {
let (run, expected) = match *args {
[
"--run-id",
run,
"--expect-selection",
expected,
"--accept-legacy-device-rebind",
]
| [
"--run-id",
run,
"--expect-selection",
expected,
"--accept-legacy-device-rebind",
"--json",
] => (run, expected),
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::recover_host_pins(candidate, run, expected);
}
#[cfg(not(target_os = "macos"))]
{
let _ = (run, expected);
return Err(invalid());
}
}
if *action == "inspect-absent-publication-cleanup" {
let (run, original, inspection) = match *args {
[
"--run-id",
run,
"--original-owner-file",
original,
"--host-inspection-file",
inspection,
]
| [
"--run-id",
run,
"--original-owner-file",
original,
"--host-inspection-file",
inspection,
"--json",
] => (run, original, inspection),
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::inspect_absent_publication_cleanup(
candidate,
run,
Path::new(original),
Path::new(inspection),
);
}
#[cfg(not(target_os = "macos"))]
{
let _ = (run, original, inspection);
return Err(invalid());
}
}
if *action == "recover-absent-publication-cleanup" {
let (run, original, inspection, expected) = match *args {
[
"--run-id",
run,
"--original-owner-file",
original,
"--host-inspection-file",
inspection,
"--expect-selection",
expected,
"--retain-data",
"--accept-unpinned-post-reboot",
]
| [
"--run-id",
run,
"--original-owner-file",
original,
"--host-inspection-file",
inspection,
"--expect-selection",
expected,
"--retain-data",
"--accept-unpinned-post-reboot",
"--json",
] => (run, original, inspection, expected),
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::recover_absent_publication_cleanup(
candidate,
run,
expected,
Path::new(original),
Path::new(inspection),
);
}
#[cfg(not(target_os = "macos"))]
{
let _ = (run, original, inspection, expected);
return Err(invalid());
}
}
if *action == "inspect-source-device-rebind" {
let run = match *args {
["--run-id", run] | ["--run-id", run, "--json"] => run,
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::inspect_source_device_rebind(candidate, run);
}
#[cfg(not(target_os = "macos"))]
{
let _ = run;
return Err(invalid());
}
}
if *action == "recover-source-device-rebind" {
let (run, expected) = match *args {
[
"--run-id",
run,
"--expect-selection",
expected,
"--accept-legacy-device-rebind",
]
| [
"--run-id",
run,
"--expect-selection",
expected,
"--accept-legacy-device-rebind",
"--json",
] => (run, expected),
_ => return Err(invalid()),
};
#[cfg(target_os = "macos")]
{
return graph::recover_source_device_rebind(candidate, run, expected);
}
#[cfg(not(target_os = "macos"))]
{
let _ = (run, expected);
return Err(invalid());
}
}
if ["run-selection", "run-service"].contains(action) {
return one_off::command(candidate, action, args);
}
Expand Down
Loading
Loading