Skip to content

feat: preserve existing basic-build resources during adoption - #220

Merged
roodboi merged 37 commits into
nextfrom
feat/native-retained-build-adoption
Oct 9, 2026
Merged

roodboi merged 37 commits into
nextfrom
feat/native-retained-build-adoption

Conversation

@roodboi

@roodboi roodboi commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Existing basic-build projects can explicitly adopt their stopped original Compose resources while preserving their images, container IDs and named data. Version 9 binds the authored build, bounded current context projection, Dockerfile/ignore inputs, image reference and birth, and saved configuration hashes. Format switch, retained start/stop, recovery and rollback neither build nor pull nor recreate those resources.

The closed subset supports root and .hack contexts, Dockerfile-specific ignore precedence, qualified inclusion/negation and explicit exclusion of owned outputs. Explicit pull_policy: build, advanced cache/platform/secret/SSH options and unsupported feature intersections refuse before context acquisition. This proves current source and retained image identity; it does not attest which historical source produced an image. Prior receipt meanings and completed-job authority remain separate.

The maintained two-worktree scenario explicitly qualifies the local default BuildKit builder, compares complete decoded COPY . output with the captured projection, and exercises SQL/image/container/volume-birth isolation, partial stop, source drift, recovery and rollback. After bootstrap its closed transport refuses builder and allocation commands. Cleanup accepts only the exact captured final image or its closed labelled parent chain, with baseline exclusions and fresh birth/tag/digest/reference/daemon/residual-inventory checks around each nonforce ID-only removal. Unknown objects remain retained; general builder-cache ownership and reclamation are unqualified.

The fixture handles an absent image Parent key without normalizing malformed present values. It admits only the exact captured public Compose project/service/release label triplet alongside its own fixed labels and carries that release through saved graph cleanup. Its latest correction issues recovery-stop transport authority only for the exact down --recover --json invocation, allowing original IDs to stop while the active generation retains its interrupted start journal. Generation, full service selection, original ID and current daemon fences remain required. Private CLI evidence records closed operation/substage names and exit/code classifications before caller assertions. Production ownership, errors and deadlines are unchanged.

Validation at current cf0bf3a1:

  • Independent cumulative source review covers the fixture-only recovery correction and normal reconciliation with canonical 7c810a55; that merge preserves the correction tree exactly. The subsequent lint-only import/block repair is separately reviewed.
  • Sixteen focused tests passed with 85 assertions. They invoke the actual emitted shim with a synthetic engine, prove the prior pending-start/stop mismatch, require the exact issued invocation, retain receipt bytes, and verify zero forwarding for wrong IDs, services, generation, publication or daemon. Diagnostic tests preserve original results/errors and omit private replies, unknown labels/codes and unreadable or oversized data. No real engine is used.
  • CLI strict typecheck, changed-path lint, privacy and diff checks passed. Two inherited complexity warnings remain. The initial lint failure is retained separately from its equivalent repair.
  • One fresh matching CLI build at cf0bf3a1 passed (766 modules), followed by compiled version and compiler-only validation. Its bytes equal the historical bundle because production inputs are unchanged, but the new receipt records the actual current build and new private file incarnations. Compiler reuse has exact production/generated/Cargo/toolchain parity; the whole package differs only in its named test file. The refreshed recipe has independent source review and private strict/shell checks. ROOT granted and executed one current bounded trial with hosted CI still pending; its executed CI/full flags correctly remained false. Fresh exact-head hosted checks now show all twelve jobs passed, including Docker E2E, the full test job, runtime state models, four compiler platforms and both candidate-core platforms. No unchanged local whole-suite repeat is claimed.

The corrected ROOT-owned M3 trial at exact cf0bf3a1 passed: one maintained scenario, 248.0 seconds (254.562 seconds wrapper), with all sixteen CLI results/settlements recorded. Forty-six observer samples had zero errors; the wrapper verified complete original rows, trusted originals and final source/artifact pins unchanged. ROOT then ran a separate independent original observer, which passed and confirmed all five original stopped containers, fourteen networks, twenty-seven volume births and twenty-one image IDs/tags. This qualifies the closed two-worktree BuildKit/COPY/SQL retained-image/container/data, recovery and rollback slice on this source and immutable pair. It is acceptance timing, not a performance claim.

Historical M3 attempts at 9b3e7ced, 6a3087b5, 104c9163 and 91d1bdaa remain failures. The 91d1bdaa attempt reached both worktrees' captured COPY/SQL controls and saved active/pending-start recovery boundaries, then failed; its first inner CLI throw and exit were not captured. Source inspection independently exposed the fixture's pending-start recovery-stop refusal, but does not establish the original first throw. The correction's synthetic control is distinct from that live evidence. The wrapper reported complete original rows unchanged, and ROOT's separate observer confirmed the complete original baseline. Earlier exact-owned image recovery receipts remain separately scoped.

Earlier focused and hosted proofs, timeouts, diagnostics and immutable artifact receipts remain separately scoped. Current exact-head merge checks and independent current-next review passed; broader NC04 mappings remain open. The PR is ready for the closed retained-build adoption slice.

hack-cli-tests added 27 commits October 8, 2026 13:11
@blacksmith-sh

This comment has been minimized.

@roodboi
roodboi marked this pull request as ready for review October 9, 2026 03:56
@roodboi
roodboi merged commit 823e8ff into next Oct 9, 2026
13 checks passed
@roodboi
roodboi deleted the feat/native-retained-build-adoption branch October 9, 2026 03:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant