Skip to content

feat: admit read-only live source in native graphs - #229

Merged
roodboi merged 12 commits into
nextfrom
feat/native-live-project-source
Oct 9, 2026
Merged

roodboi merged 12 commits into
nextfrom
feat/native-live-project-source

Conversation

@roodboi

@roodboi roodboi commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

The explicit native backend admits one read-only project-relative source bind per workload through an existing, explicitly approved live virtiofs share. Host edits remain visible. Source roots, selected paths, permissions and provider identity are checked before effects and active observations; exact owned cleanup remains available after the host source moves or disappears.

The container bind is read-only; the previously approved unfiltered guest share remains writable. This command never enrolls a share, changes pool mounts or substitutes a snapshot. Source-bearing graph receipts use version 3; image-only version 2 and the ready/control wire remain unchanged. Writable mounts, mixed live source with persistent storage, routing and other unsupported intent still refuse. Canonical persistent-only groundwork remains inactive for ordinary runtime entry. Compose remains the default backend.

The current head 02e9a8a normally integrates next 3218dd4. The combined decoder keeps image-only graph 2, live-source graph 3 and persistent-only graph 4 disjoint, including explicit null/empty cross-family fields. Mixed source/storage refuses before private preparation; the canonical ordinary persistent-input refusal remains before Engine connection or reservation. Rust and TypeScript dead-owner recovery remain graph 2 only, preserving both timestamp and session-UUID publication selectors. Source and storage verification/freshness callbacks remain at create, readiness, inspection and cleanup boundaries.

Validation and artifact provenance:

  • Independent review of the combined prospective tree and final clean two-parent commit, covering all 25 owning paths. Affected TypeScript graph/process/recovery controls pass 55 tests/359 assertions; direct IR controls pass 22. The native graph family passes 124 controls with one ignored live test; one existing invalid-version test initially expected decoding to succeed, and the independently reviewed test-only correction now requires decoder refusal and passes its owning control. The initial RED remains preserved. CLI typecheck/lint, changed-file checks, privacy, Rust formatting and default/all-feature all-target Clippy pass. No unchanged whole suite or runtime trial was repeated solely for this reconciliation. All 12 exact-head hosted CI jobs have now completed successfully. Independent current-base review also verified the conflict-free union with next 42f289e: all 23 PR-owning and 25 incoming paths are preserved without overlap.

  • Required default Rust at 855b04b passed 1,116 tests/63 ignored. With the added test-only first-refusal observation, all-feature Rust at 07c1ef9 passed 1,359 tests/96 ignored, plus three focused diagnostic controls. The final e271e4b change only moves that exact test module to the end of the file; independent source correspondence carries those results. Those formatting and default/all-feature all-target Clippy gates passed at their stated checkpoint. The earlier wildcard-port refusal is retained; its original cause remains unproven and no product fix is claimed.

  • A fresh optimized six-feature native binary and normal Bun 1.4.2 CLI were built on M5 from exact e271e4b source, before the test-only platform guards and disjoint incoming job-test changes, with before/after verification of all 1,837 source entries. Compiler and relay reuse has explicit owning-input correspondence; compiler test-only differences are disclosed. Strict code-signature validity and relay verification pass. The debug ignored-test executable remains attributed to 07c1ef9 and the reviewed module-layout carry.

  • Historical 6823822 matched the diagnostic hook and module to their existing macOS-only test consumers. Independent source review, formatting, and default/all-feature all-target Clippy pass; bodies, assertions and production paths are unchanged. That exact-head CI ended with 11 successful jobs and one Docker failure. The completed-job adoption test refuses at alpha-start-2 with E_CONFIG_INVALID (no timeout); its preserved log contains no narrower predicate. No unchanged CI rerun or source-cause claim is made. The earlier e271e4b Ubuntu Clippy failure and canceled Mac lane remain preserved; the separately scoped source-bearing provider trial is described below.

  • One frozen M5 native-consumer trial passed using the e271 package: initial HTTP content, in-place live edit, atomic child-file replacement, container EROFS/read-only bind, source-directory withdrawal refusal, exact Ready-to-Removed binding and absent workloads, retained host data, and normal isolated-pool down. All 16 child stages exited successfully and settled both captures. Before/after checks preserved the original one process identity, thirteen stable runtime fields, boot UUID, disk identities/permissions and fresh digests of the same 120-byte header regions. This is direct native-consumer/provider proof for one synthetic source directory, not ordinary frontend or Compose parity. The earlier count-conflation preflight refusal and a later overly broad dynamic-status summary assertion remain preserved as private harness evidence; neither changes the successful frozen trial.

Earlier 0114933 evidence remains separate: all 12 CI jobs passed; default Rust 1,116 passed/63 ignored and all-feature Rust 1,324 passed/96 ignored; five exact filesystem controls passed. Full frontend at e42fd0a passed 5,016 tests/93 skips, zero failures, with one fresh CLI task and one cached task. These historical checks do not replace current-head CI or live acceptance.

A separate ROOT-executed read-only M5 postflight also passed independently. It compared the original one-process identity, thirteen stable status fields, host boot UUID and both exact disk metadata/header digests against both admitted trial records; both read-only children exited and settled both captures, with no provider effects. Historical disk evidence retains its narrower identity/magic/UUID scope.

Remaining application-acceptance gates: a fresh current-source build and ordinary frontend/same-source Compose-native qualification. The previous ordinary frontend attempt exited with E_STARTUP_INCOMPLETE before reservation; its underlying cause remains unproved. Its exact isolated pool was normally stopped and a separate read-only observer verified original-provider preservation. A new CLI built from e271 plus only the two closed startup-diagnostic production changes ran once. Its exact immutable compiler diagnosed the synthetic fixture's bare readiness argv as an invalid command shape; the same argv wrapped in an exec object passed the focused compiler control. The failed trial remains RED. Its isolated pool was normally stopped and an independent original-process/disk postflight passed; a fresh fixture-only correction is being staged with the same artifacts. None of those artifacts is relabeled as the current-union build. The isolated source-directory native-consumer trial has passed. Filesystem sealing and offline platform-content image projection passed without provider effects; their earlier artifact provenance is preserved. Source-bearing dead-owner recovery and complete NC05 support remain outside this increment. No performance claim is made.

@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment has been minimized.

@roodboi
roodboi marked this pull request as ready for review October 9, 2026 07:16
@roodboi
roodboi merged commit 5c9f0ad into next Oct 9, 2026
13 checks passed
@roodboi
roodboi deleted the feat/native-live-project-source branch October 9, 2026 07:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant