Skip to content

fix(compose): classify captured ownership refusals - #231

Closed
roodboi wants to merge 4 commits into
nextfrom
feat/native-compose-ownership-diagnostics
Closed

roodboi wants to merge 4 commits into
nextfrom
feat/native-compose-ownership-diagnostics

Conversation

@roodboi

@roodboi roodboi commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

An uncertain process-policy startup can currently surface only a generic ownership refusal. This change records the first refused ownership predicate in a module-private WeakMap and carries its closed reason through the existing captured-reply replay. For a future matching after-Compose refusal, the fixture also writes the first replay reason to an exclusive 0600 file and a fixed-field CI log line before normal fixture cleanup.

Only the owning refusal sites can issue reasons. Caller-created errors, copies, prototypes, accessors, and proxies cannot mint them. The capsule contains a bounded observation index, closed reason values, and explicit flags that the replay uses recorded replies, does not reproduce wall timing, and cannot identify the original caller mode. It contains no raw inspect output, environment, arguments, or host paths. Public error codes and messages, predicates, query order, retries, deadlines, ownership fences, and effect authority are unchanged.

At exact head 72d1d1d, independent source review found that the five PR-owned files retain the reviewed diagnostic and capsule behavior while all incoming #234 paths match canonical next. Focused ownership/replay tests passed (65 tests, 710 assertions). CLI typecheck, strict scoped TypeScript for the three capsule files, changed-file lint, privacy, and diff checks passed; lint reports one complexity warning in the existing long scenario. No local real Docker query or engine effect was run.

Fresh exact-head hosted CI finished with 11 checks passing and Docker E2E failing. The first failure is the completed-job two-worktree fixture at alpha-start-2: its up command exits nonzero without a timeout and returns E_CONFIG_INVALID. The process-policy scenario passes, so this run supplies no new after-Compose refusal capsule. The completed-job failure's underlying predicate is not established by the closed substage record; no retry or ownership-policy change follows from it.

The prior #231 job restart failure and #233 process-policy startup failure remain distinct historical results. The #233 raw recorded replies were not available for an exact replay, so this change does not establish that failure's predicate or cause. A new hosted failure must provide fresh closed evidence before any ownership-policy change.

@blacksmith-sh

blacksmith-sh Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Found 1 test failure on Blacksmith runners:

Failure

Test View Logs
native-compose-adoption-job-worktrees (19.7s) — Completed-job worktree acceptance refus
ed; values omitted./
native-compose-adoption-job-worktrees (19.7s) — Completed-job worktree acceptance refus
ed; values omitted.
View Logs

Fix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need.

@roodboi

roodboi commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Closing as source consolidation into #248 at 3fb9319. The reviewed owner-issued reasons, one-use refusal capsule and replay controls are preserved there, including current network-policy and endpoint counterexamples. The original failed checks and missing-predicate evidence remain recorded; diagnostics do not prove or fix the underlying startup failure. #248 stays open for fresh CI and live routing acceptance. Branch retained.

@roodboi roodboi closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant