Skip to content

feat(native-config): retain legacy local routing during Compose adoption - #248

Merged
roodboi merged 16 commits into
nextfrom
feat/native-compose-retained-routing-v14
Oct 9, 2026
Merged

roodboi merged 16 commits into
nextfrom
feat/native-compose-retained-routing-v14

Conversation

@roodboi

@roodboi roodboi commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Preserve existing local HTTP origins when explicitly adopting a supported legacy Compose project: literal dev_host, its declared OAuth alias, and saved open preference with typed local precedence. Private v14 receipts bind the original containers, SQL volume births, default bridges, ingress/proxy observations, route claims and source files. Lifecycle and rollback use those original resources; unsupported family intersections refuse.

Read-only routing proofs reuse a resource observation within one private phase, bracketed by complete ownership proofs. Both the pre-move entry and final active-receipt save use the actual full proof just completed. The final reuse spans only an exclusive temporary receipt write; the authoritative switching receipt stays unchanged. Source, manifest, receipt, claims, stopped state, cancellation and the same absolute 15s deadline remain checked. Scoped observations revoke before a complete fresh closing proof and final receipt snapshot, before active receipt rename. Other callers retain fresh entry proofs.

The maintained isolated ingress fixture covers two worktrees, TLS markers, SQL continuity, saved open, interrupted stop recovery and rollback without changing global DNS or trust. Owner-issued closed publication stage/reason diagnostics and explicit-opt-in process-policy replay diagnostics contain no raw errors or resource values.

Verification

  • Parent b76092c1 normally joins the reviewed correction 742625a8 with literal next e267f3c4. Independent source review verified 47 own and 24 incoming paths with no overlap; all blobs and modes remain exact to their parents. Distinct v12/v13/v14 family guards remain intact.
  • New publication controls: 3 passed, 0 failed, 16 assertions. The identical positive control fails against unchanged 0782b588 at its deadline check after six charged volume inspections and passes the correction with four. Separate controls retain refusal for an already-expired entry and volume rebirth reached inside the reused window, with zero original moves or lifecycle effects. This is a deterministic duplicate-work counterexample; the exact historical M3 conjunct remains unproven.
  • Current a489a126 adds only five reviewed save-active proof/diagnostic/test/doc paths to b76092c1. Four closest controls pass with 23 assertions: the identical positive fails against unchanged b76092c1 at its original final publication deadline guard, while the correction observes four installed-native volume reads and commits active. Reached staged-receipt deadline, same-byte authoritative receipt rebirth and final volume rebirth retain switching/native-installed state and refuse before active rename. The diagnostic file passes 6 tests / 30 assertions, including closed fields and anti-forgery. The exact historical b76092c1 conjunct remains unknown.
  • CLI typecheck, changed TypeScript lint, privacy and diff checks pass; current-base CLI typecheck also passes. Six existing complexity warnings remain. Initial style RED and the original-source counterexample are retained. Product deadlines and assertions were not widened.
  • Earlier evidence remains scoped: 7 / 46 publication diagnostics; 62 / 330 family integration; 7 / 72 coalescing/drift; 79 / 232 maintained fixture; 94 / 1,041 binding; 19 / 59 preference/result capture; 14 / 391 process-policy diagnostics. The earlier compound positive reduced synthetic queries from 17,841 to 8,649 and volume inspections from 328 to 136. This is not a CPU or wall-time qualification.
  • Exact historical 3fb9319d and 0782b588 hosted CI passed all 12 required checks. New-head checks are unearned until their own jobs complete; no historical CI is relabeled.
  • The prior exact b76092c1 CLI-only build passed: child16292 exit0, no timeout/cancellation, recorded group absence and no scratch. Held-file readback binds CLI 09110943 and reused optimized compiler 4621a943 to that producing source. Its one admitted M3 trial passed the original publication-routing boundary, installed the native document, then refused at publication-save-active / legacy-state. A temporary active receipt exists; the authoritative journal remains switching/native-installed with held claims and pending null. The rejected conjunct is not proven. New fixed save substages and original deadline-guard attribution make a future failure more precise.
  • Exact b76092c1 physical cleanup and its separate original observer passed: 580 paired successful command returns, 15 exact effects, no uncertainty, zero remaining fixture resources. Full cleanup before/after snapshots are byte-equal; independent originals match 5 stopped containers, 0 running, 14 networks, 27 volume births, 21 images and both tags. Known capture-owner returns require child exit and both EOFs without group-cleanup failure; no individual current PID/group-absence ledger was serialized. Physical restoration leaves the switching/native-installed journal unresolved.
  • The matching 0782b588 M3 trial passed its saved TLS/SQL and known partial-stop sequence, then refused during publication-routing with reason legacy-state. Its receipt remains switching with native:null, held claims, no original moves and no native install. The saved timing is compatible with the 15s deadline but does not identify the actual rejected conjunct. Earlier REDs remain preserved.
  • Exact 0782b588 physical cleanup and its separate original observer passed: 580 known successful returns, 15 effects, no uncertainty, zero remaining fixture resources. Original projections match 5 stopped containers, 0 running, 14 networks, 27 volumes, 21 images and both tags. Physical restoration leaves the switching journal unresolved.

Release Signal

  • Commit / squash title: feat(native-config): retain legacy local routing during Compose adoption
  • Release intent: feat
  • Should this PR trigger a release signal? yes
  • Equivalent release artifact: the Conventional Commit/squash title supplies the repository release signal. The release workflow owns publication.

Semantic Surfaces

  • Does this change affect hack run, hack exec, env resolution, runtime-state reconciliation, or lifecycle shell/process behavior? yes
  • Targeted tests: routing generation/execution/fixture/resolution, routing import, publication diagnostics and process-policy refusal controls.
  • Matching contract: docs/reference/native-compose-adoption.md.

Risks / Follow-up

Maintained M3 two-worktree TLS/SQL adoption, lifecycle and rollback acceptance remains open. Current a489a126 still requires its own required CI, matching CLI-only artifact and separately admitted matching-artifact trial. Preserved 0782b588 and b76092c1 artifacts remain bound to their original failed trials; neither is relabeled as current. No engine retry or new build ran for this save-active correction. Broader mixed-corpus families and retired hosted/remote capabilities are not qualified.

@blacksmith-sh

This comment has been minimized.

@roodboi
roodboi marked this pull request as ready for review October 9, 2026 19:11
@roodboi
roodboi merged commit 0d7c0df into next Oct 9, 2026
13 checks passed
@roodboi
roodboi deleted the feat/native-compose-retained-routing-v14 branch October 9, 2026 21:24
roodboi added a commit that referenced this pull request Oct 9, 2026
Reconcile with the squashed #258, #255, #248, #250, #262 and #240 commits on next using the stacked base as the three-way ancestor; branch additions are kept, next's storage-witness arguments and ps documentation are carried. Scoped typecheck, lint and focused controls pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
roodboi added a commit that referenced this pull request Oct 9, 2026
Reconcile with the squashed #258, #255, #248, #250, #262 and #240 commits on next using the stacked base as the three-way ancestor; branch additions are kept, next's storage-witness arguments and ps documentation are carried. Scoped typecheck, lint and focused controls pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
roodboi added a commit that referenced this pull request Oct 9, 2026
Reconcile with the squashed #258, #255, #248, #250, #262 and #240 commits on next using the stacked base as the three-way ancestor; branch additions are kept, next's storage-witness arguments and ps documentation are carried. Scoped typecheck, lint and focused controls pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
roodboi added a commit that referenced this pull request Oct 9, 2026
Reconcile with the squashed #258, #255, #248, #250, #262 and #240 commits on next. Branch host-process, live-stop and storage-tool additions are kept; next's ps wording and the duplicated dispatcher block are deduplicated. CLI typecheck and lint pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
roodboi added a commit that referenced this pull request Oct 9, 2026
Adds retained adoption of original config `0444` binds and protected secret `0400`/`0600` binds.
Private v8 proof binds the owned host file, observed guest identity and permission, exact read-
only mount, and original containers/network/volumes. It never copies, remaps, chmods or replaces
original material. Start, restart and exec require fresh material; saved observations,
stop/recovery and rollback can settle the exact originals after material is withheld.

The v8 family refuses build, job, source-bind, branch-policy, routing, health/dependency,
custom-network and generated/local-input intersections. Other adoption families retain their own
proof and receipt rules. The maintained `native-config-protected-files` selector now covers only
two original retained checkouts; ordinary new-material delivery remains with `native-config-vm-
files`, without the old snapshot-v2 oracle.

Current head: `67c399aa3c540c61e15d019d01780b6bfd3789e4`, normally integrating the reviewed
`bf4919d6` fixture successor with literal next `e267f3c4`, then adding closed topology-refusal
diagnostics. The complete pending #248 routing source, canonical #237 cold-home initialization,
ordinary material owner and renderer remain preserved. Their runtime qualification remains
separately scoped.

The saved bf491 Docker run passed 35 of 36 scenarios. Process-policy initial up alone failed
after Compose completed; recorded-query replay refused the first topology scan, while later
fresh diagnostics showed four running services with matching topology. The saved log does not
identify the original refused check. This successor retains one of seven fixed topology
predicate labels on the exact ownership error and includes it in recorded-query replay. It keeps
existing reasons, errors, predicates, scan order, deadlines and ownership authority unchanged;
copied or hostile error fields cannot issue the label. No product cause or fix is inferred from
the later observations.

Diagnostic validation at 67c399a: the two affected ownership/trace files passed 67 tests and
827 assertions, including all seven original topology negatives, first-cause preservation,
hostile/getter/copied evidence and replay propagation. CLI typecheck, CLI lint, changed-test
lint, privacy and diff passed. Independent source review covers the exact five changed blobs and
normal current-base interaction. No build or engine ran for this successor.

The f235 live fixture reached active adoption with no pending operation, then stopped at a
fixture comparison: the stopped DB exposed-port map became empty instead of retaining its
original null-valued key. Retained up was never reached. The successor permits only that
pairwise exited/nonrunning/notpaused transition while keeping configured port policy and all
other immutable facts exact. Cleanup now uses ordinary down for a validated clean active v8
receipt and recover only for a validated whole pending selection. Malformed or unknown selection
refuses before CLI invocation; production guards are unchanged. The historical secondary cleanup
error did not capture its first predicate.

Fixture correction validation at bf4919d: four new discriminating controls plus 18 affected
fixture controls passed (22 tests, 88 assertions). CLI typecheck, changed-file Biome, privacy,
diff and commitlint passed. Independent source review covers all three changed fixture blobs.
Unchanged command-owner controls were not repeated. No build, engine or native runtime ran for
this correction, and the original artifact/RED is preserved.

Prior source verification at f235:

- v8 lifecycle: 13 passing controls covering protected permissions, saved stop/recovery,
  rollback, and post-effect drift; an additional authenticated-manifest test refuses foreign
  receipt families and mixed proof fields before engine observation.
- Existing build, branch and routing lifecycle controls pass. The integration exposed a v12
  derived-format no-op; its three affected source-bind controls pass after restoring the
  original format. The earlier failed round is retained.
- Import, binding and engine identity: 332 pass, nine compiler-dependent skips. Pure
  permission/source/fixture controls retain 119 positives and eight formatter skips, with the
  initially incorrect receipt-version oracle corrected and its focused control passing.
- Protected command capture reuses the maintained finite child owner. Seven affected controls
  pass, with seven unchanged-default owner controls carried by exact source correspondence. The
  previous owner fails the closed-pipe survivor counterexample. Unknown settlement blocks
  further commands, source restoration and resource cleanup; the intentional-unknown test
  retains its private state.
- CLI typecheck, CLI lint, changed-test lint, privacy and diff checks pass. The compound test's
  outer workflow budget is distinct from unchanged product operation limits; uncertain fixture
  settlement retains state. Historical timeout and failed controls are preserved.

Exact-head required CI, a matching current-source compiled artifact, and real corrected
protected guest lifecycle/recovery/rollback acceptance remain open. The f235 physical cleanup
and independent original-engine preservation are separate closure evidence; they do not qualify
product recovery. Historical binaries, failed actuals and bf491 CI RED remain preserved. This
source update does not establish material migration or performance gains.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant