Repository navigation
Conversation
roodboi
marked this pull request as ready for review
September 30, 2026 01:51
This was referenced Sep 30, 2026
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Host cleanup can remove the native pool’s temporary HOME alias while preserving its private home and disks. Previously every runtime command, including recovery, failed at owner loading, leaving a stopped pool inaccessible. Explicit
runtime recovernow restores only an absent exact receipt-bound alias after proving the recorded provider and other provider commands are gone, both identified disks unchanged, the VM lock free, and disk handles closed. It never replaces an existing path or boots the guest.Recovery reloads the exact owner selection before exclusive alias creation and rejects pending receipt updates. Socket absence and disk flush still precede the recovered receipt. A later failure reports incomplete recovery, preserves the exact restored alias and data, and can be retried after inspection. Status stays read-only and gives an actionable missing-alias diagnostic.
Validation: seven macOS regression tests cover disk-byte retention, live/reused PID refusal, changed disks, held VM locks, open disk handles, existing files/directories/foreign symlinks, changed receipts, exclusive-creation collisions, pending receipt updates, and active-socket refusal followed by successful retry. Full default/all-feature Rust tests pass (923/1,009, respectively; 62/80 existing ignores), with rustfmt and strict Clippy. Privacy check passes. The signed packaged disposable app proof passes: initial native HTTPS/data write, clean stop, exact owned alias removal, read-only missing-alias refusal, explicit recovery, unchanged disk device/inode/size, explicit runtime boot, same graph/new container, HTTPS before exact data readback, and final owned VM/disk/volume/alias removal. All eight hosted CI checks pass on head10697ae8.
Real Event Agent recovery is still blocked by a separate host-reboot identity issue: its APFS device number changed while inode, ext4 UUID and byte length remain identical. This PR correctly refuses that mismatch without restoring the alias or touching its data. This gap needs separate explicit recovery work; no release is published.
Release signal:
fix, with no state-schema migration. Target: protectednext.