Skip to content

fix: recover missing native provider HOME aliases - #96

Closed
roodboi wants to merge 1 commit into
nextfrom
codex/recover-missing-provider-home
Closed

roodboi wants to merge 1 commit into
nextfrom
codex/recover-missing-provider-home

Conversation

@roodboi

@roodboi roodboi commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Host cleanup can remove the native pool’s temporary HOME alias while preserving its private home and disks. Previously every runtime command, including recovery, failed at owner loading, leaving a stopped pool inaccessible. Explicit runtime recover now restores only an absent exact receipt-bound alias after proving the recorded provider and other provider commands are gone, both identified disks unchanged, the VM lock free, and disk handles closed. It never replaces an existing path or boots the guest.

Recovery reloads the exact owner selection before exclusive alias creation and rejects pending receipt updates. Socket absence and disk flush still precede the recovered receipt. A later failure reports incomplete recovery, preserves the exact restored alias and data, and can be retried after inspection. Status stays read-only and gives an actionable missing-alias diagnostic.

Validation: seven macOS regression tests cover disk-byte retention, live/reused PID refusal, changed disks, held VM locks, open disk handles, existing files/directories/foreign symlinks, changed receipts, exclusive-creation collisions, pending receipt updates, and active-socket refusal followed by successful retry. Full default/all-feature Rust tests pass (923/1,009, respectively; 62/80 existing ignores), with rustfmt and strict Clippy. Privacy check passes. The signed packaged disposable app proof passes: initial native HTTPS/data write, clean stop, exact owned alias removal, read-only missing-alias refusal, explicit recovery, unchanged disk device/inode/size, explicit runtime boot, same graph/new container, HTTPS before exact data readback, and final owned VM/disk/volume/alias removal. All eight hosted CI checks pass on head10697ae8.

Real Event Agent recovery is still blocked by a separate host-reboot identity issue: its APFS device number changed while inode, ext4 UUID and byte length remain identical. This PR correctly refuses that mismatch without restoring the alias or touching its data. This gap needs separate explicit recovery work; no release is published.

Release signal: fix, with no state-schema migration. Target: protected next.

@roodboi

roodboi commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by merged #122. This PR’s source was incorporated through #122, squash commit cf4b6e9. Independent acceptance remains in Linear. Closing as superseded; branches and worktrees are retained.

@roodboi roodboi closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant