Skip to content

Make daemon overlay launch and lifecycle ownership explicit - #406

Merged
devmobasa merged 4 commits into
mainfrom
refactor/daemon-launch-lifecycle
Oct 4, 2026
Merged

devmobasa merged 4 commits into
mainfrom
refactor/daemon-launch-lifecycle

Conversation

@devmobasa

@devmobasa devmobasa commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

Make overlay launch inputs and lifecycle transitions explicit, while preserving existing daemon behavior. Remove all Python from the repository: test fixtures are Rust, source guards are Rust tests, and release tooling is C#.

Changes

  • Replace separate pending request and activation-token fields with one owned launch request. Consume launch options once and preserve token-only retention on the existing paths.
  • Move visibility, active target, spawn backoff, start/readiness, hide, shutdown, and retirement into OverlayLifecycle.
  • Keep process identity, proof records, signaling authority, and reaping with the existing OverlayChildOwner; remove raw child-controller access from daemon callers.
  • Preserve launch argument/environment ordering, V1/V2 authorization and action handling, duplicate-toggle suppression, and the TERM → two-second grace → forced-kill policy.
  • Retain the final cleanup retry after exhausted spawn candidates and update the scoped ownership guide.
  • Keep the overlay launch error that callers display unchanged; per-candidate failures are logged and kept on a typed error.

Python removal

  • Daemon overlay fixture. The unit-test binary is its own fake overlay child: a startup hook runs the production readiness handshake and records how it was launched. No script is generated, and a child that exits before readiness is the same binary launched under a dedicated name.
  • GTK popup fixture. The Wayland protocol proxy that withholds one popup frame callback is Rust. It forwards descriptors, holds the callback and its delete_id, cleans up its process group, and reads message layouts from the protocol tables compiled into wayland-client and wayland-protocols.
  • Source guards. The process-site, config-writer, and shared-dependency checks are Rust tests in tests/repository_guards, run by every cargo test, each with regression cases for the escapes it forbids. They keep every rule of the scripts they replace; process sites now recognise test code by its #[cfg(test)] module chain, and config writers again reject as casts. The weaker C# copies are retired. no_python.rs keeps Python from coming back.
  • Release tooling. Version check, bump, and release-tag commands exist only in C#, including version check --release-version and the packaging-hotfix rules; the shell and Python versions are deleted. Nix inputs and CI package lists no longer include Python.
  • Gate. tools/lint-and-test.sh needs the .NET SDK selected by global.json and runs the same steps as ci lint-and-test. Without .NET, cargo test still runs the Rust guards; that is Cargo validation, not the complete gate.

Regression coverage

  • Real broker-child launches through show_overlay, including argument/environment delivery, hide, restart, and natural retirement.
  • Failed launches (a real child that exits before readiness, with the displayed error text pinned), backoff, preparation errors, and token/options non-replay.
  • Token retention after hide, visible V2 action delivery, and internal-runner success/failure.
  • Active flag, named target, poll-FD, and proof-record cleanup.
  • Forced shutdown of a TERM-ignoring child, including an assertion that rejects a shorter grace period.
  • Native GTK popup and menu presentation through the Rust proxy (tools/test-gtk-widgets.sh, four EXECUTED markers).
  • C# version, release-tag, desktop-asset, and code-health regressions replacing the deleted shell and Python tests.

- Run the daemon overlay fixture as the test binary itself: a startup hook
  runs the production readiness handshake, and a child that exits before
  readiness is the same binary launched under a dedicated name. The launch
  error text stays as it was; per-candidate failures stay on a typed error.
- Port the GTK popup Wayland proxy to Rust, reading message layouts from the
  protocol tables compiled into wayland-client and wayland-protocols.
- Move the process-site, config-writer, and shared-dependency guards to Rust
  tests in tests/repository_guards, run by every cargo test, retire the C#
  copies, and add a guard that keeps Python out.
- Make version check, bump, and release tags C# only, keeping the
  packaging-hotfix rules, and restore the code-health report's status lines.
- Require the .NET SDK for tools/lint-and-test.sh, which runs the same plan
  as ci lint-and-test, and drop Python from Nix inputs and CI packages.
@devmobasa
devmobasa merged commit b34e6ce into main Oct 4, 2026
3 checks passed
@devmobasa
devmobasa deleted the refactor/daemon-launch-lifecycle branch October 4, 2026 21:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant