You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(sdk): complete session lifecycle and mobile ownership contracts #269
Own client session lifecycle and language-boundary behavior: open/detach/close/cancel, process/control deadlines, per-operation diagnostics, mobile ownership and typed API validation. Consolidated from the lifecycle/mobile parts of #203.
This is the sole active owner of audit IDs 03, 08, 10, 11, 12, 13, 26, 28, 39, 41, 42, 52, 61, 63 from the archived #203. Original acceptance and evidence remain there. Guest SQL timeout/recovery is #201; database durability is #249; byte queues, raw exchange framing and data streaming are #244; packaged build products are #213; optimization research is #266. Each item below includes its own behavioral verification; shared packaged-product/integration evidence is owned by #213.
Reviewed 8 October 2026: main 293f31f4; integration #218 at 3b1f7cd4. #255 merged through #247 into #218; #268 is also in #218. #218 remains open, so candidate changes are not on main or published.
Remaining work
Detach/reset outcome (03). Integrate fix(runtime): consolidate patch correctness and retire unsafe shortcuts #218's checked PostgreSQL reset commands. Treat ErrorResponse as failure, preserve diagnostic precedence, and distinguish a reusable logical detach from terminal shutdown. Exercise failed reset/transaction/session cleanup through the public direct and broker boundaries.
Child launch failure (08). Handle spawn errors as well as exits in the shared JS child wrapper. ENOENT/permissions/early failure must settle startup and cleanup exactly once with the real cause, without an unhandled error event or hanging waiter.
Control deadlines and diagnostics (10–13). Carry deadlines through dispatched close, startup readiness/authentication/handshake and cancellation control reads/writes. Rust close must retain write_request/read_response failures plus cleanup diagnostics. A later bounded process reap does not bound an earlier acknowledgement read. Preserve intentional waits for admitted SQL and accurately state uninterruptible direct-backend limits.
Kotlin initialization ownership (26). Delete only staging owned by the failing attempt. The Android direct temporary-storage root is process-shared and failure cleanup can currently remove it before ownership is established; later Rust session admission does not protect that earlier boundary. Test overlapping opens and failure before/after acquiring ownership without damaging a live database.
Swift callback reentry (28). Enforce reentry rejection across callback-created tasks/threads, beyond inherited TaskLocal context. Use the existing ownership state coherently and fail before waiting on the operation that owns the callback; preserve legitimate unrelated concurrency.
Kotlin encoding (52). Replace boxed MutableList parameter accumulation with checked presized byte storage while preserving wire encoding, overflow checks, null handling and supported parameter limits. This is the concrete encoding task; speculative copy/scheduling optimizations belong to perf(runtime): measure startup, execution and package costs #266.
Current language-boundary contracts (41, 61). Extend shared fixtures for reset outcomes, cleanup ownership, diagnostic precedence and callback reentry. Execute Swift/Kotlin typed facades for nulls, custom OIDs, duplicate fields and error conversion. Keep platform schedulers/adapters separate; changing one expectation should update the relevant shared fixture.
Public adapter and installed-app evidence (39, 42). Reuse matching existing OS/runtime and device evidence, then fill the relevant missing cells for current desktop hosts and installed iOS/Android/React Native lifecycle/storage behavior. Cover close/reopen, cancellation, invalidation, background/foreground and ownership failures where supported. Host/C++ tests do not replace an installed app. Coordinate storage assertions with fix(storage): complete persistence, publication and maintenance contracts #249 and carrier identity with build(runtime): consolidate dependencies and verify packaged products #213.
SDK behavior documentation (63). Document the tested one-physical-session contract, logical detach versus terminal close, admitted cancellation/teardown semantics, supported limits and current generated Java byte-array boundary. Raw exchange and streaming guarantees are defined in feat(transport): bound streaming, framing and queued work #244. Do not promise unlimited Java output or universal startup/close deadlines for an uninterruptible direct backend.
Already resolved or retired — do not reimplement
Main #209 fixed RN acknowledgement registration/invalidation with the shared C++ Lifecycle guard (old item 25); its 1,000-race suite passed again during reconciliation. The old handwritten JNI UTF-8/jsize conversions and Swift shared diagnostic slot were retired by the generated UniFFI/JNA/owned-error bridge (27, 29, 30). #209/#226 made Swift native-required smoke execute actual native tests (40). These old fixes are not active tasks here; current binding/device behavior still has the scoped acceptance above. #205 already improved session/lifecycle documentation.
Original detailed triggers and acceptance: #203, especially native SDK report B and mobile report C. Closure requires the owned lifecycle contracts to be implemented and verified through their public boundaries.
Own client session lifecycle and language-boundary behavior: open/detach/close/cancel, process/control deadlines, per-operation diagnostics, mobile ownership and typed API validation. Consolidated from the lifecycle/mobile parts of #203.
This is the sole active owner of audit IDs 03, 08, 10, 11, 12, 13, 26, 28, 39, 41, 42, 52, 61, 63 from the archived #203. Original acceptance and evidence remain there. Guest SQL timeout/recovery is #201; database durability is #249; byte queues, raw exchange framing and data streaming are #244; packaged build products are #213; optimization research is #266. Each item below includes its own behavioral verification; shared packaged-product/integration evidence is owned by #213.
Reviewed 8 October 2026: main
293f31f4; integration #218 at3b1f7cd4. #255 merged through #247 into #218; #268 is also in #218. #218 remains open, so candidate changes are not on main or published.Remaining work
Already resolved or retired — do not reimplement
Main #209 fixed RN acknowledgement registration/invalidation with the shared C++ Lifecycle guard (old item 25); its 1,000-race suite passed again during reconciliation. The old handwritten JNI UTF-8/jsize conversions and Swift shared diagnostic slot were retired by the generated UniFFI/JNA/owned-error bridge (27, 29, 30). #209/#226 made Swift native-required smoke execute actual native tests (40). These old fixes are not active tasks here; current binding/device behavior still has the scoped acceptance above. #205 already improved session/lifecycle documentation.
Original detailed triggers and acceptance: #203, especially native SDK report B and mobile report C. Closure requires the owned lifecycle contracts to be implemented and verified through their public boundaries.