Skip to content

fix: explicitly recover retained graph host pins after reboot - #101

Closed
roodboi wants to merge 4 commits into
nextfrom
codex/recover-host-pins
Closed

roodboi wants to merge 4 commits into
nextfrom
codex/recover-host-pins

Conversation

@roodboi

@roodboi roodboi commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Physical host reboots can change a filesystem device number while retaining the same inodes. After explicit provider recovery, old foreground, relay-control and dependency socket pins still refuse cleanup. Add hash-selected graph inspect-host-pin-recovery / recover-host-pins commands that publish an immutable witness for one prior guest generation, then allow exact owned cleanup and publisher retirement without rewriting the historical pins or removing data.

Recovery checks the running guest identity independently, holds and rechecks publication/control/provider locks, and binds raw receipts, unchanged paths/inodes, dead pre-host-boot processes and current retained-volume observations. Ordinary reads and successor publications stay strict. Missing temporary roots refuse; this does not reconstruct vanished ownership evidence or migrate shared-source graph identity.

Validation:

  • Default Rust: 937 passed / 62 ignored; all-feature Rust: 1,023 passed / 81 ignored. Strict Clippy/rustfmt, repository check and staged privacy scan passed.
  • Signed macOS candidate built and verified with the pinned toolchain. Owned native CLI/VM fixture passed in 44.34 seconds: named refusal controls, same-run restore, retained marker readback, live sibling isolation, and idempotent retirement. Both test graphs/data, VM and provider alias were removed with readbacks.
  • Regression coverage includes stale selections, missing roots, changed provider bytes/guest boot, lock replacement and interrupted retirement. A native negative control caught Owner-derived boot self-comparison; the final code independently checks the kernel boot and storage owner before selection or cleanup.

Release signal: fix; explicit recovery only. Legacy device rebinding does not prove original physical-volume continuity. Synthetic old host-device receipts plus a real guest reboot qualify the command path; physical host reboot and full application/browser acceptance remain separate.

Stack: depends on #96 and #97 and targets next. Restack onto next once those parents merge. Private logs, bundles, fixture data and internal planning are excluded.

@roodboi

roodboi commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by merged #122. This PR’s source was incorporated through #122, squash commit cf4b6e9. Independent acceptance remains in Linear. Closing as superseded; branches and worktrees are retained.

@roodboi roodboi closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant