Skip to content

fix: retire acknowledged stopped graph publishers explicitly - #115

Closed
roodboi wants to merge 24 commits into
nextfrom
codex/retire-acknowledged-publisher
Closed

roodboi wants to merge 24 commits into
nextfrom
codex/retire-acknowledged-publisher

Conversation

@roodboi

@roodboi roodboi commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Ordinary graph cleanup can finish and be acknowledged before dependency-journal archival fails. The stopped graph then retains a dead foreground publication, so retained startup correctly refuses it.

Add private retire-acknowledged-publisher recovery requiring exact run, Owner, receipt SHA and publisher SHA. It binds the current-boot cleanup ACK to the resource/inventory effect, independently checks retained volumes and compute/environment/bridge/startup/probe absence, and rechecks that proof under held locks at every publication effect. Existing retirement history preserves the original files and resumes either socket-first rename interruption. No graph receipt, VM, dependency journal or retained data changes; historical recovery never supplies fallback authority.

Validation at the recovery implementation0b80466a: 979 default and1066 all-feature Rust tests pass (62/84 explicit ignores); strict Clippy default and all-target/all-feature pass; four admission/effect/journal controls and rename fault controls pass. Typecheck/lint/Bun test output was a Turbo cache replay for the unchanged TypeScript tree. Staged privacy, format, signatures and bundle manifest pass. Current headff48ed71 adds Claude's isolated frontend acceptance stand-in lock fix: 12 Python controls pass freshly, and all eight CI checks pass at that exact head.

M3 native acceptance: the selected retained Event Agent publisher was retired successfully. Current receipt, Owner, source witness, dependency journal, volume bindings and sibling receipt stayed byte-unchanged; original publication bytes/inodes were preserved in retirement history. Retained preflight passes. Normal up reached the startup hook then refused a separate leftover dependency reservation. Managed reservation release, full application restart/browser/data acceptance and the broader isolated historical-rebind fixture remain separate open gates; this is not a whole-product readiness claim.

Release signal: fix, private v5 recovery correction. Based on next, with the pending recovery stack through#113. No publication is included; HACK-1210/HACK-1159 track integration acceptance.

hack-cli-tests added 24 commits September 29, 2026 21:41
Stand-in invocations ran concurrently (a foreground `up` while the driver
polls `ps`) and each did an unlocked read-modify-write of state.json. A
`ps` that loaded the state before the second `up` saved its foreground
token then saved its stale copy over it, so `up` saw its token gone and
exited 0 before readiness; lost call records failed the acceptance test
as well. That failed 26 of 40 local runs, and Runtime state models on CI.

Each invocation now holds an exclusive flock across its read-modify-write
and releases it only before its long waits (the foreground loop and the
ps-hang fault). 40 of 40 local runs pass.
@roodboi

roodboi commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by merged #122. This PR’s source was incorporated through #122, squash commit cf4b6e9. Independent acceptance remains in Linear. Closing as superseded; branches and worktrees are retained.

@roodboi roodboi closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant