Repository navigation
Conversation
added 24 commits
September 29, 2026 21:41
Stand-in invocations ran concurrently (a foreground `up` while the driver polls `ps`) and each did an unlocked read-modify-write of state.json. A `ps` that loaded the state before the second `up` saved its foreground token then saved its stale copy over it, so `up` saw its token gone and exited 0 before readiness; lost call records failed the acceptance test as well. That failed 26 of 40 local runs, and Runtime state models on CI. Each invocation now holds an exclusive flock across its read-modify-write and releases it only before its long waits (the foreground loop and the ps-hang fault). 40 of 40 local runs pass.
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ordinary graph cleanup can finish and be acknowledged before dependency-journal archival fails. The stopped graph then retains a dead foreground publication, so retained startup correctly refuses it.
Add private
retire-acknowledged-publisherrecovery requiring exact run, Owner, receipt SHA and publisher SHA. It binds the current-boot cleanup ACK to the resource/inventory effect, independently checks retained volumes and compute/environment/bridge/startup/probe absence, and rechecks that proof under held locks at every publication effect. Existing retirement history preserves the original files and resumes either socket-first rename interruption. No graph receipt, VM, dependency journal or retained data changes; historical recovery never supplies fallback authority.Validation at the recovery implementation0b80466a: 979 default and1066 all-feature Rust tests pass (62/84 explicit ignores); strict Clippy default and all-target/all-feature pass; four admission/effect/journal controls and rename fault controls pass. Typecheck/lint/Bun test output was a Turbo cache replay for the unchanged TypeScript tree. Staged privacy, format, signatures and bundle manifest pass. Current headff48ed71 adds Claude's isolated frontend acceptance stand-in lock fix: 12 Python controls pass freshly, and all eight CI checks pass at that exact head.
M3 native acceptance: the selected retained Event Agent publisher was retired successfully. Current receipt, Owner, source witness, dependency journal, volume bindings and sibling receipt stayed byte-unchanged; original publication bytes/inodes were preserved in retirement history. Retained preflight passes. Normal
upreached the startup hook then refused a separate leftover dependency reservation. Managed reservation release, full application restart/browser/data acceptance and the broader isolated historical-rebind fixture remain separate open gates; this is not a whole-product readiness claim.Release signal:
fix, private v5 recovery correction. Based onnext, with the pending recovery stack through#113. No publication is included; HACK-1210/HACK-1159 track integration acceptance.