Repository navigation
fix(scope): retain observation leases and stop unsafe capture paths - #31
Merged
Scaxlibur merged 1 commit intoOct 10, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope waveform reports could write a valid channel before discovering an invalid later channel, and released the resource lease between the final input-safety check and waveform fetch. Reports also opened fresh sessions after uncertain I/O. This change keeps the report in one owned or borrowed session, validates every requested channel through guarded queries before capture writes, and stops subsequent I/O after session or transport failures. Completed results survive close failures, which are recorded explicitly.
Observation uses a read-only effective configuration and the V2 pure-query snapshot contract; missing legacy-only snapshots remain unavailable. Disabled access and offline preflight failures stop before driver construction. Observation-owned factories use the construction I/O latch even for legacy descriptors, so factory initialization cannot write before channel checks. Final input-safety checks share the capture session and exclusive lease. Keeping the session open does not claim synchronized acquisition: cross-channel timing stays skipped. Advice with insufficient evidence returns
advice_unavailable, and relationship helpers default to unproven timing.Unreleased entry points and their execution contract are documented in Development, with links from the released CLI and MCP pages. Model-specific limits stay in descriptors/drivers.
Validation covers the real factory/guard/session/lease with fake transport, cross-process lock contention, invalid later channels with zero capture writes, failure cancellation, owned/borrowed lifecycle cleanup, partial V2 snapshots, advice evidence and synthetic phase regressions. The final implementation passed the full Windows Python 3.12 suite: 2677 passed, 5 skipped and 221 subtests passed. Ruff, generated Reference checks, scoped strict documentation audit, and strict MkDocs builds pass. Tests use PYTHONUTF8=1 and OPENBLAS_NUM_THREADS=1; all instrument exchanges are fake.
All five GitHub checks passed for
6337021: Linux Python 3.11/3.12, Windows Python 3.11/3.12, and documentation build. Target branch:Dev. Legacy-only snapshots remain explicitly unavailable; plugins that perform device I/O during factory construction must defer that I/O before using the observation path. Hardware support and acceptance still depend on plugin evidence.