Skip to content

fix(daemon): serve cold-daemon reads once their owner is ready - #2612

Merged
ScriptedAlchemy merged 6 commits into
masterfrom
fleet/fix-unowned-issues-master-reds
Sep 29, 2026
Merged

ScriptedAlchemy merged 6 commits into
masterfrom
fleet/fix-unowned-issues-master-reds

Conversation

@ScriptedAlchemy

Copy link
Copy Markdown
Owner

Fixes #2482
Fixes #2487

Cold-daemon git reads (#2482)

The git owner registry published an owner before project open installed its authority, so a read in that window got a terminal policy denial (not_found_or_not_authorized). An owner whose authority is not installed yet is now reported as mounting, which returns the retryable application.runtime.mounting problem that the CLI re-sends. The surface transport test now waits on the product's graph_ready status signal before it reads the graph.

Loop proof under CPUQuota=100%, 8 runs each:

  • master: the primitive-tools test passed 1/8 and the git test 5/8
  • fix: 8/8 and 8/8
  • On the merged tree, core_cli_suite::tool_surface_transport_test passed 14/14 three times.

runtime_acceptance_suite reds (#2487)

Built-CLI journey: a cold daemon, init, the graph_ready wait, then the first code_facets read.

  • master: unavailable 20/20
  • fix: completed 20/20, with 6 path facets

Suites:

  • runtime_acceptance_suite, pre-merge: 136/136 twice, then 136/136 again with the seat race fix at a 15-minute load average of about 320. The code_facets test looped 8/8.
  • runtime_acceptance_suite, merged tree: 135/137. The loom restart test passes once CARGO is set; outside cargo that variable is missing. workflow_json_preserves_a_typed_application_problem_envelope fails in the workflow CLI path, which this PR does not touch. It passed pre-merge and arrived red with the master merge.
  • tracedecay-code-index-runtime lib: 540/540 pre-merge. Merged tree: 544/545; the failure is the RSS-watermark memory_tests test, which passes alone 3/3.
  • core_cli_suite: 159/159 pre-merge.
  • tracedecay-application lib: 481/481. application_suite: 66/66.
  • mcp_suite: failures only in the harness's 20 s wait for code-index publication under host load, with the same failure shape on master: 44 failures on master against 41 on the fix for the same 85-test batch. That wait is tracked by test(mcp): graph_query fixtures miss the 20s publication wait under load #2502.
  • clippy -D warnings (tracedecay-code-index-runtime, tracedecay, tracedecay-cli, all targets) and cargo fmt --check are clean.

#2430, not addressed

This PR does not address the SIGTERM exit bound. The measured timeline under a CPU cap shows the cooperative drain expiring while project open is inside the session-store mount's schema install. That store-runtime open is detached and not cancellable, and shutdown closes only idle Ready runtimes. Cutting that wait needs interruptible schema install with typed rollback, which belongs in a separate change.

A git owner published before project open installed its authority
answered every read as a policy denial; until the authority lands the
owner is still mounting, so reads get the retryable mounting problem
the CLI re-sends.

A whole-generation code read's own demand starts the deferred decode
of a published text owner; it now waits for that seat within its
resolution deadline instead of answering the first read unavailable.

Test fixtures: the surface transport test waits on graph_ready before
reading the graph, the runtime fixtures' hermetic PATH regains the
toolchain's $CARGO_HOME/bin so the daemon can route rust-analyzer, and
the host-event acceptance test asserts the session attribution hook
rows carry since #2480 while still refusing it in any other field.
…ssues-master-reds

# Conflicts:
#	crates/tracedecay-code-index-runtime/src/code_index_scheduler/registry/serving_reads.rs
@changeset-bot

changeset-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: b7a9d70

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T09:40:06.256987Z 78e2f28 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 78e2f28946

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +880 to +884
worktree
.complete_generation_requested
.load(Ordering::Acquire)
&& !worktree.memory_retry.waiting()
&& !worktree.shutting_down.load(Ordering::Acquire)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Stop waiting after terminal convergence parks

When a retained text owner has no decoded seat and its decode ends in one of the worker's terminal convergence-park paths (for example, reproducible input failure or unrecoverable publication corruption), complete_generation_requested remains permanently true while memory_retry is false and shutdown has not begun. This predicate therefore continues to report work as pending after the worker's final notification; the loop consumes the entire generation-resolution deadline—up to 30 seconds—before returning the already-known unavailable result. Include the convergence park or actual worker/decode activity in this check so terminal background repair cannot block an ordinary code-facet read.

AGENTS.md reference: AGENTS.md:L222-L224

Useful? React with 👍 / 👎.

@ScriptedAlchemy
ScriptedAlchemy merged commit b896d9f into master Sep 29, 2026
5 of 7 checks passed
@ScriptedAlchemy
ScriptedAlchemy deleted the fleet/fix-unowned-issues-master-reds branch September 29, 2026 10:17
ScriptedAlchemy added a commit that referenced this pull request Oct 1, 2026
)

Project open published each Git transaction owner when it started the
service and installed the owner's authority later, so the slot held an
Option and every lookup had to hide an authority-less owner as still
mounting. Shutdown cleared the same Option, so a request that had
already resolved an owner saw a policy denial instead of the daemon
going away.

`mount` now starts the service around an authority it has already
constructed and inserts the entry in one step; remounting the same
identity replaces the authority in place. The slot is `Installed` or
`Revoked`, and a revoked owner answers `DaemonUnavailable`, which Git
reads now map through the typed port problem instead of concealing it.
The engine-side `ensure` wrapper, `install_authority`, the `installed`
guard, and the session database threaded only to feed them are gone.

Refs #2612
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant