Repository navigation
fix(runtime): repair cross-host storage and verification journeys - #3200
Closed
ScriptedAlchemy wants to merge 32 commits into
Closed
ScriptedAlchemy wants to merge 32 commits into
ScriptedAlchemy wants to merge 32 commits into
Conversation
Paginate unoffered source records and accept empty refresh output when canonical effects support the bound frontier. Cover skipped refreshes across reopen and keep unsupported frontier advancement refused. Integrates the production fixes contributed in PR #3185. Fixes #3183. Fixes #3199. Co-authored-by: spa5k <79936503+spa5k@users.noreply.github.com>
Use the workspace flate2 backend for Windows ZIP extraction without activating another backend for content-addressed sealed storage. Fixes #3197.
|
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This was referenced Oct 8, 2026
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Superseded by merged #3141. The complete #3200 head (34ed0ff) is an ancestor of the Rust upgrade head (078b96b); its runtime source and build repairs are present on master. Native Windows validation and the unresolved incident evidence remain tracked in their open issues.
Repairs failures found while testing the beta.76 installation and its Linux and Windows verification paths.
Cross-platform builds and storage
Windows compiler commands now use the wrapper's existing response-file support. Fixtures now use canonical paths, declared Bazel inputs, portable tool lookup, and settled runtime owners. Sealed storage uses the same compression backend on every platform. The dashboard receipt test now controls curator completion directly.
Session rewrites and large histories
Session rewrites now continue beyond the engine row cap. An all-skipped refresh can finish only when the same session has an exact effect at the advancing target frontier.
This PR includes the reviewed work from #3185 with contributor credit. Later tests prove actual retirement, rollback after a late provenance collision, and a successful retry across keyset pages.
Large-history fixtures batch writes through the existing persistence and transaction code. The fixtures retain all 1,500 lookup messages, 24,000 dashboard messages, and the final session metadata.
Daemon capture
Daemon binding publication now creates the capture spool's exact records file, its matching checkpoint, and a durable directory entry. The first callback reuses that checkpoint. The regression failed before the follow-up fix and now passes.
Capture no longer syncs the directory during the first four live callbacks. Measured capture time fell from 52 to 62 ms to 2.25 to 3.44 ms. Admission budgets did not change.
Source reads
Source-body reads now require only the resident engine. They no longer wait for an unrelated catalog rebuild. Other reads still require catalog readiness.
The production regression first failed at its caller deadline. It now passes while the catalog rebuild remains blocked. The original live timeout in #3202 happened near a memory-exhaustion event, so its cause remains unknown.
Distribution acceptance
The manual distribution test now runs workspace MCP checks through Bazel and supplies the extracted CLI directly. Extracted-crate and downstream-consumer checks remain separate package acceptance tests.
Dashboard transcripts
Dashboard transcript selection now uses the canonical context limit of 64 records. A normal 100-record request keeps its opaque continuation token.
Before the fix, a production HTTP test with 70 messages failed. It now returns 64 messages on the first page and 6 distinct messages on the second. Timeline buckets include all 70 messages.
Received
Unknownresponses keep their typed state and explain that the daemon returned no usable result. Completed transcript pages now report measured canonical coverage instead ofUnknown. The regression distinguishes the six records on the last page from the raw session count of 70.Issue #3211 still tracks the difference between raw and canonical counts.
Background LCM convergence
All six background LCM read sites now use the existing background-reader admission path. A registered-store regression failed when convergence consumed capacity reserved for foreground work. It now passes with foreground reads available, and convergence resumes after the background leases are released.
Pool sizes, admission deadlines, and retry behavior did not change.
Rust and Bazel tooling
Rust formatting now uses native Bazel checks that read source files only. Rustfmt remains pinned to 1.97.1, and the checks still cover private test binaries without analyzing production dependencies.
The old aspect finished formatting but continued to analyze more than 52,000 production targets. The new checks analyze about 5,400 targets locally. Generated build rules now separate Rust sources from fixture resources.
CI and release metadata generation call the existing generator through Bazel. Developer performance checks, daemon checks, benchmarks, and host smoke tests now use Bazel targets or named prebuilt binaries. This PR removes obsolete Cargo fallbacks, the benchmark source archive, and the index backup.
Linux fixtures and benchmark rules
Linux suite fixtures now use committed observation-receipt sequences and canonical per-session refresh discovery. Hook tests verify that capture releases its maintenance lease. The spool-refusal fixture replaces the enrolled spool file with an invalid directory before it checks the typed denial. The temporal runner regression runs Bazel on both Linux and macOS paths.
Bazel generation now honors Cargo benchmark targets that set
test = false. Measurements run only when selected. Default builds still compile the code through test-only benchmark filegroups.The sealed-storage benchmark captures unchanged source bytes needed for cross-file resolution. It counts file, evidence, resolution-index, and graph segments by their production publication kinds.
Verification
Work-history read measurements now interleave short and long histories at the unchanged threshold. Five runs pass; temporarily restoring per-version refolding fails at 208x growth.
The diagnostics stale-publication test holds the existing scheduler mutex while observing the refusal, then releases renewal and verifies the same finding returns. The exact test passes on Rust 1.97.1 and 1.99.0.
Current master dependency upgrades are integrated, dependencies refreshed, and all 59 generated BUILD files remain current.
All five explicit Git ancestry benchmark scenarios pass, including close and reopen digest checks, after the graph map owner was mounted and retained.
Explicit LCM expansion passes canonical rendering and hydrates all 16 summary sources after temporal relations are published and the real store watermarks are frozen.
Both benchmark targets pass Clippy and formatting.
The repaired fixture tests pass: 37 LCM tests, 4 temporal benchmark tests, 5 hook lifecycle tests, the invalid-spool regression, the Linux and macOS runner regression, and the Bazel test-environment isolation probe.
Temporal preparation, ranking, and hydration tests completed in 8.17 seconds.
Sealed-storage clean, successor, and linked-worktree sealing and restore completed on an isolated Git fixture with 34 cross-referencing source files and 2 edits.
A separate full-repository sealed-storage run hit the existing 300-second test deadline. This PR does not claim full-corpus performance verification.
The repaired benchmark binary groups build. All 3 changed Rust packages pass formatting, and both commit messages pass commitlint.
All 59 generated BUILD files pass drift checks, and the resulting benchmark binary groups build.
The following tests pass: 5 frontier regressions, 4 MCP fixtures, 12 memory tests, 2 transport tests, 15 wrapper tests, 1 dashboard receipt test, 7 lifecycle and WAL tests, and 13 source-read, codec, rewrite, and portability checks.
Six dashboard LCM API tests, 7 dashboard adapter tests, 26 UI tests, and dashboard TypeScript checking pass.
The background-convergence admission regression passes after reproducing the defect. Production and unit-test session-runtime Clippy targets also pass.
Both source-rewrite tests pass, including actual projected-record retirement and rollback. They took 13.33 seconds in total.
Both large-history tests and scalar fixture compatibility pass. Session setup fell from 19.044 seconds to 9.480 seconds. Dashboard seeding fell from 45.127 seconds to 31.653 seconds. Read behavior did not change.
Packaged CLI selection rejects an explicitly missing binary as expected. The installed binary passes the same exact bridge test.
Clippy passes for the 19 Bazel targets affected at first and all 27 targets affected by the benchmark migration. Failed checks caught a redundant
Copyclone in the contributed test and a constant assertion in the benchmark. Both are fixed.The old and new formatting inputs contain the same 3,863 Rust source files. All 51 non-MCP package checks pass. A deliberate formatting error failed the check and passed after restoration.
The MCP package passes its pinned Bazel formatting check, including the diagnostics fixture repair.
Both workflows pass actionlint. Both real source and resource fixture checks pass.
Hosted CI passed the full committed-source formatting check in 4 minutes 52 seconds, including cold setup. All repository gates passed within the existing budget.
Eight scorecard tests, 4 isolated-daemon tests, 6 dogfood tests, and 6 release-helper tests pass. The tests cover build and discovery failures, missing binaries, paths with spaces, override precedence, and zero-test denial.
Claude benchmark validation passes 2 of 2 tests in default Bazel runfiles after the missing runtime evidence inputs were reproduced and fixed. The session benchmark's custom-main validator also passes.
Full benchmark measurement capture requires a clean checkout and was not run in this shared checkout.
Seven publication tests cover failed index moves, retries, interrupts at both publication boundaries, pre-existing results, and preservation of unreadable or malformed indexes. The old runner failed the index-move regression.
All 54 spool tests, the daemon publication regression, and the real concurrent hook-capture path pass.
Integration with the current Rsbuild bundle passes 3 freshness checks, extension type checking, 6 adapter tests, and 3 browser tests against the packaged app and an isolated real daemon.
The integrated hook suite passes all 105 selected tests.
Native CI must pass on the latest head before merge. Local checks do not prove Windows correctness. A separate Windows investigation covers shutdown WAL ownership and the live transcript-refresh deadline without changing budgets.
The original #3188 CI timeout did not reproduce locally. This PR removes the measured cold-directory barrier, but native CI remains required.
This PR addresses #3202. Keep that issue open until the original live path passes after installation. It partially addresses #3211. Keep that issue open until the raw and canonical count difference has a known cause and a verified installed fix.
Fixes #3183.
Fixes #3186.
Fixes #3187.
Fixes #3188.
Fixes #3189.
Fixes #3190.
Fixes #3191.
Fixes #3192.
Fixes #3193.
Fixes #3194.
Fixes #3195.
Fixes #3196.
Fixes #3197.
Fixes #3198.
Fixes #3199.
Fixes #3201.
Fixes #3203.
Fixes #3204.
Fixes #3205.
Fixes #3206.
Fixes #3207.
Fixes #3208.
Fixes #3210.
Fixes #3212.
Fixes #3219.