fix: retain admitted images during active native restart - #126
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Active native restart re-resolved mutable image tags, so an unchanged project could fail compatibility review before cleanup after tags moved. Restart now reuses admitted immutable image IDs when the original Compose input is unchanged, matching retained startup. Fresh native service authority brackets the receipt read and is rechecked after compatibility and listener review. Changed input keeps ordinary resolution and existing ownership, source, network and admission guards; completed initializers remain supported.
Validation: 111 focused startup/restart/review/image tests pass. The full suite passes with 1,825 tests, 67 existing skips and no failures; full typecheck, lint/privacy and CLI build pass. All eight CI jobs pass at f17ede1.
On the M3, preflight preserves all 14 admitted images and nine routes without resolving mutable tags. A signed local frontend correction using unchanged published native binaries completed active replacement; exec, one-off run, retained Redis marker and trusted HTTPS with all 16 assets passed. The published next.1 package remains immutable and does not contain this correction.
A separate normal-down test exposed a partial stop failure reported as engine_protocol. Explicit receipt/owner-selected recovery on the immediate successor guest boot preserved the disks, CA, target volumes and stopped sibling. The published package was restored and fresh authenticated browser search, commands, retained data and HTTPS assets pass again. This does not establish ordinary down/up qualification; that separate blocker is tracked as HACK-1212. The cause of the stop transport failure is not yet proven.