Skip to content

fix: diagnose and recover partial native graph shutdown - #127

Open
roodboi wants to merge 2 commits into
nextfrom
codex/partial-graph-shutdown
Open

roodboi wants to merge 2 commits into
nextfrom
codex/partial-graph-shutdown

Conversation

@roodboi

@roodboi roodboi commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

A retaining down can leave an admitted graph partially stopped. The frontend previously sent that pending shutdown through failed-start recovery, where a completed historical startup journal caused a refusal without useful diagnostics. This change preserves the mapping, reports bounded service/stage diagnostics, and adds read-only doctor --native-cleanup inspect output with the supported explicit recovery flow.

Immediate-successor recovery now recognizes the interrupted operation’s exact pre-effect bridge selection, including graphs with no ingress routes. Empty selections still require a verified dead predecessor; historical generations still require independent restore-history proof. Same-boot uncertain stop requests are not replayed.

Validation on isolated Apple Silicon macOS pools:

  • Normal 14-service foreground shutdown → retained marker → foreground restore → final owned cleanup passed.
  • One controlled real stop-transport refusal → ordinary/same-boot/stale-receipt refusal → exactly one managed boot rollover → exact recovery passed, preserving target/sibling volume identities, markers and the stopped sibling receipt. Final cleanup stopped the pool.
  • The preserved failing zero-ingress fixture also recovered on its existing successor boot with the corrected build.
  • TypeScript typecheck/check and full tests passed (1,834 passed, 67 skipped); Rust default/all-feature clippy and all-feature tests passed (949 unit tests plus integration suites, 82 ignored). Default tests also passed (928 unit tests plus integration suites, 57 ignored); all eight GitHub Actions jobs passed on final head 51188903e3b5625d9af7f117cf8b492bf0820a80 (run). Privacy and generated CLI-reference checks passed.

The original published engine_protocol failure cause remains unproven. Native fixtures are ignored by ordinary CI and require explicit isolated pools/watchdogs; this PR does not claim new application acceptance, comparative performance gains, or an updated published prerelease. Private logs/research are excluded.

Tracks HACK-1212. Candidate base: next.

Hosted Linux lint initially found an unused plain stop wrapper. It is now compiled only for its macOS recovery callers; diagnosed graph shutdown remains available on both platforms. Local default/all-feature clippy and final-head Linux/macOS CI pass.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant