Skip to content

fix: wait for HTTPS authority startup admission - #133

Open
roodboi wants to merge 6 commits into
nextfrom
codex/authority-startup-admission
Open

roodboi wants to merge 6 commits into
nextfrom
codex/authority-startup-admission

Conversation

@roodboi

@roodboi roodboi commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

A concurrent hack ps can hold the provider lock when the managed HTTPS authority starts. Authority startup previously used a fail-fast acquisition and could exit before publishing its socket. Reuse the existing five-second startup admission wait, then verify the current pool and publish the authority once under the acquired lease. Deadline expiry admits no authority; socket/lease ownership rules and serving/cleanup behavior remain unchanged.

Capture only a bounded structured error code from the owned native authority child, with no raw stderr or application values. Child exit revokes readiness immediately; diagnostic draining after exit is bounded. Separate readiness from later authority-identity, permission-port and Caddyfile preparation stages so a failure receipt identifies the correct boundary.

Validation: the actual managed startup path passes deterministic brief-lock and persistent-lock controls; 38 focused TypeScript checks cover child output filtering, no-stderr and successful exits, inherited stderr, delayed classification, and no Caddy start after authority exit. CLI/root typecheck/check, changed-test lint, privacy and diff checks pass. Independent read-only review found no concrete issue. Default Rust fmt/Clippy/tests pass (1,061 passed, 62 ignored); all-feature Clippy/tests pass (1,154 passed, 85 ignored). The full root test gate passes: CLI 1,845 passed, 67 skipped, zero failures. All eight required hosted CI checks passed on previous head e3f3d07b; new exact-head CI is pending after integrating dependencies. Fresh root typecheck and diff checks pass on the merged source. The optional Markdown Prettier check flags existing whole-guide formatting; this integration preserves the guide text without broad reformatting.

Dependencies: includes #131 exact-lease release diagnostics and the separately reviewed test-only cancellation correction from #132. Merge #132 and #131 before this PR. The current head 15a3227c includes #131 through a normal merge, with both documentation sections retained and reordered so the intended squash merge order is conflict-free. A merge-tree simulation against the #131 squash tree passed and produced exactly this head tree.

Release signal: fix. The source race is demonstrated; the previous isolated native fixture's original cause is still unproven because it discarded child output. A fresh isolated native domain matrix passed all 54 behavior checks and owned disposal under HACK-1163: prepared-base linked-worktree startup; down/edit/up with the same run and a new container; exact source and retained marker; legacy, OAuth and API aliases; six-route migration and forward restart; drift refusal, exact rollback and reverse restart; removed-alias negative controls bracketed by working routes; and unchanged primary-checkout bytes/modes. Post-run observation found no fixture processes and the fixture TLS port was free. Native source was e3f3d07b; the frontend was composite d67f4a9d (this correction plus #131 and #132); harness source was 4548f6a8. This is combined-candidate local HTTPS and cleanup proof, not browser/System DNS, performance or published-artifact proof. It does not prove the original opaque failure was caused by contention. No mutation is replayed and no diagnostic grants recovery authority.

Source qualification: production, tests, scripts, entry point and dependency Git objects at 15a3227c match the successfully qualified composite d67f4a9d exactly. Only documentation paragraph order differs. Existing Rust, full-suite and native evidence is retained with its recorded source; no unchanged native matrix or duplicate full suite was rerun for the documentation integration.

@roodboi
roodboi marked this pull request as ready for review October 5, 2026 02:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant