Conversation
roodboi
marked this pull request as ready for review
October 5, 2026 02:04
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A concurrent
hack pscan hold the provider lock when the managed HTTPS authority starts. Authority startup previously used a fail-fast acquisition and could exit before publishing its socket. Reuse the existing five-second startup admission wait, then verify the current pool and publish the authority once under the acquired lease. Deadline expiry admits no authority; socket/lease ownership rules and serving/cleanup behavior remain unchanged.Capture only a bounded structured error code from the owned native authority child, with no raw stderr or application values. Child exit revokes readiness immediately; diagnostic draining after exit is bounded. Separate readiness from later authority-identity, permission-port and Caddyfile preparation stages so a failure receipt identifies the correct boundary.
Validation: the actual managed startup path passes deterministic brief-lock and persistent-lock controls; 38 focused TypeScript checks cover child output filtering, no-stderr and successful exits, inherited stderr, delayed classification, and no Caddy start after authority exit. CLI/root typecheck/check, changed-test lint, privacy and diff checks pass. Independent read-only review found no concrete issue. Default Rust fmt/Clippy/tests pass (1,061 passed, 62 ignored); all-feature Clippy/tests pass (1,154 passed, 85 ignored). The full root test gate passes: CLI 1,845 passed, 67 skipped, zero failures. All eight required hosted CI checks passed on previous head
e3f3d07b; new exact-head CI is pending after integrating dependencies. Fresh root typecheck and diff checks pass on the merged source. The optional Markdown Prettier check flags existing whole-guide formatting; this integration preserves the guide text without broad reformatting.Dependencies: includes #131 exact-lease release diagnostics and the separately reviewed test-only cancellation correction from #132. Merge #132 and #131 before this PR. The current head
15a3227cincludes #131 through a normal merge, with both documentation sections retained and reordered so the intended squash merge order is conflict-free. A merge-tree simulation against the #131 squash tree passed and produced exactly this head tree.Release signal:
fix. The source race is demonstrated; the previous isolated native fixture's original cause is still unproven because it discarded child output. A fresh isolated native domain matrix passed all 54 behavior checks and owned disposal under HACK-1163: prepared-base linked-worktree startup; down/edit/up with the same run and a new container; exact source and retained marker; legacy, OAuth and API aliases; six-route migration and forward restart; drift refusal, exact rollback and reverse restart; removed-alias negative controls bracketed by working routes; and unchanged primary-checkout bytes/modes. Post-run observation found no fixture processes and the fixture TLS port was free. Native source wase3f3d07b; the frontend was composited67f4a9d(this correction plus #131 and #132); harness source was4548f6a8. This is combined-candidate local HTTPS and cleanup proof, not browser/System DNS, performance or published-artifact proof. It does not prove the original opaque failure was caused by contention. No mutation is replayed and no diagnostic grants recovery authority.Source qualification: production, tests, scripts, entry point and dependency Git objects at
15a3227cmatch the successfully qualified composited67f4a9dexactly. Only documentation paragraph order differs. Existing Rust, full-suite and native evidence is retained with its recorded source; no unchanged native matrix or duplicate full suite was rerun for the documentation integration.