Skip to content

test(config): qualify native process policy execution - #186

Merged
roodboi merged 31 commits into
nextfrom
feat/native-process-policy-acceptance
Oct 8, 2026
Merged

roodboi merged 31 commits into
nextfrom
feat/native-process-policy-acceptance

Conversation

@roodboi

@roodboi roodboi commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Native workloads can author init, shutdown signals/grace and restart policies. This adds a required Docker scenario that observes SIGUSR1 delivery, delayed graceful exit, forced termination after authored grace, orphan adoption/reaping by init, and exactly two on-failure retries before a successful third start. A separate attempt-result marker, exact engine restart state and owned start/die history must all agree; bounded synthetic proof is retained privately before verification and teardown.

The fixture uses a cached immutable Bun image and one owned persistent evidence volume, publishes no ports and changes no DNS or trust. A second native profile checks retained records and an EROFS write refusal on its read-only mount. A supported baseline must validate first. Active and inactive unsupported resource/logging declarations require precise compiler diagnostics through config validate, followed by the execution command’s fixed redacted refusal before hooks or engine requests. Teardown checks exact ownership and preserves both private roots and recovery identities if cleanup is incomplete.

Verification

At 1c7b74c:

  • Current compiled CLI build; full typecheck/check, privacy and changed-test lint pass. CLI checks executed fresh; unchanged DB checks reused cache.
  • Full CLI suite at prior d33662e: 3322 pass, 73 skip, 0 fail; 19281 assertions across 321 files. The subsequent fixture-only correction passes 9 focused tests/78 assertions plus current CLI typecheck, changed-test lint and privacy; product source/executable is unchanged.
  • Independent source review approved the evidence controls. Reconciliation preserves that source plus cached-reader pull refusal.
  • Matching compiler source tree, executable hash and protocol verified.
  • M3/orbstack compiled Docker scenario passes at this exact head: 27.1s, 1 pass, 0 fail, 0 skip. Observed SIGUSR1, graceful exit0 after 1201.6ms, forced exit137 with 1944.1ms heartbeat, actual init adoption/reaping, attempts3/RestartCount2/on-failure limit2 and three start/two exit17 events. Native read-only profile rejects writes with EROFS/exit23 and preserves the records. Exact fixture cleanup passes; all pre-existing 5 container, 14 network and 27 volume IDs are unchanged.
  • Hosted exact-head CI remains pending.

Release Signal

  • Squash title: test(config): qualify native process policy execution
  • Release intent: test
  • Trigger a release signal: no; this adds verification without changing product behavior.

Semantic Surfaces

Product execution semantics are unchanged. The new registered scenario, evidence controls and harness documentation cover the existing process-policy surface.

Risks / Follow-up

This fixture does not qualify resource limits/reservations, logging policy, multi-network, file-secret or advanced-build execution. Hosted exact-head CI remains required; M3 live acceptance is complete.

hack-cli-tests added 28 commits October 7, 2026 19:44
@blacksmith-sh

This comment has been minimized.

@roodboi
roodboi merged commit 34ff0eb into next Oct 8, 2026
13 checks passed
@roodboi
roodboi deleted the feat/native-process-policy-acceptance branch October 8, 2026 04:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant