Repository navigation
feat(managed-agent): Add W0e terminal recovery fences #12839
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 1 commit
Commits
Show all changes
8 commits
Select commit
Hold shift + click to select a range
353b652
docs(managed-agent): Design W0e recovery and reclamation
727aafb
feat(managed-agent): Add W0e terminal recovery fences
092283b
Merge main into W0e recovery and preserve deferred receipts
9e42875
fix(runtime-broker): Retry confirmation for owned live workers
0dd60d4
fix(runtime-broker): Scope unadmitted startup block (#12839)
35e6525
Merge remote-tracking branch 'origin/main' into codex/managed-workspa…
752bff4
Merge remote-tracking branch 'origin/main' into codex/managed-workspa…
2d95f1a
test(runtime-broker): Pin local confirmation retry (#12839)
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev
Previous commit
test(runtime-broker): Pin local confirmation retry (#12839)
- Loading branch information
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[Suggestion] R1-38: The gate added to pin the transient-confirm retry asserts the numeric status and retryable flag but not the error code
503 with retryable=true is what at least three semantically different codes return on this path, including runtime_broker_runtime_lost — the permanent-loss answer that, per the settled PR discussion, never clears without stop proof. Changing the confirm-failure code from runtime_provision_failed to runtime_broker_runtime_lost keeps every assertion in aTransientConfirmFailureKeepsAnOwnedWorkerReady green (not ok, 503, retryable, binding still READY with the same bindingId, third warm READY, cross-workspace PROVISIONING) while telling a client to give up on a healthy, still-owned worker. The file's own convention is to pin the code (:117 and :146 both assert managed_runtime_unavailable); this is the only reply assertion in the file that checks a bare numeric status. Since this gate is the one the PR added to close the round-4 mutation gap, its own discrimination matters.
Witness:
Suggested fix: Add one line after assertTrue(failed.retryable()), following the file's convention:
assertEquals("runtime_provision_failed", failed.code());One premise this fix must not break: The actual code is fixed by LocalProcessRuntimeProvisioner.java:453 — confirm -> attestOwned -> attest's catch branches (:370, :372) route through failed(...), so the asserted literal must be runtime_provision_failed, not managed_runtime_unavailable.
Fix acceptance — That assertion is itself the pin. Falsification: changing the code in LocalProcessRuntimeProvisioner.failed(...) to runtime_broker_runtime_lost reddens the gate with the assertion and leaves it green without. Please prove it by mutation: apply the fix, then revert it and confirm that test goes red.
中文说明
[Suggestion] R1-38:在同一条
ensureBindingREADY 分支上,503 + retryable=true至少对应三种语义完全不同的 code,其中包括runtime_broker_runtime_lost——按本 PR 已 settled 的讨论,那是没有停写证明就永不清除的丢失语义。把 confirm 失败对外抛出的 code 从runtime_provision_failed改成runtime_broker_runtime_lost,aTransientConfirmFailureKeepsAnOwnedWorkerReady的每一条断言都仍然成立(not ok、503、retryable、绑定仍 READY 且 bindingId 不变、第三次 warm READY、跨 workspace PROVISIONING),而客户端会被告知放弃一个进程仍存活、绑定仍 READY 的健康 worker。同文件的惯例恰恰是钉 code 的(:117 与 :146 都断言managed_runtime_unavailable),这是全文件唯一一处只断言裸数字 status 的应答断言。由于这道门禁正是本 PR 为补上第四轮变异缺口而新增的,它自己的判别力尤其重要。修复建议:在
assertTrue(failed.retryable());之后按本文件惯例补一行:assertEquals("runtime_provision_failed", failed.code());修复不得违反的既有事实:实际 code 由
LocalProcessRuntimeProvisioner.java:453决定——confirm -> attestOwned -> attest的 catch 分支(:370、:372)走的正是failed(...),所以断言的字面量必须是runtime_provision_failed,不是managed_runtime_unavailable。修复验收:上方 “Fix acceptance” 一句点名的测试即验收标准(测试名与标识符在两种语言中逐字保留);请用变异验证——先应用修复,再回退它,确认该测试变红。
证据见上方 Witness 代码块:那是程序输出,按规则逐字保留、不翻译。
— kimi-k3 via Qwen Code /review (v0.24.7)