Observed behavior: Static review at 8625cc50fbd07ef66e5fde1b96d8b8a77cd6d414 shows explicit restartDaemon has publication assertions outside the final ensureDaemon assertion covered by #865. Its initial assertion can collide with the old daemon's passive sweep. After manager stop/start, the nested ensureDaemon initial assertion can collide with the newly launched daemon before its child identity is admitted, and the outer final restart assertion can collide again after nested ensure succeeds.
Expected behavior: Explicit restart should have bounded, identity-authenticated publication convergence at its own assertion boundaries without retrying manager mutations, trusting lock-owner records as identity, or reacquiring identity from an unverified PID file.
Root cause: src/daemon/lifecycle.ts:3306-3311 contains unwrapped initial/final restart assertions. ensureAfterManagerOperation at lines 3612-3633 calls public ensure after manager start with an authorized manager PID, but public ensure performs its initial assertion before authenticated admission (1580-1588). These are distinct from #865's final ensure assertion and remain fail-closed reliability failures.
How to reproduce safely: Use complete hermetic lifecycle fixtures and fake supervisors/health only. Inject typed publication contention at each of the three assertion points with known fixture owner and release it deterministically. Assert manager stop/start is never replayed. No live daemon, installation, host process signaling, or operational reproduction is needed or was performed.
Environment:
- Agent: Astra owner, GLM5.3 max/Grok4.6 medium independent reviews and Opus5 medium adjudication
- Connector: static source review
- OS: Fedora Linux; lifecycle behavior is cross-platform
Discovered in #865 under Epic #848. P2 reliability follow-up; outside immutable S1 cutoff. Current #865 fixes only the final ensure assertion and does not claim whole explicit-restart convergence.
Observed behavior: Static review at
8625cc50fbd07ef66e5fde1b96d8b8a77cd6d414shows explicitrestartDaemonhas publication assertions outside the finalensureDaemonassertion covered by #865. Its initial assertion can collide with the old daemon's passive sweep. After manager stop/start, the nestedensureDaemoninitial assertion can collide with the newly launched daemon before its child identity is admitted, and the outer final restart assertion can collide again after nested ensure succeeds.Expected behavior: Explicit restart should have bounded, identity-authenticated publication convergence at its own assertion boundaries without retrying manager mutations, trusting lock-owner records as identity, or reacquiring identity from an unverified PID file.
Root cause:
src/daemon/lifecycle.ts:3306-3311contains unwrapped initial/final restart assertions.ensureAfterManagerOperationat lines 3612-3633 calls public ensure after manager start with an authorized manager PID, but public ensure performs its initial assertion before authenticated admission (1580-1588). These are distinct from #865's final ensure assertion and remain fail-closed reliability failures.How to reproduce safely: Use complete hermetic lifecycle fixtures and fake supervisors/health only. Inject typed publication contention at each of the three assertion points with known fixture owner and release it deterministically. Assert manager stop/start is never replayed. No live daemon, installation, host process signaling, or operational reproduction is needed or was performed.
Environment:
Discovered in #865 under Epic #848. P2 reliability follow-up; outside immutable S1 cutoff. Current #865 fixes only the final ensure assertion and does not claim whole explicit-restart convergence.