v0.4 automation integration and transaction safety - #71
Conversation
|
M1 transaction-safety checkpoint pushed at Isolated local evidence (fresh HOME/UserProfile/Codex/SQLite/AppData/Temp/cache roots; credential-like variables removed):
This checkpoint fixes the macOS order-sensitive cancellation case by deterministic rollout ordering and substantially hardens Issue #69 partial-write tracking, rollback, crash recovery, journal acknowledgement, cross-runtime backup metadata, and lock ownership. CI run 30878602260 is the first exact-head validation for this commit. Still intentionally deferred (not claimed complete): transaction journal v2 per-target rollback evidence and shared-SQLite pending markers. Windows Application/Business/GUI work continues in parallel. PR remains Draft. |
|
Milestone checkpoint at exact head 88dc703:\n\n- macOS desktop/Core/Application/Release build: PASS\n- desktop-test: PASS\n- Node 16/24 on Windows and Ubuntu: PASS\n- ci-gate: PASS\n- exact run: https://github.com/Dailin521/codex-provider-sync/actions/runs/30879154032\n\nThe follow-up fixes Node 16 test compatibility and makes lock publication no-replace on POSIX. Windows Application/API/GUI work continues in separate local slices; none of that unverified work is represented by this green head. |
|
SQLite consistency checkpoint at exact head f68279d4ef196c8030831fd038c7f44dbfc632d:\n\n- managed Node/.NET backups now use SQLite online backup\n- manifests record one standalone main database; live WAL/SHM are not copied independently\n- legacy metadata mirror is derived from the consistent snapshot\n- exact run: https://github.com/Dailin521/codex-provider-sync/actions/runs/30879424821\n- all required jobs and ci-gate: PASS\n\nWindows Application/API/GUI changes remain local and are not represented by this green checkpoint. |
|
Milestone pushed: \ef8cef240a492dc445169e4cbfb96842e055764\ (isolated WinForms automation bridge). Evidence at this exact commit:
Not claimed at this milestone: MainForm→shared Application migration, GUI→Application trace, modal-dialog E2E, or final headful PASS. Those are active follow-up slices. Exact-head CI is now pending. |
|
Exact-head CI checkpoint for \ef8cef240a492dc445169e4cbfb96842e055764: run \30880210036\ passed all required jobs (Node Windows/Ubuntu 16+24, Windows desktop, macOS desktop, ci-gate). This is a checkpoint only; later unpushed Application/Business/GUI trace work is not represented by this run. |
|
Milestone pushed: Exact clean-worktree evidence:
Coverage includes directory-generation ABA, file/symlink fail-closed diagnostics, bounded stale reclaim, claim cleanup semantics, no-replace recovery, owner-only Unix publication, and a stable busy marker/predicate while preserving the existing exact InvalidOperationException contract. Deferred by design: journal v2 and shared-DB pending markers. Exact-head remote CI is pending. |
|
Milestone pushed: Exact clean-worktree evidence:
Implemented:
Known honest limitation: auto-prune binds the complete managed backup-root inventory + retention action rather than publishing a fabricated per-directory deletion list. GUI migration/trace and headful E2E remain separate active milestones. Exact-head CI is pending. |
|
P0 follow-up pushed: Why this was required: the prior online-snapshot creation milestone no longer stored independent live WAL/SHM copies, but the restore path still deleted live sidecars before replacing the main file. A restore failure could therefore discard committed WAL data. Exact clean-worktree evidence:
Both Node and .NET now use backup snapshot as SQLite source and live DB as destination; neither manually deletes/copies live WAL/SHM. Node driver selection requires both |
|
Exact-head CI checkpoints:
The latter passed the expanded gate: Release desktop build/tests including Automation, macOS, Node Windows/Ubuntu 16+24, the new Ubuntu .NET lock job, and ci-gate. Current head \5b8be5\ has its own CI still in progress; these earlier runs are checkpoints only. |
|
Milestone: WinForms now shares the v0.4 Application use cases ( |
|
Exact-head CI checkpoint: PASS: Windows desktop tests, macOS Core/Application + Mac build, Linux lock tests, Node 16/24 on Windows and Ubuntu, and This is an intermediate checkpoint. The PR remains Draft; the real headful Windows Release GUI E2E, its CI wiring, documentation/version finalization, and final exact-diff Claude review are still in progress. |
|
Milestone pushed at �6a91cb: Windows lock identity reads now use delete-sharing, owned claim cleanup is bounded/revalidated/retryable, and cleanup exhaustion preserves both the original contention and cleanup evidence. Local evidence: LockService 28/28 PASS; full lock-filter suite previously 46/46 PASS; two-reclaimer stress 50 rounds per run (plus repeated 500-round verification) PASS; diff check PASS. Next: land the SQLite SHM plan-stability fix, then rerun the one-shot real Release GUI E2E. |
|
Database plan-stability milestone pushed at 6603dd8. Real Headful evidence showed restore replanning twice with identical main/WAL hashes and only state_5.sqlite-shm timestamp drift. Fix: SHM is excluded as derived WAL-index/lock state; SQLite plan fingerprints bind main/WAL bytes without mtime; missing and zero-length WAL normalize identically; snapshot format is v2. Durable drift protection remains: a committed WAL-resident SQL change is rejected before mutation. Evidence: new planning tests 11/11, repeated 110/110; full Core Debug 176 pass + 1 existing WSL skip; full Core Release 176 pass + 1 skip; Application 49/49; diff check PASS. Independent Claude database/reliability challenge was read and its actionable mtime/empty-WAL concerns were incorporated. Next: rerun the hardened real Release GUI E2E after its anti-false-PASS gates finish. |
v0.4 Windows GUI E2E milestonePushed implementation commit Visible interactive Windows Release E2E at
|
COMPLETE — final exact-head gate
PR remains Draft. No main mutation, auto-merge, tag, or Release was performed. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ed6cd7243f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Review-fix checkpoint —
|
Review ResultNo additional P0/P1/P2 findings were identified at checkpoint The reviewed changes address all three earlier findings:
The worktree was already clean at the supplied commit, so I made no changes, created no additional commit, and—per the repository workflow—did not create a new pull request. Checks
|
|
@codex review Please review exact head The prior three findings were addressed with regression coverage:
Exact-head CI run 30893772549 passed all 8 jobs. Visible Windows Release GUI E2E passed 40/40 manifest and 53/53 required scenarios with 0 errors/blockers. |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3a97301a40
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| await syncStagedFile(tmpPath); | ||
| await fsp.rename(tmpPath, change.path); |
There was a problem hiding this comment.
Skip rollouts that remain open on POSIX
When sync runs on Linux or macOS while Codex still has an active rollout open, this staged replacement swaps the directory entry while the writer's existing file descriptor remains attached to the old inode; later session records can therefore be appended to an unlinked inode and disappear from the visible rollout. The final size/mtime check cannot detect writes made after the rename, and this commit routes equal-length provider rewrites through this replacement instead of the previous in-place update, broadening the data-loss case. Detect and skip active rollouts or preserve the inode during rewriting.
AGENTS.md reference: AGENTS.md:L137-L141
Useful? React with 👍 / 👎.
| const normalizedBackupDir = path.resolve(backupDir); | ||
| let boundJournal = null; | ||
| try { | ||
| boundJournal = await readTransactionJournal( | ||
| path.join(normalizedBackupDir, "transaction-journal.jsonl") |
There was a problem hiding this comment.
Reject restores while another transaction is pending
When transaction A has a non-terminal recovery journal and the user invokes the Node CLI to restore backup B, this code inspects only B's journal and never checks findPendingTransactions(codexHome). It consequently permits an unrelated snapshot to overwrite the partially recovered state while A remains pending; the later mandatory restore of A then overwrites B again. Reject the restore when any pending transaction is bound to a different backup, as the .NET restore path already does.
Useful? React with 👍 / 👎.
Summary
Draft v0.4.0 integration PR, built from the verified PR #70 Application/Controller baseline and completed on branch
agent/v0.4-automation-integration.Final branch head:
3a97301a40b499f07d482248502b48c1c31df713(documentation-only evidence update).Final implementation/headful head:
28c4dd40a5a23282a990533a350b88b334e3d5c7.describe,status,plan,sync,switch,restore, andprune; writes are dry-run by default and require explicit--applyplus the bound plan and digest;--sqlite-home,--allow-sqlite-home-relocation, and--no-configfor Automation restore relocation;5for complete-rollback evidence, uses2beforeApplying, and fails closed with10for applying failures without rollback/recovery evidence;Verification
All fixtures used disposable HOME/UserProfile/Codex/SQLite/AppData/Temp roots. No real
auth.json, token, Codex Home, SQLite Home, or user data was read or tested.28c4dd4: 40/40 manifest entries, 53/53 required scenarios, 17 dialogs, 6 file-diff groups, 57 trace rows, restart passed, 0 errors, 0 blockers, and the published EXE SHA-256 matched independently.@codex reviewreported no major issues. The single external reliability challenge was unavailable after repeated server-side 502 retries and was cancelled at maintainer direction; it is not represented as a PASS.Release state
Final exact-head CI and fresh Codex review are green, and primary review found no P0/P1/P2. No
mainmutation, merge, auto-merge, formal tag, or Release has yet been performed. CI contract tests are explicitly non-Headful; the real visible Headful run above is the release evidence.Closes #69 when merged.