fix(code-index): answer master-red reads from their true authority - #2361
Merged
Merged
Conversation
- Lexical artifact full-verify open classifies the format revision before decoding the embedded receipt, so a historical artifact is Incompatible. - Diagnostics publication identity reads the retained generation, not lexical serving, and a publication whose source proof moved reads as stale rather than as an unavailable authority. - Ignored-dependency admission demands the decoded generation when a ready generation serves without its decoded seat. - A status readiness wait reports the reading that reached it. - Symbol-graph receipts end at the metered read's measured end. - Pins for owner refusals now assert the isError problem records.
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2313, Fixes #2333, Fixes #2336, Fixes #2344
Master-red bundle, plus the #2339 follow-up. For each test, this states the cause and whether production or the pin was wrong. Fail-before evidence is from
origin/master(d0d4d3a at the start of the work), or from this branch with the production change reverted and the new test kept.Per test
#2313
search_quality_suite candidate_producers::reader_refuses_historical_v10_writer_artifact_as_incompatible: production wrongSince d054014,
open_content_addressedgoes through the full-verify path. That path decoded the embedded receipt before checkingformat_revision, so a revision-10 artifact failed serde asCorrupt("unknown fieldgeneration…")instead ofIncompatible. The pre-refactor open checked the revision first; the full-verify open now does too (verify_artifact_state_revisionbefore the receipt decode). The lib test named in #2313 was already green on master.70 passed; 1 failed,unexpected error: Corrupt("unknown fieldgeneration…")71 passed; 0 failed#2333 / #2344 (1)
tracedecay --lib daemon::tests::runtime_identity::concurrent_same_identity_worktrees_keep_exact_server_and_scheduler_bindings: stale pin21552e3 (#2319, #2340) intentionally answers graph-owner refusals as
isErrortool results, and #2319 re-pinned the mcp_suite callers; this daemon lib test was missed. The route still refuses the listing. The pin now assertsisError: trueplus the literal problem: kindunavailable, codecode-graph-unavailable, messagethe exact project code graph is unavailable: the verified code graph is not ready for the exact project root. The two "readiness" lib tests another lane reported did not fail in any full lib run here. On master the only lib failures were this test and a rebind race indaemon_http_shutdown_releases_loopback_listener, filed as #2342.768 passed; 2 failed; branch:770 passed; 0 failed#2336
core_cli_suite tool_diagnostics_reads_the_typescript_producer_publication/…_a_monorepo_package_finding: production wrong (two causes)A temporary probe (removed) showed that every failing read returned from
diagnostic_identity.resolve() == Nonewhile a complete publication for generation G existed.resolve_current_publication_identitynow reads the retained owner. It uses only the manifest and snapshot, the same "identity, not serving" rule the LSP identity port already follows. The perf(diagnostics): check only changed TypeScript projects at the seal #2325 reconcile test that pinnedresolve == Nonewhile projection is held now pins "nothing serves" through the serving accessor, and asserts that the read identity names the sealed generation.fresh=false: the source proof had moved (for example, Git metadata) and was being renewed. The fence documents this state as "reads report the retained owner stale". The diagnostics read now checks the retained code-index identity first (a call it already made), so an unresolved publication identity reads asapplication.diagnostics.stale, notunavailable.application.diagnostics.unavailable), and 1 of 120 with only fix 1 applied under 8-way contentionmcp_suite diagnostics_read_test::moved_source_proof_reads_the_publication_as_stale_until_renewedpublishes TS4023, moves.git/index's mtime, and requires every read to bestaleuntil the same finding returns. master:[String("application.diagnostics.unavailable")]; branch: pass.the retained generation answers identity while its text projection is heldpanics; branch: pass.#2344 (2)
daemon_suite indexing_lifecycle_test::ignored_dependency_admission_survives_physical_daemon_restart_without_widening: production wrong, then shapeThe refusal was not just the #2340 shape change: it said
ignored-dependency admission found no exact-scope serving generation. Since #2332, a ready generation serves from its text owner and decodes only on demand. Ignored-dependency admission requires the decoded seat but never demanded it, so every retry would have refused. Admission now demands the complete generation when a graph-on mount has no decoded seat, and the caller's typed retry finds it seated. An earlier variant that waited inside admission hung a symlink-rejection test that never seats; it was dropped for this one. The test retries through that typed state, then pinsisErrorwith codeapplication.symbol-graph.ignored-dependency-generation-advancedand messageignored dependency indexing advanced the graph generation; retry the request.#2344 (3)
daemon_suite indexing_lifecycle_test::status_wait_for_returns_reached_with_the_saved_edit_generation: production wrong (payload)Re-checked after #2341: it passes alone on current master but fails under full-suite load, with
wait: reachedbesidecode_index_freshness.status: stale/staleness_state: verifyingon the edit's generation. There is one freshness authority,CodeIndexSchedulerRegistryV1::dashboard_freshness_read, and it was read twice. The wait read it and reached; then status built the payload from a second read, after a late watcher event had moved the proof.CodeIndexReadinessWaitReadV1::Reachednow carries the reading that satisfied the wait, and status renderscode_index_freshnessfrom that reading, as the dispatch comment already promised ("the payload describes the worktree the wait ended on").daemon_suiterun before this change (left: "stale" right: "current");daemon_suiteis64 passedafter it.#2339 follow-up: symbol-graph
ended_at == started_atcomplete_or_failedstampedfinished_at: context.observed_at. It now ends atobserved_at + wall_micros, from the same cost receipt that supplieselapsed_micros. An overflow is a typed failure.typed_callers_carry_their_read_costassertsended_at - started_at == cost.wall_micros. master:left: Some(0) right: Some(1750); branch: pass.Suites (local, Linux)
tracedecay-query: lib267 passed,search_quality_suite71 passedtracedecaylib770 passed;tracedecay-applicationlib478;tracedecay-code-index-runtimelib529in a full run and528 passed; 1 failedin the next, where the failure (shutdown_timeout_retains_blocked_worker_owner_until_retry_joins_it, a 2 s admission wait under load) passes 5/5 alone;tracedecay-mcplib387;tracedecay-contractslib420daemon_suite64 passedmcp_suite585 passed; 1 failed. The failure isstatus_behavior_test::tracedecay_status_reports_the_sealed_branch_and_keeps_diagnostics_opt_in, which fails on current master with every crate at master (8 of 10 isolated runs, together withcontext_related_order_test), filed as test(mcp): status and context pins read a transient verifying state #2356.tracedecay-cli: bin334,core_cli_suite145 passed; 1 failed. The failure isbranch_add_admits_background_publication_and_remove_retires_its_exact_artifacts: it pins a transientindexinglabel that is alreadysynced. It first failed after refactor(mcp): serve admin project through its owners #2351 and refactor(mcp): serve admin cli through its owners #2354, and this diff doesn't touch branch admission; filed as test(cli): branch add pin expects an indexing state that already finished #2360.core_cli_suitewas146 passedbefore rebasing onto those.1,2+1,9,4,6passed).cargo clippy -p tracedecay-query -p tracedecay-application -p tracedecay-code-index-runtime -p tracedecay-contracts -p tracedecay-mcp -p tracedecay -p tracedecay-cli --all-targets -- -D warnings, with and withouttracedecay-cli/test-transport,tracedecay/test-transport,tracedecay/test-helpers: cleancargo fmt --all -- --check: cleancargo check --workspace --all-targets --target x86_64-pc-windows-gnu --features tracedecay/test-transport,tracedecay/test-helpers,tracedecay-cli/test-transport: exit 0. Its warnings are pre-existing unix-only test code; none is on a changed line.Runtime journey
core_cli_suite tool_surface_transport_test::tool_diagnostics_reads_*drives the shippedtarget/debug/tracedecay(tracedecay tool diagnostics --format jsonagainst a spawned daemon in an isolatedHOME, a real TS project with its ownnode_modules/.bin/tsc). Run as 8 parallel loops × 15 runs on the final binary:A..H failed=0.