Fleet role finalization and closed receiver continuation - #57
Merged
Merged
Conversation
…continuation # Conflicts: # crates/cellule-host/src/fleet/reconciler/observation/mod.rs # crates/cellule-host/tests/node/fleet_maintenance.rs # docs/fleet-operations-plan.md # docs/fleet-operations-progress.md
Require both native role policies and refuse closure with a missing reader replacement. Share the existing four-boot setup, public reconciler and joined cleanup. Split reader phases and box complete reconciliation to avoid a reproduced default-stack overflow. Qualify exact Rust source with 19 native regressions, both production commands and warning-denied lint.
Publication temporarily owns the publisher, and root advancement invalidates exact fleet captures. Retain the activation fence for exact quiescence and independently verified explicit maintenance demand while keeping complete-count, ordinary movement, final publication and role barriers intact. Add the canonical minion maintenance-busy command, joined failure cleanup, exact outcome/audit readback and deterministic publication/observation regressions. Qualified the exact sixteen Rust paths on native Rust 1.99: 36 selected regressions, three production commands and warning-denied host/runtime lint. Local regressions, API docs and document/boundary gates also passed.
Share bounded irreversible admission across namespace operations and GC. Preserve native failure sources and refuse closure after an original supervisor is lost during runtime teardown. Install the same owner through the existing host facility drain. Fix the minion successor corruption fixture to assert construction refusal and coherent substituted fences. Record exact native qualification and remaining fleet work.
Use the configured store admission for prepared commands, clones and restored snapshots. Retain accepted native dispatch after caller cancellation and keep convenience mutation within its existing whole-operation owner without changing command or snapshot bytes. Add real SQLite cancellation, closed-dispatch and exact replay regressions. Reproduce the CI two-job fixture race by delaying supervisor cleanup, then join prior fixture work before measuring the paused original operation. Preserve exact assertions and qualification profiles.
forhappy
marked this pull request as ready for review
October 5, 2026 16:34
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Continue
docs/fleet-operations-plan.mdafter merged PRs #37 and #56. Minion is the canonical executable atcrates/cellule-host/minion.Latest checkpoint: prepared Blob admission and fixture CI race
Prepared Blob command execution through the configured client now uses the same original store admission and retained native owner. Clones and restored snapshots refuse new dispatch after closure; accepted execution survives caller loss. Convenience mutation retains its one whole-operation owner across staging and dispatch, using the same native command path. Request identity, input/digest, snapshot bytes, resolution and durability are unchanged.
Add three public regressions for closed prepared clones/restores, cancelled accepted execution behind real SQLite work, and exact open replay with one upload. Resolve the original upload outcome bytes/sequence after closure. Reproduce and fix the full Rust CI fixture race: a prior reply can arrive before its supervisor releases ownership. Fixture setup now joins prior jobs before measuring the next paused job. The delayed-cleanup probe reproduced 2 versus 1 and passed after the test fix; the probe is removed and the one-job assertion remains exact.
Local Rust 1.97: eight Blob/Cron cases, five snapshot contracts and the typed application consumer passed; warning-denied lint/API docs, format, architecture/layout and document/SQL/peer gates passed. Final native qualification passed all 215 cases, warning-denied lint/API docs and static gates on exact snapshot
f8174764; full new-head CI remains required. BlobInventory still blocks maintenance until Cell-scoped pins, complete global retention and uncertain remote outcomes are covered.Earlier checkpoint: original Blob operation lifetime and minion CI fix
CellNode::install_blob_artifact_storethrough the existing ordered facility drain; keep the configured provider and client capability on one shared owner. No separate scheduler or drain lane.7fd0a2e5.9dad2e91. This snapshot precedes the final forced-runtime-loss guard; full new-head CI remains required.BlobInventory still blocks maintenance: local joining does not prove returned PreparedCommand lifetimes, Cell-scoped pins, complete global retention, remote outcomes or safe movement. These remain plan work.
Earlier checkpoint: parallel maintenance cleanup regression
Fix the full Rust CI maintenance cleanup test. Default hosts intentionally share a process-wide disk budget; an unrelated held 4096-byte reservation reproduced the final disk-zero failure. Give each simulated donor/successor a distinct budget at unchanged default capacity, retain donor zero assertions, add successor disk-zero and require the unrelated reservation to remain intact. Production behavior is unchanged.
Exact native run 37267463895 passed two complete parallel runtime suites (231 passed/4 ignored each) and warning-denied lint on snapshot
a3cfd497.The retained earlier Compose campaign passed reader smoke/object-only routing and failed leased local expired-burst query p99 (2.13677x baseline; 3.059677 ms versus 1.431917 ms). Cause is unproven; gates remain unchanged.
Earlier checkpoint: busy SQL maintenance
Add canonical minion
maintenance-busy: two continuous command lanes use the same public reconciler to cordon the donor, prepare receivers, dispatch native busy release, move all twelve Cells and finalize the exact boot. Every acknowledged request is resolved on its canonical successor with its original digest, sequence and result; an exact audit count detects duplicated or missing effects. Both lanes must be refused before their finite command bound. Client tasks join on success and failure before node/journal cleanup; startup failure retains its native source.Fix two reproduced starvation paths. Exact quiescence/release now use the immutable activation fence while accepted publication owns the publisher. Advisory owner inventory retains that fence; the planner and reference observer can retain explicit maintenance demand for an independently rechecked writer after root advancement. Complete counts and ordinary movement still invalidate; receiver preparation precedes source quiescence, and native settlement/final publication/role barriers remain required. Wrong identity, missing cost, Blob and foreign-role guards remain blocking. The planner digest advances to v15 and binds the fence; persisted ID, root and action codec bytes are unchanged.
Local Rust 1.97: 29 selected regressions, production busy command, warning-denied host/runtime lint and API docs, format, architecture/layout, document and SQL/peer gates passed. Production readback covered 88 acknowledged commands plus twelve original receipts, final counts
[0, 6, 6], and all three joined/retired boots. The exact sixteen Rust paths passed native job 111619387502 on snapshote3f6dacand Rust 1.99: all 36 selected regressions, three production commands and warning-denied host/runtime lint. Native busy readback preserved all 384 acknowledgements, twelve original receipts and exact audit rows; artifactbusy-maintenance-37264858825-1retains source/binary/environment/limits and raw results. This is finite in-process SQL evidence; full W4–W10 qualification remains required.Earlier checkpoint: combined reader/follower maintenance
Add canonical minion
maintenance-rolesusing the same four managed boots, supervisor, signed native peers and public reconciler. A donor holds both a reader and a foreign follower tail. Follower policy alone cannot authorize Finalize; native reader evacuation refuses an absent selected replacement and preserves the original Established open view. Both replacements must establish readers before joined original retirement and immutable reader policy. Fresh complete observation must prove both roles before SettleRoles and Finalize. Check both replacement receipts, original request history, renewed writer acknowledgement and[1, 0, 0, 0]ownership; join all four nodes and eleven enrollment rows.Native combined job 111610477201 passed on exact snapshot
8f64d2f: 19 selected regressions, both production commands and warning-denied Clippy on Rust 1.99. Local Rust 1.97 regressions, command, API docs and document/boundary gates passed. A reproduced stack overflow was fixed by splitting reader phases and boxing complete reconciliation at the scenario boundary; final runs use normal stack limits with no probes. No assertions, profiles or deadlines changed.The earlier parent
f9a476ecomplete Compose campaign passed, including original constrained reader scaling and leased/object-only routing. The earlier intermittent availability failure remains unexplained. This adds an in-process role combination; full primitive/process/provider qualification remains required.Earlier checkpoint: executable live-follower maintenance
Add
maintenance-followerto canonical minion using four managed boots and the existing durability supervisor. Zero local writers cannot hide a retained foreign follower lane. Missing replacement policy remains blocking; canonical writer drain covers the original tail, both original member retirements are confirmed, and the installed epoch 2 ensemble has two eligible members. Canonical acquisition resumes the writer on its original node and acknowledges another command. Fresh immutable policy and complete role observation authorize native Finalize and exact withdrawal. Canonical-root readback covers both acknowledgements and preserves the original request digest, expiry, sequence and stored outcome. Cleanup joins four nodes, both ensembles and every boot, with final writer counts[1, 0, 0, 0].Native follower job 111605650581 passed on the exact 11 changed Rust files: 18 selected regressions, production command and warning-denied host Clippy on Rust 1.99. Local executable, observation/reader/balance checks, host API docs and document/boundary/contract gates passed. The finite adapter retains two epochs and exact close barriers; it provides no failed-owner recovery capability or external process/provider qualification.
Parent f9a476e full Rust workspace job succeeded with all 376 minion cases, provider/process smoke, local/replica LTX and lint gates. Follower/object proof and other quality checks passed. Its Compose smoke and reader-scaling steps also passed; entity/routing measurements remain live. The earlier constrained-reader availability failure remains unexplained: two independent diagnostic attempts passed original 3/5/10/20-node profiles with all 300 scheduled writes committed per scale. No production runtime fix is claimed from passing reproductions. The new published head requires complete CI.
Executable reader maintenance
Add
maintenance-readerto canonical minion. The public driver cordons a managed reader boot, preserves its usable reader while replacement policy is missing, opens a canonical selected replacement, publishes immutable evacuation evidence, settles the full role graph and finalizes native shutdown/withdrawal. Verify replacement value 29, the original stored mutation result, unchanged writer ownership and all joined runtime/enrollment ledgers. Share the signed native peer adapter with existing reader tests. Wait for real selection to observe the cordon through its bounded cache; sign only actual samples matching current local admission mode.Native reader job 111598959724 succeeded on the exact Rust source: the production CLI, 1 executable regression, 10 existing reader fault cases, 2 reader observer contracts, 3 follower observer contracts and warning-denied host Clippy.
The parent 9257b18 Compose smoke failed in unchanged constrained mixed-reader load with ReplicaUnavailable. Driver/arrival/container/provider evidence is retained in its artifact; cause is not yet proven. Complete current-head CI and this availability regression are the highest next priorities.
Role-result publication and cancelled owners
Fix a reproduced deadlock after unpublished native SettleRoles results. A failed retry returns the original journal error and retires only the joined read-only role proof. The next pass requires complete fresh evidence at the current head/registry; original acceptance and historical results remain unchanged. Physical-effect receipts remain retained without reexecution.
Add before-write and after-commit faults under same-claimant renewal and replacement after actual lease expiry, plus cancellation while the original native owner is paused. Exact duplicates join that owner and competing proofs remain refused until it finishes. Cases verify Closing/Completed, Stopped, withdrawal, exact-root and original request-result readback and joined ledgers.
Native Ubuntu publication job 111594331530 passed on the exact Rust source with no probes: 6 restart cases, 2 cancelled owners, 3 unchanged observer cases, 7 physical-action retention cases, 3 opaque-proof refusals, and warning-denied host Clippy on Rust 1.99. Original profiles, deadlines and assertions are unchanged.
Parent ab5eb0b full Rust workspace job succeeded with all 369 minion cases, provider/process smoke, local/replica LTX and lint gates. Complete source hashes and dated scope are in the progress record.
Remaining plan work
W4–W10 remain incomplete. Highest priorities are current-head CI and unexplained constrained-reader availability; busy primitive and external-owner maintenance, successive boot/lineage and remaining role faults including external Cron/Blob owners; recorded W9 process/provider, load and mixed-version campaigns; and exercised W10 rollout/rollback/recovery runbooks. In-process closures do not qualify OS crashes or external job supervision.
Main synchronization
This branch includes main at 80c4fd9. PR #37 is already merged; its reported conflict files have no conflict markers here. No unresolved index entries remain.