Fix all 12 verified defects from the second systematic bug scan - #47
Merged
Merged
Conversation
Medium: - Bound the per-poll decision history: keep the most recent OBSERVATION_RETENTION (20) check-observed entries per task, pruned after each record; decisions and delivery records are never pruned, and a (task_id, kind, at) index keeps the excluded-kind queries on-index (runner, activity) - Apply activity-write isolation to the blocked/retry paths too: a failing append no longer swallows the BLOCKED notification/state or double-counts consecutive failures via the daemon (runner) - Register the inbox sink's SQLite connection with the teardown registry, and register every resource as it is created so a mid-wiring failure still unwinds what already opened; the unwind also runs when lease entry itself fails (cli) - Record before egress: an event is logged (with its occurrence identity) before the optional summary request, so nothing reaches a provider that the log cannot reconstruct (adapter-seam discipline 3); a run superseded while summarizing suppresses delivery, not the record (runner) - Stop re-forwarding the terminal's group-delivered SIGINT from the npm launcher: the child already received it, and the second interrupt was aborting the graceful teardown (bin/nanodot.cjs) Low: - Teardown.run catches BaseException per step so a mid-unwind interrupt costs one step, never the remaining stores (teardown) - Probe Python in the caller environment (not isolated mode): an interpreter broken by a stray PYTHONHOME now fails probing with a clean nanodot message instead of a raw fatal on every command (bin/nanodot.cjs) - Package smoke allowlist permits the LICENSE file npm always includes (npm-tests) - Discipline 3 wording scoped to system-derived fields, with the --intent sentence as the documented exception (adapter-seam.md) - README names tar as a setup requirement alongside curl; decision-log.md documents the retention policy and replay identity (docs) 552 pytest tests pass (6 new); npm launcher tests 12/12 (2 new, one rebased onto #41's fixture); package smoke and the e2e demo pass.
The bootstrap smoke intercepted the launcher's Python probes by their -I flag; the probe now runs in the caller environment (#45 fix 9), so hide the probe by its sys.version_info gate instead.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #45 — all 12 verified defects from the second systematic bug scan (decision log #36, teardown registry #37/#39, npm packaging #30/#41, DSH admission discipline).
Branch is rebased on current
main(63d2f13, includes #41/#43).Medium fixes
core/runner.py,core/activity.py) — each task keeps its most recentOBSERVATION_RETENTION(20)check-observedentries, pruned after each record; decisions and delivery records are never pruned. A(task_id, kind, at)index keeps the excluded-kind queries (watch list,activity) on-index. Replaces the unbounded ~1.2MB/day/task growth; the design doc now records the retention policy.core/runner.py) —_blockand_schedule_retrynow use the isolation-guarded record: a failing append no longer swallows the BLOCKED notification/state, and no longer double-countsconsecutive_failuresthrough the daemon.cli.py) —NativeNotifier.closejoins the teardown registry (inbox-sink, reverse order preserved); registration happens per-resource as it is created, so a mid-wiring failure (e.g. provider setup raising) unwinds everything already opened; an outer idempotent unwind covers lease-entry failures.core/runner.py) — each event is recorded (carrying theoccurrenceidentity the sink dedups on) before the optional summary request, and the supersession check precedes recording. Egress can no longer outrun the log (discipline 3); a run superseded during summarizing suppresses delivery but keeps the record of what the provider saw.bin/nanodot.cjs) — the launcher swallows its own group-delivered SIGINT (the CLI already received it) instead of sending a second one that aborted the graceful teardown; SIGTERM forwarding is unchanged.Low fixes
teardown.run()catchesBaseExceptionper step (a mid-unwind Ctrl-C costs one step, never the remaining stores); Python is probed in the caller environment instead of-Iisolated mode (strayPYTHONHOMEnow fails probing with a clean message); the package-smoke allowlist permits the LICENSE npm always includes; discipline 3 is scoped to system-derived fields with--intentas the documented exception; README namestaras a setup requirement.Verification
-Iflag to the probe's code string, rebased onto npm launcher: pin uv download integrity (no unpinned remote shell) #41/Verify uv download integrity; stop executing a downloaded script (#41) #43's fixture.first_pr_watche2e demo pass.