Skip to content

spark d0 front door: supply the failed-connect reading instead of assuming a SIGTERM vacated the port - #12632

Merged
gunbai-bot[bot] merged 3 commits into
mainfrom
session/crisp-lynx-364-vacated
Sep 29, 2026
Merged

gunbai-bot[bot] merged 3 commits into
mainfrom
session/crisp-lynx-364-vacated

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Red: test.claim.spark.pair_serving_d0_front_door_real_execution.a_vacated_port_reads_as_no_response_by_real_execution failed with WetTerminalVerdictNotExpected (expected passed, observed failed) on srv4-15, in merge-group run 36575660396 for #12420. It dequeues unrelated PRs whose floor lands on that runner.

Chain (DESIGN §6b). d0fd_vacated_port started a forked listener, sent it SIGTERM, and returned the port as soon as os.kill returned. Signal delivery is asynchronous, so the premise "this port is vacant" was assumed, never observed. The earliest unjustified boundary is that fixture, not the harness classification or front_door_as_incumbent. Two claims consumed the premise: the vacated-port claim and a_failed_connect_fences_…_by_real_execution. A third consumed it in the procfs tail of a_listener_behind_a_failed_connect_…. The failed-run log carries only the verdict, so the race is the one premise that was never observed, not a proven cause.

Repair: SUPPLY, following #12478 and #12614 (DESIGN §3, a witness discriminates at one interface).

  • a_vacated_port_reads_as_no_response_by_real_execution is replaced by a_front_door_with_no_status_reads_as_an_incumbent_that_did_not_answer. It supplies FrontDoorNoStatus to front_door_as_incumbent under a quiet head and under an unread head. It is pure, so its rows leave floor_route_gap and local_repo_wet_terminal.
  • a_failed_connect_fences_under_an_active_head_unit_and_suspends_only_under_a_quiet_one_by_real_execution now takes a supplied IncumbentDidNotAnswer. Its subject is the transaction's fence/suspend decision and the real log; both still execute for real.
  • Pairing obligation. The real failed-connect route stays wet, keyed to its own subject: an address where nothing accepts, not a vacated port. a_listener_behind_a_failed_connect_is_read_on_the_host_and_fences_by_real_execution already asserted curl 7 at 127.0.0.2:P. It now also asserts that observe_front_door reads FrontDoorNoStatus there. That makes it the inhabitance claim for the supplied reading.
  • The same claim's procfs "no listener" read keeps its real execution. It now runs over a port vacated by construction: the fixture listens and then close()s the socket in its own process before printing the port. A close is synchronous; a signal is not.

Evidence (local claim_batch):

  • --wet: all four affected claims PASS.
    • the supplied claim
    • a_failed_connect_fences…
    • a_listener_behind_a_failed_connect…
    • an_error_status_is_an_answer…
  • Hermetic: the supplied claim PASSES. The two claims that write the temp-dir store route-gap on Dir, as they are rostered to.
  • Discriminating control: I planted FrontDoorNoStatus → IncumbentRouteUnread in pair_serving_d0 front_door_as_incumbent, and the supplied claim went FAIL. The mutation was reverted.

The superseded first commit, a fixture that observed vacancy after SIGTERM, is replaced by the supplying repair, per the manager's ruling.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 3 commits September 29, 2026 16:38
…ent SIGTERM

The kill fixture returned right after os.kill, so the vacated-port claim read a listener
that could still answer (srv4-15, merge-group run 36575660396, WetTerminalVerdictNotExpected).
The fixture now waits (bounded) for the pid to be gone and the port to refuse a connect,
exiting nonzero otherwise, so d0fd_vacated_port yields no port instead of an assumed one.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… by construction for the one procfs read

Replaces the observing kill fixture (previous commit) per the manager's SUPPLY ruling: the
real curl-7 route already executes, keyed to its own subject, in the 127.0.0.2 claim, which now
also asserts observe_front_door reads FrontDoorNoStatus there. The vacated-port claim becomes a
supplied reading of front_door_as_incumbent; the fence/suspend transaction claim takes a supplied
IncumbentDidNotAnswer. The procfs no-listener read keeps its real execution over a port closed
in-process (close() is synchronous), not one a SIGTERM was sent to.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title spark d0 front door: observe the vacated port instead of assuming it from a sent SIGTERM spark d0 front door: supply the failed-connect reading instead of assuming a SIGTERM vacated the port Sep 29, 2026
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit e1acab2 Sep 29, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/crisp-lynx-364-vacated branch September 29, 2026 21:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants