Repository navigation
cmux-tui: journal terminal host loss proof - #9821
lawrencecchen wants to merge 4 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Found 4 test failures on Blacksmith runners: Failures
|
|
Obsolete stacked draft; see the closing note above. |
![Fix with [code]smith](https://pr-comments-assets.blacksmith.sh/codesmith/fix-with-codesmith-light.png)
Scope
This is the detector-wiring successor slice stacked after #9819. It connects the existing terminal-host liveness proof to the durable
runtime.host_loss.provenboundary from #9818.When
terminal_host_record_livenessreportsDeadfor the exact hosted terminal incarnation, mux writesruntime.host_loss.provenbefore exit cleanup. The proof event updates runtime attachment and session lifecycle to interrupted through the existing atomic SQLite recorder. Ordinary exit cleanup then cannot overwrite an interrupted runtime withdetached.The proof uses only the terminal public id and terminal-host incarnation-derived opaque ids. It does not persist PID, socket, owner token, process-start nonce, command, environment, URLs, secrets, or live capabilities.
Out of scope: recover command, Pi launch, provider resume, auto-resume, fork launch, hibernation command, and hibernation policy UI.
Stack
Depends on #9726, #9806, #9813, #9815, #9816, #9818, and #9819. Keep this draft until all predecessors are reliable, gated, and landed.
Verification
Red commit:
96171bdaa5 test(tui): require host loss detector journalingfailed because the mux had no host-loss detector method.Green commit:
be205df9a0 feat(tui): journal terminal host loss proof.Passed locally:
CMUX_ALLOW_LOW_SPACE_BUILD=1 cargo fmtCMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core host_liveness_dead_journals_interruption_before_exit_detachCMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core hosted_terminal_CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core runtime_attachment_CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core runtime_host_lossCMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core session_effectCMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core session_runtime_and_policy_state_machines_rebuild_from_journalCMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core canonical_agent_state_preserves_sequential_roots_children_and_providersCMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core canonical_native_payload_rejects_secrets_live_capabilities_and_unknown_extensionsCMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core agent_projection_is_derived_from_pi_journal_and_reopen_preserves_continuitygit diff --checkOwner Closeout
Fixed: a real terminal-host loss could still flow through ordinary exit cleanup and lose the interrupted recovery state. Now the exact dead-host liveness proof journals interruption before cleanup and fences later detached state.
How: principled. The detector verifies the current surface identity and terminal lifecycle, then calls the proof recorder from #9818. No provider recovery or process launch occurs.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Adds a durable host-loss proof when the exact terminal-host incarnation is declared dead, recorded before exit so an interrupted runtime isn’t downgraded to detached. Uses only the terminal public id and incarnation-derived opaque ids; no sensitive process details are stored.
New Features
terminal_host_liveness_deadthat validates the current identity and idempotently recordsruntime.host_loss.proven; invoked in thesurfaceexit path beforesurface_exited.Bug Fixes
detachedwhen the attachment is alreadyinterrupted.Written for commit a06d160. Summary will update on new commits.