Skip to content

cmux-tui: journal terminal host loss proof - #9821

Closed
lawrencecchen wants to merge 4 commits into
task-journal-runtime-attachment-sourcefrom
task-journal-host-loss-detector
Closed

lawrencecchen wants to merge 4 commits into
task-journal-runtime-attachment-sourcefrom
task-journal-host-loss-detector

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor

Scope

This is the detector-wiring successor slice stacked after #9819. It connects the existing terminal-host liveness proof to the durable runtime.host_loss.proven boundary from #9818.

When terminal_host_record_liveness reports Dead for the exact hosted terminal incarnation, mux writes runtime.host_loss.proven before exit cleanup. The proof event updates runtime attachment and session lifecycle to interrupted through the existing atomic SQLite recorder. Ordinary exit cleanup then cannot overwrite an interrupted runtime with detached.

The proof uses only the terminal public id and terminal-host incarnation-derived opaque ids. It does not persist PID, socket, owner token, process-start nonce, command, environment, URLs, secrets, or live capabilities.

Out of scope: recover command, Pi launch, provider resume, auto-resume, fork launch, hibernation command, and hibernation policy UI.

Stack

Depends on #9726, #9806, #9813, #9815, #9816, #9818, and #9819. Keep this draft until all predecessors are reliable, gated, and landed.

Verification

Red commit: 96171bdaa5 test(tui): require host loss detector journaling failed because the mux had no host-loss detector method.

Green commit: be205df9a0 feat(tui): journal terminal host loss proof.

Passed locally:

  • CMUX_ALLOW_LOW_SPACE_BUILD=1 cargo fmt
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core host_liveness_dead_journals_interruption_before_exit_detach
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core hosted_terminal_
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core runtime_attachment_
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core runtime_host_loss
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core session_effect
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core session_runtime_and_policy_state_machines_rebuild_from_journal
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core canonical_agent_state_preserves_sequential_roots_children_and_providers
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core canonical_native_payload_rejects_secrets_live_capabilities_and_unknown_extensions
  • CMUX_ALLOW_LOW_SPACE_BUILD=1 RUSTC=$HOME/.rustup/toolchains/1.94.0-aarch64-apple-darwin/bin/rustc cargo test -p cmux-tui-core agent_projection_is_derived_from_pi_journal_and_reopen_preserves_continuity
  • git diff --check

Owner Closeout

Fixed: a real terminal-host loss could still flow through ordinary exit cleanup and lose the interrupted recovery state. Now the exact dead-host liveness proof journals interruption before cleanup and fences later detached state.

How: principled. The detector verifies the current surface identity and terminal lifecycle, then calls the proof recorder from #9818. No provider recovery or process launch occurs.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Adds a durable host-loss proof when the exact terminal-host incarnation is declared dead, recorded before exit so an interrupted runtime isn’t downgraded to detached. Uses only the terminal public id and incarnation-derived opaque ids; no sensitive process details are stored.

  • New Features

    • Add terminal_host_liveness_dead that validates the current identity and idempotently records runtime.host_loss.proven; invoked in the surface exit path before surface_exited.
  • Bug Fixes

    • Short-circuit runtime attachment updates to prevent writing detached when the attachment is already interrupted.

Written for commit a06d160. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: de8c089a-082b-4048-abbd-49f7090dcde7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@blacksmith-sh

blacksmith-sh Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

Found 4 test failures on Blacksmith runners:

Failures

Test View Logs
generated protocol coverage matches the canonical v11 IR View Logs
github.com/manaflow-ai/cmux/cmux-tui/bindings/go/raw/
TestGeneratedInventoryHasTypedMethodForEveryCommand
View Logs
test_orchestrator.PythonDevOrchestratorTests/
test_fake_server_emits_canonical_terminal_snapshot
View Logs
test_protocol.GeneratedProtocolTests/test_protocol_inventory_is_exhaustive View Logs

Fix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Closing this obsolete draft because its dependency stack is dead (#9806 and #9813 are closed, and this chain depends on those predecessors). Any remaining intent should be reintroduced in a fresh PR from current main.

@lawrencecchen

Copy link
Copy Markdown
Contributor Author

Obsolete stacked draft; see the closing note above.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant