Skip to content

Pin the fail-open branch of the harness-live rebind check - #727

Open
rensei-ai[bot] wants to merge 2 commits into
mainfrom
agent/d4888ae0-ed8d-4ad9-a971-e331534d8ecc
Open

rensei-ai[bot] wants to merge 2 commits into
mainfrom
agent/d4888ae0-ed8d-4ad9-a971-e331534d8ecc

Conversation

@rensei-ai

@rensei-ai rensei-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Test-only change: pins the rebind gate's fail-open branch for an unreadable registry record.

Scope: one regression test in daemon/session_shim_rebind_test.go. No production behavior changes.

What the test proves:

  • The seam reports live=true alongside the registry read error (never fail-closed).
  • The caller proceeds past the gate toward the adoption dial instead of refusing harness-not-live; the adoption pass reports what it found for the corrupted identity, the in-flight claim is released, and no durable adoption runs.

Load-bearing proof (isolated snapshot, production restored byte-identical afterwards):

  • RED: with the branch inverted to return live=false on read error, the new test fails against a compiling runtime.
  • GREEN: exact restore passes, plus all neighboring rebind tests.

Rework verification (2026-10-09, branch head 239d00c, production files untouched):

  • go test -race -run 'TestRebindTreatsAnUnreadableRegistryRecordAsLive' -count=1 -v ./daemon/ → PASS (1.665s)
  • go test -race -run 'TestRebind' -count=1 ./daemon/ → ok (2.205s)
  • go test -race -run 'TestAmbiguousLaunchCommit' -count=1 ./daemon/ → ok (14.955s) — the CI-red gate test passes locally
  • Mutation re-proof: fail-closed inversion → FAIL RED as designed (want live=true, session_shim_rebind_test.go:339); exact restore → GREEN
  • go build ./daemon/ ./sessionshim/ → clean
  • go vet ./daemon/ → clean
  • golangci-lint run daemon/ → 0 issues
  • gofmt -l on changed files → clean
  • guard-b self-test 59/59 OK, diff-gate self-test 5/5 OK, guard-b scan clean

Blocking finding B1 (red CI test job on the prior head):

  • The failed subtest was TestAmbiguousLaunchCommitDoesNotStrandTheHost/explicit_outcome-unknown_sentinel with ptyhost: pty start: fork/exec /bin/sh: operation not permitted and runner nproc at its cap (nproc_cur=63136 nproc_max=63136).
  • Local rerun of that exact test passes, supporting environmental runner exhaustion rather than a PR-caused failure. A fresh push retriggered the CI test job; its result is pending on the new head.
  • No blocking findings on the test content itself.

View with [code]smith View with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The rebind gate treats an unreadable registry record as live, carrying
the read error alongside, so repair of a lineage the shim can still
serve is never refused over a transient read failure. This pins that
choice at both levels the seam exposes: the predicate reports
live=true with the read error, and the caller proceeds past the gate
toward the adoption dial instead of refusing harness-not-live.
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Donmai native drift check

Commit: 239d00cfba4e091b2e60b69cc108bc0d2bf91561
Policy: no-severity-high

Policy passed.
Native observations: 0 (patterns: 0, conventions: 0, decisions: 0).

This is regex-based diff analysis, not a learned architectural baseline or a semantic review.
Analyzer: Donmai 0.72.53. A passed policy does not mean there are no architectural problems.

…tion

The required test job on this head fails only in TestAmbiguousLaunchCommitDoesNotStrandTheHost with a PTY spawn refused under runner process-count exhaustion. A local race run of that exact test passes, so the finding is environmental rather than caused by the test-only change. No production code touched.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants