Skip to content

fix(runtime): report safe startup locator publication failures - #5551

Open
huangruiteng wants to merge 3 commits into
mainfrom
codex/runtime-startup-publication-diagnostic-20261004
Open

huangruiteng wants to merge 3 commits into
mainfrom
codex/runtime-startup-publication-diagnostic-20261004

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

When the managed Effect runtime cannot publish its startup locator, an unhandled async listen-callback rejection makes the launcher report only runtime_exited_before_ready. For a locator directory conflict or a live mutation lock, this loses the actionable filesystem/lock reason.

Catch that publication failure and reuse effectRuntimeErrorPayload's existing codes in the already-supported typed startup envelope. Emit a fixed bounded message without raw Node errors, paths, tokens or stack traces. Preserve the original locator/live lock, startup ownership and current retry rules. No new vocabulary, fallback runner, readiness claim or authority repair. The guide and S2/S12 checkpoint document the boundary.

Validation on macOS / Node 24.21.0 / Python 3.12.15:

  • Both real fault fixtures fail on main 99839aeb8fed5fae38a5d319391cd050672a6508 with the generic diagnostic, and pass with exact io_is_directory (Unix directory conflict) / mutation_lock_timeout codes. Windows directory replacement retains the shared io_permission_denied classification. They verify a single failed startup, safe stderr, start-lock cleanup and preservation of the original occupant.
  • Runtime integration/restart/compile-cache/request-scope suites: 94 passed.
  • Native error/IO/fairness tests: 9 passed. Control-plane typecheck and Chat bundle build passed.
  • Semantic advisory: no new supported vocabulary carriers; full drift suite: 116 passed.
  • Risk-selected premerge: 4 direct + 14 selected passed. Final committed diff check passed.
  • Isolated installed-wheel runtime journeys: 4 passed, including both publication failures, unexpected-exit recovery and stale-metadata replacement; all loaded LoopX modules come from the wheel. Metadata version remains 1.2.4; source revision is recorded separately.

This is a reproduced diagnostic repair, not attribution or waiver of an unrelated Linux unexpected-exit CI failure. Imports, bind errors and other exits without a typed envelope can still report runtime_exited_before_ready. Linux/Windows CI and maintainer review remain required. This PR is independent on main; deployment with other unmerged changes requires separate composed-candidate qualification. No production service or formal installation was changed.

Current validation head: a9994b1643aa1df19982563c82ae8be806eaef11. The first Windows run exposed a Unix-only test expectation (1 failed, 172 passed, 6 skipped). Correct the directory fixture to require Windows’ existing permission diagnostic; retain the exact envelope, privacy, readiness and occupant-preservation assertions. No runtime behavior changed in that correction. The 94 runtime tests, premerge 4 direct + 14 selected checks, and a freshly built installed-wheel 4-journey canary pass again on macOS. Earlier native/semantic/typecheck/build evidence covers unchanged runtime code. Exact-head run 37173578474 is now complete: Windows succeeded; Linux JUnit records 15,721 passed, 72 failed and 83 skipped. Both new locator-publication fixtures and the original retry-safe unexpected-exit recovery passed in this run. The prior Linux unexpected-exit failure remains unattributed; this passing sample is not causal proof. Backpressured preview-input cleanup still failed. Overall CI remains failed, and no failure is waived.

Composition checkpoint: local composition of this exact head with public #5546, #5543, #5548 and #5550 on main 99839aeb8fed5fae38a5d319391cd050672a6508 passes 682 targeted Python tests (one upstream settings forward-reference warning), 45 native Core tests, Core/dashboard typechecks, Chat build, Ruff, the repository-configured 19-file Mypy set, and premerge 5 direct + 19 selected checks. A freshly built isolated wheel passes 12 conversation/Agent/status journeys and 4 runtime fault/recovery journeys; native macOS service install/restart, frozen package identity, rejection of unqualified replacements and cleanup also pass with synthetic configuration. An additional expanded Mypy scan following imports fails on 4,436 errors across 533 files; it is not declared passed. These bounded checks do not qualify overall CI or a release.

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant