Make the Windows downloaded GUI name the cache cause behind exit 3 - #17
Merged
Merged
Conversation
added 4 commits
September 22, 2026 00:18
The packaged windowed client has no visible stderr: the suite-preparation, preflight, and batch-gate returns printed only there, so a first-run preparation failure surfaced as nothing but "Run failed (exit code 3)", and the worker's done handler overwrote even a reported cause with that bare exit code. Emit run_error events with the full causal message at every gate the GUI can reach (sweep planner and suite preparation, compatibility/runtime-integrity preflight, v7 clip preparation and argument gates, batch identity/budget checks), retain the last cause in the app, and compose "Run failed (exit code N): <cause>" into both the status line and the event log when a run ends failed. Adds causal-event regressions for the three exit-3 sites and cause retention through the GUI done handler.
An extraction root created by an administrator-privileged or foreign-account run is invisible to os.path.exists and undeletable by the normal user, so every normal run re-downloaded, re-verified, and then lost the swap with WinError 5 behind a generic 'suite unavailable' and exit 3. Classify the unreadable/foreign-ACL cache before burning a re-extraction, report the target path plus the actionable delete instruction when the swap itself is refused, and stop swallowing the swap failure behind ignore_errors.
Protocol 7.1 and the minimum-client gate are unchanged; the bump only makes the cache-cause fix distinguishable in submission metadata and download provenance.
Stamp the rebuilt Windows GUI digest, move rc.2 to the superseded packaged section with its published digests, keep the rc.1 plain CLI builds reachable under their own tag, and update the README current-release statements. macOS/Linux primary digests are unchanged: byte-identical republish.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What broke
The published 1.3.0-rc.2 Windows GUI showed
Run failed (exit code 3)on the reporter's machine with no cause. Two independent defects combined:--windowedPyInstaller build — and the GUI done-handler replaced any reported cause with the bare exit code..suite-packcreated by an administrator-privileged (or foreign-account) run carries a DACL with no normal-user ACE.os.path.existsthen reports it missing, so every normal run re-downloads and re-extracts the whole pack, and the final swap is refused (WinError 5) behindshutil.rmtree(..., ignore_errors=True)— a guaranteed exit 3 that no cleanup can end.Reproduction (native, published rc.2 binaries)
Replica of the reporter's default cache (identical bytes, same
SYSTEM/Administrators/OWNER RIGHTSDACL) driven under a normal (Limited) token:The replica pack itself is hash-valid; the same cache with open ACLs completes end-to-end (2 encodes, exit 0) — isolating the ACL state, not the data.
Changes
client/main.py:run_errorevents with the full causal message at every gate the GUI can reach; last cause retained; status/event log now readRun failed (exit code N): <cause>.client/suite.py:_suite_pack_target_access_error()classifies an unreadable/foreign-ACL cache before burning the multi-gigabyte re-extraction (names the folder and the recovery), and the staging swap failure reports the target path instead of dying silently.1.3.0-rc.3/client/0.3.2; protocol 7.1 andPROTOCOL_MINIMUM_CLIENT_VERSIONunchanged.Verification
test_runtime_lockerrors (missing locallibsvtav1), no new failures.--submitsweep produced durable campaign evidence + two server receipts (see lane handoff).