feat: execute durable client commands through supervisor
This commit is contained in:
@@ -1765,6 +1765,24 @@ rows in order. Advertise capacity and accept new dispatch only in `active`.
|
||||
Cancellation of one session context must join all its readers/writers before a
|
||||
new session can use their queues.
|
||||
|
||||
The current implementation checkpoint is intentionally split at this seam:
|
||||
`internal/client/agent.RunOnce` owns the reconnect/session reader and remains
|
||||
the sole live-session writer; `internal/client/spool` owns the SQLite source of
|
||||
truth; and `internal/client/agent.Executor` owns process lifetime independently
|
||||
of the WebSocket context. A bounded event-notification channel wakes the active
|
||||
writer to assign and send newly appended events, while reconnect replay uses
|
||||
the same spool rows and a per-session sent cursor. Every accepted dispatch is
|
||||
stored with its deterministic execution specification (and, for scripts, its
|
||||
descriptor reservation) before acknowledgement.
|
||||
|
||||
Add a schema launch barrier to every implementation of the executor. Persist
|
||||
`prepared` before entering the supervisor, persist `authorized` before the OS
|
||||
release boundary, and clear it only when a terminal lifecycle transition is
|
||||
committed. Startup recovery must convert any non-terminal `authorized` row to
|
||||
one `interrupted` event before registering a new network session. This is the
|
||||
at-most-once fence for a crash between process release and the first `running`
|
||||
event; it is not a substitute for verifying a native process creation identity.
|
||||
|
||||
### 7.2 Output capture and offline caps
|
||||
|
||||
Create non-blocking readers for stdout and stderr immediately after process
|
||||
@@ -1917,6 +1935,15 @@ Implement Windows code in platform-specific files so non-Windows builds never
|
||||
import Windows APIs. Keep launch phases identical across platforms:
|
||||
`accepted -> launch_prepared -> launch_authorized -> running`, with no shortcut.
|
||||
|
||||
The first native adapter is now required to expose this contract through
|
||||
`internal/client/supervisor.Supervisor`: the non-Windows adapter is test-only,
|
||||
while the Windows implementation must perform token selection and Job setup
|
||||
inside the same `Start` call. It may return only after the child has been
|
||||
assigned to its kill-on-close Job and released; all token/session attempts must
|
||||
be represented in the returned immutable identity. A failed start clears the
|
||||
pre-launch barrier and produces one rejected lifecycle event; an uncertain
|
||||
authorized row is never retried as a fresh process.
|
||||
|
||||
Implement one exhaustive token selector; do not scatter token fallback across
|
||||
launch code:
|
||||
|
||||
|
||||
+28
-8
@@ -17,6 +17,8 @@ scripts/test-unit --package ./internal/domain --run UUIDv7 --race
|
||||
|
||||
The integration harness provides the Phase 0 `sample` suite, the incremental
|
||||
Phase 2 `store` suite, and the incremental Phase 3 `server-session` suite.
|
||||
The resumable E2E harness adds `smoke`, `script`, `recovery`, and `all`
|
||||
scenarios. Each run writes its manifest and run ID before starting work.
|
||||
The storage suite uses a real temporary SQLite database in WAL mode and a real
|
||||
segment/audit filesystem. The session suite uses a real HTTP/WebSocket listener,
|
||||
binary protobuf frames, SQLite fencing, and the race detector; neither mocks its
|
||||
@@ -44,8 +46,25 @@ scripts/test-env logs --run-id session-smoke
|
||||
scripts/test-env collect --run-id session-smoke
|
||||
scripts/test-env reset --run-id session-smoke
|
||||
scripts/test-env purge --run-id session-smoke
|
||||
|
||||
scripts/test-e2e --scenario smoke --run-id e2e-smoke
|
||||
scripts/test-env status --run-id e2e-smoke
|
||||
scripts/test-env recover --run-id e2e-smoke
|
||||
scripts/test-e2e --scenario smoke --run-id e2e-smoke --resume
|
||||
scripts/test-env reset --run-id e2e-smoke
|
||||
scripts/test-env purge --run-id e2e-smoke
|
||||
```
|
||||
|
||||
The client runtime unit lane also exercises a real child process through the
|
||||
portable supervisor adapter. `internal/client/agent/executor_test.go` verifies
|
||||
that command text is accepted once, output is journaled, lifecycle/terminal
|
||||
events are durable, and a script cannot launch before its contiguous upload is
|
||||
committed. The Windows build uses the same executor contract with the
|
||||
platform-native adapter: a verified token is selected, the child is created
|
||||
suspended, assigned to a kill-on-close Job, and only then released. The
|
||||
durable `launch_phase` barrier is recovered as `interrupted` after a daemon
|
||||
restart, so an uncertain release is never redispatched.
|
||||
|
||||
Suite output is capped at 1 MiB and stored as `artifacts/suite.log`. A failed
|
||||
run remains inspectable and can be moved back to `ready` with `recover`, then
|
||||
resumed with the same run ID and deterministic shuffle seed. Test-run cleanup
|
||||
@@ -60,11 +79,12 @@ cleanup.
|
||||
|
||||
`test/coverage.toml` is the incremental requirement-to-test inventory. The
|
||||
`make verify` lint stage checks unique stable IDs and verifies every implemented
|
||||
test reference against source. A resettable Windows smoke VM is now available;
|
||||
its exact headless VirtualBox/Guest Control runbook is in section 2.6.1 of
|
||||
`docs/implementation-plan.v1.md`. Native Windows integration/E2E entries may
|
||||
run there once the Windows harness acquires the exclusive lease and performs
|
||||
the documented snapshot/health checks. The VM is only the minimum smoke lane,
|
||||
so deferred native multi-session/ambiguous-session, Server Core, and
|
||||
older-build entries remain explicitly blocked until their own fixtures exist.
|
||||
Wine or a protocol stub is not treated as equivalent coverage.
|
||||
test reference against source. A resettable Windows smoke VM is now available.
|
||||
The exact headless VirtualBox/Guest Control adapter is
|
||||
`scripts/windows/test-host.ps1`; it takes the VM name, baseline snapshot, and
|
||||
guest credentials only from host environment variables, acquires an exclusive
|
||||
lease, and never writes secrets to the repository. Use `Prepare`, `Run`,
|
||||
`Collect`, `Stop`, and `Reset` in that order for a native run. The VM is the
|
||||
minimum smoke lane, so deferred native multi-session/ambiguous-session, Server
|
||||
Core, and older-build entries remain explicitly blocked until their own
|
||||
fixtures exist. Wine or a protocol stub is not treated as equivalent coverage.
|
||||
|
||||
Reference in New Issue
Block a user