Conversation
|
Cross-vendor review completed through Advisory dispositions:
Delivery remains blocked by CI runner availability, not by a known code defect. All four CI jobs request Blacksmith labels and have no assigned runner; the repository runner endpoint reports zero runners. Fork main already has a CI run queued since 2026-09-22 08:01Z. The GitHub-hosted Nightly validation job passed. No workflow-runner changes are bundled into this lifecycle fix. |
Thread transfer impact
This comment will update automatically after the next completed run. |
9bd270e to
7088ec3
Compare
What Changed
Pin the V2 runtime ownership fix into Fork Nightly. A second server using the same state directory now fails before constructing runtime services, so it cannot cancel work owned by the running server. The lock stays held through shutdown cleanup and the OS releases it on process exit.
Fork
maincarries release configuration rather than V2 source. This PR selects one source commit after the existing 14 patches. No merge or installation is performed by this PR preparation.Why
The cancellations at 2026-09-22 15:49:33Z and 23:42:19Z came from
command:runtime-reconcile:startup, not a user cancel or WebSocket disconnect. Recovery marked persisted runs cancelled and sessions stopped without contacting the process that owned them. The second batch happened while the standalone server and its Claude child were still running. Historical process output identifies PID 26669 as the desktop's Electron executable parenting provider CLIs, consistent with its embedded Node server. Its full script argument was truncated in the capture.The fix holds an exclusive transaction on a separate SQLite ownership file for the server lifetime. It does not lock the conversation database, use expiring heartbeats, or signal another process. Codex, Claude, Cursor, Grok, OpenCode and the remaining V2 adapters all use the guarded server entry point. Web, desktop and mobile share the server behavior; wire contracts are unchanged.
Late completion remains unable to revive a cancelled run because finalization requires a current active attempt. Existing false cancellations are not repaired automatically, which avoids reviving deliberate cancellations or duplicating a relaunched lane. Both standalone and desktop-bundled servers must be upgraded because old builds do not acquire this lock. The sibling 429 fix can be sequenced independently: this patch does not edit provider terminal-status handling.
Verification
running, receivedcancelled.vp test run apps/server/src/serverRuntimeLock.test.ts apps/server/src/serverRuntimeOwnership.test.ts apps/server/src/orchestration-v2/ProviderRuntimeOwnership.test.ts apps/server/src/orchestration-v2/ProviderRuntimeRecoveryService.test.ts apps/server/src/serverRuntimeStartup.test.ts: 26 passed.vp exec tsc --noEmit -p apps/server/tsconfig.json: passed. Focusedvp lintand formatting: passed.060756de5adcda82fedace42d8c47b449bc1097b; the resulting source matches the tested tree apart from generated release metadata.node --test .github/scripts/downstream-nightly.test.mjs: 22 passed. V2 manifest parses successfully.0eca7a70b426321775e14fd82dbf77c1a10e0694throughdelegate_task: no blocking findings. It independently passed the seven new tests, server typecheck, and focused lint.Checklist
Implementation: GPT-6 Astra in Codex through T3 Code. Independent review through
delegate_task: Claude Fable 5.1, high effort.Rebased on 2026-09-29 onto current main (now includes #89, #90 and the ACP settle replacement); the only conflict was the patch list, resolved by keeping all main entries and appending this pin last.