Conversation
c0ef0b7 to
96f69e8
Compare
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Targeted tests and Ruff passed, but these executed degraded paths fail. Live PR head matched Replay: fresh clone and checkout the SHA, then create and execute the two test files exactly as included in the pipeline review result. |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC Live head remains
Targeted upstream healthcheck tests: 5 passed. Ruff: passed. The two degraded-path tests: 2 failed. Replay rm -rf /tmp/pr2208 && git clone https://github.com/eumemic/aios.git /tmp/pr2208
cd /tmp/pr2208 && git checkout 07bd37748d28aafd6723660bc3d96c32fde8f807
cat > packages/aios-connector-http/tests/test_pr2208_degraded_review.py <<'PY'
import asyncio
from pathlib import Path
from unittest.mock import AsyncMock, MagicMock, patch
import pytest
from aios_connector_http.runner import HttpConnector
class Probe(HttpConnector): connector = "probe"
@pytest.mark.asyncio
async def test_unknown_discovery_does_not_publish_health(tmp_path: Path):
c = Probe(base_url="http://example.test", token="token")
c.HEARTBEAT_INTERVAL = .01
path = tmp_path / "alive"
task = asyncio.create_task(c._heartbeat_loop(path))
try:
await asyncio.sleep(.03)
assert not path.exists()
finally:
task.cancel()
with pytest.raises(asyncio.CancelledError): await task
@pytest.mark.asyncio
async def test_setup_failure_preserves_preexisting_heartbeat(tmp_path: Path):
path = tmp_path / "operator-owned"
path.write_text("operator data")
class Broken(Probe):
async def load_answered(self): return {}
async def _publish_tools_schema(self): return None
async def setup(self, tg): raise RuntimeError("injected setup failure")
cm = MagicMock(); cm.__aenter__ = AsyncMock(return_value=MagicMock()); cm.__aexit__ = AsyncMock(return_value=False)
with patch("aios_connector_http.runner.Client", return_value=cm), patch("aios_connector_http.runner.resolve_heartbeat_path", return_value=path), pytest.raises(ExceptionGroup):
await Broken(base_url="http://example.test", token="token").run()
assert path.exists() and path.read_text() == "operator data"
PY
uv run --package aios-connector-http pytest packages/aios-connector-http/tests/test_pr2208_degraded_review.py -q
uv run --package aios-connector-http pytest packages/aios-connector-http/tests/test_healthcheck.py -q
uv run --package aios-connector-http ruff check packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py packages/aios-connector-http/tests/test_healthcheck.py |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Replay commands are included in the review result artifact; both use fresh checkout SHA |
Code reviewVerdict: NEEDS-CHANGES
The previous alarm-conjunction and unknown-discovery properties now pass targeted tests. Existing pre-existing-file coverage passes, but does not exercise replacement during the claim window. Live PR head matched the reviewed SHA. Targeted tests (14) and Ruff passed. Replay: rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 7824c387f451faac2c93fd4082b022562259ec37
cat > packages/aios-connector-http/tests/test_review_heartbeat_race.py <<'PY'
from __future__ import annotations
import asyncio
from pathlib import Path
import pytest
from aios_connector_http.runner import HttpConnector
class Connector(HttpConnector):
connector = "probe"
@pytest.mark.asyncio
async def test_operator_replacement_during_claim_is_not_owned_or_removed(tmp_path: Path, monkeypatch: pytest.MonkeyPatch):
connector = Connector(base_url="http://example.test", token="token")
connector._discovery_cursor = 0
connector.HEARTBEAT_INTERVAL = 0.01
heartbeat = tmp_path / "alive"
original_touch = Path.touch
first = True
def racing_touch(self: Path, *args, **kwargs):
nonlocal first
result = original_touch(self, *args, **kwargs)
if self == heartbeat and first:
first = False
self.unlink()
self.write_text("operator replacement")
return result
monkeypatch.setattr(Path, "touch", racing_touch)
task = asyncio.create_task(connector._heartbeat_loop(heartbeat))
try:
await asyncio.sleep(0.03)
finally:
task.cancel()
with pytest.raises(asyncio.CancelledError):
await task
assert heartbeat.read_text() == "operator replacement"
assert connector._heartbeat_owned is False
PY
uv run pytest -q packages/aios-connector-http/tests/test_review_heartbeat_race.py |
Code reviewVerdict: NEEDS-CHANGES
Executed: reviewed/live head equality; focused tests (16 passed); full connector-http tests (157 passed); Ruff on changed Python; unhealthy+healthy sibling-container degraded path; heartbeat replacement-inode guard mutation (negative test failed as required); stale/missing heartbeat tests; stopped/absent-container detector test. No production mutations were performed. Replay for CR-1 (fresh clone): git clone https://github.com/eumemic/aios.git /tmp/aios-2208 && cd /tmp/aios-2208
git fetch origin pull/2208/head && git checkout f5e29625d23024868c18893f0d6c79b7fa0d180a
uv run python - <<'PY'
import asyncio
from unittest.mock import patch
from aios.harness.connector_liveness import DockerConnectorHealthReader
class C:
def __init__(self, d): self.d=d
async def show(self): return self.d
class Containers:
async def list(self, all):
return [
C({'Name':'/aios-whatsapp','Config':{'Labels':{'com.docker.compose.service':'whatsapp'}},'State':{'Status':'running','Health':{'Status':'unhealthy'}}}),
C({'Name':'/old-whatsapp','Config':{'Labels':{'com.docker.compose.service':'whatsapp'}},'State':{'Status':'running','Health':{'Status':'healthy'}}}),
]
class D:
def __init__(self): self.containers=Containers()
async def close(self): pass
async def main():
with patch('aios.harness.connector_liveness.aiodocker.Docker', D):
got=await DockerConnectorHealthReader().read()
print(got)
assert not got['whatsapp'].healthy, got
asyncio.run(main())
PYCurrent output is |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
The earlier conjunction, unknown-discovery, stale-heartbeat recovery, and safe-claim properties pass targeted tests on live head Replay rm -rf /tmp/pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/pr2208
cd /tmp/pr2208 && git checkout -q 939715640823fd7f6cfbbbd3d4d01c47083bf359
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'; s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'; assert old in s; open(p,'w').write(s.replace(old,'if True:',1))
PY
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode
cp /tmp/runner.py packages/aios-connector-http/aios_connector_http/runner.py
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'; s=open(p).read(); a=s.index('class DockerConnectorHealthReader:'); b=s.index('\n\nclass ConnectorLivenessDetector:',a); open(p,'w').write(s[:a]+'class DockerConnectorHealthReader:\n async def read(self) -> dict[str, TransportHealth]:\n return {}\n'+s[b:])
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Previously asserted properties were rechecked on live head Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 37ad71f49cf818e922d6c051c9c2cca9240478dd
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read()
old=''' rows = await pool.fetch(
"""'''
new=''' return []
rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,new,1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed (this mutation must instead make the suite fail).
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
# Destructive-guard negative control (expected RED):
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read()
old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode
cp /tmp/runner.py packages/aios-connector-http/aios_connector_http/runner.py |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties were rechecked on live head Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 37ad71f49cf818e922d6c051c9c2cca9240478dd
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py tests/unit/test_ci_pytest_diagnostics.py tests/unit/test_docker_e2e_ci_resources.py
uv run ruff check src/aios/harness/connector_liveness.py packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py tests/unit/harness/test_connector_liveness.py packages/aios-connector-http/tests/test_healthcheck.py
git diff --check 560eabda9967f0977f8481002a4260a9bafb2640..HEAD
cp src/aios/harness/connector_liveness.py /tmp/pr2208_connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read()
old=''' rows = await pool.fetch(
"""'''
new=''' return []
rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,new,1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; this mutation must make the suite fail.
cp /tmp/pr2208_connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/pr2208_runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read()
old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode
cp /tmp/pr2208_runner.py packages/aios-connector-http/aios_connector_http/runner.py |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Rechecked standing properties: unknown discovery withholding, stale-heartbeat recovery, safe descriptor-based claim, replacement-inode cleanup refusal, unhealthy-replica aggregation, and stopped-container Docker observation all pass targeted execution. The cleanup identity-guard bypass and whole Docker-reader bypass both make their negative tests fail as required. Targeted suites: 15 passed; Ruff and Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 37ad71f49cf818e922d6c051c9c2cca9240478dd
test "$(git rev-parse HEAD)" = 37ad71f49cf818e922d6c051c9c2cca9240478dd
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read()
old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; this mutation must make the accepted suite fail.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
# Destructive cleanup guard negative control (expected RED):
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode
cp /tmp/runner.py packages/aios-connector-http/aios_connector_http/runner.py
# Docker reader negative control (expected RED):
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'; s=open(p).read()
a=s.index('class DockerConnectorHealthReader:'); b=s.index('\n\nclass ConnectorLivenessDetector:',a)
open(p,'w').write(s[:a]+'class DockerConnectorHealthReader:\n async def read(self) -> dict[str, TransportHealth]:\n return {}\n'+s[b:])
PY
! uv run pytest -q tests/unit/harness/test_connector_liveness.py |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties were rechecked from the unchanged diff/head: unknown-discovery withholding, stale-heartbeat recovery, safe descriptor claim, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container observation remain represented by focused tests. No destructive operation was performed in this round. Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 37ad71f49cf818e922d6c051c9c2cca9240478dd
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current exact-head result from the prior executed review: 5 passed; this mutation must make the suite fail. |
Seat note: the review loop here was blocked by a FULL DISK, not by a disagreementThis PR ran 10 review rounds in 1.6h against an unchanged head ( It isn't. From the latest verdict:
The shared I reclaimed 547M, so writes work again — a reprieve, not a fix. Deliberately NOT stamping a The reviewer's substantive blocker (detector tests substitute |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties remain represented on the unchanged head: unknown-discovery withholding, stale-heartbeat recovery, descriptor-based heartbeat claiming, replacement-inode cleanup refusal, unhealthy-replica aggregation, and stopped-container observation. No destructive operation was performed this round. Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 37ad71f49cf818e922d6c051c9c2cca9240478dd
test "$(git rev-parse HEAD)" = 37ad71f49cf818e922d6c051c9c2cca9240478dd
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current exact-head result from prior execution: 5 passed; the required real-path test must make this mutation red. |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties were rechecked against the unchanged diff/head: unknown-discovery withholding, stale-heartbeat recovery, descriptor-based heartbeat claiming, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container observation remain represented by focused tests. No destructive operation was performed this round. Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 37ad71f49cf818e922d6c051c9c2cca9240478dd
test "$(git rev-parse HEAD)" = 37ad71f49cf818e922d6c051c9c2cca9240478dd
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Exact-head executed result: 5 passed; the required production-path test must make this mutation red. |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties were rechecked: unknown-discovery withholding, stale-heartbeat recovery, safe descriptor claim, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container observation passed focused execution. Bypassing the destructive inode identity guard made Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 37ad71f49cf818e922d6c051c9c2cca9240478dd
test "$(git rev-parse HEAD)" = 37ad71f49cf818e922d6c051c9c2cca9240478dd
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py
uv run ruff check src/aios/harness/connector_liveness.py packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py tests/unit/harness/test_connector_liveness.py packages/aios-connector-http/tests/test_healthcheck.py
git diff --check 560eabda9967f0977f8481002a4260a9bafb2640..HEAD
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; the required production-path test must make this red.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode |
37ad71f to
6122d18
Compare
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties rechecked by execution: unknown-discovery withholding, stale-heartbeat recovery, descriptor-based claim, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container reader observation pass focused tests. Bypassing the destructive inode identity guard makes its negative test fail as required. Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 37ad71f49cf818e922d6c051c9c2cca9240478dd
test "$(git rev-parse HEAD)" = 37ad71f49cf818e922d6c051c9c2cca9240478dd
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; the required production-path test must make this mutation red.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties rechecked by execution: focused unmodified suites passed 18 tests, including unknown-discovery withholding, stale-heartbeat recovery, descriptor-based claim, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container Docker-reader observation. Bypassing the destructive inode identity guard made Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 6122d18900614e1cab77c2a3d43e200bd7a8fdd1
test "$(git rev-parse HEAD)" = 6122d18900614e1cab77c2a3d43e200bd7a8fdd1
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py tests/unit/test_ci_pytest_diagnostics.py tests/unit/test_docker_e2e_ci_resources.py
uv run ruff check src/aios/harness/connector_liveness.py packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py tests/unit/harness/test_connector_liveness.py packages/aios-connector-http/tests/test_healthcheck.py
git diff --check 78e73d2f679a72314767da099b625735162b0dc1..HEAD
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; the required production-path test must make this mutation red.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties rechecked by execution: the focused unmodified suites passed 18 tests, including unknown-discovery withholding, stale-heartbeat recovery, descriptor-based claiming, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container Docker-reader observation. Bypassing the destructive inode identity guard made Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q 6122d18900614e1cab77c2a3d43e200bd7a8fdd1
test "$(git rev-parse HEAD)" = 6122d18900614e1cab77c2a3d43e200bd7a8fdd1
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py tests/unit/test_ci_pytest_diagnostics.py tests/unit/test_docker_e2e_ci_resources.py
uv run ruff check src/aios/harness/connector_liveness.py packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py tests/unit/harness/test_connector_liveness.py packages/aios-connector-http/tests/test_healthcheck.py
git diff --check 78e73d2f679a72314767da099b625735162b0dc1..HEAD
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; the required production-path test must make this mutation red.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode |
6122d18 to
b83578a
Compare
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties rechecked by execution: focused unmodified suites passed 18 tests, including unknown-discovery withholding, stale-heartbeat recovery, descriptor-based claiming, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container Docker-reader observation. Bypassing the destructive inode identity guard made Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q b83578a986565160248c8bc57a0d1896751c9c9e
test "$(git rev-parse HEAD)" = b83578a986565160248c8bc57a0d1896751c9c9e
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py tests/unit/test_ci_pytest_diagnostics.py tests/unit/test_docker_e2e_ci_resources.py
uv run ruff check src/aios/harness/connector_liveness.py packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py tests/unit/harness/test_connector_liveness.py packages/aios-connector-http/tests/test_healthcheck.py
git diff --check b6b91a6cad8a8239fbdb1ce6937d2fb4077948db..HEAD
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; the required production-path test must make this mutation red.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode |
2 similar comments
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties rechecked by execution: focused unmodified suites passed 18 tests, including unknown-discovery withholding, stale-heartbeat recovery, descriptor-based claiming, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container Docker-reader observation. Bypassing the destructive inode identity guard made Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q b83578a986565160248c8bc57a0d1896751c9c9e
test "$(git rev-parse HEAD)" = b83578a986565160248c8bc57a0d1896751c9c9e
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py tests/unit/test_ci_pytest_diagnostics.py tests/unit/test_docker_e2e_ci_resources.py
uv run ruff check src/aios/harness/connector_liveness.py packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py tests/unit/harness/test_connector_liveness.py packages/aios-connector-http/tests/test_healthcheck.py
git diff --check b6b91a6cad8a8239fbdb1ce6937d2fb4077948db..HEAD
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; the required production-path test must make this mutation red.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties rechecked by execution: focused unmodified suites passed 18 tests, including unknown-discovery withholding, stale-heartbeat recovery, descriptor-based claiming, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container Docker-reader observation. Bypassing the destructive inode identity guard made Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q b83578a986565160248c8bc57a0d1896751c9c9e
test "$(git rev-parse HEAD)" = b83578a986565160248c8bc57a0d1896751c9c9e
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py tests/unit/test_ci_pytest_diagnostics.py tests/unit/test_docker_e2e_ci_resources.py
uv run ruff check src/aios/harness/connector_liveness.py packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py tests/unit/harness/test_connector_liveness.py packages/aios-connector-http/tests/test_healthcheck.py
git diff --check b6b91a6cad8a8239fbdb1ce6937d2fb4077948db..HEAD
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; the required production-path test must make this mutation red.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
Standing properties rechecked by execution: focused unmodified suites passed 18 tests, including unknown-discovery withholding, stale-heartbeat recovery, descriptor-based claiming, replacement-inode cleanup refusal, unhealthy-replica aggregation, conjunction behavior, and stopped-container Docker-reader observation. Bypassing the destructive inode identity guard made Replay rm -rf /tmp/aios-pr2208 && git clone -q https://github.com/eumemic/aios.git /tmp/aios-pr2208
cd /tmp/aios-pr2208 && git checkout -q b83578a986565160248c8bc57a0d1896751c9c9e
test "$(git rev-parse HEAD)" = b83578a986565160248c8bc57a0d1896751c9c9e
uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py tests/unit/harness/test_connector_liveness.py tests/unit/test_ci_pytest_diagnostics.py tests/unit/test_docker_e2e_ci_resources.py
uv run ruff check src/aios/harness/connector_liveness.py packages/aios-connector-http/aios_connector_http/healthcheck.py packages/aios-connector-http/aios_connector_http/runner.py tests/unit/harness/test_connector_liveness.py packages/aios-connector-http/tests/test_healthcheck.py
git diff --check b6b91a6cad8a8239fbdb1ce6937d2fb4077948db..HEAD
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# Current result: 5 passed; the required production-path test must make this mutation red.
cp /tmp/connector_liveness.py src/aios/harness/connector_liveness.py
cp packages/aios-connector-http/aios_connector_http/runner.py /tmp/runner.py
python3 - <<'PY'
p='packages/aios-connector-http/aios_connector_http/runner.py'
s=open(p).read(); old='if (stat.st_dev, stat.st_ino) == self._heartbeat_identity:'
assert old in s
open(p,'w').write(s.replace(old,'if True:',1))
PY
! uv run pytest -q packages/aios-connector-http/tests/test_healthcheck.py -k cleanup_refuses_to_unlink_replacement_inode |
Code reviewVerdict: BLOCK-BUILD-VIOLATES-SPEC
No destructive guard mutation was executed this round because the fresh clone could not be created. Replay rm -rf /workspace/pr2208-review
git clone https://github.com/eumemic/aios.git /workspace/pr2208-review
cd /workspace/pr2208-review
git checkout b83578a986565160248c8bc57a0d1896751c9c9e
test "$(git rev-parse HEAD)" = b83578a986565160248c8bc57a0d1896751c9c9e
cp src/aios/harness/connector_liveness.py /tmp/connector_liveness.py
python3 - <<'PY'
p='src/aios/harness/connector_liveness.py'
s=open(p).read(); old=''' rows = await pool.fetch(
"""'''
assert old in s
open(p,'w').write(s.replace(old,''' return []
rows = await pool.fetch(
"""''',1))
PY
uv run pytest -q tests/unit/harness/test_connector_liveness.py
# The required production-path test must make this mutation red. |
…d newest probe DockerConnectorHealthReader scanned health logs newest-first, skipped malformed records, and accepted an older valid record. For a running but unhealthy container, an older healthy_connection_ids entry was converted to TransportHealth(healthy=True), so a current probe read/ serialization failure suppressed the connection liveness alarm. Fix: track whether malformed records were skipped before the accepted record (i.e. the NEWEST probe observation was malformed). When so, a stale healthy attribution is downgraded to unhealthy (detail 'probe read failed') rather than reported as current health. We still consume the older record to attribute WHICH connections were served, and an older UNHEALTHY attribution is kept unchanged (fail closed). Over- correction guard: a clean newest healthy record still yields healthy=True. Note on remedy scope: the reviewer's property is satisfied by suppressing only stale GREEN behind a malformed newest record; we deliberately do NOT invent a stale outage or stop attributing connections.
Callbacks alone run after the SDK reconnect attempt, so supervise is_connected as well and restore readiness only for a usable replacement session.
…start After a connector process restarts with all transports still starting, the fail-closed claim path (_claim_heartbeat, touch_mtime=False) hit FileExistsError on any pre-existing pathname and returned None, so a stale heartbeat left by the crashed process kept its obsolete payload. The external liveness detector then read the previous process's IDs and suppressed multi-connection alarms for the currently-bound connections. Fix the cause: on FileExistsError, discriminate by freshness. A file already older than the probe max age is reclaimable crash debris; publish our fully-prepared, already-stale temporary inode over it with os.rename (atomic, single step -- the pathname is never observed fresh and its mtime is never transiently advanced). A FRESH pre-existing file (a live peer or operator replacement) is still refused, preserving replacement-inode safety. This is the over-correction guard: reclaiming debris must NOT extend to clobbering a live file. The suggested remedy is followed and it does achieve the property; the remedy was accurate here. Adds test_fail_closed_claim_reclaims_stale_ crash_debris (the finding's contract) and test_fail_closed_claim_refuses_ fresh_preexisting_file (over-correction guard).
Code reviewVerdict: fail
Targeted liveness/heartbeat tests passed locally (54 tests). Head CI was still in progress when reviewed. |
Code reviewVerdict: NEEDS-CHANGES
import os, time
from pathlib import Path
import pytest
from aios_connector_http.runner import HttpConnector
class C(HttpConnector): connector = "review"
def test_stale_reclaim_refuses_replacement_after_inspection(monkeypatch: pytest.MonkeyPatch, tmp_path: Path):
path = tmp_path / "alive"
path.write_bytes(b"stale-debris")
os.utime(path, (time.time()-3600, time.time()-3600))
inspected = path.stat(); real_rename = os.rename; replacement_identity = None
def race(source, destination):
nonlocal replacement_identity
old_fd = os.open(destination, os.O_RDONLY)
os.unlink(destination); Path(destination).write_bytes(b"operator-replacement")
replacement = Path(destination).stat()
replacement_identity = (replacement.st_dev, replacement.st_ino)
assert replacement_identity != (inspected.st_dev, inspected.st_ino)
real_rename(source, destination); os.close(old_fd)
monkeypatch.setattr(os, "rename", race)
identity = C._claim_heartbeat(path, b"current-unhealthy", False)
assert identity is None
assert path.read_bytes() == b"operator-replacement"
current = path.stat()
assert (current.st_dev, current.st_ino) == replacement_identity
Standing restart-attribution behavior was re-executed and passes. Focused heartbeat/runner suite: 105 passed. Exact-head GitHub checks are green, but this executed race remains red. |
Code reviewCanonical review record (reconciler-written, company#383) Verdict: NEEDS-CHANGES at
Canonical record written by the reconciler from the reviewer's structured return (company#383); the reviewer's own prose comment is discussion. |
Code reviewVerdict: NEEDS-CHANGES
uv sync --package aios-connector-http --group dev --frozen
uv run python - <<'PY'
import os,time,tempfile
from pathlib import Path
from aios_connector_http.runner import HttpConnector
with tempfile.TemporaryDirectory() as d:
p=Path(d)/'alive'; p.write_bytes(b'stale-owner'); old=time.time()-3600; os.utime(p,(old,old))
real=os.ftruncate; raced=False
def peer_refresh_then_truncate(fd,n):
global raced
if not raced:
with p.open('r+b') as f:
f.seek(0); f.truncate(); f.write(b'live-peer'); f.flush(); os.fsync(f.fileno())
os.utime(p,None); raced=True
real(fd,n)
os.ftruncate=peer_refresh_then_truncate
try: ident=HttpConnector._claim_heartbeat(p,b'claimant',False)
finally: os.ftruncate=real
print({'claim_identity':ident,'content':p.read_bytes().decode(),'fresh_age_s':time.time()-p.stat().st_mtime})
assert ident is None, 'claim must be refused after peer refresh'
assert p.read_bytes() == b'live-peer'
PYCurrent output reports a non-null identity and
Executed on the exact live head: connector HTTP suite ( |
Code reviewCanonical review record (reconciler-written, company#383) Verdict: NEEDS-CHANGES at
Canonical record written by the reconciler from the reviewer's structured return (company#383); the reviewer's own prose comment is discussion. |
Code reviewVerdict: NEEDS CHANGES
Executed on |
The advisory hard-link approach cannot satisfy same-inode refresh safety because validating pathname identity does not prevent a later peer write. Serialize cooperative refreshes with inode locks and atomically exchange the prepared claimant, retaining the displaced inode to detect and roll back both same-inode refreshes and pathname replacements.
Code reviewVerdict: NEEDS-CHANGES
git checkout 4e510e786d1b542a898470f05595ae8347a8a0c7
cat >/tmp/repro2208.py <<'PY'
import os,time,tempfile
from pathlib import Path
import aios_connector_http.runner as r
from aios_connector_http.runner import HttpConnector
with tempfile.TemporaryDirectory() as d:
p=Path(d)/'alive'; p.write_bytes(b'stale'); old=time.time()-3600; os.utime(p,(old,old))
real=r._rename_exchange; calls=0
def interpose(src,dst):
global calls
calls+=1
if calls==1:
ok=real(src,dst); os.utime(src,None); return ok
Path(dst).unlink(); Path(dst).write_bytes(b'operator')
return real(src,dst)
r._rename_exchange=interpose
ident=HttpConnector._claim_heartbeat(p,b'claimant',False)
print({'identity':ident,'calls':calls,'public':p.read_bytes(),'operator_survived':p.read_bytes()==b'operator'})
PY
uv run --package aios-connector-http python /tmp/repro2208.pyExpected safe behavior: the operator replacement survives. Actual output: Validation: |
Code reviewCanonical review record (reconciler-written, company#383) Verdict: NEEDS-CHANGES at
Canonical record written by the reconciler from the reviewer's structured return (company#383); the reviewer's own prose comment is discussion. |
Code reviewVerdict: fail
Focused checks passed: 107 connector-http tests, 34 connector-liveness tests, Ruff, and mypy. |
A pre-check cannot make rename-exchange conditional as suggested. Verify each displaced inode and continue compensating until the claimant itself is displaced, so an owner interposed before a rollback mutation remains public.
Code reviewVerdict: NEEDS-CHANGES
import os, time, tempfile
from pathlib import Path
import aios_connector_http.runner as m
from aios_connector_http.runner import HttpConnector
class C(HttpConnector): connector = "x"
with tempfile.TemporaryDirectory() as d:
p = Path(d) / "alive"; p.write_bytes(b"stale")
old = time.time() - 3600; os.utime(p, (old, old))
op = Path(d) / "operator"; op.write_bytes(b"operator replacement")
real = m._rename_exchange; calls = 0
def exchange(src, dst):
global calls
calls += 1
if calls == 1:
os.replace(op, p)
return real(src, dst)
return False
m._rename_exchange = exchange
try:
identity = C._claim_heartbeat(p, b"claimant", False)
finally:
m._rename_exchange = real
assert identity is None
assert p.read_bytes() == b"operator replacement"
Executed on the exact live head: focused heartbeat suite passed (23 tests), stale-debris attribution recovery passed, and replacement-at-rollback with successful exchanges passed. The injected rollback-failure degraded path above failed. No destructive-operation diff required a destructive-guard negative test. |
Code reviewCanonical review record (reconciler-written, company#383) Verdict: NEEDS-CHANGES at
Canonical record written by the reconciler from the reviewer's structured return (company#383); the reviewer's own prose comment is discussion. |
Code reviewVerdict: fail
Core liveness suites and connector suites otherwise passed in review; one combined runner-suite invocation showed a timing-only timeout that passed immediately in isolation. |
Code reviewVerdict: fail
Checks run: focused connector-liveness/heartbeat suite passed (57 tests); Ruff and mypy passed for the primary new modules. |
|
|
Superseded by #2355 (runner + Dockerfile HEALTHCHECKs + matrix healthcheck, carved out of this branch at 3ef6f2c; all six connector suites pass against the new runner with the connector.py edits dropped). The per-connector readiness changes stay on |
Automated dev-pipeline build for issue #2153.