Repository navigation
Tracking: PET reliability, performance, architecture, and coverage audit implementation plan #528
Description
Activity
karthiknadig commented
on Sep 21, 2026 MemberAuthorMore actionsImplementation progress (local worktrees, not yet published)
The first independent batch is implemented in separate worktrees based on
114686c. Existing PRs #526 (for #525) and #524 (for #522) were left untouched. No audit issue is being closed by this update.Issue Local branch Verified result Remaining gate #529 fix/audit-529-eofClean EOF, typed transport failures, tracked request workers, and safe draining. Full workspace: 651 passed / 0 failed / 2 ignored; after restart, 67 focused tests passed again. A real delayed interpreter completed and was reaped before PET exited successfully. Bounded cancellation of genuinely hung external commands is not solved. This foundation deliberately waits rather than orphaning children; complete that acceptance item with #530/#539 and run Linux/macOS CI. #531 fix/audit-531-client-metricsSchema-v3 client round-trip and request-relative TTFE, retained discovery/startup metrics, explicit exact-base transition. 7 Rust timing/client tests and 52 Python quality-tooling tests passed. Comparable repeated Linux/Windows/macOS release baselines are still required for calibration. Existing tolerances are not evidence that new metrics have been calibrated. #535 fix/audit-535-glob-dispatchOff-dispatcher expansion, bounded traversal/admission, expanded-path coalescing, and explicit errors. Full workspace: 663 passed / 0 failed / 2 ignored. Real JSONRPC fixture returned exactly three expected environments for duplicate globs, rejected malformed/over-limit patterns with -4, and remained usable for info requests. Linux/macOS CI and integration with #531 metrics; when stacked after #529, retain transport-owned workers rather than reintroducing detached refresh workers. All three worktrees pass Windows
cargo fmt --all -- --check,cargo clippy --offline --locked --workspace --all-targets --all-features -- -D warnings, andgit diff --check.Review corrections completed
- Removed a proposed EOF grace-period exit after reproducing that it orphaned a still-running interpreter. The remaining hung-process cancellation requirement is explicitly documented rather than claimed complete.
- Fixed glob brace compatibility, case-sensitive Windows wildcard identity, trailing directory-only pattern identity, and glob/literal equivalence for refresh coalescing.
- Added differential tests against the pinned
globimplementation, including terminal**/**/, mixed brace/wildcard forms, dot directories, and 49 two-component combinations. The actual pinned implementation, not an assumption about shell globbing, is the compatibility oracle. - Requests without wildcard traversal bypass saturated glob slots. Directory traversal and brace expansion are iterative; intermediate brace work has an explicit cap. Errors never publish a partial refresh inventory/configuration.
Changes are saved but uncommitted and unpushed. The original checkout remains unchanged. Branches have been validated independently; final stacking/rebase review is still needed before merging overlapping handler changes. Next steps remain publication/CI, the #529 cancellation dependency, and #531 cross-platform calibration rather than starting the measurement-gated optimization/refactor phase prematurely.
karthiknadig commented
on Sep 21, 2026 MemberAuthorMore actionsPublished the #535 implementation as draft PR #541 from
fix/audit-535-glob-dispatch, commit56a0d620a56a92538f9fca2c3ba2d436c5820ae1.Final review caught swallowed metadata errors; those were fixed and the Reviewer follow-up confirmed resolution. Final Windows validation: 664 workspace tests passed, 0 failed, 2 ignored documentation examples, repository precommit checks and all-target/all-feature Clippy passed. The PR documents intentional glob limits, explicit-error semantics, and OS-call cancellation limitations.
The draft is pending cross-platform CI, quality-snapshot inspection, and review. #529 and #531 remain in their separate local worktrees and are not included or closed. No merge or auto-merge has been requested.
karthiknadig commented
on Sep 21, 2026 MemberAuthorMore actionsParallel work update
- fix: bound glob expansion outside RPC dispatch (Fixes #535) #541 / Move refresh glob expansion off the RPC dispatcher and bound traversal work #535: Copilot's duplicate-brace work-budget finding is fixed and pushed in
94f869c. Exact-boundary/public-API regressions pass (79 pet-fs tests), along with required precommit and CI-strength Clippy. The later terminal-**suggestion was resolved with pinnedglob0.3.3 source and differential-test evidence rather than introducing an incompatible inventory change. CI is still finishing; no merge/auto-merge requested. - test: measure client-observed refresh latency (Refs #531) #542 / Gate client-observed refresh latency and define accurate first-environment timing #531: A separate draft PR now contains schema-v3 client RTT/TTFE measurement and real request-path regression tests. Malformed notifications fail before timestamping. Eight Rust and 52 Python tests pass. Three hosted, all-platform baseline runs at exact head
9c1b003are collecting actual calibration data: run 1, run 2, run 3. Gate client-observed refresh latency and define accurate first-environment timing #531 remains open until the repeated distributions are reviewed. - Drain subprocess pipes while probing interpreters and standardize probe deadlines #530: An isolated worktree reuses existing Fix interpreter discovery panic on non-UTF-8 stdout #526's UTF-8 fix without modifying that PR. The runner is wired through interpreter/Conda/Poetry callsites, and 102 targeted tests pass on Windows, but independent safety review identified unbounded termination/pipe-cleanup failure paths. Those are being redesigned around bounded nonblocking pipe draining before publication. Passing happy-path cleanup tests is not being treated as proof of the deadline guarantee.
#529 stays unpublished until the subprocess cancellation/cleanup dependency is safe. Work continues in separate branches; the original checkout is unchanged.
- fix: bound glob expansion outside RPC dispatch (Fixes #535) #541 / Move refresh glob expansion off the RPC dispatcher and bound traversal work #535: Copilot's duplicate-brace work-budget finding is fixed and pushed in
karthiknadig commented
on Sep 24, 2026 MemberAuthorMore actionsProgress checkpoint: #531 is closed after acceptance-by-acceptance verification of the merged client metrics and 21 Rust/48 comparator tests. #555 (bounded Conda/Poetry probes) is now ready with verified squash auto-merge, a clean current-head Copilot re-review, all 35 automated checks passing, improved coverage, and a documented same-host macOS quality control. It is still waiting for required approval/the external VS Code PR Check; it has not merged. The remaining process-tree/active-shutdown work under #530/#529 is not being marked complete by this manager slice. #520 also remains open because the historical signed Azure artifact/signing logs needed for provenance verification are not accessible in this session. No incomplete tracking issue has been closed.
karthiknadig commented
on Sep 28, 2026 MemberAuthorMore actions#559 and #560 are merged; #529 and #532 are closed. Work is now proceeding in isolated parallel branches on #534 (coverage integrity/reporting, including native macOS) and #533 (long-lived deterministic session/scale workloads). The #536/#539/#540 ownership/concurrency changes remain behind those measurement prerequisites; no issues are being closed merely because partial prerequisites landed. Existing signing work remains separate, with no signing/release services invoked and no updates posted on #520.
Goal
Implement the September 21, 2026 PET performance, architecture, refactoring, and test-coverage audit in an evidence-driven order: fix demonstrated reliability failures first, make measurements reflect client behavior next, then simplify and bound concurrency. Do not start with a broad rewrite or an async-runtime migration.
This plan links 12 newly filed implementation issues, reuses #525 for the UTF-8 panic, and tracks #522 as an existing quality-workflow prerequisite.
Evidence and audit scope
The audit examined
4e523bad8bb9be8a84c01800a3e400a6a771cf8e. At filing, main isd586c60ec6b7191256fa3f47a2c866cc5739914e; the intervening change only removes redundant Conda vector drains and does not address these findings.cargo test --workspace --offline --lockedpassed 647 tests, with 0 failures and 2 ignored documentation examples. Quality-tooling Python tests: 47 passed.Existing work: reuse, do not duplicate
#525 / PR #526: existing non-UTF-8 interpreter-output fix. Review/validate and integrate it before overlapping subprocess-runner changes.
#522 / PR #524: existing fork-safe quality-workflow fix. Complete it so fork contributions execute the substantive quality gates. Runtime fixes do not need to wait for comment-publishing changes; never weaken the gates or grant untrusted PRs write credentials as a workaround.
Ordered implementation plan
Order below is the recommended landing sequence, not a requirement to serialize independent investigation or test preparation. P1/P2/P3 are relative priorities within this audit, not estimates of effort. The dependency column distinguishes required foundations from coordination.
Phase 1 - Reliability boundaries
Phase exit: reproduced process/transport failures are covered by deterministic regressions; normal request behavior, streaming, and locator priority remain intact.
Phase 2 - Trustworthy measurements, responsiveness, and coverage
Phase exit: the roughly 400 ms client / 2 ms reported-duration reproduction is no longer invisible to the performance gate; black-box server testing contributes usable coverage; repeatable workloads establish a baseline for architectural changes.
Phase 3 - Coherent ownership, bounded work, and focused refactoring
Phase exit: ownership/resource limits are explicit and tested. Optimizations are supported by measurements. The locator framework and public behavior are preserved rather than replaced wholesale.
Parallel work and review boundaries
Transport shutdown/framing and subprocess-runner work can use separate PRs; coordinate the latter with #526. Metric/coverage test preparation can run alongside those fixes. Snapshot, scheduler, and writer changes should not be merged as one large refactor: establish ownership first, then independently validate scheduling and output behavior. Poetry profiling can run in parallel once the workload harness is ready.
Purely mechanical library-module reuse or the find read-guard fix may be isolated earlier; do not smuggle behavioral changes into those cleanups. Do not delay demonstrated reliability fixes for the optional Poetry optimization or final module cleanup.
Shared implementation and verification contract
Each ticket includes its own scope and acceptance tests. Implementations must preserve locator ordering, complete environment/manager information, platform path/symlink behavior, refresh coalescing, generation filtering, and scoped state synchronization. Use explicit errors, not success-shaped fallback data. Measure intentional metric/protocol changes and update directly related documentation.
Run targeted tests first, then relevant workspace/platform/feature jobs. Before committing Rust changes, run
cargo fmt --allandcargo clippy --all -- -D warnings; CI's all-targets/all-features lint and the existing exact-base quality gates must also remain green. Concurrency tests should use deterministic barriers/channels rather than timing guesses. Test fixtures must bound and clean up their own subprocesses and files.Milestones
Close this tracking issue only when each linked item is complete or explicitly deferred with a recorded reason. Check issue/PR state when starting work; links above describe filing-time status, not a substitute for current GitHub state.