Skip to content

fix(pp5): isolate targeted checkpoint handshake paths - #1052

Open
zoorpha wants to merge 2 commits into
pp5-s5-foundationfrom
pp5-1051-checkpoint-path-contract
Open

zoorpha wants to merge 2 commits into
pp5-s5-foundationfrom
pp5-1051-checkpoint-path-contract

Conversation

@zoorpha

@zoorpha zoorpha commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Issue

Fix #1051 as a narrow follow-up to #1046.

Depends on #1046 and keeps #1046 frozen.

Intent

Confirm and fix the root-owned 0755 vs unprivileged daemon EACCES boundary for the targeted orphan-repair checkpoint seam.

Design

  • Use a private run-scoped daemon-owned 0700 directory under $STATE_ROOT/data.
  • Keep checkpoint publication and release waiting fail-closed before unbind/release.
  • Capture bounded sanitized publication step/kind/errno fields in both collectors.
  • Run a pre-VM publisher plus checkpoint/waiter/release diagnostic.

Evidence

The focused child-process regression reproduced temporary_create / permission_denied with errno under the root-owned legacy layout and passed publication/release under the daemon-owned corrected layout.

Validation

  • Focused compute tests: 110 passed.
  • Five PostgreSQL tests: passed against fresh guarded o3k_p13_test_1051_pg_1790684931, owned by o3k, then dropped.
  • Workspace clippy, fmt, diff checks, restart guards: passed.
  • Local Mock Cinder component test: passed.
  • Governed nextest/workspace PostgreSQL failures from the earlier run were due to missing destructive DB purpose configuration; the five blocked tests were subsequently rerun successfully with the guarded disposable database.

Scope and non-goals

No networking, scheduling, lease, P11 v3/fabric, S5, host-maintenance, or #1035 redesign changes. Protected 1035-crash-recovery was dispatched once as run 36573826866 and blocked before the acceptance lane by an immutable-checkout guard mismatch. #1035 remains open and PP.5 certification is not claimed.

Approval gate

New approval required for exact commit 3d99d80dd8eefa68e39e3f9399faa6951acbe63e; protected 1035-crash-recovery may run once after all checks pass.

@zoorpha
zoorpha requested a review from senolcolak as a code owner September 29, 2026 12:31
@zoorpha
zoorpha force-pushed the pp5-1051-checkpoint-path-contract branch from d75eea0 to 39bd389 Compare September 29, 2026 12:41
@zoorpha

zoorpha commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator Author

Review request for exact final commit 39bd389e0f32d350104dd08c558535f56ad369cb.

The initial CI run found and I corrected only a test-placement issue: the unprivileged boundary regression now lives in src/checkpoint_tests.rs, so maintainability architecture guards pass without changing production behavior. Local focused tests, full workspace clippy, fmt, guards, and guarded PostgreSQL validation are green.

Please approve this exact commit after CI is green. I will not dispatch protected 1035-crash-recovery until that approval is recorded; #1046 remains frozen.

@zoorpha

zoorpha commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator Author

CI is green for exact head 3d99d80dd8eefa68e39e3f9399faa6951acbe63e (run 36580174477). Please review and approve this new commit. The prior approval was for 39bd389e and does not authorize this changed commit; no protected dispatch will occur until approval is recorded for 3d99d80d.

@zoorpha
zoorpha requested a review from senolcolak September 29, 2026 14:22

This branch had an error being deployed

1 failed deployment
o3k-real-host-validation — 3d99d80d Deployed Sep 29, 2026 by github-actions[bot] via Protected TestLab real-host validation #472
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants