A server-started stop for an engine that exits on its own: no request,
no confirmation; it closes admission and supersedes the current stop
(H17), but refuses stop-owned under a force stop or another engine
exit. The binding follows it like a force stop at startStop,
advance-stop and confirm-stopped, and its proof needs a member.
Dispatched or acknowledged input goes delivery-unknown; working input
keeps its state. Five lifecycle sequences and two shape cases.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Row 51, owner Dewey, candidate c34039dc (5 files). A claim recorded
stopped on a cohort proof whose scope is still listed is released on
start (classify's stopped branch and the free path's session and seat
heads) and on a confirmed recover, after every recover check. A release
that ended unavailable or still listed is retried; the proof check stays
in #releaseScope. close({ killEngine: true }) no longer signals the
recorded PID after a proven stop. Tests R7-R12 kill relok, closeany,
noprooffkind and nopush; R9 pins the recover order.
Reviews: Filbert approve (27070, 27074), Darkwing changes then approve
(27071, 27075). Gate green on 032b5408 plus the candidate.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Rev 299 is a failed first request: no credential file was set, so nothing
was sent. Rev 301 posted the request as comment 27068.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
No engine-exit stop over an unfinished force stop, the binding follows
the stop at all three force-stop mode checks, the proof names the engine
as a member, and the proof has a deadline that frees the escalation slot.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Row 51 needs a CHAT-01 rule changed to record `stopped` at engine exit.
The engine-exit proof moves to its own row with a CHAT-01 amendment and
contract review; row 51 keeps the crash window, the close PID fix and
the mutant tests.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
releaseCohort sends `release` only to a scope shim that answers hello
with the recorded invocation ID, then waits for systemd to drop the
unit. The controller releases once per claim, after a proven force stop
and on close of a proven-stopped binding; every uncertain path keeps the
scope as evidence. The harness's killShims refuses units outside
^mosaic-chat-, R5 checks liveShims positively, and K19's wait on
proc.exited is bounded.
Dewey's candidate, manifest 375594fc (8 files), approved by Filbert
(comment 27053) and Darkwing (comment 27055). Normal engine exit still
leaves the scope; the follow-up is #1537.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Engine exit proof and release, the crash window and release retry,
close's SIGKILL of a recorded PID, and the reviewers' surviving mutants
(relok, closeany, noprooffkind, nopush).
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Row 47, the S5 follow-up. flows.test gains a test for a hold set inside
held input, which kills mutant Mr. claim W5 and W13 reap their own
force-stopped scopes, K19 kills its scope if its kill or release fails,
and the harness gains liveShims, killShims and shimsGone with a final
sweep in reap. claim, cohort and races each end by asserting no shim
outlives the file.
Author: Dewey. Approved round 1 by Filbert (comment 27041) and Darkwing
(comment 27043) on candidate 0587e393. The src side, where a force stop
never sends release, is row 50 (#1536).
Co-Authored-By: Claude Opus 5.5 <[email protected]>