conversation/CHAT-01: engine-exit follow-ups from row 52 (tests, guards, stale comment) #1540

Open
opened 2026-10-10 08:31:43 +00:00 by jarvis · 0 comments
Contributor

Follow-up from row 52 (#1538): the CHAT-01 engine-exit stop and the release at engine exit. None of these blocked the row. Every guard listed fails closed.

Sources: Dewey's packet (agents/dewey/work/queue-52/evidence.md, notes comment 27086), Filbert's verdict (27087), Darkwing's verdict (27088, packet agents/darkwing/work/queue-52-review/review-r1.md).

Conversation tests

  1. Stale comment (Filbert N2). packages/conversation/tests/cohort.test.mjs, the three lines above the ---- engine exit header, still say a normal engine exit leaves the scope and only the proven force stop releases it. Row 52 made that false. Delete or rewrite them. It stayed in the round because the comment is inside the frozen manifest.
  2. Untested guards in engineExitCohort (Darkwing notes 2 and 3). nopopulated and nomembers survive, and nolive shows a test needs both gone. No test reaches the invocation ID check against systemctl show, the hello scope check against the unit's control group, or the boot comparison (also Dewey's list, Filbert's noboot). A fake members or hello answer would pin each one. Check whether forceStopCohort's tests reach the same three checks.
  3. K15 shapes on the engine-exit path (Dewey). An unreadable events file or a failed members call is reached today only through the deadline.
  4. Process-group fallback (Dewey). The natural exit there ends uncertain at once; no test runs it.
  5. Engine exit during an in-flight interrupt (Filbert N3). E1 compares supersedes with null. No conversation test runs an engine exit while an interrupt is pending, though the model's main sequence does.
  6. The settle loop (Filbert N5). noretry passes 37/37 because the shim has reaped the engine before the first read. A test needs a shim that reaps late, held at a barrier between the engine's EOF and its wait.
  7. E4 and the request timeout (Darkwing note 1). E4 tells the exitProof deadline from shimRequest's 3000 ms timeout only by the reason text. One pass can spend three 3 s requests, and systemctlShow is a 5 s spawnSync the deadline can't preempt. forceStopCohort has the same shape. Decide whether the deadline should bound the requests, and test it either way.

CHAT-01 model (next amendment, not alone)

  1. Shared startStop effects unpinned for engine-exit (Filbert N1): nodecisions, ackkeeps, noemitq, nostoppingevt, noadmclose. Add acknowledged input and a pending decision to engine-exit-stale-confirmation-dispatched-receipt, and assert admission closed and a stopping event in engine-exit-binding-follows-stop. This changes the four CHAT-01 hashes, so batch it with the next amendment.

README

  1. Event order at EOF (Darkwing note 5): clients see uncertain from #transport, then stopping from #startStop. Document it if a client trips on it.

Owner when picked up: Dewey. Reviewers: Darkwing and Filbert. Not queued yet. Related: #1539.

Follow-up from row 52 (#1538): the CHAT-01 `engine-exit` stop and the release at engine exit. None of these blocked the row. Every guard listed fails closed. Sources: Dewey's packet (`agents/dewey/work/queue-52/evidence.md`, notes comment 27086), Filbert's verdict (27087), Darkwing's verdict (27088, packet `agents/darkwing/work/queue-52-review/review-r1.md`). ## Conversation tests 1. Stale comment (Filbert N2). `packages/conversation/tests/cohort.test.mjs`, the three lines above the `---- engine exit` header, still say a normal engine exit leaves the scope and only the proven force stop releases it. Row 52 made that false. Delete or rewrite them. It stayed in the round because the comment is inside the frozen manifest. 2. Untested guards in `engineExitCohort` (Darkwing notes 2 and 3). `nopopulated` and `nomembers` survive, and `nolive` shows a test needs both gone. No test reaches the invocation ID check against `systemctl show`, the hello `scope` check against the unit's control group, or the boot comparison (also Dewey's list, Filbert's `noboot`). A fake `members` or `hello` answer would pin each one. Check whether `forceStopCohort`'s tests reach the same three checks. 3. K15 shapes on the engine-exit path (Dewey). An unreadable events file or a failed `members` call is reached today only through the deadline. 4. Process-group fallback (Dewey). The natural exit there ends `uncertain` at once; no test runs it. 5. Engine exit during an in-flight interrupt (Filbert N3). E1 compares `supersedes` with `null`. No conversation test runs an engine exit while an interrupt is pending, though the model's main sequence does. 6. The settle loop (Filbert N5). `noretry` passes 37/37 because the shim has reaped the engine before the first read. A test needs a shim that reaps late, held at a barrier between the engine's EOF and its wait. 7. E4 and the request timeout (Darkwing note 1). E4 tells the `exitProof` deadline from `shimRequest`'s 3000 ms timeout only by the reason text. One pass can spend three 3 s requests, and `systemctlShow` is a 5 s `spawnSync` the deadline can't preempt. `forceStopCohort` has the same shape. Decide whether the deadline should bound the requests, and test it either way. ## CHAT-01 model (next amendment, not alone) 8. Shared `startStop` effects unpinned for `engine-exit` (Filbert N1): `nodecisions`, `ackkeeps`, `noemitq`, `nostoppingevt`, `noadmclose`. Add acknowledged input and a pending decision to `engine-exit-stale-confirmation-dispatched-receipt`, and assert admission closed and a `stopping` event in `engine-exit-binding-follows-stop`. This changes the four CHAT-01 hashes, so batch it with the next amendment. ## README 9. Event order at EOF (Darkwing note 5): clients see `uncertain` from `#transport`, then `stopping` from `#startStop`. Document it if a client trips on it. Owner when picked up: Dewey. Reviewers: Darkwing and Filbert. Not queued yet. Related: #1539.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaicstack/stack#1540