← Priority list
In progress

Finish four watchdog gates and remaining durable-admission fixes

Finish four inherited gates, two review experiments, capacity and retry fixes, then whole-PR validation. Three candidate selectors passed first attempt; baseline failed as expected three times. Source PR remains unchanged with five failed checks.

Claimed by fable-hq-20261004

Handoff document

Markdown

Finish four watchdog gates and remaining durable-admission fixes

RE-VERIFY: 2026-10-09T05:26:28.082832+00:00 CHECKPOINT at the lane time box. Re-fetch main, PR states and this body before acting. Historical conclusions are hypotheses. The supervisor owns every merge, enqueue, deployment, publication and handoff completion.

Mission

The original request is near100% BuildTest droplet utilization with both blocking durable-admission defects fixed. Preserve the approved conservative migration, completed-static cleared-field/detail-history policy and settled fixture rulings. Immediate conclusive no-create return followed by FIFO reacquisition is approved. Run10 approves a separate post-proof unit snapshot while preserving every inherited assertion, including exactly one total snapshot in the interrupted copied-boundary fixture.

Approved fixture decision and run11 checkpoint

The supervisor explicitly APPROVED establishing a complete fleet observation through public operations while preserving every inherited assertion. The alternative nullable observer assertion is rejected. The earlier separate destruction/post-proof snapshot ruling remains approved. Do not ask these questions again.

The fresh run11 candidate is cf95ec2c53d934525fa570fbfd5ac3a6de4330bb on main f87fd2d969d2c78b3a17104f7ca65583f5ca012a. Approved setup submits a real held capacity waiter, awaits both its wait boundary and the existing completed-fleet-observation callback, checks a non-null fleet snapshot, cancels the waiter, and requires zero provider creates plus unchanged original admission state, status and destruction history. All24 inherited check/assert calls are unchanged.

The corrected fixture compiled and failed3/3 automatic attempts at the original missing-unit assertion on unrepaired-watchdog baseline5e4de22d92e6d87ffdd3cdeb419ce77be64e6219 (mainb865c4a8). All preceding setup and original proof/status/request assertions passed. Final scenario count0passed/1failed; this is the expected old-code failure. Full XML, console and three traces are pushed in run11 evidence under baseline-proof.md and watchdog-baseline4.. Baseline execution started04:02:17UTC and completed within its1800-second bound. Candidate cf95ec2c compiled and passed this same regression on its first attempt: 1 passed, 0 failed, no retry. Full output is saved in candidate-proof.md and watchdog-candidate3.. The later inherited assertions for exact snapshot count, public fleet re-entry, history and copied-record restart all passed. The baseline/candidate fixture bytes are identical. No source PR push.

Before the latest main rebase the only baseline-to-candidate difference was the34-line watchdog production delta. The newer main changes bound archive test extraction and validate runner timestamps; the relevant watchdog/helper changes remain intact. Re-verify and preserve those changes before further builds. Two of six inherited gates now pass on their first attempt at the same candidate head: testWatchdogThenReaperRetiresEveryConfirmedAbsentIdInUnit and watchdogAbsenceWriteFailureKeepsFollowerQueuedAcrossRestart. Candidate total is 3 passed, 0 failed, all first attempts. Four inherited gates, remaining capacity/retry experiments, whole-PR reviews and exact-head full suite remain pending.

The historical run10 result remains 3/3 fixture failures caused by the documented nullable fleet result before observation; full evidence is retained in the run10 branch. That question is now settled, not an outstanding operator decision.

Chain of findings

  1. The approved inherited wake ordering correction is integrated. Identical corrected fixture failed main441a2fcb0/1, then passed3bd7f6b5 1/1 first attempt. Both follower replies are held until a real prepared two-slot wait; every old workload/capacity/count/FIFO/timeout assertion remains. A new frozen-clock assertion proves grant before the unchanged deadline. README1120–1122 already states immediate release/FIFO.
  2. Legacy migration excludes permanently released shards only from reconstructed missing demand. Historical baseline0/3, original fixed1/1, fresh source630fb14d fixed1/1 first attempt across two actual service starts, retaining exact primary/request/unit identity. This correction and public regression are carried into current source; those legacy passes are historical after integration.
  3. The corrected NEW retry regression failed3/3 automatic baseline attempts on630fb14d plus only an observer seam: the released follower persisted a fresh queued request and waited in admission rather than stopping. The same fixture passed1/1 first attempt against the guard and1/1 at current integrated source1efee264c5b99c401b1d7ab3f544b6675d5aa4ef. The guard checks saved and actual mutation state under the run disk lock, rejects fresh demand from a released follower, and preserves sibling requests. Existing deadline stop text, exact primary ownership, empty follower assignment/history and no extra provider/grant/demand counts are asserted.
  4. Current source integrates main's per-worker provisioning-budget behavior. The first integrated compile exposed one missing retained-recovery worker argument; corrected before push. Main's e2eFailedDeletionFinishOrdersSiblingRequeue then passed1/1 first attempt at1efee264c5b99c401b1d7ab3f544b6675d5aa4ef. The single-branch clone fetch refspec excludes main; explicit git fetch origin main:refs/remotes/origin/main is required. Source is based on main d4d7d7185798086bb8fb24103caa84411bfeffc2; six integration conflicts were resolved preserving both main's worker/lock boundaries and the PR's retained replacement state.
  5. NEW public watchdog baseline compiled and failed3/3 automatic attempts at1efee264c5b99c401b1d7ab3f544b6675d5aa4ef, outside the PR. It proves exact intact two-ID membership after startup, then writes alias absence, invokes the real watchdog, and verifies committed absence/live status/unchanged requests. The wholly absent unit remains alongside an independent positive unit. Production updates destroyed history/proof and older derived accounting but never retires the persisted admission unit. No watchdog fix was made because of the inherited contract question below.
  6. Historical CI associated with630fb14d: https://github.com/CodexCoder21Organization/BuildTestEmbedded/actions/runs/37319511467 — all four artifacts read;3751 scenarios,3733 first-attempt passes,3743 final passes,8 failures,34 failed attempts,10 retry-only final passes. Its workflow checks out github.sha (PR merge ref), so these are associated-head artifacts, not exact local-source passes. Seven earlier failures persist; testReleasedUncreatedSlotLateDeletionKeepsPrimaryReservation also failed. All full traces/XML are preserved. Earlier3bd CI3742/3749 with7 failures and920 CI3731 first/3737 final of3745 with8 failures are historical. No manual CI rerun was requested.
  7. Historical run9 admission-scoped inventory:710 selectors in708 files,33 helpers excluded;2 first-attempt passes at the then-current head (retry and sibling ordering),708 unexecuted. This is not the entire suite; run10 current source has about3962 root test scripts. The attempted unchanged unknown-owner selector exited75 at memory gate before launching a compile/test JVM: zero executed tests. Do not turn it into a baseline verdict or call remaining cases host-load flakes. Full suite, other ownership/restart/budget neighbors, retry-only classification and whole-PR independent reviews remain open.

Historical run10 findings

  1. Read every failed attempt before implementation. Source-associated Actions run https://github.com/CodexCoder21Organization/BuildTestEmbedded/actions/runs/37325503186 contains 3762 scenarios: 3744 first-attempt passes, 10 retry-only passes, 8 final failures. Four shards and dependent bld-build failed. All eight final-failure fixtures are byte-identical to the saved main comparison and current candidate; main c918 passed all eight first attempt in https://github.com/CodexCoder21Organization/BuildTestEmbedded/actions/runs/37858390400 . Two cache retries have matching first-attempt failures on that main. Causal classification of five other retry-only mechanisms remains open after the three landed repairs below.
  2. Candidate source is 9c0d2b90e77fc7a1212a6d7a890750ec61230bf0 on wip/L44-run10-watchdog-fix, based on main 09770c9c. The watchdog commits destruction/proof first, then retires fully absent units in a separate snapshot outside admissionLock. Unknown aliases remain intact; interrupted or closing callers do not start the separate operation. No inherited assertion changed. This is a FAILED candidate test result, not a verified fix.
  3. Historical unchanged new-test baseline: 3/3 failures at the missing unit-removal assertion on 1efee264. Relevant watchdog/helper bytes match the rebased baseline. The final candidate invocation compiled successfully and failed 3/3 at the fixture problem above: 0/1 scenario passed. The other six named gates remain unexecuted on this candidate. Earlier bounded commands ended during compilation without executing a test; they are not failures or passes. No test/project timeout was changed and no CI rerun was requested.
  4. The last verified remote main is 0be27701e9c3e236afddd7ec15bd2d080591e6b0. It advanced while the exact-head selector was queued/running; source was deliberately not changed underneath that command. Its new service hunks concern duration statistics and archive project identity; the scheduler also changes repeated memory-skip logging. The later completion-timestamp change also leaves the nullable fleet contract unchanged; both getFleetStatus implementations explicitly return null before any complete observation (their later reservation filtering differs). They do not implement durable admission retirement. Rebase after the fixture ruling before another build or PR update.
  5. Remaining capacity hypothesis: a conclusive no-create path lowers the in-memory reservation but leaves a persisted unit which later deletion recount can restore. Current public reproduction is required before any fix. The late-refusal/unknown ownership cases overlap https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1286, which remains another actor's OPEN draft at d42d54ac with five failed checks. Its accounting changes do not contain this durable-unit cleanup. Do not touch its branch.
  6. Separate narrow test/code reviews are preserved, including their correction after the actual result. The initial review missed the missing fleet observation; it is not a full approval. The repeat-confirmation wake question remains unproved, with a public experiment written down and no speculative patch. Whole-PR review and all remaining gates are open.
  7. The owned PR https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1130 remains OPEN at 1efee264c5b99c401b1d7ab3f544b6675d5aa4ef with all five checks FAILURE. No PR branch push this invocation. All 41 inherited branches were rechecked and retained. Both new WIP branches preserve source, test, CI/main evidence and the required fixture decision. No remote suite, merge, enqueue, deploy, publication or handoff completion was performed.

Newer main repairs to preserve

Three retry-only fixtures now match main exactly, and all three passed first attempt in the saved main comparison. Their merge commits are verified ancestors of the candidate. Preserve them; do not duplicate their implementation. Candidate integration still needs verification.

  • Duplicate finalize: https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1298 merged as https://github.com/CodexCoder21Organization/BuildTestEmbedded/commit/5f67f3df8026fdfbee73c611001795142d855504 . The fixture holds resumed workers and waits for independent backfill before exact directory comparisons.
  • Stalled creation: https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1291 merged as https://github.com/CodexCoder21Organization/BuildTestEmbedded/commit/519bb78520bb3838889d3c8c95cfaf60c63efc1d . Manual time advances follow registered cleanup sleeps, preserving original assertions and bounds.
  • Startup heap: https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1300 merged as https://github.com/CodexCoder21Organization/BuildTestEmbedded/commit/7cb3a6330d3b097eda0fed0d334b2606011574bc . The repair includes bounded cold/restarted result reads as well as shared fixture encoding; earlier notes describing only fixture costs were incomplete. Original volumes, heap and time bounds remain. Five other retry-only mechanisms remain unresolved; see ci-classification.md and landed-retry-findings.md. Two cache retries have matching main failures. All eight final-failure fixtures are byte-identical across old PR, main comparison and candidate.

Relevant PRs / refs

  • OPEN source PR: https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1130 — live1efee264c5b99c401b1d7ab3f544b6675d5aa4ef; all four shards and bld-build FAILURE at final run11 verification. Reason-first description includes honest counts and unexecuted gates. No merge approval.
  • Already merged: https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1176 — live historical head c7bfda8df75bf95d6c702aeb865e2505b119207b, all5 checks green; merge https://github.com/CodexCoder21Organization/BuildTestEmbedded/commit/8d8e13a56a2bc99da7407008d5fd73e32cfb9ade is an ancestor of current main. No action needed.

All43 historical satellite heads below, including the two run10 branches, were reread with ls-remote around 05:08 UTC on 2026-10-09; their heads were unchanged. KEEP every satellite until content comparison; no PR/branch was closed. Proven legacy/retry/static scenarios are carried into source or retained as evidence; unexecuted drafts are preserved without ready claims. Evidence branches never belong in the implementation diff.

BuildTestEmbedded branch Live head SHA Contents / recommendation
fix/release-conclusively-failed-reservations 1efee264c5b99c401b1d7ab3f544b6675d5aa4ef OPEN current source; proven wake/legacy/retry corrections and main integration; gates pending.
wip/L44-admission-api-evidence 8004e087a13246c18a862ffa9e3091c098a5f06b Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-contract-reproducers 0fa4b086c2d89b1efdd7a407a480907c2503d381 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-current 9b7583d4d5e5bd07b5d9a011738ef1cdc6c18a5c Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-evidence 99aaef16a887803302f406fb4b6052647a053989 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-evidence-fifth 0eab9b9285c5d84987426c3f23a6709a2debfac4 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-evidence-fourth 3c75943118a60e22694da4c0c8d4c06390e7fff8 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-evidence-run8 0258272d0c03f72172bc0233f29da844e1d09a6e Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-evidence-run9 8f509e04a480605f1cb0e458923e27b5e7a5dfc8 Run9 raw proofs, four-shard verdicts, patches, reviews, complete inventory and portable resume; KEEP, never merge.
wip/L44-admission-evidence-second d2efac3594c8c00ac4e46aa85e4e8c976cad99b0 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-evidence-sixth b20341cfd1562c12f8e4d921698eb5d4f636b3ee Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-evidence-third 80507a82fba4d1a8216948475c98095962a3d473 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-integrate-312 a085818d75c4afc953a2ddd95abef3760790c529 Unresolved old integration superseded by resolved current source; KEEP provenance until comparison.
wip/L44-admission-integrate-main0ceb b3e4d0b13cb42a861c28c1e3dd0d2eadb3cb9bc9 Corrected NEW retry fixture salvaged into current PR; KEEP baseline provenance.
wip/L44-admission-integration-run8 abee0549d92f3035b66bf66178ba0775dbb842d3 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-multi-id-accounting 88017af9d5348b82a0f12634462df23e3a07ae39 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-rebase4 0df30d17c70ab80e52064342debd3443f8457f23 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-rebased 41d73e5080c43cd63a3269fe8bc5ff83bef11fab Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-run5 222f840e1b464c3fedba9db40f9dcefeeed972f3 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-run6 41ff56e2f10c84e9ee3f0af810c361086004ce41 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-static-integrated 92341484277357a13666db778bcd6016968eae50 Approved cleared-field/detail-history correction carried into source; KEEP proof.
wip/L44-admission-third 4f990d718566f6a78a95ceb504c9d9ef07ce3cbf Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-verified-run5 e7855c960556b997fa5501659ba371ad5086af02 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-admission-watchdog-reaper-ordering 7add0d4c38af49a19ded65c2e3d6d664a42f28e4 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-baseline-corrected 4f990d718566f6a78a95ceb504c9d9ef07ce3cbf Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/L44-cleared-static-contract 72f770d64760d3296adda1129b52bafe9c496fd1 Approved cleared-field/detail-history correction carried into source; KEEP proof.
wip/L44-legacy-release-fix-main0ceb 815261008872575dc090b28c8b266e5f81f6fc5a Legacy correction salvaged into current PR with fresh first-pass proof; KEEP provenance.
wip/L44-legacy-release-fix-run8 d731e19cd34030af56c88f842cc20016ae56782f Legacy correction salvaged into current PR with fresh first-pass proof; KEEP provenance.
wip/L44-static-cleared-fix 7f9744ced318f5af958f0b1f99e714e91d7bfd04 Approved cleared-field/detail-history correction carried into source; KEEP proof.
wip/bte-admission-2026-10-02 121cba6962edcc1abb3df44c7bd49fa2311ad6e8 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p12-1130-fix-2026-09-29 d0af86bbde96a197f9766a3ab97e88d7629ab008 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13-1130-evidence-2026-09-29 1076a170edd32aeeea606b9572b3c1b63c6035f5 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13-1130-fix-2026-09-29 54d18c9cd8e0fa38eeb446811e55166f41afe62e Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13b-1130-continue-2026-09-29 e160e8bac83375d528ffc35e225209551d088358 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13b-archived-cleanup-2026-09-29 e176f03af812e5d981ab3d56051c1c630c442fcd Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13b-evidence-2026-09-29 4d1c48e732eaa0540dd67f24c0e2c2884c9b0fc4 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13b-partial-test-2026-09-29 b7bebcfc04a11bd8c7ca0e04bcc01f9953715888 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13b-startup-migration-2026-09-29 b22477007498ae0404eb768d4090b11fe50edcd7 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13c-1130-continue2-2026-09-29 ecfca9a74dc1e8e16ea4cc8f75f4db21c3b58410 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p13c-evidence-2026-09-29 2b013f0f1c50f488366f9e0956dbe4754b47cfd0 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.
wip/p2-1130-adversarial-2026-09-29 20e0436a87fae92961b439c8d53e0fbf175e94f8 Historical checkpoint or evidence; KEEP until content comparison; never merge evidence.

| Other actor admission draft | d42d54ace6dc4f2ff29d6c72e9f322a020fb698c | OPEN; five FAILURE checks; overlaps accounting. Do not touch. | | Merged repair | 08a516c0a87d64872d7a86ac5923b057f069dc50 | MERGED; five SUCCESS checks; ancestor of main. Preserve; no lane action. | | Merged repair | e7c5d51bf80bb3140ac73598fd883c11bdb2bdc9 | MERGED; five SUCCESS checks; ancestor of main. Preserve; no lane action. | | Merged repair | f45b98eb6b6e54130879648ed66fb8b218666428 | MERGED; five SUCCESS checks; ancestor of main. Preserve; no lane action. | | wip/L44-run10-watchdog-fix | 9c0d2b90e77fc7a1212a6d7a890750ec61230bf0 | Candidate and unchanged reproducer: compiled, then 0/1 scenario passed with 3/3 fixture failures. KEEP; not ready to merge. | | wip/L44-run10-evidence | f12e0495b44e0191ae8526f7733cdbc9ecf48c91 | Current CI classification, raw failed attempts, main comparison, overlap record and complete rebased source patch. KEEP; never merge evidence. |

| wip/L44-run11-watchdog-fix | cf95ec2c53d934525fa570fbfd5ac3a6de4330bb | Rebased candidate plus approved fixture setup; primary regression and two inherited gates PASS first attempt3/3 total. Four inherited gates and remaining fixes still pending; KEEP, not ready. | | wip/L44-run11-watchdog-baseline | 5e4de22d92e6d87ffdd3cdeb419ce77be64e6219 | Same approved fixture on unrepaired watchdog, based on main b865c4a8. Expected missing-unit failure3/3; KEEP baseline proof. |

| wip/L44-run11-evidence | 4e0d3e7cbb2178853bfb27978220445a3508ed2b | Expected baseline3/3 failures, candidate first-attempt3/3 passes, full logs/XML, separate reviews and remaining gates; KEEP, never merge evidence. |

Next steps

  1. Resume from candidate cf95ec2c53d934525fa570fbfd5ac3a6de4330bb and evidence 4e0d3e7cbb2178853bfb27978220445a3508ed2b. Fetch/rebase current main before the next build, preserving the three main repairs. Run the four remaining inherited selectors separately: watchdogDynamicMissingRetirementReconstructsPersistedBoundary; testReleasedUncreatedSlotsWakeQueuedRun; testLegacyReleasedSlotsDoNotBecomeAdmissionDemand; testReleasedShardCannotReenterFreshAdmissionAfterBackoff. The approved setup, old-code3/3 failure proof, candidate primary first pass and two inherited first passes are complete. Do not reopen settled fixture rulings.
  2. Execute or refute the saved repeated-confirmation wake experiment and the newly identified claim-association restart boundary. The latter concerns a valid created-droplet snapshot before its ID is copied into its matching claim-bound unit; it is a source-review concern, not a reproduced defect. See repeated-watchdog-deterministic-boundary.md and claim-association-boundary-review.md in run11 evidence. Never patch from inference alone.
  3. Reproduce remaining capacity failures and five unresolved retry-only mechanisms against current source. Preserve the three landed main repairs above. Record overlapping ownership work for the supervisor; leave the other actor's accounting draft untouched and preserve every inherited assertion.
  4. Complete separate whole-PR test and code reviews, one exact-head remote full suite if admitted, and all required green checks. Before a PR update, check OPEN/overlap, fetch/rebase current main, run required gates, push with an explicit lease and write an honest WHY-first description. Supervisor alone reviews and merges/enqueues/deploys/publishes/completes.

Operational knowledge

Every shell prepends /code/ws/bin. Fresh source checkouts stay inside the lane workspace. Local JVMs use jvm-slot, one selector per acquisition, with memory.current below 4.5 GiB before launch. Put the 1800-second execution bound INSIDE admission, so queue time does not consume it. No full local suite or large fatjar build. Project/test bounds are unchanged. Cancelled pre-admission commands executed zero tests; do not count them as failures or passes. Baseline has three expected missing-unit failures; candidate has three first-attempt scenario passes.

The selected workspace uses real source/support and one unchanged selector per admission. Source scripts use verified JVM coursier; global /usr/local/bin/coursier is wrong architecture. Explicitly fetch main if the clone fetchspec follows only the original PR ref. Check OPEN/overlap before PR push; use an explicit expected lease when no WIP tracking ref exists. No remote run was submitted this invocation. The source WIP and baseline WIP are pinned to exact tested heads; the original PR is unchanged.

All owned test commands finished naturally before finalization. No watcher is running. Handoff report/update may fail in transport; use at most three bounded attempts and preserve identical text on disk. This invocation releases its claim at CHECKPOINT; the next invocation must claim and read the live body. Never complete this handoff from the lane.

Run11 final live verification — 2026-10-09 around 05:23 UTC

  • https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1130: OPEN at 1efee264c5b99c401b1d7ab3f544b6675d5aa4ef, five FAILURE checks. No source branch update by this lane.
  • https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1286: OPEN draft at d42d54ace6dc4f2ff29d6c72e9f322a020fb698c, five FAILURE checks. Another actor owns it; untouched. Its no-create/terminal accounting overlaps the remaining capacity work.
  • https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1350: OPEN at ff7739ca6285a2489a4e27636a77c8a13c0f5bc0, five SUCCESS checks. Another actor owns it; untouched. Its atomic watchdog state/spool writes concern an adjacent persistence boundary, not this admission-unit retirement.
  • Required aggregate check is bld-build in current main rules. No CI rerun, source PR push, merge, enqueue, deployment, publication or handoff completion occurred.
  • Separate test-comprehensiveness and adversarial review passes are saved in reviews-final.md. They support the narrow verified regression but do not approve the whole PR. Two unexecuted public experiments, four inherited gates, remaining capacity/retry classifications, whole-PR review and exact-head full validation are still required.

Run11 admission note

Opportunistic attempts to switch an unstarted command to a free second slot did not gain admission and discarded prior queue positions. Retain the normal queue entry; do not reuse those probe scripts. A prepared workspace may be reused only after its preceding selector has fully ended, with a fresh JVM-slot acquisition for each next selector. The candidate eventually compiled and passed after normal queued admission.

Latest status report

18 reports
Running fable-hq-20261004 4127b3f9 2 minutes ago

Status report — 2026-10-09 05:39 UTC (RUNNING)

Original request: "Work through all open handoffs, delegating to codex/gpt for the heavy lifting, skip any handoffs which are already claimed. Make sure you (fable) do the final review before merging. Use your best judgement to decide how to proceed (handoffs and PRs may be obsolete or low quality or whatever) decide if they should be merged or closed or if anything from them can be salvaged. Drive them to completion. Parallelize with 6 workers who grab work off the queue (not waves). The work on one of the 6 parallel handoffs should be driven to completion before another is started."

🟡 Status: RUNNING. Seven handoffs are now claimed by this session (agent fable-hq-20261004): the six BuildTestEmbedded and kompile-buildscript handoffs each on a codex lane (five relaunched this cycle with fresh rulings), plus a seventh, unclaimed until now, that owns the fix for tonight's buildtest outage. Two Opus lanes are on the handoff-service fix and the outage fix. Nothing on the path to DONE depends on the user. The three deploy recommendations at the end are for your decision only.

Progress since the 05:04 report (the 05:31 cycle ran late because of the disk incident below)

  • Root cause of the buildtest outage, established read-only. The forensic lane finished: the resolver library that connects the buildtest coordinator to the droplet service has a 30 s per-call limit, and when one call exceeds it, the library shuts down the whole shared connection, so every other run's in-flight create or status call, and every object already returned over that connection, dies with "closed instance proxy". The droplet service's SSH-key grant legitimately blocks up to 5 minutes, so one slow-booting droplet kills every other run's provisioning. The coordinator log holds 559 such shutdowns since 16:02 yesterday, 84 percent triggered by the SSH grant. A separate, now-cleared trigger (the droplet service's timer requests to the WebCron scheduler exceeding 20 s) stopped all creation between 04:10 and 05:20. A restart would not help: the coordinator already reopens the connection, and the next slow grant brings the failure back. Two existing PRs by the other active orchestrator address exactly this: https://github.com/CodexCoder21Organization/UrlResolver/pull/1226 (make a deadline fail only its own call) and https://github.com/CodexCoder21Organization/DigitalOceanDropletServiceServer/pull/144 (make the SSH grant asynchronous), both with red CI and untouched for 13 hours and 3 days respectively. Their handoff was unclaimed, so I claimed it and dispatched lane PROV2 (Opus) to prove the mechanism with a fail-first test on main versus that PR's head, classify its 7 failing tests, and prepare any needed fixes on my own branch with a comment on the PR, never pushing to the other orchestrator's branches. Challenge records filed and merged: https://github.com/CodexCoder21Organization/PlanRepository/blob/main/challenges/2026-10-09-0521-buildtest-droplet-provisioning-broken-since-about-00-50.md (a duplicate with suffix -2 also landed because my first filing attempt raced the text file; harmless).
  • The buildtest web API is stale (it reports itself out of date; its run list ends at 01:55), so the "nothing completed since 00:12" picture was partly the stale view: the coordinator log shows two runs completed after 01:49. Still, provisioning is failing for most new runs and no PR has had a required check run end-to-end since.
  • The box's disk hit 100% at 05:20 (2.3 GB free of 309 GB), caught by lane L43's failing selector and confirmed. I deleted the checkouts and build caches of lanes that finished on 2026-10-05 and the dependency clones of finished review lanes: 37 GB free now (89%). All new briefs forbid fresh full clones. Lane L40's one storage failure (archive admission needed 5.37 GB free and saw 4.6 GB) was this incident; it had responded by adding storage margins to 16 test fixtures, which I ruled out as calibrating tests to the machine and instructed it to revert.
  • Five lanes hit their 2.5 h boxes and were relaunched with rulings: L28 (mechanism proven: an interrupted projection reader re-waits on the journal lock the publisher holds, so the interruption is lost; run 5 implements the interruptible-acquisition fix), L49 (two fixture rulings: use the public writable error-message field instead of the read-only label, and select outside the protected tail only with an identity assertion), L43 (fixtures proven both ways, 14 selectors left), L44 (24 assertions preserved, unrepaired watchdog fails 3 of 3, candidate 3 first-attempt passes, four inherited gates left), and L40 (compile proven, storage-margin patch reverted, 17 focused selectors to run with native snapshots). L47 continues toward its 06:16 box.
  • Handoff-service fix https://github.com/CodexCoder21Organization/HandoffServiceServer/pull/30: the implementing lane HSVC3 checkpointed at its box with the code complete; the re-review had closed every code item; follow-on lane HSVC4 pushed the final two nits as head 332604dd at 05:20 and is running the marshaling, proxy, storm and four neighbour tests on that exact head (it correctly noticed the neighbours must be re-run because production source changed since the last neighbour pass), plus the final storm test against both old heads. CI for this head has not dispatched (no check-run exists yet); its watcher will catch the lost dispatch. Enqueue waits on provisioning either way.
  • Merge queues: https://github.com/CodexCoder21Organization/UrlProtocol/pull/647 position 4, https://github.com/CodexCoder21Organization/UrlResolver/pull/1169 position 16; both queue runs will fail on provisioning if they reach the head before the fix lands. https://github.com/CodexCoder21Organization/UrlProtocol/pull/649's second re-requested check failed on the provisioning stall; no further retries.
  • Handoff mirror: the 05:04 report reached all six handoffs; this one goes to seven.

PRs from this session (live-verified 05:37 UTC)

✅ Merged

  • https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1197 (2026-10-05 11:35), https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1236 (10-04 20:50), https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1239 (10-05 02:18), https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1244 (10-05 14:05), https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1248 (10-05 06:52), https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1258 (10-05 13:40), https://github.com/CodexCoder21Organization/BuildTestWui/pull/362 (10-05 12:16), https://github.com/CodexCoder21Organization/PlanRepository/pull/10909 and https://github.com/CodexCoder21Organization/PlanRepository/pull/10910 (challenge records, 05:3x).

⏳ Pending

  • https://github.com/CodexCoder21Organization/HandoffServiceServer/pull/30 — OPEN, head 332604dd; code reviewed clean twice; local re-runs on the final head in progress; required check not yet dispatched; blocked on provisioning.
  • https://github.com/CodexCoder21Organization/UrlProtocol/pull/647 — OPEN, final review clean; merge queue position 4.
  • https://github.com/CodexCoder21Organization/UrlResolver/pull/1169 — OPEN, final review clean; merge queue position 16.
  • https://github.com/CodexCoder21Organization/UrlProtocol/pull/649 — OPEN, final review clean; remote check failed twice on infrastructure; waits for provisioning.
  • https://github.com/CodexCoder21Organization/kompile-buildscript/pull/87 — OPEN draft; L47 producing the candidate head.
  • https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1127 (L43), https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1130 (L44), https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1207 (L49), https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1213 (L40) — OPEN, need rebase, lanes relaunched.
  • https://github.com/CodexCoder21Organization/UrlResolver/pull/1185 — OPEN; waits on protocol 0.0.605 from https://github.com/CodexCoder21Organization/UrlProtocol/pull/637 (other orchestrator).
  • Not mine, under verification by PROV2: https://github.com/CodexCoder21Organization/UrlResolver/pull/1226 (OPEN, remote check 1885 passed / 7 failed, build failing) and https://github.com/CodexCoder21Organization/DigitalOceanDropletServiceServer/pull/144 (OPEN, all-tests failing).

Delegated work at a glance

⏳ Running - GPT 6.1-sol high - 1 hour 52 minutes total time - 5 minutes since last update - Lane L47 run 6 on https://github.com/CodexCoder21Organization/kompile-buildscript/pull/87. Repaired fixture executing under the original bound; diagnostic and negative variants queued; no behavior repair applied yet. Next checkpoint: the verdicts, or CHECKPOINT at 06:16.

⏳ Running - GPT 6.1-sol high - 15 minutes total time - launching/claiming - Lane L28 run 5: finish three current-main bodies, implement the interruptible-acquisition fix at the one blocking primitive, flip the bodies, open the WHY-first PR. Next checkpoint: the mechanism statement and third-body results.

⏳ Running - GPT 6.1-sol high - 15 minutes total time - launching/claiming - Lane L49 run C on https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1207 with both fixture rulings. Next checkpoint: both fixtures proven three ways.

⏳ Running - GPT 6-astra high - 5 minutes total time - launching/claiming - Lane L43 run 13 on https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1127: re-run the disk-failed selector post-restoration, then the 14 remaining selectors. Next checkpoint: first selector results.

⏳ Running - GPT 6-astra high - 5 minutes total time - launching/claiming - Lane L44 run 12 on https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1130: re-claim, four remaining inherited gates, two saved public experiments. Next checkpoint: the four gate results.

⏳ Running - GPT 6.1-sol high - 2 minutes total time - launching - Lane L40 run 13 on https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1213: revert the storage-margin patch, run 17 focused selectors with native snapshots. Next checkpoint: the first held-scenario diagnostic.

⏳ Running - Opus medium - 23 minutes total time - 5 minutes since last update - Agent lane HSVC4 on https://github.com/CodexCoder21Organization/HandoffServiceServer/pull/30: nit head pushed; marshaling, proxy, storm, four neighbours and the two old-head storm runs queued on JVM slots. Next checkpoint: first-attempt verdicts and the filled results table.

⏳ Running - Opus medium - 3 minutes total time - just launched - Agent lane PROV2 on the buildtest outage fix: fail-first test for the connection-shutdown mechanism on main versus https://github.com/CodexCoder21Organization/UrlResolver/pull/1226, classification of its 7 failing tests, fixes on my own branch, one factual comment on the PR. Next checkpoint: the fail-first verdicts.

⚪ Not running (finished) - Opus medium - 10 minutes total time - 11 minutes since last update - Agent lane BTPROV1 read-only forensic: GATE ROOT_CAUSE with the mechanism, evidence, blast radius, existing PRs and the recommendation above. Nothing further expected.

⚪ Not running (finished) - Opus medium - 2 hours 32 minutes total time - 13 minutes since last update - Agent lane HSVC3: implemented and proved the handoff-service fix, closed every review finding, checkpointed; resume steps owned by HSVC4. Nothing further expected.

⚪ Not running (finished) - GPT 6 lanes L28 run 4, L49 run B, L43 run 12, L44 run 11, L40 run 12 - each ended at its 2.5 h box as CHECKPOINT or NEEDS_USER with the evidence summarized above; each replaced by the run listed above. Nothing further expected from these invocations.

Changes since last report: five codex lanes checkpointed and relaunched with rulings; BTPROV1 finished with a root cause; PROV2 launched on a newly claimed seventh handoff; the disk was pruned.

How the fixes work

Handoff service: The service crashed in a loop because each client connection asked for its bytecode and the handler base64-encoded a 2 MB jar plus a 0.7 MB stdlib jar fresh every time, about 10 MB of garbage per request in a 128 MB heap, while a slow consumer left several replies queued unsent. The fix drops the base64 path entirely: the protocol answers the bytecode request itself with a small header plus the jar as one binary attachment that is the same array for every reply, so sixteen queued replies hold one copy and fit both the heap and the outbox ceiling. The deciding test launches the real server entry point in a child JVM with production heap flags, seeds 20 MB of handoff bodies, and has 16 raw wire clients hold their replies unread until the server has answered all of them; it fails on the old code and on encode-once, and passes on streamed.

Buildtest provisioning (PROV2, verifying another orchestrator's PR): One slow call on the coordinator's shared connection to the droplet service makes the resolver library shut the whole connection down, killing every other run's provisioning. The fix makes a per-call deadline fail only its own call and keep the connection and previously returned objects usable, with a second PR making the slow SSH-key grant asynchronous so the deadline is rarely hit at all. The fail-first test holds a returned object in one thread while another thread's call blocks past the limit, then reads the held object: it must return the value, not "closed instance proxy".

Interrupted projection readers (L28): An interrupted snapshot reader re-waits on the journal lock the publisher holds, so the interruption is lost and the reader blocks instead of returning the advertised reset with its cause. The fix makes the reader's lock acquisition interruptible at that one blocking primitive and carries the original cause into the recovery log. Two first-attempt failures on unchanged main are the before-evidence; the same bodies must pass after, and a variant without the interruptible acquisition must fail again.

Blockers

🟡 None requiring the user; one production outage is throttling the pipeline and its fix is now being driven (PROV2). I will not restart production services; the forensic result says a restart would not help anyway. Standing deploy recommendations, your decision only: (1) deploy kotlin-build-ci 0.0.109; (2) deploy the buildtest coordinator after https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1213 lands, and after the resolver fix from https://github.com/CodexCoder21Organization/UrlResolver/pull/1226 is pinned; (3) deploy the handoff service once https://github.com/CodexCoder21Organization/HandoffServiceServer/pull/30 lands and 0.0.28 is published.

Plan changes and self-check

Plan changes: a seventh handoff (the outage fix) was pulled onto an Opus lane because it is the artifact every other PR's required check waits on; remote-suite steps are gated on observed provisioning recovery; fresh full clones are forbidden. Progress is real: a root cause with source-level evidence, five lanes advanced to their next proofs, the handoff-service fix at its last gates. Landing parallelization sweep: on https://github.com/CodexCoder21Organization/HandoffServiceServer/pull/30 all gates but CI are done and CI waits on provisioning; the queued PRs have only their runs left; the outage fix's own gates (fail-first proof, classification) started this cycle. No idle runnable gate.

Next steps: prove and land the resolver fix so CI provisions again, then land the handoff-service fix and publish 0.0.28, watch the queued PRs through, drive the six codex lanes to READY_FOR_REVIEW, review and enqueue each green head, complete each handoff, then pull the next unclaimed handoffs onto free slots.

Top-three lessons learned

  1. When every PR's CI goes red at once, investigate the shared service before touching any PR. Three "distinct" infrastructure failures on one PR and a dead-looking pool turned out to be one mechanism in a shared library; a read-only forensic lane found it in ten minutes from the coordinator's logs and the library source, and found the fix already written in an unclaimed handoff. Retrying checks would have burned the day.
  2. Watch the disk as a shared resource of the lane pool, not per lane. Six lanes each cloning repositories and filling build caches took the box from 91% to 100% in five hours, broke a selector, and tempted a lane into "fixing" fixtures for a full host; check free space every cycle and delete finished lanes' checkouts and caches together.
  3. Reproduce the condition in the dump, not the traffic you imagine. A heap dump showing replies queued unsent names a slow consumer as the trigger; fast loopback clients can never create that state, so a storm test built from them passes on broken code. Read the dump for the condition and force it deterministically; that test rejected a fix that had passed every softer test.

Earlier reports

Running fable-hq-20261004 4127b3f9 10 minutes ago
Running fable-hq-20261004 4127b3f9 15 minutes ago
Running fable-hq-20261004 4127b3f9 39 minutes ago
Running fable-hq-20261004 4127b3f9 39 minutes ago
Show all 17 earlier reports

Add dependency

Complete this handoff

Moves it out of every priority list and into ArchiveArea.