Handoff: Finish the single reply reader gates and the resolver pin after upstream publication
Written: 2026-10-04T16:21:07.229396+00:00. This updates the workstream started 2026-10-02.
RE-VERIFY: All state below is a write-time snapshot. Before acting, run handoff-cli claims/get for this id, gh pr view <full URL> --json state,headRefOid,mergeStateStatus,statusCheckRollup,mergedAt, inspect mergeQueueEntry, and git ls-remote for each branch. Fresh queries win. No merge, enqueue, publish, production deploy or handoff completion was performed by this lane.
Mission
The original request was to finish the UrlResolver single reply reader fix and open its unmerged PR. Sandboxed clients in https://github.com/CodexCoder21Organization/HardwareControlFabricWui/pull/3 and https://github.com/CodexCoder21Organization/GithubProxyWui/pull/12 reported Inbound JSON frame exceeds the single-frame wire limit: frameBytes=2065855077, maxFrameBytes=10000000. Exactly one reader must consume each response input across plain and sandboxed connections and all configurable resolver constructors.
The upstream scope decision is made: an optional UrlProtocol ownership API is permitted in a linked PR. The old blocked reason has been cleared. Supervisor owns every merge, queue entry, publication and deployment decision.
What was found and done
- The earlier deterministic real-transport guard reproduced two simultaneous reply readers 10/10 times on unchanged resolver/protocol source. Provider stream creation started its automatic reader, then the resolver started its persistent dispatch reader on the same input. The fail-first record and full stack remain on the resolver WIP branch. This lane inspected that reproducer and the corresponding ownership API rather than treating the old handoff as authority.
- Protocol lets callers select immutable CALLER ownership before stream creation; optional interfaces preserve legacy automatic defaults. Provider/TCP public openings and built-in wrappers preserve ownership, and close stops the selected reader once. Resolver selects CALLER before dial, guards ownership before reading and closes rejected streams while preserving cleanup errors.
- A separate held real peer-exchange reply proved that an independent runBlocking bridge did not respond to owner cancellation. Resolver now uses runInterruptible for that bridge, keeping existing deadlines. The recorded fail-first commit is https://github.com/CodexCoder21Organization/UrlResolver/commit/aa15351b797bd9ade3481dd29e4cdda4622c6363.
- Protocol was rebased on main 004d87381653774a37c24821e393b5a5cf1b0ab0. Only build.kts version text conflicted; it retains unpublished 0.0.605. Four ownership scenarios passed 4/4. Original clock scenario passed 1/1 on the rebased source and 1/1 on current main; those passes do not prove the timing test reliable. Independent retrieval of https://github.com/CodexCoder21Organization/UrlProtocol/actions/runs/36809388075 confirmed the identical timer assertion failed on older main 78deea8c61311e47596dad9c99b72763292e70e8. Reader changes do not modify that reconciliation code or test. Existing https://github.com/CodexCoder21Organization/UrlProtocol/pull/642 addresses its queued-event-loop ordering; keep it separate, and review its red remote gate.
- The resolver Actions failure at 1134b802 was a test failure, not a compile error: stressTestFreshJoinWithdrawalDeliveryUnderConcurrentReannounce failed one of 48 trials, wave 4 pair 6 initial announcement SETUP_MISS. That unchanged test uses CPU spinners. This lane did not run artificial CPU load or weaken it. Existing https://github.com/CodexCoder21Organization/UrlResolver/pull/1176 replaces those spinners and adds a deterministic one-frame transport contract test while retaining counts and deadlines. Its relationship to this particular SETUP_MISS is unproven. https://github.com/CodexCoder21Organization/UrlResolver/pull/1177 fixes a different withdrawal-echo mechanism; do not assume it explains an initial announcement miss.
- Protocol slim buildMaven succeeded locally at 0.0.605, artifact SHA256 b9216ce87eb43a96e4a351b6efdc52cb85a60f70072924fff0be7b62e6a30e8b. No publication. Resolver source built against that artifact; seven reader scenarios, seven requested RPC neighbors, held-reply cancellation and injected gossip/RPC passed 16/16 in small batches. All local repository/pin changes were restored before pushing; review head 8c00203b41d8e51f83647f354902680d0e6e0ec8 changes only the removal of investigation Markdown.
- Dedicated test-comprehensiveness and adversarial code review passes are recorded separately in the lane findings. No changed reader-source blocker was found. Review found investigation Markdown in source PRs: protocol notes were preserved remotely and removed from its review head; resolver notes were also preserved and removed from its review head. No test/assertion/timeout/iteration count was weakened or disabled.
- Fresh required CI is pending: protocol bld-build passed, bld-all-tests runs, and remote https://buildtest.kotlin.build/run?id=ba799e13 awaits scheduling; resolver fresh build and remote https://buildtest.kotlin.build/run?id=b18f4b87 are in progress. The plain build-watchman stopped at its 1200-second tracked deadline, exit 124, with the protocol remote still queued. It was not deleted or rerequested. No remote run or check rerequest was submitted: this invocation was explicitly instructed not to submit while buildtest cannot create workers. Historical result pages returned HTTP 503 before completion: resolver first 500/1889 rows had 362 incomplete-execution failures, 137 passes and one pending; protocol first 2000/2318 passed but reconciliation was pending. These partial rows are not full-suite counts or a readiness proof.
Relevant PRs / refs
| Ref |
Remote head / artifact |
Write-time state and recommendation |
| https://github.com/CodexCoder21Organization/UrlProtocol/pull/637; https://github.com/CodexCoder21Organization/UrlProtocol/tree/wip/rpc-stream-reader-ownership |
51ef040b4359f3b0d17cfdf59634bcb84efde7ee |
OPEN, rebased; bld-build SUCCESS, bld-all-tests and remote IN_PROGRESS, informational NEUTRAL. Keep; description opens with original reason. |
| https://github.com/CodexCoder21Organization/UrlResolver/pull/1185; https://github.com/CodexCoder21Organization/UrlResolver/tree/fix/rpc-stream-single-reader |
8c00203b41d8e51f83647f354902680d0e6e0ec8 |
OPEN; fresh bld-build and remote IN_PROGRESS, no bld-all-tests yet. Keep and finish gates; still pins published 0.0.603. |
| https://github.com/CodexCoder21Organization/UrlProtocol/pull/642 |
1feb64a0d62ea01930393e37d610aa3b5fd06c88 |
OPEN, Actions green, required remote failed. Separate existing clock correction; keep, do not duplicate. |
| https://github.com/CodexCoder21Organization/UrlResolver/pull/1176 |
efa2f3547e991dd648d91de69883962747d196ac |
OPEN, bld-build and remote failed. Separate fresh-join test-methodology correction; keep for its owner/supervisor review. |
| https://github.com/CodexCoder21Organization/UrlResolver/pull/1177 |
9949c330f46c6362b7f70e48405afa5361d8ddaa |
OPEN, bld-build SUCCESS, required remote FAILURE; different withdrawal-echo repair, not modified by this lane. |
| https://github.com/CodexCoder21Organization/UrlProtocol/tree/wip/L24-protocol-reader |
f990715a632d8b994d35c41af28d6ec4dc3cb18e |
Pushed/verified rebase checkpoint including old evidence; keep until work lands. |
| https://github.com/CodexCoder21Organization/UrlResolver/tree/wip/L24-resolver-reader |
1134b802bea243ab09ed24fb7ded50af7ef77a04 |
Pushed/verified source/evidence checkpoint; keep until work lands. |
| https://github.com/CodexCoder21Organization/UrlProtocol/tree/wip/L24-protocol-evidence |
63d2b340a48e8eef090c9810592ee55c6bbab499 |
Pushed/verified stacks, local artifact recipe, two review passes and 16/16 local downstream summary. Evidence only; no merge PR. |
| https://github.com/CodexCoder21Organization/UrlResolver/tree/wip/rpc-stream-single-reader |
1134b802bea243ab09ed24fb7ded50af7ef77a04 |
Earlier complete source/evidence checkpoint; keep until work lands, then archive duplicate. |
| https://github.com/CodexCoder21Organization/UrlProtocol/tree/wip/hfReader3-reader-rebase-baseline |
67134e49b03113a5953b2e1ff69824066a22290b |
Earlier rebase baseline; preserve fail-first evidence until related work lands. |
| https://github.com/CodexCoder21Organization/UrlProtocol/tree/wip/hfReader3-reader-rebase-fixed |
7d3352855572563d42e5fa020b1e78bb96e27bcd |
Earlier fixed source checkpoint; superseded by current rebased PR, archive after merge. |
| Served foundation.url:protocol:0.0.603 |
SHA256 6afcdd4b01ee0fc83035912c917de6dbc8bc1b18f97e9f4133c98094929e946d |
Downloaded and rechecked here; prior source 760676789f753cc4278ab5482c76ae13f471a751 is still unmerged. Do not republish it. |
| Local-only foundation.url:protocol:0.0.605 |
source f990715a; SHA256 above |
Built outside clones, not published, no deployment. Supervisor publishes only after upstream merge/review. |
No PR was closed. Earlier UrlResolver https://github.com/CodexCoder21Organization/UrlResolver/pull/1146 remains excluded by the brief; this lane did not act on it. Earlier protocol https://github.com/CodexCoder21Organization/UrlProtocol/pull/644 is merged into the main used here; its old 0.0.605 reservation description is stale. Lane labels in older evidence are prior-session identifiers, with no runtime meaning and no place in source/PR text.
Next steps
- Re-verify current claims, PR heads, main, queue membership and all required checks first. Never push a queued or merged PR branch; never remove another owner's queue entry. Stop if a foreign live claim owns this handoff.
- The local 16/16 gate, restoration of every temporary local pin/repository, support-file cleanup, motivated descriptions and lease-protected source pushes are complete. Preserve these checkpoints. Rebase again only if main advances; do not repeat the already-proven reader diagnosis unless new source changes warrant it.
- Obtain exact-head full-suite and required CI verdicts once the supervisor allows remote work again. Required protocol gates are bld-build, bld-all-tests, kotlin.build (remote). Use bounded build-watchman plain mode. Do not rerequest a test failure; no blind reruns. Diagnose any newly observed defect with deterministic public tests first.
- Supervisor should review the separate clock correction and fresh-join methodology PRs with their owners; neither is green. The older main clock failure is proven pre-existing. SETUP_MISS remains unclassified; do not call host load its cause or weaken that test.
- After upstream gates and supervisor review, supervisor merges/publishes protocol 0.0.605. Then update resolver build.kts, the fifteen current 0.0.603 capability test pins/adapters and README to foundation.url:protocol:0.0.605, rebase, run full remote suite before pushing this shared dependency change, and complete downstream gates/review. Never commit a local repository path.
- Supervisor alone makes final merge, publication, production rollout and handoff-completion decisions. This lane does none of them.
Operational knowledge
- Fresh clones are /code/ws/L24/UrlProtocol and /code/ws/L24/UrlResolver. Evidence worktree /code/ws/L24/ProtocolEvidence. Findings/report files are in /tmp/claude-1000/-code/4127b3f9-6050-446f-a28d-b0511dacd396/scratchpad/hq/out/L24-findings.md and L24-report.md.
- Export PATH=/code/ws/bin:$PATH. cs is the working JVM launcher. These scripts use clone jars/coursier, so an ignored executable shim runs java -jar /code/ws/bin/coursier.jar; no shim or output JAR is committed. Maintain the first-line KotlinBuildScript marker.
- Local artifact recipe: https://github.com/CodexCoder21Organization/UrlProtocol/blob/wip/L24-protocol-evidence/investigation/L24/local-artifact-verification.md. WithRepository on build.kts does not set MavenPrebuilt2 dependency repositories. Test custom repository lists also need the normal public repositories; they replace defaults.
- gh run view --log-failed returned empty; gh api repos/<owner>/<repo>/actions/jobs/<id>/logs recovered full stacks. gh pr edit uses retired projectCards on this host; update PR bodies with structured REST PATCH JSON instead.
- Paginated buildtest results use page/limit and totalCount; offset is rejected. A failed page/503 is missing evidence, never a pass. Do not submit remote runs in this invocation.
- Handoff format/triage standard: https://github.com/CodexCoder21Organization/PlanRepository/blob/main/handoffs/README.md, especially Triaging handoffs and Partial work belongs on a remote branch. Reviews relied on https://github.com/CodexCoder21Organization/DocumentationRepository/blob/main/PHILOSOPHY.md (reproduce before fixing, honest concurrency), https://github.com/CodexCoder21Organization/DocumentationRepository/blob/main/architecture/TESTING.md (public API, deterministic ordering), and https://github.com/CodexCoder21Organization/DocumentationRepository/blob/main/CODE_REVIEW.md (Claims That a Host Is Overloaded, Work-in-Progress Support Files). Host load is a symptom, not an explanation.
Lane terminal state
CHECKPOINT under the explicit no-remote/full-local-suite constraint. Supervisor must obtain remaining gates, review linked test fixes, merge/publish upstream only after approval, apply the permanent 0.0.605 resolver pin and complete downstream review/CI. No all-green claim is made. No PR or branch was closed. No other handoff was changed. Local build outputs are deliberately omitted from remote source/evidence; rebuild them from the verified checkpoint and recipe.