Handoff: Verify the separate expiry fix and settle the PR-added allowance failure before final review
RE-VERIFY: Snapshot 2026-10-04 (L17-opus lane). Query gh pr view https://github.com/CodexCoder21Organization/UrlProtocol/pull/647 --json state,headRefOid,statusCheckRollup and the same for https://github.com/CodexCoder21Organization/UrlProtocol/pull/618; check handoff claims and remote branch heads before acting. The supervisor owns merging, enqueueing, deployment, publishing and handoff completion.
Mission summary
The original request investigated URL bytecode fetches that failed callers after a transient stream close. The ordinary-relay gossip child-flow-control and compact-buffer ownership changes are in https://github.com/CodexCoder21Organization/UrlProtocol/pull/618. This lane reviews those changes, accounts for historical failed attempts, and resolves the counting mismatch exposed by a PR-added test. The separately assigned BuildTest detailed-result projection work is excluded.
What was found and done
- Expiry fix PR is open: https://github.com/CodexCoder21Organization/UrlProtocol/pull/647 (branch
wip/L17-expired-positive-write-budget, head 1e6ecd83768fb9b1244e41ea14d5cc380f62cbeb, based on main 004d87381653774a37c24821e393b5a5cf1b0ab0). Three commits: a1e6ec53 adds tests/testExpiredPositiveWriteBudgetCannotUseZeroWaitAdmission.kts (public writer, real TCP, held root event loop, deterministic expiry ordering); 115bc767 adds allowZeroWaitAdmission to the private tryWriteOnEventLoopIf, derived once from the caller's original maxWaitMs == 0L in writeFramedBufferWithBackpressureImpl and passed to all four helper calls. An expired positive budget now returns RETRY and the existing recovery path drops and releases the frame. 1e6ecd83 applies review round 1: allocator-level leak assertions (UnpooledByteBufAllocator.DEFAULT usedHeapMemory) replace vacuous refCnt checks, adds tests/testExpiredPositiveWriteBudgetCannotJoinCompactLaneAsZeroWait.kts (expiry at the compact-lane join call site), documents the read order each test depends on, asserts the full budget was spent, and moves the helper KDoc onto tryWriteOnEventLoopIf. No timeout, budget constant, iteration count or existing assertion changed; README unchanged (public contract unchanged).
- Verified locally (OBSERVED): with the production file at main, BOTH expiry tests FAIL on their zero-wait admission assertions; with the fix but the expiry-drop
buf.release() removed, BOTH FAIL on the allocator assertion (Expected <4194304>, actual <4259840>); on head 1e6ecd83 both tests plus 45 neighbouring writer/admission/compact-lane/fan-out test files pass: ALL TESTS PASSED (49/49). An independent review (production change clean) is at the supervisor scratchpad out/L17-review-findings.md; its four findings were applied in 1e6ecd83. The full local suite was NOT run (6 GiB host ceiling); branch CI is the whole-suite gate and the PR says so.
- Branch CI on PR 647: see the CI status line at the end of this section (updated by the lane when build-watchman exits).
- Historical classification of PR 618's failures (unchanged): 23 failed attempts / 17 names. One name has a failed main record, with only original attempt 1 matching its assertion. The remaining 16 names / 21 attempts have NO RECORD AVAILABLE. No PR-caused classification is proven. The main selector run 1d867c5e executed zero tests, so it is not classification evidence.
- T1 remains open: PR-added testYamuxRelayChildCompactAllowanceReleasesOnEveryExit failed its exact root bound in run 561baac1 attempt 1. The expiry defect fixed by PR 647 is a matching candidate mechanism, but no causal attribution of that historical Yamux failure is claimed. Its later passing attempts cannot erase the failure.
- PR 618 was not modified by this lane. PR 618 remained OPEN at 60568412c096c6796f12be17c3defd33235874c3 as of the previous snapshot.
CI status (PR 647, head 1e6ecd83): bld-build PASS, bld-all-tests PASS. kotlin.build (remote) shows FAILURE ("2338 passed, 0 failed, 2338 total; 28 passed only after retry"), but GitHub concluded it before buildtest run https://buildtest.kotlin.build/run?id=bd4e431d finished. That run's coordinator log says every test had an authoritative result at 18:11:05 UTC. /api/runs then stayed at status=TESTING, 2221/2338 passed, 0 failed, from 18:47 to at least 19:48 UTC (outOfDate=true), and the per-test attempt history is unreadable, so the 28 retried tests are unnamed. NEXT: once bd4e431d reaches a terminal status with testsFailed=0, re-request the check once (gh api -X POST repos/CodexCoder21Organization/UrlProtocol/check-runs/111487356089/rerequest) and watch it. If it shows real failures, record and fix them at their cause.
Relevant PRs / refs
| Repo |
Branch / PR |
Remote head |
State and contents |
| UrlProtocol |
https://github.com/CodexCoder21Organization/UrlProtocol/pull/647 ; https://github.com/CodexCoder21Organization/UrlProtocol/tree/wip/L17-expired-positive-write-budget |
1e6ecd83768fb9b1244e41ea14d5cc380f62cbeb |
OPEN; expiry fix + two fail-first tests; review round 1 applied; local targeted 49/49 pass; awaiting supervisor final review |
| UrlProtocol |
https://github.com/CodexCoder21Organization/UrlProtocol/pull/618 ; https://github.com/CodexCoder21Organization/UrlProtocol/tree/fix/relay-gossip-large-frame-child-flow-control |
60568412c096c6796f12be17c3defd33235874c3 |
OPEN; bld-build green; other required checks pending; retain existing changes |
| PlanRepository |
https://github.com/CodexCoder21Organization/PlanRepository/tree/wip/L17-expired-positive-wait-evidence |
21d57103766024c1c985ea33e5fcd330c1cf480a |
Current-main reproduction, complete historical matrix, source compile logs and findings; preserve |
| PlanRepository |
https://github.com/CodexCoder21Organization/PlanRepository/tree/wip/L17-failed-attempt-classification |
b8ee2be8be920372af6615d22034b64587db7c73 |
Prior two invocations' records, standalone probe and reviews; preserve |
| PlanRepository |
https://github.com/CodexCoder21Organization/PlanRepository/tree/wip/p618-verification-evidence-2026-10-04 |
d13671fa502a68e57187817c4f0903437bf9de20 |
Original stacks and attempt-authority records; preserve |
Next steps
- Re-verify PR 647 and PR 618 state first. Do not submit extra remote runs while buildtest provisioning is degraded.
- PR 647: if the head changed since 1e6ecd83, re-run reviews against it; otherwise proceed to the supervisor's final review and merge decision. If
kotlin.build (remote) failed for an infrastructure reason, it was re-requested at most once; record and escalate rather than re-running blindly.
- Settle T1 with a deterministic public-API Yamux test of the suspected expiry condition on top of PR 647; if evidence points elsewhere, pursue that mechanism. Keep the 64-unit assertion and existing test parameters.
- Complete written reviews of PR 618; correct the comment saying original child buffers enter the root handoff, since the implementation copies them.
- Supervisor decides integration order of PR 647 and PR 618 and the final merges. Do not merge, enqueue, deploy, publish, release or complete the handoff in a lane.
Operational knowledge
Use PATH=/code/ws/bin:$PATH; cs and handoff-cli wrappers work. Scripts use clone-local jars/coursier. Only small source compiles / targeted tests are allowed locally; no full local suite or fat-jar build under the shared 6-GiB ceiling. The source probe compiles unchanged main Libp2pHostFactory.kt plus FrameAdmission.kt against published 0.0.603 support dependencies, with those source classes first on the runtime classpath. It is not a whole-repository build.
Required reading completed: PlanRepository handoffs/README.md (Format, Triaging handoffs), DocumentationRepository PHILOSOPHY.md, architecture/TESTING.md, CODE_REVIEW.md, and fresh clone READMEs. Neither fresh clone has AGENTS.md. The README's legacy enqueue flow is overridden by this brief's no-enqueue rule and central handoff CLI. All prior branches are evidence worth retaining; no satellite is recommended for deletion.