← Priority list
Blocked

Finish UrlResolver round twelve after registry and clock-ownership decisions

Finish direct registry refresh after an authorized upstream notification API and artifact, and agree the cleanup probe clock-ownership gate before updating the PR branch. Partial fixes and all evidence are pushed at72f883164; corrected selectors pass88/88; PR remainsOPEN at32eb4905.

The phase does not authorize the upstream registry notification artifact; the unchanged cleanup gate conflicts with caller-owned discovery.

Handoff document

Markdown

Handoff: Finish UrlResolver round twelve after registry and clock-ownership decisions

Written 2026-10-07 08:18:53 UTC; lane fx1205r.

RE-VERIFY: All live state here is a write-time snapshot. Recheck https://github.com/CodexCoder21Organization/UrlResolver/pull/1205 with gh pr view https://github.com/CodexCoder21Organization/UrlResolver/pull/1205 --json state,headRefOid,mergedAt,mergeStateStatus,statusCheckRollup, and verify both branch heads with git ls-remote origin refs/heads/work/fx1205r-round12 refs/heads/work/fx1205r-corrected-probe-baseline. The supervisor makes all merge decisions. Do not enqueue, dequeue, merge, deploy, restart, publish without explicit scope, or spawn agents under the original lane rules.

Mission

The user asked to close the round-eleven re-check's three findings on https://github.com/CodexCoder21Organization/UrlResolver/pull/1205 (round twelve), carry the review tests, push the PR branch, add a Review round11 paragraph via REST PATCH, and stop. Baseline32eb4905 fixed the intermittent testOpenPersistentRpcConnectionWaitsForGossipWhenNoCandidatesFound by reselecting a pooled parent that physically closed before child publication, once within its remaining budget. Earlier rounds added parent, ownership, cleanup and configured-clock guarantees.

The stated gate is not satisfied in the authorized scope. The partial implementation and all evidence are pushed; the PR branch remains unchanged at32eb4905. Decision dependency: url://handoff/handoffs/hf-2026-10-07-decide-urlresolver-registry-notification-scope-and-caller-clock-test-ownership . It is blocked on an upstream registry notification API/publication decision and agreement about the carried cleanup probe's clock expectation.

Findings and completed work

  1. The mechanism of the missed registry wake is that getPeerRegistry() exposes the upstream final PeerRegistry directly, while its add/address-change paths offer no listener and never call the resolver refresh publisher. The evidence is the public Clock-boundary registry probe failing at32eb4905, the registry API declarations for pinned protocol0.0.551 and published0.0.603, and inspected UrlProtocol main7b3f99062226f5108cce2e267ee4f58cbc0bb918. No upstream code was edited or artifact published. Resolver-owned peer admission already used the helper; added helper calls cover local registration/unregistration, accepted active-query records, gossip records, withdrawal/restoration, address changes, pruning and removals. The local-registration public probe passes5/5. Direct caller registry mutation is unresolved. Do not replace its notification contract with polling or tell callers to avoid the supported registry API.
  2. The mechanism of the expired return is a configured clock callback advancing time during a final cleanup read after the deadline task has been cancelled, while that read returns its earlier sample. The original carried test failed at baseline with an expired PersistentRpcConnection returned. The partial fix completes the callback-capable cleanup sample, takes a decision sample when needed, and checks it with the terminal latch under publicationLock. Budget failure and cleanup suppression retain their existing aggregation. The required carried file remains unchanged, but its next assertion is incompatible with the unbounded public API: after the corrected rejection, it starts a new10,000ms secondary discovery window with deadlineMs=null, and a frozen caller-owned ManualClock cannot expire it. The fixed-1 trace parks at that exact wait. The additional ownership-correct public probe advances that separate window itself, waits on the real asynchronous child-close future using the existing5s bound, and verifies the complete budget-error text and closed recovery resources. It failed against baseline and passes5/5 with the partial fix. It does not replace or modify the required carried file.
  3. The mechanism of the controller left pending is using streamResult.thenAccept on a returned CompletableFuture which the caller can complete, cancel or change. The partial fix records the attempt's publication claim under publicationLock and uses an attempt-owned publication signal; failure/cancellation settles the controller, and an externally supplied pending stream value does not claim that attempt's publication. Public probes cover exceptional pending completion, successful pending completion with another real stream, and changing an already completed stream promise to failure. All pass5/5 after failing baseline. The uncarried review probe's immediate isDone assertion was corrected to await the actual public controller within its existing5s bound: the real binding's negotiated marker fires before its transport thread returns/installs the composed future. The local-registration probe's request counter was corrected to count its newly selected local handler. These fixture corrections and all intermediate failures are recorded; no bounds or iterations were relaxed.
  4. All six round-eleven guards and the original gossip test pass3/3. The exact positive gate passes27/27 once. Eight new/corrected probes pass5/5, for88/88 total executions in the final corrected partial gate. The test-bearing head was325d6c29368b439e36e9fc117efdd2ab1b3ea383; final artifact-only head72f883164 has identical src029ccc805a704c7c0b16289a0b93735489be12aa and testsfdd896c9a93833015fe1ee07b6f7546d14d8e532 trees. No more test batches or CI re-runs were launched.
  5. The three required carried files remain byte-for-byte unchanged. testBoundedSecondaryDiscoveryUsesManualClockBudget and testClosedReplacementChildFailsBothPublicPromisesBeforePublication already pass at baseline, contrary to the literal all-new-tests-fail premise. testFinalCleanupClockCallbackCannotPublishExpiredRecoveryResult demonstrates the old expired return but has the post-rejection ownership mismatch described above. testFrozenSecondaryDiscoveryUsesCallerOwnedClock covers8 parked opens released by exact close failure or caller advancement to the deadline; it is correctly a baseline-positive contract guard.
  6. The Review round11 paragraph was added to the existing PR by REST PATCH, naming all three findings and required carried tests and explicitly stating that the round is blocked and the PR branch unchanged. Live PR at the stop snapshot is OPEN, unmerged, head32eb4905, mergeStateStatusBLOCKED. Existing bld-build is FAILURE; remote check was IN_PROGRESS at the last read. These are old-branch checks, not confirmation of the WIP code. No CI was re-run.

Remote work and outstanding state

Reference Remote head at write time State
https://github.com/CodexCoder21Organization/UrlResolver/tree/work/fx1205r-round12 72f883164e6d61dbf09079cd88f34cc83d08dc3b Partial fixes, all probes, full XML output, API evidence, writer inventory, selectors, findings and checkpoint; unmerged and not on PR branch
https://github.com/CodexCoder21Organization/UrlResolver/tree/work/fx1205r-corrected-probe-baseline 22e6794b3d416deaa7e20d5afc3d0d23665d231b Corrected probes against unchanged32eb4905 production source, with failing output; no PR
https://github.com/CodexCoder21Organization/UrlResolver/pull/1205 32eb4905ed0e8d8dfb0dd78e46885b4579663403 OPEN/unmerged; body updated, code branch untouched

Deployed or published but unmerged by this lane: none. Production state was not changed. The read-only UrlProtocol checkout is clean at7b3f99062226f5108cce2e267ee4f58cbc0bb918, with no local commits/stash/worktrees needing recovery. Build caches and JARs are omitted deliberately; evidence and scripts are in the remote review-notes directory. Both pushed heads were confirmed with ls-remote. No agents were used.

Exact evidence and resume steps

Detailed observations, full failure traces, invariant/writer inventory, independent review and counts: https://github.com/CodexCoder21Organization/UrlResolver/blob/72f883164e6d61dbf09079cd88f34cc83d08dc3b/review-notes/fx1205r/findings.md . All XML outputs and runnable selector lists are alongside it; fixed-1.xml contains the frozen post-failure discovery thread dump. The runner contains original lane absolute paths, which must be adjusted for a new checkout.

  1. Re-verify the PR, remote branches and decision dependency before doing anything. Clone fresh under the new lane's workspace and read root README (no root AGENTS was present).
  2. Resolve url://handoff/handoffs/hf-2026-10-07-decide-urlresolver-registry-notification-scope-and-caller-clock-test-ownership . Under a new explicit upstream/publication authorization, add a proper registry change-notification API at its owning layer, with public-API tests for additions, service/address replacement, import/pruning/removal, close/re-entry and callback ownership. Publish only when explicitly authorized, then update the resolver dependency and make direct caller registry mutation wake parked opens. The baseline registry probe is already retained.
  3. Agree whether the corrected caller-owned discovery probe is the acceptance gate. Preserve the README clock ownership rule unless the supervisor explicitly changes the public contract. Do not make the unchanged frozen-clock probe pass by adding wall-time polling, retries, sleeps or skipping discovery.
  4. Bring the complete result onto the actual PR branch only after confirming it remains OPEN, fetching/rebasing on latest main, and running the agreed selectors from the exact resulting source. The original gate was three carried plus new tests5/5, six round-eleven and original3/3, positive gate once with counts. Use explicit selectors and scripts/test.bash --local under this lane's brief. Do not run the full suite or wildcard selectors in this phase.
  5. Keep the supervisor's no-merge/no-queue/no-deploy/no-restart/no-publish-without-scope rules, do not modify the other active BuildTest/kompile/ContainerNursery/UrlResolver efforts named in the lane brief, and checkpoint every milestone to a remote branch. Stop at the agreed gate.

Documents and operating notes

Read and applied: UrlResolver README; https://github.com/CodexCoder21Organization/DocumentationRepository/blob/main/architecture/TESTING.md ; https://github.com/CodexCoder21Organization/DocumentationRepository/blob/main/PHILOSOPHY.md ; the pinned re-check https://github.com/CodexCoder21Organization/UrlResolver/blob/d8a14a2727d8d7259990af1d49966fcb19651e65/review-notes/rv1205g-findings.md ; prior fx1205o/fx1205p notes; current handoff skill and central handoff README. Canonical old README merge instructions are retired by the current service skill and also forbidden by this lane; no git handoff PR or merge was created.

Tests use real TCP/libp2p transport, actual public promises, caller-driven clocks and deterministic publication boundaries. No mocks, implementation reflection, timeout increases, reduced iteration counts, disabled tests, retries or added sleeps. A protocol binding's negotiated marker is not necessarily the completion of the public controller future; a returned CompletableFuture is not an immutable internal ownership record; and every new ManualClock discovery window needs an owner to advance it or close the resolver.

No status reports yet.

Add dependency

Complete this handoff

Moves it out of every priority list and into ArchiveArea.