Handoff: Verify required remote CI for the ContainerNursery persistent URL start fix
Written 2026-10-09 09:30:25 UTC. RE-VERIFY: this is a write-time snapshot. Re-check https://github.com/CodexCoder21Organization/ContainerNursery/pull/654 with gh pr view 654 --repo CodexCoder21Organization/ContainerNursery --json state,isDraft,headRefOid,statusCheckRollup,mergedAt; inspect its Actions run and the required remote check before acting. Poll Actions no faster than every two minutes; use build-watchman at its default four-minute cadence.
The user asked for the cnfix2 brief to be completed: reproduce the omitted URL_BIND_DOMAIN on cold persistent URL starts with a real child JAR, fix the common environment construction, preserve startup ownership, complete the listed gates, open a draft PR and verify CI. This lane must not merge, enqueue, mark ready, publish, deploy, restart production, alter test deadlines or weaken tests. The remaining work is to observe the required remote CI once the separately owned service incident is resolved, and report readiness; no merge or deployment is authorized by this handoff.
What was found and done
- ConfigManager updateInMemoryRoute and startPersistentContainerIfCold merged raw JSON instead of calling the facade hook. Request URL starts and boot use applyLaunchEnvInjection, and dependency wakes already use buildLaunchContainerConfig; admin restart only removes a generation. The sole provider createContainer call is in ContainerNursery. Both ConfigManager launch branches now use the existing facade buildLaunchContainerConfig hook. Mapping configuration and lifecycle ownership are unchanged.
- The raw process environment contains localhost.tcp:${PORT}; the service substitutes the numeric PORT. The brief's request stdout showed numeric binding, while the persistent child stdout showed standalone mode and its listed environment names omitted URL_BIND_DOMAIN. Tests assert raw and substituted binding before releasing a real compiled child JAR to bind readiness.
- Four JUnit RPC cases fail deterministically on unchanged main (missing and conflicting bindings for both branches), with the exact canonical binding assertion. An HTTP case verifies preservation, and caller/persisted JSON remains unchanged. Equivalent independent scripts cover both edited branches. Tests use public ConfigManager.updateRoute, real provider, real nursery, real child sockets; no mocks or reflection.
- Fixed gate: 10 fresh first attempts, five cases each, 50/50 passes. Product-only revert: four RPC cases failed again and HTTP passed; restored head passed 5/5. Full Gradle test task: 945/945, zero failures/errors/skips, exit0. Independent test and code review found no remaining correction.
- Source composes cleanly with https://github.com/CodexCoder21Organization/ContainerNursery/pull/653. A combined source branch ran both new scripts, both ownership regressions and 13 lifecycle neighbors, each 3/3 first attempts: 51/51, zero retries/skips/failures. Exact XML and raw log are preserved. Two earlier workflow preparation failures ran zero tests (Git missing before checkout, then shallow rebase); they are not failed test attempts. Final workflow installed Git before checkout and used fetch-depth 0.
- Draft PR is based on main and the final fetch/rebase kept exact source/main unchanged. Commits include the required coauthor and body has the required footer. The PR's Gradle and release workflows run; Gradle CI passed 945/945 first attempts (raw run log), and release package CI passed. Final PR snapshot is OPEN/isDraft=true, mergeStateStatus=BLOCKED, mergedAt=null; the source head is unchanged. Required kotlin.build(remote) has no dispatched run, with suite 102705439797 queued/runs 0. This is an external CI dispatch blocker identified by build-watchman, not a regression failure. Common brief assigns that incident separately; this lane did not warm receivers, rerequest suites, submit remote build runs or inspect production.
Relevant PRs / refs
| Repo |
Branch |
Remote head |
PR |
Contents / state |
| ContainerNursery |
wip/sol-cnfix2 |
a4c45aa84260b96d5d455d9c6523370bbe6414ca |
https://github.com/CodexCoder21Organization/ContainerNursery/pull/654 |
Minimal ConfigManager fix, JUnit/scripts, README; draft open; all local/selected gates pass |
| ContainerNursery |
wip/sol-cnfix2-evidence |
c88212255f98a8a3ccd9e7258090708985288d4d (verified immediately before handoff creation; resolve branch for newer terminal notes) |
no PR |
handoff-artifacts/cnfix2: fail-first logs/XML, all gates, mutation, full suite, review, source patches, PR body, runner scripts, CI watcher, these resume notes |
| ContainerNursery |
wip/sol-cnfix2-composition-evidence |
58884c6649701d6d541349ad4b6a348dfd21b5a2 |
no PR |
Exact combined source tested; ownership selected files plus this fix |
Composition CI: https://github.com/CodexCoder21Organization/ContainerNursery/actions/runs/37908370290 (success). PR Gradle CI: https://github.com/CodexCoder21Organization/ContainerNursery/actions/runs/37909579704. PR release CI: https://github.com/CodexCoder21Organization/ContainerNursery/actions/runs/37909579700 (success).
Deployed/published but unmerged: none. This lane ran local tests and throwaway Actions tests only, never invoked production management or publication commands. No merge/enqueue/ready marking was performed. Build outputs and dependency caches are intentionally omitted from evidence.
Next steps
- Re-verify current PR head/draft state, Actions verdict and required remote check. Watch with
PATH=$HOME/bin:$PATH timeout 1800 coursier launch buildwatchman:build-watchman:0.0.21 -r https://kotlin.directory -- --repo CodexCoder21Organization/ContainerNursery --pr 654 --check 'Build and test with Gradle'. Plain mode observes checks only; never use --to-merged for this lane.
- The separate incident owner must restore/dispatch the missing remote check. Do not infer a product failure from zero test execution and do not rerun tests blindly. Do not alter this fix to handle the CI service issue.
- If incoming main edits do not intersect touched hunks/test paths, keep the completed gate credit. If they do, rerun only affected regressions once after a clean rebase; preserve current tests/deadlines. Before any build fetch/rebase main. Target JUnit with
./gradlew test --no-daemon --max-workers=2 --tests org.example.PersistentUrlLaunchEnvironmentTest; scripts use scripts/test.bash --local --test <scenario>, on an Actions host for multi-test gates.
- When all required checks and Gradle are green, append
READY FOR ORCHESTRATOR REVIEW <PR URL> <head SHA> — CI <Gradle run URL> to findings and report to the orchestrator. Until then record NOT READY with the missing check. User/orchestrator decides any later merge or deployment.
Reusable knowledge
- Raw launch env uses a PORT placeholder; requiring numeric rewriting would change existing request semantics. Verify both raw and resolved values.
- Use explicit conflicting route binding to ensure ambient parent env cannot make an unfixed regression pass.
- Keep async Result until the success await so assertion failures are not replaced by child cleanup failures.
- Gradle is the active repository test workflow; script-only changes do not cover its CI gate.
- Throwaway JDK-container workflows must install Git before checkout and fetch full history before rebase.