← Handoffs

Repository · handoffs

Handoff: Finish reader cancellation ownership checks and implement the completion fix

View on GitHub ↗

id: hf-2026-10-02-reproduce-and-fix-interrupted-buildtest-projection-snapshot-readers url: url://handoff/handoffs/hf-2026-10-02-reproduce-and-fix-interrupted-buildtest-projection-snapshot-readers title: Finish reader cancellation ownership checks and implement the completion fix summary: Implement complete cancellation and ownership handling, then obtain passing gates and a green source PR. CHECKPOINT: six public bodies executed; five proved bugs, one close-contract question; tests and full evidence pushed, no production edits. created: 2026-10-02T19:10:22.869Z completed: null dependencies:

Handoff: Finish reader cancellation ownership checks and implement the completion fix

RE-VERIFY — 2026-10-05T14:06:18.183326+00:00: This is a snapshot. Recheck claims, fetch main, verify branch heads with git ls-remote and PR state/checks with gh pr view before acting. The supervisor alone owns merge, enqueue, deploy, publish and handoff-completion decisions. None occurred in this lane.

Mission

Reproduce and fix interrupted reset-snapshot readers following the owner's 2026-10-02 projection-feed outage request. B1/B2 are already on main through https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1234. B3/B4 still need a complete independently cancellable publication/read path and retained recovery causes. The supervisor ruled that uninterrupted detecting readers keep receiving the recovered reset; preserve that public behavior and the README, with no new API.

What was found and done

  1. Required handoff, PHILOSOPHY, TESTING and CODE_REVIEW documents, full repository README and linked lifecycle documents were read. Ownership and completion hypotheses were re-verified against a fresh own clone. Initial publication and recovery ownership are already merged through https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1187 and https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1189.
  2. Three baselines executed against production main 441a2fcb531323894e6c3130f7ceec3413d4dbaa: recovery cancellation, retained recovery cause, and initial publication cancellation. Each failed deterministically (0 passed / 3 failed). Both cancellation stacks show ConditionObject.await reacquiring the journal lock held by the publisher. The retained-cause assertion expected one initiating suppressed failure and found zero.
  3. A fourth body executed after rebase to main 35563d4f998b72b05503f2fe380a37bf2b138c2c: the late reader failed prompt cancellation while in noninterruptible ReentrantLock.lock inside requireNotAdvertisedResetRecoveryOwner, before either completion wait. Four cancellation/cause bodies failed; the two pre-start experiments below have also executed. Main's intervening change was only the tests from https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1258; src and build.kts match the first three baselines exactly.
  4. The saved latch/cause proposal applies by content, but is now proved incomplete for the earlier public lock acquisition. It has not been applied as production source. Other public availability/startup/page acquisitions after the guard also use the journal lock. A diagnostic prechecked-reader scenario pauses a named public reader after its guard, lets another reader hold recovery commit, then resumes and interrupts it. Root review added a callback-exited signal so it cannot pass by interrupting its setup gate. This diagnostic draft is unexecuted and is not proof.
  5. Seven public scenarios are pushed on the test-only branch: the four executed baselines, pre-start reentry and close experiments, and the saved close-drain scenario. The recovery baseline was strengthened using the existing public before-recovery-staging hook to force Condition wait entry before owner commit. Every previous assertion and bound remains. Pre-start reentry executed and failed: its requesting callback waits for the registered publisher it has not yet started. Pre-start close executed and failed its expectation of immediate refusal: close completed, then the newly started worker aborted for shutdown. All six bodies ran (0 passed / 6 failed); five demonstrate named bugs, while the close-refusal expectation remains unsettled. The README's close refusal covers a callback running on the publisher, while the pre-start hook runs on the requesting reader; assess the experiment before extending the contract.
  6. Earlier runs executed zero bodies: one local acquisition/compilation deadline, one local compiler OOM under the lane-chosen 512 MiB cap, and two remote pre-submission failures (full-clone tar construction OOM including .git/jars; tracked-HEAD export health RPC TIMEOUT before upload). No remote runId was issued, no checks were rerun and no remote resubmission followed. The corrected 1 GiB local launcher compiled and executed all four failures under a stricter memory-below-3.5-GiB admission rule. Test deadlines and counts were unchanged. These preparation outcomes are not behavioral results or a host-overload diagnosis.
  7. Separate root test-comprehensiveness and adversarial review sections are in the full progress record. Both remain open: current-head passing proof, later acquisition cancellation, cursor reads and lifecycle/ordinary-reader neighbors are not verified. No source PR exists and nothing is ready for merge. The lane stops at CHECKPOINT within its time box. All 49 captured runner/tracker PIDs were absent during cleanup; only conversation harness processes and the cleanup command matched L28.
  8. Salvage is preserved: old failing/passing logs, public tests, the complete source proposal, current deterministic failure stacks, the corrected fixture and the lifecycle inventory. Historical proposal results (2/2 passes on old bases) are not current-head gates. No satellite was closed or deleted; keep all older references until the useful material is landed. Full run2 written findings are tracked as diagnostics/L28-run2/progress-record.md because this repository ignores *-findings.md.

Relevant PRs / refs

PR states below were refreshed 2026-10-05T14:02Z; refresh again before acting. WIP run2 heads were verified with git ls-remote at this checkpoint.

Repo Remote branch/ref Head SHA PR Contents and write-time state
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/L28-interrupted-snapshot-reader 3c735db47ac74ca20b3df2692c1b30899bad79ef none Nine public scenarios: seven migrated drafts, proved initial cancellation test, unexecuted late-reader experiment. Test-only WIP, production source unchanged; never open all drafts as a ready PR.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/L28-reader-analysis a31830ec4895f6d918169cbbb146f43530d1610d none Full traces, passing logs, exact remote CLI bytecode, findings, source patch and resume state. Intentional diagnostics, not a source PR.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/interrupted-reader-not-snapshot-damage-2026-10-02 47634515c286379b74e68358790cbdf911ba7de9 none Historical seven drafts, superseded by observer-migrated WIP; preserve until salvage is landed.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/f-bt5b-defect-b-handoff-2026-10-02 b3d2f4a4941e603701a88de1c6bc863fd322310b none Historical improved seven drafts with obsolete constructor. Preserve until salvage is landed.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/L28-run2-public-baselines c49ef726b9ebe28d02bc8672ba1cf3a3169db81d none Current-main seven public tests only; deterministic recovery-staging coordination added; Six public bodies ran (0 passed / 6 failed): five proved bugs plus one unresolved close-contract experiment. Production source unchanged.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/L28-run2-reader-analysis 6aeea72b203eb17a2a01e11cb78695fd69b20752 none Full current-main failure logs, complete progress record, source comparison, reviewed prechecked draft, inventories and unchanged source proposal; diagnostics only.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/resetpub/journal-owned-reset-publication ce3dd64f56cb1b68573ee65aa3530326babccb8d https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1187 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/journal-recovery-publication-owned-by-journal 9d3ce7b6557c1f7de0556072f032aaf620d81592 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1189 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/projection-repair-missing-child-sources-2026-10-02 3a7293e1d73b8a9be56a48d91ec06e8aa84c3042 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1198 OPEN; checked 2026-10-05T14:02Z: 0 green / 5 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/feat/shared-helper-buildmaven-20261004 2f89862024bf38c0d2840bbe9b5470007833df39 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1228 OPEN; checked 2026-10-05T14:02Z: 1 green / 4 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/startup-single-record-pass-20261004 7d1ef210f42f4f378fdcc6543e000013f3dc9a26 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1231 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/feed-authority-stability-20261004 63ce7a14394685147b693d5e7e52bfc35fe933f8 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1234 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/test/deterministic-runner-policy-storage 4db77d73cd2c9f76fa0e8d0d244e6fd31a9349ae https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1235 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/RSV9-admission-reservations ec1f67f0e2295e8342117101e30cc90118a40155 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1237 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/FPCF2-continuous-maintenance-event-gates 4dd5f2731a4f4fff6a106b39a4ff6cbebc219295 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1248 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/SSH1-before-exec-channel-open 321ced9e6ab6712585fd563ed5451852c5f6bb9c https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1249 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/SSH2-preserve-session-on-channel-refusal 4c55b6f794b1dc48fa71a37c8d976f9a82663396 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1250 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/l052-reconnect-publication-ownership 4cfe2b2e761125aa7eb4932efa44cf3f09aae525 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1197 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/snapshot-reader-keeps-its-continuation 781068845ce0ad39a326e0603b09b0bf27308213 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1254 OPEN; checked 2026-10-05T14:02Z: 2 green / 0 red / 2 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/interrupted-reset-requester-caller-local-page 5fd63f2adbd6eb768181826ccfc94af5e8188b71 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1258 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/FLK3-reset-interrupted-callers e47118fc102e31a6e7bb1d93172f907af93a1548 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1252 MERGED; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/FLK8-publication-arrival 8b444953cf0ee4d543a5e410a968f06f505e4413 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1259 OPEN; checked 2026-10-05T14:02Z: 5 green / 0 red / 0 pending. Keep owner's PR; refresh before action.

Historical artifacts: https://github.com/CodexCoder21Organization/PlanRepository/tree/wip/handoff-artifacts-fable-7dd6a506-2026-10-02 (not refetched; preserve). Local experiment SHAs are evidence, not remote source branches. No source PR exists for B3/B4.

Next steps

  1. Recheck live ownership before each update. A foreign live claim means finish current step, push and stop ALREADY_CLAIMED. Do not push to another lane's queued branch or dequeue it.
  2. All six requested bodies are now executed. First resolve pre-start-close behavior: should the preparing caller be refused immediately, or should close complete and abort the pending request without starting a worker after return? The current draft expects refusal, while the README names only running-publisher callbacks. Prefer ownership refusal if the preparer cannot drain itself, but obtain the supervisor ruling before adopting that expectation. Keep all assertions and record the terminal-close public evidence.
  3. Run the reviewed prechecked-reader draft through the public API and add equivalent cursor-read cancellation coverage. Capture the exact later lock boundary, then extend the invariant table and implementation plan. The saved latch proposal alone does not cover the proved early guard wait.
  4. Implement the complete reader/publication ownership fix only after the named conditions have deterministic public failing proof. Keep owner commits independent of caller interruption, retain the initiating snapshot cause, preserve close/drain/reentry behavior and uninterrupted recovered-reset pages. No new public seam, retry, timeout increase or reduced test bound.
  5. Flip the same current-main failing bodies to passing, then run touched tests and the listed close/staging/commit/restart/ordinary-reader neighbors from the exact source head. Complete both independent review passes, fix findings and re-verify. Use remote only under the supervisor's stated health/one-gate rules; otherwise bounded local one selector per invocation. Do not treat old logs or zero-executed runs as gates.
  6. Rebase immediately before opening/updating a main-targeting source PR, check current open overlaps and PR state, and lead its description with the owner's interrupted-reader symptoms and preserved-reset ruling. Footer: "🤖 Generated with Claude Code". Watch every required check with plain build-watchman, never --to-merged. Supervisor review and merge remain the final steps after green checks.

Operational knowledge

  • Every shell starts with export PATH=/code/ws/bin:$PATH. Use a fresh own clone under /code/ws/L28; do not reuse sibling checkouts. cs is the working JVM Coursier wrapper; the repository scripts already use their pinned digest-checked launcher jar. rg is absent here; use the next available search tool.
  • Remote tar construction includes .git and jars; if remote is authorized, export tracked HEAD bytes before invoking it. The two earlier launches never submitted a remote run. Do not retry a zero-executed failure as a debugging strategy.
  • Local runner is run-selector.py in diagnostics/L28-run2. It checks safe memory and slot availability before the existing blocking jvm-slot helper; one selector per invocation, total guard at most 1800 s. Final lane selectors have shorter operation guards to respect the job time box, with all test timeouts unchanged. Kill only recorded PIDs. No full local suite or fat-jar build.
  • Findings: /tmp/claude-1000/-code/4127b3f9-6050-446f-a28d-b0511dacd396/scratchpad/hq/out/L28-findings.md. Append around five minutes, report around twenty, and checkpoint every milestone. Diagnostics are intentional evidence and must stay out of the source PR.
  • Do not merge, enqueue, deploy, publish or complete this handoff. Report-challenge auto-merges and conflicts with this lane's rule; tool friction is preserved in the evidence for supervisor action.