fix(runtime-host): report startup recovery failures - #2906

Merged
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors
Aug 12, 2026
Merged

fix(runtime-host): report startup recovery failures#2906
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors

Conversation

@M4n5ter

@M4n5terM4n5ter commented Aug 12, 2026

Copy link
Copy Markdown
Member
English

Summary

Runtime Host recovery failures could be hidden by shutdown errors, while Candidate election exposed the temporary host_draining state to Desktop, TUI, and CLI. This made an incompatible stored record look like a generic startup failure.

This change preserves the primary recovery error, carries a bounded non-sensitive failure reason through Candidate exit and election, and presents an actionable shared startup message. It does not migrate or accept incompatible stored records; that remains separate migration work.

Verification

  • Reproduced with a real SQLite workspace containing an incompatible persisted message; election returned {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host and the full Runtime Host test suite
  • Typechecks for Storage, Runtime Host, Desktop, and CLI
  • Biome check for all changed files and git diff --check

AI disclosure

OpenAI Codex assisted with the implementation and verification. I reviewed the resulting changes and confirm this submission.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No
简体中文

摘要

Runtime Host 的恢复错误可能被 shutdown 错误掩盖,同时 Candidate election 会把临时的 host_draining 状态暴露给 Desktop、TUI 和 CLI,导致不兼容的持久化记录最终只显示为模糊的启动失败。

本次变更保留首要恢复错误,通过 Candidate 退出和 election 传递有界且不包含敏感信息的失败分类,并统一显示可操作的启动提示。它不会迁移或接受不兼容的持久化记录;相关兼容工作仍由独立变更负责。

验证

  • 使用包含不兼容持久化消息的真实 SQLite 工作区复现;election 返回 {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host 及 Runtime Host 全量测试
  • Storage、Runtime Host、Desktop 和 CLI typecheck
  • 所有变更文件的 Biome check 与 git diff --check

AI 披露

OpenAI Codex 协助了实现与验证。我已人工审核最终变更,并确认提交此 PR。

检查清单

  • 测试覆盖该变更,且在修复前会失败
  • lint、format、typecheck 和受影响测试均在本地通过

此 PR 是否改变行为?

  • 是——已在摘要中说明

Preserve the primary recovery failure through Host shutdown and carry a bounded, non-sensitive classification through Candidate election. Desktop, TUI, and CLI now report actionable startup errors instead of exposing a transient draining state.
This deliberately leaves incompatible stored records unchanged for the owning migration work.
Generated-by: Codex
Treat a failed Candidate as diagnostic evidence instead of authority over the entire election, allowing a ready successor to win. Keep transient recovery and storage failures reconnectable while preserving deterministic stored-data failures.
Classify only the primary error chain, recognize filesystem storage failures, and remove the migration category that had no production source.
Generated-by: Codex
Remove top-level filesystem and SQLite error guessing because the Candidate boundary cannot know which resource owns a generic failure. Only the Storage-owned persisted-message error remains a deterministic startup classification.
Generic failures stay retryable and no longer suppress successor Candidates within the same election.
Generated-by: Codex
@M4n5ter
M4n5terforce-pushed the fix/runtime-host-startup-errors branch from 73df0e2 to b0bf84cCompareAugust 12, 2026 08:49
@M4n5ter
M4n5ter marked this pull request as ready for review August 12, 2026 09:00
@M4n5ter

Copy link
Copy Markdown
MemberAuthor
English

I have manually reviewed this pull request and confirmed the fixes it contains.

The implementation now preserves the primary Runtime Host recovery failure, reports persisted-data incompatibility without exposing stored content, keeps unknown startup failures retryable, and allows a healthy successor Host to win the election after an earlier Candidate fails. I also confirmed that only the explicitly typed stored-data incompatibility is treated as permanent, without inferring storage ownership from generic filesystem or SQLite errors.

The implementation and relevant validation results are acceptable to me.

简体中文

我已人工审查此 Pull Request,并确认其中包含的修复。

当前实现能够保留 Runtime Host 的首要恢复错误,在不暴露持久化内容的前提下报告数据不兼容;未知启动失败仍可重试,较早失败的 Candidate 也不会阻止健康的后继 Host 赢得 election。我同时确认,只有明确类型化的持久化数据不兼容会被视为永久错误,代码不会再根据通用文件系统或 SQLite 错误猜测存储归属。

该实现及相关验证结果对我而言是可接受的。

@M4n5ter
M4n5ter merged commit bb52f3f into mainAug 12, 2026
10 checks passed
@M4n5ter
M4n5ter deleted the fix/runtime-host-startup-errors branch August 12, 2026 09:00
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@M4n5ter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(runtime-host): report startup recovery failures - #2906

Merged
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors
Aug 12, 2026
Merged

fix(runtime-host): report startup recovery failures#2906
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors

Conversation

@M4n5ter

@M4n5terM4n5ter commented Aug 12, 2026

Copy link
Copy Markdown
Member
English

Summary

Runtime Host recovery failures could be hidden by shutdown errors, while Candidate election exposed the temporary host_draining state to Desktop, TUI, and CLI. This made an incompatible stored record look like a generic startup failure.

This change preserves the primary recovery error, carries a bounded non-sensitive failure reason through Candidate exit and election, and presents an actionable shared startup message. It does not migrate or accept incompatible stored records; that remains separate migration work.

Verification

  • Reproduced with a real SQLite workspace containing an incompatible persisted message; election returned {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host and the full Runtime Host test suite
  • Typechecks for Storage, Runtime Host, Desktop, and CLI
  • Biome check for all changed files and git diff --check

AI disclosure

OpenAI Codex assisted with the implementation and verification. I reviewed the resulting changes and confirm this submission.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No
简体中文

摘要

Runtime Host 的恢复错误可能被 shutdown 错误掩盖,同时 Candidate election 会把临时的 host_draining 状态暴露给 Desktop、TUI 和 CLI,导致不兼容的持久化记录最终只显示为模糊的启动失败。

本次变更保留首要恢复错误,通过 Candidate 退出和 election 传递有界且不包含敏感信息的失败分类,并统一显示可操作的启动提示。它不会迁移或接受不兼容的持久化记录;相关兼容工作仍由独立变更负责。

验证

  • 使用包含不兼容持久化消息的真实 SQLite 工作区复现;election 返回 {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host 及 Runtime Host 全量测试
  • Storage、Runtime Host、Desktop 和 CLI typecheck
  • 所有变更文件的 Biome check 与 git diff --check

AI 披露

OpenAI Codex 协助了实现与验证。我已人工审核最终变更,并确认提交此 PR。

检查清单

  • 测试覆盖该变更,且在修复前会失败
  • lint、format、typecheck 和受影响测试均在本地通过

此 PR 是否改变行为?

  • 是——已在摘要中说明

Preserve the primary recovery failure through Host shutdown and carry a bounded, non-sensitive classification through Candidate election. Desktop, TUI, and CLI now report actionable startup errors instead of exposing a transient draining state.
This deliberately leaves incompatible stored records unchanged for the owning migration work.
Generated-by: Codex
Treat a failed Candidate as diagnostic evidence instead of authority over the entire election, allowing a ready successor to win. Keep transient recovery and storage failures reconnectable while preserving deterministic stored-data failures.
Classify only the primary error chain, recognize filesystem storage failures, and remove the migration category that had no production source.
Generated-by: Codex
Remove top-level filesystem and SQLite error guessing because the Candidate boundary cannot know which resource owns a generic failure. Only the Storage-owned persisted-message error remains a deterministic startup classification.
Generic failures stay retryable and no longer suppress successor Candidates within the same election.
Generated-by: Codex
@M4n5ter
M4n5terforce-pushed the fix/runtime-host-startup-errors branch from 73df0e2 to b0bf84cCompareAugust 12, 2026 08:49
@M4n5ter
M4n5ter marked this pull request as ready for review August 12, 2026 09:00
@M4n5ter

Copy link
Copy Markdown
MemberAuthor
English

I have manually reviewed this pull request and confirmed the fixes it contains.

The implementation now preserves the primary Runtime Host recovery failure, reports persisted-data incompatibility without exposing stored content, keeps unknown startup failures retryable, and allows a healthy successor Host to win the election after an earlier Candidate fails. I also confirmed that only the explicitly typed stored-data incompatibility is treated as permanent, without inferring storage ownership from generic filesystem or SQLite errors.

The implementation and relevant validation results are acceptable to me.

简体中文

我已人工审查此 Pull Request,并确认其中包含的修复。

当前实现能够保留 Runtime Host 的首要恢复错误,在不暴露持久化内容的前提下报告数据不兼容;未知启动失败仍可重试,较早失败的 Candidate 也不会阻止健康的后继 Host 赢得 election。我同时确认,只有明确类型化的持久化数据不兼容会被视为永久错误,代码不会再根据通用文件系统或 SQLite 错误猜测存储归属。

该实现及相关验证结果对我而言是可接受的。

@M4n5ter
M4n5ter merged commit bb52f3f into mainAug 12, 2026
10 checks passed
@M4n5ter
M4n5ter deleted the fix/runtime-host-startup-errors branch August 12, 2026 09:00
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@M4n5ter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(runtime-host): report startup recovery failures - #2906

Merged
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors
Aug 12, 2026
Merged

fix(runtime-host): report startup recovery failures#2906
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors

Conversation

@M4n5ter

@M4n5terM4n5ter commented Aug 12, 2026

Copy link
Copy Markdown
Member
English

Summary

Runtime Host recovery failures could be hidden by shutdown errors, while Candidate election exposed the temporary host_draining state to Desktop, TUI, and CLI. This made an incompatible stored record look like a generic startup failure.

This change preserves the primary recovery error, carries a bounded non-sensitive failure reason through Candidate exit and election, and presents an actionable shared startup message. It does not migrate or accept incompatible stored records; that remains separate migration work.

Verification

  • Reproduced with a real SQLite workspace containing an incompatible persisted message; election returned {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host and the full Runtime Host test suite
  • Typechecks for Storage, Runtime Host, Desktop, and CLI
  • Biome check for all changed files and git diff --check

AI disclosure

OpenAI Codex assisted with the implementation and verification. I reviewed the resulting changes and confirm this submission.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No
简体中文

摘要

Runtime Host 的恢复错误可能被 shutdown 错误掩盖,同时 Candidate election 会把临时的 host_draining 状态暴露给 Desktop、TUI 和 CLI,导致不兼容的持久化记录最终只显示为模糊的启动失败。

本次变更保留首要恢复错误,通过 Candidate 退出和 election 传递有界且不包含敏感信息的失败分类,并统一显示可操作的启动提示。它不会迁移或接受不兼容的持久化记录;相关兼容工作仍由独立变更负责。

验证

  • 使用包含不兼容持久化消息的真实 SQLite 工作区复现;election 返回 {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host 及 Runtime Host 全量测试
  • Storage、Runtime Host、Desktop 和 CLI typecheck
  • 所有变更文件的 Biome check 与 git diff --check

AI 披露

OpenAI Codex 协助了实现与验证。我已人工审核最终变更,并确认提交此 PR。

检查清单

  • 测试覆盖该变更,且在修复前会失败
  • lint、format、typecheck 和受影响测试均在本地通过

此 PR 是否改变行为?

  • 是——已在摘要中说明

Preserve the primary recovery failure through Host shutdown and carry a bounded, non-sensitive classification through Candidate election. Desktop, TUI, and CLI now report actionable startup errors instead of exposing a transient draining state.
This deliberately leaves incompatible stored records unchanged for the owning migration work.
Generated-by: Codex
Treat a failed Candidate as diagnostic evidence instead of authority over the entire election, allowing a ready successor to win. Keep transient recovery and storage failures reconnectable while preserving deterministic stored-data failures.
Classify only the primary error chain, recognize filesystem storage failures, and remove the migration category that had no production source.
Generated-by: Codex
Remove top-level filesystem and SQLite error guessing because the Candidate boundary cannot know which resource owns a generic failure. Only the Storage-owned persisted-message error remains a deterministic startup classification.
Generic failures stay retryable and no longer suppress successor Candidates within the same election.
Generated-by: Codex
@M4n5ter
M4n5terforce-pushed the fix/runtime-host-startup-errors branch from 73df0e2 to b0bf84cCompareAugust 12, 2026 08:49
@M4n5ter
M4n5ter marked this pull request as ready for review August 12, 2026 09:00
@M4n5ter

Copy link
Copy Markdown
MemberAuthor
English

I have manually reviewed this pull request and confirmed the fixes it contains.

The implementation now preserves the primary Runtime Host recovery failure, reports persisted-data incompatibility without exposing stored content, keeps unknown startup failures retryable, and allows a healthy successor Host to win the election after an earlier Candidate fails. I also confirmed that only the explicitly typed stored-data incompatibility is treated as permanent, without inferring storage ownership from generic filesystem or SQLite errors.

The implementation and relevant validation results are acceptable to me.

简体中文

我已人工审查此 Pull Request,并确认其中包含的修复。

当前实现能够保留 Runtime Host 的首要恢复错误,在不暴露持久化内容的前提下报告数据不兼容;未知启动失败仍可重试,较早失败的 Candidate 也不会阻止健康的后继 Host 赢得 election。我同时确认,只有明确类型化的持久化数据不兼容会被视为永久错误,代码不会再根据通用文件系统或 SQLite 错误猜测存储归属。

该实现及相关验证结果对我而言是可接受的。

@M4n5ter
M4n5ter merged commit bb52f3f into mainAug 12, 2026
10 checks passed
@M4n5ter
M4n5ter deleted the fix/runtime-host-startup-errors branch August 12, 2026 09:00
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@M4n5ter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(runtime-host): report startup recovery failures - #2906

Merged
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors
Aug 12, 2026
Merged

fix(runtime-host): report startup recovery failures#2906
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors

Conversation

@M4n5ter

@M4n5terM4n5ter commented Aug 12, 2026

Copy link
Copy Markdown
Member
English

Summary

Runtime Host recovery failures could be hidden by shutdown errors, while Candidate election exposed the temporary host_draining state to Desktop, TUI, and CLI. This made an incompatible stored record look like a generic startup failure.

This change preserves the primary recovery error, carries a bounded non-sensitive failure reason through Candidate exit and election, and presents an actionable shared startup message. It does not migrate or accept incompatible stored records; that remains separate migration work.

Verification

  • Reproduced with a real SQLite workspace containing an incompatible persisted message; election returned {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host and the full Runtime Host test suite
  • Typechecks for Storage, Runtime Host, Desktop, and CLI
  • Biome check for all changed files and git diff --check

AI disclosure

OpenAI Codex assisted with the implementation and verification. I reviewed the resulting changes and confirm this submission.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No
简体中文

摘要

Runtime Host 的恢复错误可能被 shutdown 错误掩盖,同时 Candidate election 会把临时的 host_draining 状态暴露给 Desktop、TUI 和 CLI,导致不兼容的持久化记录最终只显示为模糊的启动失败。

本次变更保留首要恢复错误,通过 Candidate 退出和 election 传递有界且不包含敏感信息的失败分类,并统一显示可操作的启动提示。它不会迁移或接受不兼容的持久化记录;相关兼容工作仍由独立变更负责。

验证

  • 使用包含不兼容持久化消息的真实 SQLite 工作区复现;election 返回 {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host 及 Runtime Host 全量测试
  • Storage、Runtime Host、Desktop 和 CLI typecheck
  • 所有变更文件的 Biome check 与 git diff --check

AI 披露

OpenAI Codex 协助了实现与验证。我已人工审核最终变更,并确认提交此 PR。

检查清单

  • 测试覆盖该变更,且在修复前会失败
  • lint、format、typecheck 和受影响测试均在本地通过

此 PR 是否改变行为?

  • 是——已在摘要中说明

Preserve the primary recovery failure through Host shutdown and carry a bounded, non-sensitive classification through Candidate election. Desktop, TUI, and CLI now report actionable startup errors instead of exposing a transient draining state.
This deliberately leaves incompatible stored records unchanged for the owning migration work.
Generated-by: Codex
Treat a failed Candidate as diagnostic evidence instead of authority over the entire election, allowing a ready successor to win. Keep transient recovery and storage failures reconnectable while preserving deterministic stored-data failures.
Classify only the primary error chain, recognize filesystem storage failures, and remove the migration category that had no production source.
Generated-by: Codex
Remove top-level filesystem and SQLite error guessing because the Candidate boundary cannot know which resource owns a generic failure. Only the Storage-owned persisted-message error remains a deterministic startup classification.
Generic failures stay retryable and no longer suppress successor Candidates within the same election.
Generated-by: Codex
@M4n5ter
M4n5terforce-pushed the fix/runtime-host-startup-errors branch from 73df0e2 to b0bf84cCompareAugust 12, 2026 08:49
@M4n5ter
M4n5ter marked this pull request as ready for review August 12, 2026 09:00
@M4n5ter

Copy link
Copy Markdown
MemberAuthor
English

I have manually reviewed this pull request and confirmed the fixes it contains.

The implementation now preserves the primary Runtime Host recovery failure, reports persisted-data incompatibility without exposing stored content, keeps unknown startup failures retryable, and allows a healthy successor Host to win the election after an earlier Candidate fails. I also confirmed that only the explicitly typed stored-data incompatibility is treated as permanent, without inferring storage ownership from generic filesystem or SQLite errors.

The implementation and relevant validation results are acceptable to me.

简体中文

我已人工审查此 Pull Request,并确认其中包含的修复。

当前实现能够保留 Runtime Host 的首要恢复错误,在不暴露持久化内容的前提下报告数据不兼容;未知启动失败仍可重试,较早失败的 Candidate 也不会阻止健康的后继 Host 赢得 election。我同时确认,只有明确类型化的持久化数据不兼容会被视为永久错误,代码不会再根据通用文件系统或 SQLite 错误猜测存储归属。

该实现及相关验证结果对我而言是可接受的。

@M4n5ter
M4n5ter merged commit bb52f3f into mainAug 12, 2026
10 checks passed
@M4n5ter
M4n5ter deleted the fix/runtime-host-startup-errors branch August 12, 2026 09:00
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@M4n5ter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(runtime-host): report startup recovery failures - #2906

Merged
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors
Aug 12, 2026
Merged

fix(runtime-host): report startup recovery failures#2906
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors

Conversation

@M4n5ter

@M4n5terM4n5ter commented Aug 12, 2026

Copy link
Copy Markdown
Member
English

Summary

Runtime Host recovery failures could be hidden by shutdown errors, while Candidate election exposed the temporary host_draining state to Desktop, TUI, and CLI. This made an incompatible stored record look like a generic startup failure.

This change preserves the primary recovery error, carries a bounded non-sensitive failure reason through Candidate exit and election, and presents an actionable shared startup message. It does not migrate or accept incompatible stored records; that remains separate migration work.

Verification

  • Reproduced with a real SQLite workspace containing an incompatible persisted message; election returned {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host and the full Runtime Host test suite
  • Typechecks for Storage, Runtime Host, Desktop, and CLI
  • Biome check for all changed files and git diff --check

AI disclosure

OpenAI Codex assisted with the implementation and verification. I reviewed the resulting changes and confirm this submission.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No
简体中文

摘要

Runtime Host 的恢复错误可能被 shutdown 错误掩盖,同时 Candidate election 会把临时的 host_draining 状态暴露给 Desktop、TUI 和 CLI,导致不兼容的持久化记录最终只显示为模糊的启动失败。

本次变更保留首要恢复错误,通过 Candidate 退出和 election 传递有界且不包含敏感信息的失败分类,并统一显示可操作的启动提示。它不会迁移或接受不兼容的持久化记录;相关兼容工作仍由独立变更负责。

验证

  • 使用包含不兼容持久化消息的真实 SQLite 工作区复现;election 返回 {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host 及 Runtime Host 全量测试
  • Storage、Runtime Host、Desktop 和 CLI typecheck
  • 所有变更文件的 Biome check 与 git diff --check

AI 披露

OpenAI Codex 协助了实现与验证。我已人工审核最终变更,并确认提交此 PR。

检查清单

  • 测试覆盖该变更,且在修复前会失败
  • lint、format、typecheck 和受影响测试均在本地通过

此 PR 是否改变行为?

  • 是——已在摘要中说明

Preserve the primary recovery failure through Host shutdown and carry a bounded, non-sensitive classification through Candidate election. Desktop, TUI, and CLI now report actionable startup errors instead of exposing a transient draining state.
This deliberately leaves incompatible stored records unchanged for the owning migration work.
Generated-by: Codex
Treat a failed Candidate as diagnostic evidence instead of authority over the entire election, allowing a ready successor to win. Keep transient recovery and storage failures reconnectable while preserving deterministic stored-data failures.
Classify only the primary error chain, recognize filesystem storage failures, and remove the migration category that had no production source.
Generated-by: Codex
Remove top-level filesystem and SQLite error guessing because the Candidate boundary cannot know which resource owns a generic failure. Only the Storage-owned persisted-message error remains a deterministic startup classification.
Generic failures stay retryable and no longer suppress successor Candidates within the same election.
Generated-by: Codex
@M4n5ter
M4n5terforce-pushed the fix/runtime-host-startup-errors branch from 73df0e2 to b0bf84cCompareAugust 12, 2026 08:49
@M4n5ter
M4n5ter marked this pull request as ready for review August 12, 2026 09:00
@M4n5ter

Copy link
Copy Markdown
MemberAuthor
English

I have manually reviewed this pull request and confirmed the fixes it contains.

The implementation now preserves the primary Runtime Host recovery failure, reports persisted-data incompatibility without exposing stored content, keeps unknown startup failures retryable, and allows a healthy successor Host to win the election after an earlier Candidate fails. I also confirmed that only the explicitly typed stored-data incompatibility is treated as permanent, without inferring storage ownership from generic filesystem or SQLite errors.

The implementation and relevant validation results are acceptable to me.

简体中文

我已人工审查此 Pull Request,并确认其中包含的修复。

当前实现能够保留 Runtime Host 的首要恢复错误,在不暴露持久化内容的前提下报告数据不兼容;未知启动失败仍可重试,较早失败的 Candidate 也不会阻止健康的后继 Host 赢得 election。我同时确认,只有明确类型化的持久化数据不兼容会被视为永久错误,代码不会再根据通用文件系统或 SQLite 错误猜测存储归属。

该实现及相关验证结果对我而言是可接受的。

@M4n5ter
M4n5ter merged commit bb52f3f into mainAug 12, 2026
10 checks passed
@M4n5ter
M4n5ter deleted the fix/runtime-host-startup-errors branch August 12, 2026 09:00
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@M4n5ter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(runtime-host): report startup recovery failures - #2906

Merged
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors
Aug 12, 2026
Merged

fix(runtime-host): report startup recovery failures#2906
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors

Conversation

@M4n5ter

@M4n5terM4n5ter commented Aug 12, 2026

Copy link
Copy Markdown
Member
English

Summary

Runtime Host recovery failures could be hidden by shutdown errors, while Candidate election exposed the temporary host_draining state to Desktop, TUI, and CLI. This made an incompatible stored record look like a generic startup failure.

This change preserves the primary recovery error, carries a bounded non-sensitive failure reason through Candidate exit and election, and presents an actionable shared startup message. It does not migrate or accept incompatible stored records; that remains separate migration work.

Verification

  • Reproduced with a real SQLite workspace containing an incompatible persisted message; election returned {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host and the full Runtime Host test suite
  • Typechecks for Storage, Runtime Host, Desktop, and CLI
  • Biome check for all changed files and git diff --check

AI disclosure

OpenAI Codex assisted with the implementation and verification. I reviewed the resulting changes and confirm this submission.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No
简体中文

摘要

Runtime Host 的恢复错误可能被 shutdown 错误掩盖,同时 Candidate election 会把临时的 host_draining 状态暴露给 Desktop、TUI 和 CLI,导致不兼容的持久化记录最终只显示为模糊的启动失败。

本次变更保留首要恢复错误,通过 Candidate 退出和 election 传递有界且不包含敏感信息的失败分类,并统一显示可操作的启动提示。它不会迁移或接受不兼容的持久化记录;相关兼容工作仍由独立变更负责。

验证

  • 使用包含不兼容持久化消息的真实 SQLite 工作区复现;election 返回 {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host 及 Runtime Host 全量测试
  • Storage、Runtime Host、Desktop 和 CLI typecheck
  • 所有变更文件的 Biome check 与 git diff --check

AI 披露

OpenAI Codex 协助了实现与验证。我已人工审核最终变更,并确认提交此 PR。

检查清单

  • 测试覆盖该变更,且在修复前会失败
  • lint、format、typecheck 和受影响测试均在本地通过

此 PR 是否改变行为?

  • 是——已在摘要中说明

Preserve the primary recovery failure through Host shutdown and carry a bounded, non-sensitive classification through Candidate election. Desktop, TUI, and CLI now report actionable startup errors instead of exposing a transient draining state.
This deliberately leaves incompatible stored records unchanged for the owning migration work.
Generated-by: Codex
Treat a failed Candidate as diagnostic evidence instead of authority over the entire election, allowing a ready successor to win. Keep transient recovery and storage failures reconnectable while preserving deterministic stored-data failures.
Classify only the primary error chain, recognize filesystem storage failures, and remove the migration category that had no production source.
Generated-by: Codex
Remove top-level filesystem and SQLite error guessing because the Candidate boundary cannot know which resource owns a generic failure. Only the Storage-owned persisted-message error remains a deterministic startup classification.
Generic failures stay retryable and no longer suppress successor Candidates within the same election.
Generated-by: Codex
@M4n5ter
M4n5terforce-pushed the fix/runtime-host-startup-errors branch from 73df0e2 to b0bf84cCompareAugust 12, 2026 08:49
@M4n5ter
M4n5ter marked this pull request as ready for review August 12, 2026 09:00
@M4n5ter

Copy link
Copy Markdown
MemberAuthor
English

I have manually reviewed this pull request and confirmed the fixes it contains.

The implementation now preserves the primary Runtime Host recovery failure, reports persisted-data incompatibility without exposing stored content, keeps unknown startup failures retryable, and allows a healthy successor Host to win the election after an earlier Candidate fails. I also confirmed that only the explicitly typed stored-data incompatibility is treated as permanent, without inferring storage ownership from generic filesystem or SQLite errors.

The implementation and relevant validation results are acceptable to me.

简体中文

我已人工审查此 Pull Request,并确认其中包含的修复。

当前实现能够保留 Runtime Host 的首要恢复错误,在不暴露持久化内容的前提下报告数据不兼容;未知启动失败仍可重试,较早失败的 Candidate 也不会阻止健康的后继 Host 赢得 election。我同时确认,只有明确类型化的持久化数据不兼容会被视为永久错误,代码不会再根据通用文件系统或 SQLite 错误猜测存储归属。

该实现及相关验证结果对我而言是可接受的。

@M4n5ter
M4n5ter merged commit bb52f3f into mainAug 12, 2026
10 checks passed
@M4n5ter
M4n5ter deleted the fix/runtime-host-startup-errors branch August 12, 2026 09:00
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@M4n5ter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(runtime-host): report startup recovery failures - #2906

Merged
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors
Aug 12, 2026
Merged

fix(runtime-host): report startup recovery failures#2906
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors

Conversation

@M4n5ter

@M4n5terM4n5ter commented Aug 12, 2026

Copy link
Copy Markdown
Member
English

Summary

Runtime Host recovery failures could be hidden by shutdown errors, while Candidate election exposed the temporary host_draining state to Desktop, TUI, and CLI. This made an incompatible stored record look like a generic startup failure.

This change preserves the primary recovery error, carries a bounded non-sensitive failure reason through Candidate exit and election, and presents an actionable shared startup message. It does not migrate or accept incompatible stored records; that remains separate migration work.

Verification

  • Reproduced with a real SQLite workspace containing an incompatible persisted message; election returned {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host and the full Runtime Host test suite
  • Typechecks for Storage, Runtime Host, Desktop, and CLI
  • Biome check for all changed files and git diff --check

AI disclosure

OpenAI Codex assisted with the implementation and verification. I reviewed the resulting changes and confirm this submission.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No
简体中文

摘要

Runtime Host 的恢复错误可能被 shutdown 错误掩盖,同时 Candidate election 会把临时的 host_draining 状态暴露给 Desktop、TUI 和 CLI,导致不兼容的持久化记录最终只显示为模糊的启动失败。

本次变更保留首要恢复错误,通过 Candidate 退出和 election 传递有界且不包含敏感信息的失败分类,并统一显示可操作的启动提示。它不会迁移或接受不兼容的持久化记录;相关兼容工作仍由独立变更负责。

验证

  • 使用包含不兼容持久化消息的真实 SQLite 工作区复现;election 返回 {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host 及 Runtime Host 全量测试
  • Storage、Runtime Host、Desktop 和 CLI typecheck
  • 所有变更文件的 Biome check 与 git diff --check

AI 披露

OpenAI Codex 协助了实现与验证。我已人工审核最终变更,并确认提交此 PR。

检查清单

  • 测试覆盖该变更,且在修复前会失败
  • lint、format、typecheck 和受影响测试均在本地通过

此 PR 是否改变行为?

  • 是——已在摘要中说明

Preserve the primary recovery failure through Host shutdown and carry a bounded, non-sensitive classification through Candidate election. Desktop, TUI, and CLI now report actionable startup errors instead of exposing a transient draining state.
This deliberately leaves incompatible stored records unchanged for the owning migration work.
Generated-by: Codex
Treat a failed Candidate as diagnostic evidence instead of authority over the entire election, allowing a ready successor to win. Keep transient recovery and storage failures reconnectable while preserving deterministic stored-data failures.
Classify only the primary error chain, recognize filesystem storage failures, and remove the migration category that had no production source.
Generated-by: Codex
Remove top-level filesystem and SQLite error guessing because the Candidate boundary cannot know which resource owns a generic failure. Only the Storage-owned persisted-message error remains a deterministic startup classification.
Generic failures stay retryable and no longer suppress successor Candidates within the same election.
Generated-by: Codex
@M4n5ter
M4n5terforce-pushed the fix/runtime-host-startup-errors branch from 73df0e2 to b0bf84cCompareAugust 12, 2026 08:49
@M4n5ter
M4n5ter marked this pull request as ready for review August 12, 2026 09:00
@M4n5ter

Copy link
Copy Markdown
MemberAuthor
English

I have manually reviewed this pull request and confirmed the fixes it contains.

The implementation now preserves the primary Runtime Host recovery failure, reports persisted-data incompatibility without exposing stored content, keeps unknown startup failures retryable, and allows a healthy successor Host to win the election after an earlier Candidate fails. I also confirmed that only the explicitly typed stored-data incompatibility is treated as permanent, without inferring storage ownership from generic filesystem or SQLite errors.

The implementation and relevant validation results are acceptable to me.

简体中文

我已人工审查此 Pull Request,并确认其中包含的修复。

当前实现能够保留 Runtime Host 的首要恢复错误,在不暴露持久化内容的前提下报告数据不兼容;未知启动失败仍可重试,较早失败的 Candidate 也不会阻止健康的后继 Host 赢得 election。我同时确认,只有明确类型化的持久化数据不兼容会被视为永久错误,代码不会再根据通用文件系统或 SQLite 错误猜测存储归属。

该实现及相关验证结果对我而言是可接受的。

@M4n5ter
M4n5ter merged commit bb52f3f into mainAug 12, 2026
10 checks passed
@M4n5ter
M4n5ter deleted the fix/runtime-host-startup-errors branch August 12, 2026 09:00
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@M4n5ter
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(runtime-host): report startup recovery failures - #2906

Merged
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors
Aug 12, 2026
Merged

fix(runtime-host): report startup recovery failures#2906
M4n5ter merged 3 commits into
mainfrom
fix/runtime-host-startup-errors

Conversation

@M4n5ter

@M4n5terM4n5ter commented Aug 12, 2026

Copy link
Copy Markdown
Member
English

Summary

Runtime Host recovery failures could be hidden by shutdown errors, while Candidate election exposed the temporary host_draining state to Desktop, TUI, and CLI. This made an incompatible stored record look like a generic startup failure.

This change preserves the primary recovery error, carries a bounded non-sensitive failure reason through Candidate exit and election, and presents an actionable shared startup message. It does not migrate or accept incompatible stored records; that remains separate migration work.

Verification

  • Reproduced with a real SQLite workspace containing an incompatible persisted message; election returned {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host and the full Runtime Host test suite
  • Typechecks for Storage, Runtime Host, Desktop, and CLI
  • Biome check for all changed files and git diff --check

AI disclosure

OpenAI Codex assisted with the implementation and verification. I reviewed the resulting changes and confirm this submission.

Checklist

  • Tests cover the change and fail without it
  • Lint, format, typecheck and the affected suites pass locally

Does this PR entail a change in behavior?

  • Yes — described under Summary above
  • No
简体中文

摘要

Runtime Host 的恢复错误可能被 shutdown 错误掩盖,同时 Candidate election 会把临时的 host_draining 状态暴露给 Desktop、TUI 和 CLI,导致不兼容的持久化记录最终只显示为模糊的启动失败。

本次变更保留首要恢复错误,通过 Candidate 退出和 election 传递有界且不包含敏感信息的失败分类,并统一显示可操作的启动提示。它不会迁移或接受不兼容的持久化记录;相关兼容工作仍由独立变更负责。

验证

  • 使用包含不兼容持久化消息的真实 SQLite 工作区复现;election 返回 {"kind":"failed","reason":"stored_data_incompatible"}
  • npm test -w @maka/storage
  • npm run build -w @maka/runtime-host 及 Runtime Host 全量测试
  • Storage、Runtime Host、Desktop 和 CLI typecheck
  • 所有变更文件的 Biome check 与 git diff --check

AI 披露

OpenAI Codex 协助了实现与验证。我已人工审核最终变更,并确认提交此 PR。

检查清单

  • 测试覆盖该变更,且在修复前会失败
  • lint、format、typecheck 和受影响测试均在本地通过

此 PR 是否改变行为?

  • 是——已在摘要中说明

Preserve the primary recovery failure through Host shutdown and carry a bounded, non-sensitive classification through Candidate election. Desktop, TUI, and CLI now report actionable startup errors instead of exposing a transient draining state.
This deliberately leaves incompatible stored records unchanged for the owning migration work.
Generated-by: Codex
Treat a failed Candidate as diagnostic evidence instead of authority over the entire election, allowing a ready successor to win. Keep transient recovery and storage failures reconnectable while preserving deterministic stored-data failures.
Classify only the primary error chain, recognize filesystem storage failures, and remove the migration category that had no production source.
Generated-by: Codex
Remove top-level filesystem and SQLite error guessing because the Candidate boundary cannot know which resource owns a generic failure. Only the Storage-owned persisted-message error remains a deterministic startup classification.
Generic failures stay retryable and no longer suppress successor Candidates within the same election.
Generated-by: Codex
@M4n5ter
M4n5terforce-pushed the fix/runtime-host-startup-errors branch from 73df0e2 to b0bf84cCompareAugust 12, 2026 08:49
@M4n5ter
M4n5ter marked this pull request as ready for review August 12, 2026 09:00
@M4n5ter

Copy link
Copy Markdown
MemberAuthor
English

I have manually reviewed this pull request and confirmed the fixes it contains.

The implementation now preserves the primary Runtime Host recovery failure, reports persisted-data incompatibility without exposing stored content, keeps unknown startup failures retryable, and allows a healthy successor Host to win the election after an earlier Candidate fails. I also confirmed that only the explicitly typed stored-data incompatibility is treated as permanent, without inferring storage ownership from generic filesystem or SQLite errors.

The implementation and relevant validation results are acceptable to me.

简体中文

我已人工审查此 Pull Request,并确认其中包含的修复。

当前实现能够保留 Runtime Host 的首要恢复错误,在不暴露持久化内容的前提下报告数据不兼容;未知启动失败仍可重试,较早失败的 Candidate 也不会阻止健康的后继 Host 赢得 election。我同时确认,只有明确类型化的持久化数据不兼容会被视为永久错误,代码不会再根据通用文件系统或 SQLite 错误猜测存储归属。

该实现及相关验证结果对我而言是可接受的。

@M4n5ter
M4n5ter merged commit bb52f3f into mainAug 12, 2026
10 checks passed
@M4n5ter
M4n5ter deleted the fix/runtime-host-startup-errors branch August 12, 2026 09:00
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@M4n5ter