fix(server): reconcile stalled provider starts - #192

Merged
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation
Aug 31, 2026
Merged

fix(server): reconcile stalled provider starts#192
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation

Conversation

@rynfar

@rynfarrynfar commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Problem

A native provider could remain logically present while teardown or startup was stuck, leaving a durable turn indefinitely starting. Provider lifecycle events could also race a timeout, retry, replacement, or restart and overwrite the exact admission that currently owned the thread.

Fixes#175.

Fix

  • Persist a server-clock admission record and reconcile it with exact request, message, provider instance, and immutable session-incarnation CAS commands.
  • Bound admission work and per-instance startup inventory without interrupting a legitimate long-running turn after its exact start is accepted.
  • Reject stale, pre-bind, failed-lineage, and replaced-session runtime events across Codex, Claude, Cursor, Grok, OpenCode, Prime ACP, and Prime daemon paths.
  • Add migration 048 with ambiguity-safe backfill, missing-session recovery, and full-replay parity.
  • Logically evict Prime sessions before bounded cleanup, preserve ordered events under backpressure, and share one exception-safe native-disposal completion across explicit and scope callers.
  • Bound replacement gates, multi-session shutdown, and retained admission-fiber cleanup.
  • Preserve exact pending admission lineage when a runtime-mode change races provider startup, and defer that mode to the next safe session ensure.
  • Keep temporarily unknown startup inventory on the original admission deadline and accept a late exact start without duplicate settlement.
  • Treat expected stale session-lifecycle CAS misses as accepted no-ops rather than invariant failures.
  • Document provider admission timeout and daemon teardown behavior.

Validation

  • 721 focused tests across contracts, orchestration, migration, all provider adapters, ProviderService, and Prime daemon paths
  • 360 exact final Prime runtime/adapter tests after the disposal-latch amendment
  • Server and contracts typechecks
  • Targeted lint and format checks
  • git diff --check origin/pylon...HEAD
  • Repeated independent adversarial reviews of concurrency, migration, provider boundaries, backpressure, and Effect cleanup
  • Exact post-review repair: 86 focused orchestration tests and 415 combined ProviderService/Prime adapter/runtime tests
  • Exact post-review server typecheck plus targeted lint, format, and diff checks

Browser verification was not needed because this change is server-only.

Model: openai-codex/gpt-5.6-sol
Harness: Prime Agent RLM


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Aug 30, 2026
@github-actions

github-actionsBot commented Aug 30, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.7 KiB+449 B (+3.3%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+56 B (+0.8%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.8 KiB+393 B (+6.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB58.7 KiB+3.1 KiB (+5.6%)66.4 KiB
CodexLive turn messages1011+1 (+10.0%)21
ClaudeTotal thread wire13.3 KiB13.5 KiB+246 B (+1.8%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+50 B (+0.7%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.6 KiB+196 B (+3.0%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB58.0 KiB+1.6 KiB (+2.9%)66.4 KiB
ClaudeLive turn messages109−1 (−10.0%)21

Baseline: e62ad6a · PR result: ccbd0e9 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.5 KiB
  • Claude decoded thread snapshot: 110.2 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Bound Prime native teardown outside thread permits and gate replacement
sessions on teardown completion. Correlate pending turn admissions, time
out blocked provider preparation, and reconcile overdue starts on boot.
Fixes#175
@rynfar
rynfarforce-pushed the fix/provider-start-reconciliation branch from 9867ad2 to ccbd0e9CompareAugust 31, 2026 03:44
@rynfar
rynfar merged commit 4ce0070 into pylonAug 31, 2026
15 checks passed
@rynfar
rynfar deleted the fix/provider-start-reconciliation branch August 31, 2026 03:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXLvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provider teardown can leave later turns stuck starting

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(server): reconcile stalled provider starts - #192

Merged
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation
Aug 31, 2026
Merged

fix(server): reconcile stalled provider starts#192
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation

Conversation

@rynfar

@rynfarrynfar commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Problem

A native provider could remain logically present while teardown or startup was stuck, leaving a durable turn indefinitely starting. Provider lifecycle events could also race a timeout, retry, replacement, or restart and overwrite the exact admission that currently owned the thread.

Fixes#175.

Fix

  • Persist a server-clock admission record and reconcile it with exact request, message, provider instance, and immutable session-incarnation CAS commands.
  • Bound admission work and per-instance startup inventory without interrupting a legitimate long-running turn after its exact start is accepted.
  • Reject stale, pre-bind, failed-lineage, and replaced-session runtime events across Codex, Claude, Cursor, Grok, OpenCode, Prime ACP, and Prime daemon paths.
  • Add migration 048 with ambiguity-safe backfill, missing-session recovery, and full-replay parity.
  • Logically evict Prime sessions before bounded cleanup, preserve ordered events under backpressure, and share one exception-safe native-disposal completion across explicit and scope callers.
  • Bound replacement gates, multi-session shutdown, and retained admission-fiber cleanup.
  • Preserve exact pending admission lineage when a runtime-mode change races provider startup, and defer that mode to the next safe session ensure.
  • Keep temporarily unknown startup inventory on the original admission deadline and accept a late exact start without duplicate settlement.
  • Treat expected stale session-lifecycle CAS misses as accepted no-ops rather than invariant failures.
  • Document provider admission timeout and daemon teardown behavior.

Validation

  • 721 focused tests across contracts, orchestration, migration, all provider adapters, ProviderService, and Prime daemon paths
  • 360 exact final Prime runtime/adapter tests after the disposal-latch amendment
  • Server and contracts typechecks
  • Targeted lint and format checks
  • git diff --check origin/pylon...HEAD
  • Repeated independent adversarial reviews of concurrency, migration, provider boundaries, backpressure, and Effect cleanup
  • Exact post-review repair: 86 focused orchestration tests and 415 combined ProviderService/Prime adapter/runtime tests
  • Exact post-review server typecheck plus targeted lint, format, and diff checks

Browser verification was not needed because this change is server-only.

Model: openai-codex/gpt-5.6-sol
Harness: Prime Agent RLM


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Aug 30, 2026
@github-actions

github-actionsBot commented Aug 30, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.7 KiB+449 B (+3.3%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+56 B (+0.8%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.8 KiB+393 B (+6.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB58.7 KiB+3.1 KiB (+5.6%)66.4 KiB
CodexLive turn messages1011+1 (+10.0%)21
ClaudeTotal thread wire13.3 KiB13.5 KiB+246 B (+1.8%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+50 B (+0.7%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.6 KiB+196 B (+3.0%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB58.0 KiB+1.6 KiB (+2.9%)66.4 KiB
ClaudeLive turn messages109−1 (−10.0%)21

Baseline: e62ad6a · PR result: ccbd0e9 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.5 KiB
  • Claude decoded thread snapshot: 110.2 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Bound Prime native teardown outside thread permits and gate replacement
sessions on teardown completion. Correlate pending turn admissions, time
out blocked provider preparation, and reconcile overdue starts on boot.
Fixes#175
@rynfar
rynfarforce-pushed the fix/provider-start-reconciliation branch from 9867ad2 to ccbd0e9CompareAugust 31, 2026 03:44
@rynfar
rynfar merged commit 4ce0070 into pylonAug 31, 2026
15 checks passed
@rynfar
rynfar deleted the fix/provider-start-reconciliation branch August 31, 2026 03:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXLvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provider teardown can leave later turns stuck starting

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): reconcile stalled provider starts - #192

Merged
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation
Aug 31, 2026
Merged

fix(server): reconcile stalled provider starts#192
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation

Conversation

@rynfar

@rynfarrynfar commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Problem

A native provider could remain logically present while teardown or startup was stuck, leaving a durable turn indefinitely starting. Provider lifecycle events could also race a timeout, retry, replacement, or restart and overwrite the exact admission that currently owned the thread.

Fixes#175.

Fix

  • Persist a server-clock admission record and reconcile it with exact request, message, provider instance, and immutable session-incarnation CAS commands.
  • Bound admission work and per-instance startup inventory without interrupting a legitimate long-running turn after its exact start is accepted.
  • Reject stale, pre-bind, failed-lineage, and replaced-session runtime events across Codex, Claude, Cursor, Grok, OpenCode, Prime ACP, and Prime daemon paths.
  • Add migration 048 with ambiguity-safe backfill, missing-session recovery, and full-replay parity.
  • Logically evict Prime sessions before bounded cleanup, preserve ordered events under backpressure, and share one exception-safe native-disposal completion across explicit and scope callers.
  • Bound replacement gates, multi-session shutdown, and retained admission-fiber cleanup.
  • Preserve exact pending admission lineage when a runtime-mode change races provider startup, and defer that mode to the next safe session ensure.
  • Keep temporarily unknown startup inventory on the original admission deadline and accept a late exact start without duplicate settlement.
  • Treat expected stale session-lifecycle CAS misses as accepted no-ops rather than invariant failures.
  • Document provider admission timeout and daemon teardown behavior.

Validation

  • 721 focused tests across contracts, orchestration, migration, all provider adapters, ProviderService, and Prime daemon paths
  • 360 exact final Prime runtime/adapter tests after the disposal-latch amendment
  • Server and contracts typechecks
  • Targeted lint and format checks
  • git diff --check origin/pylon...HEAD
  • Repeated independent adversarial reviews of concurrency, migration, provider boundaries, backpressure, and Effect cleanup
  • Exact post-review repair: 86 focused orchestration tests and 415 combined ProviderService/Prime adapter/runtime tests
  • Exact post-review server typecheck plus targeted lint, format, and diff checks

Browser verification was not needed because this change is server-only.

Model: openai-codex/gpt-5.6-sol
Harness: Prime Agent RLM


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Aug 30, 2026
@github-actions

github-actionsBot commented Aug 30, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.7 KiB+449 B (+3.3%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+56 B (+0.8%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.8 KiB+393 B (+6.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB58.7 KiB+3.1 KiB (+5.6%)66.4 KiB
CodexLive turn messages1011+1 (+10.0%)21
ClaudeTotal thread wire13.3 KiB13.5 KiB+246 B (+1.8%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+50 B (+0.7%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.6 KiB+196 B (+3.0%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB58.0 KiB+1.6 KiB (+2.9%)66.4 KiB
ClaudeLive turn messages109−1 (−10.0%)21

Baseline: e62ad6a · PR result: ccbd0e9 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.5 KiB
  • Claude decoded thread snapshot: 110.2 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Bound Prime native teardown outside thread permits and gate replacement
sessions on teardown completion. Correlate pending turn admissions, time
out blocked provider preparation, and reconcile overdue starts on boot.
Fixes#175
@rynfar
rynfarforce-pushed the fix/provider-start-reconciliation branch from 9867ad2 to ccbd0e9CompareAugust 31, 2026 03:44
@rynfar
rynfar merged commit 4ce0070 into pylonAug 31, 2026
15 checks passed
@rynfar
rynfar deleted the fix/provider-start-reconciliation branch August 31, 2026 03:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXLvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provider teardown can leave later turns stuck starting

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): reconcile stalled provider starts - #192

Merged
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation
Aug 31, 2026
Merged

fix(server): reconcile stalled provider starts#192
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation

Conversation

@rynfar

@rynfarrynfar commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Problem

A native provider could remain logically present while teardown or startup was stuck, leaving a durable turn indefinitely starting. Provider lifecycle events could also race a timeout, retry, replacement, or restart and overwrite the exact admission that currently owned the thread.

Fixes#175.

Fix

  • Persist a server-clock admission record and reconcile it with exact request, message, provider instance, and immutable session-incarnation CAS commands.
  • Bound admission work and per-instance startup inventory without interrupting a legitimate long-running turn after its exact start is accepted.
  • Reject stale, pre-bind, failed-lineage, and replaced-session runtime events across Codex, Claude, Cursor, Grok, OpenCode, Prime ACP, and Prime daemon paths.
  • Add migration 048 with ambiguity-safe backfill, missing-session recovery, and full-replay parity.
  • Logically evict Prime sessions before bounded cleanup, preserve ordered events under backpressure, and share one exception-safe native-disposal completion across explicit and scope callers.
  • Bound replacement gates, multi-session shutdown, and retained admission-fiber cleanup.
  • Preserve exact pending admission lineage when a runtime-mode change races provider startup, and defer that mode to the next safe session ensure.
  • Keep temporarily unknown startup inventory on the original admission deadline and accept a late exact start without duplicate settlement.
  • Treat expected stale session-lifecycle CAS misses as accepted no-ops rather than invariant failures.
  • Document provider admission timeout and daemon teardown behavior.

Validation

  • 721 focused tests across contracts, orchestration, migration, all provider adapters, ProviderService, and Prime daemon paths
  • 360 exact final Prime runtime/adapter tests after the disposal-latch amendment
  • Server and contracts typechecks
  • Targeted lint and format checks
  • git diff --check origin/pylon...HEAD
  • Repeated independent adversarial reviews of concurrency, migration, provider boundaries, backpressure, and Effect cleanup
  • Exact post-review repair: 86 focused orchestration tests and 415 combined ProviderService/Prime adapter/runtime tests
  • Exact post-review server typecheck plus targeted lint, format, and diff checks

Browser verification was not needed because this change is server-only.

Model: openai-codex/gpt-5.6-sol
Harness: Prime Agent RLM


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Aug 30, 2026
@github-actions

github-actionsBot commented Aug 30, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.7 KiB+449 B (+3.3%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+56 B (+0.8%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.8 KiB+393 B (+6.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB58.7 KiB+3.1 KiB (+5.6%)66.4 KiB
CodexLive turn messages1011+1 (+10.0%)21
ClaudeTotal thread wire13.3 KiB13.5 KiB+246 B (+1.8%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+50 B (+0.7%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.6 KiB+196 B (+3.0%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB58.0 KiB+1.6 KiB (+2.9%)66.4 KiB
ClaudeLive turn messages109−1 (−10.0%)21

Baseline: e62ad6a · PR result: ccbd0e9 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.5 KiB
  • Claude decoded thread snapshot: 110.2 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Bound Prime native teardown outside thread permits and gate replacement
sessions on teardown completion. Correlate pending turn admissions, time
out blocked provider preparation, and reconcile overdue starts on boot.
Fixes#175
@rynfar
rynfarforce-pushed the fix/provider-start-reconciliation branch from 9867ad2 to ccbd0e9CompareAugust 31, 2026 03:44
@rynfar
rynfar merged commit 4ce0070 into pylonAug 31, 2026
15 checks passed
@rynfar
rynfar deleted the fix/provider-start-reconciliation branch August 31, 2026 03:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXLvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provider teardown can leave later turns stuck starting

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(server): reconcile stalled provider starts - #192

Merged
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation
Aug 31, 2026
Merged

fix(server): reconcile stalled provider starts#192
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation

Conversation

@rynfar

@rynfarrynfar commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Problem

A native provider could remain logically present while teardown or startup was stuck, leaving a durable turn indefinitely starting. Provider lifecycle events could also race a timeout, retry, replacement, or restart and overwrite the exact admission that currently owned the thread.

Fixes#175.

Fix

  • Persist a server-clock admission record and reconcile it with exact request, message, provider instance, and immutable session-incarnation CAS commands.
  • Bound admission work and per-instance startup inventory without interrupting a legitimate long-running turn after its exact start is accepted.
  • Reject stale, pre-bind, failed-lineage, and replaced-session runtime events across Codex, Claude, Cursor, Grok, OpenCode, Prime ACP, and Prime daemon paths.
  • Add migration 048 with ambiguity-safe backfill, missing-session recovery, and full-replay parity.
  • Logically evict Prime sessions before bounded cleanup, preserve ordered events under backpressure, and share one exception-safe native-disposal completion across explicit and scope callers.
  • Bound replacement gates, multi-session shutdown, and retained admission-fiber cleanup.
  • Preserve exact pending admission lineage when a runtime-mode change races provider startup, and defer that mode to the next safe session ensure.
  • Keep temporarily unknown startup inventory on the original admission deadline and accept a late exact start without duplicate settlement.
  • Treat expected stale session-lifecycle CAS misses as accepted no-ops rather than invariant failures.
  • Document provider admission timeout and daemon teardown behavior.

Validation

  • 721 focused tests across contracts, orchestration, migration, all provider adapters, ProviderService, and Prime daemon paths
  • 360 exact final Prime runtime/adapter tests after the disposal-latch amendment
  • Server and contracts typechecks
  • Targeted lint and format checks
  • git diff --check origin/pylon...HEAD
  • Repeated independent adversarial reviews of concurrency, migration, provider boundaries, backpressure, and Effect cleanup
  • Exact post-review repair: 86 focused orchestration tests and 415 combined ProviderService/Prime adapter/runtime tests
  • Exact post-review server typecheck plus targeted lint, format, and diff checks

Browser verification was not needed because this change is server-only.

Model: openai-codex/gpt-5.6-sol
Harness: Prime Agent RLM


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Aug 30, 2026
@github-actions

github-actionsBot commented Aug 30, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.7 KiB+449 B (+3.3%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+56 B (+0.8%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.8 KiB+393 B (+6.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB58.7 KiB+3.1 KiB (+5.6%)66.4 KiB
CodexLive turn messages1011+1 (+10.0%)21
ClaudeTotal thread wire13.3 KiB13.5 KiB+246 B (+1.8%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+50 B (+0.7%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.6 KiB+196 B (+3.0%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB58.0 KiB+1.6 KiB (+2.9%)66.4 KiB
ClaudeLive turn messages109−1 (−10.0%)21

Baseline: e62ad6a · PR result: ccbd0e9 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.5 KiB
  • Claude decoded thread snapshot: 110.2 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Bound Prime native teardown outside thread permits and gate replacement
sessions on teardown completion. Correlate pending turn admissions, time
out blocked provider preparation, and reconcile overdue starts on boot.
Fixes#175
@rynfar
rynfarforce-pushed the fix/provider-start-reconciliation branch from 9867ad2 to ccbd0e9CompareAugust 31, 2026 03:44
@rynfar
rynfar merged commit 4ce0070 into pylonAug 31, 2026
15 checks passed
@rynfar
rynfar deleted the fix/provider-start-reconciliation branch August 31, 2026 03:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXLvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provider teardown can leave later turns stuck starting

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): reconcile stalled provider starts - #192

Merged
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation
Aug 31, 2026
Merged

fix(server): reconcile stalled provider starts#192
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation

Conversation

@rynfar

@rynfarrynfar commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Problem

A native provider could remain logically present while teardown or startup was stuck, leaving a durable turn indefinitely starting. Provider lifecycle events could also race a timeout, retry, replacement, or restart and overwrite the exact admission that currently owned the thread.

Fixes#175.

Fix

  • Persist a server-clock admission record and reconcile it with exact request, message, provider instance, and immutable session-incarnation CAS commands.
  • Bound admission work and per-instance startup inventory without interrupting a legitimate long-running turn after its exact start is accepted.
  • Reject stale, pre-bind, failed-lineage, and replaced-session runtime events across Codex, Claude, Cursor, Grok, OpenCode, Prime ACP, and Prime daemon paths.
  • Add migration 048 with ambiguity-safe backfill, missing-session recovery, and full-replay parity.
  • Logically evict Prime sessions before bounded cleanup, preserve ordered events under backpressure, and share one exception-safe native-disposal completion across explicit and scope callers.
  • Bound replacement gates, multi-session shutdown, and retained admission-fiber cleanup.
  • Preserve exact pending admission lineage when a runtime-mode change races provider startup, and defer that mode to the next safe session ensure.
  • Keep temporarily unknown startup inventory on the original admission deadline and accept a late exact start without duplicate settlement.
  • Treat expected stale session-lifecycle CAS misses as accepted no-ops rather than invariant failures.
  • Document provider admission timeout and daemon teardown behavior.

Validation

  • 721 focused tests across contracts, orchestration, migration, all provider adapters, ProviderService, and Prime daemon paths
  • 360 exact final Prime runtime/adapter tests after the disposal-latch amendment
  • Server and contracts typechecks
  • Targeted lint and format checks
  • git diff --check origin/pylon...HEAD
  • Repeated independent adversarial reviews of concurrency, migration, provider boundaries, backpressure, and Effect cleanup
  • Exact post-review repair: 86 focused orchestration tests and 415 combined ProviderService/Prime adapter/runtime tests
  • Exact post-review server typecheck plus targeted lint, format, and diff checks

Browser verification was not needed because this change is server-only.

Model: openai-codex/gpt-5.6-sol
Harness: Prime Agent RLM


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Aug 30, 2026
@github-actions

github-actionsBot commented Aug 30, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.7 KiB+449 B (+3.3%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+56 B (+0.8%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.8 KiB+393 B (+6.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB58.7 KiB+3.1 KiB (+5.6%)66.4 KiB
CodexLive turn messages1011+1 (+10.0%)21
ClaudeTotal thread wire13.3 KiB13.5 KiB+246 B (+1.8%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+50 B (+0.7%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.6 KiB+196 B (+3.0%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB58.0 KiB+1.6 KiB (+2.9%)66.4 KiB
ClaudeLive turn messages109−1 (−10.0%)21

Baseline: e62ad6a · PR result: ccbd0e9 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.5 KiB
  • Claude decoded thread snapshot: 110.2 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Bound Prime native teardown outside thread permits and gate replacement
sessions on teardown completion. Correlate pending turn admissions, time
out blocked provider preparation, and reconcile overdue starts on boot.
Fixes#175
@rynfar
rynfarforce-pushed the fix/provider-start-reconciliation branch from 9867ad2 to ccbd0e9CompareAugust 31, 2026 03:44
@rynfar
rynfar merged commit 4ce0070 into pylonAug 31, 2026
15 checks passed
@rynfar
rynfar deleted the fix/provider-start-reconciliation branch August 31, 2026 03:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXLvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provider teardown can leave later turns stuck starting

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): reconcile stalled provider starts - #192

Merged
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation
Aug 31, 2026
Merged

fix(server): reconcile stalled provider starts#192
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation

Conversation

@rynfar

@rynfarrynfar commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Problem

A native provider could remain logically present while teardown or startup was stuck, leaving a durable turn indefinitely starting. Provider lifecycle events could also race a timeout, retry, replacement, or restart and overwrite the exact admission that currently owned the thread.

Fixes#175.

Fix

  • Persist a server-clock admission record and reconcile it with exact request, message, provider instance, and immutable session-incarnation CAS commands.
  • Bound admission work and per-instance startup inventory without interrupting a legitimate long-running turn after its exact start is accepted.
  • Reject stale, pre-bind, failed-lineage, and replaced-session runtime events across Codex, Claude, Cursor, Grok, OpenCode, Prime ACP, and Prime daemon paths.
  • Add migration 048 with ambiguity-safe backfill, missing-session recovery, and full-replay parity.
  • Logically evict Prime sessions before bounded cleanup, preserve ordered events under backpressure, and share one exception-safe native-disposal completion across explicit and scope callers.
  • Bound replacement gates, multi-session shutdown, and retained admission-fiber cleanup.
  • Preserve exact pending admission lineage when a runtime-mode change races provider startup, and defer that mode to the next safe session ensure.
  • Keep temporarily unknown startup inventory on the original admission deadline and accept a late exact start without duplicate settlement.
  • Treat expected stale session-lifecycle CAS misses as accepted no-ops rather than invariant failures.
  • Document provider admission timeout and daemon teardown behavior.

Validation

  • 721 focused tests across contracts, orchestration, migration, all provider adapters, ProviderService, and Prime daemon paths
  • 360 exact final Prime runtime/adapter tests after the disposal-latch amendment
  • Server and contracts typechecks
  • Targeted lint and format checks
  • git diff --check origin/pylon...HEAD
  • Repeated independent adversarial reviews of concurrency, migration, provider boundaries, backpressure, and Effect cleanup
  • Exact post-review repair: 86 focused orchestration tests and 415 combined ProviderService/Prime adapter/runtime tests
  • Exact post-review server typecheck plus targeted lint, format, and diff checks

Browser verification was not needed because this change is server-only.

Model: openai-codex/gpt-5.6-sol
Harness: Prime Agent RLM


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Aug 30, 2026
@github-actions

github-actionsBot commented Aug 30, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.7 KiB+449 B (+3.3%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+56 B (+0.8%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.8 KiB+393 B (+6.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB58.7 KiB+3.1 KiB (+5.6%)66.4 KiB
CodexLive turn messages1011+1 (+10.0%)21
ClaudeTotal thread wire13.3 KiB13.5 KiB+246 B (+1.8%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+50 B (+0.7%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.6 KiB+196 B (+3.0%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB58.0 KiB+1.6 KiB (+2.9%)66.4 KiB
ClaudeLive turn messages109−1 (−10.0%)21

Baseline: e62ad6a · PR result: ccbd0e9 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.5 KiB
  • Claude decoded thread snapshot: 110.2 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Bound Prime native teardown outside thread permits and gate replacement
sessions on teardown completion. Correlate pending turn admissions, time
out blocked provider preparation, and reconcile overdue starts on boot.
Fixes#175
@rynfar
rynfarforce-pushed the fix/provider-start-reconciliation branch from 9867ad2 to ccbd0e9CompareAugust 31, 2026 03:44
@rynfar
rynfar merged commit 4ce0070 into pylonAug 31, 2026
15 checks passed
@rynfar
rynfar deleted the fix/provider-start-reconciliation branch August 31, 2026 03:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXLvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provider teardown can leave later turns stuck starting

1 participant

@rynfar
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(server): reconcile stalled provider starts - #192

Merged
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation
Aug 31, 2026
Merged

fix(server): reconcile stalled provider starts#192
rynfar merged 2 commits into
pylonfrom
fix/provider-start-reconciliation

Conversation

@rynfar

@rynfarrynfar commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Problem

A native provider could remain logically present while teardown or startup was stuck, leaving a durable turn indefinitely starting. Provider lifecycle events could also race a timeout, retry, replacement, or restart and overwrite the exact admission that currently owned the thread.

Fixes#175.

Fix

  • Persist a server-clock admission record and reconcile it with exact request, message, provider instance, and immutable session-incarnation CAS commands.
  • Bound admission work and per-instance startup inventory without interrupting a legitimate long-running turn after its exact start is accepted.
  • Reject stale, pre-bind, failed-lineage, and replaced-session runtime events across Codex, Claude, Cursor, Grok, OpenCode, Prime ACP, and Prime daemon paths.
  • Add migration 048 with ambiguity-safe backfill, missing-session recovery, and full-replay parity.
  • Logically evict Prime sessions before bounded cleanup, preserve ordered events under backpressure, and share one exception-safe native-disposal completion across explicit and scope callers.
  • Bound replacement gates, multi-session shutdown, and retained admission-fiber cleanup.
  • Preserve exact pending admission lineage when a runtime-mode change races provider startup, and defer that mode to the next safe session ensure.
  • Keep temporarily unknown startup inventory on the original admission deadline and accept a late exact start without duplicate settlement.
  • Treat expected stale session-lifecycle CAS misses as accepted no-ops rather than invariant failures.
  • Document provider admission timeout and daemon teardown behavior.

Validation

  • 721 focused tests across contracts, orchestration, migration, all provider adapters, ProviderService, and Prime daemon paths
  • 360 exact final Prime runtime/adapter tests after the disposal-latch amendment
  • Server and contracts typechecks
  • Targeted lint and format checks
  • git diff --check origin/pylon...HEAD
  • Repeated independent adversarial reviews of concurrency, migration, provider boundaries, backpressure, and Effect cleanup
  • Exact post-review repair: 86 focused orchestration tests and 415 combined ProviderService/Prime adapter/runtime tests
  • Exact post-review server typecheck plus targeted lint, format, and diff checks

Browser verification was not needed because this change is server-only.

Model: openai-codex/gpt-5.6-sol
Harness: Prime Agent RLM


View with [code]smithAutofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Aug 30, 2026
@github-actions

github-actionsBot commented Aug 30, 2026

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.7 KiB+449 B (+3.3%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+56 B (+0.8%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.8 KiB+393 B (+6.0%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB58.7 KiB+3.1 KiB (+5.6%)66.4 KiB
CodexLive turn messages1011+1 (+10.0%)21
ClaudeTotal thread wire13.3 KiB13.5 KiB+246 B (+1.8%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB+50 B (+0.7%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.6 KiB+196 B (+3.0%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB58.0 KiB+1.6 KiB (+2.9%)66.4 KiB
ClaudeLive turn messages109−1 (−10.0%)21

Baseline: e62ad6a · PR result: ccbd0e9 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.5 KiB
  • Claude decoded thread snapshot: 110.2 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

Bound Prime native teardown outside thread permits and gate replacement
sessions on teardown completion. Correlate pending turn admissions, time
out blocked provider preparation, and reconcile overdue starts on boot.
Fixes#175
@rynfar
rynfarforce-pushed the fix/provider-start-reconciliation branch from 9867ad2 to ccbd0e9CompareAugust 31, 2026 03:44
@rynfar
rynfar merged commit 4ce0070 into pylonAug 31, 2026
15 checks passed
@rynfar
rynfar deleted the fix/provider-start-reconciliation branch August 31, 2026 03:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXLvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Provider teardown can leave later turns stuck starting

1 participant

@rynfar