Skip to content

Bound checkpoint readback and metadata listing - #223

Merged
chaoz23 merged 1 commit into
mainfrom
agent/checkpoint-bounded-readback-followup
Aug 22, 2026
Merged

chaoz23 merged 1 commit into
mainfrom
agent/checkpoint-bounded-readback-followup

Conversation

@chaoz23

@chaoz23 chaoz23 commented Aug 20, 2026 •

Copy link
Copy Markdown
Owner

Why

Large shared-search checkpoints can be valid on disk yet unsafe to reopen inside the current runtime envelope. Retention operations also need trustworthy metadata without inflating or hashing every payload. This is a bounded lifecycle prerequisite for #156 and the long-run work tracked by #215.

Phase 0 corrective PR #222 is merged. This draft is restacked directly on current main.

What changed

  • bounds stored input and schema-v1 decompressed/decoded JSON bytes before parsing, within the runtime buffer/string ceilings; it does not add an independent frontier-graph shape limit
  • exposes typed corrupt, unsupported, and resource_limit checkpoint read failures while leaving filesystem I/O failures as native errors
  • adds a small exact-key, canonical, self-checksummed sidecar manifest bound to the stored payload digest
  • makes list/prune read only the bounded manifest plus payload stat for manifested artifacts
  • verifies manifest checksum, then full stored-payload digest, then bounded decode/parse and stable logical ID on open/resume
  • counts payload and sidecar bytes in artifact size and retention quotas before publication
  • writes a durable recovery manifest in a fixed, nonce-claimed same-ID transaction slot before exposing the payload through same-directory hard-link no-clobber publication
  • makes reservation and cleanup acquire the same exclusive per-slot .claim.cleaning mutex, removes it last, and leaves a stale cleaning claim fail-closed so delayed cleanup cannot delete a reused pathname
  • binds owner claims and release markers to exact nonces: a durable marker enables cross-process/worker-isolate reclamation, while release-marker I/O failure retires the nonce only in the originating isolate and foreign live-PID readers remain fail-closed
  • recovers payload-visible crash windows without decoding the payload, and revalidates bounded payload identity plus canonical metadata before releasing recovery state
  • makes same-ID concurrent writers and portable manifest replacement converge on one verified payload/manifest pair without overwriting future-schema or resource-limited canonical metadata
  • opens legacy JSON checkpoint bytes once, applying stored and decoded ceilings to the same descriptor so file growth cannot race past the storage bound
  • uses the same fixed 32-slot namespace for legacy sidecar repair and, during same-ID resource-limit reuse/recovery, hashes with a fixed-size buffer up to the smaller active checkpoint/project cap, including caller caps above 512 MiB
  • documents the local trust boundary: the manifest self-check catches accidental/torn metadata but is not authentication against a local actor able to rewrite both files

Deliberate scope

  • Issue Compact shared checkpoints before frontier artifacts dominate campaigns #156 remains open; this PR is only a bounded lifecycle prerequisite and is not checkpoint v2
  • does not stream checkpoint construction from the live engine graph
  • does not activate resumable epochs, adaptive allocation, retention budgets, or a new search policy
  • resource-limit same-ID reuse verifies the physical stored bytes and requested summary but deliberately does not decode the artifact again to re-prove its logical ID
  • schema v1 remains one JSON value: there is no independent structural graph cap, and a stored payload allowed by a larger write cap can still be impossible to open/resume above the runtime string/decompression envelope
  • a stale .claim.cleaning consumes one of the 32 per-ID slots until an operator removes it while no save is active; hidden crash debris is intentionally excluded from the project artifact quota
  • cross-ID debris accounting and a project-wide journal remain checkpoint-v2 work

Verification

  • current-main restacked suite: 315 total, 312 passed, 0 failed, 3 expected sandbox/socket skips
  • fresh install from the current main lock reported 0 vulnerabilities
  • TypeScript build passed at exact restacked head 1298a17
  • all 10 fresh hosted push/PR checks passed at 1298a17 in runs 32530350483 and 32530354354
  • focused tests cover bounded readback, metadata-only list/prune, manifest tamper, pair-inclusive quota, six simultaneous child-process writers, same-process nonce owners, exact release/retry across processes and worker isolates, live-vs-dead corrupt-release handling, stale cleaning claims, portable stale-displaced takeover, deterministic crash windows, future-schema preservation, active digest caps above 512 MiB, and fixed-slot legacy growth/repair
  • two independent final protocol reviews found no remaining merge-readiness blocker in the byte-identical reviewed tree; the restack preserved its exact tree and stable patch ID
  • git diff --check origin/main...1298a17 passed

Related: #156, #215, #218.

@chaoz23 chaoz23 added the enhancement New feature or request label Aug 20, 2026
@chaoz23
chaoz23 force-pushed the agent/checkpoint-bounded-readback-followup branch from ff57b23 to 1298a17 Compare August 21, 2026 21:50
@chaoz23
chaoz23 changed the base branch from agent/pilot-finalization-followup to main August 21, 2026 21:50
@chaoz23
chaoz23 marked this pull request as ready for review August 22, 2026 02:48
@chaoz23
chaoz23 merged commit f5b051c into main Aug 22, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant