Repository navigation
fix: recreate a missing managed runtime from the recorded bundle in setup - #42
Merged
Merged
Conversation
…etup Removing the container while state and the content-addressed bundle survive (remove --service without --purge-data, or a manual docker compose down) left setup unrecoverable: the matching-unhealthy recovery only knew docker restart, which refuses when the container is absent, while repair needs a profile attachment and remove --service cannot resolve a compose path without container labels. Setup's recovery branch now mirrors repair's recreate-runtime semantics: when the container is absent, recreate the runtime from the bundle named by the recorded configurationSha256 (restart unchanged for a wedged but present runtime); without a recorded digest the deployment is refused with E_STATE_INVALID instead of guessing a compose path. Verified against a live reproduction: compose down (volume kept) into a state that previously failed with 'Managed Docker resources are incomplete', then setup recreates the runtime and passes all nine status checks.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The bug
Removing the managed container while
state.jsonand the content-addressed bundle survive leavessetupunrecoverable:setupresolves the deployment as matching (state fields agree, ownership is'owned'through the surviving volume), readiness times out, and the recovery branch callsdocker restart— which refuses when the container is absent:E_STATE_INVALID: Managed Docker resources are incomplete.repairrefuses for lack of a profile attachment (removedetached it).remove --servicecannot resolve a compose path (it readscom.docker.compose.project.config_filesoff container labels that no longer exist).This is exactly the state
remove --servicewithout--purge-dataleaves (compose down, volume kept), observed live and recorded as finding 6 of the 2026-09-19 baseline window-2 report.The fix
Setup's matching-unhealthy recovery branch now mirrors the semantics repair's
recreate-runtimeaction already has:docker restart(unchanged);docker upagainst the bundle named by the recordedconfigurationSha256(bundleComposePath);E_STATE_INVALIDinstead of guessing a compose path.The subsequent flow (readiness → real search → attach or validate → commit) is unchanged; with no attachment the same recovery runs first, so the original detach-then-cleanup scenario is covered by the same code path.
Deliberately out of scope, recorded as a follow-up:
remove --service --purge-datastill needs a present container to resolve its compose path, so a full purge after a container-less leftover requires onesetupfirst. Changing what ownership verification means for a destructive command deserves its own discussion.Verification
test/cli/setup.test.ts(recreate-from-bundle with the recorded digest, refuse without one); harnessdeploymentStatusbecame configurable. All 75 setup tests green;pnpm verifygreen.docker compose down(volume kept) into the exact state that previously failed withManaged Docker resources are incomplete, then the fixedsetuprecreates the runtime andstatus --jsonpasses 9/9 checks.