hyf

Context-aware query service for Radroots
git clone https://radroots.dev/git/hyf.git
Log | Files | Refs | README | LICENSE

commit 76426ad7e9264c8ae50735abb82464cfb2046d4c
parent 66cd9c0663c2ee705433a36f5c0d46b5b1ea3598
Author: triesap <tyson@radroots.org>
Date:   Wed, 23 Sep 2026 03:21:43 +0000

test(hyf): truthful startup-failure ownership and malformed controls (C002D review 2)

Second independent read-only review of 66cd9c0 returned FAIL. Repair within
ADR-0017 D37 PC01/PC02/PC05; test-only.

PC02/LC01: both provider startup-readiness failure paths now use one shared
finalize_owned_failure() that releases ownership only when no waitable child
can remain. An unproved/uncertain termination keeps reaped=false, invalidates
the report descriptor and records the exact pid plus reap status in the
caller-owned ledger instead of claiming collection. The raised startup error
also carries the pid and cleanup truth. Executed control drives the shared
finalizer with a controlled wait failure and with a real owned child.

PC01: the malformed lexical controls (unknown_status, invalid_count,
unknown_field, duplicate_field) now execute through BOTH provider reap paths,
not only the parser.

Re-verified on final source: provider-helpers 77/77, repo-local-process 9/9,
test-stdio 56/32/24/0 with identical D16 names and reasons, format/architecture/
build green.

Diffstat:
Mtests/jev_provider_helper.mojo | 25++++++++++++++++++-------
Mtests/max_local_process_helper.mojo | 25++++++++++++++++++-------
Mtests/parent_lifecycle.mojo | 23+++++++++++++++++++++++
Mtests/test_provider_helpers.mojo | 54++++++++++++++++++++++++++++++++++++++++++++++++++++++
4 files changed, 113 insertions(+), 14 deletions(-)

diff --git a/tests/jev_provider_helper.mojo b/tests/jev_provider_helper.mojo @@ -21,6 +21,7 @@ from parent_lifecycle import ( child_exit, close_fd, dup2_fd, + finalize_owned_failure, fork_owned_or_close, make_pipe, now_ms, @@ -620,24 +621,34 @@ def _spawn_child_or_cleanup( try: ready_line = state.read_line(STRICT_MAX_REPORT_BYTES, deadline_ms) except e: - var st = terminate_owned(pid, TERMINATION_GRACE_MS) - state.status = st.copy() - state.reaped = True - state.close_reader() + var st = finalize_owned_failure( + state, pid, "jev startup readiness cleanup unproved" + ) raise Error( "jev stub readiness failed (" + String(e) + + " pid=" + + String(pid) + " / " + st.describe() + + " cleanup=" + + ("proved" if st.cleanup_proved() else "unreaped") + ")" ) var reported_port = 0 try: reported_port = parse_ready_or_cleanup(pid, ready_line, 256) except e: - state.reaped = True - state.close_reader() - raise Error("jev stub malformed readiness (" + String(e) + ")") + _ = finalize_owned_failure( + state, pid, "jev startup malformed-readiness cleanup unproved" + ) + raise Error( + "jev stub malformed readiness (" + + String(e) + + " pid=" + + String(pid) + + ")" + ) _ = mode return SpawnedJevStubAuto( port=reported_port, stub=SpawnedJevStub(pid, state^) diff --git a/tests/max_local_process_helper.mojo b/tests/max_local_process_helper.mojo @@ -23,6 +23,7 @@ from parent_lifecycle import ( child_exit, close_fd, dup2_fd, + finalize_owned_failure, fork_owned_or_close, make_pipe, now_ms, @@ -734,22 +735,32 @@ def _spawn_max_local( try: ready_line = state.read_line(STRICT_MAX_REPORT_BYTES, deadline_ms) except e: - var st = terminate_owned(pid, TERMINATION_GRACE_MS) - state.status = st.copy() - state.reaped = True - state.close_reader() + var st = finalize_owned_failure( + state, pid, "max_local startup readiness cleanup unproved" + ) raise Error( "max_local stub readiness failed (" + String(e) + + " pid=" + + String(pid) + " / " + st.describe() + + " cleanup=" + + ("proved" if st.cleanup_proved() else "unreaped") + ")" ) var reported_port = 0 try: reported_port = parse_ready_or_cleanup(pid, ready_line, 256) except e: - state.reaped = True - state.close_reader() - raise Error("max_local stub malformed readiness (" + String(e) + ")") + _ = finalize_owned_failure( + state, pid, "max_local startup malformed-readiness cleanup unproved" + ) + raise Error( + "max_local stub malformed readiness (" + + String(e) + + " pid=" + + String(pid) + + ")" + ) return SpawnedMaxLocalStub(pid, reported_port, state^) diff --git a/tests/parent_lifecycle.mojo b/tests/parent_lifecycle.mojo @@ -860,6 +860,29 @@ def piped_child_state( ) +def finalize_owned_failure( + mut state: PipedChildState, pid: Int, label: String +) -> ProcessStatus: + """Reap-or-retain an owned child after a startup/readiness failure. + + Uses the same ownership truth as ``cleanup``: ownership is released only + when no waitable child can remain. An unproved or uncertain termination + keeps ``reaped=False`` and records the failure in the caller-owned ledger, + so a startup failure can neither claim nor hide an uncollected child. The + report descriptor is invalidated in both cases because the failed startup + will never consume a report. + """ + var st = terminate_owned(pid, TERMINATION_GRACE_MS) + state.status = st.copy() + state.close_reader() + if st.cleanup_proved(): + state.reaped = True + else: + state.cleanup_error = "unreaped:" + st.describe() + state.ledger.record(label + " pid=" + String(pid) + " " + st.describe()) + return st^ + + def parse_ready_line(line: String, max_bytes: Int) raises -> Int: """Parse the exact ``ready <port>`` grammar with a valid TCP port range.""" if line.byte_length() == 0: diff --git a/tests/test_provider_helpers.mojo b/tests/test_provider_helpers.mojo @@ -22,6 +22,7 @@ from parent_lifecycle import ( close_fd, descriptor_census, dup2_fd, + finalize_owned_failure, fork_owned_or_close, fork_owned_or_close3, fork_pid, @@ -1589,6 +1590,59 @@ def test_report_stream_controls_both_providers() raises: 0, "missing_field", ) + _report_controls( + ( + "result maybe phase=complete case=- reason=ok requests=1" + " connections=1\n" + ), + 0, + "unknown_status", + ) + _report_controls( + "result ok phase=complete case=- reason=ok requests=x connections=1\n", + 0, + "invalid_count", + ) + _report_controls( + ( + "result ok phase=complete case=- reason=ok requests=1 connections=1" + " extra=z\n" + ), + 0, + "unknown_field", + ) + _report_controls( + ( + "result ok phase=complete case=- reason=ok requests=1 requests=1" + " connections=1\n" + ), + 0, + "duplicate_field", + ) + + +def test_startup_failure_cleanup_ownership_is_truthful() raises: + # PC02/LC01: the shared startup-failure finalizer used by both provider + # spawners must not claim an unproved termination as reaped; it records the + # exact pid and reap status in the caller-owned ledger. + var recorded = List[String]() + var ledger = CleanupLedger(UnsafePointer(to=recorded)) + var state = piped_child_state(0, -1, 100, 1, ledger) + var status = finalize_owned_failure(state, 0, "startup cleanup unproved") + assert_true(not status.cleanup_proved()) + assert_true(not state.reaped) + assert_true(state.cleanup_error.startswith("unreaped")) + assert_equal(len(recorded), 1) + assert_true(recorded[0].find("startup cleanup unproved") >= 0) + assert_true(recorded[0].find("pid=0") >= 0) + + var stub = _owned_report_child(0, "") + var owned = stub.pid + var proved = finalize_owned_failure(stub.state, owned, "startup cleanup") + assert_true(proved.cleanup_proved()) + assert_true(stub.state.reaped) + assert_true(pid_not_waitable(owned)) + assert_equal(len(recorded), 1) def test_descriptor_read_error_is_distinct_from_eof() raises: