commit 76426ad7e9264c8ae50735abb82464cfb2046d4c
parent 66cd9c0663c2ee705433a36f5c0d46b5b1ea3598
Author: triesap <tyson@radroots.org>
Date: Wed, 23 Sep 2026 03:21:43 +0000
test(hyf): truthful startup-failure ownership and malformed controls (C002D review 2)
Second independent read-only review of 66cd9c0 returned FAIL. Repair within
ADR-0017 D37 PC01/PC02/PC05; test-only.
PC02/LC01: both provider startup-readiness failure paths now use one shared
finalize_owned_failure() that releases ownership only when no waitable child
can remain. An unproved/uncertain termination keeps reaped=false, invalidates
the report descriptor and records the exact pid plus reap status in the
caller-owned ledger instead of claiming collection. The raised startup error
also carries the pid and cleanup truth. Executed control drives the shared
finalizer with a controlled wait failure and with a real owned child.
PC01: the malformed lexical controls (unknown_status, invalid_count,
unknown_field, duplicate_field) now execute through BOTH provider reap paths,
not only the parser.
Re-verified on final source: provider-helpers 77/77, repo-local-process 9/9,
test-stdio 56/32/24/0 with identical D16 names and reasons, format/architecture/
build green.
Diffstat:
4 files changed, 113 insertions(+), 14 deletions(-)
diff --git a/tests/jev_provider_helper.mojo b/tests/jev_provider_helper.mojo
@@ -21,6 +21,7 @@ from parent_lifecycle import (
child_exit,
close_fd,
dup2_fd,
+ finalize_owned_failure,
fork_owned_or_close,
make_pipe,
now_ms,
@@ -620,24 +621,34 @@ def _spawn_child_or_cleanup(
try:
ready_line = state.read_line(STRICT_MAX_REPORT_BYTES, deadline_ms)
except e:
- var st = terminate_owned(pid, TERMINATION_GRACE_MS)
- state.status = st.copy()
- state.reaped = True
- state.close_reader()
+ var st = finalize_owned_failure(
+ state, pid, "jev startup readiness cleanup unproved"
+ )
raise Error(
"jev stub readiness failed ("
+ String(e)
+ + " pid="
+ + String(pid)
+ " / "
+ st.describe()
+ + " cleanup="
+ + ("proved" if st.cleanup_proved() else "unreaped")
+ ")"
)
var reported_port = 0
try:
reported_port = parse_ready_or_cleanup(pid, ready_line, 256)
except e:
- state.reaped = True
- state.close_reader()
- raise Error("jev stub malformed readiness (" + String(e) + ")")
+ _ = finalize_owned_failure(
+ state, pid, "jev startup malformed-readiness cleanup unproved"
+ )
+ raise Error(
+ "jev stub malformed readiness ("
+ + String(e)
+ + " pid="
+ + String(pid)
+ + ")"
+ )
_ = mode
return SpawnedJevStubAuto(
port=reported_port, stub=SpawnedJevStub(pid, state^)
diff --git a/tests/max_local_process_helper.mojo b/tests/max_local_process_helper.mojo
@@ -23,6 +23,7 @@ from parent_lifecycle import (
child_exit,
close_fd,
dup2_fd,
+ finalize_owned_failure,
fork_owned_or_close,
make_pipe,
now_ms,
@@ -734,22 +735,32 @@ def _spawn_max_local(
try:
ready_line = state.read_line(STRICT_MAX_REPORT_BYTES, deadline_ms)
except e:
- var st = terminate_owned(pid, TERMINATION_GRACE_MS)
- state.status = st.copy()
- state.reaped = True
- state.close_reader()
+ var st = finalize_owned_failure(
+ state, pid, "max_local startup readiness cleanup unproved"
+ )
raise Error(
"max_local stub readiness failed ("
+ String(e)
+ + " pid="
+ + String(pid)
+ " / "
+ st.describe()
+ + " cleanup="
+ + ("proved" if st.cleanup_proved() else "unreaped")
+ ")"
)
var reported_port = 0
try:
reported_port = parse_ready_or_cleanup(pid, ready_line, 256)
except e:
- state.reaped = True
- state.close_reader()
- raise Error("max_local stub malformed readiness (" + String(e) + ")")
+ _ = finalize_owned_failure(
+ state, pid, "max_local startup malformed-readiness cleanup unproved"
+ )
+ raise Error(
+ "max_local stub malformed readiness ("
+ + String(e)
+ + " pid="
+ + String(pid)
+ + ")"
+ )
return SpawnedMaxLocalStub(pid, reported_port, state^)
diff --git a/tests/parent_lifecycle.mojo b/tests/parent_lifecycle.mojo
@@ -860,6 +860,29 @@ def piped_child_state(
)
+def finalize_owned_failure(
+ mut state: PipedChildState, pid: Int, label: String
+) -> ProcessStatus:
+ """Reap-or-retain an owned child after a startup/readiness failure.
+
+ Uses the same ownership truth as ``cleanup``: ownership is released only
+ when no waitable child can remain. An unproved or uncertain termination
+ keeps ``reaped=False`` and records the failure in the caller-owned ledger,
+ so a startup failure can neither claim nor hide an uncollected child. The
+ report descriptor is invalidated in both cases because the failed startup
+ will never consume a report.
+ """
+ var st = terminate_owned(pid, TERMINATION_GRACE_MS)
+ state.status = st.copy()
+ state.close_reader()
+ if st.cleanup_proved():
+ state.reaped = True
+ else:
+ state.cleanup_error = "unreaped:" + st.describe()
+ state.ledger.record(label + " pid=" + String(pid) + " " + st.describe())
+ return st^
+
+
def parse_ready_line(line: String, max_bytes: Int) raises -> Int:
"""Parse the exact ``ready <port>`` grammar with a valid TCP port range."""
if line.byte_length() == 0:
diff --git a/tests/test_provider_helpers.mojo b/tests/test_provider_helpers.mojo
@@ -22,6 +22,7 @@ from parent_lifecycle import (
close_fd,
descriptor_census,
dup2_fd,
+ finalize_owned_failure,
fork_owned_or_close,
fork_owned_or_close3,
fork_pid,
@@ -1589,6 +1590,59 @@ def test_report_stream_controls_both_providers() raises:
0,
"missing_field",
)
+ _report_controls(
+ (
+ "result maybe phase=complete case=- reason=ok requests=1"
+ " connections=1\n"
+ ),
+ 0,
+ "unknown_status",
+ )
+ _report_controls(
+ "result ok phase=complete case=- reason=ok requests=x connections=1\n",
+ 0,
+ "invalid_count",
+ )
+ _report_controls(
+ (
+ "result ok phase=complete case=- reason=ok requests=1 connections=1"
+ " extra=z\n"
+ ),
+ 0,
+ "unknown_field",
+ )
+ _report_controls(
+ (
+ "result ok phase=complete case=- reason=ok requests=1 requests=1"
+ " connections=1\n"
+ ),
+ 0,
+ "duplicate_field",
+ )
+
+
+def test_startup_failure_cleanup_ownership_is_truthful() raises:
+ # PC02/LC01: the shared startup-failure finalizer used by both provider
+ # spawners must not claim an unproved termination as reaped; it records the
+ # exact pid and reap status in the caller-owned ledger.
+ var recorded = List[String]()
+ var ledger = CleanupLedger(UnsafePointer(to=recorded))
+ var state = piped_child_state(0, -1, 100, 1, ledger)
+ var status = finalize_owned_failure(state, 0, "startup cleanup unproved")
+ assert_true(not status.cleanup_proved())
+ assert_true(not state.reaped)
+ assert_true(state.cleanup_error.startswith("unreaped"))
+ assert_equal(len(recorded), 1)
+ assert_true(recorded[0].find("startup cleanup unproved") >= 0)
+ assert_true(recorded[0].find("pid=0") >= 0)
+
+ var stub = _owned_report_child(0, "")
+ var owned = stub.pid
+ var proved = finalize_owned_failure(stub.state, owned, "startup cleanup")
+ assert_true(proved.cleanup_proved())
+ assert_true(stub.state.reaped)
+ assert_true(pid_not_waitable(owned))
+ assert_equal(len(recorded), 1)
def test_descriptor_read_error_is_distinct_from_eof() raises: