Files
Garry Tan d13aa742fd
Some checks failed
Actionlint / actionlint (push) Failing after 16s
E2E Tests / Tier 2 (LLM Skills) (push) Has been skipped
Release / version (push) Successful in 5s
Test / gitleaks (push) Failing after 59s
Test / security-regressions (1.3.11, ubuntu-latest) (push) Failing after 10m54s
Test / security-regressions (1.3.13, ubuntu-latest) (push) Failing after 10m49s
Test / dependency-audit (push) Successful in 9s
Test / verify (push) Failing after 11s
Test / serial-tests (1) (push) Failing after 1m4s
Test / serial-tests (2) (push) Failing after 14s
Test / serial-tests (3) (push) Failing after 14s
Test / serial-tests (4) (push) Failing after 14s
Test / slow-eval-longmemeval (push) Failing after 11s
Test / slow-brainbench-e2e (push) Failing after 13s
Test / brainbench (push) Failing after 10s
Test / slow-entity-resolve-perf (push) Failing after 12s
Test / test (1) (push) Failing after 28s
Test / test (10) (push) Failing after 27s
Test / test (2) (push) Failing after 26s
Test / test (3) (push) Failing after 34s
Test / test (4) (push) Failing after 39s
Test / test (5) (push) Failing after 36s
Test / test (6) (push) Failing after 36s
Test / test (7) (push) Failing after 22s
Test / test (8) (push) Failing after 42s
Test / test (9) (push) Failing after 23s
Test / native-locks (push) Failing after 23m32s
Test / persistence-validation (push) Failing after 38m54s
Release / build (gbrain-linux-x64, ubuntu-latest, bun-linux-x64) (push) Failing after 11m35s
Test / coverage-report (push) Failing after 27s
Test / Native-only result (full CI not run) (push) Has been skipped
Release / build (gbrain-darwin-arm64, macos-latest, bun-darwin-arm64) (push) Has been cancelled
Test / security-regressions (1.3.11, macos-latest) (push) Has been cancelled
Test / security-regressions (1.3.11, windows-latest) (push) Has been cancelled
Test / security-regressions (1.3.13, macos-latest) (push) Has been cancelled
Test / security-regressions (1.3.13, windows-latest) (push) Has been cancelled
Release / release (push) Has been cancelled
Release / publish-template (push) Has been cancelled
Release / publish-codex-plugin (push) Has been cancelled
Test / ${{ github.event_name == 'workflow_dispatch' && inputs.native_only == true && 'full-suite-not-run' || 'test-status' }} (push) Has been cancelled
E2E Tests / JSONB parity (#2339 regression guard) (push) Failing after 12s
E2E Tests / prepare-e2e (push) Failing after 11s
E2E Tests / Selected E2E (diff-relevant) ${{ matrix.shard }} (push) Has been skipped
E2E Tests / Tier 1 (Mechanical) (push) Failing after 11s
E2E Tests / coverage-full-unit (1) (push) Failing after 24s
E2E Tests / coverage-full-unit (10) (push) Failing after 24s
E2E Tests / coverage-full-unit (2) (push) Failing after 21s
E2E Tests / coverage-full-unit (3) (push) Failing after 31s
E2E Tests / coverage-full-unit (4) (push) Failing after 33s
E2E Tests / coverage-full-unit (5) (push) Failing after 30s
E2E Tests / coverage-full-unit (6) (push) Failing after 30s
E2E Tests / coverage-full-unit (7) (push) Failing after 19s
E2E Tests / coverage-full-unit (8) (push) Failing after 37s
E2E Tests / coverage-full-unit (9) (push) Failing after 18s
E2E Tests / coverage-full-serial (push) Failing after 8s
E2E Tests / coverage-full-slow (push) Failing after 8s
E2E Tests / coverage-full-e2e (push) Failing after 11s
E2E Tests / coverage-full-report (push) Failing after 13s
E2E Tests / e2e-status (push) Failing after 0s
OSV-Scanner / osv-scan (push) Failing after 0s
Semgrep / semgrep (push) Failing after 0s
Heavy Tests / Heavy tests (push) Failing after 10s
Heavy Tests / Real-agent door e2e (skips without authed binaries) (push) Failing after 9s
Heavy Tests / Hermes door e2e (real binary, loud-fail) (push) Failing after 10s
Heavy Tests / Grok door e2e (real binary, keyless-first) (push) Has been skipped
Heavy Tests / Plugin doors (codex + claude, install tier) (push) Failing after 9s
Heavy Tests / opencode door e2e (real binary, keyless SMOKE) (push) Failing after 10s
Heavy Tests / opencode door canary (latest, keyless, non-gating) (push) Failing after 9s
v0.51.0.0 feat: make concurrent writes durable and revision-safe (#5149)
* Add typed mutation receipts and preserve pending write errors

* Add canonical page revisions, snapshot reads, and composable transaction guards

* fix: add portable native writer locks and runtime gates

* Route PGLite operations through bounded local persistence IPC

* Add durable mutation admission and recoverable canonical page publication

* Prepare CLI mutations before connecting and preserve replay intent

* Wire resident writer ingress and fence unmanaged canonical mutation

* Fence derived projections by canonical revision and persist withdrawal rebuild work

* Expose principal-scoped durable write receipts without widening grants

* fix: retain datastore ownership through shutdown and fence lease cleanup

* Journal memory verbs and publish semantic fact updates under canonical guards

* Coordinate semantic page mutations and seal only current sanitized projections

* Administer resident writers through authenticated local CLI IPC

* Journal takes mutations and share long-hold budgets across physical pools

* Route take mutations through replayable operations before opening PGLite

* Compose canonical projections with publication and retry transient database contention

* Document concurrent write guarantees and explicit receipt grant migration

* test: exercise durable persistence schedules and process crash recovery

* Apply shared persistence limits and compact permanent receipts with exact accounting

* fix: honor explicit direct routes for generic Postgres poolers

* Retain original page visibility ceilings and intentional sandbox persistence

* test: verify pooler capacity and owner incarnation fencing

* Preserve canonical projection round trips and timeline detail through recovery

* Wire persistence distribution guards and refresh public operation documentation

* Retry postcommit effects and recover withdrawal mirrors independently

* Include outbox schema in snapshot identities and isolate fresh test brains

* Fence legacy canonical writers and require revision-safe imports

* Activate managed persistence only after explicit quiescence and durable fencing

* Require honest median-of-three read latency under public writer load

* Require writer progress during read latency samples

* Compose graph reconciliation with canonical publication and retain writer ceilings

* Exercise source-scoped takes and duplicate fences with durable principals

* Preserve transaction receivers when restoring extraction test stubs

* Install revision-bound retrieval fixtures and preserve strict projection gates

* Keep engine test overrides composable across transaction clones

* Assert atomic readback rollback and public failed write receipts

* Settle definite publication failures and preserve typed receipts across CLI boundaries

* Restore bounded fact extraction receipts and durable postpublication scheduling

* Share activation fixtures within explicit engine lifecycles

* Model scoped read transactions and publish complete retrieval fixtures

* Coordinate resumable owner-scoped Markdown sync through durable page receipts

* Exercise page source and privacy boundaries with durable writer fixtures

* Publish complete search fixtures and assert composable scoped SQL routing

* fix: retain archived alias reads and expose writer ingress diagnostics

* Exercise managed writer activation in persistence validation workloads

* Publish revision-bound ranker and max-pool retrieval fixtures

* test: bind engine fixtures to coherent page projections and durable writes

* fix: compare enrichment against its original page snapshot

* fix: preserve withdrawal markers across legacy history and projection rebuilds

* fix: authenticate resident sync ingress and prevent writer starvation

* fix: durably acknowledge recovery and advance missing-file withdrawal effects

* Retain mutation identity and revision through internal caller retries

* Preserve contextual wrapping for deferred coordinated embeddings

* Install coherent retrieval fixtures and inspect raw chunk state explicitly

* fix: budget and fairly schedule standalone publication recovery

* Keep privacy and image fixtures aligned with projection visibility

* Bind embedding provenance to the prepared provider context

* Publish complete relational and search regression fixtures

* Preserve raw registry write checks and seal deferred embedding fixtures

* Retry coordinated imports when source policy cannot be read

* Preserve legacy migration data and exercise revision-aware public writers

* Coordinate managed source lifecycle and durable clone recovery

* fix: bind owner identity to the physical canonical checkout

* fix: reserve control capacity during source lifecycle publication

* fix: preserve delegated sync recovery and deferred embed ownership

* Verify lifecycle staging identity and preserve bounded recovery

* fix: account for pending clone requests in shared admission quotas

* test: align retrieval and replay fixtures with durable publication

* Release clone reservations exactly once and recheck source routing

* Require PostgreSQL lifecycle and recovery contracts in CI

* test: require physical-root refusal in the deployment matrix

* Route source administration through resident ownership and retained identities

* fix: retain captured canonical file routing under registered ownership

* test: exercise authenticated atomic take publication and retained replay IDs

* Retry confirmed admission aborts and preserve direct CLI conflict receipts

* Fix revision-safe import revival and preserve identity deduplication

* test: publish embedding migration fixtures before re-embedding

* Exercise durable publication with the actual release executable

* Exercise conditional embedding updates with coherent serial fixtures

* Verify clean resident EOF shutdown in the release smoke

* Seal search fixtures and assert durable side-effect outcomes

* Bound recovery preparation and exercise admission timeout receipts

* fix: retain delegated ownership and enforce take receipt holder grants

* Restore tombstoned pages consistently and preserve unexpected local files

* Preserve deletion state in canonical page versions

* Retry withdrawals after releasing the complete transaction

* Keep canonical version deletion schema bootstraps consistent

* Keep canonical version types beside page state

* Filter protected timeline content from remote version history

* Require PostgreSQL version history privacy coverage

* Require explicit native test timeouts in every CI entry point

* Bind Windows native locks to the active runtime API

* Test fact authorization with durable source grants

* Wait for authenticated persistence readiness in compiled CLI smoke

* Seal search fixtures against their canonical page revisions

* Refresh managed lifecycle fixtures and reviewed canonical writer inventory

* Measure staging bytes in clone metadata quota regression

* Preserve canonical write provenance and typed storage failures

* Measure durable admission through stable warmed workload instrumentation

* Require both engines in durable admission instrumentation regression

* Preserve bounded soak failure diagnostics and test fixtures

* Exercise timeout preflight in local CI execution fixtures

* Verify tombstone restoration values and stable no-op bytes

* Keep native workflow coverage checks compatible with explicit timeouts

* fix: bind local IPC safely across long paths and concurrent owners

* Require IPC ownership and path tests on every native target

* fix: preserve inaccessible IPC owners when Bun loses connect errno

* Isolate PgBouncer fixtures from test database guards and shard resets

* ci: isolate native-only dispatches from full persistence validation

* Keep agent seed worktrees outside their coordination state

* Seal expert search fixtures at their canonical page revision

* test: exercise durable PostgreSQL take publication and replay

* fix: retain native ownership across Windows IPC listeners

* fix: serve admin SPA from hidden checkout directories

* fix: derive Windows pipe claims from NT Unicode upcasing

* test: match Unicode IPC aliases to actual Windows pipe equality

The four Windows runners in run35037789501 proved dotless-i and I are
separate pipe names: kernel_alias=false, CompareStringOrdinal=3, with
identical NT and invariant-locale case tables. Keep both independent
providers in coverage and require genuine sigma/accent aliases to share
one live provider and native claim. Preserve the native API oracle.

Restore the exact native source, build recipe, manifest and artifacts from
2a703bb9875f214708d0c23b070fdd188ed3b459; the provisional NT upcase change
was unnecessary. All six non-Windows artifacts remain byte-identical.

Input SHA256:
before b86ba93886091ab6b8dbba48c891966680ed3484b5d815ac31684da401f1ec73
after  4759bdd927c0c0fa29c2d5af30e42972a183f9be006d595144d73b6ca1111636
Windows x64 SHA256:
before f5c9d45e261757b510979534b447bb118e95d5699c3dd6e8f1ec31200c6372aa
after  0b494ec94896219a3b142b6f216bf12c9ee94d27fa7e7399bcdab707ca60212e
Windows ARM64 SHA256:
before 74fe0d4e8205738675ba5dcccf55edbf5bb250ec96724b84b3490c30e3e27bf2
after  e8315b4453dce3df775eeb76c73e8895c273390e64b16a2c255e10790fa75dd7

* Repair merged fixtures for revision-bound chunk reads

* Require local legacy-chunk reads to honor projection seals

* Account for reviewed upstream canonical write references

* Isolate ambient keyset fixture page clocks from fact writes

* fix: settle publication failures beneath blocked file ancestors

* Match TTL vector fixture to the initialized fact column

* Record coordinated purge in canonical writer census

* docs: align concurrent persistence contracts and sync guidance

* fix: fence projection replacement to its originating snapshot

* fix: bound unit shard processes without dropping coverage

* fix: publish embedding vectors and contextual completion atomically

* test: isolate thin-client health and write fixtures

* test: isolate healthy doctor checks from retained E2E grants

* test: isolate each local unit file in its own Bun process

* fix: keep persistence parameter schemas free of registry cycles

* test: restore thin-client routing exit state

* style: consolidate page operation engine imports

* fix: isolate purge validator from generic flag scans

* test: isolate Postgres bootstrap ownership fixture

* test: isolate open-loop engine parity database

* chore: bump version and changelog (v0.51.0.0)

Document the coordinated concurrent-writer upgrade and synchronize the
release manifests, migration guide, generated stamps and skills lock.

Co-Authored-By: Codex <noreply@openai.com>

* docs: update concurrent-write guide for v0.51.0.0

* fix: resolve concurrency persistence security scan findings

---------

Co-authored-by: Codex <noreply@openai.com>
2026-09-17 06:44:17 -07:00
..

Native writer locks

locks.c is a first-party C Node-API v3 addon exposing opaque openLock, nonblocking tryLock, and idempotent close operations. POSIX uses flock; Windows uses LockFileEx. The kernel releases ownership on process death. The TypeScript wrapper in src/core/persistence/native-lock.ts adds cancellable asynchronous waiting, defaults to a 5-second deadline and 25-ms polling, and loads the addon only when a caller needs lock capability.

The caller must supply an absolute, stable lock path in a host-controlled directory outside any replaceable datastore or worktree. Keep the file after release. Never unlink, rotate, copy over, or infer ownership from its age or metadata: replacing a locked inode can permit two owners. Leaf symlinks, reparse points and nonregular files are rejected. Directory confinement and the filesystem's cross-process lock semantics are prerequisites supplied by the host; this binding does not establish distributed ownership across hosts. An unavailable addon or an OS error produces writer_lock_unavailable. There is no timestamp, PID, or TTL ownership fallback. A close failure must stop publication; it cannot be treated as successful relinquishment.

Windows IPC adds two narrowly scoped operations in windows-ipc.h. Named pipes retain a nonblocking Global kernel mutex from before probing through the listener's actual close. Windows invariant Unicode uppercase plus CNG SHA-256 gives case and prefix aliases one identity independent of homes and logon sessions. The environment registry and a small shared kernel owner record prevent recursive acquisition through separate addon copies on the same thread; opaque finalizers and cleanup release on the owning thread. Failed finalizer release retains the handle and registry reference until verified cleanup. Abandoned mutexes are acquired only through the kernel. Namespace permission errors refuse binding.

For a provably dead Windows AF_UNIX listener, cleanup requires a still-held opaque file binding claim. It opens the leaf without following reparse points, verifies IO_REPARSE_TAG_AF_UNIX, and marks that exact handle for deletion. Ordinary files, directories, other reparse tags and access errors are refused. This avoids treating Bun's stale-socket lstat errors as proof that an arbitrary filesystem entry may be removed.

Distribution and reproducible builds

All eight addons are checked in, so source installs work with bun install --frozen-lockfile --ignore-scripts. They support x64 and arm64 on Linux glibc (2.17 ABI baseline), Linux musl, macOS (13.0 deployment target), and Windows. Supported Bun versions are tested at the repository's minimum, 1.3.11, and release version, 1.3.13. OS compatibility also requires the selected Bun version's own platform minimums.

Node-API headers and their upstream license are vendored from Node v22.15.0. darwin-abi.h declares the narrow public Darwin LP64 ABI needed for SDK-free cross-compilation, with constants/layout checked against Apple XNU tag xnu-11215.81.4; macOS CI compiles abi-check.c against the actual SDK. The x86_64 fstat$INODE64 symbol and arm64 fstat symbol are distinct. No Apple SDK is redistributed. Windows resolves its used Node-API symbols from the running executable through windows-napi.h, including renamed compiled CLIs. It never loads a separate node.exe. A process-wide once guard publishes the complete function table before any API call; missing exports refuse registration without borrowing another runtime's environment. The Windows IPC helpers link the OS-provided bcrypt CNG library and remain within Node-API v3 and the existing Windows platform minimum.

Use the pinned Zig 0.14.1 compiler. Archive URLs, SHA-256 hashes and sizes are in scripts/native/toolchain.json; setup verifies them before extracting.

bun scripts/native/setup-toolchain.ts --dir .context/native-toolchain
ZIG=/absolute/path/to/the/downloaded/zig bun scripts/native/build.ts --target all --write-manifest
bun scripts/native/verify.ts
ZIG=/absolute/path/to/the/downloaded/zig bun scripts/native/build.ts --output /tmp/native-rebuilt
bun scripts/native/verify.ts --rebuilt /tmp/native-rebuilt

The manifest hashes every addon plus the build inputs, compiler recipe and toolchain metadata. Commit source, all eight regenerated binaries and the manifest together. Builds fix the source timestamp, macOS install name and Linux build ID behavior to permit byte-for-byte comparison across output directories. CI rebuilds each target on its platform and compares bytes.

Runtime validation

bun test test/native-lock.test.ts runs real competing Bun processes, retained-inode checks, cancellation, deadline cleanup, live-holder staleness, SIGKILL recovery, and fail-closed missing-addon/invalid-path cases. test/scripts/native-lock-prebuilds.test.ts proves source/binary tampering fails verification and checks that the required CI matrix covers all sixteen target/runtime pairs. Native CI also runs the tests in native musl userspace.

bun scripts/native/compiled-smoke.ts builds a focused executable importing the exact production wrapper, proves two compiled processes exclude each other, kills the holder and proves immediate handoff. Release CI additionally passes --binary bin/<artifact> to require that the actual CLI executable embeds the exact current-platform addon. That assertion verifies packaging; the focused executable verifies compiled lock execution.

bun scripts/native/cli-persistence-smoke.ts --binary bin/<artifact> copies the actual release executable outside the source checkout and exercises keyless disk-PGLite initialization, native ownership activation, canonical publication, revision conflicts with typed receipts, exact replay, resident stdio/CLI IPC, and shutdown/reopen. Release CI runs it for both published Linux x64 and macOS arm64 artifacts. Child homes and credentials are isolated; the script never loads repository TypeScript or adjacent native files to satisfy the executable.