fix(runtime): retain publications when recovery state is unreadable

This commit is contained in:
Alexandre Teixeira
2026-10-02 23:39:13 +01:00
parent 3834cd72b1
commit 3db903c336
2 changed files with 19 additions and 3 deletions
+9 -3
View File
@@ -452,13 +452,19 @@ def prune_foreground_publications():
A dead/replaced manager cannot resume attachment. A missing receipt also
makes attachment impossible; publication cannot reconstruct that receipt.
Its process tree still
belongs to containment recovery; deleting a publication never signals or
Its process tree still belongs to containment recovery; deleting a publication never signals or
asserts tree death. Live/unverifiable managers and background history stay.
"""
from src import containment
from src import process_ownership
receipts = containment._load_records()
try:
receipts = json.loads(containment._store_path().read_text())
except FileNotFoundError:
receipts = {}
except (OSError, ValueError):
return 0 # Unreadable state is not evidence that consumers are gone.
if not isinstance(receipts, dict) or any(not isinstance(r, dict) for r in receipts.values()):
return 0
retired = 0
for path in _LAUNCH_DIR.glob("*.json"):
try:
+10
View File
@@ -168,3 +168,13 @@ def test_missing_receipt_publication_cannot_recover_authority(workspace):
assert resources.prune_foreground_publications() == 1
assert not resources.launch_path(launch.generation).exists()
assert not containment._load_records()
@pytest.mark.parametrize('receipt_data', ['{corrupt', '[]', '{"receipt":null}'])
def test_unreadable_receipts_cannot_retire_live_consumers(workspace, receipt_data):
admitted = authority(workspace)
launch = resources.resolve_process_operation(admitted, ExactOperation.normalize('bash', 'printf pending'), NativeBackendResource('bash')).launch
resources.publish_launch(launch, admitted, 'receipt')
containment._store_path().write_text(receipt_data)
assert resources.prune_foreground_publications() == 0
assert resources.launch_path(launch.generation).is_file()