Repository navigation
fix: harden cross-platform CI and lifecycle contracts - #8
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8124ffbc21
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| UV_PROJECT_ENVIRONMENT: ${{ runner.temp }}/virea-docs-venv | ||
| VIREA_HOME: ${{ runner.temp }}/virea-docs-home | ||
| UV_PROJECT_ENVIRONMENT: ${{ github.workspace }}/.ci/virea-docs-venv | ||
| VIREA_HOME: ${{ github.workspace }}/.ci/virea-docs-home |
There was a problem hiding this comment.
Keep VIREA_HOME outside the source checkout
When a job or test uses this ambient VIREA_HOME to initialize persistent state, VireaPaths.ensure_layout() detects that .ci/virea-docs-home is beneath the checked-out repository and raises ValueError("VIREA_HOME must be outside the VIREA source checkout") (packages/core/src/virea_core/paths.py:134-140); StateStore, ModelPool, and WorkerSupervisor all invoke that guard. The same unusable workspace-relative home is assigned to every Python job, so these paths should instead be exported from RUNNER_TEMP in a step or otherwise resolve outside github.workspace.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: afdb6402ec
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| __version__ = "0.4.0" | ||
|
|
||
|
|
||
| def __getattr__(name: str) -> Any: |
There was a problem hiding this comment.
Preserve the app export after direct submodule imports
When virea_api.app is imported before the package-level export (for example, the CLI's virea_api.app:create_app target), importlib assigns the submodule to virea_api.app. A later from virea_api import app then returns that module without invoking __getattr__; in from virea_api import app, create_app, resolving create_app eventually repairs the package attribute, but the local app binding remains the module. The previous eager initializer consistently exposed the FastAPI instance regardless of import order, so the lazy implementation needs to account for direct child-module imports as well.
Useful? React with 👍 / 👎.
| __version__ = "0.4.0" | ||
|
|
||
|
|
||
| def __getattr__(name: str) -> Any: |
There was a problem hiding this comment.
Preserve the app export after direct submodule imports
When virea_api.app is imported before the package-level export (for example, the CLI's virea_api.app:create_app target), importlib assigns the submodule to virea_api.app. A later from virea_api import app then returns that module without invoking __getattr__; in from virea_api import import app, create_app, resolving create_app eventually repairs the package attribute, but the local app binding remains the module. The previous eager initializer consistently exposed the FastAPI instance regardless of import order, so the lazy implementation needs to account for direct child-module imports as well.
Useful? React with 👍 / 👎.
| _make_internal_asset_root_movable(asset_root) | ||
| os.replace(asset_root, destination) |
There was a problem hiding this comment.
Re-harden assets when recovering interrupted quarantines
If the control-plane process exits after _make_internal_asset_root_movable() succeeds but before this operation re-hardens the destination, the durable journal recovery accepts either the still-present source or the moved destination and removes the journal without calling _make_internal_asset_read_only(). This new interruption window therefore leaves a stable model-asset root owner-writable after restart, despite the quarantine journal specifically existing to stabilize interrupted operations; recovery should restore the read-only mode in both accepted states.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 39b95ccb13
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| raise ProcessInspectionError( | ||
| f"proc_pidinfo returned an invalid creation time for Worker PID {pid}" | ||
| ) | ||
| return f"{seconds}.{microseconds:06d}" |
There was a problem hiding this comment.
Migrate persisted macOS creation tokens
When a macOS control plane is upgraded or restarted while a Worker recorded by the previous release remains alive, its persisted v1 creation_token contains normalized ps -o lstart text, while this function now returns epoch microseconds. recover_orphans() compares those strings exactly, so it marks the genuine Worker RECOVERY_BLOCKED, and admission_blocked subsequently rejects production jobs; because the diagnostics schema remains virea.worker_process_identity.v1, no migration path is selected. Preserve or recognize the legacy token format during recovery, or version and migrate this identity field.
Useful? React with 👍 / 👎.
Summary
posix_spawn/execValidation
The macOS ARM and Intel jobs exercise the real libproc/sysctl Worker recovery path. This PR remains unmerged until the hosted Windows/Linux/macOS/Web matrix is green.