Skip to content

fix: harden cross-platform CI and lifecycle contracts - #8

Merged
Joker-of-Gotham merged 5 commits into
mainfrom
codex/fix-refactor-ci-context
Aug 25, 2026
Merged

Joker-of-Gotham merged 5 commits into
mainfrom
codex/fix-refactor-ci-context

Conversation

@Joker-of-Gotham

@Joker-of-Gotham Joker-of-Gotham commented Aug 25, 2026 •

Copy link
Copy Markdown
Member

Summary

  • harden CI environment paths and suppress duplicate branch/PR runs
  • make API imports lazy and repair Windows, WSL/Linux, and macOS lifecycle races
  • persist the final post-readiness Worker identity across macOS posix_spawn/exec
  • guarantee StateStore failures cannot gate process-tree termination, and reap every Worker snapshot before reporting errors
  • make generation feedback deterministic and serialize HTTP/WebSocket VIREA_HOME authority through the durable POST boundary
  • preserve bilingual UTF-8 CLI output, safe legacy-code-page fallback, and cross-platform public-path redaction

Validation

  • Windows full Python repository suite: 725 passed, 34 skipped
  • Linux/WSL Worker, execution-domain, and cancellation contracts: 63 passed, 5 skipped
  • Web unit/browser/viewer suite: 68 passed; production TypeScript/Vite build passed
  • original browser race scenarios: 6/6 repeated stress runs passed
  • legacy viewer suites: 60 passed
  • documentation: 141 Markdown files; 6 tests passed
  • Ruff lint/format (398 files), 18 runtime locks, generated docs, GitNexus impact mapping, and git diff checks passed
  • independent final diff review: approved, no P0/P1/P2 findings

The macOS ARM and Intel jobs exercise the real libproc/sysctl Worker recovery path. This PR remains unmerged until the hosted Windows/Linux/macOS/Web matrix is green.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8124ffbc21

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/refactor-ci.yml Outdated
UV_PROJECT_ENVIRONMENT: ${{ runner.temp }}/virea-docs-venv
VIREA_HOME: ${{ runner.temp }}/virea-docs-home
UV_PROJECT_ENVIRONMENT: ${{ github.workspace }}/.ci/virea-docs-venv
VIREA_HOME: ${{ github.workspace }}/.ci/virea-docs-home

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep VIREA_HOME outside the source checkout

When a job or test uses this ambient VIREA_HOME to initialize persistent state, VireaPaths.ensure_layout() detects that .ci/virea-docs-home is beneath the checked-out repository and raises ValueError("VIREA_HOME must be outside the VIREA source checkout") (packages/core/src/virea_core/paths.py:134-140); StateStore, ModelPool, and WorkerSupervisor all invoke that guard. The same unusable workspace-relative home is assigned to every Python job, so these paths should instead be exported from RUNNER_TEMP in a step or otherwise resolve outside github.workspace.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: afdb6402ec

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

__version__ = "0.4.0"


def __getattr__(name: str) -> Any:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve the app export after direct submodule imports

When virea_api.app is imported before the package-level export (for example, the CLI's virea_api.app:create_app target), importlib assigns the submodule to virea_api.app. A later from virea_api import app then returns that module without invoking __getattr__; in from virea_api import app, create_app, resolving create_app eventually repairs the package attribute, but the local app binding remains the module. The previous eager initializer consistently exposed the FastAPI instance regardless of import order, so the lazy implementation needs to account for direct child-module imports as well.

Useful? React with 👍 / 👎.

__version__ = "0.4.0"


def __getattr__(name: str) -> Any:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve the app export after direct submodule imports

When virea_api.app is imported before the package-level export (for example, the CLI's virea_api.app:create_app target), importlib assigns the submodule to virea_api.app. A later from virea_api import app then returns that module without invoking __getattr__; in from virea_api import import app, create_app, resolving create_app eventually repairs the package attribute, but the local app binding remains the module. The previous eager initializer consistently exposed the FastAPI instance regardless of import order, so the lazy implementation needs to account for direct child-module imports as well.

Useful? React with 👍 / 👎.

Comment on lines +779 to 780
_make_internal_asset_root_movable(asset_root)
os.replace(asset_root, destination)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Re-harden assets when recovering interrupted quarantines

If the control-plane process exits after _make_internal_asset_root_movable() succeeds but before this operation re-hardens the destination, the durable journal recovery accepts either the still-present source or the moved destination and removes the journal without calling _make_internal_asset_read_only(). This new interruption window therefore leaves a stable model-asset root owner-writable after restart, despite the quarantine journal specifically existing to stabilize interrupted operations; recovery should restore the read-only mode in both accepted states.

Useful? React with 👍 / 👎.

@Joker-of-Gotham Joker-of-Gotham changed the title ci: repair cross-platform workflow environment paths fix: harden cross-platform CI and lifecycle contracts Aug 25, 2026
@Joker-of-Gotham
Joker-of-Gotham merged commit 54ca222 into main Aug 25, 2026
9 checks passed
@Joker-of-Gotham
Joker-of-Gotham deleted the codex/fix-refactor-ci-context branch August 25, 2026 14:16

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 39b95ccb13

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

raise ProcessInspectionError(
f"proc_pidinfo returned an invalid creation time for Worker PID {pid}"
)
return f"{seconds}.{microseconds:06d}"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Migrate persisted macOS creation tokens

When a macOS control plane is upgraded or restarted while a Worker recorded by the previous release remains alive, its persisted v1 creation_token contains normalized ps -o lstart text, while this function now returns epoch microseconds. recover_orphans() compares those strings exactly, so it marks the genuine Worker RECOVERY_BLOCKED, and admission_blocked subsequently rejects production jobs; because the diagnostics schema remains virea.worker_process_identity.v1, no migration path is selected. Preserve or recognize the legacy token format during recovery, or version and migrate this identity field.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant