Skip to content

test(sync): preserve Edge selected-CG lifetime and restart invariants #2364

Description

@branarakic

Outcome

Preserve the Edge selected-Context-Graph lifetime and restart acceptance scenarios from the retired M1 stack against today's subscription, selected-bootstrap, and recovery architecture.

This is an acceptance-first issue. Implement code only for scenarios that fail on current canary.

Current policy to preserve

  • always-on intent is durable and must resume after restart.
  • on-demand member intent remains process-local but keeps its live state for the process lifetime; the retired fix(sync): make Edge on-demand synchronization point-in-time #2045 point-in-time detach semantics are not being revived.
  • Broad sync disabled must not silently expand a selected Edge into all-CG/system-graph synchronization.
  • Authorization denial must remain distinguishable from local backpressure/deferral.

Related current work:

Scenarios to preserve

  1. A configured/durably saved always-on selection enters bounded VM and SWM recovery on first boot; a second restart is not required.
  2. After restart, the same selection resumes both finalized VM and live/shared-memory recovery while broad sync remains disabled.
  3. Runtime-only and on-demand selections are not promoted into durable periodic work.
  4. Removing or demoting a subscription while work is in flight invalidates later phases and prevents stale readiness/progress commits.
  5. With broad sync enabled, ordinary system/configured scope remains intact; the narrow selected path must not accidentally replace it.
  6. A pure authorization denial wins over local admission deferral in user-facing readiness.
  7. Evidence/status schema changes remain backward compatible or receive an explicit version bump.

Acceptance criteria

  • Each scenario has a focused current-canary test using production wiring rather than private prototype stubs where practical.
  • A real first-boot/restart gate proves exact VM and SWM outcomes for one selected graph and exclusion for one unselected graph.
  • Tests distinguish persisted intent, active process-local intent, Core hosting obligation, and readiness.
  • No new parallel mutable admission set is introduced; one current owner determines eligibility.
  • Any implementation change is split from the acceptance tests and limited to a demonstrated current gap.

Provenance

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions