fleetd #226: reserve architect slots before launch #228

Merged
ltms merged 2 commits from worker/cb226-architect-slot-race-cd3aa8-3 into main 2026-09-02 02:54:52 +02:00
Member

Fixes fleetd #226.

Production change

  • Add atomic architect-slot reservations in MemberRegistry.
  • SessionManager reserves before launch, binds after launch, and releases on every RuntimeException path before a successful bind.
  • A full architect pool refuses before the launcher starts a process. The acquired fallback and WARN remain for an unexpected failed reservation bind.
  • Correct the terminalToSlot lock comment.

Tests

  • aContendedArchitectSlotRefusesBeforeTheLauncherStartsAMember drives SessionManager.acquire with a real ClaudeCodeLauncher/FakeHerdr and proves agent.start was never called. This is the proof that no member receives a wrong charter.
  • aSecondArchitectOnAnAlreadyBoundProfileIsHeldAsDevNotArchitectAndWarnsLoudly reserves successfully, simulates a racer taking the released slot so bind fails, then drives SessionManager.acquire. It asserts DEV and checks the WARN names the profile and terminal. I watched this test fail first: Tests run: 1, Failures: 1, Errors: 0; expected ARCHITECT but was DEV.
  • reservedArchitectSlotBindsTheLaunchedMember checks the successful live binding.
  • failedArchitectLaunchReleasesItsReservationForTheNextLaunch makes a real spawn fail its readiness gate, then a retry succeeds as ARCHITECT.
  • Updated the worktree capacity expectation to refuse before launch.

Charter receipt correction
I dropped the claim that CharterReceipt.role proves charter delivery. That field echoes the request. The no-agent.start contention test is the criterion 4 proof.

Reservation release
I counted two acquire branches: normal and worktree. In the normal branch, one RuntimeException catch covers launcher.spawn and later setup before return; it releases an unbound reservation. In the worktree branch, the outer RuntimeException catch releases the reservation for worktree setup, launcher.spawn, and setup after launch. A successful bind removes the reservation and creates the live terminal binding, so it must not be released. The failed-readiness-then-retry test covers the launcher exception path.

Build
mvn clean install
Tests run: 1092, Failures: 0, Errors: 0, Skipped: 0
BUILD SUCCESS

Fixes fleetd #226. Production change - Add atomic architect-slot reservations in MemberRegistry. - SessionManager reserves before launch, binds after launch, and releases on every RuntimeException path before a successful bind. - A full architect pool refuses before the launcher starts a process. The acquired fallback and WARN remain for an unexpected failed reservation bind. - Correct the terminalToSlot lock comment. Tests - aContendedArchitectSlotRefusesBeforeTheLauncherStartsAMember drives SessionManager.acquire with a real ClaudeCodeLauncher/FakeHerdr and proves agent.start was never called. This is the proof that no member receives a wrong charter. - aSecondArchitectOnAnAlreadyBoundProfileIsHeldAsDevNotArchitectAndWarnsLoudly reserves successfully, simulates a racer taking the released slot so bind fails, then drives SessionManager.acquire. It asserts DEV and checks the WARN names the profile and terminal. I watched this test fail first: Tests run: 1, Failures: 1, Errors: 0; expected ARCHITECT but was DEV. - reservedArchitectSlotBindsTheLaunchedMember checks the successful live binding. - failedArchitectLaunchReleasesItsReservationForTheNextLaunch makes a real spawn fail its readiness gate, then a retry succeeds as ARCHITECT. - Updated the worktree capacity expectation to refuse before launch. Charter receipt correction I dropped the claim that CharterReceipt.role proves charter delivery. That field echoes the request. The no-agent.start contention test is the criterion 4 proof. Reservation release I counted two acquire branches: normal and worktree. In the normal branch, one RuntimeException catch covers launcher.spawn and later setup before return; it releases an unbound reservation. In the worktree branch, the outer RuntimeException catch releases the reservation for worktree setup, launcher.spawn, and setup after launch. A successful bind removes the reservation and creates the live terminal binding, so it must not be released. The failed-readiness-then-retry test covers the launcher exception path. Build mvn clean install Tests run: 1092, Failures: 0, Errors: 0, Skipped: 0 BUILD SUCCESS
agent added 1 commit 2026-09-02 02:45:28 +02:00
#226 reserve architect slots before launch
CI / contract (pull_request) Successful in 1m19s
CI / build (pull_request) Failing after 1m33s
e694deace3
agent added 1 commit 2026-09-02 02:50:37 +02:00
#226 retain architect fallback coverage
CI / contract (pull_request) Successful in 1m17s
CI / build (pull_request) Successful in 1m33s
b40f477210
ltms merged commit cc919aa2b6 into main 2026-09-02 02:54:52 +02:00
Sign in to join this conversation.