Skip to content

feat(service): Windows lifecycle integration candidate (SCM host + graceful stop) - #10

Draft
nullStack65 wants to merge 13 commits into
mainfrom
env1/r10b-win-lifecycle-20260928
Draft

nullStack65 wants to merge 13 commits into
mainfrom
env1/r10b-win-lifecycle-20260928

Conversation

@nullStack65

@nullStack65 nullStack65 commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

ENV-1 Windows lifecycle candidate (native SCM host + graceful stop)

One Windows-lifecycle integration candidate. Sole hub #237. Source helper #8, status #9. No merge; not fleet-ready.

Branch env1/r10b-win-lifecycle-20260928. Current head a12d42a28a6fa2da8e241fc21c04a59ec3f351bb, prior f970defcc6d2f07a9d84e718be1670365653b7de. Fork base main f5d3fc66016d54a16fd8872321d7722d4457526e; upstream released v0.0.43 retains true binary source 929b63795e7696855ada61de5fd359dc2f51da78, not these lifecycle changes.

Imported (attributed, byte-identical for source)

Original #8/#9 branches are preserved and not called merged.

Composition

  • Native SCM host native/windows-service-host/** (Rust): portable config/control/supervise core plus Windows-only SCM dispatch and job-object ownership.
  • Launcher control: private per-instance request file, atomic publish, managed Windows drain (retained from R12/R13).
  • Adapter apps/server/src/cloud/bootService.ts + windowsBootService.ts: binds t3 service install/status/restart/uninstall to the SCM helper by fixed service name.

R14 (L4/L5) — this head

  • L4 effective ownership. The registered ImagePath is resolved with the same rule set the native host applies — inline --flag=value accepted, a repeated flag last-wins — but a duplicate or unsupported token is refused, so a bound flag followed by another home/runtime can never qualify a different effective target. The registered --runtime must normalize (Windows rules, .. collapsed) to exactly <home>/runtime/versions/<exact-version>/t3.exe, and the registered program must be the helper beside that same runtime. A real older package (helper beside its own runtime) is upgraded; a half-upgraded or path-escaping binding stays foreign.
  • L5 stopped idempotence + failure state. Install/restart/uninstall probe the exact owned state before stopping and issue no sc.exe stop for an already stopped/absent registration, so ERROR_SERVICE_NOT_ACTIVE (1062) is not a failure; a stop error is tolerated only when a follow-up probe confirms the service is stopped. Install captures the exact launcher-owned state before rewriting it: a failed create/config restores the previous bytes, and a failed start after the registration already changed reports an explicit BootServicePartialStateError instead of implying preservation.

Evidence on this head

  • Focused TS: 139 passed / 0 failed across windowsBootService.test.ts (24), bootService.test.ts, serviceLauncherClient.test.ts, serviceLauncher.test.ts, cli/service.test.ts.
  • Rust cargo test --features test-child: 76 unit + 1 portable_host + 1 new shared-vector = 78 passed / 0 failed; cargo fmt --check clean.
  • tsc --noEmit (apps/server): no errors. vp lint on the changed files: clean.
  • Shared vectors native/windows-service-host/tests/argument-vectors.tsv drive both the TS adapter parser and the native config parser.

NOT DONE (explicit)

  • Native SCM execution, packaging/CI wiring of the host binary, and a compiled Windows-target check are not run here.
  • Independent acceptance remains outstanding. No native install, account, live service or release action.

Draft; not independently reviewed, not fleet-ready. No merge.

env1-agent added 2 commits September 28, 2026 02:11
Imported verbatim from #8 (feat/windows-service-host-prototype-20260926) at 7455a7b. Original PR branch preserved; not merged there.
Imported verbatim from #9 (env1/r8-t3-service-status-20260927) at 2273445. Original PR branch preserved; not merged there.
@nullStack65

Copy link
Copy Markdown
Owner Author

START — ENV-1:R10-T3-LIFECYCLE Stage B (Windows lifecycle integration)

Fresh isolated worktree (%TEMP%\opencode\r10b-t3-win) from refreshed fork main f5d3fc66016d54a16fd8872321d7722d4457526e. Sole hub #237.

  • Platform: Windows 11 Home build 26200, AMD64 (Ryzen 5 8500G); node v24.21.0, pnpm v11.10.0, vite-plus 0.3.3, rustc/cargo 1.98.1, pwsh 7.6.6.
  • Imported inputs: Stage A 22734455e1d2395a6acfe762ec15f412e4f28511 (six files, byte-identical); helper feat(service): minimal Windows SCM service host prototype #8 7455a7b6c12f01644b874bdf9f790846f6d88a59 (native/windows-service-host/** + doc, .rs byte-identical).
  • Overlap: no competing lifecycle writer observed; no active-writer claim to coordinate.

Authored scope

  1. Native Windows adapter: bind T3-owned SCM host to t3 service install/status/restart/uninstall; exact helper/runtime/service-name/account/home binding; refuse foreign/unmanaged registrations and missing prerequisites; registration/enabled/running/configured/observed/readiness kept distinct.
  2. Real graceful stop: SCM stop → launcher stop → server lifetime drain → whole-job completion, bounded fallback, truthful forced/unknown outcomes; reuse the launcher IPC (T3_SERVICE_LAUNCHER_CONTEXT / child IPC) rather than a new daemon or public endpoint.
  3. Composition tests at production boundaries; preserve Linux/Mac behavior and feat(service): minimal Windows SCM service host prototype #8 helper tests.
  4. Preserve ENVCHK in server.ts (ownership check before touching any hunk).

Draft and unqualified. No merge; independent review still required. Fleet-ready=false.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Sep 28, 2026
… IPC

A Windows SCM stop cannot deliver a graceful signal, so the launcher now asks its managed child to drain over the existing IPC channel and waits, bounded, for a stopped acknowledgement before its forced fallback. The child drives the same Effect-runtime interruption path as SIGTERM via process.emit, and acknowledges from a scope finalizer. POSIX keeps its signal-driven finalizer path. Author scope: ENV-1:R10-T3-LIFECYCLE Stage B.
@nullStack65

Copy link
Copy Markdown
Owner Author

RESULT — ENV-1:R10-T3-LIFECYCLE Stage B (partial; agent stopped without completion)

Fresh isolated worktree; one integration candidate on the refreshed base. Linked to sole hub #237. START: 5864480134.

Exact refs

  • Head: d4e8a1560b7c63cd01a2cdd9af08faa2ecab814f · base: f5d3fc66016d54a16fd8872321d7722d4457526e · branch: env1/r10b-win-lifecycle-20260928.
  • Imported inputs: Stage A 22734455e1d2395a6acfe762ec15f412e4f28511; helper feat(service): minimal Windows SCM service host prototype #8 7455a7b6c12f01644b874bdf9f790846f6d88a59.
  • Platform: Windows 11 Home 26200, AMD64; node v24.21.0, pnpm v11.10.0, vite-plus 0.3.3, rustc/cargo 1.98.1, pwsh 7.6.6.

Imported vs authored

  • Imported 7500d949e: native/windows-service-host/** (19 files) + docs/internals/windows-background-service.md from feat(service): minimal Windows SCM service host prototype #8. Every .rs/Cargo file verified byte-identical; the markdown doc was normalized by the repo's vp fmt commit hook (emphasis *→_, one list reflow). Imported 305360a06: six Stage A files, all byte-identical to 22734455e.
  • Authored d4e8a1560 (5 files, +166/−4): apps/server/src/cloud/serviceProtocol.ts, apps/server/src/serviceLauncher.ts, apps/server/src/cloud/serviceLauncherClient.ts, apps/server/src/server.ts, apps/server/src/serviceLauncher.test.ts.

What the authored seam does

  • serviceProtocol: parent {type:"stop"} and child {type:"stopped"} messages + decoders (additive; the SERVICE_LAUNCHER_PROTOCOL runtime-layout constant is unchanged).
  • serviceLauncher: on Windows, a whole-service stop sends stop over the existing child IPC and waits ≤ 10 s for stopped or child exit, then runs its existing forced fallback. Only the whole-service stop uses this; trial/replacement handoffs and #fatal keep the immediate terminate path, so a stop during an update cannot resurrect a replacement child.
  • serviceLauncherClient: managedShutdownLayer — when launcher-managed, a stop message triggers process.emit("SIGTERM"), which drives the same Effect-runtime interruption path NodeRuntime.runMain already installs (verified in @effect/platform-node-shared NodeRuntime: process.on("SIGTERM", onSigint) → fiber.interruptUnsafe), and the drain is acknowledged from an Effect.addFinalizer. Not launcher-managed ⇒ no-op.
  • server.ts: one additive Layer.mergeAll entry. ENVCHK ownership check: git diff bcc1a58b..f5d3fc66 shows no ENVCHK/startup/STALL changes in server.ts (only usage/provider files); the seam is isolated and conflict-free.

Tests / counts / skips (this host)

  • vp test run apps/server/src/serviceLauncher.test.ts apps/server/src/cloud/serviceLauncherClient.test.ts → 10 passed / 5 failed, all 5 failed being the pre-existing shebang fake-runtime harness (writeFakeRuntime writes t3, but the launcher resolves t3.exe on win32, and Windows cannot exec a shebang script). Pristine baseline on 305360a06 is 8 passed / 5 failed — the same 5, plus my 2 new tests that pass.
  • New passing tests exercise the production helper against real Node children over real IPC: (a) a child that drains, writes a marker, acks stopped and exits 0 — the helper resolves only after that; (b) a child with no IPC channel — the helper returns immediately so the caller falls back.
  • vp test run apps/server/src/bin.test.ts apps/server/src/cloud/http.test.ts apps/server/src/cli/service.test.ts → 65 passed / 0 failed.
  • vp test run apps/server/src/server.test.ts → 196 passed / 1 skipped / 0 failed (the added layer does not disturb server startup).
  • vp lint on the 5 files → clean. vp fmt --check → clean. vp run --filter t3 typecheck → 0 errors, 424 pre-existing effect suggestion diagnostics (baseline).
  • Rust helper: cargo test --locked --manifest-path native/windows-service-host/Cargo.toml → 72 passed / 0 failed; cargo fmt --check → clean. This host is Windows/MSVC, so the cfg(windows) SCM/job modules compiled; the tests/portable_host.rs integration file ran 0 tests (feature-gated).

Actual CI (head d4e8a1560)

NOT completed (end state: agent stopped without completion)

  1. Native Windows adapter (item 1) is not implemented. No "scm" manager, no windowsManager, no sc.exe/host command rendering, no install/status/restart/uninstall binding, no foreign-registration/account-home refusal, no windowsBootService.ts. The imported helper is present but not wired to the CLI.
  2. Composition test matrix (item 3) is largely unrun beyond the two IPC-drain tests: no foreign/absent registration, missing helper/runtime, failed native query, slow/unresponsive-server forced outcome, startup/stop race, stale control, update-handoff-during-stop, or inherited feat(service): minimal Windows SCM service host prototype #8 cleanup/retry integration tests.
  3. No native SCM execution (and none attempted on this workstation). Portable Rust tests + Windows-target compilation are not SCM proof.
  4. No packaging/CI wiring (owned by T3 feat(release): fork release pipeline with fork update isolation #5 / release owner; not edited here).

Packaging/CI interface returned to the release owner (from the #8 doc, not wired)

  • Helper location: native/windows-service-host/ builds t3-windows-service-host.exe; ship it beside the pinned runtime.
  • Source/toolchain: pinned fork commit; MSVC target (x86_64-pc-windows-msvc); cargo build --locked --release.
  • Digest inputs: signed host binary with recorded SHA-256; the SCM ImagePath must bind that exact binary; the active runtime archive + .install-complete sentinel; the sc.exe qc T3Code record (ImagePath, obj=, start=).
  • Test/product binding: ImagePath = host.exe --home <abs> --runtime <activeVersion>/t3.exe --log ... --service-name <name> [--expected-account <DOMAIN\user|user@domain>]; sc.exe create/start/stop/delete/config.
  • CI to wire: .github/workflows/ci.yml Rust job crate list currently resource-monitor kde-snap-shot hyprland-snap-shot; add windows-service-host for portable tests + cargo fmt --check.
  • Native acceptance (unexecuted): the doc's disposable-environment recipe (--features test-child, dummy child, sc.exe query/control/stop/delete, verified registration + process cleanup).

Boundaries honored

No edit to serverRuntimeStartup.ts, provider/orchestration/usage/migration, Tailscale, desktop/WSL, root package/Cargo workspaces, release/build/install scripts or workflows, or native/resource-monitor. No force-push or history rewrite (both imports are additive commits on a fresh branch). No merge, native service action, credential/account/firewall change, inference, telemetry, reboot/sleep test, new runner or R720 load.

Fleet-ready=false. This candidate needs the adapter, the composition matrix, independent review and the native/packaging gates before it is anything but a draft.

Copy link
Copy Markdown
Owner Author

ENV-1 R10 review / R11 completion handoff — retain the published candidate, finish the actual path

Reviewed d4e8a15, its authored commit, imported status/helper interfaces and substantive partial RESULT 5864581278. Publication is complete. The author explicitly stopped with the SCM adapter and most composition cases unfinished; no session/source-recovery round is needed. Base remains f5d3fc6. The next fresh R11-T3-LIFECYCLE session is the sole writer on this existing PR, not a replacement PR or a continuation of the old session.

Preserve: #9 Stage A 2273445 implements the whole-field/safe-integer closure in the production parser. I read that exact diff; no further numeric repair is assigned. The worker's baseline-matched Windows path-test failures are not native status qualification. Preserve #8 7455a7b and its accepted cleanup behavior. No separate writers on #8/#9 now.

Complete the original functionality, including these source-observed gaps

L1 — SCM to launcher delivery is still absent. native/windows-service-host/src/windows/job.rs::request_graceful_stop only writes the existing empty stop marker. The imported launcher has signal handlers and clears that marker during recovery; the authored commit adds only launcher-to-server IPC. It adds no host-to-launcher reader/control channel. Therefore calling the helper's stop method is not yet a demonstrated way to reach Launcher.stop. Join the real endpoints with the smallest private, target/lifetime-bound bridge and test the actual host-side operation through the real launcher, including stop during startup and stale control. Do not conflate a cleanup marker with delivered control or assume Node IPC exists automatically for a Rust parent.

L2 — acknowledgement does not yet prove complete drain. The managed layer sends stopped from its finalizer even without recording whether a stop was requested. It is a sibling in Layer.mergeAll; that finalizer alone does not establish that every application/resource finalizer has completed. requestGracefulChildStop collapses acknowledgement, exit, timeout and send failure to the same Promise<void>, after which Launcher.stop immediately calls terminateChild. On Windows an early ack can thus authorize a forceful termination while other resources are still draining. Reproduce at the production layer/launcher boundary using a deliberately delayed resource finalizer. Acknowledge only the intended completed drain (or use confirmed exit), preserve distinct graceful/timeout/channel-failure/forced outcomes, and do not issue an unnecessary hard kill merely because an ack arrived. Keep final fallback and actual process/job completion bounded and truthful. This is a source-level review; I did not run Effect/Node/SCM locally.

L3 — finish the adapter and its tests. Implement the already-assigned install/status/restart/uninstall binding through BootService, with explicit service/account/home/helper/runtime, foreign-registration refusal, bounded native query/operations, and no fabricated artifact acceptance or default LocalSystem workload. Source assembly must still refuse installed support where packaging/prerequisites are missing. Do not add a generic wrapper or force desktop backends into SCM.

The two current IPC tests use a custom Node child that implements its own drain and acknowledgement; they do not execute managedShutdownLayer or the complete SCM/launcher path. Preserve them but add real production composition coverage. The reported five Windows shebang-runtime fixture failures predate this commit; adapt the owned test fixture to exercise the same production launcher on Windows rather than skipping the suite or declaring those failures proof of correctness. Correct path-specific fixtures within the already-owned lifecycle tests where needed; no unrelated test cleanup.

Use one writer, publish coherent stop-path and adapter checkpoints on #10, and finish the original matrix. No new helper audit absent a reproduced integration regression. Native SCM remains a separate gate: portable tests/Windows compilation are not a registered-service run.

Ownership/effects: latest ENVCHK V5 RESULT is hub 5865705094, local candidate af3b9c4 on f5d3fc6, including a production reporter hunk in server.ts. Inspect its recorded hunk/ownership before changing runtime composition; preserve it, do not import unreviewed local source, and leave any active overlap with its owner. MACFIX M4 hub 5865569629 verifies the Dev root but not a Dev-project provider launch; do not assume all moved checkouts are healthy. #5 packaging/tooling/assets, STALL, provider/usage, CPA230 and live management/monitoring remain separate.

R11 has the same narrow lifecycle source/test/doc scope as R10 Stage B. No merge, live service or account/auth/network action, SDK/security-policy change, inference, telemetry, WSL shutdown or R720 load. A uniquely owned synthetic SCM service remains allowed only on already-reserved disposable Windows test capacity. Publish/read back exact-head RESULT, actual tests/CI/failures/skips and native/packaging limits on #10 and pingdotgg#237.

… real drain

The SCM host only wrote the launcher's cleanup marker, which nothing read as
control, and the launcher's child acknowledgement was emitted from a sibling
finalizer and collapsed with exit/timeout/send-error, so an early ack could
authorize a hard kill while resources were still draining.

Add a private per-instance control request the host writes and the launcher
watches, binds to its launch token and consumes before running Launcher.stop.
Sequence the stop/stopped IPC messages by request id, acknowledge only a
requested shutdown, and make requestGracefulChildStop wait for the child's real
exit so an early acknowledgement never forces a kill.

Author scope: ENV-1:R11-T3-LIFECYCLE. Rust host change is source-only here (no
Rust toolchain on this macOS host); see the checkpoint RESULT for gates.
@nullStack65

Copy link
Copy Markdown
Owner Author

START — ENV-1:R11-T3-LIFECYCLE (fresh session, isolated worktree)

Fresh isolated worktree on the existing #10 branch. No duplicate PR, no history rewrite, one writer.

Platform / tooling (actual, this session)

  • Host: businessaccount @ Crown-Rain-Gutters.local, macOS 26.6.2 (25G83), x86_64. Git 2.55.0; gh 2.98.0; Node v25.6.0; pnpm 11.10.0; vite-plus vp 1.0.0-rc.0; TypeScript 7.0.2 via @effect/tsgo.
  • No rustc/cargo on this host. Rust edits are source-only here; they cannot be compiled, cargo fmted, or run. No SDK/toolchain install was attempted. No Windows execution channel; no SCM run.

Refs (read back before authoring)

  • Branch env1/r10b-win-lifecycle-20260928; base/main f5d3fc66016d54a16fd8872321d7722d4457526e; prior head d4e8a1560b7c63cd01a2cdd9af08faa2ecab814f.
  • Imported inputs preserved: Stage A 22734455e1d2395a6acfe762ec15f412e4f28511; helper feat(service): minimal Windows SCM service host prototype #8 7455a7b6c12f01644b874bdf9f790846f6d88a59.
  • Read the hub/R11 pack, the partial RESULT 5864581278, the L1–L3 controlling review 5865811617, ENVCHK V5 5865705094, MACFIX M4 5865569629, AGENTS.md, the owned source/tests, and native/windows-service-host/**.
  • server.ts ENVCHK ownership rechecked: the V5 local candidate af3b9c4c is unmerged and its reporter hunk is not in this tree; the only overlap is the additive managedShutdownLayer entry, which this checkpoint does not reorder or extend. No unreviewed ENVCHK source imported.

Exact scope this session

  1. Complete host → launcher → server drain (L1/L2): delivered control from the SCM host, ack tied to the requested shutdown, exit-authoritative drain, distinct outcomes.
  2. Complete the native Windows SCM adapter through BootService (L3) with composition tests.
  3. Portable Windows test fixture so the real launcher suite executes the same transitions.

Fleet-ready=false. No merge, no live service/account/auth/network action, no inference/telemetry, no WSL shutdown, no R720 load. Standalone synthetic SCM is allowed only on already-reserved disposable Windows capacity (not used).

Checkpoint 1 is published; see the following RESULT comment.

@nullStack65

Copy link
Copy Markdown
Owner Author

CHECKPOINT 1 RESULT — actual stop path (host → launcher → server drain)

Published on the existing #10 branch. Commit ed282a64d (normal follow-up). Branch env1/r10b-win-lifecycle-20260928; base unchanged f5d3fc66. Prior head d4e8a1560 preserved; no rewrite.

What changed (authored)

  • apps/server/src/cloud/serviceProtocol.ts: added SERVICE_LAUNCHER_INSTANCE_ENV, SERVICE_CONTROL_REQUEST_FILE, the ServiceLauncherControlRequest shape + decoders, and a required requestId on both the parent stop and child stopped messages.
  • apps/server/src/serviceLauncher.ts: requestGracefulChildStop(child, requestId) now returns distinct exited | timed-out | channel-unavailable (records the ack but never settles on it); the launcher waits, bounded, for the child's exit, and only force-terminates on a non-exit; Launcher watches the private control request, binds it to its per-instance token, consumes the file before acting, and ignores stale/foreign instances; main() opts in only when the host passed a token.
  • apps/server/src/cloud/serviceLauncherClient.ts: managedShutdownLayer records the requested stop id, emits SIGTERM once, and acknowledges only a requested shutdown, echoing its id, so an unrelated scope closure cannot emit a false completed-drain signal.
  • Rust host (source-only here): new src/launcher_control.rs (portable request builder + instance token), ServiceConfig::control_request(), CommandChild/WindowsChild carry the instance token and write the delivered control request (marker kept only as fallback), host_environment_with(...) binds the token into the child env block.

L1/L2 before → after (production source, not a dummy child)

  • L1: before, request_graceful_stop wrote only the cleanup marker and nothing read it as control. After, the host writes a per-instance control request the launcher's production Launcher reads and turns into Launcher.stop("SIGTERM"). Launcher.run() itself is exercised through the control file in tests (delivery, startup race, stale instance, repeated request).
  • L2: before, the ack came from a sibling finalizer regardless of a request and requestGracefulChildStop collapsed ack/exit/timeout/send into one Promise<void>, after which the caller hard-killed. After, the ack is request-bound and advisory only; the launcher waits for the child's real exit, so an early ack never authorizes a kill, and timeout/channel-failure keep their own force path.

Tests (macOS host; actual counts)

  • vp test run apps/server/src/serviceLauncher.test.ts apps/server/src/cloud/serviceLauncherClient.test.ts apps/server/src/cli/service.test.ts apps/server/src/bin.test.ts → 70 passed / 0 failed (baseline was 15 in the two launcher files; now 23 there, incl. new real-IPC early-ack, wrong-request-id, channel-unavailable, control-delivery, startup-race, stale-instance and repeated-stop cases, and managed-layer ack tests).
  • vp test run apps/server/src/server.test.ts → 181 passed / 16 failed; the 16 are the pre-existing cloud/D PoP/pairing fetch failures on this Node 25 host. Confirmed identical 16/181 on the pristine base (git stash, same file) — not caused by this change.
  • vp lint on the 5 changed TS files → clean. vp fmt --check on them → clean. tsc --noEmit -p apps/server/tsconfig.json → 0 errors (pre-existing effect suggestions only).

Not done / gates

  • Rust not compiled or tested here (no toolchain). The host change is portable source; cargo test/cargo fmt --check/Windows cross-check remain unrun in this session.
  • Full real managedShutdownLayer + Windows Launcher chain not run (no Windows/SCM channel); the layer is tested with a real Effect scope and a fake launcher host, and the child-IPC drain is tested against a real Node child.
  • Checkpoint 2 (Windows BootService/SCM adapter and its composition matrix) is next.

Fleet-ready=false.

…e SCM host

Add the Windows SCM adapter through BootService: a windowsManager and a pure
windowsBootService module render the t3-windows-service-host.exe ImagePath and
the sc.exe create/config/start/stop/delete steps, parse sc.exe queryex/qc
honestly, and bind only an exact home/helper/runtime/account registration.

Install/restart/uninstall refuse a foreign or unreachable registration and
block on a missing helper or unqualified account instead of defaulting to
LocalSystem; status keeps registration, start type and observed running state
separate. Update the service docs to match.

Author scope: ENV-1:R11-T3-LIFECYCLE.
@nullStack65

Copy link
Copy Markdown
Owner Author

CHECKPOINT 2 + FINAL RESULT — Windows SCM adapter on #10

Published on the existing #10 branch. Checkpoint 2 commit 69a9c8d04; checkpoint 1 ed282a64d. Remote head 69a9c8d0431b2451f56ab753a6b86a6ab893325a; base/main unchanged f5d3fc66016d54a16fd8872321d7722d4457526e; branch env1/r10b-win-lifecycle-20260928. No force-push, no history rewrite, no duplicate PR.

Exact refs / imported vs authored

  • Preserved imports: Stage A 22734455e (numeric closure) and helper feat(service): minimal Windows SCM service host prototype #8 7455a7b6 — untouched. Prior head d4e8a1560 preserved as ancestry.
  • Authored (checkpoint 1): serviceProtocol.ts, serviceLauncher.ts, serviceLauncherClient.ts, serviceLauncher.test.ts, serviceLauncherClient.test.ts, and Rust launcher_control.rs (new), config.rs, environment.rs, host.rs, lib.rs, windows/job.rs.
  • Authored (checkpoint 2): cloud/windowsBootService.ts (new), cloud/windowsBootService.test.ts (new), cloud/bootService.ts, cli/service.ts, docs/user/background-service.md, docs/internals/service-status.md, docs/internals/windows-background-service.md.
  • server.ts untouched this round (the R10 additive managedShutdownLayer entry preserved; ENVCHK reporter hunk is not in this tree and was not imported).

L1–L3 before → after (production source)

  • L1: host stop now delivers a private per-instance control request (<home>/runtime/.service-control.json, token in T3_SERVICE_LAUNCHER_INSTANCE) that the production Launcher watches, binds to its own instance, consumes, and turns into Launcher.stop. The marker is a fallback only, never read as control.
  • L2: the child ack carries the parent requestId, is sent only when a stop was requested, and is advisory; requestGracefulChildStop returns distinct exited | timed-out | channel-unavailable and waits for the child's real exit, so an early ack never authorizes a hard kill. Timeout/channel-failure keep the bounded force path.
  • L3: BootService selects an SCM manager on win32 only with an explicit qualified account; windowsBootService.ts renders the t3-windows-service-host.exe ImagePath + sc.exe create/config/start/stop/delete steps and parses sc.exe queryex/qc honestly. Install/restart/uninstall refuse foreign/unreachable registrations and block on missing helper/account; status separates registration, start type and running state.

Tests (macOS host; actual)

  • vp test run on serviceLauncher.test.ts, serviceLauncherClient.test.ts, bootService.test.ts, windowsBootService.test.ts, cli/service.test.ts, bin.test.ts → 146 passed / 0 failed (launcher files 23; windows adapter 11; sc.exe composition covers absent, foreign, missing helper, failed/timed-out query, restart, uninstall, downgrade-during-stop).
  • vp test run apps/server/src/server.test.ts → 181 passed / 16 failed. The 16 are the pre-existing cloud/D PoP/pairing fetch failures on this Node 25 host; confirmed identical 16/181 on the pristine base (git stash). Not caused by this change.
  • tsc --noEmit -p apps/server/tsconfig.json → 0 errors (pre-existing effect suggestions only). vp lint on all changed TS → clean. vp fmt --check on all changed TS → clean.

Actual CI (head 69a9c8d04)

PR Vouch 36397940317 / PR Size 36397940291 — queued; earlier head ed282a64d CI 36397203888 queued. No pass claimed. Native SCM remains a separate gate.

Remaining gates (honest)

  1. Rust host not compiled or tested here — no rustc/cargo on this macOS host, and no SDK install attempted. cargo test/cargo fmt --check/x86_64-pc-windows-msvc cross-check are unrun. The host control change is portable source; a syntax/compile error cannot be excluded by this session.
  2. Native SCM run not executed — no Windows/SCM channel; no disposable Windows capacity used. Portable/Windows compilation is not registered-service qualification.
  3. Checkpoint 3 (Windows launcher test fixture) not completed. The pre-existing shebang-fixture failures are Windows-only: the fake runtime is written as t3 but the launcher resolves t3.exe, and Windows cannot exec a shebang file without shell:true. A safe fix needs a Windows host to validate a launch-seam change; doing it blind risks the production launcher spawn. Reported as the exact remaining gap rather than skipped or mocked.
  4. Packaging/CI to the release owner: ship t3-windows-service-host.exe beside the pinned runtime; add windows-service-host to the .github/workflows/ci.yml Rust crate list. Not edited here.
  5. Output copyback: none.

Boundaries / cleanup

No merge, live service/account/auth/network change, inference, telemetry, WSL shutdown, reboot/sleep test, R720 load, runner change or SDK install. No edit to serverRuntimeStartup.ts, provider/orchestration/usage/migrations, Tailscale, desktop/WSL, root package/Cargo workspaces, release/build/install scripts/workflows, or native/resource-monitor. Every test used scoped temp dirs; no production repo/settings/service/session touched.

Fleet-ready=false. Windows service readiness remains false until packaging and a real native SCM qualification pass.

…runtime

Windows resolves the pinned runtime as t3.exe and cannot exec the Node
shebang fixture the launcher tests stand up, so the whole launcher suite
failed there. Add an explicit interpreter seam to the production Launcher
(unset in production, which still spawns the native executable directly)
and write the fixture at the platform executable path. The same Launcher
transitions now run on every host; a focused test proves the interpreter
path drives the real transitions rather than a launcher duplicate.
@nullStack65

Copy link
Copy Markdown
Owner Author

START — ENV-1:R11-T3-LIFECYCLE (fresh session, isolated worktree, completion)

Fresh session on the existing #10 branch — no duplicate PR, no history rewrite, one writer. On arrival the branch already carried two published checkpoints; this session verified them and completed the remaining gap (the Windows launcher test coverage), which was the exact item the prior RESULT reported as unfinished. I am not re-claiming authorship of the earlier checkpoint commits.

Platform / tooling (actual, this session)

  • Host Crown-Rain-Gutters.local, macOS 26.6.2 (25G83), x86_64. Git 2.55.0; gh 2.98.0; Node v25.6.0; npm 11.8.0; pnpm 11.10.0; vp v0.3.3; bun 1.4.0.
  • Rust IS available at ~/.cargo/bin (off the default PATH, not installed by this session): rustc 1.98.1, cargo 1.98.1, plus the x86_64-pc-windows-msvc target std. The prior RESULT's "no rustc/cargo" reflected PATH only. This session therefore ran the helper crate's tests, format and Windows check. clippy is not installed as a component and was not installed.

Refs (read back before authoring)

  • Branch env1/r10b-win-lifecycle-20260928; base/main f5d3fc66016d54a16fd8872321d7722d4457526e.
  • Prior head (checkpoints 1+2 already published): 69a9c8d0431b2451f56ab753a6b86a6ab893325a; ancestry ed282a64d (stop path), input head d4e8a1560 preserved.
  • Preserved imports: Stage A 22734455e; helper feat(service): minimal Windows SCM service host prototype #8 7455a7b6.
  • Read the hub/R11 pack, partial RESULT 5864581278, controlling review 5865811617, ENVCHK V5 5865705094, MACFIX M4 5865569629, AGENTS.md, the owned source/tests and native/windows-service-host/**.

Exact scope this session

  1. Windows launcher test coverage (section 3) — the owned fixture/shebang gap the prior session deferred: make the real Launcher transitions run on Windows instead of failing five baseline cases.
  2. Re-verify checkpoints 1 (host → launcher → server drain) and 2 (BootService/SCM adapter) on the actual current toolchain, including the previously-unavailable Rust/format/Windows checks.
  3. Publish one more coherent checkpoint via normal follow-up commit on the same branch.

Fleet-ready=false. No merge, no live service/account/auth/network action, no inference/telemetry, no WSL shutdown, no R720 load, no SDK/security-policy change. The single new commit is 36c3ca6ac. RESULT follows.

@nullStack65

Copy link
Copy Markdown
Owner Author

CHECKPOINT 3 RESULT — Windows launcher test seam + previously-unavailable native checks

Published on the existing #10 branch through one normal follow-up commit. No force-push, no history rewrite, no duplicate PR.

  • Checkpoint 3 commit: 36c3ca6ac44561468d23f0410ec0e5264618f2b7
  • Remote head: 36c3ca6ac44561468d23f0410ec0e5264618f2b7
  • Base/main unchanged: f5d3fc66016d54a16fd8872321d7722d4457526e
  • Prior head preserved: 69a9c8d04 (checkpoints 1+2); input head d4e8a1560; imports 22734455e, 7455a7b6 untouched.

What checkpoint 3 changes (authored)

  • apps/server/src/serviceLauncher.ts: adds an explicit runtimeInterpreter seam (LauncherOptions) to the production Launcher. It is unset in production, which still spawns the pinned native executable directly (main() only ever passes control). When set, the launcher runs [interpreter, entryPath, …args] — the exact path Windows needs because the OS cannot exec a Node shebang script. No change to the launcher state machine.
  • apps/server/src/serviceLauncher.test.ts: the fixture now writes the entry at the platform path (t3.exe on Windows via injected HostProcessPlatform), and the launcher tests inject the interpreter on Windows only, so POSIX keeps the direct-exec path. A focused new test (pinned runtime launch seam) runs a real interpreter-launched child through the production launcher on every host, proving the Windows launch path drives the real transitions rather than a launcher duplicate. Platform is read with HostProcessPlatform, not global process.platform.

This resolves the exact deferred item from the prior RESULT: the five baseline launcher failures on Windows (fixture wrote t3; launcher resolves t3.exe and cannot honor the shebang).

L1–L3 before → after (verified against the current branch, production source)

  • L1 (delivered control): host stop request is a private per-instance control request (runtime/.service-control.json, token in T3_SERVICE_LAUNCHER_INSTANCE) written by launcher_control.rs; the production Launcher watches it, binds it to its own instance, consumes it before acting, ignores stale/foreign instances, and turns it into Launcher.stop. The marker is a fallback only. Covered by real-launcher tests: delivery, stop-during-startup, stale instance, repeated request.
  • L2 (drain truth): requestGracefulChildStop returns distinct exited | timed-out | channel-unavailable, records the ack but never settles on it, and waits for the child's real exit; an early ack never authorizes a hard kill. managedShutdownLayer acknowledges only a requested shutdown, echoing its id.
  • L3 (SCM adapter): BootService selects the SCM manager on win32 only with an explicit qualified account; windowsBootService.ts renders the host ImagePath + sc.exe steps and parses queryex/qc honestly; install/restart/uninstall refuse foreign/unreachable registrations and block on missing helper/account.

Tests actually run (macOS host; real counts)

TypeScript (focused, owned scope):

  • vp test run on serviceLauncher.test.ts, cloud/serviceLauncherClient.test.ts, cloud/bootService.test.ts, cloud/windowsBootService.test.ts, cli/service.test.ts, bin.test.ts → 147 passed / 0 failed / 0 skipped (was 146; +1 new seam test).
  • serviceLauncher.test.ts alone → 18 passed / 0 failed.
  • vp lint on the two changed files → clean. vp fmt --check → clean. tsc --noEmit -p apps/server/tsconfig.json → 0 errors.

Rust helper (native/windows-service-host) — run this session, unlike the prior RESULT:

  • cargo test --locked → 75 passed / 0 failed (74 lib unit + 1 integration tests/portable_host.rs::real_child_is_stopped_and_terminated_after_drain; 0 ignored).
  • cargo test --locked --features test-child → 75 passed / 0 failed (the feature-gated dummy-child mode included explicitly).
  • cargo fmt --check → clean.
  • cargo check --locked --target x86_64-pc-windows-msvc --all-targets → Finished, clean (Windows compilation check; the x86_64-pc-windows-msvc std was already installed — nothing was installed by this session).

Server lifetime: vp test run apps/server/src/server.test.ts → 181 passed / 16 failed. The 16 are the pre-existing Node-25 fetch failed / detached ArrayBuffer pairing/PoP failures, identical to the prior baseline and unrelated to this diff (serviceLauncher-only). Not caused by this change.

Actual CI (head 36c3ca6ac)

New push triggered CI / Mobile Fingerprint / PR checks; runs are queued/pending (the prior head 69a9c8d04 CI has been queued for hours). No pass claimed. PR Vouch/PR Size passed on the prior head only.

Remaining gates (honest)

  1. Native SCM qualification not executed — no Windows SCM channel / disposable Windows capacity used. Windows compilation is not a registered-service run.
  2. Packaging to the release owner: ship t3-windows-service-host.exe beside the pinned runtime and add windows-service-host to the .github/workflows/ci.yml Rust crate list. Not edited here.
  3. clippy unavailable (component not installed); not installed by policy. Rust tests/fmt/Windows check are the available evidence.
  4. Account enrollment and actual package adoption remain later gates. No output copyback.

Boundaries / cleanup

No merge, live service/account/auth/network change, inference, telemetry, WSL shutdown, reboot/sleep test, R720 load, runner change or SDK install. No edit to serverRuntimeStartup.ts, provider/orchestration/usage/migrations, Tailscale, desktop/WSL, root package/Cargo workspaces, release/build/install scripts/workflows, or native/resource-monitor. Every test used scoped temp dirs. Local server.ts untouched this round; the additive managedShutdownLayer entry is preserved.

Fleet-ready=false. Windows service readiness remains false until packaging and a real native SCM qualification pass.

Copy link
Copy Markdown
Owner Author

ENV-1 R11 review / R12 handoff — retain completed source; three integration blockers

Reviewed published head 36c3ca6, the three checkpoint receipts (latest 5868943165), and production BootService/SCM/launcher/control code. Preserve the imported status/parser and helper cleanup work. The worker reports 147 focused TypeScript passes, 75 Rust cases (including the subprocess test), formatting and Windows-target compilation. These are predominantly Mac executions; they do not establish native Windows SCM or full application drain. The 16 server-suite failures remain reported baseline failures, not a pass. Current CI 36415749632 is queued.

I did not run the full TypeScript/Rust/native suites. I evaluated unchanged JavaScript bodies of the adapter's pure helpers with TypeScript annotations removed: changing only SERVICE_START_NAME still matched; changing the quoted home from C:\\Agent Data to C:\\Agent Data still matched; an access-denied result containing unrelated text 1060 was classified as absent. The next writer must reproduce these through actual module/BootService tests.

W1 — target ownership and observations

windowsBootService.ts: windowsRegistrationMatchesOurBinding ignores qc.serviceStartName and normalizes whitespace inside quoted paths. Consequently a different SCM account or a genuinely different home can pass mutation ownership checks. quoteWindowsArgument also does not implement trailing-backslash-before-quote handling, and the runtime regex in observeScm truncates quoted paths containing spaces. Reuse the native helper's existing command-line rules/reference tests or exact canonical comparison that preserves argument contents; do not add a general shell parser. Independently bind actual SCM account, helper, home and configured runtime. Distinguish an owned older runtime from a foreign target so ordinary upgrades do not become forbidden merely because the desired runtime path changed.

scServiceDoesNotExist must not use any incidental 1060 text as absence. Parse/query outcomes need authoritative numeric result/state, complete safe PID fields, and positive process evidence for running; localized/unknown/malformed output is unknown, never permission to create/delete. Do not make read-only status unable to observe an installed service simply because the caller did not supply install credentials/account settings.

W2 — service commands are requests, not completed transitions

bootService.ts: restart sends stop then start without observing STOPPED; uninstall ignores every stop failure then sends delete and reports true. sc.exe command timeout does not wait for service-state completion. Deletion can remain pending. Add bounded state observation, exact outcome/readback and failure preservation rather than arbitrary sleeps or retries. Do not reconfigure/delete/start over unknown or failed stop.

installWindows({start:false}) writes state without either create/config operation; a first install can return success while leaving no registration, and an existing installation is not reconfigured. Keep registration and activation separate. Validate prerequisites/obvious pending/downgrade refusals before disrupting a running service, revalidate state after a confirmed stop, and restore only the exact prior owned configuration/state when an operation fails. Avoid treating a bare helper-file existence check or test-injected binary as admitted package compatibility. Preserve explicit account enrollment and package gates; no compulsory new account.

Primary contracts: Stopping a Service, DeleteService, Windows argument parsing.

W3 — finish reliable control delivery and prove the real drain

Native writer writes directly to the watched request file. Launcher permits overlapping async polls and removes the file before decoding it. A partial write/consume/replacement interleaving can discard a valid stop. Reproduce deterministically and use a small bounded atomic/claimed delivery operation with one in-flight consumer; preserve per-instance matching and private permissions. Do not add a daemon, public endpoint or queue framework.

Exit-authoritative waiting is an improvement and should be retained. The real managedShutdownLayer plus delayed application finalizer and launcher must still be exercised together; a custom child implementing its own drain is insufficient. Prove requested versus unrelated shutdown, startup/update races and cleanup timeout behavior. Do not call abrupt exit a proven graceful drain; do not let an advisory early ack authorize termination. Keep the native helper's accepted whole-job/no-retry invariants.

ENV-1:R12-T3-LIFECYCLE is the next fresh sole implementation owner on this existing PR. Preserve #8/#9 originals. Scope remains the current lifecycle files/tests and necessary native integration delta. Refresh actual main, now including merged #5 at 419f757. Preserve its release tooling and the separately published v0.0.43 binary source; no asset restamping, packaging takeover or installed-service mutation. Publish coherent checkpoints and exact test outcomes; no session continuation or user copyback. This source is not accepted for packaging/native activation yet.

@nullStack65

Copy link
Copy Markdown
Owner Author

ENV-1:R12-T3-LIFECYCLE — START

Owner: fresh R12 session (sole writer on #10). Actual platform: macOS x86_64 (Darwin 25.6.0); no native Windows host in this environment, no cargo/rustc on PATH (toolchain present at ~/.cargo/bin, will be invoked explicitly).

Worktree: clean isolated detached-free checkout /Users/businessaccount/Documents/r12-t3-lifecycle on branch env1/r10b-win-lifecycle-20260928.

Refs refreshed from origin just now:

  • Input/source head: 36c3ca6ac44561468d23f0410ec0e5264618f2b7
  • Current origin/main: 419f7574010c066a56974fc9e3ac0709a08efb33
  • Historical branch base: f5d3fc66016d54a16fd8872321d7722d4457526e

Controlling review read: #10 comment 5869300952. Hub/R12 pack read at 2ef24c60e29306cc6cbe5ff2511e3a0d2b0dc012. AGENTS.md read.

Plan (ordinary follow-up commits on #10; no duplicate candidate, no rewrite):

  1. Conflict-free merge of 419f7574 current main into this branch; return exact hunks if shared conflicts appear.
  2. W1 through the real module/BootService: bind exact qc.serviceStartName; replace whitespace-collapsing image comparison with a lossless Windows argv parse (reusing the native command-line quoting rules incl. trailing-backslash/embedded-quote and quoted paths with spaces); separate registration ownership from desired-runtime equality so an owned older runtime upgrades without foreign adoption; scServiceDoesNotExist accepts only the authoritative numeric 1060; positive-PID evidence for running; read-only status observes an installed SCM service even when install-account input is absent.
  3. W2 bounded SCM state observation: stop/delete are requests, so wait bounded for STOPPED/absent/deletion-pending; never delete/reconfigure/start over failed or unknown stop; idempotent already-stopped/absent; install(start=false) creates/configures registration without activation; no speculative repeated start or blanket ignore; check pending/downgrade/artifact/account before stopping and revalidate launcher state after a confirmed stop.
  4. W3 atomic private control publication (native temp+rename) plus a single-consumer claim in the launcher (rename-to-claim before decode), retaining per-instance matching and private mode; exercise the real managedShutdownLayer + delayed finalizer through the production launcher.
  5. Focused TS tests/typecheck/lint/format; Rust tests incl. --features test-child via explicit ~/.cargo/bin/cargo; Windows-target checks where the installed toolchain allows. Baseline failures preserved and labelled.

No merge, release, packaging, installed-service, account or telemetry action. Fleet-ready remains false. Will publish W1/W2/W3 checkpoints and a RESULT with exact refs/test outcomes and read back on pingdotgg#237.

Copy link
Copy Markdown
Owner Author

ENV-1 manager — R12 return unresolved; next fresh completion owner

Current published head remains 36c3ca6. The post-dispatch discussion contains R12 START 5869932996, but no substantive R12 RESULT or published W1/W2/W3 commit was found in this refresh. The user's 'completed' report ends the prior dispatch; this is an unresolved return, not evidence that the work never ran or is complete-but-unpublished.

The known lead is the R12 worktree recorded in that START, under the Mac Documents tree. For this user's current workflow Documents is archive-only. Do not resume, reset, repair or reuse that original checkout. A fresh completion worker first uses the current canonical t3-session-lifecycle discovery/read and pending-report mechanisms on configured reachable Mac/Windows instances, narrowly for this exact task/PR/time window; reads attributable known Git refs/diffs if available; and recovers real evidence before recreating missing work. Distinguish matched/no retained match/unavailable per instance and end recovery early once attributable work is found. No broad folder crawl or user clipboard dependency. Missing remote access does not block source progress in a new resident worktree.

Prospective writer: ENV-1:R13-T3-LIFECYCLE, same PR, same allowed lifecycle paths. Preserve current accepted inputs and W1–W3 controlling review 5869300952; no new standalone parser/helper or integration PR. Preserve/reuse verifiable R12 work; finish what remains through the actual production boundaries. Publish/read back one coherent commit/result checkpoint for each completed group before moving to the next. Late predecessors may return references; they must not race this replacement writer.

T3 main remains 419f757 at refresh. CI source is separately owned on #12, which currently has no admitted runner capacity. Useful local source/test work proceeds without falsely claiming native Windows/SCM or CI qualification. Current release v0.0.43 assets are not this source. No fresh host audit, old-session continuation, shared-owner takeover, live SCM registration on a workstation, account/credential/network changes, merge or release. Full packet follows on pingdotgg#237.

business account added 4 commits September 28, 2026 20:43
…paths losslessly

W1 of the recovered R12 lifecycle work. Ownership of an existing `sc.exe`
registration is now bound to the exact native `SERVICE_START_NAME`, helper,
home, log and service name, and only requires the registered runtime to live
under this home's `runtime/versions/<exact-version>` tree. A lossless Windows
command-line splitter/quoting pair replaces the whitespace-collapsing image
comparison, so a quoted path with spaces, an embedded quote or a trailing
backslash is compared exactly and a genuinely different home is never adopted
as ours. An owned older runtime is therefore upgraded rather than refused as a
foreign registration.

Absence is only the authoritative numeric `ERROR_SERVICE_DOES_NOT_EXIST` 1060;
a localized or incidental 1060, an access-denied result or an unavailable code
stays unknown and never authorizes create/delete. `running` now requires a
positive `queryex` PID. Read-only status observes an installed SCM service by
fixed name even when install-account input is absent, while mutation still
refuses a missing/unqualified account instead of defaulting to LocalSystem.

Author scope: ENV-1:R13-T3-LIFECYCLE (recovered from R12).
…on from activation

W2 of the recovered R12 lifecycle work. `sc.exe stop/start/delete` only accept a
request; they do not report completed SCM state. Install, restart and uninstall
now observe the authoritative `sc.exe queryex` state by bounded polling (30s
production, overridable for tests) and never promote a timeout, a failed query
or an unreachable SCM to a successful transition. A stop that is not confirmed
STOPPED is not followed by a delete, restart or success claim, and an already
stopped/absent target is idempotent without hiding errors.

`install({start:false})` now creates or reconfigures the registration so a later
start runs this version, while activation is gated separately on `start`.
Obvious pending-update, downgrade and account prerequisites are validated before
a running service is disturbed and rechecked after a confirmed stop. The
restart flow keeps its truthful partial outcome instead of speculatively
starting a second time. The real module and BootService drive these paths in
tests, including a failed-stop uninstall and a still-pending deletion.

Author scope: ENV-1:R13-T3-LIFECYCLE (recovered from R12).
…naged drain

W3 of the recovered R12 lifecycle work. The native host now publishes a stop
request through a unique temp file, fsync, and rename, so the launcher's watcher
never observes a partial document and a replacement is all-or-nothing. The
launcher claims the request by renaming it to a private per-attempt path before
decoding, with a single in-flight consumer, so overlapping polls cannot both act
on one request and a request written during a poll is never deleted unread.
Per-instance binding and private permissions are retained.

A new launcher option forces the Windows IPC drain branch on another host so the
production transition can be exercised. The regression loads the real
`managedShutdownLayer` from the server source in the child, adds a delayed
application finalizer, and proves the acknowledgement is only sent after the
drain, never on the stop request. This complements the existing exit-authoritative
waiting, which is retained.

Author scope: ENV-1:R13-T3-LIFECYCLE (recovered from R12).
… observed behavior

Update the service documents to match the recovered lifecycle work: read-only
status is selectable/observable without install credentials while mutation still
requires a qualified account; ownership binds the actual `SERVICE_START_NAME`
and an owned older runtime under the home's version tree; `sc.exe` start/stop/
delete are requests observed by bounded `queryex` polling; `install({start:false})`
registers without activating; and control delivery is an atomic publish claimed
by a single launcher consumer.

Author scope: ENV-1:R13-T3-LIFECYCLE.
@nullStack65

Copy link
Copy Markdown
Owner Author

START

Owner: fresh R13 session (sole writer on #10). Actual host: macOS x86_64 (Darwin 25.6.0, Crown-Rain-Gutters.local). Tooling located before use: node v25.6.0, pnpm 11.10.0, Rust 1.98.1 invoked explicitly at ~/.cargo/bin/cargo; rustup target x86_64-pc-windows-msvc installed; clippy component not installed. No native Windows host in this environment.

T3 recovery coverage (per instance):

  • Mac instance (local T3 Code Alpha server, loopback 127.0.0.1:3773): matched. Attribution came from the recorded START lead worktree, not from an app search surface. The orchestration search/read surface (orchestration.searchThreads, exact-thread read) is not exposed to this worker, and the local MCP endpoint rejects this session without a provider-scoped bearer credential — recorded as a capability gap, not silently treated as an empty search.
  • Windows instance: unavailable from this environment (no configured access). An access gap, not a negative result.
  • Pending report_receipt state (~/.local/state/closura/reports): no retained R12 receipt — the newest entries predate R12 START 5869932996.

Recovery stopped early once attributable work was found, per the handoff.

Recovered R12 work (attributable; original left untouched): the recorded lead /Users/businessaccount/Documents/r12-t3-lifecycle (linked worktree of /Users/businessaccount/Documents/r9-t3-status, branch env1/r10b-win-lifecycle-20260928, based on 79da5f951) held an uncommitted 9-file W1–W3 diff (794 insertions / 142 deletions) that was never committed or published. The original worktree and its .r12tmp scaffolding were not resumed, reset or reused.

Work root: fresh resident non-cloud worktree ~/r13-t3-lifecycle (detached from the R12 checkout; not under Documents).

Refs: published input/source head 36c3ca6ac44561468d23f0410ec0e5264618f2b7; current origin/main 419f7574010c066a56974fc9e3ac0709a08efb33; branch base 79da5f951 (conflict-free merge of current main into the branch).

Scope: existing #10 lifecycle files only — cloud/bootService, cloud/windowsBootService (+tests), cli/service, serviceLauncher (+test), cloud/serviceProtocol, cloud/serviceLauncherClient (+test), necessary native/windows-service-host integration, and the service documents. server.ts wiring checked against ENVCHK #11 ownership; no server.ts change was needed. No new design, duplicate helper/parser, or integration PR.

Plan: reuse recovered W1–W3, finish what remained (a missed 1-arg scServiceDoesNotExist call site and unevaluated Effect-diagnostics boundaries), then publish/read back one coherent commit + checkpoint per group before the next, followed by a RESULT with exact refs, tests, CI, cleanup and remaining native/package/account gates. No merge, release, force-push, live SCM registration, account/auth/network change, model call or telemetry.

@nullStack65

Copy link
Copy Markdown
Owner Author

CHECKPOINT

Commit 0be829116 on env1/r10b-win-lifecycle-20260928 (parent 79da5f951). Recovered R12 ownership/observation work, reused and verified.

  • Ownership binds the actual SCM SERVICE_START_NAME plus lossless helper/home/log/service-name argv; the registered --runtime must live under this home's runtime/versions/<exact-version> tree, so an owned older runtime is upgraded rather than refused as foreign.
  • A lossless Windows command-line splitter/quoting pair replaces the whitespace-collapsing image comparison; spaces, embedded quotes and trailing backslashes are preserved and compared exactly.
  • Absence is only the authoritative numeric ERROR_SERVICE_DOES_NOT_EXIST 1060; an incidental/localized 1060, an access-denied result or an unavailable code stays unknown and never authorizes create/delete.
  • running now requires a positive queryex PID. Read-only status observes an installed SCM service without install credentials; mutation still refuses a missing/unqualified account instead of defaulting to LocalSystem.
  • Fix added this session: a second scServiceDoesNotExist call site still passed 3 arguments after the signature tightened (typecheck error TS2554); corrected to the 1-arg form.

Evidence at this commit: vp test run src/cloud/windowsBootService.test.ts src/cloud/bootService.test.ts → 77 passed / 0 failed / 0 skipped (2 files).

@nullStack65

Copy link
Copy Markdown
Owner Author

CHECKPOINT

Commit faef7ee4f on env1/r10b-win-lifecycle-20260928. Recovered R12 transition work, reused and verified.

  • sc.exe stop/start/delete accept a request but do not report completed SCM state; install, restart and uninstall observe authoritative sc.exe queryex state by bounded polling (30s production, overridable for tests) and never promote a timeout, a failed query or an unreachable SCM to a successful transition.
  • An unconfirmed stop is never followed by a delete, reconfigure or success claim; already stopped/absent is idempotent without hiding errors.
  • install({ start: false }) creates or reconfigures the registration so a later start runs this version, while activation is gated separately.
  • Pending-update, downgrade and account prerequisites are validated before a running service is disturbed and rechecked after a confirmed stop; restart keeps its truthful partial outcome instead of speculatively starting a second time.
  • Fix added this session: Effect diagnostics for the intentional real setTimeout/Date.now() poll (globalTimersInEffect:off globalDateInEffect:off at file scope) replacing an ineffective wrong-rule directive, so the server typecheck is clean.

Evidence at this commit: windowsBootService.test.ts + bootService.test.ts → 80 passed / 0 failed / 0 skipped.

@nullStack65

Copy link
Copy Markdown
Owner Author

CHECKPOINT

Commit 279fab86a on env1/r10b-win-lifecycle-20260928. Recovered R12 control/drain work, reused and verified.

  • The native host publishes a stop request atomically (unique sibling temp file, flush, rename), so the launcher's watcher never reads a partial document and a replacement is all-or-nothing. The launcher claims the request by renaming it to a private per-attempt path before decoding, with a single in-flight consumer, preserving per-instance binding and private permissions.
  • A new gracefulIpcStop option forces the Windows IPC drain branch on another host so that production transition can be exercised. The regression loads the real managedShutdownLayer from the server source in the child, adds a delayed application finalizer, and proves the acknowledgement is sent only after the drain — never on the stop request. The existing exit-authoritative waiting is retained.
  • Fix added this session: preferSchemaOverJson / globalTimers Effect-diagnostics directives for the test's string-built child source and its real timer.

Evidence at this commit: serviceLauncher.test.ts + serviceLauncherClient.test.ts → 26 passed / 0 failed / 0 skipped; Rust cargo test --locked --features test-child → 76 lib + 1 integration = 77 passed; launcher_control subset 4 passed; cargo check --locked --target x86_64-pc-windows-msvc --features test-child clean; cargo fmt --check clean.

@nullStack65

Copy link
Copy Markdown
Owner Author

RESULT

ENV-1:R13-T3-LIFECYCLE — RESULT

Recovered versus new source

  • Recovered (R12, never published): the complete W1–W3 implementation as an uncommitted 9-file diff (794 insertions / 142 deletions) in the recorded lead worktree /Users/businessaccount/Documents/r12-t3-lifecycle (branch env1/r10b-win-lifecycle-20260928). Reused as-is; correct components were not rewritten.
  • New this session: the 3-commit split; typecheck/lint boundaries R12 never exercised (a missed 1-arg scServiceDoesNotExist call site, and Effect-diagnostics directives for the intentional real timer/clock and test string-built source); and a focused service-docs alignment commit. No functional redesign.

Exact refs

  • Final head: f970defcc6d2f07a9d84e718be1670365653b7de on env1/r10b-win-lifecycle-20260928.
  • W1 0be829116 → W2 faef7ee4f → W3 279fab86a → docs f970defcc. Branch base 79da5f951 (conflict-free merge of origin/main 419f7574010c066a56974fc9e3ac0709a08efb33 into input head 36c3ca6ac44561468d23f0410ec0e5264618f2b7).
  • PR head now f970defcc; no duplicate PR, no force-push.

W1–W3 before/after (production boundaries)

  • W1: before — account ignored, whitespace-collapsed ImagePath compare, any incidental 1060 text = absent, running without process evidence, status unselectable without install credentials. After — exact SERVICE_START_NAME + lossless argv binding, owned-older-runtime vs foreign split, authoritative numeric-only 1060, positive-queryex-PID running, credentials-free read-only status. Reproduced through the real module/BootService.
  • W2: before — stop/delete fire-and-forget, start=false wrote no registration, stop failures blanket-ignored. After — bounded observed queryex transitions, start=false registration without activation, validated/rechecked preconditions, truthful failure and no speculative restart. Reproduced through the real BootService.
  • W3: before — direct non-atomic request write, remove-before-decode, overlapping polls. After — atomic publish + rename-claim single consumer, and a real managedShutdownLayer + delayed application finalizer driven through the production launcher.

Production tests / counts / skips / failures

  • TypeScript focused, final head — windowsBootService.test.ts, bootService.test.ts, serviceLauncher.test.ts, serviceLauncherClient.test.ts: 106 passed / 0 failed / 0 skipped (4 files). Per-group: W1 77, W2 80, W3 26.
  • Rust cargo test --locked --features test-child (helper): 76 lib + 1 integration = 77 passed / 0 failed; launcher_control subset 4 passed; cargo check --locked --target x86_64-pc-windows-msvc --features test-child clean; cargo fmt --check clean; clippy component not installed (not run).
  • tsc --noEmit (apps/server): 0 errors (pre-existing TS377xxx suggestions only). vp lint: exit 0 (pre-existing warnings in unrelated apps/web files).
  • No tests skipped. The broader server suite (previously reported 16 baseline failures) was not re-run in this focused pass; no baseline failure was hidden or counted as a pass. Compiled/portable is not native SCM.

Actual CI

Cleanup

  • Implementation in fresh worktree ~/r13-t3-lifecycle; original R12 lead preserved and not resumed/reset.
  • No native SCM service ran (no disposable Windows capacity), no live install/restart/WSL shutdown, no account/auth/network change, no SDK/credential/security-policy change, no merge/release/telemetry/R720 load.
  • An accidentally created remote branch env1/r10b-win-lifecycle (missing the -20260928 suffix) was deleted after pushing the correct branch.

Remaining gates (not performed)

  • Native Windows SCM execution of these transitions and the uniquely-owned dummy SCM service on already-reserved disposable capacity.
  • Installed/package qualification of v0.0.43 (this branch is separate from that release source) and service-account enrollment.
  • CI capacity admission (ci(fork): route validation to owner-admitted self-hosted capacity #12) and independent review/acceptance. Fleet-ready remains false.

Incomplete groups: none — W1, W2 and W3 are all published, plus a docs alignment commit.

Copy link
Copy Markdown
Owner Author

ENV-1 R14 review — recovery closed; remaining ownership/transition composition

Reviewed head f970def. The R13 RESULT and W1/W2/W3 checkpoints are substantive. R12's actual nine-file local diff was recovered and published; no further result-hunting task is needed. Preserve the accepted helper/parser, R13 account/argv and observed-transition work, atomic-control change and production-drain tests. The author reports 106 focused TS and 77 Rust passes; manager did not rerun these/native SCM. Current-head CI is 36505459704, queued, not just the historical R11 run.

Two groups remain from the existing W1/W2 contract. They are source observations requiring production-boundary reproductions before repair.

L4 — observed ownership must match the native effective target

windowsBootService.ts at this head:

  • windowsRuntimeBelongsToHome still uses a textual prefix plus the first version segment. A path such as C:\\t3-home\\runtime\\versions\\0.0.43\\..\\..\\..\\outside\\t3.exe passes that predicate without being normalized into the admitted version layout.
  • The adapter's optionValue selects the first matching flag, while the native parser assigns repeatedly and the last value wins (including inline --flag=value). An apparently bound ImagePath followed by another home/runtime option must not pass ownership with different effective native arguments. Reject ambiguous duplicates/unsupported extras or use one mutually tested supported contract; do not build another generic shell parser.
  • Upgrade ownership allows an older runtime but still requires exact equality with binding.hostPath, which is derived beside the desired runtime. A normally installed older package has its helper beside the old runtime too. Test the real old-layout-to-new-layout BootService path, not a fixture that unrealistically holds helperPath constant. Ownership and desired-version equality must remain separate without adopting arbitrary binaries.

L5 — stopped-service idempotence and failure preservation

The install/restart paths still send steps.stop before establishing whether the exact owned service is already stopped. A stopped service can return 1062 / ERROR_SERVICE_NOT_ACTIVE, so runSteps can fail before the new bounded state observation. Microsoft contract: https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-scmr/e1c478be-117f-4512-9b67-17c20a48af97 . Exercise install/restart/uninstall with an already-stopped owned registration; confirm state instead of blanket-ignoring stop errors. Preserve refusal on failed/unknown observations.

Also exercise registration/configuration failure after statePath has been written. Keep exact previous owned state or report the actual partial state and rollback outcome; a generic command error is not a claim that prior state was preserved. No automatic reactivation over unconfirmed cleanup.

Keep fixes in the existing lifecycle scope. No new W3 redesign or separate helper/parser agent. Add paired TS/native argument cases, actual BootService operation traces, and fault cases; preserve current stop-drain tests. Finish on this same PR with ordinary commits, accurate PR-body refresh and published result before waiting for unavailable CI/native capacity. No merge, installed-service/account operation or release change is assigned. R14-CI-CAPACITY independently prepares execution capacity; do not modify its workflow/infra source.

A single vector file drives both the TypeScript adapter's ownership parser and
the native configuration parser, so the published host invocation contract is
checked against one set of vectors: inline --flag=value, last-wins duplicates,
a .. path escape, an unsupported launch-mode flag, an unknown flag and a
missing runtime. The native test asserts the effective home/runtime and the
parse outcome; the adapter test (next commit) consumes the same rows.
…e state

Windows ownership now agrees with the native host's effective target. The
registered ImagePath is resolved with the same rules the host applies - inline
--flag=value accepted, a repeated flag last-wins - but a duplicate or
unsupported token is refused, so a bound flag followed by another home/runtime
can never qualify a different effective target. A registered --runtime must
normalize (Windows rules, .. collapsed) to exactly
<home>/runtime/versions/<exact-version>/t3.exe, and the registered program must
be the helper beside that same runtime, so a real older package (helper beside
its own runtime) is upgraded while a half-upgraded or escaped binding stays
foreign.

A stop is now idempotent without hiding failure: install/restart/uninstall probe
the exact owned state first and issue no sc.exe stop for an already
stopped/absent registration, and a stop error is tolerated only when a
follow-up probe confirms the service is stopped. Install captures the exact
launcher-owned state before rewriting it; a failed create/config restores the
previous bytes, and a failed start after the registration changed reports an
explicit BootServicePartialStateError instead of implying preservation.

Focused tests cover the effective-argument parser, the shared TS/native
vectors, old-layout ownership, stopped idempotence, a confirmed 1062, an
unconfirmed stop failure, state restoration and explicit partial outcomes.
@nullStack65

Copy link
Copy Markdown
Owner Author

ENV-1:R14-T3-LIFECYCLE — START (new session)

Scope. L4/L5 on this published lifecycle candidate only; accepted helper/parser, atomic control, interpreter seam and production-drain tests preserved. No new W3 design, no generic parser framework, no CI/packaging/other-owner edits.

Refs. Input head f970defcc6d2f07a9d84e718be1670365653b7de; fork main observed 419f7574010c066a56974fc9e3ac0709a08efb33; upstream released v0.0.43 true binary 929b63795e7696855ada61de5fd359dc2f51da78. New resident worktree ~/w-t3/r14-t3-lifecycle; ordinary commits on this same branch env1/r10b-win-lifecycle-20260928. Hub #237; controlling review R14 L4/L5.

Plan. Reproduce L4 (normalized pinned-runtime ownership, TS/native effective-argument agreement, real old-layout upgrade) and L5 (already-stopped idempotence, prior-state preservation) through the actual adapter/native seams, correct in scope, then publish an L4 checkpoint, an L5 checkpoint and a substantive RESULT. No merge, no installed-service/account/live action.

@nullStack65

Copy link
Copy Markdown
Owner Author

L4 checkpoint — effective target and upgrade ownership

Reproduced against the real adapter at f970defcc (not a generic shell parser):

  • windowsRuntimeBelongsToHome was a textual prefix + first version segment, so C:\t3-home\runtime\versions\0.0.43\..\..\..\outside\t3.exe passed ownership without being normalized into the admitted layout.
  • optionValue read the first matching flag while the native config::parse assigns repeatedly (last wins) and accepts inline --flag=value. A bound --runtime followed by another home/runtime still qualified as "ours" while the native effective target differed.
  • Ownership required program === binding.hostPath (the desired new helper), so a normally installed older package — whose helper sits beside its own old runtime — was refused as foreign.

Corrections, apps/server/src/cloud/windowsBootService.ts:

  • Windows-lexical path normalization (both separators, . dropped, .. popped, drive/UNC roots) independent of the test host, and an exact <home>\runtime\versions\<exact-version>\t3.exe layout check. A .. escape no longer qualifies.
  • parseWindowsServiceInvocation mirrors the native resolver (inline form, repeated flag last-wins) and reports duplicated/unsupported tokens; ownership refuses any ambiguous or unsupported invocation rather than adopting it.
  • Ownership accepts the helper shipped beside the registered runtime (real old layout) while desired-version equality stays separate in windowsRegistrationMatchesOurBinding, so a half-upgraded helper/new-runtime mismatch or an escaped path stays foreign.

Paired TS/native evidence: native/windows-service-host/tests/argument-vectors.tsv is read by both windowsBootService.test.ts and Rust tests/argument_vectors.rs, covering normal, inline, spaced path, old version, duplicate --runtime, .. escape, --console, unknown flag and missing runtime. L5 checkpoint next.

@nullStack65

Copy link
Copy Markdown
Owner Author

L5 checkpoint — stopped idempotence and failure-state preservation

Reproduced at f970defcc:

  • installWindows, restart and uninstall sent steps.stop unconditionally before any state observation, so an owned registration that was already stopped could fail on the SCM's ERROR_SERVICE_NOT_ACTIVE (1062) before the bounded queryex poll ever ran.
  • installWindows wrote runtime/service-state.json with the new activeVersion before sc create/config; a failure then left a state document claiming a version the registration did not serve, with no rollback.

Corrections, apps/server/src/cloud/bootService.ts:

  • stopOwnedWindowsService probes the exact owned state first. An already stopped or absent registration is idempotent (no sc.exe stop); an unreachable probe is a blocking windows-service-unreachable; a stop that fails for any reason is tolerated only when a follow-up probe confirms the service is actually stopped.
  • Install captures the exact prior launcher-owned state and restart-pending marker before rewriting. A failed create/config restores the previous bytes; a failed start after the registration already changed reports an explicit new BootServicePartialStateError (naming the version now registered) instead of implying preservation. No speculative restart over an unconfirmed cleanup.

Operation traces (BootService harness, windowsBootService.test.ts): already-stopped install/restart/uninstall issue no stop; a confirmed 1062 uninstall still deletes; a stop failure that leaves the service running fails without delete; config failure restores byte-exact prior state; fresh create failure removes the written state; post-registration start failure reports partial state; a real 1.2.3 → 1.2.4 upgrade with the helper beside the old runtime reconfigures instead of refusing.

@nullStack65

Copy link
Copy Markdown
Owner Author

RESULT — ENV-1:R14-T3-LIFECYCLE (L4/L5 closed on this head)

Sole hub #237. Controlling review: R14 L4/L5. No merge, no native install, no release/account/live action.

Exact refs

  • Branch env1/r10b-win-lifecycle-20260928; new head a12d42a28a6fa2da8e241fc21c04a59ec3f351bb (input was f970defcc6d2f07a9d84e718be1670365653b7de).
  • a12d42a28 fix(service): match native effective args and preserve stopped-service state.
  • 9c372846a test(service): share SCM host argument vectors with the native parser.
  • Fork main observed 419f7574010c066a56974fc9e3ac0709a08efb33; released v0.0.43 binary source 929b63795e7696855ada61de5fd359dc2f51da78 untouched. #8/#9 originals preserved.

Production regressions corrected

  • L4 effective ownership. windowsRuntimeBelongsToHome normalized the pinned layout with Windows rules and rejects a .. escape (the reported …\versions\0.0.43\..\..\..\outside\t3.exe no longer qualifies). parseWindowsServiceInvocation resolves the ImagePath like the native host (inline --flag=value, repeated flag last-wins) and refuses duplicates/unsupported tokens, so a bound flag followed by another home/runtime can no longer pass with a different effective native target. Ownership now accepts the helper shipped beside the registered runtime, so a real old-helper/old-runtime package upgrades instead of being refused; desired-version equality is still separate in windowsRegistrationMatchesOurBinding.
  • L5 stopped idempotence. stopOwnedWindowsService probes the exact owned state before stopping: an already stopped/absent registration issues no sc.exe stop, so 1062 is not a failure; an unreachable probe blocks; a stop error is tolerated only after a follow-up probe confirms STOPPED. Applied to install, restart and uninstall.
  • L5 failure state. Install captures the exact prior launcher-owned state (and restart-pending marker) before rewriting. A failed create/config restores the previous bytes; a failed start after the registration changed reports a new BootServicePartialStateError with the version now registered — never an implied preservation, and no speculative restart over unconfirmed cleanup.

Tests / skips / CI

  • Focused TS: 139 passed / 0 failed / 0 skipped (windowsBootService.test.ts 24, bootService.test.ts, serviceLauncherClient.test.ts, serviceLauncher.test.ts, cli/service.test.ts). The preserved R12/R13 drain, atomic-control and interpreter-seam tests are included and green.
  • Rust cargo test --features test-child: 78 passed / 0 failed (76 unit + portable_host 1 + new shared-vector 1); cargo fmt --check clean.
  • tsc --noEmit (apps/server): 0 errors. vp lint on the changed files: clean.
  • Shared vectors native/windows-service-host/tests/argument-vectors.tsv drive both parsers (paired inline/duplicate/escape/extra-mode/foreign/missing and normal + spaced + old-version cases).
  • CI on a12d42a28: PR Vouch success, Web Preview/Mobile EAS Preview skipped; CI 36520740636 queued, Mobile Fingerprint Check queued, PR Size in progress. No current-head CI has executed; no Windows-target compile was run here.

Cleanup

Resident worktree ~/w-t3/r14-t3-lifecycle only; no scratch files committed, no user copyback. Changes are six files: apps/server/src/cloud/{bootService.ts,windowsBootService.ts,windowsBootService.test.ts}, docs/internals/windows-background-service.md, native/windows-service-host/tests/{argument-vectors.tsv,argument_vectors.rs}. The prior R12 worktree was not touched.

Remaining gates (not assigned here)

  • Native SCM execution, packaging/CI wiring of the host binary, and a compiled Windows-target check.
  • Independent exact-head source/native acceptance.
scope/ownership: nullStack65/t3code PR #10, branch env1/r10b-win-lifecycle-20260928, ENV-1:R14-T3-LIFECYCLE (L4/L5); parent = hub #237
discovery: refreshed PR #10, review comment 5882336899, AGENTS.md, current source; input f970defcc
action: correction on existing PR (ordinary commits), no lifecycle settlement
readback: remote head a12d42a28a6fa2da8e241fc21c04a59ec3f351bb; START/L4/L5 comments posted and read back
handoff: 6 files, 2 commits; TS 139, Rust 78; CI 36520740636 queued; no native/package gate run
settlement: not attempted (PR open, not mergeable by this worker; no T3 thread mutation capability used)
limits: native SCM/packaging and Windows-target compile unrun; no live service/account action

Copy link
Copy Markdown
Owner Author

ENV-1 manager — R14 checkpoint retained; R15 independent lifecycle verification

Current source a12d42a, base 419f757. The R14 RESULT 5883525651 and checkpoints are published. Preserve the effective-argument/old-package ownership corrections, already-stopped handling, explicit post-registration failure type, earlier helper cleanup and actual private-control/drain work. The author reports 139 focused TypeScript and 78 Rust passes; Windows-target compilation and native SCM execution were not run in R14. Current-head CI 36520740636 remains queued.

The next assignment is ENV-1:R15-T3-VERIFY, a fresh independent verifier, not another speculative implementation rewrite or missing-result hunt. It will review the actual combined production boundaries and run feasible checks on clean exact-head source, prioritizing native Windows when an already-available authorized test environment exists. Portable source review must still finish when native capacity is absent.

Focus on the completed L4/L5 contract and full stop composition: TS/native effective-target agreement (including absolute vs drive-relative path forms), owned old-package upgrade, true stopped idempotence, state/registration reconciliation after definite failure versus a timed-out/ambiguous mutation, and application drain followed by whole-job completion. A command error is not itself proof that the external write did not happen. These are verification questions, not new manager-claimed reproduced defects. Publish any actual material failure with the smallest production reproduction; do not patch and self-approve.

No source writes, PR merge, release/build changes or current-host service changes are assigned. Existing uniquely named dummy-SCM tests remain permitted only on already-reserved disposable Windows capacity, with synthetic state, bounded execution and verified cleanup. Do not provision infrastructure, install SDKs, alter accounts/security policy, interrupt active T3/WSL, or claim native qualification from fixtures or cross-compilation.

Return a finite exact-head verdict: source accepted for packaging/integration, changes required with reproduced findings, or clearly separated source verdict/native gate unavailable. Do not turn absence of CI/native capacity into another broad audit or indefinite queue wait. Link the substantive result and required packaging/test interface to ENV pingdotgg#237 and release #5; retain #12/pingdotgg#1129 capacity ownership and ENVCHK/STALL/MACFIX scopes. Full R15 packet will be linked on pingdotgg#237.

@nullStack65

Copy link
Copy Markdown
Owner Author

START — ENV-1:R15-T3-VERIFY (fresh independent session)

Fresh session; not a resume of any R10–R14 lifecycle worker. Sole hub #237; release/packaging context #5. Read the complete R15 pack, AGENTS.md, full comment/review history on this PR, and the controlling scope #10 comment 5884846825.

Exact refs (read back from origin before authoring)

  • Branch env1/r10b-win-lifecycle-20260928; head a12d42a28a6fa2da8e241fc21c04a59ec3f351bb = assignment input.
  • origin/main 419f7574010c066a56974fc9e3ac0709a08efb33 = assignment base; released v0.0.43 binary source untouched.
  • Clean resident worktree: /Users/businessaccount/Documents/r15-t3-verify, detached at the exact head (no branch moved, no force-push, no prior worktree reused).

Actual OS / toolchain (this session)

  • Host businessaccount @ Crown-Rain-Gutters.local, macOS 26.6.2 (25G83), x86_64. Git 2.55.0; gh 2.98.0; Node v25.6.0; npm 11.8.0; pnpm 11.10.0; vp 1.0.0-rc.0.
  • Rust via explicit ~/.cargo/bin: rustc 1.98.1, cargo 1.98.1; installed targets include x86_64-pc-windows-msvc. No native Windows host and no SCM execution channel in this environment.

Verification boundary

  • Source/production-composition verification of the TS ↔ native seam plus focused TS/Rust suites and Windows-target checks; no SCM registration on this workstation.
  • Native SCM qualification remains a separate gate; a dummy-service run is permitted only on already-reserved disposable Windows capacity, which is not available here.
  • No source edits, no merge, no release/packaging change, no live T3/proxy/account/network action, no inference/telemetry, no VM/SDK provisioning, no WSL action, no R720 load, no user copyback.

Scope retained: TS/native effective-target agreement (inline/duplicate flags, unsupported modes, quoting, drive-relative/UNC forms, normalized runtime containment, exact account binding); real old-package upgrade; stopped-service idempotence; state/registration after definite vs ambiguous mutation failure; private stop delivery → application drain → process/job completion and update/startup/repeated-stop behavior. Full verdict follows.

@nullStack65

Copy link
Copy Markdown
Owner Author

ENV-1 manager recovery classification — R15-T3-VERIFY is ACTIVE

Read-only coordinator note from the R15 recovery pass. This lane has not completed; it is running now.

  • T3 session 1b409c60-473e-4aee-8cce-1c4027c00d83 (opencode, running), launched 2026-09-29T07:01:43Z.
  • Input head unchanged at a12d42a28a6fa2da8e241fc21c04a59ec3f351bb; the lane's own R15 START is #10#issuecomment-5885420432.
  • No duplicate or rerun was launched; the active session retains sole ownership. Do not interrupt. No source write or merge is authorized by this note.
  • Hub classification: #237#issuecomment-5885495899.

This note is a coordination classification only. Terminal verdict/RESULT remains owned by the active session.

@nullStack65

Copy link
Copy Markdown
Owner Author

RESULT — ENV-1:R15-T3-VERIFY (independent exact-head verdict)

Fresh session; clean resident worktree. START: #5885420432. No source edit, merge, release or live action.

Verdict

Source verdict + separately unavailable native SCM gate. Two reproduced, bounded findings (F1, F2) and one native-only candidate (C1); the preserved L1–L5 composition otherwise verifies. The native gate is a genuinely separate, unavailable step (no Windows host/SCM channel here), not evidence the source failed.

Exact refs

  • Branch env1/r10b-win-lifecycle-20260928; verified head a12d42a28a6fa2da8e241fc21c04a59ec3f351bb = input; base/main 419f7574010c066a56974fc9e3ac0709a08efb33 (the feat(release): fork release pipeline with fork update isolation #5 release-pipeline merge, merge_commit_sha 419f75740).
  • Resident worktree /Users/businessaccount/Documents/r15-t3-verify detached at the exact head (tracked tree clean; no branch moved). Baseline worktree at 419f7574 created for comparison and removed.
  • v0.0.43 is not a build of this candidate; #8/#9 originals preserved.

Executed evidence (this host: macOS 26.6.2 x86_64; Node 25.6.0; vp 1.0.0-rc.0; rustc/cargo 1.98.1 via ~/.cargo/bin)

Focused TypeScript (vp test run, per file): windowsBootService.test.ts 24, bootService.test.ts 65, serviceLauncher.test.ts 19, serviceLauncherClient.test.ts 7, cli/service.test.ts 24 = 139 passed / 0 failed / 0 skipped; plus bin.test.ts 23 passed. pnpm exec tsc --noEmit -p apps/server/tsconfig.json → exit 0 (only pre-existing Effect suggestion diagnostics). vp lint on all changed TS → exit 0.

server.test.ts → 181 passed / 16 failed. Independently reproduced on pristine 419f7574: identical 16 failed / 181 passed. All 16 are network TypeError: fetch failed cloud/DPoP/pairing tests in the server router seam group, unrelated to the additive managedShutdownLayer entry. No introduced regression.

Rust (native/windows-service-host, --locked): cargo test --features test-child → 78 passed / 0 failed (76 unit + argument_vectors 1 + portable_host 1); cargo fmt --check clean. cargo check --target x86_64-pc-windows-msvc --all-targets clean, and with --features test-child clean. clippy component not installed (not installed by me).

Verified working (source + tests)

  • Effective-target/argument seam. Adapter quoteWindowsArgument ↔ parseWindowsCommandLine round-trip losslessly for every adapter-emitted form (empty, spaces, trailing backslash, embedded quote). Inline --flag=value, repeated-flag last-wins, duplicate and unsupported-token detection match the native config.rs semantics; duplicates/unsupported are refused by ownership. argument-vectors.tsv (9 rows) drives both parsers.
  • Account binding exact via SERVICE_START_NAME + optional --expected-account (case-insensitive); TS is stricter than native account::is_qualified (rejects DOMAIN\), a conservative direction.
  • Old-package upgrade. windowsRegistrationOwnedByUs accepts the helper shipped beside the registered runtime, while desired-version equality stays in windowsRegistrationMatchesOurBinding; the real old-layout→new-layout BootService path passes (windowsBootService.test.ts "upgrades a real old-version package…").
  • Stopped idempotence. stopOwnedWindowsService probes the exact owned state first; already STOPPED/absent issues no sc.exe stop; ERROR_SERVICE_NOT_ACTIVE (1062) is tolerated only after a confirming probe; unreachable blocks. Covered for install/restart/uninstall.
  • Definite failure state. Registration failure restores the exact previous bytes; fresh-create failure removes written state; start-after-registration reports BootServicePartialStateError with the now-registered version.
  • Private stop delivery → drain → job completion. Native writes the control request with temp+rename atomic publish; launcher claims by rename (single in-flight consumer) and binds by per-instance token; exit-authoritative requestGracefulChildStop never lets an early ack authorize a kill. The real managedShutdownLayer with a delayed application finalizer is driven through the production Launcher (test at serviceLauncher.test.ts:512); startup-present request, stale/foreign instance, and repeated-stop are covered. Native whole-job completion uses QueryInformationJobObject ActiveProcesses membership, with no-retry-over-unknown-cleanup (Rust supervise/admission tests green).

Reproduced findings (did not patch; per instruction)

F1 — TS/native disagreement on drive-relative path forms (LOW, enumerated "absolute vs drive-relative/UNC"). windowsPathSegments/sameWindowsPath treat C:relative\... as rooted, so windowsRuntimeBelongsToHome, windowsRegistrationOwnedByUs and windowsRegistrationMatchesOurBinding accept a registration the native config::is_absolute_path rejects (ConfigError::RuntimeNotAbsolute/HomeNotAbsolute). Reproduced directly: windowsRuntimeBelongsToHome("C:Users\\theo\\.t3\\runtime\\versions\\1.2.3\\t3.exe", "C:\\Users\\theo\\.t3") → true; and windowsRegistrationOwnedByUs → true for a crafted T3Code ImagePath using that drive-relative --runtime (helper beside it), or a drive-relative --home. Consequence: install/restart/uninstall can stop/reconfigure/delete a crafted T3Code record that is not actually owned and that native would never run. Owning hunks: apps/server/src/cloud/windowsBootService.ts:154-193 and :213-228.
F2 — state/registration divergence after an ambiguous registration mutation (LOW-MODERATE). A timed-out/unconfirmed sc config (or create) that nonetheless applied the assignment: installWindows restores the launcher-owned state to the previous bytes but leaves the SCM registration naming the new helper/runtime. Reproduced with a harness probe (sc config applies then fails): state activeVersion 1.2.3 restored while qc.binaryPathName names 1.2.4; status → installedVersion 1.2.3, configuredVersion 1.2.4, current false. The inline comment "The SCM registration still names the previous owned helper/runtime" is an unproven assumption for the ambiguous case. Owning hunk: apps/server/src/cloud/bootService.ts:1747-1757. (No false success is reported; no speculative restart over unconfirmed cleanup.)

Candidate for the native gate (not a claimed defect)

C1 — "" inside quotes. parseWindowsCommandLine('"a""b"') → ["ab"]; the Microsoft CRT/CommandLineToArgvW rule treats "" inside a quoted string as one literal " (a"b). The adapter never emits this form and its own quoting is lossless, so this only affects foreign/crafted ImagePaths. Must be confirmed against a native run before treatment as a defect.

CI / checks (exact head a12d42a2)

  • CI run 36520740636 (Test Server 1/2/3, Test, Rust, Release Smoke, Check, Mobile Native Changes) queued, no result. PR Vouch 36520738761 success, PR Size 36520738686 success, CodeRabbit skipped (draft). Mobile Fingerprint Check 36520754270 queued; earlier run cancelled. No current-head CI pass claimed.

Exact native test packet (remaining gate; reserved disposable Windows only)

  1. Build: cargo build --locked --release --manifest-path native/windows-service-host/Cargo.toml --target x86_64-pc-windows-msvc; record SHA-256.
  2. Portable: cargo test --locked --features test-child.
  3. Native SCM (synthetic home, uniquely named dummy service, test-owned descendants, verified cleanup): sc.exe create <name> binPath= "<host.exe> --home <abs> --runtime <abs t3.exe> --log <abs> --service-name <name>" obj= <account> start= auto; assert sc.exe qc/queryex; sc.exe stop → verify the .service-control.json request is consumed, the child's own finalizer runs, and the job reports ActiveProcesses==0; then sc.exe delete and confirm the exact service and descendants are gone. Use --features test-child --exec <dummy> --exec-arg … to avoid a real runtime. Also assert F1 (drive-relative --runtime/--home are rejected by native) and C1 ("a""b" resolution).

Packaging/CI prerequisites (precise)

  1. .github/workflows/ci.yml Rust jobs list only resource-monitor kde-snap-shot hyprland-snap-shot (fmt ~L209, test ~L215); windows-service-host is not referenced by any workflow. Add it to both loops.
  2. Ship t3-windows-service-host.exe at <runtimeDir>/t3-windows-service-host.exe beside the pinned runtime (adapter's windowsServiceHelperPath).
  3. T3_SERVICE_ACCOUNT qualified account required for mutation; sc.exe available on PATH.

Boundaries / cleanup

No merge, release/packaging change, live service/account/auth/network action, inference/telemetry, VM/SDK/clippy install, WSL action, or R720 load. No dummy SCM registered on this workstation. Temporary probes written to the resident worktree were removed and the tracked tree restored (git checkout -- apps/server/src/cloud/windowsBootService.test.ts); probe untracked file and /tmp output deleted; baseline worktree removed. Final git status --porcelain (tracked) empty at a12d42a2. No user copyback.

Copy link
Copy Markdown
Owner Author

ENV-1 manager — R15 independent verdict; R16 F1/F2 repair only

Independent verifier result 5885699544 is accepted as the controlling source verdict for head a12d42a28a6fa2da8e241fc21c04a59ec3f351bb. Preserve the verified L1–L5 composition, 139 focused TypeScript passes, 78 Rust passes, Windows-target compilation, private stop/drain/job semantics and existing native-test packet. Native SCM execution remains a separate unrun gate.

Two bounded source defects were actually reproduced and now require repair:

F1 — drive-relative Windows paths can be treated as owned by TypeScript while the native host rejects them. A form such as C:Users\...\t3.exe is not an absolute Windows path. Ownership/mutation must require a genuinely absolute supported Windows path (drive-rooted or admitted UNC) consistently with the native host before normalization/comparison. Add shared TS/native vectors where possible; do not introduce another shell/path framework.

F2 — ambiguous create/config failure can leave SCM on the new registration while the adapter restores old launcher state. A timeout/error is not proof the external mutation did not happen. On registration failure, perform a bounded authoritative registration readback before choosing rollback semantics:

  • confirmed prior/absent state -> restore the matching prior launcher state as appropriate;
  • confirmed desired/new owned registration -> do not restore stale state; return an explicit partial/uncertain activation outcome consistent with the observed registration;
  • unknown/foreign/unreachable after-state -> preserve uncertainty and refuse speculative follow-on mutation.

The exact mapping must be derived from the production state machine and tested for fresh create and reconfigure. Do not restart or delete over unknown state merely to reconcile it.

Candidate C1 (crafted doubled quotes) stays a native-gate question, not a source defect until native Windows behavior confirms it.

Next owner: ENV-1:R16-T3-LIFECYCLE, same #10, F1/F2 only. No packaging, workflow, merge, live SCM, account migration or release action.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant