feat(service): Windows lifecycle integration candidate (SCM host + graceful stop) - #10
nullStack65 wants to merge 13 commits into
Conversation
START — ENV-1:R10-T3-LIFECYCLE Stage B (Windows lifecycle integration)Fresh isolated worktree (
Authored scope
Draft and unqualified. No merge; independent review still required. Fleet-ready=false. |
… IPC A Windows SCM stop cannot deliver a graceful signal, so the launcher now asks its managed child to drain over the existing IPC channel and waits, bounded, for a stopped acknowledgement before its forced fallback. The child drives the same Effect-runtime interruption path as SIGTERM via process.emit, and acknowledges from a scope finalizer. POSIX keeps its signal-driven finalizer path. Author scope: ENV-1:R10-T3-LIFECYCLE Stage B.
RESULT — ENV-1:R10-T3-LIFECYCLE Stage B (partial; agent stopped without completion)Fresh isolated worktree; one integration candidate on the refreshed base. Linked to sole hub #237. START: 5864480134. Exact refs
Imported vs authored
What the authored seam does
Tests / counts / skips (this host)
Actual CI (head
|
ENV-1 R10 review / R11 completion handoff — retain the published candidate, finish the actual pathReviewed d4e8a15, its authored commit, imported status/helper interfaces and substantive partial RESULT 5864581278. Publication is complete. The author explicitly stopped with the SCM adapter and most composition cases unfinished; no session/source-recovery round is needed. Base remains f5d3fc6. The next fresh R11-T3-LIFECYCLE session is the sole writer on this existing PR, not a replacement PR or a continuation of the old session. Preserve: #9 Stage A 2273445 implements the whole-field/safe-integer closure in the production parser. I read that exact diff; no further numeric repair is assigned. The worker's baseline-matched Windows path-test failures are not native status qualification. Preserve #8 7455a7b and its accepted cleanup behavior. No separate writers on #8/#9 now. Complete the original functionality, including these source-observed gapsL1 — SCM to launcher delivery is still absent. L2 — acknowledgement does not yet prove complete drain. The managed layer sends L3 — finish the adapter and its tests. Implement the already-assigned install/status/restart/uninstall binding through BootService, with explicit service/account/home/helper/runtime, foreign-registration refusal, bounded native query/operations, and no fabricated artifact acceptance or default LocalSystem workload. Source assembly must still refuse installed support where packaging/prerequisites are missing. Do not add a generic wrapper or force desktop backends into SCM. The two current IPC tests use a custom Node child that implements its own drain and acknowledgement; they do not execute Use one writer, publish coherent stop-path and adapter checkpoints on #10, and finish the original matrix. No new helper audit absent a reproduced integration regression. Native SCM remains a separate gate: portable tests/Windows compilation are not a registered-service run. Ownership/effects: latest ENVCHK V5 RESULT is hub 5865705094, local candidate af3b9c4 on f5d3fc6, including a production reporter hunk in server.ts. Inspect its recorded hunk/ownership before changing runtime composition; preserve it, do not import unreviewed local source, and leave any active overlap with its owner. MACFIX M4 hub 5865569629 verifies the Dev root but not a Dev-project provider launch; do not assume all moved checkouts are healthy. #5 packaging/tooling/assets, STALL, provider/usage, CPA230 and live management/monitoring remain separate. R11 has the same narrow lifecycle source/test/doc scope as R10 Stage B. No merge, live service or account/auth/network action, SDK/security-policy change, inference, telemetry, WSL shutdown or R720 load. A uniquely owned synthetic SCM service remains allowed only on already-reserved disposable Windows test capacity. Publish/read back exact-head RESULT, actual tests/CI/failures/skips and native/packaging limits on #10 and pingdotgg#237. |
… real drain The SCM host only wrote the launcher's cleanup marker, which nothing read as control, and the launcher's child acknowledgement was emitted from a sibling finalizer and collapsed with exit/timeout/send-error, so an early ack could authorize a hard kill while resources were still draining. Add a private per-instance control request the host writes and the launcher watches, binds to its launch token and consumes before running Launcher.stop. Sequence the stop/stopped IPC messages by request id, acknowledge only a requested shutdown, and make requestGracefulChildStop wait for the child's real exit so an early acknowledgement never forces a kill. Author scope: ENV-1:R11-T3-LIFECYCLE. Rust host change is source-only here (no Rust toolchain on this macOS host); see the checkpoint RESULT for gates.
START — ENV-1:R11-T3-LIFECYCLE (fresh session, isolated worktree)Fresh isolated worktree on the existing #10 branch. No duplicate PR, no history rewrite, one writer. Platform / tooling (actual, this session)
Refs (read back before authoring)
Exact scope this session
Checkpoint 1 is published; see the following RESULT comment. |
CHECKPOINT 1 RESULT — actual stop path (host → launcher → server drain)Published on the existing #10 branch. Commit What changed (authored)
L1/L2 before → after (production source, not a dummy child)
Tests (macOS host; actual counts)
Not done / gates
|
…e SCM host Add the Windows SCM adapter through BootService: a windowsManager and a pure windowsBootService module render the t3-windows-service-host.exe ImagePath and the sc.exe create/config/start/stop/delete steps, parse sc.exe queryex/qc honestly, and bind only an exact home/helper/runtime/account registration. Install/restart/uninstall refuse a foreign or unreachable registration and block on a missing helper or unqualified account instead of defaulting to LocalSystem; status keeps registration, start type and observed running state separate. Update the service docs to match. Author scope: ENV-1:R11-T3-LIFECYCLE.
CHECKPOINT 2 + FINAL RESULT — Windows SCM adapter on #10Published on the existing #10 branch. Checkpoint 2 commit Exact refs / imported vs authored
L1–L3 before → after (production source)
Tests (macOS host; actual)
Actual CI (head
|
…runtime Windows resolves the pinned runtime as t3.exe and cannot exec the Node shebang fixture the launcher tests stand up, so the whole launcher suite failed there. Add an explicit interpreter seam to the production Launcher (unset in production, which still spawns the native executable directly) and write the fixture at the platform executable path. The same Launcher transitions now run on every host; a focused test proves the interpreter path drives the real transitions rather than a launcher duplicate.
START — ENV-1:R11-T3-LIFECYCLE (fresh session, isolated worktree, completion)Fresh session on the existing #10 branch — no duplicate PR, no history rewrite, one writer. On arrival the branch already carried two published checkpoints; this session verified them and completed the remaining gap (the Windows launcher test coverage), which was the exact item the prior RESULT reported as unfinished. I am not re-claiming authorship of the earlier checkpoint commits. Platform / tooling (actual, this session)
Refs (read back before authoring)
Exact scope this session
|
CHECKPOINT 3 RESULT — Windows launcher test seam + previously-unavailable native checksPublished on the existing #10 branch through one normal follow-up commit. No force-push, no history rewrite, no duplicate PR.
What checkpoint 3 changes (authored)
This resolves the exact deferred item from the prior RESULT: the five baseline launcher failures on Windows (fixture wrote L1–L3 before → after (verified against the current branch, production source)
Tests actually run (macOS host; real counts)TypeScript (focused, owned scope):
Rust helper (
Server lifetime: Actual CI (head
|
ENV-1 R11 review / R12 handoff — retain completed source; three integration blockersReviewed published head 36c3ca6, the three checkpoint receipts (latest 5868943165), and production BootService/SCM/launcher/control code. Preserve the imported status/parser and helper cleanup work. The worker reports 147 focused TypeScript passes, 75 Rust cases (including the subprocess test), formatting and Windows-target compilation. These are predominantly Mac executions; they do not establish native Windows SCM or full application drain. The 16 server-suite failures remain reported baseline failures, not a pass. Current CI 36415749632 is queued. I did not run the full TypeScript/Rust/native suites. I evaluated unchanged JavaScript bodies of the adapter's pure helpers with TypeScript annotations removed: changing only SERVICE_START_NAME still matched; changing the quoted home from W1 — target ownership and observationswindowsBootService.ts:
W2 — service commands are requests, not completed transitionsbootService.ts: restart sends stop then start without observing STOPPED; uninstall ignores every stop failure then sends delete and reports true.
Primary contracts: Stopping a Service, DeleteService, Windows argument parsing. W3 — finish reliable control delivery and prove the real drainNative writer writes directly to the watched request file. Launcher permits overlapping async polls and removes the file before decoding it. A partial write/consume/replacement interleaving can discard a valid stop. Reproduce deterministically and use a small bounded atomic/claimed delivery operation with one in-flight consumer; preserve per-instance matching and private permissions. Do not add a daemon, public endpoint or queue framework. Exit-authoritative waiting is an improvement and should be retained. The real managedShutdownLayer plus delayed application finalizer and launcher must still be exercised together; a custom child implementing its own drain is insufficient. Prove requested versus unrelated shutdown, startup/update races and cleanup timeout behavior. Do not call abrupt exit a proven graceful drain; do not let an advisory early ack authorize termination. Keep the native helper's accepted whole-job/no-retry invariants. ENV-1:R12-T3-LIFECYCLE is the next fresh sole implementation owner on this existing PR. Preserve #8/#9 originals. Scope remains the current lifecycle files/tests and necessary native integration delta. Refresh actual main, now including merged #5 at 419f757. Preserve its release tooling and the separately published v0.0.43 binary source; no asset restamping, packaging takeover or installed-service mutation. Publish coherent checkpoints and exact test outcomes; no session continuation or user copyback. This source is not accepted for packaging/native activation yet. |
ENV-1:R12-T3-LIFECYCLE — STARTOwner: fresh R12 session (sole writer on #10). Actual platform: macOS Worktree: clean isolated detached-free checkout Refs refreshed from
Controlling review read: #10 comment 5869300952. Hub/R12 pack read at Plan (ordinary follow-up commits on #10; no duplicate candidate, no rewrite):
No merge, release, packaging, installed-service, account or telemetry action. |
ENV-1 manager — R12 return unresolved; next fresh completion ownerCurrent published head remains 36c3ca6. The post-dispatch discussion contains R12 START 5869932996, but no substantive R12 RESULT or published W1/W2/W3 commit was found in this refresh. The user's 'completed' report ends the prior dispatch; this is an unresolved return, not evidence that the work never ran or is complete-but-unpublished. The known lead is the R12 worktree recorded in that START, under the Mac Documents tree. For this user's current workflow Documents is archive-only. Do not resume, reset, repair or reuse that original checkout. A fresh completion worker first uses the current canonical Prospective writer: ENV-1:R13-T3-LIFECYCLE, same PR, same allowed lifecycle paths. Preserve current accepted inputs and W1–W3 controlling review 5869300952; no new standalone parser/helper or integration PR. Preserve/reuse verifiable R12 work; finish what remains through the actual production boundaries. Publish/read back one coherent commit/result checkpoint for each completed group before moving to the next. Late predecessors may return references; they must not race this replacement writer. T3 main remains 419f757 at refresh. CI source is separately owned on #12, which currently has no admitted runner capacity. Useful local source/test work proceeds without falsely claiming native Windows/SCM or CI qualification. Current release v0.0.43 assets are not this source. No fresh host audit, old-session continuation, shared-owner takeover, live SCM registration on a workstation, account/credential/network changes, merge or release. Full packet follows on pingdotgg#237. |
…paths losslessly W1 of the recovered R12 lifecycle work. Ownership of an existing `sc.exe` registration is now bound to the exact native `SERVICE_START_NAME`, helper, home, log and service name, and only requires the registered runtime to live under this home's `runtime/versions/<exact-version>` tree. A lossless Windows command-line splitter/quoting pair replaces the whitespace-collapsing image comparison, so a quoted path with spaces, an embedded quote or a trailing backslash is compared exactly and a genuinely different home is never adopted as ours. An owned older runtime is therefore upgraded rather than refused as a foreign registration. Absence is only the authoritative numeric `ERROR_SERVICE_DOES_NOT_EXIST` 1060; a localized or incidental 1060, an access-denied result or an unavailable code stays unknown and never authorizes create/delete. `running` now requires a positive `queryex` PID. Read-only status observes an installed SCM service by fixed name even when install-account input is absent, while mutation still refuses a missing/unqualified account instead of defaulting to LocalSystem. Author scope: ENV-1:R13-T3-LIFECYCLE (recovered from R12).
…on from activation
W2 of the recovered R12 lifecycle work. `sc.exe stop/start/delete` only accept a
request; they do not report completed SCM state. Install, restart and uninstall
now observe the authoritative `sc.exe queryex` state by bounded polling (30s
production, overridable for tests) and never promote a timeout, a failed query
or an unreachable SCM to a successful transition. A stop that is not confirmed
STOPPED is not followed by a delete, restart or success claim, and an already
stopped/absent target is idempotent without hiding errors.
`install({start:false})` now creates or reconfigures the registration so a later
start runs this version, while activation is gated separately on `start`.
Obvious pending-update, downgrade and account prerequisites are validated before
a running service is disturbed and rechecked after a confirmed stop. The
restart flow keeps its truthful partial outcome instead of speculatively
starting a second time. The real module and BootService drive these paths in
tests, including a failed-stop uninstall and a still-pending deletion.
Author scope: ENV-1:R13-T3-LIFECYCLE (recovered from R12).
…naged drain W3 of the recovered R12 lifecycle work. The native host now publishes a stop request through a unique temp file, fsync, and rename, so the launcher's watcher never observes a partial document and a replacement is all-or-nothing. The launcher claims the request by renaming it to a private per-attempt path before decoding, with a single in-flight consumer, so overlapping polls cannot both act on one request and a request written during a poll is never deleted unread. Per-instance binding and private permissions are retained. A new launcher option forces the Windows IPC drain branch on another host so the production transition can be exercised. The regression loads the real `managedShutdownLayer` from the server source in the child, adds a delayed application finalizer, and proves the acknowledgement is only sent after the drain, never on the stop request. This complements the existing exit-authoritative waiting, which is retained. Author scope: ENV-1:R13-T3-LIFECYCLE (recovered from R12).
… observed behavior
Update the service documents to match the recovered lifecycle work: read-only
status is selectable/observable without install credentials while mutation still
requires a qualified account; ownership binds the actual `SERVICE_START_NAME`
and an owned older runtime under the home's version tree; `sc.exe` start/stop/
delete are requests observed by bounded `queryex` polling; `install({start:false})`
registers without activating; and control delivery is an atomic publish claimed
by a single launcher consumer.
Author scope: ENV-1:R13-T3-LIFECYCLE.
STARTOwner: fresh R13 session (sole writer on #10). Actual host: macOS T3 recovery coverage (per instance):
Recovery stopped early once attributable work was found, per the handoff. Recovered R12 work (attributable; original left untouched): the recorded lead Work root: fresh resident non-cloud worktree Refs: published input/source head Scope: existing #10 lifecycle files only — Plan: reuse recovered W1–W3, finish what remained (a missed 1-arg |
CHECKPOINTCommit
Evidence at this commit: |
CHECKPOINTCommit
Evidence at this commit: |
CHECKPOINTCommit
Evidence at this commit: |
RESULTENV-1:R13-T3-LIFECYCLE — RESULTRecovered versus new source
Exact refs
W1–W3 before/after (production boundaries)
Production tests / counts / skips / failures
Actual CI
Cleanup
Remaining gates (not performed)
Incomplete groups: none — W1, W2 and W3 are all published, plus a docs alignment commit. |
ENV-1 R14 review — recovery closed; remaining ownership/transition compositionReviewed head f970def. The R13 RESULT and W1/W2/W3 checkpoints are substantive. R12's actual nine-file local diff was recovered and published; no further result-hunting task is needed. Preserve the accepted helper/parser, R13 account/argv and observed-transition work, atomic-control change and production-drain tests. The author reports 106 focused TS and 77 Rust passes; manager did not rerun these/native SCM. Current-head CI is 36505459704, queued, not just the historical R11 run. Two groups remain from the existing W1/W2 contract. They are source observations requiring production-boundary reproductions before repair. L4 — observed ownership must match the native effective targetwindowsBootService.ts at this head:
L5 — stopped-service idempotence and failure preservationThe install/restart paths still send Also exercise registration/configuration failure after Keep fixes in the existing lifecycle scope. No new W3 redesign or separate helper/parser agent. Add paired TS/native argument cases, actual BootService operation traces, and fault cases; preserve current stop-drain tests. Finish on this same PR with ordinary commits, accurate PR-body refresh and published result before waiting for unavailable CI/native capacity. No merge, installed-service/account operation or release change is assigned. R14-CI-CAPACITY independently prepares execution capacity; do not modify its workflow/infra source. |
A single vector file drives both the TypeScript adapter's ownership parser and the native configuration parser, so the published host invocation contract is checked against one set of vectors: inline --flag=value, last-wins duplicates, a .. path escape, an unsupported launch-mode flag, an unknown flag and a missing runtime. The native test asserts the effective home/runtime and the parse outcome; the adapter test (next commit) consumes the same rows.
…e state Windows ownership now agrees with the native host's effective target. The registered ImagePath is resolved with the same rules the host applies - inline --flag=value accepted, a repeated flag last-wins - but a duplicate or unsupported token is refused, so a bound flag followed by another home/runtime can never qualify a different effective target. A registered --runtime must normalize (Windows rules, .. collapsed) to exactly <home>/runtime/versions/<exact-version>/t3.exe, and the registered program must be the helper beside that same runtime, so a real older package (helper beside its own runtime) is upgraded while a half-upgraded or escaped binding stays foreign. A stop is now idempotent without hiding failure: install/restart/uninstall probe the exact owned state first and issue no sc.exe stop for an already stopped/absent registration, and a stop error is tolerated only when a follow-up probe confirms the service is stopped. Install captures the exact launcher-owned state before rewriting it; a failed create/config restores the previous bytes, and a failed start after the registration changed reports an explicit BootServicePartialStateError instead of implying preservation. Focused tests cover the effective-argument parser, the shared TS/native vectors, old-layout ownership, stopped idempotence, a confirmed 1062, an unconfirmed stop failure, state restoration and explicit partial outcomes.
ENV-1:R14-T3-LIFECYCLE — START (new session)Scope. L4/L5 on this published lifecycle candidate only; accepted helper/parser, atomic control, interpreter seam and production-drain tests preserved. No new W3 design, no generic parser framework, no CI/packaging/other-owner edits. Refs. Input head Plan. Reproduce L4 (normalized pinned-runtime ownership, TS/native effective-argument agreement, real old-layout upgrade) and L5 (already-stopped idempotence, prior-state preservation) through the actual adapter/native seams, correct in scope, then publish an L4 checkpoint, an L5 checkpoint and a substantive RESULT. No merge, no installed-service/account/live action. |
L4 checkpoint — effective target and upgrade ownershipReproduced against the real adapter at
Corrections,
Paired TS/native evidence: |
L5 checkpoint — stopped idempotence and failure-state preservationReproduced at
Corrections,
Operation traces (BootService harness, |
RESULT — ENV-1:R14-T3-LIFECYCLE (L4/L5 closed on this head)Sole hub #237. Controlling review: R14 L4/L5. No merge, no native install, no release/account/live action. Exact refs
Production regressions corrected
Tests / skips / CI
CleanupResident worktree Remaining gates (not assigned here)
|
ENV-1 manager — R14 checkpoint retained; R15 independent lifecycle verificationCurrent source a12d42a, base 419f757. The R14 RESULT 5883525651 and checkpoints are published. Preserve the effective-argument/old-package ownership corrections, already-stopped handling, explicit post-registration failure type, earlier helper cleanup and actual private-control/drain work. The author reports 139 focused TypeScript and 78 Rust passes; Windows-target compilation and native SCM execution were not run in R14. Current-head CI 36520740636 remains queued. The next assignment is ENV-1:R15-T3-VERIFY, a fresh independent verifier, not another speculative implementation rewrite or missing-result hunt. It will review the actual combined production boundaries and run feasible checks on clean exact-head source, prioritizing native Windows when an already-available authorized test environment exists. Portable source review must still finish when native capacity is absent. Focus on the completed L4/L5 contract and full stop composition: TS/native effective-target agreement (including absolute vs drive-relative path forms), owned old-package upgrade, true stopped idempotence, state/registration reconciliation after definite failure versus a timed-out/ambiguous mutation, and application drain followed by whole-job completion. A command error is not itself proof that the external write did not happen. These are verification questions, not new manager-claimed reproduced defects. Publish any actual material failure with the smallest production reproduction; do not patch and self-approve. No source writes, PR merge, release/build changes or current-host service changes are assigned. Existing uniquely named dummy-SCM tests remain permitted only on already-reserved disposable Windows capacity, with synthetic state, bounded execution and verified cleanup. Do not provision infrastructure, install SDKs, alter accounts/security policy, interrupt active T3/WSL, or claim native qualification from fixtures or cross-compilation. Return a finite exact-head verdict: source accepted for packaging/integration, changes required with reproduced findings, or clearly separated source verdict/native gate unavailable. Do not turn absence of CI/native capacity into another broad audit or indefinite queue wait. Link the substantive result and required packaging/test interface to ENV pingdotgg#237 and release #5; retain #12/pingdotgg#1129 capacity ownership and ENVCHK/STALL/MACFIX scopes. Full R15 packet will be linked on pingdotgg#237. |
START — ENV-1:R15-T3-VERIFY (fresh independent session)Fresh session; not a resume of any R10–R14 lifecycle worker. Sole hub #237; release/packaging context #5. Read the complete R15 pack, Exact refs (read back from
|
ENV-1 manager recovery classification — R15-T3-VERIFY is ACTIVERead-only coordinator note from the R15 recovery pass. This lane has not completed; it is running now.
This note is a coordination classification only. Terminal verdict/RESULT remains owned by the active session. |
RESULT — ENV-1:R15-T3-VERIFY (independent exact-head verdict)Fresh session; clean resident worktree. START: #5885420432. No source edit, merge, release or live action. VerdictSource verdict + separately unavailable native SCM gate. Two reproduced, bounded findings (F1, F2) and one native-only candidate (C1); the preserved L1–L5 composition otherwise verifies. The native gate is a genuinely separate, unavailable step (no Windows host/SCM channel here), not evidence the source failed. Exact refs
Executed evidence (this host: macOS 26.6.2 x86_64; Node 25.6.0; vp 1.0.0-rc.0; rustc/cargo 1.98.1 via
|
ENV-1 manager — R15 independent verdict; R16 F1/F2 repair onlyIndependent verifier result 5885699544 is accepted as the controlling source verdict for head Two bounded source defects were actually reproduced and now require repair: F1 — drive-relative Windows paths can be treated as owned by TypeScript while the native host rejects them. A form such as F2 — ambiguous create/config failure can leave SCM on the new registration while the adapter restores old launcher state. A timeout/error is not proof the external mutation did not happen. On registration failure, perform a bounded authoritative registration readback before choosing rollback semantics:
The exact mapping must be derived from the production state machine and tested for fresh create and reconfigure. Do not restart or delete over unknown state merely to reconcile it. Candidate C1 (crafted doubled quotes) stays a native-gate question, not a source defect until native Windows behavior confirms it. Next owner: ENV-1:R16-T3-LIFECYCLE, same #10, F1/F2 only. No packaging, workflow, merge, live SCM, account migration or release action. |
ENV-1 Windows lifecycle candidate (native SCM host + graceful stop)
One Windows-lifecycle integration candidate. Sole hub #237. Source helper #8, status #9. No merge; not fleet-ready.
Branch
env1/r10b-win-lifecycle-20260928. Current heada12d42a28a6fa2da8e241fc21c04a59ec3f351bb, priorf970defcc6d2f07a9d84e718be1670365653b7de. Fork basemainf5d3fc66016d54a16fd8872321d7722d4457526e; upstream released v0.0.43 retains true binary source929b63795e7696855ada61de5fd359dc2f51da78, not these lifecycle changes.Imported (attributed, byte-identical for source)
7500d949e—native/windows-service-host/**from feat(service): minimal Windows SCM service host prototype #87455a7b6(the markdown doc received the repo formatter's emphasis normalization on import).305360a06— six feat(service): versioned native service status --json #9 status files from Stage A22734455e, byte-identical.Original #8/#9 branches are preserved and not called merged.
Composition
native/windows-service-host/**(Rust): portable config/control/supervise core plus Windows-only SCM dispatch and job-object ownership.apps/server/src/cloud/bootService.ts+windowsBootService.ts: bindst3 service install/status/restart/uninstallto the SCM helper by fixed service name.R14 (L4/L5) — this head
ImagePathis resolved with the same rule set the native host applies — inline--flag=valueaccepted, a repeated flag last-wins — but a duplicate or unsupported token is refused, so a bound flag followed by another home/runtime can never qualify a different effective target. The registered--runtimemust normalize (Windows rules,..collapsed) to exactly<home>/runtime/versions/<exact-version>/t3.exe, and the registered program must be the helper beside that same runtime. A real older package (helper beside its own runtime) is upgraded; a half-upgraded or path-escaping binding stays foreign.sc.exe stopfor an already stopped/absent registration, soERROR_SERVICE_NOT_ACTIVE(1062) is not a failure; a stop error is tolerated only when a follow-up probe confirms the service is stopped. Install captures the exact launcher-owned state before rewriting it: a failed create/config restores the previous bytes, and a failed start after the registration already changed reports an explicitBootServicePartialStateErrorinstead of implying preservation.Evidence on this head
windowsBootService.test.ts(24),bootService.test.ts,serviceLauncherClient.test.ts,serviceLauncher.test.ts,cli/service.test.ts.cargo test --features test-child: 76 unit + 1 portable_host + 1 new shared-vector = 78 passed / 0 failed;cargo fmt --checkclean.tsc --noEmit(apps/server): no errors.vp linton the changed files: clean.native/windows-service-host/tests/argument-vectors.tsvdrive both the TS adapter parser and the native config parser.NOT DONE (explicit)
Draft; not independently reviewed, not fleet-ready. No merge.