Bound authentication, stabilize residency, and restore retained catalog identities - #18
Conversation
A competing listener reproduced AddrInUse after the original preflight pause. Allocate the server port at bind time and retain a listener on the old address while preserving all lease assertions. Record the immutable production build and functional Git checks separately from incomplete candidate recovery and performance qualification.
Keep the read-only v0 no-haves transfer probe separate from the bound live campaign. Count actual pack-channel bytes, reject malformed and failed responses, retain incomplete receipts, and require strict stock-Git indexing and full graph verification. Record serial transfer scope without claiming clone throughput or cold recovery. All 52 harness tests pass on Python 3.12 and 3.14.
Keep the immutable running fleet and campaign unchanged. Read Darwin rusage v2 with its Mach timebase and Linux proc stat ticks; preserve raw counters and process identities and reject discontinuities. Verify native CPU-clock calibration and delayed child rollup, while explicitly excluding live-tree totals and Git-only attribution. All 59 harness tests pass on Python 3.12 and 3.14.
|
Latest Cellule candidate Linux CI is now closed and passed: https://github.com/crabbuild/canopy/actions/runs/36965371936 . Exact head 63c93b0 pins Cellule 191409685b001a82bd02780def45102b4fc2f164. Log reconciliation confirms 244 top-level Rust tests passed, zero failed, nine ignored; two nested child results are not double-counted. All 84 Python harness tests and all eight exact fresh RustFS compatibility gates passed, as did formatting, all-target Clippy and the debug server build. Native/release qualification, retained-store upgrade/recovery and performance do not follow from these debug CI results. The live fleet and PR pin remain on the separately qualified 0dc04a6 revision. Both PR and push CI at documentation-only head ec81650 also passed all four Rust/harness jobs, including RustFS compatibility. The PR description now records those closed scopes. Closed candidate CI/source/log evidence has nine copied and independently reread files; manifest SHA-256 880d2100bf28801b80aeaa0cd6b38bfd50abe0b263b19189b273cf03531de1c1. The independent log-accounting copy has manifest 7683fcea17f284d593cbfdea6f5975aa5e5a51c653e151c16b41a832e0f475f1. These are local cross-filesystem evidence copies, not off-machine/provider-data backups. The original full campaign has now closed 64 windows and moved to incremental pull. The eight incremental-fetch windows finished at 771 OK / 1,200 scheduled, 418 busy drops and 11 Git errors; all 32 finalized source/copy file pairs were reread. At concurrency 16 / 4/s, the first repetition returned 211/240 OK (18 busy, 11 Git errors), delivering 3.333 successful operations/s with completed-attempt p95/p99 7,245.835/8,568.187 ms; the second returned 240/240 OK, delivering 3.883/s with p95/p99 3,847.302/4,845.643 ms. Variability and failed arrivals remain recorded, with no matched speedup claimed. A separate complete-recovery verifier is prepared outside the repository. It gates on the full terminal audit/ACK inventory, the exact three old owners being absent for at least 32 recorded monotonic seconds, unchanged provider/deployment/budgets, distinct new owners, the same executable and fresh local-state provenance. It invokes full original 10K/100 content checks plus every creation, ref/fresh-object Git push, LFS and complete critical-workflow ACK verifier, retaining a request ledger. Eleven pure guard/accounting tests passed; ledger reconciliation also matched the actual earlier complete pre-load record (10,002 identities, 100 full LFS downloads, 824 Git commands). The real live-campaign invocation refused before reading nonexistent owner/fresh-launch inputs or creating any verifier output. No owner signal or provider request was sent. The real post-terminal/fresh-fleet path and every-ACK remote recovery have not run; this is preparation, not a correctness pass. Its four-file verified qualification copy has manifest febe3e79bc3a3be77274084b79b0d0dd5bce07224ecc6abea13a2e7092eca231. The existing large-transfer workflow requires a dedicated self-hosted Linux runner. The repository runner inventory currently returns zero registered runners, so no unserviceable job was queued. Full schedule/audit and owner-loss recovery continue to be required before reference capacity or any improvement claim; all 638 frozen live input bindings remain unchanged. |
|
Closed verification update (no changes to the live benchmark):
Immutable receipts: release artifact audit |
|
New negative correctness evidence and closed push accounting:
Immutable receipts: CI contradiction audit |
|
Updated this PR to The unchanged-source release diagnostic passed 100 isolated runs and both full-target runs (104 passed, zero failed, nine ignored each). The GitHub archive, all 264 source inputs, retained ELF and every result/log binding were independently verified; 115 evidence files were copied and reread. This does not clear the original release failure, establish a fix, or qualify recovery/performance. The update is documentation-only. No production code, assertions, dependencies, workflows, workload budgets or provider state changed. Fresh PR-head CI is separate. |
|
The complete unchanged baseline is now closed and independently audited: 108 windows / 114,960 arrivals / 59,554 OK / 55,406 failed arrivals. Every positive ACK is preserved: 1,464 creations, 1,490 Git writes, 242 LFS uploads and 19 critical workflows. This is not a performance or capacity pass. After the closed-evidence preflight passed, only the exact three owned gateways were removed. 32.008191 seconds of confirmed owner absence was recorded, with RustFS unchanged. A first fresh-start observer race was preserved and all its nodes drained normally; a separately qualified, bounded same-child metrics wait allowed a new attempt to reach readiness. Full original-corpus and every-ACK read-only verification is running; recovery is not yet proven. Fresh PR-head checks are green, but the earlier residency 503 remains unresolved. The seven-case stage-context diagnostic did not reproduce it: the target passed all seven cases. A different SSH SHA-256 bind test failed |
|
Published cb78793: bounded redacted Git failure evidence, independent schema checks and complete baseline/recovery documentation. All 91 local Python tests, Rust formatting, whitespace checks and 27 local documentation links passed. Fresh PR/push and release RustFS CI are running. Correction to the previous progress update: full post-owner-loss verification terminated at 08:13:33 UTC with a Git v2 clone exit 128; no complete stage or every-ACK recovery pass was recorded. All 3,684 failed-attempt files were copied and hash-checked, with all 651 bound inputs unchanged. The PR description and documentation now reflect this failure. No runtime, provider, frozen checkout, workload, deadline or admission budget changed for this publication. |
|
Separate recovery diagnosis: one isolated v2 clone passed exact commits, fixture digests and fsck. A fixed diagnostic covering the two original 16-entry batches also passed once through the proxy and each direct node: 32 identities per route, the original LFS body, v0/v2 clones and fsck; all 20 traced Git HTTP responses were 200. These fresh-client, already-serving-fleet probes did not reproduce or clear the original failed full-corpus/every-ACK gate and are not performance samples. Closed diagnostics and the SSH pre-fix CI evidence were audited/copied: 384 files, manifest SHA-256 619320c999c82e01c734df7be2a486152534ebd5c581ab866b83cf2458173c56. The SSH injected HTTP-reservation regression failed AddrInUse 3/3 before the fix; ten affected stock-Git runs passed and both full-target runs retained the injected failure. A listener-retention correction is isolated on 9a0ed8e, with the same 3+10+2 release diagnostic queued at https://github.com/crabbuild/canopy/actions/runs/37024939150 and verification at https://github.com/crabbuild/canopy/actions/runs/37024938646. It has not been folded into this PR pending qualification. Neither this correction nor passing probes establish a cause for the original clone failure or residency 503. Full recovery, current-pin performance and reference capacity remain open. |
|
All five checks at cb78793 have now passed. The exact release run 37023329269 was independently audited: 244 top-level Rust passes, zero failed, nine ignored (nested children counted once); 91 Python passes; all eight exact release RustFS gates; all 268 retained source/workflow inputs, six Cellule package pins and the retained ELF digest verified. Linux binary SHA-256 remains 5ff3a4daf2c2012357b4643b896e4f89b8402f7cad9c29679ea20c12becc880d. Nineteen closed files were copied and reread on a second local filesystem. Audit SHA-256: 28a209445c9ac6774eed1fd65bf0e209e3050d1cbae10632a5d81431a3be45a5; preservation manifest: 2f495842920d209684dee026da237e66d1d8b47e3c02470b216afee930bdfd2c. This is current-head Linux correctness, not original/every-ACK recovery, native latest-pin qualification or a speedup; earlier 503 and clone failures remain unresolved. A separate wrapper around the frozen full verifier now retains bounded redacted Git failure evidence, with nine passing checks and preserved before/after evidence. Its actual full-run preflight refused the unchanged 20-GiB floor with zero Git traffic and no verification workspace created. SSH candidate 9a0ed8e is now compiling under the unchanged fixed diagnostic schedule, still outside this PR pending its results. |
|
Full-scope recovery and diagnostic checkpoint (October 2):
The live fleet and RustFS provider remain unchanged on the frozen |
|
All five checks for The closed Linux release run was independently audited: 244 top-level Rust tests passed, zero failed, nine ignored; two nested child results were counted once; 91 Python tests and all eight exact fresh RustFS compatibility gates passed. All 268 source/workflow input hashes, the six locked Cellule package sources, release output and ELF digest match the tested commit. Cargo changes normalize exactly to the prior pin: no unrelated dependency, feature, implementation or runtime-budget changes.
The executable was inspected, not run on the Mac. The live baseline fleet and RustFS provider remain unchanged. This establishes Linux release correctness on a fresh fixture, not native qualification, retained-store upgrade, full-corpus/every-ACK recovery, matched performance or isolated capacity. Both failed full recovery attempts and earlier CI failures remain retained and unresolved. The dependency document's pending status records publication time; this comment records the now-closed qualification for the exact published head. |
|
Updated this PR with commit This update changes only two documentation files. All 91 local Python harness tests passed and A separate test-only diagnostic, excluded from this PR, now reproduces a recovery defect on Cellule No recovery fix, end-to-end recovery pass or performance gain is claimed. The frozen native fleet and RustFS provider were not restarted or upgraded for this publication. |
|
Publication checkpoint: all five checks for the current PR head The recovery-fix experiment remains excluded from this PR: its focused deadline regression passed, but broader debug and release suites failed the existing cross-account cold-admission regression. A separate safety diagnostic is still running; no experimental runtime fix has been promoted. Complete original-corpus/every-ACK recovery and matched performance remain unverified. The frozen native fleet and RustFS provider are unchanged. |
|
Recovery investigation checkpoint: the independently audited safety diagnostic at The audit observed 254 resident-only misses that still had valid active local owners. Draft Cellule PR #44 adds metadata-free active-owner lookup, keeping resident-only lookup and fencing semantics intact. Rust workspace/MSRV and fresh RustFS three-process smoke passed; a separate follower-capacity window failed (59/60 completed, one scheduler-late arrival, matching expected/actual readback for all 12 entities), so the framework candidate remains draft. Separate Canopy candidate |
|
Updated the PR description at unchanged head The separate metadata-free recovery candidate
Candidate code remains excluded from this PR: it depends on draft Cellule #44, whose follower-capacity proof failed 59/60 arrivals (one scheduler-late arrival; all 12 readbacks matched), and has not passed native retained-store or complete original/every-ACK recovery. Temporary admission snapshots at The live three-node fleet, RustFS provider and UI were not rebuilt, restarted or changed. No matched speedup or isolated Linux capacity is claimed. |
|
Authoritative fleet revalidation corrects the earlier live-fleet status: supervisor session closed with exit 1, and PIDs 10143/10617/10794/12878/13313 are absent. The final supervisor record is timestamped 2026-10-02T17:40:07Z. All three node logs report Preserved and reread 1,644 closed fleet/input files (328,057,447 bytes), including all local runtime database/checksum files and 658 historical input bindings, on another local filesystem. Manifest SHA-256 The separate diagnostic-only Next: native qualification of the instrumentation-free candidate, using external build/scratch storage because the primary volume has less than the existing 20-GiB qualification floor. Retained-corpus recovery and every-ACK verification remain mandatory before qualification claims. |
Verification checkpoint — October 2, 18:55 UTCThe published PR head remains New retained-corpus evidence:
The earlier full-recovery failures and terminal fleet failure remain unresolved. Complete original/every-ACK recovery, native fresh-RustFS qualification, deployment upgrade and matched performance/capacity comparisons remain required. Cellule #44 remains a draft; its follower capacity check failed and no speedup is claimed. |
Native candidate checkpoint — October 2, 19:28 UTCThe separate instrumentation-free
These results are not a retained-store upgrade, original/every-ACK recovery, historical-failure resolution, five-GiB qualification, matched speedup or isolated Linux capacity. The candidate remains excluded from this PR. Upstream Cellule main was rechecked and remains |
Summary
Follow-up to merged #17: bound authentication work, stabilize cold-residency admission, restore verified retained catalog identities, preserve HTTP listener reservations through startup, and add reproducible three-node qualification tools and documentation.
Cellule is now pinned to
0f4ca0919b0dfe20a3dcd964d21da03135e42eed, the upstream main revision checked on October 2. Only five direct pins and six lockfile source entries changed from1914096; unrelated dependencies, features and runtime budgets are unchanged. The dependency checkpoint distinguishes the new pin from historical results.The benchmark retains bounded, redacted Git failure details and independently validates them without changing deadlines, retrying failed arrivals or rewriting historical evidence.
Verification
bbd3c54git diff --checkpassed. Production, Cargo lockfile, tests and workflows are unchanged frome8eef77. All five PR/push checks passed, including release correctness. The new release artifact has not yet been independently auditede8eef777497fc7; the newer release artifact has not yet been independently audited7497fc7cb78793, Cellule19140960f4ca095581d5cfailed the disconnected-admission regression with HTTP 503. Subsequent passes and unchanged-source diagnostics do not establish its cause or resolutiond1f9250, excluded from this PR9a5ff42are also excluded0dc04a6. On revalidation, all three previously recorded owners were absent; terminal records show node-lease-bounds errors and unconfirmed drains at 17:40 UTC on October 2. No restart or upgrade was performed. All closed runtime files and 658 bound inputs were preserved; see the checkpoint belowSee the dependency checkpoint and listener qualification.
Complete baseline and failed recovery
The original RustFS corpus passed controlled activation and pre-load remote verification: 10,000 identities, 100 complete LFS bodies, 200 stock-Git v0/v2 clones and both critical fixtures. This is not post-load recovery evidence.
The full campaign audit is
23836f6a437826a58e5157b534a17346b939e9c4e7213168b1c872c19f387f59; failed recovery receipt is54c3e058871c7c57ef65f9b8f32f3f94cdd93151915d757af49cfcce333a3b54; preservation manifest isc9b314798f1071dcb625f95e9cd4da8b9d64618051d8f7d61b100dfe85a601fc.See complete outcomes and recovery evidence and the performance plan.
Native and retained-store checkpoint
The excluded active-owner candidate
d1f9250also passed native Mac release lints, 247 top-level Rust tests (nine ignored), 91 Python tests and eight fresh RustFS gates. Independent audits verified all 270 source/workflow inputs and six Cellule package revisions. The fresh-provider gates ran the retained test executable, not the standalone CLI. Two post-test collector failures remain preserved; separate collectors and audits verified the results without rerunning tests or builds.A write-refusing inspector completed two identical full scans: 11,509 Cells, including all 11,505 required Cells and four extras. It observed 10,993 Idle / 516 Serving, six retired owners, no advertised writers and zero provider write attempts. Catalog visibility is not remote Git/LFS recovery proof.
The inspector's current-code-only predicate rejected Directory's retained schema-1 code. The fetched stored release descriptor was independently BLAKE3-verified and explicitly supports that retained code. Source inspection found the same restriction in the frozen maintenance worker's
Registry::is_current_cellcheck. This is a source-level compatibility defect, not a failed maintenance execution: no maintenance, activation, original-provider restart or upgrade was performed. All 938 negative-attempt/input files were preserved and hash-checked on another local filesystem.The candidate remains excluded: retained recovery is unqualified, and draft Cellule #44's follower-proof capacity check failed. The PR still pins latest upstream main
0f4ca09, rechecked at publication.See the native qualification checkpoint and retained-corpus inspection.
Follow-up recovery prerequisites
The separate maintenance correction
5ab8638reproduced two exact retained-code predicate failures twice before the fix. Changing only the catalog predicate tosupports_cellpassed all three regressions, all 13 deployment tests and release all-target lints. Persisted-Control validation, quotas, leases and deadlines are unchanged. Published-root and stored-byte preservation passed; unknown code/schema/role/namespace, live-owner, wrong-operation and missing-root refusals remain intact. The owned-fixture audit and 556-file cross-filesystem copy are verified. This candidate remains excluded from PR #18.The corrected write-disabled inspector passed six tests and completed two matching full scans of 11,509 Cells, including all 11,505 required Cells and four extras. Independent reconciliation verified that catalog, Control, roots, owners, ETags, release and shard inventory exactly match the preserved negative snapshot; only its two predicate errors disappeared. The descriptor explicitly supports Directory's retained code. 516 Cells remain unsettled, and frozen-maintenance-worker qualification remains false. The original provider was not written, restarted or activated. The 944-file inspection/input copy is hash-verified.
The separate image-transition fixture
049f5d1passed four regressions, all 14 deployment tests and release all-target lints. It uses canonical release preparation to select a new image with the same descriptor, retires the owned old session, refuses the old-image worker and preserves the retained Directory root/data. Its independent audit and 280-file local copy are verified. Synthetic fixture image digests do not qualify a physical maintenance bridge. That executable, supported original-store transition, complete remote recovery and performance remain open.Remaining gates
Resolve retained correctness failures; verify complete original-corpus and every-ACK recovery; qualify the new pin natively and against retained stores; run concurrent faults, higher admission profiles, uniform/skewed active sets, independent operation rates/concurrency, matched comparisons, non-sparse five-GiB transfers and isolated Linux capacity.
No matched speedup, latest-pin recovery or isolated Linux capacity is claimed. Future comparisons must use the same instrumented driver on both binaries; new diagnostics cannot reconstruct missing historical stderr.