Skip to content

fix(sandbox): bind Docker controls and cleanup to run ownership - #191

Merged
ttbombadil merged 1 commit into
mainfrom
fix/docker-lifecycle-ownership
Oct 5, 2026
Merged

ttbombadil merged 1 commit into
mainfrom
fix/docker-lifecycle-ownership

Conversation

@ttbombadil

Copy link
Copy Markdown
Collaborator

Scope

Fix Docker lifecycle ownership on fresh origin/main d9a21de. Implements the approved internal-only decision. Wire schema, API version and operation_error operations remain unchanged.

Changes

  • Pause/unpause admission remains boolean; WS awaits internal completion. State, deadlines, batching and clock markers change only after successful Docker completion.
  • Controls capture run generation, abort identity, originating state and container. Stop/reuse/natural exit/actual Docker deadline invalidate late results. Current failure stops and releases via existing serial diagnostic and stopped status.
  • Natural exit, deadline and Stop join runner-owned cleanup. Nonzero rm is not success: an allowlist-compatible successful daemon listing must confirm absence for --rm auto-removal.
  • Failed cleanup retains its pool slot in quarantine. Retry uses the existing idle-maintenance interval; success restores the same runner. Shutdown retries stopped cleanup owners. Other pre-existing reset failure replacement behavior is retained.

Regression evidence

  • Baseline RED: 11 of 15 runner cases failed; 3 WS cases failed. Review RED: auto-removal, natural-close control resurrection, failed-owner quarantine/recovery/shutdown. Additional RED uses actual DockerManager runtime deadline.
  • New deterministic tests cover nonzero, spawn failures, timeouts, delayed unpause after Stop/reuse, stale failures, confirmation-only status, failed removal retry, quarantine and shutdown.
  • Real Docker test inspects confirmed pause/unpause and checks same-runner reuse after natural --rm exit. Unique synthetic missing-container probe exercises real ProcessExecutor cleanup confirmation.
  • Existing assertions unchanged. Two cleanup mocks now return the real successful ProcessExecution shape instead of undefined. Existing timing tests await control completion before unchanged PAUSED/Stop and time-freeze assertions; the freeze baseline is captured after confirmation, matching the approved requirement.

Verification

All local gates green: unit 2834 passed / 1 existing skip; integration toolchain 14 passed / 1 existing skip; Docker 28 passed; E2E 25 passed, no race events, zero retries; Typecheck, docs check, read-only lint, build and fresh coverage/Sonar quality gate passed. E2E uses unchanged assertions in temporary copies on port 3307 to avoid an unrelated service on port 3000. No no-verify, no real Provider calls, no SSOT/Tutor/Planner/Mastery/Evidence/prompt/content changes. Original untracked local documents and .env.local untouched. macOS Docker Desktop correctness tests are not representative capacity measurements.

@ttbombadil
ttbombadil merged commit 6c284fb into main Oct 5, 2026
5 checks passed
@ttbombadil
ttbombadil deleted the fix/docker-lifecycle-ownership branch October 5, 2026 13:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant