Skip to content

fix(test): keep the default Bun transpiler cache inside its sandbox - #710

Closed
luvs01 wants to merge 12 commits into
devfrom
codex/fix-private-test-transpiler-cache-20261007
Closed

luvs01 wants to merge 12 commits into
devfrom
codex/fix-private-test-transpiler-cache-20261007

Conversation

@luvs01

@luvs01 luvs01 commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Put the automatically selected Bun runtime transpiler cache inside the existing exclusively created test root, with a separately created mode-0700 cache directory on POSIX. Do not adopt, repair, migrate or delete the old fixed host-temporary cache.
  • Keep the selected path in the child environment. Nested sandboxes and fixture children can reuse their owning environment's cache despite changing HOME/USERPROFILE; nested cleanup leaves the parent's cache intact, and the owner removes it with its root.
  • Preserve every explicit BUN_RUNTIME_TRANSPILER_CACHE_PATH value, including "" and "0". Explicit paths remain the operator's protected-path responsibility; this patch does not validate arbitrary overrides or sandbox same-user code.
  • Include the subsequent test-harness repairs exposed during validation: retry-aware fixture removal, routing-history index closure before auth-fixture teardown, response-body diagnostics, bounded synchronous children, graph warm-ups for timed subprocess tests, and serial execution of ci-gui-typecheck-gate.
  • Move management-auth helper functions into tests/helpers/management-auth-fixture.ts to keep the test file within the existing file-size limit.
  • The current PR changes 23 files: scripts/test.ts, structure/ops/cross-platform-ci.md, and 21 test/helper files. Product runtime source, credentials, dependencies and release workflows are unchanged.

Draft / operational hold: independent test environments and CI batches no longer automatically reuse one persistent cache. Current-head hosted Linux and Windows checks have passed. Independent security review and acceptance of the isolation/cold-start trade-off remain required. Passing CI does not withdraw those holds.

Verification

Current published checkpoint — 2026-10-08 (4b9952e7)

  • Published HEAD: 4b9952e72b8b3912f715c90bb835268b4b11e014; published tree: 442793437e5f5276b7d05410580e58ba4b4b247c.
  • Current PR inventory against dev e6c6e13a22e465812f509a423990e9f09e32b1d0: 23 files, 425 additions and 162 deletions.
  • This merge integrates that dev commit into the previous PR head 2d948e1b. The sole conflict in tests/claude-integration/claude-picker-startup.test.ts was resolved by preserving the exact dev version, including retry cleanup, ACL draining, attempt-all cleanup, environment restoration and its three regression tests. That file is now identical to dev and is no longer part of the PR diff.
  • Cross-platform CI 37855863476 completed success: 23 successful jobs, nine skipped jobs, no failed or cancelled jobs. All four Linux test shards and all nine Windows test shards passed, including the final ci aggregate.
  • The actual test checkout was merge ref 2e47636c22ee93819c9498725a99b5ab5ad8ef04, combining dev e6c6e13a22e465812f509a423990e9f09e32b1d0 with this PR HEAD. Its tree is 442793437e5f5276b7d05410580e58ba4b4b247c, exactly matching the published HEAD's source tree. The log records repository-pinned Bun 1.4.0 (34cbb9a40). This establishes coverage for that source tree and integration, not a later dev state.
  • Root TypeScript, GUI tests, privacy scan under gates, generated skill-surface check, release-helper syntax check, CLI help, structure, storage/API usage, Docker and Linux/Windows keyring checks passed.
  • React Doctor 37855863428 and CodeQL also passed for this head. These checks do not replace the independent security and operational acceptance below.
  • Skipped jobs: macOS control, macOS test matrix, macOS widget/bundle, setup-action matrix, remote-helper matrix, docs-site build, standalone privacy gate, npm-global matrix and desktop shell. GUI lint/build steps were also skipped inside gates. The privacy scan itself passed within gates.
  • Outside Cross-platform CI, the duplicate PR-target check was cancelled. The subsequent status-triggered PR-target run succeeded; the original cancellation remains recorded.
  • This description refresh records the published merge and existing hosted evidence; it runs no additional local tests. Earlier local counts remain bound to their recorded heads and runtimes. Current-head full-local-suite and import-connected validation are not established by this refresh.
  • Earlier failed and cancelled runs remain historical failures and incomplete coverage. They are not relabeled as passes. The subsequent changes address fixture cleanup/diagnostics, synchronous child bounds, batch isolation and warm-up coverage; passing CI does not independently establish every proposed root-cause explanation.
  • The original cache-reuse review thread is resolved. The later verification-scope finding concerns the expanded changes and current-head Windows evidence recorded here; its reviewer resolution remains pending. The displayed CodeRabbit review covers 11592cf57, not this expanded head.
  • Draft and the independent security/native cold-start acceptance hold remain in place. No merge into dev, deployment, installed-environment change or security-finding closure is claimed.

Historical checkpoint — 2026-10-08 (2d948e1b)

Before the dev integration, HEAD 2d948e1bfaa80e4f3b1f62b34980ddcd243fd48d had tree 8ce459db80c5eb30df1eda328db96bf10f8d03e6 and a 24-file diff (+428/-164). Cross-platform CI 37737749299 passed 23 jobs with nine skipped, including four Linux and nine Windows shards. Its checkout was merge ref 835c450153146aa619ce783860960dca5261ebb4, tree b14c4d04533db93782091e091ff440b56049f24b, combining dev bf9ecf3d79c7b1b6436e2922f52d421ab550b744 with that head. React Doctor 37737749306 also passed. Those results remain historical integration evidence, separate from the current checkpoint above.

Historical publication

Original publication base: 9099e4bf99166677db0f5fa6df81fe30208dd795 (rechecked at that historical publication).
Original publication head (historical validation below): 66cd2855d9fc7a7a6c45c4e2139d4894388f5c93.
Exact checked and read-back tree: 251fa37e3e6fd194ef93328c2e449f8b896891ec.
The original publication changed three files, with 142 insertions and 12 deletions. Auxiliary source-transfer workflows and patch data are absent from this PR tree.

Historical checkpoint — 2026-10-07 (11592cf57)

Recorded head: 11592cf57f11b2618a9ca266b5224edf376e18bf; tree fe026adea028c929e41b1015cd34af8605e2c3f2; parent 66cd2855d9fc7a7a6c45c4e2139d4894388f5c93. That checkpoint changed three files, with 166 insertions and 12 deletions. The follow-up strengthens the existing cross-home cache-reuse regression with cache-entry set and sentinel-mtime checks.

The author's Windows/Bun 1.4.2 report records 70/70 runner-file tests and typecheck/privacy/structure checks passing. That is useful additional evidence, not a repository-pinned Bun 1.4.0 full-suite pass. The original cache-reuse review thread is resolved.

Historical 11592cf57 Cross-platform CI failed. Windows shard 2/9 reports native first-party ON pins the committed mode on a stale live config expecting HTTP 200 but receiving 500, followed by an EPERM cleanup failure. The response body was not logged, so the underlying 500 cause is unclassified. The same case passed at the unchanged baseline and the preceding candidate, which does not establish either a deterministic regression or a transient flake. Keep the assertion failure and cleanup error separate. No additional retry is counted as validation.

This historical checkpoint had failed CI and incomplete coverage. The later published-head integration result is recorded above. Independent security and operational acceptance remain pending. The Linux original-head results below remain historical and are not relabeled as final-head validation.

Linux / repository-pinned Bun 1.4.0 (original publication head)

  • New-regression red control, using the original production runner: 3 pass / 6 fail, 61 existing tests filtered. The override/disable controls already passed; the six isolation/ownership cases exposed the previous behavior.
  • New-regression green run: 9 pass / 0 fail, 41 assertions. Covers private default ownership/mode, independent and nested lifetimes, explicit/disabled cache choices, pre-existing legacy directories and symlinks left unchanged, and real Bun children with different homes using the selected cache. The benign cacheable fixture loads no application code or credentials.
  • Broader six-file execution: 124 pass / 3 platform skips / 1 fail, 1,120 assertions. This run is NOT green. Its sole failure is the unchanged bun test argv > the wrapper passes parallel execution through to bun without leaving TEMP roots smoke. The nested wrapper first tries to install missing GUI dependencies and fails because the named bun executable is absent from that subprocess PATH. A separate actual-wrapper control with the original scripts/test.ts reproduced the same ENOENT. Supplying the exact Bun directory then reached the frozen GUI dependency install, which could not finish in this offline executor and was stopped at the control's ten-second limit. The runner was restored after baseline comparisons; no fixture, deadline or assertion was weakened. This is an environment diagnosis, not a passing full baseline/candidate suite comparison.
  • Root TypeScript, privacy scan, structure SSOT and staged whitespace checks all passed.

Additional native Linux access-control probe used two distinct OS accounts with a shared mode-1777 temporary parent. A pre-existing legacy cache belonged to one account; the other invoked the actual patched environment creator. The selected cache belonged to the invoking account with mode 0700, and the other account's read and write attempts both returned EACCES. The legacy sentinel remained unchanged, and owner cleanup removed the new cache. This checks the repaired filesystem boundary; it does NOT rerun the supplied forged-cache substitution proof or access real credentials.

Commands executed in disposable homes with the repository Bun:

bun test --isolate tests/ci-workflows/test-runner.test.ts -t 'test runner transpiler cache isolation'
bun test --isolate tests/ci-workflows/test-runner.test.ts tests/ci-workflows/test-sandbox-cleanup.test.ts tests/ci-workflows/test-home-guard.test.ts tests/test-layout.test.ts tests/test-layout-tooling.test.ts tests/ci-workflows/file-size-ratchet.test.ts
bun node_modules/typescript/bin/tsc --noEmit
bun scripts/privacy-scan.ts
bun scripts/structure-ssot.ts
git diff --cached --check

The focused resource exception was used because the executor has no external dependency-install access. The six-file run's failure is retained above, rather than silently excluded or counted as passing. Root dependencies/runtime were obtained from a prior isolated source artifact; relevant pinned versions were checked against this source. GUI dependencies were not fabricated or bypassed.

Publication run 37561725134 applied the readable full-index patch only after verifying its SHA-256, original index preimages, exact three-file scope and complete resulting tree. Connector readback confirms the commit's parent and tree. No patched application code or dependency installation ran with the publication write token. This is transport verification, not another test suite.

Remaining coverage

The published head's hosted integration run passed all selected Linux and Windows test shards using repository-pinned Bun 1.4.0. The earlier Windows/Bun 1.4.2 runner-file report and original Linux red/green results remain separate historical evidence.

Native macOS behavior, Windows ACL inheritance and the skipped platform/package lanes remain unverified by this run. Current-head full local and import-connected validation is not established by this description refresh. The supplied cross-user cache-substitution payload was not re-executed by these follow-ups.

Some subprocess regressions now warm their module graphs during setup before their timed assertions. Successful Windows jobs provide current integration evidence; independent acceptance of the private-cache cold-start trade-off remains required. The product-side Windows ACL inspection stall was made more diagnosable, not fixed by a runtime change in this PR.

Keep Draft pending independent security review, operational/native cold-start acceptance, current-dev readiness checks and disposition of the remaining review thread. Skipped and older-head results are not current executed coverage. This PR does not modify an installed environment or the old shared cache, and does not close the Security Cloud finding.

Checklist

  • Current 23-file scope includes the cache change and subsequent test-harness repairs.
  • Owning documentation describes private cache lifetime, overrides and lost cross-batch reuse.
  • Original cache behavior has recorded red/green regression evidence.
  • Published-head associated CI passes, including all selected Linux and Windows shards; checkout and coverage limits are recorded above.
  • Independent security review and native cold-start compatibility are accepted.

Review readiness checklist

  • Required final validation and its scope are accepted.
  • Current dev ancestry is rechecked before readiness.
  • All correct review findings are resolved.
  • Ready for review. Keep draft pending the remaining gates.

Devin Review

Summary by CodeRabbit

  • Improvements
    • Isolated test runs now use a private transpiler cache by default, keeping cache data separate between environments and CI batches.
    • Nested test environments reuse their parent’s cache, while separately created environments keep independent caches.
    • Explicit cache settings remain respected, including values that disable caching. Existing shared cache directories and symlinks are left untouched, and cleanup is limited to caches owned by the corresponding test environment.

Preserve nested-child reuse and explicit overrides, but do not adopt the
fixed shared temporary cache. Independent environments start cold.

Linux/Bun 1.4.0: nine new regressions pass; cross-user access is denied.
Broader run: 124 pass, 3 skips, 1 environment-dependent wrapper failure.
Typecheck, privacy, structure and whitespace checks pass. Native cold-start
coverage and independent review remain required; keep draft.

Fork-only candidate; no merge, release or finding closure.
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: luvs01/opencodex/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 550e6597-9af6-4282-b3a0-9c5f9de10623
📥 Commits

Reviewing files that changed from the base of the PR and between 9099e4b and 11592cf.

📒 Files selected for processing (3)
  • scripts/test.ts
  • structure/ops/cross-platform-ci.md
  • tests/ci-workflows/test-runner.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The isolated test environment now defaults Bun’s transpiler cache to a private directory under the test root. Explicit cache values remain unchanged. Added tests cover cache permissions, ownership, cleanup, overrides, pre-existing paths, and reuse.

Changes

Isolated transpiler cache

Layer / File(s) Summary
Resolve and document cache ownership
scripts/test.ts, structure/ops/cross-platform-ci.md
The environment creates the default cache under the isolated test root with mode 0700 and preserves explicit values, including empty strings and "0". The documentation describes inheritance, cleanup, separate caches, and handling of the legacy host-TEMP cache.
Validate cache isolation and reuse
tests/ci-workflows/test-runner.test.ts
Tests verify cache permissions, independent and nested sandbox behavior, explicit and disabling overrides, preservation of pre-existing directories and symlinks, and cache reuse by Bun children with different home directories.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Suggested reviewers: lidge-jun

Merge Risk: ⚪ Minimal · up to 11592

The private default cache and explicit overrides have no identified merge-blocking defect. Complete the planned platform and CI checks before accepting the draft.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: keeping the default Bun transpiler cache inside the isolated test sandbox while preserving explicit cache paths.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

✅ Deterministic PR hygiene checks passed.

devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions github-actions Bot added the bug Something isn't working label Oct 7, 2026
Co-Authored-By: Epinephrine <luvs01@hanmail.net>
@devin-ai-integration

Copy link
Copy Markdown

Fair point — the .pile existence check was satisfied by the first child alone. Fixed in 11592cf57: the first child's cache entries are now sealed at a sentinel mtime, and the second home's run must leave an identical entry set with every seal untouched (a miss on the identical input would add or rewrite an entry). It also asserts no .pile exists anywhere else in the sandbox, so the second transpile provably came from the selected private cache rather than any other location. Verified on Bun 1.4.2/Windows: the test and all 70 tests in the file pass.

@devin-ai-integration

Copy link
Copy Markdown

Review-triage summary (Devin session):

Unresolved findings collected: 1 — Devin Review on tests/ci-workflows/test-runner.test.ts:509. CodeRabbit skipped the draft; no chatgpt-codex-connector findings; hygiene bot passed.

Fixed: 11592cf57 — the cross-home child-process test now proves a real cache hit: the first child's .pile entries are sealed at a sentinel mtime, and the second home's run must leave the same set with untouched seals plus no .pile anywhere else in the sandbox. Previously the existence check passed even if the second child ignored the cache.

Dismissed: none.

Checks (Windows, Bun 1.4.2): bun run typecheck ✅, bun run privacy:scan ✅, bun run structure:check ✅, bun test tests/ci-workflows/test-runner.test.ts — 70/70 pass (the wrapper smoke test that failed in the author's offline executor passes here; GUI deps are installed).

Written by Devin

@devin-ai-integration

Copy link
Copy Markdown

Done. One genuine finding on PR #710, fixed and pushed.

What I found: Only one unresolved thread existed — Devin Review on test-runner.test.ts:509. CodeRabbit skipped the draft, the Codex connector left no comments, and the hygiene bot passed.

The finding was real: the "Bun children with different homes reuse only the selected private cache" test asserted a .pile exists after two child runs, but the first child alone could satisfy it — nothing proved the second home actually hit the cache.

Fix pushed as 11592cf57: after the first child runs, its .pile entries are sealed at a sentinel mtime (2001-01-01); the second home's run must produce an identical entry set with every seal untouched — a miss on the identical input would have to add or rewrite an entry. It also asserts no .pile exists anywhere else in the sandbox, so the second transpile provably came from the selected private cache. Thread resolved.

Checks (Windows, Bun 1.4.2): bun run typecheck ✅, bun run privacy:scan ✅, bun run structure:check ✅, and the full tests/ci-workflows/test-runner.test.ts — 70/70 pass, including the wrapper smoke that failed in the author's offline executor. CI is queued on the new head (3 passed, 8 pending, 0 failed).

Summary comment posted: #710

@devin-ai-integration

Copy link
Copy Markdown

Failure diagnosis for the exact-head Windows shard 2/9 run (job):

Mechanism. PUT /api/native-integrations/claude-desktop (enable) → applyDesktopFirstParty → ensureLocalInterceptCa → assertLocalCaWindowsAcl → Bun.spawnSync of the trusted PowerShell ACL inspector (src/claude/intercept/local-ca-windows.ts:31). That child stalled past the ACL budget on the hosted runner, so applyDesktopFirstParty returned ca_unavailable → the route answered 500 (native-integration-routes.ts postCommitRefusal(500, "claude-desktop", "ca_unavailable", …)). The orphaned PowerShell child then kept a handle inside the test root, which is the EPERM in removeTestTempTree. Assertion failure and cleanup error are the same event, not two failures.

Not a regression from this PR. The merge-base diff touches only scripts/test.ts, tests/ci-workflows/test-runner.test.ts and structure/ops/cross-platform-ci.md — src/claude/**, tests/claude-integration/** and scripts/test-temp.ts are byte-identical to dev, so the executed path cannot differ. The failing test also doesn't consume the change: it builds its root with mkdtempSync, not createIsolatedTestEnvironment, and the stalled child is PowerShell, which never reads BUN_RUNTIME_TRANSPILER_CACHE_PATH.

Independent reproduction. On a Windows box (Bun 1.4.2) the same file exhibits the identical signature — ca_unavailable returns, killed N dangling process(es), and [opencodex] ACL hardening timed out (ETIMEDOUT) — transient icacls stall … continuing without NTFS ACL harden — in the same unchanged code. This is the hosted-Windows icacls/PowerShell stall the code already documents and tolerates elsewhere; the route test just had no tolerance path for it this run.

Classification: transient flake on the Windows runner, not a deterministic regression. I re-ran the failed jobs at head 11592cf57; if the shard passes, the "failure diagnosis" and "successful current-head required CI" hold criteria are both satisfied. The draft hold still stands on its remaining condition (independent security/native cold-start review), which is a reviewer decision, not a code change.

Written by Devin

A 500 from these routes was previously reported as a bare
"Expected: 200 / Received: 500", leaving the underlying reason
unclassified (the windows 2/9 failure on 11592cf needed a manual
diagnosis to identify ca_unavailable). Status assertions now carry
the response body via an expectStatus helper, so a hosted-runner
flake classifies itself in CI output.

Co-Authored-By: Epinephrine <luvs01@hanmail.net>
@devin-ai-integration

Copy link
Copy Markdown

Follow-up to the diagnosis above: pushed 3f274db — test(claude-desktop): attach response bodies to status assertions.

This closes the diagnosability gap the shard failure exposed ("the response body was not logged, so the underlying 500 cause is unclassified"): every status assertion in claude-desktop-first-party.test.ts now goes through an expectStatus helper that prints the response body on failure. Verified on Windows — the same environmental stall now reports {"code":"native_integration_failed","reason":"write_failed","message":"The local intercept certificate could not be created (…ca.pem)"} instead of a bare 500, so any recurrence classifies itself in the job log.

Note this is observability, not a fix for the stall itself: the route correctly fails closed when the CA's ACL can't be verified (you can't ship an unverified private-key ACL), and mocking the ACL runner via setLocalCaWindowsAclRunnerForTests would just trade the real end-to-end coverage this file deliberately exercises. If the hosted-runner icacls/PowerShell stall keeps recurring at a meaningful rate, the production-side options (retry once inside the ACL budget, or a shared warm inspector child) belong in a separate PR — they change product behavior, not test code.

The windows 1/9 rerun failed on EBUSY in claude-picker-startup's
afterEach: a still-exiting spawned child held the test root while
bare rmSync had no tolerance. Eleven fixtures that spawn real
children but removed roots with raw rmSync now use the shared
removeTreeWithRetry helper (EPERM/EBUSY/ENOTEMPTY retry, plus the
protected-tree refusal every caller shares). File-level rmSync calls
inside those files are unchanged.

Co-Authored-By: Epinephrine <luvs01@hanmail.net>
@devin-ai-integration

Copy link
Copy Markdown

The new run surfaced the sibling failure mode — windows 1/9, EBUSY in claude-picker-startup.test.ts's afterEach: a still-exiting spawned child held the test root and that file's bare rmSync had zero tolerance. Fixed the class rather than the instance in eadccf7: all eleven fixtures that spawn real children but removed roots with raw rmSync now go through removeTreeWithRetry (retries EPERM/EBUSY/ENOTEMPTY, keeps the protected-tree refusal), matching the helper's "one removal path the whole suite shares" policy. File-level rmSync calls (lock files, single-file removals) untouched. Verified: typecheck/privacy/structure gates pass, 51 focused tests green on Windows.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 new potential issue.

Devin Review

try { child.kill("SIGKILL"); } catch { /* already gone */ }
}
for (const dir of dirs.splice(0)) rmSync(dir, { recursive: true, force: true });
for (const dir of dirs.splice(0)) removeTreeWithRetry(dir);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Verification scope omits the cleanup changes

The PR description still says three files change, but twelve test files now replace cleanup calls. Its recorded validation predates those changes. Update the scope and report current-head Windows results.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated the description against unchanged published HEAD 2d948e1bfaa80e4f3b1f62b34980ddcd243fd48d.

The current scope is 24 files (+428/-164), including the cleanup changes, routing-history handle closure, subprocess diagnostics/bounds, warm-ups, serial-lane adjustment and helper extraction. The original three-file publication and 11592cf57 results are now explicitly historical.

Cross-platform CI 37737749299 completed 23 successful jobs / 9 skipped / 0 failed or cancelled, including all four Linux and all nine Windows shards. Its actual checkout was merge ref 835c450153146aa619ce783860960dca5261ebb4 (dev bf9ecf3d plus this head), using Bun 1.4.0. The description records that integration boundary and all skipped coverage rather than attributing it to the standalone published tree.

This is a description/evidence correction; no code or new local tests were run. Draft remains in place for independent security/native cold-start acceptance and the remaining readiness checks. Leaving this thread open for reviewer verification.

@devin-ai-integration

Copy link
Copy Markdown

On it — collecting all unresolved review threads on PR #710 (Devin Review, CodeRabbit, Codex connector), then triaging and fixing the genuine ones on the head branch.

The private per-sandbox transpiler cache means the first --eval child in a
batch pays its cold module-graph load inside its own 3000ms spawnSync bound;
windows 3/9 killed it with ETIMEDOUT. Register the file's union eval script
with warmModuleGraph so the cold load happens in setup, and switch the
file:// hrefs to absolute paths so the warm-up's import scan can see them.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
test 1/4 batch 4 pinned for the full 120s shard deadline in run
37730984813: the file's spawnSync children carry no timeout, so a wedged
bun child froze the test inside a synchronous wait the per-test timeout
cannot interrupt. The 60s test timeout killed one dangling process and
the wait still never settled. Every spawnSync in the file now runs
under INTERNAL_DEADLINE_MS, with SIGKILL for the bun children per the
cli-connect-readiness shape, and cold-spawn-warmup records the unwarmed
disposition the deadline oracle requires: the children run a script
importing only node builtins, so an import scan has nothing to warm.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…h test home

windows 8/9 run 37730984813 job 113160397742: the afterEach removal of
ocx-management-auth-* lost the whole 15s retry budget to EPERM on the
root rmdir. A routed request opens the process-wide request-history
SQLite index under OPENCODEX_HOME and nothing in this file closes it,
so the home's files leave delete-pending handles the same process
cannot release while Bun.sleepSync blocks the loop. Same signature and
same fix as 1c27b3f: call closeRequestHistoryIndex between the
config-dir flight drain and the reaps barrier, matching
settleServerAuthFixture's drain order.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
test 2/4 run 37734155690 job 113170258422: the file-size ratchet reported
NEW_OVERSIZED on tests/server/server-management-auth.test.ts after
a81c8bc's five lines took it from 1999 to 2004. Move remoteConfig,
hubConfig, startEphemeralHubServer, and websocketHandshakeOpens unchanged
into tests/helpers/management-auth-fixture.ts; none of them read the
file-scoped fixture state, so behavior is identical and the file is back
under the 2000-line threshold at 1931.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
… eval children

test 1/4 batch 4 timed out three runs in a row inside the 12-file batch
while every case passed alone (37730984813, 37732846946, 37735238354),
the same multi-file process-state class as the other serial-lane
entries; move ci-gui-typecheck-gate to SERIAL_FULL_SUITE_FILES.

windows 3/9 killed both real-Bun-transport children at their 10s
deadline on a cold catalog-remote graph load. Register the graph with
warmModuleGraph so the cold load happens in setup, pass
BUN_RUNTIME_TRANSPILER_CACHE_PATH into the child env so the warm
transfers, and use an absolute path the import scan can see.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@luvs01

luvs01 commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

CI flake classification across runs on this head (independent analysis; a concurrent session is pushing fixes and may supersede some entries):

Class A — Windows ACL spawn stall: Bun.spawnSync(PowerShell icacls inspector) inside assertLocalCaWindowsAcl stalls on hosted runners → ca_unavailable → HTTP 500 in handleClaudeDesktopToggle, plus EPERM on fixture removal from the orphaned child. Mitigation landed: expectStatus in tests/claude-integration/claude-desktop-first-party.test.ts (commit 3f274db) so any recurrence self-classifies with code/reason/message. Product-side stall (retry / warm inspector pool) is out of scope here — the route correctly fails closed.

Class B — teardown-vs-child-exit race: bare rmSync on fixture roots racing still-exiting spawned children → EBUSY/EPERM. Mitigation landed: eadccf7 routes all process-spawning fixture removals through removeTreeWithRetry (EPERM/EBUSY/ENOTEMPTY retries + protected-tree refusal). Follow-on a81c8bcb0 fixes the real handle holder (routing-history SQLite index left open).

Class C — shared 120s batch watchdog: test 1/4 batch 4 pinned twice (runs 37730984813, 37735238354); the attribution sweep passes all 12 files solo — cumulative multi-file cost, plausibly the private per-sandbox transpiler cache's cold start that this PR intentionally trades for isolation (cf. 9443c416f, which added the shared cache to fix this same class). 79ea0f37f bounds ci-gui-typecheck-gate's spawnSync children under INTERNAL_DEADLINE_MS; c94eaff45 warms the readiness eval graph. Batch 4 still timed out at 3390e7dbf, so the residual is cumulative cost across the batch rather than one wedged child — repacking spawn-heavy files or accepting per the PR's cold-start hold is a maintainer call.

Class D — runner-image behavior differences: windows 3/9 in run 37735238354 (job 113173494885): remote catalog acquisition > real Bun transport respects the catalog guard for NO_PROXY=... failed twice at ~10–12s each on the windows-2025-vs2026 image — a real-transport test sensitive to the runner image, not touched by this PR (needs its own triage).

Net: A and B are fixed or made self-describing; C is the PR's accepted cold-start trade-off hitting a marginal batch; D is orthogonal.

Written by Devin

devin-ai-integration Bot and others added 3 commits October 8, 2026 06:24
test 1/4 batch 6 pinned for the full 120s shard deadline in run
37736425700: the file's spawnSync children carry no timeout, so a wedged
bun child froze the test inside a synchronous wait the per-test timeout
cannot interrupt. The 60s dangling-process sweep killed one child and
the wait still never settled. Both spawnSync sites now run under
INTERNAL_DEADLINE_MS, with SIGKILL for the bun child per the
cli-connect-readiness shape, and cold-spawn-warmup records the unwarmed
disposition the deadline oracle requires: the children run a script
importing only node builtins, or a bash -c fragment, so an import scan
has nothing to warm.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…hildren

The private per-sandbox transpiler cache means the first spawned child in a
batch pays its cold module-graph load inside its own bound; windows 9/9 run
37736425700 killed the ready --wait child at its 10s deadline before it ever
reached /healthz (healthzHits 0 vs 1). Register src/cli/index.ts's entry
graph with warmModuleGraph so the cold load happens in setup, matching the
cli-models precedent.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Integrate dev e6c6e13 into the
published PR head 2d948e1.

Resolve the sole conflict with the exact upstream picker-startup file.
It already contains removeTreeWithRetry and adds ACL draining,
attempt-all cleanup, environment restoration, and three regressions.
Preserve all other PR changes and the upstream pinned test runner.

Local integration only; no remote publication or readiness claim.

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: JUN <jun@lidgeai.com>
@luvs01

luvs01 commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

No description provided.

@luvs01

luvs01 commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

No description provided.

@luvs01 luvs01 closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant