Skip to content

Track remaining lifecycle extractions from #1754 #1864

Description

@jhgaylor

Finish replacing frozen #1754 with focused, independently reviewable PRs. The small-extraction audit is complete; the remaining changes need working lifecycle paths with their persistence and recovery rules.

Reference: frozen source, audited against main bed264af on 2026-09-10. Parent: #1732; consumer: Review Loop #30.

Already extracted: #1796, #1797, #1818, #1820, #1826, #1827, #1831 and #1840. Reset fencing and its caller-transaction guard belong to #1768. Preserve the earlier #1761#1764 fixes and #1801's same-identity co-tenant rule. Recheck current main before each extraction.

Suggested sequence; replace each checkbox with its implementing PR links:

  • Provider create intent and result. Integrate SandboxOperations with one real provisioning caller. Commit intent before provider I/O; retain physical identity, original owner and capacity through timeout, caller loss and parent deletion. Test confirmed success, definite refusal and uncertain completion. Pair dependency upgrades with their tested consumer.
  • Confirmed deletion and reconciliation. Extend that journal through teardown, reaping and account deletion. Release reservations only with sufficient provider evidence; retain uncertain obligations and their accounting. Test crash/retry and name reuse. GET 404 alone must not release the existing uncertain create 53c090d1-fc9e-46e9-b88a-478a4c984f4a.
  • Committed holder transfer. Extract the relevant SandboxHolders behavior with conditional binding updates, attachment-clock writes and post-commit notifications. Preserve tenant/environment/vault identity, reject stale transfers and account for unused reservations. Test concurrent wake/rebind. Current notifications precede binding updates; the frozen destination-checked callback requires a committed producer.
  • Actor launch ownership and recovery. Integrate claims, launch/startup outcomes and one worker startup/teardown path. Fence stale callbacks by actor incarnation; registry absence must not authorize takeover of unresolved work. Test caller loss, restart, reconnect and delayed callbacks. Add dispatch/watchdog recovery in follow-up PRs with their callers.
  • Durable prompt delivery. Persist and claim a prompt through an actual worker, including admission, images, refusal and wake dispatch. Ship HTTP receipt/idempotency outcomes with that behavior. Test duplicate requests, conflicting keys, crash/replay, cancellation and replaced actors; preserve fix: validate opening input before allocating a sandbox #1840's input validation.
  • Journaled park/resume/checkpoint. Combine SandboxActivity, locked holder decisions and one SandboxTransitions caller at a time. Test attachment racing idle reclamation and uncertain park/resume/checkpoint responses. Keep unresolved operations fenced and record confirmed outcomes accurately.
  • Bounded-execution integration and evidence. Map residual ExecutionGuard/deadline changes to focused replacements for held Journal bounded turn deadlines and remote stop intent #1744Refuse conversation release while remote execution is unresolved #1752. Preserve admission, startup and prompt fences. Prove bounded stopping, cancellation/restart recovery and physical worker deletion on the integrated revision; link that evidence back to Expose typed runtime execution limits for bounded agent turns #1732 and Review Loop fix(render): drop Burrito wrap from fountain_server release #30.

Keep each PR to one complete behavior, with its schema, caller and meaningful regression tests. Split larger items by caller or provider while preserving the invariants above. Use independent PostgreSQL interleavings for lock claims, validate migration rollback, run full precommit and CI, and regenerate revision-specific evidence. Use one CI watcher per PR at a 60-second interval. Review and merge remain with the merge agent.

Track deployment, runtime/provider recovery activation and SDK publication separately. Keep #1754 frozen until every useful residual hunk has a replacement or an explicitly linked deferral. Close this tracker when the checklist and that residual mapping are complete; publishing schemas or carrying forward historical evidence does not satisfy the lifecycle acceptance criteria.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Important planned work; not an emergency.area:conversationsConversation lifecycle, turns, streaming, recovery and orchestration.area:sandboxSandbox providers, machine identity, capabilities and lifecycle.type:trackerCoordinates child deliverables; not a separate implementation task.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions