Repository navigation
fix(desktop): finish regenerate archival before host shutdown - #1447
Merged
Merged
Conversation
A finished turn can leave activeTurns while its branch archive is still pending. Stop event production and await tracked terminal persistence with the host alive, preserving the existing bounded quit behavior when storage is unresponsive. Cover successful, failed and stalled archives through the real outbox and quit handler, plus an isolated Electron regenerate and restart flow.
The summary is outside the quit-time persistence fix and duplicates the shared root path added by other ready maintenance PRs. Drop it so the PR stays scoped and later conflict resolution covers only the E2E plan entries.
muzimu217
reviewed
Oct 7, 2026
muzimu217
left a comment
Contributor
There was a problem hiding this comment.
Verified locally on head fb48a3fb6 (rebased on today's main, which now includes the merged #1435):
- New regression suite
shutdown-regenerate-persistence.test.mjs: 3/3 pass — success, storage-error and unresponsive-archive scenarios, driven through real event persistence, disk outbox and shutdown wiring. - Related existing suites show no regression:
inflight-checkpoint8/8,persistence-outbox10/10,regenerate-branch-archive4/4.
The implementation reads correct to me:
trackWritekeeps aSetof in-flight terminal writes and removes on both settle paths, so nothing leaks;flush()loopsPromise.allSettleduntil the set drains.- The quit ordering makes that drain guaranteed to converge: sidecar event production is disposed before the drain, so no new terminal writes can arrive mid-flush.
flushEventPersistenceracing the existingQUIT_TURN_SETTLE_BUDGET_MS(warn-and-exit on timeout) preserves the bounded-quit contract instead of making quit hang on a stuck archive — the right trade for a shutdown path. - Outbox flush stays after the drain, so the archive that motivated this fix can't be lost between persistence and outbox.
One nit, non-blocking: Summary.md at the repo root is new in this PR. If it's meant as PR documentation it probably shouldn't ship in the repo — worth confirming whether upstream wants a root summary file at all.
Everything I can check locally is green; the remaining call is the maintainer's on the ADR 0060 wording.
…hive-landing # Conflicts: # docs/spec/06-delivery/04-e2e-test-plan.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Quitting just after a regenerated answer finishes can dispose host-core while
session.saveActiveRevisionis still pending. The turn has already leftactiveTurns, and an empty message outbox does not prove the archive finished.On upstream 0.17.0, a held archive RPC reproduces host disposal before archival.
Track terminal event-persistence promises. During quit, stop sidecar event
production and drain those writes, checkpoints and the outbox while host-core
is alive. The terminal-write wait uses the existing two-second quit budget;
unresponsive archival logs a warning and does not prevent exiting. The existing
single-RPC archive operation and stored transcript format remain unchanged.
Validation:
disposed while the archive is held. After the fix, success, storage error and
unresponsive archive scenarios pass using real event persistence, disk outbox
and shutdown wiring. Only Electron and the host RPC boundary are simulated.
standalone PR branch.
the combined candidate and this standalone branch, whose sidecar uses the
unchanged upstream runtime code.
node scripts/e2e-regenerate-quit.mjs: isolated Windows Electron, realsidecar and Rust host, controlled local provider. Regenerate through the
context menu, quit immediately on the terminal event, restart, read both
revisions, and verify there is no disposed-host archival error. All six
assertions passed on this standalone branch as well as the combined candidate.
No user profile or paid model is used. macOS/Linux execution and GitHub CI have
not been run for this local draft.
Related work: #704 optimizes live branch storage, while #947 and #606 address transcript/outbox recovery. This change addresses terminal archival racing with host disposal during quit.
Validation candidate:
fb48a3fb6d0a6941207fec2be09add64b3fcd397; upstream main:72b5e826cb7a9928467091ccf745aa9b225eeb04.