From ca3e06559a8a77f2ebb1ca0128c3ea959f882f49 Mon Sep 17 00:00:00 2001 From: Neil <4138956+nwparker@users.noreply.github.com> Date: Sat, 29 Aug 2026 03:42:19 -0700 Subject: [PATCH] test(ssh): prove previous-boot lock recovery live --- config/reliability-gates.jsonc | 1 + .../ssh-relay-upload-cancel.docker.test.ts | 39 +++++++++++++++++++ 2 files changed, 40 insertions(+) diff --git a/config/reliability-gates.jsonc b/config/reliability-gates.jsonc index 38c64abe945..bf1772486ca 100644 --- a/config/reliability-gates.jsonc +++ b/config/reliability-gates.jsonc @@ -1094,6 +1094,7 @@ { "file": "src/main/ssh/ssh-relay-upload-cancel.docker.test.ts", "assertions": [ + "replaces a fresh previous-boot install lock over live ssh2 while preserving promoted payload and leaving no tombstone", "aborts a live SFTP upload after remote bytes arrive without creating the shared lock", "recovers cancellation with bounded safe reclamation and bounded real version GC" ] diff --git a/src/main/ssh/ssh-relay-upload-cancel.docker.test.ts b/src/main/ssh/ssh-relay-upload-cancel.docker.test.ts index e67fb3116c0..b09fba46633 100644 --- a/src/main/ssh/ssh-relay-upload-cancel.docker.test.ts +++ b/src/main/ssh/ssh-relay-upload-cancel.docker.test.ts @@ -152,6 +152,45 @@ describe.skipIf(!RUN_REVIEW_ORACLE)('SSH relay upload cancellation recovery', () stopTarget(fixture) }) + it('recovers a post-promotion install lock from a previous execution-host boot', async () => { + const activeFixture = fixture as TargetFixture + const remoteRelayDir = '/root/.orca-remote/relay-reboot-lock-oracle' + const previousBootId = 'linux:00000000-0000-0000-0000-000000000000:0' + dockerExec( + activeFixture, + [ + `rm -rf ${shellQuote(remoteRelayDir)}`, + `mkdir -p ${shellQuote(`${remoteRelayDir}/.install-lock`)} ${shellQuote(`${remoteRelayDir}/node_modules`)}`, + `printf '%s\\n' promoted > ${shellQuote(`${remoteRelayDir}/relay.js`)}`, + `printf '%s\\n' ${shellQuote(previousBootId)} > ${shellQuote(`${remoteRelayDir}/.install-lock/.boot-id`)}` + ].join(' && ') + ) + const connection = createConnection(activeFixture) + await connection.connect() + try { + const startedAt = Date.now() + await acquireInstallLock(connection, remoteRelayDir, getRemoteHostPlatform('linux-arm64')) + const elapsedMs = Date.now() - startedAt + const state = dockerExec( + activeFixture, + [ + `cat ${shellQuote(`${remoteRelayDir}/.install-lock/.boot-id`)}`, + `cat ${shellQuote(`${remoteRelayDir}/relay.js`)}`, + `find ${shellQuote('/root/.orca-remote')} -maxdepth 1 -name 'relay-reboot-lock-oracle.tombstone.*' -print | wc -l | tr -d ' '` + ].join('; ') + ).split(/\r?\n/u) + + expect(elapsedMs).toBeLessThan(10_000) + expect(state[0]).toMatch(/^linux:[0-9a-f-]+:[0-9]+$/u) + expect(state[0]).not.toBe(previousBootId) + expect(state[1]).toBe('promoted') + expect(state[2]).toBe('0') + } finally { + await connection.disconnect() + dockerExec(activeFixture, `rm -rf ${shellQuote(remoteRelayDir)}`) + } + }, 60_000) + it('aborts a live SFTP upload after remote bytes arrive without creating the shared lock', async () => { const activeFixture = fixture as TargetFixture const localRelayDir = join(process.cwd(), 'out', 'relay', 'linux-arm64')