Skip to content

test(ladder): the P/M matrix — ordinary + control walked step by step, two modules, every step checked (stacked on #6124) - #6139

Merged
rbuergi merged 2 commits into
feat/module-reloadfrom
test/ladder-matrix
Oct 5, 2026
Merged

rbuergi merged 2 commits into
feat/module-reloadfrom
test/ladder-matrix

Conversation

@rbuergi

@rbuergi rbuergi commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The module update ladder as an ordered P/M matrix (stacked on #6124)

Rule table: Doc/Architecture/ModuleUpdateLadder (lands in the companion PR from test/module-update-ladder). This PR holds the rows whose behaviour exists only in #6124: A1–A6, B1/B3 in sequence, E1.

ModuleUpdateLadderMatrixTest / ModuleUpdateLadderControlMatrixTest

Each row = (running platform, published module set) → expected loaded version per module, activation path (live / restart / none / declined), restarts this step, and whether a platform roll happened. One ordered scenario per instance. Two modules with different floors: M_a swaps live, M_b declares boot-time infrastructure.

Step Platform Published Ordinary expects Control expects
0 P1 M_a 1.0 / M_b 1.0 both 1.0 same
1 P2 (roll) unchanged both keep serving, 0 restarts same
2 P2 M_a 1.1 (floor P2) M_a 1.1 live same
3 P2 M_a 1.2 (floor P1) M_a 1.2 live same
4 P2 M_b 1.1 (floor P2) M_b 1.1, exactly 1 restart same
5 P2 / P3 on control M_a 1.3 (floor P3), M_b 1.2 M_a declined (no download, 1.2 keeps serving), M_b 1.2 by one restart rolls P3; both land in ONE restart
6 P3 (roll) / P3 unchanged M_a 1.3 lands live, no other step nothing to do

Every step also asserts the module lane never patched the image.

Real: RegistryUpdateReconciler.ReconcileNow, PluginBundleClient + its floor decision, ModuleLandingService, the module-set proposal, ModuleReload request + executor, SelfUpdateHostedService with a recording updater. Seams: the running platform (RunningPlatformVersionOverride, transient so a roll is visible to the next decision), a roll's new process = the production boot computation over the same volume, the live swap through IModuleLiveActivation (#6123 provides the real loader), the restarted pod's report through a ModuleReloadAgent started after the restart stamp.

Premise of row E1 on every step: no seal for the running identity, every module partition sync-owned with its sync at OLD content.

Results (local, Release, -warnaserror clean)

  • ModuleUpdateLadder* + PackagesAutoUpdate* + ModuleReload*: 20 passed, 1 skipped (below), 0 failed.

Negative controls

A row that FAILS today — row A4's naming half

ModuleUpdateLadderDeclineIsNamedTest.AModuleDeclinedForItsFloor_IsNamedOnTheInstallRecord is skipped with the defect named. Un-skipped, it fails: declined, but no node names it — the install record's heldUpdate is ''. A module declined for its floor on the unattended auto-update lane is logged at Information by PluginBundleClient.AdoptModuleOutcome and written nowhere. heldUpdate is only written by the content lane, which is idle when the package's content identity did not move. The explicit reload path names it (ModuleReloadByRestartTest.ANewerVersionAboveTheFloor_…). Un-skip with the fix.

Not established

Merge

Auto-merge deliberately NOT armed: the base feat/module-reload is an unprotected feature branch, where arming merges at once. This retargets to main when #6124 merges.

Pairs-with: none — tests only
Implementers: none — no interface member added
Mirror-sync: none — no catalog key

🤖 Generated with Claude Code

…nary + control), two modules, every step checked

ModuleUpdateLadderMatrixTest walks P1+M1 → P2+M1 → P2+M2 → P2+M3 → P3+M3 on one
instance as one ordered scenario: each row is (running platform, published module
set) with the loaded version of every module, its activation path (live / restart /
none / declined) and whether a platform roll happened. Two modules with different
floors: M_a swaps live, M_b declares boot-time infrastructure (exactly one restart).
Real registry reconcile, bundle client, floor decision, landing, module-set proposal,
ModuleReload request + executor and the self-update restart path; a platform roll is
the running-platform seam plus the production boot computation over the same volume.
Premise of row E1 throughout: no seal, sync-owned partitions at OLD content.

The ordinary instance rolls P3 one step after control; control takes M_a 1.3
(floor P3) first. Negative control in the suite: M_a pinned → the walk fails at
step 2 and nowhere earlier. By-hand negative control run: re-inserting the retired
#4355 gate 1b (a sync-owned module waits for the seal its content does) fails both
the ordinary and the control walk at step 2.

ModuleUpdateLadderDeclineIsNamedTest pins row A4's naming half, which FAILS today:
a module declined for its floor on the auto-update lane is named on no node (only
an Information log line). Skipped with that reason; run un-skipped it fails with
"declined, but no node names it — the install record's heldUpdate is ''".

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@meshweaver-cloud

Copy link
Copy Markdown
Contributor

Auto-merge was not armed. This pull request targets feat/module-reload, not the default branch main — a non-default base has no branch protection and therefore no required contexts, so arming it would merge it immediately, before its own CI runs. Merge it by hand when you are ready, or retarget it at main to have it armed normally.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Test Results

    2 files   -    19      2 suites   - 19   8m 20s ⏱️ - 31m 19s
2 313 tests  - 7 183  2 312 ✅  - 6 991  1 💤  - 192  0 ❌ ±0 
2 317 runs   - 7 189  2 316 ✅  - 6 997  1 💤  - 192  0 ❌ ±0 

Results for commit a8615ed. ± Comparison against base commit cae6c96.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 4)

0 files   -     3  0 suites   - 3   0s ⏱️ - 11m 42s
0 tests  - 2 502  0 ✅  - 2 502  0 💤 ±0  0 ❌ ±0 
0 runs   - 2 506  0 ✅  - 2 506  0 💤 ±0  0 ❌ ±0 

Results for commit a8615ed. ± Comparison against base commit cae6c96.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 2)

0 files   -     5  0 suites   - 5   0s ⏱️ - 3m 33s
0 tests  - 1 279  0 ✅  - 1 279  0 💤 ±0  0 ❌ ±0 
0 runs   - 1 280  0 ✅  - 1 280  0 💤 ±0  0 ❌ ±0 

Results for commit a8615ed. ± Comparison against base commit cae6c96.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 5)

0 files   -     2  0 suites   - 2   0s ⏱️ - 8m 41s
0 tests  - 1 104  0 ✅  - 1 104  0 💤 ±0  0 ❌ ±0 
0 runs   - 1 105  0 ✅  - 1 105  0 💤 ±0  0 ❌ ±0 

Results for commit a8615ed. ± Comparison against base commit cae6c96.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 3)

0 tests   - 2 297   0 ✅  - 2 297   0s ⏱️ - 6m 20s
0 suites  -     4   0 💤 ±    0 
0 files    -     4   0 ❌ ±    0 

Results for commit a8615ed. ± Comparison against base commit cae6c96.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 0)

    1 files   -   2      1 suites   - 2   4m 5s ⏱️ +20s
1 146 tests +585  1 146 ✅ +776  0 💤  - 191  0 ❌ ±0 
1 146 runs  +581  1 146 ✅ +772  0 💤  - 191  0 ❌ ±0 

Results for commit a8615ed. ± Comparison against base commit cae6c96.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 1)

    1 files   -   3      1 suites   - 3   4m 15s ⏱️ - 1m 21s
1 167 tests  - 586  1 166 ✅  - 585  1 💤  - 1  0 ❌ ±0 
1 171 runs   - 582  1 170 ✅  - 581  1 💤  - 1  0 ❌ ±0 

Results for commit a8615ed. ± Comparison against base commit cae6c96.

♻️ This comment has been updated with latest results.

@systemorph-com

systemorph-com Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The control plane does not arm auto-merge on this pull request: its base 'feat/module-reload' is not the default branch 'main' — an unprotected base merges the moment it is armed (#1685), so merge it by hand.

PR babysitter — posted once per head; see ReviewFindingsAnswered.md → "The arm gate".

2 similar comments
@systemorph-com

systemorph-com Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The control plane does not arm auto-merge on this pull request: its base 'feat/module-reload' is not the default branch 'main' — an unprotected base merges the moment it is armed (#1685), so merge it by hand.

PR babysitter — posted once per head; see ReviewFindingsAnswered.md → "The arm gate".

@systemorph-com

systemorph-com Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The control plane does not arm auto-merge on this pull request: its base 'feat/module-reload' is not the default branch 'main' — an unprotected base merges the moment it is armed (#1685), so merge it by hand.

PR babysitter — posted once per head; see ReviewFindingsAnswered.md → "The arm gate".

@systemorph-com

systemorph-com Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🚰 PR babysitter (build instance) is merging the base into this branch on head 9121e29a2645 — once per head.

Why: stale: 'lane / Automatic review answered' red on a head that tested 'feat/module-reload' at 1196734 — green on the base's newest run, so a gate the base has fixed since, not the diff ('lane / Automatic review answered' concluded failure: Process completed with exit code 1.) — the base 'feat/module-reload' moved from 1196734 (what the red run tested) to 5e51313. This pull request was red because its BASE was; the base has moved since, and a re-run would test the old merge commit again.

Validated: 'lane / Automatic review answered' is red on run 37288553599, a head that tested its base feat/module-reload at 1196734, while that base's newest run (now at 5e51313) is green on this check — the red is a gate the base has fixed since, not this diff's. Merging the current base into this stacked branch gives a new head whose run re-tests against the fixed base.

It does not merge the pull request, push anything else or dequeue. A red after this is left for the owner (rbuergi).

@systemorph-com

systemorph-com Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The control plane does not arm auto-merge on this pull request: its base 'feat/module-reload' is not the default branch 'main' — an unprotected base merges the moment it is armed (#1685), so merge it by hand.

PR babysitter — posted once per head; see ReviewFindingsAnswered.md → "The arm gate".

@systemorph-com

systemorph-com Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The control plane does not arm auto-merge on this pull request: its base 'feat/module-reload' is not the default branch 'main' — an unprotected base merges the moment it is armed (#1685), so merge it by hand.

PR babysitter — posted once per head; see ReviewFindingsAnswered.md → "The arm gate".

1 similar comment
@systemorph-com

systemorph-com Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The control plane does not arm auto-merge on this pull request: its base 'feat/module-reload' is not the default branch 'main' — an unprotected base merges the moment it is armed (#1685), so merge it by hand.

PR babysitter — posted once per head; see ReviewFindingsAnswered.md → "The arm gate".

@rbuergi
rbuergi merged commit 1fabbf6 into feat/module-reload Oct 5, 2026
65 of 69 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

thread:pr-systemorph-meshweaver-6139-1f7448 https://memex.systemorph.com/Hosting/Triage/_Thread/pr-systemorph-meshweaver-6139

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant