Skip to content

fix: bound conformance and repair lifecycle cleanup - #6

Merged
kevinten10 merged 1 commit into
mainfrom
fix/runtime-maintenance
Oct 9, 2026
Merged

kevinten10 merged 1 commit into
mainfrom
fix/runtime-maintenance

Conversation

@kevinten10

@kevinten10 kevinten10 commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Use the public lifecycle transition table for termination eligibility, including ambiguous pause/resume and repeated terminating observations; retain generation fencing and serialization.
  • Give every conformance Provider call a deadline and cancellation signal. Validate timeout options, isolate create-intent identities, skip data-plane probes after failed recovery, and always attempt bounded cleanup after provisioning. Verify that cleanup actually returns terminated.
  • Upgrade the dependency updates proposed in build(deps-dev): bump the development-tooling group with 3 updates #4 and build(deps-dev): bump yaml from 2.9.0 to 2.9.1 #5 with matching Vitest/coverage versions, a matching Biome schema, and grouped future Vitest upgrades. Refresh source-map-js to 1.2.2 for GHSA-68fv-2mgg-jv7q. Make the all-dependency high-severity audit part of pnpm check.
  • Include specifications, guides, and diagrams in the package. Check actual tarball exports, CLI, documentation, and all packaged Markdown local links. Correct the bilingual SDK/transport description and distinguish historical validation from verified release evidence.

Verification (2026-10-09)

  • pnpm install --frozen-lockfile passed.
  • PR CI passed on Node.js 22 and 24 at da60a72c3a01ae6f34eed28c1a88b18d83d7b2f2.
  • pnpm check passed: 6 files, 109 tests; formatting, lint, types, build, docs, coverage, actual tarball, and full dependency audit.
  • Coverage: 89.77% statements, 85.12% branches, 93.50% functions, 91.94% lines.
  • Actual tarball validation passed with 73 entries, including diagrams and local documentation links.
  • New regression cases failed against the old behavior before the fixes. A deliberate image omission made package validation fail; restoring the manifest made it pass.
  • Timeout regressions use virtual clocks to avoid load-dependent timing assumptions; cancellation rejection and late rejection also have coverage.
  • pnpm audit --prod --audit-level high passed.
  • pnpm sanitize passed, including repository history and image metadata checks. Independent staging scanning found no credential, organization-fingerprint, private-document, or dangerous-file hits. Two address-shaped soft matches are the public pnpm version 10.33.0 in CI/package metadata, not network addresses; both are retained intentionally.

Independent rationale and boundary

The changes follow this repository's public state model and first-principles handling of asynchronous cancellation, ambiguous responses, idempotency, and package completeness. Fixtures use synthetic identities and Mock/Local Providers only. No real cloud Provider, production deployment, npm publication, or replacement of the existing v0.1.0 tag is included.

@kevinten10
kevinten10 merged commit bcfdfd4 into main Oct 9, 2026
2 checks passed
@kevinten10

Copy link
Copy Markdown
Member Author

Verified closeout (2026-10-09):

  • Merged to main as bcfdfd4794bb4c30dc5229514091a9971d4977bc.
  • Main CI passed on Node.js 22 and 24, including 109 tests, coverage, actual package validation, full dependency audit, and public-content scanning.
  • The local main checkout is clean and its Git tree equals the tested PR candidate tree.
  • Open GitHub secret-scanning and dependency-alert counts are both zero at read-back time.
  • Dependency PRs build(deps-dev): bump the development-tooling group with 3 updates #4 and build(deps-dev): bump yaml from 2.9.0 to 2.9.1 #5 are superseded by this change; their updates are included here.
  • No real cloud Provider, production deployment, npm publication, or new release tag was performed. Existing v0.1.0 remains unchanged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant