Skip to content

fix(leasing): free the waiter's running slot when a failed boot's device is claimed before the destroy - #425

Open
V3RON wants to merge 3 commits into
mainfrom
claude/issue-401-0rpyxb
Open

V3RON wants to merge 3 commits into
mainfrom
claude/issue-401-0rpyxb

Conversation

@V3RON

@V3RON V3RON commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Requested by Szymon · project thread

Closes #401

Status

Implement: done (green) Review: round 1, 0 open Mutate: 0 alive Hardware: n/a Gate: not run (the gate script needs GraphQL, which this session cannot call)

Done when

  • A waiter's running-slot reservation is released whenever destroy does not throw, including when it returns undefined because another boot claimed the device first. Checked by the triage repro test, which fails with expected { global: 1, ios: 1 } to deeply equal { global: +0, ios: +0 } on the old code.
  • A destroy that throws still keeps the slot and fences the device. Checked by a new test; it fails if that path is changed.

The existing test for a device deleted mid-boot asserted the old fence. It now asserts the slot is freed and no fence, as the triage fix decided.

Assumptions

none

Review

Spec review: 0 blocking, 0 fixed, 1 notes. Code review: 0 blocking, 0 fixed, 0 notes. Claims review: 0 blocking, 0 fixed, 1 notes.
Mutate: 2 mutants, 0 alive.

Written by an agent.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CA6eBy6noXJbLUzgedJtga

V3RON and others added 3 commits October 6, 2026 20:40
…t claims the device before the destroy (#401)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CA6eBy6noXJbLUzgedJtga
…t throw (#401)

1 failing -> 0 failing

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CA6eBy6noXJbLUzgedJtga

V3RON commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Review notes

Not blocking, not verified. Each is one reviewer's claim.

  • spec: src/leasing/lease-acquisition-coordinator.test.ts:1518 the setup that makes destroy unable to claim the device (the makeReady spy that moves the record to deleted) is outside the diff's hunks, so the diff alone does not show the renamed test reaches the undefined return; the repro test proves the same path.
  • claims: src/leasing/lease-acquisition-coordinator.ts:891-892 the comment lists why destroy returns undefined as if complete; it also returns undefined when another operation (cleanup, reclaim, nuke) holds the claim, the record is in another state, its driverDeviceId changed, or the commit recheck fails (src/core/managed-device-lifecycle.ts:296, :318-319, :350-355).

Written by an agent.


Generated by Claude Code

@V3RON
V3RON marked this pull request as ready for review October 6, 2026 20:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A running-slot reservation can leak when the warm pool claims a device between a failed boot and its destroy

2 participants