Adversarial editor runner can miss the live-restart handshake #226

Closed
opened 2026-09-27 10:35:53 +00:00 by kayg · 7 comments
Owner

Finding

The post-merge adversarial run on job/menu-icons at cdc09b1d reports FINDING editor server restart with a live editor: server runner did not complete requested restart. This run did not establish a product restart failure: restart-go-3 was never created, so the restart was never requested.

In tests/adversarial/run.sh, the script starts bun editor.mjs in the background and then calls restart_on_request 3 TERM synchronously. That helper gives restart-ready-3 only 60 seconds to appear. The editor reaches the restart case after its earlier browser, paste, and 500-step undo/redo probes. In this run, restart-ready-3 appeared after the helper's 60-second loop had returned; the file exists but restart-go-3 does not. The editor then times out after 90 seconds with the misleading restart finding.

Make the runner observe the restart handshake for the full editor probe lifetime (or run the watcher concurrently), then verify the live editor restart case reaches restart-go-3 before it reports a product result. Evidence log: target/tmp/menu-icons-adversarial-latest.log in the menu-icons worktree.

## Finding The post-merge adversarial run on `job/menu-icons` at `cdc09b1d` reports `FINDING editor server restart with a live editor: server runner did not complete requested restart`. This run did not establish a product restart failure: `restart-go-3` was never created, so the restart was never requested. In `tests/adversarial/run.sh`, the script starts `bun editor.mjs` in the background and then calls `restart_on_request 3 TERM` synchronously. That helper gives `restart-ready-3` only 60 seconds to appear. The editor reaches the restart case after its earlier browser, paste, and 500-step undo/redo probes. In this run, `restart-ready-3` appeared after the helper's 60-second loop had returned; the file exists but `restart-go-3` does not. The editor then times out after 90 seconds with the misleading restart finding. Make the runner observe the restart handshake for the full editor probe lifetime (or run the watcher concurrently), then verify the live editor restart case reaches `restart-go-3` before it reports a product result. Evidence log: `target/tmp/menu-icons-adversarial-latest.log` in the menu-icons worktree.
Author
Owner

The same one-round run also reproduced the runner report FINDING editor server restart with a live editor seed=25608414: server runner did not complete requested restart. This is the same live-restart handshake finding noted here; the phone-chrome run did not establish an independent product restart failure. Full log: target/tmp/phone-chrome-adversarial-retry.log in the phone-chrome worktree.

The same one-round run also reproduced the runner report `FINDING editor server restart with a live editor seed=25608414: server runner did not complete requested restart`. This is the same live-restart handshake finding noted here; the phone-chrome run did not establish an independent product restart failure. Full log: `target/tmp/phone-chrome-adversarial-retry.log` in the phone-chrome worktree.
Author
Owner

The post-merge adversarial round for CSP issue #118 reproduced this runner-handshake finding at seed 25608414: FINDING editor server restart with a live editor: server runner did not complete requested restart. It followed the browser editor's 500-step history probe, which exceeded the runner's 60-second handshake window. The run did not create restart-go-3, so this does not establish a product restart failure. The EDITOR_ONLY round reported three findings total; the history-storm data corruption is tracked separately in #225, and the 10,000-block sync timeout is tracked in #166.

The post-merge adversarial round for CSP issue #118 reproduced this runner-handshake finding at seed 25608414: `FINDING editor server restart with a live editor: server runner did not complete requested restart`. It followed the browser editor's 500-step history probe, which exceeded the runner's 60-second handshake window. The run did not create `restart-go-3`, so this does not establish a product restart failure. The `EDITOR_ONLY` round reported three findings total; the history-storm data corruption is tracked separately in #225, and the 10,000-block sync timeout is tracked in #166.
Author
Owner

Post-merge editor probe at c2ff7b40 again reported that the editor server runner did not complete its requested restart handshake. The later standalone restart probe completed with 0 findings and the backend was alive at the end. This points to the editor runner handshake rather than an observed server restart failure.

Post-merge editor probe at c2ff7b40 again reported that the editor server runner did not complete its requested restart handshake. The later standalone restart probe completed with 0 findings and the backend was alive at the end. This points to the editor runner handshake rather than an observed server restart failure.
Author
Owner

Post-merge replay on job/fonts at ffcc5d2a117ebafd4d32df9968230b3803f25a32: the live editor restart probe passed, and the final room restart probe reported 0 findings. The earlier missing restart handshake did not reproduce after merging the runner update.

Post-merge replay on `job/fonts` at `ffcc5d2a117ebafd4d32df9968230b3803f25a32`: the live editor restart probe passed, and the final room restart probe reported 0 findings. The earlier missing restart handshake did not reproduce after merging the runner update.
Author
Owner

New evidence from #219's required adversarial round at merge head 3025699104e0b57ec2275edd5fee00b5374f3d9d: the live-editor restart probe reached the requested restart handshake and then reported transient 502 responses for /api/v1/files/entries, /api/v1/notes, a Note backlinks route and /api/v1/search while the backend was being restarted. The probe's ordered checks had already observed the restart edit exactly once before it failed on the browser error list. The server remained alive at the end, and the separate restart probe reported 0 findings. This is the deliberate restart outage case, not the earlier missing-handshake report; recording it here so the probe can distinguish expected in-flight 502s from persistence failures.

New evidence from #219's required adversarial round at merge head `3025699104e0b57ec2275edd5fee00b5374f3d9d`: the live-editor restart probe reached the requested restart handshake and then reported transient `502` responses for `/api/v1/files/entries`, `/api/v1/notes`, a Note backlinks route and `/api/v1/search` while the backend was being restarted. The probe's ordered checks had already observed the restart edit exactly once before it failed on the browser error list. The server remained alive at the end, and the separate restart probe reported 0 findings. This is the deliberate restart outage case, not the earlier missing-handshake report; recording it here so the probe can distinguish expected in-flight 502s from persistence failures.
Author
Owner

Already fixed on origin/dev. git log origin/dev --grep='Wait for delayed editor restart probes' shows f087cceba. Current tests/adversarial/run.sh::restart_on_request waits for restart-ready while the editor probe is alive, with 6,000 polls at 0.1 seconds by default, instead of returning after the earlier 60-second window. Recommend recording this runner fix here. Do not close the issue in this audit.

Already fixed on origin/dev. git log origin/dev --grep='Wait for delayed editor restart probes' shows f087cceba. Current tests/adversarial/run.sh::restart_on_request waits for restart-ready while the editor probe is alive, with 6,000 polls at 0.1 seconds by default, instead of returning after the earlier 60-second window. Recommend recording this runner fix here. Do not close the issue in this audit.
Author
Owner

Fixed in f087cceba (origin/dev); tests/adversarial/restart.mjs now waits for the live restart marker before continuing.

Fixed in f087cceba (origin/dev); `tests/adversarial/restart.mjs` now waits for the live restart marker before continuing.
kayg closed this issue 2026-10-03 11:55:22 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#226
No description provided.