Skip to content

fix(host): keep empty readiness checks responsive - #382

Merged
Microck merged 1 commit into
mainfrom
fix/readiness-status-cache-miss
Oct 5, 2026
Merged

Microck merged 1 commit into
mainfrom
fix/readiness-status-cache-miss

Conversation

@Microck

@Microck Microck commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

after setup clears native readiness, the mac host can listen normally while /v1/capabilities times out. an in-flight stack shows the status lookup authenticating the Codex app to build a cache key even though there is no saved evidence to reuse. this prevents the controller from reaching first-use preflight.

the status path now checks authoritative SQLite for an unexpired successful candidate first. empty, failed, future, expired and invalidated evidence returns unavailable without native runtime discovery. a candidate still needs the full current authenticated key, so changed runtime evidence cannot authorize execution. prompt admission and live probes keep their existing checks.

validation: the owning runtime test uses real SQLite and the existing fake adapter to cover all seven states, including exact-match reuse and runtime mismatch. Crabbox passed all three owning runtime tests, including the seven candidate states, and workspace/all-target/all-feature Clippy with warnings denied. formatting passed. the build used one worker and disabled debug symbols because the shared host is short on disk and memory. cross-platform CI, build and lifecycle checks are running. device acceptance will follow the signed release; this PR does not claim the updated Mac has passed Luna yet.

Summary by CodeRabbit

  • Bug Fixes
    • Native readiness is now reported as unavailable when no valid, unexpired successful result matches the current authenticated cache key. This prevents stale or unrelated readiness results from being reused.

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
satelle Ready Ready Preview Oct 5, 2026 3:54pm UTC

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: Microck/satelle/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 385426f9-f304-4b2b-8231-fd530f3b60f2
📥 Commits

Reviewing files that changed from the base of the PR and between b5b8168 and f28c976.

📒 Files selected for processing (4)
  • .facts
  • crates/satelle/src/host/runtime-tests.rs
  • crates/satelle/src/host/runtime.rs
  • crates/satelle/src/host/storage/operational.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Runtime readiness reuse now checks storage for an unexpired successful native-readiness result before requesting the authenticated cache key. Tests cover candidate states and cache-key lookup calls.

Changes

Native readiness lookup

Layer / File(s) Summary
Check for a live readiness candidate
crates/satelle/src/host/storage/operational.rs
Storage::has_native_readiness_candidate checks for a passed result for the current host, observed by the current time and not yet expired.
Gate authenticated readiness lookup
crates/satelle/src/host/runtime.rs, crates/satelle/src/host/runtime-tests.rs, .facts
RuntimeEngine::has_reusable_readiness skips cache-key discovery when no candidate exists. Tests cover empty, expired, future-dated, failed, runtime-mismatched, matching, and invalidated entries. The Host capabilities rule describes the candidate check and full cache-key match.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to f28c9

The readiness shortcut has no identified merge-blocking issue; complete the remaining normal CI and release checks before deployment.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to f28c9

The change avoids unnecessary runtime authentication when no usable readiness evidence exists. It does not make a stored candidate sufficient to authorize work: current identity, runtime, permissions, and approvals must still match, and execution retains its separate checks. No material security risk was identified in the changed behavior.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly affected production behavior is capability reporting for the current daemon host. The shortcut cannot expand desktop execution authority because it returns false rather than supplying execution evidence, and positive reporting still requires the current full readiness key.

Trust Boundaries and Controls

  • observed — Capability reporting remains separate from execution admission. New run admission invokes the adapter's Run control, while execution preflight independently resolves the current readiness key, reconciles probe ownership, loads exact evidence or performs a live native probe, and then authorizes provider intent. The candidate shortcut is not used as execution authorization.

Resilience and Maintainability Implications

  • inferred — Removal or expiry of a candidate before the final lookup produces a miss because that lookup rechecks storage and time. A concurrent insertion after a negative read can conservatively delay positive reporting until another read. Both status reads are nonmutating, so interruption introduces no new reservation or cleanup obligation. A status result becoming stale after its final read is a pre-existing advisory timing window, not a new execution bypass.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 55.56% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 3 files. (1 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: keeping host readiness checks responsive when no reusable readiness evidence exists.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 55.56% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 3 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Microck

Microck commented Oct 5, 2026

Copy link
Copy Markdown
Owner Author

Note

🤖 Codex responding on behalf of Microck

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Pull request base or head changed.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@Microck

Microck commented Oct 5, 2026

Copy link
Copy Markdown
Owner Author

Note

🤖 Codex responding on behalf of Microck

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@Microck

Microck commented Oct 5, 2026

Copy link
Copy Markdown
Owner Author

Note

🤖 Codex responding on behalf of Microck

the new storage lookup documents the candidate check and why it cannot authorize execution. the runtime explains why an empty cache must skip native authentication. the remaining coverage warning includes test helpers and an existing private method; i am keeping those comments focused on the behavior rather than adding docstrings to meet a percentage. all three OS quality lanes pass, and the native build and lifecycle checks are still running.

@Microck
Microck merged commit 763d523 into main Oct 5, 2026
32 checks passed

This branch was successfully deployed

1 active deployment
Preview — f28c9768 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant