Repository navigation
feat(setup-owner): fence Windows setup trees - #31
Merged
Merged
Conversation
There was a problem hiding this comment.
🔵 Needs a closer look
It introduces new low-level Windows Job Object/process-control code and a new fenced persistence protocol, which warrants careful human review on real Windows environments.
Pull request overview
Adds a Windows-only, identity-fenced “setup-owner” protocol so Blender Box can reliably own/cancel/recover a setup process tree even if SSH launch is interrupted before the client can record a PID.
Changes:
- Introduces
setup_ownerstate machine and record formats (request / receipt / terminal) with strict fencing and create-once persistence. - Implements a Windows keeper (
windows_setup_process) that creates a kill-on-close Job Object, starts PowerShell suspended with atomic job assignment, verifies script bytes (size/SHA-256/strict UTF‑8), then resumes. - Extends the CLI and docs with a runtime-gated
windows-setup-owner-v1capability probe andsetup-ownercommand, plus comprehensive tests.
File summaries
| File | Description |
|---|---|
| tests/test_windows_setup_process.py | Validates suspended creation, job assignment, bootstrap behavior, and keeper edge cases. |
| tests/test_setup_owner.py | Exercises request fencing, replay, stop/status recovery, and record invariants. |
| tests/test_cli.py | Adds CLI coverage for setup-owner routing and capability gating. |
| src/blendersessiond/windows_setup_process.py | Implements Windows Job Object “keeper” and suspended PowerShell bootstrap/IO handling. |
| src/blendersessiond/setup_owner.py | Implements fenced request/receipt/terminal protocol and persistence for setup attempts. |
| src/blendersessiond/cli.py | Adds setup-owner command and runtime-gated capability reporting. |
| README.md | Documents the new setup-owner command and capability probe. |
| docs/adr/0005-fenced-windows-setup-owner.md | ADR describing the setup-owner design and invariants. |
| CHANGELOG.md | Notes the addition of the Windows-only setup-owner protocol and capability probe. |
Review details
- Files reviewed: 9/9 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Owner
Author
|
Independent merge gate passed on
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Blender Box setup currently loses process ownership if its SSH launch is interrupted before PowerShell records a process identity. That makes safe cancellation and recovery impossible without broad process discovery.
This adds a private, fixed-purpose
setup-ownercontract backed by atomic suspended-process assignment to a kill-on-close Windows Job Object. Requests, receipts, and terminal records are create-once and fenced by Attempt ID, Launch ID, exact request SHA-256, and deadline. The bootstrap accepts only the staged script bytes declared by the request, verifies their size/SHA-256/strict UTF-8 encoding, and never exposes a generic command runner. Status and stop recover conservatively and reportcleanup_unverifiedwhenever exact tree disappearance cannot be proven.Proof:
uv run ruff check .uv run pytest -m "not e2e" -q— 152 passed, 1 Windows-only skipuv run pytest -m "e2e and not real_blender" -q— 18 passedSystemRootdeliberately poisoned, byte-identical replay, stale-stop rejection, exact root/child teardown, unrelated decoy survival, stable repeated stop, owner-loss reconciliation, and clean completion all passedSupports BramVR/blender-box#12 without closing it.
Model: GPT-5.6 Sol (high). Harness: Codex desktop, pytest/ruff, autoreview, and opt-in Windows SSH proof.