Files
truf-server/docs/worker-operator-experience-live-trace-2026-09-25.md
2026-09-30 20:30:56 +03:00

14 KiB

Worker Operator Experience Live Trace - 2026-09-25

Result

The accepted Windows package and Linux image completed a fresh, concurrent live cohort against the sec runtime. All 295 assignments were acknowledged, ingested, projected, and settled. There were no unresolved assignments, pre-commit bundles, expiries, pre-bundle failures, quarantine rows, append failures, or publication-outbox rows at the final cut.

The worker transport and server pipeline acceptance result is pass. Four product defects and two operational warnings were found. The defects did not invalidate the one-authoritative-acceptance, ingestion, projection, recovery, or shutdown guarantees demonstrated by this cohort, but they remain release inputs and are listed below.

This report is sanitized. It intentionally excludes authentication values, private routes, worker command lines, raw targets, raw findings, secrets, and runtime configuration bodies. The protected evidence files referenced below contain sensitive material and must not be published.

Validated artifacts

The run used the previously accepted reproducible artifacts without modifying their product code:

Platform Accepted identity
Windows x86-64 package manifest 78a962b2bd3fa411413c79e9a8ffb021608a08ff020b1ad851f4505ea634b2b6
Linux x86-64 package identity 45588f2cf406b41b239cfa3b8a9dc83fe84b587229bc997b2729016e1f0dde42
Linux image sha256:3a088f5743121d823aae132234a29730a84339cecbfda5fc601e8e942f9948c3

Both trusted manifests remained registered on the server. Each validation worker ran one slot with local parallelism 1. The measured combined concurrency reached exactly 2, proving concurrent accepted Windows and Linux execution without increasing either worker's local parallelism.

Final cohort

Platform and source distribution

Worker DockerHub GitLab Hugging Face Total
Windows 58 57 51 166
Linux 50 30 49 129
Total 108 87 100 295

Every history row ended with bundle_accepted and mapped to exactly one server reservation and receipt. The Windows and Linux reservation sets were disjoint and their union exactly matched the 295-row server cohort.

Scan and queue outcomes

Scan outcome Count
clean 143
degraded 73
error 75
found 4
Queue disposition Count
done 220
deferred 74
failed 1

These are scanner/queue outcomes, not transport failures. All corresponding result bundles were accepted and projected. In particular, timeout and scanner error results remained normal uploadable terminal results.

Persisted detail

The stable capture contains:

  • 295 admission intents, reservations, bundles, target scans, compatibility rows, and completed scan projection jobs;
  • 2,905 ordered progress events;
  • 75 structured diagnostics;
  • 129 normalized scan errors;
  • 4 normalized findings, 4 stable UID mappings, and 4 bounded compatibility payloads;
  • 4 pending keycheck candidates linked to 2 normalized credentials;
  • 374 appended projection records across 3 streams;
  • 956 pipeline artifacts, all deleted by the final snapshot; and
  • 19 successful typed runtime operations with 38 chained audit events.

The diagnostic aggregate was:

Worker Scanner result errors Stage timeouts Total diagnostics
Windows 55 8 63
Linux 1 11 12

Of the Windows scanner-result errors, 54 were retryable and one was non-retryable. The Linux scanner-result error was retryable. Complete safe diagnostic envelopes, exception identities, bounded process-log representations, occurrence times, receipt authority, and scan links were retained and checked.

End-to-end integrity checks

build/operator-experience-validation/analyze-live-trace-final-20260925.py executed 65,675 checks with zero failures. It verified, row by row:

  • admission, reservation, queue, bundle, scan, compatibility, and projection foreign-key relationships;
  • receipt, payload, bundle, event, device, and deadline identities;
  • canonical SHA-256 values for execution snapshots, progress events, diagnostics, compatibility metadata, plans, projection events, and finding payloads;
  • exact bounded reconstruction of the four compatibility findings, including their original numeric detector identity and explicit null mapped fields;
  • every normalized error, finding, keycheck candidate, credential reference, projection append, capacity release, and deleted artifact;
  • all 19 operation-to-audit pairs; and
  • the complete 38-event audit parent/hash chain.

build/operator-experience-validation/analyze-worker-states-final-20260925.py executed a further 28,686 checks with zero failures. It parsed every retained worker JSON/JSONL record and verified:

  • 166 Windows and 129 Linux history rows against the server receipts;
  • 2,338 contiguous Windows events and 1,672 contiguous Linux events;
  • receipt payload, bundle, event, acceptance-time, and reservation identities;
  • clean local shutdown with drained=true, exit_code=0, and empty progress outboxes; and
  • no active work root in either final worker snapshot.

The two analyzers therefore executed 94,361 deterministic checks without a failure.

Recovery and shutdown

The validation exercised durable recovery rather than only clean executions:

  • transient server 502 responses were retained in both local worker logs and recovered without duplicate authoritative acceptance;
  • one Linux assignment survived a worker stop in the persistent volume, resumed after restart, produced one accepted result, and released all capacity;
  • a transient assignment-status network failure retried the same durable assignment without rescanning or data loss; and
  • both workers then drained and stopped cleanly.

The final local states were:

Worker State Drained Exit Pending outbox
Windows stopped true 0 0
Linux container exited true 0 0

Retained work/abandoned roots are inactive evidence governed by normal worker retention. They are not active assignments.

Worker API validation

Authenticated worker API validation covered:

  • device identity, package-manifest trust, and assignment-cap enforcement;
  • claim, reservation replay, assignment status, and immutable execution snapshot;
  • monotonic progress submission and latest-progress readback;
  • bounded diagnostic body and process-log payloads;
  • durable bundle upload, idempotent receipt replay, and accepted resolution;
  • local restart recovery and terminal history;
  • server ingestion, normalized scan authority, compatibility reconstruction, and projection completion; and
  • terminal capacity release and zero unresolved work.

The API preserved receipt, payload, scan-event, diagnostic, and reservation identities throughout the cohort. A separate terminal readback defect affecting only scan_deadline_at is documented below.

Admin UI and operator workflow

The authenticated admin UI was exercised through a browser across the complete operator surface:

  • Workers / Dispatch: control state, users, devices, assignment caps, enable, disable, revoke, unrevoke, and bounded worker detail;
  • Overview: runtime health, producer lifecycle, pipeline workers, leases, queue counts, capacity, controls, recent operations, and duration groups;
  • Search: bounded assignment, scan, finding, error, diagnostic, and progress lookup with safe empty and populated states;
  • Supervisor: source start, restart, stop, lifecycle, and safe error rendering;
  • Logs: bounded source/component/level/time filters and empty-result handling;
  • Config and Secrets: active identities, stale-candidate warning, redacted projections, validation, and non-secret operation results;
  • Files: bounded listing, file identity/hash verification, and safe download behavior;
  • Operations: accepted/running/succeeded projections and filters; and
  • Audit: accepted/succeeded event pairs, pagination, actor/action filters, and parent/hash continuity.

The final UI snapshot showed:

  • Supervisor ACTIVE and PostgreSQL READY;
  • result ingester, JSONL projector, janitor, and worker API all running;
  • ingester and projector leases ready;
  • control revision 126, discovery and dispatch open, drain state normal;
  • zero active assignments and zero pre-commit bundles; and
  • zero quarantined queue rows.

The current DockerHub producer safe state remained runtime_error; it is the known retry-coalescing defect plus unavailable credential pool described below, not an unclassified new failure.

Server and pipeline final state

The final server snapshot at 2026-09-25 14:59 UTC confirmed:

  • 295 issued, 295 accepted, 295 ingested, 295 projected, and 295 settled;
  • 0 unresolved, expired, pre-bundle-failed, pre-commit, quarantine, and drain blockers;
  • bundle, projection, and quarantine capacity at zero;
  • keycheck capacity at 137 items / 27,262,866 bytes, representing real pending work rather than leaked assignment or projection capacity;
  • runtime container healthy with zero restarts and no OOM;
  • edge container running with zero restarts and no OOM; and
  • dashboard health endpoint returning 200 ok.

Defects found

1. Windows scanner timestamps lose their UTC offset

Status: open in the accepted Windows package.

Naive local scanner timestamps are relabeled as UTC, producing approximately a three-hour future displacement on the validation host. Progress transport and monotonic durations remain correct, but diagnostic ordering, time filters, and scan start/end instants are wrong.

Detailed evidence and correction: docs/defect-windows-scan-timestamps-utc-2026-09-25.md.

2. DockerHub retry coalescing fails with a null retry time

Status: open in the live runtime; fixed locally but not deployed.

PostgreSQL cannot infer the type of a nullable retry placeholder while coalescing an existing row, raising SQLSTATE 42P18. The managed producer masks that exception as a generic delegation failure. A minimal local correction casts the placeholder to text, and regression coverage now exercises same-row null-time coalescing.

Detailed evidence and local fix: docs/defect-dockerhub-discovery-retry-null-type-2026-09-25.md.

3. Terminal status can lose the durable scan deadline

Status: open in the live runtime.

A later progress event with a null scan deadline can replace the durable receipt's concrete immutable deadline in authenticated terminal status readback. The persisted receipt and all other identities remain correct.

Detailed evidence: docs/defect-terminal-status-scan-deadline-readback-2026-09-25.md.

4. Network OSError is mislabeled as local I/O

Status: open in the accepted workers.

The broad safe-summary branch classifies socket/transport OSError as local I/O operation failed. Recovery worked and no data was lost, but the operator message incorrectly points toward local storage.

Detailed evidence: docs/defect-worker-network-oserror-mislabeled-local-io-2026-09-25.md.

Operational warnings

  • The server root filesystem was approximately 90% used with roughly 1 GiB free. Containers remained healthy, but capacity should be reclaimed or expanded.
  • The DockerHub credential pool was independently unavailable: ten credentials were invalid and the remaining entry was rate-limited. Deploying the SQL fix preserves retries correctly but cannot make an unavailable credential pool healthy.

Tests and specification gates

The retained gates are:

  • worker/operator focused matrix: 355 passed, 3 skipped;
  • admin/runtime focused matrix: 124 passed, 2 warnings;
  • DockerHub incremental discovery matrix: 27 passed;
  • SQLite retry lifecycle regression: 1 passed;
  • corrected PostgreSQL statement verified transactionally against the live schema and rolled back; and
  • OpenSpec strict validation passed with all 27 implementation tasks complete.

The disposable PostgreSQL integration test remains skipped locally because no disposable DSN was configured. The live transactional SQL verification did not persist a change.

Evidence manifest

Artifact Bytes SHA-256
build/live-trace-20260925/raw-evidence-final.json 10,030,750 4071e38a1dec540663bc6febd9538ff54bedafa1627250933045beb8f7d09ec5
build/live-trace-20260925/monitor-final.ndjson 1,260,087 e07507b0b8f0f86d1a1c7aade7186297c372b1ff177067bea19dfd219f5027a9
build/live-trace-20260925/summary-final.json 3,669 19e5ec40cf354c6095a478b68a69f8e51fb3b8ea1c6f278c1d9c90bdaab9ebe2
build/live-trace-20260925/final-analysis-summary.json 946 2d17605ba7b730ad78a48bcc70e40e78f90637e3fd59004ebf5eb4a08241ba42
build/live-trace-20260925/final-worker-state-analysis-summary.json 1,376 b0ab428eb08587f13f59a1763f835125216f769713e259d85989ea8b7f8af95c
build/live-trace-20260925/linux-worker-state-final.tar.gz 134,380 b64e81c90b232f46b400a63ed08f5660f46e34fedb1f67b64afba079d8d36364

The final Windows state is retained under build/live-trace-20260925/windows-localappdata/TRUF/RemoteWorker.

Deliberately retained live state

The user requested that validation state not be restored. The following changes therefore remain deliberate:

  • accepted Windows and Linux trusted manifests remain installed;
  • the keycheck queue maximum remains increased from 4,096 to 8,192 items;
  • the Linux validation user remains enabled at assignment cap 0;
  • the Windows validation user remains enabled at assignment cap 1;
  • both validation workers themselves are stopped;
  • normal global controls remain open at revision 126; and
  • the dashboard remains running.

The config editor still contains an intentionally stale candidate based on the pre-validation active hash. It must not be applied without first rebasing it onto the current active configuration.

Release conclusion

The accepted worker artifacts passed live cross-platform execution, concurrent dispatch, bounded progress/diagnostics, durable recovery, one-authoritative receipt handling, normalized ingestion, projection, audit, local shutdown, and operator UI validation. The complete cohort settled without leaked worker, bundle, projection, or quarantine capacity.

Before broad rollout, deploy and revalidate the DockerHub SQL correction, decide release treatment for the Windows timestamp and terminal-deadline defects, fix network error classification, and address server disk pressure and DockerHub credential health. The OpenSpec change is complete but remains unarchived until explicitly requested.