Skip to content

Publish blueprint sites transactionally - #165

Draft
Deicyde wants to merge 5 commits into
mainfrom
fix/transactional-publication-current
Draft

Deicyde wants to merge 5 commits into
mainfrom
fix/transactional-publication-current

Conversation

@Deicyde

@Deicyde Deicyde commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Merge order: land #165 first. Then restack #90 onto this transactional publication path and resolve the combined publication schema. Restack #75 only after #90 lands.

Summary

This supersedes stale #73 and rebuilds the repaired dc80ef23 transaction on current main.

  • derive one bounded immutable file plan from descriptor-bound blueprint and Lean generations
  • probe the mounted filesystem, sync the complete stage, install first output with atomic no-replace, and replace an exact owned v2 publication with one atomic directory exchange
  • retain and name the prior generation whenever commit state or cleanup is uncertain; never delete or rewrite live output before the commit, and never attempt a rollback exchange afterward
  • bind Git links and the dashboard graph to the exact captured bytes, while preserving current open-statement rendering, container behavior, durable/path claim aliases, and Host/Origin guards
  • fail closed before changing output on Windows or filesystems without the required primitives; the Ubuntu Pages/MkDocs path remains unchanged

Platform boundary

Transactional render requires Linux renameat2 or macOS renameatx_np, descriptor-relative traversal, advisory locking, and directory sync. Windows has no supported atomic exchange for an existing non-empty directory, so it receives an actionable no-write failure rather than a destructive two-rename fallback.

Validation

At exact head 09e374c6:

  • touched production/test surface: 434 passed, 6 skipped, 1 pre-existing xfailed
  • make lint
  • make check-example (check, visualize, render, strict MkDocs)
  • real subprocess exit immediately after exchange retains both complete generations
  • focused filesystem-capability, workspace-ownership, dashboard-concurrency, and pathname-ABA regressions
  • git diff --check upstream/main...HEAD
  • independent exact-head agent audit: clean; human GitHub review pending;
  • exact-head GitHub CI: all 9 checks pass, including both real-Lean and Windows jobs

@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Meta Open Source bot. label Oct 6, 2026
@Deicyde Deicyde added the review: ready Review complete with no known merge blockers label Oct 6, 2026
@Deicyde
Deicyde marked this pull request as ready for review October 6, 2026 07:45
@Deicyde

Deicyde commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Final exact-head gate at 09e374c6: independent audit is clean; 434 touched-surface tests pass (6 skipped, 1 pre-existing xfail); lint and strict example/MkDocs pass; and both Python 3.10/3.13, both Windows, both real-Lean runs, and CLA pass. Dashboard serialization, workspace ownership/recovery paths, filesystem capability probing, and snapshot policy-page canonicalization regressions are included. No blocker remains.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Meta Open Source bot. review: ready Review complete with no known merge blockers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant