Files
hermes-agent/tests/conformance/persistence
kshitijk4poor 905fdda100 fix(conformance): make the journal-mode matrix honest — steer the child resolver, audit the effective mode
Salvage round on the Phase 1 skeleton (three findings from review):

1. The DELETE leg was silently upgraded to WAL on healthy SQLite:
   pre-seeding the file via PRAGMA was undone by SessionDB.__init__'s
   apply_wal_with_fallback(), which upgrades any non-WAL file whenever
   the configured mode (default wal) says so — only WAL-reset-vulnerable
   interpreters preserved DELETE, i.e. the leg tested the advertised
   mode only where CI wasn't running. Each matrix leg now pins
   database.journal_mode in an isolated HERMES_HOME for the child and
   audits the ON-DISK mode after the run (effective_mode_or_skip):
   a leg that ran in a different mode skips instead of double-counting.

2. Cell 2 exit-code conflation: a claimant crashing with an unhandled
   exception exits 1 — indistinguishable from the clean "lost the
   claim" exit(1), so one winner + seven crashes passed as consume-once
   proof. Codes are now disjoint (0=won, 10=lost, anything else=crash).

3. Crashed-writer diagnostics: wait_for now fails immediately with the
   child's stderr when the writer dies before reaching the kill window
   (was: 60s opaque deadline, stderr discarded). spawn_child prepends
   to an inherited PYTHONPATH instead of clobbering it.

Plus: dead `if False` scaffolding removed from cell 1's writer; README
matrix section corrected (cell 2 is default-mode-only by design — the
consume-once property rests on a single predicated UPDATE).
2026-08-24 15:54:23 +05:30
..

Crash/resume persistence conformance cells

Phase 1 of the machine-checked conformance suite proposed in #80921, following the contract framing of "Resume Means Resume" (arXiv:2608.03836): each cell is a deterministic, LLM-free probe of one persistence contract clause, run against the real SessionDB with a real SIGKILL delivered to a separate OS process mid-write.

Cells

cell contract clause origin
1 — test_cell1_prefix_durability acknowledged appends survive a hard crash; contiguous prefix; deterministic recovery adapted from the tracking issue's spot-probe (29.5K-message original, scaled to a ≥200-append kill window with identical assertions)
2 — test_cell2_consume_once a parked handoff is claimed by exactly one of N racing processes adapted from the tracking issue's spot-probe (8-process file-barrier race)
3 — test_cell3_rotation_atomicity a compression rotation is visible entirely or not at all — never a compression-ended parent without a continuation (the #80337 orphan shape; recovery for the legacy population merged in #80487) new in this suite
4 — fork determinism on edit/rewind recovery yields exactly the chosen prefix after a fork stub — interlocked with the rewind/archive redesign (#82956–#82959)
5 — delivery-outbox effect exactly-once crash between provider send and durable record must not double-deliver on catch-up stub — needs a fake-transport seam; cron delivery scope in flight (#83197/#83557)

Method

  • Real SessionDB(db_path=...) in an isolated tmp_path; no mocks on the persistence layer.
  • Crashes are real SIGKILLs to a separate interpreter, asserted to be alive at kill time (a clean early exit cannot masquerade as a crash test); acknowledgement journals tolerate a torn final line (the kill can interrupt the journal write itself).
  • Every wait is deadline-bounded; coordination uses file barriers, never sleeps-for-correctness.
  • Journal-mode matrix (cells 1 and 3): the resolver's default, explicit DELETE, and explicit WAL — each leg steers the child's own resolver via an isolated HERMES_HOME config, then audits the on-disk mode after the run and skips when the environment didn't honor the request (e.g. the resolver's WAL-reset downgrade gate, the tracking issue's 3.50.4 caveat). A leg that ran in a different mode never counts as evidence for the advertised one. Cell 2 runs on the resolver's default only (the consume-once property is journal-mode-independent: it rests on a single predicated UPDATE).

Semantics

These are conformance cells: they are expected GREEN on main (cells 1–2 reproduce the tracking issue's passing probes; cell 3 pins the atomicity the #80337 forensics established). A failing cell is a fire: report it on #80921 with the cell's evidence — do not silence it, and do not attach a fix to this suite.