Skip to content

test(pixel): pin the model transaction coordinator lifecycle and recovery contract - #5681

Closed
tang-vu wants to merge 5 commits into
Osmantic:public-betafrom
tang-vu:test/beta-model-coordinator-20260917
Closed

tang-vu wants to merge 5 commits into
Osmantic:public-betafrom
tang-vu:test/beta-model-coordinator-20260917

Conversation

@tang-vu

@tang-vu tang-vu commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds ods/tests/test_pixel_model_coordinator.py — the first coverage for ods/bin/pixel_model_coordinator.py, the zero-coverage transaction coordinator that owns the model-swap lifecycle (model-status / model-begin / model-apply / model-finish) on the Pixel generation path.

Why this matters

Every model switch on public-beta flows through this coordinator: it journals a transaction, takes edge + native runtime holds, plans the target contract, applies it through the worker, verifies the runtime projection, and releases with a durable completion record. A regression here leaves the runtime held, replays a half-applied config, or reports the wrong model — exactly the class of bugs the beta needs shaken out before release.

The tests drive a scripted FakeBridge (real edge/native hold state machine, real openclaw.json on disk with POSIX custody, real worker) so the coordinator's actual transaction logic runs end-to-end — nothing inside the coordinator is stubbed.

What is tested (32 cases)

Request validation — unknown operations, malformed request shapes, non-hex transaction ids, invalid model targets, outcome allowlist.

Lifecycle — model-status on a clean runtime; full begin → apply → commit with journal phases, model-completed.json content, and durable applied config; rollback restoring model-before.json; conflicting transaction id; idempotent model-begin replay on a held journal; runtime-busy refusal; completed-transaction replay (idempotent same-outcome finish, rejected conflicting outcome).

Recovery — stale revision → model-inspection-changed; commit while held → model-apply-unverified; worker returning a mismatched sha → model-projection-mismatch; pinned target after a lost apply reply → model-target-changed; lost model-begin reply resumes acquiring → held instead of restarting; lost model-apply reply commits by proof — model-finish verifies the already-applied config without re-dispatching apply; worker pending with no journal → model-recovery-journal-missing.

State guards — releasing journal rejects apply; flipped outcome → model-outcome-conflict; corrupted journal (kind/phase/sha fields) → invalid-model-transition fail-closed on every operation; dropped edge hold → model-hold-unconfirmed; readback disagreeing with the config projection → model-runtime-mismatch; stopped native runtime → model-runtime-unavailable; config tampered between apply and commit → model-config-changed; probe returning the wrong access mode → model-access-proof-failed with the journal preserved (fail-closed); malformed model-completed.json → invalid-model-completion.

Overlap check

Searched open + closed PRs for pixel_model_coordinator, "model coordinator", "model transaction journal", model-apply/model-begin/transition.json — no existing PR touches this module. #5606 (projection() float coercion) and #3121 (upgrade-model checksum) touch pixel_model_contract.py / upgrade paths only; this PR asserts coordinator transaction semantics, a disjoint surface. Complements my own #5668 (model contract projection tests) without overlap.

Validation

$ pytest ods/tests/test_pixel_model_coordinator.py -x -q
32 passed in 2.93s

Test-only change — no production code modified; revert is a single file deletion.

@tang-vu tang-vu closed this Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant