Commit eeae1ee
fix(ocap-kernel): peer-incarnation restart detection across receiver state loss (#948)
## What
Closes [#944](#944): a
remote peer restarting with a fresh incarnation (e.g. plugin kernel
reload) caused the receiving kernel to silently drop the new
connection's seq=1 messages.
## Why
The receiver's persisted `RemoteHandle.#highestReceivedSeq` outlived the
in-memory PeerStateManager that was supposed to detect the restart. The
handshake then mis-classified a real restart as a first connection, and
dedup ate the messages.
## How
- Persist the peer's last-observed incarnation in a new
`peerIncarnation.{peerId}` KV namespace, so the comparison survives
receiver state loss.
- Fire `onIncarnationChange` on every successful handshake; the kernel
compares observed against persisted and returns whether a restart was
detected. The transport uses that verdict to close the channel and
re-dial, symmetric on both inbound and outbound paths.
- On detected restart, clear the peer's c-list contributions
(`forgetEndpointImports`) and reject promises it was deciding,
atomically with the persisted incarnation update via a savepoint.
In-memory state changes and run-queue notifications are deferred until
after commit so a kv rollback can't leave the views inconsistent.
- Add `PeerRestartedError`, `IntentionalCloseError`,
`NetworkStoppedError` to `@metamask/kernel-errors` (with
`isTerminalSendError`) so the kernel-side abort-retransmit predicate
stops relying on string matching.
## Test plan
- [x] Unit tests: `yarn workspace @metamask/kernel-errors
test:dev:quiet`, `yarn workspace @MetaMask/ocap-kernel test:dev:quiet`,
`kernel-browser-runtime`, `kernel-node-runtime`
- [x] `yarn build`, `yarn workspace @MetaMask/ocap-kernel lint:fix`
- [x] E2E `packages/extension/test/e2e/remote-comms.test.ts` (timeout
budget raised to fit the 40s URL redemption ceiling)
- [x] E2E `packages/kernel-node-runtime/test/e2e/remote-comms.test.ts`
#944 regression
🤖 Generated with [Claude Code](https://claude.com/claude-code)
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **Medium Risk**
> Touches remote-communications handshake, kernel persistence, and
retransmit logic; mistakes could cause dropped messages, excessive
reconnects, or incorrect promise rejection. Mitigated by extensive new
unit/e2e coverage and fail-closed defaults.
>
> **Overview**
> Fixes a remote-comms restart edge case by **persisting the last-seen
peer incarnation** and consulting it on *every* handshake, allowing
restart detection even after receiver-side in-memory state loss.
>
> Updates the transport and platform-services RPC plumbing so
`onIncarnationChange(peerId, observedIncarnation)` returns a boolean
verdict; the transport uses this verdict to **drop/close channels and
suppress potentially stale outbound messages** (with explicit
fail-closed behavior on RPC/handler errors).
>
> Hardens kernel restart handling by splitting peer-restart cleanup into
persisted vs in-memory phases (savepoint-protected), adding
`forgetEndpointImports` c-list teardown, improving retransmit to send
sequentially and abort on terminal send errors, and introducing new
sentinel errors (`PeerRestartedError`, `IntentionalCloseError`,
`NetworkStoppedError`) plus `isTerminalSendError`. E2E timeouts/tests
are adjusted/added to cover the regression scenario.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
6aae9ea. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 306d874 commit eeae1ee
34 files changed
Lines changed: 2315 additions & 219 deletions
File tree
- packages
- extension/test/e2e
- kernel-browser-runtime
- src
- kernel-errors
- src
- errors
- utils
- kernel-node-runtime/test/e2e
- ocap-kernel
- src
- remotes
- kernel
- platform
- rpc/kernel-remote
- store
- methods
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
| 8 | + | |
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
| |||
140 | 140 | | |
141 | 141 | | |
142 | 142 | | |
143 | | - | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
144 | 148 | | |
145 | 149 | | |
146 | 150 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
10 | 14 | | |
11 | 15 | | |
12 | 16 | | |
| |||
Lines changed: 191 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
513 | 513 | | |
514 | 514 | | |
515 | 515 | | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
| 661 | + | |
| 662 | + | |
| 663 | + | |
| 664 | + | |
| 665 | + | |
| 666 | + | |
| 667 | + | |
| 668 | + | |
| 669 | + | |
| 670 | + | |
| 671 | + | |
| 672 | + | |
| 673 | + | |
| 674 | + | |
| 675 | + | |
| 676 | + | |
| 677 | + | |
| 678 | + | |
| 679 | + | |
| 680 | + | |
| 681 | + | |
| 682 | + | |
| 683 | + | |
| 684 | + | |
| 685 | + | |
| 686 | + | |
| 687 | + | |
| 688 | + | |
| 689 | + | |
| 690 | + | |
| 691 | + | |
| 692 | + | |
| 693 | + | |
| 694 | + | |
| 695 | + | |
| 696 | + | |
| 697 | + | |
| 698 | + | |
| 699 | + | |
| 700 | + | |
| 701 | + | |
| 702 | + | |
| 703 | + | |
| 704 | + | |
| 705 | + | |
| 706 | + | |
516 | 707 | | |
517 | 708 | | |
518 | 709 | | |
Lines changed: 68 additions & 23 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| 28 | + | |
28 | 29 | | |
29 | 30 | | |
30 | 31 | | |
| |||
329 | 330 | | |
330 | 331 | | |
331 | 332 | | |
332 | | - | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
333 | 337 | | |
334 | | - | |
335 | | - | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
336 | 348 | | |
337 | | - | |
338 | | - | |
339 | | - | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
340 | 374 | | |
341 | | - | |
342 | 375 | | |
343 | 376 | | |
344 | 377 | | |
| |||
383 | 416 | | |
384 | 417 | | |
385 | 418 | | |
386 | | - | |
387 | | - | |
388 | | - | |
389 | | - | |
390 | | - | |
391 | | - | |
392 | | - | |
393 | | - | |
394 | | - | |
395 | | - | |
396 | | - | |
397 | | - | |
398 | | - | |
399 | | - | |
400 | | - | |
401 | | - | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
402 | 447 | | |
403 | 448 | | |
404 | 449 | | |
| |||
0 commit comments