|
| 1 | +# Project-Scoped Daemon Release |
| 2 | + |
| 3 | +## Decision |
| 4 | + |
| 5 | +Provide one explicit release lifecycle per canonical project root across daemon control, watchdog supervision, MCP coordination, and the CLI. |
| 6 | + |
| 7 | +## Scope |
| 8 | + |
| 9 | +The chain adds one explicit project-scoped release operation across daemon lifecycle control, watchdog supervision, MCP proxy coordination, and the non-interactive CLI. |
| 10 | + |
| 11 | +## Non-Negotiable Invariants |
| 12 | + |
| 13 | +- **Generation-safe ownership**: release targets a canonical root and one authenticated daemon generation. It never signals an unverified PID. |
| 14 | +- **Startup exclusion**: startup and release arbitrate ownership before publishing or deleting daemon artifacts. |
| 15 | +- **Intentional release is stable**: watchdog supervision does not immediately respawn a deliberately released root. A later normal CodeGraph launch or query may establish a new lifecycle. |
| 16 | +- **Ordered requests**: a release waits for earlier requests and rejects later project calls on the owning proxy. |
| 17 | +- **Explicit operator access**: MCP release remains opt-in and destructive; CLI release requires an explicit path. |
| 18 | +- **Project isolation**: releasing one root leaves unrelated projects available. Process-wide cleanup is not part of this design. |
| 19 | +- **Idempotent outcomes**: repeated release returns a typed outcome: `released`, `not-running`, `no-daemon`, `identity-mismatch`, `unreachable`, or `termination-failed`. |
| 20 | +- **Resource release only**: release does not remove a worktree or project directory. |
| 21 | +- **Tests travel with behavior**: each child carries focused behavior-first tests and builds independently on Node 22. |
| 22 | + |
| 23 | +## Chain Units |
| 24 | + |
| 25 | +1. Lifecycle arbitration, authenticated generation-safe release, leases, heartbeat recovery, startup exclusion, and core tests. |
| 26 | +2. Watchdog release tombstones, canonical aliases, explicit resume, and focused tests. |
| 27 | +3. Proxy request barriers, per-root coordination, opt-in MCP surface, annotations, and focused tests. |
| 28 | +4. Non-interactive CLI command, daemon manager presentation, parser and integration tests, and final cross-surface coverage. |
| 29 | + |
| 30 | +## Operator Surfaces |
| 31 | + |
| 32 | +The non-interactive CLI surface is `codegraph daemon stop --path <project-root>`. The destructive MCP surface is `codegraph_release`, disabled by default and requiring an explicit `path`. |
| 33 | + |
| 34 | +## Consequences |
| 35 | + |
| 36 | +Each child targets its immediate parent. Reviewers can validate and roll back one behavior boundary at a time while the tracker remains a durable integration map. |
| 37 | + |
| 38 | +## Contributor Checklist |
| 39 | + |
| 40 | +- [ ] Keep each child diff limited to its declared unit. |
| 41 | +- [ ] Run the focused tests and build under Node 22. |
| 42 | +- [ ] Preserve authenticated ownership, startup exclusion, and request ordering. |
| 43 | +- [ ] Do not merge the tracker before all children are integrated. |
0 commit comments