Skip to content

ateapi: stamp the golden tag into the created Actor's source_tag - #2290

Open
cloudonly wants to merge 2 commits into
agent-substrate:mainfrom
cloudonly:create-actor-golden-source-tag
Open

cloudonly wants to merge 2 commits into
agent-substrate:mainfrom
cloudonly:create-actor-golden-source-tag

Conversation

@cloudonly

@cloudonly cloudonly commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Refs #2210

CreateActor already borrows the template's golden snapshot when the caller omits source_tag. This change also records that golden tag in the stored Actor's source_tag, so the Actor names the snapshot source it used.

The default is applied to a copy of the request. Explicit source tags and golden snapshot scope validation keep their existing behavior. Regression assertions check that both successful and rejected requests remain unchanged.

Whole-object UpdateActor requests must retain the recorded source_tag under the existing immutability rule. kubectl ate get actor now displays sourceTag for golden-created Actors. The API guide and proto field comment describe the default.

This PR records provenance only. Resuming after template deletion still requires separate changes: resume currently resolves the template, and template deletion also deletes the golden tag and releases its snapshot. A source_tag fallback alone would not preserve that snapshot.

Validation on Linux/amd64 with Go 1.27.1, real PostgreSQL 18 testcontainers and Kubernetes envtest, with REQUIRE_DOCKER=1:

  • go test -race ./cmd/ateapi/internal/controlapi ./cmd/ateapi/internal/controlapi/functionaltest -count=1: 326 top-level tests passed, 750 results including subtests, zero failures or skips. All seven golden-tag scenarios and the six changed functional tests executed and passed.

  • Removing the request copy in a temporary test variant made all six default-tag scenarios fail the new input-immutability assertion. The explicit-tag case passed. The original implementation was restored before the passing run.

  • bash hack/verify-all.sh: all 14 static verifiers passed.

  • make verify: 137 packages passed; cmd/atelet/internal/filecache and internal/imagecache failed with write-protection and OverlayFS mount errors on this root/Linux 5.14 host. The same five top-level failures reproduced at the PR's merge base, 3230f9f8, with no skips. These failures prevent an overall make verify pass on this host.

Creating an Actor from a template with a golden snapshot borrows the
golden tag's snapshot into Status.ExternalSnapshot without recording
which tag it borrowed. The template's golden_tag pointer was the only
record of that reference, so deleting the template left never-resumed
actors with no way to name their snapshot source.

Default the request's source_tag to the template's golden tag so the
stored Actor carries the reference itself. The stamp is applied to a
copy of the request, so the caller's message and the RPC log keep
reflecting what was sent. Explicit source tags and golden-scope
validation are unchanged.

Recording the reference also tightens updates: a whole-object
UpdateActor that omits source_tag on such an Actor now fails the
existing immutability rule. Resume still resolves the template
unconditionally, so consuming the recorded reference is future work.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/api-machinery area/scheduling kind/bug Something isn't working / bugfixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants