Nine commits, seven adversarial review rounds. The starting point was a real
defect — after 0c the capture sink is connection-owned, so a dead host leaves
loopbacks with no `module-null-sink` to trace its pid from, and discovery went
blind rather than getting smaller. Everything after that was the review finding
that the fix's foundations were softer than they looked.
What landed:
- Discovery derives candidate pids independently from all three module shapes,
A/B-proven on the live graph against the old binary.
- Recognition is exact-form only, and the matcher's templates are generated from
the loader's own renderer, so the two cannot drift; anything naming our sinks
that matches no known form is reported rather than silently ignored.
- Observation and unloading go through libpulse introspection over one
verified-local connection. `pactl`'s text output cannot carry this: a genuine
module whose argument contains a newline renders a first line that is
byte-exactly canonical (field-confirmed, no adversary needed), the JSON listing
carries no module index at all, and `PULSE_SERVER` is a fallback list that never
proved locality.
- A pid is not an owner. Every module carries a machine/boot/pid-namespace token,
and repair asks about a pid only when all three match — otherwise the module is
reported and its pid is never even looked up. Untagged modules from older builds
are refused by default, behind `--repair-legacy-untagged`.
- A plan is not a licence, and neither is ordering: fingerprints are re-verified
against a fresh snapshot per action, the sink unload is gated on nothing still
referencing it, and liveness runs before the snapshot so a replacement arriving
in that window is caught.
Verified beyond the unit suite: 256 tests, the phase-5 audit re-run with and
without tokens to prove the new property is inert to the taint engine, and four
live field gates covering orphan removal, the reference gate, and the token's
three cases.
Two lessons this merge is worth remembering for:
- The live field test found what unit tests structurally could not — including a
drop-order bug that made a completely successful repair exit 134, which is phase
0b's invariant one layer down.
- Every fix round in this branch contained a defect the next review caught. The
design held; the execution shell kept slipping.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>