tmux-amq/workplans/TAMQ-WP-0013-emergency-cleanup.md
repo-manager ca4e78ad07
Some checks failed
tamq-ci / test (push) Failing after 5s
chore(registrar): assign State Hub identifiers
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a03397-4d51-7fd1-8ff2-946eb22ea2bc
2026-08-25 15:22:14 +02:00

86 lines
3.2 KiB
Markdown

---
id: TAMQ-WP-0013
type: workplan
title: "Emergency shutdown and owned-artifact cleanup"
domain: communication
repo: tmux-amq
status: finished
owner: codex
topic_slug: coulomb-social
planning_priority: P0
planning_order: 18
created: "2026-08-25"
updated: "2026-08-25"
state_hub_workstream_id: "8b9010f9-0806-5805-b68c-b05b6c093d96"
---
# Emergency shutdown and owned-artifact cleanup
Provide a conservative operator escape hatch for runaway or stale local tamq
state, and remove the preserved WP0012 feedback chain exactly.
## Purge the incident chain precisely
```task
id: TAMQ-WP-0013-T01
status: done
priority: critical
state_hub_task_id: "9adf631b-98ca-5e95-884c-d1d14fff87d6"
```
Resolve descendants of root message
`m-a0570ba1-7088-40f3-892f-8c981b4bb69e` only when their receipt identity,
chronology, and direction match the preceding durable delivery. Prove the
82-record dry run, delete that exact set, and retain all unrelated history.
## Add dry-run emergency cleanup
```task
id: TAMQ-WP-0013-T02
status: done
priority: high
state_hub_task_id: "65e92cc5-0370-5d9a-a095-4c0950ed25e3"
```
Add `tamq cleanup`, dry-run by default. Its confirmed form stops a verified
broker, closes only the tamq-marked tmux session, clears transient endpoints
and leases, removes configured runtime socket/PID/lock files, and removes only
generated tamq address shims. Preserve durable history and unrelated tmux
sessions/files.
## Prove, install, and document recovery
```task
id: TAMQ-WP-0013-T03
status: done
priority: high
state_hub_task_id: "7244d391-ecd8-5f85-b035-1b0824ecb443"
```
Cover ownership checks, stale/missing state, idempotence, dry-run behavior,
feedback-chain selection, and isolated installed cleanup. Update help and
operator documentation, install, and leave the live broker stopped.
## Completion evidence
- `tamq purge --feedback-chain m-a0570ba1-7088-40f3-892f-8c981b4bb69e`
dry-ran at exactly 82 records. The broker was stopped again after an external
restart, then the confirmed purge deleted exactly 82 records; the root no
longer exists and 25 unrelated records, including 14 pending, remain.
- `tamq cleanup` reports service identity, managed-session ownership, transient
DB counts, runtime files, generated shims, stale socket count, and preserved
history without mutation. `--yes` refuses unverified service PIDs and
unmarked tmux sessions.
- Confirmed cleanup stops the verified broker and verifies it is down, closes
the marked session, disconnects endpoints, clears leases, removes exact
configured runtime files and marker-owned shims, and removes only owned
`tamq-*` Unix sockets that refuse connections. It preserves live sockets,
unrelated files/sessions, and all durable history.
- The installed isolated smoke proved dry-run non-mutation and confirmed
cleanup, then read the preserved message after broker/session/runtime removal.
It also removed the accumulated dead `tamq-*` tmux sockets from prior test
runs; live and default tmux sockets were excluded.
- `make check`: 131 tests passed. Coverage is 78% overall and 83% for the new
cleanup module. `make install` refreshed `tmux-amq==0.1.0`.
- The operator broker remains stopped. This workplan creates no reliability
residual beyond `TAMQ-WP-0003`.