Skip to content

Trim safe serve upgrade to drain, restore, and retire (MN-REQ-06.14) - #210

Merged
chouswei merged 2 commits into
masterfrom
cursor/trim-serve-upgrade-416f
Oct 9, 2026
Merged

chouswei merged 2 commits into
masterfrom
cursor/trim-serve-upgrade-416f

Conversation

@chouswei

@chouswei chouswei commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Summary

Trims the squash-merged safe-upgrade cut (#208) to what a standalone memnet serve needs: save every loaded session, restart on the new version, reload every session. MN-REQ-06.14 and MN-VER-06-S12 are narrowed first. Version stays 0.19.21. No changelog version section. Not merged.

Kept

  • Admin drain memnet admin upgrade-prepare (MEMNET_ADMIN_TOKEN): quiesce, @ERR: serve_draining|retry_after_s=<seconds>, and the in-flight wait.
  • Lossless snapshot of every loaded session, the manifest (counts and checksums), and the unsaveable block plus --allow-unsaved.
  • Startup restore with the same session ids, ACL bindings, TTL clock, and house, and @STAT: upgrade_restore|ok|n|failed|m.
  • Loud failure that leaves the snapshot files untouched and does not retire.
  • Retire after a clean restore, now automatic inside that startup, so a later restart does not replay the snapshots.

Removed

  • Client retry in memnet-mcp and the product gateway (MEMNET_UPGRADE_RETRY_S). Clients see the normal refusal or a connection error during the restart.
  • The memnet-upgrade helper (systemd ExecStart swap, gateway pin edit, unit rollback, and the clients-ready gate).
  • The operator upgrade-retire command. Serve retires a clean manifest itself.

Operator note: docs/operations/safe-upgrade.md is the short procedure (install the new venv, upgrade-prepare, check ready-to-stop, restart the unit, read the restore stat). Rollback is pointing the unit at the old venv.

Tests

tests/test_safe_upgrade.py and tests/test_sysml_safe_upgrade.py: ACL, near-expiry TTL, and a near-cap graph; unsaveable blocks ready-to-stop; a corrupt snapshot fails loud and stays on disk; an older format v1 loads; an unsupported format leaves the file; drain refuses new work while in-flight commands finish; a clean restore retires and a later start does not replay; TCP restart keeps the same id, then a further restart does not replay.

Open in Web Open in Cursor 

cursoragent and others added 2 commits October 9, 2026 04:27
The upgrade stays inside memnet serve. Client retry and the systemd helper leave the requirement, the verify case, and the operator note.

Co-authored-by: chouswei <chouswei@users.noreply.github.com>
memnet-mcp and the gateway no longer retry serve_draining. A clean startup restore marks the manifest retired so a later restart does not replay the snapshots.

Co-authored-by: chouswei <chouswei@users.noreply.github.com>
@chouswei
chouswei marked this pull request as ready for review October 9, 2026 04:32
@chouswei
chouswei merged commit d0643eb into master Oct 9, 2026
2 checks passed
chouswei added a commit that referenced this pull request Oct 9, 2026
* Bump package identity to 0.19.22.

Hatch, project.toml, changelog, and the version map name the safe serve upgrade path (#208, MN-REQ-06.14). Not 0.20.

* Rewrite the 0.19.22 changelog to the trimmed safe upgrade scope (#210).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants