Qwen and native session import checkpoint — 2026-09-13 UTC
Qwen and native session import checkpoint — 2026-09-13 UTC
OpenBao-backed Qwen3.8 testing passed coding, deterministic retry and cancellation twice each on the disposable test cluster. Full #820 qualification remains INCOMPLETE. Recorded results include the original failed attempts, successful assertions, resource identities, surviving workload image IDs, and native import observations. Complete command journals remain in private fixture storage; their hashes are included in this summary.
| Scenario | Passing runs | Observed assertion |
|---|---|---|
| Real coding | qwen-coding-3, qwen-coding-4 | Saved file independently verified by a separate read-only Pod |
| Deterministic retry | qwen-retry-1, qwen-retry-2 | Two failed Pods, one owned Job, exactly two persisted effects |
| Cancellation | qwen-cancel-2, qwen-cancel-3 | Sleep process observed; all containers terminated; owned Task/Job/Pod absent |
| Native Codex import | One offline probe | One history turn loaded; original thread identity preserved by native resume |
| Native Claude import | One offline probe | Original session identity recognized; authenticated turn NOT_RUN |
The coding model was `qwen/qwen3.8-flash`, routed through OpenRouter from the pinned Claude Code agent image. The internal OpenBao catalog's scoped reader supplied the runtime credential. No root token or new AppRole was used. The bridge read the selected KV field in memory, created the fixture Secret through stdin, and revoked its temporary Vault token. After all started Qwen workload containers terminated, the Secret was deleted using its recorded UID precondition, and absence was verified. The provider key itself was not rotated or revoked.
The fixture's helper webhook replaces upstream Git and Node helper tags with the recorded digests. Its live server-side dry-run confirmed both substitutions before workload execution. Its first version rejected the Kubernetes query-string URL; that failed admission attempt created no workloads. URL parsing was corrected.
A subsequent Task was accepted but could not acquire the controller finalizer: the Go client omitted an explicitly empty environment `value`, and the immutable spec rule rejected the update. The corrected profile omits that field at creation. This keeps the environment variable empty while preserving the controller's round-trip representation. The original blocked Task is retained in failure evidence; successful attempts use new identities.
The first cancellation probe failed at its first exec during startup. The original raw diagnostic was not retained. A later read-only probe on the same Pod successfully observed the sleep process, consistent with a startup race. The runner now waits for the agent's running container state before exec; two fresh cancellation attempts passed. Cancellation still uses the fixture-only evidence finalizer, so the uninstrumented production path is not qualified here.
Native session imports copied one existing project transcript per provider, without copying sibling login files or settings. Source transcript checksums were verified unchanged. A tracked workspace snapshot at `feacd77` was also staged; it excludes uncommitted and untracked host files. Both probes used isolated containers with networking disabled. Codex `thread/read` and `thread/resume` loaded and resumed the original thread. Claude emitted the original session ID, then exited unsuccessfully without a configured account. Recognition is not an authenticated continuation. No native conversation was sent to Qwen/OpenRouter.
The complete Kelos Session import, authenticated continuation, history continuity, Pod replacement, suspend/resume, controller restart and cleanup/PV residue checks remain outstanding. The cluster and private import copies are retained for these checks. Operator confirmation of the account source for imported Claude/Codex sessions remains pending. Infrastructure inventory/CMDB reconciliation for the retained transient fixture is not yet complete.
All 28 Python fixture tests passed locally and on the remote test host. The helper webhook's image substitutions and namespace rejection also passed local assertions; its live dry-run passed after URL handling was corrected.