feat(rsi): persist restart-safe proof campaigns - #25
Merged
Merged
Conversation
w4ffl35
marked this pull request as ready for review
September 30, 2026 20:11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #19. Adds a versioned frozen proof-campaign manifest and PostgreSQL-backed root/arm/attempt ledger. Attempts are admitted against root and per-attempt ceilings before dispatch; leases fence coordinator recovery, and result import validates artifact and broker receipt identity before persisting decisions. The campaign schedule includes development and final confirmation cells across both arms, with distinct mutation and benchmark broker allocations under one root ceiling.
PostgreSQL now gates confirmation admission on durable development-phase completion for both arms. It closes development writes after that transition, preserves read-only replay for completed attempts, and makes phase finalization idempotent. A crash after the database phase commit rebuilds the evaluated archive view from the last valid checkpoint without restarting development or waiting for the other arm.
Recovery handles never-claimed queued jobs, imported results, and benchmark artifacts written before ledger settlement without repeating paid work. Ambiguous dispatched work stays charged and blocks proof completion. Existing v1/v2 archives remain readable.
The controller currently runs only the development phase and leaves the arm
evaluated; confirmation execution and live campaign orchestration are deferred to #20. These changes do not claim a completed proof campaign.Verification
npm run typecheck— exit 0.git diff --check— exit 0.npm test— exit 0;run-tests: all 178 file(s) passed. TAP reported 34 skipped database/S3-gated cases (9 queue tests and 25 proof-campaign tests) because the default run had no integration services configured.HEADLESSCODE_RSI_TEST_*:npx tsx --test src/rsi/__tests__/postgres-queue.test.ts src/rsi/__tests__/proof-campaign.test.ts— exit 0; 39 passed, 0 failed, 0 skipped.Security impact
Campaign admission, spend reservations, coordinator epochs, phase transitions, and result imports are authoritative in PostgreSQL. Confirmation cannot start until both arms have durably completed development. Candidate results are not accepted from archive JSON alone; queue completion checks the frozen campaign binding, artifacts, and durable broker accounting. Unknown or ambiguous dispatched usage remains reserved and cannot qualify. This PR does not run a live paid campaign or confirmation phase.
Test plan
Run
npm run typecheck,git diff --check, andnpm test. For the database path, start disposable PostgreSQL 16 and RustFS, setHEADLESSCODE_RSI_TEST_DATABASE_URL,HEADLESSCODE_RSI_TEST_S3_ENDPOINT,HEADLESSCODE_RSI_TEST_S3_ACCESS_KEY, andHEADLESSCODE_RSI_TEST_S3_SECRET_KEY, then run:The integration tests cover root budget enforcement, frozen cell identity, paired broker allocations, phase ordering, coordinator fencing, dispatch/recovery crash windows, archive recovery, artifact and receipt verification, queued-job rebind rules, selection replay, and lineage.