Skip to content

feat(rsi): persist restart-safe proof campaigns - #25

Merged
w4ffl35 merged 2 commits into
masterfrom
codex/rsi-proof-19
Sep 30, 2026
Merged

w4ffl35 merged 2 commits into
masterfrom
codex/rsi-proof-19

Conversation

@w4ffl35

@w4ffl35 w4ffl35 commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

Closes #19. Adds a versioned frozen proof-campaign manifest and PostgreSQL-backed root/arm/attempt ledger. Attempts are admitted against root and per-attempt ceilings before dispatch; leases fence coordinator recovery, and result import validates artifact and broker receipt identity before persisting decisions. The campaign schedule includes development and final confirmation cells across both arms, with distinct mutation and benchmark broker allocations under one root ceiling.

PostgreSQL now gates confirmation admission on durable development-phase completion for both arms. It closes development writes after that transition, preserves read-only replay for completed attempts, and makes phase finalization idempotent. A crash after the database phase commit rebuilds the evaluated archive view from the last valid checkpoint without restarting development or waiting for the other arm.

Recovery handles never-claimed queued jobs, imported results, and benchmark artifacts written before ledger settlement without repeating paid work. Ambiguous dispatched work stays charged and blocks proof completion. Existing v1/v2 archives remain readable.

The controller currently runs only the development phase and leaves the arm evaluated; confirmation execution and live campaign orchestration are deferred to #20. These changes do not claim a completed proof campaign.

Verification

  • npm run typecheck — exit 0.
  • git diff --check — exit 0.
  • npm test — exit 0; run-tests: all 178 file(s) passed. TAP reported 34 skipped database/S3-gated cases (9 queue tests and 25 proof-campaign tests) because the default run had no integration services configured.
  • With disposable PostgreSQL 16 and RustFS configured through HEADLESSCODE_RSI_TEST_*: npx tsx --test src/rsi/__tests__/postgres-queue.test.ts src/rsi/__tests__/proof-campaign.test.ts — exit 0; 39 passed, 0 failed, 0 skipped.
  • RustFS was removed after the integration run. No paid production provider request was made.

Security impact

Campaign admission, spend reservations, coordinator epochs, phase transitions, and result imports are authoritative in PostgreSQL. Confirmation cannot start until both arms have durably completed development. Candidate results are not accepted from archive JSON alone; queue completion checks the frozen campaign binding, artifacts, and durable broker accounting. Unknown or ambiguous dispatched usage remains reserved and cannot qualify. This PR does not run a live paid campaign or confirmation phase.

Test plan

Run npm run typecheck, git diff --check, and npm test. For the database path, start disposable PostgreSQL 16 and RustFS, set HEADLESSCODE_RSI_TEST_DATABASE_URL, HEADLESSCODE_RSI_TEST_S3_ENDPOINT, HEADLESSCODE_RSI_TEST_S3_ACCESS_KEY, and HEADLESSCODE_RSI_TEST_S3_SECRET_KEY, then run:

npx tsx --test src/rsi/__tests__/postgres-queue.test.ts src/rsi/__tests__/proof-campaign.test.ts

The integration tests cover root budget enforcement, frozen cell identity, paired broker allocations, phase ordering, coordinator fencing, dispatch/recovery crash windows, archive recovery, artifact and receipt verification, queued-job rebind rules, selection replay, and lineage.

@w4ffl35
w4ffl35 marked this pull request as ready for review September 30, 2026 20:11
@w4ffl35
w4ffl35 merged commit 7b65343 into master Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RSI proof 5/6: Make campaign lineage and budgets restart-safe

1 participant