fix: preserve executor refusals and bound verified warm reads - #52
Merged
Merged
Conversation
The executor checked success fulfillment keys on a completed refusal, replacing its outcome and error with FulfillmentKeysMismatch. Restrict that check to accepted outcomes while preserving exact success contracts. Pin refusal identity, atomic rollback, retry and malformed-action behavior in executor regressions and authored conformance scenarios. Refs: #49
Add explicitly versioned execution and batch entry points so input-only refusals can be selected before existence, revision and history reads. Retain legacy row authority and exact historical retry bytes. Pin the ordering, version authority and atomicity with regression and review tests. Refs: #50
Combine the independently reviewed executor change with the approved integration design and conformance work. Preserve the existing recorded request encoding and row-derived legacy APIs. Refs: #50
Add five conformance scenarios for explicit version authority, atomic refusals, malformed input and merge preparation. Preserve every existing scenario contract and record independent review and the green repository gate. Record the accepted SQLite integrity boundary for remaining work. Refs: #49, #50, #51
Retain completely verified observations behind an explicit read policy and verify acknowledged append suffixes without revisiting prior histories. Preserve full verification defaults and provide one-call scoped histories. Add policy specification, exact delta and receipt regressions, and a real SQLite shared-clock benchmark with retained red and green evidence. Refs: #51
Pin the reviewed Eventlog capture-continuity commit and add executable SQLite/facade integrity scenarios to the required repository gate. Retain exact record/state assertions, source-bound evidence, and the final release benchmark passing the shared-clock growth bound. Complete governed acceptance for issues 49, 50 and 51. All original ESS scenario contracts remain intact and the PostgreSQL lanes execute.
Mirror the locally verified provider ESS lane in the reusable CI workflow and retain its exact report, generated suite and coverage inventory.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Declared service refusals now survive success-fulfillment keys and, with explicit definition authority, precede subject existence/revision checks. Opt-in provider tracking removes repeated whole-store verification from warm shared-clock batches while retaining complete verification on open.
execute_versionedandbatch_versionedwithout changing legacy request shapes or canonical retry bytes. Saved definitions remain authoritative for committed/imported retries.CapturePolicy::ProviderTracked, verified append suffixes, and scoped facade reads including ordered multi-subject histories. Existing constructors retain full verification.The real SQLite/public-facade release probe uses 55, 601 and 1,203 events with a clock shared by all historical batches. Baseline warm batch medians were 92.52 / 7,038.15 / 12,449.72 ms. Final integrated medians are 11.53 / 13.05 / 13.57 ms: 1.177× growth, passing the unchanged 2× assertion. Cold opening and full-history output still scale with their inputs and outputs. Consumer adoption is separate.
Provider support is pinned to Eventlog 6983cc25, bot-published on
fix/er-51-capture-checkpoints. Its full gate and PostgreSQL 17.6/TLS persistence proof passed 545 tests with zero skips. This dependency commit is not merged or released; no second PR or persisted-format migration is included.Validation: final
task checkpassed with real PostgreSQL execution, 186 Eventlog runtime tests, 421 original ESS scenarios and 17 provider scenarios. Every prior scenario contract is unchanged. The release performance probe ran separately and passed. Independent review caught receipt-key and projection-alias defects; both original failing cases pass after correction. Source hashes, reports and governed review records are committed.Fixes #49.
Fixes #50.
Fixes #51.