Skip to content

fix: preserve executor refusals and bound verified warm reads - #52

Merged
b10x-bot[bot] merged 10 commits into
mainfrom
fix/github-issues-49-51
Oct 3, 2026
Merged

b10x-bot[bot] merged 10 commits into
mainfrom
fix/github-issues-49-51

Conversation

@b10x-bot

@b10x-bot b10x-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Declared service refusals now survive success-fulfillment keys and, with explicit definition authority, precede subject existence/revision checks. Opt-in provider tracking removes repeated whole-store verification from warm shared-clock batches while retaining complete verification on open.

  • Preserve the exact declared refusal and keep accepted fulfillment checks and atomic rollback.
  • Add execute_versioned and batch_versioned without changing legacy request shapes or canonical retry bytes. Saved definitions remain authoritative for committed/imported retries.
  • Add CapturePolicy::ProviderTracked, verified append suffixes, and scoped facade reads including ordered multi-subject histories. Existing constructors retain full verification.
  • SQLite-visible writes invalidate tracked observations, including old-blob tampering with an unchanged event head. Raw database-file edits bypassing SQLite are outside the explicitly selected warm policy. Every open fully verifies.

The real SQLite/public-facade release probe uses 55, 601 and 1,203 events with a clock shared by all historical batches. Baseline warm batch medians were 92.52 / 7,038.15 / 12,449.72 ms. Final integrated medians are 11.53 / 13.05 / 13.57 ms: 1.177× growth, passing the unchanged 2× assertion. Cold opening and full-history output still scale with their inputs and outputs. Consumer adoption is separate.

Provider support is pinned to Eventlog 6983cc25, bot-published on fix/er-51-capture-checkpoints. Its full gate and PostgreSQL 17.6/TLS persistence proof passed 545 tests with zero skips. This dependency commit is not merged or released; no second PR or persisted-format migration is included.

Validation: final task check passed with real PostgreSQL execution, 186 Eventlog runtime tests, 421 original ESS scenarios and 17 provider scenarios. Every prior scenario contract is unchanged. The release performance probe ran separately and passed. Independent review caught receipt-key and projection-alias defects; both original failing cases pass after correction. Source hashes, reports and governed review records are committed.

Fixes #49.
Fixes #50.
Fixes #51.

b10x-bot Bot added 10 commits October 3, 2026 16:50
Record scoped refusal fixes and the bounded-read verification dependency,
with one integration branch and one pull request as the delivery boundary.

Refs: #49, #50, #51
The executor checked success fulfillment keys on a completed refusal,
replacing its outcome and error with FulfillmentKeysMismatch. Restrict
that check to accepted outcomes while preserving exact success contracts.
Pin refusal identity, atomic rollback, retry and malformed-action behavior
in executor regressions and authored conformance scenarios.

Refs: #49
Add exact executor refusal scenarios without changing existing scenario
contracts, retain adversarial evidence, and specify the approved additive
version-selection contract. Record the unresolved SQLite cache integrity
boundary separately from the completed refusal fix.

Refs: #49, #50, #51
Add explicitly versioned execution and batch entry points so input-only
refusals can be selected before existence, revision and history reads.
Retain legacy row authority and exact historical retry bytes. Pin the
ordering, version authority and atomicity with regression and review tests.

Refs: #50
Combine the independently reviewed executor change with the approved
integration design and conformance work. Preserve the existing recorded
request encoding and row-derived legacy APIs.

Refs: #50
Add five conformance scenarios for explicit version authority, atomic
refusals, malformed input and merge preparation. Preserve every existing
scenario contract and record independent review and the green repository
gate. Record the accepted SQLite integrity boundary for remaining work.

Refs: #49, #50, #51
Retain completely verified observations behind an explicit read policy and
verify acknowledged append suffixes without revisiting prior histories.
Preserve full verification defaults and provide one-call scoped histories.

Add policy specification, exact delta and receipt regressions, and a real
SQLite shared-clock benchmark with retained red and green evidence.

Refs: #51
Pin the reviewed Eventlog capture-continuity commit and add executable
SQLite/facade integrity scenarios to the required repository gate.
Retain exact record/state assertions, source-bound evidence, and the final
release benchmark passing the shared-clock growth bound.

Complete governed acceptance for issues 49, 50 and 51. All original ESS
scenario contracts remain intact and the PostgreSQL lanes execute.
Mirror the locally verified provider ESS lane in the reusable CI workflow
and retain its exact report, generated suite and coverage inventory.
Version the additive executor and provider-tracking APIs and their issue fixes.
Keep workspace requirements and both lockfiles aligned, date the release notes,
and record the authorized release candidate and its passing full local gate.

Refs: #49, #50, #51
@b10x-bot
b10x-bot Bot merged commit 7fe81ca into main Oct 3, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

0 participants