Skip to content

[P0] Persist reputation source-generation uniqueness with atomic snapshot publication #192

Description

@seonghobae

Proven production defect and current implementation boundary — refreshed 2026-09-20 KST

Refs #80 #190 #191 #199 #200 #207 #208 #209 #212 #216 #217 #219 #221 #223 #224 #225 #226 #228 #229 #231 #233 #234 #236 #241 #242 #243 #244.

Test-only #191 proved a current-only generation cursor cannot enforce historical token uniqueness across transitions: an opaque source-generation token can ABA-reappear at a later ordinal. A bounded recent-token cache only delays the defect. PostgreSQL therefore remains planned production authority for historical generation identity and publication state.

Protected/default Wardnet truth remains main@f8260f1e03836039ff9463dd99fa982e4e270c4b; StateAuthority::Postgres remains disabled. Every PostgreSQL head remains Draft/unreleased until the complete dependency lineage reaches protected truth and an immutable release gate is satisfied.

Current canonical PostgreSQL lineage

Order remains:

#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244

#227/#230/#232/#235/#239/#240/#243 remain acceptance/RED or completion lanes. Parent movement requires ordinary non-force adoption and fresh exact-head evidence; predecessor checks never transfer.

The lineage is parked behind Runtime Configuration. Canonical #140 is now exact 99c7c6c798f13c9c37d00d9f586f102585ad3494, directly based on protected main@f8260f1e03836039ff9463dd99fa982e4e270c4b, mechanically mergeable and still Draft. The earlier protected-base synthesis/reconciliation lineage is integrated into this root: one immutable Runtime Configuration snapshot composes with protected credential/RBAC/public-bind semantics rather than allowing stale ambient run_from_env state to become authority. Repository-owned CI/Fuzz/SAST/Security evidence on the unchanged root is terminal GREEN; delegated CodeQL terminal settlement remains central .github#1929 ownership and is not a Wardnet source/test/SARIF RED.

Keep #193 and every descendant parked until #140 satisfies live review/governance and reaches protected truth by normal integration. Do not blind-rerun, add no-op churn, transfer predecessor GREEN, force/rebase, self/model approve, weaken gates or routinely bypass protection.

The first PostgreSQL child remains on its historical parent and its historical successes are predecessor evidence only. Current Draft tip #244 remains implementation evidence only; real PostgreSQL preflight/probe p95 and recovery evidence on that lineage must be reacquired after dependency-first non-force restack.

Draft contract already demonstrated

On real PostgreSQL 18.4 fixtures, without enabling production authority, the lineage has demonstrated durable tenant/source generation token+ordinal uniqueness under ENABLE+FORCE RLS; immutable admission and stable divergent conflicts; atomic publication history/last-known-good head; least-privilege capability roles; failure-atomic migrations and startup compatibility; externally managed ordinary runtime LOGIN mapping; transaction-local tenant binding and pooled cleanup; typed publication/read APIs with mandatory actor/decision attribution and no public raw-SQL escape; authoritative-complete reads; bounded pool replenishment/readiness; typed unknown-COMMIT outcome with no automatic replay; destructive physical backup/WAL/PITR recovery; divergent-writer serialization and byte-identical replay; half-open protocol-progress detection and selective healthy-member failover; and 200 real PostgreSQL preflight+probe samples at p95 <=20 ms on the Draft lineage.

Those receipts must be reacquired after dependency-first integration. cargo test/CI GREEN does not prove the standing 100% owned-production statement/line, branch, edge and public-rustdoc contract.

Durable aggregate contract

One authoritative PostgreSQL transaction must preserve tenant/source identity, opaque generation token, normalized generation ordinal, producer/version/tombstone identity, immutable evidence/provenance/completeness proof, exact prior publication and last-known-good head, plus attributable actor/decision audit evidence.

Database uniqueness is authoritative in both directions: one opaque token cannot bind to two ordinals and one ordinal cannot bind to two opaque tokens for one tenant/source. Exact committed replay is valid only when immutable publication identity and attribution are byte-identical; divergent replay fails deterministically.

Production repositories expose typed bounded operations, never generic raw-SQL callbacks. Partially admitted generations, partial evidence, partial publication and unaudited mutation are never current truth. Crash/cancellation/connection loss retains the prior published snapshot until complete commit. Unknown COMMIT is explicit and never converted to automatic replay or inferred success.

No explicit database lock or long-lived transaction may remain open across LLM calls, external I/O, sandbox execution or long-running computation. Read bounded state and end the transaction, perform slow work outside the transaction, then open a bounded write transaction and revalidate the required optimistic/concurrency predicate before commit. Cross-service SQL remains forbidden.

Remaining hostile acceptance / production gate

Before closure, one unchanged dependency-restacked integration candidate must prove: machine-verifiable 100% owned-production statement/branch/edge/public-rustdoc coverage; production backup/WAL retention/storage authority, encryption and key/IAM ownership without embedded long-lived secrets; production-shaped recovery objectives and destructive restore evidence; readiness/liveness/startup against the authoritative database; preserved historical uniqueness, publication completeness, actor/decision audit linkage, tenant RLS, commit ambiguity, pool bounds and no-replay semantics after restack; terminal CI/Fuzz/security/SAST/CodeQL/review/thread/package/SBOM/provenance/reproducibility/governance evidence on the same exact head; and ordinary protected integration followed by immutable Wardnet release identity binding source, artifact digest, SBOM, provenance/signature, reproducibility, rollback and recovery evidence.

StateAuthority::Postgres remains fail closed until that contract is protected truth. A Draft branch, successful cargo test, recovery fixture, p95 measurement or predecessor receipt is not production authority.

Ownership / architecture

This remains Wardnet Reputation Security Evidence state. It does not move to EgressWeave, contextual-orchestrator, quarantine-sandbox-runtime, AppGuardrail, CGC or EA Core. Keyverse may supply released authenticated tenant/subject claims; Wardnet validates action context and binds its database transaction. Principal lifecycle and backup-storage IAM remain deployment/infrastructure authority.

No source copy, cross-service SQL, mutable foreign production dependency, self/model approval, routine administrator bypass, force/destructive rebase, gate weakening, automatic replay of started database work or predecessor-evidence transfer. Generic solo-maintainer approval remains central .github#772; runner/OpenCode defects remain .github#712/#1234; delegated CodeQL settlement remains .github#1929 or verified successors.

Traceability

Activity

  1. added
    bugSomething isn't working
    enhancementNew feature or request
    area: securitySecurity boundary, hardening, or vulnerability prevention
    priority: criticalImmediate blocker, P0, urgent deadlock, or critical incident
    on Sep 8, 2026
  2. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    Fresh Wardnet owner-path progress, 2026-09-08 KST:

    This remains a bounded #80/#192 progression, not production authority. PostgreSQL selection is still fail closed, and atomic coupling to producer lifecycle, accepted evidence snapshot/completeness, last-known-good publication, concurrency/crash behavior, pooling, migrations/recovery and backup/restore remain open acceptance. No recent-token cache or foreign-owner state is introduced.

  3. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    Fresh durable-publication TDD progress — 2026-09-08 KST.

    Draft successor #207 is directly stacked on exact #20063b2731. Test-only head d8d0cd3 produced the intended real RED in CI 34237346607 / job 102098369156 after rustfmt was repaired: cargo fmt --check passed, the existing workspace tests ran, and tests/postgres_atomic_publication.rs failed specifically because migrations/0003_reputation_source_publication.sql did not exist. The test requires first commit, exact replay, exact-prior CAS, atomic generation/evidence/completeness/lifecycle/LKG publication, rollback after an evidence constraint failure, stale-prior fail-closed behavior, and one-winner/one-conflict concurrent writers against PostgreSQL 18.4 under a non-owner/non-BYPASSRLS role.

    Minimal production candidate 5761071 now adds only migration 0003 on top of that RED. It keeps production PostgreSQL selection disabled and uses SECURITY INVOKER + FORCE RLS, immutable publication history, a tenant/source LKG pointer, source-scoped transaction advisory serialization, exact replay identity, and stable reputation_source_publication_conflict CAS. Its hosted CI 34238358576 has materialized but is not yet terminal, so no GREEN is claimed.

    This remains an incremental #80/#192 slice. Pool checkout/reset hygiene, repository wiring, migration/rollback/recovery, backup/restore, and immutable release evidence remain separate acceptance; no EgressWeave/quarantine/Context Graph/EA authority is copied into Wardnet.

  4. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    Fresh hostile publication-order finding on 2026-09-08 KST. After the first atomic-publication candidate was added, review found that exact-prior CAS alone still allowed an unused but regressive ordinal to advance last-known-good authority. Test head f2ef0b0bbaa5599c9d82dbc54e3e27b71e5d643a added a real PostgreSQL 18.4 case generation-9@9 -> generation-10@8 under the non-owner/non-BYPASSRLS runtime role. CI 34238906678, rust job 102103706051, acquired ubuntu-24.04, passed checkout/format, passed the original atomic/idempotent/concurrent publication acceptance, then RED exactly because the regressive transition returned committed instead of reputation_source_publication_conflict.

    Minimal causal repair is current Draft #207 head f595bc83198b45bc99fe1d9393dcb3ee3db8a860: when a publication head exists, successor admission now requires both exact prior-generation identity and candidate_ordinal > current_head_ordinal; otherwise the same stable conflict class is raised before generation admission. Current-head CI 34240277646 is materialized but still non-terminal, so GREEN is not claimed and no predecessor result transfers. Production PostgreSQL selection remains disabled; pooling context hygiene, migration/rollback/restore and full #80 repository wiring remain open acceptance.

  5. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    Fresh privilege-boundary RED and causal repair — 2026-09-08 KST.

    After the official-image startup harness was repaired, exact 43c6396e750d27c35f0a071543e81fce4cc788f2 produced the intended hosted semantic RED in CI 34243761631, rust job 102120327373: formatting and every preceding PostgreSQL 18.4 acceptance passed, including atomic/idempotent/concurrent publication, ordinal-regression rejection, generation RLS and admission. tests/postgres_publication_privilege_boundary.rs then failed exactly because the runtime role could execute direct UPDATE reputation_source_publication_head and bypass the function's CAS/monotonicity state machine. This confirms that RLS tenant isolation alone is insufficient when a SECURITY INVOKER publication function requires underlying runtime DML grants.

    Minimal repair is current Draft #207 head 80af90273def9f72042ef378d3a74ea31b8a6de6: migration 0003 changes the publication boundary to SECURITY DEFINER with search_path = pg_catalog, pg_temp; PUBLIC execute remains revoked. The executable deployment-role acceptance provisions a dedicated NOLOGIN/NOSUPERUSER/NOBYPASSRLS state owner, transfers the publication function to it, gives that owner only the DML needed by the bounded transaction, and gives the runtime role SELECT + publication-function EXECUTE only. It asserts rolsuper=false, rolbypassrls=false, prosecdef=true, runtime INSERT/UPDATE privileges=false, successful function-mediated publication, failed direct head regression, failed direct history forgery, unchanged last-known-good head and immutable history count. Migration deliberately does not create cluster roles; production PostgreSQL selection remains disabled until #80 supplies the deployment/migration/pooling/recovery contract.

    Current-head CI 34244982960 is queued/non-terminal, so GREEN is not claimed and no predecessor receipt transfers.

  6. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    Exact-current publication slice is now GREEN and code-current. Draft #207 remains stacked on exact #20063b2731; current head is 1d45a024f7e6a0cc351eda3b9fb317ccf6e35300. The intervening post-repair delta was read/adopted non-force: CHANGELOG plus Proposed ADR docs/adr/2026-09-08-reputation-source-publication-transaction-boundary.md and its index only; migration/tests remain the least-privilege atomic-publication implementation already reviewed.

    Hosted CI 34245836806, rust job 102127456517, is terminal SUCCESS on unchanged 1d45a024...: hosted ubuntu-24.04 executed fmt, locked workspace tests against PostgreSQL 18.4, including atomic publication/CAS/rollback/concurrency/FORCE-RLS and the dedicated NOLOGIN/NOSUPERUSER/NOBYPASSRLS state-owner + least-privilege runtime boundary, then strict Clippy. Reviews 0; inline threads 0. Predecessor 80af... GREEN is retained only as history, not promoted to the documentation head.

    #207 therefore closes the bounded publication-transaction/privilege slice but does not enable production PostgreSQL authority. The next #80/#192 acceptance remains executable deployment-role provisioning plus repository/pool context hygiene, migration upgrade/rollback/recovery, backup/restore and production fail-closed readiness. In particular, deployment must prove the final state-owner/runtime grants rather than relying on the test fixture: state owner remains NOLOGIN/NOSUPERUSER/NOBYPASSRLS, runtime receives no direct publication INSERT/head UPDATE or inner-admission authority, and pooled transactions establish tenant context transaction-locally with no context surviving connection reuse.

  7. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    Exact-current follow-up — #207 is now GREEN on its documentation-bearing head. Current Draft head 1d45a024f7e6a0cc351eda3b9fb317ccf6e35300 is still based directly on #200@63b2731d7173d24fc15cc1c340fb177727d33251. Hosted CI 34245836806, rust job 102127456517, completed SUCCESS on this exact head: checkout/toolchain, cargo fmt --check, locked workspace tests including all real PostgreSQL 18.4 atomicity/concurrency/ordinal/tenant/least-privilege cases, strict Clippy and cleanup all passed.

    The slice now also carries Proposed ADR docs/adr/2026-09-08-reputation-source-publication-transaction-boundary.md and the matching Unreleased CHANGELOG entry. It does not promote PostgreSQL to production authority. Remaining #80/#192 acceptance is unchanged and explicit: deployment state-owner/runtime role installation, repository wiring, pooled-connection tenant-context checkout/reset, migration upgrade/rollback/recovery, crash/retry semantics, backup/restore survival and immutable protected release evidence. No predecessor result, self/model approval or bypass is being used.

  8. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    Exact-current deployment-role/atomicity GREEN — 2026-09-08 KST. Draft #208 remains directly stacked on #207@1d45a024f7e6a0cc351eda3b9fb317ccf6e35300; current exact head is 03af6b3c962ce7d681bd49f5a80487aa94283bc6, mergeable, with zero current review threads. Hosted CI 34248937286 / rust 102138060537 is terminal SUCCESS on that unchanged head: formatting, all locked workspace tests including real PostgreSQL 18.4 role installation/replay, least-privilege mediation and deterministic mid-flight rollback, plus strict Clippy all passed.

    The hostile predecessor 282f0fec7ff16b3aa4e1e086900970e154e4f1c0 / CI 34248558975 proved the deployment artifact was non-atomic: an injected ALTER FUNCTION failure stranded both capability roles and temporary state-owner schema CREATE. The minimal repair wraps the full installer in one PostgreSQL transaction, so role creation, grants, ownership-transfer privilege and revocations now roll back together. No production PostgreSQL selection is enabled.

    #80/#192 still require repository wiring, actual deployment principal mapping, pooled tenant-context checkout/reset, migration upgrade/rollback/recovery, crash/retry, backup/restore and protected immutable release evidence before PostgreSQL can become production authority. No predecessor receipt, self/model approval or bypass is used.

  9. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    2026-09-09 KST state-authority progression, preserving #80/#192 ownership:

    #224 does not claim the whole #192 aggregate complete. After its typed publication repository is GREEN, remaining acceptance still includes attributable audit/evidence coupling at the durable boundary, phase-specific connection-loss/cancellation rollback, authoritative reads of only complete published aggregates, backup/restore with retention/encryption/RPO/RTO, readiness/degraded evidence, protected integration and immutable release.

  10. seonghobae commented on Sep 8, 2026

    @seonghobae
    ContributorAuthor

    Current Wardnet application-repository prerequisite has advanced beyond this issue body and was re-read on exact live evidence.

    • security(state): bind external runtime principal #221 current exact e2ff0fe4055a598a5c450e7942fed2051ec21238: terminal CI 34275523673; rejects both shadow runtime-membership paths and pre-existing effective Wardnet mutation/inner-admission authority before mapping an external LOGIN.
    • test(state): require pooled transaction-local tenant context #223 current exact 0876c55fdc82927adaece4f3bb414a7a631dea68: terminal CI 34284257853 and Fuzz 34284257807; owns pooled transaction-local tenant binding, RLS isolation, physical-connection cleanup and cancellation rollback.
    • test(state): require typed PostgreSQL publication repository #224 current exact c805d83484be91a157ed8350944bf7d35d37bc7e: terminal CI 34290913936 / rust 102277031944 and Fuzz 34290913959 / 102277103330; owns the bounded typed publish_reputation_source repository call and stable Committed / Replay / PublicationConflict mapping. Real PostgreSQL 18.4 proves 8@8 -> 9@9, historical 8@10 ABA rejection, last-known-good replay, and ordinal rebound rejection.

    Fresh exact-source review confirms the next #192 acceptance boundary is not another publication wrapper. migrations/0003_reputation_source_publication.sql atomically writes generation/publication/head evidence but creates no attributable audit relation/row; PostgresTenantPool::publish_reputation_source carries no authenticated subject/audit decision identity. The existing standalone/community AppData.audit_logs model is not production PostgreSQL authority and must not be silently reused as a tenantless persistence contract. Startup schema truth is separately versioned at 4 by deploy/postgresql/reputation_state_migrate.sql, so adding audit persistence must be an explicit supported schema evolution rather than editing 0003 in place.

    Next bounded RED acceptance before production authority can advance: from exact #224 ancestry, use real PostgreSQL 18.4 and the externally managed runtime LOGIN; require a publication to commit exactly one tenant-scoped attributable audit record in the same database transaction; exact replay must not duplicate the audit record; a divergent publication or injected failure before audit completion must leave neither the candidate publication/head nor audit residue; cross-tenant/unbound audit visibility must remain default-deny; actor/decision identity must be validated parameter data and must not come from display names or ambient SQL/session text. GREEN must introduce the smallest new migration/version/role/repository contract needed for that invariant, preserve canonical 0001..0004 history, startup locking/future-schema refusal/recovery discipline and #223 transaction-local session semantics, and keep StateAuthority::Postgres disabled. No generic raw-SQL escape hatch, tenantless audit table, mutable sibling dependency, or predecessor evidence transfer.

  11. seonghobae commented on Sep 9, 2026

    @seonghobae
    ContributorAuthor

    2026-09-09 KST durable-aggregate progression: #227's complete-current-read acceptance now has an executed semantic RED and a minimum production candidate in Draft #228 on exact parent #226 da5f2b01163e9db1416bfa4162ebdb7953778fc5.

    Exact d5b8bb17e3ebc6f97a1c7c88f7c63456f617e356 reached the intended RED in CI 34303075828 / rust 102313985043: checkout/toolchain/formatting completed and locked workspace compilation failed because the typed current_reputation_source_publication contract and fail-closed IncompletePublication outcome were absent. Candidate 5d4ce5b2... added only that typed immutable read inside the existing transaction-local tenant boundary. When its CI finally acquired a hosted runner, it failed only an emitted rustfmt line wrap before tests; Wardnet repaired exactly that formatting delta at current #228 f0c42b84b16549f58a0f93d8b74d643cebba91bf.

    Current exact CI 34306473646 and Fuzz 34306473577 are queued, so GREEN is not claimed. The real PostgreSQL 18.4 fixture still requires generation 9 to remain complete current truth after generation 10 is merely admitted, typed absence for another tenant/unknown source, blank-source rejection, and IncompletePublication after required audit evidence is removed. Production PostgreSQL authority stays disabled. After this read reaches exact-head GREEN, remaining #80/#192 acceptance is repository-level divergent-writer concurrency, publication-phase crash/cancellation/connection-loss + idempotent retry, real backup/restore/RPO-RTO, readiness/degraded behavior, protected integration and immutable release.

  12. seonghobae commented on Sep 9, 2026

    @seonghobae
    ContributorAuthor

    Fresh 2026-09-09 current-state correction: exact #228 f0c42b84b16549f58a0f93d8b74d643cebba91bf now has both repository-owned CI 34306473646 and Fuzz 34306473577 terminal SUCCESS; fresh submitted reviews and inline review threads remain zero. That closes only acceptance item 9 (typed complete-current aggregate read) for the unchanged #228 slice and does not transfer through parent/protected-base movement.

    Fresh post-GREEN source review found the next bounded #192 degraded-capacity/connection-loss gap in the typed pool: PostgresTenantPool::next_connection() blindly round-robins fixed Client slots, so a driver-closed backend can continue to be selected even while another pool member is healthy. Draft test-first child #229 is stacked on exact #228. Its formatted production-unchanged head is 2810982b207663e2d97c581e88073b859c344fcc; current CI 34307833504 is queued, so no semantic RED claim is made yet. Acceptance is intentionally narrow: a member known closed before an operation must be skipped in favor of a healthy member, while Wardnet must not replay a transaction/query after it has begun or failed because commit outcome may be ambiguous. Automatic replenishment and publication-phase ambiguous-commit recovery remain later #80/#192 work.

  13. seonghobae commented on Sep 9, 2026

    @seonghobae
    ContributorAuthor

    Durable-state reliability continuation — 2026-09-09 KST

    The bounded pre-operation closed-member slice is now exact-head GREEN: Draft #229 exact 1df6e3e094d92ad8038fa6c911a7a1aaddc7a6c0 has terminal CI 34308523814 and Fuzz 34308523755, with zero submitted reviews and zero inline review threads. Its repair skips only driver-known closed fixed pool members before an operation, never replays an already-started/failed query or transaction, and fails closed with typed PoolUnavailable if all configured fixed members are closed.

    Fresh review found the next distinct production-readiness gap instead of widening the GREEN slice: those dead fixed slots are never replenished, so sequential independent backend loss permanently drains process capacity even while PostgreSQL is reachable. #230 now owns that acceptance contract. Draft test-first child #231 starts from exact #229 at production-unchanged head 1e5ebac6c3def12b6d1612f578287024c0431dc7 and requires a replacement physical backend after the first original member dies, zero leaked tenant context, survival after the second original member dies, and unchanged exactly-once publication residue.

    Current #231 CI 34309353476 / rust 102332594728 is pre-checkout queued with runner_id=0, steps=[]; this is not semantic RED. Exact evidence plus owner acceptance has been handed to .github#712 in comment 5595611551. Keep #231 Draft and production source unchanged until its real PostgreSQL fixture executes and isolates the causal missing-replenishment RED.

    After that slice, #192 still needs publication-phase crash/cancellation/connection-loss plus idempotent-retry semantics, unreliable-network/readiness behavior, divergent-writer acceptance, authoritative backup/restore with measured RPO/RTO, protected integration and immutable release. No predecessor gate transfers.

  14. seonghobae commented on Sep 9, 2026

    @seonghobae
    ContributorAuthor

    2026-09-10 current-stack supplement superseding the body's older #236/#239 tail without discarding its durable aggregate acceptance.

    Canonical Draft branch order is now #140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244.

    Newer completed branch-level acceptance since the issue body was written:

    • test(state): prove ambiguous PostgreSQL publication commit recovery #236 exact e1131c2ce1078322b48caa87b2088b1866b08626: real two-direction COMMIT ambiguity fixture; typed CommitOutcomeUnknown; exact CI 34336708591 and Fuzz 34336708581 SUCCESS; no automatic replay.
    • test(state): require physical PostgreSQL recovery drill evidence #241 exact 992d9c366c47515a121b786197c872db81957dcc: destructive PostgreSQL 18.4 base-backup + archived-WAL/PITR recovery after source destruction, manifest/missing-WAL/unreachable-target/partial-role+RLS/elevated-runtime hostile cases, controlled zero lost publication transactions and measured non-zero RTO; CI 34375192687 SUCCESS. Production backup storage/IAM/retention/encryption authority remains external/unproven.
    • test(state): prove divergent PostgreSQL writer serialization #242 exact 641d7cd4b12d174015801ce4aee8f29803f239ad: real concurrent divergent-writer acceptance proves existing PostgreSQL tenant/source serialization yields one authoritative commit and stable loser conflict without global tenant blocking; CI 34381212642 SUCCESS. No production/schema delta was needed.
    • test(state): expose established PostgreSQL blackhole stall #244 exact 198c1b47c897c4654d9494aeec33070af4549640: established-session half-open protocol liveness. Valid RED d560234... exposed reuse/slot retention after timed-out check_connection(). Minimum production repair drops a failed/desynchronized session before slot release, preserves one replacement authority, divides the 500 ms readiness budget across remaining candidates, and never replays started work. The exact head also measures 200 unexcluded preflight+probe buyer samples at p95 <=20 ms without reconnect churn. CI 34388202520 and Fuzz 34388202810 are SUCCESS; reviews/threads are zero.

    docs/product-technical-gap-baseline.md has been advanced on #130 to exact ca2057b5e83ce6dae9a54153454cb3fa6d7032e3 with this current lineage and the fresh central model-control-plane handoffs.

    StateAuthority::Postgres remains disabled. The remaining #80/#192 release boundary is protected integration/reacquisition of current-head gates for this stacked lineage, any still-unproven unreliable-network/operability semantics, production backup/WAL storage/retention/encryption/IAM plus real recovery/SLO evidence, and immutable release. Do not infer those production facts from the controlled loopback/container fixtures or predecessor branch receipts.

  15. seonghobae commented on Sep 9, 2026

    @seonghobae
    ContributorAuthor

    Current execution receipt — 2026-09-10 KST. This comment supersedes the issue body's older ... -> #236 stack endpoint; it does not rewrite or invalidate the earlier causal evidence.

    Fresh live PR reads show the PostgreSQL authority line has advanced non-force and remains Draft/unreleased:

    Current dependency order for this P0 therefore extends to #140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244. #227/#230/#232/#235/#239/#240/#243 remain acceptance issues/RED lanes rather than additional canonical branch nodes after their valid evidence was incorporated into the named successors.

    This materially advances #192 acceptance: the previously open explicit divergent-writer case is now proven on #242, and the destructive recovery case is executed on #241. Production PostgreSQL authority still remains disabled because none of these Draft heads is protected/released truth, the whole prerequisite chain must eventually be reconstructed/integrated under live governance, and the final release gate still requires one immutable protected source/artifact identity with then-live coverage/security/package/SBOM/provenance/reproducibility/rollback/operability evidence. Parent/head movement invalidates descendant evidence; no predecessor GREEN transfers.

    Do not close #192 yet. The next durable work is not another in-memory uniqueness workaround: continue from exact #244 only for a still-unproven PostgreSQL authority/operability/release invariant, while the central protected-merge governance defect remains owned by .github#772 and must not be bypassed by this stack.

  16. seonghobae commented on Sep 11, 2026

    @seonghobae
    ContributorAuthor

    2026-09-12 KST dependency-state correction. The durable reputation/publication aggregate contract is unchanged; this comment supersedes stale Runtime Configuration exact-head/conflict snapshots in the body.

    The PostgreSQL lineage remains dependency-ordered #140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244.

    Root #140 is now exact 0c678a924e3bf6ecdd248167e4289c1cbff60688 while protected/default main is f8260f1e03836039ff9463dd99fa982e4e270c4b. src/credentials.rs has already been causally reconciled with protected #155; only src/lib.rs remains a semantic conflict in reverse-direction repair #310. The remaining repair must preserve #140's immutable Runtime Configuration boundary and #155's strict admin-token/RBAC/public-bind/readiness/body/rate-limit/shutdown semantics, including blank/whitespace WAF_IDS_STATE_PATH staying in-memory/unset.

    Current #140 Noema 34620116801 and dynamic CodeQL 34620114135 are SUCCESS, but they do not substitute for fresh repository Rust/hostile-suite/coverage/rustdoc evidence after the final semantic merge. Therefore every descendant PostgreSQL receipt remains historical implementation evidence until foundation-first non-force restack and exact-head reacquisition. StateAuthority::Postgres stays fail closed.

  17. seonghobae commented on Sep 16, 2026

    @seonghobae
    ContributorAuthor

    Fresh prerequisite status correction — 2026-09-16 KST: Runtime Configuration child #430 is no longer merely queued. Fuzz 35029440921 is terminal SUCCESS. CI 35029440905 / rust job 104584220679 passed checkout/toolchain/format and established semantic RED because stale run_from_env bound public 0.0.0.0:44429 and returned success without a write-capable administrator; protected-auth helpers in credentials.rs were also reported as non-test dead code. The required repair remains the bounded src/lib.rs synthesis preserving #140 immutable Runtime Configuration together with protected #155 strict/write-capable/header-presentable administrator authority and pre-bind denial. Keep #193 and the PostgreSQL publication/state lineage parked until this foundation reaches unchanged-head GREEN; old-parent PostgreSQL receipts remain implementation evidence only.

  18. seonghobae commented on Sep 16, 2026

    @seonghobae
    ContributorAuthor

    Fresh prerequisite status correction — 2026-09-16 KST

    Runtime Configuration #140 remains exact 7d98725cc51b259b0be940385b2245758d098081; synthesis child #430 remains exact 062ea6ab787d0a1d864e429a95f7ed1642fbf37e. Its state has advanced beyond the queue status recorded above: Fuzz 35029440921 is terminal SUCCESS and CI 35029440905 / rust job 104584220679 is a semantic RED after checkout/toolchain/format. Stale run_from_env bound public 0.0.0.0:44429, printed readiness, and returned success with no write-capable administrator; the run also exposed live dead-code warnings for protected-auth primitives not consumed by current src/lib.rs.

    The minimum causal repair remains the bounded one-file src/lib.rs synthesis preserving #140 immutable non-secret Runtime Configuration plus protected #155 strict/header-presentable/write-capable administrator parsing, pre-bind require_write_auth_for_bind, readiness auth mode, constant-time authentication, management 401/403 and body/rate/flush/shutdown semantics. Keep #193 and every PostgreSQL descendant parked until this exact prerequisite is repaired and current protected-compatible GREEN evidence exists.

  19. seonghobae commented on Sep 16, 2026

    @seonghobae
    ContributorAuthor

    Status correction — 2026-09-16 KST: Runtime Configuration foundation synthesis #430 exact 062ea6ab787d0a1d864e429a95f7ed1642fbf37e has reached semantic RED, not queue-only state. Fuzz 35029440921 is SUCCESS; CI 35029440905 / rust job 104584220679 passed checkout/toolchain/format, then proved stale #140 run_from_env can bind a public listener and report readiness with no write-capable administrator. Non-test dead-code warnings for protected #155 auth helpers corroborate the missing integration. Minimum repair is the bounded #310 src/lib.rs synthesis preserving #140 Runtime Configuration plus #155 strict/write-capable/header-presentable admin parsing, pre-bind require_write_auth_for_bind, listener/readiness auth mode, constant-time matching and 401/403 management semantics. The durable-state chain remains parked until the foundation reaches unchanged-head GREEN; no predecessor-check transfer or source restack.

  20. seonghobae commented on Sep 17, 2026

    @seonghobae
    ContributorAuthor

    Fresh foundation-state correction, 2026-09-17 KST: the body’s statement that #430 remains at helper-only cc8f721... is stale. Current #430 is exact 65b887e347d47e3cd29071342c353408c3f14e4a; bounded synthesis run 35160876925 completed SUCCESS, committed the reviewed src/lib.rs composition as 0e0f01efbd6e21874c94eed987192534e234f211, and the temporary helper was removed by ordinary fast-forward. Exact-current CI 35180770661 and Fuzz 35180770659 remain QUEUED, so the Runtime Configuration foundation is not yet admissible. Keep #193 and every PostgreSQL descendant parked until current-head GREEN permits normal #430→#140 integration and non-force #140 reconciliation against protected main@f8260f1e03836039ff9463dd99fa982e4e270c4b; predecessor construction evidence does not transfer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: securitySecurity boundary, hardening, or vulnerability preventionenhancementNew feature or requestpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incident

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions