Repository navigation
[P0] Persist reputation source-generation uniqueness with atomic snapshot publication #192
Description
Activity
- addedbugSomething isn't workingSomething isn't workingenhancementNew feature or requestNew feature or requestarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentImmediate blocker, P0, urgent deadlock, or critical incident
on Sep 8, 2026 seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actionsFresh Wardnet owner-path progress, 2026-09-08 KST:
- Draft security(state): persist tenant-scoped generation bindings #199 now has exact current
b23c34f6656f6c4abd0b59875894d47bd86379e6with terminal hosted CI34230257863SUCCESS. Its PostgreSQL 18.4 acceptance proves tenant-scoped historical token uniqueness, ordinal uniqueness, missing/cross-tenant fail-closed RLS, transaction-local tenant cleanup, and immutable history even when the test runtime role is deliberately granted SQL UPDATE/DELETE privileges. The latter operations expose zero rows because no mutation RLS policy exists; original provenance remains unchanged. - A review-found single-writer violation on security(state): persist tenant-scoped generation bindings #199 was repaired at
e0e0cbb75ce5f2f39f501bf4d145755965b983ea: the competingdocs/product-technical-gap-baseline.mdwas removed, leaving docs(gaps): add exact-head readiness baseline #130 as the sole commercial ledger writer. security(state): persist tenant-scoped generation bindings #199 now changes only CHANGELOG, migration 0001, and its PostgreSQL acceptance. - Draft successor security(state): define idempotent generation admission #200 is now the deliberate next RED directly on security(state): persist tenant-scoped generation bindings #199. Exact
b27ae591d52375aec1e00958742341e3ddaf90faadds only a real PostgreSQL acceptance for a defined generation-admission boundary: first bindingcommitted; exact immutable replayreplay; divergent provenance/token rebinding and occupied-ordinal rebinding must fail with stable conflict classes and leave history unchanged. Production is unchanged and the required migration 0002 is intentionally absent at the RED head. CI34231630231has materialized and is currently queued; predecessor GREEN is not transferred.
This remains a bounded #80/#192 progression, not production authority. PostgreSQL selection is still fail closed, and atomic coupling to producer lifecycle, accepted evidence snapshot/completeness, last-known-good publication, concurrency/crash behavior, pooling, migrations/recovery and backup/restore remain open acceptance. No recent-token cache or foreign-owner state is introduced.
- Draft security(state): persist tenant-scoped generation bindings #199 now has exact current
seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actionsFresh durable-publication TDD progress — 2026-09-08 KST.
Draft successor #207 is directly stacked on exact #20063b2731. Test-only head d8d0cd3 produced the intended real RED in CI 34237346607 / job 102098369156 after rustfmt was repaired:
cargo fmt --checkpassed, the existing workspace tests ran, andtests/postgres_atomic_publication.rsfailed specifically becausemigrations/0003_reputation_source_publication.sqldid not exist. The test requires first commit, exact replay, exact-prior CAS, atomic generation/evidence/completeness/lifecycle/LKG publication, rollback after an evidence constraint failure, stale-prior fail-closed behavior, and one-winner/one-conflict concurrent writers against PostgreSQL 18.4 under a non-owner/non-BYPASSRLS role.Minimal production candidate 5761071 now adds only migration 0003 on top of that RED. It keeps production PostgreSQL selection disabled and uses SECURITY INVOKER + FORCE RLS, immutable publication history, a tenant/source LKG pointer, source-scoped transaction advisory serialization, exact replay identity, and stable
reputation_source_publication_conflictCAS. Its hosted CI 34238358576 has materialized but is not yet terminal, so no GREEN is claimed.This remains an incremental #80/#192 slice. Pool checkout/reset hygiene, repository wiring, migration/rollback/recovery, backup/restore, and immutable release evidence remain separate acceptance; no EgressWeave/quarantine/Context Graph/EA authority is copied into Wardnet.
seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actionsFresh hostile publication-order finding on 2026-09-08 KST. After the first atomic-publication candidate was added, review found that exact-prior CAS alone still allowed an unused but regressive ordinal to advance last-known-good authority. Test head
f2ef0b0bbaa5599c9d82dbc54e3e27b71e5d643aadded a real PostgreSQL 18.4 casegeneration-9@9 -> generation-10@8under the non-owner/non-BYPASSRLSruntime role. CI34238906678, rust job102103706051, acquiredubuntu-24.04, passed checkout/format, passed the original atomic/idempotent/concurrent publication acceptance, then RED exactly because the regressive transition returnedcommittedinstead ofreputation_source_publication_conflict.Minimal causal repair is current Draft #207 head
f595bc83198b45bc99fe1d9393dcb3ee3db8a860: when a publication head exists, successor admission now requires both exact prior-generation identity andcandidate_ordinal > current_head_ordinal; otherwise the same stable conflict class is raised before generation admission. Current-head CI34240277646is materialized but still non-terminal, so GREEN is not claimed and no predecessor result transfers. Production PostgreSQL selection remains disabled; pooling context hygiene, migration/rollback/restore and full #80 repository wiring remain open acceptance.seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actionsFresh privilege-boundary RED and causal repair — 2026-09-08 KST.
After the official-image startup harness was repaired, exact
43c6396e750d27c35f0a071543e81fce4cc788f2produced the intended hosted semantic RED in CI34243761631, rust job102120327373: formatting and every preceding PostgreSQL 18.4 acceptance passed, including atomic/idempotent/concurrent publication, ordinal-regression rejection, generation RLS and admission.tests/postgres_publication_privilege_boundary.rsthen failed exactly because the runtime role could execute directUPDATE reputation_source_publication_headand bypass the function's CAS/monotonicity state machine. This confirms that RLS tenant isolation alone is insufficient when a SECURITY INVOKER publication function requires underlying runtime DML grants.Minimal repair is current Draft #207 head
80af90273def9f72042ef378d3a74ea31b8a6de6: migration 0003 changes the publication boundary to SECURITY DEFINER withsearch_path = pg_catalog, pg_temp; PUBLIC execute remains revoked. The executable deployment-role acceptance provisions a dedicated NOLOGIN/NOSUPERUSER/NOBYPASSRLS state owner, transfers the publication function to it, gives that owner only the DML needed by the bounded transaction, and gives the runtime role SELECT + publication-function EXECUTE only. It assertsrolsuper=false,rolbypassrls=false,prosecdef=true, runtime INSERT/UPDATE privileges=false, successful function-mediated publication, failed direct head regression, failed direct history forgery, unchanged last-known-good head and immutable history count. Migration deliberately does not create cluster roles; production PostgreSQL selection remains disabled until #80 supplies the deployment/migration/pooling/recovery contract.Current-head CI
34244982960is queued/non-terminal, so GREEN is not claimed and no predecessor receipt transfers.seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actionsExact-current publication slice is now GREEN and code-current. Draft #207 remains stacked on exact #20063b2731; current head is
1d45a024f7e6a0cc351eda3b9fb317ccf6e35300. The intervening post-repair delta was read/adopted non-force: CHANGELOG plus Proposed ADRdocs/adr/2026-09-08-reputation-source-publication-transaction-boundary.mdand its index only; migration/tests remain the least-privilege atomic-publication implementation already reviewed.Hosted CI
34245836806, rust job102127456517, is terminal SUCCESS on unchanged1d45a024...: hostedubuntu-24.04executed fmt, locked workspace tests against PostgreSQL 18.4, including atomic publication/CAS/rollback/concurrency/FORCE-RLS and the dedicated NOLOGIN/NOSUPERUSER/NOBYPASSRLS state-owner + least-privilege runtime boundary, then strict Clippy. Reviews 0; inline threads 0. Predecessor80af...GREEN is retained only as history, not promoted to the documentation head.#207 therefore closes the bounded publication-transaction/privilege slice but does not enable production PostgreSQL authority. The next #80/#192 acceptance remains executable deployment-role provisioning plus repository/pool context hygiene, migration upgrade/rollback/recovery, backup/restore and production fail-closed readiness. In particular, deployment must prove the final state-owner/runtime grants rather than relying on the test fixture: state owner remains NOLOGIN/NOSUPERUSER/NOBYPASSRLS, runtime receives no direct publication INSERT/head UPDATE or inner-admission authority, and pooled transactions establish tenant context transaction-locally with no context surviving connection reuse.
seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actionsExact-current follow-up — #207 is now GREEN on its documentation-bearing head. Current Draft head
1d45a024f7e6a0cc351eda3b9fb317ccf6e35300is still based directly on #200@63b2731d7173d24fc15cc1c340fb177727d33251. Hosted CI34245836806, rust job102127456517, completed SUCCESS on this exact head: checkout/toolchain,cargo fmt --check, locked workspace tests including all real PostgreSQL 18.4 atomicity/concurrency/ordinal/tenant/least-privilege cases, strict Clippy and cleanup all passed.The slice now also carries Proposed ADR
docs/adr/2026-09-08-reputation-source-publication-transaction-boundary.mdand the matching Unreleased CHANGELOG entry. It does not promote PostgreSQL to production authority. Remaining #80/#192 acceptance is unchanged and explicit: deployment state-owner/runtime role installation, repository wiring, pooled-connection tenant-context checkout/reset, migration upgrade/rollback/recovery, crash/retry semantics, backup/restore survival and immutable protected release evidence. No predecessor result, self/model approval or bypass is being used.seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actionsExact-current deployment-role/atomicity GREEN — 2026-09-08 KST. Draft #208 remains directly stacked on #207@
1d45a024f7e6a0cc351eda3b9fb317ccf6e35300; current exact head is03af6b3c962ce7d681bd49f5a80487aa94283bc6, mergeable, with zero current review threads. Hosted CI34248937286/ rust102138060537is terminal SUCCESS on that unchanged head: formatting, all locked workspace tests including real PostgreSQL 18.4 role installation/replay, least-privilege mediation and deterministic mid-flight rollback, plus strict Clippy all passed.The hostile predecessor
282f0fec7ff16b3aa4e1e086900970e154e4f1c0/ CI34248558975proved the deployment artifact was non-atomic: an injectedALTER FUNCTIONfailure stranded both capability roles and temporary state-owner schema CREATE. The minimal repair wraps the full installer in one PostgreSQL transaction, so role creation, grants, ownership-transfer privilege and revocations now roll back together. No production PostgreSQL selection is enabled.#80/#192 still require repository wiring, actual deployment principal mapping, pooled tenant-context checkout/reset, migration upgrade/rollback/recovery, crash/retry, backup/restore and protected immutable release evidence before PostgreSQL can become production authority. No predecessor receipt, self/model approval or bypass is used.
seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actions2026-09-09 KST state-authority progression, preserving #80/#192 ownership:
- test(state): require pooled transaction-local tenant context #223 is now exact
0876c55fdc82927adaece4f3bb414a7a631dea68, Draft on security(state): bind external runtime principal #221@e2ff0fe4055a598a5c450e7942fed2051ec21238. Hosted CI34284257853/ rust102256023876and Fuzz34284257807/ job102256114065are terminal SUCCESS. The session boundary binds tenant identity transaction-locally, cleans pooled connections across commit/error/cancellation, and now also rejects non-loopback PostgreSQLhostaddrbefore the test-only NoTls connector can perform remote I/O. Production PostgreSQL state authority remains disabled. - The next bounded typed application-repository child is test(state): require typed PostgreSQL publication repository #224, exact test-only
38ff51a63e7fab153a0b1ca411265a45ec17ce35on that test(state): require pooled transaction-local tenant context #223 head. Its PostgreSQL 18.4 hostile contract requires typedgeneration-8@8 -> generation-9@9, stable rejection of historical token ABAgeneration-8@10, preservation/replay of generation 9 after the failed ABA, and rejection of a different token rebound to ordinal 9. It intentionally requires callers not to construct SQL or parse PostgreSQL error strings.
#224 does not claim the whole #192 aggregate complete. After its typed publication repository is GREEN, remaining acceptance still includes attributable audit/evidence coupling at the durable boundary, phase-specific connection-loss/cancellation rollback, authoritative reads of only complete published aggregates, backup/restore with retention/encryption/RPO/RTO, readiness/degraded evidence, protected integration and immutable release.
- test(state): require pooled transaction-local tenant context #223 is now exact
seonghobae commented
on Sep 8, 2026 ContributorAuthorMore actionsCurrent Wardnet application-repository prerequisite has advanced beyond this issue body and was re-read on exact live evidence.
- security(state): bind external runtime principal #221 current exact
e2ff0fe4055a598a5c450e7942fed2051ec21238: terminal CI34275523673; rejects both shadow runtime-membership paths and pre-existing effective Wardnet mutation/inner-admission authority before mapping an external LOGIN. - test(state): require pooled transaction-local tenant context #223 current exact
0876c55fdc82927adaece4f3bb414a7a631dea68: terminal CI34284257853and Fuzz34284257807; owns pooled transaction-local tenant binding, RLS isolation, physical-connection cleanup and cancellation rollback. - test(state): require typed PostgreSQL publication repository #224 current exact
c805d83484be91a157ed8350944bf7d35d37bc7e: terminal CI34290913936/ rust102277031944and Fuzz34290913959/102277103330; owns the bounded typedpublish_reputation_sourcerepository call and stableCommitted/Replay/PublicationConflictmapping. Real PostgreSQL 18.4 proves8@8 -> 9@9, historical8@10ABA rejection, last-known-good replay, and ordinal rebound rejection.
Fresh exact-source review confirms the next #192 acceptance boundary is not another publication wrapper.
migrations/0003_reputation_source_publication.sqlatomically writes generation/publication/head evidence but creates no attributable audit relation/row;PostgresTenantPool::publish_reputation_sourcecarries no authenticated subject/audit decision identity. The existing standalone/communityAppData.audit_logsmodel is not production PostgreSQL authority and must not be silently reused as a tenantless persistence contract. Startup schema truth is separately versioned at 4 bydeploy/postgresql/reputation_state_migrate.sql, so adding audit persistence must be an explicit supported schema evolution rather than editing 0003 in place.Next bounded RED acceptance before production authority can advance: from exact #224 ancestry, use real PostgreSQL 18.4 and the externally managed runtime LOGIN; require a publication to commit exactly one tenant-scoped attributable audit record in the same database transaction; exact replay must not duplicate the audit record; a divergent publication or injected failure before audit completion must leave neither the candidate publication/head nor audit residue; cross-tenant/unbound audit visibility must remain default-deny; actor/decision identity must be validated parameter data and must not come from display names or ambient SQL/session text. GREEN must introduce the smallest new migration/version/role/repository contract needed for that invariant, preserve canonical 0001..0004 history, startup locking/future-schema refusal/recovery discipline and #223 transaction-local session semantics, and keep
StateAuthority::Postgresdisabled. No generic raw-SQL escape hatch, tenantless audit table, mutable sibling dependency, or predecessor evidence transfer.- security(state): bind external runtime principal #221 current exact
seonghobae commented
on Sep 9, 2026 ContributorAuthorMore actions2026-09-09 KST durable-aggregate progression: #227's complete-current-read acceptance now has an executed semantic RED and a minimum production candidate in Draft #228 on exact parent #226
da5f2b01163e9db1416bfa4162ebdb7953778fc5.Exact
d5b8bb17e3ebc6f97a1c7c88f7c63456f617e356reached the intended RED in CI34303075828/ rust102313985043: checkout/toolchain/formatting completed and locked workspace compilation failed because the typedcurrent_reputation_source_publicationcontract and fail-closedIncompletePublicationoutcome were absent. Candidate5d4ce5b2...added only that typed immutable read inside the existing transaction-local tenant boundary. When its CI finally acquired a hosted runner, it failed only an emitted rustfmt line wrap before tests; Wardnet repaired exactly that formatting delta at current #228f0c42b84b16549f58a0f93d8b74d643cebba91bf.Current exact CI
34306473646and Fuzz34306473577are queued, so GREEN is not claimed. The real PostgreSQL 18.4 fixture still requires generation 9 to remain complete current truth after generation 10 is merely admitted, typed absence for another tenant/unknown source, blank-source rejection, andIncompletePublicationafter required audit evidence is removed. Production PostgreSQL authority stays disabled. After this read reaches exact-head GREEN, remaining #80/#192 acceptance is repository-level divergent-writer concurrency, publication-phase crash/cancellation/connection-loss + idempotent retry, real backup/restore/RPO-RTO, readiness/degraded behavior, protected integration and immutable release.seonghobae commented
on Sep 9, 2026 ContributorAuthorMore actionsFresh 2026-09-09 current-state correction: exact #228
f0c42b84b16549f58a0f93d8b74d643cebba91bfnow has both repository-owned CI34306473646and Fuzz34306473577terminal SUCCESS; fresh submitted reviews and inline review threads remain zero. That closes only acceptance item 9 (typed complete-current aggregate read) for the unchanged #228 slice and does not transfer through parent/protected-base movement.Fresh post-GREEN source review found the next bounded #192 degraded-capacity/connection-loss gap in the typed pool:
PostgresTenantPool::next_connection()blindly round-robins fixedClientslots, so a driver-closed backend can continue to be selected even while another pool member is healthy. Draft test-first child #229 is stacked on exact #228. Its formatted production-unchanged head is2810982b207663e2d97c581e88073b859c344fcc; current CI34307833504is queued, so no semantic RED claim is made yet. Acceptance is intentionally narrow: a member known closed before an operation must be skipped in favor of a healthy member, while Wardnet must not replay a transaction/query after it has begun or failed because commit outcome may be ambiguous. Automatic replenishment and publication-phase ambiguous-commit recovery remain later #80/#192 work.seonghobae commented
on Sep 9, 2026 ContributorAuthorMore actionsDurable-state reliability continuation — 2026-09-09 KST
The bounded pre-operation closed-member slice is now exact-head GREEN: Draft #229 exact
1df6e3e094d92ad8038fa6c911a7a1aaddc7a6c0has terminal CI34308523814and Fuzz34308523755, with zero submitted reviews and zero inline review threads. Its repair skips only driver-known closed fixed pool members before an operation, never replays an already-started/failed query or transaction, and fails closed with typedPoolUnavailableif all configured fixed members are closed.Fresh review found the next distinct production-readiness gap instead of widening the GREEN slice: those dead fixed slots are never replenished, so sequential independent backend loss permanently drains process capacity even while PostgreSQL is reachable. #230 now owns that acceptance contract. Draft test-first child #231 starts from exact #229 at production-unchanged head
1e5ebac6c3def12b6d1612f578287024c0431dc7and requires a replacement physical backend after the first original member dies, zero leaked tenant context, survival after the second original member dies, and unchanged exactly-once publication residue.Current #231 CI
34309353476/ rust102332594728is pre-checkout queued withrunner_id=0,steps=[]; this is not semantic RED. Exact evidence plus owner acceptance has been handed to.github#712in comment5595611551. Keep #231 Draft and production source unchanged until its real PostgreSQL fixture executes and isolates the causal missing-replenishment RED.After that slice, #192 still needs publication-phase crash/cancellation/connection-loss plus idempotent-retry semantics, unreliable-network/readiness behavior, divergent-writer acceptance, authoritative backup/restore with measured RPO/RTO, protected integration and immutable release. No predecessor gate transfers.
seonghobae commented
on Sep 9, 2026 ContributorAuthorMore actions2026-09-10 current-stack supplement superseding the body's older #236/#239 tail without discarding its durable aggregate acceptance.
Canonical Draft branch order is now
#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244.Newer completed branch-level acceptance since the issue body was written:
- test(state): prove ambiguous PostgreSQL publication commit recovery #236 exact
e1131c2ce1078322b48caa87b2088b1866b08626: real two-direction COMMIT ambiguity fixture; typedCommitOutcomeUnknown; exact CI34336708591and Fuzz34336708581SUCCESS; no automatic replay. - test(state): require physical PostgreSQL recovery drill evidence #241 exact
992d9c366c47515a121b786197c872db81957dcc: destructive PostgreSQL 18.4 base-backup + archived-WAL/PITR recovery after source destruction, manifest/missing-WAL/unreachable-target/partial-role+RLS/elevated-runtime hostile cases, controlled zero lost publication transactions and measured non-zero RTO; CI34375192687SUCCESS. Production backup storage/IAM/retention/encryption authority remains external/unproven. - test(state): prove divergent PostgreSQL writer serialization #242 exact
641d7cd4b12d174015801ce4aee8f29803f239ad: real concurrent divergent-writer acceptance proves existing PostgreSQL tenant/source serialization yields one authoritative commit and stable loser conflict without global tenant blocking; CI34381212642SUCCESS. No production/schema delta was needed. - test(state): expose established PostgreSQL blackhole stall #244 exact
198c1b47c897c4654d9494aeec33070af4549640: established-session half-open protocol liveness. Valid REDd560234...exposed reuse/slot retention after timed-outcheck_connection(). Minimum production repair drops a failed/desynchronized session before slot release, preserves one replacement authority, divides the 500 ms readiness budget across remaining candidates, and never replays started work. The exact head also measures 200 unexcluded preflight+probe buyer samples at p95<=20 mswithout reconnect churn. CI34388202520and Fuzz34388202810are SUCCESS; reviews/threads are zero.
docs/product-technical-gap-baseline.mdhas been advanced on #130 to exactca2057b5e83ce6dae9a54153454cb3fa6d7032e3with this current lineage and the fresh central model-control-plane handoffs.StateAuthority::Postgresremains disabled. The remaining #80/#192 release boundary is protected integration/reacquisition of current-head gates for this stacked lineage, any still-unproven unreliable-network/operability semantics, production backup/WAL storage/retention/encryption/IAM plus real recovery/SLO evidence, and immutable release. Do not infer those production facts from the controlled loopback/container fixtures or predecessor branch receipts.- test(state): prove ambiguous PostgreSQL publication commit recovery #236 exact
seonghobae commented
on Sep 9, 2026 ContributorAuthorMore actionsCurrent execution receipt — 2026-09-10 KST. This comment supersedes the issue body's older
... -> #236stack endpoint; it does not rewrite or invalidate the earlier causal evidence.Fresh live PR reads show the PostgreSQL authority line has advanced non-force and remains Draft/unreleased:
- test(state): prove ambiguous PostgreSQL publication commit recovery #236 exact
e1131c2ce1078322b48caa87b2088b1866b08626is the canonical ambiguous-COMMIT repair, directly based on fix(state): bound PostgreSQL reconnect readiness and slot ownership #234. Exact CI34336708591and Fuzz34336708581are terminal SUCCESS. Its production change remains the typedCommitOutcomeUnknownclassification only; no automatic replay. - test(state): require physical PostgreSQL recovery drill evidence #241 exact
992d9c366c47515a121b786197c872db81957dccis the direct child of test(state): prove ambiguous PostgreSQL publication commit recovery #236 and now owns the destructive PostgreSQL 18.4 physical base-backup/WAL/PITR recovery acceptance that issue [P0] Prove PostgreSQL backup/restore preserves security evidence authority and measured RPO/RTO #239 specified. Exact CI34375192687is terminal SUCCESS, including the destructive recovery drill and unsafe-role mapping guard. This proves the controlled recovery fixture only; it does not manufacture production RPO/RTO, storage-provider, encryption-key, or IAM authority. - test(state): prove divergent PostgreSQL writer serialization #242 exact
641d7cd4b12d174015801ce4aee8f29803f239adis the direct child of test(state): require physical PostgreSQL recovery drill evidence #241 and closes the previously explicit repository-level divergent-writer acceptance. Exact CI34381212642is terminal SUCCESS on realpostgres:18.4-bookworm: divergent races settle as oneCommittedplus one stablePublicationConflict, byte-identical duplicates as oneCommittedplus oneReplay, and tenant/source serialization does not become a global writer lock. No production code/schema change was needed. - test(state): expose established PostgreSQL blackhole stall #244 exact
198c1b47c897c4654d9494aeec33070af4549640is the direct child of test(state): prove divergent PostgreSQL writer serialization #242 and closes a further established-session liveness defect found by real protocol blackholing. Exact CI34388202520and Fuzz34388202810are terminal SUCCESS. The causal pool repair retires a timed-out/desynchronised client before slot reuse, bounds replacement authority per slot, and shares the fixed readiness window across candidates without replaying started DB work. The same exact head measures 200 unexcluded real buyer-path samples through PostgreSQL preflight + probe query with p95 <=20 ms while retaining exactly the original two runtime sessions.
Current dependency order for this P0 therefore extends to
#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244. #227/#230/#232/#235/#239/#240/#243 remain acceptance issues/RED lanes rather than additional canonical branch nodes after their valid evidence was incorporated into the named successors.This materially advances #192 acceptance: the previously open explicit divergent-writer case is now proven on #242, and the destructive recovery case is executed on #241. Production PostgreSQL authority still remains disabled because none of these Draft heads is protected/released truth, the whole prerequisite chain must eventually be reconstructed/integrated under live governance, and the final release gate still requires one immutable protected source/artifact identity with then-live coverage/security/package/SBOM/provenance/reproducibility/rollback/operability evidence. Parent/head movement invalidates descendant evidence; no predecessor GREEN transfers.
Do not close #192 yet. The next durable work is not another in-memory uniqueness workaround: continue from exact #244 only for a still-unproven PostgreSQL authority/operability/release invariant, while the central protected-merge governance defect remains owned by
.github#772and must not be bypassed by this stack.- test(state): prove ambiguous PostgreSQL publication commit recovery #236 exact
seonghobae commented
on Sep 11, 2026 ContributorAuthorMore actions2026-09-12 KST dependency-state correction. The durable reputation/publication aggregate contract is unchanged; this comment supersedes stale Runtime Configuration exact-head/conflict snapshots in the body.
The PostgreSQL lineage remains dependency-ordered
#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244.Root #140 is now exact
0c678a924e3bf6ecdd248167e4289c1cbff60688while protected/default main isf8260f1e03836039ff9463dd99fa982e4e270c4b.src/credentials.rshas already been causally reconciled with protected #155; onlysrc/lib.rsremains a semantic conflict in reverse-direction repair #310. The remaining repair must preserve #140's immutable Runtime Configuration boundary and #155's strict admin-token/RBAC/public-bind/readiness/body/rate-limit/shutdown semantics, including blank/whitespaceWAF_IDS_STATE_PATHstaying in-memory/unset.Current #140 Noema
34620116801and dynamic CodeQL34620114135are SUCCESS, but they do not substitute for fresh repository Rust/hostile-suite/coverage/rustdoc evidence after the final semantic merge. Therefore every descendant PostgreSQL receipt remains historical implementation evidence until foundation-first non-force restack and exact-head reacquisition.StateAuthority::Postgresstays fail closed.seonghobae commented
on Sep 16, 2026 ContributorAuthorMore actionsFresh prerequisite status correction — 2026-09-16 KST: Runtime Configuration child #430 is no longer merely queued. Fuzz
35029440921is terminal SUCCESS. CI35029440905/ rust job104584220679passed checkout/toolchain/format and established semantic RED because stalerun_from_envbound public0.0.0.0:44429and returned success without a write-capable administrator; protected-auth helpers incredentials.rswere also reported as non-test dead code. The required repair remains the boundedsrc/lib.rssynthesis preserving #140 immutable Runtime Configuration together with protected #155 strict/write-capable/header-presentable administrator authority and pre-bind denial. Keep #193 and the PostgreSQL publication/state lineage parked until this foundation reaches unchanged-head GREEN; old-parent PostgreSQL receipts remain implementation evidence only.seonghobae commented
on Sep 16, 2026 ContributorAuthorMore actionsFresh prerequisite status correction — 2026-09-16 KST
Runtime Configuration #140 remains exact
7d98725cc51b259b0be940385b2245758d098081; synthesis child #430 remains exact062ea6ab787d0a1d864e429a95f7ed1642fbf37e. Its state has advanced beyond the queue status recorded above: Fuzz35029440921is terminal SUCCESS and CI35029440905/ rust job104584220679is a semantic RED after checkout/toolchain/format. Stalerun_from_envbound public0.0.0.0:44429, printed readiness, and returned success with no write-capable administrator; the run also exposed live dead-code warnings for protected-auth primitives not consumed by currentsrc/lib.rs.The minimum causal repair remains the bounded one-file
src/lib.rssynthesis preserving #140 immutable non-secret Runtime Configuration plus protected #155 strict/header-presentable/write-capable administrator parsing, pre-bindrequire_write_auth_for_bind, readiness auth mode, constant-time authentication, management 401/403 and body/rate/flush/shutdown semantics. Keep #193 and every PostgreSQL descendant parked until this exact prerequisite is repaired and current protected-compatible GREEN evidence exists.seonghobae commented
on Sep 16, 2026 ContributorAuthorMore actionsStatus correction — 2026-09-16 KST: Runtime Configuration foundation synthesis #430 exact
062ea6ab787d0a1d864e429a95f7ed1642fbf37ehas reached semantic RED, not queue-only state. Fuzz35029440921is SUCCESS; CI35029440905/ rust job104584220679passed checkout/toolchain/format, then proved stale #140run_from_envcan bind a public listener and report readiness with no write-capable administrator. Non-test dead-code warnings for protected #155 auth helpers corroborate the missing integration. Minimum repair is the bounded #310src/lib.rssynthesis preserving #140 Runtime Configuration plus #155 strict/write-capable/header-presentable admin parsing, pre-bindrequire_write_auth_for_bind, listener/readiness auth mode, constant-time matching and 401/403 management semantics. The durable-state chain remains parked until the foundation reaches unchanged-head GREEN; no predecessor-check transfer or source restack.seonghobae commented
on Sep 17, 2026 ContributorAuthorMore actionsFresh foundation-state correction, 2026-09-17 KST: the body’s statement that #430 remains at helper-only
cc8f721...is stale. Current #430 is exact65b887e347d47e3cd29071342c353408c3f14e4a; bounded synthesis run35160876925completed SUCCESS, committed the reviewedsrc/lib.rscomposition as0e0f01efbd6e21874c94eed987192534e234f211, and the temporary helper was removed by ordinary fast-forward. Exact-current CI35180770661and Fuzz35180770659remain QUEUED, so the Runtime Configuration foundation is not yet admissible. Keep #193 and every PostgreSQL descendant parked until current-head GREEN permits normal #430→#140 integration and non-force #140 reconciliation against protectedmain@f8260f1e03836039ff9463dd99fa982e4e270c4b; predecessor construction evidence does not transfer.
Proven production defect and current implementation boundary — refreshed 2026-09-20 KST
Refs #80 #190 #191 #199 #200 #207 #208 #209 #212 #216 #217 #219 #221 #223 #224 #225 #226 #228 #229 #231 #233 #234 #236 #241 #242 #243 #244.
Test-only #191 proved a current-only generation cursor cannot enforce historical token uniqueness across transitions: an opaque source-generation token can ABA-reappear at a later ordinal. A bounded recent-token cache only delays the defect. PostgreSQL therefore remains planned production authority for historical generation identity and publication state.
Protected/default Wardnet truth remains
main@f8260f1e03836039ff9463dd99fa982e4e270c4b;StateAuthority::Postgresremains disabled. Every PostgreSQL head remains Draft/unreleased until the complete dependency lineage reaches protected truth and an immutable release gate is satisfied.Current canonical PostgreSQL lineage
Order remains:
#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244#227/#230/#232/#235/#239/#240/#243 remain acceptance/RED or completion lanes. Parent movement requires ordinary non-force adoption and fresh exact-head evidence; predecessor checks never transfer.
The lineage is parked behind Runtime Configuration. Canonical #140 is now exact
99c7c6c798f13c9c37d00d9f586f102585ad3494, directly based on protectedmain@f8260f1e03836039ff9463dd99fa982e4e270c4b, mechanically mergeable and still Draft. The earlier protected-base synthesis/reconciliation lineage is integrated into this root: one immutable Runtime Configuration snapshot composes with protected credential/RBAC/public-bind semantics rather than allowing stale ambientrun_from_envstate to become authority. Repository-owned CI/Fuzz/SAST/Security evidence on the unchanged root is terminal GREEN; delegated CodeQL terminal settlement remains central.github#1929ownership and is not a Wardnet source/test/SARIF RED.Keep #193 and every descendant parked until #140 satisfies live review/governance and reaches protected truth by normal integration. Do not blind-rerun, add no-op churn, transfer predecessor GREEN, force/rebase, self/model approve, weaken gates or routinely bypass protection.
The first PostgreSQL child remains on its historical parent and its historical successes are predecessor evidence only. Current Draft tip #244 remains implementation evidence only; real PostgreSQL preflight/probe p95 and recovery evidence on that lineage must be reacquired after dependency-first non-force restack.
Draft contract already demonstrated
On real PostgreSQL 18.4 fixtures, without enabling production authority, the lineage has demonstrated durable tenant/source generation token+ordinal uniqueness under ENABLE+FORCE RLS; immutable admission and stable divergent conflicts; atomic publication history/last-known-good head; least-privilege capability roles; failure-atomic migrations and startup compatibility; externally managed ordinary runtime LOGIN mapping; transaction-local tenant binding and pooled cleanup; typed publication/read APIs with mandatory actor/decision attribution and no public raw-SQL escape; authoritative-complete reads; bounded pool replenishment/readiness; typed unknown-COMMIT outcome with no automatic replay; destructive physical backup/WAL/PITR recovery; divergent-writer serialization and byte-identical replay; half-open protocol-progress detection and selective healthy-member failover; and 200 real PostgreSQL preflight+probe samples at p95
<=20 mson the Draft lineage.Those receipts must be reacquired after dependency-first integration.
cargo test/CI GREEN does not prove the standing 100% owned-production statement/line, branch, edge and public-rustdoc contract.Durable aggregate contract
One authoritative PostgreSQL transaction must preserve tenant/source identity, opaque generation token, normalized generation ordinal, producer/version/tombstone identity, immutable evidence/provenance/completeness proof, exact prior publication and last-known-good head, plus attributable actor/decision audit evidence.
Database uniqueness is authoritative in both directions: one opaque token cannot bind to two ordinals and one ordinal cannot bind to two opaque tokens for one tenant/source. Exact committed replay is valid only when immutable publication identity and attribution are byte-identical; divergent replay fails deterministically.
Production repositories expose typed bounded operations, never generic raw-SQL callbacks. Partially admitted generations, partial evidence, partial publication and unaudited mutation are never current truth. Crash/cancellation/connection loss retains the prior published snapshot until complete commit. Unknown COMMIT is explicit and never converted to automatic replay or inferred success.
No explicit database lock or long-lived transaction may remain open across LLM calls, external I/O, sandbox execution or long-running computation. Read bounded state and end the transaction, perform slow work outside the transaction, then open a bounded write transaction and revalidate the required optimistic/concurrency predicate before commit. Cross-service SQL remains forbidden.
Remaining hostile acceptance / production gate
Before closure, one unchanged dependency-restacked integration candidate must prove: machine-verifiable 100% owned-production statement/branch/edge/public-rustdoc coverage; production backup/WAL retention/storage authority, encryption and key/IAM ownership without embedded long-lived secrets; production-shaped recovery objectives and destructive restore evidence; readiness/liveness/startup against the authoritative database; preserved historical uniqueness, publication completeness, actor/decision audit linkage, tenant RLS, commit ambiguity, pool bounds and no-replay semantics after restack; terminal CI/Fuzz/security/SAST/CodeQL/review/thread/package/SBOM/provenance/reproducibility/governance evidence on the same exact head; and ordinary protected integration followed by immutable Wardnet release identity binding source, artifact digest, SBOM, provenance/signature, reproducibility, rollback and recovery evidence.
StateAuthority::Postgresremains fail closed until that contract is protected truth. A Draft branch, successfulcargo test, recovery fixture, p95 measurement or predecessor receipt is not production authority.Ownership / architecture
This remains Wardnet Reputation Security Evidence state. It does not move to EgressWeave, contextual-orchestrator, quarantine-sandbox-runtime, AppGuardrail, CGC or EA Core. Keyverse may supply released authenticated tenant/subject claims; Wardnet validates action context and binds its database transaction. Principal lifecycle and backup-storage IAM remain deployment/infrastructure authority.
No source copy, cross-service SQL, mutable foreign production dependency, self/model approval, routine administrator bypass, force/destructive rebase, gate weakening, automatic replay of started database work or predecessor-evidence transfer. Generic solo-maintainer approval remains central
.github#772; runner/OpenCode defects remain.github#712/#1234; delegated CodeQL settlement remains.github#1929or verified successors.Traceability