feat(state): make production authority explicit - #193
Draft
seonghobae wants to merge 14 commits into
Draft
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Sep 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #80 #192. Draft child of current #140 Runtime Configuration foundation.
Bounded production-authority contract
Wardnet must never infer deployment intent from listener topology: production may bind loopback behind a proxy/sidecar. This slice makes mutable-state authority explicit while leaving the actual PostgreSQL repository/migrations/RLS/recovery under #80/#192.
It does not claim PostgreSQL durability, RLS, tenant isolation, migration/recovery, backup/restore, source-generation uniqueness or release readiness.
Hostile RED → causal repair lineage
Test-only
37f5c8cb73ed45a003e1d4ca69771d649db5a5f7produced the original hosted semantic RED in CI34175687088/ rust101904485782: checkout/toolchain/formatting passed and locked workspace tests failed because the explicit deployment/state-authority contract did not exist. The minimum implementation then reached source GREEN.Fresh review found a second fail-closed edge:
StateAuthority::FilerejectedNonebut acceptedPathBuf::from(""). Test-only exact2d57983d38a8e712a6103f6898906ed88b569be0, CI34177340458/ rust101909271259, passed checkout/toolchain/formatting and failed semantically on the empty-path case. Repairf50e7204df5e6467297969eddff70891358e4bffmade tests pass but strict Clippy rejected the spelling; exact88e54cd18fb686a6b61525c400531820f7a014b4applied only Clippy's semantics-preservingOption::is_none_orform.Current parent adoption and exact-current evidence — 2026-09-09 KST
#140 subsequently advanced through additional hostile Runtime Configuration environment-alias fitness repairs to exact
93a51f9706cf8a9704f69aed4a69df5be16c84e4. This branch adopted that intervening foundation normally rather than treating it as a race or copying it.Current exact head is
7a93322c9a824e6e939a8143b1f20eccaeac856d, commitchore(stack): adopt current #140 foundation into #193. GitHub records base exact#140@93a51f9706cf8a9704f69aed4a69df5be16c84e4, Draft and mechanically mergeable. Fresh comparison from the prior #193 GREEN88e54cd...to current head is ahead 8 / behind 0 and the intervening effective delta is confined tosrc/runtime_config.rs, i.e. the parent foundation movement rather than a second state-authority implementation.On unchanged exact
7a93322c9a824e6e939a8143b1f20eccaeac856d:34234733846— terminal SUCCESS;34234733840— terminal SUCCESS;The earlier
88e54cd...checks are predecessor evidence only; current exact executions above are the bounded child evidence. The branch remains Draft because #140 is still unintegrated protected truth and all later PostgreSQL children depend on this exact stack ancestry.Integration boundary
Keep order
#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233. Any parent movement is adopted non-force and invalidates dependent gate evidence.No force update, destructive rebase, self/model approval, routine administrator bypass, gate weakening, mutable foreign dependency, source copy, cross-service SQL, no-op dispatch churn or predecessor-evidence transfer.