Skip to content

Prove session-event retention across authority paths #869

Description

@flyingrobots

1. Background Context

Source: git-warp #869. Audited against main 94b40dac64034cd8caab9bb05efe14a0c22bd735. Template: feature; work type: type:maintenance.

Current scope and disposition: The CLI surfaces needed by this proof already exist. Local conformance was reported complete, but the owner explicitly records #870 as preventing publication; retain it until bounded browser shutdown clears that gate. Do not add #854 occurrence relations, which this card excludes.

Discussion evidence, including corrections:

2. Problem Description

The CLI surfaces needed by this proof already exist. Local conformance was reported complete, but the owner explicitly records #870 as preventing publication; retain it until bounded browser shutdown clears that gate. Do not add #854 occurrence relations, which this card excludes.

Historical source report; the current disposition above supersedes obsolete claims:
Prove through the public v19 CLI that an opaque, complete consumer event entity survives process restart and remains correctly evidenced across both supported authority profiles:

  • direct admission into an authoritative worldline;
  • candidate admission into independent Strands followed by exact-frontier settlement.

2b. Proposed Solution

The CLI surfaces needed by this proof already exist. Local conformance was reported complete, but the owner explicitly records #870 as preventing publication; retain it until bounded browser shutdown clears that gate. Do not add #854 occurrence relations, which this card excludes.

Historical approach to reconcile:
Current architecture rules take precedence: parsing/encoding stays at adapters, domain concepts are runtime-backed, no trust casts are introduced, and tests run in Docker.
Prove through the public v19 CLI that an opaque, complete consumer event entity survives process restart and remains correctly evidenced across both supported authority profiles:

  • direct admission into an authoritative worldline;
  • candidate admission into independent Strands followed by exact-frontier settlement.

2c. Alternatives considered and rejected

No additional alternatives are recorded as decided. Reject duplicate ownership, private-import escape hatches and a broken intermediate mainline; retain original alternatives below when present.

2d. Acceptance Criteria

  • The write receipt preserves application intent identity, application subject identity, graph subject identity, and causal occurrence identity without conflating them.
  • One entity birth returns one patch-support witness and exact opaque bytes are recoverable by graph subject after restart.
  • A candidate at an unchanged fork basis settles with the exact derived classification and complete settlement evidence.
  • A second candidate from the stale common basis is obstructed with git-warp.settlement-common-basis-required on both preview and apply.
  • The settled entity is visible in the target while both settled and obstructed source entities remain recoverable in their source Strands.
  • Negative target readings remain basis-bound.

2e. Test Plan

Golden: Exercise the stated admission/merge or evidence contract with explicit basis and expected outcome.

Edges: Concurrent and stale bases, empty input, obstruction, plurality and repeated requests where supported.

Known failure modes: No partial publication or forced winner when the contract requires refusal/plurality.

Fuzz and stress: Deterministic multi-writer fixtures and provenance-preserving replay; keep all harness execution in Docker.

All tests and benchmarks execute in COPY-based Docker containers without host repository or Git-directory mounts. This planning audit does not claim those checks were run.

Existing evidence / proposed witnesses (retain their original temporal scope):
The conformance suite must run through public CLI process boundaries, include witnessed RED calibrations for load-bearing assertions, pass under PYTHONOPTIMIZE=1, and leave production source unchanged.

3. Prerequisites

Completion prerequisites; preparatory work may start earlier.

  • #870: The implementation owner reports that the required pre-push Mermaid gate hangs on browser shutdown and prevents publication of this conformance work. This is a documented delivery prerequisite, not a general blocker on every PR.

4. Scope

In: The CLI surfaces needed by this proof already exist. Local conformance was reported complete, but the owner explicitly records #870 as preventing publication; retain it until bounded browser shutdown clears that gate. Do not add #854 occurrence relations, which this card excludes.

Source scope and exclusions:

  • Do not add an occurrence-id decoder or pairwise occurrence relation command unless a named consumer claim cannot be supported by existing entity, receipt, basis, and settlement evidence.
  • Do not implement consumer-specific semantic conflict or supersession rules in Git WARP.
  • Do not treat process independence as candidate-Strand authority by default.

Safe intermediate state: the PR builds and passes relevant checks after its listed prerequisites; existing supported behavior remains usable. Any preparatory step must be independently mergeable.

5. Why now

Maintainer ordering: memory correctness first, supported attachments next, then land eligible PRs. Preserve this card’s existing priority unless a separately recorded scope decision changes it.

6. Risks

Main risk: implementing the historical description instead of the current runtime contract. Preserve compatibility, causal/ownership invariants and bounded behavior relevant to admission-merge.

7. Definition of Done

The issue-specific acceptance checks pass, relevant validation evidence is attached, and the issue links the coherent PR and resulting mainline integration commit. No open item is hidden in a later repair PR.

8. Stakeholders

James Ross: maintainer, assignee and acceptance owner. Graft/TTD and other consumers rely on lawful admission and witnessed merge outcomes.

9. Related Issues

No additional downstream blocker is established. Shared domain membership alone is not a prerequisite.

Historical paths, counts, release names and shell examples in source material are evidence to reconcile, not authority to restore retired documentation or run host tests.

Activity

  1. added
    priority:nextNext in line after active work.
    status:activeSomeone is actively working this issue.
    area:testingPrimary work area: testing.
    status:blockedBlocked by an explicit dependency or external condition.
    and removed
    status:activeSomeone is actively working this issue.
    on Aug 25, 2026
  2. flyingrobots commented on Aug 25, 2026

    @flyingrobots
    MemberAuthor

    Local conformance work is complete and cumulative self-review is zero-finding. Build, lint, typechecks, ShellCheck, all 10 BATS tests, and PYTHONOPTIMIZE=1 replay are green. The broad local unit runner remains blocked by its enforced 512 MiB free-memory floor while unrelated host tests are active. Publication is separately blocked by #870: the pre-push Mermaid gate rendered all 51 diagrams but did not return from browser shutdown after more than eight minutes. The push was aborted; no remote branch or Draft PR exists.

  3. self-assigned this
    on Oct 1, 2026
  4. added this to the v20.0.0 milestone on Oct 2, 2026
  5. added
    status:activeSomeone is actively working this issue.
    and removed
    status:blockedBlocked by an explicit dependency or external condition.
    on Oct 2, 2026
  6. flyingrobots commented on Oct 2, 2026

    @flyingrobots
    MemberAuthor

    Draft PR #944 publishes the reconstructed public-CLI conformance proof at c019da2f26451fcaefddfc3c12e200ae6bf05d3d, stacked on its recorded #870 prerequisite (PR #937). Ten BATS checks pass normally and under PYTHONOPTIMIZE=1; seven controlled evidence mutations witness exact named RED failures in both modes. The proof uses 26 fresh CLI processes and changes no production source. Actual settlement envelopes and negative checkpoint support are preserved. All ordinary COPY-only Docker gates pass, including 8,350 unit tests/two existing skips and real rendering of 51 Mermaid diagrams. Independent review and coordinated current-main stack integration remain required. #944

  7. flyingrobots commented on Oct 3, 2026

    @flyingrobots
    MemberAuthor

    Completed on main at 11336c1177600f67aa443e8201b73196a4244a4d through parent PR #937, after the authorized top-first merge of PR #944. Main has parents9b5ec9bc and20da5abd and exactly the reviewed20da5abd tree 1d3488615da63b70b5e78f2ce5422944fcd8e5c0; no additional merge resolution changes the proof.

    The complete independent session-proof review and normal/optimized BATS controls remain linked in #944; final parent validation includes all38 BATS cases, including10 session-event cases and their7 negative calibrations, all8368 ordinary unit checks, all required hosted checks and independently verified current preflight artifact. The actual public CLI authority-path proof and its operational documentation are now on the default branch. Historical browser/tooling blockers were fixed and independently reviewed before merge. This completion does not claim a published v20 package; remaining milestone issues and release gates still apply.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions