Skip to content

Resolve node removals from bounded checkpoint-tail witnesses #960

Description

@flyingrobots

id: "GW20-004"
title: "Resolve node removals from bounded checkpoint-tail witnesses"
type: "feature"
status: "planned"
milestone: "v20.1.0"
category: "required"
workstream: "query"
issue: "#960"
baseline_commit: "ceb58e656ec5bc85f0ae5991bf2a55599693bbb3"
feedback_sections: [4]
prerequisites: []

Feature

LLM prompt

Complete GW20-004: Resolve node removals from bounded checkpoint-tail witnesses.
Read this entire task and its current GitHub issue before implementation.
Verify the current mainline and all prerequisite integrations.
Read AGENTS.md and the three TypeScript policy documents.
Use runtime-backed domain values and injected ports.
Keep parsing and codecs at the adapter boundary.
Preserve v20 APIs, stored identities, CRDT semantics, and failure meanings.
Use one coherent issue, PR, and mainline integration. Do not leave a broken intermediate state.
Problem to resolve:
A tail node.remove obstructs node and property reads until another checkpoint.
Acceptance checks:
Read node presence and properties correctly after tail remove, add, and re-add operations.
Use retained live dots and tombstones. A last-operation Boolean does not replace OR-Set semantics.
Preserve concurrent unobserved adds, floating tombstones, and property lifecycle clearing.
Missing dot witnesses yield typed incomplete results. No hidden materialization occurs.
Select dot support from the exact checkpoint descriptor. Prefer retained node-alive trie roots when available.
Use bounded live-dot and tombstone reads. A boolean Roaring shard cannot replace those witnesses.
When roots lack usable dot witnesses, add a compatible optional witness artifact and an explicit bounded preparation or upgrade path.
Legacy checkpoints remain readable. Missing witnesses refuse temporarily with a specific cause; permanent refusal does not complete this task.
Do not force a substrate migration or decode a full state envelope to answer the removal.
Read these source paths:
src/domain/services/optic/CheckpointTailFactReducer.ts
src/domain/services/optic/CheckpointTailNodeScan.ts
src/domain/services/optic/CheckpointShardFactReader.ts
test/conformance/v18CheckpointLifecycleOpticReadBasis.test.ts
src/domain/orset/trie/TrieCursor.ts
src/domain/orset/ORSetElementState.ts
src/domain/services/controllers/MaterializeSessionBridge.ts
src/domain/materialization/MaterializationRoots.ts
Prerequisites: None established. Recheck external readiness.
Scope exclusions: Change OR-Set semantics or treat every remove as unconditional deletion.
Run all tests and benchmarks in COPY-based Docker without host repository mounts.
Use the project guarded runner and the shared git-locks authority.
Lock host/heavy-work and the exact worker key together for expensive work.
Limit build caches to 20 GiB, test data to 4 GiB, and logs to 128 MiB.
Require 50 GiB free on host and Docker backing storage before heavy work.
Enforce disk accounting, CPU, memory, timeout, and child-process shutdown.
Do not start an unguarded workload. Do not bypass a resource refusal.
Require full touched-code coverage for refactors and an all-green manual SSJS scorecard.
Record source, image, command, fixtures, results, limits, and the regression witness.
Commit only your own files. Do not amend, rebase, force, push, or publish without authorization.
Report incomplete or blocked checks. Do not claim completion from a narrow green test.
Link the issue, coherent PR, and actual mainline integration when those actions are authorized.

1. Background Context

Source: FEEDBACK-git-warp.md, sections 4.
The report SHA-256 is 9b15209d51cd705059a9e6bfebf0f6681ff832924c1462b99ff3cfebde6bacae.
The report uses npm git-warp 20.0.0 and git-cas 6.5.11.
Its runtime results come from macOS host experiments. This planning task did not rerun them.
Source review baseline: ceb58e65.

Tracker: #960.

Read these source and test surfaces before work:

2. Problem Description

A tail node.remove obstructs node and property reads until another checkpoint.

2b. Proposed Solution

Read exact dot and tombstone support through an injected port over retained OR-Set roots. Add compatible witness publication and bounded upgrade only where that support is absent.

2c. Alternatives considered and rejected

Reject a private-import workaround. It does not provide a supported application contract.
Reject a documentation-only substitute when this task requires runtime behavior.
Keep larger storage and package redesigns under their existing issues.

2d. Acceptance Criteria

  • Read node presence and properties correctly after tail remove, add, and re-add operations.
  • Use retained live dots and tombstones. A last-operation Boolean does not replace OR-Set semantics.
  • Preserve concurrent unobserved adds, floating tombstones, and property lifecycle clearing.
  • Missing dot witnesses yield typed incomplete results. No hidden materialization occurs.
  • Select dot support from the exact checkpoint descriptor. Prefer retained node-alive trie roots when available.
  • Use bounded live-dot and tombstone reads. A boolean Roaring shard cannot replace those witnesses.
  • When roots lack usable dot witnesses, add a compatible optional witness artifact and an explicit bounded preparation or upgrade path.
  • Legacy checkpoints remain readable. Missing witnesses refuse temporarily with a specific cause; permanent refusal does not complete this task.
  • Do not force a substrate migration or decode a full state envelope to answer the removal.

2e. Test Plan

Golden: Checkpoint a live node, remove it, and read absence and cleared properties before another checkpoint.

Edges: Observed and unobserved concurrent adds; remove with no dots; duplicate removes; re-add; stale remote dots; strand reads.

Known failure modes: preserve typed refusal, atomic publication, and complete evidence. Do not conceal unavailable support.

Fuzz and stress: use fixed fixture sizes and seeds. Apply the roadmap resource guards. Do not start an unbounded campaign.

3. Prerequisites

None established as an internal issue dependency. Verify the current boundary and external readiness before activation.

4. Scope

In: A tail node.remove obstructs node and property reads until another checkpoint.

Out: Change OR-Set semantics or treat every remove as unconditional deletion.

Safe intermediate state: one independently mergeable PR passes its relevant checks after its prerequisites.
Existing supported applications remain usable. Historical data remains intact.

5. Why now

This flaw blocks a supported Synapse store workflow or gives its operator incorrect guidance.
Resolve it within v20.1.0 without reducing the existing causal-history commitment.

6. Risks

Source inspection does not establish runtime or performance results.
Preserve historical identities, validation, and evidence. Do not weaken refusal to obtain a green result.
If the fix requires a breaking contract, record the conflict before activation. Do not hide it within a minor release.

7. Definition of Done

All acceptance checks have evidence from the exact candidate.
Relevant lint, typecheck, compatibility, and Docker checks pass.
The manual SSJS scorecard is green. Refactor coverage reaches 100% on touched code.
Record the issue, PR, and mainline integration commit. Record any external release gate.
A required check with missing evidence remains incomplete.

8. Stakeholders

James Ross: git-warp maintainer and acceptance owner.
Synapse store authors: applications need correct writes, reads, history, and operational guidance.
Library and CLI consumers: existing v20 contracts must remain usable.

9. Related Issues

Activity

  1. added this to the v20.1.0 milestone on Oct 7, 2026
  2. added
    type:featureNew capability or product behavior.
    priority:nextNext in line after active work.
    area:queryPrimary work area: query.
    status:availableOpen and available for prioritization; not blocked or actively in progress.
    on Oct 7, 2026
  3. linear-code commented on Oct 7, 2026

    @linear-code
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:queryPrimary work area: query.priority:nextNext in line after active work.status:availableOpen and available for prioritization; not blocked or actively in progress.type:featureNew capability or product behavior.

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions