id: "GW20-024"
title: "Allow validated domain decoder results in public Observers"
type: "feature"
status: "planned"
milestone: "v20.1.0"
category: "required"
workstream: "api"
issue: "#980"
baseline_commit: "ceb58e656ec5bc85f0ae5991bf2a55599693bbb3"
feedback_sections: [17]
prerequisites: []
Feature
LLM prompt
Complete GW20-024: Allow validated domain decoder results in public Observers.
Read this entire task and its current GitHub issue before implementation.
Verify the current mainline and all prerequisite integrations.
Read AGENTS.md and the three TypeScript policy documents.
Use runtime-backed domain values and injected ports.
Keep parsing and codecs at the adapter boundary.
Preserve v20 APIs, stored identities, CRDT semantics, and failure meanings.
Use one coherent issue, PR, and mainline integration. Do not leave a broken intermediate state.
Problem to resolve:
Observer generics constrain decoder results to ReadingValue. ObservedReading also validates and snapshots the decoded result at runtime.
Acceptance checks:
createObserver and createManyObserver accept concrete validated domain decoder results without casts.
Validate raw ReadingValue before decoding. A generic-only change cannot bypass the runtime snapshot gate.
Preserve returned domain class identity, behavior, and constructor invariants.
Define decoder-output ownership and immutability explicitly. Existing snapshot consumers keep their supported behavior.
Strict packed NodeNext consumers compile without skipLibCheck or unsafe casts.
Decoder failure does not produce a completed observation receipt.
Snapshot and validate raw data before invoking the decoder. Use an explicit decoded-value construction path afterward.
Do not snapshot-clone a decoded domain instance. Preserve its methods and validated identity.
The existing public raw Reading constructor retains snapshot validation and copy ownership. Do not remove that gate globally.
Read these source paths:
src/domain/api/Observer.ts
src/domain/api/ObserverRuntime.ts
src/domain/api/ObservedReading.ts
src/domain/api/ReadingValueRuntime.ts
src/application/RuntimeLaneAdapter.ts
Prerequisites: None established. Recheck external readiness.
Scope exclusions: Add unknown to core, widen only .d.ts files, or validate a domain instance as a snapshot dictionary.
Run all tests and benchmarks in COPY-based Docker without host repository mounts.
Use the project guarded runner and the shared git-locks authority.
Lock host/heavy-work and the exact worker key together for expensive work.
Limit build caches to 20 GiB, test data to 4 GiB, and logs to 128 MiB.
Require 50 GiB free on host and Docker backing storage before heavy work.
Enforce disk accounting, CPU, memory, timeout, and child-process shutdown.
Do not start an unguarded workload. Do not bypass a resource refusal.
Require full touched-code coverage for refactors and an all-green manual SSJS scorecard.
Record source, image, command, fixtures, results, limits, and the regression witness.
Commit only your own files. Do not amend, rebase, force, push, or publish without authorization.
Report incomplete or blocked checks. Do not claim completion from a narrow green test.
Link the issue, coherent PR, and actual mainline integration when those actions are authorized.
1. Background Context
Source: FEEDBACK-git-warp.md, sections 17.
The report SHA-256 is 9b15209d51cd705059a9e6bfebf0f6681ff832924c1462b99ff3cfebde6bacae.
The report uses npm git-warp 20.0.0 and git-cas 6.5.11.
Its runtime results come from macOS host experiments. This planning task did not rerun them.
Source review baseline: ceb58e65.
Tracker: #980.
Read these source and test surfaces before work:
2. Problem Description
Observer generics constrain decoder results to ReadingValue. ObservedReading also validates and snapshots the decoded result at runtime.
2b. Proposed Solution
Separate the validated raw snapshot boundary from the typed decoder-output boundary. Give output ownership a real runtime contract.
2c. Alternatives considered and rejected
Reject a private-import workaround. It does not provide a supported application contract.
Reject a documentation-only substitute when this task requires runtime behavior.
Keep larger storage and package redesigns under their existing issues.
2d. Acceptance Criteria
2e. Test Plan
Golden: Decode raw values to an immutable domain class with a method, plus a structured domain record. Compile and execute single and many observers.
Edges: Null; invalid raw values; throwing decoder; caller mutation; class identity; bytes; evidence and cancellation.
Known failure modes: preserve typed refusal, atomic publication, and complete evidence. Do not conceal unavailable support.
Fuzz and stress: use fixed fixture sizes and seeds. Apply the roadmap resource guards. Do not start an unbounded campaign.
3. Prerequisites
None established as an internal issue dependency. Verify the current boundary and external readiness before activation.
4. Scope
In: Observer generics constrain decoder results to ReadingValue. ObservedReading also validates and snapshots the decoded result at runtime.
Out: Add unknown to core, widen only .d.ts files, or validate a domain instance as a snapshot dictionary.
Safe intermediate state: one independently mergeable PR passes its relevant checks after its prerequisites.
Existing supported applications remain usable. Historical data remains intact.
5. Why now
This flaw blocks a supported Synapse store workflow or gives its operator incorrect guidance.
Resolve it within v20.1.0 without reducing the existing causal-history commitment.
6. Risks
Source inspection does not establish runtime or performance results.
Preserve historical identities, validation, and evidence. Do not weaken refusal to obtain a green result.
If the fix requires a breaking contract, record the conflict before activation. Do not hide it within a minor release.
7. Definition of Done
All acceptance checks have evidence from the exact candidate.
Relevant lint, typecheck, compatibility, and Docker checks pass.
The manual SSJS scorecard is green. Refactor coverage reaches 100% on touched code.
Record the issue, PR, and mainline integration commit. Record any external release gate.
A required check with missing evidence remains incomplete.
8. Stakeholders
James Ross: git-warp maintainer and acceptance owner.
Synapse store authors: applications need correct writes, reads, history, and operational guidance.
Library and CLI consumers: existing v20 contracts must remain usable.
9. Related Issues
id: "GW20-024"
title: "Allow validated domain decoder results in public Observers"
type: "feature"
status: "planned"
milestone: "v20.1.0"
category: "required"
workstream: "api"
issue: "#980"
baseline_commit: "ceb58e656ec5bc85f0ae5991bf2a55599693bbb3"
feedback_sections: [17]
prerequisites: []
Feature
LLM prompt
1. Background Context
Source:
FEEDBACK-git-warp.md, sections 17.The report SHA-256 is
9b15209d51cd705059a9e6bfebf0f6681ff832924c1462b99ff3cfebde6bacae.The report uses npm git-warp 20.0.0 and git-cas 6.5.11.
Its runtime results come from macOS host experiments. This planning task did not rerun them.
Source review baseline:
ceb58e65.Tracker: #980.
Read these source and test surfaces before work:
src/domain/api/Observer.tssrc/domain/api/ObserverRuntime.tssrc/domain/api/ObservedReading.tssrc/domain/api/ReadingValueRuntime.tssrc/application/RuntimeLaneAdapter.ts2. Problem Description
Observer generics constrain decoder results to ReadingValue. ObservedReading also validates and snapshots the decoded result at runtime.
2b. Proposed Solution
Separate the validated raw snapshot boundary from the typed decoder-output boundary. Give output ownership a real runtime contract.
2c. Alternatives considered and rejected
Reject a private-import workaround. It does not provide a supported application contract.
Reject a documentation-only substitute when this task requires runtime behavior.
Keep larger storage and package redesigns under their existing issues.
2d. Acceptance Criteria
2e. Test Plan
Golden: Decode raw values to an immutable domain class with a method, plus a structured domain record. Compile and execute single and many observers.
Edges: Null; invalid raw values; throwing decoder; caller mutation; class identity; bytes; evidence and cancellation.
Known failure modes: preserve typed refusal, atomic publication, and complete evidence. Do not conceal unavailable support.
Fuzz and stress: use fixed fixture sizes and seeds. Apply the roadmap resource guards. Do not start an unbounded campaign.
3. Prerequisites
None established as an internal issue dependency. Verify the current boundary and external readiness before activation.
4. Scope
In: Observer generics constrain decoder results to ReadingValue. ObservedReading also validates and snapshots the decoded result at runtime.
Out: Add unknown to core, widen only .d.ts files, or validate a domain instance as a snapshot dictionary.
Safe intermediate state: one independently mergeable PR passes its relevant checks after its prerequisites.
Existing supported applications remain usable. Historical data remains intact.
5. Why now
This flaw blocks a supported Synapse store workflow or gives its operator incorrect guidance.
Resolve it within v20.1.0 without reducing the existing causal-history commitment.
6. Risks
Source inspection does not establish runtime or performance results.
Preserve historical identities, validation, and evidence. Do not weaken refusal to obtain a green result.
If the fix requires a breaking contract, record the conflict before activation. Do not hide it within a minor release.
7. Definition of Done
All acceptance checks have evidence from the exact candidate.
Relevant lint, typecheck, compatibility, and Docker checks pass.
The manual SSJS scorecard is green. Refactor coverage reaches 100% on touched code.
Record the issue, PR, and mainline integration commit. Record any external release gate.
A required check with missing evidence remains incomplete.
8. Stakeholders
James Ross: git-warp maintainer and acceptance owner.
Synapse store authors: applications need correct writes, reads, history, and operational guidance.
Library and CLI consumers: existing v20 contracts must remain usable.
9. Related Issues