Skip to content

feat(audit): rebuild bounded snapshot manifests on current pagination - #97

Closed
seonghobae wants to merge 5 commits into
agent/bounded-checkpoint-audit-export-pages-v5from
agent/checkpoint-audit-snapshot-manifest-v3
Closed

seonghobae wants to merge 5 commits into
agent/bounded-checkpoint-audit-export-pages-v5from
agent/checkpoint-audit-snapshot-manifest-v3

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 9, 2026 •

Copy link
Copy Markdown
Contributor

Linearized replacement for stale #84

This Draft rebuilds the checkpoint-audit snapshot-manifest feature on exact current pagination predecessor #96 rather than extending stale #83 ancestry. #84 is now closed unmerged as SUPERSEDED; none of its checks, reviews, or approvals transfer.

RCA and replacement boundary

The branch starts from #96 exact head f9062821556715537a028095326544bf234e45ae. Before replay, the old #83 and current #96 baselines were verified byte-identical for the unaffected snapshot contract surfaces. pg_llm_batch/checkpoint_audit.py required deliberate composition because the current stack contains exact requested-key revalidation that #84 did not, and CHANGELOG.md required composition because the current stack contains newer accepted entries.

The replacement preserves #96 pagination/key-revalidation behavior and adds #84's bounded snapshot-manifest API, digest framing, transaction/isolation checks, timestamp-offset hardening, public exports, CI/live PostgreSQL regressions, ADR/operator/doctoring contracts, and final authoritative CHANGELOG wording. The caller must supply one active PostgreSQL transaction that is read-only and uses REPEATABLE READ or SERIALIZABLE; autocommit and session-level-only isolation are rejected.

Test-first evidence

The replacement established the snapshot contract on current #96 ancestry before production composition. After implementation, exact-head CI exposed one remaining documentation contract failure: CHANGELOG had not stated the active-transaction/autocommit/isolation boundary. Commit deed55787f4b7eb1ef57147071957f03631a3b1c corrected that authoritative contract without changing production behavior.

Current exact staged evidence

These are staged replacement checks, not protected-main acceptance. Final security/default-branch/review/policy evidence still depends on the predecessor stack reaching protected main and this unchanged final source being revalidated against the integrated base.

Dependency and merge boundary

Required order remains .github#790 -> pg-llm-batch#53 -> #57 -> #58 -> #59 -> #60 -> #92 -> #94 -> #95 -> #96 -> this replacement.

Keep Draft while predecessors remain unintegrated. After prerequisite integration, reconcile/retarget only when integration correctness requires it and regenerate every applicable exact-head/exact-base CI, live PostgreSQL transaction/concurrency, security, dependency, SBOM/provenance, packaging, automated-review, branch-protection, repository-policy, and Release Acceptance gate. Merge only with zero valid unresolved findings and a qualifying independent non-author formal APPROVED review on the unchanged final head where required. Queued, pending, cancelled, skipped-required, absent, neutral-required, stale-head/base, predecessor, synthetic-only, status-only, author-only, rate-limited, or failed evidence is not acceptance.

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 62beff85-96a8-4064-af95-4bfef6cff63c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review the exact current stacked source head deed55787f4b7eb1ef57147071957f03631a3b1c against exact predecessor #96 head f9062821556715537a028095326544bf234e45ae. Focus on snapshot-manifest transaction/isolation enforcement, bounded paging invariance, digest framing, timestamp offsets, preservation of #96 key revalidation, concurrency/overflow behavior, and public/API documentation. This is staged Draft evidence only; do not promote predecessor or default-branch-only evidence and do not treat dependency ordering itself as a source defect.

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f9062821556715537a028095326544bf234e45ae'
head='deed55787f4b7eb1ef57147071957f03631a3b1c'

git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"

printf '%s\n' '=== exact range ==='
git diff --stat "${base}" "${head}"
git diff --name-status "${base}" "${head}"

printf '%s\n' '=== changed snapshot-related files ==='
git diff --name-only "${base}" "${head}" | rg '(^|/)(checkpoint_audit|__init__|CHANGELOG|README|ADR|doctor|audit|snapshot|test).*' || true

printf '%s\n' '=== implementation outlines ==='
fd -a '^checkpoint_audit\.py$' . -E .git -x ast-grep outline '{}' --items all --view expanded

printf '%s\n' '=== focused range diff ==='
git diff --find-renames --find-copies --unified=80 "${base}" "${head}" -- \
  'pg_llm_batch/checkpoint_audit.py' \
  'pg_llm_batch/__init__.py' \
  'CHANGELOG.md' \
  ':!*.lock' || true

Length of output: 44363


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '=== implementation: page and manifest methods ==='
sed -n '430,760p' pg_llm_batch/checkpoint_audit.py

printf '%s\n' '=== test structure ==='
for file in \
  tests/test_checkpoint_audit_snapshot_manifest.py \
  tests/test_checkpoint_audit_snapshot_transaction_boundary.py \
  tests/test_checkpoint_audit_snapshot_digest_vector.py \
  tests/test_checkpoint_audit_snapshot_integration.py \
  tests/test_checkpoint_audit_snapshot_public_api.py \
  tests/test_checkpoint_audit_ci_contract.py
do
  printf '\n=== %s ===\n' "$file"
  ast-grep outline "$file" --items all --view expanded
done

printf '%s\n' '=== assertions relevant to requested scope ==='
rg -n -C 4 -i \
  'repeatable|serializable|read.?only|autocommit|isolation|transaction|snapshot|concurr|overflow|max_events|page_size|timestamp|recorded_at|digest|sha256|revalid|outside the requested key|cursor' \
  tests/test_checkpoint_audit_snapshot_manifest.py \
  tests/test_checkpoint_audit_snapshot_transaction_boundary.py \
  tests/test_checkpoint_audit_snapshot_digest_vector.py \
  tests/test_checkpoint_audit_snapshot_integration.py \
  tests/test_checkpoint_audit_snapshot_public_api.py \
  tests/test_checkpoint_audit_ci_contract.py

printf '%s\n' '=== documentation contract ==='
rg -n -C 5 -i \
  'build_audit_snapshot_manifest|snapshot manifest|repeatable|serializable|read.?only|autocommit|isolation|100,000|digest|timestamp|sha-256' \
  CHANGELOG.md docs/checkpoint-audit.md \
  docs/adr/0012-checkpoint-audit-snapshot-manifests.md \
  docs/doctoring/checkpoint-audit-snapshot-manifests.md \
  ARCHITECTURE.md AGENTS.md CLAUDE.md

printf '%s\n' '=== CI additions ==='
git diff --unified=50 \
  f9062821556715537a028095326544bf234e45ae \
  deed55787f4b7eb1ef57147071957f03631a3b1c \
  -- .github/workflows/ci.yml tests/test_checkpoint_audit_ci_contract.py

Length of output: 209297


@seonghobae I found no source-level defects in deed55787f4b7eb1ef57147071957f03631a3b1c relative to f9062821556715537a028095326544bf234e45ae.

The implementation enforces an active, read-only REPEATABLE READ or SERIALIZABLE transaction before traversal. It rejects autocommit and session-level isolation alone.

The manifest reuses the predecessor keyset page method. Exact audit-key revalidation, strict descending identities, cursor checks, and bounded lookahead remain in effect.

The traversal remains bounded. It uses at most one page plus fixed digest state. It fails closed when the event budget is exceeded.

The digest framing includes the domain, trusted key, every retained event field, UTC microsecond timestamps, and final count and identity bounds. It excludes page partitioning. The fixed digest vector and timestamp-offset tests support this contract.

The range includes deterministic and live concurrent-insert coverage. CI invokes the live snapshot integration test. The package exports and public documentation match the implemented transaction, isolation, overflow, and SHA-256 boundaries.

This result is limited to staged Draft source review of the specified range. It does not treat predecessor, default-branch, or dependency-order evidence as acceptance evidence.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact current replacement head deed55787f4b7eb1ef57147071957f03631a3b1c against exact #96 predecessor f9062821556715537a028095326544bf234e45ae. Focus on bounded snapshot-manifest framing, active read-only REPEATABLE READ/SERIALIZABLE transaction enforcement, autocommit rejection, timestamp/offset handling, pagination/key-revalidation composition, and current-stack evidence integrity. Do not transfer evidence from closed superseded #84.

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f9062821556715537a028095326544bf234e45ae'
head='deed55787f4b7eb1ef57147071957f03631a3b1c'

git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"

printf '%s\n' '=== exact range ==='
git diff --stat "$base" "$head"
git diff --name-status "$base" "$head"

printf '%s\n' '=== changed Python module structure ==='
ast-grep outline pg_llm_batch/checkpoint_audit.py --items all --view expanded
printf '%s\n' '=== changed public exports structure ==='
ast-grep outline pg_llm_batch/__init__.py --items all --view expanded

printf '%s\n' '=== focused implementation diff ==='
git diff --find-renames --unified=100 "$base" "$head" -- \
  pg_llm_batch/checkpoint_audit.py \
  pg_llm_batch/__init__.py \
  tests \
  docs \
  CHANGELOG.md \
  .github/workflows/ci.yml

printf '%s\n' '=== current implementation and API call sites ==='
rg -n -C 5 \
  'build_audit_snapshot_manifest|_validate|transaction|autocommit|isolation|REPEATABLE|SERIALIZABLE|read.?only|digest|sha256|recorded_at|timestamp|offset|page_size|max_events|cursor|revalid' \
  pg_llm_batch/checkpoint_audit.py pg_llm_batch/__init__.py tests docs CHANGELOG.md .github/workflows/ci.yml || true

printf '%s\n' '=== GitHub current PR metadata, reviews, and checks ==='
gh pr view 97 --repo ContextualWisdomLab/pg-llm-batch \
  --json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviews,statusCheckRollup
printf '%s\n' '=== GitHub unresolved review threads ==='
gh api graphql -F owner='ContextualWisdomLab' -F name='pg-llm-batch' -F number=97 -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes { isResolved comments(first: 1) { nodes { author { login } body path line } } }
      }
    }
  }
}' \
  --jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)]'

Length of output: 202480


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f9062821556715537a028095326544bf234e45ae'
head='deed55787f4b7eb1ef57147071957f03631a3b1c'

printf '%s\n' '=== relevant symbols and line ranges ==='
ast-grep outline pg_llm_batch/checkpoint_audit.py --items all --view expanded \
  | rg -n -C 2 \
    'CheckpointAuditEvent|CheckpointAuditPage|CheckpointAuditSnapshotManifest|build_audit_snapshot_manifest|list_audit_event_page|_frame|_digest|_timestamp|transaction'

printf '%s\n' '=== head: manifest implementation region ==='
rg -n \
  '^(def |class )|build_audit_snapshot_manifest|list_audit_event_page_in_transaction|_snapshot|_digest|_frame|_timestamp|transaction_status' \
  pg_llm_batch/checkpoint_audit.py
sed -n '1,260p' pg_llm_batch/checkpoint_audit.py
sed -n '400,820p' pg_llm_batch/checkpoint_audit.py

printf '%s\n' '=== predecessor versus head page implementation ==='
git show "${base}:pg_llm_batch/checkpoint_audit.py" \
  | rg -n -C 35 'def list_audit_event_page_in_transaction'
printf '%s\n' '--- head ---'
rg -n -C 35 'def list_audit_event_page_in_transaction' pg_llm_batch/checkpoint_audit.py

printf '%s\n' '=== focused tests: manifest, digest, integration ==='
for file in \
  tests/test_checkpoint_audit_snapshot_manifest.py \
  tests/test_checkpoint_audit_snapshot_digest_vector.py \
  tests/test_checkpoint_audit_snapshot_transaction_boundary.py \
  tests/test_checkpoint_audit_snapshot_integration.py \
  tests/test_checkpoint_audit_snapshot_public_api.py
do
  printf '\n=== %s symbols ===\n' "$file"
  ast-grep outline "$file" --items all --view expanded
  printf '\n=== %s focused assertions ===\n' "$file"
  rg -n -C 12 \
    '^def test_.*(overflow|page|digest|timestamp|offset|concurr|revalid|transaction|autocommit|serializ|repeatable)|assert .*snapshot|pytest\.raises' \
    "$file"
done

printf '%s\n' '=== exact changes to pre-existing page method ==='
git diff --unified=30 "$base" "$head" -- pg_llm_batch/checkpoint_audit.py \
  | sed -n '/list_audit_event_page_in_transaction/,+180p'

Length of output: 57732


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '=== digest, timestamp, and transaction helper implementation ==='
nl -ba pg_llm_batch/checkpoint_audit.py | sed -n '250,360p'

printf '%s\n' '=== fixed digest compatibility vector ==='
nl -ba tests/test_checkpoint_audit_snapshot_digest_vector.py | sed -n '45,150p'

printf '%s\n' '=== live transaction and concurrent-insert sequence ==='
nl -ba tests/test_checkpoint_audit_snapshot_integration.py | sed -n '40,225p'

printf '%s\n' '=== timestamp offset and event field digest tests ==='
rg -n -C 20 -i \
  'offset|timezone|recorded_at|timestamp|each.*field|field.*digest|digest.*field' \
  tests/test_checkpoint_audit_snapshot_manifest.py \
  tests/test_checkpoint_audit_snapshot_digest_vector.py \
  tests/test_checkpoint_audit_snapshot_integration.py \
  tests

printf '%s\n' '=== precise source range against predecessor ==='
git diff --unified=20 \
  f9062821556715537a028095326544bf234e45ae \
  deed55787f4b7eb1ef57147071957f03631a3b1c \
  -- pg_llm_batch/checkpoint_audit.py pg_llm_batch/__init__.py \
  CHANGELOG.md docs/checkpoint-audit.md docs/adr/0012-checkpoint-audit-snapshot-manifests.md \
  docs/doctoring/checkpoint-audit-snapshot-manifests.md \
  | sed -n '1,2200p'

Length of output: 1638


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '=== digest, timestamp, and transaction helper implementation ==='
cat -n pg_llm_batch/checkpoint_audit.py | sed -n '250,360p'

printf '%s\n' '=== fixed digest compatibility vector ==='
cat -n tests/test_checkpoint_audit_snapshot_digest_vector.py | sed -n '45,150p'

printf '%s\n' '=== live transaction and concurrent-insert sequence ==='
cat -n tests/test_checkpoint_audit_snapshot_integration.py | sed -n '40,225p'

printf '%s\n' '=== timestamp and digest focused tests ==='
rg -n -C 16 -i \
  'offset|timezone|recorded_at|timestamp|digest.*(field|chang)|field.*digest' \
  tests/test_checkpoint_audit_snapshot_manifest.py \
  tests/test_checkpoint_audit_snapshot_digest_vector.py \
  tests/test_checkpoint_audit_snapshot_integration.py || true

printf '%s\n' '=== exact source and public API changes ==='
git diff --unified=20 \
  f9062821556715537a028095326544bf234e45ae \
  deed55787f4b7eb1ef57147071957f03631a3b1c \
  -- pg_llm_batch/checkpoint_audit.py pg_llm_batch/__init__.py \
  | sed -n '1,1800p'

Length of output: 59875


@seonghobae I found no source-level defects in deed55787f4b7eb1ef57147071957f03631a3b1c relative to f9062821556715537a028095326544bf234e45ae.

build_audit_snapshot_manifest_in_transaction() requires Psycopg INTRANS status before it probes transaction properties or reads audit pages. It then requires read-only REPEATABLE READ or SERIALIZABLE. This rejects autocommit, session-level isolation without an active transaction, READ COMMITTED, read-write transactions, and malformed status evidence.

The manifest uses bounded keyset pages and fixed digest state. It fails closed when more events remain after max_events is consumed. The implementation retains #96 key revalidation, strict descending identities, cursor validation, and bounded lookahead.

The SHA-256 framing is length-prefixed and domain-separated. It binds the trusted key, every retained event field, normalized UTC microsecond timestamps, final event count, and identity bounds. It excludes page partitioning. The fixed schema-version-1 digest vector protects this framing contract. The timestamp guard rejects tzinfo values with no UTC offset.

The live PostgreSQL test establishes the stable read-only snapshot before another connection commits an event. It verifies page-size invariance, later-event exclusion, READ COMMITTED rejection, and autocommit rejection.

The package-root exports and the reviewed documentation state the public API and transaction boundary.

GitHub currently reports that #97 is Draft, clean, and uses the exact requested base and head. The staged CI, PostgreSQL integration, and Release Acceptance checks succeeded. There are zero unresolved review threads. No submitted independent review exists.

This is staged Draft source and current-stack evidence only. It does not transfer evidence from closed superseded #84. It is not final protected-branch or integrated-base acceptance.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

SUPERSEDED by current-main reconstruction #181 together with its obsolete predecessor line. Fresh evidence shows #97 still depends on #96, while #96 depends on closed-unmerged #95 and #92/#94/#95 are closed unmerged. Preserve this branch only as design/test provenance; do not retarget it or transfer its historical CI/review evidence onto the current protected-main reconstruction.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant