Skip to content

[P0] Persist reputation source-generation uniqueness with atomic snapshot publication #192

Description

@seonghobae

Proven production defect and current implementation boundary — refreshed 2026-09-20 KST

Refs #80 #190 #191 #199 #200 #207 #208 #209 #212 #216 #217 #219 #221 #223 #224 #225 #226 #228 #229 #231 #233 #234 #236 #241 #242 #243 #244.

Test-only #191 proved a current-only generation cursor cannot enforce historical token uniqueness across transitions: an opaque source-generation token can ABA-reappear at a later ordinal. A bounded recent-token cache only delays the defect. PostgreSQL therefore remains planned production authority for historical generation identity and publication state.

Protected/default Wardnet truth remains main@f8260f1e03836039ff9463dd99fa982e4e270c4b; StateAuthority::Postgres remains disabled. Every PostgreSQL head remains Draft/unreleased until the complete dependency lineage reaches protected truth and an immutable release gate is satisfied.

Current canonical PostgreSQL lineage

Order remains:

#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244

#227/#230/#232/#235/#239/#240/#243 remain acceptance/RED or completion lanes. Parent movement requires ordinary non-force adoption and fresh exact-head evidence; predecessor checks never transfer.

The lineage is parked behind Runtime Configuration. Canonical #140 is now exact 99c7c6c798f13c9c37d00d9f586f102585ad3494, directly based on protected main@f8260f1e03836039ff9463dd99fa982e4e270c4b, mechanically mergeable and still Draft. The earlier protected-base synthesis/reconciliation lineage is integrated into this root: one immutable Runtime Configuration snapshot composes with protected credential/RBAC/public-bind semantics rather than allowing stale ambient run_from_env state to become authority. Repository-owned CI/Fuzz/SAST/Security evidence on the unchanged root is terminal GREEN; delegated CodeQL terminal settlement remains central .github#1929 ownership and is not a Wardnet source/test/SARIF RED.

Keep #193 and every descendant parked until #140 satisfies live review/governance and reaches protected truth by normal integration. Do not blind-rerun, add no-op churn, transfer predecessor GREEN, force/rebase, self/model approve, weaken gates or routinely bypass protection.

The first PostgreSQL child remains on its historical parent and its historical successes are predecessor evidence only. Current Draft tip #244 remains implementation evidence only; real PostgreSQL preflight/probe p95 and recovery evidence on that lineage must be reacquired after dependency-first non-force restack.

Draft contract already demonstrated

On real PostgreSQL 18.4 fixtures, without enabling production authority, the lineage has demonstrated durable tenant/source generation token+ordinal uniqueness under ENABLE+FORCE RLS; immutable admission and stable divergent conflicts; atomic publication history/last-known-good head; least-privilege capability roles; failure-atomic migrations and startup compatibility; externally managed ordinary runtime LOGIN mapping; transaction-local tenant binding and pooled cleanup; typed publication/read APIs with mandatory actor/decision attribution and no public raw-SQL escape; authoritative-complete reads; bounded pool replenishment/readiness; typed unknown-COMMIT outcome with no automatic replay; destructive physical backup/WAL/PITR recovery; divergent-writer serialization and byte-identical replay; half-open protocol-progress detection and selective healthy-member failover; and 200 real PostgreSQL preflight+probe samples at p95 <=20 ms on the Draft lineage.

Those receipts must be reacquired after dependency-first integration. cargo test/CI GREEN does not prove the standing 100% owned-production statement/line, branch, edge and public-rustdoc contract.

Durable aggregate contract

One authoritative PostgreSQL transaction must preserve tenant/source identity, opaque generation token, normalized generation ordinal, producer/version/tombstone identity, immutable evidence/provenance/completeness proof, exact prior publication and last-known-good head, plus attributable actor/decision audit evidence.

Database uniqueness is authoritative in both directions: one opaque token cannot bind to two ordinals and one ordinal cannot bind to two opaque tokens for one tenant/source. Exact committed replay is valid only when immutable publication identity and attribution are byte-identical; divergent replay fails deterministically.

Production repositories expose typed bounded operations, never generic raw-SQL callbacks. Partially admitted generations, partial evidence, partial publication and unaudited mutation are never current truth. Crash/cancellation/connection loss retains the prior published snapshot until complete commit. Unknown COMMIT is explicit and never converted to automatic replay or inferred success.

No explicit database lock or long-lived transaction may remain open across LLM calls, external I/O, sandbox execution or long-running computation. Read bounded state and end the transaction, perform slow work outside the transaction, then open a bounded write transaction and revalidate the required optimistic/concurrency predicate before commit. Cross-service SQL remains forbidden.

Remaining hostile acceptance / production gate

Before closure, one unchanged dependency-restacked integration candidate must prove: machine-verifiable 100% owned-production statement/branch/edge/public-rustdoc coverage; production backup/WAL retention/storage authority, encryption and key/IAM ownership without embedded long-lived secrets; production-shaped recovery objectives and destructive restore evidence; readiness/liveness/startup against the authoritative database; preserved historical uniqueness, publication completeness, actor/decision audit linkage, tenant RLS, commit ambiguity, pool bounds and no-replay semantics after restack; terminal CI/Fuzz/security/SAST/CodeQL/review/thread/package/SBOM/provenance/reproducibility/governance evidence on the same exact head; and ordinary protected integration followed by immutable Wardnet release identity binding source, artifact digest, SBOM, provenance/signature, reproducibility, rollback and recovery evidence.

StateAuthority::Postgres remains fail closed until that contract is protected truth. A Draft branch, successful cargo test, recovery fixture, p95 measurement or predecessor receipt is not production authority.

Ownership / architecture

This remains Wardnet Reputation Security Evidence state. It does not move to EgressWeave, contextual-orchestrator, quarantine-sandbox-runtime, AppGuardrail, CGC or EA Core. Keyverse may supply released authenticated tenant/subject claims; Wardnet validates action context and binds its database transaction. Principal lifecycle and backup-storage IAM remain deployment/infrastructure authority.

No source copy, cross-service SQL, mutable foreign production dependency, self/model approval, routine administrator bypass, force/destructive rebase, gate weakening, automatic replay of started database work or predecessor-evidence transfer. Generic solo-maintainer approval remains central .github#772; runner/OpenCode defects remain .github#712/#1234; delegated CodeQL settlement remains .github#1929 or verified successors.

Traceability

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: securitySecurity boundary, hardening, or vulnerability preventionenhancementNew feature or requestpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incident

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions