Skip to content

test(identity): free ended subject after inspect and reconcile - #178

Draft
cursor[bot] wants to merge 19 commits into
mainfrom
cursor/bc-504b6712-2007-48c0-884d-72a5128725f4-de7a
Draft

cursor[bot] wants to merge 19 commits into
mainfrom
cursor/bc-504b6712-2007-48c0-884d-72a5128725f4-de7a

Conversation

@cursor

@cursor cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Why

PR #169 inspects missing or stale unique-enforcer rows after restore. PR #173 asked to fold the buyer rebind path onto that inspect line instead of landing a third persist vehicle: after unlink plus dump restore, a stale current row for the ended Keyverse subject must keep that account occupied until inspect reports drift and restore reconcile rebuilds the unique enforcer. Only then can a later participant bind the freed subject.

TDD

RED restore_inspect_then_reconcile_frees_ended_subject_for_a_new_participant plants a stale current row for ended keyverse_subject_alpha, proves inspect reports drift and persist returns SubjectAlreadyBound, then after reconcile inspect is clean and the new participant_ref recovers. GREEN is the existing #169 inspect + reconcile contract; this PR only locks the buyer path and ADR-0020 Implementation status to the TRACEABILITY landing PR.

Scope

Out of scope

Operator next action

After restore, run inspect_identity_link_current_projection_drift. If it reports drift, run reconcile_identity_link_current_projections before accepting new account-link writes, including a later participant binding an ended subject. Prefer this head over #173 and #169. Do not merge #173, #169, #158, #147, #133, #124, or #114. Do not merge this PR until exact-head checks and independent last-push approval are satisfied. Never self-approve.

Open in Web View Automation 

cursoragent and others added 17 commits August 16, 2026 15:25
A buyer who links an anonymous assessment to a Keyverse account must
still see that link after process restart. Persist assessment_participant
plus append-only link and link-end evidence, reload through the domain
lifecycle, and fail closed on conflicting replay or a subject already
bound to another participant.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Keep TRACEABILITY, ADR-0020, ERD, and as-built schema pointing at the
opened persist/reload vehicle instead of an unnamed Active PR.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
The Active PR #114 naming commit stored an empty ADR-0020. Restore the
accepted decision, including the #114 persistence status and APA 7
references, so identity-link governance is not silently deleted.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Apply each identity link and then its matching ends in one transaction so a complete in-memory unlink+relink aggregate survives restart. Cover one-shot persist, exact replay, and subject reuse after unlink.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Add a tenant-scoped current-subject lookup so a returning Keyverse login can find the same product-owned participant after the anonymous session token is gone. Ended or replaced subjects stay unfindable until they are current again.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Renumber the identity-link migration so it does not collide with #113 scoring-job health indexes on 0021. Name Active PR #124 as the merge candidate over #114.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Remove the accidentally committed build tree and ignore /target so later local verification cannot leak compiler outputs into the identity-link successor.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
A missing current_participant_identity_link row no longer hides a
returning Keyverse login or lets another participant bind the same
issuer-scoped subject. Lookup and uniqueness now read append-only
link rows that have no matching end.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Name the Active PR vehicle as the successor of #124 so TRACEABILITY,
ADR-0020, and the as-built schema do not treat projection-only lookup
as the landing contract.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Add a composite foreign key so a link-end or current projection cannot
point at another participant's identity-link row. Name Active PR #133
as the landing vehicle over #124 and #114.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Exact replay of the same identity-link history now reconciles the derived
current projection so operator repair cannot hide a returning login behind
a missing unique enforcer or leave a stale row after unlink. Name Active
PR #133 in TRACEABILITY instead of superseded #124.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
After dump restore the unique enforcer can be missing or stale even
though unterminated history is intact. Rebuild every current row from
that history, fail closed on two unterminated holders of the same
subject, and prefer this successor over #147.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Keep TRACEABILITY, ADR-0020, ERD, and as-built schema pointing at the
opened restore-reconcile vehicle instead of an unnamed successor of #147.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Add a read-only inspect so operators can see missing or stale unique-enforcer rows after dump restore, fail closed on two unterminated links for one participant, and run reconcile only when that inspect reports drift.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Point TRACEABILITY, ADR-0020, ERD, and the as-built schema at the inspect-and-reconcile landing so writers do not reopen #158 or #133.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Fold the #173 buyer path onto the #169 inspect line: a stale current row for an ended Keyverse subject must keep that account occupied until inspect reports drift and restore reconcile rebuilds the unique enforcer. After that path, a later participant can bind the freed subject. Lock ADR-0020 Implementation status to the TRACEABILITY landing PR.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
@cursor
cursor Bot requested a review from seonghobae August 16, 2026 16:15
Point TRACEABILITY, ADR-0020, AS_BUILT, and ERD at #178 so concurrent writers do not treat #173 or #169 as the identity-link landing vehicle.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review (COMMENT)

Verdict: unique slice SOUND. This is the identity-link landing vehicle.

9e31ca1 / b0bdaff lock the buyer restore path on the #169 inspect line: a stale current_participant_identity_link row for ended keyverse_subject_alpha keeps the unique enforcer occupied, inspect_identity_link_current_projection_drift reports drift and refuses new writes, persist of participant_identity_epsilon returns SubjectAlreadyBound, and only after reconcile_identity_link_current_projections does inspect go clean and the later participant bind and recover. ADR-0020 Implementation status names TRACEABILITY landing #178.

Prefer this head over #173, #169, #158, #147, #133, #124, and #114. Do not merge those. Do not fold HTTP or #166 write-path reconcile into this PR.

Do not merge until exact-head checks and independent last-push approval are satisfied. Never self-approve.

Operator next action: after restore, run inspect_identity_link_current_projection_drift. If it reports drift, run reconcile_identity_link_current_projections before accepting new account-link writes, including a later participant binding an ended subject.

Next slice (not this PR): hosted account-link HTTP on this line after #166 stays a separate write-path vehicle.

Open in Web View Automation 

Sent by Cursor Automation: Fix Issues

cursor Bot pushed a commit that referenced this pull request Aug 16, 2026
Record the dual-proof write successor as the identity-link landing
so concurrent writers do not treat #178 or #160 as the persist vehicle.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Protected-main #81 requires claim_deadline_at on processing
integration_consumption rows. Recovery fixtures that omit the column
fail constraint integration_consumption_claim_deadline_shape.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants