Skip to content

fix(response): prove restart times, recovery, and item-three prefix - #201

Closed
cursor[bot] wants to merge 6 commits into
mainfrom
cursor/bc-a6a12e01-318b-4b13-b769-74b741c16d49-5648
Closed

cursor[bot] wants to merge 6 commits into
mainfrom
cursor/bc-a6a12e01-318b-4b13-b769-74b741c16d49-5648

Conversation

@cursor

@cursor cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Why

Protected main can freeze a completed response snapshot, but a buyer still loses in-progress answers on process restart. #174 persisted the ledger with observed/received time. That head still omitted recovery COPY, AS_BUILT, stored-time reload, and the continue-after-restart scoring prefix.

Prefer this head over #174, #182, and #53. Do not land those overlapping persist slices in parallel.

This is independent of Active PR #161/#149 (session HTTP), #154 (session command lock), #151 (completed snapshot reload), and #162 (restricted linkage). Do not fold those slices into this head.

What

  • ResponseLedger::from_persisted rebuilds server sequence 1..n after restart without re-checking live session activity.
  • migrations/0020_response_event.sql stores opaque event identity, session binding, client idempotency, item version, payload digest, server sequence, and distinct observed/received timestamps.
  • persist_response_ledger / load_response_ledger use READ COMMITTED insert-then-classify. Exact replay is idempotent; client, server, sequence, or session rebinding fails closed.
  • load_response_event_times returns first-write observed/received unix-ms pairs aligned with the reloaded ledger.
  • Misaligned event_times fail as InvalidEventTimeArity, not a clock error.
  • Recovery COPY restores response_event rows. AS_BUILT and doctoring name the slice and the isolation/time citations.

Out of scope

  • HTTP POST /v1/sessions/{session_ref}/responses
  • Raw response bodies
  • Completed snapshot changes (#55 / #151)
  • Session persist/HTTP (#161 / #149 / #154)

Test plan

  • cargo test --lib postgres_response_event
  • cargo test --test response_ledger
  • cargo test --test documentation_architecture_contract --test traceability_active_pr_contract
  • cargo clippy --all-targets -- -D warnings
  • cargo test --test postgres_response_event_persistence --test postgres_response_event_error_contract --test postgres_recovery_invariants (needs TEST_DATABASE_URL)

Do not merge until exact-head checks and independent last-push approval are satisfied. Do not self-approve.

Open in Web View Automation 

cursoragent and others added 6 commits August 16, 2026 16:10
A two-item path can now reload the same answers after restart without
re-checking live session activity. Gapped sequence, reused client or
server identity, and blank session references fail closed.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Store accepted response_event rows with observed and received time so a
two-item path reloads the same answers after process restart. Exact
replay is idempotent; client, server, sequence, or session rebinding
fails closed under READ COMMITTED.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
A Korean path can now reload stored observed/received time, continue with
item 3 after restart, and keep those rows through recovery COPY. Misaligned
event times fail as arity, not a clock error.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Prefer this head over #174, #182, and #53 so later agents do not open
another overlapping response_event persist slice.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
@cursor
cursor Bot requested a review from seonghobae August 16, 2026 16:30
cursor Bot pushed a commit that referenced this pull request Aug 16, 2026
Prefer this head over #201, #174, #182, and #53. Recovery COPY now
asserts first-write times; HTTP response transport stays outside.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review

#201 is no longer the persist landing.

Recovery COPY inserted observed_at / received_at but only asserted identity, digest, and sequence. A buyer who restores after a crash would not have proof that first-write times survived. Several persist fail-closed arms were also untested: pre-epoch stored clocks, numeric session refs on load_response_event_times, REPEATABLE READ time loads, missing-relation persist, loaded-sequence overflow, and millisecond overflow. postgres_timestamptz kept an untestable checked_add overflow arm that cannot fire for any u64 millisecond offset on Unix SystemTime.

Prefer PR #208 (65566fb). That head keeps the #201 persist/load contract and adds:

  • recovery COPY assertions for first-write observed/received unix-ms
  • fail-closed reload for pre-epoch clocks, numeric session refs, and repeatable-read time loads
  • typed Database failure when the relation is missing
  • unit coverage for sequence/millisecond overflow and operator-facing error copy
  • removal of the dead checked_add arm

Do not merge #201, #174, #182, or #53 in parallel. HTTP POST /v1/sessions/{session_ref}/responses stays on #195. Do not self-approve. Independent last-push review is still required before merge.

View PR

Open in Web View Automation 

Sent by Cursor Automation: Fix Issues

Copy link
Copy Markdown
Contributor

Closing as superseded by PR #208. #208 explicitly carries this response-event persist/load/restart contract and adds the missing recovery assertions for first-write observed/received instants plus fail-closed coverage for stored clocks, alias/isolation/database failures, sequence/millisecond boundaries, and operator-facing errors. Its current scope says to prefer #208 over #201/#174/#182/#53 and not land the overlapping persistence heads in parallel. Continue exact-head CI/review on #208 or its later successor; do not merge this head separately.

@seonghobae seonghobae closed this Aug 16, 2026
cursor Bot pushed a commit that referenced this pull request Aug 16, 2026
Prefer the continue-from-reload successor over #182 and the overlapping
#174/#201 persist slices. HTTP response transport stays outside this head.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants