fix(response): prove restart times, recovery, and item-three prefix - #201
cursor[bot] wants to merge 6 commits into
Conversation
A two-item path can now reload the same answers after restart without re-checking live session activity. Gapped sequence, reused client or server identity, and blank session references fail closed. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Store accepted response_event rows with observed and received time so a two-item path reloads the same answers after process restart. Exact replay is idempotent; client, server, sequence, or session rebinding fails closed under READ COMMITTED. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
A Korean path can now reload stored observed/received time, continue with item 3 after restart, and keep those rows through recovery COPY. Misaligned event times fail as arity, not a clock error. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
There was a problem hiding this comment.
Review
#201 is no longer the persist landing.
Recovery COPY inserted observed_at / received_at but only asserted identity, digest, and sequence. A buyer who restores after a crash would not have proof that first-write times survived. Several persist fail-closed arms were also untested: pre-epoch stored clocks, numeric session refs on load_response_event_times, REPEATABLE READ time loads, missing-relation persist, loaded-sequence overflow, and millisecond overflow. postgres_timestamptz kept an untestable checked_add overflow arm that cannot fire for any u64 millisecond offset on Unix SystemTime.
Prefer PR #208 (65566fb). That head keeps the #201 persist/load contract and adds:
- recovery COPY assertions for first-write observed/received unix-ms
- fail-closed reload for pre-epoch clocks, numeric session refs, and repeatable-read time loads
- typed
Databasefailure when the relation is missing - unit coverage for sequence/millisecond overflow and operator-facing error copy
- removal of the dead
checked_addarm
Do not merge #201, #174, #182, or #53 in parallel. HTTP POST /v1/sessions/{session_ref}/responses stays on #195. Do not self-approve. Independent last-push review is still required before merge.
Sent by Cursor Automation: Fix Issues
|
Closing as superseded by PR #208. #208 explicitly carries this response-event persist/load/restart contract and adds the missing recovery assertions for first-write observed/received instants plus fail-closed coverage for stored clocks, alias/isolation/database failures, sequence/millisecond boundaries, and operator-facing errors. Its current scope says to prefer #208 over #201/#174/#182/#53 and not land the overlapping persistence heads in parallel. Continue exact-head CI/review on #208 or its later successor; do not merge this head separately. |


Why
Protected main can freeze a completed response snapshot, but a buyer still loses in-progress answers on process restart. #174 persisted the ledger with observed/received time. That head still omitted recovery COPY, AS_BUILT, stored-time reload, and the continue-after-restart scoring prefix.
Prefer this head over #174, #182, and #53. Do not land those overlapping persist slices in parallel.
This is independent of Active PR #161/#149 (session HTTP), #154 (session command lock), #151 (completed snapshot reload), and #162 (restricted linkage). Do not fold those slices into this head.
What
ResponseLedger::from_persistedrebuilds server sequence1..nafter restart without re-checking live session activity.migrations/0020_response_event.sqlstores opaque event identity, session binding, client idempotency, item version, payload digest, server sequence, and distinct observed/received timestamps.persist_response_ledger/load_response_ledgeruseREAD COMMITTEDinsert-then-classify. Exact replay is idempotent; client, server, sequence, or session rebinding fails closed.load_response_event_timesreturns first-write observed/received unix-ms pairs aligned with the reloaded ledger.event_timesfail asInvalidEventTimeArity, not a clock error.response_eventrows. AS_BUILT and doctoring name the slice and the isolation/time citations.Out of scope
POST /v1/sessions/{session_ref}/responses#55/#151)#161/#149/#154)Test plan
cargo test --lib postgres_response_eventcargo test --test response_ledgercargo test --test documentation_architecture_contract --test traceability_active_pr_contractcargo clippy --all-targets -- -D warningscargo test --test postgres_response_event_persistence --test postgres_response_event_error_contract --test postgres_recovery_invariants(needsTEST_DATABASE_URL)Do not merge until exact-head checks and independent last-push approval are satisfied. Do not self-approve.