Skip to content

R24: witnessed replay rollback and tamper protection - #199

Merged
bitmaster162 merged 2 commits into
masterfrom
agent/r24-replay-rollback-tamper-r1
Sep 18, 2026
Merged

bitmaster162 merged 2 commits into
masterfrom
agent/r24-replay-rollback-tamper-r1

Conversation

@bitmaster162

@bitmaster162 bitmaster162 commented Sep 18, 2026 •

Copy link
Copy Markdown
Owner

R24 — witnessed replay rollback / tamper protection

Current base: 5a72da3
Current head: b2e32bf
Current tree: 3edc5595bc117d5e04db38bcf4378c713a979a1a
R24 patch SHA-256 vs current master: DF4E64C8621D3E80855CD2017B12DB161FA400864270A7444664871F75AADE4A
R24 patch bytes: 65176

This head explicitly merges current master so the two parallel Remote Commander lines are preserved:

What R24 changes

  • external append-only witness protocol for R23 multi-host replay state
  • detects DB rollback/snapshot restore, journal/claim/schema tamper, witness rollback, truncated/reordered history, direct unwitnessed claims
  • recovers PostgreSQL materialization from authoritative witnessed history
  • preserves R23-compatible claim receipts and R17 approval semantics
  • separate witnessed multi-host production entrypoint; no silent fallback to R23/SQLite/memory
  • pre-existing R23 claims require explicit migration
  • no merge/deploy/runtime/trading/capital authority added

Previously found blocker and fix

Initial adversarial review found external witness I/O under PostgreSQL FOR UPDATE.
Fixed before freeze: DB snapshot/audit -> release DB transaction/row lock -> external witness CAS/read -> reacquire DB -> require unchanged snapshot -> apply witnessed suffix.

Local evidence on synchronized tree

  • targeted R17-R24: 54 passed
  • release hardening: 10/10 PASS
  • repeated full repo: 2280 passed, 2 skipped, 19 subtests
  • isolated wheel-only: 2148 passed, 112 skipped, 19 subtests
  • source_root_excluded=true
  • wheel SHA-256: 8EC0AA04D64EC959CF9D6B4FFCBD59C5193761134AF589DBC19218A889DE4EFF
  • compile + git diff --check: PASS

One earlier concurrent local full run reported a Windows loopback socket abort in
tests/test_company_twin.py::test_explorer_is_loopback_only_and_rejects_mutation_routes
(WinError 10053). It is not in the R24 diff. A clean current-master worktree at
5a72da3 reproduced the same failure on iteration 3, proving it is a baseline/local-Windows
flake rather than an R24 regression. A subsequent full R24 run completed 2280/2280 passed.
Natural GitHub CI is the authoritative cross-environment gate.

Qualification boundary

Protocol/core evidence only, not live production qualification.
Production claims still require a real independent append-only witness, shared PostgreSQL,

=2 execution hosts/process domains, network-partition/crash injection, real DB snapshot
restore, bounded witness transport/timeouts/HA/telemetry, and operator recovery/rotation.

Final synchronized exact-head evidence

Current synchronized review bundle SHA-256:
FF106BAA7AAF7D69BE3F6601DC83E288293B3700E91E8E754ED9071909DD8AB1

Fresh synchronized reviewers:

  • Hermes: PASS; blockers=0, high=0
  • Claude Sonnet 5: PASS; blockers=0, high=0
    • medium hardening notes: string-grep authority smoke-test is weak; narrow read-after-audit TOCTOU window is detected on next synchronize; prior serialization/deadlock retry note remains availability hardening
    • none is a replay bypass; qualification remains explicitly not production-ready

Natural CI on synchronized head b2e32bf:

  • P0 Unified Shadow Continuity: SUCCESS
  • CodeQL: SUCCESS
  • Ubuntu review-gates: SUCCESS
  • Windows review-gates: SUCCESS
  • Windows full editable-install pytest, wheel-only, governance regression, hardening, Ed25519 verification, receipts: SUCCESS

Baseline-local Windows loopback flake evidence:

  • tests/test_company_twin.py::test_explorer_is_loopback_only_and_rejects_mutation_routes can intermittently abort with WinError 10053
  • reproduced on clean current master 5a72da3 without R24 on iteration 3
  • therefore not attributed to R24
  • natural GitHub Ubuntu + Windows review-gates both passed the exact synchronized head

@bitmaster162
bitmaster162 marked this pull request as ready for review September 18, 2026 13:20
@bitmaster162
bitmaster162 merged commit 5e6887a into master Sep 18, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant