R24: witnessed replay rollback and tamper protection - #199
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
R24 — witnessed replay rollback / tamper protection
Current base: 5a72da3
Current head: b2e32bf
Current tree: 3edc5595bc117d5e04db38bcf4378c713a979a1a
R24 patch SHA-256 vs current master: DF4E64C8621D3E80855CD2017B12DB161FA400864270A7444664871F75AADE4A
R24 patch bytes: 65176
This head explicitly merges current master so the two parallel Remote Commander lines are preserved:
What R24 changes
Previously found blocker and fix
Initial adversarial review found external witness I/O under PostgreSQL FOR UPDATE.
Fixed before freeze: DB snapshot/audit -> release DB transaction/row lock -> external witness CAS/read -> reacquire DB -> require unchanged snapshot -> apply witnessed suffix.
Local evidence on synchronized tree
One earlier concurrent local full run reported a Windows loopback socket abort in
tests/test_company_twin.py::test_explorer_is_loopback_only_and_rejects_mutation_routes
(WinError 10053). It is not in the R24 diff. A clean current-master worktree at
5a72da3 reproduced the same failure on iteration 3, proving it is a baseline/local-Windows
flake rather than an R24 regression. A subsequent full R24 run completed 2280/2280 passed.
Natural GitHub CI is the authoritative cross-environment gate.
Qualification boundary
Protocol/core evidence only, not live production qualification.
Production claims still require a real independent append-only witness, shared PostgreSQL,
Final synchronized exact-head evidence
Current synchronized review bundle SHA-256:
FF106BAA7AAF7D69BE3F6601DC83E288293B3700E91E8E754ED9071909DD8AB1
Fresh synchronized reviewers:
Natural CI on synchronized head b2e32bf:
Baseline-local Windows loopback flake evidence: