Skip to content

R25: qualify witnessed replay against real PostgreSQL - #201

Draft
bitmaster162 wants to merge 6 commits into
masterfrom
agent/r25-replay-production-qualification-r1
Draft

bitmaster162 wants to merge 6 commits into
masterfrom
agent/r25-replay-production-qualification-r1

Conversation

@bitmaster162

@bitmaster162 bitmaster162 commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

R25 — replay production qualification harness

Base: 57c90dd
Head: 614c380
Tree: 1264b2eeb38f261f9c4033131f25719fd8354228
Patch SHA-256: EDDB091C3F76DBC55AE5C74C174CB0BDDAFB316FC028B37299E1A63E22CAAA45
Patch bytes: 71865

What R25 adds

  • real PostgreSQL 17 qualification harness for R24 witnessed replay
  • separate fsync JSONL witness container and named volume
  • eight independent worker subprocess domains
  • deterministic post-witness-fsync crash barrier
  • real pg_dump/pg_restore database rollback recovery test
  • witness outage, PostgreSQL outage, witness rollback, and row-tamper fail-closed tests
  • retry only for PostgreSQL SQLSTATE 40001 serialization_failure and 40P01 deadlock_detected
  • explicit independent DB/logical/exception-chain limits
  • shared snapshot retryable-failure budget across synchronize so outer logical retries cannot reset it
  • successful snapshot reads do not consume the retry budget
  • retry classifier follows explicit cause only, not unrelated implicit context
  • no merge/deploy/runtime/trading/capital authority expansion

Exact local evidence

Final targeted witnessed replay + R25 qualification suite:

  • 34 passed

Full repository exact-head validation:

  • 2295 passed, 2 skipped, 19 subtests passed
  • portable release hardening: 10/10 PASS
  • compileall: PASS
  • governance corpus: PASS
  • git diff --check: PASS
  • worktree: clean

Clean exact-head live qualification

Receipt SHA-256:
4915ADC3AA60DDE4104B62D46A19F390A6A2CB4BF65E8C8D78251794EFFF5D1F

Receipt status:
LOCAL_CONTAINER_QUALIFICATION_GREEN

Environment:

  • Docker Engine 29.8.0
  • PostgreSQL 17.11
  • psycopg 3.3.6
  • postgres:17-alpine digest f02121de6f74d30d8a94cd1d9584125e2178d7e6c377d8130112d4e52d867995
  • python:3.13-alpine witness digest 1a63a53928ce53d2b0baf08092a703f4840ac5dfbd61fd48802dbf48e08c801e
  • worker subprocess domains: 8
  • separate PostgreSQL/witness containers and named volumes
  • host-published ports loopback only

Fault cases PASS:

  1. concurrent double claim: exactly 1 CLAIMED + 7 ALREADY_CONSUMED
  2. PostgreSQL snapshot rollback: recovered from external witness
  3. kill after witness fsync before DB reconciliation: recovered
  4. witness outage: fail closed; recovery succeeds
  5. PostgreSQL outage: fail closed; recovery succeeds
  6. witness-log rollback: database-ahead-of-witness detected fail closed
  7. PostgreSQL claim-row tamper: claim-set integrity failure

Natural exact-head GitHub CI

For 614c380:

  • P0 Unified Shadow Continuity run 35447149482: SUCCESS
  • CodeQL run 35447149487: SUCCESS
  • review-gates run 35447149463: IN PROGRESS
  • Ubuntu / Python 3.11 job: SUCCESS
  • Windows / Python 3.11 job: IN PROGRESS
  • no manual Actions rerun used

Review state

  • Previous full semantic review identified the snapshot-budget availability overcorrection; fixed in 614c380.
  • Claude review of the supplied final exact diff: PASS, no blockers/high. It could not independently verify repository identity, so it is supporting evidence only, not the required exact-head independent review.
  • Hermes/Nemotron full-repository review with independent HEAD/tree verification for 614c380: PENDING.

PR remains Draft until the exact-head independent review and remaining natural provider CI complete.

Retry-budget boundary

The authoritative R25 handoff requires the internal DB transaction retry budget not to be reset/multiplied by the outer logical loop. Final head satisfies that invariant:

  • snapshot retry budget is shared across the whole synchronize call;
  • only retryable DB failures consume it;
  • successful snapshot reads do not consume it;
  • exhaustion fails closed.
    Other operation phases retain separately bounded fail-closed limits; no unbounded retry path is introduced.

Qualification boundary

This PR does NOT claim physical multi-host production qualification.

production_qualified_multi_host=false because:

  • PostgreSQL, witness, and workers share one physical laptop
  • qualification witness is unauthenticated loopback HTTP
  • service-stop outage is not packet-level/asymmetric partition injection
  • host-level rollback could correlate both Docker volumes

Remaining promotion gates:

  • independent witness failure domain
  • at least two physical/VM worker hosts
  • authenticated/encrypted witness transport
  • packet-level/asymmetric partition injection
  • operator witness rotation/recovery drill
  • explicit RTO/RPO/availability evidence

Authority boundary

This PR grants no merge, deploy, runtime, trading, wallet, or capital authority.
can_trade=false
capital_permission=DENY
deploy_permission=DENY

Actual merge requires a new exact Human approval token after final exact-head review/freeze.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant