Skip to content

fix(nexus): bind queries to portable project identity - #1794

Merged
kryptobaseddev merged 4 commits into
mainfrom
task/T12472-nexus-portable-query
Oct 3, 2026
Merged

kryptobaseddev merged 4 commits into
mainfrom
task/T12472-nexus-portable-query

Conversation

@kryptobaseddev

@kryptobaseddev kryptobaseddev commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Nexus queries derived default IDs from paths, and several readers opened the ambient graph while labeling it as the supplied checkout. Moving or selecting a checkout could therefore change identity or report the wrong graph. Queries now read declared portable identity, resolve recorded unambiguous legacy aliases with warnings, refuse foreign/missing selectors, and open HTTP, clusters, flows, diff and bridge stores at their actual checkout paths.

Closes T12472. Contract comparison resolves registered authorized checkouts rather than decoding IDs into paths. Legacy derivation remains only for compatibility alias population. No shared CLI installation, live Kodo store migration, archive deletion or registry cleanup is included.

Validation:

  • Original focused registry/HTTP/doctor/status run: 99/99 passed.
  • Final registry/bridge run: 55/55 passed, including a two-checkout regression that fails on ambient readers and proves clusters, flows, actual bridge content and diff isolation. Both bridge Drizzle and native reads bind the supplied checkout.
  • Final consumer dispatch/bridge run: 65/65 passed. Unit wiring mocks explicitly represent the identity boundary; real identity refusal/alias tests remain in registry coverage. Original file-bridge assertions remain, and the warning test now proves it reaches EISDIR rather than merely catching a missing identity or isolation guard.
  • Final bounded pagination fixture: 5/5 passed; all original payload-size/paging/malformed-input assertions retained.
  • Built CLI help and portable status/context pass on an isolated sanctioned Kodo snapshot without reanalysis; a foreign selector returns E_NEXUS_CROSS_PROJECT_STATUS.
  • Final full build, Biome (four existing warnings), and all 38 architecture checks pass.
  • Initial full local run: 27,244 passed assertions, 100 failures plus suite-loading errors. Identified identity fixture regressions are repaired; missing unchanged native add-ons and Studio build prerequisites have been provisioned. Recovery of the 74 failing files passes 1,107 assertions, with one remaining abort fixture that hardcoded /tmp/cleo.db; that fixture now uses an owned temporary store and passes all eight original assertions. Final required CI is pending. No initial full-suite or final-CI success is claimed.

The existing source graph truthfully reports stale/unresolved static coverage. This establishes query identity and store isolation, not exhaustive runtime caller discovery. Native artifacts were copied only after proving their source/Cargo lock unchanged, are ignored, and are not included in this PR.

T12472: preserve recorded legacy aliases while refusing ambiguous and foreign graph selectors.
T12472: preserve dispatch and bridge regression assertions with initialized or explicit mock identities; require the warning test to reach EISDIR.
T12472 verification: use an owned temporary store instead of /tmp/cleo.db; preserve all abort assertions and schema guards.
T12472: extend the independent two-store regression to verify actual rendered bridge content and exclude the other checkout.
@kryptobaseddev
kryptobaseddev marked this pull request as ready for review October 3, 2026 03:48
@kryptobaseddev
kryptobaseddev merged commit 9cd8686 into main Oct 3, 2026
96 checks passed
@kryptobaseddev
kryptobaseddev deleted the task/T12472-nexus-portable-query branch October 3, 2026 03:48
kryptobaseddev added a commit that referenced this pull request Oct 3, 2026
Brings in v2026.10.3, #1792 (T13098), #1793, #1794, #1796 (T13100) and
#1800 (T13106). One conflict, in nexus-vault.test.ts: both sides appended
a describe block at the end of the file; both are kept. No other file is
changed by both sides.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011aghp4ZSvreKRQ53YE6nau
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant