You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat(coordination): fence NoKV authority publication on the workbench incarnation
Every NoKVAuthorityStore publication now names the workbench incarnation the
envelope was read from (`expected_workspace_incarnation_id`). NoKV 0.11.1
evaluates that fence atomically with the generation before any durable row or
object exists and refuses a stale incarnation with a typed exception, so a
workbench restored to a new incarnation between the read and the publish
refuses the write instead of accepting it at a restarted generation. The
JSON-lines helper maps that refusal to `failed/store_identity_mismatch`
(the same vocabulary the PostgreSQL service uses for a stale incarnation) and
keeps a refusal that names a different fence, or an untyped RuntimeError, on
the ambiguous path. Successful publications are still accepted only after the
current-incarnation readback required by RFC 6.2.
The helper pins NoKV SDK 0.11.1 / API 1 and admits only a wheel whose
`Client.publish_bytes` names the fence parameter and whose module exports
`WorkspaceIncarnationMismatch`; a 0.11.1-labelled wheel without that surface
is refused as `nokv_sdk_capability_mismatch` before any client is constructed,
and the request path rejects a publication without a valid fence before the
SDK call. The Stage 2A live probe gains two checks that publish the
generation-1 envelope with a stale fence and prove the typed refusal, the
unchanged generation and the unchanged workbench identity; the ladder row
`s2a.nokv_live_qualification` requires both checks and the 0.11.1 pin.
Tests: helper unit tests for the typed refusal, the fence validation and the
admission matrix; a fake SDK fixture with 0.11.1, 0.11.0 and 0.11.1-unfenced
shapes; transport tests through the real helper process for the refusal and
both admission rejections; store tests for the fence on every publication, the
refused incarnation race and the fence-ignoring owner; harness tests for the
new checks and a fence-ignoring backend; a pin consistency test across the
helper, ladder and probe.
Signed-off-by: wchwawa <wch19961116@gmail.com>
Copy file name to clipboardExpand all lines: examples/shared-goal-authority-e2e/README.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -35,7 +35,7 @@ suites rather than in the pytest shards.
35
35
|`s0.file_matrix_twelve_rows`| 0 | store_direct | deterministic |`examples/nokv-shadow-provider/live_e2e.py` reports exactly the twelve known file-provider scenario rows, all true |
36
36
|`s0.nokv_live_matrix`| 0 | store_direct | env:nokv_legacy| the same twelve rows plus `restored_lineage_fails_closed` are true on a live NoKV stack and file/NoKV outcomes are identical |
37
37
|`s1.cli_document_decodes_through_ts_store`| 1 | real_cli | deterministic | three CLI writes (`todo add`, `task-lease acquire`, `todo update`) read back through `FileAuthorityStore`: `loadAuthority` loaded at cursor `3`, paged `scanCommitted` yields the three `observation_id`s in order, `readReceipt` finds the first |
38
-
|`s2a.nokv_live_qualification`| 2a | store_direct | env:nokv_authority| runs the merged `examples/nokv-authority-store/live-qualification.ts --execute-live` against an existing workbench with a fresh tenant/goal pair; requires `ok=true`, the single-node store-conformance scope, every check `passed`, NoKV SDK `0.11.0` / API `1`, and no promotion or availability claim; evidence carries check ids, counts, and config and workbench digest prefixes, never a configuration value or the workbench name |
38
+
|`s2a.nokv_live_qualification`| 2a | store_direct | env:nokv_authority| runs the merged `examples/nokv-authority-store/live-qualification.ts --execute-live` against an existing workbench with a fresh tenant/goal pair; requires `ok=true`, the single-node store-conformance scope, every check `passed`, NoKV SDK `0.11.1` / API `1`, the two stale-incarnation fence checks (`stale_incarnation_fence_rejected`, `stale_incarnation_fence_left_generation_unchanged`), and no promotion or availability claim; evidence carries check ids, counts, and config and workbench digest prefixes, never a configuration value or the workbench name |
39
39
|`s2b.postgresql_conformance_live`| 2b | store_direct | env:postgresql|`postgresql_authority_store.integration.test.ts` under node's TAP reporter: `# pass >= 9`, `# fail 0`, `# skipped 0`|
40
40
|`s2c1.configure_enable_disable_roundtrip`| 2c1 | real_cli | deterministic |`configure-goal` preview does not write, enable writes, captured observations for a todo and a lease, read-back summary `enabled/file_one_way`, disable writes and later writes neither observe nor touch candidate bytes |
41
41
|`s2c1.every_writer_family_captures`| 2c1 | real_cli | deterministic | handoff-mode set, todo add/update/complete/supersede/archive-completed, task-lease acquire/renew/transfer each carry `outcome in {captured, replayed, ambiguous_reconciled}`, `primary_writeback_preserved=true`, `provider_to_local_writes=false`, `candidate_read_for_decision=false`; an idempotent re-acquire carries no `authority_shadow`; candidate `cursor == captured count`, operation ids equal observation ids, no time-active lease in the head, head todos equal `todo list`|
@@ -86,7 +86,7 @@ TypeScript store read.
86
86
|`deterministic`| none (needs `node` on `PATH` for the CLI's TypeScript runtime and the read-back probe) |`node_missing` when the probe cannot run |
87
87
|`env:postgresql`|`LOOPX_TEST_POSTGRES_URL` plus `node_modules/pg` (`npm ci`) |`postgres_url_missing`, `pg_dependency_missing`, `node_missing`|
88
88
|`env:nokv_legacy`|`NOKV_COORDINATION_LIVE=1` and `NOKV_ETCD`, `NOKV_ETCD_PREFIX`, `NOKV_ROOT_ID`, `NOKV_BUCKET`, `NOKV_OBJECT_ENDPOINT`, `NOKV_OBJECT_ROOT`, `NOKV_OBJECT_KEY`, `NOKV_OBJECT_SECRET`; the `nokv` SDK importable |`nokv_live_env_missing`, `nokv_coordination_live_not_enabled`, `nokv_sdk_missing`|
89
-
|`env:nokv_authority`|`LOOPX_NOKV_AUTHORITY_LIVE=1` (the probe writes durable test data), `LOOPX_NOKV_AUTHORITY_CONFIG_JSON` (absolute path to the ignored NoKV client configuration), `LOOPX_NOKV_AUTHORITY_PYTHON` (absolute path to the Python executable that resolves NoKV SDK 0.11.0), `LOOPX_NOKV_AUTHORITY_WORKBENCH` (an existing workbench); `node` on `PATH`|`nokv_authority_env_missing`, `loopx_nokv_authority_live_not_enabled`, `nokv_authority_config_missing`, `nokv_authority_python_missing`, `node_missing`|
89
+
|`env:nokv_authority`|`LOOPX_NOKV_AUTHORITY_LIVE=1` (the probe writes durable test data), `LOOPX_NOKV_AUTHORITY_CONFIG_JSON` (absolute path to the ignored NoKV client configuration), `LOOPX_NOKV_AUTHORITY_PYTHON` (absolute path to the Python executable that resolves NoKV SDK 0.11.1), `LOOPX_NOKV_AUTHORITY_WORKBENCH` (an existing workbench); `node` on `PATH`|`nokv_authority_env_missing`, `loopx_nokv_authority_live_not_enabled`, `nokv_authority_config_missing`, `nokv_authority_python_missing`, `node_missing`|
90
90
91
91
POSIX-only rows report `unverified/posix_only` on Windows.
0 commit comments