Wallet interoperability and reliability: bounded sync, proof recovery and BRC-118 payments - #569
ty-everett wants to merge 121 commits into
Conversation
|
PR #569 remains open, draft and unmerged; auto-merge and reader advertisement stay off. Pushed head This batch addresses the four remaining hosted Sonar findings, retains JavaScript runtime input validation, and adds receipt tests for exact expiry/floor/capacity, malformed persisted metadata, canonical BIGINT responses, driver aliases and binding boundaries. The bounded capacity projection now uses a numeric alias. The failed receipt mutant was the empty Validation on this batch:
The prior 5de CI is terminal with 37 successful jobs but four Sonar findings and dependent mutation/merge-gate failures. Exact-head hosted qualification and the complete current journal/retained campaign are now running. The full #544 implementation remains incomplete: capture fence and connection-pair lifecycle work are outside-checkout drafts; the complete controller, continuity floor/retention, registered migration, receiver/primary, portable/remote/platform and performance work remain open. No release, deployment or funded action occurred. |
|
Paused at the maintainer’s request. PR #569 remains OPEN/DRAFT/UNMERGED at Current-head receipt/root/native qualification and the mandatory zero-new-Sonar gate pass; CodeQL, Conformance, Codegen and Container runtime contracts also passed. Complete CI 37040055306 remains pending, so no green repository gate or readiness claim is made. Local complete campaigns were stopped for this pause with all 4,544 authored inputs unchanged. Six parts had completed (revision, high-water, page, clock, MySQL observers, MySQL source), in addition to the previously completed receipt part. The retained-reader campaign recorded one native SIGSEGV before cancellation; its cause remains unresolved and it has no completed current-head result. The capture-fence and connection-reservation drafts remain outside the branch. An earlier connection draft passed ten tests including 300 generated schedules; subsequent backend/cleanup and retained-lifecycle edits are unvalidated and are being preserved as unfinished drafts, not qualified implementation. The full #544 program remains incomplete: concrete capture publication/lifetime/backend integration; retention floors, tombstone collection and complete row/byte/physical quotas; registered journal lifecycle; generation-aware receiver/provenance and primary reconciliation; remaining remote/IndexedDB/large-blob/streaming BRC-38/39/staged-import work; and complete platform/performance/fault/exact-head acceptance. Release, deployment and funded/physical drills remain separate authorized execution gates. No publication, deployment or funded action occurred. Owned local work is stopped. Hosted CI may finish independently; there is no unattended agent monitoring. BotBoard #727 is being released without an acknowledged successor. Resume requires a fresh handle, current-main reconciliation and review of the preserved partial evidence and drafts. |
…erop-reliability # Conflicts: # docs/packages/helpers/templates.md # docs/reference/package-api-migrations.md # docs/reference/stack-facts.md # governance/package-release-notes.json # governance/repository-health/baselines.json # packages/helpers/ts-templates/CHANGELOG.md # packages/helpers/ts-templates/package.json
|
Capture and main reconciliation are now pushed at The owned native capture implementation commits the durable receipt before publishing a coherent thirteen-table source, reserves distinct verified connections, and retains admission through proved physical cleanup. Current local root gates, packed consumers and 55 focused capture tests pass. Refreshed native evidence covers WAL generation/capture process cuts and all four MySQL generation/server-restart/receipt/capture groups. Serialized full wallet coverage passes 5,585 tests across 389 suites, with seven governed skips; the earlier two SQLite fixture failures and successful retries remain in the evidence record. This is a qualified component batch, not the completed #544 program. Exact-head hosted checks and complete applicable mutation still need proof. Retention floor/collection currently have an unadopted 60-test/300-ledger draft and are entering native isolation and process-loss qualification. Runtime quotas, registered recovery, receiver/primary, IDB/remote destination, streaming portability/staged import and the remaining eleven-row system/platform acceptance inventory remain open. Incremental reader advertisement stays off. Publication, deployment, funded operations and physical drills require separate authorization after concrete artifacts are ready. |
…erop-reliability # Conflicts: # docs/reference/package-api-migrations.md # governance/package-release-notes.json # packages/messaging/message-box-client/CHANGELOG.md
|
The held-open #569 branch is pushed at This batch adds internal floor advancement and bounded primary-key tombstone collection. Floors respect live receipts and database-clock expiry; scans count live/newer rows, bind cursors to epoch/floor/stream, and delete only matching old absent metadata. All thirteen source tables remain unchanged in native recovery cohorts. No incremental reader advertisement or journal migration publication is enabled. Local merged-head validation: root health/lint/format/types/security audit; 766 journal tests/19 suites with separate 300-ledger floor and collection models; 414 MessageBox tests/16 suites; both packages' clean packed consumers; native WAL and six MySQL groups, including 24 retention process-loss cuts; four TS and nine CJS modules with zero local typed findings. Collection mutation feedback is 96.8912% (372 killed, 2 timeout, 12 survivors), zero uncovered/invalid and zero unexecuted survivors. One native worker SIGSEGV was retried and retained; this is one execution part, and complete nineteen-module/seventeen-part qualification remains pending. The first failed 70.47% run is retained. The two capture fixture CodeQL races on prior |
…erop-reliability # Conflicts: # docs/reference/container-supply-chain.md
|
PR #569 remains OPEN, draft and unmerged; auto-merge is off. Pushed head Reconciliation preserves every wallet source/test/timeout union and native fingerprint input, and the corrected regression requires ordinary PR concurrency six and full campaign concurrency twenty. Required local root gates and affected fund-wallet/402-pay coverage, builds and packed consumers pass. No finding, threshold or skip was waived. Full #544 remains active and unfinished. Outside-source journal maintenance drafts have WAL and MySQL RC/RR controller/provider proofs, bounded collection preserving all thirteen source arrays, cancellation/destruction admission fences and physical connection cleanup. Eleven task lifecycle cases and twelve migration-fence cases pass with complete measured module coverage, including 300 seeded schedules. Full controller fault tests, complete additive source/test/native/mutation registration, runtime quotas and registered journal lifecycle/recovery remain required. Primary/receiver, remote/IDB, streaming encryption/staged import, consumer/performance/fault/full-system evidence and operator release/funded/physical acceptance also remain open. Reader advertisement stays off; this update authorizes no merge, publication, deployment or funded/physical action. |
|
Owned bounded journal maintenance is pushed at be0be62, with current main729ad70e0cf5d507319ded3583691184f47ba488 already reconciled. The internal provider controller validates complete owned generation/epoch/ceiling/receipt policy and excludes the configured migration owner before each bounded floor or collection transaction. Shared source admission remains owned through cancellation, rollback and physical connection/pool drain; cleanup failure remains observable and fences further retained work. Raw operator DDL remains outside the configured migration-owner contract. Validation for this batch:
Exact-new-head hosted CI and the complete manual Mutation quality campaign are being started/monitored. There is no new-head green or full-program readiness claim yet. Runtime quotas and registered forward lifecycle/recovery are next; generation-aware payload/receiver, remaining remote/IDB, streaming/staged portability, platform/performance and release/operator acceptance remain open in the eleven-row#544 inventory. Reader advertisement remains off. PR#569 stays draft, open and unmerged with auto-merge disabled; no publication, deployment or funded/physical action is authorized. |
|
Pushed head be0be62 now passes all57 ordinary hosted check runs (55success,2 governed skips), including the complete CI final gate, all six wallet shards/current Linux native recovery, conformance/runtime, the exact-head zero-new-Sonar gate and separate CodeQL reporting with zero new alerts/annotations. CI37081013773, CodeQL37081013698, runtime37081013675 and conformance37081013788 all succeed. The Sonar job's single annotation is an Ubuntu runner-label migration notice, not a code finding. The separately dispatched complete Mutation quality37081056554 remains active against this exact head. Its complete93-part inventory retains all target/test/native input unions and governed floors; no full-campaign success is claimed until its reports/gate finish. The next quota work remains outside the branch: exact logical-accounting38 tests/300 seeded schedules pass, and a corrected actual WAL component experiment passes ordinary source-write availability at row/byte/window exhaustion plus exact update/tombstone/rollback/credit accounting. The first unbootstrapped complete-journal oracle failure is retained and corrected. MySQL enforcement, source-event fan-out, whole forward-generation upgrade/crash recovery and complete target qualification remain pending; none of that prototype is an installed or production-qualified generation. All11#544 rows remain open. #569 stays draft/open/unmerged with auto-merge off and reader advertisement disabled. |
|
Exact pushed head The downloaded report identifies fixture validation running during module import in the capture and maintenance tests. Mutated validation rejects those fixtures before Jest can judge the tests. The local correction moves that validation into The bounded quota work remains outside the branch. Owned native WAL and MySQL RC/RR accounting checks pass row/byte/window exhaustion, source-write availability and transactional exact credits. Forward generation/recovery, full fan-out bounds, concurrency/process-loss qualification and the other full #544 requirements remain open. PR stays open/draft/unmerged with auto-merge and reader advertisement off; no publication/deployment/funded or physical actions. |
|
Pushed fixture-only correction The same complete revision partition now passes locally: all72 mutations,97.22%,69 killed/one timeout/two equivalent survivors; zero invalid/uncovered/unexecuted and all1599 frozen inputs unchanged. The full821-case journal dryrun,36 affected tests, strict whole-test typing, zero-new local typed analysis and root health/lint/format/types/audit pass. The initial root-health failure from concurrent Stryker sandbox discovery remains retained; after cleanup the unchanged health gate passes. Exact-head ordinary CI is running; conformance has passed. Full Mutation quality37084010210 was dispatched without a diagnostic target and queues behind the prior full campaign under unchanged concurrency. Historicalbe0 ordinary CI was green, but its full campaign revision failure remains a failed receipt, never a success claim. Complete new-head qualification and maintainer re-review remain required. Outside-only quota proof also found and fixed an actual MySQL RR deadlock at simultaneous exhausted-quota admission: quota exclusivity must precede the current invalidation read. The same controlled two-writer test now passes RC/RR without retries, alongside accounting, source availability, credits, stale snapshots and actual400-byte UTF8 boundaries. No quota source is adopted or production-qualified yet; forward generation/recovery, complete event fan-out, crash/performance/platform proof and the other full #544 requirements remain open. Reader advertisement, merge/publication/deployment/funded/physical actions stay off. |
|
Pushed head The prior campaign has also reported retained-storage feedback at 85.79%, with four uncovered mutants and 22 survivors. The report is retained. I have added four lifecycle regression cases and strengthened existing cleanup assertions: destruction during deferred capture/maintenance configuration must refuse database access, malformed maintenance input must release admission, provider destruction must stop/drain active maintenance, and teardown must detach all query listeners. These changes pass all 40 focused tests, strict whole-test typing and zero new selected typed-analysis findings. The complete original retained-storage union passes 978 tests/47 suites. Local feedback now executes all five original storage source ranges and the complete original test union with 3,219 frozen inputs; its mutation result and required root checks are pending before push. Production source and the gates are unchanged. The first new shutdown-test oracle failures are retained; the corrected tests preserve existing error identities. Outside quota work passes 83 pure/native cases with complete measured coverage of the three policy/SQLite modules, six-overlay strict typing and zero new typed findings. The full canonical journal union plus all new quota tests passes the 904-test mutation dry run; all three complete modules are being mutated with 1,604 frozen inputs. Previous WAL/RC/RR accounting evidence includes 18 transaction process-loss cuts. This is component feedback only: installed v1 is refused unchanged, and registered forward upgrade/recovery, whole-source-event fan-out bounds and provider/reader adoption remain unfinished. #569 stays open, draft and unmerged, with auto-merge and reader advertisement off. All eleven #544 acceptance rows remain open; ordinary CI, a component test suite or one mutation part does not establish full program or production completion. No publication, deployment or funded/physical action is authorized by this update. |
|
Current #569 head66f3001f962eb769984af70d1e37b07a7a02a0d0 still includes main729ad70e0 and has57 ordinary terminal-green checks, but the full #544 program is unfinished and the PR remains draft/open/unmerged with auto-merge and reader advertisement off. Full mutation37081056554 on the preceding be0 head now reports six failed parts (revision, retained-storage, connections, capture-fence, capture-backend, capture) and11retained-snapshot cancellations at the preserved90minute wall deadline. Current66 full37084010210 is queued behind it. No cancelled, stale or failed part is accepted as qualification; no gate, union, worker, seed or deadline is relaxed. The fixture-only revision fix is already pushed. The current coherent test batch adds lifecycle and backend/connection/fence boundary proof:40lifecycle cases plus the original978-case retained-storage selection pass;87boundary cases, strict whole-source typing and zero selected typed findings pass. Complete original retained-storage mutation feedback is still active; its native worker crash warning is preserved. Fresh root audit now fails high GHSA-vfj7-8cjw-p6xm through the unchanged Metro development closure. Under the exact #756 coordination ACK, a narrow two-file Metro-file-map patch calls its existing Picomatch2.3.2 loop directly and removes scoped micromatch and the now-unused affected closure. Outside frozen install, exact structural graph comparison (all41importers/settings and1631retained package metadata unchanged;no version drift), unexcluded fresh audit,1120+300seeded watcher comparisons and unchanged native Metro/Hermes platform/budget checks pass with1719copied artifact inputs unchanged. Canonical adoption and full affected validation follow when frozen workers drain; there is no advisory exclusion or audit waiver. Outside quota generation passes108pure/native tests/full measured three-module coverage, while preceding whole-module mutation failed84.45 against90 with904dryrun tests and1604inputs unchanged. That failure is retained and more meaningful integrity/boundary proof is being added. Registered v1 forward upgrade/recovery, complete per-source-event fan-out and provider/reader/receiver integration are still required. All11acceptance rows in the #544 program remain open. Component tests/ordinary CI do not establish readiness for merge or production; no publication/deployment/funded/physical action has occurred. |
|
Pushed a7ceefb86: a native regression demonstrated that transaction cleanup could replace the original capture/receipt failure. The compatible fix keeps the original cause alongside actual rollback failures; successful cleanup preserves the original rejection. Added cases cover real rollback/destroy failures and storage, fence and provider lifecycle boundaries. The coherent batch also removes the vulnerable unused Metro/micromatch/braces closure through the ACKed exact-version watcher repair. Paired JS/Flow preserve existing Picomatch2.3.2 semantics; the1120-case installed watcher oracle, complete unexcluded audit and frozen graph comparison pass, with all41 importers/settings/1631 surviving package records unchanged and zero added/changed versions. Root policy records ownership, review date and removal conditions. Validation:145focused cases/strict/no introduced typed findings;2378 tests across92 source suites at unchanged production bytes; fresh SDK/full/client/mobile builds and3 packed checks; native browser/Metro/Hermes/maps/composition at unchanged budgets; SQLite process-loss and all8MySQL groups. Complete Capture module/original888-test union now scores93.41 with zero uncovered/invalid/unexecuted mutants and4882 frozen inputs unchanged. Other unchanged whole modules pass Backend92.20/Fence93.15/Connections98.48 local feedback. The previous Capture run's two uncovered branches and all failed hosted results remain retained; this is local feedback, not full-campaign qualification. #569 remains draft/open/unmerged, auto-merge and reader advertisement off. All11 #544 acceptance rows remain open. Registered forward quota upgrade/recovery, whole-event fan-out, bounded primary reconciliation, durable remote destination, complete portability/adoption/performance/platform proof and release drill work remain in progress. New recovery prototypes are outside the branch until qualified. Exact-head hosted CI/full mutation and maintainer approval still need to pass; no production-ready claim. |
|



Program and scope
Wallet backup can hold manager ownership across a whole copy and block foreground work. Supported local SQL push, pull and backup now use a dedicated coherent source view and short atomic destination commits. Rows, bounded ID mappings and cursors commit together. Primary epochs and manager generations fence stale work; lost acknowledgements resume durable checkpoints. Unsupported providers retain the serialized path.
Issue #544 and the acceptance matrix define the complete program. BotBoard #727 owns #569. The branch includes main
022f1a25068a8533c4ebe997891b78c618f27807through mergef27e0adc8. The current checkpoint isa0e7ec198b998b451bddb71870cd1c658921ef60; exact-head hosted gates are running.Archive capture preserves all thirteen standard tables and original profile/storage/chain/schema metadata. Shared reservations precede source acquisition, and immutable receipts bind pages to a verified directory. Authenticated HTTP supports bounded admission, status, directories, pages and cancellation. The unadvertised v2 reader uses fixed leases, require-existing admission, bounded same-request recovery and verified packed rows. Source-only adapters integrate with local destinations. Backend guards bind SQLite WAL files or an actual MySQL server/database; exact-owner recovery releases quota only after physical cleanup. Old unguarded owners remain reserved. Reader advertisement remains OFF.
Auxiliary profile keys cover eight directly owned tables, numeric relation keys cover label/tag mappings, and the new certificate-field keys preserve source collation, exact text and both direct/parent ownership bases. Inconsistent relations remain visible to closure validation. Removal observers precede producers; atomic 256-row bootstrap batches resume after interrupted DDL or commits. Ordinary/archive readers adopt complete migrations inside their retained view. MySQL reader hints now preserve bounded primary-index seeks before optimizer statistics refresh as well as afterward. Standard indexes, legacy OFFSET order, source rows and cursor/archive encodings remain unchanged.
Earlier branch work includes fair resumable pull, proof recovery, coherent local BRC-38 capture, legacy-history normalization, binary negotiation, BRC-118 payment/authentication, Bob's warranted native HTTP-body correction and public Argon2id declaration compatibility.
Global proof/request reference edges, per-profile counts and source-presence indexes now have bounded, resumable bootstrap, typed durable cursors, metadata validation and observer maintenance. Ordinary and archive readers select the completed indexes inside their retained view. A repeated unchanged backup accepts the valid terminal checkpoint with reset offsets while preserving checkpoint monotonicity and failure ordering. Authenticated ordinary/binary HTTP and lost-ack regressions cover this behavior.
Remaining implementation: SQLite conflict-safe index generation and retirement; primary reconciliation; commit-order high-water positions and complete tombstone propagation; nonblocking IndexedDB/native adapters; remote destinations; bounded large-blob transport/reuse; canonical streaming BRC-38/39; durable staged import; downstream migration; and full performance/fault/platform acceptance. Logical quotas do not prove physical resource bounds or larger-wallet acceptance. This checkpoint does not complete S1–S4/P1–P3/A1/V1–V2.
Impact
Core/client/mobile remain unpublished 2.15.0 minor candidates, with SDK peers
^2.8.0 || ^3.0.0. The release ledger records the decisions. Apply additive sync/archive/request/owner/guard/profile/relation/certificate/global migrations throughmigrate(); opening a provider does not migrate it. Preserve partial index DDL/bootstrap state for retry and recover a stale Knex lock only after proving the migrator stopped. Drain readers before down or binary downgrade.snapshotSync:falseandsnapshotArchives:falsedisable the new paths with schema retained. MySQL certificate keys require transactional InnoDB tables and matching text metadata; SQLite validates the existing unique key/collation.Verification
Current qualification uses Node 24.18.0, pnpm 10.33.2, generated campaigns of 300 runs / seed 3242026, fixed source/configuration inputs and unchanged gates.
a0e7ec198: all six root checks pass (health:check,lint,format:check,typecheck,audit:security,test:governance). The complete retained selection passes 27 suites / 669 tests; full wallet coverage passes 358 suites / 4,654 passing tests, with one unchanged skip. All 18 package/packed/core/client/mobile/Chromium/Hermes/conformance/documentation phases pass.Exact-head hosted coverage, native/platform, mutation, Sonar, CodeQL and the complete repository merge gate remain required. Historical passing revisions and local receipts do not qualify the new remote head.
Security, release and operations
The index implementation introduces no application dependency. Reviewed dependency remediation remains in the dependency policy. Main reconciliation preserves the newer brace-expansion fix, includes engine.io remediation, and retains #660’s reviewed knownTxids result-BEEF behavior. Synthetic fixtures contain no production wallet data.
Completion evidence
Historical requested-changes review still requires maintainer re-review. Publication, deployment, funded operations and physical platform acceptance require separate authorization and evidence. PR #569 remains OPEN / DRAFT / UNMERGED, auto-merge disabled, while implementation and exact-head validation continue.