Skip to content

fix(ship): recover original published work after a lost checkpoint - #2794

Merged
justinhelmer merged 2 commits into
mainfrom
codex/historical-native-adoption-audit
Oct 6, 2026
Merged

justinhelmer merged 2 commits into
mainfrom
codex/historical-native-adoption-audit

Conversation

@justinhelmer

@justinhelmer justinhelmer commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

An original unit can audit its native push history and open its draft PR when a restart lost publication evidence. The old settlement and private workspace remain unchanged. Ordinary adoption keeps its existing refusals.

Why: A restart can leave successful native pushes beside an unaccepted publication checkpoint. Remote branch equality cannot repair that evidence. Explicit original-owner audit checks canonical history, pinned commit identities and rival ownership before creating a new adoption receipt.

Where to look

  1. Canonical native chain Checks the original spawn, complete causal push/tool history and immutable typed evidence.
  2. Owner transaction Prepares a bounded digest, then rechecks exact canonical rows inside the ownership transaction before CAS.
  3. Compact standing evidence Projects canonical typed fields before global byte accounting; prose and stdout keep their per-run admission bounds.
  4. Standing ownership Revalidates the original audit and attributes only matching producer and workspace obligations.
  5. Pinned identity range Reads the immutable first-to-final range and fresh identities without rewriting commits.
  6. Explicit adoption Keeps original caller, unit and thread checks; audited adoption uses the existing create-once journal.

Feedback wanted: Major delta review: close review:5422442802:F1; check compact authority, malformed fields, frozen digest/CAS, rivals and create-once reconciliation.

Risk: This adds an explicit recovery authority path. Missing, conflicting or incomplete evidence must refuse. No model run, budget renewal, old settlement rewrite or private workspace release is authorized.

Verified: 49 focused root tests and 2 real SQLite tests pass, plus scoped types, lint, format, consistency and test-loss guard. All 44 rendered captures retain their bytes. Live adoption remains unproved.

Decisions (4)
  • Keep the original producer history. Store a new explicit audit in the existing adoption action; do not upgrade historical clean/not_attempted evidence or acknowledge workspace custody.
  • Recheck inside the owner transaction. Hash before the synchronous transaction and compare exact frozen canonical rows before owner lookup and CAS. Standing scans compare bounded typed evidence without async hashing.
  • Read an immutable range. Verify only first native attachment through final pushed head using existing identity rules. The first commit is the excluded boundary; PR base remains the original base.
  • Account only canonical authority. Derive ephemeral compact events from the same canonical rows; retain every causal tool pair and sequence. Keep full snapshot/digest admission and the 16 MiB global bound. No new persistent table.
Validation (4 criteria)
Criterion Proof
Explicit audit preserves original ownership and refuses forged, stale or altered history. [unit] src/channels/adminCoordinator.test.ts::original committed head adoption — create-only draft PR::; deploy/cloudflare-memory/runLedger.test.ts::historical original native adoption owner CAS::
Pinned identities are checked without Git writes or inherited fingerprint invention. [unit] src/execution/identityRewrite.test.ts::read-only pinned native range identity audit::*
Ordinary adoption and uncertain create responses retain their refusals. [unit] src/channels/adminCoordinator.test.ts::original committed head adoption — create-only draft PR::*
Verbose display histories cannot poison initial, standing, posting/bound or ordinary ownership capacity; malformed authority and real rivals refuse. [unit] src/channels/adminCoordinator.test.ts::original committed head adoption — create-only draft PR::; deploy/cloudflare-memory/runLedger.test.ts::historical original native adoption owner CAS::
For agents

Source proof only. Do not adopt a customer unit, replay a model run, fabricate an acknowledgement, alter historical caps or release a retained workspace during review. Current release and production acceptance are separate gates.

🤖 Generated with Claude Code

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested: Audited display histories consume the global ownership budget, blocking valid recovery and poisoning in-memory ownership scans.

Warning

Changes requested · head 3f41787 · 1 finding: 1 major

Severity Finding Where
major F1 Spec contradiction — run-history.md canonical pull ownership: audit display bytes exhaust the owner budget deploy/cloudflare-memory/worker.ts:4485

F1 invariant: Historical model prose, tool stdout and diagnostics must not consume the global ownership-scan budget. Standing audit attribution must remain bounded by canonical typed authority, while admission retains its complete per-run snapshot, digest, completeness checks and atomic rival lookup.

  • SQLite adoption CAS with three prior audited producers and a fourth otherwise valid producer, each with approximately 1.4 MiB of complete events but only a small typed authority projection. → The fourth audit is not refused solely because irrelevant display events collectively exceed the 16 MiB ownership budget; full per-run audit checks and global rival admission still run.
  • SQLite standing findPullOwners for either the audited repository or another repository after verbose audited histories have accumulated. → Only bounded authoritative evidence consumes ownership capacity; unrelated model prose and stdout cannot make a complete ownership lookup incomplete.
  • SQLite ordinary unit, Main-task, recovery or effect admission invoking pullOwnershipRows alongside retained audited producers. → Valid admission is not blocked solely by historical display bytes, and real rival or incomplete authoritative evidence still refuses.
  • SQLite claimed-to-posting and posting-to-bound audited CAS, including reconciliation after an uncertain PR-create response. → Canonical audit snapshot and digest remain unchanged and rechecked before the transaction's rival lookup without charging all other producers' display events to the global owner budget; uncertain create is not replayed.
  • In-memory initial audited CAS near the ownership budget, where bindingRefusal substitutes the proposed audited unit only after pullOwnershipRows computes auditedRunIds. → The proposed state is accounted consistently before commit; a successful claim cannot make the next standing scan or posting CAS fail solely because its display events have newly entered the global budget.
  • In-memory standing ownership lookup and subsequent ordinary binding or audited CAS writes with several verbose audited histories. → Use the same authoritative-byte accounting policy as SQLite; display-only history cannot poison every subsequent ownership scan.
  • Either store encounters changed authoritative history, a missing event, a stale digest, a forged original spawn or an actual rival while using the bounded standing projection. → Refuse as before; excluding display bytes from global capacity must not weaken canonical evidence, full admission snapshot verification or rival ownership checks.
Full review

F1 — Major, high confidence. The new scan charges every audited producer’s complete event history—including model prose and tool stdout—to the global 16 MiB ownership budget. Four valid ~1.4 MiB histories consume ~16.8 MiB under the 3 * length accounting, even with tiny authority projections, so SQLite refuses the fourth audit. In-memory admission is worse: instanceStore.ts:352 counts only previously audited runs before substituting the proposed unit, allowing that claim to commit and making subsequent ownership lookups and posting CAS fail. This contradicts run-history.md:544, which explicitly excludes historical display bytes from ownership capacity. Separate complete per-run snapshot/digest verification from the transaction-local, bounded typed-authority scan in both stores; preserve completeness checks and rival refusal rather than increasing or removing the safety bound.

@justinhelmer
justinhelmer force-pushed the codex/historical-native-adoption-audit branch from 3f41787 to 2fe5b51 Compare October 6, 2026 01:36

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM: F1 is fixed; no major-or-higher defects remain in the current-head delta review.

Note

Approved · head 2fe5b51 · no findings

Prior finding Resolution Evidence at this head
review:5422442802:F1 fixed Verified all seven prior cases at this head. deploy/cloudflare-memory/worker.ts historicalOwnerEvents/pullOwnershipRows derive compact typed evidence before global accounting while retaining raw per-run count, contiguous sequence and byte fences; preparation and initial/follow-on audited CAS use the complete canonical snapshot and full-event digest with an exact synchronous transaction recheck. The fourth verbose-history claim, standing lookups for same/other repositories, ordinary unit/Main-task/recovery/effect admission, and claimed-to-posting/posting-to-bound paths all consume this compact inventory instead of display bytes. src/core/coordinator/instanceStore.ts pullOwnershipRows substitutes the proposed audited unit before collecting audited run IDs and accounting, eliminating the initial-claim/standing-scan discrepancy; subsequent standing and ordinary/audited writes share compact accounting. historicalNativeAudit.ts preserves every causal tool field and validates malformed success flags; missing events, changed authoritative history, stale digests, forged spawn and real rivals still refuse. pullOwnership.ts preserves workspace owner attribution and custody guards, with main's diagnostics remaining observational. adminCoordinator.ts preserves the create-once posting state and exact uncertain-response reconciliation without reposting. The added verbose-history regression proofs in both adminCoordinator.test.ts and the actual SQLite runLedger.test.ts independently assert claims, standing reads, posting/binding, ordinary admission, changed authority and rival refusals. Source verified; tests/build and live adoption were not run during review.
Full review

review:5422442802:F1 is resolved at 2fe5b51; no major-or-higher findings remain in the current-head delta.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: coreplane-switchboard[bot] reviewed this PR and posted an LGTM verdict (see its review). This repository opted in through its REVIEW_BOT_LOGIN and REVIEW_BOT_ID variables.

@justinhelmer
justinhelmer marked this pull request as ready for review October 6, 2026 01:41
@justinhelmer
justinhelmer merged commit 3766041 into main Oct 6, 2026
29 checks passed
@justinhelmer
justinhelmer deleted the codex/historical-native-adoption-audit branch October 6, 2026 01:41
@polylane

polylane Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Warning

Polylane could not verify the production impact of this pull request.

Checked the additive historical-native audit path (adopt unit … audit) against switchboard-memory and switchboard in coreplane-infra. Every new branch gates on the new adoption.audit field, absent from live units, so the ordinary adoption/ownership path is unchanged, and both workers hold flat, low-error load.

View the full analysis →

Also considered · 2 refuted
  • Refuted · New audit code regresses the ordinary adoption/ownership path · Every new branch in compareAndReplaceUnit, pullOwnershipRows, and get()/canonicalRun is guarded by replacement.adoption?.audit or the privatePublication flag.
  • Refuted · Audit serialization exposes model prose or tool stdout · authorityProjection and HISTORICAL_AUTHORITY_EVENT_FIELDS whitelist typed fields only: tool_result drops output, tool_call drops summary (model prose and tool stdout are excluded), and the projection is bounded to MAX_PROJECTION_BYTES.

switchboard-memory · requests per hour

Analysed against 7 cloud accounts and 1 repository
  • Cloud accounts: coreplane-prod, baseberry-uat, coreplane-infra, coreplane, coreplane-gtm, 251714435813, Polylane
  • Repository: coreplanelabs/switchboard

View in Polylane Disable reviews

Polylane could not find the cloud resources this repository manages, so this review looked at the entire cloud account. Connect this repository to its resources and the next review will focus on exactly what this code deploys to.

Connect resources

Polylane analysed 2fe5b51 for production impact. You can ask follow-ups by mentioning @polylane in a comment.

Did this help? React 👍 or 👎 so the next review is sharper.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant