Skip to content

fix: preserve expiry ownership and queued failure evidence - #11

Merged
jakthom merged 1 commit into
mainfrom
codex/fix-trust-review-2026-09-10
Sep 11, 2026
Merged

jakthom merged 1 commit into
mainfrom
codex/fix-trust-review-2026-09-10

Conversation

@jakthom

@jakthom jakthom commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Expired Verify could admit recovery before its reporting finished and omit the original issued Change from results and records. Both expiry paths now reserve publication ownership under the decision lock, preserve command evidence, and share finalization without releasing an enclosing Issue call.

Queued Runs now retain observer failures, original causes, and stacks from committed Steps when a later callback calls runtime.Goexit. The queued fuzz model checks exact event order, effect counts, independent cursors, and explicit cancellation outcomes. Full local/CI checks also scan the SQLite module's test dependencies for known vulnerabilities.

This addresses all four numbered review findings with compatible behavior fixes. Package documentation, the ADR, safety guidance, assurance requirements, and changelog describe the corrected guarantees. The review and before/after evidence are retained in scratch/review-2026-09-10.

Validation:

  • Full Go 1.26.8 source checks pass, including static analysis, race tests, SQLite integration, both vulnerability scans, and 90.8% statement coverage (90% required).
  • Minimum Go 1.26.0 and current Go 1.27.1 vet/tests pass.
  • All 20 fuzz targets pass a three-second smoke campaign; the strengthened queued model passes an additional 20 seconds under the race detector.
  • Original reproductions now pass. Isolated builds with reversed dequeue order and duplicated execution fail the strengthened model as expected.
  • Benchmark smoke checks pass. Independent implementation review found no actionable regression and repeated the targeted race regressions 20 times.

Statechart scaling and broader integration examples remain separate recommendations. No public method signatures or snapshot schema change.

@jakthom
jakthom merged commit 79192db into main Sep 11, 2026
6 checks passed
@jakthom
jakthom deleted the codex/fix-trust-review-2026-09-10 branch September 11, 2026 00:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant