feat(log): log authority is the fleet default — adopt-at-open, oracle-gated; plus the power-cut throw-site cures and the loud torn-record contract
THE DEFAULT FLIP (ruled on proven evidence — at-ack survived 301/301 acked-writes-through-power-cut in block-layer fault injection; deferred tree authority demonstrably loses flush-covered acks): a brain with NO stored authority artifact now ADOPTS LOG AUTHORITY AT OPEN. The oracle gates the flip exactly as the guarded adoption path always did — curable divergences baseline-backfilled, the flip lands ONLY on a green verdict — and a brain that cannot verify STAYS tree-authoritative loudly, with the refusal recorded on the switch artifact so subsequent opens are cheap. config logAuthority: 'defer' is the explicit documented opt-out (no automatic adoption; declared flush-window loss; adoptLogAuthority() flips later). A stored artifact always wins. RELEASES.md carries the posture. Two standing .fails debt pins FLIP TO HOLDING under the default: the at-ack crash-survival gap and the ack-at-log durability target — both now permanent asserted truths, not aspirations. POWER-CUT THROW SITES (fault-injection findings, brainy-alone config): - A manifest-listed-but-unloadable column segment QUARANTINES at discovery (loud once, counted always, quarantinedSegments() exposed for the heal) and the field serves its remaining segments DEGRADED — never a raw throw killing every query on the field. Real storage faults still propagate untouched. - Torn generation artifacts (NaN/garbage in manifest or counter) DISCARD with narration at the store's open and recovery re-derives — plus a defensive finite-integer guard at the init consumer. Never a RangeError killing an open. THE LOUD TORN-RECORD CONTRACT: an existing-but-unparseable stored record now surfaces as a typed, counted TornRecordError on every entity-read surface (including fifteen previously-blind per-item batch catches); ENOENT stays clean-absent; artifact readers with designed absent-recovery keep null-tolerance behind the loud floor. Disk corruption can no longer read as silent data invisibility. Suite migration: the default's pins inverted deliberately, generation baselines made relative, quarantine-contract pins rewritten to the ruled behavior. Gates: tsc 0 · unit 2065/2065 (159 files) · integration 826 (93 files) · conformance 31/31 · kill-matrix 15/15 · torn-open guards 2/2.
This commit is contained in:
parent
67c606be69
commit
214c98b4d5
23 changed files with 833 additions and 154 deletions
|
|
@ -477,14 +477,17 @@ describe('materializeAtGeneration — bounded & deadlock-free (GA #33)', () => {
|
|||
const store = (brain as any).generationStore
|
||||
|
||||
const N = 400
|
||||
// Relative, not absolute: under the adopt-at-open default the open-time
|
||||
// baseline backfill takes a generation of its own, so the first add is
|
||||
// NOT generation 1 — pin the deep generation to the first add's commit.
|
||||
let deepGen = 0
|
||||
for (let i = 0; i < N; i++) {
|
||||
await brain.add({ data: `doc ${i}`, type: NounType.Document, subtype: 'note', metadata: { i }, vector: VEC })
|
||||
if (i === 0) deepGen = brain.generation()
|
||||
}
|
||||
const R = brain.generation() // ≈ N (each add is its own generation)
|
||||
expect(R).toBeGreaterThanOrEqual(N)
|
||||
|
||||
const deepGen = 1
|
||||
|
||||
// Count getDelta invocations during the materialize.
|
||||
const realGetDelta = store.getDelta.bind(store)
|
||||
let getDeltaCalls = 0
|
||||
|
|
@ -509,7 +512,8 @@ describe('materializeAtGeneration — bounded & deadlock-free (GA #33)', () => {
|
|||
expect(getDeltaCalls).toBeLessThan(R * 5)
|
||||
expect(getDeltaCalls).toBeLessThan(N * N) // the regression guard
|
||||
|
||||
// The materialized at-gen-1 brain holds exactly the one entity that existed.
|
||||
// The materialized brain at the first add's generation holds exactly the
|
||||
// one user entity that existed.
|
||||
const atGen1 = await handle.find({ limit: N + 10 })
|
||||
expect(atGen1.length).toBe(1)
|
||||
await handle.close()
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue