Historical audit: the October 6 refinement audit records the subsequent design decision, completed repair and executable evidence. The open dispositions below describe the earlier snapshot.
This audit starts at PR #1179 head 34eb98b16d6174d1722878de3cb3b2cd5dc4dabe. It revisits all 15 findings from 2026-10-05-indexeddb-xhigh.md under the stronger evaluate-review standard: identify the reusable law, inspect its model and reach, and prove its assertions reject plausible wrong implementations. Changes described here are in the working tree; they are not yet committed or pushed. The deletion law remains open, with a concrete failing history and a design decision requested.
The previous evaluation overstated closure. Four wrong implementations passed its relevant green suites. The strengthened oracles reject them:
| Wrong implementation | Previous evidence | Strengthened evidence |
|---|---|---|
| Match Collection IDs instead of Collection references | 21 compatibility/persistence tests passed | Four same-ID owner-projection assertions fail; distinct-ID controls pass |
| Ignore a current durable row without a version record | 38 transport tests passed | Four current-row comparisons fail; versioned controls pass; the native witness fails in Chromium, Firefox and WebKit |
| Read storage for malformed envelopes, then ignore them | 38 transport tests passed | The zero-storage-work assertion fails; valid neighboring invalidation still reads |
| Replace a native cause with an equal-looking DOMException | 20 wrapper tests passed | Exact request-cause identity assertion fails |
These were missing distinctions, not missing random runs. Production already satisfies the strengthened four laws. No production workaround was added for these tests.
The audit also found a reachable counterexample to the repaired deletion design. A connection that observed native deletion is insufficient evidence that a received success notification belongs to that deletion. XH-07 is reopened.
Paths below refer to packages/indexeddb-db-collection/tests unless qualified. The original findings remain separate even when they share a law.
| ID | Law or obligation | Model, histories, production path and enforced observation | Disposition |
|---|---|---|---|
| XH-01 | Successful automatic writes in one Collection persist in author order; rejected handlers or failed native batches contribute no durable effect and release successors. Authority: approved ordering policy and native atomicity. | local-write-order-oracle.test.ts folds authored whole-row effects over the independently authored peer base. 576 histories cross three same/disjoint/reinsert effects, all six handler orders, eight decision masks and four ordered peer prefixes. At every decision it checks the decided author prefix in raw storage, the peer and fresh restore, plus absence of premature caller success. Four more cases cover held predecessors, handler reentry and queued successors after native failure. A completion-order mutant causes 287 assertion failures. Intermediate local optimistic publications are a separate law below. | fixed-now within these stated receiving boundaries |
| XH-02 | Mutation ownership is Collection-reference identity, independent of user IDs and cleanup of its sync run. | Compatibility checks renamed IDs and adds equal/distinct IDs, both acceptance orders, live/cleaned-up sync runs and mixed manual payloads. Every acceptance checks both stores, version ownership and restore. Keys are disjoint so core same-ID/same-key mutation merging cannot replace the tested adapter boundary. The ID-equality mutant changes both stores and fails. | fixed-now |
| XH-03 | Optional row version metadata cannot define source membership. A notification reads current durable whole-row values; duplicates cannot introduce duplicate rows or restore omitted fields. | Transport crosses initial membership, key type and metadata present/absent at the receiving read, independently of existing startup-metadata cases. Raw writes occur before delayed real peer notifications; duplicate delivery and a later versioned suffix check cache continuity. A native two-page receiving witness uses real writes, reads and duplicate BroadcastChannel messages. Low-level writers explicitly send invalidation; wrapper writes do not automatically broadcast. The missing-version mutant fails four controlled comparisons and all three engines. | fixed-now for delivered invalidations |
| XH-04 | Import accepts schema input, validates/transforms once, uses transformed keys, and rejects the entire replacement before storage if any input or key is invalid. Export returns durable schema output. | The Date example retains the input/output distinction. Settlement now crosses schema errors and transformed-key collisions with all three positions in a batch; it compares unchanged public/raw/peer rows, exact prior versions and zero storage work. An accepted suffix must produce independently authored numeric keys and uppercase values, including fresh restore. Source and published-consumer types distinguish input from output. A universal inverse transform is not promised. | fixed-now; separate trusted-output restore remains an unrequested API design |
| XH-05 | Both the requested store and the metadata store must exist before options are accepted. | Synchronous configuration examples cover missing data/metadata stores and healthy creation. The native pre-existing same-version schema reaches the missing-metadata premise. Original-source calibration failed the intended admission assertion. This finite configuration predicate needs no history state machine. | fixed-now |
| XH-06 | Managed connections close on versionchange; existing native transactions may finish, later work through the retired connection fails, and the app recreates affected Collections. | Transport checks exact native recipients, pending unmanaged blockers, preserved upgrade rows, failed old-descriptor writes, downstream error after an old read, and fresh restore/write. Native tests receive versionchange while native work is held. The policy is explicitly approved and documented; no new automatic restart or in-memory fallback is inferred. | accepted-design, not deferred implementation |
| XH-07 | Successful deletion may empty only Collections belonging to the deleted database lifetime, and only after that deletion completes. A different lifetime's notification cannot supply completion. | The existing connection-scoped model distinguishes old and recreated connections only until the recreated connection sees another deletion. The new controlled/native histories retain an old successful receipt, recreate and populate the database, start another deletion behind an unmanaged blocker, then deliver the old receipt. Durable rows remain; the recreated peer incorrectly becomes empty. The comparison reaches the intended publication cut. | design-decision; confirmed behavioral defect remains open |
| XH-08 | Invalid protocol envelopes carry no authority to access storage or publish changes; valid neighboring messages remain effective. | The existing malformed-value matrix now counts native transaction admission before any row observation can hide unnecessary work. It requires zero transactions for malformed inputs and one for a valid unseen-row invalidation. The eager-read mutant previously passed and now fails. Self/database/store routing has separate positive witnesses. | fixed-now |
| XH-09 | Contextual wrapper errors retain the original native cause object; callback rejection keeps its identity. | Wrapper checks native request/open failures and separate open/delete/store/transaction admission branches. Assertions now use identity rather than structural equality for native causes. A cloned DOMException survives the previous suite but fails the strengthened request comparison. Existing callback/native-completion matrices retain exact callback failure outcomes. | fixed-now |
| XH-10 | Exported error APIs must describe actual behavior; the approved API uses native causes instead of unused constructors. | The five unused constructors and reference pages were removed in the prior repair. Source/export inventory and declaration checks are the appropriate evidence; no product state machine is implied by removal of unused symbols. | fixed-now |
| XH-11 | Runtime/type oracle results depend on workspace source, not pre-existing distribution files. | Dedicated runtime/type source configuration and coverage-disabled oracle scripts remain unchanged. The prior full suite ran with all three dist directories absent; current source runtime and type checks pass. Declaration-consuming tests are explicitly separate. This is a test-integrity contract, not a row model. | fixed-now |
| XH-12 | Default runtime tests must not rebuild shared dependencies; published consumers must still receive completed builds. | Default scripts have no builds, root package checks follow runtime suites, and CI reuses completed builds after its runtime group. The published consumer lane builds ESM/CJS and compiles five module-resolution configurations without skipLibCheck. Duplicate builds were verified; an actual historical CI race was not claimed. | fixed-now |
| XH-13 | A native batch admits its data/version requests before awaiting their success, but only native transaction completion can establish atomic success. | Settlement counters now cover automatic insert/update/delete and import, with empty import and one/ten-row batches. Counts are exactly 2N before the first successful request. A serial-delete mutant fails both delete cases. Existing first/middle/last clone-failure and abort matrices retain value atomicity. No elapsed-speedup claim follows. | fixed-now |
| XH-14 | Wall-clock metadata has no row/version-order authority; removing it must preserve legacy reads and unrelated records. Utility types retain schema input/output and Collection key types without an unused parameter. | Persistence crosses absent/past/future legacy timestamps, update, untouched anchors, mixed-format restore and replacement. New records have only a version token. Three format assertions failed before removing updatedAt; the two-parameter utils type failed before removing the phantom key parameter. Updated source and published consumers pass. | fixed-now in this working tree |
| XH-15 | estimatedSize, when available, is the origin's approximate usage, not this database's size. | The empty-database controlled estimate and corrected property/guide/README scope remain intact. This diagnostic forwarding contract does not require a stateful oracle or invent a database-size estimate. | fixed-now |
A database lifetime starts when the named native database is created and ends when it is deleted. A connection can end earlier, for example during an upgrade. Those are distinct identities. The new model cannot collapse a retired connection from the first lifetime with a connection observing deletion in a second lifetime: the same incoming old notification must have different authority.
The controlled oracle fails at old receipt cannot complete newer deletion. The native oracle checks real versionchange, a live unmanaged connection, retained durable rows and pending native completion before judging the peer snapshot. A first Firefox fixture waited for a blocked event that did not arrive at that cut. That timeout is not credited as a product failure; blocked-event timing is not the authority being tested. The corrected native witness fails at the intended peer-snapshot assertion in Chromium, Firefox and WebKit; all three retain the durable row while the newer deletion is pending.
The recommended correction is a persisted identity for each database lifetime, carried by deletion notifications and retained by each descriptor. Native connection retirement would remain a necessary condition. An old lifetime's success could not authorize clearing a newer lifetime, even after that newer connection sees another deletion. This changes the previously approved design and stored metadata. The maintainer requested research before deciding. An alternative is to stop clearing peer snapshots on deletion and require explicit recreation; that changes the existing publication contract. No deferral is claimed.
The research found stored dataset identity in RxDB and PouchDB, and separate connection retirement/deletion APIs in Dexie and idb. It also identified a limit on the proposed correction: a native delete is queued by database name, so a captured descriptor identity does not prove which lifetime the request removes. A native-only delete/recreate/delete probe reproduced removal of the recreated dataset at the same version in Chromium, Firefox and WebKit, with both delete requests admitted while the original connection still existed. This is platform research, not a newly claimed adapter RED. A concrete design must distinguish notification authority from native request targeting; merely adding an identity field does not prove both. No deletion implementation has changed. The research record and native traces remain in task review evidence.
Before adding the newly discovered deletion counterexample, the complete suite passed 783 runtime/type tests, 12 published-consumer tests, and 57 browser cases. These numbers are not a current all-green claim: the deletion counterexample now makes the relevant suite red. The latest complete runtime/type run has 783 passing tests and one failing deletion assertion, with no type errors. The corrected native deletion witness has three assertion failures, one in each engine. TypeScript, lint and whitespace checks pass for the work through that point. The local build still uses cached Rollup 4.59.0 because tracked 4.64.0 is unavailable from the configured registry; the lockfile is unchanged.
The four formerly surviving mutants now fail assertions. The additional completion-order mutant fails 287 assertions, and serial delete admission fails two. These are counted separately from the original review's earlier RED evidence. The new cases are bounded enumeration, not claims of generated grammar coverage; existing fixed/fresh campaigns and replay interfaces are unchanged.
The local-order owner observes intermediate durable/peer/restore prefixes and final local rows. It does not replace the core optimistic-publication model. The pending companion still receives only one local intent's intermediate publications. Multi-intent intermediate local publications, peer work between local acceptances, pending mutation outcome across cleanup/restart, unordered same-key cross-Collection writes, lost notifications, and physical crash durability retain their named coverage-map boundaries. None is proved by adjacent green checks. The deletion counterexample is inside the claimed deletion boundary and therefore prevents closure of XH-07.
| Requirement | Outcome |
|---|---|
| ORC-001 | Approved author ordering, Collection-reference ownership, atomic native completion, schema-input and deletion-publication laws are stated; the new deletion design is not silently adopted. |
| ORC-002 | Authored effects/store projections determine expected rows; native reads and native error objects are independent observations. No production cache computes truth. |
| ORC-003 | Prose beside each extended owner explains law, model, finite histories, production path and cut. |
| ORC-004 | No new generated property; new matrices are explicitly bounded. Existing generated owners and their controls are unchanged. |
| ORC-005 | Actual Collection operations, native request admission, raw storage, caller outcomes, peer snapshots and fresh restores reach the asserted cuts. |
| ORC-006 | Four previous survivors now fail comparisons; completion-order and serial-delete mutants fail their intended cuts. The new deletion counterexample fails on current production. |
| ORC-007 | New matrices are finite enumeration. Existing fixed/fresh/replay campaigns remain active; no random-run claim substitutes for the matrices. |
| ORC-008 | Decided author prefixes and Collection references retain distinctions exposed by later actions. The deletion counterexample proves connection retirement loses a database-lifetime distinction. |
| ORC-009 | Collection, sync run, settlement and publication remain distinct. Database lifetime versus connection lifetime is defined above. |
| ORC-010 | Held local decisions release in finally; native/controlled deletion blockers release before comparing captured evidence. Primary failures survive cleanup. |
| ORC-011 | Raw storage and fresh restore challenge optimistic-only agreement; exact native cause identity distinguishes structurally equal replacements. |
| ORC-012 | All 15 original findings and their law evidence are accounted for. This working-tree record explicitly reports the open defect and does not claim closure. |
| ORC-013 | Equal/distinct IDs, absent/present metadata, invalid/valid messages, pending/completed prefixes, and old/new deletion lifetimes distinguish reusable boundaries. |
| ORC-014 | Missing metadata receives a native witness in all three browsers. The corrected two-deletion receiving witness fails its intended snapshot assertion in all three engines; the initial Firefox setup timeout is not credited as a kill. |
The disposition accounting is 13 fixed-now + 1 accepted-design + 1 design-decision = 15. XH-07 is confirmed and unresolved. There are no deferred items. This accounting does not mean the implementation work is finished.
The TLA+ translation and loss audit supersedes the open deletion-design disposition above. It records the approved administrative deletion contract, oracle-first RED, source repairs, loss recovery, production fault calibration and native receiving evidence. The historical counterexamples above are retained; no deferral is used to claim closure.