Base revision: 987f6ca0d (main after #2004 and #2008). The @tanstack/db source was unchanged at the branch base.
Round 3 applied 47 plausible maintenance mistakes to the ported state stack: 35 in state.ts and 12 in sync.ts, lifecycle.ts, and mutations.ts. Each mutant ran against the full @tanstack/db suite with --bail=1. Of the 47, 35 failed the suite and 12 survived. Each survivor received a probe that passes on main, a code argument, or full-suite instrumentation that counts the cases where the mutant changes a decision.
| Mutant | Change | Verdict |
|---|---|---|
| S13 | Default rowUpdateMode becomes full | Gap. Closed here. |
| A1 | A sync delete that carries metadata keeps it | Gap. Closed here. |
| A3 | An insert without metadata no longer clears metadata | Gap. Closed here. |
| S6 | markReady runs before the truncate reapply | Gap. Closed with a fix in #2033. |
| S4 | The shared clear skips the pending direct-upsert marker | Equivalent. The later retirement loop removes every confirmed key. |
| L3 | The commit skips restoreOrder | Equivalent. SortedMap restores order on the next ordered read or write. |
| L4 | reappliedKeys starts as an empty set | Equivalent. An empty set skips no key. |
| X4 | A completed load-subset operation stays active | Equivalent. Every reader ignores or tolerates a completed operation. |
| M1 | Previous row origins omit direct keys | Equivalent on reached histories. Instrumentation found no differing virtual props. |
| M2 | The commit copies the pre-sync visible state | Equivalent by argument. The commit clears that state afterward. |
| S10 | Previous virtual props ignore completed optimistic keys | Equivalent on reached histories. See below. |
| S3 | The commit keeps a cached enriched row | Open. See below. |
A fifth mutant, RB1, came from this review. It makes rebuildAutomaticRowMetadataWrites overwrite explicit metadata writes. It survived the suite and the metadata publication oracle.
Partial row updates. The optimistic-history and retention oracles always set rowUpdateMode: 'full'. No test sent a partial update in the default mode. A separate partial lane now keeps the default mode. It reuses the generated optimistic histories and marks source batches partial from its own stream, so the full-mode campaign's fixed seed 86103 still produces main's histories. A partial batch omits c from its updates, and the model merges such an update into its base row. The lane runs its own fixed (86104) and random campaigns. Its fixed campaign must write at least one partial update whose omitted c differs from the source's held row. Two fixed histories merge a partial update while an accepted delete and an accepted schema-default re-insert overlay the row. An in-suite wrong-answer witness writes the same rows in full mode and must be rejected. S13 and MS, a mutant that merges onto the visible row instead of the synced row, both fail the partial campaigns and those histories.
Row metadata composition. No test wrote a row delete that carried metadata, or an explicit set followed by an insert without metadata. The new collection-row-metadata-composition-oracle.test.ts enumerates all 1,457 legal one-key histories of up to three writes, including truncate and an idempotent re-insert, from three starting states. A last-write-wins model predicts the final metadata. Three lanes reach the immediate, held, and rebuilt production paths. The rebuilt lane also varies the earlier held transaction over a key-2 update and every key-1 row write, for 1,767 histories. A1 and A3 fail all three lanes. RB1 fails only the rebuilt lane. RI1, a mutant that computes metadata from a re-insert's original type, fails all three lanes. TR1, a mutant that keeps a transaction's earlier metadata writes through a truncate, passes the rest of the suite and fails all three lanes.
Maintainer decision. The written contract covered only writes that carry metadata. On 2026-10-05 the maintainer adopted the current behavior as the contract for the rest: an insert without metadata clears the value, an update without metadata keeps it, a row delete or a truncate clears it, and metadata.row.set after a delete or a truncate keeps metadata for the absent row. A second decision the same day made an insert equal to the held row an idempotent re-insert: without metadata it keeps the value.
The ready-callback witness in collection-sync-reentrancy-oracle.test.ts covered only an edit of a replaced key, through a subscriber with initial state. Its sent-key filter hides a duplicate message. #2033 replaces it with a model-based grid and publishes ready-callback messages after the truncate batch. Its own record covers the evidence.
A code review of the first version found six items:
A high-effort review found nine more items:
CodeRabbit then found that the partial-as-full witness was vacuous. The driver's "observation mutant reached its checkpoint" assertion always failed for it, and the witness accepted any assertion error, so it passed even with the full override removed. The configuration mutant is now exempt from that assertion, and the witness requires a row observation to reject it. With the override removed, the witness fails.
The follow-up record 2026-10-05-round-3-followups.md resolves the items this record left open. S3 was not equivalent in production builds, which the suite did not exercise, so the delete stays with new witnesses. PR #2030 removed S10's code on main. The follow-up record also said that #2030 made RB2 unreachable. That was wrong: a transaction begun inside an open one can commit first and reclassify the open one's inserts. See 2026-10-06-nested-begin-metadata-rebuild.md.
This record repairs two grammars and adds one oracle, so ORC-012 applies.
The settlement-drop change (2026-10-03 review) removes the retention of completed optimistic rows. Under that law, a delete and a re-insert can no longer overlay the source row after they settle. The two fixed partial-update histories therefore run the partial update while both transactions persist. The update is held, and it publishes with the drop at settlement. The row keeps the source's merged c. The partial-as-full witness is still rejected, now by the row observation at settlement. S13 still fails the retention oracle on the merged revision, and S6 still fails the reentrancy oracle.