TanStack

Content temporarily unavailable

IndexedDB donor coverage port

Reviewed implementation: c4441632c7ac595d11c57061f5c5f9a3ae556de9. Production baseline: fd3c05c818d76489438224e24d4e935751596dc0. This record concerns DP08, DP09, DP10 and DP17 from the sighted donor survey. It preserves the survey's original dispositions as historical evidence.

Result and receiving scope

No production changes or new product policy were required. The port extends the existing per-store and persistence models and adds a separate distribution smoke lane. The shared rich-value definition is structured-clone-oracle.ts; its controlled receiving companion is persistence-values-oracle.test.ts. The native driver is e2e/coverage-browser.ts, with comparisons in value-oracle.spec.ts. Drivers are not counted as additional independent models.

FindingExecuted law and boundLimit
DP08Two/three competing first native opens; same/independent absent names; complete identical declarations; schema, held restore/readiness, disjoint writes, convergence, fresh restore and later upgrade. Native engines receive three-open histories.Opens settle before writes; no callback-order promise or union of conflicting declarations. No new liveness guarantee.
DP09Seven authored native value shapes: Date, odd ArrayBuffer, offset Uint8Array/DataView, BigInt64Array, Blob and nested array. Unrelated scalar update, peer, export/import, fresh descriptor; insert/import rejection at first/middle/last nested function; raw row/version rollback and valid suffix.No post-submission mutation, custom prototypes, cycles, Map/Set, detached/shared/resizable buffers or schema transforms in this companion.
DP10Six legal database/store substitutions, prefix neighbor and anchor; scalar typed keys in separate transactions, update/import/clear, peer/public/durable/restore and untouched version values.Native receiving covers prototype/Unicode creation and ordinary writes, not the entire controlled renaming/import/clear matrix.
DP17Tarball ESM/CJS consumers plus missing-export controls; Vite with no aliases/config rescue; native browser execution of persist/reopen.Installed dependency closure is pinned with tarball overrides. This does not prove registry range selection, old runtimes, all bundlers or every export.

The new finite grammars intentionally extend existing models without multiplying all value shapes by the entire lifecycle state space. Existing fixed/random history campaigns and direct replay remain unchanged. The TLA+ lifecycle models are unchanged because names, payload fidelity and package resolution add no lifecycle or authority policy.

Sensitivity and test-first evidence

review-evidence/donor-port contains the replay script, source hash, classifications and complete receipts.

  • name-prefix: change exact metadata-store matching to startsWith. Six assertion failures at metadata ownership after replacement; a neighbor's entries disappear. This is neither timeout nor setup failure.
  • premature-readiness: publish readiness before persisted restore. Four assertions reject ready while native reads remain held/pending.
  • json-values: JSON-convert accepted rows before native persistence. The Date history rejects the peer's string value at the first insert checkpoint.
  • Two resolver controls remove one installed tarball entry each. ESM/CJS loaders fail with the missing-entry path; workspace aliases cannot rescue either path.
  • Value-observer controls accept each correctly constructed corpus value and reject flattened shapes, lost view offsets, altered backing bytes and omissions.

All production mutants were restored. These establish sensitivity to the named wrong designs, not universal coverage. There is no newly repaired source bug.

The first legal-name draft inserted numeric 0 and string "0" in one Collection transaction and reproduced the already tracked HC005 core payload collision. Both ordinary and unusual names lost the numeric row. The final name grammar uses separate transactions to isolate routing; HC005 stays open with its existing core owner rather than being represented as fixed by this port.

Native provider distinction

Chromium and Firefox receive all seven preservation shapes. The local Playwright WebKit provider rejects Blob preparation with native UnknownError: Error preparing Blob/File data to be stored in object store. A direct native transaction without adapter code reproduces it. The executable raw-provider witness preserves this classification.

For the two Blob-containing WebKit cells, the test requires that exact native failure, matching adapter rejection, empty public/durable/export rows, and a successful Date suffix. These are executed rejection tests, not skipped tests or Blob-preservation evidence. If native Blob storage succeeds on another platform, the same test executes the full preservation history. A Blob-capable WebKit receiving witness is still needed for that claim; the coverage map names it.

Guide audit

RequirementEvidence
ORC-001Existing persistence, schema, readiness and per-store contracts; each owner states its finite domain and exclusions. No recovery/ownership policy is inferred from a donor.
ORC-002Authored per-store arrays and tagged value descriptions never derive expected rows from production storage or version classifiers. Production receives detached scalar inputs or fresh native values.
ORC-003Opening and adjacent prose distinguish law, value model, finite grammar, real API driver and checkpoint in each oracle/companion.
ORC-004No new random generator: bounded enumeration is explicit. Removing unusual names loses dictionary/routing cases; removing independent names loses isolation; removing native holds loses premature-readiness reach; removing offsets/types loses fidelity. Empty/reserved stores and conflicting declarations remain separate negative controls.
ORC-005Native open admission counts precede settlement; zero old versions prove absent names; held native reads precede readiness. Public/peer/raw/export/restore observations occur at stated cuts. Package consumers execute real loaders and storage.
ORC-006Three production mutants fail by assertion at the named cuts; value and packed resolver controls remain executable.
ORC-007Not triggered for new finite enumerations. Existing generated persistence and cross-tab campaigns remain registered and unchanged.
ORC-008No lifecycle states added. Value tags, content, offsets and backing bytes remain because an untouched-field observation distinguishes them; object identity is deliberately outside the law.
ORC-009Collection status/readiness, persisted restore, public snapshot, native transaction and settlement retain glossary meanings. Value descriptions are test-only observations, not product states.
ORC-010Controlled harness retains primary failures and cleanup errors. Native runner aggregates cleanup errors with the primary cause. Tarball fixtures own/dispose temporary directories. No shrinker or failure classifier was changed.
ORC-011Native constructors and independent typed/byte observations reject shared JSON assumptions. Direct native Blob admission distinguishes provider rejection from adapter corruption. Legal-name substitution preserves authored meaning.
ORC-012This versioned record identifies the reviewed implementation and reports each applicable obligation, calibration and open boundary. No universal bug-class closure is claimed.
ORC-013Prefix neighbor versus exact-name metadata; held versus completed restore; offset versus flattened view; native rejected Blob versus accepted Date; existing versus missing packed export are distinguishing neighbors.
ORC-014Native first opens, held restore and cross-page values run in Chromium/Firefox/WebKit. WebKit Blob preservation and the wider native naming matrix are explicitly unclaimed, with owners in the coverage map.

Validation

  • 2,446 adapter runtime/type cases passed; 15 files, no type errors.
  • 192 native browser cases passed across Chromium, Firefox and WebKit. Of the 36 added cases, 19 prove rich-value preservation, two prove the documented native Blob rejection/suffix, 12 prove first-open readiness/schema, and three execute packed browser bundles.
  • 16 package-consumer cases passed: 12 existing declaration checks, two packed runtime examples and two missing-export controls.
  • Full test-driver typecheck, changed-file ESLint, formatting and whitespace checks passed. No production code changed, so no core rerun is claimed.

An attempted dependency refresh hit the configured registry's unavailable packages. Tests used the available cached Vite/Rollup installation; source, manifest and lockfile were not changed to bypass it. A dependency declaration removed by its prepare script was restored from the local package cache; external packing now uses npm pack --ignore-scripts. No suite rebuilds another suite's input. The native CI build list now includes the adapter before packed-browser consumption.

What remains

  • Product decisions: abnormal native closure (DP02), mutable-value capture and ownership (DP12), and worker-host support (DP13). These have not been silently assigned recovery behavior.
  • Optional new APIs: blocked-operation diagnostics, atomic storage read-modify-write, and durability hints. Existing accepted contracts remain unchanged.
  • Provider evidence: WebKit Blob preservation and the wider native naming matrix.
  • Existing open boundaries, including HC005 and the previously recorded lifecycle/ suspension/crash limits, remain in the coverage map. This port does not retire them.

Approved follow-up

The later follow-up audit records the approved closure/capture/worker contracts, optional blocked diagnostics, core typed-key repair, and completed native naming and persistent-WebKit Blob evidence. The earlier findings above retain their original revision and evidence boundary.