TanStack

Content temporarily unavailable

Oracle law ownership overlap review — 2026-10-10

Reviewed baseline: 4bd66cf8ee72cf2c318878995222415b0452b031. Carry-forward base: f7ac2c63a3cabc864caf38b7a4e966088cfe73bb. This review focuses on prose and ownership, with the follow-up test-integrity repairs described below. It is not a full ORC-012 conformance audit.

Scope and method

At the reviewed baseline, we read the law, authority, model, history, production-path, observation, and limit prose in all 194 tracked oracle-named TypeScript and JavaScript paths under packages/ and examples/. That inventory contains 165 test, spec, or suite modules, four type-test files, and 25 companion modules. We also read the two package ORACLE.md files and the adjacent where-prefilter-property-visibility.test.ts generated-history file. The baseline inventory is reproducible with:

shell
git ls-tree -r --name-only 4bd66cf8ee72cf2c318878995222415b0452b031 -- packages examples \
  | rg -i 'oracle' | rg '\.(ts|tsx|js|jsx)$'

Within that output, paths matching \.test\., \.spec\., or suite are runner modules. The four \.test-d\.ts paths are type tests. The remaining paths are companion modules. These disjoint groups contain 165, four, and 25 paths respectively.

Untracked review copies and historical review records were not counted as current executable owners. For each apparent overlap we compared the promised law, legal history, production path, and public observation checkpoint. Shared words or a shared model are insufficient to call two checks duplicates.

Between the reviewed baseline and the carry-forward base, three oracle-named files were added and twelve existing oracle-named files changed. We read the new files, the changed files' law and owner prose, and the affected coverage-map entries. The additions are:

  • Facade rollback owns internal flush rollback and bounded row-read work. The existing includes-Collection owner checks public facade lifecycle and events.
  • Alias shadowing checks finite exact public keys and captured references. The scope-identity grammar owns broader alpha-renaming histories.
  • Leader-close OPFS receives manual source-backed recovery in real Chromium tabs. Controlled coordinator and persistence models and the Electric SDK receiver have different provider and observation boundaries.

The twelve modified paths fall into three ownership groups:

  • Browser coordinator, per-Collection coordinator, persisted wrapper, and SQLite core oracles add leader-close and exact-receipt histories. Controlled routing, Collection publication, durable SQLite evidence, and the OPFS host receiver remain separate boundaries.
  • Includes recomputation, scope identity, and Collection-valued includes add legal alias shadowing, exact public-key delegation, and a facade retry witness. The alpha-renaming model, exact-key companion, facade rollback owner, and public Collection receiver retain distinct checkpoints.
  • Proxy native methods, proxy revert, deep equality, Electric recovery, and oracle configuration add native-mutator/revert, persisted-snapshot comparison, peer-notice ordering, and campaign registration checks. They do not create a second owner for those laws.

The complete 194-file prose review remains tied to its baseline. This carry-forward review covers the changed ownership prose and affected entries; it does not claim a full conformance audit of every newly added assertion. None of these changes calls for merging the owners in the table below.

Ownership decisions

Shared claim or surfaceCanonical owner and companion boundaryDecision
Failed Collection replay keeps a public snapshot privateLifecycle publication owns exact public rows and batches. Replay applies that law to replay generations and same-key source writes.Keep both. Fresh-key and same-key post-failure witnesses reject different faults.
Exact subset demand and applied abortIR identity owns key construction; load subset owns runtime sharing, retry, and readiness; transaction refinement owns the abort cut around sync acceptance and publication.Keep all three production cuts. Point the broader campaign to the precise boundary owner.
Ordered window rowsPagination owns general ordered-window rows and publication. Ordered work checks the same rows while bounding eager indexed and joined work. Query DB's cursor model owns opaque backend paging through a different adapter path.Keep row checks at both paths so a work bound cannot pass by dropping rows.
Optimistic whole-row state and settlementOptimistic history supplies the shared base/intent/source-queue model. Same-key composition exhausts a three-update matrix; transaction ownership owns release across two Collections. Outcome and publication drivers reuse the history model.Keep the distinct matrix and observation drivers; do not count each shared-model replay as a new law.
Correlated includesIncludes owns broad nested recomputation. Query-shape, temporal demand, facade, publication, projection, and work owners exercise narrower architecture laws or checkpoints.Keep the architecture's owner split. The focused input-boundary tests are regression witnesses, not another model owner.
D2 value identity and top-KHash identity owns identity. Flat hash checks equal-hash consequences for flat equivalent constructions. The TopKRelation checker requires unit weights for both numeric- and fractional-index output; ordinary top-K cases using it supply unit support, while ordinary top-K can retain multiplicity.Clarify both scope statements; retain distinct hash graph, retry, and top-K production paths.
Provider and framework receivingCore/controlled models own their laws; IndexedDB browser specs, SQLite/OPFS hosts, Electric SDK delivery, and backend Collection E2E suites receive named premises. Shared framework contracts own row/page semantics while React and Vue drivers observe their own render cuts.Keep receiving witnesses. Do not credit a controlled seam as native-host or framework timing evidence.
Opaque pagination no-peek candidateThe cursor-pagination owners retain the shipped peek-ahead contract. No-peek integration exercises a test-only candidate against the full-relation model.List it as experimental, separate from shipping coverage.

The only filename correction is virtual-row-legacy-guard-oracle.test-d.ts to virtual-row-legacy-guard.test-d.ts. It contains concrete type assertions, not an independent model or reusable checker. The independent virtual-row type-shape owner remains query/virtual-row-fields-oracle.test-d.ts.

Repairs made during this review

  • Named the primary and receiving owners in the replay, load-subset, ordered-work, flat-hash, and notification oracle prose.
  • Corrected the indexed-DB portfolio's controlled-versus-native scope and three receiving-spec paths in the coverage map.
  • Classified backend Collection E2E separately from framework conformance, listed the live-query notification owner and the no-peek experiment, and linked the same-key optimistic composition witness.
  • Corrected stale Electric SDK receiving references and inaccurate prose about LocalStorage same-tab authority, direct change-event settlement, row metadata, and fractional top-K multiplicity.
  • Removed collision-sensitive distinct-digest assertions from the flat-hash and identity owners. The identity model still checks equalHashValues for distinct values, including a forced digest collision and a digest-only hostile mutant.
  • Tightened the proxy-revert native-history checker: an equal-valued f may appear in getChanges() only after a live write to f. A spurious-field report is a hostile control for this assertion.

No production code changed. Collision-sensitive controls and their generators were removed; the proxy-revert checker gained an assertion. This review found no pair with the same complete law, legal history, production path, and observation cut that should be merged into one test file.

Validation

At the reviewed baseline, Vitest discovered the renamed file and both type assertions passed. The @tanstack/db package-wide typecheck exited with unrelated missing @playwright/test and fake-indexeddb declarations and was not rerun in the carry-forward worktree. Dependency installation there failed with a private npm-proxy 403. Using the existing checkout's dependencies, focused worktree runs passed: 91 flat-hash and hash-identity tests, four hash-session replay tests, 61 legacy hash examples, and 48 proxy-revert tests. The @tanstack/db-ivm typecheck passed. The proxy run used a minimal Vitest configuration because the package's normal setup requires the unavailable fake-indexeddb package. The digest-only and spurious-field hostile controls both failed their intended checker assertions. Prettier accepted every edited file, all new review links resolved locally, and git diff --check passed. No provider E2E tests ran.

Remaining review work

Several oracle-named files still need a clearer opening contract or authority source. The clearest are query/ir-stable-identity-oracle.test.ts, the two ordered-source-loader oracles, query/derived-delete-reconciliation-oracle.test.ts, the two top-K batch/fractional files, and several SQLite and provider owners. Those are literate-prose gaps, not evidence of duplicate ownership. Follow-up review removed the collision-sensitive distinct-digest assertions. The identity owner still checks distinct values through equalHashValues, including under forced digest collisions.