# Content temporarily unavailable
# Ordinary SQLite work oracle review

Baseline production: `origin/main` at `ef1e6a4aa25fcfa988b1a14c7aa91406885814fe`.
Repair: `codex/issue-1992-sqlite-writes`, starting from that baseline. Oracle: `packages/db-sqlite-persistence-core/tests/ordinary-transaction-work-oracle.ts`, invoked by `sqlite-resume-snapshot.test.ts`. The ordinary write work law is RED on the baseline and GREEN with the repair. This record does not claim untested host behavior.

| Guide item | Outcome and evidence |
| --- | --- |
| ORC-001 | The file's opening contract derives durable row/metadata/position semantics from `PersistedTx` and the existing SQLite owner. Chunk-bounded work is explicitly a proposed acceptance law from #1992, not an existing promise. Browser and other host limits are named. |
| ORC-002 | `modelAfter` is a Map reducer over cloned public actions. It imports no SQL scheduler, batching classifier, or production serializer. |
| ORC-003 | The opening prose, `modelAfter`, fixed and generated semantic/work histories, node:sqlite fixture, and complete-observation/work comparisons expose the five responsibilities. |
| ORC-004 | The semantic generator is seed -> ordinary transaction -> optional dependent followup, with a late-bookkeeping rollback branch. Seven mandatory suffixes reconstruct repeated-key, delete/reinsert, partial-update, and present/absent row-metadata set/delete cases; random prefixes vary nearby action order. Its 120-sample fixed calibration reaches all seven scenarios on both rollback outcomes, both target keys, both followup outcomes, and a nonempty action/metadata prefix overlap. Removing a suffix loses its witness; removing prefixes loses adjacent orders. Bounds: 0–4 prefix mutations, 0–3 row-metadata actions, 0–2 collection-metadata actions, keys `a`/`b` plus absent `c`, values 0–9, one term with seq 1–3. The separate independent-key work generator has 0–60 unique keys, six insert/update/delete/row and collection metadata shapes, and 100/999 parameter caps; its 120-sample calibration reaches all shapes and caps. Truncate, concurrent owners, other key types, arbitrary-long histories, invalid positions, and interleaved row metadata are excluded. Fixed 25/26 and 10k work cases remain separate. |
| ORC-005 | The driver calls real `SQLiteCorePersistenceAdapter.applyCommittedTx`. Every generated seed/candidate/followup and late rollback resets counters around that apply and asserts exactly one `SQLiteDriver.transaction` entry before snapshot queries. The independent-key generator also captures query/run counts before comparing durable state, then applies `12 + 6 × ceil(n / min(100, floor(cap / 4)))`. Semantic/conflicting histories have no call bound. Durable observations come from `loadResumeSnapshot` plus diagnostic SQL tables. Public `pullSince` distinguishes 128 replay actions from 130 full-reload actions. |
| ORC-006 | An adapter-path driver corruption drops metadata and the complete observation rejects it. A test-only two-statement replacement of 26 rows passes the 100-parameter cap and value comparison but loses metadata, which the row comparison rejects. A temporary metadata-dropping driver mutation in the generated campaign failed at `candidate durable checkpoint` and shrank to repeated-key case `{seed:1992, path:"0:0:0:0:0"}`; the mutation was restored. Count perturbation controls add a phantom second transaction at each seed/candidate/followup and rollback checkpoint, and 20 phantom row calls to a normally green one-row case. Each is rejected by the corresponding transaction or work assertion. The baseline fails fixed and generated work assertions at the driver-call checkpoint. With the repair, a temporary row classifier mutation that admits repeated keys to a batch fails the generated oracle at the candidate durable checkpoint, seed 1992, path `2:0:0:2:2:2:2`. A separate temporary chunk-limit mutation passes the Cloudflare 25-row case but fails its 26-row case with `host parameter limit exceeded`. A collection-metadata classifier mutation that treats duplicate keys as distinct fails the fixed `repeated-collection-metadata-key-keeps-order` case at the complete durable checkpoint: it leaves `cursor` set after the model deletes it. All were restored. |
| ORC-007 | Semantic fixed/random campaigns share `generatedHistoryArbitrary`, `assertGeneratedHistory`, and `oracleRuns(24)`, fixed seed 1992, property `sqlite-ordinary.write-history`; the temporary metadata mutant failure directly replayed at path `0:0:0:0:0`. Independent work campaigns share `independentWorkArbitrary`, `assertIndependentWork`, and `oracleRuns(24)`, fixed seed 31992, property `sqlite-ordinary.independent-work`. The baseline shrinks to `{shape:"insert-later-metadata",size:3,cap:100}` at path `0:0:1:0:0:0`; direct random-campaign replay reproduces 20 calls against bound 18 and records `numRuns:1, failed:true`. The collection-metadata work gap on the first repair shrinks to `{shape:"collection-metadata-only",size:15,cap:100}` at path `0:2:2`, with 19 calls against bound 18. The repaired focused SQLite owner passes 36/36, the Cloudflare driver tests pass 6/6, and standalone package TypeScript passes. Two earlier broad package runs had resource-sensitive timeouts; the two affected CLI tests and 15-second lifecycle test pass when run alone. Neither broad run is a clean suite pass. |
| ORC-008 | The reducer retains rows, row metadata, tombstones, collection metadata, applied positions and latest position. A later partial update, delete/reinsert, metadata action, or replay distinguishes these states. It omits schema/reset/leader state because this bounded single-adapter history does not act on them. |
| ORC-009 | The opening prose maps diagnostic `expectedKeys`, `tombstones`, and `applied` to the persisted SQLite tables and uses glossary terms for committed transaction, metadata, position, and full reload. No model-only lifecycle is presented as production state. |
| ORC-010 | Every fixture is closed even after assertion failure. An `AggregateError` retains the primary error as `cause` and cleanup as a separate error. Fast-check shrink paths are reported and replayed directly; the generated work failure remains a work-checkpoint failure after shrinking to three rows. |
| ORC-011 | The generated semantic model uses a Map reducer, independent of the production classifier and SQL. The temporary repeated-key classifier mutation fails that model at the durable checkpoint. Existing owner tests separately exercise full replacement and resume; the Cloudflare driver provides a receiving seam. No additional shared-fault hypothesis has been named. |
| ORC-012 | This record covers every numbered guide item for the baseline and repair. The exact tested code HEAD is `1c521597f289226050285c27669907a300e9b2b6`; the record-only follow-up does not change production or oracle code. The generated campaigns sample nearby semantics and independent-key work within their stated bounds, including one-transaction checks for each generated apply. The bounded ordinary-write class is closed for these owner and Cloudflare storage-seam histories and observations; the host limits below remain outside that claim. |
| ORC-013 | Numeric 100/101 parameter guard and 25/26 rows are executable, and 64/65 mutations straddle the public 128-action replay threshold. A repeated-key classifier mutant fails at the generated candidate durable checkpoint, and a chunk-limit mutant crosses the 25/26 Cloudflare receiving boundary. Both were restored. |
| ORC-014 | The synthetic node:sqlite cap is a controlled host premise. The Cloudflare driver now covers the 100-parameter ordinary-write seam at 25, 26, and 205 rows with row and collection metadata as well as full replacement. The storage seam does not execute in Workers. OPFS scheduling and browser latency remain unverified receiving boundaries. |

The violated proposed law is bounded query/run calls per parameter-limited chunk for ordinary independent-key writes, while preserving atomic durable observations. The original witness is 10,000 distinct inserts plus metadata; adjacent cases include 25/26 and 100/101 keys, partial updates, deletes, row and collection metadata-only writes, repeated keys, and two rollback cuts. On the baseline, the owner has 33 passing tests and three RED work tests. With the repair, the owner has 36 passing tests. The 10,000-row insert plus metadata takes 505 query/run calls, down from 50,005; partial update, delete, and row metadata-only at 205 rows take 49, 31, and 13 calls. Collection metadata-only at 205 keys takes 22 calls, down from 209 before the extra batching pass. The tested component path is `applyCommittedTx` on node:sqlite after schema setup, with durable observations after settlement. Production source weight is 136 lines added and 153 removed, net -17 against the baseline.

The pre-repair package run reported 695 passing tests, one intended RED work test, two todo, and 153 `rootDir` source errors from cross-package imports in its typecheck worker; that run preceded the independent-key work generator. After the repair, two broad runs had resource-sensitive timeouts. The two affected CLI tests passed alone, and the 15-second lifecycle test passed alone in 14.76 seconds. Standalone `tsc -p packages/db-sqlite-persistence-core/tsconfig.json --noEmit` passes. A clean broad package run is still outstanding.

Replay command for the captured mutant path, from `packages/db-sqlite-persistence-core` (the temporary mutation has been restored):

```sh
TANSTACK_DB_ORACLE_SEED=1992 TANSTACK_DB_ORACLE_PATH='0:0:0:0:0' TANSTACK_DB_ORACLE_PROPERTY=sqlite-ordinary.write-history ../../node_modules/.bin/vitest run tests/sqlite-resume-snapshot.test.ts --testNamePattern 'preserves bounded ordinary write histories \(random or replayed\)' --coverage.enabled false --typecheck.enabled false
```

The baseline work failure replays directly against `ef1e6a4` with:

```sh
TANSTACK_DB_ORACLE_SEED=31992 TANSTACK_DB_ORACLE_PATH='0:0:1:0:0:0' TANSTACK_DB_ORACLE_PROPERTY=sqlite-ordinary.independent-work ../../node_modules/.bin/vitest run tests/sqlite-resume-snapshot.test.ts --testNamePattern 'bounds independent-key write work \(random or replayed\)' --coverage.enabled false --typecheck.enabled false
```

## Repeated-key work follow-up (2026-10-02)

The tested implementation commit is `326b1da83ea2978a52b2a07daa9347ee10492391` on `codex/issue-1992-sqlite-writes`. This section adds evidence for the repeated-key law. The earlier independent-key review above remains a record of its own tested commit.

The proposed work law now counts distinct keys in each row, row-metadata, and collection-metadata action family. A transaction with many actions on one key must use bounded query/run calls. The durable law still applies actions in their original order. A 205-update transaction on one key, with partial values and periodic inline metadata overrides, was RED on the published pre-follow-up commit `9d43ec43b81a24f6f8ef26e04f81fd7358676df6`: the independent Map model matched complete durable state, but the driver made 824 query/run calls against a bound of 18. The same witness is GREEN at 8 calls on `326b1da83`.

The existing generated-history grammar now samples 0–4, 5–24, and 25–60 action prefixes before its required scenario suffix. It checks complete durable state and the distinct-key work bound after committed candidates and late-bookkeeping rollback. Its scope remains two writable string keys, one absent metadata key, at most three row-metadata prefix actions, at most two collection-metadata prefix actions, and up to three committed positions. Fixed 25/26 and 10,000-key cases keep the parameter-boundary and large independent-key checks. This bounded grammar does not establish arbitrary-length histories, concurrent owners, or other host schedulers.

A separate truncate witness requires invalid intermediate values to reject atomically, even when a later same-key action overwrites them. It covers row values, inline row metadata, row metadata actions, and collection metadata actions. The first implementation was RED when a collection-metadata `set(undefined)` preceded a delete: the promise resolved and committed because the fold removed the invalid set. Before the fold, SQLite rejected the unbindable value. The final helper validates superseded sets under the same bound-value rule while retaining row metadata's `undefined`-to-NULL rule. The witness is GREEN on `326b1da83`, and the durable position remains unchanged after rejection. The pre-follow-up implementation is a hostile work-law case; the intermediate unbindable-value implementation is a hostile atomic-rejection case. Both fail at the intended checkpoint.

Final local verification on the implementation commit: the full SQLite core package run passed 394 tests with one todo across nine files, and the full Cloudflare package run passed 54 tests across four files. Both packages passed standalone TypeScript checks. Changed-file ESLint reported zero errors and three existing fixture warnings. Prettier and `git diff --check` passed. The repeated-key follow-up adds 82 and removes 20 production lines relative to `9d43ec43`; the complete PR adapter diff adds 199 and removes 148 lines against the fetched `origin/main`. The extra fold is the cost of the stronger work law. Browser latency, OPFS scheduling, Cloudflare Workers execution, Electric, Tauri, and native mobile remain outside this evidence.
