The high-effort review found a real adjacent failure in PR #2037 at 5688e232eff34eeac555f2586a34672bad25865b. The earlier merge-ready assessment is withdrawn. The local repair passes the tests below. The maintainer has now specified persisted-baseline precedence; the dated follow-up below supersedes the initial pending-policy assessment. No broad bug-class closure is claimed.
This record supplements the original audit. The initial evaluation checked that exact PR head and these candidate blobs:
The author and bot commits remain intact. The first evaluation left changes local while the policy question was pending. The dated follow-up records the subsequent maintainer decision and verification. Historical hashes identify historical evidence; they are not silently replaced with new hashes. The initial formatting-only successor reflowed one flatMap expression.
The existing metadata-ownership test already supports beginning during H1 and committing after H1 finishes. The old 24-cell grammar only begins before any hydration. It cannot reconstruct this supported admission timing.
The new eight-cell grammar begins during H1, retains its captured metadata ownership, and commits after H1 finishes. H1's adapter scope remains held after its task completes. In ordinary mode, one or two later subset loads reserve the mutex first. In immediate mode, existing admission logic holds those loads behind the source. The driver records the load count at source durability to prove these different orders. The other axis is whether H1 supplied the source key. All receipts settle before rows, metadata and status are compared.
At the reviewed head, all four ordinary cases reject the source receipt with a persisted sync transaction cannot cross a hydration cycle, retain the old row, and set Collection status to error. The four immediate cases pass. Instrumentation confirms ordinary admission is accepted at sequence 1 but publication checks sequence 2 or 3. The original matrix always has queuedBecauseHydrating === false at source admission.
The candidate retires openTransaction.hydrationSequence only after ordinary commit admission. The publication check remains unconditional. Queued replay retains its sequence, and all transactions retain their captured hydrationContext. The flag is not cleared or reinterpreted: it also controls metadata treatment and immediate replay. The candidate is two production lines smaller than the PR, and adds three lines over the integration main.
The reviewer supplied eight numbered findings and two omitted notes. Each is retained separately below. Overlap does not remove an item.
| ID | Technical judgment | Action and durable value |
|---|---|---|
| H01 | Confirmed P1. Four legal ordinary histories reproduce accepted-commit failure at the receipt/status/row checkpoint. | fixed-now locally. Eight adjacent histories remain in the persistence oracle. |
| H02 | Correct distinction between captured hydration ownership and commit's replay branch. Clearing the existing flag would conflate other responsibilities. | duplicate of H01. The suggested retirement of the sequence on ordinary admission is the implemented alternative. |
| H03 | Confirmed missing timing dimension. Instrumentation proves the original matrix never flags its source transactions. | fixed-now. The new grammar varies timing, captured key membership, count and admission order. |
| H04 | Confirmed scope change, not a proven corruption result. Accepted inserts and deletes survive queued collection-reset and coordinator full-reload notifications on the PR; they reject on pre-PR main. | fixed-now oracle coverage after the maintainer decision below. Accepted sync transactions follow the older persisted baseline. Compatible rereads and ordered truncate replay now have 90 permanent histories; invalidated resume points remain outside this evidence. |
| H05 | The claimed contradiction is refuted: the comment says fresh inserts reset metadata, not complete row values. A quiescent pre-PR comparison preserves omitted detail in all 24 cases. The reference does not import production classifiers. | refuted as a defect in this scheduling change. Added prose identifies retained legacy upsert/partial-value behavior. This is compatibility evidence, not an independent proof that all legacy insert semantics are ideal. |
| H06 | The original prose explicitly limited the result to 24 histories, but its checked broad title could imply more coverage. H01 defeats that wider reading. | fixed-now. The coverage item is open, with supported histories and remaining reset, cancellation, cleanup and failure witnesses named. |
| H07 | The old record identifies an older blob. The claim that formatting invalidates the results is too strong: the exact reviewed head passes its 39 focused checks, and fresh controls reproduce the intended failures. | fixed-now evidence receipt. This record preserves historical provenance and pins the tested local candidate blobs. |
| H08 | Recording occurred before adapter completion, but the claimed false green is refuted. Injecting a rejection after that recording makes all 24 original cases fail on receipt/status/durable-state assertions. | fixed-now recorder precision: record titles after adapter success. No expectation is weakened. |
| H09 | Confirmed behavior change without a demonstrated defect. A delete issued while its public row is absent removes the row after later hydration supplies it. Receipts fulfill and public/durable state agree. | fixed-now permanent delete dimension in the 90-history grammar, including on-demand commits before the persisted row is public. The omitted-public-delete mutant fails all ten no-truncate delete histories. |
| H10 | The speculative leftover-replay/reset failure was not reproduced. Two commits queued during H1 drain before a reset queued behind that scope, on both reviewed head and candidate. | confirmed-open with an evidence gap, not a confirmed product defect. A smallest failing schedule is still required; the owner and bounded successful control are recorded in the coverage map. |
Current totals: ten raw items = seven fixed locally + one duplicate + one refuted + one open evidence gap. H04 was initially a design decision and H09 was initially deferred; the dated follow-up resolves both within its stated scope. H10 still lacks a failing history. No item is discarded.
The final candidate passes 23 package test files: 746 tests, two existing TODOs, and no type errors. Standalone TypeScript passes. ESLint reports no errors and 22 existing require-await warnings. No warnings occur in the added block. The same cached third-party toolchain limitation as the original audit applies. DB and DB-IVM resolve to builds from this worktree.
| Control | Result at the intended checkpoint |
|---|---|
| Restore the reviewed publication guard | Four new ordinary cases fail receipt/status/row comparison. |
| Restore integration-main production | Original 24 cases and four new ordinary cases fail. |
| Remove ordinary commit validation | Existing begin-before/commit-after test fails its missing-throw assertion. |
| Retire captured metadata context with the sequence | Four owner-supplied cases fail metadata comparison. |
| Remove ordinary insert's explicit metadata deletion | All 12 original insert cases fail metadata comparison; updates pass. |
| Reject adapter write after the original early recorder | All 24 original cases fail, disproving the proposed false-green mechanism. |
| Establish baseline before source writes on pre-PR production | All 24 original row/metadata comparisons pass, supporting compatibility. |
| Queue reset or coordinator full reload before accepted insert/delete | Six route/operation probes pass on reviewed head and candidate, and fail on pre-PR main. The subset route is the comparison control. |
| Queue two hydration-owned commits, then reset | Both replay receipts fulfill and the second value survives reset; no leftover failure is established. |
Every negative result above is an assertion failure, not a timeout or setup failure. Temporary mutants were removed and candidate hashes rechecked. An initial nonexistent config path and one transient formatting syntax error were setup failures, corrected and excluded from behavioral evidence.
The reset probes use real runtime coordinator-message handling and a controlled adapter. They do not establish browser cross-tab delivery or choose reset precedence. RFC #1659 invariant 7 allows durability/replay or observable failure; it does not by itself choose the result of accepted work across a full reset. Source-truncate notification, schema-changing resets, native-host execution, and arbitrary reset/replay interleavings remain outside these probes.
| Requirement | Follow-up evidence |
|---|---|
| ORC-001 | Supported begin-during/commit-after history derives from the existing metadata-ownership contract; full-reset policy remains explicitly open. |
| ORC-002 | Constant source records and captured key-membership expectations are independent of production sequence/queue helpers. The new source insert supplies its complete expected row. |
| ORC-003 | Local prose states the law, finite grammar, adapter hold, immediate-order difference, observations and settlement checkpoint. |
| ORC-004 | Four ordinary failing histories are reconstructed; four immediate histories preserve the alternate legal order. Captured key membership distinguishes wrong metadata rebinding. |
| ORC-005 | Real source begin/write/commit and subset paths run. Adapter counts witness the source-versus-hydration ordering; receipts, full rows, metadata and status are compared. |
| ORC-006 | Old guard, metadata-context loss, commit-check loss and stale insert metadata all fail the intended assertions. |
| ORC-007 | Not triggered by these bounded enumerations. Existing generated campaigns remain unchanged. |
| ORC-008 | No state is added to the independent reference model. |
| ORC-009 | Shared terms retain glossary meaning; captured metadata ownership and replay admission are explicitly distinguished. |
| ORC-010 | Observations precede bounded cleanup; load and scope gates release in finally; each unload is inside the existing cleanup helper. |
| ORC-011 | The named insert-semantics concern is compared with pre-PR quiescent behavior. This establishes compatibility only; ideal legacy insert semantics are not independently proved. No product expectation was rewritten. |
| ORC-012 | All ten review inputs, exact revision/blob receipts, requirement outcomes and unresolved boundaries are preserved here. No class closure is asserted. |
| ORC-013 | Original and adjacent admission timings distinguish the old guard from the candidate; captured key membership kills context loss. |
| ORC-014 | Evidence remains at controlled adapter/coordinator boundaries. Live Electric/OPFS schedules retain their named receiving owner in the coverage map. |
The maintainer specified: "persisted reads are by definition more stale than a new network read" and requested an oracle update. For the compatible-baseline histories here, persisted rows precede newer accepted sync transactions from the sync adapter. Reading those rows cannot revoke acceptance. An authoritative truncate replay has its own position in source order: it supersedes earlier writes, and later sync transactions apply to that replacement.
The previous recommendation to preserve rejection after every reset or full reload is withdrawn. The six original probes supplied coordinator notifications that requested another persistence read. They did not establish an invalidated resume point or a schema-changing destructive reset. Observable failure remains required when work actually fails; it does not justify rejecting valid work.
The follow-up starts from PR head 5688e232eff34eeac555f2586a34672bad25865b. These exact final blobs are the verification receipt, independent of the later commit that stores this record:
The 24 original and eight adjacent histories remain. The new 90-case grammar has five mode/route combinations, three source operations, three truncate-replay positions, and two schedules. On-demand Collections acquire a subset or receive reset/full-reload notifications. Eager Collections receive those notifications. Each insert/update/delete history runs with no truncate replay, replay before the change, and replay after it. Commit acceptance occurs either before the queued read runs or after its publication. Expected results do not depend on that timing.
The reference computes the final snapshot directly from source order. A later replacement wins. Otherwise the newer change decides the shared key, and unrelated baseline rows survive only without a truncate replay. Row values are complete and metadata is explicit, so this extension does not redefine partial updates or the omitted-field question in H05. The cursor is opaque collection metadata, not proof of a compatible provider resume point.
The driver holds an earlier persistence write and invokes the real Collection, persisted wrapper, and coordinator-message handler. The loaded rows and durable completion trace prove that the older baseline runs before the newer source changes. The final checkpoint compares every operation outcome, Collection status, exact public/durable rows, row metadata, and cursor metadata before cleanup. The mixed operation list includes applied receipts and a subset-load promise; it does not treat them as the same boundary.
| Verification | Result |
|---|---|
| New grammar on the local repair | All 90 histories pass. |
| Original implementation on the new grammar | All 45 queued histories fail at the outcome/row/status comparison; all 45 serial controls pass. |
| Omit public application of source truncate | All 60 histories containing truncate replay fail final comparisons. The 30 histories without it pass. |
| Omit public application of source delete | All ten no-truncate delete histories fail exact public-row comparison. The other 80 histories pass; truncate makes the omitted delete unobservable at their final checkpoint. |
| Final configured package suite | 23 files pass, 837 checks pass, two existing TODOs, and no type errors. |
| Standalone TypeScript | Exit 0. |
| ESLint | Exit 0, no errors, 22 existing require-await warnings outside the new block. |
| Experimental Prettier CLI and whitespace check | Pass. |
The mutant runs produced assertion failures, not timeouts or setup failures. Their test revision preceded the final mixed-operation naming and parameter formatting changes. The final suite ran on the exact oracle blob above. Every mutant was removed; the production hash matches the initial local repair.
Local logs and mutation scripts remain in .review-2036-2037/high-effort/ and are not PR content. Earlier cached tool links broke. Fresh installation failed at the configured registry with 403 and at the public registry with a fetch failure. Verification used local cached packages: Node 24.19.0, Vitest 3.2.4, TypeScript 5.9.3, Prettier 3.9.9, and compatible Rollup 4.59.0 instead of locked 4.64.0. Package imports resolve to DB and DB-IVM builds from this checkout. The lockfile and package manifests did not change. CI must check the locked toolchain. Failed dependency/formatter setup attempts and the initial recorder type error are excluded from RED evidence. The optional changeset validation script is absent; the existing patch changeset covers the only changed package.
The production follow-up remains +4/-6 lines against the published PR, or +3/-0 against its integration main. The oracle follow-up is +457/-5 lines against the published PR, including the earlier eight-history repair. This precedence extension adds no production state or behavior beyond that repair.
A fresh correctness review found no blocking model, driver, or product defect. The simplification review recommended only clearer naming for the mixed wait list. It recommended keeping the finite grammar and all observations intact.
| ID | Raw finding or note | Evaluation and disposition |
|---|---|---|
| P01 | The new receipts list also contains a subset-load promise. | Direct source confirms the terminology mismatch. fixed-now: use pendingOperations/retainOperation and name both settlement kinds. |
| P02 | The final checkpoint does not establish intermediate publication or individual receipt timing. | Correct limit of the declared settled-result law. deferred stronger claim to the persistence-history owner and coverage map. |
| P03 | Controlled notifications do not establish real cross-tab delivery or invalidated-resume behavior. | Correct controlled-boundary limit. deferred to the named persistence-history and browser OPFS/Electric owners in the coverage map. |
| P04 | Pending-reset-policy and missing-delete documentation is stale after the new evidence. | Direct source confirms both statements need revision. fixed-now in the coverage map and this record. |
The new review totals are four = two fixed-now + two deferred with named owners. The original ten-item totals are seven fixed-now + one duplicate + one refuted
| Requirement | Outcome |
|---|---|
| ORC-001 | The maintainer decision establishes precedence. The glossary defines sync transaction, applied receipt, publication and truncate replay. Compatible-baseline and settled-result limits are explicit. |
| ORC-002 | The reference derives exact snapshots from ordered replacement and newer insert/update/delete effects. It reads no production flags, sequence counters or classifications. |
| ORC-003 | Prose precedes the grammar, explains the independent algebra, describes controlled production scheduling, and names the final observations. |
| ORC-004 | Bounded enumeration covers 5 mode/routes × 3 operations × 3 replay positions × 2 schedules. Each axis changes a path, effect or precedence boundary. Both notification routes, eager startup, absent-key delete, and both replacement orders are reconstructible. Invalidated resume points, errors and still-open cross-read transactions are excluded explicitly. |
| ORC-005 | Real begin/write/truncate/commit, subset acquisition and coordinator-message handling run. Exact loaded baseline, pre-release observations and completion traces witness the path. All modeled rows, metadata and cursor values reach comparisons. |
| ORC-006 | The original guard fails 45 queued histories while serial controls pass. Public-truncate and public-delete mutants fail 60 and ten histories respectively at assertions. |
| ORC-007 | Not triggered: the extension is a bounded enumeration, not a random generated property. Existing generated campaigns remain intact. |
| ORC-008 | No mutable reference state is introduced. The reference directly computes the final snapshot from input source order. |
| ORC-009 | Shared concepts use glossary terms. Source-step labels identify input sync transactions, while the mixed wait list distinguishes applied receipts from subset-load settlement. |
| ORC-010 | Observations precede cleanup. The held persistence gate releases in finally, retained rejections are observed, and the existing bounded cleanup helper preserves primary and secondary failures. |
| ORC-011 | Serial controls supply a second scheduling formulation for the same source history. Original production agrees with the reference on all 45 controls, while queued cases expose the guard error. H05's separate quiescent compatibility evidence remains intact. |
| ORC-012 | Both review inventories reconcile above. Exact head/blob receipts, all applicable requirement outcomes, limitations and coverage-map destinations are retained. |
| ORC-013 | Before/after truncate distinguishes ordered replacement from unconditional source preservation. Queued/serial controls distinguish acceptance from publication timing. Eager/on-demand no-truncate deletes distinguish already-public and absent-key admission. |
| ORC-014 | The claim is limited to controlled compatible notifications and recording adapters. The coverage map names live Electric/browser OPFS, invalidated resume points, schema changes, and intermediate publication as separate receiving evidence. |
No broad closure claim follows. Cancellation, cleanup, read failure, arbitrary buffered replay/reset interleavings, and the semantic basis of the still-open transaction restriction retain their named persistence-history owner.
PR head 4c9962e4ec30e2579dfbbd4bc7ad4e61d10c408f passed the standalone-branch checks recorded above. Those results did not establish that it passed with current main. CI job 112035444776 in run 37388315568 checked out merge 7ef5161 against main 49abb32ff. Main commit eac6e8b6a (#2030) had removed begin({ immediate }). Three calls in the new oracle still used that API. Four histories also expected the reservation that the removed option no longer supplied. CI correctly rejected both the calls and those ordering observations.
This follow-up merges main 482196ec4c4369ec540b510ced926bb7d82d7231 without rewriting published history. DB-IVM and DB were rebuilt from the merged sources before testing. The unmodified integration reproduced all four runtime failures and all three type-error locations. The earlier local success was a base-integration gap, not evidence of a flaky test or stale dependency output.
The existing adapter capability metadata.persistence.reserveCommitTurn() replaces the removed option in these fixtures. Its documented contract reserves an open sync transaction's turn ahead of later subset reads; Electric uses it for overlapping stream transactions. All 24 original and eight adjacent histories remain. Their rows, metadata, receipts and exact ordering comparisons are unchanged. The two admission orders are now named unreserved/reserved commit turns. The 90 precedence histories and their reference algebra are unchanged. This repair adds no production behavior beyond main's integration.
| Check on the integrated candidate | Result |
|---|---|
| Unmodified integration | Same four ordering failures and three type-error locations as CI. |
| Updated fixture | All 122 histories and their three typechecked definitions pass. |
| Remove sequence retirement | 73 histories fail: the original 24, four unreserved begin-during-read histories, and 45 queued precedence histories. The other 49 runtime histories pass. |
| Restore the reviewed flag-based guard | All four unreserved begin-during-read histories fail; the four reserved controls pass. |
| Omit public truncate | 60 precedence histories fail, 30 pass. |
| Omit public delete | Ten no-truncate delete histories fail, 80 pass. |
| Omit commit-turn reservation from the updated fixture | Four reserved histories fail the exact read-count observation; four unreserved controls pass. |
| Final full package suite | 23 files, 836 passing checks, two existing TODOs, no type errors. |
| Standalone TypeScript | Exit 0. |
| Final package lint | No errors; 25 existing require-await warnings. |
All hostile controls failed at assertions, with no type, timeout, or setup failure. Every temporary mutation was restored. The only additional correction sorts two imported names in sqlite-boolean-arity-oracle.test.ts; that lint error was already present on main and does not alter the oracle's behavior.
ORC-001 and ORC-009 now cite the documented commit-turn capability for the fixture's ordering control. ORC-002's independent expected values do not change. ORC-003 and ORC-004 retain all histories and describe both supported orders. ORC-005, ORC-006 and ORC-013 have fresh path and hostile-control evidence above, including a direct omission control for the replacement API. ORC-007 remains inapplicable to the bounded enumeration; ORC-008 adds no model state. ORC-010's cleanup and ORC-011's serial controls remain intact. This appended revision receipt satisfies ORC-012 for the integration repair. ORC-014 retains the controlled-adapter limit; calling the same capability as Electric does not prove live Electric or host delivery. The coverage item remains open.
CI01, the user-reported integration failure, is confirmed and fixed-now. CI02, the inherited import-order lint error, is confirmed and fixed-now. The ten original review items retain seven fixed-now, one duplicate, one refuted, and one confirmed-open evidence gap (H10). The four additional review items retain two fixed-now and two deferred to their named owners. Current-head CodeRabbit review 87aabed8-7ed1-4853-a6c0-d83e12999aeb has no new code findings; its repeated docstring metric remains duplicate C04. No review item or tested history was discarded to make this integration pass.