TanStack

Content temporarily unavailable

Accepted source publication after queued hydration

This is the original 24-case audit. The admission follow-up records a subsequently reproduced timing gap and withdraws the merge-ready assessment.

Reviewed boundary

Issue #2036 reports a source commit accepted before subset hydration starts, then rejected when publication follows that hydration. PR #2037 limits the publication-time sequence check to hydration-owned replay. Commit admission and writes during hydration keep their existing sequence checks.

The independent law is the existing RFC #1659 durability obligation: an accepted source commit remains an obligation across persistence scheduling. The covered history has successful hydration, no cancellation, and one sync run. Observation occurs after all source and subset receipts settle, before cleanup. This record does not claim every interleaving or live-provider reach.

Revisions and preservation

  • Original main: e21c280f3c4e56f6c0d05ec0eed87db29c623489.
  • Original PR: d18a7c72557e8e8067cc494e84c11ad11ab0baca.
  • Integration main: cfb03f201bb21d82b7f537a9fbe59d3623f395d6.
  • Merge before the oracle extension: 17a56e64bcabc24dd4ec74597530f1adf644fdbf.
  • Reviewed code and oracle head: c9a2c631c073bae95c08dc306d642a5687c471ad.
  • Tested production blob: 50920367aa97667de71ca319c46e810d35a0d1a6.
  • Tested oracle blob: 4a5665e0955015ed24730f3d98047a41ff6cec07.

The integration preserves the author's commit and merges current main normally. It retains main's reversion of the separate immediate-publication cycle repair. The new immediate cases hold a predecessor at durability, after its publication. They do not enter that unsupported publication cycle.

Loss audit of the original two witnesses

The expanded grammar contains both original fixtures at hydration count two, ordinary admission, and a dependent successor. It crosses insert/update with one/two/three hydrations, ordinary/immediate admission, and absent/present successor. These 24 histories are a complete finite enumeration.

Original observationReceiving assertion
Hydration does not start before source commitZero adapter subset calls before source begin/commit
Hydrated baseline precedes source publicationPublic title recorded at every adapter subset call
All source and subset receipts fulfillExact fulfilled outcomes after Promise.allSettled
Collection remains readyExact Collection status
Final source row and unseen baseline field surviveIndependent complete-row expectation for public and durable rows
Fresh insert resets metadata, update preserves itExact row metadata per operation
Successor reads pending metadata and winsStaged cursor read and final durable cursor
Source transactions persist in FIFO orderDurable mutation keys plus source-title order
Cleanup preserves the primary failureExisting bounded cleanup helper and gate release

foldDurabilityLedger folds complete source obligations in commit order. It has no production generation, queue, or classification helper. Expected source rows include the preceding baseline's untouched detail. The driver sends only the source title patch, so production must preserve that detail itself.

No existing main assertion or test expectation changes. The extension replaces the PR's two fixtures with their finite generalization, without a failure gate.

Evidence

On original main, both unmodified PR fixtures reject with the reported hydration-cycle error through applyTransactionToCollection and applyBufferedSyncTransactionUnsafe. The expanded 24 histories fail at the receipt/status/public-row/durable-row assertion.

The same 24 histories fail against integration main without the publication guard. With the guard, all 39 selected new and existing checks pass without type errors. The following wrong designs fail at their intended assertions:

Wrong designDistinguishing witnessOutcome
Reject any publication after a sequence advanceEvery accepted-before-hydration matrix cell24 assertion failures
Remove commit-time sequence validationExisting begin-before-hydration, commit-after-hydration historyMissing-throw assertion failure
Preserve stale metadata for ordinary insertsEvery insert matrix cell12 metadata assertion failures; update cells pass

These are assertion failures, not setup failures or timeouts. All temporary production variants were removed. Historical full-suite evidence on original main plus the guard was 739 passing tests. That count does not certify the later integration revision.

On the integration revision with the expanded oracle, the full package suite passed: 23 files, 737 tests, two existing TODOs, and no type errors. Standalone tsc --noEmit passed. ESLint reported zero errors and 22 existing require-await warnings outside the new cases. After the review moved each subset unload into the existing bounded cleanup helper, the final focused run again passed all 39 selected checks with no type errors. The added block was formatted, and git diff --check passed. The cached formatter also proposed unrelated changes to existing type unions; those changes were excluded.

Independent correctness and simplification reviews found no production or oracle-correctness defect and no worthwhile simplification. Both identified the same audit mismatch: subset unloads were outside the bounded helper. The final fixture puts each unload through that helper so one cleanup failure cannot skip later actions or mask the primary failure. No failing product history was inferred from this harness correction.

The commands use the checked-in package configuration. A local run uses:

shell
cd packages/db-sqlite-persistence-core
PATH="$PWD/../../node_modules/.bin:$PATH" ../../node_modules/.bin/vitest run \
  tests/persisted-oracle.test.ts \
  -t 'publishes committed source|rejects a source transaction|preserves.*metadata|rejects a transaction begun before hydration' \
  --coverage.enabled=false --maxWorkers=2 --reporter=dot

Node 24.19.0, Vitest 3.2.4 and TypeScript 5.9.3 ran with jsdom. Registry failures prevented a fresh lockfile install, so the run reused cached third-party tools. DB and DB-IVM were built from this worktree, and runtime workspace imports resolve to those builds. No runtime source alias or SQLite-host shim was added. This is not an exact-lockfile toolchain receipt.

Oracle-guide audit

RequirementOutcome and evidence
ORC-001Pass. Existing durability law, controlled history and observation boundary stated above and in the executable owner.
ORC-002Pass. Independent ledger and baseline expectations do not import production semantic machinery.
ORC-003Pass. Opening contract, local model/grammar prose, production driver and settlement comparison remain visible in the oracle file.
ORC-004Pass. Original cells reconstruct exactly. Each axis contributes metadata behavior, count boundaries, admission mode or successor dependence. Domains are explicit. Open-crossing histories remain rejection controls.
ORC-005Pass. Zero pre-commit loads and per-hydration titles witness reach. The recorder distinguishes receipt rejection, wrong status, row loss, stale metadata, omission and durable reordering.
ORC-006Pass. The three wrong designs above reach their intended assertion checkpoints.
ORC-007Not applicable. This change adds a finite enumeration, not an important randomized property. Existing random campaigns remain unchanged.
ORC-008Not applicable. The existing reference model gains no state fields or transitions.
ORC-009Pass. Shared concepts retain glossary terms. The ledger abstracts complete source obligations and does not model hydration state.
ORC-010Pass. Results are captured before cleanup. The existing helper bounds every cleanup action and preserves primary and secondary diagnostics.
ORC-011Not triggered. No shared semantic fault needing another formulation was identified. Provider ordering is a separate receiving-witness gap.
ORC-012Pass for this bounded audit. This versioned record identifies every requirement, exact revisions and tested blobs. No universal bug-class closure is claimed.
ORC-013Pass for the declared finite domain. Adjacent counts, operation/admission/successor cases and existing open-crossing controls distinguish plausible wrong consequences.
ORC-014Limited to the controlled receiving boundary. Live Electric/OPFS handoff remains open with a named owner below.

Remaining witnesses

The coverage map assigns cancellation, cleanup/restart and hydration-failure compositions to packages/db-sqlite-persistence-core/tests/persisted-oracle.test.ts. Those paths need this accepted-before-hydration schedule, not merely their existing separate histories.

The exact real-provider schedule belongs in packages/browser-db-sqlite-persistence/e2e/electric-hydration-straddle.opfs.spec.ts. Its existing during-hydration history does not establish this handoff. The controlled fixture does not prove live Electric delivery, browser scheduling, OPFS behavior, or application-level downstream error propagation.