TanStack

Content temporarily unavailable

Hydration source durability: loss audit and oracle strengthening

Current status

PR #2049 contains the approved call-local adapter repair, committed oracles, and a patch changeset. The production base advanced to a37e69ab6aa35fd6a2a72d727de2b5168d10b1a0 before the repair was committed. The latest review receipt is authoritative for the current executable hashes, 640 passing core checks (with one existing todo), and 25 passing Chromium OPFS checks.

This document preserves a chronological audit. Earlier statements about uncommitted tests, unchanged production, no PR, old baselines, and smaller counts describe those historical stages only. Each SHA-256 binds its named stage; it is not an assertion that every historical digest matches HEAD. The final executable hashes at reviewed commit 90cbda1e5 all matched the receipt below, including the later cleanup correction to the core test hash.

Historical identity and scope: pre-fix loss audit

At this pre-fix stage on 2026-10-06, the production baseline was 65992aacda530fde89f4c8ffa803b60cd708c425 (origin/main). Worktree branch: codex/issue-2046-red-oracles. The tests were uncommitted; the executable SHA-256 bindings below identify their reviewed content without pretending that the production commit contains these tests. Production and the lockfile were unchanged at this stage. The initial review remains an historical record of the smaller 24-core/12-browser candidate.

The user requested Field Lab's Hidden-signal recovery assay (loss-audit) and separately authorized improving the oracle. The candidate was frozen before three fresh, read-only scanners received separate sources with sibling findings hidden: S1 the oracle guide; S2 persistence contracts; S3 the existing oracle portfolio. Recovery and implementation judgment are separated below. At this stage, no Field Log, external message, production fix, commit, push, or PR had been created.

This improves enforcement of the local composition: source transactions buffered by persisted hydration must use the current scoped adapter, preserve their ordered durable obligations, settle each acceptance/receipt at its own boundary, and release that scope for ordinary/peer work. It does not claim all persistence laws universally proved or the production bug repaired.

Frozen candidate SHA-256 (paths are repository relative):

FileSHA-256
packages/db-sqlite-persistence-core/tests/persisted-oracle.test.ts412f3ba03af8f1d82da5c6a6f8d3dd15c975261646d988bf9995a4ce30415e55
packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.tsae78b9254ab52c2fbb9a29dd9042aef8c4502efd0ae43b46e7914bca88328e4f
packages/browser-db-sqlite-persistence/e2e/hydration-commit-oracle.opfs.spec.ts8cdb922972059c9a0a5d667f03a9d8b1802ff6cd1ec35aa6305f4d437c55c0ce
docs/contributing/oracle-reviews/issue-2046-hydration-commit-deadlock.md7954be179200f8c80da08488c45bb779fbc5e9dde8d58b8e88159ce27145a4a1
docs/contributing/oracle-coverage.mde84ea6d6455f9d1c91590a5242754f84ee64a700218f9bd26061c80dcee3ba90

Source-by-source recovery ledger

Pointers in this section refer to the frozen candidate or unchanged production baseline, not moving line numbers after the edits. P is the core persisted-oracle.test.ts; B is hydration-commit.opfs.ts; R is the initial review; C is src/persisted.ts in persistence-core. S is shared-logical-scheduling-oracle.test.ts; F is browser tests/shared-driver-fairness-oracle.ts; PC is browser tests/per-collection-coordinator-oracle.test.ts.

These 23 source-specific recoveries preserve overlapping support. They are not 23 distinct bugs or an instruction to restore every possible cross-product.

IDSupported material omitted from the frozen reductionSupport and loss pointDrop mechanism
S1-1Each receipt pending, not just an aggregate pendingORC-005; guide 818–825; P19243–19250; R79–84. A pending preload/sibling masks early fulfillment. A standalone all-fulfilled Promise-shape control also read pending after the candidate's single microtask.Observation compression and insufficient reaction drain
S1-2Immutable primary evidence survives all cleanup failuresORC-010; B220–247 publishes after cleanup and retains a live errors array. Collection cleanup/dispose can erase the capture or skip database close.Cleanup treated only as release; late/shallow capture
S1-3Review binds the actual executable revisionORC-012; R6–8 identifies production HEAD, not new test content.Baseline identity substituted for oracle identity
S1-4Existing direct replay stays directORC-007; P121–126 guards existing suites, but P19121 uses unconditional describe. New red cases can contaminate another property's replay.Local finite-test classification hid package integration
S1-5Expected records remain independent of mutable driver inputsORC-002; P197,19240,19272 reuse baseline/source objects to compute expectations.Formula independence mistaken for record independence
S1-6Supplied adapter expires with its callbackORC-001/005/013; R53–56 cites lifetime, but P19178–19197 uses a permanently callable bound store.Two-sided scope law reduced to no public reentry
S2-1Acceptance/durability differ from visibility under optimistic workC3943–3954,1412–1426,2744–2754; P19243–19250 aggregates receipts; existing causal replay P18613–18745 uses the same adapter for both routes.Settlement observations collapsed
S2-2Correct current loan and per-Collection adapter identityC438–445,880–884,978–999; P19178–19188 reuses one scoped object/store.Identity/lifetime projection
S2-3Ordinary work remains scheduled, including during another Collection's hydrateC2828–2834,446–449; B193–202 only starts an empty peer. Temporal overlap alone is not nested dependency.Dependency relation replaced by scope-active flag
S2-4Metadata/truncate require durability; only a truly empty transaction does notC2817–2823,2890–2939,4477–4486; P19144–19146 and19272–19281 only inspect distinct inserts/keys.Zero row mutations equated with no durable obligation
S2-5Durability error envelope, prefix/suffix fencing, no implicit rollbackC898–901,2713–2719,2792–2805; errors.ts52–90; all scoped stores succeed.Failure category compressed
S2-6Failed incremental reads may preserve independent source work; baseline failure is terminalC2397–2423,2531–2533; P14283–14387 uses an unscheduled adapter.Request-local and terminal failures merged
S2-7Abort timing and successor dependency determine the resultP90–96,3863–4047; C2769–2805; no signals/dependencies in the new matrix.Abort/cleanup grouped into one future category
S2-8Cleanup invalidates queued work; old continuations cannot alter a replacement runC2203–2288,2732–2733,2755,2852,4668–4726; P19286–19296 only cleans settled work.History truncated before replacement
S3-1Independent receipt observations at held reads already existP8594–8666,806–856 versus19243–19253.Existing observation granularity lost in composition
S3-2Same-key source precedence, deletion, truncate and FIFOP67–77,11804–11811,12005–12014,12169–12430; disjoint baseline/source keys cannot witness stale overwrite or resurrection.Input simplification/explicit operation exclusion
S3-3Metadata-only versus empty work, captured row-metadata ownership, sequence evidenceP2683–2716,3769,11629–11786; PC3766–3952. Candidate observes only rows and keys.Result projection drops metadata and sequence
S3-4Startup/replay/durability failures differ from request-local failures; rejected hydrate releases peersP750–856,9089–9160,9587–9706,4172–4246,4701–4859,14283–14482; S343–374.Explicit exclusion compressed into generic failure
S3-5Independent/dependent and pre-/post-application aborts differP3705–3763,9192–9405,3863–3939,11097–11219,4880,5023.Signal timing and dependency erased
S3-6Handler may await acceptance while its own optimistic publication is pendingP9995–10079,18614–18740; P18639 supplies no distinct scoped route.Causal distinction hidden by “commit settles”
S3-7Scope non-interleaving, ordinary route after exit, K=1/FIFO fairnessS4–18,263–299,343–374; F4–18 and fairness tests256–295,574–619. B193–229 observes eventual peer readiness only.Identity/order laws reduced to completion
S3-8Adapter also belongs to correct Collection/schema/elected ownerPC123–135,2437–2506,3645–3952; B158–200 uses same schema and only A writes.Empty peer hides contamination and owner identity
S3-9Replacement fencing is different from successful harness teardownP7206,7330,17739–17810,5177,5293; candidate never replaces a pending run.Lifecycle distinctions collapsed

All scanners cautioned against turning recovery into an unrestricted Cartesian product of the persistence portfolio. The guide does not require random campaigns for this finite matrix or a second formulation without a named shared-fault hypothesis. Existing open-transaction/hydration restrictions are characterized limitations, not newly invented product laws.

Separate evaluation and implemented restoration

The user separately requested improvements. The implementation restores the following distinctions while reusing existing primary owners:

  • Individual obligations: Each receipt and each whenSyncAccepted promise is observed independently at held-read and held-durability cuts. A task boundary drains reactions while the gate remains causally held. A permanent wrong-answer test proves a fulfilled receipt cannot hide behind its sibling.
  • Independent values and ordering: An immutable input edit log recomputes the last row/metadata edit. Inputs are cloned before the driver sees them. Exact transaction data, FIFO turns, sequence/row-version numbers, durable prefixes and final public/durable state are checked. put means a full source update/upsert in this core driver; the OPFS driver separately performs literal inserts, updates and deletes.
  • Scope lifetime: Each controlled callback lends a fresh adapter identity. Nested calls, ordinary same-run tail commits, a second on-demand hydration, and reopen distinguish the current loan from public reentry and cached loans.
  • Transaction shapes: Twelve history templates cover one/two distinct upserts, same-key replacement/delete, metadata-plus-truncate/replacement, row/collection metadata set/delete, metadata-only, truncate-only, empty, atomic multi-row, independent pre-abort, and first/second durable failure. Each runs for three phases, two scope modes and two baseline sizes: 144 histories. A populated baseline shares the source key, making precedence observable. Empty work must not allocate a durable sequence.
  • Failure classes: Held first/second storage failures preserve exact cause, code/path, shared terminal error, durable prefix, suffix rejection and later same-run rejection. Publication rollback is not invented. Existing startup read-failure and incremental request-local failure witnesses now lend a distinct scoped adapter. The latter retains its successful overlapping retry.
  • Acceptance before visibility: The existing causal replay witness now lends a distinct adapter, holds the optimistic handler after acceptance, checks the durable row and still-pending/absent public result, then releases publication. A repair cannot wait on the handler that awaits acceptance.
  • Cleanup as an action: Four additional histories cross startup/subscription with scoped/unscheduled adapters, clean up while a source receipt is queued, reject that receipt, release the old read, restart and reject late old-control publication while fresh source work succeeds. The no-write claim is limited to work not yet issued to storage.
  • Receiving host: 24 actual Chromium OPFS histories retain the original three phases, two coordinators and two baseline cases, adding single-insert versus rich transaction histories. A=11, B=22 and C=33 are separate schema adapters on the same database. A's nested work, B's cold hydration and C's ordinary source write must finish without cross-contamination. No additional SQL may enter the provider while the owning read is held. Exact metadata, schemas, rows and reopen are compared. The exact scope containing the held SELECT must exit; another scope's exit cannot satisfy that obligation.
  • Causal cycle detection: Browser instrumentation matches the transaction ID passed with a live scoped adapter to its erroneous public-adapter call. Merely overlapping ordinary work cannot trigger the cycle observation.
  • Failure fidelity: Browser observations are deep-copied before teardown. Every cleanup failure is retained separately, coordinator disposal cannot skip database close, and red cycles close the worker/context. A permanent browser calibration injects first and last cleanup failures and checks both diagnostics plus the intact primary observation. All setup after opening the database is inside its cleanup guard.
  • Replay/provenance: The finite matrix and strengthened fixed routing witnesses now use an explicit replay guard. The versioned content hashes below bind this evidence to the changed files.

The controlled probe forwards invalid routes so the harness can release its gates and clean up. It therefore proves routing, not a simulated scheduler. The OPFS receiver supplies the real non-preemptible scope and self-cycle premise.

One attempted assertion was rejected during contract review: core truncate can establish Collection readiness at publication (collection/state.ts, truncate publication path). It cannot establish source durability. The retained test checks acceptance/receipt pendingness at that cut without inventing a stronger universal Collection-readiness law. An attempted second subset hydration in an eager Collection was also an unreached fixture path; repeated scope coverage now uses the legal on-demand path. Neither harness failure is product evidence.

Verification and hostile calibration

The same narrow temporary scoped-adapter forwarding repair from the initial review was used only to reach the successful comparison cuts. Every calibration restored the original production file in finally.

ExecutionResultClassification
Complete core suite, unchanged production48 failed, 480 passed, 1 existing todoReached routing assertions: 44 initial nonempty scoped histories, 2 second-scope empty-history continuations, 2 strengthened existing causal/failure witnesses. No timeout/setup failures.
OPFS receiver, unchanged production8 failed, 17 passedReached same-transaction scheduler-cycle assertions in default-coordinator startup/subscription cases. Both workarounds and cleanup calibration pass.
Complete core suite, temporary forwarding repair528 passed, 1 existing todoSame histories and comparisons.
OPFS receiver, temporary forwarding repair25 passedSame real database, scheduler, peer/schema and cleanup paths.
Eight hostile repairsAll rejected by assertionsCounts/checkpoints below; production restored after each campaign.
Existing FIFO property's direct replay3 passed, 510 skipped, 1 existing todoRequested replay plus existing global harness checks; no new routing cases execute.
Retained-demand replay special case361 passed, 151 skipped, 1 existing todoIts legacy outer guard retains existing fixed tests; the new 149 finite checks and two strengthened routing witnesses are excluded.
TypeScriptCore package and focused browser oracle checks passedFull browser package still needs unrelated Electric/pg dependencies unavailable in this partial install.
ESLintNo errors; 22 existing require-await warningsNo new warnings in the added oracle block/browser files.
Production/lockfile diffEmptyNo repair or dependency changes retained.

Eight additional wrong repairs were applied independently on top of that calibration repair. All reached assertion failures; none timed out, failed setup, remained unreached, survived, or was equivalent in the tested domain:

Wrong repairFailing cases / 149 focused checksDistinguishing checkpoint
Resolve source receipt before durability88Individual receipt/acceptance at held durability
Cache the supplied scoped adapter as the registered adapter36Ordinary post-scope route / expired loan
Drop row and collection metadata48Durable prefix or final metadata
Ignore truncate24Exact admitted transaction truncate flag
Drop row mutations148Exact admitted transaction or fresh restart row
Reverse buffered FIFO48Exact transaction at durability admission
Swallow storage failure24No suffix admission after rejected durable turn
Replace classified storage error with generic error24Error type/code/path/cause and shared identity

A standalone Promise-shape probe exposed the frozen aggregate false green. The retained early-receipt calibration exercises the replacement checker. The final browser cleanup calibration supplies permanent ORC-010 evidence. Original main is itself the routing hostile subject in both controlled and actual-host tests.

The following historical session-only commands used cached tools and untracked local-source aliases. No other checkout's production build supplied test behavior. These commands are not runnable from a fresh checkout because the cache configuration and temporary typecheck project were not committed. Use the fresh-checkout instructions below to run the retained checks with repository configurations.

shell
node node_modules/vitest/vitest.mjs run --config node_modules/.cache/issue-2046/vitest.config.ts --reporter=dot
node node_modules/vitest/vitest.mjs run --config node_modules/.cache/issue-2046/vitest.config.ts -t 'hydration source durability routing' --reporter=dot
TANSTACK_DB_ORACLE_PROPERTY=sqlite-persistence.source-fifo-order TANSTACK_DB_ORACLE_SEED=2046 TANSTACK_DB_ORACLE_PATH=0 node node_modules/vitest/vitest.mjs run --config node_modules/.cache/issue-2046/vitest.config.ts --reporter=dot
node node_modules/typescript/bin/tsc --noEmit -p packages/db-sqlite-persistence-core/tsconfig.json
node node_modules/typescript/bin/tsc --noEmit -p /private/tmp/issue-2046-audit/browser-types.json

From the browser package:

shell
PATH="$PWD/../../node_modules/.bin:$PATH" node node_modules/@playwright/test/cli.js test --config playwright.opfs.config.ts hydration-commit-oracle.opfs.spec.ts --reporter=line --timeout=15000

Temporary logs, frozen files, calibration patch/scripts and mutation outcomes are under /private/tmp/issue-2046-loss-audit/. The assertions, laws, finite cases and verdict-critical results are retained here and in the executable files; future readers need not trust the existence of those temporary logs.

Guide conformance and remaining boundaries

RequirementOutcome and evidence
ORC-001Scope API, established persisted-history durable/failure laws, and core acceptance/publication authority are named. Limits below remain explicit.
ORC-002Immutable input edit-log recomputation; cloned inputs; no production queue, classifier or scheduler computes expected state. Browser literal snapshots give a different formulation.
ORC-003Opening laws/limits, model rationale, grammar, production driver, cuts and comparisons are adjacent in executable files. Model edits distinguish row and collection metadata across truncate.
ORC-004Bounded enumeration, not an important random property. Reconstruction retains reported startup/subscription/empty/populated traces and both controls. Each template/axis's contribution is stated below. Nearby invalid open transactions crossing another hydration are excluded; the grammar contains only committed independent transactions. No invalid history is silently treated as a successful transaction.
ORC-005Read-entry, exact transaction admission, each accepted/applied receipt, exact held-scope exit, durable rows/metadata and reopen are witnessed. Diagnostics include duplicates/order/value omissions. Real OPFS supplies the actual receiving path.
ORC-006Eight independently run hostile designs fail reached assertions; permanent receipt and cleanup controls; unchanged main fails the routing/cycle comparison.
ORC-007New bounded matrices do not trigger random-campaign requirements. Existing generated campaigns remain under the full suite. The explicit replay smoke check confirms the new matrix is skipped during another property's direct replay.
ORC-008Reference recomputes snapshots from an input log, not a new state machine. Driver scope tokens, gates and counters are instrumentation. Separate pending/fulfilled/rejected observations cannot be merged: gate release or failure distinguishes them.
ORC-009Glossary terms are retained: Collection versus subscription readiness, source acceptance versus applied receipt, cleanup/restart. Model-only put maps to source full update/upsert; edit-log filtering abstracts independently pre-aborted transactions.
ORC-010Gates always release; primary failure survives existing core cleanup diagnostics. Browser deep capture precedes cleanup; each failure is retained and database close is attempted. Permanent two-failure calibration passes.
ORC-011Named shared fault: insert-only source/baseline concatenation and a fake scope could agree on wrong precedence or scheduling. Real SQLite snapshots, independently written rich-history expectations and actual scheduled/ordinary peers distinguish that hypothesis.
ORC-012This versioned record lists every requirement, exact baseline/content bindings, calibration classifications and unresolved cells. No bug-class closure claimed while production remains red.
ORC-013Boundary witnesses include scoped versus ordinary, current versus expired loan, metadata-only/truncate-only versus empty, pending versus completed durable turns, first versus second failure, same-key versus disjoint writes, cleanup before storage versus next-run admission. Mutation kills demonstrate the intended distinctions.
ORC-014The browser receiver supplies the real shared-scope/read/source-commit premise and rich row/metadata operations. Controlled storage rejection, abort and cleanup timing do not claim actual-host I/O/cancellation coverage; owners below retain those handoffs.

Grammar ablations: removing startup misses eager loading; removing subscription misses on-demand buffering with already-ready status; removing after-ready loses the regular route control. Removing scope distinction loses the original bug; removing default/browser coordinator loses its real workaround. Baseline zero proves no stored rows are needed; baseline one challenges source precedence. Distinct and repeated keys distinguish count/order from final membership; delete and truncate distinguish absence from stale rows; row/collection metadata and empty transactions distinguish zero mutations from zero obligations. Atomic batches check transaction granularity. Failure ordinal distinguishes preserved prefix from abandoned suffix; pre-abort distinguishes abandonment from failure of independent work. Tail, second on-demand scope and reopen distinguish current adapter loans, later ordinary use and durable storage. Bounds are 0/1 baseline, 1–3 transactions per core template, 0–3 edits per transaction, 0/1 independently pre-aborted transaction, and storage failure at ordinal 0/1. Browser rich history has six transactions plus its ordinary tail. No random-run confidence is used to extend these bounds.

The laws still have meaningful open compositions. They are retained with owners in the coverage map, not hidden by the green calibration:

  • Primary persisted-history owner: dependent aborts, abort during/after publication, buffered partial-update recovery, arbitrary queued reloads, late already-issued storage success/failure across replacement, and metadata inherited from different owning reads need distinct scoped-adapter witnesses. Existing tests continue to own their unscoped semantic laws. The new cleanup witness does not promise cancellation/rollback of an already-issued write.
  • Shared-driver fairness owner: K=1 and FIFO under storms already have their own models and OPFS receiver. This change proves finite peer progress and ordinary-work exclusion at a held hydrate; it does not claim the nested-source composition under arbitrary backlogs. Needed witness: nested source commit inside a hydrate while both lanes retain a K-bound-distinguishing backlog.
  • Per-Collection coordinator owner: current-host schema/data isolation is now received in OPFS, but elected-owner transfer and cross-tab RPC while nested durability is pending remain with its ownership ledger.
  • OPFS receiver: physical storage failure, abort/cleanup races, other browser engines and non-browser hosts need provider-supplied premises. Controlled errors in the core suite do not discharge those receiving obligations.
  • Production/history: the default-coordinator repair remains open; historical package release attribution still requires a bisect. A known reachable red counterexample prevents closure regardless of the stronger test coverage.

Reviewed executable content

FileSHA-256
packages/db-sqlite-persistence-core/tests/persisted-oracle.test.ts08ba69cdb4bcad7fa1c683d080ac3c51e75642caccf137864c87ca13ac8f17fe
packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.ts200fd6fb5edd99a000acbb92b7e67b79b4949978953e0de8efbefd4efb2360bd
packages/browser-db-sqlite-persistence/e2e/hydration-commit-oracle.opfs.spec.ts48a5b85740c4e7a282ba7fdda53b076c44ac36bda6d2b06e9820554440e8003d
packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.html28b99007a046019cc8466eb5d51561a55ab2c975d94bb98880e3f09b0f762058
packages/browser-db-sqlite-persistence/playwright.opfs.config.tsd596da20036070bc4fded9829517aa8c2e69844061d7ac66c4b2233871c184cd

Change weight against origin/main: production 0 lines; tests/fixtures/config +1705 / −220 (net +1485); documentation +559 / −0 (net +559). The larger test diff includes formatting around two existing witnesses; no production machinery was added.

Retained repair and current-base verification — 2026-10-06

The user approved the call-local adapter repair and PR preparation after the RED audit above. The unpublished branch advanced to current origin/main, a37e69ab6aa35fd6a2a72d727de2b5168d10b1a0, before retaining the repair. That base adds Temporal persistence coverage. Its new dependency required linking an already cached temporal-polyfill into this worktree's ignored dependencies. The initial missing-import run collected no tests and is setup evidence only. No package manifest or lockfile change belongs to this repair.

SingleProcessCoordinator.requestApplyCommittedTx now accepts the interface's existing optional scopedAdapter and selects it for that call. Ordinary work continues to use the registered adapter. The coordinator does not retain the loan. This changes two production lines and removes one, for a net addition of one line. Test and contract-documentation growth is separate from that budget.

The current implementation preserves the existing hydration completion, acceptance/publication, FIFO, failure and scheduler contracts. It does not add recovery state, bypass unrelated scheduled work, or replace the default coordinator. The earlier RED-stage statements remain historical evidence.

Initial repair execution on the advanced baseResultReached evidence
Original core implementation48 failed, 566 passed, 1 existing todoRouting assertions, with no timeout or setup failures
Retained repair, complete persisted oracle614 passed, 1 existing todoAll existing and added comparisons
Original implementation, real Chromium OPFS8 failed, 17 passedSame-transaction scheduled reentry/cycle assertions
Retained repair, real Chromium OPFS25 passedAll histories and cleanup-failure calibration
Eight independent hostile repairsAll rejected by assertionsEarly receipt 88, cached scope 36, dropped metadata 48, ignored truncate 24, dropped rows 148, reverse FIFO 48, swallowed failure 24, generic error 24
TypeScriptCore package and focused browser oracle passedNo type errors
ESLint0 errors, 22 existing warningsExisting require-await warnings only
Formatting and whitespacePassedChanged executable files and diff

The hostile repairs ran separately on the retained repair, and the exact repaired production file was restored in finally. None failed during setup, timed out, remained unreached, or survived. The counts refer to the 149 focused checks. Browser GREEN uses the same local source paths as RED. Cached tooling from another checkout supplies dependencies only, never the production build.

Executable SHA-256 bindings at the initial repair stage (superseded below):

FileSHA-256
packages/db-sqlite-persistence-core/src/persisted.ts84ad4e2e5c8c071c44f72dcff007a220484d2a9530a5a0db033efd49b0c03bd4
packages/db-sqlite-persistence-core/tests/persisted-oracle.test.ts7c8fe3aeb32afb66303392c2b79762cf005790cab91c455d64634ba82b9b7845
packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.ts200fd6fb5edd99a000acbb92b7e67b79b4949978953e0de8efbefd4efb2360bd
packages/browser-db-sqlite-persistence/e2e/hydration-commit-oracle.opfs.spec.ts48a5b85740c4e7a282ba7fdda53b076c44ac36bda6d2b06e9820554440e8003d

Current Vitest commands add --pool=threads --pool-options.threads.maxThreads=2 --pool-options.threads.minThreads=1 to the commands above. Current browser verification uses --timeout=15000. Logs and raw prep-pr reviews are under /private/tmp/issue-2046-prep-pr/; this record preserves the verdict-critical results without requiring those temporary files.

Original issue ledger: disposition after the production repair

This entry updates the original R1–R9 ledger without rewriting its historical verdicts. R1, R2, R3, R4 and R9 are fixed-now within the declared source hydration grammar and Chromium receiving path. R5, R6 and R7 retain the approved existing behavior and executable controls: accepted-design. R8 remains confirmed-open only for historical release attribution. The causal source change and current repair are established, but the earliest published affected version still needs a package bisect. Totals: nine raw items = five fixed-now + three accepted-design + one confirmed-open.

The scoped routing defect is repaired. The broader scoped lifecycle, fairness backlog, elected-owner/host handoff and historical-version witnesses listed in the coverage map remain separate open evidence. These bounded results do not establish universal liveness or every persistence composition.

Initial prep-pr review and cleanup oracle receipt

The simplifier returned no proposals. Five parallel review angles checked repository instructions, obvious bugs, history, prior PR decisions and code comments. Their raw reports preserve 25 source-specific candidates, including rejected hypotheses and all nine historical review findings. No reviewer found an introduced production defect. The parent evaluated every candidate without a severity cap: one fixed-now, ten already-fixed, twelve refuted and two duplicates. The task-local append-only evaluation ledger retains the full raw claims, sources, judgments and independent cleanup score. No candidate was silently filtered or deferred. The reviewers traced the existing contracts and distinguished introduced defects from historical diagnostic limitations.

Two independent reviewers identified the same preexisting diagnostic weakness in the strengthened optimistic causal witness. Direct cleanup in finally could replace its primary error. The parent injected two sentinel failures in that actual witness: the original form reported only the cleanup error. The existing cleanupPersistedOracle helper retained the primary error and logged the separate cleanup error. Both calibration runs reached their intended error assertions without timeout. The retained test uses the helper and contains no sentinel injection. This is oracle diagnostic hardening, not another production bug or proof of a native cleanup failure. The helper's permanent calibration continues to exercise primary and cleanup diagnostics.

After this seven-line test increase, the complete persisted oracle again passed 614 tests with one existing todo. Core TypeScript and lint passed with the same 22 warnings, and the file remains formatted. Its final SHA-256 is 7156c39e8b657367aeea5491065b5836beecfeecc1f1855e344f5a4fcec36f15. The other executable hashes above remain unchanged. The eight hostile runs preceded this diagnostic-only edit and exercised the unchanged 149-case suite. Direct FIFO replay on the new base passed three checks, skipped 596, and kept one existing todo. The repair and browser fixture remained unchanged for the 25-check browser GREEN receipt.

Two review qualifications remain explicit. Exact owning-scope exit is observed for the held startup/subscription histories. The after-ready control does not establish a universal readiness-versus-scope-exit ordering. Browser reopen here creates a new Collection over retained persistence, not a physical browser or worker restart. Native failures and process restart keep their separate owners.

Reproducing the retained checks from a fresh checkout

These commands use tracked package scripts and configurations. Run them from the repository root with the repository's supported Node.js and pnpm versions. Install dependencies and build the core package with its workspace dependencies:

shell
pnpm install --frozen-lockfile
pnpm --filter '@tanstack/db-sqlite-persistence-core...' build

Run the complete persisted oracle through its repository Vitest configuration, with at most two workers. Coverage and integrated typechecking are disabled for this focused runtime invocation, as in the historical source-alias run:

shell
pnpm --filter @tanstack/db-sqlite-persistence-core exec vitest run --config vite.config.ts tests/persisted-oracle.test.ts --coverage.enabled=false --typecheck.enabled=false --pool=threads --pool-options.threads.maxThreads=2 --pool-options.threads.minThreads=1
pnpm --filter @tanstack/db-sqlite-persistence-core exec tsc --noEmit -p tsconfig.json

For only the finite routing matrix, add -t 'hydration source durability routing' to the Vitest command. To replay the existing FIFO property, prefix that same command with TANSTACK_DB_ORACLE_PROPERTY=sqlite-persistence.source-fifo-order TANSTACK_DB_ORACLE_SEED=2046 TANSTACK_DB_ORACLE_PATH=0.

Install Chromium and run the real OPFS receiver. The explicit browser channel selects the installed Playwright Chromium instead of requiring local Chrome:

shell
pnpm --filter @tanstack/browser-db-sqlite-persistence exec playwright install --with-deps chromium
PLAYWRIGHT_CHANNEL=chromium pnpm --filter @tanstack/browser-db-sqlite-persistence exec playwright test --config playwright.opfs.config.ts hydration-commit-oracle.opfs.spec.ts --reporter=line --timeout=15000

The browser Vite configuration aliases the workspace source packages. These commands need no node_modules/.cache/issue-2046 configuration or /private/tmp project. The temporary paths elsewhere in this record identify historical session artifacts only. The reported historical counts belong to their stated source/dependency revisions, not to an unexecuted clean installation. The PR's CI separately runs the tracked package and OPFS configurations.

The documentation follow-up for CodeRabbit review 5431163123 distinguishes these reproducible entry points from the original session commands and removes nontechnical personnel commentary. No executable file, oracle law, assertion, or recorded runtime result changed.

High-effort review receipt

This follow-up evaluates all ten items from a source-only review of 90cbda1e5, against the later documentation head 996292b31. The review found no introduced production bug. Its useful findings concern the coordinator contract, historical documentation, and oracle integrity. The runtime repair remains unchanged; this follow-up adds six lines of interface JSDoc, with no new production state, branch, fallback, or coordinator replacement.

The interface now states that wrappers must forward a supplied leader-local adapter and must not retain or serialize it. A forwarding wrapper and a loan-dropping wrapper reach the actual default coordinator and produce opposite routing observations. An explicit-adapter control also shows that this call can succeed without a registered fallback; a later ordinary call must reject before an apply until that fallback is registered. Collection construction supplies that registration. This records the existing optional-adapter design, rather than adding a new configuration restriction.

The controlled routing probe now tracks each callback's lifetime independently. Three calibration histories cover nested callbacks and overlapping callbacks with either exit order. Each distinguishes a live loan, an expired loan, reentry through the public adapter, and ordinary work after all callbacks exit. These histories describe the controlled adapter. They do not claim that the real SQLite scheduler permits overlapping hydrate callbacks.

The eight rejected-buffer histories, request-local failed-read/retry witness, and optimistic causal-replay witness each run with no scope API, a same-adapter scope, and a distinct loan. Their existing exact failure, durability, public row, acceptance, and applied-receipt comparisons are preserved. Adding a scope probe no longer substitutes for either original adapter path.

The OPFS receiver now observes both contenders at their actual scheduling entry points before taking the held-read snapshot. It continues observing peer hydrate and regular callback entry, and C's commit SQL, until A's owning callback exits. A positive count requires the C SQL observer to be reached exactly once, so a changed query cannot silently disable that comparison. Election stream-position reads deliberately bypass logical scheduling and are outside this regular-work law; treating all peer SQL as forbidden would impose a false contract. The default coordinator's tail must enter public apply; the browser coordinator's tail must enter its regular scope. Rich subscription histories join the follow-up hydrations triggered by truncate before issuing that ordinary tail. Final rows alone cannot establish correct tail routing.

Scope identity is now a callback invocation token, not a reusable adapter object or singleton active value. The actual held SELECT requires exactly one owning callback and publishes a diagnostic immediately if that premise is missing. Sixteen startup/subscription histories assert owning-scope exit. Eight after-ready controls report no held scope (null); their useful receipt, row, schema and reopen checks remain. Those controls do not prove a universal readiness-versus-scope-exit ordering.

Calibration and validation

All runs used this worktree's source with the historical cached tooling explained above. The fresh-checkout entry points remain the tracked commands in the previous section. Temporary mutations were restored byte-for-byte. The missing-owner injection below is a deliberate harness fault, not evidence of reachable overlapping callbacks in the real host.

CheckResult and meaning
Original scope-dropping behavior with strengthened core oracle50 assertion failures, 590 passes, 1 existing todo; no setup or timeout failure
Retained repair, complete core oracle640 passes, 1 existing todo
Original scope-dropping behavior, strengthened Chromium receiver8 cycle assertion failures, 17 passes; no setup or timeout failure
Retained repair, complete Chromium receiver25 passes
Callback-lifetime calibration against old probe3 assertion failures; all 3 pass with independent lifetime tracking
Cached-loan mutationOld browser receiver: 25 passes. Strengthened receiver: 8 tail-route assertion failures, 17 passes
Ordinary scheduling bypass mutationOld receiver: all 4 selected held-read histories pass. Strengthened receiver: all 4 fail at whole-callback peer exclusion, without timeout
Missing no-scope failure identity4 restored rejection histories fail exact-reason assertions; 20 other rejection histories pass
Missing owning-callback identity injectionOld harness waits until its 15-second test timeout with no observation. New harness reaches an immediate missing-owner diagnostic and assertion failure; no timeout
Types and static checksCore and focused browser TypeScript pass; ESLint has 0 errors and the same 22 existing warnings; executable formatting and diff whitespace pass

The original eight hostile-repair counts earlier in this record remain bound to their earlier executable revision. The new runs establish sensitivity for the newly strengthened boundaries; they do not retroactively relabel those historical runs as executions of this revision.

Review accounting and limits

All ten review items retain separate dispositions in the task-local lossless ledger: eight fixed-now (contract prose, documentation clarity, scope probe, adapter-mode coverage, tail routing, owner diagnostics, causal preemption checks, and after-ready coverage credit), one already-fixed (personnel commentary, removed in 996292b31), and one accepted-design (explicit adapter versus registered ordinary fallback). Some claims needed qualification: the historical hashes were stage-specific and the final reviewed hashes matched; after-ready histories were not wholly vacuous; and real public A callbacks are serialized, so the hypothesized existing overlap timeout was not reproduced as product behavior. The deliberate lost-owner fault established the diagnostic weakness.

There is no deferred repair from these ten findings and no new runtime defect. The scope remains finite: the primary routing grammar, the restored failure and replay paths, and one Chromium OPFS host. Arbitrary custom coordinator wrappers must obey the stated contract; this suite cannot enforce third-party code. The separately recorded scoped lifecycle, fairness backlog, host/election handoff, native failure, and historical release-attribution gaps remain in the coverage map. A Collection reopen here is not a process or worker restart.

Current executable SHA-256 bindings for this follow-up:

FileSHA-256
packages/db-sqlite-persistence-core/src/persisted.tsd319f74a1020f6fd96db5cd5cb995c42a7809c105b423abdc6da25ba2d1fb070
packages/db-sqlite-persistence-core/tests/persisted-oracle.test.tsf3939fc3cdc81580398b7ff8a07737a5745dfb0da458b85af02585eaacdce89a
packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.tsa0044df64bbe8281a53150b2698b97a25f796d3cfae707f7eb5220dfd682bb68
packages/browser-db-sqlite-persistence/e2e/hydration-commit-oracle.opfs.spec.ts6e7936824e92fb4f0adb2f7da5650ff5aaf9d2d10ecb8c8833b0947529f8271e