PR #2049 contains the approved call-local adapter repair, committed oracles, and a patch changeset. The production base advanced to a37e69ab6aa35fd6a2a72d727de2b5168d10b1a0 before the repair was committed. The latest review receipt is authoritative for the current executable hashes, 640 passing core checks (with one existing todo), and 25 passing Chromium OPFS checks.
This document preserves a chronological audit. Earlier statements about uncommitted tests, unchanged production, no PR, old baselines, and smaller counts describe those historical stages only. Each SHA-256 binds its named stage; it is not an assertion that every historical digest matches HEAD. The final executable hashes at reviewed commit 90cbda1e5 all matched the receipt below, including the later cleanup correction to the core test hash.
At this pre-fix stage on 2026-10-06, the production baseline was 65992aacda530fde89f4c8ffa803b60cd708c425 (origin/main). Worktree branch: codex/issue-2046-red-oracles. The tests were uncommitted; the executable SHA-256 bindings below identify their reviewed content without pretending that the production commit contains these tests. Production and the lockfile were unchanged at this stage. The initial review remains an historical record of the smaller 24-core/12-browser candidate.
The user requested Field Lab's Hidden-signal recovery assay (loss-audit) and separately authorized improving the oracle. The candidate was frozen before three fresh, read-only scanners received separate sources with sibling findings hidden: S1 the oracle guide; S2 persistence contracts; S3 the existing oracle portfolio. Recovery and implementation judgment are separated below. At this stage, no Field Log, external message, production fix, commit, push, or PR had been created.
This improves enforcement of the local composition: source transactions buffered by persisted hydration must use the current scoped adapter, preserve their ordered durable obligations, settle each acceptance/receipt at its own boundary, and release that scope for ordinary/peer work. It does not claim all persistence laws universally proved or the production bug repaired.
Frozen candidate SHA-256 (paths are repository relative):
| File | SHA-256 |
|---|---|
| packages/db-sqlite-persistence-core/tests/persisted-oracle.test.ts | 412f3ba03af8f1d82da5c6a6f8d3dd15c975261646d988bf9995a4ce30415e55 |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.ts | ae78b9254ab52c2fbb9a29dd9042aef8c4502efd0ae43b46e7914bca88328e4f |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit-oracle.opfs.spec.ts | 8cdb922972059c9a0a5d667f03a9d8b1802ff6cd1ec35aa6305f4d437c55c0ce |
| docs/contributing/oracle-reviews/issue-2046-hydration-commit-deadlock.md | 7954be179200f8c80da08488c45bb779fbc5e9dde8d58b8e88159ce27145a4a1 |
| docs/contributing/oracle-coverage.md | e84ea6d6455f9d1c91590a5242754f84ee64a700218f9bd26061c80dcee3ba90 |
Pointers in this section refer to the frozen candidate or unchanged production baseline, not moving line numbers after the edits. P is the core persisted-oracle.test.ts; B is hydration-commit.opfs.ts; R is the initial review; C is src/persisted.ts in persistence-core. S is shared-logical-scheduling-oracle.test.ts; F is browser tests/shared-driver-fairness-oracle.ts; PC is browser tests/per-collection-coordinator-oracle.test.ts.
These 23 source-specific recoveries preserve overlapping support. They are not 23 distinct bugs or an instruction to restore every possible cross-product.
| ID | Supported material omitted from the frozen reduction | Support and loss point | Drop mechanism |
|---|---|---|---|
| S1-1 | Each receipt pending, not just an aggregate pending | ORC-005; guide 818–825; P19243–19250; R79–84. A pending preload/sibling masks early fulfillment. A standalone all-fulfilled Promise-shape control also read pending after the candidate's single microtask. | Observation compression and insufficient reaction drain |
| S1-2 | Immutable primary evidence survives all cleanup failures | ORC-010; B220–247 publishes after cleanup and retains a live errors array. Collection cleanup/dispose can erase the capture or skip database close. | Cleanup treated only as release; late/shallow capture |
| S1-3 | Review binds the actual executable revision | ORC-012; R6–8 identifies production HEAD, not new test content. | Baseline identity substituted for oracle identity |
| S1-4 | Existing direct replay stays direct | ORC-007; P121–126 guards existing suites, but P19121 uses unconditional describe. New red cases can contaminate another property's replay. | Local finite-test classification hid package integration |
| S1-5 | Expected records remain independent of mutable driver inputs | ORC-002; P197,19240,19272 reuse baseline/source objects to compute expectations. | Formula independence mistaken for record independence |
| S1-6 | Supplied adapter expires with its callback | ORC-001/005/013; R53–56 cites lifetime, but P19178–19197 uses a permanently callable bound store. | Two-sided scope law reduced to no public reentry |
| S2-1 | Acceptance/durability differ from visibility under optimistic work | C3943–3954,1412–1426,2744–2754; P19243–19250 aggregates receipts; existing causal replay P18613–18745 uses the same adapter for both routes. | Settlement observations collapsed |
| S2-2 | Correct current loan and per-Collection adapter identity | C438–445,880–884,978–999; P19178–19188 reuses one scoped object/store. | Identity/lifetime projection |
| S2-3 | Ordinary work remains scheduled, including during another Collection's hydrate | C2828–2834,446–449; B193–202 only starts an empty peer. Temporal overlap alone is not nested dependency. | Dependency relation replaced by scope-active flag |
| S2-4 | Metadata/truncate require durability; only a truly empty transaction does not | C2817–2823,2890–2939,4477–4486; P19144–19146 and19272–19281 only inspect distinct inserts/keys. | Zero row mutations equated with no durable obligation |
| S2-5 | Durability error envelope, prefix/suffix fencing, no implicit rollback | C898–901,2713–2719,2792–2805; errors.ts52–90; all scoped stores succeed. | Failure category compressed |
| S2-6 | Failed incremental reads may preserve independent source work; baseline failure is terminal | C2397–2423,2531–2533; P14283–14387 uses an unscheduled adapter. | Request-local and terminal failures merged |
| S2-7 | Abort timing and successor dependency determine the result | P90–96,3863–4047; C2769–2805; no signals/dependencies in the new matrix. | Abort/cleanup grouped into one future category |
| S2-8 | Cleanup invalidates queued work; old continuations cannot alter a replacement run | C2203–2288,2732–2733,2755,2852,4668–4726; P19286–19296 only cleans settled work. | History truncated before replacement |
| S3-1 | Independent receipt observations at held reads already exist | P8594–8666,806–856 versus19243–19253. | Existing observation granularity lost in composition |
| S3-2 | Same-key source precedence, deletion, truncate and FIFO | P67–77,11804–11811,12005–12014,12169–12430; disjoint baseline/source keys cannot witness stale overwrite or resurrection. | Input simplification/explicit operation exclusion |
| S3-3 | Metadata-only versus empty work, captured row-metadata ownership, sequence evidence | P2683–2716,3769,11629–11786; PC3766–3952. Candidate observes only rows and keys. | Result projection drops metadata and sequence |
| S3-4 | Startup/replay/durability failures differ from request-local failures; rejected hydrate releases peers | P750–856,9089–9160,9587–9706,4172–4246,4701–4859,14283–14482; S343–374. | Explicit exclusion compressed into generic failure |
| S3-5 | Independent/dependent and pre-/post-application aborts differ | P3705–3763,9192–9405,3863–3939,11097–11219,4880,5023. | Signal timing and dependency erased |
| S3-6 | Handler may await acceptance while its own optimistic publication is pending | P9995–10079,18614–18740; P18639 supplies no distinct scoped route. | Causal distinction hidden by “commit settles” |
| S3-7 | Scope non-interleaving, ordinary route after exit, K=1/FIFO fairness | S4–18,263–299,343–374; F4–18 and fairness tests256–295,574–619. B193–229 observes eventual peer readiness only. | Identity/order laws reduced to completion |
| S3-8 | Adapter also belongs to correct Collection/schema/elected owner | PC123–135,2437–2506,3645–3952; B158–200 uses same schema and only A writes. | Empty peer hides contamination and owner identity |
| S3-9 | Replacement fencing is different from successful harness teardown | P7206,7330,17739–17810,5177,5293; candidate never replaces a pending run. | Lifecycle distinctions collapsed |
All scanners cautioned against turning recovery into an unrestricted Cartesian product of the persistence portfolio. The guide does not require random campaigns for this finite matrix or a second formulation without a named shared-fault hypothesis. Existing open-transaction/hydration restrictions are characterized limitations, not newly invented product laws.
The user separately requested improvements. The implementation restores the following distinctions while reusing existing primary owners:
The controlled probe forwards invalid routes so the harness can release its gates and clean up. It therefore proves routing, not a simulated scheduler. The OPFS receiver supplies the real non-preemptible scope and self-cycle premise.
One attempted assertion was rejected during contract review: core truncate can establish Collection readiness at publication (collection/state.ts, truncate publication path). It cannot establish source durability. The retained test checks acceptance/receipt pendingness at that cut without inventing a stronger universal Collection-readiness law. An attempted second subset hydration in an eager Collection was also an unreached fixture path; repeated scope coverage now uses the legal on-demand path. Neither harness failure is product evidence.
The same narrow temporary scoped-adapter forwarding repair from the initial review was used only to reach the successful comparison cuts. Every calibration restored the original production file in finally.
| Execution | Result | Classification |
|---|---|---|
| Complete core suite, unchanged production | 48 failed, 480 passed, 1 existing todo | Reached routing assertions: 44 initial nonempty scoped histories, 2 second-scope empty-history continuations, 2 strengthened existing causal/failure witnesses. No timeout/setup failures. |
| OPFS receiver, unchanged production | 8 failed, 17 passed | Reached same-transaction scheduler-cycle assertions in default-coordinator startup/subscription cases. Both workarounds and cleanup calibration pass. |
| Complete core suite, temporary forwarding repair | 528 passed, 1 existing todo | Same histories and comparisons. |
| OPFS receiver, temporary forwarding repair | 25 passed | Same real database, scheduler, peer/schema and cleanup paths. |
| Eight hostile repairs | All rejected by assertions | Counts/checkpoints below; production restored after each campaign. |
| Existing FIFO property's direct replay | 3 passed, 510 skipped, 1 existing todo | Requested replay plus existing global harness checks; no new routing cases execute. |
| Retained-demand replay special case | 361 passed, 151 skipped, 1 existing todo | Its legacy outer guard retains existing fixed tests; the new 149 finite checks and two strengthened routing witnesses are excluded. |
| TypeScript | Core package and focused browser oracle checks passed | Full browser package still needs unrelated Electric/pg dependencies unavailable in this partial install. |
| ESLint | No errors; 22 existing require-await warnings | No new warnings in the added oracle block/browser files. |
| Production/lockfile diff | Empty | No repair or dependency changes retained. |
Eight additional wrong repairs were applied independently on top of that calibration repair. All reached assertion failures; none timed out, failed setup, remained unreached, survived, or was equivalent in the tested domain:
| Wrong repair | Failing cases / 149 focused checks | Distinguishing checkpoint |
|---|---|---|
| Resolve source receipt before durability | 88 | Individual receipt/acceptance at held durability |
| Cache the supplied scoped adapter as the registered adapter | 36 | Ordinary post-scope route / expired loan |
| Drop row and collection metadata | 48 | Durable prefix or final metadata |
| Ignore truncate | 24 | Exact admitted transaction truncate flag |
| Drop row mutations | 148 | Exact admitted transaction or fresh restart row |
| Reverse buffered FIFO | 48 | Exact transaction at durability admission |
| Swallow storage failure | 24 | No suffix admission after rejected durable turn |
| Replace classified storage error with generic error | 24 | Error type/code/path/cause and shared identity |
A standalone Promise-shape probe exposed the frozen aggregate false green. The retained early-receipt calibration exercises the replacement checker. The final browser cleanup calibration supplies permanent ORC-010 evidence. Original main is itself the routing hostile subject in both controlled and actual-host tests.
The following historical session-only commands used cached tools and untracked local-source aliases. No other checkout's production build supplied test behavior. These commands are not runnable from a fresh checkout because the cache configuration and temporary typecheck project were not committed. Use the fresh-checkout instructions below to run the retained checks with repository configurations.
node node_modules/vitest/vitest.mjs run --config node_modules/.cache/issue-2046/vitest.config.ts --reporter=dot
node node_modules/vitest/vitest.mjs run --config node_modules/.cache/issue-2046/vitest.config.ts -t 'hydration source durability routing' --reporter=dot
TANSTACK_DB_ORACLE_PROPERTY=sqlite-persistence.source-fifo-order TANSTACK_DB_ORACLE_SEED=2046 TANSTACK_DB_ORACLE_PATH=0 node node_modules/vitest/vitest.mjs run --config node_modules/.cache/issue-2046/vitest.config.ts --reporter=dot
node node_modules/typescript/bin/tsc --noEmit -p packages/db-sqlite-persistence-core/tsconfig.json
node node_modules/typescript/bin/tsc --noEmit -p /private/tmp/issue-2046-audit/browser-types.jsonFrom the browser package:
PATH="$PWD/../../node_modules/.bin:$PATH" node node_modules/@playwright/test/cli.js test --config playwright.opfs.config.ts hydration-commit-oracle.opfs.spec.ts --reporter=line --timeout=15000Temporary logs, frozen files, calibration patch/scripts and mutation outcomes are under /private/tmp/issue-2046-loss-audit/. The assertions, laws, finite cases and verdict-critical results are retained here and in the executable files; future readers need not trust the existence of those temporary logs.
| Requirement | Outcome and evidence |
|---|---|
| ORC-001 | Scope API, established persisted-history durable/failure laws, and core acceptance/publication authority are named. Limits below remain explicit. |
| ORC-002 | Immutable input edit-log recomputation; cloned inputs; no production queue, classifier or scheduler computes expected state. Browser literal snapshots give a different formulation. |
| ORC-003 | Opening laws/limits, model rationale, grammar, production driver, cuts and comparisons are adjacent in executable files. Model edits distinguish row and collection metadata across truncate. |
| ORC-004 | Bounded enumeration, not an important random property. Reconstruction retains reported startup/subscription/empty/populated traces and both controls. Each template/axis's contribution is stated below. Nearby invalid open transactions crossing another hydration are excluded; the grammar contains only committed independent transactions. No invalid history is silently treated as a successful transaction. |
| ORC-005 | Read-entry, exact transaction admission, each accepted/applied receipt, exact held-scope exit, durable rows/metadata and reopen are witnessed. Diagnostics include duplicates/order/value omissions. Real OPFS supplies the actual receiving path. |
| ORC-006 | Eight independently run hostile designs fail reached assertions; permanent receipt and cleanup controls; unchanged main fails the routing/cycle comparison. |
| ORC-007 | New bounded matrices do not trigger random-campaign requirements. Existing generated campaigns remain under the full suite. The explicit replay smoke check confirms the new matrix is skipped during another property's direct replay. |
| ORC-008 | Reference recomputes snapshots from an input log, not a new state machine. Driver scope tokens, gates and counters are instrumentation. Separate pending/fulfilled/rejected observations cannot be merged: gate release or failure distinguishes them. |
| ORC-009 | Glossary terms are retained: Collection versus subscription readiness, source acceptance versus applied receipt, cleanup/restart. Model-only put maps to source full update/upsert; edit-log filtering abstracts independently pre-aborted transactions. |
| ORC-010 | Gates always release; primary failure survives existing core cleanup diagnostics. Browser deep capture precedes cleanup; each failure is retained and database close is attempted. Permanent two-failure calibration passes. |
| ORC-011 | Named shared fault: insert-only source/baseline concatenation and a fake scope could agree on wrong precedence or scheduling. Real SQLite snapshots, independently written rich-history expectations and actual scheduled/ordinary peers distinguish that hypothesis. |
| ORC-012 | This versioned record lists every requirement, exact baseline/content bindings, calibration classifications and unresolved cells. No bug-class closure claimed while production remains red. |
| ORC-013 | Boundary witnesses include scoped versus ordinary, current versus expired loan, metadata-only/truncate-only versus empty, pending versus completed durable turns, first versus second failure, same-key versus disjoint writes, cleanup before storage versus next-run admission. Mutation kills demonstrate the intended distinctions. |
| ORC-014 | The browser receiver supplies the real shared-scope/read/source-commit premise and rich row/metadata operations. Controlled storage rejection, abort and cleanup timing do not claim actual-host I/O/cancellation coverage; owners below retain those handoffs. |
Grammar ablations: removing startup misses eager loading; removing subscription misses on-demand buffering with already-ready status; removing after-ready loses the regular route control. Removing scope distinction loses the original bug; removing default/browser coordinator loses its real workaround. Baseline zero proves no stored rows are needed; baseline one challenges source precedence. Distinct and repeated keys distinguish count/order from final membership; delete and truncate distinguish absence from stale rows; row/collection metadata and empty transactions distinguish zero mutations from zero obligations. Atomic batches check transaction granularity. Failure ordinal distinguishes preserved prefix from abandoned suffix; pre-abort distinguishes abandonment from failure of independent work. Tail, second on-demand scope and reopen distinguish current adapter loans, later ordinary use and durable storage. Bounds are 0/1 baseline, 1–3 transactions per core template, 0–3 edits per transaction, 0/1 independently pre-aborted transaction, and storage failure at ordinal 0/1. Browser rich history has six transactions plus its ordinary tail. No random-run confidence is used to extend these bounds.
The laws still have meaningful open compositions. They are retained with owners in the coverage map, not hidden by the green calibration:
| File | SHA-256 |
|---|---|
| packages/db-sqlite-persistence-core/tests/persisted-oracle.test.ts | 08ba69cdb4bcad7fa1c683d080ac3c51e75642caccf137864c87ca13ac8f17fe |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.ts | 200fd6fb5edd99a000acbb92b7e67b79b4949978953e0de8efbefd4efb2360bd |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit-oracle.opfs.spec.ts | 48a5b85740c4e7a282ba7fdda53b076c44ac36bda6d2b06e9820554440e8003d |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.html | 28b99007a046019cc8466eb5d51561a55ab2c975d94bb98880e3f09b0f762058 |
| packages/browser-db-sqlite-persistence/playwright.opfs.config.ts | d596da20036070bc4fded9829517aa8c2e69844061d7ac66c4b2233871c184cd |
Change weight against origin/main: production 0 lines; tests/fixtures/config +1705 / −220 (net +1485); documentation +559 / −0 (net +559). The larger test diff includes formatting around two existing witnesses; no production machinery was added.
The user approved the call-local adapter repair and PR preparation after the RED audit above. The unpublished branch advanced to current origin/main, a37e69ab6aa35fd6a2a72d727de2b5168d10b1a0, before retaining the repair. That base adds Temporal persistence coverage. Its new dependency required linking an already cached temporal-polyfill into this worktree's ignored dependencies. The initial missing-import run collected no tests and is setup evidence only. No package manifest or lockfile change belongs to this repair.
SingleProcessCoordinator.requestApplyCommittedTx now accepts the interface's existing optional scopedAdapter and selects it for that call. Ordinary work continues to use the registered adapter. The coordinator does not retain the loan. This changes two production lines and removes one, for a net addition of one line. Test and contract-documentation growth is separate from that budget.
The current implementation preserves the existing hydration completion, acceptance/publication, FIFO, failure and scheduler contracts. It does not add recovery state, bypass unrelated scheduled work, or replace the default coordinator. The earlier RED-stage statements remain historical evidence.
| Initial repair execution on the advanced base | Result | Reached evidence |
|---|---|---|
| Original core implementation | 48 failed, 566 passed, 1 existing todo | Routing assertions, with no timeout or setup failures |
| Retained repair, complete persisted oracle | 614 passed, 1 existing todo | All existing and added comparisons |
| Original implementation, real Chromium OPFS | 8 failed, 17 passed | Same-transaction scheduled reentry/cycle assertions |
| Retained repair, real Chromium OPFS | 25 passed | All histories and cleanup-failure calibration |
| Eight independent hostile repairs | All rejected by assertions | Early receipt 88, cached scope 36, dropped metadata 48, ignored truncate 24, dropped rows 148, reverse FIFO 48, swallowed failure 24, generic error 24 |
| TypeScript | Core package and focused browser oracle passed | No type errors |
| ESLint | 0 errors, 22 existing warnings | Existing require-await warnings only |
| Formatting and whitespace | Passed | Changed executable files and diff |
The hostile repairs ran separately on the retained repair, and the exact repaired production file was restored in finally. None failed during setup, timed out, remained unreached, or survived. The counts refer to the 149 focused checks. Browser GREEN uses the same local source paths as RED. Cached tooling from another checkout supplies dependencies only, never the production build.
Executable SHA-256 bindings at the initial repair stage (superseded below):
| File | SHA-256 |
|---|---|
| packages/db-sqlite-persistence-core/src/persisted.ts | 84ad4e2e5c8c071c44f72dcff007a220484d2a9530a5a0db033efd49b0c03bd4 |
| packages/db-sqlite-persistence-core/tests/persisted-oracle.test.ts | 7c8fe3aeb32afb66303392c2b79762cf005790cab91c455d64634ba82b9b7845 |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.ts | 200fd6fb5edd99a000acbb92b7e67b79b4949978953e0de8efbefd4efb2360bd |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit-oracle.opfs.spec.ts | 48a5b85740c4e7a282ba7fdda53b076c44ac36bda6d2b06e9820554440e8003d |
Current Vitest commands add --pool=threads --pool-options.threads.maxThreads=2 --pool-options.threads.minThreads=1 to the commands above. Current browser verification uses --timeout=15000. Logs and raw prep-pr reviews are under /private/tmp/issue-2046-prep-pr/; this record preserves the verdict-critical results without requiring those temporary files.
This entry updates the original R1–R9 ledger without rewriting its historical verdicts. R1, R2, R3, R4 and R9 are fixed-now within the declared source hydration grammar and Chromium receiving path. R5, R6 and R7 retain the approved existing behavior and executable controls: accepted-design. R8 remains confirmed-open only for historical release attribution. The causal source change and current repair are established, but the earliest published affected version still needs a package bisect. Totals: nine raw items = five fixed-now + three accepted-design + one confirmed-open.
The scoped routing defect is repaired. The broader scoped lifecycle, fairness backlog, elected-owner/host handoff and historical-version witnesses listed in the coverage map remain separate open evidence. These bounded results do not establish universal liveness or every persistence composition.
The simplifier returned no proposals. Five parallel review angles checked repository instructions, obvious bugs, history, prior PR decisions and code comments. Their raw reports preserve 25 source-specific candidates, including rejected hypotheses and all nine historical review findings. No reviewer found an introduced production defect. The parent evaluated every candidate without a severity cap: one fixed-now, ten already-fixed, twelve refuted and two duplicates. The task-local append-only evaluation ledger retains the full raw claims, sources, judgments and independent cleanup score. No candidate was silently filtered or deferred. The reviewers traced the existing contracts and distinguished introduced defects from historical diagnostic limitations.
Two independent reviewers identified the same preexisting diagnostic weakness in the strengthened optimistic causal witness. Direct cleanup in finally could replace its primary error. The parent injected two sentinel failures in that actual witness: the original form reported only the cleanup error. The existing cleanupPersistedOracle helper retained the primary error and logged the separate cleanup error. Both calibration runs reached their intended error assertions without timeout. The retained test uses the helper and contains no sentinel injection. This is oracle diagnostic hardening, not another production bug or proof of a native cleanup failure. The helper's permanent calibration continues to exercise primary and cleanup diagnostics.
After this seven-line test increase, the complete persisted oracle again passed 614 tests with one existing todo. Core TypeScript and lint passed with the same 22 warnings, and the file remains formatted. Its final SHA-256 is 7156c39e8b657367aeea5491065b5836beecfeecc1f1855e344f5a4fcec36f15. The other executable hashes above remain unchanged. The eight hostile runs preceded this diagnostic-only edit and exercised the unchanged 149-case suite. Direct FIFO replay on the new base passed three checks, skipped 596, and kept one existing todo. The repair and browser fixture remained unchanged for the 25-check browser GREEN receipt.
Two review qualifications remain explicit. Exact owning-scope exit is observed for the held startup/subscription histories. The after-ready control does not establish a universal readiness-versus-scope-exit ordering. Browser reopen here creates a new Collection over retained persistence, not a physical browser or worker restart. Native failures and process restart keep their separate owners.
These commands use tracked package scripts and configurations. Run them from the repository root with the repository's supported Node.js and pnpm versions. Install dependencies and build the core package with its workspace dependencies:
pnpm install --frozen-lockfile
pnpm --filter '@tanstack/db-sqlite-persistence-core...' buildRun the complete persisted oracle through its repository Vitest configuration, with at most two workers. Coverage and integrated typechecking are disabled for this focused runtime invocation, as in the historical source-alias run:
pnpm --filter @tanstack/db-sqlite-persistence-core exec vitest run --config vite.config.ts tests/persisted-oracle.test.ts --coverage.enabled=false --typecheck.enabled=false --pool=threads --pool-options.threads.maxThreads=2 --pool-options.threads.minThreads=1
pnpm --filter @tanstack/db-sqlite-persistence-core exec tsc --noEmit -p tsconfig.jsonFor only the finite routing matrix, add -t 'hydration source durability routing' to the Vitest command. To replay the existing FIFO property, prefix that same command with TANSTACK_DB_ORACLE_PROPERTY=sqlite-persistence.source-fifo-order TANSTACK_DB_ORACLE_SEED=2046 TANSTACK_DB_ORACLE_PATH=0.
Install Chromium and run the real OPFS receiver. The explicit browser channel selects the installed Playwright Chromium instead of requiring local Chrome:
pnpm --filter @tanstack/browser-db-sqlite-persistence exec playwright install --with-deps chromium
PLAYWRIGHT_CHANNEL=chromium pnpm --filter @tanstack/browser-db-sqlite-persistence exec playwright test --config playwright.opfs.config.ts hydration-commit-oracle.opfs.spec.ts --reporter=line --timeout=15000The browser Vite configuration aliases the workspace source packages. These commands need no node_modules/.cache/issue-2046 configuration or /private/tmp project. The temporary paths elsewhere in this record identify historical session artifacts only. The reported historical counts belong to their stated source/dependency revisions, not to an unexecuted clean installation. The PR's CI separately runs the tracked package and OPFS configurations.
The documentation follow-up for CodeRabbit review 5431163123 distinguishes these reproducible entry points from the original session commands and removes nontechnical personnel commentary. No executable file, oracle law, assertion, or recorded runtime result changed.
This follow-up evaluates all ten items from a source-only review of 90cbda1e5, against the later documentation head 996292b31. The review found no introduced production bug. Its useful findings concern the coordinator contract, historical documentation, and oracle integrity. The runtime repair remains unchanged; this follow-up adds six lines of interface JSDoc, with no new production state, branch, fallback, or coordinator replacement.
The interface now states that wrappers must forward a supplied leader-local adapter and must not retain or serialize it. A forwarding wrapper and a loan-dropping wrapper reach the actual default coordinator and produce opposite routing observations. An explicit-adapter control also shows that this call can succeed without a registered fallback; a later ordinary call must reject before an apply until that fallback is registered. Collection construction supplies that registration. This records the existing optional-adapter design, rather than adding a new configuration restriction.
The controlled routing probe now tracks each callback's lifetime independently. Three calibration histories cover nested callbacks and overlapping callbacks with either exit order. Each distinguishes a live loan, an expired loan, reentry through the public adapter, and ordinary work after all callbacks exit. These histories describe the controlled adapter. They do not claim that the real SQLite scheduler permits overlapping hydrate callbacks.
The eight rejected-buffer histories, request-local failed-read/retry witness, and optimistic causal-replay witness each run with no scope API, a same-adapter scope, and a distinct loan. Their existing exact failure, durability, public row, acceptance, and applied-receipt comparisons are preserved. Adding a scope probe no longer substitutes for either original adapter path.
The OPFS receiver now observes both contenders at their actual scheduling entry points before taking the held-read snapshot. It continues observing peer hydrate and regular callback entry, and C's commit SQL, until A's owning callback exits. A positive count requires the C SQL observer to be reached exactly once, so a changed query cannot silently disable that comparison. Election stream-position reads deliberately bypass logical scheduling and are outside this regular-work law; treating all peer SQL as forbidden would impose a false contract. The default coordinator's tail must enter public apply; the browser coordinator's tail must enter its regular scope. Rich subscription histories join the follow-up hydrations triggered by truncate before issuing that ordinary tail. Final rows alone cannot establish correct tail routing.
Scope identity is now a callback invocation token, not a reusable adapter object or singleton active value. The actual held SELECT requires exactly one owning callback and publishes a diagnostic immediately if that premise is missing. Sixteen startup/subscription histories assert owning-scope exit. Eight after-ready controls report no held scope (null); their useful receipt, row, schema and reopen checks remain. Those controls do not prove a universal readiness-versus-scope-exit ordering.
All runs used this worktree's source with the historical cached tooling explained above. The fresh-checkout entry points remain the tracked commands in the previous section. Temporary mutations were restored byte-for-byte. The missing-owner injection below is a deliberate harness fault, not evidence of reachable overlapping callbacks in the real host.
| Check | Result and meaning |
|---|---|
| Original scope-dropping behavior with strengthened core oracle | 50 assertion failures, 590 passes, 1 existing todo; no setup or timeout failure |
| Retained repair, complete core oracle | 640 passes, 1 existing todo |
| Original scope-dropping behavior, strengthened Chromium receiver | 8 cycle assertion failures, 17 passes; no setup or timeout failure |
| Retained repair, complete Chromium receiver | 25 passes |
| Callback-lifetime calibration against old probe | 3 assertion failures; all 3 pass with independent lifetime tracking |
| Cached-loan mutation | Old browser receiver: 25 passes. Strengthened receiver: 8 tail-route assertion failures, 17 passes |
| Ordinary scheduling bypass mutation | Old receiver: all 4 selected held-read histories pass. Strengthened receiver: all 4 fail at whole-callback peer exclusion, without timeout |
| Missing no-scope failure identity | 4 restored rejection histories fail exact-reason assertions; 20 other rejection histories pass |
| Missing owning-callback identity injection | Old harness waits until its 15-second test timeout with no observation. New harness reaches an immediate missing-owner diagnostic and assertion failure; no timeout |
| Types and static checks | Core and focused browser TypeScript pass; ESLint has 0 errors and the same 22 existing warnings; executable formatting and diff whitespace pass |
The original eight hostile-repair counts earlier in this record remain bound to their earlier executable revision. The new runs establish sensitivity for the newly strengthened boundaries; they do not retroactively relabel those historical runs as executions of this revision.
All ten review items retain separate dispositions in the task-local lossless ledger: eight fixed-now (contract prose, documentation clarity, scope probe, adapter-mode coverage, tail routing, owner diagnostics, causal preemption checks, and after-ready coverage credit), one already-fixed (personnel commentary, removed in 996292b31), and one accepted-design (explicit adapter versus registered ordinary fallback). Some claims needed qualification: the historical hashes were stage-specific and the final reviewed hashes matched; after-ready histories were not wholly vacuous; and real public A callbacks are serialized, so the hypothesized existing overlap timeout was not reproduced as product behavior. The deliberate lost-owner fault established the diagnostic weakness.
There is no deferred repair from these ten findings and no new runtime defect. The scope remains finite: the primary routing grammar, the restored failure and replay paths, and one Chromium OPFS host. Arbitrary custom coordinator wrappers must obey the stated contract; this suite cannot enforce third-party code. The separately recorded scoped lifecycle, fairness backlog, host/election handoff, native failure, and historical release-attribution gaps remain in the coverage map. A Collection reopen here is not a process or worker restart.
Current executable SHA-256 bindings for this follow-up:
| File | SHA-256 |
|---|---|
| packages/db-sqlite-persistence-core/src/persisted.ts | d319f74a1020f6fd96db5cd5cb995c42a7809c105b423abdc6da25ba2d1fb070 |
| packages/db-sqlite-persistence-core/tests/persisted-oracle.test.ts | f3939fc3cdc81580398b7ff8a07737a5745dfb0da458b85af02585eaacdce89a |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit.opfs.ts | a0044df64bbe8281a53150b2698b97a25f796d3cfae707f7eb5220dfd682bb68 |
| packages/browser-db-sqlite-persistence/e2e/hydration-commit-oracle.opfs.spec.ts | 6e7936824e92fb4f0adb2f7da5650ff5aaf9d2d10ecb8c8833b0947529f8271e |