Skip to content

Prove Bounty COMMIT rollback and all honor round context boundaries - #188

Merged
LIghtJUNction merged 5 commits into
mainfrom
work/bounty-honor-commit-boundaries-20260929
Sep 30, 2026
Merged

LIghtJUNction merged 5 commits into
mainfrom
work/bounty-honor-commit-boundaries-20260929

Conversation

@LIghtJUNction

Copy link
Copy Markdown
Contributor

Refs #72, #77. Depends on #187; merge serially after that installed-package restore fix passes.

Inject a real deferred PostgreSQL constraint trigger at Bounty COMMIT after the claim/transfer/receipt/Event/Inbox/result facts are prepared. Compare values in every public business table after rejection, retry the exact request, and prove one payment/notice with an unchanged committed replay.

Exercise each honor round R1–R5 with a wrong nonce, question digest and inclusive deadline, then verify durable failure, evidence removal and explicit restart. Verify a foreign subject cannot consume the owner's final challenge, and two concurrent final requests produce exactly one grant/audit with an unchanged winning request replay. Independent nonces are checked at every transition.

These are disposable real-PostgreSQL application/signature tests; no production money/Root or honor claim is made. Final full node-ID gate, quality and installed package checks must pass before merge. The umbrella issues retain their remaining design/field acceptance scope.

Copilot AI balanced review requested due to automatic review settings September 29, 2026 23:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-29T23:26:31.123697Z 6d4843d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@LIghtJUNction
LIghtJUNction merged commit c8ed261 into main Sep 30, 2026
19 checks passed

Copy link
Copy Markdown
Contributor Author

已按 expected head 串行合并 #187、#188,当前 main c8ed2610ab774dba3085972683c1d2c8a9232222,实际 tree 89f8e4119e625cb421b75be468392b2d7b187930 与本 PR 验收 tree 一致。#187 merge c5c1f61f242d1b9818f582f92d1b2ffc0805288c 的 tree bc0c07151c9fe43cd595e2d026ff1e170226cc74 亦与其已验 tree 一致。

独立下载并核对最终头 7aacc278cf26e8660a8fb7a4ca953cd6f32fd44e 的全部 10 份 ZIP SHA-256;八个 shard manifest/JUnit 构成 2569 core 精确 node-ID 完整互斥并集,另 8 conformance,零 failure/error/skipped,未以计数代替集合校验。Rewrite 36644965337。

Quality 36644965239:Python 3.15.0rc2、Ruff 0.16.9、uv 0.12.20;零 lint 诊断、stderr 空、588 文件 format、warnings-as-error compile 通过。

Deployment 36644965142:同一 wheel 的 server 安装检查 12 项、真实 OpenSSH/PAM/StrictModes 7 项、installed official selftest 42 项均通过;client-only 安装不含服务端实现。核心构建与部署演练的 wheel/sdist 逐字节一致,产物内全部 release-sha256.txt 已按实际文件校验:

  • wheel: 658fc637298399a786baf6e4b5820a16847aa303c0b920ead2c76a7756e80d9a
  • sdist: 9625897c020c21f26b91550fba5ae948ef953717ea228c4c270b27e9b1b22f2d
  • server-dependencies.lock: 646e39420ec9748e3c44185005365b32a7fa81021c3e10b2873c8ac0330c57ef
  • client-dependencies.lock: dc6f6422620b810166640e03d72d62facf6733f48275e8e8a08925eb825504c4

候选交付产物。真实 PG+Git/CAS 全表 values/sequence、SIGKILL 重启、备份到空 PG 恢复、删除 marker 后仍持久隔离均已在演练核对;promotion=false。CI 环境 4 CPU 的测量仅属有界隔离演练:启动1.4292s,32次写入6.5149s/4.9118req/s,32次读取19.2719s/1.6604req/s,RSS/HWM81292KiB,重启1.3049s,备份1.6874s,恢复3.1091s。不是生产容量或现场恢复证据。

独立 main push 当前 4 项已 success,Rewrite 仍排队;最终主线门槛尚待该运行完成及产物核对。#72/#77 这里只增加明确事务/上下文负例,完整条款还须逐项审计;现场材料见 #84,未执行生产部署、资金、Root、真实外发或恢复放行。

Copy link
Copy Markdown
Contributor Author

合并后独立 main 验收现已完成:source c8ed2610ab774dba3085972683c1d2c8a9232222 / tree 89f8e4119e625cb421b75be468392b2d7b187930。Rewrite36683776551 的8个 shard和contracts job实际全部success;八份ZIP摘要独立核验,manifest/JUnit精确node-ID完整互斥并集 2569 core + 8 conformance,无failure/error/skipped。质量、部署、Recovery safety、Issue recovery的独立主线门槛均已通过,共5个适用工作流。

已独立核对质量36683776303和部署36683776308 ZIP摘要/source/实际报告;588文件格式、零Ruff诊断/stderr,Python3.15.0rc2。核心构建wheel/sdist与部署产物一致;所有release摘要正确,wheel/sdist/server/client锁四文件与已验#188逐字节一致。主线交付包。

独立主线安装演练:server12项、真实OpenSSH7项、official selftest42项全部通过;client-only无服务端实现。4CPU临时CI环境测量:启动1.1885s;32写入6.5881s/4.8572req/s;32读取15.1822s/2.1077req/s;RSS/HWM81180KiB;SIGKILL重启1.0437s;备份1.5109s、空PG恢复3.1388s。全表values/sequence守恒,删marker仍持久quarantine,promotion=false。这些是该run的有界隔离结果,不是目标机容量或已部署。

新增#189/#190已进入审查;#191是后续#72具体断言收口,#192是对#189的独立当前授权/只读回归。各自最终组合须重验。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants