Notes restart: establish a new epoch before requiring legacy refusal #600

Open
opened 2026-10-01 08:13:07 +00:00 by kayg · 1 comment
Owner

#427 follow-up. Compare production cc25c441b and merged a6fd7f704 with the original restart.mjs: 10/10 passes on each build. This report is not reproduced on either build. restart.mjs, calternal-collab and the Notes provider are byte-identical across those heads. The old report has no preserved response/epoch witness, so these results do not prove its incident was harmless.

Confirmed pre-existing probe defect: the crash cut point follows a fixed 4 s sleep rather than an observed Markdown write. An in-process regression now demonstrates that a crash before the write keeps the matching cached epoch and replays a pending edit exactly once, even when its update is applied twice. No timer or process kill is used by that regression. #427 now waits for the actual save before the crash and retains the original integrity assertions.

Severity: test reliability defect confirmed; potential data-integrity incident remains unreproduced. There is no evidence here that round 4 makes production worse. Keep this issue open if the original raw evidence can be recovered; reproduce against that exact fixture before changing the product contract.

Original label: restart 2 legacy. If disk still matches the stored cache, the room restores the same epoch and its original lineage. The old probe had not established that the room started a new epoch.

#427 follow-up. Compare production cc25c441b and merged a6fd7f704 with the original restart.mjs: 10/10 passes on each build. This report is not reproduced on either build. restart.mjs, calternal-collab and the Notes provider are byte-identical across those heads. The old report has no preserved response/epoch witness, so these results do not prove its incident was harmless. Confirmed pre-existing probe defect: the crash cut point follows a fixed 4 s sleep rather than an observed Markdown write. An in-process regression now demonstrates that a crash before the write keeps the matching cached epoch and replays a pending edit exactly once, even when its update is applied twice. No timer or process kill is used by that regression. #427 now waits for the actual save before the crash and retains the original integrity assertions. Severity: test reliability defect confirmed; potential data-integrity incident remains unreproduced. There is no evidence here that round 4 makes production worse. Keep this issue open if the original raw evidence can be recovered; reproduce against that exact fixture before changing the product contract. Original label: restart 2 legacy. If disk still matches the stored cache, the room restores the same epoch and its original lineage. The old probe had not established that the room started a new epoch.
Author
Owner

Already fixed: origin/dev contains f64643562, Observe the Note save before testing a crash epoch. In tests/adversarial/restart.mjs:189-193, the probe writes a marker and waits until the Note body contains it before the crash checks. This removes a crash precondition based only on a fixed sleep. The original integrity event remains unconfirmed because no response or epoch witness is preserved. #597-#600 repeat this probe finding with different original labels; recommend linking them and keeping one follow-up only for recovery or reproduction of the original evidence. Do not close this issue as part of the audit.

Already fixed: origin/dev contains f64643562, Observe the Note save before testing a crash epoch. In tests/adversarial/restart.mjs:189-193, the probe writes a marker and waits until the Note body contains it before the crash checks. This removes a crash precondition based only on a fixed sleep. The original integrity event remains unconfirmed because no response or epoch witness is preserved. #597-#600 repeat this probe finding with different original labels; recommend linking them and keeping one follow-up only for recovery or reproduction of the original evidence. Do not close this issue as part of the audit.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#600
No description provided.