Skip to content

D-GSO-8: seal boundary (P8) - #1363

Merged
AdaWorldAPI merged 1 commit into
mainfrom
claude/gso-8
Oct 6, 2026
Merged

AdaWorldAPI merged 1 commit into
mainfrom
claude/gso-8

Conversation

@AdaWorldAPI

@AdaWorldAPI AdaWorldAPI commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

What

P8 of .claude/plans/2026-10-06-global-sudoku-replayable-orchestration-v1.md: run many internal operations without durable materialization, seal only at one declared semantic boundary, and show that replay from the prior seal reproduces the next seal (§15, §18 P8).

crates/lance-graph-planner/examples/seal_boundary_probe.rs (planner tests already run in CI), no library code changes.

  • Internal events change only working rows; nothing durable is written.
  • A declared Boundary event seals the rows changed since the last seal with the shipped persist_sink::DetachedCycleBatch::freeze. The seal goes into a local ledger as cycle, base version and frozen batch.
  • A boundary with nothing changed writes nothing. This matches the "no artifact-backed change → no write" rule.
  • Replay: replaying the persisted events from each prior seal reproduces the next seal exactly: frame, landings, coalesced image and batch_hash.

Demo run: 1000 internal operations produce 4 seals of 5 landings each, and the last seal replays exactly.

The tie limit

The plan names this limit: freeze sorts stably, so equal stream_positions keep their arrival order, and arrival order is not durable. Of the three options in the plan, this probe takes option 1: the stream key is the event's own durable, globally unique sequence number, and a batch with a tied key is refused rather than sealed. A test shows on the real freeze that tied keys make both the coalesced image and the hash depend on arrival order, which is why the refusal is needed.

Scope limits

  • The ledger is local. No WalSink is driven, so publication, fencing and recovery are not exercised.
  • One boundary kind. Which semantic events earn a boundary (§15 lists several) is not decided.
  • The internal operation is a stand-in fold.

Tests (6) and disable runs (5, all red)

  • only a boundary writes (999 internal events → empty ledger, then exactly one seal) — D1: an internal op seals
  • an unchanged boundary writes nothing — D2: seal even when nothing changed
  • replay from each prior seal reproduces the next, for 8 seals in a row — D4: resume ignores the prior seal's image
  • the seal binds its base, content and order: a wrong base, a dropped event or a swapped order each change it
  • unique keys make the seal independent of arrival order
  • tied keys make the seal depend on arrival order on the real freeze, and the probe refuses them — D3: tie check removed; D5: key not the durable seq

Board

STATUS_BOARD: D-GSO-8 In PR; D-GSO-7 Shipped (#1360); the D-GSO-6 follow-up marked Shipped (#1362). The branch is rebased on main including #1361 and #1362.

🤖 Generated with Claude Code

https://claude.ai/code/session_01DgxrCafsJuAahpBs7oC14R


Generated by Claude Code

Summary by CodeRabbit

  • Tests
    • Added validation for replay consistency, seal-boundary behavior, unchanged data, and ordering cases.
    • Added checks that ambiguous tied keys are refused rather than producing an uncertain result.

Internal events change only working rows and never write durably. A
declared Boundary event seals the rows changed since the last seal with
the shipped persist_sink::DetachedCycleBatch::freeze into a local ledger
(cycle, base version, frozen batch); a boundary with nothing changed
writes nothing. Replaying the persisted events from each prior seal
reproduces the next seal exactly: frame, landings, coalesced image and
batch_hash. A wrong base, a dropped event and a swapped order on one row
each change the seal.

Tie limit (plan §18 P8, option 1): the stream key is the event's own
durable, globally unique sequence number, and a batch with a tied key is
refused instead of sealed. A test shows on the real freeze that tied keys
make the coalesced image and the hash depend on arrival order.

Not exercised: WalSink publication, fencing and recovery (the ledger is
local); which semantic events earn a boundary; the internal operation is
a stand-in fold.

6 tests, 5 disable runs red. Board: D-GSO-8 In PR; D-GSO-7 Shipped
(#1360); the D-GSO-6 follow-up marked Shipped (#1362).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DgxrCafsJuAahpBs7oC14R
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 48bc979b-37a3-4931-ae09-a75fc14cd4e4
📥 Commits

Reviewing files that changed from the base of the PR and between 8744ac7 and c615d18.

📒 Files selected for processing (3)
  • .claude/board/STATUS_BOARD.md
  • crates/lance-graph-planner/Cargo.toml
  • crates/lance-graph-planner/examples/seal_boundary_probe.rs
 __________________________________________________________________
< Engage! Making your code boldly go where no one has gone before. >
 ------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Comment @coderabbitai help to get the list of available commands.

@cursor

cursor Bot commented Oct 6, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: 0a6e1f69-c273-4644-8b3b-2b0d5b1356a2)

@AdaWorldAPI
AdaWorldAPI marked this pull request as ready for review October 6, 2026 12:22
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T12:25:11.555929Z c615d18 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c615d182ad

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +153 to +154
if let Some(k) = first_tie(&casts) {
return Err(SealError::TiedKey(k));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate event sequence uniqueness before row coalescing

When two Internal events reuse a seq on the same row, or reuse one across separate seals, casts() has already reduced them to one slot in the current batch, so first_tie returns None and the seal is accepted. This violates the probe's globally unique durable-key precondition: replay cannot recover the live arrival order for those events from the duplicated key and may produce a different next seal. Track and reject duplicate event sequence numbers across the engine lifetime before folding or row coalescing.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed: uniqueness was stated but never checked, and both reuse cases got past first_tie. #1363 merged before the fix landed, so it is in a follow-up PR on claude/gso-8-seq. apply now refuses a seq that is not greater than the last one accepted, and resume_after restores the highest persisted key. The new test a_reused_seq_is_refused covers a reuse on the same row, a reuse across seals and a reuse after a resume, and was verified with disable runs.


Generated by Claude Code

@AdaWorldAPI
AdaWorldAPI merged commit e718a0f into main Oct 6, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants