Skip to content

Implement durable authenticated reads bound to a fenced snapshot (KEEP-RECONSTRUCT-009, -010) #109

Description

@flyingrobots

Problem

docs/invariants/authenticated-reconstruction/requirements.md rows KEEP-RECONSTRUCT-009 and -010 are planned gaps that cite #22 and #23, both of which closed on the Echo side. No Keep issue owns them. The durable segment, catalog, publication, and recovery surfaces do not yet form one BlobId-to-writer read contract: a read must bind to one admitted immutable snapshot, keep its evidence from being collected during the read, verify the retained closure, resolve exact immutable records, preserve the view while successors publish, and return a receipt naming the view, with refusal distinct from operational failure and no hidden whole-blob allocation.

Scope

  • DurableStore::{open, snapshot, contains_blob, reconstruct, reconstruct_layout, read_range} composing the reader fence (PR Retention recovery, crash-matrix evidence, reader fence, and model-based transitions (item 6) #99), catalog lookup, segment record reads, layout admission, and the existing reconstruction core.
  • DurableReconstructionReceipt extending ReconstructionReceipt with catalog generation and digest and liveness generation and manifest digest.
  • The Golden File Worldline restart and range assertions run against the durable backend.

Acceptance criteria

  • Every ReferenceStore read law has a durable twin.
  • Segment unreadable is an operational failure; layout naming a chunk the catalog lacks is an evidenced refusal.
  • Reads during publication and during a blocked GC observe one view.
  • KEEP-RECONSTRUCT-009 and -010 Implemented; README "Try it" gains a Linux-only durable example.

Roadmap: F-23 / T-23.1 in ROADMAP.md. Depends on PR #99 (reader fence); the "evidence cannot be collected" law holds vacuously until #21 lands. Refs #20 #22 #23.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions