You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
docs/invariants/authenticated-reconstruction/requirements.md rows KEEP-RECONSTRUCT-009 and -010 are planned gaps that cite #22 and #23, both of which closed on the Echo side. No Keep issue owns them. The durable segment, catalog, publication, and recovery surfaces do not yet form one BlobId-to-writer read contract: a read must bind to one admitted immutable snapshot, keep its evidence from being collected during the read, verify the retained closure, resolve exact immutable records, preserve the view while successors publish, and return a receipt naming the view, with refusal distinct from operational failure and no hidden whole-blob allocation.
DurableReconstructionReceipt extending ReconstructionReceipt with catalog generation and digest and liveness generation and manifest digest.
The Golden File Worldline restart and range assertions run against the durable backend.
Acceptance criteria
Every ReferenceStore read law has a durable twin.
Segment unreadable is an operational failure; layout naming a chunk the catalog lacks is an evidenced refusal.
Reads during publication and during a blocked GC observe one view.
KEEP-RECONSTRUCT-009 and -010 Implemented; README "Try it" gains a Linux-only durable example.
Roadmap: F-23 / T-23.1 in ROADMAP.md. Depends on PR #99 (reader fence); the "evidence cannot be collected" law holds vacuously until #21 lands. Refs #20#22#23.
Problem
docs/invariants/authenticated-reconstruction/requirements.mdrowsKEEP-RECONSTRUCT-009and-010are planned gaps that cite #22 and #23, both of which closed on the Echo side. No Keep issue owns them. The durable segment, catalog, publication, and recovery surfaces do not yet form oneBlobId-to-writer read contract: a read must bind to one admitted immutable snapshot, keep its evidence from being collected during the read, verify the retained closure, resolve exact immutable records, preserve the view while successors publish, and return a receipt naming the view, with refusal distinct from operational failure and no hidden whole-blob allocation.Scope
DurableStore::{open, snapshot, contains_blob, reconstruct, reconstruct_layout, read_range}composing the reader fence (PR Retention recovery, crash-matrix evidence, reader fence, and model-based transitions (item 6) #99), catalog lookup, segment record reads, layout admission, and the existing reconstruction core.DurableReconstructionReceiptextendingReconstructionReceiptwith catalog generation and digest and liveness generation and manifest digest.Acceptance criteria
ReferenceStoreread law has a durable twin.KEEP-RECONSTRUCT-009and-010Implemented; README "Try it" gains a Linux-only durable example.Roadmap: F-23 / T-23.1 in
ROADMAP.md. Depends on PR #99 (reader fence); the "evidence cannot be collected" law holds vacuously until #21 lands. Refs #20 #22 #23.🤖 Generated with Claude Code