fix(reporting): timestamp revisions at trusted publication time - #1207
Merged
Merged
Conversation
This was referenced Sep 23, 2026
Base automatically changed from
conductor/fix-reporting-late-account-progress
to
main
September 25, 2026 12:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A conforming reporting source can observe official finality after worker dispatch. The producer previously reused dispatch time as revision
created_at, producingfinalized_at > created_atand a correct buyer rejection withFINALITY_EVIDENCE_INVALID.The producer now samples its trusted publication clock after successful acquisition and staged-row verification, and uses that sample for revision creation. A clock that regresses behind dispatch, or source evidence outside the publication bounds, raises actionable
PUBLICATION_TIME_INVALIDbefore immutable revision/row publication. Replaying an existing publication preserves its original creation time and supersession parent while still reconstructing and validating the supplied immutable content.The existing
acquire_obligation(now=...)argument remains the dispatch/read-cutoff instant. The existingcommit_revision_from_manifest(now=...)override is a trusted publication instant; if omitted, that method samples the producer clock. Replay retains the original committed timestamp instead of replacing it with the new sample. The change preserves source observation, finality and watermarks, rather than backdating them or deriving a future creation time withmax(source_time, now). Buyer validation remains unchanged and no caller knob is added.This is the separate PY-FINALITY-001 child: head
26151fc50ef4f3e24308f6cef1304b8faf8603d0, tree7dabb6ec23be43ca450c769aefcf88a9d94eb853, sole parentdba15b6b0dd8063d38c2df4196491ae64d9720ae. The six-file delta is +623/-11; production changes are confined toreporting/ledger/producer.py.Validation and retained failures:
FINALITY_EVIDENCE_INVALIDafter materialization; that assertion is not a wire error body or installed-parent result. These originals remain distinct from earlier 1f953/b203 observations and runtime r3 starvation isolation.Inherited evidence and acceptance limits remain explicit:
fe1a1cbd/ fix(decisioning): preserve sanitized validation fallback #1204 fixes it in a separate sibling, without suppression or retroactive green. Revocation fix(signing): classify revocation checker trust failures #1205 is also separate. Fresh aggregate hooks and main checks remain required.Selected existing artifacts built from this frozen source (candidate metadata
adcp==8.0.0b15, not the published registry beta15):556cf3eabad08149e9584a19906d60e420bc31b4e3ee89960d3eddd2055d5ab447df47adf61eee6699b24db2fa8a39a5132c3203ee5c53aa91a7fdb6c721fe6f26fdc0e703345dc3d9252d87197604db1346b4cffddcd584efb8e03afa1e3ad9The two wheels have identical 7,813 member paths and bytes, with distinct ZIP hashes. Exact file URLs, directly rehashed original archives and installed origins/module hashes bind every cell; optional installer archive-hash metadata is additional evidence. The earlier runner metadata setup failure and bounded runner correction remain separate originals. Standalone metadata predates reviewed main #1190; final integration must retain and recheck the supported 2.13.0/2.0.0 floor. No Pydantic 2.12 acceptance is claimed.
Original records and streams under
.context/py-finality-001-20260922/:source-parent-required-correct.json,focused-parent-publication-red/,public-parent-red-result.json,frozen-runtime-source-public-red/retain the exact-parent failures and original commands.final-focused-publication-before-freeze/,affected-memory-pg-publication-r1/,public-real-clock-source-r1/,mutation-results.json,mutations/andmutation-to-frozen-source-comparison.jsonretain source-development controls and their identities.completed-local-installed-disposition.json,frozen-source-coverage-result.json,frozen-full-source-coverage/,artifacts/,installed-publication-r2/andcompleted-postgres-cleanup.jsonretain frozen-source, selected archive, installed command/output, wire/observation, replay and cleanup evidence.This draft targets the exact runtime branch at dba15 as a source-review leaf. Its ordinary scheduled checks are reported as observed; no full SDK CI is inferred for an excluded base, and no check transfers from #1203. Finality source acceptance, approved ancestry-preserving integration, main #1190 metadata and fresh floor verification, TS rc.45 / #1199, aggregate/main/security checks, #1182 and release decisions remain separate. No integration, package release, settings/workflow action or pin promotion is authorized by this source publication.