Skip to content

fix(reporting): timestamp revisions at trusted publication time - #1207

Merged
bokelley merged 1 commit into
mainfrom
conductor/fix-reporting-publication-timestamp
Sep 25, 2026
Merged

bokelley merged 1 commit into
mainfrom
conductor/fix-reporting-publication-timestamp

Conversation

@bokelley

Copy link
Copy Markdown
Contributor

A conforming reporting source can observe official finality after worker dispatch. The producer previously reused dispatch time as revision created_at, producing finalized_at > created_at and a correct buyer rejection with FINALITY_EVIDENCE_INVALID.

The producer now samples its trusted publication clock after successful acquisition and staged-row verification, and uses that sample for revision creation. A clock that regresses behind dispatch, or source evidence outside the publication bounds, raises actionable PUBLICATION_TIME_INVALID before immutable revision/row publication. Replaying an existing publication preserves its original creation time and supersession parent while still reconstructing and validating the supplied immutable content.

The existing acquire_obligation(now=...) argument remains the dispatch/read-cutoff instant. The existing commit_revision_from_manifest(now=...) override is a trusted publication instant; if omitted, that method samples the producer clock. Replay retains the original committed timestamp instead of replacing it with the new sample. The change preserves source observation, finality and watermarks, rather than backdating them or deriving a future creation time with max(source_time, now). Buyer validation remains unchanged and no caller knob is added.

This is the separate PY-FINALITY-001 child: head 26151fc50ef4f3e24308f6cef1304b8faf8603d0, tree 7dabb6ec23be43ca450c769aefcf88a9d94eb853, sole parent dba15b6b0dd8063d38c2df4196491ae64d9720ae. The six-file delta is +623/-11; production changes are confined to reporting/ledger/producer.py.

Validation and retained failures:

  • Own exact, unmodified dba15 parent source reproduced the required-correct red: focused controls recorded 8 failures / 1 pass / 9 PostgreSQL deselections. A separate actual typed MCP/PostgreSQL source-parent case also failed the local buyer reconciliation assertion with FINALITY_EVIDENCE_INVALID after materialization; that assertion is not a wire error body or installed-parent result. These originals remain distinct from earlier 1f953/b203 observations and runtime r3 starvation isolation.
  • Source-development controls passed: 22 focused cases, 249 affected memory/PostgreSQL cases, and two real typed production/restart cases. Controls cover observation after dispatch, historical/equality positives, delayed staged reads, future evidence and regressing clocks with no corrupt immutable write, explicit dispatch versus direct-commit time, source temporal negatives, and official/snapshot replay including supersession and content identity. Three development mutations were caught: early clock sampling (3 failures), missing time bounds (3 failures), and new creation time on replay (2 failures). The executable AST is unchanged between that mutation source and the frozen producer; the later delta only clarifies the clock contract in a docstring. This is a source comparison, not a claim that those mutations were rerun on the frozen head.
  • Frozen full source coverage: 10,975 passed, 2,101 skipped, 9 deselected, 1 xfailed. PostgreSQL drivers are absent by design in this coverage lane. Before/after identities are clean and exact. Lint, typing, generated validation and unchanged changed-file/commit hooks pass. This child retains inherited B110; its separately reviewed hygiene sibling is not included.
  • Four fresh installed cells passed 162 tests each, with zero failures or skips: VCS/sdist-built wheels on CPython 3.10.21 with Pydantic 2.13.0/MCP 2.0.0 and 2.13.5/2.2.0. The installed supervisor ended successfully at 17:05:35 UTC on September 22, 2026.
  • Each installed cell exercises fully typed onboarding from empty state through the actual production service on separate MCP HTTP and PostgreSQL 16.14, pool size 1. USD503/EUR3 exact reads return 6/1 pages, independently recomputed content digests match, receipts are accepted, and reconciliation is definitive. Source observations occur after dispatch and before revision creation with default real clocks. The same installed artifact is restarted; selected revision/evidence, receipt, digest and materialization remain unchanged, with no repeated receipt submission. This is not a cross-build restart claim.
  • All 16 owned receiver processes were reaped with shutdown markers and closed destination sessions. Each installed database had zero remaining sessions before removal; scratch environments were removed, and the finality-only PostgreSQL cluster was stopped and removed. Raw wire and source-observation streams are retained.

Inherited evidence and acceptance limits remain explicit:

  • The runtime parent's original Python 3.10.21 functional supervisor remains exit 1, 17 passing / 2 failing groups, including receipt 6/8 and feed 7/9. Separate complete configured Python 3.12.14 receipt 8/8 and feed 9/9 passes qualify their named unchanged workflow lanes only. They do not waive the old declared Python >=3.10 support limitation, establish one cause for every original failure, or rewrite the original supervisor.
  • The historical B22 snapshot decoder's bare timestamp parsing on Python 3.10 is separate from this producer publication-time defect. Current installed floor controls and the separate Python 3.10 B23/hardening activation/continuation proof do not establish universal old-decoder support.
  • PR fix(reporting): restore late-account materializer progress #1206's exact dba15 source/concurrency and independent installed public floor MCP/PG/restart reviews are accepted in those bounded scopes. They satisfy the parent review prerequisite for this leaf; they do not confer aggregate acceptance or finality approval. The independent reviewer's own build and results remain separate from the owner artifacts below.
  • Inherited dispatch B110 remains on this child. Approved fe1a1cbd / fix(decisioning): preserve sanitized validation fallback #1204 fixes it in a separate sibling, without suppression or retroactive green. Revocation fix(signing): classify revocation checker trust failures #1205 is also separate. Fresh aggregate hooks and main checks remain required.
  • The deferred initial artifact-build command, earlier package-queue failure, private runner metadata correction, and earlier setup diagnostics remain at their original exits. Exact source artifacts and completed installed outcomes below do not overwrite those records. Controlled-clock negatives remain separate from real-clock HTTP/PG cases.

Selected existing artifacts built from this frozen source (candidate metadata adcp==8.0.0b15, not the published registry beta15):

Artifact SHA-256
VCS wheel 556cf3eabad08149e9584a19906d60e420bc31b4e3ee89960d3eddd2055d5ab4
sdist-built wheel 47df47adf61eee6699b24db2fa8a39a5132c3203ee5c53aa91a7fdb6c721fe6f
source archive 26fdc0e703345dc3d9252d87197604db1346b4cffddcd584efb8e03afa1e3ad9

The two wheels have identical 7,813 member paths and bytes, with distinct ZIP hashes. Exact file URLs, directly rehashed original archives and installed origins/module hashes bind every cell; optional installer archive-hash metadata is additional evidence. The earlier runner metadata setup failure and bounded runner correction remain separate originals. Standalone metadata predates reviewed main #1190; final integration must retain and recheck the supported 2.13.0/2.0.0 floor. No Pydantic 2.12 acceptance is claimed.

Original records and streams under .context/py-finality-001-20260922/:

  • source-parent-required-correct.json, focused-parent-publication-red/, public-parent-red-result.json, frozen-runtime-source-public-red/ retain the exact-parent failures and original commands.
  • final-focused-publication-before-freeze/, affected-memory-pg-publication-r1/, public-real-clock-source-r1/, mutation-results.json, mutations/ and mutation-to-frozen-source-comparison.json retain source-development controls and their identities.
  • completed-local-installed-disposition.json, frozen-source-coverage-result.json, frozen-full-source-coverage/, artifacts/, installed-publication-r2/ and completed-postgres-cleanup.json retain frozen-source, selected archive, installed command/output, wire/observation, replay and cleanup evidence.

This draft targets the exact runtime branch at dba15 as a source-review leaf. Its ordinary scheduled checks are reported as observed; no full SDK CI is inferred for an excluded base, and no check transfers from #1203. Finality source acceptance, approved ancestry-preserving integration, main #1190 metadata and fresh floor verification, TS rc.45 / #1199, aggregate/main/security checks, #1182 and release decisions remain separate. No integration, package release, settings/workflow action or pin promotion is authorized by this source publication.

Base automatically changed from conductor/fix-reporting-late-account-progress to main September 25, 2026 12:40
@bokelley
bokelley merged commit 3f4ae61 into main Sep 25, 2026
4 checks passed
@bokelley
bokelley deleted the conductor/fix-reporting-publication-timestamp branch September 25, 2026 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant