WI-3 (#830): compaction observers → revoke + D4 same-PID generation auto-revoke #842

Merged
jason.woltje merged 4 commits from feat/830-compaction-revoke into main 2026-07-19 19:46:29 +00:00
Owner

WI-3 (#830) — compaction observers → REVOKE + D4 same-PID generation auto-revoke

closes #830

Reviewed head (PINNED): f400830738998db105107a2a4c69c7f2a2a6fd5d — pushed == CI'd == merged SHA. No rebase/amend; any head move invalidates the review-of-record (Gate-16).

Scope (D2-v5)

Compaction observers now REVOKE (not just observe) + D4 same-PID generation-bump auto-revoke. Touches revoke-lease / lease_generation / mutator-gate; runtime hooks (claude settings, pi lease-lifecycle, mosaic-extension, claudex); acceptance + pi-compaction-lifecycle specs; docs. Includes route-(i) amendment (disclosure + one backstop test). Rebased onto de-flaked #838 main (shared broker-test-client.ts).

Verdicts (review-of-record: docs reviews/WI3-830-RoR-f4008307.md, author≠reviewer)

  • CODE = APPROVE (pi-terra, lane ms-rev-828, exact-head @ f4008307): 1409/1409 tests + root 43/43 green; D2/D4 revoke correctness; #838 rebase integrity; backstop test genuinely exercises the catch.
  • SECURITY = APPROVED (claude-Opus, lane ms-secrev-828, independent construct+run @ f4008307, ≠ amendment author).

Gate0 probe-3 admission — VALIDATED

The D4 generation-revoke mechanism was validated by the Gate0 probe-3 focused harness (sha 92ff11bd) under a fail-closed fire gate: 3/3 isolation runs machine_assertions=PASS; mechanism executed (same-PID/starttime, reload-revoke-verified, generations 1→12 monotonic); invariants MUTATOR_UNVERIFIED / STALE_GENERATION held; no assertion softened, no path escape. Classified 3/3 PASS (not Case-C).

## WI-3 (#830) — compaction observers → REVOKE + D4 same-PID generation auto-revoke closes #830 **Reviewed head (PINNED): `f400830738998db105107a2a4c69c7f2a2a6fd5d`** — pushed == CI'd == merged SHA. No rebase/amend; any head move invalidates the review-of-record (Gate-16). ### Scope (D2-v5) Compaction observers now REVOKE (not just observe) + D4 same-PID generation-bump auto-revoke. Touches revoke-lease / lease_generation / mutator-gate; runtime hooks (claude settings, pi lease-lifecycle, mosaic-extension, claudex); acceptance + pi-compaction-lifecycle specs; docs. Includes route-(i) amendment (disclosure + one backstop test). Rebased onto de-flaked #838 main (shared broker-test-client.ts). ### Verdicts (review-of-record: docs reviews/WI3-830-RoR-f4008307.md, author≠reviewer) - **CODE = APPROVE** (pi-terra, lane ms-rev-828, exact-head @ f4008307): 1409/1409 tests + root 43/43 green; D2/D4 revoke correctness; #838 rebase integrity; backstop test genuinely exercises the catch. - **SECURITY = APPROVED** (claude-Opus, lane ms-secrev-828, independent construct+run @ f4008307, ≠ amendment author). ### Gate0 probe-3 admission — VALIDATED The D4 generation-revoke mechanism was validated by the Gate0 probe-3 focused harness (sha `92ff11bd`) under a fail-closed fire gate: 3/3 isolation runs machine_assertions=PASS; mechanism executed (same-PID/starttime, reload-revoke-verified, generations 1→12 monotonic); invariants MUTATOR_UNVERIFIED / STALE_GENERATION held; no assertion softened, no path escape. Classified 3/3 PASS (not Case-C).
jason.woltje added 4 commits 2026-07-19 19:37:13 +00:00
jason.woltje merged commit e4d7d4502d into main 2026-07-19 19:46:29 +00:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaicstack/stack#842