Skip to content

Fix clean writer takeover after empty epochs - #774

Merged
flyingrobots merged 2 commits into
mainfrom
fix/empty-writer-epoch-continuity
Oct 8, 2026
Merged

flyingrobots merged 2 commits into
mainfrom
fix/empty-writer-epoch-continuity

Conversation

@flyingrobots

Copy link
Copy Markdown
Owner

Fresh filesystem takeover advanced an empty predecessor's unused LSN, creating a gap, and could admit a new epoch over an unreconciled tail. This preserves the unused coordinate, requires a clean recovered tail before ledger changes, and refuses committed-LSN overflow with a typed error.

Closes #773. Extracted from #716/#727. Independently correct on main; queued after #772 in the agreed landing sequence. Process-descriptor lease redesign (#718) remains outside scope.

Docker evidence on parent 2d79ecc: expected LSN 0 versus actual 1; expected dirty-tail refusal versus successful admission. After the fix, formatting and the full WAL hardening suite passed: 126 passed, one existing ignored. Fixtures verify live-lease exclusion, distinct successor identity, dirty-tail refusal, writable reconciliation, committed append and clean reopen. No physical power-loss claim.

Documentation: canonical WAL topic and changelog updated. Takeover can now require explicit writable recovery before retry. Raw logs, source manifests and guarded resource receipts retained. No host tests ran.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 32 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: flyingrobots/echo/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 188ff7cd-a8f1-4056-9f5d-a31bef1e2c9f
📥 Commits

Reviewing files that changed from the base of the PR and between c144123 and 2652c63.

📒 Files selected for processing (4)
  • CHANGELOG.md
  • crates/warp-core/src/causal_wal.rs
  • crates/warp-core/tests/causal_wal_hardening_tests.rs
  • docs/topics/WAL.md
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer audit, exact head c7893ce:

Item Severity Source Commit Validation Outcome
Empty epoch skips unused LSN P2 #716/current source c7893ce Docker RED expected 0 versus actual 1; GREEN overlap/takeover and suite Fixed
Takeover admits unreconciled tail P2 #727/current source c7893ce Docker RED expected refusal versus successful admission; GREEN writable recovery, append and reopen Fixed
Committed final-LSN overflow P2 Source audit c7893ce Checked successor derivation returns typed chain-gap refusal; inspected only at overflow boundary Corrected

Full four-file diff audited against current main: shared request validation, fresh takeover lease acquisition/reload, tail recovery, predecessor closure/rollback, successor identity, typed recovery-index errors, commit append and recovery paths. No WAL format change or physical power-loss guarantee. Existing descriptor inheritance work #718 remains out of scope. Full hardening suite: 126 passed, one existing ignored; Docker formatting passed. Initial snapshot had no review threads. Independent agy review and current CI remain pending; merge gate is not yet open. @codex

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Adversarial Independent Review: PR #774 (flyingrobots/echo)


Executive Summary & Verdict

PR #774 resolves a core causal continuity defect in Echo's write-ahead log:

  1. Unused LSN Preservation: When an active writer epoch terminates or drops without committing any transactions (final_lsn == None), successor takeover preserves the unused starting LSN coordinate rather than advancing it by 1, eliminating an artificial LSN gap in the log chain.
  2. Clean-Tail Validation Under Lease: Prior to altering the persisted epoch ledger, closing an unclosed predecessor epoch, or admitting a successor epoch, takeover acquires the filesystem writer lease and performs a read-only recovery scan across segments. If an uncommitted frame, torn record, or trailing garbage is detected, takeover immediately refuses with WalStoreError::SegmentHasUncommittedTail without mutating on-disk ledger state.
  3. Committed-LSN Overflow Refusal: If a predecessor's final_lsn reaches u64::MAX, successor derivation now refuses with WalStoreError::WriterEpochChainGap via checked arithmetic (checked_next()) rather than silently wrapping or resetting to minimum_started_at_lsn.
  4. Typed Error Mapping: Recovery index construction errors encountered during pre-takeover tail inspection are explicitly mapped to a new enum variant WalStoreError::RecoveryIndex(#[from] WalRecoveryIndexError).
  5. Ledger Reload Parity: validate_writer_epoch_request now permits request.started_at_lsn == previous_epoch.started_at_lsn when previous_closure.final_lsn is None, ensuring that stored ledgers containing empty predecessor epochs pass deserialization validation upon recovery.

Verdict: APPROVE


Findings & Observations

[P4] Architectural Separation Between High-Level Takeover and Low-Level Raw Port Acquisition

  • File:Line: crates/warp-core/src/causal_wal.rs:5742-5751 vs crates/warp-core/src/causal_wal.rs:5980-6007
  • Concrete Scenario:
    FilesystemWalStore::acquire_fresh_writer_epoch (the production takeover path used by TrustedRuntimeHost::acquire_runtime_writer_epoch) executes read-only recovery and verifies matches!(recovery.tail_posture, RecoveryTailPosture::Clean). In contrast, the trait method WalStorePort::acquire_writer_epoch on FilesystemWalStore validates ledger continuity and acquires the writer lock, but does not perform a segment scan for uncommitted tails.
  • Evidence:
    WalStorePort::acquire_writer_epoch accepts an externally pre-constructed WriterEpochRequest. Calling acquire_writer_epoch directly bypasses recover_filesystem_store tail checks.
  • Evaluation:
    This is an acceptable architectural separation of concerns: WalStorePort represents the primitive store interface for raw admission, while acquire_fresh_writer_epoch owns the lifecycle protocol for host takeover and predecessor reconciliation. In production, TrustedRuntimeHost delegates exclusively to acquire_fresh_writer_epoch.
  • Suggested Fix (Follow-on / Non-blocking):
    Document on WalStorePort::acquire_writer_epoch that caller-synthesized requests do not validate segment tail cleanliness, and that callers recovering a filesystem store must use acquire_fresh_writer_epoch or run explicit recovery before raw epoch admission.

[P5] Coverage Limitation: Synthetic Fixture for Saturated Lsn::MAX

  • File:Line: crates/warp-core/src/causal_wal.rs:5777-5780
  • Concrete Scenario:
    The fix changes .and_then(Lsn::checked_next).unwrap_or(minimum_started_at_lsn) to final_lsn.checked_next().ok_or(WalStoreError::WriterEpochChainGap)?. If a ledger records final_lsn == Lsn::MAX (u64::MAX), checked_next() yields None and returns Err(WalStoreError::WriterEpochChainGap). Because writing u64::MAX transactions in integration tests is infeasible, this error path is verified through static reasoning and type-level checked arithmetic rather than an executable integration fixture.
  • Suggested Fix (Follow-on / Non-blocking):
    Add a focused unit test in causal_wal_tests.rs with a handcrafted in-memory WriterEpochLedger where final_lsn == Lsn::from_raw(u64::MAX) to assert WalStoreError::WriterEpochChainGap.

Execution Boundaries & Coverage Limitations

  • Checks Statically Inspected & Verified:
    • 100% of the 4-file git diff between 2d79ecc4 and c7893cea (CHANGELOG.md, crates/warp-core/src/causal_wal.rs, crates/warp-core/tests/causal_wal_hardening_tests.rs, docs/topics/WAL.md).
    • Git commit object tree, parent pointers, author/committer timestamps, and commit signatures.
    • Callers and call-graph routes in warp-core (causal_wal.rs, trusted_runtime_host.rs, tests).
    • Both RED logs, launch manifests, resource telemetry, and exit codes.
    • All four GREEN logs, launch configurations, test outputs, and resource telemetry.
    • Repository SPDX headers, documentation paragraphs (one physical line per paragraph), and formatting whitespace (git diff --check).
  • Inspected Only (Evidence from Worker Runs):
    • Docker container execution logs: retained evidence: landing-epoch-{red,tail-red,green4}.log.
    • Resource receipts and launch specifications: landing-epoch-{red,tail-red,green4}.{launch,result}.json.
    • Source manifest SHA-256 bindings: landing-epoch-{red,tail-red,green4}.manifest.json.
  • Intentionally Skipped / Unavailable:
    • Host test execution and Docker daemon execution (forbidden by read-only audit constraint).
    • Physical power loss / unbuffered disk crash injection (explicitly declared out of scope; existing suite verifies process termination and uncommitted frame recovery).
    • Hardware power-loss durability is not inferred from green suite passes.

Runtime Path Trace (File:Line on Both Sides)

Code Path / Behavior Production Implementation Parallel / Comparative Path Audit Assessment
Lease Acquisition on Takeover causal_wal.rs:5740
acquire_writer_epoch_lock(&self.root)?
causal_wal.rs:5987
acquire_writer_epoch_lock(&self.root)? in WalStorePort
Identical file lock semantics (WriterEpochLock using flock). Prevents concurrent live writers from taking over.
Ledger Reload Under Lease causal_wal.rs:5741
self.reload_writer_epoch_ledger()?
causal_wal.rs:5990
self.reload_writer_epoch_ledger()?
Identical. Rereads persisted epoch ledger before inspecting or closing active epochs.
Tail Cleanliness Gate causal_wal.rs:5742-5751
recover_filesystem_store(..., ReadOnly)
matches!(..., RecoveryTailPosture::Clean)
N/A in WalStorePort
(Enforced in high-level takeover only)
Refuses with WalStoreError::SegmentHasUncommittedTail before modifying active epoch, closure map, or on-disk ledger.
Recovery Error Mapping causal_wal.rs:5743-5747
Maps Store, Validation, and Index variants
causal_wal.rs:10062-10072
WalRecoveryError definition
Exhaustive 1:1 typed mapping. Maps WalRecoveryIndexError to new WalStoreError::RecoveryIndex.
Predecessor Closure Handling causal_wal.rs:5753-5768
Closes leftover active epoch under lease
causal_wal.rs:8281-8316
Deserialization recovery of ledger
Leftover active epoch is appended to closed_epochs, ledger persisted, rolled back on failure.
Successor LSN Derivation causal_wal.rs:5776-5781
match previous_closure.final_lsn:
- Some(final_lsn) => final_lsn.checked_next()?
- None => previous_epoch.map_or(...)
Base 2d79ecc4 causal_wal.rs:5764-5768:
incremented even when final_lsn was None
Eliminates unused LSN advancement for empty epochs; refuses overflow on checked_next() returning None.
Successor Epoch Request Synthesis causal_wal.rs:5788-5828
Derives deterministic epoch evidence
N/A (unique to filesystem store) Increments ordinal (closed_len + 1), ensuring unique epoch_id, fencing_token, and lease_or_lock_evidence even when LSN is reused.
Epoch Request Validation causal_wal.rs:5829-5834
calls validate_writer_epoch_request
causal_wal.rs:2019 (InMemoryWalStore)
causal_wal.rs:5992 (FilesystemWalStore)
causal_wal.rs:8287, 8306 (Ledger decode)
causal_wal.rs:1586-1591 relaxed from <= previous_epoch.started_at_lsn to < previous_epoch.started_at_lsn. Permitted in memory, filesystem, and during deserialization.
Production Runtime Integration trusted_runtime_host.rs:3432
store.acquire_fresh_writer_epoch(next_lsn)
trusted_runtime_host.rs:2508
Called during TrustedRuntimeHost::open after store.recover_for_writer()?
When TrustedRuntimeHost opens, recover_for_writer reconciles unreconciled tails first, then acquire_fresh_writer_epoch succeeds cleanly. Direct takeover without recovery refuses dirty tails.

Merges & Integration Audit

  1. Commit Topology:
    • Merge Base: 2d79ecc4f08181e0d2c8829b09335567373fbd9b (HEAD of origin/main).
    • PR Head: c7893cea27a54028b06b6ce7b84e4564dce64931.
    • Number of commits: Exactly 1.
    • Merge commits in branch history: 0 (confirmed via git log --merges 2d79ecc4..c7893cea).
  2. Semantic Diff Inspection:

Constants & Numeric Evidence Verification

Claim / Constant Location in PR / Docs Raw Evidence Coordinate Verification Result
RED 1 LSN Mismatch: expected 0, got 1 PR #774 body, line 5 retained evidence: landing-epoch-red.log:16-18 Verified Exact:
thread panicked at causal_wal_hardening_tests.rs:967:5
left: Lsn(1), right: Lsn(0)
RED 2 Dirty Tail Admission Mismatch PR #774 body, line 5 retained evidence: landing-epoch-tail-red.log:12-13 Verified Exact:
thread panicked at causal_wal_hardening_tests.rs:89:22
expected Err(..), got Ok(WriterEpoch { started_at_lsn: Lsn(1) ... })
Parent Commit SHA 2d79ecc4 PR #774 body, line 5 landing-epoch-red.log:1
landing-epoch-tail-red.log:1
landing-epoch-green4.log:1
Verified Exact:
SOURCE_VERIFIED 2d79ecc4f08181e0d2c8829b09335567373fbd9b 991
GREEN Hardening Suite: 126 passed, 1 ignored PR #774 body, line 5 retained evidence: landing-epoch-green4.log:149 Verified Exact:
test result: ok. 126 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out
Existing Ignored Test Identity PR #774 body, line 5 retained evidence: landing-epoch-green4.log:33 Verified Exact:
test emit_filesystem_writer_epoch_process_step ... ignored, child entrypoint exercised by the independent-process writer-epoch test
Formatting Gate Passed PR #774 body, line 5 retained evidence: landing-epoch-green4.log:1-5 Verified Exact:
cargo fmt --all -- --check exited cleanly before test run
Intermediate Failures Resolved Landing log trail landing-epoch-green.log:6 (trailing newline)
landing-epoch-green2.log:6-10 (line wrap)
landing-epoch-green3.log:3-7 (missing WalStoreError::RecoveryIndex)
Verified Exact:
All intermediate formatting and compiler errors were resolved in green4.
Host Build Cache Usage landing-epoch-green4.result.json:3 13,384,397,914 bytes (~12.46 GiB) Verified Within Bound:
Budget <= 21,474,836,480 bytes (20 GiB)
Host Test Data Usage landing-epoch-green4.result.json:4 4,281,693,274 bytes (~3.988 GiB) Verified Within Bound:
Budget <= 4,294,967,296 bytes (4 GiB)
Log Output Usage landing-epoch-green4.result.json:5 19,741,973 bytes (~18.83 MiB) Verified Within Bound:
Budget <= 134,217,728 bytes (128 MiB)
Free Storage Floors landing-epoch-green4.result.json:6-7 Host: 719,326,203,904 B (~670 GiB)
VM: 683,667,574,784 B (~636 GiB)
Verified Within Bound:
Both floors well above required 50 GiB floor
Worker Process Constraints landing-epoch-green4.launch.json:25-26,34 CPUs: 4.0, Memory: 6 GiB, Timeout: 1100s Verified Exact:
Matches project resource bounds

State Machine & Error Transition Analysis

  1. Takeover Over Dirty / Torn Tail:
    • Under lease, recover_filesystem_store scans segments in ReadOnly mode.
    • Any uncommitted frames or torn records cause tail_posture to become WouldTruncateAfter(lsn) or WouldTruncateAll.
    • !matches!(recovery.tail_posture, RecoveryTailPosture::Clean) fires and returns Err(WalStoreError::SegmentHasUncommittedTail(self.segment_id)).
    • Zero state mutation occurs. The lease is dropped on error.
  2. Successor After Empty Epoch:
    • Active predecessor epoch is recovered and closed.
    • previous_closure.final_lsn is None.
    • required_started_at_lsn resolves to previous_epoch.started_at_lsn.
    • started_at_lsn = minimum_started_at_lsn.max(previous_epoch.started_at_lsn).
    • validate_writer_epoch_request admits request.started_at_lsn == previous_epoch.started_at_lsn.
    • Successor receives incremented ordinal, yielding fresh cryptographic evidence tokens (epoch_id, storage_fencing_token, lease_or_lock_evidence).
    • Distinct identities prevent fencing collision despite LSN reuse.
  3. Successor After Committed Epoch:
    • previous_closure.final_lsn is Some(final_lsn).
    • required_started_at_lsn resolves to final_lsn.checked_next().ok_or(WalStoreError::WriterEpochChainGap)?.
    • If final_lsn == u64::MAX, refused immediately.
    • If normal LSN, successor must strictly start at or after final_lsn + 1.
  4. Crash During Takeover Writing:
    • If persist_writer_epoch_ledger fails when closing the previous epoch, in-memory state is restored via self.install_writer_epoch_ledger(previous_ledger).
    • If persist_writer_epoch_ledger fails when recording the new active epoch, state is restored via self.install_writer_epoch_ledger(closed_ledger) and self.active_epoch is cleared.
    • Atomic replacement via temporary file and rename preserves on-disk ledger integrity.

Repository Standards & AGENTS.md Conformance

  • Documentation Standards (docs/DOCUMENTATION_STANDARDS.md):
    • Canonical ownership respected: docs/topics/WAL.md:374 owns the WAL takeover contract.
    • Paragraph formatting: docs/topics/WAL.md:374 and CHANGELOG.md:18 are authored as one physical line per paragraph.
    • License Headers: Valid SPDX identifiers present in all four modified files.
    • Git Discipline: 0 amend commits, 0 rebases, 0 force-pushes, 0 merge commits. Standard linear commit on branch.
  • Out-of-Scope Integrity:

Mandatory Verification Checklist


APPROVE

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent Codex review of PR #774, exact head 2652c63e74e3f6f8a7003f0d903b83644ce167b5, targeting main c144123559d8f9ac1368e929695e815f6ecbc075.

No verified blocking defects found. Approval is limited to this writer-takeover correction and its integration with the previously approved snapshot-root change.

Verification Checklist

  • Entire PR diff inspected: Four files: causal_wal.rs, its hardening integration tests, docs/topics/WAL.md, and CHANGELOG.md. Empty predecessors permit equality with their unused starting LSN; committed predecessors still require a strictly later coordinate.
  • Production takeover path traced: trusted_runtime_host.rs:2490–2508 recovers its writer store, derives its cursor and acquires an epoch through trusted_runtime_host.rs:3417–3432; filesystem dispatch reaches causal_wal.rs:5733–5843. Takeover acquires the lease, reloads the ledger, checks read-only recovery posture, closes the predecessor, derives and validates a successor, persists it, and retains the lease.
  • Parallel validation paths inspected: Shared validate_writer_epoch_request at causal_wal.rs:1555–1611 serves in-memory acquisition (:2019), fresh filesystem takeover (:5829), explicit raw-port acquisition (:5992), and ledger decoding (:8287, :8306). All consistently permit an empty predecessor’s unused start while checking predecessor identity, final digest and distinct fencing evidence. Raw-port acquisition does not automatically close a predecessor or perform fresh takeover; its different behavior is intentional, rather than a second implementation of automatic takeover.
  • Recovery paths inspected: causal_wal.rs:6160–6196 combines validated frame/commit recovery with torn-tail posture. :8579–8652 checks frame integrity and continuity and distinguishes clean tails from writable/read-only truncation postures. Fresh takeover refuses every non-clean posture before persisting predecessor closure. The regression covers uncommitted frames; a new dedicated torn-tail takeover fixture was not supplied.
  • Append and lease paths inspected: causal_wal.rs:5857–5874, :5878–5938, and :6010–6044 retain transaction integrity, writer-lease and epoch checks. WriterEpochLock acquisition/drop at :8476–8500 releases the local acquired lease on early-return paths. The inherited-descriptor redesign in Make OS lease guards prove process-bound release across inherited descriptors #718 remains outside scope.
  • Errors and state transitions inspected: Recovery Store, Validation, and Index errors map to corresponding typed store errors at :5742–5747; the added transparent RecoveryIndex variant preserves the underlying error rather than converting it to misleading success. Closure persistence failure restores the previous in-memory ledger; successor persistence failure restores the closed ledger. Atomic ledger publication at :8408–8424 uses write, file sync, rename and directory sync. Failures after a rename can leave a newer durable ledger, so these receipts do not establish rollback of every disk side effect; retry reloads persisted state under the lease.
  • Overflow inspected: causal_wal.rs:5776–5781 uses checked_next() and refuses a saturated committed LSN with WriterEpochChainGap. This boundary was statically inspected, not exercised by a new saturated-LSN fixture. Empty predecessor selection does not increment an unused coordinate. Minimum-coordinate selection remains explicit and unchanged.
  • Merge audited against both parents: Merge 2652c63e74e3f6f8a7003f0d903b83644ce167b5 has parents c7893cea27a54028b06b6ce7b84e4564dce64931 and c144123559d8f9ac1368e929695e815f6ecbc075. Against the writer-fix parent, it adds only the incoming snapshot correction, its two witnesses, canonical Merkle documentation, and changelog entry. Against main, it contains only the four-file writer correction. Both changelog entries survive. Snapshot domain separation at snapshot_accum.rs:813 remains present; the integration does not alter WAL or snapshot semantics beyond those independent corrections.
  • Source-hash evidence inspected: The integrated manifest identifies exact head 2652c63e…, reports a clean checkout, and the log records SOURCE_VERIFIED … 991. Independently computed SHA-256 values match the manifest for all four PR files and the incoming snapshot_accum.rs and docs/spec/merkle-commit.md. Key matches: causal_wal.rs 05fdb18682c6d1e8c205fbb140ce2b7ffa851663dd1583e4d852591189bb27fd; hardening tests 28b8e287b18bf881152a29d55c730606985475387aeafe390b1ce882425f0e88.
  • RED/GREEN numeric claims inspected: landing-epoch-red.log shows expected LSN 0 versus actual 1 on parent 2d79ecc4…. landing-epoch-tail-red.log shows expected refusal versus successful dirty-tail admission on that same parent. landing-epoch-integrated.log:149 reports 126 passed, zero failed, one ignored; :171 reports 14 snapshot accumulator tests passed, zero failed. Formatting precedes both tests in the launch command; the integrated result has exit code zero. The ignored test is an existing subprocess entrypoint, not a newly ignored regression.
  • Resource numbers inspected: Integrated result records build 13,491,472,092 bytes below the 21,474,836,480 limit; data 4,272,338,652 below 4,294,967,296; logs 20,968,560 below 134,217,728. Host and VM free-space receipts exceed the 50 GiB floor. Launch specifies four CPUs, 6 GiB memory, 1,100-second timeout and a fail-closed monitored runner. These are inspected runner receipts, not independently repeated resource measurements.
  • Documentation and numeric scope checked: WAL.md:374 accurately states the new fresh-takeover ordering, empty-coordinate reuse, committed-coordinate advancement and overflow refusal. CHANGELOG.md:18 accurately describes the correction. Incoming Merkle documentation retains the existing v1 domain and explicitly disclaims migration of previously incorrect roots. No new throughput, latency, physical power-loss or production-adoption claim appears in the changed documentation.
  • Current GitHub state inspected: Fresh API inspection confirms the exact head/base above, MERGEABLE/CLEAN, all returned CI checks successful, zero review threads, zero formal reviews, and no additional pages in threads, reviews or global comments. All five conversation comments were inspected; prior approval concerns an older head and was treated as background, not current acceptance. Provider quota notices do not constitute reviews.
  • Repository standards: Clean worktree confirmed. Canonical documentation ownership and changelog updates are respected; no new ADR, backlog or unrelated architectural changes. Existing license headers remain intact. Read-only authorization prohibited fetching or mutating shared refs, so the skill’s usual fetch step was replaced by direct live GitHub head/base verification.

Execution boundary: I executed only static source/Git/hash inspection and GitHub API reads. I did not run tests, Docker, scripts, builds, publish comments, edit files or acquire shared workers. Test results above are inspected execution evidence. They do not prove physical power-loss durability or absence of every regression. The parent must recheck head, CI and repository protections immediately before merging.

Exact-head verdict for 2652c63e74e3f6f8a7003f0d903b83644ce167b5:

APPROVE

@flyingrobots
flyingrobots merged commit 1589743 into main Oct 8, 2026
42 checks passed
@flyingrobots
flyingrobots deleted the fix/empty-writer-epoch-continuity branch October 8, 2026 05:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Preserve unused LSN continuity during clean writer takeover

1 participant