fix(tournaments): make arena deadlines cluster-authoritative - #91
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Summary by QodoMake Arena deadlines authoritative across replicas
AI Description
Diagram
High-Level Assessment
Files changed (26)
|
Code Review by Qodo
1.
|
|
|
/review Please review exact HEAD e866eac. Corrections include database membership fairness, malformed recovery projection, bounded planner, cancellation, spectator reads, sanitized errors, postcommit semantics and accurate mutation attribution. Please explicitly report Bugs, Rule violations, requirement gaps and any actionable findings, including nonblocking ones. No reviewer gate is presumed satisfied by the prior-head result. |
|
@greptileai review Please perform a fresh review of exact HEAD e866eac. Both prior findings are fixed and explained in their threads. Please verify the database-owned allocation membership boundary with adversarial middle-ID arrivals and SIGTERM raw restoration. Report all blocking/nonblocking actionable findings and the exact reviewed SHA. |
|
Code review by qodo was updated up to the latest commit e866eac |
|
Want your agent to iterate on Greptile's feedback? Try greploops. |
|
/review Review NEW exact HEAD35c91fe893e1a677a6328a7dd1345d9c8627ee51. The three published findings are fixed with RED/GREEN: participant/player-state corruption immediate SQL repair; positive-safe duration route/service validation; inactive-game repair diagnostics. A fourth confirmed linked identical-seat pairing gap is also corrected structurally (safe Number-compatible sequence, supported namespace, participant seats, duplicate simultaneous players). Fresh local315 scripts/4003 hermetic/206 persistence/106 API/86 Linuxgateway/2 backup and35 compiling killed mutants,0 survivors. Please explicitly report Bugs, Rule violations, requirement gaps and all blocking/nonblocking actionable findings on THIS SHA; prior e866eac review is stale. Scope/invariants are in ADR0156 and current active pairing/local validation/mutation audits. Do not presume approval from earlier head. |
|
@greptileai review Please review NEW exact HEAD35c91fe893e1a677a6328a7dd1345d9c8627ee51, including the full Arena implementation and four corrections. Inspect SQL/restore active-pairing equivalence, guarded casts, identical/duplicate seats, valid linked versus pending behavior, participant corruption, safe duration, sanitized repair diagnostics, membership fairness/restart/concurrency, deadline T boundary and durable recovery. Fresh complete positive gates and35 valid behavioral mutation kills are documented. Report exact reviewed SHA and every blocking or nonblocking actionable finding. Earlier e866eac evidence is stale. PR must remain open/unmerged. |
|
/ask On exact PR HEAD35c91fe893e1a677a6328a7dd1345d9c8627ee51, independently compare the implementation against ADR0156 and the acceptance requirements in PROJECT_STATE Increment89 and the current active-pairing audit. Are there ANY actionable requirement gaps, rule violations, bugs or nonblocking actionable findings remaining? Explicitly report the reviewed SHA, requirement-gap count, actionable-finding count, Bugs count and Rule violations count, with concrete file/line evidence for any nonzero count. Check database-only clock authority, T-1/T boundary, finite membership under repeated middle-ID arrivals, restart/concurrency, no duplicate launch/results, immediate repair for malformed participants/linked pairings, valid linked/unlinked behavior, positive safe duration without new product policy, migration backfill and drain rollout, shutdown cancellation and accurate35-mutation evidence. Do not infer requirement gaps=0 merely from Bugs=0 or historical resolved threads; evaluate the current implementation. No code edits or merge requested. |
|
Code review by qodo was updated up to the latest commit 35c91fe |
|
Confirmed on exact HEAD35c91fe893e1a677a6328a7dd1345d9c8627ee51 with one isolated real-PostgreSQL RED, without source changes: raw JSONB points1.00000000000000001 is returned exactly as text, parsed as JS1; ArenaTournament.restore accepts the running future idle Arena. Projection nevertheless has invalid=true/pending=false/deadlineNULL, and work discovery includes it. Assertion expected invalid=false and failed; disposable database cleaned before assertion. This is a distinct participant-counter numeric-equivalence defect outside the owner's approved fourth active-pairing structural correction. Acceptance is STOPPED; no fifth fix or extra push, no dismissal/resolution of this thread. Required next scoped work is guarded Number-compatible counter conversion and JS-arithmetic consistency plus focused legacy JSONB RED/GREEN, followed by invalidated validation/mutations/exact-head PR gates. Current PR must remain OPEN/unmerged. |
|
/review |
|
@greptileai review the new exact final head 44bf25c. Prior exact-head evidence is invalidated. Include all six corrections, legacy JS-number parity and canonical deadline arithmetic, recovery/fairness, migration/backfill and recorded diagnosis/mutation evidence; report all blocking and non-blocking actionable findings. |
|
/ask On exact head 44bf25c, compare the complete Arena deadline implementation with PR requirements and docs/adr/0156-arena-deadline-authority.md. Independently report requirement gaps and actionable findings counts (zero only if supported), separate from Bugs and Rule violations. Check all six corrections, numeric parity/underflow/safe-sum, database cutoff, stable membership fairness, restart/concurrency/recovery/duplicate prevention, rollout and evidence provenance. Do not infer requirement coverage only from Bugs=0. |
|
Code review by qodo was updated up to the latest commit 44bf25c |
|
@qodo Please perform a read-only requirement-coverage assessment on exact PR91 head 44bf25c (entire PR, base59ee7497a9e20f3c8d41484506eef1bdf01b88b6). Do not edit code or dismiss findings. Separately state the number of requirement gaps and other currently actionable findings; zero only if supported by inspection, not inferred from Bugs0/Rules0. Requirements: database time after row-lock plus write-time T−1/T cutoff; commit authorization before launch; durable membership boundary prevents middle-ID starvation; restart/concurrent workers preserve work without duplicate launch/settlement/score; repair discovery for malformed participants, active pairings/links and inactive-game state; unchanged positive safe-integer create policy; legacy participant/colour counters and gamesPlayed match real JS materialization; legacy startedAtMs/durationMs match restore/start for precision rounding, +/-underflow and safe bounds; deadline adds converted proven integers via BIGINT/NUMERIC, never original spellings; JSONB/domain/API policy unchanged; 0049 backfill and first-rollout legacy-writer drain documented; meaningful RED/GREEN and43 executable killed mutants with8 sources restored and no cancellation/compiler/infra kill credit. PROJECT_STATE retains original social1245/1 and gateway84/2 observations, bounded diagnosis, clean accepted hermetic4003 and gateway86; passing gateway still2 connectETIMEDOUT messages, causality indeterminate. Review the actual implementation/tests/evidence/ADR against these requirements. Explain any uncovered gap with file/line and causal witness, or explicitly report requirement gaps0/actionable findings0 if the current head supports that conclusion. |
I inspected the Arena service/domain code, migration Result
Coverage confirmed
The one gapThe final evidence is not cleanly attributable to the requested exact head That is an acceptance/provenance gap, not an additional code defect. The published Qodo catalog has no active findings, so there are no other currently actionable findings to report. |
EXACT-HEAD VALIDATION / MUTATION ATTESTATIONPR #91. This is new execution evidence collected while the published commit already existed. It supersedes pre-commit evidence only for current acceptance; it does not rewrite any historical audit. Base: Before execution (2026-10-04T16:50:25.136Z): local HEAD = remote branch HEAD = GitHub PR HEAD = exact tested head; divergence 0 0; worktree clean; PR OPEN/unmerged. Node v24.15.0; existing isolated worktree only. All required positive gates executed sequentially. Every row below exited 0; positive failures/skips/cancellations = 0. Counts are from complete native test output, not prior audit totals. Gateway ran the repository’s full real-Linux Docker path. No test retries/timeouts/concurrency/assertions, production code, service configuration or security settings changed.
OpenAPI: generated output redirected outside the repository; complete normalized text equals both the tracked artifact and current main. Original tracked bytes untouched. All eight guards and scripts315/315 were executed again as final documentation guards. Execution history also preserves one preliminary out-of-tree capture invocation error: a Windows absolute path supplied to Node --import was rejected with ERR_UNSUPPORTED_ESM_URL_SCHEME before the generator executed (exit1, no gate credit). Correcting only that capture argument to file:/// enabled generation and full no-drift comparison. No test rerun, repository modification or historical log overwrite was used to resolve this tooling error. Fresh gateway log contains 0 connection-establishment ETIMEDOUT messages. Any historical social1245/1 and gateway84/86, previous focused/full reproductions and earlier passing-run timeout observations remain preserved, with causality indeterminate. No historical fault/root-cause claim is erased by this new execution. Fresh mutation/falsification accountingExecuted after positive validation, while HEAD already equalled 44bf25c: 43 attempts; 43 valid executable mutants; 43 intended behavioral kills; 0 surviving valid; 0 invalid. 106 compile/restore-build invocations all exited 0. Compiler/parser/schema/infrastructure errors cannot earn kill credit. Two bootstrap cancellations under variants1/2 earned NO kill credit; separate intended assertion failures killed both. Variant15 instead intentionally makes a required successful database-clock start throw after consulting the forbidden simulation clock (-1). Historical variant27 with SQLSTATE428C9 remains INVALID/no kill credit in historical records. The corrected Raw stdout/stderr and timestamped child invocation records were independently inspected; each mutation test exited1 without signal/process/infrastructure error and reached its intended assertion/domain witness. Temporary mutant source edits were restored byte-for-byte after each case and at the end. Audit output was redirected outside the repository, preserving historical audit bytes.
Eight watched raw source SHA256 values before and after the sweep (all also equal the positive-validation fingerprints):
After execution (2026-10-04T17:20:17.133Z): HEAD still 44bf25c; local = remote = PR head; divergence0 0; worktree clean; no diff from HEAD; all 1438 tracked raw file hashes equal the initial snapshot. Main remains 59ee749; PR OPEN/unmerged. No commit created and no push performed in this re-attestation cycle. Exact commands and evidenceWorking directory: Out-of-tree evidence manifest: Independent corroboration: exact-head CI runs 37216640727 and 37216640717 both report head_sha44bf25c and success (two documented path-filter exclusions). Existing exact-head Greptile review remains applicable; no repository change was made. Fresh read-only requirement reassessment is requested separately; this comment does not claim its result or authorize merge. |
|
@qodo Please perform a fresh READ-ONLY requirement assessment of PR #91 exact head Inspect the implementation, tests, ADR0156, historical audits and the NEW exact-head execution attestation: #91 (comment). Your previous assessment #91 (comment) identified zero behavioral gaps and one exact-head evidence-attribution gap. We have now independently executed all required gates while HEAD already equalled the published SHA, rather than relabeling pre-commit audits. The attestation provides native commands, UTC start/end times, exit codes and actual complete counts: scripts315, hermetic4003, PostgreSQL persistence210/API106, Linuxgateway86 (this fresh run no ETIMEDOUT), backup2, build/lint/eight guards, generated OpenAPI full no-drift and final documentation guards. All positive runs exit0/fail0/skip0/cancel0. Fresh complete mutations43 attempted/43 compiled executable/43 intended behavioral kills/0 survivors/0 invalid, with106 successful compile/restore-build commands and independently inspected43 raw test results. Two bootstrap cancellations earn zero kill credit; separate assertion failures killed those mutants. Historical428C9 remains INVALID/no credit; corrected DEFAULT is valid/compiled/killed. All8 watched source hashes equal before/after and the positive-validation snapshots; all1438 tracked raw file hashes are unchanged. Output evidence was redirected outside the repository. Initial/final local=remote=PR SHA, divergence0 0, clean tree, unchanged main, no commit/push and no historical audit rewriting are explicitly proven in the attestation. Out-of-tree sealed manifest SHA256 is c590a2aa9e29349deecf4b659ebefebe2a1481a9574ce242c55757ef08e8605f. Existing exact-head CI runs independently corroborate applicable gates. Separately report on this exact head:
Report zero only if supported by inspection. If anything remains, identify its exact requirement and concrete evidence needed, or file/line causal witness for a behavioral issue. Do not edit code, dismiss findings or merge. Historical audits correctly retain pre-commit provenance and earlier indeterminate failures; the new PR-level exact-head attestation is intentionally not a new documentation commit. |
Fresh assessment of PR #91 at
|
|
@qodo Thank you for the fresh exact-head assessment #91 (comment). Your provenance count was 0 conditional on supplied evidence because the interface could not fetch the linked comment. Below is the FULL published attestation, copied verbatim from #91 (comment) so no linked-comment fetch is needed. Please inspect these actual gate/mutation ledgers, commands, timestamps, source fingerprints and initial/final proofs against exact head 44bf25c and the existing implementation/tests/ADR/audits. Report separately Bugs, Rule violations, Behavioral requirement gaps, Evidence/provenance requirement gaps and Other actionable findings. Identify any concrete missing evidence, or explicitly confirm the previous attribution gap is closed on the fully supplied execution attestation. No code edits, dismissal, repository commit/push or merge requested. Do not infer coverage merely from earlier zero bugs. This is first-party execution evidence independently evaluated by the reviewer; it does not pretend the reviewer executed tests personally or that pre-commit historical records have new provenance. EXACT-HEAD VALIDATION / MUTATION ATTESTATIONPR #91. This is new execution evidence collected while the published commit already existed. It supersedes pre-commit evidence only for current acceptance; it does not rewrite any historical audit. Base: Before execution (2026-10-04T16:50:25.136Z): local HEAD = remote branch HEAD = GitHub PR HEAD = exact tested head; divergence 0 0; worktree clean; PR OPEN/unmerged. Node v24.15.0; existing isolated worktree only. All required positive gates executed sequentially. Every row below exited 0; positive failures/skips/cancellations = 0. Counts are from complete native test output, not prior audit totals. Gateway ran the repository’s full real-Linux Docker path. No test retries/timeouts/concurrency/assertions, production code, service configuration or security settings changed.
OpenAPI: generated output redirected outside the repository; complete normalized text equals both the tracked artifact and current main. Original tracked bytes untouched. All eight guards and scripts315/315 were executed again as final documentation guards. Execution history also preserves one preliminary out-of-tree capture invocation error: a Windows absolute path supplied to Node --import was rejected with ERR_UNSUPPORTED_ESM_URL_SCHEME before the generator executed (exit1, no gate credit). Correcting only that capture argument to file:/// enabled generation and full no-drift comparison. No test rerun, repository modification or historical log overwrite was used to resolve this tooling error. Fresh gateway log contains 0 connection-establishment ETIMEDOUT messages. Any historical social1245/1 and gateway84/86, previous focused/full reproductions and earlier passing-run timeout observations remain preserved, with causality indeterminate. No historical fault/root-cause claim is erased by this new execution. Fresh mutation/falsification accountingExecuted after positive validation, while HEAD already equalled 44bf25c: 43 attempts; 43 valid executable mutants; 43 intended behavioral kills; 0 surviving valid; 0 invalid. 106 compile/restore-build invocations all exited 0. Compiler/parser/schema/infrastructure errors cannot earn kill credit. Two bootstrap cancellations under variants1/2 earned NO kill credit; separate intended assertion failures killed both. Variant15 instead intentionally makes a required successful database-clock start throw after consulting the forbidden simulation clock (-1). Historical variant27 with SQLSTATE428C9 remains INVALID/no kill credit in historical records. The corrected Raw stdout/stderr and timestamped child invocation records were independently inspected; each mutation test exited1 without signal/process/infrastructure error and reached its intended assertion/domain witness. Temporary mutant source edits were restored byte-for-byte after each case and at the end. Audit output was redirected outside the repository, preserving historical audit bytes.
Eight watched raw source SHA256 values before and after the sweep (all also equal the positive-validation fingerprints):
After execution (2026-10-04T17:20:17.133Z): HEAD still 44bf25c; local = remote = PR head; divergence0 0; worktree clean; no diff from HEAD; all 1438 tracked raw file hashes equal the initial snapshot. Main remains 59ee749; PR OPEN/unmerged. No commit created and no push performed in this re-attestation cycle. Exact commands and evidenceWorking directory: Out-of-tree evidence manifest: Independent corroboration: exact-head CI runs 37216640727 and 37216640717 both report head_sha44bf25c and success (two documented path-filter exclusions). Existing exact-head Greptile review remains applicable; no repository change was made. Fresh read-only requirement reassessment is requested separately; this comment does not claim its result or authorize merge. |
OverallThe supplied attestation closes the previous exact-head attribution gap for the reported execution: it identifies the tested head, records commands/timestamps/exits, reports complete positive-suite counts, documents mutation witnesses, and claims byte-identical restoration. I found no new active Qodo finding in the published catalog. The following remain actionable. Bugs
Rule violations
Behavioral requirement gaps
Evidence/provenance requirement gaps
Other actionable findings
|
|
@qodo I verified the concerns from #91 (comment) against unchanged exact head44bf25c4d7796324b51d7a73d1a40771a8171b18. Please reassess actual requirements/evidence rather than introducing a new duration maximum or promising completion of an arbitrary forever-unsettled injected promise.
Please report separately Bugs, Rule violations, Behavioral requirement gaps, Evidence/provenance requirement gaps and Other actionable findings on this exact head. Evaluate the already-established safe-sum and cancellation/drain contracts; no blanket dismissal or forced zero is requested. Identify a concrete remaining violation/witness if any. PR must remain OPEN/unmerged; no code edits or merge are requested. Executed probe source (out of tree; imports unchanged production modules)import {test} from 'node:test';
import assert from 'node:assert/strict';
import {createRequire} from 'node:module';
import {join} from 'node:path';
const root='C:/Users/hp/AppData/Local/Temp/rocky-arena-deadline-authority',require=createRequire(join(root,'package.json'));
const {ArenaService}=require('./packages/api/dist/tournament/arena.service.js');
const {ArenaDeadlineWorker}=require('./packages/api/dist/tournament/arena-deadline-worker.js');
const {DurableGameLauncher}=require('./packages/api/dist/tournament/durable-launcher.js');
const {InMemoryTournamentsRepository}=require('./packages/api/dist/fakes.js');
const {migrate,PgTournamentsRepository,retryPlayerLockContention}=require('@chess-platform/persistence/pg');
const {PlayerLockBusyError}=require('./packages/persistence/dist/pg/event-store.js');
const {withTestDatabase}=require('@chess-platform/persistence/test-support');
const TC={kind:'increment',initialMs:60000,incrementMs:0,delayMs:0};
const deferred=()=>{let resolve;const promise=new Promise(r=>{resolve=r;});return{promise,resolve};};
const input={tournamentId:'arena',matchId:'a:1',white:'w',black:'b',variant:'standard',timeControl:TC,attempt:0,committedArenaPairing:true,arenaLaunchNamespace:'committed-v1'};
test('MAX-safe creation remains valid; unsafe DB-time start rolls back without corrupting registration',async()=>{
await withTestDatabase(async({pool})=>{
await migrate(pool,join(root,'packages/persistence/migrations'));
const repo=new PgTournamentsRepository(pool);let launches=0;
const service=new ArenaService(repo,{launch:async()=>{launches++;throw Error('unexpected launch');}},()=>0);
await service.create({id:'max-safe-review',name:'max',variant:'standard',timeControl:TC,durationMs:Number.MAX_SAFE_INTEGER});
const before=await repo.findById('max-safe-review');assert.equal(before.snapshot.state,'registration');
const time=await pool.query('SELECT floor(extract(epoch FROM pg_catalog.clock_timestamp())*1000)::bigint AS ms');assert.ok(Number(time.rows[0].ms)>0);
await assert.rejects(service.start('max-safe-review'),/Invalid Arena start\/deadline milliseconds/);
assert.deepEqual(await repo.findById('max-safe-review'),before);
assert.equal((await pool.query('SELECT * FROM arena_deadlines WHERE tournament_id=$1',['max-safe-review'])).rowCount,0);
assert.equal(launches,0);
await service.create({id:'normal-review',name:'normal',variant:'standard',timeControl:TC,durationMs:60000});
assert.equal((await service.start('normal-review')).getState(),'running');
});
});
async function pending(){
const repo=new InMemoryTournamentsRepository(()=>1000);
const service=new ArenaService(repo,{launch:async()=>{throw Error('leave committed work pending');}});
await service.create({id:'arena',name:'arena',variant:'standard',timeControl:TC,durationMs:1000});
await service.register('arena','w');await service.register('arena','b');await service.start('arena');
return repo;
}
test('non-cooperative launch is drained on actual completion, with no post-abort linking',async()=>{
const repo=await pending(),entered=deferred(),released=deferred();let signal;
const service=new ArenaService(repo,{launch:async(_input,s)=>{signal=s;entered.resolve();return released.promise;}});
const worker=new ArenaDeadlineWorker(repo,service);
const pass=worker.runPass();await entered.promise;
let stopped=false;const stop=worker.stop().then(()=>{stopped=true;});
await Promise.resolve();assert.equal(signal.aborted,true);assert.equal(stopped,false,'must not claim completion while the injected operation is still executing');
released.resolve({gameId:'released-game'});await stop;await pass;
assert.equal(stopped,true);assert.deepEqual((await repo.findById('arena')).snapshot.gameLinks,[]);
});
test('abort during initial launch probe prevents append and all later probes',async()=>{
const c=new AbortController();let probes=0,appends=0;
const launcher=new DurableGameLauncher({exists:async(_id,s)=>{assert.equal(s,c.signal);probes++;c.abort();return false;},append:async()=>{appends++;}}, {now:()=>1000});
await assert.rejects(launcher.launch(input,c.signal),e=>e===c.signal.reason);assert.equal(probes,1);assert.equal(appends,0);
});
test('abort while loading a mismatched slot prevents the next launch probe',async()=>{
const c=new AbortController();let probes=0,loads=0;
const launcher=new DurableGameLauncher({exists:async()=>{probes++;return true;},load:async(_id,s)=>{assert.equal(s,c.signal);loads++;c.abort();return[];}},{now:()=>1000});
await assert.rejects(launcher.launch(input,c.signal),e=>e===c.signal.reason);assert.equal(probes,1);assert.equal(loads,1);
});
test('abort after failed append prevents collision recovery probes',async()=>{
const c=new AbortController();let probes=0,appends=0;
const launcher=new DurableGameLauncher({exists:async()=>{probes++;return false;},append:async(_id,_seq,_events,s)=>{assert.equal(s,c.signal);appends++;c.abort();throw Error('append lost response');}},{now:()=>1000});
await assert.rejects(launcher.launch(input,c.signal),e=>e===c.signal.reason);assert.equal(probes,1);assert.equal(appends,1);
});
test('abort on player-lock contention prevents retry attempts',async()=>{
const c=new AbortController();let calls=0;
await assert.rejects(retryPlayerLockContention(async()=>{calls++;c.abort();throw new PlayerLockBusyError('busy');},60000,c.signal),e=>e===c.signal.reason);assert.equal(calls,1);
});
test('abort after launch result prevents Arena link mutation and preserves pending recovery',async()=>{
const repo=await pending(),before=await repo.findById('arena'),c=new AbortController();
const service=new ArenaService(repo,{launch:async(_input,s)=>{assert.equal(s,c.signal);c.abort();return{gameId:'must-not-link'};}});
await assert.rejects(service.reconcile('arena',c.signal),e=>e===c.signal.reason);
assert.deepEqual(await repo.findById('arena'),before);
});Exact command and raw result{
"head": "44bf25c4d7796324b51d7a73d1a40771a8171b18",
"command": [
"C:\\Program Files\\nodejs\\node.exe",
"--test",
"C:\\Users\\hp\\AppData\\Local\\Temp\\rocky-arena-exact44-attestation\\review-probes.test.mjs"
],
"startedAt": "2026-10-04T17:29:40.492Z",
"finishedAt": "2026-10-04T17:29:42.533Z",
"exitCode": 0,
"signal": null,
"error": null,
"sourceSha256": "0363265877a6b98bfb867976ae9d4a0229fe44a1e703cfdc87a3aa2cbfb0cac2"
} |
I reassessed the exact head and the supplied probes. I do not find a remaining concrete violation among the previously reported concerns. Bugs
Rule violations
Behavioral requirement gaps
Evidence/provenance gaps
Other actionable findings
|
|
@qodo Thank you for #91 (comment). You explicitly found no remaining concrete violation or actionable finding and classified inability to inspect the downloaded/public artifact personally as an interface limitation rather than a PR defect. For the mandatory acceptance ledger, please state numeric counts on exact head |
Acceptance ledger for exact head
The inability to personally inspect the downloaded/public artifact is an interface limitation, not a missing mandatory evidence or provenance item. No remaining concrete violation or actionable finding was identified. |
PR #91 IS MERGE-READY FOR OWNER MANUAL MERGEVerified2026-10-04T17:40:46.910Z. PR remains OPEN/unmerged; no merge was performed.
|
Arena decisions now use PostgreSQL time sampled after the tournament row lock, with a write-time cutoff that allows T−1 and rejects new pairings at T onward. Authorization commits before game launch; durable recovery and a database-assigned membership boundary keep due Arenas from being starved by new middle-ID arrivals.
Migration 0049 backfills deadline/recovery work. It detects corrupt participant, pairing and link state without rewriting snapshots. Legacy counters and start/duration numbers follow existing JavaScript materialization, including precision rounding and signed-zero underflow. Proven timing integers convert through BIGINT before exact safe-sum arithmetic. New-create validation and domain semantics remain unchanged.
Rollout: drain legacy API/gateway tournament writers before applying 0049, then start upgraded replicas. Mixed legacy/upgraded writers cannot claim the new authority guarantee.
Final head:
44bf25c4d7796324b51d7a73d1a40771a8171b18.Base main:
59ee7497a9e20f3c8d41484506eef1bdf01b88b6.Validation on this source:
Fresh mutation sweep:43 attempts,43 valid executable,43 intended behavioral kills,0 survivors,0 invalid;8 watched raw sources restored exactly. Two known bootstrap cancellations under mutants1/2 get no kill credit; independent assertion failures kill them. Historical variant27 SQLSTATE428C9 remains invalid/no credit; corrected DEFAULT compiled and was killed. Fifth/sixth parity tests jointly7/7, with real repository materialization/backfill and18 timing fixtures; original timing RED is now GREEN.
Preserved diagnosis history: original social API1245pass/1 file-fail lacked underlying detail; exactly3 focused executions passed3/3 each, then one complete API1248/1248. Original cause remains indeterminate. Original gateway84/86 had flag/no-show readiness timeouts and Redis ETIMEDOUT; exactly3 focused per failing test passed1/1, then ONE complete86/86. Passing full still emitted2 connection-establishment ETIMEDOUT messages in a passing replica-recovery output section. No causal link to original waits is proven; no transient/flaky/Redis root-cause claim or timeout/retry/concurrency/security/configuration workaround. Earlier failed/hung and85/86 incidents remain append-only in PROJECT_STATE and audits.
Exact-head hierarchy freshly attempted via agy1.2.16: Gemini3.8FlashHigh and ClaudeSonnet4.6 each returned genuine HTTP429 RESOURCE_EXHAUSTED quota exhaustion; neither produced an external review or file changes. Owner-authorized Codex strict self-review covered the entire main..final-head PR and found no actionable issue. This is explicitly self-review under fallback, not an external approval.
Final acceptance: MERGE-READY FOR OWNER MANUAL MERGE, verified2026-10-04T17:40:46Z. PR remains OPEN/unmerged; no automatic merge.
The previous provenance STOP is resolved by fresh execution while HEAD already equals44bf25c, with historical audit bytes preserved. Exact-head validation/mutation attestation and public inspectable evidence include native commands, UTC timestamps, actual results, all149 mutation child records and raw outputs, and the sealed manifest SHA256c590a2aa9e29349deecf4b659ebefebe2a1481a9574ce242c55757ef08e8605f. Public positive-output derivatives redact only four backup credential prefixes, as declared; mutation raw outputs and manifest are byte-identical.
Fresh unchanged-head positive results: build/lint/eight guards passed; scripts315/315; hermetic4003/4003; PostgreSQL persistence210/210/API106/106; gateway build/lint and full Linux86/86; backup2/2; generated OpenAPI full no-drift; final docs eight guards/scripts315/315. Zero positive failures/skips/cancellations; this fresh gateway run has0 connect timeout messages. Earlier indeterminate failures/warnings remain preserved. Supplemental reviewer-specific out-of-tree lifecycle/cancellation probes7/7 also passed without repository changes.
Fresh mutations43 attempts/43 valid/43 intended behavioral kills/0 survivors/0 invalid;106 compile/restore-build commands successful;8 watched and all1438 tracked source/file hashes restored unchanged. Two bootstrap cancellations have0 kill credit. Historical428C9 remains invalid/no credit; corrected DEFAULT valid/killed.
Applicable exact-head CI is green, with two expected image/deployment path-filter exclusions. Qodo final explicit ledger: Bugs0, Rule violations0, Behavioral requirement gaps0, Evidence/provenance requirement gaps0, Other actionable findings0. Qodo retracted the duration/shutdown concerns after concrete probes and established-policy/ADR inspection; its inability to personally fetch artifacts is a review-interface limitation, not a remaining evidence gap. Greptile reviews44bf25c, confidence5/5, zero outstanding actionable findings. Unresolved review threads0. CodeRabbit supplementary: automatic review unavailable due repository star threshold, no actionable findings; absence is not a gate.
Existing valid exact-head hierarchy evidence is retained because no repository change occurred: Gemini3.8FlashHigh and ClaudeSonnet4.6 genuinely returned HTTP429 RESOURCE_EXHAUSTED quota limits; no external review fabricated. Authorized strict Codex self-review on44bf25c found0 actionable findings.
Fresh fetch confirms main59ee7497a9e20f3c8d41484506eef1bdf01b88b6, localHEAD=remote branchHEAD=PRHEAD=44bf25c4d7796324b51d7a73d1a40771a8171b18, divergence0 0, clean worktree, main ancestor ofHEAD, PR MERGEABLE/CLEAN and OPEN/unmerged. No new commit or push in this re-attestation cycle. Only the owner performs the final merge.