Skip to content

Repair inverse-intent WAL recovery after a second restart #751

Description

@flyingrobots

The existing inverse_intent_resolves_one_admitted_transition_after_restart fixture fails while reopening the WAL after an inverse replacement has applied. The new history host refuses recovery with Wal(Recovery(Validation(LsnContinuityMismatch))) at crates/warp-core/tests/external_consumer_contract_fixture_tests.rs:687.

This is independently reproducible before Bunny integration: unchanged base 5f99097d9a5c45a91ab22ec996f7a24266f92a13 fails using its original Rust1.90.0, and also with1.96.0, in the same guarded Docker worker. The original-toolchain run completed compilation, ran exactly the named test, and reported0passed/1failed, Cargo101. The test itself is unchanged by companionPR750; its only WAL-file production changes are equivalent strict-lint corrections. The root cause is not yet established.

Reproduction inside the bounded Docker validation environment, on the pinned base:

cargo +1.90.0 test --locked -p warp-core \
  --features native_rule_bootstrap,trusted_runtime,host_test \
  --test external_consumer_contract_fixture_tests \
  inverse_intent_resolves_one_admitted_transition_after_restart -- --exact

Observable outcome: a committed inverse transition remains recoverable after the next restart, with valid contiguous WAL evidence and the expected typed inverse derivation.

Scope: isolate and repair the WAL append/recovery or fixture defect that produces this failure. Preserve transaction integrity, causal parent binding and refusal of genuinely corrupt/noncontiguous history. Do not suppress continuity validation or merely remove the restart assertion. Excludes Bunny arithmetic, fixed-point language features, application-specific Jim operations and unrelated WAL redesign.

Acceptance checks:

  • Preserve the existing deterministic failing fixture as RED on the pinned base, then make it pass through both restart boundaries.
  • Verify recovered document value, frontier/provenance advancement and typed inverse receipt derivation.
  • Retain meaningful negative coverage that refuses actual LSN gaps/duplicates or malformed transaction evidence.
  • Run the relevant WAL/runtime suites and selected external-consumer feature lane in guarded Docker, with compiler/source identities recorded.

Related tracking scope: inverse Intent path #494 describes the broader capability. This issue isolates a concrete restart failure in the existing implementation and does not duplicate that full feature scope.

No prerequisite is currently established; investigation may identify one with evidence. This should be one independently mergeable repair that leaves ordinary admission/recovery checks working. The Bunny foundation is not a prerequisite; this issue records a pre-existing failure observed during PR750 validation.

Evidence: retained echo-bunny-echo-final-gates.log, baseline-original-toolchain section at base5f99097d, and earlier echo-bunny-echo-verify2.log original-base1.96 comparison. The complete final log hash will be attached after the ongoing candidate gate finishes. These are process-level restart witnesses; no power-loss claim is made.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions