Skip to content

fix: preserve Effect equality and scoped test lifetimes - #4

Merged
ScriptedAlchemy merged 1 commit into
ScriptedAlchemy:mainfrom
BleedingDev:fix/native-effect-conformance
Sep 8, 2026
Merged

ScriptedAlchemy merged 1 commit into
ScriptedAlchemy:mainfrom
BleedingDev:fix/native-effect-conformance

Conversation

@BleedingDev

Copy link
Copy Markdown
Contributor

Summary

Fix five adapter conformance gaps without changing dependencies or the public test API:

  • Register Effect's Equal protocol tester, returning undefined for ordinary values so native equality/asymmetric matchers still work.
  • Generate schemas in synchronous tuple/record it.prop inputs, using the same Schema.toArbitrary path as effectful properties.
  • Actually discard non-void Effect successes before the Rstest Promise boundary. A success value with a throwing then getter now remains a successful Effect test instead of being assimilated as a Promise.
  • Await timed-out test fiber settlement/finalizers with an untimed onTestFinished barrier, without rethrowing failures the runner has already handled (including .fails).
  • Retain and interrupt the shared-layer setup fiber before closing its scope, including named/unnamed setup timeout and early failure.

All implementation changes are in src/internal/internal.ts. The rest is generic regression coverage and precise lifecycle documentation; no dependency/lockfile/workflow or compatibility changes.

Regression evidence

Tested with the repository's locked Effect 4.0.0-rc.112 / Rstest 0.11.11 on Node 26.5.0.

Against original commit 79abbf684c7b150ee5f32694129a7caf969903bc, using a separate source copy with the same installed versions:

  • Both synchronous schema-property files fail registration with Schemas are not supported yet.
  • Both semantic equality/inequality regressions fail; native plain-object control passes.
  • Layer-lifetime child report has four failed observers rather than zero.
  • Test-lifetime child report has eight failures rather than the three deliberately expected failures.
  • Both hostile-thenable success-value regressions fail with the throwing getter error.

With this change:

  • pnpm check — passes.
  • pnpm test --pool.maxWorkers=9 --maxConcurrency=9 — 53 passed, 5 existing intentional skips across 9 files.
  • pnpm test:types — 11 tests / 15 assertions passed.
  • pnpm build — passes.
  • pnpm publint — passes.
  • Independent packed-consumer runtime and declaration checks passed without source aliases.

The lifecycle tests execute actual Rstest subprocesses and inspect their JSON reports, including intentional timeout/failure/skip outcomes, rather than mocking runner hooks. Child fixtures use thread workers so their 20-second process deadline cannot orphan fork workers; normal test-runner defaults and worker counts are unchanged. A separate hung-worker probe verified that deadline termination leaves no live worker or owned fixture directory.

Deliberate limits

  • Native afterEach runs before onTestFinished; timeout cleanup ordering does not cover native hooks.
  • The per-test settlement barrier has no second deadline: a finalizer that never completes can hold suite completion.
  • Shared-layer teardown retains its hook deadline; cleanup exceeding that deadline can outlive the hook.
  • This does not serialize explicitly concurrent tests or promise process-kill-safe Effect cleanup.
  • Schemas still need to support arbitrary generation.

🤖 Generated with Claude Code

Generate schemas in synchronous properties, discard Effect success values at the runner boundary, and await timed-out test and shared-layer setup fibers. Add generic runtime, subprocess lifecycle, and type regressions.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Sep 8, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 1026323

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-08T13:14:19.601699Z 1026323 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

BleedingDev added a commit to TechsioCZ/ontos that referenced this pull request Sep 8, 2026
Adopt the immutable upstream package and remove the owned adapter. Carry the generic conformance fixes from ScriptedAlchemy/effect-rstest#4 in one temporary pnpm patch, tracked for removal by #507. Update actual imports and lint provenance without compatibility aliases or runner wrappers.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
JiProchazka added a commit to TechsioCZ/ontos that referenced this pull request Sep 8, 2026
* fix(db): audit reachable role grant options

* fix(database-audit): tighten view privilege evidence

* fix(database-audit): include inherited view-owner authority

* docs: finish authority cleanup and upgrade pnpm

* test: align Locki pnpm pin with 11.25.0

* fix: align authorization rollout ownership

* fix: align stage authorization approval reference

* docs(skills): preserve explicit OntOS priming guardrails

* docs(skills): restore transitive review guidance

* docs(skills): restore explicit implementation guardrails

* docs(skills): restore explicit planning guidance

* docs(skills): keep generator discovery source-owned

* docs(skills): retain focused branch divergence check

* docs: retain support impersonation configuration

* docs: restore pinned MicroVertical creation command

* ci: scope push checks to main and stage

* docs: add Effect v4 anti-pattern audit

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* feat(core): define application composition contract

* fix(core): satisfy composition contract lint

* fix(core): type composition rejection and artifact ownership

* fix(core): validate complete observed composition

* fix(core): verify remote composition evidence

* Use Effect non-empty string schema

* Use Effect orders for composition sorting

* Use Effect codecs and typed composition validation

* Require development evidence for loopback composition artifacts

* Default composition error code through Effect Schema

* feat(party-registry): implement issue 179 and all subissues

Deliver the approved V1 Party identity, evidence, matching, counterparty, search and ARES boundaries with the breaking Contacts engagement cutover.

Includes governed public Actions/Reads, worker deployment, database constraints and RLS, generator support, and per-family regression coverage. Production merge remains disabled per ADR 0018. Live PostgreSQL and SpiceDB verification remains environment-blocked.

* fix(build): verify API-only release execution assets

* feat(db): upgrade to Drizzle 1.0.0-rc.4 and Better Auth 1.7.2

Move all three schema owners (Core, Shell Auth, Contacts) to Drizzle ORM/Kit
1.0.0-rc.4 and Better Auth 1.7.2 instead of only documenting readiness (#98).

- Convert migration histories to the v3 folder layout with `drizzle-kit up`;
  every migration.sql stays byte-identical to the previous SQL file.
- Normalize converted snapshots so the rc.4 reader stops emitting false DDL
  (drizzle-team/drizzle-orm#6020); `db:generate` is clean for all owners.
- Replace RQB v1 `relations()` with `defineRelations`, type databases as
  `NodePgDatabase<typeof relations>`, and use `withRLS` instead of the
  deprecated `enableRLS` wrapper (drops `enableGovernedRls`).
- Switch to `@better-auth/drizzle-adapter/relations-v2` and add the required
  `account.issuer` column with a guarded backfill and unique
  (issuer, account_id) index.
- Add `db:check` (commutativity) scripts per owner and at the root.
- Document the cohort, layout, and re-proof steps in
  docs/architecture/DRIZZLE_V1_UPGRADE.md; update DATABASE, DEPLOYMENT, README.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(auth): keep account.issuer expand-only with an insert compat trigger

Better Auth 1.6 writers do not supply `issuer`, so `SET NOT NULL` alone
would break account creation while the previous Shell release still runs
against the expanded schema (Deployment step 7). Install a BEFORE INSERT
trigger that derives `issuer` with the backfill rule when it is missing;
drop it in a later contraction once no 1.6 writer remains.

Proven on a fresh database: migrate + verify pass, inserts without
`issuer` as the runtime role get `local:credential` / `local:oauth:<id>`,
and the Shell integration suite passes 8/8.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(docs,topology): retarget stage replay migration and drop pinned versions from DATABASE.md

- topology/authorization-contexts/stage.json pointed at the removed
  verticals/contacts/drizzle/0003_sticky_maverick.sql; point it at the v1
  folder so authorization readiness can read the replay migration.
- DATABASE.md described the cohort with exact Drizzle and Better Auth
  versions, which README forbids for current docs; keep the cohort
  invariant and defer exact versions to the package manifests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(ci): restore issue 179 verification gates

* fix(ci): derive workerd proof route from topology

* feat(lint): enforce Effect audit with 71 diagnostic-only Oxlint rules

Add strict rule registration, production-default fixtures, fail-closed reporting, and audit coverage. Preserve application violations and forced framework boundaries; no autofixes or application changes.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* docs(lint): refresh enforcement snapshot against current main

Record 3,909 diagnostics and 155 passing tooling tests; distinguish pnpm's stale-install blocker from intentional application lint failures.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* test(lint): run rule gates in CI and preserve workspace identity contract

Add an independent CI implementation gate and keep a domain-helper fixture neutral without changing its assertion or application code.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(lint): classify nested scripts and import fixture rules by URL

Cover relative and absolute workspace script paths, default and opt-in rule scope, and isolated ESM discovery from URL-sensitive paths. Preserve all application diagnostics and reporting-only policy scope.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* docs(lint): refresh rebased enforcement snapshot and rule totals

Record the pinned 9adca84 application tree and 1531cfb lint implementation: 5,286 diagnostics across 753 scanned files, including Party Registry. Refresh every catalog row from the validated JSON report and document the 162-test clean-install CI evidence.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(lint): launch Oxlint portably and align script fix scope

Run the package JavaScript entry point with process.execPath instead of a POSIX-only shim. Add real-process and command-scope regressions; all 164 tests pass and the diagnostic multiset remains unchanged. Extend the existing opt-in lint:fix command to scripts without running fixes or changing diagnostic-only rules.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* [codex] merge Contacts into Party Registry (#395)

* fix: merge Contacts into Party Registry

* fix: pass PR checks and repair Party Registry route

* fix: repair CI configuration and promise bridges

* fix: keep Party scaffold deploy modes in sync

* feat(core): add typed persistence attempt constructor (#362)

* feat: add shared Effect BFF client factory

* feat: share operation gateway runtime (#361)

* feat: centralize PostgreSQL failure classification

* test: enforce shared client type proof

* feat: add shared Effect BFF client factory

* test: enforce shared client type proof

* feat: extract shared gateway principal verifier

* refactor(party-registry): decompose API runtime (#355)

* style(party-registry): format API runtime

* fix(core): expose persistence adapter to worker builds (#362)

* feat: centralize PostgreSQL failure classification

* feat(core): compose owner-configured mutation failures (#364)

* feat(core-db): add the Core-owned transaction bridge

One bridge runs an Effect transaction body inside the Drizzle Promise callback, keeps the caller context, preserves the original Cause on failure, distinguishes its own rollback sentinel from driver failures, and settles interruption before the connection is released.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* test: link shared verifier in generated owner fixture

* [codex] centralize MicroVertical HTTP authentication (#351)

* fix(transactions): run every Core transaction body through the bridge

Actions, governed reads and the search snapshot no longer run Effects inside the Drizzle Promise callback. Typed failures, defects and interruption keep their original Cause; only genuine driver rejections become transaction failures with the rejection retained as cause; the search snapshot keeps repeatable read.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* feat(actions): add governed Action HTTP runner

* fix(security): observe signing-key rotation and never cache issued API-key secrets

The gateway issuer loaded configuration and imported the private key once per
process behind Effect.cached, so a failed import was memoized for the lifetime
and a rotated ONTOS_GATEWAY_PRIVATE_JWK was not observed without a restart.
Configuration is loaded per issuance again; the key import is reused only while
the sha256(kid, x, d) fingerprint of the JWK matches, is shared by concurrent
issuances and evicted on failure.

Responses that return a freshly issued API-key secret now carry
Cache-Control: no-store through the BFF pre-response seam.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(errors): keep governed-read interruption and never discard denial-evidence failures

A governed read that is interrupted now ends interrupted, after the driver settles, instead of surfacing as a handler execution error. When persisting denial evidence fails or dies, the caller still receives the original ReadPermissionDenied and the evidence failure is combined into the Cause rather than replacing or hiding it.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(ownership): retain repository failure causes in class-private state

ActionTransactionError and ActionInvocationPersistenceError keep their original defect in a private #cause field set once by a Core-owned factory and read only through internal readers. The reflectable ontosRepositoryFailureCause property is gone, so no other module can read, forge, or clone the retained cause.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(availability): bound every PostgreSQL pool with shared deadlines and hold module-load permits to settlement

The three physical pool owners (Core, Shell auth, Party Registry) built
new Pool(configuration) with no acquisition timeout and no statement deadline.
One shared pool configuration now gives every owner an acquisition timeout and
a statement_timeout; lock_timeout is applied only when explicitly opted in so
designed lock waits stay bounded by the statement deadline alone; database URL
parameters that override deadline policy are rejected as a typed configuration
failure. A live-PostgreSQL integration test proves statement cancellation,
acquisition timeout and deadline-bounded lock waits.

The module entrypoint loader released a concurrency slot at timeout while the
uncancellable dynamic import kept running, so the bound escaped. A slot is now
held until the import settles; the caller is still answered at its own deadline
and a late rejection is never surfaced.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* feat: share MicroVertical API baseline contracts

* feat: factor typed problem details schemas

* Add report-only code quality audits and CI artifacts

* refactor: generate governed clients through shared runtime

* fix: enforce generated seam integrity

* Calibrate quality reports against concrete consumer evidence

* Make resolver calibration fixtures deterministic across installs

* Record native Drizzle adoption and normalize current snapshots

* [codex] make governed read servers thin adapters (#353)

* fix: validate governed seam structure

* fix: bind generated seam validation

* Make local initialization native Effect end to end

* Address audit review findings with focused fixes

* Keep audit reports outside configured source roots

* refactor: make permission clients Effect-only

* refactor: share invariant Effect BFF assembly (#356)

* fix: close generated seam acceptance gaps

* Share Effect workspace discovery between audit models

* Reuse resolver proof helpers in static path analysis

* Replace bootstrap class checks with typed Effect handlers

* Consolidate audit failure reports with native Effect recovery

* refactor: move Auth persistence to native Effect Drizzle

* Use the Better Auth SDK guard at its foreign error boundary

* Reject audit output symlinks into source directories

* fix: adapt assertion redemption to Effect Drizzle

* fix: adapt assertion redemption to Effect Drizzle

* fix: adapt assertion redemption to Effect Drizzle

* Wait for stage user creation to settle before closing its scope

* Use native Effect predicates in runtime and test assertions

* Enforce native Effect interfaces and remove generator Promise bridges

* Keep foreign SDK callbacks compatible with Effect diagnostics

* Close test-local Promise and imported tag assertion bypasses

* Respect tag exemptions in assertion comparisons

* fix(auth): close replay and generated boundary gaps

* test(auth): encode redemption errors through Effect Schema

* refactor: remove action gateway compatibility exports

Use the operation gateway directly in clients, ARES coordination, tests, and Codesmith. Remove the old action names, redundant attempt aliases, and compatibility lint suppression; prevent regeneration with a negative assertion.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(scaffolding): preserve governed client and provider identities

Disambiguate provider suffixes by generator provenance, repair nested helper coverage, share token/path helpers, and document tested owner adaptations and trusted transport configuration.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Verify assertion imports and honor switch tag exemptions

* Preserve tag checks through Rstest assertion exports

* fix: harden governed scaffolds and preserve injectable runtime ownership

Add pinned owner roots to the integration fixture; handle code-only API terminators, independent slots, multiline additions and authentication acceptance. Cache lexical depths, validate typed runtime injection and cover assertion replay.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): vendor @app/effect-rstest and run pilot suites through Rstest projects

Vendor the community port of @effect/vitest for Rstest as a workspace package,
define unit/integration/component Rstest projects for every app package, and
migrate five pilot suites to it.effect / it.live / it.layer with no Promise bridges.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Limit assertion tag detection to compared value projections

* test: assert generated owner uses the governed read adapter

Replace the obsolete direct ReadRuntime source assertion with the shared handler and exact registration wiring. Full isolated migrations, verification and integration tests pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(contracts): match generated Problem Details errors with Effect

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Resolve Promise-returning generic function aliases at port declarations

* fix(tooling): prove generated adapters through shared BFF assembly

Recognize canonical Problem Details factories, prove generated Layer imports and same-module API aliases, and follow the exported assembled handler layer. Keep detached-handler, counterfeit-import, wrong-status and unused-neighbor regression controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(tooling): align published strict API validators with generated reads

Update all three code-tools rule formats to verify canonical same-module API exports and imported GovernedReadLayer bindings. Reject counterfeit imports, shadowed bindings, and unused neighboring APIs; refresh the frozen patch hash and exercise positive and negative controls against every published format.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(party): preserve request validation at Action boundary

Keep Party Command's 200-character correlation limit and map wire payload validation failures to declared 400 problems. Cover both correlation boundaries and invalid contact payloads.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(party): type runtime fixture counter snapshot

Keep TypeScript control-flow inference stable after validation counter assertions.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(api): validate readiness topology and value imports

Use configured BFF prefixes, guard required topology metadata, and reject commented type-only imports using the AST. Preserve public composed business APIs and align generated validators and runtime fixtures with current main.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* wip(merge): partial generator and boundary repair after integrating main #491

* test(rstest): migrate every test to Rstest + @app/effect-rstest and delete the Promise bridges

- all app, tooling, scaffolding and lint-rule tests run through Rstest projects (it.effect / it.live / it.layer)
- remove packages/core-runtime testing/effect-runtime bridges; fixture factories return Effects
- lint: restrict node:test / node:assert / @rstest/core / effect-runtime imports in tests, lint tooling tests
- rstest configs: SWC .mts parser override, core-runtime externals for natively imported generated modules
- no-promise-shaped-port: resolve substitutions through generic object and interface aliases

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: preserve formatter-stable governed API composition

Accept the trusted final Effect identity terminator in repository and published AST validators, with counterfeit and discarded API controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: checkpoint quality purge before main integration

Consolidate duplicate implementations, remove unused public bindings and dependencies, and simplify control flow. First-pass audit and targeted checks recorded; final validation follows main integration.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): close enforcement gaps and verify scoped cleanup

Cover Promise-returning owned test callbacks, preserve synchronous tests, and reap child processes on failure and interruption. Canonicalize temporary fixture paths for macOS lint overrides.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(scaffolding): preserve nested fluent slot calls

Record fluent tail boundaries through the existing protected-character and bracket scanner instead of splitting every newline-dot sequence. Preserve statement grouping and syntax rejection, with nested-chain and protected-text regressions.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* test(auth): distinguish successful navigation from router failure

Restore the router mock's native Promise contract and assert completed submission without an internal-error toast. Cover rejected navigation separately.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): interrupt timed-out layers and verify generated checker scope

Reproduce real hook timeout leakage. Await setup interruption before closing suite resources. Keep generated API validation aligned with source-only workspace boundaries with ignored-artifact and real-positive controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): support schema properties and Effect semantic equality

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(ci): isolate analyzer colors and retain wire codec requirements

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): read subprocess reports independently of CLI banners

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* docs(testing): document local adapter corrections and property APIs

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(lint): track native test APIs inside wrapped suites

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): await timed-out test finalizers before suite release

Also preserve typed startup defects and use the declared API readiness endpoint for browser startup.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(playwright): load Core through native Node TypeScript boundary

Use the supported build.external setting so private Core class identity is preserved and type-only declare fields bypass the incompatible Babel transform order.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect): remove generic Promise adapter helpers

Adapt real driver calls lazily in place and retain typed discovery rejection causes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect): compose native programs and reject Promise round trips

Expose action discovery as an Effect and assert typed failures directly. Reject explicit Effect runners and Promise matcher chains hidden inside test Promise adapters.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): isolate generated validator execution

Exercise generated validator formats against their existing owned workspace instead of racing transient contract bundles in the live source tree. Preserve valid-output and negative enforcement proofs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect): remove browser runtime and loader Promise round trips

Keep browser programs native until router or React execution edges. Exercise the configured runtime through scoped Fibers with deterministic abort/finalizer synchronization and test module timeouts with TestClock.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): remove forced Core serialization

Restore Rstest's native N-1 worker default. Core integrations passed four explicit nine-worker stress runs, then all workspace integrations passed with nine workers after removing the override.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: checkpoint exhaustive quality purge and enforcement

Publish the second cleanup pass for incremental review. Dead-code and clone reductions, strict audit enforcement, and switching regression tests are checkpointed together. Cross-generator integration and aggregate validation remain in progress; this checkpoint is not merge-ready.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): recognize genuine Playwright extended test bindings

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): close destructured and partial tag assertion gaps

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: reconcile purge contracts and shared build boundaries

Validate mounted gateway issuer bindings and exact quality command wiring. Expose the shared build identity helper through its supported package boundary, retain precise auth catalog types, and restore historical specification references.\n\nFocused boundary and helper tests: 54 passed; workspace contract and scoped typed lint passed. Full production release remains blocked by source-revision metadata; fixture cleanup and final audit integration remain pending.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(e2e): enforce isolated parallel browser coverage in CI

Own authentication identities per worker; bound native acquisition without abandoning scoped cleanup. Wait for the real hydrated account menu before post-reload interaction. Run all browser tests with N-1 workers and no retries locally and in the integration gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: delete orphaned Party payload type surfaces

Remove six unused type declarations and collapse schema-only forwarding bindings. Preserve live schemas, action behavior, and the shared payload type with real consumers. Focused matching/correction Node tests: 19 passed; scoped typed lint passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: keep fixture cleanup Effect-native and ordered

Return typed sequential cleanup Effects; run them only at existing managed Node test boundaries. Preserve first-failure short circuit and child-before-parent order, with three independent regression controls. Replace six preexisting manual error-tag assertions with Effect predicates.

Focused cleanup tests and scoped typed lint pass; implementation root typecheck passed before concurrent generated-contract changes. Live database integration remains pending and no shared databases were used for this checkpoint.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect): assert object variants through native schemas and predicates

Reject expected object discriminants in equality and containment matchers, including Node deep assertions. Migrate 59 assertions across 21 suites while preserving exact payload and extra-field checks. Add ten failing provenance-aware matcher regressions and migrate the old positive fixture.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(integration): scope Party fixture mutations to owned records

Prevent parallel governed tests from having their customer roles ended by the database-boundary fixture. Also scope delivery-purpose updates/readback and the billing constraint probe. Preserve independent tenant rows with full-row regression snapshots; both defects reproduced within owned tenants before correction and all five Party integrations pass five parallel repeats.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: consolidate engagement lifecycle registration

Share exact governed write registration across four distinct action entrypoints while preserving concrete schemas, permission targets, transaction services and archive state transitions. Add registration contract assertions alongside existing lifecycle and command regressions.

Validation: 36 focused tests pass; scoped lint and format pass. Generated transport and strict CLI test integration continue separately; no full-tree completion claim.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test: use a real server environment subprocess fixture

Replace evaluated child-source imports with a static-import fixture while retaining the foreign working directory and all three configuration-path assertions. Keep the authentication ROOT_ENV_PATH export: the actual test consumes it, so deletion would be incorrect.

Validation: all four root environment tests, scoped lint and format pass. Fresh combined analyzer verification follows remaining in-flight integration.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): recognize native test hooks and property tag assertions

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect-rstest): pin upstream table row semantics

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): inspect inherited and applied generic Promise ports

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: consolidate governed transport and preserve strict owner contracts

Share problem mapping and Effect BFF transport across 36 generated adapters, keep authorization and schema provenance fail-closed, and recognize owner-local lifecycle registrations. Move private search normalization outside the generated provider surface.\n\nCo-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: finish baseline purge and restore strict quality tooling

Remove unreachable additional-Shell validation, preserve nested fluent-slot semantics and starter parity, repair pinned i18n and declaration defects without version changes, and enforce full audit source coverage with regression controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test: accept zero-diagnostic Oxlint summaries in CI

Preserve exact clean-success and nonzero violation/crash checks across formatter environments; add positive and negative summary controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: share typed scaffold error normalization

Keep concrete owner failures while centralizing optional-cause projection and synchronous failure normalization. Preserve identity and strict fallback behavior with regression controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: remove redundant outbox error schema witnesses

Use concrete tagged errors under the one-class-per-file rule. Preserve public contracts and fix persistence error construction's missing local runtime binding. Cover serialization, cross-schema rejection, yieldability, private causes and sanitization.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: align generated API checks with Cloudflare build output

Preserve authored API enforcement while matching the live checker's generated dist-cloudflare exclusion. Prove both behaviors across all three published scaffold formats after real production builds.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* chore: upgrade PostgreSQL to 18 (#505)

* chore: upgrade PostgreSQL to 18

* fix(ci): align PostgreSQL 18 Zerops contracts

* fix(ci): forward deployment impact flags

* refactor(test): replace vendored runner with patched effect-rstest

Adopt the immutable upstream package and remove the owned adapter. Carry the generic conformance fixes from ScriptedAlchemy/effect-rstest#4 in one temporary pnpm patch, tracked for removal by #507. Update actual imports and lint provenance without compatibility aliases or runner wrappers.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(auth): refresh stage rollout inventory baseline

* fix(quality): model native Rstest project environments

Follow exported static project configurations with source evidence and pinned-Knip positive and negative controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): inspect proven asymmetric tag assertions

Resolve framework objectContaining and arrayContaining expected values while preserving lexical identity, mutation guards, ADT exemptions and payload semantics.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): recognize negated asymmetric tag assertions

Accept one static expect.not modifier without weakening helper provenance or mutation guards. Add ten failing-before positive cases and foreign, shadowed, mutated, payload and unsupported-modifier controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Petr Glaser <syreanis+1@gmail.com>
Co-authored-by: BleedingDev <12586960+BleedingDev@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
JiProchazka added a commit to TechsioCZ/ontos that referenced this pull request Sep 8, 2026
* fix(database-audit): tighten view privilege evidence

* fix(database-audit): include inherited view-owner authority

* docs: finish authority cleanup and upgrade pnpm

* test: align Locki pnpm pin with 11.25.0

* fix: align authorization rollout ownership

* fix: align stage authorization approval reference

* docs(skills): preserve explicit OntOS priming guardrails

* docs(skills): restore transitive review guidance

* docs(skills): restore explicit implementation guardrails

* docs(skills): restore explicit planning guidance

* docs(skills): keep generator discovery source-owned

* docs(skills): retain focused branch divergence check

* docs: retain support impersonation configuration

* docs: restore pinned MicroVertical creation command

* ci: scope push checks to main and stage

* docs: add Effect v4 anti-pattern audit

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* feat(core): define application composition contract

* fix(core): satisfy composition contract lint

* fix(core): type composition rejection and artifact ownership

* fix(core): validate complete observed composition

* fix(core): verify remote composition evidence

* Use Effect non-empty string schema

* Use Effect orders for composition sorting

* Use Effect codecs and typed composition validation

* Require development evidence for loopback composition artifacts

* Default composition error code through Effect Schema

* feat(party-registry): implement issue 179 and all subissues

Deliver the approved V1 Party identity, evidence, matching, counterparty, search and ARES boundaries with the breaking Contacts engagement cutover.

Includes governed public Actions/Reads, worker deployment, database constraints and RLS, generator support, and per-family regression coverage. Production merge remains disabled per ADR 0018. Live PostgreSQL and SpiceDB verification remains environment-blocked.

* fix(build): verify API-only release execution assets

* feat(db): upgrade to Drizzle 1.0.0-rc.4 and Better Auth 1.7.2

Move all three schema owners (Core, Shell Auth, Contacts) to Drizzle ORM/Kit
1.0.0-rc.4 and Better Auth 1.7.2 instead of only documenting readiness (#98).

- Convert migration histories to the v3 folder layout with `drizzle-kit up`;
  every migration.sql stays byte-identical to the previous SQL file.
- Normalize converted snapshots so the rc.4 reader stops emitting false DDL
  (drizzle-team/drizzle-orm#6020); `db:generate` is clean for all owners.
- Replace RQB v1 `relations()` with `defineRelations`, type databases as
  `NodePgDatabase<typeof relations>`, and use `withRLS` instead of the
  deprecated `enableRLS` wrapper (drops `enableGovernedRls`).
- Switch to `@better-auth/drizzle-adapter/relations-v2` and add the required
  `account.issuer` column with a guarded backfill and unique
  (issuer, account_id) index.
- Add `db:check` (commutativity) scripts per owner and at the root.
- Document the cohort, layout, and re-proof steps in
  docs/architecture/DRIZZLE_V1_UPGRADE.md; update DATABASE, DEPLOYMENT, README.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(auth): keep account.issuer expand-only with an insert compat trigger

Better Auth 1.6 writers do not supply `issuer`, so `SET NOT NULL` alone
would break account creation while the previous Shell release still runs
against the expanded schema (Deployment step 7). Install a BEFORE INSERT
trigger that derives `issuer` with the backfill rule when it is missing;
drop it in a later contraction once no 1.6 writer remains.

Proven on a fresh database: migrate + verify pass, inserts without
`issuer` as the runtime role get `local:credential` / `local:oauth:<id>`,
and the Shell integration suite passes 8/8.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(docs,topology): retarget stage replay migration and drop pinned versions from DATABASE.md

- topology/authorization-contexts/stage.json pointed at the removed
  verticals/contacts/drizzle/0003_sticky_maverick.sql; point it at the v1
  folder so authorization readiness can read the replay migration.
- DATABASE.md described the cohort with exact Drizzle and Better Auth
  versions, which README forbids for current docs; keep the cohort
  invariant and defer exact versions to the package manifests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(ci): restore issue 179 verification gates

* fix(ci): derive workerd proof route from topology

* feat(lint): enforce Effect audit with 71 diagnostic-only Oxlint rules

Add strict rule registration, production-default fixtures, fail-closed reporting, and audit coverage. Preserve application violations and forced framework boundaries; no autofixes or application changes.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* docs(lint): refresh enforcement snapshot against current main

Record 3,909 diagnostics and 155 passing tooling tests; distinguish pnpm's stale-install blocker from intentional application lint failures.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* test(lint): run rule gates in CI and preserve workspace identity contract

Add an independent CI implementation gate and keep a domain-helper fixture neutral without changing its assertion or application code.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(lint): classify nested scripts and import fixture rules by URL

Cover relative and absolute workspace script paths, default and opt-in rule scope, and isolated ESM discovery from URL-sensitive paths. Preserve all application diagnostics and reporting-only policy scope.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* docs(lint): refresh rebased enforcement snapshot and rule totals

Record the pinned 9adca84 application tree and 1531cfb lint implementation: 5,286 diagnostics across 753 scanned files, including Party Registry. Refresh every catalog row from the validated JSON report and document the 162-test clean-install CI evidence.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(lint): launch Oxlint portably and align script fix scope

Run the package JavaScript entry point with process.execPath instead of a POSIX-only shim. Add real-process and command-scope regressions; all 164 tests pass and the diagnostic multiset remains unchanged. Extend the existing opt-in lint:fix command to scripts without running fixes or changing diagnostic-only rules.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* [codex] merge Contacts into Party Registry (#395)

* fix: merge Contacts into Party Registry

* fix: pass PR checks and repair Party Registry route

* fix: repair CI configuration and promise bridges

* fix: keep Party scaffold deploy modes in sync

* feat(core): add typed persistence attempt constructor (#362)

* feat: add shared Effect BFF client factory

* feat: share operation gateway runtime (#361)

* feat: centralize PostgreSQL failure classification

* test: enforce shared client type proof

* feat: add shared Effect BFF client factory

* test: enforce shared client type proof

* feat: extract shared gateway principal verifier

* refactor(party-registry): decompose API runtime (#355)

* style(party-registry): format API runtime

* fix(core): expose persistence adapter to worker builds (#362)

* feat: centralize PostgreSQL failure classification

* feat(core): compose owner-configured mutation failures (#364)

* feat(core-db): add the Core-owned transaction bridge

One bridge runs an Effect transaction body inside the Drizzle Promise callback, keeps the caller context, preserves the original Cause on failure, distinguishes its own rollback sentinel from driver failures, and settles interruption before the connection is released.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* test: link shared verifier in generated owner fixture

* [codex] centralize MicroVertical HTTP authentication (#351)

* fix(transactions): run every Core transaction body through the bridge

Actions, governed reads and the search snapshot no longer run Effects inside the Drizzle Promise callback. Typed failures, defects and interruption keep their original Cause; only genuine driver rejections become transaction failures with the rejection retained as cause; the search snapshot keeps repeatable read.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* feat(actions): add governed Action HTTP runner

* fix(security): observe signing-key rotation and never cache issued API-key secrets

The gateway issuer loaded configuration and imported the private key once per
process behind Effect.cached, so a failed import was memoized for the lifetime
and a rotated ONTOS_GATEWAY_PRIVATE_JWK was not observed without a restart.
Configuration is loaded per issuance again; the key import is reused only while
the sha256(kid, x, d) fingerprint of the JWK matches, is shared by concurrent
issuances and evicted on failure.

Responses that return a freshly issued API-key secret now carry
Cache-Control: no-store through the BFF pre-response seam.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(errors): keep governed-read interruption and never discard denial-evidence failures

A governed read that is interrupted now ends interrupted, after the driver settles, instead of surfacing as a handler execution error. When persisting denial evidence fails or dies, the caller still receives the original ReadPermissionDenied and the evidence failure is combined into the Cause rather than replacing or hiding it.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(ownership): retain repository failure causes in class-private state

ActionTransactionError and ActionInvocationPersistenceError keep their original defect in a private #cause field set once by a Core-owned factory and read only through internal readers. The reflectable ontosRepositoryFailureCause property is gone, so no other module can read, forge, or clone the retained cause.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(availability): bound every PostgreSQL pool with shared deadlines and hold module-load permits to settlement

The three physical pool owners (Core, Shell auth, Party Registry) built
new Pool(configuration) with no acquisition timeout and no statement deadline.
One shared pool configuration now gives every owner an acquisition timeout and
a statement_timeout; lock_timeout is applied only when explicitly opted in so
designed lock waits stay bounded by the statement deadline alone; database URL
parameters that override deadline policy are rejected as a typed configuration
failure. A live-PostgreSQL integration test proves statement cancellation,
acquisition timeout and deadline-bounded lock waits.

The module entrypoint loader released a concurrency slot at timeout while the
uncancellable dynamic import kept running, so the bound escaped. A slot is now
held until the import settles; the caller is still answered at its own deadline
and a late rejection is never surfaced.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* feat: share MicroVertical API baseline contracts

* feat: factor typed problem details schemas

* Add report-only code quality audits and CI artifacts

* refactor: generate governed clients through shared runtime

* fix: enforce generated seam integrity

* Calibrate quality reports against concrete consumer evidence

* Make resolver calibration fixtures deterministic across installs

* Record native Drizzle adoption and normalize current snapshots

* [codex] make governed read servers thin adapters (#353)

* fix: validate governed seam structure

* fix: bind generated seam validation

* Make local initialization native Effect end to end

* Address audit review findings with focused fixes

* Keep audit reports outside configured source roots

* refactor: make permission clients Effect-only

* refactor: share invariant Effect BFF assembly (#356)

* fix: close generated seam acceptance gaps

* Share Effect workspace discovery between audit models

* Reuse resolver proof helpers in static path analysis

* Replace bootstrap class checks with typed Effect handlers

* Consolidate audit failure reports with native Effect recovery

* refactor: move Auth persistence to native Effect Drizzle

* Use the Better Auth SDK guard at its foreign error boundary

* Reject audit output symlinks into source directories

* fix: adapt assertion redemption to Effect Drizzle

* fix: adapt assertion redemption to Effect Drizzle

* fix: adapt assertion redemption to Effect Drizzle

* Wait for stage user creation to settle before closing its scope

* Use native Effect predicates in runtime and test assertions

* Enforce native Effect interfaces and remove generator Promise bridges

* Keep foreign SDK callbacks compatible with Effect diagnostics

* Close test-local Promise and imported tag assertion bypasses

* Respect tag exemptions in assertion comparisons

* fix(auth): close replay and generated boundary gaps

* test(auth): encode redemption errors through Effect Schema

* refactor: remove action gateway compatibility exports

Use the operation gateway directly in clients, ARES coordination, tests, and Codesmith. Remove the old action names, redundant attempt aliases, and compatibility lint suppression; prevent regeneration with a negative assertion.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(scaffolding): preserve governed client and provider identities

Disambiguate provider suffixes by generator provenance, repair nested helper coverage, share token/path helpers, and document tested owner adaptations and trusted transport configuration.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Verify assertion imports and honor switch tag exemptions

* Preserve tag checks through Rstest assertion exports

* fix: harden governed scaffolds and preserve injectable runtime ownership

Add pinned owner roots to the integration fixture; handle code-only API terminators, independent slots, multiline additions and authentication acceptance. Cache lexical depths, validate typed runtime injection and cover assertion replay.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): vendor @app/effect-rstest and run pilot suites through Rstest projects

Vendor the community port of @effect/vitest for Rstest as a workspace package,
define unit/integration/component Rstest projects for every app package, and
migrate five pilot suites to it.effect / it.live / it.layer with no Promise bridges.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Limit assertion tag detection to compared value projections

* test: assert generated owner uses the governed read adapter

Replace the obsolete direct ReadRuntime source assertion with the shared handler and exact registration wiring. Full isolated migrations, verification and integration tests pass.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(contracts): match generated Problem Details errors with Effect

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Resolve Promise-returning generic function aliases at port declarations

* fix(tooling): prove generated adapters through shared BFF assembly

Recognize canonical Problem Details factories, prove generated Layer imports and same-module API aliases, and follow the exported assembled handler layer. Keep detached-handler, counterfeit-import, wrong-status and unused-neighbor regression controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(tooling): align published strict API validators with generated reads

Update all three code-tools rule formats to verify canonical same-module API exports and imported GovernedReadLayer bindings. Reject counterfeit imports, shadowed bindings, and unused neighboring APIs; refresh the frozen patch hash and exercise positive and negative controls against every published format.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(party): preserve request validation at Action boundary

Keep Party Command's 200-character correlation limit and map wire payload validation failures to declared 400 problems. Cover both correlation boundaries and invalid contact payloads.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(party): type runtime fixture counter snapshot

Keep TypeScript control-flow inference stable after validation counter assertions.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(api): validate readiness topology and value imports

Use configured BFF prefixes, guard required topology metadata, and reject commented type-only imports using the AST. Preserve public composed business APIs and align generated validators and runtime fixtures with current main.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* wip(merge): partial generator and boundary repair after integrating main #491

* test(rstest): migrate every test to Rstest + @app/effect-rstest and delete the Promise bridges

- all app, tooling, scaffolding and lint-rule tests run through Rstest projects (it.effect / it.live / it.layer)
- remove packages/core-runtime testing/effect-runtime bridges; fixture factories return Effects
- lint: restrict node:test / node:assert / @rstest/core / effect-runtime imports in tests, lint tooling tests
- rstest configs: SWC .mts parser override, core-runtime externals for natively imported generated modules
- no-promise-shaped-port: resolve substitutions through generic object and interface aliases

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: preserve formatter-stable governed API composition

Accept the trusted final Effect identity terminator in repository and published AST validators, with counterfeit and discarded API controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: checkpoint quality purge before main integration

Consolidate duplicate implementations, remove unused public bindings and dependencies, and simplify control flow. First-pass audit and targeted checks recorded; final validation follows main integration.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): close enforcement gaps and verify scoped cleanup

Cover Promise-returning owned test callbacks, preserve synchronous tests, and reap child processes on failure and interruption. Canonicalize temporary fixture paths for macOS lint overrides.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(scaffolding): preserve nested fluent slot calls

Record fluent tail boundaries through the existing protected-character and bracket scanner instead of splitting every newline-dot sequence. Preserve statement grouping and syntax rejection, with nested-chain and protected-text regressions.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* test(auth): distinguish successful navigation from router failure

Restore the router mock's native Promise contract and assert completed submission without an internal-error toast. Cover rejected navigation separately.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): interrupt timed-out layers and verify generated checker scope

Reproduce real hook timeout leakage. Await setup interruption before closing suite resources. Keep generated API validation aligned with source-only workspace boundaries with ignored-artifact and real-positive controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): support schema properties and Effect semantic equality

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(ci): isolate analyzer colors and retain wire codec requirements

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): read subprocess reports independently of CLI banners

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* docs(testing): document local adapter corrections and property APIs

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(lint): track native test APIs inside wrapped suites

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): await timed-out test finalizers before suite release

Also preserve typed startup defects and use the declared API readiness endpoint for browser startup.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(playwright): load Core through native Node TypeScript boundary

Use the supported build.external setting so private Core class identity is preserved and type-only declare fields bypass the incompatible Babel transform order.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect): remove generic Promise adapter helpers

Adapt real driver calls lazily in place and retain typed discovery rejection causes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect): compose native programs and reject Promise round trips

Expose action discovery as an Effect and assert typed failures directly. Reject explicit Effect runners and Promise matcher chains hidden inside test Promise adapters.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): isolate generated validator execution

Exercise generated validator formats against their existing owned workspace instead of racing transient contract bundles in the live source tree. Preserve valid-output and negative enforcement proofs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect): remove browser runtime and loader Promise round trips

Keep browser programs native until router or React execution edges. Exercise the configured runtime through scoped Fibers with deterministic abort/finalizer synchronization and test module timeouts with TestClock.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(rstest): remove forced Core serialization

Restore Rstest's native N-1 worker default. Core integrations passed four explicit nine-worker stress runs, then all workspace integrations passed with nine workers after removing the override.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: checkpoint exhaustive quality purge and enforcement

Publish the second cleanup pass for incremental review. Dead-code and clone reductions, strict audit enforcement, and switching regression tests are checkpointed together. Cross-generator integration and aggregate validation remain in progress; this checkpoint is not merge-ready.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): recognize genuine Playwright extended test bindings

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): close destructured and partial tag assertion gaps

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: reconcile purge contracts and shared build boundaries

Validate mounted gateway issuer bindings and exact quality command wiring. Expose the shared build identity helper through its supported package boundary, retain precise auth catalog types, and restore historical specification references.\n\nFocused boundary and helper tests: 54 passed; workspace contract and scoped typed lint passed. Full production release remains blocked by source-revision metadata; fixture cleanup and final audit integration remain pending.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(e2e): enforce isolated parallel browser coverage in CI

Own authentication identities per worker; bound native acquisition without abandoning scoped cleanup. Wait for the real hydrated account menu before post-reload interaction. Run all browser tests with N-1 workers and no retries locally and in the integration gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: delete orphaned Party payload type surfaces

Remove six unused type declarations and collapse schema-only forwarding bindings. Preserve live schemas, action behavior, and the shared payload type with real consumers. Focused matching/correction Node tests: 19 passed; scoped typed lint passed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: keep fixture cleanup Effect-native and ordered

Return typed sequential cleanup Effects; run them only at existing managed Node test boundaries. Preserve first-failure short circuit and child-before-parent order, with three independent regression controls. Replace six preexisting manual error-tag assertions with Effect predicates.

Focused cleanup tests and scoped typed lint pass; implementation root typecheck passed before concurrent generated-contract changes. Live database integration remains pending and no shared databases were used for this checkpoint.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect): assert object variants through native schemas and predicates

Reject expected object discriminants in equality and containment matchers, including Node deep assertions. Migrate 59 assertions across 21 suites while preserving exact payload and extra-field checks. Add ten failing provenance-aware matcher regressions and migrate the old positive fixture.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(integration): scope Party fixture mutations to owned records

Prevent parallel governed tests from having their customer roles ended by the database-boundary fixture. Also scope delivery-purpose updates/readback and the billing constraint probe. Preserve independent tenant rows with full-row regression snapshots; both defects reproduced within owned tenants before correction and all five Party integrations pass five parallel repeats.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: consolidate engagement lifecycle registration

Share exact governed write registration across four distinct action entrypoints while preserving concrete schemas, permission targets, transaction services and archive state transitions. Add registration contract assertions alongside existing lifecycle and command regressions.

Validation: 36 focused tests pass; scoped lint and format pass. Generated transport and strict CLI test integration continue separately; no full-tree completion claim.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test: use a real server environment subprocess fixture

Replace evaluated child-source imports with a static-import fixture while retaining the foreign working directory and all three configuration-path assertions. Keep the authentication ROOT_ENV_PATH export: the actual test consumes it, so deletion would be incorrect.

Validation: all four root environment tests, scoped lint and format pass. Fresh combined analyzer verification follows remaining in-flight integration.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): recognize native test hooks and property tag assertions

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(effect-rstest): pin upstream table row semantics

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): inspect inherited and applied generic Promise ports

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: consolidate governed transport and preserve strict owner contracts

Share problem mapping and Effect BFF transport across 36 generated adapters, keep authorization and schema provenance fail-closed, and recognize owner-local lifecycle registrations. Move private search normalization outside the generated provider surface.\n\nCo-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: finish baseline purge and restore strict quality tooling

Remove unreachable additional-Shell validation, preserve nested fluent-slot semantics and starter parity, repair pinned i18n and declaration defects without version changes, and enforce full audit source coverage with regression controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test: accept zero-diagnostic Oxlint summaries in CI

Preserve exact clean-success and nonzero violation/crash checks across formatter environments; add positive and negative summary controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: share typed scaffold error normalization

Keep concrete owner failures while centralizing optional-cause projection and synchronous failure normalization. Preserve identity and strict fallback behavior with regression controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* refactor: remove redundant outbox error schema witnesses

Use concrete tagged errors under the one-class-per-file rule. Preserve public contracts and fix persistence error construction's missing local runtime binding. Cover serialization, cross-schema rejection, yieldability, private causes and sanitization.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix: align generated API checks with Cloudflare build output

Preserve authored API enforcement while matching the live checker's generated dist-cloudflare exclusion. Prove both behaviors across all three published scaffold formats after real production builds.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* chore: upgrade PostgreSQL to 18 (#505)

* chore: upgrade PostgreSQL to 18

* fix(ci): align PostgreSQL 18 Zerops contracts

* fix(ci): forward deployment impact flags

* refactor(test): replace vendored runner with patched effect-rstest

Adopt the immutable upstream package and remove the owned adapter. Carry the generic conformance fixes from ScriptedAlchemy/effect-rstest#4 in one temporary pnpm patch, tracked for removal by #507. Update actual imports and lint provenance without compatibility aliases or runner wrappers.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(auth): refresh stage rollout inventory baseline

* fix(quality): model native Rstest project environments

Follow exported static project configurations with source evidence and pinned-Knip positive and negative controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): inspect proven asymmetric tag assertions

Resolve framework objectContaining and arrayContaining expected values while preserving lexical identity, mutation guards, ADT exemptions and payload semantics.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(lint): recognize negated asymmetric tag assertions

Accept one static expect.not modifier without weakening helper provenance or mutation guards. Add ten failing-before positive cases and foreign, shadowed, mutated, payload and unsupported-modifier controls.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(build): keep dependency reset bootstrap standalone

---------

Co-authored-by: Petr Glaser <syreanis+1@gmail.com>
Co-authored-by: BleedingDev <12586960+BleedingDev@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
@ScriptedAlchemy
ScriptedAlchemy merged commit f29b3f4 into ScriptedAlchemy:main Sep 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants