test(shared-fs): probe split-plane adaptive content custody - #343
peerbit-org wants to merge 1 commit into
Conversation
New released-cohort rebaseline: both live modes passPublished as peerbit-org on experimental branch This keeps the dependency rebaseline separate from this PR's test-only head. It does not merge the held cohort upgrade or enable production adaptive replication. This PR's existing CI is for its old dependency head, not validation of this new branch. One plain pnpm install after pinning peerbit 5.4.1 / document 15.0.32 / shared-log 16.0.29 / program 6.0.59 / trusted-network 6.0.130. No dedupe; only the shared-fs library lockfile importer changed. The five measured harness/helper source hashes are unchanged. Both full and adaptive ran once, sequentially, with the original deadlines and no retries.
Independent audit confirmed raw report gates, offline identities/bytes, source hashes and phase timings. Additional checks: 12 analysis tests, 33 CLI tests, library/CLI builds, standalone TypeScript, lint/format and package exclusion all pass. No full new-cohort shared-fs suite or cross-OS/N=3/real-host campaign is claimed. One integration concern remains: Raw files are retained locally under |
|
N=3 follow-up is published on experimental branch Complete N=3 results, profile interpretation, source/lock/log hashes and reproduction.
Keep this PR draft and adaptive production integration disabled. The successful prior N=2 rebaseline is not a successful N=3 adaptive result. All git/GitHub actions used verified |
|
Bounded diagnostics follow-up published on the separate experimental branch, exact head Diagnostic fields, stop phases, limits and validation.
Old run source remains at15f40b98; raw failures unchanged. No controller policy, production code, dependency install/dedupe, merge, or release. Full details and source have been sent directly upstream; waiting for its coherent published cohort. All git/GitHub actions verified peerbit-org. |
Scope
Draft, test-only split metadata/content-plane design and opt-in experiment. No production schema, address, ACL, replication default, dependency, or published package code changes. Empty changeset: no release bump.
The intended boundary keeps all namespace/version metadata local while independently placing content chunks. This prototype uses immutable manifests, not the actual shared-fs namespace or concurrent-write semantics. The design documents migration, uncertain two-log outcomes, exact persisted-entry receipt ordering, source-retirement fencing, authorization/encryption, soft log-byte budgets, and fail-closed physical GC.
Experiment
Five independent disk-backed local processes: publisher plus 3→4→3 custodians, 24 files/42 chunks, experimental N=2, full-control vs unequal-budget adaptive placement. Intended final gates include a demonstrably missing-content read, renewed actual-entry receipts, same-identity offline reopen, local content verification, and natural process exit. Publisher copies never count toward remote custody. No retries or forced successful exits.
Results: both corrected live runs FAILED
Existing loaded library cohort: peerbit 5.3.35 / document 15.0.16 / shared-log 16.0.15, macOS 26.6.2 arm64, Node 24.13.1. This is NOT a test of the newer upstream cohort. No install/dedupe or held-upgrade-worktree mutation.
The design document includes exact event timings, entry hashes, source/lockfile/log hashes, loaded package provenance, raw-log locations and reproduction commands. It distinguishes unpublished local commits from acknowledged data loss. Do not merge/enable production adaptive sharding based on these results; rebaseline on the coherent newer upstream cohort first.
Validation
This draft is authored and published as
peerbit-orgusing the repository.envrc. Main checkout and unrelated worktrees remain unchanged. No release or upstream message sent.