fix: bind Web Push mutations to exact authority

WP-01: a CAS receipt is only evidence when it names the expected key and the
exact next revision. Write and remove now share one validator, so a stale or
arbitrary repository receipt can no longer be packaged as a confirmed control.

WP-05: a pre-aborted command records the operation the caller requested instead
of always reporting an inspection.

WP-06: bounded fan-out is reported honestly. The subscriptionchange client
handoff and the notification cleanup both emit countBucket and truncated, and an
incomplete cleanup returns { complete: false } and is observed as DEGRADED
separately from revoke authority.

WP-07: the user-visible native notification effect is tracked through
NOT_APPLIED, MAYBE_APPLIED and CONFIRMED phases and surfaced as observation
evidence, never as retry authorization.

WP-02, WP-03 and WP-04 stay open: they need the V2 wire protocol with server
request-shape negotiation, which belongs to the versioned-migration task rather
than this correctness pass. The ledger records them as DEFERRED_TO_MIGRATION.

Web Push remains NOT_SELECTED and AVAILABLE_NOT_COMPOSED.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
DongHyeonka
2026-08-14 00:34:09 +09:00
co-authored by Claude Opus 5
parent 58efe6ddbd
commit fce8e046ea
9 changed files with 170 additions and 44 deletions
+31
View File
@@ -42,6 +42,37 @@ function manualScheduler() {
}
describe("Web Push durable control fence", () => {
it.each([0, 2, 3, 9_999])(
"rejects a CAS receipt that is not the exact next revision (%i)",
async (revision) => {
// WP-01. Only the exact next revision is evidence that this command
// actually wrote the control it claims to have written.
const dependencies = createFakePushControlStoreDependencies();
const repository = dependencies.repository;
const compareAndSwap = repository.compareAndSwap.bind(repository);
repository.compareAndSwap = async (input) => {
const written = await compareAndSwap(input);
return written.ok
? {
ok: true as const,
value: { ...written.value, revision },
}
: written;
};
const store = createPushAssociationFenceStore(dependencies);
await expect(
store.prepare({
authority: firstAuthority,
updatedAt: "2026-07-28T00:00:00.000Z",
}),
).resolves.toMatchObject({
ok: false,
error: { code: "CONTROL_CORRUPT" },
});
},
);
it("CASes UNASSOCIATED to ACTIVE and prevents tombstone resurrection", async () => {
const store = createPushAssociationFenceStore(
createFakePushControlStoreDependencies(),