Skip to content

fix(coordinator): preserve acknowledged state across access changes - #28

Merged
Mathieu2301 merged 3 commits into
mainfrom
nox/sdk-confirmed-state-20261003
Oct 3, 2026
Merged

Mathieu2301 merged 3 commits into
mainfrom
nox/sdk-confirmed-state-20261003

Conversation

@Mathieu2301

Copy link
Copy Markdown
Member

Summary

  • Preserve relay-acknowledged coordinator state across ACL/event/function re-declarations and reconnects, instead of replaying initial configuration values.
  • Keep explicit state replacement authoritative; do not replay rejected or outcome-unknown mutations or application calls. Handle pending ACK races without blocking access revocation.
  • Restore acknowledged deletions after activation and document the protocol-limited transient value window.
  • Make the starter binary regression build its own prerequisite (independently reproduced missing-dist failure in a fresh checkout).
  • Prepare miakapi@4.0.0-alpha.1; CLI stays at alpha.9.

Evidence

  • Original owner/guest integration: acknowledged temperature 22 reverted to 21 after guest access withdrawal, with the owner view incorrectly marked current.
  • 20 focused regression tests, root 429 tests, 11 pinned coordinator contracts and Node/browser/pack checks passed independently before version preparation.
  • Actual local Go relay + pinned browser SDK + trusted shell + isolated app: two device/language groups, each with owner, guest and outsider, now pass state projection, owner-only synthetic action, dynamic withdrawal/re-grant, same-socket reauthentication, identity switch and sign-out.
  • Fixture-only lease corrected from 30s to 31s client maximum to cover the relay fixture clock offset; no SDK assertion weakened. No production credential or actual resident identity used.
  • Final root and all-package checks run before merge; CI required.

Limits / deployment

  • No live home, device, real account, coordinator deployment or platform/browser bundle changed by this PR.
  • STATE_SYNC cannot encode an owned path without a value; an acknowledged deletion is restored just after activation. A brief declared-value window remains and is documented.
  • Unknown outcomes fall back to last acknowledged state, not inferred success. Real authenticated resident acceptance remains open.

Mathieu2301 and others added 3 commits October 3, 2026 11:34
RFC 0001 §7.5 resends all five slices on every declaration change, and
STATE_SYNC carries a value for each owned path. The SDK resent the configured
values, so an ACL-only change (revoking one guest) rolled every resident's view
back to the initial state while reporting it current (reproduced with the real
Go relay and browser host: owner 22 -> 21, stale:false).

- StateManager records each batch the relay acknowledges (STATE_SET_OK),
  including one abandoned after handoff, tagged with the state-slice revision
  it targeted and its send order. Rejected and outcome_unknown batches are never
  recorded, so nothing unacknowledged is replayed.
- DeclarationManager stages those values in every re-declaration of the same
  state revision (ACL, events, functions, reconnect, new epoch). An explicit
  state.declare/configure carries a new revision and stays authoritative; a
  rejected one leaves acknowledged values in force.
- A batch pending when a re-declaration starts is acknowledged before that
  STATE_SYNC is (per-connection order), so the unhanded transaction is
  restarted with the acknowledged value instead of activating the stale one.
  Revocation never waits for a missing ACK. A protocol-violating late ACK after
  handoff triggers one follow-up transaction.
- STATE_SYNC cannot declare a valueless path, so an acknowledged deletion is
  reapplied by one SDK-sent STATE_SET delete right after activation; a refusal
  is reported on coordinator.errors and the relay value becomes acknowledged.
- 20 regression tests; README documents the behavior and the deletion window.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Mathieu2301
Mathieu2301 merged commit abe5a65 into main Oct 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant