Handoff: Finish atomic retirement-safe projection commits and the round-eight gate
RE-VERIFY: This is a write-time snapshot for supervised lane fx1203o. Re-check https://github.com/CodexCoder21Organization/UrlResolver/pull/1203 (state, head, queue entry) and fetch its live branch before editing or pushing. Another tests-only lane may update the branch. The supervisor alone reviews and makes merge decisions.
Mission
The user asked to close G1, G2 and M1 from the seventh production review, carry two review tests unchanged, prove the local gate, push and stop. Scope: https://github.com/CodexCoder21Organization/UrlResolver/pull/1203 at 1004cec9 or newer. No agents, enqueue/dequeue/merge, deployment, restart or Maven publishing. Local tests only. Never weaken a test, lower stress iterations, increase timeouts or retry past a failure. Hard lane time box90 minutes. This handoff records partial progress, not completion of the requested gate.
Findings and work
- G1 is proven by the unchanged public test: a retired generation held in the lineage diagnostic overwrites replacement300 with200. The response generation check precedes observeLineage's off-guard diagnostic and applySnapshot; it reads the replacement revision base after retirement.
- G2 is proven by the unchanged public test: a listener on the first delta retires and replaces the binding; the old frame's remaining delta changes new-item to old-item. applyPushFrame validates binding only before entering application callbacks, not at every state commit.
- M1 is proven by a new real-server public command test: onWriteTimestamp throws after the server write, awaitTerminal returns FAILED rather than SUCCEEDED. drainStates catches that failure before terminalReached and synthesizes FAILED with TRANSIENT retryability. The partial fix retains the actual SUCCEEDED state/timestamp exactly once and emits ProjectionCommandTimestampInstallationFailedEffect with the full original local error. Listener/effect work stays off applyLock. README and the older timestamp-failure test now specify the requested success contract.
- G1/G2 API constraint: Observable0.3.22 has only applySnapshot/applyDelta/applyListDelta; each synchronously combines state mutation and notifications, and value equality can also run application code. Holding lifecycleLock around these calls violates the brief's off-guard application rule. Merely adding another off-guard validity check does not make retirement atomic. A serial application owner cannot hold replacement snapshot completion behind a listener that synchronously retires/reactivates and waits for that replacement. An upstream staged preparation/commit/notification API is the identified path; publishing is explicitly prohibited here. The pending scope question is whether to authorize that upstream API/artifact work. No upstream code edited or artifact published.
- Public API inventory was confirmed by javap of the pinned0.3.22 jar and a fresh read-only source clone: https://github.com/CodexCoder21Organization/Observable/blob/6731d91d6314f75619caf2a460699dea27e75c78/observable-core/src/jvmMain/kotlin/community/kotlin/observable/ProjectionState.kt#L375, #L502, #L619. It needs off-guard preparation (including equality/materialization), a short guarded installation that revalidates ownership, then off-guard notifications. A notification-only split is insufficient if equality remains under the transport guard.
Branches and verification
Written 2026-10-07 UTC. Live GraphQL check: PR OPEN, head1004cec9f7a19dd645aa8bf1ee6e6101c7eb6441, mergeQueueEntry=null. No PR branch update by this lane.
| Repository |
Branch |
Remote head |
PR relationship |
State |
| UrlResolver |
wip/fx1203o-round-eight |
1e4671cdc8346d507d14211c6a38b9828e3b50e6 |
Partial work for https://github.com/CodexCoder21Organization/UrlResolver/pull/1203, not pushed to its branch |
Contains unchanged review tests, new M1 test/fix, README/old test contract update. New M1 and five neighboring tests each5/5 PASS (30/30 qualified). G1/G2 unresolved. |
| UrlResolver |
proof/fx1203o-m1-reverted |
76095a6135623cb5180952a97f504c5ef51951d6 |
No PR; deliberately failing proof |
Reverts only M1 production source. New M1 test fails1/1 again with expected SUCCEEDED actual FAILED. |
| Observable |
inspected main commit |
6731d91d6314f75619caf2a460699dea27e75c78 |
Read-only inspection |
No changes or artifact publication. |
Qualified fixed batches2/3/4/5 and replacement-qualified1 each6/6 PASS: new M1 proof; legacy timestamp failure; timestamp callback guard; state callback guard; terminal-vs-running publication; idempotent cancellation. An earlier warm-up6/6 PASS is excluded: rebase rejected uncommitted source edits and the shell continued to tests. The fix was then committed, successfully rebased on unchanged origin/main4fe061512ba91888439a2cf10608631bb99b6121, and the qualified gate ran from that head. This process error is recorded, not hidden. No failing test was retried past.
Original requested gate is INCOMPLETE: G1/G2 fixed proofs, all other regressions, relay/rebound runs, G1/G2 independent reversions, and the23-row final re-verification have not been completed. No Review round8 success paragraph was added. M1 is locally proven; the supervisor must decide how to resume the upstream API work.
No code deployed, services restarted, queue entries changed, PR merged or artifact published by this lane. PR branch has not been pushed by this lane. G1/G2 production code remains unchanged. Their carried tests are byte-identical to review commit https://github.com/CodexCoder21Organization/UrlResolver/commit/00a5c02024164ecf2b36c4a2b4f17bc72dfa4be8.
Next steps
- Re-verify live PR and WIP heads, and preserve any tests-only lane commits. Read the original phase/invariant briefs; supervisor has lanes/rv1203g.phase.md plus fx1203b throughfx1203m and review/fix findings in scratchpad. Original review branch: https://github.com/CodexCoder21Organization/UrlResolver/tree/review/rv1203g-seventh-production.
- Resolve the upstream API/publication scope question. Do not implement lifecycleLock around current ProjectionState apply calls, a revision recheck that leaves retirement outside the actual state commit, or a serial lane that prevents callback-driven replacement from completing.
- Implement G1/G2 at their owners using a state API that allows the required atomic commit. Preserve the M1 success result and full effect.
- Complete the prescribed exact local gate: G1/G2/M1 tests5/5; all existing regressions5/5; relay-kill10/10; rebound5/5; each G1/G2/M1 fails with its fix reverted alone. Re-verify invariant rows1-23. The full suite is not required by this phase.
- Before PR push, confirm OPEN and not queued; fetch/rebase live PR and origin/main, test exact head, push --force-with-lease, append Review round8. Then stop immediately. No enqueue, merge, publication or deployment under the current phase.
Operational details
Fresh lane repo workspace/UrlResolver; read-only workspace/Observable. scripts/test.bash --local --test <selector> --log <path>. XML is custom <tests><test success=...>, not JUnit testcase tags: inspect every test and stacktrace, not client exit code. Cold source compilation takes minutes and may show dependency-pin warnings unrelated to this change. No timeouts were altered.
Read required https://github.com/CodexCoder21Organization/DocumentationRepository/blob/main/architecture/TESTING.md and https://github.com/CodexCoder21Organization/DocumentationRepository/blob/main/PHILOSOPHY.md. No root AGENTS.md. README read. Independent M1 test/code passes examined real server mutation, full effect message, one timestamp callback and one terminal notification, callback guards, cancellation and racing terminal publication. Full23-row re-verification remains incomplete because G1/G2 are still unresolved. Prior unexplained one-off second RPC open timeout was not reproduced here and is not reclassified as the separate jvm-libp2p visitor-close defect.
Fail-first proof stack traces
foundation.url.resolver.testProjectionGenerationRetiredDuringLineageDiagnosticCannotPublishSnapshot
java.lang.AssertionError: A generation retired during lineage processing cannot publish its snapshot over the new generation. Expected <300>, actual <200>.
at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
at kotlin.test.Asserter$DefaultImpls.assertEquals(Assertions.kt:671)
at kotlin.test.DefaultAsserter.assertEquals(DefaultAsserter.kt:11)
at kotlin.test.AssertionsKt__AssertionsKt.assertEquals(Assertions.kt:63)
at kotlin.test.AssertionsKt.assertEquals(Unknown Source)
at foundation.url.resolver.TestProjectionGenerationRetiredDuringLineageDiagnosticCannotPublishSnapshotKt.testProjectionGenerationRetiredDuringLineageDiagnosticCannotPublishSnapshot(testProjectionGenerationRetiredDuringLineageDiagnosticCannotPublishSnapshot.kt:106)
at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
at java.base/java.lang.reflect.Method.invoke(Method.java:580)
at kompile.TestRunner.executeTest(TestRunner.kt:46)
at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
at java.base/java.lang.reflect.Method.invoke(Method.java:580)
at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)
foundation.url.resolver.testProjectionFrameRetiredDuringFirstDeltaCannotPublishRemainingDelta
java.lang.AssertionError: An old frame retired by its first delta listener cannot apply its remaining delta to the new binding. Expected <new-item>, actual <old-item>.
at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
at kotlin.test.Asserter$DefaultImpls.assertEquals(Assertions.kt:671)
at kotlin.test.DefaultAsserter.assertEquals(DefaultAsserter.kt:11)
at kotlin.test.AssertionsKt__AssertionsKt.assertEquals(Assertions.kt:63)
at kotlin.test.AssertionsKt.assertEquals(Unknown Source)
at foundation.url.resolver.TestProjectionFrameRetiredDuringFirstDeltaCannotPublishRemainingDeltaKt.testProjectionFrameRetiredDuringFirstDeltaCannotPublishRemainingDelta(testProjectionFrameRetiredDuringFirstDeltaCannotPublishRemainingDelta.kt:131)
at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
at java.base/java.lang.reflect.Method.invoke(Method.java:580)
at kompile.TestRunner.executeTest(TestRunner.kt:46)
at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
at java.base/java.lang.reflect.Method.invoke(Method.java:580)
at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)
foundation.url.resolver.testProjectionSucceededCommandTimestampFailureRemainsSucceeded
java.lang.AssertionError: A successful server write must stay successful when local timestamp installation fails. Expected <SUCCEEDED>, actual <FAILED>.
at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
at kotlin.test.Asserter$DefaultImpls.assertEquals(Assertions.kt:671)
at kotlin.test.DefaultAsserter.assertEquals(DefaultAsserter.kt:11)
at kotlin.test.AssertionsKt__AssertionsKt.assertEquals(Assertions.kt:63)
at kotlin.test.AssertionsKt.assertEquals(Unknown Source)
at foundation.url.resolver.TestProjectionSucceededCommandTimestampFailureRemainsSucceededKt.testProjectionSucceededCommandTimestampFailureRemainsSucceeded(testProjectionSucceededCommandTimestampFailureRemainsSucceeded.kt:93)
at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
at java.base/java.lang.reflect.Method.invoke(Method.java:580)
at kompile.TestRunner.executeTest(TestRunner.kt:46)
at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
at java.base/java.lang.reflect.Method.invoke(Method.java:580)
at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)
Isolated M1 reversion proof
java.lang.AssertionError: A successful server write must stay successful when local timestamp installation fails. Expected <SUCCEEDED>, actual <FAILED>.
at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
at kotlin.test.Asserter$DefaultImpls.assertEquals(Assertions.kt:671)
at kotlin.test.DefaultAsserter.assertEquals(DefaultAsserter.kt:11)
at kotlin.test.AssertionsKt__AssertionsKt.assertEquals(Assertions.kt:63)
at kotlin.test.AssertionsKt.assertEquals(Unknown Source)
at foundation.url.resolver.TestProjectionSucceededCommandTimestampFailureRemainsSucceededKt.testProjectionSucceededCommandTimestampFailureRemainsSucceeded(testProjectionSucceededCommandTimestampFailureRemainsSucceeded.kt:93)
at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
at java.base/java.lang.reflect.Method.invoke(Method.java:580)
at kompile.TestRunner.executeTest(TestRunner.kt:46)
at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
at java.base/java.lang.reflect.Method.invoke(Method.java:580)
at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)
Original invariant brief excerpts
These are the supplied review specifications, retained for cold pickup. They describe the earlier review assignment; the remaining task and current prohibitions above take precedence.
rv1203g.phase.md
Phase: seventh adversarial production review of https://github.com/CodexCoder21Organization/UrlResolver/pull/1203 at head 1004cec9, then stop
Verify, do not re-derive: the PR fixes a lock-ordering defect in src/foundation/url/resolver/projection/ProjectionServiceHandler.kt (subscription held the projection's state guard while waiting on a source snapshot; the source's publication callback needed the same guard). Seven fix rounds closed twenty-six production findings (PR description "Review round 1" to "Review round 7"; briefs lanes/fx1203b.md to fx1203m.md under /tmp/claude-1000/-code/bc2b7c27-444b-42de-a7b4-fa2149a96ecf/scratchpad/ carry the invariant rows, which are the spec; notes out/fx1203j-findings.md and out/fx1203m-findings.md; prior reviews out/rv1203f-findings.md, out/rv1203ft-findings.md and earlier). Round seven: (A) a failed close registration rolls back only its own registration lifetime; (B) a retired generation's SUBSCRIBE response never changes public state (generation check before any lineage change or state application, every mode); (C) a clock-schedule failure in the close callback releases the dead subscription; (D) a null wire binding identity on a poll-only replacement rejects frames carrying any binding identity; (E) a command's terminal state is published exactly once even when the timestamp callback throws, with the terminal flag set only when the state is actually published; (F) cancel() returns only after CANCEL_REQUESTED or a terminal is publicly readable without holding applyLock across application code. Gate: 79 regressions x5, relay-kill 10/10, rebound 5/5, all six reversions. One timeout seen once in 85+ runs of testProjectionCancelledReaderWhileSharingPreparedFrameKeepsOtherReader remains unexplained (second RPC open timed out; an unrelated upstream defect was found on the way and fixed in https://github.com/CodexCoder21Organization/jvm-libp2p/pull/45).
Your job: the whole production diff origin/main...head (handler and client transport) against the full invariant set (rows 1-19 of lanes/rv1203f.phase.md plus rows of rv1203e/rv1203d) plus: (20) for each of A-F, the fix's precondition is re-validated at commit time, and the rollback or rejection touches only its own lifetime (registration attempt, generation, reap claim, binding, command); (21) F's wait for publication cannot deadlock when the publishing lane is the caller's own thread (re-entrant cancel from a state listener) or when the lane's owner throws; (22) E's single publication holds when the dispatcher's FAILED settlement races the timestamp callback's success path; (23) the second-RPC open on a shared connection after the first subscription: enumerate every wait the second open can block on (handler admission, prepared-frame sharing, the reader's cancellation path) and write the hostile sequence or a public test that forces it; this is the open timeout's suspect area. For each row point at the code or write the hostile-caller sequence and a public-API fail-first test in tests/ on a review branch (report; do not fix production). Run relay-kill 5 times, rebound 3 times, and each round-seven regression test once locally (scripts/test.bash --local; no remote runs). Done = REVIEWS-DONE head=<sha> verdict=CLEAN|FINDINGS with file:line findings. STOP — no enqueue, no merge.
rv1203f.phase.md
Phase: sixth adversarial production review of https://github.com/CodexCoder21Organization/UrlResolver/pull/1203 at head 6ec43b6d, then stop
Verify, do not re-derive: the PR fixes a lock-ordering defect in src/foundation/url/resolver/projection/ProjectionServiceHandler.kt (subscription held the projection's state guard while waiting on a source snapshot; the source's publication callback needed the same guard). Six fix rounds closed twenty production findings (PR description "Review round 1" to "Review round 6"; briefs lanes/fx1203b.md to fx1203h.md under /tmp/claude-1000/-code/bc2b7c27-444b-42de-a7b4-fa2149a96ecf/scratchpad/ carry the invariant rows, which are the spec; notes out/fx1203h-findings.md; prior reviews out/rv1203e-findings.md and earlier). Round six moved connection construction, idle-hold operations, timestamp/state callbacks and lineage bookkeeping in src/foundation/url/resolver/projection/LiveProjectionClient.kt outside the client guards (connectionLock, lifecycleLock, effectHandlerLock, requiredPadLock, pushWaitLock, lineageLock, ResolverRemoteCommand.applyLock, the membershipRevisions and commandHandlesByCommandId concurrent maps), made frames wait for snapshot/binding installation instead of being dropped, rolled back a replacement's admission when its close registration fails, and keyed close/grace cleanup by physical connection ID. A tests-only commit carrying seven tests from the fifth test review will be appended to the head while you work; production code is 6ec43b6d.
Your job: the whole production diff origin/main...head (handler and client transport) against the full invariant set (rows 1-15 of lanes/rv1203e.phase.md, rows 1-12 of lanes/rv1203d.phase.md) plus: (16) every client lock listed above: no wait on a future, callback, connection construction, application code, clock scheduling or another lock while it is held; for each lock, list each critical section and what it calls; (17) frames deferred until binding installation are applied exactly once, in revision order, and are released (not leaked, not applied twice, not applied to a later binding) when the SUBSCRIBE fails, times out, or is superseded before installation; (18) the rolled-back admission after a failed close registration leaves no half-registered state: the replacement handle is closed, its pads are released, and the previous binding is either still live or already signalled, never both lost; (19) cleanup keyed by physical connection ID cannot act on a different logical binding that reuses the same connection. For each row point at the code or write the hostile-caller sequence and a public-API fail-first test in tests/ on a review branch (report; do not fix production). Hunt what six rounds leave behind: a wait moved outside a lock that now races a concurrent state change it used to exclude (check every "compute off guard, commit under it" site for a stale precondition at commit time), lost wakeup, double registration, leak on an exception path, swallowed exception, changed error literal, lock-order inversion. Run relay-kill 5 times, rebound 3 times, and each round-six regression test once locally (scripts/test.bash --local; no remote runs). Done = REVIEWS-DONE head=<sha> verdict=CLEAN|FINDINGS with file:line findings. STOP — no enqueue, no merge.
rv1203e.phase.md
Phase: fifth adversarial production review of https://github.com/CodexCoder21Organization/UrlResolver/pull/1203 at its live head (a9d21022 or newer), then stop
Verify, do not re-derive: the PR fixes a lock-ordering defect in src/foundation/url/resolver/projection/ProjectionServiceHandler.kt (subscription held the projection's state guard while waiting on a source snapshot; the source's publication callback needed the same guard). Five fix rounds closed sixteen production findings (PR description "Review round 1" to "Review round 5"; briefs lanes/fx1203b.md, fx1203d.md, fx1203e.md, fx1203f.md, fx1203g.md under /tmp/claude-1000/-code/bc2b7c27-444b-42de-a7b4-fa2149a96ecf/scratchpad/ carry the invariant rows, which are the spec; notes out/fx1203g-findings.md). Round five enforced the general rule that no handler-owned lock is held across source publication or application code (locks audited: the state monitor, the removed required-pad notification lock now replaced by the in-flight owner claim, commandMonitor, pushWaitLock, the child-handler map lock), and gave every subscription binding an identity carried in the SUBSCRIBE response and every push so a client ignores signals for superseded bindings. Prior reviews: out/rv1203d-findings.md and earlier.
Your job: the whole production diff origin/main...head (handler and transport) against the full invariant set (rows 1-12 of lanes/rv1203d.phase.md) plus: (13) for EVERY lock in the file and the transport, no wait on a future, callback, application code, clock scheduling, or another lock occurs while it is held (read every synchronized block and every Object.wait; a wait that releases its own monitor is allowed only if nothing else is held); (14) the binding identity is unforgeable across reuse of the same connection and token: a stale signal, delta, resubscribe-required or failure frame for an older binding can never be applied by the client to a newer binding, and the client's filtering never drops a frame for the current binding; (15) the removed notification lock's replacement (the in-flight owner claim) still guarantees exactly-once required-pad refresh with no lost refresh under concurrent SUBSCRIBE and PAD_UPDATE. For each row point at the code or write the hostile-caller sequence and a public-API fail-first test in tests/ (report; do not fix production). Hunt what five rounds leave behind: lost wakeup, double registration, leak on an exception path, swallowed exception, changed error literal, lock-order inversion between any two of the audited locks, a frame applied to the wrong binding. Run relay-kill 5 times, rebound 3 times, and each regression test once locally (scripts/test.bash --local; no remote runs). Done = REVIEWS-DONE head=<sha> verdict=CLEAN|FINDINGS with file:line findings. STOP — no enqueue, no merge.
rv1203d.phase.md
Phase: fourth adversarial production review of https://github.com/CodexCoder21Organization/UrlResolver/pull/1203 at its live head (cc5bda60 or newer), then stop
Verify, do not re-derive: the PR fixes a lock-ordering defect in src/foundation/url/resolver/projection/ProjectionServiceHandler.kt (subscription held the projection's state guard while waiting on a source snapshot; the source's publication callback needed the same guard). Four fix rounds closed fourteen production findings; the PR description sections "Review round 1" to "Review round 4" list them, and the briefs lanes/fx1203b.md, fx1203d.md, fx1203e.md, fx1203f.md under /tmp/claude-1000/-code/bc2b7c27-444b-42de-a7b4-fa2149a96ecf/scratchpad/ carry the invariant rows (read them; they are the spec). Prior review notes: out/rv1203-findings.md, rv1203b, rv1203c, rv1203ct, rv1203bt. Round three introduced two algebraic effects (ProjectionCleanupFailedEffect, ProjectionPublicationFailedEffect) tossed from the delivery drain and cleanup paths, a RESUBSCRIBE_REQUIRED push frame on shared-frame preparation failure, admission tokens with rollback, and idempotent shutdown; round four re-checks binding liveness and terminal state under the guard when each queued write is claimed.
Your job: the whole production diff origin/main...head against the full invariant set (rows 1-8 of lanes/rv1203c.phase.md plus: (9) no transport write starts after its binding retired, an in-flight write never frees or delivers to a later binding, a retired lane's queue drains its tickets without leaking; (10) admission is atomic with liveness and rolled back on any failure; (11) shutdown is idempotent end to end) and, as the supervisor's specific question, (12) the effect tosses: establish from the algebraic-effects library in use what happens when ProjectionPublicationFailedEffect or ProjectionCleanupFailedEffect is tossed with NO handler installed on the current thread (a listener callback thread, or another subscriber's SUBSCRIBE seed path, or the RPC effect-handler thread). If an unhandled toss abandons the continuation, throws, or blocks, show the hostile sequence in which a preparation failure then strands the drain or the callback and other readers lose their delivery, with a public-API fail-first test; if it is safe, point at the library semantics that make it so and at a test that pins it. For every row point at the code or write the hostile-caller sequence and a public-API fail-first test in tests/ (report; do not fix production). Hunt what four rounds leave behind: lost wakeup, double registration, leak on an exception path, swallowed exception, changed error literal, lock-order inversion, a frame delivered twice, a RESUBSCRIBE_REQUIRED frame delivered to a binding that was not the failed reader's. Run relay-kill 5 times, rebound 3 times, and each of the regression tests once locally (scripts/test.bash --local; no remote runs). Done = REVIEWS-DONE head=<sha> verdict=CLEAN|FINDINGS with file:line findings. STOP — no enqueue, no merge.
rv1203c.phase.md (rows1-8)
Phase: third adversarial production review of https://github.com/CodexCoder21Organization/UrlResolver/pull/1203 at its live head (ced93f05 or newer), then stop
Verify, do not re-derive: the PR fixes a lock-ordering defect in src/foundation/url/resolver/projection/ProjectionServiceHandler.kt (subscription held the projection's state guard while waiting on a source snapshot; the source's publication callback needed the same guard). Three rounds have now closed nine production findings; the PR description's "Review round 1" and "Review round 2" sections list them. Round two (brief lanes/fx1203d.md, notes out/fx1203d-findings.md under /tmp/claude-1000/-code/bc2b7c27-444b-42de-a7b4-fa2149a96ecf/scratchpad/) redesigned delivery ownership: one prepared frame per accepted publication shared by every push-ready reader in revision order, push-failure cleanup keyed to the exact binding lifetime, shutdown re-checked under the guard at admission, and retired-listener cleanup failures surfaced on the next request instead of masking a successful response. Prior review notes: out/rv1203-findings.md (invariant rows), out/rv1203b-findings.md.
Your job: the whole production diff origin/main...head of the handler against the invariant set: (1) no path acquires the state guard and then waits on anything outside it; (2) every accepted publication reaches every push-ready connection exactly once, in revision order per connection, whichever path (listener callback or subscriber seed) accepted it, including when a seed wins the sequence race while the callback is off-guard and when two publications of different properties interleave; (3) a retired attachment's callback never updates a later attachment; (4) shutdown is terminal and idempotent, every owned listener removed exactly once, nothing admitted after shutdown even when it ran during a SUBSCRIBE's off-guard section; (5) subscribers initialize independently; (6) public getter, watermark, invalidation and error-text semantics unchanged; (7) a write failure from a retired push never frees a later binding of the same token, even on the same connection; (8) a prepared-frame failure (application getter or watermark throwing during frame preparation) is reported to every reader that shares the frame and never leaves a reader waiting or a frame half-delivered. For each row point at the code or write the hostile-caller sequence and a public-API fail-first test in tests/ (report; do not fix production). Hunt what three rounds of patching leave behind: a lost wakeup, a listener added twice, a leak on an exception path, a swallowed exception, a changed error literal, a lock-order inversion against any other guard in the file, and a frame delivered twice to one connection. Run relay-kill 5 times, rebound 3 times, and each of the 24 regression tests once locally (scripts/test.bash --local; no remote runs). Done = REVIEWS-DONE head=<sha> verdict=CLEAN|FINDINGS with file:line findings. STOP — no enqueue, no merge.