Skip to content

Add optional PostgreSQL checkpoints for a single active SI executor - #57

Draft
infotradescout wants to merge 1 commit into
codex/si-harness-runtimefrom
codex/neon-backend-adoption
Draft

infotradescout wants to merge 1 commit into
codex/si-harness-runtimefrom
codex/neon-backend-adoption

Conversation

@infotradescout

@infotradescout infotradescout commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

SI sessions currently persist to local files. This adds an optional PostgreSQL store through the canonical lane_session owner so a replacement runtime can recover checkpoint JSON and revisions after the previous executor has terminated. The portable file backend remains the default and requires no database, API key, paid service, or additional dependency.

The opt-in store uses direct verified-TLS connections, namespace/session advisory locks, revision compare-and-swap, explicit schema initialization and sanitized failures. It never falls back to local state when a configured database fails. Runtime packaging includes the optional module and its reference; delivery fixtures now include the real transitive helper modules.

Independent Objector finding SI-PG-01 was sustained and addressed by restricting the supported scope. A lost database connection can release the lock while an executor still writes or rolls back files. Revision checks fence session JSON, not external actions. SI_SESSION_EXECUTION_MODE=single-active is required as explicit acknowledgement; recovery requires confirmed termination of the old executor. This does not implement automatic failover, active-active execution, filesystem fencing, or exactly-once tools.

Validation: all five local quality-gate checks passed (controls, Council safeguards, behavior-evidence safeguards, unit tests, release integrity). Seven Postgres configuration tests passed with the optional driver. ChatGPT package validation passed with 61 files; delivery tests passed 25/25; public-plugin delivery passed 14/14; public-plugin tests passed 4/4. The reviewed canonical owner digest remains 4fc15e1b2f9e68966e50bc42e032b5a71c9693a078b853e6b5147df4e8966054. Published tree matches local commit 902a7a18f02c7ce3bd9f53381f9c3ad73d31db17.

Live validation (2026-09-18): all 13 Postgres tests passed, including all six real recovery/concurrency tests, against a dedicated synthetic Neon PostgreSQL 18 database. Render build dep-dam8kte1egvs738i89o0 on service srv-dam8j961egvs738i33t0 verified exact published commit f759ac2 before running the suite with psycopg 3.3.5 and Python 3.13.5. A read-only cleanup query confirmed zero remaining test rows.

Deployment configuration discovered during live testing: use the direct endpoint, sslmode=verify-full, and an explicit trusted CA bundle when the binary libpq build cannot resolve system trust roots. On Render, sslrootcert=/etc/ssl/certs/ca-certificates.crt passed; certificate verification was never disabled. Initial pooled/require-only connection configurations were correctly rejected, and the first hosted attempt failed certificate verification before this configuration correction.

The isolated validation project uses fixed 0.25 CU, five-minute idle shutdown, no restore history, and explicit compute/data quotas under the approved shared $50/30-day test budget. These quotas are not an account-wide dollar cap. No production migration or client adoption is implied. This proves hosted checkpoint persistence/recovery under the documented single-active contract; cross-machine artifact availability and existing release/client acceptance gates remain separate. Draft stacked on codex/si-harness-runtime.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant