feat: isNewerMajor + store write-refusal backstop (F5 SLICE-2, INV-16, #14)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Ben Stull
2026-06-10 22:59:04 -07:00
parent a6b16f0d9c
commit 746071a585
4 changed files with 41 additions and 1 deletions
+8
View File
@@ -116,6 +116,14 @@ export function emptyArtifact(docPath: string): Artifact {
};
}
/**
* INV-16 fail-safe: schemaVersion IS the major. A sidecar from a future major
* is render-only — a conforming writer never rewrites what it can't fully read.
*/
export function isNewerMajor(a: Pick<Artifact, "schemaVersion">): boolean {
return a.schemaVersion > SCHEMA_VERSION;
}
/** Stable, generated id (spec §6.3). */
export function newId(prefix: string): string {
return `${prefix}_${randomUUID()}`;
+8 -1
View File
@@ -8,7 +8,7 @@
*/
import * as fs from "node:fs";
import * as path from "node:path";
import { emptyArtifact, serializeArtifact, type Artifact } from "./model";
import { SCHEMA_VERSION, emptyArtifact, isNewerMajor, serializeArtifact, type Artifact } from "./model";
export class CoauthorStore {
/**
@@ -67,6 +67,13 @@ export class CoauthorStore {
*/
update(docPath: string, mutate: (artifact: Artifact) => void): Artifact {
const artifact = this.load(docPath) ?? emptyArtifact(docPath);
if (isNewerMajor(artifact)) {
// INV-16 backstop: the controllers gate first (VersionGuard); this throw
// guarantees no missed write path can ever destroy a newer rung's data.
throw new Error(
`refusing to write ${docPath}: sidecar schemaVersion ${artifact.schemaVersion} > supported ${SCHEMA_VERSION} (INV-16)`,
);
}
mutate(artifact);
const referenced = new Set<string>([
...artifact.threads.map((t) => t.anchorId),