feat(deletion): execute graceful and forced lock deletion - #21

Open
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution
Open

feat(deletion): execute graceful and forced lock deletion#21
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution

Conversation

@dzdidi

@dzdididzdidi commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Part 5 of the graceful-deletion stack. Depends on Part 4.

Completes the durable graceful and active-force deletion lifecycle.

Graceful execution:

  1. publishes and verifies the public tombstone;
  2. starts and drains frozen payment obligations;
  3. drains existing credentials;
  4. issues final credentials;
  5. drains final reads;
  6. verifies and removes frozen guarded content;
  7. verifies the retained tombstone;
  8. stops before the separately deferred operational-state purge.

The change also:

  • adds exact external-action ownership;
  • uses storage-authoritative time after the relevant fence;
  • executes public-first active-force deletion;
  • persists permanent force receipts;
  • adds operation-specific dependency readiness;
  • supervises deletion and verification workers;
  • adds bounded shutdown and worker-failure handling;
  • covers PostgreSQL crash/reclaim boundaries;
  • removes duplicate executor and test-fixture paths;
  • migrates the Paykit local demo to persisted runtime-master-key schema v2.

Active force is the only intentionally unconditional deletion path.

Graceful Pubky tombstone publication remains a GET followed by unconditional PUT. A replacement observed before the PUT is preserved, but an out-of-band replacement between the final GET and PUT may be overwritten. This accepted Pubky 0.9.3 limitation is explicitly documented.

Contract and risk impact

  • Public API or SDK contract
  • Persisted data or migration
  • Authentication, authorization, identity, or secret handling
  • Payment or entitlement behavior
  • Runtime, deployment, or observability
  • No contract/risk impact

Migration:

  • 0017_content_lock_deletion_resource_replaced.sql

Notable contract and risk changes:

  • graceful deletion now executes through its durable phase machine;
  • force=true executes or escalates active-force deletion;
  • destructive external actions require exact live-claim ownership;
  • dependency readiness recovers only from operation-specific healthy evidence;
  • Compose secrets schema v2 persists locksRuntimeMasterKey;
  • schema v1 local-demo state fails closed and requires the documented destructive reset;
  • PurgeOperationalState remains deferred.

Verification

Run successfully on the exact final artifact:

  • cargo fmt --all -- --check — passed
  • cargo test --workspace --all-targets --all-features — passed
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — passed
  • npm --prefix examples/js-sdk run check — passed
  • npm --prefix examples/js-sdk run smoke:paykit-compose — passed
  • npm --prefix locks-sdk/bindings/js test — passed
  • bash scripts/test-compose-bootstrap.sh — passed
  • git diff --check codex/bitkit-local-e2e-fixes..HEAD — passed

Recorded focused results from the final run:

  • locks-service library: 355 passed
  • deletion integration: 29 passed
  • tombstone integration: 6 passed
  • PostgreSQL E2E: 12 passed
  • JS/WASM generated-package and example smoke checks: passed
  • Paykit Compose model, reader-worker, and bootstrap smoke checks: passed

Exact reviewed artifact:

  • Base: ba2cfc58d1932e7fd38071b9936d53c732f62ed6
  • Tip: c54edaea8dea0b06ae92d9d3216dc42f52e9b91c
  • Tree: 08a4785704a1fb236a31b4cd572afade94956d6a
  • Canonical patch SHA-256: c92dba51e52f0a257266f22dabb258f3a02ffd041039c752b32994da35a0d756

Independent exact-artifact reviews approved:

  • Bitkit and Compose integration;
  • semantic safety of the code reduction;
  • stack topology and preservation.

Documentation

Updated:

  • docs/API.md
  • docs/RUNTIME.md
  • docs/plans/2026-08-10-graceful-content-lock-deletion.md
  • examples/js-sdk/README.md

The documentation covers:

  • graceful and active-force behavior;
  • public failure and lifecycle projection;
  • the accepted Pubky GET-to-PUT overwrite race;
  • worker readiness and supervision;
  • Compose runtime-master-key schema v2;
  • fail-closed handling and destructive reset requirements for schema v1.

Checklist

  • The change is focused and self-reviewed.
  • Regression tests were added where practical.
  • No credentials, identities, private content, payment material, or generated local state are included.
  • Formatting and relevant tests/lints pass.

Run the durable graceful and active-force deletion lifecycle with exact claim fencing, storage-owned time, final-access draining, operation-specific readiness, supervised shutdown, and crash-safe PostgreSQL and memory behavior. Keep the accepted Pubky GET-to-PUT overwrite race explicit, and remove duplicate executor and test-fixture paths.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@dzdidi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(deletion): execute graceful and forced lock deletion - #21

Open
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution
Open

feat(deletion): execute graceful and forced lock deletion#21
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution

Conversation

@dzdidi

@dzdididzdidi commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Part 5 of the graceful-deletion stack. Depends on Part 4.

Completes the durable graceful and active-force deletion lifecycle.

Graceful execution:

  1. publishes and verifies the public tombstone;
  2. starts and drains frozen payment obligations;
  3. drains existing credentials;
  4. issues final credentials;
  5. drains final reads;
  6. verifies and removes frozen guarded content;
  7. verifies the retained tombstone;
  8. stops before the separately deferred operational-state purge.

The change also:

  • adds exact external-action ownership;
  • uses storage-authoritative time after the relevant fence;
  • executes public-first active-force deletion;
  • persists permanent force receipts;
  • adds operation-specific dependency readiness;
  • supervises deletion and verification workers;
  • adds bounded shutdown and worker-failure handling;
  • covers PostgreSQL crash/reclaim boundaries;
  • removes duplicate executor and test-fixture paths;
  • migrates the Paykit local demo to persisted runtime-master-key schema v2.

Active force is the only intentionally unconditional deletion path.

Graceful Pubky tombstone publication remains a GET followed by unconditional PUT. A replacement observed before the PUT is preserved, but an out-of-band replacement between the final GET and PUT may be overwritten. This accepted Pubky 0.9.3 limitation is explicitly documented.

Contract and risk impact

  • Public API or SDK contract
  • Persisted data or migration
  • Authentication, authorization, identity, or secret handling
  • Payment or entitlement behavior
  • Runtime, deployment, or observability
  • No contract/risk impact

Migration:

  • 0017_content_lock_deletion_resource_replaced.sql

Notable contract and risk changes:

  • graceful deletion now executes through its durable phase machine;
  • force=true executes or escalates active-force deletion;
  • destructive external actions require exact live-claim ownership;
  • dependency readiness recovers only from operation-specific healthy evidence;
  • Compose secrets schema v2 persists locksRuntimeMasterKey;
  • schema v1 local-demo state fails closed and requires the documented destructive reset;
  • PurgeOperationalState remains deferred.

Verification

Run successfully on the exact final artifact:

  • cargo fmt --all -- --check — passed
  • cargo test --workspace --all-targets --all-features — passed
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — passed
  • npm --prefix examples/js-sdk run check — passed
  • npm --prefix examples/js-sdk run smoke:paykit-compose — passed
  • npm --prefix locks-sdk/bindings/js test — passed
  • bash scripts/test-compose-bootstrap.sh — passed
  • git diff --check codex/bitkit-local-e2e-fixes..HEAD — passed

Recorded focused results from the final run:

  • locks-service library: 355 passed
  • deletion integration: 29 passed
  • tombstone integration: 6 passed
  • PostgreSQL E2E: 12 passed
  • JS/WASM generated-package and example smoke checks: passed
  • Paykit Compose model, reader-worker, and bootstrap smoke checks: passed

Exact reviewed artifact:

  • Base: ba2cfc58d1932e7fd38071b9936d53c732f62ed6
  • Tip: c54edaea8dea0b06ae92d9d3216dc42f52e9b91c
  • Tree: 08a4785704a1fb236a31b4cd572afade94956d6a
  • Canonical patch SHA-256: c92dba51e52f0a257266f22dabb258f3a02ffd041039c752b32994da35a0d756

Independent exact-artifact reviews approved:

  • Bitkit and Compose integration;
  • semantic safety of the code reduction;
  • stack topology and preservation.

Documentation

Updated:

  • docs/API.md
  • docs/RUNTIME.md
  • docs/plans/2026-08-10-graceful-content-lock-deletion.md
  • examples/js-sdk/README.md

The documentation covers:

  • graceful and active-force behavior;
  • public failure and lifecycle projection;
  • the accepted Pubky GET-to-PUT overwrite race;
  • worker readiness and supervision;
  • Compose runtime-master-key schema v2;
  • fail-closed handling and destructive reset requirements for schema v1.

Checklist

  • The change is focused and self-reviewed.
  • Regression tests were added where practical.
  • No credentials, identities, private content, payment material, or generated local state are included.
  • Formatting and relevant tests/lints pass.

Run the durable graceful and active-force deletion lifecycle with exact claim fencing, storage-owned time, final-access draining, operation-specific readiness, supervised shutdown, and crash-safe PostgreSQL and memory behavior. Keep the accepted Pubky GET-to-PUT overwrite race explicit, and remove duplicate executor and test-fixture paths.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@dzdidi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(deletion): execute graceful and forced lock deletion - #21

Open
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution
Open

feat(deletion): execute graceful and forced lock deletion#21
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution

Conversation

@dzdidi

@dzdididzdidi commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Part 5 of the graceful-deletion stack. Depends on Part 4.

Completes the durable graceful and active-force deletion lifecycle.

Graceful execution:

  1. publishes and verifies the public tombstone;
  2. starts and drains frozen payment obligations;
  3. drains existing credentials;
  4. issues final credentials;
  5. drains final reads;
  6. verifies and removes frozen guarded content;
  7. verifies the retained tombstone;
  8. stops before the separately deferred operational-state purge.

The change also:

  • adds exact external-action ownership;
  • uses storage-authoritative time after the relevant fence;
  • executes public-first active-force deletion;
  • persists permanent force receipts;
  • adds operation-specific dependency readiness;
  • supervises deletion and verification workers;
  • adds bounded shutdown and worker-failure handling;
  • covers PostgreSQL crash/reclaim boundaries;
  • removes duplicate executor and test-fixture paths;
  • migrates the Paykit local demo to persisted runtime-master-key schema v2.

Active force is the only intentionally unconditional deletion path.

Graceful Pubky tombstone publication remains a GET followed by unconditional PUT. A replacement observed before the PUT is preserved, but an out-of-band replacement between the final GET and PUT may be overwritten. This accepted Pubky 0.9.3 limitation is explicitly documented.

Contract and risk impact

  • Public API or SDK contract
  • Persisted data or migration
  • Authentication, authorization, identity, or secret handling
  • Payment or entitlement behavior
  • Runtime, deployment, or observability
  • No contract/risk impact

Migration:

  • 0017_content_lock_deletion_resource_replaced.sql

Notable contract and risk changes:

  • graceful deletion now executes through its durable phase machine;
  • force=true executes or escalates active-force deletion;
  • destructive external actions require exact live-claim ownership;
  • dependency readiness recovers only from operation-specific healthy evidence;
  • Compose secrets schema v2 persists locksRuntimeMasterKey;
  • schema v1 local-demo state fails closed and requires the documented destructive reset;
  • PurgeOperationalState remains deferred.

Verification

Run successfully on the exact final artifact:

  • cargo fmt --all -- --check — passed
  • cargo test --workspace --all-targets --all-features — passed
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — passed
  • npm --prefix examples/js-sdk run check — passed
  • npm --prefix examples/js-sdk run smoke:paykit-compose — passed
  • npm --prefix locks-sdk/bindings/js test — passed
  • bash scripts/test-compose-bootstrap.sh — passed
  • git diff --check codex/bitkit-local-e2e-fixes..HEAD — passed

Recorded focused results from the final run:

  • locks-service library: 355 passed
  • deletion integration: 29 passed
  • tombstone integration: 6 passed
  • PostgreSQL E2E: 12 passed
  • JS/WASM generated-package and example smoke checks: passed
  • Paykit Compose model, reader-worker, and bootstrap smoke checks: passed

Exact reviewed artifact:

  • Base: ba2cfc58d1932e7fd38071b9936d53c732f62ed6
  • Tip: c54edaea8dea0b06ae92d9d3216dc42f52e9b91c
  • Tree: 08a4785704a1fb236a31b4cd572afade94956d6a
  • Canonical patch SHA-256: c92dba51e52f0a257266f22dabb258f3a02ffd041039c752b32994da35a0d756

Independent exact-artifact reviews approved:

  • Bitkit and Compose integration;
  • semantic safety of the code reduction;
  • stack topology and preservation.

Documentation

Updated:

  • docs/API.md
  • docs/RUNTIME.md
  • docs/plans/2026-08-10-graceful-content-lock-deletion.md
  • examples/js-sdk/README.md

The documentation covers:

  • graceful and active-force behavior;
  • public failure and lifecycle projection;
  • the accepted Pubky GET-to-PUT overwrite race;
  • worker readiness and supervision;
  • Compose runtime-master-key schema v2;
  • fail-closed handling and destructive reset requirements for schema v1.

Checklist

  • The change is focused and self-reviewed.
  • Regression tests were added where practical.
  • No credentials, identities, private content, payment material, or generated local state are included.
  • Formatting and relevant tests/lints pass.

Run the durable graceful and active-force deletion lifecycle with exact claim fencing, storage-owned time, final-access draining, operation-specific readiness, supervised shutdown, and crash-safe PostgreSQL and memory behavior. Keep the accepted Pubky GET-to-PUT overwrite race explicit, and remove duplicate executor and test-fixture paths.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@dzdidi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(deletion): execute graceful and forced lock deletion - #21

Open
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution
Open

feat(deletion): execute graceful and forced lock deletion#21
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution

Conversation

@dzdidi

@dzdididzdidi commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Part 5 of the graceful-deletion stack. Depends on Part 4.

Completes the durable graceful and active-force deletion lifecycle.

Graceful execution:

  1. publishes and verifies the public tombstone;
  2. starts and drains frozen payment obligations;
  3. drains existing credentials;
  4. issues final credentials;
  5. drains final reads;
  6. verifies and removes frozen guarded content;
  7. verifies the retained tombstone;
  8. stops before the separately deferred operational-state purge.

The change also:

  • adds exact external-action ownership;
  • uses storage-authoritative time after the relevant fence;
  • executes public-first active-force deletion;
  • persists permanent force receipts;
  • adds operation-specific dependency readiness;
  • supervises deletion and verification workers;
  • adds bounded shutdown and worker-failure handling;
  • covers PostgreSQL crash/reclaim boundaries;
  • removes duplicate executor and test-fixture paths;
  • migrates the Paykit local demo to persisted runtime-master-key schema v2.

Active force is the only intentionally unconditional deletion path.

Graceful Pubky tombstone publication remains a GET followed by unconditional PUT. A replacement observed before the PUT is preserved, but an out-of-band replacement between the final GET and PUT may be overwritten. This accepted Pubky 0.9.3 limitation is explicitly documented.

Contract and risk impact

  • Public API or SDK contract
  • Persisted data or migration
  • Authentication, authorization, identity, or secret handling
  • Payment or entitlement behavior
  • Runtime, deployment, or observability
  • No contract/risk impact

Migration:

  • 0017_content_lock_deletion_resource_replaced.sql

Notable contract and risk changes:

  • graceful deletion now executes through its durable phase machine;
  • force=true executes or escalates active-force deletion;
  • destructive external actions require exact live-claim ownership;
  • dependency readiness recovers only from operation-specific healthy evidence;
  • Compose secrets schema v2 persists locksRuntimeMasterKey;
  • schema v1 local-demo state fails closed and requires the documented destructive reset;
  • PurgeOperationalState remains deferred.

Verification

Run successfully on the exact final artifact:

  • cargo fmt --all -- --check — passed
  • cargo test --workspace --all-targets --all-features — passed
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — passed
  • npm --prefix examples/js-sdk run check — passed
  • npm --prefix examples/js-sdk run smoke:paykit-compose — passed
  • npm --prefix locks-sdk/bindings/js test — passed
  • bash scripts/test-compose-bootstrap.sh — passed
  • git diff --check codex/bitkit-local-e2e-fixes..HEAD — passed

Recorded focused results from the final run:

  • locks-service library: 355 passed
  • deletion integration: 29 passed
  • tombstone integration: 6 passed
  • PostgreSQL E2E: 12 passed
  • JS/WASM generated-package and example smoke checks: passed
  • Paykit Compose model, reader-worker, and bootstrap smoke checks: passed

Exact reviewed artifact:

  • Base: ba2cfc58d1932e7fd38071b9936d53c732f62ed6
  • Tip: c54edaea8dea0b06ae92d9d3216dc42f52e9b91c
  • Tree: 08a4785704a1fb236a31b4cd572afade94956d6a
  • Canonical patch SHA-256: c92dba51e52f0a257266f22dabb258f3a02ffd041039c752b32994da35a0d756

Independent exact-artifact reviews approved:

  • Bitkit and Compose integration;
  • semantic safety of the code reduction;
  • stack topology and preservation.

Documentation

Updated:

  • docs/API.md
  • docs/RUNTIME.md
  • docs/plans/2026-08-10-graceful-content-lock-deletion.md
  • examples/js-sdk/README.md

The documentation covers:

  • graceful and active-force behavior;
  • public failure and lifecycle projection;
  • the accepted Pubky GET-to-PUT overwrite race;
  • worker readiness and supervision;
  • Compose runtime-master-key schema v2;
  • fail-closed handling and destructive reset requirements for schema v1.

Checklist

  • The change is focused and self-reviewed.
  • Regression tests were added where practical.
  • No credentials, identities, private content, payment material, or generated local state are included.
  • Formatting and relevant tests/lints pass.

Run the durable graceful and active-force deletion lifecycle with exact claim fencing, storage-owned time, final-access draining, operation-specific readiness, supervised shutdown, and crash-safe PostgreSQL and memory behavior. Keep the accepted Pubky GET-to-PUT overwrite race explicit, and remove duplicate executor and test-fixture paths.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@dzdidi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(deletion): execute graceful and forced lock deletion - #21

Open
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution
Open

feat(deletion): execute graceful and forced lock deletion#21
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution

Conversation

@dzdidi

@dzdididzdidi commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Part 5 of the graceful-deletion stack. Depends on Part 4.

Completes the durable graceful and active-force deletion lifecycle.

Graceful execution:

  1. publishes and verifies the public tombstone;
  2. starts and drains frozen payment obligations;
  3. drains existing credentials;
  4. issues final credentials;
  5. drains final reads;
  6. verifies and removes frozen guarded content;
  7. verifies the retained tombstone;
  8. stops before the separately deferred operational-state purge.

The change also:

  • adds exact external-action ownership;
  • uses storage-authoritative time after the relevant fence;
  • executes public-first active-force deletion;
  • persists permanent force receipts;
  • adds operation-specific dependency readiness;
  • supervises deletion and verification workers;
  • adds bounded shutdown and worker-failure handling;
  • covers PostgreSQL crash/reclaim boundaries;
  • removes duplicate executor and test-fixture paths;
  • migrates the Paykit local demo to persisted runtime-master-key schema v2.

Active force is the only intentionally unconditional deletion path.

Graceful Pubky tombstone publication remains a GET followed by unconditional PUT. A replacement observed before the PUT is preserved, but an out-of-band replacement between the final GET and PUT may be overwritten. This accepted Pubky 0.9.3 limitation is explicitly documented.

Contract and risk impact

  • Public API or SDK contract
  • Persisted data or migration
  • Authentication, authorization, identity, or secret handling
  • Payment or entitlement behavior
  • Runtime, deployment, or observability
  • No contract/risk impact

Migration:

  • 0017_content_lock_deletion_resource_replaced.sql

Notable contract and risk changes:

  • graceful deletion now executes through its durable phase machine;
  • force=true executes or escalates active-force deletion;
  • destructive external actions require exact live-claim ownership;
  • dependency readiness recovers only from operation-specific healthy evidence;
  • Compose secrets schema v2 persists locksRuntimeMasterKey;
  • schema v1 local-demo state fails closed and requires the documented destructive reset;
  • PurgeOperationalState remains deferred.

Verification

Run successfully on the exact final artifact:

  • cargo fmt --all -- --check — passed
  • cargo test --workspace --all-targets --all-features — passed
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — passed
  • npm --prefix examples/js-sdk run check — passed
  • npm --prefix examples/js-sdk run smoke:paykit-compose — passed
  • npm --prefix locks-sdk/bindings/js test — passed
  • bash scripts/test-compose-bootstrap.sh — passed
  • git diff --check codex/bitkit-local-e2e-fixes..HEAD — passed

Recorded focused results from the final run:

  • locks-service library: 355 passed
  • deletion integration: 29 passed
  • tombstone integration: 6 passed
  • PostgreSQL E2E: 12 passed
  • JS/WASM generated-package and example smoke checks: passed
  • Paykit Compose model, reader-worker, and bootstrap smoke checks: passed

Exact reviewed artifact:

  • Base: ba2cfc58d1932e7fd38071b9936d53c732f62ed6
  • Tip: c54edaea8dea0b06ae92d9d3216dc42f52e9b91c
  • Tree: 08a4785704a1fb236a31b4cd572afade94956d6a
  • Canonical patch SHA-256: c92dba51e52f0a257266f22dabb258f3a02ffd041039c752b32994da35a0d756

Independent exact-artifact reviews approved:

  • Bitkit and Compose integration;
  • semantic safety of the code reduction;
  • stack topology and preservation.

Documentation

Updated:

  • docs/API.md
  • docs/RUNTIME.md
  • docs/plans/2026-08-10-graceful-content-lock-deletion.md
  • examples/js-sdk/README.md

The documentation covers:

  • graceful and active-force behavior;
  • public failure and lifecycle projection;
  • the accepted Pubky GET-to-PUT overwrite race;
  • worker readiness and supervision;
  • Compose runtime-master-key schema v2;
  • fail-closed handling and destructive reset requirements for schema v1.

Checklist

  • The change is focused and self-reviewed.
  • Regression tests were added where practical.
  • No credentials, identities, private content, payment material, or generated local state are included.
  • Formatting and relevant tests/lints pass.

Run the durable graceful and active-force deletion lifecycle with exact claim fencing, storage-owned time, final-access draining, operation-specific readiness, supervised shutdown, and crash-safe PostgreSQL and memory behavior. Keep the accepted Pubky GET-to-PUT overwrite race explicit, and remove duplicate executor and test-fixture paths.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@dzdidi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(deletion): execute graceful and forced lock deletion - #21

Open
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution
Open

feat(deletion): execute graceful and forced lock deletion#21
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution

Conversation

@dzdidi

@dzdididzdidi commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Part 5 of the graceful-deletion stack. Depends on Part 4.

Completes the durable graceful and active-force deletion lifecycle.

Graceful execution:

  1. publishes and verifies the public tombstone;
  2. starts and drains frozen payment obligations;
  3. drains existing credentials;
  4. issues final credentials;
  5. drains final reads;
  6. verifies and removes frozen guarded content;
  7. verifies the retained tombstone;
  8. stops before the separately deferred operational-state purge.

The change also:

  • adds exact external-action ownership;
  • uses storage-authoritative time after the relevant fence;
  • executes public-first active-force deletion;
  • persists permanent force receipts;
  • adds operation-specific dependency readiness;
  • supervises deletion and verification workers;
  • adds bounded shutdown and worker-failure handling;
  • covers PostgreSQL crash/reclaim boundaries;
  • removes duplicate executor and test-fixture paths;
  • migrates the Paykit local demo to persisted runtime-master-key schema v2.

Active force is the only intentionally unconditional deletion path.

Graceful Pubky tombstone publication remains a GET followed by unconditional PUT. A replacement observed before the PUT is preserved, but an out-of-band replacement between the final GET and PUT may be overwritten. This accepted Pubky 0.9.3 limitation is explicitly documented.

Contract and risk impact

  • Public API or SDK contract
  • Persisted data or migration
  • Authentication, authorization, identity, or secret handling
  • Payment or entitlement behavior
  • Runtime, deployment, or observability
  • No contract/risk impact

Migration:

  • 0017_content_lock_deletion_resource_replaced.sql

Notable contract and risk changes:

  • graceful deletion now executes through its durable phase machine;
  • force=true executes or escalates active-force deletion;
  • destructive external actions require exact live-claim ownership;
  • dependency readiness recovers only from operation-specific healthy evidence;
  • Compose secrets schema v2 persists locksRuntimeMasterKey;
  • schema v1 local-demo state fails closed and requires the documented destructive reset;
  • PurgeOperationalState remains deferred.

Verification

Run successfully on the exact final artifact:

  • cargo fmt --all -- --check — passed
  • cargo test --workspace --all-targets --all-features — passed
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — passed
  • npm --prefix examples/js-sdk run check — passed
  • npm --prefix examples/js-sdk run smoke:paykit-compose — passed
  • npm --prefix locks-sdk/bindings/js test — passed
  • bash scripts/test-compose-bootstrap.sh — passed
  • git diff --check codex/bitkit-local-e2e-fixes..HEAD — passed

Recorded focused results from the final run:

  • locks-service library: 355 passed
  • deletion integration: 29 passed
  • tombstone integration: 6 passed
  • PostgreSQL E2E: 12 passed
  • JS/WASM generated-package and example smoke checks: passed
  • Paykit Compose model, reader-worker, and bootstrap smoke checks: passed

Exact reviewed artifact:

  • Base: ba2cfc58d1932e7fd38071b9936d53c732f62ed6
  • Tip: c54edaea8dea0b06ae92d9d3216dc42f52e9b91c
  • Tree: 08a4785704a1fb236a31b4cd572afade94956d6a
  • Canonical patch SHA-256: c92dba51e52f0a257266f22dabb258f3a02ffd041039c752b32994da35a0d756

Independent exact-artifact reviews approved:

  • Bitkit and Compose integration;
  • semantic safety of the code reduction;
  • stack topology and preservation.

Documentation

Updated:

  • docs/API.md
  • docs/RUNTIME.md
  • docs/plans/2026-08-10-graceful-content-lock-deletion.md
  • examples/js-sdk/README.md

The documentation covers:

  • graceful and active-force behavior;
  • public failure and lifecycle projection;
  • the accepted Pubky GET-to-PUT overwrite race;
  • worker readiness and supervision;
  • Compose runtime-master-key schema v2;
  • fail-closed handling and destructive reset requirements for schema v1.

Checklist

  • The change is focused and self-reviewed.
  • Regression tests were added where practical.
  • No credentials, identities, private content, payment material, or generated local state are included.
  • Formatting and relevant tests/lints pass.

Run the durable graceful and active-force deletion lifecycle with exact claim fencing, storage-owned time, final-access draining, operation-specific readiness, supervised shutdown, and crash-safe PostgreSQL and memory behavior. Keep the accepted Pubky GET-to-PUT overwrite race explicit, and remove duplicate executor and test-fixture paths.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@dzdidi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(deletion): execute graceful and forced lock deletion - #21

Open
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution
Open

feat(deletion): execute graceful and forced lock deletion#21
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution

Conversation

@dzdidi

@dzdididzdidi commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Part 5 of the graceful-deletion stack. Depends on Part 4.

Completes the durable graceful and active-force deletion lifecycle.

Graceful execution:

  1. publishes and verifies the public tombstone;
  2. starts and drains frozen payment obligations;
  3. drains existing credentials;
  4. issues final credentials;
  5. drains final reads;
  6. verifies and removes frozen guarded content;
  7. verifies the retained tombstone;
  8. stops before the separately deferred operational-state purge.

The change also:

  • adds exact external-action ownership;
  • uses storage-authoritative time after the relevant fence;
  • executes public-first active-force deletion;
  • persists permanent force receipts;
  • adds operation-specific dependency readiness;
  • supervises deletion and verification workers;
  • adds bounded shutdown and worker-failure handling;
  • covers PostgreSQL crash/reclaim boundaries;
  • removes duplicate executor and test-fixture paths;
  • migrates the Paykit local demo to persisted runtime-master-key schema v2.

Active force is the only intentionally unconditional deletion path.

Graceful Pubky tombstone publication remains a GET followed by unconditional PUT. A replacement observed before the PUT is preserved, but an out-of-band replacement between the final GET and PUT may be overwritten. This accepted Pubky 0.9.3 limitation is explicitly documented.

Contract and risk impact

  • Public API or SDK contract
  • Persisted data or migration
  • Authentication, authorization, identity, or secret handling
  • Payment or entitlement behavior
  • Runtime, deployment, or observability
  • No contract/risk impact

Migration:

  • 0017_content_lock_deletion_resource_replaced.sql

Notable contract and risk changes:

  • graceful deletion now executes through its durable phase machine;
  • force=true executes or escalates active-force deletion;
  • destructive external actions require exact live-claim ownership;
  • dependency readiness recovers only from operation-specific healthy evidence;
  • Compose secrets schema v2 persists locksRuntimeMasterKey;
  • schema v1 local-demo state fails closed and requires the documented destructive reset;
  • PurgeOperationalState remains deferred.

Verification

Run successfully on the exact final artifact:

  • cargo fmt --all -- --check — passed
  • cargo test --workspace --all-targets --all-features — passed
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — passed
  • npm --prefix examples/js-sdk run check — passed
  • npm --prefix examples/js-sdk run smoke:paykit-compose — passed
  • npm --prefix locks-sdk/bindings/js test — passed
  • bash scripts/test-compose-bootstrap.sh — passed
  • git diff --check codex/bitkit-local-e2e-fixes..HEAD — passed

Recorded focused results from the final run:

  • locks-service library: 355 passed
  • deletion integration: 29 passed
  • tombstone integration: 6 passed
  • PostgreSQL E2E: 12 passed
  • JS/WASM generated-package and example smoke checks: passed
  • Paykit Compose model, reader-worker, and bootstrap smoke checks: passed

Exact reviewed artifact:

  • Base: ba2cfc58d1932e7fd38071b9936d53c732f62ed6
  • Tip: c54edaea8dea0b06ae92d9d3216dc42f52e9b91c
  • Tree: 08a4785704a1fb236a31b4cd572afade94956d6a
  • Canonical patch SHA-256: c92dba51e52f0a257266f22dabb258f3a02ffd041039c752b32994da35a0d756

Independent exact-artifact reviews approved:

  • Bitkit and Compose integration;
  • semantic safety of the code reduction;
  • stack topology and preservation.

Documentation

Updated:

  • docs/API.md
  • docs/RUNTIME.md
  • docs/plans/2026-08-10-graceful-content-lock-deletion.md
  • examples/js-sdk/README.md

The documentation covers:

  • graceful and active-force behavior;
  • public failure and lifecycle projection;
  • the accepted Pubky GET-to-PUT overwrite race;
  • worker readiness and supervision;
  • Compose runtime-master-key schema v2;
  • fail-closed handling and destructive reset requirements for schema v1.

Checklist

  • The change is focused and self-reviewed.
  • Regression tests were added where practical.
  • No credentials, identities, private content, payment material, or generated local state are included.
  • Formatting and relevant tests/lints pass.

Run the durable graceful and active-force deletion lifecycle with exact claim fencing, storage-owned time, final-access draining, operation-specific readiness, supervised shutdown, and crash-safe PostgreSQL and memory behavior. Keep the accepted Pubky GET-to-PUT overwrite race explicit, and remove duplicate executor and test-fixture paths.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@dzdidi
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(deletion): execute graceful and forced lock deletion - #21

Open
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution
Open

feat(deletion): execute graceful and forced lock deletion#21
dzdidi wants to merge 1 commit into
stack/graceful-deletion/04-access-drainfrom
stack/graceful-deletion/05-execution

Conversation

@dzdidi

@dzdididzdidi commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Part 5 of the graceful-deletion stack. Depends on Part 4.

Completes the durable graceful and active-force deletion lifecycle.

Graceful execution:

  1. publishes and verifies the public tombstone;
  2. starts and drains frozen payment obligations;
  3. drains existing credentials;
  4. issues final credentials;
  5. drains final reads;
  6. verifies and removes frozen guarded content;
  7. verifies the retained tombstone;
  8. stops before the separately deferred operational-state purge.

The change also:

  • adds exact external-action ownership;
  • uses storage-authoritative time after the relevant fence;
  • executes public-first active-force deletion;
  • persists permanent force receipts;
  • adds operation-specific dependency readiness;
  • supervises deletion and verification workers;
  • adds bounded shutdown and worker-failure handling;
  • covers PostgreSQL crash/reclaim boundaries;
  • removes duplicate executor and test-fixture paths;
  • migrates the Paykit local demo to persisted runtime-master-key schema v2.

Active force is the only intentionally unconditional deletion path.

Graceful Pubky tombstone publication remains a GET followed by unconditional PUT. A replacement observed before the PUT is preserved, but an out-of-band replacement between the final GET and PUT may be overwritten. This accepted Pubky 0.9.3 limitation is explicitly documented.

Contract and risk impact

  • Public API or SDK contract
  • Persisted data or migration
  • Authentication, authorization, identity, or secret handling
  • Payment or entitlement behavior
  • Runtime, deployment, or observability
  • No contract/risk impact

Migration:

  • 0017_content_lock_deletion_resource_replaced.sql

Notable contract and risk changes:

  • graceful deletion now executes through its durable phase machine;
  • force=true executes or escalates active-force deletion;
  • destructive external actions require exact live-claim ownership;
  • dependency readiness recovers only from operation-specific healthy evidence;
  • Compose secrets schema v2 persists locksRuntimeMasterKey;
  • schema v1 local-demo state fails closed and requires the documented destructive reset;
  • PurgeOperationalState remains deferred.

Verification

Run successfully on the exact final artifact:

  • cargo fmt --all -- --check — passed
  • cargo test --workspace --all-targets --all-features — passed
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — passed
  • npm --prefix examples/js-sdk run check — passed
  • npm --prefix examples/js-sdk run smoke:paykit-compose — passed
  • npm --prefix locks-sdk/bindings/js test — passed
  • bash scripts/test-compose-bootstrap.sh — passed
  • git diff --check codex/bitkit-local-e2e-fixes..HEAD — passed

Recorded focused results from the final run:

  • locks-service library: 355 passed
  • deletion integration: 29 passed
  • tombstone integration: 6 passed
  • PostgreSQL E2E: 12 passed
  • JS/WASM generated-package and example smoke checks: passed
  • Paykit Compose model, reader-worker, and bootstrap smoke checks: passed

Exact reviewed artifact:

  • Base: ba2cfc58d1932e7fd38071b9936d53c732f62ed6
  • Tip: c54edaea8dea0b06ae92d9d3216dc42f52e9b91c
  • Tree: 08a4785704a1fb236a31b4cd572afade94956d6a
  • Canonical patch SHA-256: c92dba51e52f0a257266f22dabb258f3a02ffd041039c752b32994da35a0d756

Independent exact-artifact reviews approved:

  • Bitkit and Compose integration;
  • semantic safety of the code reduction;
  • stack topology and preservation.

Documentation

Updated:

  • docs/API.md
  • docs/RUNTIME.md
  • docs/plans/2026-08-10-graceful-content-lock-deletion.md
  • examples/js-sdk/README.md

The documentation covers:

  • graceful and active-force behavior;
  • public failure and lifecycle projection;
  • the accepted Pubky GET-to-PUT overwrite race;
  • worker readiness and supervision;
  • Compose runtime-master-key schema v2;
  • fail-closed handling and destructive reset requirements for schema v1.

Checklist

  • The change is focused and self-reviewed.
  • Regression tests were added where practical.
  • No credentials, identities, private content, payment material, or generated local state are included.
  • Formatting and relevant tests/lints pass.

Run the durable graceful and active-force deletion lifecycle with exact claim fencing, storage-owned time, final-access draining, operation-specific readiness, supervised shutdown, and crash-safe PostgreSQL and memory behavior. Keep the accepted Pubky GET-to-PUT overwrite race explicit, and remove duplicate executor and test-fixture paths.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@dzdidi