fix(rectification): product-domain open wrapper runs as invoker; V10 turn append in history test and replay harness; rename segment migrations (BUG-1131)
- open_agentic_rectification_case_v2 (12 args) becomes SECURITY INVOKER: the immutable-skill ACL reconciliation leaves EXECUTE on the 11-arg open only to service_role, so the definer wrapper hit 42501 on every homepage/new open. - The pending-opening read moves to owner function agentic_rectification_opening_pending_v1, granted to service_role only. - History test and persisted replay harness append turns through the V10 request-idempotent overload; the V9 overload is revoked from service_role. - Opening test fixture adds the required birth_time_source. - Segment migrations renamed to 20261001* so they sort after staging's 20260930* migrations on both fresh and existing databases. - Stale Windows replay replaced with the production-path replay (M1/M2 equal to accepted research, implementation_identity included). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eEAG8HD3mm8gsKXgk8uU8
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
66f087b588
commit
73605c3b8e
@@ -13,7 +13,7 @@ import { decideAfterInferenceChange, rectificationFollowupCatalog } from "../src
|
||||
import type { EvidenceKind } from "../src/lib/rectification-agentic/v9/evidence-model.ts";
|
||||
import { resolveRectificationProductDomain } from "../src/lib/rectification-agentic/v9/product-domain.ts";
|
||||
import { scoreAndPersistCurrentEvidence } from "../src/lib/rectification-agentic/v9/score-persist.ts";
|
||||
import { appendV9Turn, confirmV9Evidence, loadV9CaseDossier, proposeV9Evidence } from "../src/lib/rectification-agentic/v9/tool-service.ts";
|
||||
import { confirmV9Evidence, loadV9CaseDossier, proposeV9Evidence } from "../src/lib/rectification-agentic/v9/tool-service.ts";
|
||||
import { startPostgresFixture } from "../tests/helpers/postgres-fixture.ts";
|
||||
import { segmentReplayOracleAnswer } from "./rectification-segment-oracle.ts";
|
||||
|
||||
@@ -81,11 +81,14 @@ try {
|
||||
assert.equal(seeded.case.rectificationDomain, domain);
|
||||
trace.domain = seeded.case.rectificationDomain;
|
||||
trace.targets = targetChartsForDomain(seeded.case.rectificationDomain);
|
||||
trace.stage = "appendV9Turn";
|
||||
trace.stage = "append_turn_v10";
|
||||
trace.ledger_before = ledger();
|
||||
const turn = await appendV9Turn(service, userId, caseId, {
|
||||
modelName: "public-benchmark-oracle-not-provider", userMessage: row.events.map(event => event.summary).join("; "),
|
||||
});
|
||||
// Same V10 request-idempotent overload as agent-run-prepare.ts; the V9 overload is revoked from service_role.
|
||||
const appended = await service.rpc("append_agentic_rectification_turn", { p_user_id: userId, p_case_id: caseId,
|
||||
p_user_message: row.events.map(event => event.summary).join("; "), p_assistant_message: null,
|
||||
p_model_name: "public-benchmark-oracle-not-provider", p_model_version: null, p_status: "pending", p_request_id: randomUUID() });
|
||||
assert.equal(appended.error, null, JSON.stringify(appended.error));
|
||||
const turn = { turnId: (appended.data as { turn_id: string }).turn_id };
|
||||
trace.stage = "evidence";
|
||||
for (const event of row.events) {
|
||||
const proposed = await proposeV9Evidence(service, userId, caseId, {
|
||||
|
||||
Reference in New Issue
Block a user