fix(rectification): product-domain open wrapper runs as invoker; V10 turn append in history test and replay harness; rename segment migrations (BUG-1131)

- open_agentic_rectification_case_v2 (12 args) becomes SECURITY INVOKER: the
  immutable-skill ACL reconciliation leaves EXECUTE on the 11-arg open only to
  service_role, so the definer wrapper hit 42501 on every homepage/new open.
- The pending-opening read moves to owner function
  agentic_rectification_opening_pending_v1, granted to service_role only.
- History test and persisted replay harness append turns through the V10
  request-idempotent overload; the V9 overload is revoked from service_role.
- Opening test fixture adds the required birth_time_source.
- Segment migrations renamed to 20261001* so they sort after staging's
  20260930* migrations on both fresh and existing databases.
- Stale Windows replay replaced with the production-path replay (M1/M2 equal
  to accepted research, implementation_identity included).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eEAG8HD3mm8gsKXgk8uU8
This commit is contained in:
Jesse_Chen
2026-10-01 08:04:05 +08:00
co-authored by Claude Opus 5.5
parent 66f087b588
commit 73605c3b8e
8 changed files with 79203 additions and 79152 deletions
@@ -13,7 +13,7 @@ import { decideAfterInferenceChange, rectificationFollowupCatalog } from "../src
import type { EvidenceKind } from "../src/lib/rectification-agentic/v9/evidence-model.ts";
import { resolveRectificationProductDomain } from "../src/lib/rectification-agentic/v9/product-domain.ts";
import { scoreAndPersistCurrentEvidence } from "../src/lib/rectification-agentic/v9/score-persist.ts";
import { appendV9Turn, confirmV9Evidence, loadV9CaseDossier, proposeV9Evidence } from "../src/lib/rectification-agentic/v9/tool-service.ts";
import { confirmV9Evidence, loadV9CaseDossier, proposeV9Evidence } from "../src/lib/rectification-agentic/v9/tool-service.ts";
import { startPostgresFixture } from "../tests/helpers/postgres-fixture.ts";
import { segmentReplayOracleAnswer } from "./rectification-segment-oracle.ts";
@@ -81,11 +81,14 @@ try {
assert.equal(seeded.case.rectificationDomain, domain);
trace.domain = seeded.case.rectificationDomain;
trace.targets = targetChartsForDomain(seeded.case.rectificationDomain);
trace.stage = "appendV9Turn";
trace.stage = "append_turn_v10";
trace.ledger_before = ledger();
const turn = await appendV9Turn(service, userId, caseId, {
modelName: "public-benchmark-oracle-not-provider", userMessage: row.events.map(event => event.summary).join("; "),
});
// Same V10 request-idempotent overload as agent-run-prepare.ts; the V9 overload is revoked from service_role.
const appended = await service.rpc("append_agentic_rectification_turn", { p_user_id: userId, p_case_id: caseId,
p_user_message: row.events.map(event => event.summary).join("; "), p_assistant_message: null,
p_model_name: "public-benchmark-oracle-not-provider", p_model_version: null, p_status: "pending", p_request_id: randomUUID() });
assert.equal(appended.error, null, JSON.stringify(appended.error));
const turn = { turnId: (appended.data as { turn_id: string }).turn_id };
trace.stage = "evidence";
for (const event of row.events) {
const proposed = await proposeV9Evidence(service, userId, caseId, {