Skip to content

feat: expand Firebase compatibility inventory and parity - #1

Draft
t-k wants to merge 3620 commits into
mainfrom
feat/compatibility-inventory
Draft

t-k wants to merge 3620 commits into
mainfrom
feat/compatibility-inventory

Conversation

@t-k

@t-k t-k commented Sep 13, 2026 •

Copy link
Copy Markdown
Owner

Scope and current behavior

Implement application-facing Identity Platform and Firestore Standard/Native compatibility on feat/compatibility-inventory, excluding Enterprise-only features. This remains a draft: COMPAT_VERIFIED 0/14. READY_FOR_COMPATIBILITY_REVIEW has not been reached.

Auth configuration connects canonical config, namespace-specific management APIs, runtime enforcement, persistence and SDK harnesses for password policy, account linking, client permissions, email privacy, owned Blocking Functions selection/token forwarding and local signup-quota simulation. Generated UID reservations carry request ownership and reset generation; callback revision checks run inside the commit boundary. Firestore changes cover Rules query-proof soundness, REST/gRPC diagnostics, transaction/stream safeguards and SDK/Listen harnesses. Local implementation and test coverage do not establish complete production parity.

Production evidence and saved repairs

  • Document size/depth: One approved FS-DATA-WRITE-LIMITS-02 iteration at 40dfc0da3 recorded 16 observations using 36/40 requests, typed cleanup, unchanged configuration and released locks. Original comparison: eight diagnostic mismatches and eight expected nondeterministic differences. The reviewed repair at 8b33aac4d, artifact 76f855367910ad237de6ffd491091f20bcdccdb2e5eb8ee417e80b94bf6ac397, reuses that immutable production receipt: 1 MATCH, 15 EXPECTED_NONDETERMINISM, no remaining mismatch or indeterminate row. The original comparison remains intact.
  • Write/transaction contention: One approved iteration at dee737c14 used 33 requests including two bounded OAuth requests, three owned documents and approximately 63.48 seconds. Typed cleanup, unchanged configuration and shared reservation release were independently verified. The original GetDocument NOT_FOUND diagnostic mismatch is preserved. Runtime repair 567565bdd, artifact e792e0bc1947bbd227b3ee9778eca093cda94fbde767911dd6139a6cbfd90be4, passes a new owned local rehearsal. The independently reviewed v2 saved comparator at 6dff3192a keeps the pre-fix pair SEMANTIC_MISMATCH and classifies the repaired pair EXPECTED_NONDETERMINISM.

Both single-iteration permissions are consumed. Neither repair repeated production. Conservative accounting is not a measured invoice. These finite observations close specific conditions and one diagnostic cluster, not an entire parent.

Public records:

  • spec/compatibility/broad-runs/fs-write-limits-02-40dfc0da3-production-result.json
  • spec/compatibility/broad-runs/fs-write-limits-02-8b33aac4d-saved-result.json
  • spec/compatibility/broad-runs/fs-write-txn-567565bdd-saved-result.json
  • docs/compatibility/fs-write-limits-campaign-preparation.md
  • docs/compatibility/fs-write-transaction-campaign-preparation.md

Acquisition and regression safeguards

Acquisition failure is permanent during ordinary saved comparison: v2 receipts retain final source, dirty state, artifact and collector measurements. Explicit hash-bound historical validation accepts only declared legacy receipts. Shared locks require typed, request-bound cleanup evidence, and phase deadlines are rechecked after shared-ledger waits. gRPC credential rejection stops later grants while preserving recovery responsibility. Stream terminal handling distinguishes delayed status from missing responses and bounds all event failures.

The three Query IN30/31 review defects are repaired through cb7bcc7d4: independent hierarchy validation, current-run conditional-creation/version evidence before deletion, and final publication failures reflected in completion. Actual local API execution confirms creation, IN30 success, IN31 refusal, unchanged state, conditional cleanup and typed absence. This is local evidence only.

Validation

  • Fixed source 4658dc3b520728cc874453daddb78ca858e6f2fc: cargo nextest run --workspace --profile pr passed 2,623 tests, with 14 slow tests and 81 skipped. Normal CI and inventory CI both completed successfully at that source. CI formatting/compilation is separate from the local workspace test execution.
  • The ignored-test audit distinguishes formal/Java, real Functions SDK, release qualification and intentional leak-driver obligations. All seven release/resource tests were explicitly run in release mode at 49e445e05 and passed after correcting the million-document test fixture's history capacity; independent review approved the test-only change. Historical PR-profile skips remain skips, and these local checks are not production parity.
  • The reviewed gRPC repair passed 385 adapter tests with one existing skip. Both affected Quint models were regenerated; 23 selected Connect/evidence checks passed. This does not imply all formal lanes ran at the latest source.
  • The versioned stream recompare passed 92 Node tests and the actual saved-input authority test, with independent review. Query IN repairs passed 40 focused tests, Ruff and independent review.
  • Source 06ab2a6ad also explicitly ran all 24 selected ignored Functions SDK/discovery/runtime tests successfully using the locked SDK dependencies. This is SDK-local evidence; the normal workspace result remains 81 skips.
  • The workspace verification above remains bound to 4658dc3b5, not a rebuild of the later Commit acquisition source.

Latest preparation and execution status

The reviewed Query IN30/31 repair is followed by a separate closed offline O4 preparation bridge: 125 targeted tests and independent review passed. It has no production send capability and remains BLOCKED_TECHNICAL until live binding, admission and recovery contracts are complete. Request-byte boundary preparation includes a reviewed local collector with exact raw request/response evidence and version-bound cleanup. A real-artifact local shadow at a3153c176 observed 200/200/typed 413 for canonical 10,485,759/760/761-byte requests and 51 typed absences. The original collector reported incomplete because it expected 400; the repaired collector records 413 as a local semantic discrepancy, never production parity. The current campaign suite passes 61 tests. A fixed-origin, bounded HTTPS transport was integrated at 79eb68be5 after independent correctness and security review; 48 transport/collector tests and Ruff passed at the integrated source. It does not hold credentials or provide campaign admission. Schedule-aware Gate, shared Ledger binding, O7 freeze, production runner and comparator remain closed, so no request-byte production operation is authorized by this addition.

The first Commit500/501 production attempt stopped after two OAuth calls and two metadata reads because the live database projection did not match its frozen digest. It sent zero Firestore data requests and created zero documents. The immutable failed receipt remains retained. A separately reviewed no-data abort moved its shared reservation to aborted-no-data, stopped the Gate and released its locks while retaining nonce and budget history; independent audit found no active reservation. No automatic retry occurred. A fresh campaign requires a new nonce, manifest, permission binding, O7 approval and live preflight. The saved database response is only a candidate baseline and must not be auto-rebased on drift.

The checked-in Explain preparation was refreshed as v8 without changing historical v7 evidence. Portable owned-runner tests no longer require private docs.local artifacts and retain independent checks of the pinned production artifact digest. Both fixes were independently reviewed. At fixed source a3153c176, the broad offline suite passed 1,363 tests with 14 skips and exit zero; inventory CI also succeeded. The earlier moving-source checkout failure passed in isolation and the Explain binding was repaired by v8. The follow-up request-byte collector commit has 61 passing focused tests, Ruff and independent correctness/security review; inventory CI completed successfully at 80840b4db. A derived replay of the immutable local shadow verified 258 rows, 241 response sidecars and three request bodies without sending new requests; it retains the observed 413 as a local semantic discrepancy. A current-head real firebase@12.18.0 password-policy SDK shadow also passed weak/compliant controls with condition-level lowercase/uppercase results and unchanged Auth state; this remains SDK-local evidence.

Remaining work

FS-DATA-WRITE is the next closure target. Commit500/501, request-byte limits, index/field limits and broader declared Commit/BatchWrite conditions require finite evidence and final review. The separate Commit attempt above did not reduce an unobserved condition. All other parent conditions remain in the existing denominator. Production observations, saved-production comparisons, local artifact runs, SDK-local checks, formal evidence and documentation evidence remain separate. The aggregate owner budget does not replace per-campaign frozen bindings, resource locks, complete recovery contracts or O7 admission. No main push, merge or release is included.

Current checkpoint (2026-09-19)

The current branch head is bccce023baf9733b96ff32a9d9a0784176f12608. O8 production transport authorization is now capability-gated at the public request, descriptor, and lower-level real-exchange boundaries; capability state is authoritative and immutable, and acquisition exit revokes it. Shared Gate/Ledger finish refuses to release reservations while conditional creates remain uncertain. A scheduled read-only Gate fixture was corrected to declare non-creating observation slots explicitly; the shared Gate suite passes 143 tests.

Normal CI at this head is successful. The compatibility-inventory workflow's long offline job is still running. The 81 skipped workspace jobs remain intentionally skipped and are tracked as unexecuted evidence, not failures or production verification.

Production has not been run in this checkpoint. The owner approvals under the USD 10 ceiling remain bounded, but O7 still lacks a complete current permission/manifest/credential/preflight package and a true end-to-end CLI-to-collector production-path proof. Read-only project and Firestore database lookup succeeded for fireemu-35fe6 / (default); Identity Toolkit config lookup returned HTTP 403 for the available principal. No configuration mutation, credential use for observation, new nonce, or production request was performed. The draft remains COMPAT_VERIFIED 0/14 until those evidence and review conditions are satisfied.

Current checkpoint (2026-09-19, latest push)

The branch is now at a4572e6c9. The latest fixes include legacy schedule-less create tracking through Gate/Ledger finish, O8 local lifecycle alias guards, refreshed request-byte local-shadow evidence, regenerated Explain v8 manifest/binding, and a production transport admission hardening. The fixed-limits transport no longer exposes a mutable session registry or launchable worker network path: production I/O stays inside an admitted bridge session, while direct worker entry and unbound request calls fail closed.

Focused validation at this checkpoint: 177 fs-write-limits/bridge/shared-gate tests passed before the final session-object change; the final transport/bridge suite passed 33 tests and Ruff. Normal CI for a4572e6c9 passed; compatibility-inventory is still running. The generated artifacts are committed and the checked-in Explain stability test passes. Production observation has not been run from this checkpoint. The approved under-USD-10 envelopes remain bounded, but O7 still requires a current campaign binding, independent security approval, credential/preflight evidence and recovery lock verification before any request is sent.

Current checkpoint (2026-09-19, reservation-bound transport)

Latest branch head is f5a71e984. Production transport now requires a ReservedCoordinator, validates its Ledger claim at bind time and before each exchange, and rejects direct transport/worker entrypoints. The focused production bridge suite passes 18 tests and Ruff. The normal CI and compatibility-inventory workflows for this latest push are still pending/running.

Production remains unexecuted. User permission under USD 10 is recorded, but current O7 admission still requires a frozen campaign package, independent security approval, live credential/preflight binding, immutable collector/comparator binding, and complete recovery verification.

Latest checkpoint (2026-09-19, legacy unknown-create coverage)

Latest branch head is 99decc9f4. The schedule-less legacy Gate path already inferred potential creating operations and retained pending/unknown outcomes through both Gate.finish() and Ledger.finish(). Added regression coverage now exercises legacy conditional Commit and conditional PATCH shapes with timeout, HTTP 500 and HTTP 504 after a complete recovery sequence; all seven targeted cases pass. The non-authorizing O8 local proof now explicitly expects a held reservation when transform-only Commit acknowledgements cannot prove a non-creating operation, preserving fail-closed ownership rather than treating the local fixture as released production evidence. Focused Gate/Ledger/O8 tests pass 287 cases and Ruff passes.

Normal CI for 99decc9f4 is running and the compatibility-inventory workflow is queued. Production remains unexecuted; the user's bounded under-USD-10 permission does not replace current O7 manifest, credential, recovery and independent-review gates.

Checkpoint: 64806be (2026-09-19)

  • Fixed legacy schedule-less ownership accounting by recognizing explicit currentDocument.exists=true transform writes as non-creating while retaining fail-closed ownership for missing, malformed, or mixed preconditions.
  • Updated the Commit transform compiler to emit the existing-document precondition for exact and over-limit transform writes.
  • Validation: 7 focused Gate cases, transform compiler 8, Gate adapter 17, Commit production 4, O8 local proof, and Ruff passed. A long combined acquisition invocation was stopped while idle and is not claimed as evidence.
  • No production request was sent. O7 remains blocked pending current artifact/binding refresh, credential/preflight, immutable collector/comparator, cleanup/recovery, and independent security approval.

Offline round35 import (271b4c9af, 2026-09-20)

Imported the cumulative 209-file patch based on 64806be16 from the externally prepared round35 bundle. The three round35-specific files add v1 Task Queue discovery, HTTP signature handling for Tasks and Blocking Auth, and invocation generation bound to the announced manifest. Rust formatting was applied, and the affected AuthTotp and CompatibilitySelection Quint evidence was regenerated with the repository's mutation runner.

Local checks so far: Node runner 603/603, Listen 284/284, Auth preparation Python 78/78, cargo check --workspace --all-targets, cargo fmt --check, traceability, and Quint evidence contract pass. npm tests report 28 pass and 2 installed-native skips. Workspace nextest and the broad Python corpus are still running; their outcomes will be reported separately. The original round35 environment used test doubles for SDK metadata, Express, and Task Queue dispatch, so this import does not establish native Task Queue or production compatibility. No production request was sent.

Checkpoint: d10727a (2026-09-20)

Imported the bounded round36 and round37 delta patches after checking prior-round cumulative coverage. Round36 resolves endpoint option expressions; an independent security review found and closed rejected-Promise process termination. Round37 resolves trigger option expressions; an independent correctness review found and closed empty projected Pub/Sub topics and rejected async trigger records. Both reviews now have no blocking findings. Current Node runner suite: 722 passed, 0 failed.

The earlier broad CI failure at fbf3a8095 comprised nine stale current-local-evidence binding tests. The four affected evidence lanes were regenerated from clean source commit 4130d105b, historical evidence was preserved, and independent evidence review approved the binding. The compatibility-inventory run for 4130d105b passed; runs for later commits are still in progress or queued. Normal CI for 4e6b6ce2a passed; the new d10727ad1 run is pending. No new production observation was performed. This checkpoint does not establish native Functions SDK/Task Queue behavior or parent compatibility closure.

Production queue check: 80815a5 (2026-09-20)

Luna agents audited current O7/O8 readiness without receiving credentials or sending production requests. The previously authorized FS-DATA-WRITE-LIMITS-02 and Write/transaction campaigns already have immutable production receipts; their single-iteration permissions are consumed. Commit field-transform 500/501 is likewise already observed, so those cases are not repeated. The next unobserved FS request-byte boundary has a locally wired O8 path and its focused offline suite passed 480 tests. Its current local shadow was regenerated from clean source d10727ad1, with complete recording and typed cleanup, then independently reviewed and published at 80815a5fe. This is local evidence only (productionExecuted=false). O7 still lacks a frozen campaign-specific permission/window, current credential binding, shared reservation/locks, tariff acceptance and final preflight. No campaign is PROD_READY, and this checkpoint sent no production request.

@t-k

t-k commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

Integrated at 71596358 (test(conformance): classify local-only admin probe rows).

The three bounded Firestore Admin inventory requests (list-databases, get-database, get-named-database) are now explicitly marked localOnly. pnpm -C conformance run firestore:check requires complete local HTTP observations for them, but excludes them from official-emulator compatibility claims. The saved production matrix and historical evidence remain unchanged.

Verification:

  • Firestore probe tests: 6 passed
  • pnpm -C conformance run firestore:check: 323 gated rows matched; 3 local-only rows observed
  • pnpm -C conformance run selftest: 61 passed
  • pnpm -C conformance run fmt:check: passed
  • pnpm -C conformance run lint: passed with existing warnings

@t-k

t-k commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

Follow-up on 71596358: regenerated spec/compatibility/broad-catalog.json from the existing generator after the three Firestore Admin inventory steps were classified as localOnly. This fixes the source-bound catalog digest checked by offline-acquisition-integrity; historical production matrices and receipts remain unchanged.

Verification: broad.py --check-catalog passed; REST admin/document coexistence 3/3, Auth export provider regressions 3/3, project/SAML mask regressions 2/2, Explain campaign tests 121/121, and saved Explain recompare tests 6/6. No production operation was performed.

@t-k

t-k commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

The refreshed CI is green: offline-acquisition-integrity and feature-inventory-integrity both passed for b63634b2; the PR gate also passed. The remaining workflow jobs are skipped by the repository path filters. The branch is clean and no production request was made during this continuation.

@t-k

t-k commented Sep 16, 2026

Copy link
Copy Markdown
Owner Author

Local Explain shadow checkpoint (feature HEAD 4d03a2f2)

  • The existing shared local adapter completed the six bounded query/aggregation Explain cases, setup/readback, and owned cleanup: 12 observation rows and 6 recovery rows.
  • The redacted binding is spec/compatibility/broad-runs/a30b39b5-explain-local-shadow.json, binding execution commit a30b39b556fbf8239ecb104ba8835e08ae903ad2, manifest 8f9ea90e…785ffc, observer 9e5b2f61e…dcb4c4f, comparison contract b0f1a1d0…de8fab, configuration cf2b716a…3db80, and binary artifact a90ba5ba…17d4b.
  • Recording, state verification, cleanup, process stop and listener closure all passed. productionExecuted: false and compatibility: not-observed; no Cloud operation or receipt rewrite occurred.
  • Targeted campaign tests: 121 passed. An independent read-only review approved the evidence binding with no blockers.

This is local shadow evidence only and does not promote any parent feature group.

t-k added 24 commits September 24, 2026 01:48
Source b25d749: 630/631 AUTH-ACCOUNT rows (the one documented A12 message
divergence), 23 historical rows and 48 saved-reference cases match, and the
workspace passes 3290 tests.
The independent closure and security review approved round 3 at 3eb6830:
32/32 conditions are verified on artifact db8cafcd (source b25d749), with the
gson message text of one row as the owner-decided divergence A12. The closure
test binds the approval to the evidence artifact, and the compatibility table
records the parent as closed.
t-k added 29 commits September 24, 2026 22:03
A read-write transaction continues an ordered page from a token issued
outside it, holds the whole listing (an out-of-band write to a document
it did not return is refused while it is open) and commits. Inside a
transaction, name-ordered pages, pages whose token carries no order
values, and showMissing continue and list as outside one. The fault test
also checks the transaction and incarnation counters. Test-only: the
release build is unchanged (sha256 32e58e92).
… transaction

A token with forged order values moves the cursor within its own
listing (fireemu issues the tokens; nothing else is reachable). A
read-write transaction holding an ordered listing also refuses a write
to a document of an earlier page and an insert before the token.
Test-only.
Regenerate the CompatibilitySelection evidence digest for identity_toolkit.rs.
…3 preflight

866bb06 removed NUMBER from request_bytes_preflight.py. limits_03_preflight.py
still copied it at import time, so every compat-broad shard failed at collection.
…/compatibility-inventory

Brings in FS-QUERY-INDEX (COMPAT_VERIFIED on the query sandbox) and the four
FS-DATA-WRITE list conditions' implementation and evidence, per addendum 8 and the
2026-09-24 owner decision. CHANGELOG sections were combined; the public status
table keeps feat's FS-DATA-WRITE row and the branch's FS-QUERY-INDEX row.
…uching the strict campaign

866bb06 moved REQUEST_TARGETS to the strict 11 MiB Commit pair. The exporter
then generated the saved production samples decoded-request-bytes/{under,exact,
over} at 11 MiB, so their recipe digests no longer matched and two FS-DATA-WRITE
closure tests failed; the offline metric audit silently became an 11 MiB study.

request_bytes_catalog_samples.py compiles the 10 MiB triple from a private
instance of the compiler with only its target triple replaced. The compiler and
campaign stay byte-identical, so the published 11 MiB local shadow still binds
them. The exporter and the metric audit use the new module.
…ist and stay pinned

closure_records.py reads every spec/compatibility/closure/*.json: each cited
repository path must exist, a #fragment must name an entry (a heading anchor in
Markdown), a <name>Path / <name>Sha256 pair must match, and cited records under
spec/ and conformance/ are pinned in record-digests.json so they cannot change
without an explicit --write in the same commit. A closure may not cite a suite
that CI no longer runs (RETIRED_SUITES in the compatibility-inventory workflow).
…on doc

The checked-in matrix cites file:line locations that moved with later code
changes (rest/mod.rs and others), so test_fs_config_surface_matrix and
test_fs_config_docs failed. Regenerated with surface_matrix.py --write and
doc_render.py --write; only the cited line numbers change.
…ee directory

test_historical_worktree_parent_accepts_the_real_repository_parent required the
developer checkout's .worktree directory and failed on every CI runner. Build a
real worktree parent under tmp_path instead; the refusal test for a symlinked
parent is unchanged.
…shard by duration

Owner decision 2026-09-25. The retired test files are listed once in the
workflow's RETIRED_SUITES with the reasons: each fails because 866bb06 moved
the shared request_bytes_preflight.py to the sandbox project (passes at
866bb06^, fails at 866bb06), because an O7/O8 shadow or runtime binding
predates later source changes, because it fails only on the CI runner, or
because it alone exceeds the 45-minute job limit. They run on demand through
workflow_dispatch (run_retired) with the O7-era history.py frozen-bytes check;
no test code or expectation changed.

compat-broad shards are planned from measured per-file durations (7 shards,
about 27 minutes for the fullest). A new required job checks the records every
closure cites and runs the closure contracts.
Artifact-backed tests refuse a dirty working tree, and the list written into
the checkout made it dirty.
fs-rules-publication/test_o5_user_token_comparator_v2.py builds a fully bound
collection per test (about 2 minutes each, 178 tests), so no file-level plan
fits the 45-minute limit. broad_shards.py now runs a file longer than 0.8 of
the budget as contiguous chunks of whole tests, rebases the collected IDs on
the repository path, and plans 22 shards (about 31 minutes for the fullest).

Also retire fs-write-limits/test_limits_03_baseline_prep.py: limits-03 takes
its project from the shared request-byte preflight, which now names the
sandbox, while baseline preparation requires fireemu-35fe6.
…ed CI

Owner decision 2026-09-25: auth-totp-enroll/test_mfa_shadow_binding.py belongs
to the O2/O8 campaign for fireemu-35fe6, which AUTH-MFA replaces with its
sandbox closure, so its shadow is not re-taken. The file moves to
RETIRED_SUITES and stays runnable on demand; no closure cites it.
…n seven shards

The fs-rules-publication O5 campaign targeted fireemu-35fe6; the FS-RULES sandbox
harness replaced it as the lane's closure evidence (owner decision 2026-09-25). Its
collector tests predate the 2026-09-22 Rules management session requirement and
test_o5_user_token_comparator_v2.py alone took about 6 hours of shard time. The 25
files join RETIRED_SUITES; code and records stay. Without them seven shards keep
every shard under 28 minutes.

(cherry picked from commit 6fcfd9b)
@t-k
t-k force-pushed the feat/compatibility-inventory branch from e366c8a to 368c0e9 Compare September 28, 2026 09:39

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant