Implement the optional host-authority interface and minimal local/reference profile from specification §18 and merged conformance #73 / #77. Related specification #70 and #90 / #92.
The pure core and simple embedded application transaction remain coordinator-free. This work supplies explicit host/plugin scope identity, ownership epoch, writer/worker fencing, guarded transaction, native fate and frozen-inventory interfaces. Implement only local/reference behavior; no distributed coordination service, leader election, managed control plane or private hosted infrastructure.
A claimed guarded write must hold the actual authority guard through the same native checkpoint/journal commit or rollback. A separate authority check followed by unrelated CAS is insufficient. Unknown transaction fate blocks freeze, retirement and activation until native evidence resolves it and old sessions are fenced. Scope allocation remains permanently reserved. Unsupported worker, inventory or safe-relocation capabilities fail closed; do not certify safe relocation before the separate recovery suite.
Acceptance:
- production execution of all applicable 22 authority operations, six composition rows, seven clocks, seven worker checks, nine native traces, allocation and four unavailable/unsupported refusal cases;
- configured reports bind exact installed source closure, configuration, instance, scope, storage boundary, authority, participant inventory and topology, with truthful unsupported capabilities;
- actual concurrent native writer/freeze, rollback, lost response, process restart and unknown-fate probes;
- no mutation, callback/dispatch or information leak on stale/unauthorized requests;
- complete existing engine/artifact/conformance gates, Python 3.11/3.12/3.13, strict format/lint/types, live PostgreSQL persistence, packaging and clean installs;
- updated unreleased 0.3.0 notes and independent exact-head LGTM.
One issue, one PR. No compatibility layer, core timer, tag or publication.
Implement the optional host-authority interface and minimal local/reference profile from specification §18 and merged conformance #73 / #77. Related specification #70 and #90 / #92.
The pure core and simple embedded application transaction remain coordinator-free. This work supplies explicit host/plugin scope identity, ownership epoch, writer/worker fencing, guarded transaction, native fate and frozen-inventory interfaces. Implement only local/reference behavior; no distributed coordination service, leader election, managed control plane or private hosted infrastructure.
A claimed guarded write must hold the actual authority guard through the same native checkpoint/journal commit or rollback. A separate authority check followed by unrelated CAS is insufficient. Unknown transaction fate blocks freeze, retirement and activation until native evidence resolves it and old sessions are fenced. Scope allocation remains permanently reserved. Unsupported worker, inventory or safe-relocation capabilities fail closed; do not certify safe relocation before the separate recovery suite.
Acceptance:
One issue, one PR. No compatibility layer, core timer, tag or publication.