Commit Graph

7 Commits

Author SHA1 Message Date
Teknium 696662997b Revert "refactor(gateway/hosted_rooms): reflow multi-line SQL constants (whitespace-only, parity-verified)"
This reverts commit fa827f596e.
2026-09-02 17:18:13 -07:00
Teknium 598065384d refactor(gateway/hosted_rooms): driver generation-transition spec table + run-fence transition helper; replicas ingest_page row-state/store extraction 2026-09-02 17:14:41 -07:00
Teknium fa827f596e refactor(gateway/hosted_rooms): reflow multi-line SQL constants (whitespace-only, parity-verified) 2026-09-02 16:46:00 -07:00
Teknium c4bc0ada79 refactor(gateway/hosted_rooms): inline replica clock helper, collapse driver literal 2026-09-02 16:23:44 -07:00
Teknium 44e37bc7e3 refactor(gateway/hosted_rooms): table-driven task transitions in hosted_room_driver; fold replica schema init, share leaf helpers (-40% LOC, parity-neutral) 2026-09-02 16:19:39 -07:00
Teknium 659c6b9fff refactor(gateway): simplify session, status, stream_consumer, kanban_watchers, relay adapter, hosted-room driver/discussion/replicas, shutdown/lifecycle, pairing, channel_directory, control_socket and small modules 2026-09-02 13:31:54 -07:00
Teknium e730deedd1 feat(bot-mode): Group Chats survive the authority gateway dying — log replication and fenced takeover
Every participant gateway can now keep a durable copy of a hosted room's
ordered log and continue the room when its authority host is gone:

- gateway/hosted_room_replicas.py: replica store in root state.db.
  ingest_page() persists authority-stamped groups.log pages idempotently,
  refusing sequence gaps and authority-epoch regressions. promote_replica()
  continues the room locally at epoch+1 with a lineage-proving
  authority.claimed event; the stale owner is fenced everywhere the claim
  replicates. demote_room() lets a returning stale authority fence itself
  (authority.lost) upon observing a newer epoch, killing split-brain writes.
- tui_gateway/methods_groups.py: groups.replicate / groups.replica_state /
  groups.promote / groups.demote RPC surface. Promotion requires
  confirm=true — storage decides HOW takeover is atomic and provable, the
  caller (user action now, lease/quorum driver later) decides WHEN it is
  safe, matching the boundary blessed on #97681.

Validation: 20 new tests incl. a full failover round-trip (A hosts, B
replicates incrementally, A dies, B promotes with complete history, A
returns demoted and fenced); 69 total across the hosted-rooms area; E2E
with two real gateway stores and real install identities.
2026-08-30 20:39:58 -07:00