{"_id":"@alma-harness/execution","_rev":"7-45a91b5e21dbaea39722b839bb4d3b40","name":"@alma-harness/execution","dist-tags":{"latest":"0.10.1"},"versions":{"0.6.0":{"name":"@alma-harness/execution","version":"0.6.0","license":"Apache-2.0","_id":"@alma-harness/execution@0.6.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"aaa6568d858e0885a195be08478a1fb94c51a08f","tarball":"https://registry.npmjs.org/@alma-harness/execution/-/execution-0.6.0.tgz","fileCount":12,"integrity":"sha512-A7l9R5lHTbC8gMFRDmMXh/p24GrGIyblT2Lt3v0Pdm56kybGibNBPpg2DySwzi9TfgWXSKeRUzujDXRMVhSQOw==","signatures":[{"sig":"MEYCIQCg3dnh+1eZsDOU5n4nqSJidV1JhmjmSra1nEZ/YGHbWwIhAJwcgoDsRnKS5c6WlWKoFsx+LktGXJqRSEtTibwom2FH","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":225749},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-execution-0.6.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./testing":{"types":"./dist/testing/index.d.ts","default":"./dist/testing/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/76b6a4e47ac136298093783b0b98fbab/alma-harness-execution-0.6.0.tgz","_integrity":"sha512-A7l9R5lHTbC8gMFRDmMXh/p24GrGIyblT2Lt3v0Pdm56kybGibNBPpg2DySwzi9TfgWXSKeRUzujDXRMVhSQOw==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/execution"},"_npmVersion":"11.18.0","description":"Durable execution persistence helpers for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.1.0"},"peerDependencies":{"@alma-harness/core":"^0.6.0"},"_npmOperationalInternal":{"tmp":"tmp/execution_0.6.0_1788902326500_0.7124266631156779","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@alma-harness/execution","version":"0.6.1","license":"Apache-2.0","_id":"@alma-harness/execution@0.6.1","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"cd97c6952827dec15b05da98bfba95d58c8c00d9","tarball":"https://registry.npmjs.org/@alma-harness/execution/-/execution-0.6.1.tgz","fileCount":12,"integrity":"sha512-4WtonBZxM0LxBUt683Nf05MlxmSpPnIEhhCRHE0fmsJkIS1DgtnCzFynkdVWBQ/RbxY3GVDh4ePWNq61EFGlAA==","signatures":[{"sig":"MEYCIQCxYfcdZCuxQ0TBcHn2KvoxgAI1tyhixFHuHFv1QNKpwQIhAIO22xv7yR5Z8z7I+TlWXcr2AH6hMNWQNn2wIgY9Bkek","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":225749},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-execution-0.6.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./testing":{"types":"./dist/testing/index.d.ts","default":"./dist/testing/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/6beda0e84dbd651a56437d3732ae334f/alma-harness-execution-0.6.1.tgz","_integrity":"sha512-4WtonBZxM0LxBUt683Nf05MlxmSpPnIEhhCRHE0fmsJkIS1DgtnCzFynkdVWBQ/RbxY3GVDh4ePWNq61EFGlAA==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/execution"},"_npmVersion":"11.18.0","description":"Durable execution persistence helpers for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.1.0"},"peerDependencies":{"@alma-harness/core":"^0.6.1"},"_npmOperationalInternal":{"tmp":"tmp/execution_0.6.1_1788905831230_0.8928296722639455","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@alma-harness/execution","version":"0.7.0","license":"Apache-2.0","_id":"@alma-harness/execution@0.7.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"09fc1cb7b7d9dce7aba2a9d1db4e15d227cc4ad4","tarball":"https://registry.npmjs.org/@alma-harness/execution/-/execution-0.7.0.tgz","fileCount":12,"integrity":"sha512-kc8HHrBO6ThhVBBWVhG3KYtRJHRdPWvMj/Vb80vY///Uh6rwmOhhuL0bnHJVa4sj1ps4CBvK75gUY2TNFj561A==","signatures":[{"sig":"MEQCIAPZECMmMjIIPa75OKm5Kr3q2WCmBPZX2DWuzV6qumIRAiAsbtHCeEOtrBJM2I+msev3+YRjbtRQnpTM3SIQXOoknw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":226897},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-execution-0.7.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./testing":{"types":"./dist/testing/index.d.ts","default":"./dist/testing/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/3acb44e9c47908923b563894e8a19f94/alma-harness-execution-0.7.0.tgz","_integrity":"sha512-kc8HHrBO6ThhVBBWVhG3KYtRJHRdPWvMj/Vb80vY///Uh6rwmOhhuL0bnHJVa4sj1ps4CBvK75gUY2TNFj561A==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/execution"},"_npmVersion":"11.18.0","description":"Durable execution persistence helpers for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.1.0"},"peerDependencies":{"@alma-harness/core":"^0.7.0"},"_npmOperationalInternal":{"tmp":"tmp/execution_0.7.0_1789137033773_0.7592812355958929","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@alma-harness/execution","version":"0.8.0","license":"Apache-2.0","_id":"@alma-harness/execution@0.8.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"c01f316337a570818a680b20eacd7a27e2932815","tarball":"https://registry.npmjs.org/@alma-harness/execution/-/execution-0.8.0.tgz","fileCount":12,"integrity":"sha512-bONeHvmhxvYxcWOA1k76OLwKX98Lo83eWPwV7AZqnaIUyNychS4xQmboTwFugWitBf0WHv01Ct7BW7qUgJS4KA==","signatures":[{"sig":"MEUCIQC4kQH7qHwhXylMoUbRvk8Dkd5hmp6thprba8YwxyXotQIgcZWqA6DpoH4Qi6KjJHX3UvPpNuxsFGrUP2ffehax358=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":226897},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-execution-0.8.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./testing":{"types":"./dist/testing/index.d.ts","default":"./dist/testing/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/03426f310a020351745300447b423ce8/alma-harness-execution-0.8.0.tgz","_integrity":"sha512-bONeHvmhxvYxcWOA1k76OLwKX98Lo83eWPwV7AZqnaIUyNychS4xQmboTwFugWitBf0WHv01Ct7BW7qUgJS4KA==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/execution"},"_npmVersion":"11.18.0","description":"Durable execution persistence helpers for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.1.0"},"peerDependencies":{"@alma-harness/core":"^0.8.0"},"_npmOperationalInternal":{"tmp":"tmp/execution_0.8.0_1789155222777_0.8430923738558023","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@alma-harness/execution","version":"0.9.0","license":"Apache-2.0","_id":"@alma-harness/execution@0.9.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"6f47a68e703bd6b0edeeb0053f3411edd1617ec8","tarball":"https://registry.npmjs.org/@alma-harness/execution/-/execution-0.9.0.tgz","fileCount":12,"integrity":"sha512-XSBh8RhvYmBEbdYIO742hogxWte5DWoXRbyIiKTAOwXQJox1pL3wAcOlSJe/nkhXmjUhK1rJCwfVuib2Ow9OoQ==","signatures":[{"sig":"MEYCIQCtICfQ6zBMn26VMmgmyZx3LMIFSfrUOCU4zHvts4UhNAIhAP4o37BeqXTH4VDw8nhpZOqkGq4bdmeqtEnol1UaoHdh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":226897},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-execution-0.9.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./testing":{"types":"./dist/testing/index.d.ts","default":"./dist/testing/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/7c989df85fe4f5e817531d01945681bf/alma-harness-execution-0.9.0.tgz","_integrity":"sha512-XSBh8RhvYmBEbdYIO742hogxWte5DWoXRbyIiKTAOwXQJox1pL3wAcOlSJe/nkhXmjUhK1rJCwfVuib2Ow9OoQ==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/execution"},"_npmVersion":"11.18.0","description":"Durable execution persistence helpers for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.1.0"},"peerDependencies":{"@alma-harness/core":"^0.9.0"},"_npmOperationalInternal":{"tmp":"tmp/execution_0.9.0_1789655795590_0.3812426785259213","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@alma-harness/execution","version":"0.10.0","license":"Apache-2.0","_id":"@alma-harness/execution@0.10.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"4afa43495335a584208899e2ed4593b9c361b18f","tarball":"https://registry.npmjs.org/@alma-harness/execution/-/execution-0.10.0.tgz","fileCount":12,"integrity":"sha512-fzbAu0LN1iD/zJzEhUt3qa8ajikPwKs9PzgxX9l5W53qPlkCY4ir8CeMBBJN6yr/V0sJK1MKxvwyKNRNtYXFfA==","signatures":[{"sig":"MEUCIQDsU9IkipuG6lFryph8vDTP6ZcoDGk4clcUaTHZ+RTleQIgLZGZIU+SUUGtdLoJCES40Y2OxKSicXTx67nBudwJn+I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDjvgjyofVdt7I2vbb30huANKL4L89uaivk86hebnSKhwIhANTRCxPAM8cwAqQs8RR49r4LNI4cE1m/RqaeA/xuSHdm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":226899},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-execution-0.10.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./testing":{"types":"./dist/testing/index.d.ts","default":"./dist/testing/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/ad58aa39f26dce665f392fe1e8d50c3c/alma-harness-execution-0.10.0.tgz","_integrity":"sha512-fzbAu0LN1iD/zJzEhUt3qa8ajikPwKs9PzgxX9l5W53qPlkCY4ir8CeMBBJN6yr/V0sJK1MKxvwyKNRNtYXFfA==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/execution"},"_npmVersion":"11.18.0","description":"Durable execution persistence helpers for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.1.0"},"peerDependencies":{"@alma-harness/core":"^0.10.0"},"_npmOperationalInternal":{"tmp":"tmp/execution_0.10.0_1789675252936_0.40265982385899135","host":"s3://npm-registry-packages-npm-production"}},"0.10.1":{"_id":"@alma-harness/execution@0.10.1","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"0b5ef4da51556fb9b68d7c7bc29b193239e2cc34","tarball":"https://registry.npmjs.org/@alma-harness/execution/-/execution-0.10.1.tgz","fileCount":12,"integrity":"sha512-54cLqx0qE8sK1LuMCgu85eiM/9/1IsyzSXdYkUwqtLMvQtPYJRlNpme5pwpY7+fKA4CtpHds9SghXsJB5vvHkw==","signatures":[{"sig":"MEYCIQDvnxDMjP6EFlTep55vXZgMVvR2P4JiVFQdhOXfzb3FBQIhAKEqr/55lZh7kEiBDdQvJ8AOZk45rK+Q5Pu+1JK+J4I/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBJvsjZk9uTPtcHS5WySyOkE1fl/zdwlUA1w4EcbvG8UAiAKli552OWj8BzGJvNrK6DTleYU9J7d+oHfAYVoj+F4SA=="}],"unpackedSize":226899},"main":"./dist/index.js","name":"@alma-harness/execution","type":"module","_from":"file:alma-harness-execution-0.10.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./testing":{"types":"./dist/testing/index.d.ts","default":"./dist/testing/index.js"}},"license":"Apache-2.0","scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"version":"0.10.1","_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/be78af2ea3656f25a74bc9f36615afc5/alma-harness-execution-0.10.1.tgz","_integrity":"sha512-54cLqx0qE8sK1LuMCgu85eiM/9/1IsyzSXdYkUwqtLMvQtPYJRlNpme5pwpY7+fKA4CtpHds9SghXsJB5vvHkw==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/execution"},"_npmVersion":"11.18.0","description":"Durable execution persistence helpers for Alma.","directories":{},"maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.1.0"},"peerDependencies":{"@alma-harness/core":"^0.10.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/execution_0.10.1_1789680448235_0.6337390197975408"}}},"time":{"created":"2026-09-08T21:18:46.321Z","modified":"2026-09-17T21:27:28.482Z","0.6.0":"2026-09-08T21:18:46.620Z","0.6.1":"2026-09-08T22:17:11.362Z","0.7.0":"2026-09-11T14:30:33.932Z","0.8.0":"2026-09-11T19:33:42.918Z","0.9.0":"2026-09-17T14:36:35.693Z","0.10.0":"2026-09-17T20:00:53.037Z","0.10.1":"2026-09-17T21:27:28.329Z"},"bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"license":"Apache-2.0","homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/execution"},"description":"Durable execution persistence helpers for Alma.","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"readme":"# @alma-harness/execution\n\nBackend-neutral execution persistence helpers for Alma. Part of\nthe fixed compatible workspace version group.\n\nCore owns `UsageInbox` contracts. This package owns closed snapshot validation:\n`normalizeUsageInboxInput`, `normalizeUsageInboxRecord`, `normalizeUsageInboxQuery`.\n`./testing` exports the volatile `InMemoryUsageInbox(now?)` reference, without\nvitest. PostgreSQL owns durable SQL and row-level security. Loop owns enforcement.\n\n## Usage preservation\n\nAppend the original trusted execution snapshot, event id and evidence before\njournal receive. Exact replay retains first receipt time and never recreates\nacknowledged work; changed input conflicts even after acknowledgement. A different\nobservation has a different event id, including contradictory evidence for one\ncall. No charge is deduplicated by event id: authoritative call/settlement identity\nbelongs to the journal and accounting store.\n\n`list` includes immutable history; `listPending` includes unacknowledged work.\nBoth use default 50/max 100 pages and an exclusive `after: { receivedAt, id }`.\nStart each reconciliation pass from the beginning; never persist a high-water\ncheckpoint, which would lose late commits. Paging lets unresolved items stay\npending without hiding later work. Corrupt rows fail loudly; repair is an operator\nconcern, never silently omitted accounting evidence.\n\nExactly one logical recovery consumer owns acknowledgement, with potentially\ncompeting workers. Acknowledge only after durable recovery/disposition. This is\nwork completion, never proof of charging. Compare the complete execution binding\nwith the authoritative journal and make recovery idempotent before acknowledging.\nCatch append, journal receive and acknowledgement errors separately. A stale fence\ncannot authorize acknowledgement, another provider call or invented zero usage.\n\nThe inbox stores no prompts, replies, raw errors or SDK objects and changes no\njournal, financial counter or provider state. Unknown/unpriced evidence stays\nunresolved. Metadata survives session/result erasure indefinitely; there is no\nretention or operator-correction API yet. Hosts supply scope inventory and drains.\n\nSee [durable usage inbox](../../docs/specs/082-durable-usage-inbox.md).\n\n## Governed financial receipts\n\n`GovernedCostSettlementStore` adds transactional monetary decisions to the ordinary\ncost receipt. `financialDecisions` uses actual locked pre/post session/day amounts,\nstrict `>` thresholds and explicit normalized warn/block policies. Warn decisions\nnever withhold output here. Ordinary `capsCrossed` stays warn-only; block evidence\nis separate. `normalizeGovernedSettlementInput` and `normalizeGovernedCostReceipt`\nreject content keys, invalid amounts and inconsistent derived decisions.\n\n`InMemoryGovernedCostSettlementStore` in `./testing` owns one volatile state for\nlegacy and governed writes. A separately constructed reference owns separate\ncounters. The PostgreSQL adapter shares its durable counters with the existing\nspend/settlement tables. Never run legacy accounting alongside a governed call.\n\nOne governed operation is one call: operation/call uniqueness prevents double\naccounting under another settlement id. This API is not yet suitable for a\nmulti-call turn. Replays return original decisions; mode, policy or identity\nchanges conflict. `getGoverned`, `listGoverned` and `pendingGoverned` include the\nfull immutable request and decisions. Generic readers retain ordinary receipts.\nUse distinct projection consumer IDs by mode, or drain both pending APIs. The\nexisting acknowledgement removes work only; retrying settlement never recreates it.\nGoverned receipts persist indefinitely, including after projection acknowledgement\nand content erasure. Runner continuation, preflight and operator correction follow.\n\nFinancial cap and receipt normalization now comes from core, shared with governed\njournal inputs. To advance that journal after settlement, explicitly project the\nclosed proof: `journal.settle(fence, {request: governed.request, receipt: governed.receipt})`.\nThe extra `decisions` field is intentionally not accepted by the journal boundary.\n\nThe volatile governed settlement reference exposes read-only `peek(SpendKey)` over\nits own counters. Pair this with governed runner preflight; a separate memory spend\nstore does not see governed charges. PostgreSQL's paired adapters share tables.\n\n## Durable operation lineage\n\n`OperationTreeStore` binds main/direct/delegate/summary calls to one scoped root\n(spec: durable-operation-lineage). `claim` returns a fence only once; equal replay\nreturns a record without authority. `reserve` snapshots a complete execution under\na stable slot, checks root scope/session/policy/caps/sensitivity/deadline, and\nrequires a prior same-root parent for non-main calls. Scoped call/settlement IDs\nand operation keys cannot belong to two roots. Ordinals start at1 and maxCalls is\n1..512; pages default50/max100. `close` stops new reservations, with idempotent\nrepeat by the same fence. Expiry refuses admission before or after a bounded\n`reconcileExpired` sweep; no takeover or renewed execution token is issued.\n\n`InMemoryOperationTreeStore` is exported from `/testing` without vitest. The durable\nadapter is `PostgresOperationTreeStore` in `@alma-harness/postgres-execution`.\nRecords are defensive copies, exclude tokens and contain closed metadata only.\nRoot closure is not cost settlement, result persistence or delivery. No runner\nadopts this prerequisite yet; aggregate accounting follows separately.\n\n## Root financial receipts\n\n`OperationAccountingStore.record(scope, rootKey, callId)` adopts the registered\ncall's original governed receipt into an inclusive root summary, without invoking\nany financial writer. Missing settlements return pending; known receipts must\nmatch reserved identity, policy and saved pricing. `get` returns bounded warning\nevidence and totals; `list` pages in accounting order, distinct from reservation\norder. Each root/cap warning is recorded once, and exact retries return the same\nreceipt. Per-turn decisions use inclusive root cost; persistent decisions retain\nthe original financial receipt totals, even if accounted out of order.\n\nThe memory reference takes trusted tree/getGoverned capabilities. PostgreSQL uses\nits own atomic aggregate transaction after the original financial settlement.\nRepair this boundary by recording the call again, including after root closure or\nexpiry; never dispatch again. Root totals are not additional billable rows. Warning\ntransport and runtime enforcement remain later host/runner responsibilities\n(spec: root-financial-receipts).\n\nSession admission uses `OperationSessionStore` and the memory reference\n`InMemoryOperationSessionStore` from `execution/testing`. Claim before creating\nthe operation root. The first claimant receives the only fence; equal replay\nreturns metadata. A different root is busy until the owner finishes cleanly.\nExpiry and uncertainty preserve occupancy. Explicit operator resolution requires\nexternal effects and writes reconciled and prior workers quiescent; runners must\nnever call it automatically. This store alone does not integrate the conversation\nloop. See the governed-session-admission spec.\n\nA summary may reserve a root-level call before the first main call, omitting\n`parentCallId`. It is a real metered call and consumes a root ordinal/slot.\nMain remains parentless; direct/delegate require prior same-root parents.\nParented summaries retain those same prior-parent checks. Deploy matching readers\nbefore enabling this representation (spec: prelude-summary-lineage).\n\nRoots and admissions optionally bind a closed `request` descriptor:\n`{inputRevision, configRevision, resultContractVersion, resultRetentionMs}`.\nAll fields become immutable at first claim; adding/removing it later conflicts.\nThe host resolves revisions for the complete incoming request and configuration,\nincluding intent/profile/trigger and all prompt/tool/hook/price/limit choices.\nLegacy records keep absence. Conversation adoption must require this binding and\nreserve final output before loading content. Final output belongs to the scoped\nroot key in a separate root-result namespace, never a fabricated billable call or\nan unchecked step-result key. No result reservation or loop wiring is implemented\nby this descriptor alone (spec: conversation-root-binding).\n\n## Durable batch submission\n\n`BatchSubmissionStore` and `InMemoryBatchSubmissionStore` (`execution/testing`)\nretain a closed, ordered manifest before provider work. Claim returns the only\nfence; replay has metadata only. `beginDispatch` grants `dispatch: true` once.\nOnly that response permits a future adopting runner to submit; a lost ACK,\nexpiry or repeated call never grants another attempt. `accept` binds the original\nprovider/model handle once; late evidence retains `reconciliation_required` and\nnever renews authority. `markUncertain` is irreversible and preserves the handle.\n\nManifest items carry normalized governed batch-tier execution snapshots. They are\npricing/identity metadata, not claims in the synchronous ExecutionStore. Recovery\nof batch item evidence needs a separate adopting protocol; synchronous recovery\ncannot receive unknown late results after expiry. Use scope/key lookups before\nany future provider access. Raw handles from callers are not authorization.\nConfiguration revisions must identify immutable host configuration, including\nprovider account selection. The store accepts only a trusted owner's handle\nobservation; it cannot authenticate a provider's receipt by itself.\n\nClaims bind 1..512 items and at most 2 MiB of normalized UTF-8 JSON; a future\nsubmission deadline must be within one hour. This deadline governs submission,\nnot how long the provider may process a batch. `get` returns a defensive manifest;\n`list` returns summaries without item arrays, in exclusive ASCII key pages\n(default50/max100). Metadata and charge identities remain retained indefinitely.\nNo provider calls, cancellation, collection, cost writes or routine adoption are\nimplemented by this storage prerequisite (spec: durable-batch-submission).\n\n`SingleDispatchBatchClient` is the additive transport seam for the governed\nbatch runner. It returns independent `BatchItemEvidence` and content, not legacy\nJobResult usage coupled to content success. Every submit invocation is a new\nattempt; ownership remains in BatchSubmissionStore. Its once-consumable\nsubmitEvidence iterable exposes OpenAI input_file evidence before accepted.\nThe host may save the file reference before resuming create; abandonment stops\nthere. Optional `cancel(handle, opts?)` requests cancellation once and returns\nobserved JobProgress; absence means unsupported. An acknowledgement cannot prove\nterminal processing. The batch package resolves original scoped handles for\nstatus/cancel and separately adopts collection/accounting (spec 128).\n\n## Batch usage journal\n\n`BatchUsageStore` persists immutable financial observations under scope/batch/id;\n`InMemoryBatchUsageStore` lives in `/testing`. Append requires the exact accepted\nhandle and manifest item, including after deadline/uncertainty. The store obtains\nthe execution snapshot itself. Different observation IDs retain contradictory\nmetadata; equal replay preserves the original timestamp, and changed input\nconflicts. Known evidence admits only batch billing. Unknown/unpriced remains\npending; not_dispatched and content-bearing payloads are rejected.\n\n`batchUsageSettlement(record)` derives the original governed request when evidence\nis known and priceable. Persist first, call settleGoverned idempotently, then\nrecordSettlement to adopt the actual source receipt. Adoption performs no monetary\nwrite. Multiple matching observations can share that one charge; contradictory\nones cannot replace it. No observation acknowledges provider EOF or output delivery.\n\nList pages default50/max100 in exclusive ASCII observation-ID order. Restart\npending drains from the first page to catch late lower IDs. Metadata and adopted\nreceipts survive indefinitely; unknown/unpriced/conflicting observations need\nexplicit reconciliation. No provider access, lease, dispatch token, output store\nor automatic operator resolution is introduced (spec: durable-batch-usage).\n\n## Inclusive batch accounting\n\n`BatchAccountingStore` adopts an already journaled governed receipt once per\nmanifest item. `InMemoryBatchAccountingStore` is the volatile reference. Record\nby scoped batch key and observation ID; even alternate-observation replay needs a\nmatching adopted source. Unknown/unpriced observations remain pending. Only the\noriginal settlement writes money; aggregate receipts never increment counters.\n\nPerTurnUsd compares the inclusive batch total. Persistent session/day decisions\nkeep original source pre/post amounts even when items are adopted out of order.\nWarn crossings are retained once per cap/batch; block decisions remain evidence\nfor the adopting runner. Record accepts late repair without renewing dispatch.\n\nGet returns bounded original warnings, total and expected/accounted item counts;\nlist pages in accounting order (default50/max100), retaining manifest position\nseparately. All records are defensive and content-free. Financial completeness is\nnot proof of provider EOF, output availability, delivery or resolved contradictory\nobservations (spec: batch-financial-summary).\n\nUsage inbox normalization binds the synchronous Anthropic context-rejection proof\nto its original provider. Batch usage cannot carry that synchronous attestation\n(spec: safe-context-rejection-rotation).\n","readmeFilename":"README.md"}