{"_id":"@alma-harness/postgres-execution","_rev":"6-1117202960be27f685e4dbca8a32cff5","name":"@alma-harness/postgres-execution","dist-tags":{"latest":"0.10.0"},"versions":{"0.6.0":{"name":"@alma-harness/postgres-execution","version":"0.6.0","license":"Apache-2.0","_id":"@alma-harness/postgres-execution@0.6.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"ec66766ff588d17784f16b3df10f28d762ab976e","tarball":"https://registry.npmjs.org/@alma-harness/postgres-execution/-/postgres-execution-0.6.0.tgz","fileCount":6,"integrity":"sha512-ZXswblF7YiKET0JJDNOuZBxRY0YGcI95VGR7E2rog8b0zO29y7OL8xYH58GFGQ5yvTA/30yrqbTPbsU1Imir8w==","signatures":[{"sig":"MEYCIQCgtbVuSMetDYm59Thd/Dd8S100xNy3a/RgYOGpAHbTjgIhANGADssPAl4qcTCNIInMgtyBkGr2RLyUIIrxz8e7gDC4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":237464},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-postgres-execution-0.6.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/b40c76109712eefe778957d106c06b94/alma-harness-postgres-execution-0.6.0.tgz","_integrity":"sha512-ZXswblF7YiKET0JJDNOuZBxRY0YGcI95VGR7E2rog8b0zO29y7OL8xYH58GFGQ5yvTA/30yrqbTPbsU1Imir8w==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/postgres-execution"},"_npmVersion":"11.18.0","description":"PostgreSQL operation lineage for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"pg":"^8.16.3","vitest":"^3.2.4","@types/pg":"^8.15.4","typescript":"^5.9.2","@types/node":"^24.1.0","@alma-harness/core":"^0.6.0","@alma-harness/testing":"^0.6.0","@alma-harness/postgres":"^0.6.0","@alma-harness/execution":"^0.6.0"},"peerDependencies":{"pg":">=8","@alma-harness/core":"^0.6.0","@alma-harness/postgres":"^0.6.0","@alma-harness/execution":"^0.6.0"},"_npmOperationalInternal":{"tmp":"tmp/postgres-execution_0.6.0_1788902326125_0.6297669668100436","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@alma-harness/postgres-execution","version":"0.6.1","license":"Apache-2.0","_id":"@alma-harness/postgres-execution@0.6.1","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"1fbc7fb6a56df4654ca6d4099a9ac6b9b436ba6c","tarball":"https://registry.npmjs.org/@alma-harness/postgres-execution/-/postgres-execution-0.6.1.tgz","fileCount":6,"integrity":"sha512-XXE4rnL9G6H3c/td5EjRH8GgkwY65dDlbZwlb/rjdU91jX091GI/sr5v7cBIu71AQh/paAiPnvNx4n7y2Cjqpg==","signatures":[{"sig":"MEUCIE/fiItAUqoNi21VI9nQ7sXGmEvysY9H0pPVQYle35rKAiEAzxUYcA0gRSb3FGrKhZF6hdc1ew1S3jyK46fDlHviXZI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":237464},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-postgres-execution-0.6.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/bd6da0cec7d40f12ef249b503166d23e/alma-harness-postgres-execution-0.6.1.tgz","_integrity":"sha512-XXE4rnL9G6H3c/td5EjRH8GgkwY65dDlbZwlb/rjdU91jX091GI/sr5v7cBIu71AQh/paAiPnvNx4n7y2Cjqpg==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/postgres-execution"},"_npmVersion":"11.18.0","description":"PostgreSQL operation lineage for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"pg":"^8.16.3","vitest":"^3.2.4","@types/pg":"^8.15.4","typescript":"^5.9.2","@types/node":"^24.1.0","@alma-harness/core":"^0.6.1","@alma-harness/testing":"^0.6.1","@alma-harness/postgres":"^0.6.1","@alma-harness/execution":"^0.6.1"},"peerDependencies":{"pg":">=8","@alma-harness/core":"^0.6.1","@alma-harness/postgres":"^0.6.1","@alma-harness/execution":"^0.6.1"},"_npmOperationalInternal":{"tmp":"tmp/postgres-execution_0.6.1_1788905831193_0.4321047947225216","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@alma-harness/postgres-execution","version":"0.7.0","license":"Apache-2.0","_id":"@alma-harness/postgres-execution@0.7.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"354060c89354263e88caadbbc8624a59d1dac47b","tarball":"https://registry.npmjs.org/@alma-harness/postgres-execution/-/postgres-execution-0.7.0.tgz","fileCount":6,"integrity":"sha512-MA8X9uDdjF3+/3WL4dlzdfdPCSH/HhaSv9BznlleDGDNDsshgTc4pJVx3ZztEikUBqot33jvYcSFDcZc4ifjUw==","signatures":[{"sig":"MEYCIQCwmGnWFtSjhBlCE54xWjY4/DQ/dKh7PZnlSajJmy/iRAIhALDh4Plm5GNxt4kZucjt5xj4zfw+ld9rkZOKdGEuZLXx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":242841},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-postgres-execution-0.7.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/3ae7872a3ff853e31d2b38bd0d54c357/alma-harness-postgres-execution-0.7.0.tgz","_integrity":"sha512-MA8X9uDdjF3+/3WL4dlzdfdPCSH/HhaSv9BznlleDGDNDsshgTc4pJVx3ZztEikUBqot33jvYcSFDcZc4ifjUw==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/postgres-execution"},"_npmVersion":"11.18.0","description":"PostgreSQL operation lineage for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"pg":"^8.16.3","vitest":"^3.2.4","@types/pg":"^8.15.4","typescript":"^5.9.2","@types/node":"^24.1.0","@alma-harness/core":"^0.7.0","@alma-harness/testing":"^0.7.0","@alma-harness/postgres":"^0.7.0","@alma-harness/execution":"^0.7.0"},"peerDependencies":{"pg":">=8","@alma-harness/core":"^0.7.0","@alma-harness/postgres":"^0.7.0","@alma-harness/execution":"^0.7.0"},"_npmOperationalInternal":{"tmp":"tmp/postgres-execution_0.7.0_1789137034371_0.022476642778428424","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@alma-harness/postgres-execution","version":"0.8.0","license":"Apache-2.0","_id":"@alma-harness/postgres-execution@0.8.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"7959539c4c2aa2a6ff444e125f863f71ad85c7d7","tarball":"https://registry.npmjs.org/@alma-harness/postgres-execution/-/postgres-execution-0.8.0.tgz","fileCount":6,"integrity":"sha512-KFc4K1ZhdmxqsgvadCcIB/Qdp3RhDhS7dyQO5h160H/GHveXrgrlzS0cBIO4E89z1CMscFfBwLSC/X4ls1N3nQ==","signatures":[{"sig":"MEQCIHQzEQt0O+xFmlnAVbfArdHjia5G5km/bNTZzNLxDdegAiBTvJKMrKoYt1Mk3zEoeANfEmsShaTm9gor60c6SqkgWg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":242841},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-postgres-execution-0.8.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/ebe5f11ad5eadb7caacdab8bec80162f/alma-harness-postgres-execution-0.8.0.tgz","_integrity":"sha512-KFc4K1ZhdmxqsgvadCcIB/Qdp3RhDhS7dyQO5h160H/GHveXrgrlzS0cBIO4E89z1CMscFfBwLSC/X4ls1N3nQ==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/postgres-execution"},"_npmVersion":"11.18.0","description":"PostgreSQL operation lineage for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"pg":"^8.16.3","vitest":"^3.2.4","@types/pg":"^8.15.4","typescript":"^5.9.2","@types/node":"^24.1.0","@alma-harness/core":"^0.8.0","@alma-harness/testing":"^0.8.0","@alma-harness/postgres":"^0.8.0","@alma-harness/execution":"^0.8.0"},"peerDependencies":{"pg":">=8","@alma-harness/core":"^0.8.0","@alma-harness/postgres":"^0.8.0","@alma-harness/execution":"^0.8.0"},"_npmOperationalInternal":{"tmp":"tmp/postgres-execution_0.8.0_1789155222778_0.11324185152806443","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@alma-harness/postgres-execution","version":"0.9.0","license":"Apache-2.0","_id":"@alma-harness/postgres-execution@0.9.0","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"f8a12a0846393567af13fd6bc9d627003efdd8ee","tarball":"https://registry.npmjs.org/@alma-harness/postgres-execution/-/postgres-execution-0.9.0.tgz","fileCount":6,"integrity":"sha512-+X5p/7WLEjxE0pg60QXTHPIyIrr+ekVNwUOHzj+CYplWEAD/POTcWDPwUGm9HjDclP1F6TSkcFAsf2+gTCXyIQ==","signatures":[{"sig":"MEQCIH/cf/Q4DGR6yZ6j9iAcqEkBNykqBZEJ+R2PLmqEzFCNAiBI4Gm8Q81ME9MyyXqcSbvAIjvU7R7SG+UhpoUeP5w/Gw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDaDe4JNQo4aYKrntchBOIwisbr1R3EmE6zjLzTMPl+rwIgaGW8CQtmhUOHXimvLHwabqRyE2IV8I3f9AF52RaeOsg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":242841},"main":"./dist/index.js","type":"module","_from":"file:alma-harness-postgres-execution-0.9.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/c40eb119f971fb8aa9cf196183c4733c/alma-harness-postgres-execution-0.9.0.tgz","_integrity":"sha512-+X5p/7WLEjxE0pg60QXTHPIyIrr+ekVNwUOHzj+CYplWEAD/POTcWDPwUGm9HjDclP1F6TSkcFAsf2+gTCXyIQ==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/postgres-execution"},"_npmVersion":"11.18.0","description":"PostgreSQL operation lineage for Alma.","directories":{},"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"pg":"^8.16.3","vitest":"^3.2.4","@types/pg":"^8.15.4","typescript":"^5.9.2","@types/node":"^24.1.0","@alma-harness/core":"^0.9.0","@alma-harness/testing":"^0.9.0","@alma-harness/postgres":"^0.9.0","@alma-harness/execution":"^0.9.0"},"peerDependencies":{"pg":">=8","@alma-harness/core":"^0.9.0","@alma-harness/postgres":"^0.9.0","@alma-harness/execution":"^0.9.0"},"_npmOperationalInternal":{"tmp":"tmp/postgres-execution_0.9.0_1789655873201_0.230397445028383","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"_id":"@alma-harness/postgres-execution@0.10.0","bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"dist":{"shasum":"d94783078fcd7263f4155b1cc9e221a1688d07f7","tarball":"https://registry.npmjs.org/@alma-harness/postgres-execution/-/postgres-execution-0.10.0.tgz","fileCount":6,"integrity":"sha512-trVIDcvuMAHiRFoosZBzpJZhl8Ncnd8+AU5EyttFXniDecjyVOTCmVJerG9WGj2yJcf8ImyV1uR3Gnfdmjir7Q==","signatures":[{"sig":"MEYCIQCB6d9j980bvyRFrpqx7B+4k9gyctti05xYW241kY5sJgIhALBTiwJy5sFDPFwgS5CWgMwPTvTREl3GUfRPrgTV1u2y","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCv7wQbxv7Huzr31OChWDTUZzXgX5DXt/xHsE7M9JY1lQIgaHfbPKSUAFsPw8uY0y0vmfvhJP2k6Q+jJrr6sUw+ipA="}],"unpackedSize":247665},"main":"./dist/index.js","name":"@alma-harness/postgres-execution","type":"module","_from":"file:alma-harness-postgres-execution-0.10.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"license":"Apache-2.0","scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"version":"0.10.0","_npmUser":{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"},"homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","_resolved":"/private/var/folders/zc/snhwcnp15dj2hk0k9_g1fh3h0000gn/T/c86300e3415012d706a2223e17219b11/alma-harness-postgres-execution-0.10.0.tgz","_integrity":"sha512-trVIDcvuMAHiRFoosZBzpJZhl8Ncnd8+AU5EyttFXniDecjyVOTCmVJerG9WGj2yJcf8ImyV1uR3Gnfdmjir7Q==","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/postgres-execution"},"_npmVersion":"11.18.0","description":"PostgreSQL operation lineage for Alma.","directories":{},"maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"_nodeVersion":"26.4.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"pg":"^8.16.3","vitest":"^3.2.4","@types/pg":"^8.15.4","typescript":"^5.9.2","@types/node":"^24.1.0","@alma-harness/core":"^0.10.0","@alma-harness/testing":"^0.10.0","@alma-harness/postgres":"^0.10.0","@alma-harness/execution":"^0.10.0"},"peerDependencies":{"pg":">=8","@alma-harness/core":"^0.10.0","@alma-harness/postgres":"^0.10.0","@alma-harness/execution":"^0.10.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/postgres-execution_0.10.0_1789675275194_0.5611230973104719"}}},"time":{"created":"2026-09-08T21:18:45.980Z","modified":"2026-09-17T20:01:15.487Z","0.6.0":"2026-09-08T21:18:46.256Z","0.6.1":"2026-09-08T22:17:11.323Z","0.7.0":"2026-09-11T14:30:34.516Z","0.8.0":"2026-09-11T19:33:42.923Z","0.9.0":"2026-09-17T14:37:53.290Z","0.10.0":"2026-09-17T20:01:15.285Z"},"bugs":{"url":"https://github.com/FabioFernandesCarneiro/alma/issues"},"license":"Apache-2.0","homepage":"https://github.com/FabioFernandesCarneiro/alma#readme","repository":{"url":"git+https://github.com/FabioFernandesCarneiro/alma.git","type":"git","directory":"packages/postgres-execution"},"description":"PostgreSQL operation lineage for Alma.","maintainers":[{"name":"fabiofernandescarneiro","email":"fabiofernandescarneiro@gmail.com"}],"readme":"# @alma-harness/postgres-execution\n\nPostgreSQL operation lineage (spec: durable-operation-lineage). This additive\npackage depends on the matching `core`, `execution` and `postgres` release; it\nreuses the shared scoped transaction, role and statement-timeout helpers.\n\n`migrateOperationTreeStore(pool)` installs the current execution shape helper and\n`alma_operation_roots`/`alma_operation_calls`. `PostgresOperationTreeStore(pool,\nScopedStoreOptions?)` implements the neutral `OperationTreeStore` from execution.\nDefault transactions SET LOCAL ROLE alma_app and bind org/uid with a 30s timeout.\nAn explicit null role retains the existing host opt-out from role switching.\nMigration needs the same privileged migration connection as postgres; runtime\nconnections use limited login membership via grantRole.\n\nClaim a root once; only its first claimant receives an opaque fence. Reserve stable\nmain/direct/delegate/summary slots before dispatch. Root/child scope, session,\npolicy, caps, sensitivity and deadline must agree. Parent links stay within a\nroot. SQL locks serialize ordinals; a trigger validates root admission and updates\nmembership count atomically. Lost acknowledgements are resolved by scoped reads\nor equal reservation replay, never a new root execution authority.\n\nA root claim INSERT uniqueness failure permits one read after rollback and connection\nrelease. Only an exactly equal normalized binding returns `existing`, without a\nfence; a closed or expired winner gains no renewed authority. Readback failures,\nother SQL errors and COMMIT uncertainty remain errors. Mapped errors retain the\noriginal PostgreSQL `cause` non-enumerably for trusted diagnostics; do not serialize\nthat cause into client output or routine logs (spec: operation-tree-claim-readback).\n\nExpired roots cannot reserve even before `reconcileExpired(scope)` marks them for\nreconciliation. The bounded sweep skips locked roots. `close` stops admission;\nit does not mean accounting or delivery completed. `listCalls` pages by ordinal,\ndefault50/max100, with at most512 members per root. Reads never return the fence\ntoken. Metadata is content-free and retained; no deletion or takeover API exists.\n\nGoverned conversation and step runners bind these reservations before egress.\nLineage itself creates no billable cost rows.\n\n## Root financial accounting\n\n`migrateOperationAccountingStore` composes lineage and governed-cost migrations.\n`PostgresOperationAccountingStore` reads actual governed receipts by registered\ncall identity and writes only `alma_operation_financial_calls` and\n`alma_operation_warnings`. A root lock serializes accounting ordinals and totals;\nSQL verifies financial associations and exact decision metadata, and inserts\nwarning evidence atomically. Source cost rows/counters are never incremented.\n\nThe source settlement and aggregate are separate transactions. Lost aggregate\nacknowledgements replay the stored receipt; missing aggregates can be repaired\nwithout root dispatch authority, including after closure/expiry. Scoped FKs retain\nthe source governed rows; ordinary cost retention already preserves those rows.\nSummary counts do not certify completion or external delivery. Out-of-order root\naccounting uses original session/day amounts; root warnings are immutable evidence,\nnot a notification outbox (spec: root-financial-receipts).\n\n`migrateOperationSessionStore(pool)` installs scoped session lock rows and immutable\nadmissions. `PostgresOperationSessionStore` serializes claims across connections;\na partial unique index permits only one unfinished admission per scoped session.\nDeadlines mark uncertainty without granting takeover. Finish requires the original\nfence before expiry; its replay remains stable. Operator resolution has a separate\nreceipt and cannot be replayed as an owner finish.\n\nNormal operations assume `alma_app`; explicit `resolve` assumes the separately\nconfigured `operatorRole` (default `alma_retention`) with membership required and\nFORCE RLS still active. Grant that membership only to the trusted reconciliation\nhost. Migration accepts matching `role`/`operatorRole`. Do not invoke resolution\nfrom a runner, sweeper or timeout handler. Admit before root creation; a crash\nbetween those transactions intentionally leaves the session occupied. Deploy\nmatching readers and roles before adoption; admission itself includes no automatic retention. See the governed-session-admission spec.\n\nOperation-tree migration also upgrades the legacy parent-kind CHECK to permit\nparentless prelude summaries. Scoped parent FKs and lower-ordinal checks remain.\nReapplying old migration SQL preserves the upgrade; old TypeScript readers may\nstill reject this new representation and must be replaced before adoption.\n\nConversation request descriptors roundtrip through both admission input and the\nnullable root `request` column. New SQL checks validate closed bounded metadata;\na root UPDATE trigger protects original binding fields while allowing existing\nstatus/count changes. Migration retains legacy descriptor absence and survives\nfrozen old SQL replay. Install migrations before current adapters (which select the\nnew column), then replace old readers before enabling descriptors. No fabricated\nrevisions, content rows or charges are created (spec: conversation-root-binding).\n\n## Batch submission ownership\n\n`migrateBatchSubmissionStore` adds `alma_batch_submissions` and `alma_batch_items`;\n`PostgresBatchSubmissionStore` implements the execution package's neutral contract.\nThe parent insert creates the complete membership through a SQL trigger in the\nsame transaction. Scoped operation/call/settlement uniqueness and immutable JSON\nbindings prevent reassociation. FORCE RLS covers both org and uid; use the ordinary\nlimited login with alma_app membership and statement-timeout settings. Runtime\ngets no delete grants or ownership reset API.\n\nSQL guards reject expired new dispatch, reverse transitions and acceptance without\na prior dispatch marker. The clock is sampled after row locks. A late handle stays\navailable under reconciliation; acceptance is not batch completion, accounting or\npermission to submit again. Scoped reads never expose the original fence token.\nSQL access remains a trusted host capability, as with existing fenced stores.\n\nA claim INSERT uniqueness failure is read back once after transaction cleanup,\nin a fresh scoped transaction. Only an identical complete normalized manifest\nreturns `existing`; no fence is recovered and the INSERT is never retried.\nMissing or changed bindings still conflict; unrelated errors and lost COMMIT\nacknowledgements cannot enable this path (spec: batch-claim-readback).\nMapped batch conflict/state errors retain the original SQL error in non-enumerable\n`cause`, including any constraint/detail supplied by PostgreSQL. These diagnostics\nare for trusted inspection only: they may contain scoped identifiers. Do not\nserialize causes into client responses or automatically log the entire error.\n\nInstall the additive migration before constructing the adapter; populated replay\nis supported and old execution migrations leave the new tables intact. Input\nnormalization caps manifests at 2 MiB; SQL additionally bounds JSONB text to 4 MiB\nbecause its numeric/whitespace encoding differs. All recursive metadata shapes\nare closed; content must use a separate result store. No automatic retention,\nprovider access, collection, settlement or routine integration is included.\n\n`migrateBatchUsageStore` composes batch and governed settlement migrations and\nadds `alma_batch_usage`. `PostgresBatchUsageStore` uses the normal scoped limited\nlogin and timeout options. SQL binds observations to the accepted handle/member,\nchecks closed evidence, and permits only a one-way association to an existing\nmatching governed cost. FORCE RLS and scoped FKs protect observations and source\nreceipt retention; app receives no delete grant. Readers validate complete saved\npricing and receipt consistency, failing on corrupt metadata.\n\nReceipt adoption locks the observation first, then reads its joined receipt in a\nfresh SQL statement: a statement snapshot taken before a competing adoption must\nnot mix the new association with old joined data. Lost append, settlement and\nadoption acknowledgements replay the same identities. The adapter never increments\nspend or invokes a provider. Install the additive migration before new readers;\npopulated repeated upgrades preserve records. See execution's batch usage journal\ncontract; content, valid EOF, collection completion and delivery remain separate.\nThe SQL association guard also computes the frozen batch price, including highest\napplicable prompt band, cache fallback/one-hour rates and provider search charges.\nParity tests compare its amount with core pricing; a matching identity/usage receipt\nwith a different monetary amount cannot make an observation unreadable or resolved.\n\n`migrateBatchAccountingStore` adds `alma_batch_financial_items` and\n`alma_batch_warnings` on top of the batch usage migrations.\n`PostgresBatchAccountingStore` uses the same limited scoped connection options.\nA batch row lock serializes accounting ordinals and inclusive totals; item and\nwarning inserts commit atomically. Unique scoped item keys prevent two observations\nfrom contributing twice. SQL checks the adopted observation, source amount,\nmanifest position and exact decisions/warning set. App grants are SELECT/INSERT\nonly; scoped FKs protect source observations. Populated upgrade replay is supported.\nThe adapter never writes monetary counters or cost rows and grants no execution\nor channel-delivery authority.\n\nSQL validators and triggers that depend on Alma objects pin their invoker path to\n`pg_catalog, installation_schema, pg_temp`. Install in a trusted schema and rerun\ncurrent migrations before backup; old startup SQL may replace function settings.\nThis preserves CHECK evaluation during pg_restore and prevents caller-path shadows.\n\nTool selection in nested `execution.controls.toolChoice` remains part of each immutable call or batch item. Run both `migrateOperationTreeStore` and `migrateBatchSubmissionStore` before writing choices. Populated schemas upgrade their closed guards without changing existing records; versioned helpers preserve validation when older migration SQL is replayed. Reapplying the migrations preserves constraint identities. A changed choice conflicts with the original call slot or batch manifest and does not authorize another dispatch. Deploy readers that understand the optional field before enabling writers; prior binaries cannot normalize selected-tool records.\n","readmeFilename":"README.md"}