Skip to content

v6.0.0 — durable authorization ownership and compensation safety

Latest

Choose a tag to compare

@SAY-5 SAY-5 released this 29 Sep 09:52
5447da6

LedgerMesh 6.0.0

This release repairs order deduplication, cancellation compensation and payment
authorization ownership in LedgerMesh's synthetic-provider demo. The previous
assigned-ID merge path could let two requests with one idempotency key create two
orders. Cancelled orders could retain card authorizations, and competing payment
creators or late approvals could leave surplus holds at the processor.

New records insert rather than overwrite an existing request or payment. Payment
cancellation is acknowledged and resent until answered; the operator resend endpoint
also covers older cancelled orders. Inventory reservations belong to an order and
SKU, so repeated or out-of-order releases do not credit stock that order never held.

Durable, order-bound authorization decisions serialize claim and retirement before
a fresh payment read. Claim, payment authorization and the completion outbox commit
together. Retirement is irreversible and commits before provider release, preventing
both a late claim of an already released hold and release of a concurrently claimed
hold. Failed releases retry from outstanding-provider listings after restart; retired
codes never become claimable again. This includes H2 and PostgreSQL race regressions,
first-insert conflicts, cancellation, transaction rollback and an additive-schema
upgrade check.

The chaos verifier inspects final orders, payments, stock holds and synthetic
processor authorizations, not only aggregate request counts. Cleanup is conditional
on provider/database availability, scheduler progress and listing throughput; grace
plus one interval is not an unconditional time guarantee. Concurrent attempts can
still produce temporary surplus authorizations; only one can be kept and the others
must be released. These tests are not evidence of a production payment deployment.

Upgrade requirements

  • Stop and drain all old payment listeners, sweepers and callback-capable processes
    before activating the new protocol. Do not use a mixed-version rolling upgrade.
  • Preserve authorization decision tombstones. An old binary is not a safe rollback
    target while retired-code callbacks can still arrive.
  • Let old inventory orders and their compensations finish before upgrading inventory.
    The new reservation ledger cannot reconstruct or automatically credit deductions
    made by the 5.0.0 inventory service. Terminal order state alone is insufficient.
  • Replay older uncompensated cancellations with the documented bounded administrator
    resend endpoint until none remain. Consult the operator upgrade guide.

Verification

The reconciled release tree passed 172 local tests: 144 unit/H2, ten PostgreSQL
ownership/upgrade and 18 end-to-end tests, with zero failures, errors or skips.
Independent review reproduced the original races before repair and reran the
ownership tests on both databases. Formatting, configuration and measured-artifact
drift checks, TypeScript/Vite build and all browser self-checks passed.

Final release PR CI
passed all seven jobs. ExactlyOnce
passed 50/50 fresh-stack runs (300 test executions); CompensationResend
passed 50/50 (50 test executions). Independent inspection of seed 74713's retained
chaos artifact found 1,200 submitted orders, 1,170 confirmations, 30 stock cancellations,
three service kills and no failed/stuck orders or money/stock violations. Every
confirmed payment retained exactly one matching authorization; 14 surplus holds
were released. The PR synthetic-merge checkout and final release tree are identical.
The merged commit also passed all seven jobs in main CI 36551110669, including a fresh chaos run.