mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
The §2.8 corrective-retain failure path was only proven at the extracted helper. No test crossed the real `?` propagation site, so weakening it to a swallow left the whole suite green — the pass-1 defect, reintroducible undetected. The boot-reconcile requeue was proven only from synthetically seeded state, not the state a failed command actually leaves. Extract the retain -> apply -> §2.8 convergence body of the blocking command into `apply_inbound_upsert_in_scope`, generic over `tauri::Runtime`, so a mock app can drive it. No behavior change: the wrapper resolves the arrival scope and the §2.7 preflight, then delegates; the corrective `?` moves inside the seam unchanged. Add one integration fixture that drives the real seam against a MockRuntime app, an active workspace scope, and a retention DB with a conditional trigger that permits the inbound `pending_sync = 0` write and rejects the corrective `pending_sync = 1` write. It asserts the command returns `Err`, the frozen linkage persists to disk with the safe field applied, the hostile inbound head stays retained, and the real boot reconcile against that same state restores the authoritative projection at a bumped `created_at` with `pending_sync = 1`. Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>