Wave 11 Protocol async contracts
- Source
- Ledger event v15
Living Program Ledger
Immutable ingestion receipt
protocol
ci → green (verified run 29373589606: canonical type contract, strict Rust, seven-crate publication dry-run, CLI, live integration, and both mandatory coverage ratchets)
Closed: PROTO-1
Commits 15ce42f and 5461d23 complete the Send + Sync async Provider and Store contracts across frauthy-core, OIDC, SpiceDB, Keto, lifecycle callers, conformance fixtures, and observe tests. Public consistency, lookup, watch, discovery, verified-claim, and write-cursor types now have one canonical core contract.
SpiceDB writes preserve real ZedTokens, lookup flows through the Store trait, and watch uses the native gRPC WatchService with official protobuf wire shapes. Keto exposes opaque monotonic cursors and a paginated tuple-diff watch stream; neither adapter substitutes a fake in-process event queue.
Real SpiceDB and Keto permission, lifecycle, lookup, OIDC, Jaeger, and Keto watch suites pass. Native SpiceDB watch was separately proven against a watch-capable memory datastore because the registered PostgreSQL-backed development container reports WatchService unsupported.
All offline workspace targets, strict Clippy, formatting, the seven-crate packaging dry-run, CLI tests, and canonical type checks pass. Focused async edge-case tests raise Rust line coverage from the transient 69.47% result to 70.52%, above the unchanged 69.72% ratchet.
Program-wide
Wave 11 stayed within root/specs/08-CONCURRENT-PROGRAM-HANDOFF.md. Only Protocol core/backend contracts, Protocol tests/documentation, and the Research ledger changed; no UI-owned, product packages/ui, Portal, registry publication, or tag path was touched.