Skip to content

Harden workflow ID minting and surface real collisions #934

Description

@christian-byrne

Random ID collisions can fail silently. Global seeding makes draws repeatable.

Full context for agent readers

Follow-up from the ID contract correction. That review established two behavior gaps intentionally excluded from the documentation-only pull request:

  1. mint_id() uses the process-global random.getrandbits. A caller's random.seed(...) can make independently created ID streams repeatable. Use an OS-backed or module-private source such as secrets.randbits or random.SystemRandom() and add a regression test proving global seeding does not control IDs.
  2. A genuine same-actor node or link ID collision has no explicit outcome. Node replay is first-arrival-wins; link replay can retain a destination reference to an unrelated existing link. Design the smallest safe collision contract: redraw while minting against a known graph, and surface a typed conflict when replay receives two different entities with one ID.

Acceptance criteria:

  • Global random.seed(...) cannot force mint_id() to repeat a known stream.
  • Local minting does not emit an ID already present in the target graph.
  • Replay of two distinct entities with one ID produces an explicit, tested outcome rather than silent success.
  • Node and link paths have asymmetric regression cases where the competing payloads differ.

Source findings: silent collision handling and seedable random source.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions