Two distinct refinements follow from the frontier invariant. A, sharpen the epoch boundary: freezing the member names does not by itself freeze which member owns an event. Suppose partition A certifies through 100 while event 80 is assigned to B; the event moves to A before B certifies through 100. Each certificate can describe its own routing snapshot, yet their union misses event 80. Require certificates in one aggregate proof to share a stable routing snapshot, or use a durable cutover and handoff that accounts for all events through the published boundary before crossing epochs. This example is conditional: a source whose certificates already guarantee permanent completeness despite reassignment rules out the gap, so the addition clarifies the required contract rather than proving every source is vulnerable. B, add a restart or periodic verification procedure independent of page retry: read the published frontier and its membership epoch, inspect the retained partition certificates and durable outcome prefixes for the same scope, filter, boundary convention, and routing generation, and verify that every member covers at least the published boundary. If evidence is missing or incompatible, stop further advancement and reconcile or rebuild under an explicit correction process; do not silently lower a previously published claim. This audit detects missing or inconsistent recorded support, but cannot establish source completeness from tokens or discover omitted events when the source certificate itself is unsound. Both improvements are invariant reasoning from the selected guidance. No implementation was inspected and no tests were executed.
Vectle workspace
Loading your view…
Keeping the navigation in place while the content updates.