Read-only ActivityPub → atproto bridge for the threadiverse using Coves lexicons

consume: the #account tier claims its seq; deletions are exactly-once and terminal master

Chunk-3 finding 2 (5 streams, probe-proven) plus the two state-machine HARDs and the seq-validation gap from the second-opinion re-review. The #account path was read-decide-write-advance as four autocommit statements while main runs the connector and the DLQ redriver over one Dispatcher: two racers read the same watermark, both passed the gate, a stale pause could land after a reactivation, and status="deleted" reached the terminal, irreversible TerminateAccount twice — two Delete{Person} for one deletion, with the suite green. applyAccountClaimed now brackets the transition in applyGatedTx's shape — claim first, apply under it, seq advanced and committed last — with one deliberate divergence, documented at length: the claim is a per-DID pg_advisory_xact_lock, not the ap_actors row lock, because the deleted path's apply reaches outbound.Purger which tombstones that exact row in its own transaction (the deadlock rev_gate.go's own note names). The claim is held across the PDS/PLC confirm on purpose: releasing it re-opens the double-confirm window, and advancing before the probe consumes an event a failed confirm must be able to retry. Also closed, in the same claim: - A nil terminal tier no longer advances the seq past a deletion — errAccountUnapplied rolls the claim back un-advanced, so the frame stays replayable for a build with the tier wired. - A confirmed deletion now leaves a terminal record the actor row agrees with (mirrorTerminalPreference reads federation_prefs and mirrors enabled=false onto ap_actors in the claim tx), so a later active=true frame at a greater seq cannot re-open delivery for an identity whose Delete{Person} went out. - Seq is validated alongside time_us: a frame without a positive seq is ErrPermanentEvent, not a silent "stale or duplicate" skip that would take the whole tier dark if a Jetstream version omitted seq. Race tests pin exactly-once termination (blocking-terminator barrier), the stale-pause interleaving (25 rounds under -race), replayability under a nil tier, terminal survival across reactivation, and the purged-identity characterization. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>


+622 -44
3 changed files