upstream test harness + ingest notes #
condensed study of bluesky-social/jetstream, written 2026-07-08.
Upstream pin: 289b0328c2e1a0ccf8c870cb45de0b2397de19fb (v0.2.0, the
2026-08-13 official release — Bluesky Protocol Services / Jetstream v2 with
network replay). Server-side delta from the prior pin d4dd2f0 is PR #336
(end-to-end kinds filtering); the rest is client/SDK/docs. The
suites below verify against that commit — see lines citing it further down. This
is the pin most Stream docs share; note jss-format-v1.md and jss-seal-spec.md
are instead on 0c45f29 (2026-07-08), 56 commits earlier.
You need an upstream checkout, and the paths below are upstream's, not ours.
Everything in the simulator and oracle sections — cmd/simulator, segment/*.go,
internal/subscribe/, specs/ — lives in upstream's tree. Clone it wherever you
keep source and check out the pin:
git clone https://github.com/bluesky-social/jetstream
git -C jetstream checkout d4dd2f0127e8934d125b2a26a90fe88239ca98a2
On the maintainer's machine this sits at ~/github.com/bluesky-social/jetstream
(the ~/{forge}/{org}/{repo} layout); nothing in this repository depends on
that path.
The checkout answers questions not decidable from Stream alone: for example,
git log 0c45f29..f29815c -- segment/ shows the per-block bloom right-sizing
described in jss-seal-spec.md.
simulator — our ISP-friendly test network #
self-contained fake atproto network: PLC + one PDS + one relay under a single HTTP listener, default :7777. plain go, no nix: go run ./cmd/simulator serve (builds on macOS arm64, go 1.26).
endpoints (production XRPC paths, no auth, no TLS):
GET /xrpc/com.atproto.sync.subscribeRepos— websocket firehose,?cursor=replay from pebble ring (--firehose-history, default 10k events); too-old cursor →#infoframeGET /xrpc/com.atproto.sync.listRepos(paginated),GET /xrpc/com.atproto.sync.getRepo?did=— backfill path, real signed CARGET /did:...— minimal DID doc pointing back at--public-url
flags: --addr :7777, --data-dir ./data/simulator (pebble), --reset, --seed 42, --accounts 10000, --initial-records-per-account 5, --commits-per-sec 10, --traffic-rate-multiplier.
emits REAL bytes: signed commits, real MST, CAR diffs (Sync 1.1-verifiable), #commit/#identity/#account/#sync. no tooBig. deterministic-ish (seeded logical clock; bootstrap seeded separately from live traffic). adversarial/fault modes are programmatic (oracle-only), not CLI.
zig usage: point stream at ws://localhost:7777/xrpc/com.atproto.sync.subscribeRepos.
oracle (what an equivalent zig harness would check) #
driver boots real server against simulator, walks lifecycle gated on durable-append acks (never sleeps). the simulator world doubles as independent ground truth. contracts: seq ordering, final-state vs world, event-log equivalence (catches lost intermediate events), compaction watermark rules, replay==archive, fold-convergence, anti-vacuity on injected faults (every scheduled fault must prove it fired). tiers incl. crash/restart (SIGKILL real children at crashpoints), deterministic store faults (a selected real RocksDB mutation fails, then the same disk state is reopened), segment faults (real JSS write/fsync/rename calls fail at a selected process-wide ordinal, with exhaustive Patch/Rewrite sweeps and fault-free reopen), and power loss. Upstream models power loss with its strict in-memory VFS; Stream exercises the production Linux filesystem path with ext4 on a strict NBD write-cache backend. detection power measured by mutation campaign.
ingest / live consumer (upstream reference) #
- subscribe url:
ws(s)://host/xrpc/com.atproto.sync.subscribeRepos?cursor=N; cursor persisted (pebble) is the verify-watermark (≤ any in-flight seq), inclusive, at-least-once - decode: CBOR two-part frame; jetstream reads only ops + CAR blocks, never walks MST. verifier (Sync 1.1) mandatory upstream; zat has verifyCommitDiff.
- conversion (pure function): #commit → one internal event per op {witnessed_at µs shared per upstream event, kind create/update/delete, did, collection, rkey, rev, payload=raw DAG-CBOR block}. #identity/#account → single event, payload = envelope CBOR. #sync → tombstone row + resync rows (not on v1 wire).
- validation gate (drop, count, never crash): non-TID rev → whole event (no log line — hostile input must not drive log volume); invalid NSID/rkey → that op; missing CAR block for create/update → that op (partial CARs are spec-legal upstream omissions — no-op updates and non-canonical PDSs — not local corruption; survivors still archived), and ONLY this reason logs: one warn per affected event with seq/count/did, mirroring upstream's processBatch. metrics: dropped_events_total{reason=invalid_rev|invalid_collection|invalid_rkey|field_too_long|missing_block}
- field limits (upstream columnar format): did ≤65535, collection/rkey/rev ≤255, payload ≤u32
- invariants: fsync data before committing cursor; seq assigned at append under writer mutex, starts at 1 (0 = sentinel); per-DID order preserved; never crash on upstream data / crash loud on own corruption
- readable log (hot tail): writer-owned deque, deep-copied entries at seq allocation, 256MiB budget, evicts only below durable watermark (pinned above), notify channel per append, encode-once wire memo per entry shared across fan-out; cursor below floor → cold reader over sealed segments. Stream's tail enforces the same pin: an undurable suffix is retained even when it overruns the byte budget,
publishDurablereleases only the newly durable byte suffix before eviction, and scrape-time readable/pinned/overrun gauges are O(1) accumulators rather than a scan under the hot lock. Its physical deque retires prefix entries in O(1) and compacts only after a large amortized prefix; the 20,000-row burst regression catches the formerorderedRemove(0)implementation that made an 8,192-row repair quadratic and stalled global ingest. - subscribe retention and slow-client controls: the configured read-log byte
budget is the
Tail.max_bytesused by that physical eviction path. Each real subscriber receives the configured sustained window and fractional minimum log-scan rate; caught-up or sufficiently progressing clients reset the streak exactly as upstream does.just subscribe-config-contractruns explicit and non-positive/default values through the ReleaseSafe daemon; Zig receipts separately force physical eviction and both sides of the configured rate boundary without sleeps or sockets. - cold block sharing: production replay uses a 64 MiB byte-bounded LRU by default. A cache item owns one real decompressed JSS block and memoizes v1, v2, and both dictionary-zstd bodies exactly once; memo growth is charged to the same budget. Same-key misses single-flight while unrelated keys decode outside the cache lock. Handles pin evicted items, and manifest refreshes advance a per-segment generation so an in-flight old decode cannot reinsert. The offline receipt opens real sealed files from eight subscriber threads, observes one decode and pointer-identical JSON/zstd payloads, forces memo-growth eviction, then proves a verified manifest refresh re-decodes.
- subscriber read batches: hot and cached-cold pulls scan at most 1,024 raw
entries by default (
--subscribe-read-batch). The boundary precedes v1 skips and client filters, cursor progress includes suppressed rows, and the cold reader stops at the captured hot floor before resolving a hot index. Unit receipts exercise those rules against the real tail and sealed JSS;just subscribe-read-batch-contractdrives a rejecting production WebSocket through 5,000 sealed rows and observes exactly 295 cold pulls at batch 17 plus a stable empty-hot handoff.just subscribe-config-contractcovers explicit and non-positive CLI values. A separate real-archive receipt leaves four rows in the unsealed active segment, confirms only its fsynced prefix is cold-readable, and crosses that active-to-hot boundary in two bounded pulls. The archive snapshot captures sealed metadata, active index, and durable byte boundary under one writer lock, then releases it before any decode or subscriber write. - resync memory lifetime: upstream appends each converted replacement and immediately forwards it to the bounded readable log; it does not retain a second whole-repository wire representation. Stream batches physical archive writes in groups of 1,024 but releases the complete v1/v2 encoder arena after each row is copied into the tail. The offline 4,096-record MST receipt is capped at 1 MiB of repair scratch and mutation-checks the former repair-lifetime JSON ownership by reproducing its exact
ArchiveAppendFailed. - resync capacity envelope: a pinned-simulator ReleaseSafe receipt seeds 96 signed repositories, establishes real verifier chain state, creates 96 genuine chain breaks, and holds only the real getRepo requests at the handler boundary. It observes exactly 32 active workers plus 64 queued jobs, releases 96 complete CAR/MST repairs, and requires the physical JSS archive to converge to simulator ground truth. With 128-record repos the receipt measured 54,886,400 bytes RSS at saturation and a 72,695,808-byte peak; repository size, not hidden scheduler work, determines the production multiplier.
- archive health: free space is collected from the filesystem containing the open archive directory on every scrape; segment-seal latency starts before the pending-block flush and is observed only after footer write/fsync plus finalized-header pwrite/fsync succeeds, using upstream's
0.01 × 2^nbucket boundaries. - block integrity: the JSS xxh3 authenticates only header/footer metadata, while upstream's zstd decoder independently verifies each frame's content checksum. Stream uses its pinned vendored libzstd for the same check; flipping only the final checksum byte of an upstream-produced block is the mutation receipt.
zig oracle v1 (2026-07-12) #
just oracle (tests/oracle.py): crash-matrix restart harness against the
simulator. arms --crashpoint=<seam> (src/internal/crashpoint.zig — abort()
at durable commit boundaries incl. mid-download), lets the real binary die,
restarts clean, asserts convergence: serving ungates, listSegments non-empty,
/subscribe-v2 replay seq-monotonic, serving proves the RocksDB phase reached
steady_state, backfill tree cleaned, no legacy metadata stores reappear, and
interrupted repos are repaired by the pending pass (anti-vacuity via log
markers). Every restart also scrapes the production metrics endpoint: phase 3,
the real merging→steady transition, merge/write-state histograms, and all six
registered merge counters are mandatory; bootstrap-resume cases additionally
prove bootstrap→merging plus drain/seal/close/write timings, and the interrupted
download case must perform nonzero source, DID-lookup, and event work. A
separate injected metadata-commit failure test proves the archive
does not publish or strand a segment durability boundary. Event-log and final
state equivalence are covered by the pinned differential oracle below; strict
lifecycle, compaction, and timestamp-import power loss are covered by the Linux
tier below. Seed-derived restart determinism is covered by the five-world
predicate-kill tier below.
The harness is runnable without internet after dependencies are
cached. Start the pinned simulator with GOPROXY=off go run ./cmd/simulator serve ..., then run UV_OFFLINE=1 just oracle; the recipe builds and crashes
the ReleaseSafe candidate rather than a debug-only binary. Replay checks
consume the entire sealed archive when it contains fewer than 200 rows and a 200-row prefix
otherwise; they never wait for an arbitrary cardinality the simulator did not
produce. Every case also rejects OutOfMemory and fatal event-handler log
evidence. The harness caught a live-repair regression that recreated
backfill/repo-scratch after cutover; bootstrap, live repair, and failed-repo
healing have disjoint scratch namespaces, and every case proves the
lifecycle-owned backfill/ tree is absent at steady state.
strict Linux power-loss oracle (2026-07-20) #
just powerloss-oracle runs the real aarch64-linux-gnu ReleaseSafe binary,
RocksDB, and JSS on ext4 mounted over a kernel NBD device. The Python nbdkit
backend has separate live and durable images: ordinary writes affect only the
live image, while NBD FLUSH/FUA copies dirty extents to the durable image and
fsyncs it. At the selected boundary the harness kills nbdkit first, SIGKILLs
Stream second, recreates the live device exclusively from the durable image,
runs e2fsck, remounts it, and starts an uninstrumented recovery process.
The calibration is fail-closed: a raw fsynced OLD block must survive while a
later direct, readable, unflushed NEW block must disappear, and the flush
receipt must remain unchanged. Every lifecycle case requires a unique cutpoint
receipt, at least one pre-cut storage flush, real RocksDB and segment trees,
nonempty archive XRPC results, healthy serving, and 100 ordered public
/subscribe-v2 rows (or the complete archive when smaller). The passing
candidate recovered all eight schedules: after-repo-complete ordinals 1 and
2, destination-flush-before-source-commit, destination-seal-before-discovery,
discovery-before-cleanup, cleanup-complete, bootstrap-live-close-before-seal,
and steady-phase-before-steady-run.
The same production-binary campaign covers upstream's mutation boundaries.
Six delete-compaction schedules cut at each rewrite write/fsync/rename/dir-fsync
boundary and on both sides of the durable watermark; every recovery converged
to watermark 2500 and exactly 1,507 retained events after dropping 993 rows.
Four timestamp-import schedules cut at each sealed-segment patch boundary; the
target rows recovered with the imported timestamp while untargeted rows kept
their exact witness-derived time. All ten cases reject stale temporary files,
require complete duplicate-free public V2 replay, and use fixtures created by
the real Stream JSS writer rather than synthetic segment bytes. This campaign
found a Linux-only O_PATH parent-directory handle whose fsync failed with
EBADF; rewrite directories are opened as readable directory handles and
the full campaign passes on Linux.
An additional two-crash schedule covers upstream's restart-after-cleanup
guard: the first process is killed after removing backfill/ but before the
directory fsync; the second observes the cached absence, must emit another
durability flush before deleting merge cursors, and is then power-cut at
cleanup-complete. Recovery must still find the source tree absent and every
survivor exactly once.
This campaign found production defects that process-local crash tests could
not: Linux directory handles opened with O_PATH made the required cleanup
fsync fail; cleanup cursor deletion—including its restart guard—was not coupled
to durable directory removal; a 256 KiB ping-thread stack failed on Linux; the listener briefly
served before bootstrap gating; and leading sequence-zero hot-tail rows could
misclassify an archive cursor as resident. The Linux process regression
observes repeated 503 responses throughout bootstrap and then replays
sequences 1 through 10 from the fresh archive without restart.
The one-time just powerloss-image step builds the digest-pinned Ubuntu tool
image containing nbdkit, nbd-client, and ext4 utilities. Actual oracle runs
use --pull=never, uv --offline, and the pinned local simulator. They require
privileged Linux container access and /dev/nbd3; failure evidence is retained
under the printed stream-powerloss-* temporary directory instead of being
deleted.
archive client contract #
just archive-contract creates a temporary three-segment, 5,000-row JSS
archive and serves it from a real ReleaseSafe Stream process. It directly
checks listSegments, getSegment, getBlock, and planBackfill, then runs
the upstream Go client through whole-segment, DID-filtered block, sentinel-only
block, bounded-range, and archive-to-live-cutover plans. The client harness
requires upstream HEAD
d4dd2f0127e8934d125b2a26a90fe88239ca98a2, selects a cached Go 1.26.5
toolchain when necessary, and forces GOTOOLCHAIN=local, GOPROXY=off, and
GOSUMDB=off for the actual Go build and run. uv is also forced offline;
Zig's checksum-pinned dependencies must already be in its global cache. A
missing pin, Go toolchain/module, Python environment, row, sentinel, or cursor
transition fails the command.
The same official-client run checks the resident manifest after its
archive-to-live cutover: the sealed gauge equals listSegments, the load
histogram has one observation per startup segment, replay has produced a real
resident block-index hit, and no unknown-index lookup occurred. Unit adversity
holds an old refcounted index across a verified rewrite and proves cold cursor
translation combines its historical envelope with offsets read from the newly
opened file generation, matching upstream's topology-preserving race contract.
The direct planner regression goes further: after startup it renames every JSS
file out of the segment namespace, requires an unfiltered plan to remain exact,
then restores the files for download tests. That fails if planBackfill opens
segment data instead of using its refcounted resident envelopes, DID blooms,
and collection summaries.
just http-metrics-contract launches the real candidate with
--segment-cache-max-age=1500ms and requires getBlock to return
Cache-Control: public, max-age=2. This records upstream's positive-duration
ceil behavior independently of the default public, no-cache archive receipt.
just plan-config-contract builds a real three-segment JSS archive whose
selected-block density is exactly 3/4, then starts three production Stream
processes. It proves the distinct DID/collection caps (including zero disabling
filters), one-entry work-unit pagination, zero-entry-limit unbounded paging,
and the 1.0-versus-0.75 whole-segment threshold boundary through public
planBackfill responses.
just cursor-lookback-contract seeds three real sealed segments and starts
three production Stream processes. With the upstream 36-hour default it proves
that v2 rejects an old sequence cursor before upgrade while v1 clamps to the
oldest eligible segment. A widened window replays from the requested sequence;
--cursor-lookback=0 upgrades without replay and records the disabled cursor
mode. Timestamp cursors use the same conservative segment floor and clamp on
both protocols. The receipt speaks raw WebSocket framing with Python's standard
library and needs no network access.
just compaction-config-contract seeds two physical create/delete segments
twice. A production process with tombstone cap 1 and one rewrite worker must
commit two chunks and report a one-worker rewrite group. A second process with
cap 0 (upstream's unlimited sentinel) and two rewrite workers must commit one
chunk and report a two-worker group. A third production process repeats that
physical pass on a 250 ms Go-duration interval. All public archives must contain
only the two surviving marker rows at durable watermark 4. A real archive unit
receipt separately proves the first cap trigger wakes and completes in under
500 ms despite a one-hour periodic interval. The receipt checks the timer,
trigger, fold, and rewrite paths.
just retry-config-contract seeds durable failed-repository rows, serves real
getRepo failures from a threaded loopback HTTP server, and runs four
ReleaseSafe Stream processes. Held requests prove explicit global concurrency
3, explicit per-host concurrency 2, and upstream's zero-value defaults of 16
global and 4 per host. Each process is stopped after exactly one completed
pass; the receipt reopens the real RocksDB store and requires every row to have
one additional attempt plus a next-attempt delay inside the configured
1–1.5-second exponential-jitter window. This covers scheduling, admission,
failure persistence, Go-duration parsing, zero defaults, and max-delay clamping
without network access.
The pinned upstream simulator drives four complete bootstrap/merge lifecycles.
The normal two-page crawl makes three real listRepos requests: two bootstrap
pages and the final-page merge-discovery replay. With
--skip-merge-discovery, it makes exactly the two bootstrap requests. A
max-repo selection proves the same automatic two-request short circuit, while
an explicit-DID selection bypasses listRepos entirely. Both automatic cases
also traverse the configured-skip lifecycle branch, matching upstream.
Three additional runs use the same real request ledger. With batch size 2, the
first getRepo precedes the second listRepos page; with batch size 3, both
two-entry pages precede every getRepo, proving the page-aligned batch may
exceed its target. A zero-sized setting follows Jetstream's
100,000-entry production default and has the same cross-page ordering. Relay
resume and merge-discovery cursors are committed together only after the
corresponding dispatch batch reaches durable terminal state.
A separate 104-account simulator world holds real getRepo handlers before
serving their CARs. Three ReleaseSafe Stream processes reach measured request
peaks of 7 for an explicit worker setting, 100 for zero, and 100 when the flag
is omitted. Releasing the handlers lets every process prepare the real CARs,
converge its physical archive, enter steady state, and drain cleanly. This
detects the former behavior where the advertised count was silently reduced to
four by a 2 GiB-per-worker formula.
The bootstrap archive has a separate physical compression receipt. Four
deterministic 8 MiB columnar blocks overlap in four real zstd workers (no sleep
or compression mock). A second archive run compares synchronous and async JSS
bytes exactly, then checks all eight committed blocks and the final durability
watermark. This verifies that --backfill-async-flush-workers is exercised by
the write path.
pinned differential oracle (2026-07-20) #
just differential-oracle refuses to run unless the upstream checkout is at
d4dd2f0127e8934d125b2a26a90fe88239ca98a2. A Go overlay places the committed
test source inside upstream's internal/oracle package, so the receipt directly
reuses its simulator world, physical JSS reader, event-log comparator,
independent MST reconstruction, invariant checker, and public archive client.
The candidate is the real ReleaseSafe Stream process using real sockets and a
temporary on-disk archive; GOPROXY=off, GOSUMDB=off, and a local Go
toolchain keep the run offline and fail closed when prerequisites are absent.
The current tier proves bootstrap convergence and controlled live equivalence for create, update, delete, identity, account, sync, and create_resync rows. It also removes an intermediate update to demonstrate comparator detection power, requires clean SIGTERM drain, restarts the same data directory, and reconstructs the complete archive through planBackfill/getSegment/getBlock/subscribe-v2. The production disconnect check additionally terminates and restarts the pinned local simulator while the ReleaseSafe binary is ingesting: Stream must retain its cursor, reconnect, resume delivery, and then exit cleanly on SIGTERM. The archive fallback close is deliberately registered above consumer teardown, so an unexpected consumer error cannot invoke the durability hook through freed cursor state.
just differential-oracle-multiseed adds upstream's restart-chain baseline
and exact seeded predicate-kill selector. Five distinct simulator worlds drive
real create/update/delete/account/sync intermediate chains through selected
(crashpoint, ordinal) process aborts, same-disk recovery, upstream event-log
coverage, compaction filtering, final-state reconstruction, recreated-record
visibility, and the red-first missing-delete check. The campaign exposed two
gaps: bootstrap could begin before its live websocket handshake, and the
close-before-seal seam had drained pipeline work whose final partial JSS block
was not yet durable. Stream gates backfill on the firehose connection and
flushes that block before the seam; all five worlds pass offline.
The real-process wire tier injects upstream's duplicate and regressed relay
windows on the same connection and requires the exact once-per-frame archive,
including account delete/reactivate/recreate. The complete upstream frame-fault
campaign is covered: malformed CBOR and FutureCursor advisory frames; two
successive 3 MiB read-limit failures followed by cursor-safe reconnect; a
swallowed frame reported as an exact one-sequence gap and recovered by
authenticated repair; a schema-ordered unknown future frame that occupies the
missing sequence without becoming a decode error; and a partial CAR whose
missing record block drops exactly one op while its siblings and verifier chain
survive. The receipts caught three production divergences: a cursor fallback
that lost the global relay high-water, Zat rejecting an omitted optional
prevData field, and strict repository DAG-CBOR ordering leaking into the
forward-compatible wire inspector. All three are regression-covered.
The adversarial tier now reuses upstream's exact lie tables and ledger. Real
signed commits prove that invalid collection, rkey, and column-width ops drop
individually while benign siblings survive. A divergent #sync with a non-TID
envelope proves the Atmos ordering boundary: authenticated getRepo repair
advances durable verifier state before the ingest gate drops the entire
directive as live/invalid_rev. A separately signed non-TID commit is rejected
by the verifier, then a valid follow-up chain-break repairs both records. A
DID-scoped PLC resolution failure cannot wedge a sibling DID. Finally, real
bootstrap CARs carry invalid UTF-8, no-slash, dot-dot, and 300-byte keys; only
valid records reach physical JSS, filtered MST truth converges, and every
canonical (source, reason) counter meets the upstream ledger floor.
The differential tier alone does not claim filesystem durability. The strict
Linux tier closes the pinned storage, lifecycle-power-loss, compaction, and
timestamp-import mutation schedules. On 2026-07-21 the five-world predicate-
kill tier passed again against candidate 8b04c42; every selected real-process
abort fired, recovered on the same disk, and matched the upstream oracle.
HTTP and getBlock metrics contract #
just http-metrics-contract seeds the same real sealed archive and launches a
ReleaseSafe Stream process with loopback-only dependencies. Standard-library
HTTP requests exercise getBlock 200, conditional 304, failed-precondition 412,
Range 206, invalid Range 416, malformed 400, and missing-block 404 responses.
The archive contract additionally drives both getSegment and getBlock through real multipart ranges,
mixed overlapping/non-overlapping members, the aggregate-size fallback, and
the different headers and bodies for malformed versus non-overlapping 416s.
It verifies Last-Modified against the physical segment mtime and exercises
If-Match, If-Unmodified-Since, If-None-Match, If-Modified-Since, and ETag/date
If-Range with Go's precondition precedence. Unknown NSIDs traverse the same real route and must return
501 MethodNotImplemented; deleting a manifest-resident segment proves both
byte endpoints use the canonical 500 InternalServerError envelope. A
separate real-server test holds the serving gate closed and requires the JSON
503 ServiceUnavailable envelope instead of Stream's former plain-text 503.
The combined receipts prove
upstream's ok, bad_request, not_found, and error partition; duration
cardinality; and that served bytes increase by exactly one completely written
200 frame, never by partial or conditional responses. It also sends a real
masked WebSocket close frame and waits for the inline subscription handler to
finish before checking its HTTP lifetime metric. Handler labels reproduce the
pinned upstream public mux: one xrpc/ subtree, individual root/status/
subscribe routes, and no observations for debug health/metrics or unmatched
requests.
status diagnostics contract #
just status-contract seeds repository transitions through the real RocksDB
repo store, closes the seed process, and reopens the same data directory with
the production ReleaseSafe Stream binary. It checks the public text and HTML
host views over loopback: exact upstream largest/failing ordering, durable
current counts and bounded error history, safe escaping, and the browser
filter contract. The seed includes a healthy larger host and a smaller host
with repeated failures, so either sort or history silently disappearing makes
the receipt fail. Browser checks additionally exercise the filter and the
horizontal table layout at desktop and phone-sized viewports. The same
restarted binary is queried through the Account tab and legacy did alias,
including durable fields, unknown identity presentation, automatic real
verification failure presentation, no-store headers, and side-effect-free
HEAD. A separate production-route test uses a real JSS archive and signed
commit data from loopback PLC/PDS endpoints to prove successful verification
and the port-free per-source-IP limiter boundary.