Store an initial snapshot, or atomically replace the exact available
generation named by expectedSnapshotFingerprint. Reserved and terminal
generations must always win.
OptionalexpectedSnapshotFingerprint: stringRemove only an available snapshot. Reservations and terminal fences win.
Recover the exact durable operation needed to poll and reconcile after a process restart.
Atomically reserve the supplied mutation. Any retained completion
tombstone with the same operationKey must return conflict, even when
claim or binding evidence differs; an operation-identity collision must
never authorize redispatch.
Atomically consume source generations and install seller-returned successor generations.
OptionalretainedBindings: readonly EstablishedProposalMutationBinding[]Atomically terminalize successful declines while restoring authoritative unable sources.
OptionalretainedBindings: readonly EstablishedProposalMutationBinding[]OptionalpruneDelete completion tombstones whose store-authored retainUntil is at or
before the store's current time. Implementations must never prune earlier
than ESTABLISHED_PROPOSAL_COMPLETION_TOMBSTONE_RETENTION_MS after
completion. After pruning, findSubmittedTask may return undefined and
reserveMutation may return any result justified by the remaining source
records (including a fresh reservation when every source was restored).
limit is the maximum number of tombstones deleted in one call; ordering
is unspecified. Return the number of deletions committed. Durable stores
must select eligible rows and delete them atomically using one transaction
and one backing-store clock snapshot.
Optional for backward compatibility; durable implementations should implement this or provide an equivalent database-owned sweeper.
Optionallimit: numberRelease an exact reserved/retryable claim, or an exact terminal
commit-uncertain claim after authoritative seller failure evidence.
Persist one seller task ID and reject scoped reuse by live records or completion tombstones.
Production persistence contract for established 3.0/3.1 proposal compatibility state.
reserveMutationis an atomic compare-and-swap across every supplied binding. Implementations must use their database/server clock in that same transaction. Two workers must never both receivereservedfor a first attempt, and authoritatively settled terminal records must never become executable again. A terminalcommit-uncertainrecord remains fenced, but an exact seller-task reconciliation may complete it or release it after an authoritative terminal error. The mutation fence is proposal-wide within principal, seller, and version scope: alternateaccountScoperepresentations for the sameproposalIdmust conflict once any representation is reserved or terminal.Every input and output must be detached from the backing store. Do not persist raw seller responses, authentication material, presigned URLs, or live coordinator objects. The SDK supplies only its reduced allow-listed proposal snapshot.